Log management method, auxiliary investigation and evidence collection method and device

By adopting blockchain technology and a hybrid consensus mechanism in data security management, the problems of log data integrity and management decentralization are solved, and efficient, secure and traceable storage of log data is achieved.

CN113934693BActive Publication Date: 2025-05-16ALIBABA GROUP HOLDING LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010602565.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-06-29
Publication Date
2025-05-16
Estimated Expiration
2040-06-29

AI Technical Summary

Technical Problem

Existing data security management solutions cannot guarantee the integrity of log data, resulting in the inability to 100% traceability data security issues.

Method used

A hybrid consensus mechanism of blockchain technology combined with a entrusted proof of stake (DPOS) and proof of work (POW) is adopted to conduct transparent supervision to ensure the decentralization of distributed storage and management of logs.

Benefits of technology

Through the distributed storage of blockchain technology and transparent supervision of hybrid consensus mechanisms, the integrity and immutability of log data can be ensured, making it possible to trace data security issues 100%.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113934693B_ABST
    Figure CN113934693B_ABST
Patent Text Reader

Abstract

A log management method, an auxiliary investigation and evidence collection method and device are disclosed. Log acquisition step: acquiring log information generated within a first time range; node determination step: determining a recording node for recording blocks and a verification node for verifying blocks based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW); block generation step: generating a new block based on log information by the recording node, the data content of the new block includes log information, a hash value of the new block and a hash value of the previous block, wherein the hash value of the new block is obtained by hashing the log information and the hash value of the previous block using a hash algorithm; verification step: verifying the validity of the new block by the verification node; storage step: if the verification result is that the new block is valid, the data content of the new block is stored by the verification node. Thus, while ensuring data storage efficiency, decentralized management can be taken into account.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of information technology, and in particular to a log management method, an auxiliary investigation and evidence collection method and device. Background Art

[0002] With the advent of the digital age, data security issues have become increasingly prominent.

[0003] Existing data security management solutions all locate people based on account dimensions, and the design ideas are all to supervise downward in a centralized manner. The disadvantage of this solution is that the administrator with the highest authority can delete the logs of his own violations.

[0004] For example, currently the supervision of data management permissions can only be reflected in the logs. However, in many cases, one account is used for multiple purposes, that is, a high-authorized account can be used by multiple employees. Employees can use the account's permissions to perform operations such as query, download, and log deletion on sensitive data, making it impossible for the logs to record complete behavioral information, and thus it is impossible to perform 100% traceability based on the logs to discover possible data security issues.

[0005] Therefore, a log management solution is needed that can ensure the integrity of log data. Summary of the invention

[0006] A technical problem to be solved by the present disclosure is to provide a log management solution that can ensure the integrity of log data.

[0007] According to a first aspect of the present disclosure, a log management method is provided, comprising: a log acquisition step: acquiring log information generated within a first time period; a node determination step: determining a recording node for recording blocks and a verification node for verifying blocks based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW); a block generation step: generating a new block based on the log information by the recording node, wherein the data content of the new block includes the log information, a hash value of the new block and a hash value of the previous block, wherein the hash value of the new block is obtained by performing a hash calculation on the log information and the hash value of the previous block using a hash algorithm; a verification step: verifying the validity of the new block based on the hash value of the previous block in the data content of the new block by the verification node; and a storage step: if the verification result is that the new block is valid, the data content of the new block is stored by the verification node.

[0008] According to the second aspect of the present disclosure, there is also provided an auxiliary investigation and evidence collection method, including: a behavior information acquisition step: obtaining the behavior information of the case handlers conducting investigation and evidence collection within a first time period; a node determination step: determining the recording node used to record the block and the verification node used to verify the block based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW); a block generation step: the recording node generates a new block in the case chain based on the behavior information, and the data content of the new block includes the behavior information, the hash value of the new block and the hash value of the previous block, wherein the hash value of the new block is obtained by hashing the behavior information and the hash value of the previous block using a hash algorithm; a verification step: the verification node verifies the validity of the new block; a storage step: if the verification result is that the new block is valid, the verification node stores the data content of the new block.

[0009] According to the third aspect of the present disclosure, a log management method is also provided, including: recording user behavior information; uploading the behavior information to a log management system, and the log management system adding the behavior information to a blockchain.

[0010] According to a fourth aspect of the present disclosure, a log management system is provided, comprising: a scheduling node and multiple computing nodes, the scheduling node determining a recording node for recording blocks and a verification node for verifying blocks among the multiple computing nodes based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW), the scheduling node acquiring log information generated within a first time range, and sending the log information to the recording node, the recording node generating a new block based on the log information, and sending the new block to the verification node, the data content of the new block comprising the log information, a hash value of the new block, and a hash value of a previous block, wherein the hash value of the new block is obtained by performing a hash calculation on the log information and the hash value of the previous block using a hash algorithm, the verification node verifies the validity of the new block, and if the verification result is that the new block is valid, stores the data content of the new block.

[0011] According to the fifth aspect of the present disclosure, a log management device is also provided, including: a log acquisition module, used to acquire log information generated within a first time period; a node determination module, used to determine a recording node for recording a block and a verification node for verifying a block based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW); a block generation module, used to instruct the recording node to generate a new block based on the log information, the data content of the new block including the log information, a hash value of the new block and a hash value of the previous block, wherein the hash value of the new block is obtained by performing a hash calculation on the log information and the hash value of the previous block using a hash algorithm; a verification module, used to instruct the verification node to verify the validity of the new block based on the hash value of the previous block in the data content of the new block; and a storage module, used to instruct the verification node to store the data content of the new block if the verification result is that the new block is valid.

[0012] According to the sixth aspect of the present disclosure, an auxiliary investigation and evidence collection device is also provided, including: a behavior information acquisition module, used to obtain the behavior information of the case handlers conducting investigation and evidence collection within a first time period; a node determination module, used to determine the recording node for recording the block and the verification node for verifying the block based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW); a block generation module, used to instruct the recording node to generate a new block in the case chain based on the behavior information, the data content of the new block including the behavior information, the hash value of the new block and the hash value of the previous block, wherein the hash value of the new block is obtained by hashing the behavior information and the hash value of the previous block using a hash algorithm; a verification module, used to instruct the verification node to verify the validity of the new block; and a storage module, used to instruct the verification node to store the data content of the new block if the verification result is that the new block is valid.

[0013] According to the seventh aspect of the present disclosure, a log management device is also provided, including: a recording module for recording user behavior information; an uploading module for uploading the behavior information to a log management system, and the log management system adds the behavior information to the blockchain.

[0014] According to an eighth aspect of the present disclosure, a computing device is provided, comprising: a processor; and a memory on which executable code is stored, and when the executable code is executed by the processor, the processor executes the method described in any one of the first to third aspects above.

[0015] According to a ninth aspect of the present disclosure, a non-temporary machine-readable storage medium is provided, on which executable code is stored. When the executable code is executed by a processor of an electronic device, the processor executes the method described in any one of the first to third aspects above.

[0016] Therefore, in the process of distributed storage of logs with the help of blockchain technology, the present invention performs transparent supervision through a hybrid consensus mechanism based on delegated proof of stake (DPOS) and proof of work (POW), which can ensure data storage efficiency while taking into account decentralized management. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The above and other objects, features and advantages of the present disclosure will become more apparent through a more detailed description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, wherein like reference numerals generally represent like components in the exemplary embodiments of the present disclosure.

[0018] Figure 1 A schematic flow chart of a log management method according to an embodiment of the present disclosure is shown.

[0019] Figure 2 A schematic flow chart of a log management method according to another embodiment of the present disclosure is shown.

[0020] Figure 3 A schematic structural diagram of a log management device according to an embodiment of the present disclosure is shown.

[0021] Figure 4 A schematic structural diagram of an auxiliary investigation and evidence collection device according to an embodiment of the present disclosure is shown.

[0022] Figure 5 A schematic structural diagram of a log management device according to another embodiment of the present disclosure is shown.

[0023] Figure 6 A schematic diagram of the structure of a computing device that can be used to implement the above-mentioned log management method or assist in investigation and evidence collection according to an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0024] The preferred embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the preferred embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.

[0025] The present disclosure utilizes blockchain technology (such as private chains in blockchain technology) to distribute and store logs to ensure the integrity of the logs, so that 100% traceability can be performed based on the distributed stored logs to discover possible data security issues.

[0026] Since logs record real-time behavior data, logs are updated frequently, which means new log data is continuously generated. Therefore, it is necessary to continuously add new log data to new blocks for chaining, which requires high data storage efficiency in the process of distributed storage of logs. In order to ensure that logs are not tampered with, decentralized management is also required.

[0027] To this end, the present disclosure further proposes that, in the process of distributed storage of logs with the help of blockchain technology, a hybrid consensus mechanism based on delegated proof of stake (DPOS) and proof of work (POW) is used for transparent supervision, so as to ensure data storage efficiency while taking into account decentralized management.

[0028] The details involved in the present disclosure are further described below.

[0029] Figure 1 A schematic flow chart of a log management method according to an embodiment of the present disclosure is shown. Figure 1 The method shown can be implemented in software by a computer program, or can be executed by a specially configured computing device or log management system. Figure 1 The method shown.

[0030] like Figure 1 As shown, the log management method mainly includes a log acquisition step, a block generation step, a node determination step, a verification step, and a storage step. The log acquisition step can be performed first and then the block generation step, or the block generation step can be performed first and then the log acquisition step, or the log acquisition step and the node determination step can be performed simultaneously without any particular order.

[0031] 1. Log acquisition steps

[0032] Obtain the log information generated within the first time range. The first time range can be set according to actual conditions, such as 60 minutes.

[0033] Log information may refer to the recorded information of the behavior events and / or message events occurring within the first time range. As an example, the behavior events and / or message events occurring may be recorded in a log file, and log information may refer to the information recorded in the log file. For example, a log file may be a record file or a set of files for recording system operation events, and has important functions such as processing historical data, tracing of diagnostic problems, and understanding system activities.

[0034] Taking data security scenarios as an example, log information can refer to information about access, modification, deletion, and other behaviors performed on data, that is, behavioral information related to data. Data can refer to relatively important sensitive data. Therefore, log information can specifically refer to behavioral information related to sensitive data. For example, log information can be, but is not limited to, antivirus software security logs, computer system logs, database access logs, and so on. Depending on the specific application scenario, the specific content of the log information is also different.

[0035] For example, the log security management method disclosed in the present invention can be used for the security management of contract data within an enterprise. In this case, the log information may refer to the record information of various behavioral events that occur in the formulation of contracts within the enterprise, such as but not limited to contract modification record information and supplementary agreement information.

[0036] For another example, the log security management method disclosed in the present invention can also be used for the security management of internal operational data of an enterprise, and the present invention can also generate one or more operational accounts with operational permissions for sensitive data. Users (such as internal employees) can operate (such as query) sensitive data through operational accounts. Among them, different operational accounts may have different operational permissions for sensitive data. Optionally, there may be a management and managed relationship between different operational accounts. Thus, the behavior information related to sensitive data generated by the operational account within the first time range can be obtained, and the behavior information is the above-mentioned log information.

[0037] 2. Node determination steps

[0038] The recording nodes used to record blocks and the verification nodes used to verify blocks can be determined based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW), taking into account both data storage efficiency and management decentralization.

[0039] Delegated Proof of Stake (DPOS), also known as the authorized equity proof mechanism, is similar to board voting, in which all nodes vote to elect a certain number of representative nodes to participate in the recording and verification of blocks on behalf of all nodes. The advantage of the delegated proof of stake mechanism is that it can reduce the number of nodes involved in verification and accounting, and the consensus cycle is short. The disadvantage is that the degree of decentralization is low, and security issues may arise due to node clustering.

[0040] Proof of Work (POW) means, in simple terms, the more you work, the more you get. Whoever can solve the problem the fastest can be the bookkeeper. The Proof of Work mechanism has the advantage of being completely decentralized, but its disadvantage is that it consumes a lot of algorithms and takes a long time to reach consensus.

[0041] The hybrid consensus mechanism of DPOS+POW can provide all DPOS supporters (i.e. nodes that support the DPOS mechanism) and POW supporters (i.e. nodes that support the POW mechanism) with equal opportunities to win the right to record new blocks. Nodes that support the POW mechanism can increase their chances of winning the right to record new blocks by increasing their workload, and nodes that support DPOS can win the chance of winning the right to record new blocks by being elected by more nodes.

[0042] By applying the hybrid consensus mechanism of DPOS+POW to the distributed storage of logs, we can ensure the efficiency of log storage while taking into account the decentralization of log management, thus solving the problem that storage efficiency and log management security cannot be taken into account at the same time.

[0043] As an example, based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW), one node can be selected from nodes supporting the delegated proof of stake mechanism and nodes supporting the proof of work mechanism as a recording node, and the remaining nodes can be selected as verification nodes.

[0044] More specifically, a first node can be determined based on delegated proof of stake (DPOS), multiple second nodes can be determined based on the proof of work (POW) mechanism, and a node can be selected from the first node and multiple second nodes as a recording node based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW), and the remaining nodes can be used as verification nodes.

[0045] The first node can be fixed for a long time (unless the first node is removed by other nodes and a new first node is re-elected). The second node can be periodically changed, such as generating a new set of second nodes based on the POW mechanism every predetermined period (such as 60 minutes). The number of second nodes can be set according to actual conditions, and generally should not be set too large, which will increase the storage cost of new blocks and reduce data storage efficiency. For example, the number of second nodes can be set to no more than 9.

[0046] In the present disclosure, a node has data processing and storage functions. A node can be an independent physical machine or a virtual node located in a physical machine. For example, a node can refer to a computing node in a distributed system.

[0047] The recording node has the right to record the new block. The right to record the new block refers to which node acts as the recording node to be responsible for the generation of the new block before the new block is generated. The generated new block can be broadcast to other verification nodes for verification. If the verification passes, the verification node can also record the content of the new block, thereby realizing the distributed storage of blocks.

[0048] 3. Block generation steps

[0049] The recording node generates a new block based on the log information. The data content of the new block includes the log information, the hash value of the new block, and the hash value of the previous block. The hash value of the new block is obtained by hashing the log information and the hash value of the previous block using a hash algorithm. The hash algorithm can be, but is not limited to, the SHA-256 encryption algorithm.

[0050] As an example, the hash value of the new block and / or the hash value of the previous block in the data content of the new block may be signature information encrypted by the recording node using a private key.

[0051] 4. Verification steps

[0052] After generating a new block, the recording node can broadcast the new block to other verification nodes. The verification node verifies the validity of the new block. The verification node can verify the validity of the new block based on the hash value of the previous block in the data content of the new block. For example, the verification node can use a hash algorithm to perform a hash calculation on the log information and the hash value of the previous block, and compare the calculated hash value with the hash value of the new block. If they are consistent, the new block is determined to be valid, otherwise the new block is determined to be invalid.

[0053] As an example, the hash value of the new block and the hash value of the previous block in the data content of the new block can be the signature information encrypted by the recording node using the private key. The verification node can first use the public key to decrypt the signature information to obtain the hash value of the new block and the hash value of the previous block, and then use the hash algorithm to perform hash calculation on the hash value of the previous block and the log information of the new block, and compare the calculated hash value with the hash value of the new block. If they are consistent, the new block is determined to be valid, otherwise the new block is determined to be invalid.

[0054] 5. Storage steps

[0055] If the verification result is that the new block is valid, the verification node can store the data content of the new block. For example, the data content of the new block can be stored in the memory of the verification node.

[0056] Therefore, after the above steps, the log information generated within a certain period of time can be uploaded to the chain as a block, which increases the difficulty of tampering with the log information, ensures the integrity of the log, and makes it 100% traceable based on the log.

[0057] like Figure 1As shown, when a time period t (such as the first time period) has passed and more than a certain proportion of data has been stored, the above-mentioned log acquisition step, node determination step, block generation step, verification step and storage step can be returned to perform to store the log information generated in the second time range after the time period corresponding to the first time range. The second time range refers to a time period after the time period corresponding to the first time range on the time axis, and the time period can be a time period greater than or equal to the first time range. More than a certain proportion of data being stored can mean that more than a certain proportion of verification nodes have stored new blocks, and a certain proportion can refer to more than half, such as 51%.

[0058] Similarly, by continuously iterating the above-mentioned log acquisition step, node determination step, block generation step, verification step, and storage step, newly added log information can be continuously uploaded to the chain.

[0059] The present disclosure can also set access rights for blocks, and the access rights are used to represent the read rights of the data content of the block. For example, when a user wants to retrieve the data content of a block in the blockchain, he can successfully access the block only if he has the access rights corresponding to the block. Different blocks can correspond to different access rights. By setting corresponding access rights for blocks, hierarchical and classified management of blocks can be achieved.

[0060] The present disclosure can also obtain access information of the block and add the access information to the blockchain. Access information can refer to the user's behavior information such as query, investigation and evidence collection for the block data that has been uploaded to the chain. Adding access information to the blockchain means that the access information is regarded as a "log" that needs to be protected and uploaded to the chain. Among them, the blockchain where the access information is located and the blockchain where the above log information is located can be the same blockchain or different blockchains. For the specific implementation process of adding access information to the blockchain, please refer to the existing blockchain technology. As an example, the implementation method of adding log information to the blockchain mentioned above in the present disclosure can be used to add access information to the blockchain.

[0061] Figure 2 A schematic flow chart of a log management method according to another embodiment of the present disclosure is shown. Figure 2 The method shown can be implemented in software by a computer program, or can be executed by a specially configured computing device or log management system. Figure 2 The method shown.

[0062] like Figure 2 As shown, in step S1, N operation accounts with sensitive data query permissions can be generated for daily operation use. The operation accounts can be generated by the data security committee.

[0063] In step S2, for the behavior data generated by the N operating accounts, a block of data is generated every 60 minutes.

[0064] In step S3, 1+N accountable administrator accounts (corresponding to the nodes mentioned above) can be generated based on the hybrid consensus mechanism of DPOS+POW to supervise each other.

[0065] 1 is the bookkeeper that is always fixed by the committee based on DPOS (corresponding to the first node mentioned above), and N is the operational account administrator that is floating based on the POW mechanism (corresponding to the second node mentioned above).

[0066] These 1+N accountable administrator accounts can compete for the right to record new blocks. The accountable administrator account that wins the recording right will serve as a recording node to record the new block, and the remaining accountable administrator accounts will serve as verification nodes to verify the validity of the new block recorded by the recording node.

[0067] For the N accountable administrator accounts generated based on the POW mechanism, they can be refreshed once every 60 minutes based on the POW mechanism. If the results generated based on the POW mechanism are the same within 60 minutes, when competing for the right to record a new block, the most recent winning recording node with the right to record a new block can be directly used as the recording node for this time.

[0068] S4. The new block recorded by the recording node includes three parts: behavior data, hash value of the new block, and hash value of the previous block. The hash value can be a 256-bit encrypted string generated by SHA-256 encryption.

[0069] S5. The verification node can perform accounting rights identity authentication based on the hash value of the previous block to verify whether the new block recorded by the recording node is valid. For details, please refer to the relevant description above.

[0070] S6. After verification, the verification node can record and store the data content of the block to the private cloud data storage (considering the efficiency and cost of block generation, the number of verification nodes should not be set too much, such as a total of 10 verification nodes)

[0071] S7. To ensure the timeliness of data, the time for generating the next new block is still the shortest 60 minutes. The next block will not be generated until more than 51% of the data is stored, and so on.

[0072] So far combined Figure 1 , Figure 2The present disclosure is described in detail using the log management scenario as an example. The present disclosure can be applied to, but not limited to, sensitive data query, offline investigation and evidence collection by police officers, and other scenarios. Taking the application in the investigation and evidence collection scenario as an example, the present disclosure can also be implemented as an auxiliary investigation and evidence collection method. The auxiliary investigation and evidence collection method disclosed in the present disclosure includes a behavior information acquisition step, a node determination step, a block generation step, a verification step, and a storage step.

[0073] Behavior information acquisition step: obtain the behavior information of the case handlers during the first time period for investigation and evidence collection, where the behavior information may refer to the behavior information generated by the case handlers during offline investigation and evidence collection; Node determination step: determine the recording node for recording blocks and the verification node for verifying blocks based on the hybrid consensus mechanism of Delegated Proof of Stake (DPOS) and Proof of Work (POW); Block generation step: the recording node generates a new block in the case chain based on the behavior information, and the data content of the new block includes the behavior information, the hash value of the new block, and the hash value of the previous block, where the hash value of the new block is obtained by hashing the behavior information and the hash value of the previous block using a hash algorithm; Verification step: the verification node verifies the validity of the new block; Storage step: if the verification result is that the new block is valid, the verification node stores the data content of the new block. For details of each step, please refer to the relevant description above, which will not be repeated here.

[0074] As an example, when the first time period has passed and more than a certain proportion of the verification nodes have stored the data content of the new block, the behavior information acquisition step, the node determination step, the block generation step, the verification step and the storage step are executed again to store the behavior information of the case handlers conducting investigations and collecting evidence within a second time range after the time period corresponding to the first time range.

[0075] Therefore, based on the present disclosure, the behavioral information of case handlers (such as police officers) during offline investigation and evidence collection can be uploaded to the chain, so that the entire investigation and evidence collection process can be traced and 100% traceable.

[0076] The log management method disclosed in the present invention can also be implemented as a log management system, including: a scheduling node and multiple computing nodes, the scheduling node and the computing node can both be deployed in a device, different computing nodes can be deployed in different devices, and the scheduling node can be deployed in an independent device different from the computing node, and can also be deployed in the same device with one or more of the computing nodes.

[0077] The scheduling node determines the recording node for recording blocks and the verification node for verifying blocks among multiple computing nodes based on the hybrid consensus mechanism of Delegated Proof of Stake (DPOS) and Proof of Work (POW). The scheduling node obtains the log information generated within the first time period and sends the log information to the recording node. The recording node generates a new block based on the log information and sends the new block to the verification node. The data content of the new block includes the log information, the hash value of the new block, and the hash value of the previous block, wherein the hash value of the new block is obtained by hashing the log information and the hash value of the previous block using a hash algorithm. The verification node verifies the validity of the new block. If the verification result is that the new block is valid, the data content of the new block is stored. For details of the operations performed by the scheduling node and the computing node, please refer to the relevant description above, which will not be repeated here.

[0078] When the first time period has passed and more than a certain proportion of verification nodes have stored the data content of the new block, the scheduling node and the computing node can perform the above operation again to store the log information generated within the second time range after the time period corresponding to the first time range.

[0079] The present disclosure also provides a log management method for client users, which can be executed by the client, and includes: recording the user's behavior information, uploading the behavior information to the log management system, and adding the behavior information to the blockchain by the log management system. The behavior information mentioned here can be regarded as the log information that needs to be uploaded to the chain mentioned above. Regarding the specific implementation process of the log management system adding the behavior information to the blockchain, please refer to the relevant description above, which will not be repeated here.

[0080] User behavior information refers to information that needs to be uploaded to the chain for subsequent traceability. Behavior information can be information about the user's access, modification, deletion, and other behaviors on the data, that is, behavior information related to the data. The data can refer to relatively important sensitive data. Therefore, the recorded behavior information can specifically refer to behavior information related to sensitive data.

[0081] Taking the security management scenario applied to internal contract data of an enterprise as an example, the behavior information may include but is not limited to the record information of the user performing modification operations on the contract data and the record information of the user adding supplementary agreements. Taking the security management scenario applied to internal operation data of an enterprise as an example, the behavior information may include but is not limited to the record information of the user performing operations on the internal operation data of the enterprise (such as sensitive data) by using the operation account.

[0082] The log management method disclosed herein may also be implemented as a log management device. Figure 3The structure diagram of the log management device according to an embodiment of the present disclosure is shown. The log management device 300 can be set on the scheduling node of the distributed system. The functional modules of the log management device 300 can be implemented by hardware, software or a combination of hardware and software that implements the principles of the present invention. It can be understood by those skilled in the art that Figure 3 The functional modules described can be combined or divided into sub-modules to implement the principles of the above invention. Therefore, the description herein can support any possible combination, division, or further limitation of the functional modules described herein.

[0083] The following is a brief description of the functional modules that the log management device may have and the operations that each functional module may perform. For the details involved, please refer to the relevant description above and will not be repeated here.

[0084] See also Figure 3 The log management device 300 includes a log acquisition module 310, a node determination module 320, a block generation module 330, a verification module 340 and a storage module 350.

[0085] The log acquisition module 310 is used to obtain the log information generated within the first time range. The node determination module 320 is used to determine the recording node for recording the block and the verification node for verifying the block based on the hybrid consensus mechanism of the Delegated Proof of Stake (DPOS) and Proof of Work (POW). The block generation module 330 is used to instruct the recording node to generate a new block based on the log information, and the data content of the new block includes the log information, the hash value of the new block and the hash value of the previous block, wherein the hash value of the new block is obtained by hashing the log information and the hash value of the previous block using a hash algorithm. The verification module 340 is used to instruct the verification node to verify the validity of the new block based on the hash value of the previous block in the data content of the new block. The storage module 350 is used to instruct the verification node to store the data content of the new block if the verification result is that the new block is valid.

[0086] When the first time period has passed and more than a certain proportion of the verification nodes have stored the data content of the new block, the log acquisition module 310, the node determination module 320, the block generation module 330, the verification module 340 and the storage module 350 may perform the above operations again to store the log information generated within the second time range after the time period corresponding to the first time range.

[0087] The auxiliary investigation and evidence collection method disclosed in the present invention may also be implemented as an auxiliary investigation and evidence collection device. Figure 4The structure diagram of the auxiliary investigation and evidence collection device according to an embodiment of the present disclosure is shown. The auxiliary investigation and evidence collection device 400 can be set on a scheduling node of a distributed system. The functional modules of the auxiliary investigation and evidence collection device 400 can be implemented by hardware, software, or a combination of hardware and software that implements the principles of the present invention. It can be understood by those skilled in the art that Figure 4 The functional modules described can be combined or divided into sub-modules to implement the principles of the above invention. Therefore, the description herein can support any possible combination, division, or further limitation of the functional modules described herein.

[0088] The following is a brief description of the functional modules that the auxiliary investigation and evidence collection device can have and the operations that each functional module can perform. For the details involved, please refer to the relevant description above and will not be repeated here.

[0089] See also Figure 4 The auxiliary investigation and evidence collection device 400 includes a behavior information acquisition module 410 , a node determination module 420 , a block generation module 430 , a verification module 440 and a storage module 450 .

[0090] The behavior information acquisition module 410 is used to obtain the behavior information of the case handlers conducting investigations and collecting evidence within the first time period; the node determination module 420 is used to determine the recording node used to record the block and the verification node used to verify the block based on a hybrid consensus mechanism of delegated proof of stake (DPOS) and proof of work (POW); the block generation module 430 is used to instruct the recording node to generate a new block in the case chain based on the behavior information, and the data content of the new block includes the behavior information, the hash value of the new block and the hash value of the previous block, wherein the hash value of the new block is obtained by hashing the behavior information and the hash value of the previous block using a hash algorithm; the verification module 440 is used to instruct the verification node to verify the validity of the new block; the storage module 450 is used to instruct the verification node to store the data content of the new block if the verification result is that the new block is valid.

[0091] When the first time period has passed and more than a certain proportion of the verification nodes have stored the data content of the new block, the information acquisition module 410, the node determination module 420, the block generation module 430, the verification module 440 and the storage module 450 may perform the above operations again to store the behavioral information of the case handlers conducting investigations and collecting evidence within a second time range after the time period corresponding to the first time range.

[0092] Figure 5The structural diagram of the log management device according to another embodiment of the present disclosure is shown. The log management device 500 can be set on the client. The functional modules of the log management device 500 can be implemented by hardware, software or a combination of hardware and software that implements the principles of the present invention. It can be understood by those skilled in the art that Figure 5 The functional modules described can be combined or divided into sub-modules to implement the principles of the above invention. Therefore, the description herein can support any possible combination, division, or further limitation of the functional modules described herein.

[0093] The following is a brief description of the functional modules that the log management device may have and the operations that each functional module may perform. For the details involved, please refer to the relevant description above and will not be repeated here.

[0094] See also Figure 5 , the log management device 500 includes a recording module 510 and an uploading module 520. The recording module 510 is used to record the user's behavior information. The uploading module 520 is used to upload the behavior information to the log management system, and the log management system adds the behavior information to the blockchain. For the specific implementation process of the log management system adding the behavior information to the blockchain, please refer to the relevant description above, which will not be repeated here.

[0095] Figure 6 A schematic diagram of the structure of a computing device that can be used to implement the above-mentioned log management method or assist in investigation and evidence collection according to an embodiment of the present invention is shown.

[0096] See also Figure 6 , the computing device 600 includes a memory 610 and a processor 620 .

[0097] The processor 620 may be a multi-core processor or may include multiple processors. In some embodiments, the processor 620 may include a general-purpose main processor and one or more special coprocessors, such as a graphics processing unit (GPU), a digital signal processor (DSP), etc. In some embodiments, the processor 620 may be implemented using a customized circuit, such as an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA).

[0098] The memory 610 may include various types of storage units, such as system memory, read-only memory (ROM), and permanent storage devices. Among them, ROM can store static data or instructions required by the processor 620 or other modules of the computer. The permanent storage device may be a readable and writable storage device. The permanent storage device may be a non-volatile storage device that does not lose the stored instructions and data even after the computer is powered off. In some embodiments, the permanent storage device uses a large-capacity storage device (such as a magnetic or optical disk, flash memory) as a permanent storage device. In some other embodiments, the permanent storage device may be a removable storage device (such as a floppy disk, optical drive). The system memory may be a readable and writable storage device or a volatile readable and writable storage device, such as a dynamic random access memory. The system memory may store some or all instructions and data required by the processor at run time. In addition, the memory 610 may include any combination of computer-readable storage media, including various types of semiconductor memory chips (DRAM, SRAM, SDRAM, flash memory, programmable read-only memory), and disks and / or optical disks may also be used. In some embodiments, the memory 610 may include a readable and / or writable removable storage device, such as a laser disc (CD), a read-only digital versatile disc (e.g., DVD-ROM, double-layer DVD-ROM), a read-only Blu-ray disc, an ultra-density optical disc, a flash memory card (e.g., SD card, mini SD card, Micro-SD card, etc.), a magnetic floppy disk, etc. The computer-readable storage medium does not include carrier waves and transient electronic signals transmitted wirelessly or wired.

[0099] The memory 610 stores executable codes. When the executable codes are processed by the processor 620, the processor 620 can execute the log management method or the auxiliary investigation and evidence collection method mentioned above.

[0100] The log management method or the auxiliary investigation and evidence collection method according to the present invention has been described in detail above with reference to the accompanying drawings.

[0101] In addition, the method according to the present invention may also be implemented as a computer program or a computer program product, which includes computer program code instructions for executing the above steps defined in the above method of the present invention.

[0102] Alternatively, the present invention may also be implemented as a non-temporary machine-readable storage medium (or computer-readable storage medium, or machine-readable storage medium) on which executable code (or computer program, or computer instruction code) is stored. When the executable code (or computer program, or computer instruction code) is executed by a processor of an electronic device (or computing device, server, etc.), the processor executes the various steps of the above-mentioned method according to the present invention.

[0103] Those skilled in the art will further appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the disclosure herein may be implemented as electronic hardware, computer software, or a combination of both.

[0104] The flow chart and block diagram in the accompanying drawings show the possible architecture, function and operation of the system and method according to multiple embodiments of the present invention. In this regard, each square box in the flow chart or block diagram can represent a part of a module, program segment or code, and the part of the module, program segment or code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two continuous square boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0105] The embodiments of the present invention have been described above, and the above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein are selected to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.

Claims

1. A log management method, comprising: Log acquisition step: acquiring log information generated within the first time period; Node determination step: Determine the recording node for recording blocks and the verification node for verifying blocks based on the hybrid consensus mechanism of Delegated Proof of Stake (DPOS) and Proof of Work (POW); Block generation step: the recording node generates a new block based on the log information, the data content of the new block includes the log information, the hash value of the new block and the hash value of the previous block, wherein the hash value of the new block is obtained by performing hash calculation on the log information and the hash value of the previous block using a hash algorithm; Verification step: the verification node verifies the validity of the new block; Storage step: If the verification result is that the new block is valid, the verification node stores the data content of the new block. Among them, a hybrid consensus mechanism based on delegated proof of stake (DPOS) and proof of work (POW) is used to determine a recording node for recording blocks and a verification node for verifying blocks, including: determining a first node based on the delegated proof of stake (DPOS) mechanism; determining multiple second nodes based on the proof of work (POW) mechanism; selecting a node from the first node and the multiple second nodes as the recording node, and the remaining nodes as the verification nodes.

2. The method according to claim 1, further comprising: When the first time period has passed and more than a certain proportion of the verification nodes have stored the data content of the new block, the log acquisition step, the node determination step, the block generation step, the verification step and the storage step are executed again to store the log information generated within a second time range after the time period corresponding to the first time range.

3. The method according to claim 1, wherein: In the verification step, the verification node uses a hash algorithm to perform hash calculation on the log information and the hash value of the previous block, and compares the calculated hash value with the hash value of the new block. If they are consistent, the new block is determined to be valid, otherwise the new block is determined to be invalid.

4. The method according to claim 1, further comprising: An access permission is set for the block, where the access permission is used to represent the read permission of the data content of the block.

5. The method according to claim 1, further comprising: Obtaining access information of the block; The access information is added to the blockchain.

6. The method according to claim 1, further comprising: Generate one or more operation accounts with permission to operate sensitive data; Wherein, in the log acquisition step, behavioral information related to sensitive data generated by the operation account is acquired.

7. A method for assisting investigation and evidence collection, comprising: Behavior information acquisition step: obtain the behavior information of the case-handling personnel during investigation and evidence collection within the first time period; Node determination step: Determine the recording node for recording blocks and the verification node for verifying blocks based on the hybrid consensus mechanism of Delegated Proof of Stake (DPOS) and Proof of Work (POW); Block generation step: the recording node generates a new block in the case chain based on the behavior information, the data content of the new block includes the behavior information, the hash value of the new block and the hash value of the previous block, wherein the hash value of the new block is obtained by performing hash calculation on the behavior information and the hash value of the previous block using a hash algorithm; Verification step: the verification node verifies the validity of the new block; Storage step: If the verification result is that the new block is valid, the verification node stores the data content of the new block. Among them, a hybrid consensus mechanism based on delegated proof of stake (DPOS) and proof of work (POW) is used to determine a recording node for recording blocks and a verification node for verifying blocks, including: determining a first node based on the delegated proof of stake (DPOS) mechanism; determining multiple second nodes based on the proof of work (POW) mechanism; selecting a node from the first node and the multiple second nodes as the recording node, and the remaining nodes as the verification nodes.

8. The method according to claim 7, further comprising: When the first time period has passed and more than a certain proportion of the verification nodes have stored the data content of the new block, the behavior information acquisition step, the node determination step, the block generation step, the verification step and the storage step are executed again to store the behavior information of the case handlers conducting investigations and collecting evidence within a second time range after the time period corresponding to the first time range.

9. A log management system, comprising: Scheduling nodes and multiple computing nodes, The scheduling node determines a recording node for recording blocks and a verification node for verifying blocks among the multiple computing nodes based on a hybrid consensus mechanism of Delegated Proof of Stake (DPOS) and Proof of Work (POW), The scheduling node obtains log information generated within a first time period, and sends the log information to the recording node. The recording node generates a new block based on the log information, and sends the new block to the verification node, wherein the data content of the new block includes the log information, the hash value of the new block and the hash value of the previous block, wherein the hash value of the new block is obtained by performing a hash calculation on the log information and the hash value of the previous block using a hash algorithm, The verification node verifies the validity of the new block. If the verification result shows that the new block is valid, the data content of the new block is stored. The scheduling node determines a first node based on a delegated proof of stake (DPOS) mechanism, determines multiple second nodes based on a proof of work (POW) mechanism, selects one node from the first node and the multiple second nodes as the recording node, and the remaining nodes serve as the verification nodes.

10. A log management device, comprising: A log acquisition module, used to acquire log information generated within a first time range; A node determination module, which is used to determine the recording node for recording blocks and the verification node for verifying blocks based on a hybrid consensus mechanism of Delegated Proof of Stake (DPOS) and Proof of Work (POW); A block generation module, used to instruct the recording node to generate a new block based on the log information, wherein the data content of the new block includes the log information, a hash value of the new block and a hash value of the previous block, wherein the hash value of the new block is obtained by performing a hash calculation on the log information and the hash value of the previous block using a hash algorithm; A verification module, used to instruct the verification node to verify the validity of the new block based on the hash value of the previous block in the data content of the new block; a storage module, configured to instruct the verification node to store the data content of the new block if the verification result shows that the new block is valid, Among them, the node determination module determines a first node based on a delegated proof of stake (DPOS) mechanism, determines multiple second nodes based on a proof of work (POW) mechanism, selects one node from the first node and the multiple second nodes as the recording node, and the remaining nodes serve as the verification nodes.

11. An auxiliary investigation and evidence collection device, comprising: A behavior information acquisition module is used to obtain behavior information of case handlers during investigation and evidence collection within the first time period; A node determination module, which is used to determine the recording node for recording blocks and the verification node for verifying blocks based on a hybrid consensus mechanism of Delegated Proof of Stake (DPOS) and Proof of Work (POW); A block generation module, used to instruct the recording node to generate a new block in the case chain based on the behavior information, wherein the data content of the new block includes the behavior information, a hash value of the new block and a hash value of the previous block, wherein the hash value of the new block is obtained by performing a hash calculation on the behavior information and the hash value of the previous block using a hash algorithm; A verification module, used to instruct the verification node to verify the validity of the new block; a storage module, configured to instruct the verification node to store the data content of the new block if the verification result shows that the new block is valid, Among them, the node determination module determines a first node based on a delegated proof of stake (DPOS) mechanism, determines multiple second nodes based on a proof of work (POW) mechanism, selects one node from the first node and the multiple second nodes as the recording node, and the remaining nodes serve as the verification nodes.

12. A computing device comprising: processor; as well as A memory having executable codes stored thereon, which, when executed by the processor, causes the processor to execute the method according to any one of claims 1 to 8.

13. A non-transitory machine-readable storage medium having executable codes stored thereon, which, when executed by a processor of an electronic device, causes the processor to execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Archive information security management system and method based on blockchain

    CN110781525A