[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"topic-Hadoop":3},{"name":4,"kind":5,"tokens":6,"total":7,"page":7,"page_size":8,"items":9},"Hadoop","tag",[4],1,100,[10],{"id":11,"title":12,"url":13,"summary":14,"summary_zh":15,"content":16,"source_name":17,"source_url":13,"published_at":18,"category":19,"cover_url":16,"hotness":20,"is_selected":21,"score":22,"score_detail":23,"sources":30,"tags":32,"search_phrases":37,"slug":40,"view_count":41,"doi":42,"paper":43,"created_at":61},2927,"CD-KLM: A Secure Storage Architecture for Agricultural Big Data","https:\u002F\u002Fdoi.org\u002F10.20944\u002Fpreprints202609.1541.v1","With the development of smart agriculture, agricultural big data typically exhibit characteristics such as long-term accumulation and multi-source heterogeneity, which place higher demands on secure storage and sustained decryptability in long-running environments. To address this issue, this paper proposes CD-KLM, a secure storage architecture for Hadoop-based agricultural big data platforms. Specifically, we adopt a client-driven, server-lightweight-collaborative design, in which the reading and decryption capabilities of historical files are independently controlled by the client, while the server only issues collaborative salt values to authenticated clients during new-file creation. On this basis, a dynamic working-key derivation mechanism is designed based on HKDF and file-related contextual information, so that working keys no longer need to be persistently stored over the long term, thereby reducing the risk of malicious data decryption caused by prolonged exposure of critical key material. Meanwhile, threshold-based key recovery is unified at the root-key level, enabling the system to restore its overall decryption capability even when critical keys are damaged or lost. Experimental results in a Hadoop distributed environment show that, while ensuring key recoverability and continuous decryptability, the proposed architecture imposes only a low impact on system throughput, making it suitable for long-running secure storage scenarios for agricultural big data.","随着智慧农业的发展，农业大数据通常呈现出长期积累、多源异构等特征，这对长运行环境下的安全存储与持续可解密性提出了更高要求。针对这一问题，本文提出了CD-KLM，一种面向基于Hadoop的农业大数据平台的安全存储架构。具体而言，我们采用客户端驱动、服务端轻量协同的设计，其中历史文件的读取与解密能力由客户端独立控制，而服务端仅在新文件创建时向已认证客户端下发协同盐值。在此基础上，基于HKDF与文件相关上下文信息设计了动态工作密钥派生机制，使工作密钥不再需要长期持久化存储，从而降低关键密钥材料长期暴露所导致的恶意数据解密风险。同时，在根密钥层面统一了基于阈值的密钥恢复机制，使系统在关键密钥损坏或丢失时仍能恢复整体解密能力。在Hadoop分布式环境中的实验结果表明，在保证密钥可恢复性与持续可解密性的同时，所提架构对系统吞吐量的影响较低，适用于农业大数据的长期运行安全存储场景。",null,"Preprints.org","2026-09-18T00:00:00Z","论文",10,false,63,{"impact":24,"substance":25,"depth":26,"authority":27,"freshness":28,"relevant":7,"comment":29},12,20,17,6,8,"面向农业大数据长期安全存储的预印本论文，方法设计有新意但尚未经同行评审，属细分技术进展。",[31],{"name":17,"url":13},[33,34,35,4,36],"智慧农业","农业大数据","数据安全","密钥管理",[38,39],"CD-KLM 农业大数据 安全存储","Hadoop 农业大数据 密钥恢复","CD-KLM农业大数据安全存储-2927",0,"10.20944\u002Fpreprints202609.1541.v1",{"doi":42,"openalex_id":44,"authors":45,"venue":17,"cited_by_count":41,"oa_url":13,"card":54,"direction":58,"ingested_from":60},"W7213553318",[46,48,50,52],{"name":47,"orcid":16},"Bochun Cao",{"name":49,"orcid":16},"Hanbing Deng",{"name":51,"orcid":16},"Yuncheng Zhou",{"name":53,"orcid":16},"Teng Miao",{"tldr":55,"method":56,"finding":57,"direction":58,"opportunity":59},"提出CD-KLM架构，为Hadoop农业大数据提供长期安全存储与持续解密能力。","客户端驱动、服务端轻量协作，基于HKDF和文件上下文动态派生工作密钥，阈值根密钥","在保证密钥可恢复与持续解密的同时，对Hadoop系统吞吐量影响很小。","智慧农业 \u002F 农业物联网","可探索动态密钥派生与访问控制结合，适配边缘农业物联网的轻量级安全存储。","openalex","2026-09-19T23:30:11.094294Z"]