Method and apparatus for verifying audit information
By using hash calculations of public salt values and independent salt values in audit information verification, combined with the Merkel tree structure, the problem of low security of audit information is solved, and efficient and secure audit information verification is achieved.
Patent Information
- Application Number
- CN202211103832.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-09
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-09-09
AI Technical Summary
In the prior art, there is a problem of low security in the verification process of audit information, especially when multiple auditors participate, the risk of information leakage is high and the verification process lacks independence.
The initial audit information is hashed by the common salt value and independent salt value, the first verification data and the second verification data are generated, and the legitimacy of the audit information is verified by comparing the verification data. The common salt value is used for sharing multiple verification nodes and audit nodes, and the independent salt value is used for unique to each verification node, and data processing is optimized in combination with the Merkel tree structure.
It improves the security of audit information and the independence of the verification process, reduces the amount of computing during verification, protects the privacy of the initial audit information, and overturns and denies through multiple verification results, improving the security and efficiency of the verification process.
Smart Images

Figure CN115622705B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information security, and in particular, to a method and device for verifying audit information. Background Art
[0002] In the management of a confidentiality system, the management role of a system administrator plays an important role. For example, in a classified system with separation of three powers, the system administrator, security and confidentiality administrator, and security auditor are required to have clear authority division, verify each other, supervise each other, and cannot hold concurrent positions. And a certain number of administrators for each role need to be equipped according to the actual situation. In many security systems, the system auditor can audit various types of audit information in the system, but the reliability of the audit still highly depends on the system auditor himself / herself, and the trust in the auditor himself / herself also becomes an important issue to be considered. If there are too few auditors, there may be omissions in the audit by a certain auditor, or the auditor may forge audit data without authorization. Usually, multiple auditors are configured in a complex management system, but the increase in the number of auditors will increase the risk of audit information leakage, and the corresponding labor cost expenditure will also increase.
[0003] In addition, in the prior art, a private key is set for a device, its public key is made public, and when generating an audit log, the private key is used to sign the log, the log is sent to the auditor, and the signature is sent to the verifier. For any publicly available log information of the auditor, the verifier can always verify whether the signature matches the log through the public key, so as to determine whether the log is truly generated by the device. However, the above solution will lead to a large amount of asymmetric encryption and decryption operations, and can only verify based on a fixed range of logs, which depends on the log range for making the signature. The leakage of the private key may lead to the forgery of the signature. Each verifier gets the same signature, and the verification between verifiers has no independence. The public key is made public, so that everyone can verify, which will also generate the risk of information leakage, because the ability to verify at least gives the verifier the right to exclude and other problems.
[0004] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of the present invention provide a method and device for verifying audit information, so as to at least solve the technical problem of low security of audit information existing in the process of verifying the data fed back by an auditor in the related art.
[0006] According to one aspect of an embodiment of the present invention, there is provided a method for verifying audit information, including: a verification node obtains first verification data and the audit information to be verified, wherein the first verification data is obtained by the audit system through hash calculation on the initial audit information based on a common salt value and an independent salt value, the audit information to be verified is the data fed back by the audit node after auditing the initial audit information, the common salt value is a random sequence shared by multiple verification nodes and the audit node, the independent salt value is a random sequence possessed by the target verification node, and different verification nodes have different independent salt values; the verification node obtains second verification data, wherein the second verification data is obtained by hash calculation on the audit information to be verified at least based on the independent salt value; the verification node compares the second verification data with the first verification data to obtain a comparison result; the verification node verifies whether the audit information to be verified is legal information according to the comparison result, wherein the legal information indicates that the audit node has not changed the initial audit information during the process of auditing the initial audit information.
[0007] Further, the method for verifying audit information further includes: the audit system generates initial audit information, and parses the initial audit information to obtain an index identifier and a content part corresponding to the initial audit information; the audit system performs salted hash calculation on the index identifier based on the common salt value to obtain a first hash value of the index identifier; the audit system performs salted hash calculation on the content part based on the common salt value to obtain a first hash value of the content part; the audit system performs a second hash calculation on the first hash value of the index identifier based on the independent salt value to obtain an index part of the first verification data; the audit system performs a second hash calculation on the first hash value of the content part based on the independent salt value to obtain a content part of the first verification data; the audit system sends the first verification data to the verification node, the verification node stores the first verification data sent by the audit system, and constructs an index tree based on the index part of the first verification data; the audit system also sends the initial audit information to the audit node, and distributes the common salt value to all verification nodes, and separately distributes the independent salt value to each verification node.
[0008] Further, the verification method for audit information further includes: at preset time intervals, the audit system aggregates the first hash values of the index identifiers of the initial audit information within a preset duration and the first hash values of the content parts of the initial audit information respectively, to obtain the aggregated first hash value of the index identifier and the aggregated first hash value of the content part; the audit system performs hash calculations on the aggregated first hash value of the index identifier and the aggregated first hash value of the content part respectively based on the independent salt value, to obtain the second hash value of the index identifier and the second hash value of the content part, wherein the first verification data at least includes the second hash value of the index identifier and the second hash value of the content part.
[0009] Further, the verification method for audit information further includes: the verification node detects whether the target verification node has target permissions, where the target permissions indicate that the target verification node has the permission to obtain the audit information to be verified from the audit node; when the target verification node has the target permissions, the verification node obtains the audit information to be verified through the audit node; the verification node performs a hash calculation on the audit information to be verified based on the common salt value, to obtain the processed verification data; the verification node performs a second hash calculation on the processed verification data based on the independent salt value, to obtain the second verification data.
[0010] Further, the verification method for audit information further includes: when the target verification node does not have the target permissions, the verification node obtains the audit information to be verified after the first hash through the supervision node, where the supervision node is used to receive the audit information to be verified sent by the audit node and perform a hash calculation on the audit information to be verified based on the common salt value, to obtain the processed audit information to be verified; the verification node performs a second hash calculation on the processed audit information to be verified based on the independent salt value, to obtain the second verification data.
[0011] Further, the verification method for audit information further includes: the verification node parses the audit information to be verified, to obtain the index identifier and the content part corresponding to the audit information to be verified; the verification node performs hash calculations on the index identifier and the content part respectively based on the common salt value, to obtain the first hash value of the index identifier and the first hash value of the content part, wherein the processed verification data at least includes the first hash value of the index identifier and the first hash value of the content part.
[0012] Further, the verification method of audit information further includes: the verification node performs hash calculations on the first hash value of the index identifier and the first hash value of the content part respectively based on the independent salt value, to obtain the second hash value of the index identifier and the second hash value of the content part, wherein the second verification data at least includes the second hash value of the index identifier and the second hash value of the content part.
[0013] Further, the verification method of audit information further includes: before comparing the second verification data and the first verification data to obtain a comparison result, the verification node constructs an index tree corresponding to the target verification node, wherein the index tree is composed of multiple nodes; the verification node parses the first verification data to obtain a target index identifier and target verification data; the verification node decomposes the target index identifier to obtain multiple characters; the verification node determines the node position of the current character in the index tree according to the position of the current character in the multiple characters, wherein the current character is any one of the multiple characters; the verification node determines a target node from the multiple nodes and stores the target verification data in the target node, wherein the target node is the next node of the node corresponding to the last character of the multiple characters.
[0014] Further, the verification method of audit information further includes: the verification node parses the second verification data to obtain the index identifier and content part of the second verification data; the verification node indexes the index tree based on the index identifier of the second verification data to obtain candidate verification data corresponding to the index identifier of the second verification data; the verification node compares the candidate verification data with the target verification data to obtain the comparison result.
[0015] According to another aspect of the embodiments of the present invention, there is also provided a verification device for audit information, including: a first verification data acquisition module, configured to acquire, by a verification node, first verification data and the audit information to be verified, where the first verification data is obtained by the audit system through hash calculation on initial audit information based on a common salt value and an independent salt value, the audit information to be verified is the data fed back by the audit node after auditing the initial audit information, the common salt value is a random sequence shared by multiple verification nodes and the audit node, the independent salt value is a random sequence possessed by the target verification node, and different verification nodes have different independent salt values; a second verification data acquisition module, configured to acquire, by the verification node, second verification data, where the second verification data is obtained by hash calculation on the audit information to be verified at least based on the independent salt value; a data comparison module, configured to compare, by the verification node, the second verification data with the first verification data to obtain a comparison result; and an information verification module, configured to verify, by the verification node, whether the audit information to be verified is legal information according to the comparison result, where the legal information indicates that the audit node has not changed the initial audit information during the process of auditing the initial audit information.
[0016] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium storing a computer program, where the computer program is configured to execute the above verification method of audit information when running.
[0017] According to another aspect of the embodiments of the present invention, there is also provided an electronic device, including one or more processors; a memory for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement a program for running, where the program is configured to execute the above verification method of audit information when running.
[0018] According to another aspect of the embodiments of the present invention, there is also provided a computer program product including a computer program / instructions, and when the computer program / instructions are executed by a processor, the above verification method of audit information is implemented.
[0019] In an embodiment of the present invention, hash calculation is performed on audit information based on a hash salt value to obtain verification data. By comparing the verification data, it is verified whether the information fed back by the audit node after auditing the initial audit information is legal information. First, the verification node obtains the first verification data and the audit information to be verified, then the verification node obtains the second verification data, and then the verification node compares the second verification data with the first verification data to obtain a comparison result; finally, the verification node verifies whether the audit information to be verified is legal information according to the comparison result. Among them, the first verification data is obtained by the audit system performing hash calculation on the initial audit information based on a common salt value and an independent salt value. The audit information to be verified is the data fed back by the audit node after auditing the initial audit information. The common salt value is a random sequence shared by multiple verification nodes and audit nodes, and the independent salt value is a random sequence owned by the target verification node. Different verification nodes have different independent salt values. The second verification data is obtained by performing hash calculation on the audit information to be verified at least based on the independent salt value. Legal information means that the audit node has not changed the initial audit information during the process of auditing the initial audit information.
[0020] In the above process, by performing hash calculation on the initial audit information based on the common salt value, the initial audit information can be converted into a code with a fixed length, reducing the amount of calculation during verification, and the irreversibility of the hash process can be used to protect the privacy of the initial audit information. In addition, the common salt value is shared by the verification nodes and the audit nodes, which can protect and streamline the audit information; the independent salt value is independently owned by each verification node and can be used to ensure the independence of the verification results among the verification nodes. Therefore, even if the verifier corresponding to a verification node repudiates, the verification results of multiple people can be used to overturn it, achieving the purpose of improving the security of the verification process.
[0021] It can be seen that through the technical solution of the present invention, the purpose of verifying whether the information fed back by the audit node after auditing the initial audit information is legal information is achieved, thereby realizing the technical effect of improving the security of the verification process, and further solving the technical problem of low security of audit information existing in the process of verifying the data fed back by the auditor in the related art. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0023] Figure 1 is a schematic diagram of a method for verifying audit information according to an embodiment of the present invention;
[0024] Figure 2 is a specific implementation flowchart of an optional audit information according to an embodiment of the present invention;
[0025] Figure 3 is a timing diagram of a verification method for indirect verification of an optional audit information according to an embodiment of the present invention;
[0026] Figure 4 is a timing diagram of a verification method for direct verification of an optional audit information according to an embodiment of the present invention;
[0027] Figure 5 is a schematic diagram of an optional Merkle tree structure according to an embodiment of the present invention;
[0028] Figure 6 is a schematic diagram of an optional verification data storage index tree structure according to an embodiment of the present invention;
[0029] Figure 7 is a schematic diagram of an optional verification device for audit information according to an embodiment of the present invention;
[0030] Figure 8 is a schematic diagram of an optional electronic device according to an embodiment of the present invention. Detailed implementation manners
[0031] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0033] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in the present invention are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set between the present system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and after receiving the consent information feedback from the aforementioned users or institutions, the relevant information is obtained.
[0034] Embodiment 1
[0035] According to an embodiment of the present invention, a method embodiment of a method for verifying audit information is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0036] Figure 1 is a flowchart of an optional method for verifying audit information according to an embodiment of the present invention, as Figure 1 shown, the method includes the following steps:
[0037] Step S102, the verification node obtains first verification data and the audit information to be verified. Among them, the first verification data is obtained by the audit system through hashing the initial audit information based on a common salt value and an independent salt value. The audit information to be verified is the data fed back by the audit node after auditing the initial audit information. The common salt value is a random sequence shared by multiple verification nodes and the audit node, and the independent salt value is a random sequence possessed by the target verification node. Different verification nodes have different independent salt values.
[0038] Step S104, the verification node obtains second verification data, where the second verification data is obtained by hashing the audit information to be verified at least based on the independent salt value.
[0039] Step S106, the verification node compares the second verification data with the first verification data to obtain a comparison result.
[0040] Step S108, the verification node verifies whether the audit information to be verified is legal information according to the comparison result, where the legal information indicates that the audit node has not changed the initial audit information during the process of auditing the initial audit information.
[0041] In this embodiment, the above steps S102 - S108 correspond to Figure 2 the specific implementation flowchart of the audit information shown, in Figure 2Among them, the audit node, verification node, and supervision node respectively correspond to the target platforms used by the auditor, verifier, and supervisor in the administrator role of the system, and are specifically used for auditing and supervision verification of system logs.
[0042] In Figure 2 the system assigns the administrator roles as follows:
[0043] Auditor: An auditor who has full viewing rights to the audit log.
[0044] Verifier: Other management personnel who have no right to view the audit log but need to verify the authenticity of the auditor's audit results.
[0045] Supervisor: A senior supervisor with the authority to supervise the audit log. The supervisor usually accepts reports, certificates, analyses, etc. issued by the auditor.
[0046] In this embodiment, verifying whether the audit information to be verified is legal information according to the comparison result includes two methods: direct verification and indirect verification. In the sequence diagram of an optional verification method for indirect verification of audit information as shown in Figure 3 through the indirect verification method to verify the audit information to be verified. Among them, the verification node and the supervision node are different nodes, and the verifier and supervisor corresponding to the verification node and the supervision node are also different objects. During indirect verification, the auditor provides the audit information to be verified to the supervisor, and the verifier can help the supervisor confirm whether the audit information to be verified provided by the auditor truly originates from the initial audit information, and perform integrity checks and anti-tampering checks. At the same time, the verifier itself cannot obtain any information about the audit information. Even for the audit information to be verified that the verifier needs to verify, the verifier has no right to view it.
[0047] In indirect verification, the relevant permissions of each role are as follows:
[0048] Table 1 Permissions of Each Administrator in Indirect Verification
[0049]
[0050] Optionally, in the sequence diagram of an optional verification method for direct verification of audit information as shown in Figure 4 the verification node and the supervision node are the same node, and the corresponding supervisor and verifier are the same object. During direct verification, the verifier acts as the supervisor, can obtain the audit information to be verified from the auditor, and perform verification.
[0051] In direct verification, the relevant permissions of each role are as follows:
[0052] Table 2 Permissions of Each Administrator in Direct Verification
[0053]
[0054]
[0055] In step S102, the initial audit information is the log information generated by the system operation and sent to the audit node, such as time-series data information such as logs, transaction records, and monitoring data generated by the system operation. Among them, the initial audit information is audit data with timestamps. For example, in the operation log, the initial audit information is the timestamp + operation content, which can be expressed as follows: 2022.02.22 11:23:31admin user1 login in through https with host 10.180.1.3. In order to store the initial audit information in a structured manner, usually an index item can be set for each piece of initial audit information, such as an id represented by a number. For easy identification, the id usually needs to include the date and time of the log, the type of the log, and the sequence number, etc. For example, 2022-02-12_13:19:23_09_13, which means the generation date is 2022-02-12, the generation time is 13:19:23, the log type number is 09, and the sequence number is 13 (the 13th log of the same log type in the same second). An audit log can be expressed as:
[0056] (id,text)
[0057] where text is the content of the log record.
[0058] In this embodiment, the system includes but is not limited to one audit node (Auditor), denoted as A1, which has the audit authority for specific types of logs, and n verification nodes (verification), and the n verifiers are respectively denoted as V1, V2,..., Vn. For the audit information to be verified provided by the auditor, the n verifiers can independently verify the correctness of the provided content.
[0059] Optionally, the system performs a hash calculation on the initial audit information based on a common salt value and an independent salt value to obtain the first verification data. Among them, the common salt value is a salt value shared by n verification nodes (verification) and one audit node (Auditor), which is a specific randomly generated sequence. For the verifiers, the common salt value is public and shared. In this embodiment, taking the common salt value as s0, the hash algorithm as SHA256, and the initial audit information as (id, text) as an example, the first hash calculation of the initial audit information based on the common salt value is performed through the following formula:
[0060] (id,text)-->(sha(id,s0), sha(text,s0)) (1)
[0061] In the above formula (1), after adding the original id and text to the common salt value s0 respectively and then performing the hash operation, the resulting ciphertext is also a data pair, where sha(id, s0) is the key and sha(text, s0) is the value. Since this is the first hash operation, sha(id, s0) can be denoted as [id] 1 , that is, the id after one hash operation. Similarly, sha(text, s0) can be expressed as [text] 1 . The first hash process can be simply expressed as:
[0062] (id, text) --> ([id] 1 , [text] 1 ) (2)
[0063] It is easy to notice that by performing a hash calculation on the initial audit information using the common salt value, the initial audit information can be transformed into a fixed-length code, reducing the computational effort during verification and protecting the privacy of the initial audit information by leveraging the irreversibility of the hash process.
[0064] Furthermore, based on the independent salt value, a hash calculation is performed on the hash result obtained from the first hash calculation to obtain the first verification data. Here, the independent salt value is a separate and secret salt value distributed by the audit system for each verifier. For example, for verifiers V1, V2,..., V n the obtained salt values are denoted as s1, s2, s3,..., s n . Among them, s1, s2, s3,..., s n are the independent salt values corresponding to each verifier. For example, taking s i as the independent salt value, V i as the verifier, and based on the above hash result (2) [id] 1 , [text] 1 perform a second hash operation based on the independent salt value respectively to obtain the first verification data, and its calculation formula is as follows:
[0065] [id] 2 = sha([id] 1 , s i ) (3)
[0066] [text] 2 = sha([text] 1 , s i ) (4)
[0067] Among them, ([id] 2 , [text]2 ) is the first verification data.
[0068] Among them, since the second hashing operation process based on independent salt values is independent for each verifier and different salt values are used, the hashing results obtained by each verifier are also different. For example, when the system is running, the auditor A1 obtains the content of this log record as: (id, text), and the verifier obtains the content of this log record as: ([id] 2 , [text] 2 ), and the ([id] 2 , [text] 2 ) obtained by each verifier are all different because the salt values of each verifier in the second hashing process are independent. For example, the auditor A1 obtains the content of this log record as:
[0069] {
[0070] (id1, text1),
[0071] (id2, text2),
[0072] (id3, text3), ......
[0074] }
[0075] The log content obtained by each verifier is different, and the content obtained by each verifier can be expressed as:
[0076] {
[0077] ([id1] 2 , [text1] 2 ),
[0078] ([id2] 2 , [text2] 2 ),
[0079] ([id3] 2 , [text3] 2 ), ......
[0081] }
[0082] To hide all information of the log, the order of the first verification data obtained by the verifier is inconsistent with the order of the log obtained by the auditor A1. Since the two hashing algorithms have already hashed the id, only the content shown in the above formula is required, in the order of key [id k 2 (k is 1, 2, 3,...) Reorder the ASCII codes in ascending order and send them to the verification node. The first verification data obtained by the verification node is a series of unordered and unrecognizable key-value pairs.
[0083] Optionally, the audit information to be verified is the data information to be verified that the auditor feeds back to the verifier after auditing the initial audit information of the auditee.
[0084] It should be noted that by performing a hash calculation on the initial audit information based on the common salt value and the independent salt value. Among them, the common salt value is shared by the verifier and the auditor and can be used to protect and streamline the data. The independent salt value is independently owned by each verifier and can be used to ensure the independence of the verification results among different verifiers. Even if a verifier repudiates, the verification results of multiple people can be used to overturn it.
[0085] In an alternative embodiment, the audit system generates the initial audit information, parses the initial audit information to obtain the corresponding index identifier and content part; then performs a salted hash calculation on the index identifier based on the common salt value to obtain the first hash value of the index identifier; performs a salted hash calculation on the content part based on the common salt value to obtain the first hash value of the content part; further, the audit system performs a second hash calculation on the first hash value of the index identifier based on the independent salt value to obtain the index part of the first verification data; performs a second hash calculation on the first hash value of the content part based on the independent salt value to obtain the content part of the first verification data; then the audit system sends the first verification data to the verification node, and the verification node stores the first verification data sent by the audit system and constructs an index tree based on the index part of the first verification data; finally, the audit system also sends the initial audit information to the audit node and distributes the common salt value to all verification nodes and distributes the independent salt value to each verification node separately.
[0086] Optionally, in this embodiment, the audit system runs to generate the initial audit information, then parses the initial audit information to obtain the index identifier and the content part, and then performs a first hash calculation on the index identifier and the content part respectively based on the common salt value to obtain the first hash value of the index identifier and the first hash value of the content part; further, performs a second hash calculation on the first hash value of the index identifier and the first hash value of the content part respectively based on the independent salt value to obtain the index identifier of the first verification data and the content part of the first verification data, and obtains the first verification data based on the index identifier of the first verification data and the content part of the first verification data. Then the audit system sends the first verification data to the verification node, and the verification node constructs an index tree based on the index part of the first verification data.
[0087] Optionally, the audit system also sends the initial audit information to the audit nodes, distributes a common salt value to all verification nodes, and distributes an independent salt value to each verification node separately.
[0088] Furthermore, at every preset time interval, the audit system aggregates the first hash value of the index identifier of the initial audit information within a preset duration and the first hash value of the content part of the initial audit information respectively to obtain the aggregated first hash value of the index identifier and the aggregated first hash value of the content part; then the audit system performs hash calculations on the aggregated first hash value of the index identifier and the aggregated first hash value of the content part respectively based on the independent salt value to obtain the second hash value of the index identifier and the second hash value of the content part, where the first verification data includes at least the second hash value of the index identifier and the second hash value of the content part.
[0089] Optionally, the preset time is a fixed time point preset in the audit system, and the preset duration is a time length preset in the audit system. The duration of each preset time interval can be less than or greater than the preset duration. For example, the audit system starts at 24:00:00 every day to aggregate the first hash value of the index identifier of the initial audit information and the first hash value of the content part of the initial audit information between 15:00:00 and 24:00:00, which is 9 hours before this time point, or it can also start at 24:00:00 every day to aggregate the first hash value of the index identifier of the initial audit information and the first hash value of the content part of the initial audit information within 48 hours before this time point. The aggregated hash values and the single - item hash values are processed subsequently without distinction.
[0090] In an alternative embodiment, when the audit information to be verified is batch data, verifying item by item will generate a large amount of operations. To solve the above problems, in this application, a Merkle tree is used to combine the hash data into data blocks. As Figure 5 shown, when the audit system generates the initial audit information, it has already pre - calculated the first hash value of each log ([id] 1 , [text] 1 ) and stored them. The hierarchical calculation of the aggregated hash results is performed on the data level by level. The delineation of the levels can be based on the data volume. The levels usually can include: logs per second, logs per minute, logs per hour... logs per month, etc. For example, if the bottom - most level is selected as hours, then at the end of each hour, the audit system calculates an aggregated hash result for the audit logs generated in this hour. The log content generated at the current time is as follows:
[0091] {
[0092] (id1,text1),
[0093] (id2,text2), (1) ......
[0095] (id n ,text n )
[0096] }
[0097] Then, perform a hash operation on the log data in (1) above based on the common salt value to obtain the following result:
[0098] {
[0099] ([id1] 1 ,[text1] 1 )
[0100] ([id2] 1 ,[text2] 1 ) (2) ......
[0102] ([id n 1 ,[text n 1 )
[0103] }
[0104] Then, perform a summation calculation on the index identifier and the content part in the above data (2) respectively to obtain the summed index identifier:
[0105] [id1] 1 +[id2] 1 +...+[id n 1
[0106] The summed content part:
[0107] [text1] 1 +[text2] 1 +...+[text n 1
[0108] Then, perform a hash calculation on the summed index identifier and the summed content part respectively based on the common salt value to obtain the following result:
[0109] ([id 1-n 1, ,[text 1-n 1 )
[0110] Among them, [id1-n ] 1 =sha([id1] 1 +[id2] 1 +...+[id n ] 1 ,s0),[text 1-n ] 1 =sha([text1] 1 +[text2] 1 +...+[text n ] 1 ,s0)
[0111] That is, the accumulated hash value of each log is hashed again using the public salt value s0 to obtain the summary hash result of this hour. Since the hash operation still uses the public salt value s0, it is still represented by square brackets plus 1.
[0112] Then ([id 1-n ] 1 ,[text 1-n ] 1 ) are encrypted using the independent salt value of the verifier to obtain the second hash result, where the second hash result is the first verification data summarized this hour, and its form is also a key-value pair. After being sent to the verifier, the data is similar to the first verification data of a single log, so the verifier can treat it indiscriminately. The verifier cannot perceive whether this data is the verification data of a single log or some summarized verification data.
[0113] Optionally, if the previous level of the hour is the day, the summary value of each hour can be summarized again to obtain the summary hash result of the day. The summary hash result of each day is summarized again level by level to obtain the summary hash result of the month. The summary hash result of each month is summarized again to finally obtain the summary hash result of the whole year. The summary hash results of each level are hashed twice using independent salt values to obtain the verification data of nodes at each level of the Merkle tree, which are sent together to the verifier.
[0114] It should be noted that by combining hash data into data blocks based on the Merkle tree and verifying the data blocks, the technical problem in the prior art that the audit information to be verified is batch data and thus the verification of each item will generate a large amount of calculations is solved, thereby effectively improving the efficiency of audit information supervision and review.
[0115] In another alternative embodiment, before the auditing system compares the second verification data with the first verification data to obtain a comparison result, it constructs an index tree corresponding to the target verification node through a verification node, where the index tree consists of multiple nodes; the verification node parses the first verification data to obtain a target index identifier and target verification data; the verification node decomposes the target index identifier to obtain multiple characters; the verification node determines the node position of the current character in the index tree according to the position of the current character among the multiple characters, where the current character is any one of the multiple characters; the verification node determines a target node from the multiple nodes and stores the target verification data in the target node, where the target node is the next node of the node corresponding to the last character among the multiple characters.
[0116] In this embodiment, taking the verification node V i as an example, it is assumed that the verification node V i has the verification right for various auditing information, and the verification node V i does not need to care about which specific auditing information the verification data sent to it by the system corresponds to.
[0117] For the verification node V i , the first verification data it receives is a large number of key-value pairs in the following form:
[0118] ([id] 2 , [text] 2 )
[0119] Both the key and the value are hash values obtained through two hash operations, their lengths are fixed, and the contents are unrecognizable.
[0120] The verification node only needs to decompose the key-value pair to obtain the target index identifier key and the target verification data value, according to the key, that is, the target index identifier [id] 2 , then decompose the target index identifier to obtain the ASCII codes of multiple characters, determine the node position in the index tree based on the ASCII codes of the characters, determine the target node from the multiple nodes, and store them in the target node of the index tree in the order of the ASCII code sizes of the multiple characters. As Figure 6 shown in a schematic diagram of an optional verification data storage index tree structure, the key-value values stored in the leaf nodes are [id] 2 and [text] 2。The nth layer of the tree structure corresponds to the n-1th character of the key string (base64 encoded). The index tree based on the tree structure facilitates the quick insertion of new leaf nodes and also facilitates the quick search for a certain leaf node. For example, root is the root node of the index tree, A, B, and C are the child nodes at the next level of the root node, AA, AB, and AC are the leaf nodes of the child node A, and the nth layer of the tree structure corresponds to the n-1th character of the key string (base64 encoded). Decompose [id] 2 into AAN0b25l, and store its corresponding value in the child node of AA. Optionally, the target node is the next node of the node corresponding to the last character among multiple characters.
[0121] Optionally, when the audit information itself is deleted, the leaf node corresponding to the first verification data is also deleted.
[0122] In step S104, the verifier performs a second hashing calculation on the audit information to be verified sent by the auditor based on the public salt value and the independent salt value to obtain the second verification data. Since the verifier cannot directly log in to the system to view the audit log and can only accept the results announced by the auditor, the verifier uses the second verification data to confirm whether the audit information to be verified provided by the auditor is correct.
[0123] Optionally, the audit node provides the audit information to be verified to the supervision node with the authority to supervise the audit information according to actual needs. The functions of the audit information to be verified include but are not limited to issuing reports, providing proofs, and undergoing verification. Among them, the audit information to be verified is part of the initial audit information. Taking the audit log as the audit information to be verified as an example, when a certain audit log is included in the corresponding auditor's report, the supervisor needs to verify the authenticity of this log. In addition, if the auditor's report includes the audit logs of one day, the supervisor needs to verify the authenticity and integrity of the logs of this day.
[0124] It should be noted that hashing the auditor's audit information to be verified through the unique independent salt value of the verifier can ensure the confidentiality of the audit information and improve the security of the audit information.
[0125] Furthermore, the audit system detects whether the target verification node has the target authority through the verification node, where the target authority indicates that the target verification node has the authority to obtain the audit information to be verified from the audit node; when the target verification node has the target authority, the verification node obtains the audit information to be verified through the audit node; the verification node performs a hashing calculation on the audit information to be verified based on the public salt value to obtain the processed verification data; the verification node performs a second hashing calculation on the processed verification data based on the independent salt value to obtain the second verification data.
[0126] In this embodiment, the verification node is used to detect whether the target verification node has the target permission. When the target verification node has the target permission, it is determined that the second verification data is obtained through direct verification. For example, as Figure 4 shown, the audit system runs to generate initial audit information, and then sends the initial audit information to the audit node, calculates the first hash value of the initial audit information, then calculates the second hash of the initial audit information to obtain the first verification data. The audit system sends the first verification data to the verification node and stores the first verification data in a structured manner. The audit node publishes the audit information to be verified to the verification node. The verification node calculates the hash value corresponding to the audit information to be verified to obtain the second verification data. The verification node verifies the authenticity of the audit information to be verified based on the first verification data and the second verification data. The specific steps are as follows:
[0127] (1) Auditor A1 publishes a certain piece of initial audit information to the verifier:
[0128] (id,text)
[0129] (2) Use a common salt value to perform a hash operation on the initial audit information to obtain the first hash value:
[0130] ([id] 1 ,[text] 1 )
[0131] (3) Each verifier uses an independent salt value to perform a hash calculation on the first hash value:
[0132] [id] 2 =sha([id] 1 ,s1)
[0133] [text] 2 =sha([text] 1 ,s1)
[0134] With the above hash calculation results, the second verification data ([id] 2 ,[text] 2 ) is obtained.
[0135] It should be noted that by directly verifying the audit result by the verifier, the verifier can know the clear text of the audit log published by the auditor and directly verify the audit log, which can improve the verification efficiency of the audit information.
[0136] Further, when the target verification node does not have the target permission, the verification node obtains the audit information to be verified after the first hashing through the supervision node, where the supervision node is used to receive the audit information to be verified sent by the audit node, and perform hashing calculation on the audit information to be verified based on the public salt value to obtain the processed audit information to be verified; the verification node performs a second hashing calculation on the processed audit information to be verified based on the independent salt value to obtain the second verification data.
[0137] In this embodiment, when the target verification node does not have the target permission, it is determined to obtain the second verification data through indirect verification. As Figure 3 shown, the audit system runs to generate the initial audit information, then sends the initial audit information to the audit node, calculates the first hash value of the initial audit information, then calculates the second hash of the initial audit information to obtain the first verification data, the system sends the first verification data to the verification node, stores the first verification data structurally, the audit node announces the audit information to be verified to the supervision node, and the supervision node provides the hash value corresponding to the audit information to be verified to the verification node to obtain the second verification data, and the verification node verifies the authenticity of the audit information to be verified according to the first verification data and the second verification data.
[0138] Optionally, the verifier obtains the second verification data through the following steps:
[0139] (1) The auditor A1 announces the audit information to be verified to the supervisor:
[0140] (id,text)
[0141] (2) Perform hashing operation on this information using the public salt value to obtain the first hash value:
[0142] ([id] 1 , [text] 1 )
[0143] (3) The supervisor only provides the verifier with the hash result shown in step (2), and the verifier performs hashing calculation using the independent salt value to obtain the second verification data:
[0144] ([id] 2 , [text] 2 )
[0145] It should be noted that by indirectly verifying the audit result through the supervisor, the verifier cannot know the plaintext of the audit log announced by the auditor, which further improves the security of the audit information.
[0146] Optionally, the supervision node performs the first hash calculation on the audit information to be verified through the above formula (2). When the audit information to be verified is a single log, the processed audit information to be verified is expressed as:
[0147] ([id] 1 , [text] 1 )
[0148] When the audit information to be verified is a log within a certain range, taking the logs of a whole year as an example, the processed audit information to be verified is expressed as:
[0149] (id year , text year )-->([id year 1 , [text year 1 )
[0150] Furthermore, based on the hash value obtained from the received first hash calculation, the verification node performs a second hash calculation on the hash value obtained from the first hash calculation through the above formula (3). When the audit information to be verified is a single log, the second verification data is expressed as:
[0151] ([id] 1 , [text] 1 )-->([id] 2 , [text] 2 )
[0152] When the audit information to be verified is a log within a certain range, taking the logs of a whole year as an example, the second verification data is expressed as:
[0153] ([id year 1 , [text year 1 )-->([id year 2 , [text year 2 )
[0154] In an optional embodiment, the verification node parses the audit information to be verified to obtain the index identifier and the content part corresponding to the audit information to be verified; the verification node performs hash calculations on the index identifier and the content part respectively based on the common salt value to obtain the first hash value of the index identifier and the first hash value of the content part. Among them, the processed verification data includes at least the first hash value of the index identifier and the first hash value of the content part.
[0155] Further, the verification node performs hash calculations on the first hash value of the index identifier and the first hash value of the content part respectively based on independent salt values to obtain the second hash value of the index identifier and the second hash value of the content part. Among them, the second verification data at least includes the second hash value of the index identifier and the second hash value of the content part.
[0156] Optionally, the second verification data is obtained through hash calculation in the following specific way: The verification node parses the audit information to be verified to obtain the corresponding index identifier and content part, and then performs hash calculations on the index identifier and the audit data respectively based on the common salt value to obtain the first hash value of the index identifier and the first hash value of the content part. Furthermore, hash calculations are performed on the first hash value of the index identifier and the first hash value of the content part respectively based on independent salt values to obtain the second hash value of the index identifier and the second hash value of the content part. The second verification data is obtained based on the second hash value of the index identifier and the second hash value of the content part.
[0157] It should be noted that by splitting the audit log into a number and the body text and performing hashing respectively. Hashing the numbers and storing them in a shuffled order effectively hides the association information between each piece of audit data, further improving the security of the audit information.
[0158] In steps S106 - S108, the verification node obtains a comparison result by comparing the second verification data with the first verification data, and verifies whether the audit information to be verified truly originates from the initial audit information based on the comparison result, and performs integrity verification and anti-tampering verification. When the comparison result is the same as the audit information to be verified, it is determined that the audit information to be verified is legal information. When the comparison result is different from the audit information to be verified, it is determined that the audit information to be verified is illegal information.
[0159] Further, the verification node parses the second verification data to obtain the index identifier and content part of the second verification data; the verification node indexes the index tree based on the index identifier of the second verification data to obtain the candidate verification data corresponding to the index identifier of the second verification data; the verification node compares the candidate verification data with the target verification data to obtain a comparison result.
[0160] Optionally, for the verification node, the second verification data it obtains is partial key-value pairs, such as ([id] 2 , [text] 2 ). By parsing the second verification data into the index identifier [id] 2 , the content part [text] 2 , and then retrieving 2 based on the index identifier [id] Figure 6For the index tree shown, find the candidate verification data stored in the leaf node, i.e., the value part, and compare the value part of the leaf node with the target verification data [text] 2 to check if they are the same and obtain the comparison result.
[0161] Furthermore, when the audit information to be verified is a single piece of audit information and the content part of the second verification data is inconsistent with the content part of the first verification data, the verification node determines that there is an illegal change in the audit information to be verified; when the audit information to be verified is multiple pieces of audit information and the content part of the second verification data is inconsistent with the content part of the first verification data, the verification node determines that there is an illegal change or information loss in the audit information to be verified.
[0162] Optionally, when the audit information to be verified is a single piece of audit information and the content part [text] 2 of the second verification data is inconsistent with the content part of the leaf node value (the content part of the first verification data), it is determined that the audit information to be verified has been tampered with.
[0163] Optionally, when the audit information to be verified is multiple pieces of audit information and the content part [text] 2 of the second verification data is inconsistent with the content part of the leaf node value (the content part of the first verification data), it is determined that the audit information to be verified has been tampered with or is incomplete (information loss).
[0164] It should be noted that by verifying whether the audit information to be verified is legal information based on the comparison result, the supervision and review efficiency of audit information is efficiently improved on the basis of ensuring the privacy of audit information.
[0165] Based on the solution defined in the above steps S102 to S108, it can be learned that in the embodiment of the present invention, the verification data is obtained by performing a hash calculation on the audit information based on the hash salt value. By comparing the verification data, it is verified whether the information fed back after the audit node audits the initial audit information is legal information. First, the verification node obtains the first verification data and the audit information to be verified, then the verification node obtains the second verification data, and then the verification node compares the second verification data with the first verification data to obtain a comparison result; finally, the verification node verifies whether the audit information to be verified is legal information according to the comparison result, where the first verification data is obtained by the audit system performing a hash calculation on the initial audit information based on the public salt value and the independent salt value, the audit information to be verified is the data fed back after the audit node audits the initial audit information, the public salt value is a random sequence shared by multiple verification nodes and audit nodes, the independent salt value is a random sequence owned by the target verification node, different verification nodes have different independent salt values, the second verification data is obtained by performing a hash calculation on the audit information to be verified at least based on the independent salt value, and the legal information indicates that the audit node does not change the initial audit information during the process of auditing the initial audit information.
[0166] It is easy to notice that in the above process, by performing a hash calculation on the initial audit information based on the public salt value, the initial audit information can be converted into a code with a fixed length, reducing the amount of calculation during verification, and the irreversibility of the hash process can be used to protect the privacy of the initial audit information. In addition, the public salt value is shared by the verification nodes and the audit nodes, which can protect and streamline the audit information; the independent salt value is independently owned by each verification node and can be used to ensure the independence of the verification results among the verification nodes. Therefore, even if the verifier corresponding to a verification node repudiates, the verification results of multiple people can be used to overthrow it, achieving the purpose of improving the security of the verification process.
[0167] Thus, through the technical solution of the present invention, the purpose of verifying whether the information fed back after the audit node audits the initial audit information is legal information is achieved, thereby realizing the technical effect of improving the security of the verification process, and further solving the technical problem of low security of audit information existing in the related technology during the process of verifying the data fed back by the auditor.
[0168] As can be seen from the above, in the audit system, to ensure the reliability and authenticity of the audit by the audit administrator, for any audit information provided by the audit administrator, the present application provides zero-knowledge verification for other administrators, that is, although other administrators do not have the permission to view the audit information, they have the right to verify whether any audit information provided by the audit administrator is true, and at the same time, they will not obtain any more audit information. On the basis of protecting the privacy of audit information, reliable supervision is provided for the audit of auditors. At the same time, means such as double hashing and Merkle trees are adopted to further enhance the security of the verification process and improve the verification efficiency.
[0169] Embodiment 2
[0170] Based on Embodiment 1 of the present invention, an embodiment of a verification device for audit information is further provided. When the device runs, it executes the verification method for audit information in Embodiment 1 above. Among them, Figure 7 is a schematic diagram of an optional verification device for audit information according to an embodiment of the present invention, as Figure 7 shown, the device includes: a first verification data acquisition module 701, a second verification data acquisition module 703, a data comparison module 705, and an information verification module 707.
[0171] The first verification data acquisition module 701 is used for the verification node to acquire the first verification data and the audit information to be verified. Among them, the first verification data is obtained by the audit system through hashing the initial audit information based on a common salt value and an independent salt value. The audit information to be verified is the data fed back by the audit node after auditing the initial audit information. The common salt value is a random sequence shared by multiple verification nodes and audit nodes, and the independent salt value is a random sequence possessed by the target verification node. Different verification nodes have different independent salt values. The second verification data acquisition module 703 is used for the verification node to acquire the second verification data. Among them, the second verification data is obtained by hashing the audit information to be verified at least based on the independent salt value. The data comparison module 705 is used for the verification node to compare the second verification data with the first verification data to obtain a comparison result. The information verification module 707 is used for the verification node to verify whether the audit information to be verified is legal information according to the comparison result. Among them, the legal information indicates that the audit node has not changed the initial audit information during the process of auditing the initial audit information.
[0172] Optionally, the first verification data acquisition module includes: an initial audit information parsing unit, an initial audit information first hash calculation unit, an initial audit information second hash calculation unit, a first verification data sending unit, and a salt value distribution unit. The initial audit information parsing unit is used for the audit system to generate initial audit information and parse the initial audit information to obtain the index identifier and the content part corresponding to the initial audit information; the initial audit information first hash calculation unit is used for performing salted hash calculation on the index identifier based on the public salt value to obtain the first hash value of the index identifier; performing salted hash calculation on the content part based on the public salt value to obtain the first hash value of the content part; the initial audit information second hash calculation unit is used for the audit system to perform a second hash calculation on the first hash value of the index identifier based on the independent salt value to obtain the index part of the first verification data; performing a second hash calculation on the first hash value of the content part based on the independent salt value to obtain the content part of the first verification data; the first verification data sending unit is used for the audit system to send the first verification data to the verification node, and the verification node stores the first verification data sent by the audit system and constructs an index tree based on the index part of the first verification data; the salt value distribution unit is used for the audit system to send the initial audit information to the audit nodes and distribute the public salt value to all the verification nodes and distribute the independent salt value to each verification node separately.
[0173] Furthermore, the verification device for audit information further includes: a first hash value summarization unit and a second hash calculation unit. The first hash value summarization unit is used for the audit system to summarize the first hash value of the index identifier of the initial audit information within a preset time period and the first hash value of the content part of the initial audit information within a preset duration at intervals of a preset time to obtain the summarized first hash value of the index identifier and the summarized first hash value of the content part; the second hash calculation unit is used for the audit system to perform hash calculation on the summarized first hash value of the index identifier and the summarized first hash value of the content part respectively based on the independent salt value to obtain the second hash value of the index identifier and the second hash value of the content part, wherein the first verification data includes at least the second hash value of the index identifier and the second hash value of the content part.
[0174] Another optional, the verification device for audit information further includes: an index tree construction module, a verification data parsing module, an index identifier decomposition module, a node position determination module, and a node determination module. The index tree construction module is used to construct an index tree corresponding to the target verification node through verification nodes, where the index tree consists of multiple nodes; the verification data parsing module is used to parse the first verification data by the verification nodes to obtain a target index identifier and target verification data; the index identifier decomposition module is used to decompose the target index identifier by the verification nodes to obtain multiple characters; the node position determination module is used to determine the node position of the current character in the index tree by the verification nodes according to the position of the current character among the multiple characters, where the current character is any one of the multiple characters; the node determination module is used to determine a target node from the multiple nodes by the verification nodes and store the target verification data in the target node, where the target node is the next node of the node corresponding to the last character among the multiple characters.
[0175] Optionally, the second verification data acquisition module includes: a permission detection unit, a first acquisition unit, a first hash calculation unit, and a second hash calculation unit. The permission detection unit is used to detect by the verification nodes of the audit system whether the target verification node has a target permission, where the target permission indicates that the target verification node has the permission to obtain the audit information to be verified from the audit node; the acquisition unit is used to obtain the audit information to be verified by the verification nodes through the audit node when the target verification node has the target permission; the first hash calculation unit for the audit information to be verified is used to perform a hash calculation on the audit information to be verified by the verification nodes based on a common salt value to obtain processed verification data; the second hash calculation unit for the audit information to be verified is used to perform a second hash calculation on the processed verification data by the verification nodes based on an independent salt value to obtain the second verification data.
[0176] Another optional, the verification device for audit information further includes: a second acquisition unit and a second hash calculation unit. The second acquisition unit is used to obtain the audit information to be verified after the first hash by the verification nodes through the supervision node when the target verification node does not have the target permission, where the supervision node is used to receive the audit information to be verified sent by the audit node and perform a hash calculation on the audit information to be verified based on a common salt value to obtain the processed audit information to be verified; the second hash calculation unit is used to perform a second hash calculation on the processed audit information to be verified by the verification nodes based on an independent salt value to obtain the second verification data.
[0177] Optionally, the first hash calculation unit includes: an audit information parsing sub-module and a first hash calculation sub-module. The audit information parsing sub-module is used for the verification node to parse the audit information to be verified, and obtain the index identifier and the content part corresponding to the audit information to be verified; the first hash calculation sub-module is used for the verification node to perform hash calculations on the index identifier and the content part respectively based on the common salt value, and obtain the first hash value of the index identifier and the first hash value of the content part. Among them, the processed verification data at least includes the first hash value of the index identifier and the first hash value of the content part.
[0178] Optionally, the second hash calculation unit includes: a second hash calculation sub-module, which is used for the verification node to perform hash calculations on the first hash value of the index identifier and the first hash value of the content part respectively based on the independent salt value, and obtain the second hash value of the index identifier and the second hash value of the content part. Among them, the second verification data at least includes the second hash value of the index identifier and the second hash value of the content part.
[0179] In this embodiment, the second verification data is obtained through hash calculation in the following specific manner: the verification node parses the audit information to be verified to obtain the corresponding index identifier and content part, then performs hash calculations on the index identifier and the audit data respectively based on the common salt value, obtains the first hash value of the index identifier and the first hash value of the content part, and then performs hash calculations on the first hash value of the index identifier and the first hash value of the content part respectively based on the independent salt value, obtains the second hash value of the index identifier and the second hash value of the content part, and obtains the second verification data based on the second hash value of the index identifier and the second hash value of the content part.
[0180] Optionally, the data comparison module further includes: a second verification data parsing unit, an indexing unit, and a comparison unit. The second verification data parsing unit is used for the verification node to parse the second verification data and obtain the index identifier and the content part of the second verification data; the indexing unit is used for the verification node to index the index tree based on the index identifier of the second verification data and obtain the candidate verification data corresponding to the index identifier of the second verification data; the comparison unit is used for the verification node to compare the candidate verification data with the target verification data and obtain a comparison result.
[0181] Further, the information verification module includes: a single-piece information verification unit and a multi-piece information verification unit. The single-piece information verification unit is configured to determine that there is an illegal change in the audit information to be verified when the audit information to be verified is a single-piece audit information and the content part of the second verification data is inconsistent with the content part of the first verification data; the multi-piece information verification unit is configured to determine that there is an illegal change or information loss in the audit information to be verified when the audit information to be verified is multi-piece audit information and the content part of the second verification data is inconsistent with the content part of the first verification data.
[0182] Embodiment 3
[0183] On the other hand, according to an embodiment of the present invention, there is also provided a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the above-mentioned verification method of audit information when running.
[0184] Embodiment 4
[0185] On the other hand, according to an embodiment of the present invention, there is also provided an electronic device, wherein Figure 8 is a schematic diagram of an optional electronic device according to an embodiment of the present invention, as Figure 8 shown, the electronic device includes one or more processors; a memory for storing one or more programs, when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement for running the program, wherein the program is configured to execute the above-mentioned verification method of audit information when running.
[0186] Embodiment 5
[0187] On the other hand, according to an embodiment of the present invention, there is also provided a computer program product including computer programs / instructions, and the computer programs / instructions implement the above-mentioned verification method of audit information when executed by a processor.
[0188] The above serial numbers of the embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments.
[0189] In the above embodiments of the present invention, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0190] In several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.
[0191] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0192] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0193] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present invention. The aforementioned storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs, etc., which can store program codes.
[0194] The above is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A method for verifying audit information, characterized in that, Including: The verification node obtains first verification data and the audit information to be verified. Among them, the first verification data is obtained by the audit system through hashing calculation on the initial audit information based on a common salt value and an independent salt value. The audit information to be verified is the data fed back by the audit node after auditing the initial audit information. The common salt value is a random sequence shared by multiple verification nodes and the audit node, and the independent salt value is a random sequence possessed by the target verification node. Different verification nodes have different independent salt values; The verification node obtains second verification data. Among them, the second verification data is obtained by hashing calculation on the audit information to be verified at least based on the independent salt value; The verification node compares the second verification data with the first verification data to obtain a comparison result; The verification node verifies whether the audit information to be verified is legal information according to the comparison result. Among them, the legal information indicates that the audit node has not changed the initial audit information during the process of auditing the initial audit information.
2. The method according to claim 1, wherein The audit system generates initial audit information and parses the initial audit information to obtain the index identifier and content part corresponding to the initial audit information; The audit system performs salted hashing calculation on the index identifier based on the common salt value to obtain the first hash value of the index identifier; the audit system performs salted hashing calculation on the content part based on the common salt value to obtain the first hash value of the content part; The audit system performs a second hashing calculation on the first hash value of the index identifier based on the independent salt value to obtain the index part of the first verification data; The audit system performs a second hashing calculation on the first hash value of the content part based on the independent salt value to obtain the content part of the first verification data; The audit system sends the first verification data to the verification node. The verification node stores the first verification data sent by the audit system and constructs an index tree based on the index part of the first verification data; The audit system also sends the initial audit information to the audit node and distributes the common salt value to all verification nodes and distributes the independent salt value to each verification node separately.
3. The method according to claim 2, wherein The method further includes: The audit system summarizes the first hash value of the index identifier of the initial audit information within a preset duration and the first hash value of the content part of the initial audit information at preset intervals to obtain the summarized first hash value of the index identifier and the summarized first hash value of the content part; The audit system performs hashing calculation on the summarized first hash value of the index identifier and the summarized first hash value of the content part respectively based on the independent salt value to obtain the second hash value of the index identifier and the second hash value of the content part. Among them, the first verification data at least includes the second hash value of the index identifier and the second hash value of the content part.
4. The method according to claim 1, wherein The verification node obtains the second verification data, including: The verification node detects whether the target verification node has a target permission, where the target permission indicates that the target verification node has the permission to obtain the audit information to be verified from the audit node; When the target verification node has the target permission, the verification node obtains the audit information to be verified through the audit node; The verification node performs a hash calculation on the audit information to be verified based on the common salt value to obtain processed verification data; The verification node performs a second hash calculation on the processed verification data based on the independent salt value to obtain the second verification data.
5. The method according to claim 4, wherein The method further includes: When the target verification node does not have the target permission, the verification node obtains the audit information to be verified after the first hash through the supervision node, where the supervision node is used to receive the audit information to be verified sent by the audit node and perform a hash calculation on the audit information to be verified based on the common salt value to obtain the processed audit information to be verified; The verification node performs a second hash calculation on the processed audit information to be verified based on the independent salt value to obtain the second verification data.
6. The method according to claim 5, wherein Performing a hash calculation on the audit information to be verified based on the common salt value to obtain processed verification data includes: The verification node parses the audit information to be verified to obtain the index identifier and the content part corresponding to the audit information to be verified; The verification node performs a hash calculation on the index identifier and the content part respectively based on the common salt value to obtain the first hash value of the index identifier and the first hash value of the content part, where the processed verification data at least includes the first hash value of the index identifier and the first hash value of the content part.
7. The method according to claim 6, wherein The verification node performs a second hash calculation on the processed verification data based on the independent salt value to obtain the second verification data, including: The verification node performs a hash calculation on the first hash value of the index identifier and the first hash value of the content part respectively based on the independent salt value to obtain the second hash value of the index identifier and the second hash value of the content part, where the second verification data at least includes the second hash value of the index identifier and the second hash value of the content part.
8. The method according to claim 7, wherein Before comparing the second verification data and the first verification data to obtain a comparison result, the method further includes: The verification node constructs an index tree corresponding to the target verification node, where the index tree is composed of multiple nodes; The verification node parses the first verification data to obtain a target index identifier and target verification data; The verification node decomposes the target index identifier to obtain multiple characters; The verification node determines the node position of the current character in the index tree according to the position of the current character in the multiple characters, where the current character is any one of the multiple characters; The verification node determines a target node from the multiple nodes and stores the target verification data in the target node, where the target node is the next node of the node corresponding to the last character among the multiple characters.
9. The method according to claim 8, wherein Compare the second verification data with the first verification data to obtain a comparison result, including: The verification node parses the second verification data to obtain the index identifier and content part of the second verification data; The verification node indexes the index tree based on the index identifier of the second verification data to obtain candidate verification data corresponding to the index identifier of the second verification data; The verification node compares the candidate verification data with the target verification data to obtain the comparison result.
10. An audit information verification device, characterized in that Including: A first verification data acquisition module, configured to enable a verification node to acquire first verification data and audit information to be verified, where the first verification data is obtained by an audit system performing a hash calculation on initial audit information based on a common salt value and an independent salt value, the audit information to be verified is data fed back by an audit node after auditing the initial audit information, the common salt value is a random sequence shared by multiple verification nodes and the audit node, the independent salt value is a random sequence possessed by a target verification node, and different verification nodes have different independent salt values; A second verification data acquisition module, configured to enable the verification node to acquire second verification data, where the second verification data is obtained by performing a hash calculation on the audit information to be verified at least based on the independent salt value; A data comparison module, configured to enable the verification node to compare the second verification data with the first verification data to obtain a comparison result; An information verification module, configured to enable the verification node to verify whether the audit information to be verified is legal information according to the comparison result, where the legal information indicates that the audit node has not changed the initial audit information during the process of auditing the initial audit information.
Citation Information
Patent Citations
Systems and methods for managing digital identities
CN108701276A
Account key verification method and device and computer storage medium
CN111611576A