The present application relates to the technical field of encrypted data protection, in particular to a data protection method and
system based on TPM
encryption, comprising: extracting file index node and
directory item features, generating root node digest through hierarchical aggregation logic and measuring to platform configuration register, establishing hardware anchor topology based on storage root key; analyzing
data stream to generate feature keywords, generating hardware derived credentials using TPM hardware
unique key, constructing balanced search tree and encapsulating to generate
ciphertext mapping index. Analyzing I / O request, performing hardware anchored logical integrity comparison for
metadata operation; quantifying hardware evaluation value for
data content operation, if threshold is met, synchronous hardware
verification is performed, otherwise, physical block is located based on
ciphertext mapping index and
verification operation is pushed into
delay queue asynchronously. The present application realizes
strong binding of data and hardware and fast addressing of
ciphertext through
software and hardware cooperative anchoring, effectively balancing
data security protection and high
concurrency I / O
throughput performance.