A system and method for data storage integrity verification based on polynomial rings

By adopting a data storage integrity verification method based on polynomial rings, the security threats of artificial intelligence and quantum computing in data storage are solved, and unconditionally secure data integrity verification is achieved.

CN120540605BActive Publication Date: 2026-06-26BEIJING UNIV OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING UNIV OF TECH
Filing Date
2025-06-12
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively defend against attacks on cryptographic systems by artificial intelligence and quantum computing, especially in the process of data storage, where they face security threats of forgery and tampering.

Method used

A data storage integrity verification method based on polynomial rings is adopted. The data is transformed into a polynomial through the data encoding module, the basis is randomly selected by the basis generation module, and integrity verification is performed in combination with the measurement module. The verification mechanism is designed based on mathematical principles.

Benefits of technology

It achieves unconditional security against attacks from artificial intelligence and quantum computing, ensuring data integrity and preventing tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120540605B_ABST
    Figure CN120540605B_ABST
Patent Text Reader

Abstract

The application discloses a kind of data storage integrity verification system and method based on polynomial ring, it is related to data security technical field.The system includes data encoding module, base generating module, standard value library and measurement module;Data encoding module is used to convert the data to be verified into polynomial with the format of binary, base generating module is used to select base space and generate base using random selection method, measurement module completes the integrity verification of data by calling base generating module and standard value library, and the standard value library is used to store the standard integrity verification value of input data.The application is different from the conventional password based on mathematical problem design, and it is difficult to resist the password analysis based on artificial intelligence and quantum computing.The application only relies on mathematical principle to design integrity verification mechanism, and the data integrity verification is carried out based on the random selection of base of polynomial ring to resist various password attacks based on artificial intelligence and quantum computing, and does not depend on any mathematical problem, with unconditional security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a data storage integrity verification system and method based on polynomial rings, belonging to the field of data security technology. Background Technology

[0002] Artificial intelligence (AI) and quantum computing, as the core forces of the new generation of technological revolution, are profoundly changing human society. While driving social progress, AI and quantum computing have also had a profound impact on the field of cybersecurity. AI has improved the automated defense level of information systems, while quantum computing has driven a computing revolution, enabling secure key distribution. However, while AI and quantum computing contribute to the development of cybersecurity, they also pose significant challenges. Especially in the field of cryptography, AI and quantum computing will reshape the landscape of cryptanalysis. AI, through deep learning, breaks through the limits of cryptanalysis, achieving autonomous identification of encryption mechanisms and automated discovery of vulnerabilities in cryptographic protocols. Quantum computing significantly reduces the security level of classical cryptographic systems. The quantum Shor algorithm, through the parallelism and superposition characteristics of quantum computing, can directly break RSA and elliptic curve cryptography (ECC). The quantum Grover algorithm can directly halve the security strength of symmetric encryption and hashing algorithms. Currently, a global wave of post-quantum cryptography (PQC) is sweeping the world. The United States will fully replace PQC by 2035. Meanwhile, the China Commercial Cryptography Standardization Institute officially launched a call for submissions for a new generation of quantum-resistant cryptographic algorithms in February 2025.

[0003] The nation is currently making every effort to develop a trusted data space, and trusted data storage is the foundation for ensuring data security and building a trusted data space. Because data faces numerous security threats during storage, such as forgery and tampering, establishing highly reliable integrity verification algorithms for data storage and verifying the trustworthiness of stored data in real time is of great significance.

[0004] Given the significant threat that artificial intelligence and quantum computing pose to cryptographic systems, this invention proposes a data storage integrity verification method based on polynomial rings. This method uses random distribution to resist cryptanalysis, and its security relies solely on mathematical principles, thus possessing unconditional security. Summary of the Invention

[0005] The technical problem this invention aims to solve is how to improve the security of data integrity verification to resist security threats from artificial intelligence and quantum computing. This invention provides a polynomial ring-based integrity verification method and system, which, unlike conventional cryptographic designs based on mathematical problems, relies solely on mathematical principles to design an integrity verification mechanism to resist various cryptographic attacks based on artificial intelligence and quantum computing.

[0006] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows: A data storage integrity verification system based on a polynomial ring includes a data encoding module, a base generation module, a standard value library, and a measurement module; the data encoding module, the base generation module, and the standard value library are respectively connected to the measurement module; the data encoding module is used to convert the binary data to be verified into a polynomial, in preparation for the subsequent integrity verification by the measurement module; the base generation module is used to select a base space and generate a base using a random selection method, for the measurement module to perform subsequent measurements; the measurement module completes the integrity verification of the data with integrity verification by calling the base generation module and the standard value library, ensuring that the data is not tampered with; the standard value library is used to store the standard integrity verification values ​​of the input data to be verified; the data involved in this technical solution refers to the data stored in the computing device and the network communication data.

[0007] Preferably, the data encoding module converts the input integrity verification data into a polynomial ring function. The elements in the array. Let the input data to be verified be... ,in For the data labels of this data, The length of the data, the data content The data encoding module will Turn to Middle elements At this point, a group of elements is formed. , It is an element-matter polynomial.

[0008] Preferably, the base space It has A collection of elements. Base It is the base space The elements in the array are randomly generated.

[0009] Preferably, the standard integrity check values ​​of the input data to be checked are stored in a standard value library according to entries, and the specific structure of each entry is as follows:

[0010]

[0011] Data labels for standard integrity check values, The data length of the standard integrity check value. These are the base and standard check value selected for the standard integrity check value, respectively. This represents the number of data entries in the standard value library. All data in the benchmark value library is stored confidentially and is used only within the integrity verification system of this invention.

[0012] Preferably, the measurement module receives the element group. ,examine Is it in the standard value library?

[0013] 1) If If the value is not in the standard value library, the base generation module is invoked. The base generation module randomly selects values ​​from the base space A. This is then returned to the measurement module. The measurement module calculates...

[0014]

[0015] Will The data is stored in the baseline library. Simultaneously, the output data T=2 indicates that the input data to be verified is newly added data, and its data integrity verification value has been generated and stored.

[0016] 2) If The measurement module reads values ​​from the standard value library. The corresponding standard integrity check value. For symbol differentiation, assume it is read from the standard value library. The corresponding standard integrity check value is .if If the output data is T=0, it indicates that the input integrity verification data has been changed relative to the standard integrity verification value. Then utilize base Perform a modulo operation to generate a new standard check value.

[0017]

[0018] if If the input integrity check value is unchanged, the output data T=1, indicating that the input integrity check data has not changed relative to the standard integrity check value. Otherwise, the output data T=0, indicating that the input integrity check data has changed relative to the standard integrity check value.

[0019] A data storage integrity verification method based on polynomial rings includes the following steps:

[0020] Initialization phase: The standard value library is empty, the number of data entries is 0, and the base generation module selects base space A.

[0021] Step 1: Input the data to be verified for integrity. The data encoding module converts the input data into a polynomial ring. The elements in the table are processed and a group of elements is generated. The group of elements is then sent to the measurement module.

[0022] Step 2: After receiving the element group, the measurement module checks whether the data tags of the data to be verified for integrity in the element group exist in the standard value library; if they exist, proceed to step 5.

[0023] Step 3: If the data label of the data to be verified in the element group does not exist in the standard value library, then call the base generation module to generate a base.

[0024] Step 4: The measurement module uses the element-wise polynomial to take the modulus of the basis, storing the data label, data length, basis, and standard integrity check value of the data to be verified in the standard value library, and incrementing the number of entries in the standard value library by 1. Simultaneously, it outputs data T=2, indicating that the input data to be verified is newly added data, and that the standard integrity check value for this data has been generated and stored.

[0025] Step 5: If the data tag of the data to be verified in the received element group exists in the standard value library, the measurement module will read the entry corresponding to that data tag from the standard value library using the data tag as an index.

[0026] Step 6: Check if the data length of the data to be verified in the element group is equal to the data length of the standard integrity verification value in the entry. If they are not equal, output data T=0, indicating that the data to be verified has been changed relative to the standard integrity verification value.

[0027] Step 7: If the data length of the data to be verified in the element group is equal to the data length of the standard integrity verification value in the entry, then use the element polynomial to take the modulus of the basis in the entry to obtain a new standard integrity verification value; compare the new standard integrity verification value with the standard verification value in the entry. If they are equal, output data T=1, indicating that the input data to be verified has not changed relative to the standard integrity verification value.

[0028] Step 8: If the new standard integrity check value is not equal to the standard check value in the entry, output data T=0, indicating that the input integrity check data has been changed relative to the standard integrity check value.

[0029] The beneficial effects of this invention are:

[0030] 1. Unlike conventional cryptography, which is based on mathematical problems and is difficult to defend against cryptanalysis based on artificial intelligence and quantum computing, this invention relies solely on mathematical principles to design an integrity verification mechanism. It performs data integrity verification based on the random selection of the basis of a polynomial ring to resist various cryptographic attacks based on artificial intelligence and quantum computing.

[0031] 2. The security of this invention relies solely on mathematical principles and does not depend on any mathematical problems, thus possessing unconditional security. Attached Figure Description

[0032] Figure 1 For integrity verification system based on polynomial rings;

[0033] Figure 2 This is a flowchart of the integrity verification system based on polynomial rings. Detailed Implementation

[0034] The framework diagram of the system of this invention is as follows: Figure 1 As shown, the workflow diagram of the integrity verification system based on polynomial rings is as follows: Figure 2 As shown.

[0035] The following is the background mathematical knowledge of the method of this invention:

[0036] 1. Polynomial ring It satisfies the following properties:

[0037] (1)

[0038] (2) Order , but

[0039] (3) Let , ,but

[0040] .

[0041] 2. The set of polynomials of degree 1 is defined as follows:

[0042] .

[0043] 3. The set of irreducible polynomials is defined as follows:

[0044]

[0045] .

[0046] 4. They are respectively A polynomial of degree 1, satisfying

[0047] ,

[0048] like: Then define right The modulo operation is:

[0049] ,

[0050] It is called a remainder polynomial.

[0051] The technical solution of the present invention will be explained in detail below with reference to two specific examples.

[0052] Example 1: Integrity verification of data storage in a cloud environment

[0053] In a cloud computing environment, a user needs to transfer a large number of encrypted data blocks from their local terminal to the cloud environment for storage. To ensure that the data is not maliciously tampered with or damaged after storage or during subsequent use, an integrity verification method is required. This invention focuses on solving the integrity verification problem after data storage.

[0054] Initialization Phase: The cloud environment initializes its standard value library. The standard value library stores verification information for data blocks; initially, it is empty, containing no data entries, and the data entry counter is set to 0. The cloud environment's basis generation module pre-selects a suitable basis space A, for example, an irreducible polynomial space of degree 256. The elements in the base space will serve as the basis polynomials for generating the check values ​​in subsequent steps.

[0055] Step 1: The cloud environment receives input data. The data encoding module converts the data content of each data block into a polynomial ring. For example, assuming the data content is 300 bits of binary data "100……001", the data encoding module converts it into an element-wise polynomial. The data length is required here. The data encoding module generates an element group for this data block. , representing the data block ID, data length, and transformed element-polynomial, respectively. The generated element set is then sent to the measurement module in the cloud environment.

[0056] Step 2: The measurement module in the cloud environment receives the element group sent by the user terminal. The measurement module first checks whether the data block ID in the element group exists in the standard value library.

[0057] Step 3: If the data labels in the element group do not exist in the standard value library, then the base generation module is invoked. The base generation module generates data uniformly and randomly from... Select base (i.e., an irreducible polynomial of degree 256), and return to the metric module.

[0058] Step 4: The measurement module uses the element-wise polynomial to take the modulo of the base (the modulo operation is equivalent to CRC256), and stores the data tag, data length, base, and check value (the remainder polynomial obtained from the modulo operation) in the standard value library, incrementing the number of entries in the standard value library by 1. Simultaneously, it outputs data T=2, indicating to the user terminal or other systems that the received data block is a new data block, and that its integrity check value has been generated and securely stored.

[0059] Step 5: When the cloud environment receives new data, repeat steps 1 through 4. When the cloud environment needs to verify the integrity of a stored data block (e.g., before the data is used, or during periodic integrity checks), the metrics module will execute the following steps.

[0060] Step Six: The measurement module uses the data block ID as an index to read the corresponding stored data entry from the standard value repository in the cloud environment. For distinction, the data entry read from the standard value repository will be denoted as... ,in It is the length of the stored data. It is the basis of storage. This is the stored verification value. The cloud environment's metrics module compares the length of the retrieved data blocks. The data length of the corresponding data entry read from the standard value library .if If the measurement module outputs data T=0, it indicates that the length of the retrieved data block has changed compared to the previously stored data block, which usually means that the data may have been tampered with.

[0061] Step 7: If the data length in the element group is equal to the data length in the entry, then use the element polynomial to take the modulo of the basis of the entry to obtain a new check value. The new checksum and the standard checksum in this entry will be compared. The data is compared, and if they are equal, the output data T=1 is used to indicate that the retrieved data block is completely consistent with the previously stored data block and no changes have occurred.

[0062] Step 8: If the new checksum is not equal to the checksum in the entry, output data T=0, indicating that the content of the retrieved data block has changed compared to the previously stored data block, which usually means that the data may have been tampered with.

[0063] Example 2: Data Integrity Verification Based on TPCM

[0064] The following section introduces an enhanced trusted boot scheme based on TPCM and a polynomial ring. TPCM stands for Integrity Verification System.

[0065] Initialization Phase: TPCM initializes its standard value library. The standard value library stores verification information for data blocks; initially, it is empty, containing no data entries, and the data entry counter is set to 0. The basis generation module pre-selects a suitable basis space A, for example, an irreducible polynomial space of degree 256. The elements in the base space will serve as the basis polynomials for generating the check values ​​in subsequent steps.

[0066] Step 1: During the verification information generation phase, critical boot components such as the BIOS / UEFI firmware, bootloader, and operating system kernel are divided into fixed-size data blocks. Data tags, data lengths, and data blocks are considered as input data. The data encoding module converts the data content of each data block into a polynomial ring. In the BIOS, assuming the data content is 300 bits of binary data "100……001", the data encoding module converts it into an element-wise polynomial. The data length is required here. The data encoding module generates an element group for this data block. , where represents the ID of the data block, the data length, and the transformed element polynomial, respectively.

[0067] Step Two: In the verification information generation phase, the measurement module calls the base generation module. The base generation module uniformly and randomly selects data from... Select base (i.e., an irreducible polynomial of degree 256), and return it to the measurement module. The measurement module calculates the checksum of the BIOS data block. And store it in the standard value library, with the entry value being... These represent the data tag, data length, base, and checksum, respectively. Simultaneously, the output data T=2 indicates to the user terminal or other systems that the received data block is a new data block, and that its integrity checksum has been generated and securely stored.

[0068] Step 3: During the trusted boot phase, the integrity of the data block for each critical boot component about to be loaded and executed is verified sequentially. Taking BIOS as an example, the data encoding module receives... Encode BIOS data into a polynomial ring. For the elements in the array, perform the same operations as in step one.

[0069] Step 4: The measurement module receives the results from the data encoding module. According to data tags Retrieve the corresponding entry from the standard value database. To distinguish them, denote the data entry retrieved from the standard value database as... ,in The original length of the data. This is the verification value for the original data. If... If the data length is inconsistent, the measurement module outputs data T=0, indicating that the length of the retrieved data block has changed compared to the previously stored data block, and the trusted startup process terminates.

[0070] Step 5: If the length of the input data is equal to the length of the data in the standard value library, recalculate the checksum of the input data. The new checksum and the standard checksum in this entry will be compared. The data is compared. If they are equal, the output data is T=1, indicating that the retrieved data block is completely consistent with the previously stored data block and no changes have occurred, and the trusted chain continues to pass. If the calculated checksum is not equal to the stored checksum, the output data is T=0, indicating that the content of the retrieved data block has changed compared to the previously stored data block, and the trusted startup process terminates.

[0071] The method of this invention was implemented on a Xilinx FPGA 100MHz, and compared with mainstream SM3, SHA2-256 and SHA3-256 methods. The results are as follows:

[0072] This invention SM3 SHA2-256 SHA3-256 Throughput 10Gbps 3.5Gbps 3Gbps 4Gbps Resource Usage (LUT) 220 600 650 450 Resource usage (FF) 200 500 500 380

[0073] It is evident that the present invention is superior to existing algorithms in terms of both throughput and resource consumption.

[0074] The data referred to in this technical solution refers to any record of information in electronic or other ways, and in particular, the data refers to data stored in computing devices and network communication data.

Claims

1. A data storage integrity verification system based on polynomial rings, characterized in that, It includes a data encoding module, a base generation module, a standard value library, and a measurement module; the data encoding module, base generation module, and standard value library are respectively connected to the measurement module; the data involved refers to the data stored in the computing device and the network communication data; The data encoding module is used to convert the binary data to be verified into a polynomial, in preparation for the integrity verification by the measurement module. The data to be verified is information recorded electronically. The basis generation module is used to select the basis space and generate the basis using a random selection method, for the measurement module to perform measurement. The measurement module calls the base generation module and the standard value library to complete the integrity verification of the data to be verified; the standard value library is used to store the standard integrity verification values ​​of the input data to be verified. The standard value library stores standard integrity verification values ​​by entry, and the specific structure of each entry is as follows: , ; Data labels for standard integrity check values, The data length of the standard integrity check value. These are the base and standard check value selected for the standard integrity check value, respectively; This represents the number of data entries in the standard value library; all standard integrity verification values ​​in the standard value library are stored and used within the integrity verification system. The measurement module receives the element group ,examine Is it in the standard value library? 1) If If the value is not in the standard value library, the base generation module is invoked; the base generation module is located in base space A and is randomly selected. And return it to the measurement module; the measurement module uses base Perform modulo operation to generate standard verification value ,Will Stored in the benchmark library, the output data T=2 indicates that the data to be verified for integrity is newly added data, and the standard integrity verification value of this data has been generated and stored; 2) If The measurement module reads values ​​from the standard value library. The corresponding standard integrity check value; assuming it is read from the standard value library. The corresponding standard integrity check value is ;if If the output data T=0, it indicates that the input integrity verification data has been changed relative to the standard integrity verification value; if Then utilize base Perform a modulo operation to generate a new standard check value. ;if If the input integrity check value is unchanged, the output data T=1, indicating that the input integrity check value has not changed relative to the standard integrity check value; otherwise, the output data T=0, indicating that the input integrity check value has changed relative to the standard integrity check value.

2. The data storage integrity verification system based on a polynomial ring according to claim 1, characterized in that, The data encoding module converts the input integrity verification data into a polynomial ring. The elements in; let the input data to be verified be... ,in The data label for the data to be verified for integrity. The length of the data to be verified for integrity. The data content to be verified for integrity; the data encoding module will... Turn to Middle elements , forming an element group .

3. The data storage integrity verification system based on a polynomial ring according to claim 1, characterized in that, base space It has A collection of elements ,base It is the base space The elements in the array are randomly generated.

4. A method for verifying the integrity of data storage using the system described in any one of claims 1-3, characterized in that, Includes the following steps: Initialization phase: The standard value library is empty, the number of data entries is 0, and the base generation module selects base space A; Step 1: Input the data to be verified for integrity. The data encoding module converts the input data into a polynomial ring. The elements in the table are used to generate an element group, which is then sent to the measurement module. Step 2: After receiving the element group, the measurement module checks whether the data tags of the data to be verified for integrity in the element group exist in the standard value library; if they exist, proceed to step 5. Step 3: If the data tags of the data to be verified for integrity in the element group do not exist in the standard value library, then call the base generation module to generate a base; Step 4: The measurement module uses the element-wise polynomial to take the modulus of the basis, and stores the data label, data length, basis, and standard integrity check value of the data to be verified in the standard value library, incrementing the number of entries in the standard value library by 1; at the same time, the output data T=2, indicating that the input data to be verified is newly added data, and the standard integrity check value of the data has been generated and stored; Step 5: If the data tag of the data to be verified in the received element group exists in the standard value library, the measurement module reads the entry corresponding to the data tag from the standard value library using the data tag of the data to be verified as an index; Step 6: Check if the data length of the data to be verified in the element group is equal to the data length of the standard integrity verification value in the entry. If they are not equal, output data T=0, indicating that the input data to be verified has been changed relative to the standard integrity verification value. Step 7: If the data length of the data to be verified in the element group is equal to the data length of the standard integrity verification value in the entry, then use the element polynomial to take the modulus of the basis in the entry to obtain a new standard integrity verification value; compare the new standard integrity verification value with the standard verification value in the entry. If they are equal, output data T=1, indicating that the input data to be verified has not changed relative to the standard integrity verification value. Step 8: If the new standard integrity check value is not equal to the standard check value in the entry, output data T=0, indicating that the input integrity check data has been changed relative to the standard integrity check value.

Citation Information

Patent Citations

  • Data integrity verification method supporting dynamic update in cloud storage service

    CN112527808A

  • Data integrity verification method and system for distributed storage system

    CN117827527A