A method and device for verifying the integrity of multi-copy data
By generating multiple replica files in trusted containers and verifying their integrity with trusted channels, the problem of large communication and computing overhead in existing cloud audit technologies is solved, and efficient multi-replica data integrity verification is achieved.
Patent Information
- Application Number
- CN202011550172.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-24
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2040-12-24
AI Technical Summary
The existing cloud audit technology needs to introduce a third-party auditing end or generate a data block tag collection for each file, resulting in excessive communication and computing overhead between the user and the cloud server.
By generating multiple replica files in a trusted container and verifying their integrity with a trusted channel, the introduction of third-party auditors and the generation of data block tags are avoided.
It realizes multi-replica data integrity verification without third parties, reduces communication and computing overhead between the user and the cloud server side, and improves system performance.
Smart Images

Figure CN112632638B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of cloud audit technology, and specifically, relates to a multi-copy data integrity verification method and device. Background Art
[0002] Cloud storage can satisfy users' need to allocate storage resources on demand from cloud storage sharing centers, thus eliminating the cost of local data storage and maintenance. However, when storing data in cloud servers, users lose physical control over the data, and thus cannot verify the integrity of the data using traditional methods. In existing multi-copy data auditing schemes, the user needs to upload multiple different copy files to the cloud server to prevent the cloud server from declaring that a specified number of copy files are stored, but actually only one copy or less than the agreed number of copy files is stored. This increases the communication overhead between the user and the cloud server by several times, seriously reducing the performance of the multi-copy data auditing scheme. Existing cloud storage auditing schemes also need to generate corresponding data block tag sets and other auxiliary verification metadata for each file, which not only increases the computational overhead of the user, but also increases the communication overhead between the user and the cloud server. In addition, the existing multi-copy data auditing system includes not only the user and the cloud server, but also a third-party auditing end for auditing the integrity of multi-copy data. The existence of the third-party auditing end also increases the burden on the system. Summary of the invention
[0003] The present application provides a method and device for verifying the integrity of multi-copy data without a third party, so as to at least solve the problem that in current cloud auditing, a third-party audit terminal needs to be introduced or a corresponding data block labeler and other auxiliary verification data need to be generated for each file, thereby increasing the overhead of the user terminal.
[0004] According to one aspect of the present application, a method for verifying the integrity of multi-copy data without a third party is provided, comprising:
[0005] Receive files uploaded by the user and metadata corresponding to the files through a trusted channel;
[0006] Generate N copy files according to the file and the metadata corresponding to the file, N>1; wherein the trusted channel is established between the user end and the trusted container, and the trusted container is created according to the authentication request initiated by the user end; the metadata includes: a file identifier and a random timestamp set generated according to a preset number of copy files;
[0007] Generate a corresponding first hash value according to the copy file;
[0008] Transmitting the first hash value to the user terminal via the trusted channel so that the user terminal generates challenge information;
[0009] Receive the challenge information from the user and verify the data integrity of the N replica files according to the challenge information.
[0010] In one embodiment, a trusted channel is established as follows:
[0011] Create a trusted container locally based on the authentication request;
[0012] Sending a hash value of the content of the trusted container to the client so that the client can verify the hash value;
[0013] After verification, a trusted channel is established between the trusted container and the user end.
[0014] In one embodiment, the multi-copy data integrity verification method further includes:
[0015] The copy file and the first hash value are stored outside the trusted container.
[0016] In one embodiment, generating N copy files according to the file and metadata corresponding to the file includes:
[0017] Split the file uploaded by the user into several data blocks;
[0018] Generate N data block masks based on a set of random timestamps;
[0019] Each data block is matched with a different data block mask to obtain N copy files.
[0020] In one embodiment, verifying the data integrity of N replica files according to the challenge information includes:
[0021] Calculate the second hash values of the N copy files in the challenge information;
[0022] The second hash value is compared with the first hash value, and if they are equal, the verification passes.
[0023] According to another aspect of the present application, a method for verifying the integrity of multi-copy data without a third party is provided with a user terminal as the execution subject, including:
[0024] Sending the file and file metadata to the cloud server via a trusted channel so that the cloud server can generate N replica files, the file metadata including: a file identifier and a set of random timestamps generated according to a preset number of replica files;
[0025] Receiving the copy file and the first hash value of the copy file sent by the cloud server through the trusted channel;
[0026] The challenge information is generated according to the first hash value, the copy file and the file and returned to the cloud server so that the cloud server can verify the data integrity of the copy file according to the challenge information.
[0027] In one embodiment, the multi-copy data integrity verification method further includes:
[0028] Send an authentication request to the cloud server;
[0029] Receive the hash value of the trusted container returned by the cloud server;
[0030] Verify that the hash value is correct;
[0031] Once the verification is passed, a trusted channel is established with the cloud server.
[0032] In one embodiment, the multi-copy data integrity verification method further includes:
[0033] generating a file identifier for the file;
[0034] A random timestamp set is generated according to a preset number N of replica files, and the file, file identifier and timestamp set are sent to a cloud server through a trusted channel so that the cloud server can generate N replica files.
[0035] According to another aspect of the present application, a multi-copy data integrity verification device without a third party is provided with a cloud server as the execution subject, including:
[0036] A backup unit, configured to receive files uploaded by a user terminal and metadata corresponding to the files via a trusted channel and generate N copy files according to the files and metadata corresponding to the files; wherein the trusted channel is established between the user terminal and a trusted container, and the trusted container is created according to an authentication request initiated by the user terminal; the metadata includes: a file identifier and a set of random timestamps generated according to a preset number of copy files;
[0037] A first Hash value generating unit, configured to generate a corresponding first Hash value according to the copy file;
[0038] A transmission unit, configured to transmit the first hash value to a user terminal via a trusted channel so that the user terminal generates challenge information;
[0039] The integrity verification unit is used to receive challenge information from the user end and verify the integrity of multiple copies of data according to the challenge information.
[0040] In one embodiment, the backup unit includes:
[0041] A copy file generation module, used to generate N copy files for the uploaded files and metadata;
[0042] The first hash value generation module is used to generate a first hash value for each copy file and store the copy file and the first hash value outside the trusted container.
[0043] In one embodiment, the copy file generation module includes:
[0044] A segmentation module is used to segment the file uploaded by the user into several data blocks;
[0045] A mask generation module, used to generate N data block masks according to a random timestamp set;
[0046] The mask matching module is used to match different data block masks to each data block to obtain N copy files.
[0047] In one embodiment, the integrity verification unit includes:
[0048] A second hash value calculation module, used to calculate the second hash value of all the copy files in the challenge information sent by the user end;
[0049] The comparison and verification module is used to compare the second Hash value with the first Hash value, and if they are equal, the verification is passed.
[0050] Taking the user end as the execution subject, a multi-copy data integrity verification device without a third party is also provided, including:
[0051] A sending unit, configured to send the file and file metadata to a cloud server via a trusted channel so that the cloud server can generate N replica files, wherein the file metadata includes: a file identifier and a random timestamp set generated according to a preset number of replica files;
[0052] The challenge information generating unit is used to receive the first hash value of the copy file sent by the cloud server through a trusted channel and generate challenge information based on the first hash value of the copy file, the copy file and the file and return it to the cloud server for integrity verification by the cloud server.
[0053] In one embodiment, the multi-copy data integrity verification device further includes:
[0054] An environment verification unit, used to verify the hash value of the trusted container returned by the cloud server after sending an authentication request to the cloud server;
[0055] The trusted channel establishment unit is used to establish a trusted channel with the cloud server after verification.
[0056] This application uses SGX technology to ensure support for multi-copy data integrity verification, and by expanding the specified number of copies in the trusted container and saving them in the cloud server, the user side only needs to upload one file to the cloud server to ensure that the cloud server actually stores the specified number of copy files, preventing the cloud server from storing only one copy or less than the agreed number of copy files, and avoiding serious communication overhead between the user side and the cloud server side. In addition, this method does not need to generate a corresponding data block tag set for the file, thereby avoiding serious computing overhead on the user side. Compared with the prior art, this application does not need to introduce a third-party audit terminal, and does not require a large amount of computing overhead on the user side, saving computing resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0058] Figure 1 This is a flow chart of the multi-copy data integrity verification method with the cloud as the execution entity provided in this application.
[0059] Figure 2 A flow chart of a method for establishing a trusted channel with a user terminal in an embodiment of the present application.
[0060] Figure 3 This is a flow chart of a method for generating a plurality of copy files and corresponding first hash values in an embodiment of the present application.
[0061] Figure 4 This is a flowchart of generating several copy files for uploaded files and metadata in an embodiment of the present application.
[0062] Figure 5 This is a flowchart of storing a copy file and a first hash value outside a trusted container in an embodiment of the present application.
[0063] Figure 6 This is a flowchart for verifying the integrity of multiple copies of data in an embodiment of the present application.
[0064] Figure 7 This is a flow chart of the multi-copy data integrity verification method provided by this application with the user end as the execution subject.
[0065] Figure 8 This is a flow chart of the challenge information generation steps in an embodiment of the present application.
[0066] Fig. 9This is a block diagram of a multi-copy data integrity verification device with the cloud as the execution body provided in this application.
[0067] Fig.10 This is a structural block diagram of a credibility establishment unit in an embodiment of the present application.
[0068] Fig.11 This is a structural block diagram of the backup unit in an embodiment of the present application.
[0069] Fig.12 This is a structural block diagram of the copy file generation module in an embodiment of the present application.
[0070] Fig.13 This is a structural block diagram of the first hash value generation module in an embodiment of the present application.
[0071] Fig.14 This is a structural block diagram of the integrity verification unit in an embodiment of the present application.
[0072] Fig.15 This is a block diagram of a multi-copy data integrity verification device with a user end as the execution subject provided in an embodiment of the present application.
[0073] Fig.16 4 is a structural block diagram of a challenge information generating unit in an embodiment of the present application.
[0074] Fig.17 This is a specific implementation of an electronic device in an embodiment of the present application.
[0075] Fig.18 This is a modular schematic diagram of the present application.
[0076] Fig.19 Schematic diagram of the communication interaction between the user end and the cloud server end of this application. DETAILED DESCRIPTION
[0077] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. The embodiments provided in this application can be applied to the financial field, and can also be applied to other fields, and this application is not limited to this.
[0078] Based on the problems in the background technology, this application provides a method for verifying the integrity of multi-copy data without a third party. The method uses a cloud server as the execution subject, such as Figure 1 As shown, including:
[0079] S101: receiving a file uploaded by a user and metadata corresponding to the file via a trusted channel.
[0080] The client initiates a request for operating environment authentication to the cloud server. The cloud server creates a trusted container based on the authentication request. The trusted container then sends the hash value of its content to the client for verification. If the verification is successful, a trusted channel is established between the client and the cloud server. The purpose of this is to create an absolutely safe and fair audit environment before the cloud audit begins, to prevent the system from being attacked externally and affecting the fairness of the audit results.
[0081] S102: Generate N duplicate files according to the file and metadata corresponding to the file, and generate corresponding first hash values according to the duplicate files. The metadata includes: a file identifier and a set of random timestamps generated for a preset duplicate file.
[0082] The client transfers the files and metadata to the trusted container of the cloud server through a trusted channel. The cloud server pre-processes the data and then sends it to the client.
[0083] S103: Transmit the first hash value to the user terminal via the trusted channel so that the user terminal generates challenge information.
[0084] After the data pre-processed by the cloud server is sent to the user end, the user end uses this data to generate challenge information and returns it to the cloud server for cloud auditing.
[0085] S104: Receive challenge information from the user and verify the data integrity of the N copy files according to the challenge information.
[0086] After receiving the challenge information sent by the client, the cloud server uses the challenge information to verify the integrity of the multiple copies of the file.
[0087] In one embodiment, a local trusted container is created according to an authentication request initiated by a user terminal and a trusted channel is established with the user terminal, such as Figure 2 As shown, including:
[0088] S201: Creating a trusted container locally according to the authentication request.
[0089] S202: Send the hash value of the content of the trusted container to the user terminal so that the user terminal verifies the hash value.
[0090] S203: After the verification is successful, a trusted channel is established between the trusted container and the user end.
[0091] In a specific embodiment, before the cloud audit begins, the system is pre-set, and cryptographic parameters and variables are set based on the system. Let the system security parameter be l, and the large prime number p satisfy |p|=l; h(·) is the cryptographic hash function; H(·) is the secure hash function, which are defined as H 1 (·):{0,1} * →Z * p .
[0092] like Fig.19 As shown in the figure, the server on the cloud service side deploys the SGX (Software Guard Extension) environment. The user side initiates the operating environment authentication to the cloud server. The cloud server creates a trusted container (enclave) based on the authentication request. After the trusted container is created, the container will send the hash value of its content to the user side. If the hash value is inconsistent with the expected value, the user side will refuse to establish communication with the container; otherwise, the cloud server will establish a trusted channel with the user side.
[0093] In one embodiment, the files and metadata uploaded by the user are received via the trusted channel and the trusted container, and a plurality of copy files and corresponding first hash values are generated according to the files and metadata uploaded by the user, such as Figure 3 As shown, including:
[0094] S301: Generate several copy files for the uploaded files and metadata.
[0095] S302: Generate a first hash value for each copy file and store the copy file and the first hash value outside the trusted container.
[0096] In a specific embodiment, the user terminal transmits the file and metadata to the trusted container through the trusted channel, and the cloud server receives the file and related metadata uploaded by the user terminal. After receiving the user terminal data, the cloud server generates multiple copy files for the file data and related metadata, and generates a hash value for each copy file. Then, all the copy files and the corresponding hash values are stored outside the trusted container. At the same time, the hash values of all the copy files are also transmitted to the user terminal through the trusted channel.
[0097] In one embodiment, several copy files are generated for the uploaded files and metadata, such as Figure 4 As shown, including:
[0098] S401: Divide the file uploaded by the user into several data blocks.
[0099] S402: Generate N data block masks according to the random timestamp set.
[0100] S403: Match different data block masks to each data block to obtain a number of copy files.
[0101] In a specific embodiment, the user terminal generates a file identifier Fid for the file F and generates a random timestamp set T = {t j |j=1,2,…,λ}. The file F, the file identifier Fid and the timestamp set T are transmitted to the trusted container of the cloud server through the trusted channel. In the trusted container of the cloud server, the file F is divided into n data blocks. Add different data block masks to each data block to obtain λ replica file sets Γ={F 1 ,F 2 ,…,F λ}, where F j = {b j,1 ,b j,2 ,…,b j,n}(j=1,2,...,n), The calculation process is:
[0102] b j,i =m i +H(j||i||t j )
[0103] where H(j||i||t j ) is the data block mask, j||i||t j It means to put value j, value i and timestamp t j Put it together.
[0104] In one embodiment, a first hash value is generated for each replica file and the replica file and the first hash value are stored outside the trusted container, such as Figure 5 As shown, including:
[0105] S501: Calculate hash values for all duplicate files to generate a first hash value set.
[0106] S502: Store the set of duplicate files and the set of first hash values outside the trusted container.
[0107] In a specific embodiment, a hash value set Θ={h(F j )|j=1,2,...,λ}. Finally, the hash value set Θ is transmitted to the client through the trusted channel for storage, and the replica file set Γ and the corresponding hash value set Θ are sent to storage outside the trusted container.
[0108] In one embodiment, a challenge message from a user is received and the integrity of multiple copies of data is verified, such as Figure 6 As shown, including:
[0109] S601: Calculate the second hash values of the N copy files in the challenge information.
[0110] S602: Compare the second hash value with the first hash value, and if they are equal, verification is successful.
[0111] In a specific embodiment, the user terminal challenges the cloud server and sends the file identifier Fid and the hash value set Θ to the trusted container of the cloud server through the previously established secure channel. 1 ,F 2 ,…,F λ} to the trusted container. First, the hash value set Θ is calculated for all the copy files in the trusted container. * ={h * (F j )|j=1,2,...,λ}, and then verify that each pair of h(F j ) and h * (F j )(j=1,2,...,λ) are equal (refer to Merkle R C.One way hash functions and DES[C] / / Proceedings on Advances in cryptology.1989:428-446.). If a pair of verifications are equal, the corresponding copy file is complete; otherwise, the file is damaged. Finally, the verification result is sent to the user end through a secure channel.
[0112] According to another aspect of the present application, a method for verifying the integrity of multi-copy data without a third party is also provided, with the user end as the execution subject. Figure 7 As shown, including:
[0113] S701: Send the file and file metadata to the cloud server via a trusted channel so that the cloud server can generate N copy files.
[0114] S702: Receive the copy file and the first hash value of the copy file sent by the cloud server through the trusted channel.
[0115] S703: Generate challenge information according to the first hash value, the copy file and the file, and return it to the cloud server so that the cloud server can verify the data integrity of the copy file according to the challenge information.
[0116] The steps of establishing a trusted channel between the user terminal and the cloud server include:
[0117] S1: Send an authentication request to the cloud server.
[0118] S2: Receive the hash value of the trusted container returned by the cloud server.
[0119] S3: Verify whether the hash value is correct.
[0120] S4: After verification, a trusted channel is established with the cloud server.
[0121] In one embodiment, the hash value of the duplicate file, the duplicate file, and the file generation challenge information are returned to the cloud server for integrity verification by the cloud server, such as Figure 8 As shown, including:
[0122] S801: Generate a file identifier for a file.
[0123] S802: Generate a random timestamp set according to a preset number N of copy files, and send the file, file identifier and timestamp set to the cloud server through a trusted channel so that the cloud server can generate N copy files.
[0124] Fig.18 A modular schematic diagram of a system corresponding to the method provided in this application.
[0125] Based on the same inventive concept, the embodiments of the present application also provide a multi-copy data integrity verification device without a third party, which can be used to implement the method described in the above embodiments, as described in the following embodiments. Since the principle of solving the problem by the multi-copy data integrity verification device without a third party is similar to that of the multi-copy data integrity verification method without a third party, the implementation of the multi-copy data integrity verification device without a third party can refer to the implementation of the multi-copy data integrity verification method without a third party, and the repeated parts will not be repeated. As used below, the term "unit" or "module" can be a combination of software and / or hardware that implements predetermined functions. Although the system described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceived.
[0126] like Fig. 9 As shown, with the cloud server as the execution subject, the present application provides a multi-copy data integrity verification device without a third party, including:
[0127] A credibility establishing unit 901 is used to create a local trusted container and establish a trusted channel with the user terminal according to an authentication request initiated by the user terminal;
[0128] The backup unit 902 is used to receive files and metadata uploaded by the user terminal via a trusted channel and a trusted container and generate a plurality of copy files and corresponding first hash values according to the files and metadata uploaded by the user terminal; the metadata includes: a file identifier and a random timestamp set generated for a preset copy file;
[0129] A transmission unit 903, configured to transmit the first hash value to the user terminal via a trusted channel so that the user terminal generates challenge information;
[0130] The integrity verification unit 904 is used to receive the challenge information from the user end and verify the integrity of the multiple copies of data.
[0131] In one embodiment, if Fig.10 As shown, the credibility establishment unit 901 includes:
[0132] A trusted container creation module 1001, used to create a trusted container locally according to an authentication request;
[0133] A trusted container verification module 1002, configured to send a hash value of the content of the trusted container to a user terminal so that the user terminal verifies the hash value;
[0134] The trusted channel establishing module 1003 is used to establish a trusted channel between the trusted container and the user end after verification.
[0135] In one embodiment, if Fig.11 As shown, the backup unit 902 includes:
[0136] A copy file generation module 1101 is used to generate a number of copy files for the uploaded files and metadata;
[0137] The first hash value generating module 1102 is configured to generate a first hash value for each copy file and store the copy file and the first hash value outside the trusted container.
[0138] In one embodiment, if Fig.12 As shown, the copy file generation module 1101 includes:
[0139] The segmentation module 1201 is used to segment the file uploaded by the user into several data blocks;
[0140] The mask matching module 1202 is used to match different data block masks to each data block to obtain a plurality of copy files.
[0141] In one embodiment, if Fig.13 As shown, the first hash value generating module 1102 includes:
[0142] The first hash value calculation module 1301 is used to calculate hash values for all duplicate files to generate a first hash value set;
[0143] The storage module 1302 is used to store the set of duplicate files and the set of first hash values outside the trusted container.
[0144] In one embodiment, if Fig.14As shown, the integrity verification unit 904 includes:
[0145] The second hash value calculation module 1401 is used to calculate the second hash value for all the copy files sent by the user end;
[0146] The comparison and verification module 1402 is used to compare the second Hash value with the first Hash value, and if they are equal, the verification is passed.
[0147] Taking the user end as the execution subject, a multi-copy data integrity verification device without a third party is also provided, such as Fig.15 As shown, including:
[0148] The environment verification unit 1501 is used to send the hash value of the trusted container returned by the cloud server after the operation environment authentication is verified to the cloud server;
[0149] A trusted channel establishing unit 1502 is used to establish a trusted channel with the cloud server after verification;
[0150] The challenge information generating unit 1503 is used to receive the hash value of the duplicate file sent by the cloud server through the trusted channel and generate challenge information based on the hash value of the duplicate file, the duplicate file and the file and return it to the cloud server for integrity verification by the cloud server.
[0151] In one embodiment, if Fig.16 As shown, the challenge information generating unit 1503 includes:
[0152] A file identifier generating module 1601, used to generate a file identifier for a file;
[0153] The random timestamp generation module 1602 is used to generate a random timestamp set for a plurality of preset copy files, and send the files, file identifiers and timestamp sets to the cloud server through a trusted channel for integrity verification by the cloud server.
[0154] The present application provides a method and device for verifying the integrity of multiple copies of data. While ensuring support for the integrity verification of multiple copies of data, the user side only needs to upload one file to the cloud server to ensure that the cloud server actually stores a specified number of copies of the file, thereby preventing the cloud server from storing only one copy of the file or less than the agreed number of copies. This avoids the serious communication overhead between the user side and the cloud server side. In addition, the method does not need to generate a corresponding set of data block tags for the file, thereby avoiding serious computational overhead on the user side.
[0155] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0156] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0157] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0158] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0159] The present invention uses specific embodiments to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
[0160] The embodiments of the present application also provide a specific implementation of an electronic device that can implement all the steps in the method in the above embodiments, see Fig.17 , the electronic device specifically includes the following contents:
[0161] Processor 1701, memory 1702, communication interface 1703, bus 1704 and non-volatile memory 1705;
[0162] The processor 1701, memory 1702, and communication interface 1703 communicate with each other via the bus 1704;
[0163] The processor 1701 is used to call the computer program in the memory 1702 and the non-volatile memory 1705. When the processor executes the computer program, all the steps in the method in the above embodiment are implemented. For example, when the processor executes the computer program, the following steps are implemented:
[0164] S101: Create a local trusted container according to the authentication request initiated by the user terminal and establish a trusted channel with the user terminal.
[0165] S102: Accepting files and metadata uploaded by the user via a trusted channel and a trusted container, and generating a plurality of copy files and corresponding first hash values according to the files and metadata uploaded by the user.
[0166] S103: Transmit the first hash value to the user terminal via the trusted channel so that the user terminal generates challenge information.
[0167] S104: Receive challenge information from the user and verify the integrity of the multiple copies of data.
[0168] The embodiments of the present application also provide a computer-readable storage medium capable of implementing all the steps of the method in the above embodiments. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, all the steps of the method in the above embodiments are implemented. For example, when the processor executes the computer program, the following steps are implemented:
[0169] S101: Create a local trusted container according to the authentication request initiated by the user terminal and establish a trusted channel with the user terminal.
[0170] S102: Accepting files and metadata uploaded by the user via a trusted channel and a trusted container, and generating a plurality of copy files and corresponding first hash values according to the files and metadata uploaded by the user.
[0171] S103: Transmit the first hash value to the user terminal via the trusted channel so that the user terminal generates challenge information.
[0172] S104: Receive challenge information from the user and verify the integrity of the multiple copies of data.
[0173] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the hardware + program embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. Although the embodiment of this specification provides the method operation steps described in the embodiment or flow chart, more or less operation steps can be included based on conventional or non-creative means. The order of steps listed in the embodiment is only one way of executing the order of many steps, and does not represent the only execution order. When the device or terminal product in practice is executed, it can be executed in sequence or in parallel according to the method shown in the embodiment or the accompanying drawings (for example, a parallel processor or a multi-threaded processing environment, or even a distributed data processing environment). The term "include", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, product or device including a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such a process, method, product or device. In the absence of more restrictions, it is not excluded that there are other identical or equivalent elements in the process, method, product or device including the elements. For the convenience of description, the above device is described by dividing it into various modules according to its functions. Of course, when implementing the embodiments of this specification, the functions of each module can be implemented in the same one or more software and / or hardware, or the module implementing the same function can be implemented by a combination of multiple sub-modules or sub-units. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms. The present invention is described with reference to the flowchart and / or block diagram of the method, device (system) and computer program product according to the embodiments of the present invention. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the process and / or box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the process Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0174] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, the embodiments of this specification may be in the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, the embodiments of this specification may be in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes. Each embodiment in this specification is described in a progressive manner, and the same and similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts refer to the partial description of the method embodiment. In the description of this specification, the description of the reference term "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the embodiment of this specification.
[0175] In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradicting each other. The above is only an embodiment of the embodiment of this specification and is not intended to limit the embodiment of this specification. For those skilled in the art, the embodiment of this specification may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiment of this specification shall be included in the scope of the claims of the embodiment of this specification.
Claims
1. A method for verifying the integrity of multi-copy data, characterized in that: include: Receive files uploaded by the user and metadata corresponding to the files through a trusted channel; Generate λ copy files according to the file and metadata corresponding to the file, λ>1; wherein the trusted channel is established between the user end and the trusted container, and the trusted container is created according to the authentication request initiated by the user end; the metadata includes: a file identifier and a random timestamp set generated according to a preset number of copy files; Generate a corresponding first Hash value set according to the copy file, wherein the first Hash value set Θ={h(F j )|j=1,2,...,λ}, where F j is the jth copy file, λ is a natural number; Transmitting the first hash value to the user terminal via the trusted channel so that the user terminal generates challenge information; the challenge information includes a file identifier Fid and a first hash value set Θ; Receive the challenge information of the user end through the trusted channel, and load the copy file set Γ={F1,F2,...,F λ } to the trusted container, and first calculate the hash value set Θ for all the copy files in the trusted container * ={h * (F j )|j=1,2,...,λ}, and then verify that each pair of h(F j ) and h * (F j ) are equal.
2. The method for verifying the integrity of multi-copy data according to claim 1, characterized in that: The trusted channel is established in the following way: Creating a trusted container locally according to the authentication request; Sending a hash value of the content of the trusted container to the client so that the client can verify the hash value; After the verification is passed, a trusted channel is established between the trusted container and the user terminal.
3. The method for verifying the integrity of multi-copy data according to claim 1, characterized in that: The method further comprises: The copy file and the first hash value are stored outside the trusted container.
4. The method for verifying the integrity of multi-copy data according to claim 3, characterized in that: Generating λ copy files according to the file and metadata corresponding to the file includes: Split the file uploaded by the user into several data blocks; Generate λ data block masks according to the random timestamp set; Each data block is matched with a different data block mask to obtain λ copy files.
5. A method for verifying the integrity of multi-copy data, characterized in that: include: Send the file and the file metadata to the cloud server via a trusted channel so that the cloud server generates λ replica files, λ>1, and the trusted channel is established between the user terminal and the trusted container of the cloud server; The file metadata includes: a file identifier and a random timestamp set generated according to a preset number of copy files; The copy file and the first hash value set of the copy file sent by the cloud server are received through the trusted channel, wherein the first hash value set Θ={h(F j )|j=1,2,...,λ}, where F j is the jth copy file, λ is a natural number; The cloud server is challenged, and the file identifier Fid and the first hash value set Θ are sent to the trusted container of the cloud server through the trusted channel; so that the cloud server can load the copy file set Γ={F1, F2, ..., F λ } to the trusted container, and first calculate the hash value set Θ for all the copy files in the trusted container * ={h * (F j )|j=1,2,...,λ}, and then verify that each pair of h(F j ) and h * (F j ) are equal.
6. The method for verifying the integrity of multi-copy data according to claim 5, characterized in that: Also includes: Send an authentication request to the cloud server; Receive the hash value of the trusted container returned by the cloud server; Verify whether the hash value is correct; Once the verification is passed, a trusted channel is established with the cloud server.
7. The method for verifying the integrity of multi-copy data according to claim 5, characterized in that: Also includes: generating a file identifier for the file; A random timestamp set is generated according to a preset number λ of replica files, and the file, the file identifier and the timestamp set are sent to a cloud server through a trusted channel so that the cloud server generates λ replica files.
8. A multi-copy data integrity verification device, characterized in that: include: A backup unit, configured to receive a file uploaded by a user terminal and metadata corresponding to the file via a trusted channel and generate λ copy files according to the file and metadata corresponding to the file; wherein the trusted channel is established between the user terminal and a trusted container, and the trusted container is created according to an authentication request initiated by the user terminal; the metadata includes: a file identifier and a set of random timestamps generated according to a preset number of copy files; The first Hash value generating unit is used to generate a corresponding first Hash value set according to the copy file, wherein the first Hash value set Θ={h(F j )|j=1,2,...,λ}, where F j is the jth copy file, λ is a natural number; A transmission unit, configured to transmit the first hash value to a user terminal via the trusted channel so that the user terminal generates challenge information, wherein the challenge information includes a file identifier Fid and a first hash value set Θ; The integrity verification unit is used to receive the challenge information of the user terminal through the trusted channel, and load the copy file set Γ={F1, F2, ..., F λ } to the trusted container, and first calculate the hash value set Θ for all the copy files in the trusted container * ={h * (F j )|j=1,2,...,λ}, and then verify that each pair of h(F j ) and h * (F j ) are equal.
9. The multi-copy data integrity verification device according to claim 8, characterized in that: The backup unit comprises: A copy file generation module, used to generate λ copy files for the uploaded files and metadata; The first hash value generating module is used to generate a first hash value for each copy file and store the copy file and the first hash value outside the trusted container.
10. The multi-copy data integrity verification device according to claim 9, characterized in that: The copy file generation module includes: A segmentation module is used to segment the file uploaded by the user into several data blocks; A mask generation module, used to generate λ data block masks according to the random timestamp set; The mask matching module is used to match different data block masks to each data block to obtain λ copy files.
11. A multi-copy data integrity verification device, characterized in that: include: A sending unit, used for sending the file and the file metadata to the cloud server via a trusted channel so that the cloud server generates λ copy files, λ>1, and the trusted channel is established between the user terminal and the trusted container of the cloud server; The file metadata includes: a file identifier and a random timestamp set generated according to a preset number of copy files; A challenge information generating unit is used to receive the copy file and the first hash value set of the copy file sent by the cloud server through the trusted channel, wherein the first hash value set θ={h(F j )|j=1,2,...,λ}, where F j is the jth copy file, λ is a natural number; The cloud server is challenged, and the file identifier Fid and the first hash value set Θ are sent to the trusted container of the cloud server through the trusted channel; so that the cloud server can load the copy file set Γ={F1, F2, ..., F λ } to the trusted container, and first calculate the hash value set Θ for all the copy files in the trusted container * ={h * (F j )|j=1,2,...,λ}, and then verify that each pair of h(F j ) and h * (F j ) are equal.
12. The multi-copy data integrity verification device according to claim 11, characterized in that: Also includes: An environment verification unit, used to verify the hash value of the trusted container returned by the cloud server after sending an authentication request to the cloud server; The trusted channel establishment unit is used to establish a trusted channel with the cloud server after verification.
13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the multi-copy data integrity verification method described in any one of claims 1 to 4 and 5 to 7 is implemented.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the multi-copy data integrity verification method described in any one of claims 1 to 4 and 5 to 7 is implemented.
Citation Information
Patent Citations
Cloud storage method, cloud storage system and safety cloud storage system
CN106161465A
SGX-based cloud data integrity auditing method and apparatus
CN111859467A