A method and system for data verification offloading based on a distributed network
By creating a data shell for data in a distributed network and performing signature verification, the problem of data not being able to be uniformly managed and verified in a distributed network is solved, achieving real-time management and improved security.
Patent Information
- Application Number
- CN202411119832.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-15
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-08-15
AI Technical Summary
In a distributed network environment, existing technologies cannot achieve unified management and effective verification of data, making data dissemination difficult to control and increasing the risk of data leakage and misuse.
By creating a data shell for data in a distributed network, which includes the original data, its data structure, and digital signature, the data is published to the data receiver for parsing and verification. If the signature is abnormal, it is unloaded; otherwise, the data is verified and released.
It enables real-time verification and offloading of data in distributed networks, improving data management capabilities and security, and preventing data from being intercepted before it is released during the parsing process.
Smart Images

Figure CN119094130B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data verification offloading, and particularly relates to a data verification offloading method and system based on a distributed network. BACKGROUND
[0002] With the rapid development of information technology, especially under the promotion of technologies such as cloud computing, big data, and the Internet of Things, the generation, storage, processing, and transmission of data have undergone profound changes. Distributed network systems, as an important infrastructure supporting these technologies, have played a key role in promoting data sharing and collaborative work due to their efficiency and scalability. However, while enjoying the convenience brought by distributed networks, challenges in data management and security verification have also arisen.
[0003] Existing Windows uninstall software: As part of the traditional desktop operating system, Windows uninstall software allows users to manually select and remove software programs that are no longer needed. Although this method is direct and effective, it is limited to a single system and cannot be uniformly managed across multiple devices or distributed network environments, lacking the ability to centrally control from a global perspective.
[0004] Existing batch program uninstallation by housekeeper: In order to improve user experience and efficiency, some third-party software management tools provide batch uninstallation functions, which can handle multiple software uninstallation tasks at once. Although this simplifies the operation process to some extent, it is still limited to single-machine operation and cannot adapt to the complex needs of multi-node and multi-user environments in distributed networks.
[0005] Therefore, the current data verification offloading method has the following problems:
[0006] 1. Unable to uniformly control data dissemination: In a distributed network environment, data storage and transmission often span multiple nodes and servers, making unified control of data extremely difficult. Existing technical solutions often focus on data management at a single node, ignoring the monitoring and scheduling of global data flow, making it difficult to effectively control data dissemination and increasing the risk of data leakage and misuse.
[0007] 2. Unable to effectively verify the publisher of data in a distributed network: In a distributed network, data publishers may come from different nodes or systems, and their identity and credibility are difficult to verify directly. Traditional authentication mechanisms are often not applicable in a distributed environment, making it difficult to guarantee the authenticity and source reliability of data. This not only affects the normal use of data, but also may cause trust crises and security problems. SUMMARY
[0008] The technical problem solved by the present application is to provide a data verification offloading method and system based on a distributed network, which can improve the data management and control capability in the distributed network and improve the security of data publishing.
[0009] To solve the above technical problems, the technical solution adopted by the present application is:
[0010] A data verification offloading method based on a distributed network comprises the following steps:
[0011] A data shell is established for the original data of each node data end by the distributed network, the data shell comprises the original data, the data structure and the digital signature of the original data, and the data shell is published to a data receiving end;
[0012] The received data shell is parsed by the data receiving end, the digital signature of the data shell is obtained, it is judged whether the digital signature contains abnormal information, if yes, the data shell is unloaded, otherwise, the data is verified according to the data structure in the data shell and the original data is released.
[0013] To solve the above technical problems, another technical solution adopted by the present application is:
[0014] A data verification offloading system based on a distributed network comprises a distributed network and a data receiving end:
[0015] A data shell is established for the original data of each node data end by the distributed network, the data shell comprises the original data, the data structure and the digital signature of the original data, and the data shell is published to a data receiving end;
[0016] The received data shell is parsed by the data receiving end, the digital signature of the data shell is obtained, it is judged whether the digital signature contains abnormal information, if yes, the data shell is unloaded, otherwise, the data is verified according to the data structure in the data shell and the original data is released.
[0017] The beneficial effects of the present application are that a data shell is established for the original data of each node data end by the distributed network, wherein the data shell comprises the original data, the data structure and the digital signature thereof, and the data shell is published to the data receiving end, so that the data in the distributed network can be uniformly managed by establishing the data shell. The received data shell is parsed by the data receiving end, the digital signature of the data shell is obtained, if the digital signature contains abnormal information, the data shell is unloaded, otherwise, the data is checked and the original data is released according to the data structure in the data shell, so that the data can be verified and unloaded instantly, so as to achieve the effect of instant management. And when the data or the signature in the data shell does not match, the data will be unloaded, which is equivalent to that the data shell has not been released in the parsing process, and the internal data has been intercepted before being executed, so that the data management capability in the distributed network can be improved, and the security of data publishing can be improved. BRIEF DESCRIPTION OF DRAWINGS
[0018] Figure 1 A flowchart of a data verification and unloading method based on a distributed network according to an embodiment of the present application;
[0019] Figure 2 A schematic diagram of a data verification and unloading system based on a distributed network according to an embodiment of the present application;
[0020] Figure 3 A structural schematic diagram of a data shell according to an embodiment of the present application;
[0021] Figure 4 A flowchart of data parsing according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] To explain the technical content, the achieved purposes and effects of the present application in detail, the following will be explained in combination with the embodiments and the drawings.
[0023] Please refer to Figure 1 The embodiment of the present application provides a data verification and unloading method based on a distributed network, comprising the following steps:
[0024] A data shell is established for the original data of each node data end by the distributed network, wherein the data shell comprises the original data, the data structure and the digital signature thereof, and the data shell is published to the data receiving end;
[0025] The received data shell is parsed by the data receiving end, the digital signature of the data shell is obtained, it is judged whether the digital signature contains abnormal information, if yes, the data shell is unloaded, otherwise, the data is checked and the original data is released according to the data structure in the data shell.
[0026] From the above description, the beneficial effects of the present application are that a data shell is established for the original data of each node data end by the distributed network, wherein the data shell includes the original data, the data structure and the digital signature thereof, and the data shell is published to the data receiving end, so that the data in the distributed network can be uniformly managed by establishing the data shell. The received data shell is parsed by the data receiving end, the digital signature of the data shell is obtained, if the digital signature contains abnormal information, the data shell is unloaded, otherwise, the data is checked according to the data structure in the data shell and the original data is released, so that the data can be verified and unloaded instantly, so as to achieve the effect of instant management. And when the data or the signature in the data shell does not match, the data will be unloaded, which is equivalent to that the data shell has not been released in the parsing process, and the internal data has been intercepted before being executed, so as to improve the data management and control ability in the distributed network and improve the security of data publishing.
[0027] Further, a data shell is established for the original data of each node data end by the distributed network, and the data shell includes the original data, the data structure and the digital signature thereof, including:
[0028] For the original data of each node in the distributed network, the data type of the original data is recorded, and the data information of the original data is stored, the data type and the data information of the original data are taken as the data structure of the original data, the data type includes the system environment to which the original data belongs and the corresponding format, and the data information includes the data size and the data check information;
[0029] For the original data of each node in the distributed network, a digital signature is issued for the original data according to the data type of the original data;
[0030] The data shell is obtained in combination with the original data, the data structure and the digital signature thereof.
[0031] From the above description, when the data shell is set for the data, the system environment to which the data belongs and the corresponding format, the data size, the data check information and the signature of the data are fully considered, which can be applied to the data in different system environments in the distributed network, and further ensures the uniform management of the data.
[0032] Further, the digital signature is issued for the original data according to the data type of the original data, including:
[0033] The digital signature of the corresponding data type is issued for the original data according to the information of the data publishing end and the behavior data of the original data.
[0034] From the above description, according to the information of the data publishing end and the behavior data of the original data, a digital signature of a corresponding data type is issued for the original data, so that the data and the data publishing end with irregular behavior can be effectively limited during subsequent analysis, and the data security is improved.
[0035] Further, judging whether the digital signature contains abnormal information comprises:
[0036] If the digital signature contains preset irregular behavior, it is determined that the digital signature contains abnormal information, otherwise, it is determined that the digital signature does not contain abnormal information.
[0037] From the above description, during analysis, the data with irregular behavior can be limited according to the behavior information in the digital signature, and the data security can be effectively guaranteed.
[0038] Further, according to the data structure in the data shell, the data is checked and the original data is released, comprising:
[0039] According to the data checking information in the data shell, the original data is checked, and the original data is compared byte by byte, if the original data contains preset restriction information, the data shell is unloaded, otherwise, the original data is released to the execution space.
[0040] From the above description, after the digital signature verification passes, the data also needs to be checked, and the data security is further improved.
[0041] Please refer to Figure 2 Another embodiment of the application provides a system for data verification and unloading based on a distributed network, comprising a distributed network and a data receiving end:
[0042] The distributed network establishes a data shell for the original data of each node data end, the data shell comprises the original data, its data structure and a digital signature, and the data shell is published to the data receiving end;
[0043] The data receiving end analyzes the received data shell, obtains the digital signature of the data shell, judges whether the digital signature contains abnormal information, if yes, the data shell is unloaded, otherwise, according to the data structure in the data shell, the data is checked and the original data is released.
[0044] From the above description, the beneficial effects of the present application are that a data shell is established for the original data of each node data end by the distributed network, wherein the data shell includes the original data, the data structure and the digital signature thereof, and the data shell is published to the data receiving end, so that the data in the distributed network can be uniformly managed by establishing the data shell. The received data shell is parsed by the data receiving end, the digital signature of the data shell is obtained, if the digital signature contains abnormal information, the data shell is unloaded, otherwise, the data is checked according to the data structure in the data shell and the original data is released, so that the data can be verified and unloaded instantly, so as to achieve the effect of instant management. And when the data or the signature in the data shell does not match, the data will be unloaded, which is equivalent to that the data shell has not been released in the parsing process, and the internal data has been intercepted before being executed, so as to improve the data management and control ability in the distributed network and improve the security of data publishing.
[0045] Further, the data shell is established for the original data of each node data end by the distributed network, and the data shell includes the original data, the data structure and the digital signature thereof, including:
[0046] For the original data of each node in the distributed network, the data type of the original data is recorded, and the data information of the original data is stored, the data type and the data information of the original data are taken as the data structure of the original data, the data type includes the system environment to which the original data belongs and the corresponding format, and the data information includes the data size and the data check information;
[0047] For the original data of each node in the distributed network, a digital signature is issued for the original data according to the data type of the original data;
[0048] The data shell is obtained in combination with the original data, the data structure and the digital signature thereof.
[0049] From the above description, when the data shell is set for the data, the system environment to which the data belongs and the corresponding format, the data size, the data check information and the signature of the data are fully considered, which can be applied to the data in different system environments in the distributed network, and further ensures the uniform management of the data.
[0050] Further, the digital signature is issued for the original data according to the data type of the original data, including:
[0051] The digital signature of the corresponding data type is issued for the original data according to the information of the data publishing end and the behavior data of the original data.
[0052] From the above description, according to the information of the data publishing end and the behavior data of the original data, a digital signature of a corresponding data type is issued for the original data, so that the data and the data publishing end with irregular behavior can be effectively limited during subsequent analysis, and the data security is improved.
[0053] Further, judging whether the digital signature contains abnormal information comprises:
[0054] If the digital signature contains a preset irregular behavior, it is determined that the digital signature contains abnormal information, otherwise, it is determined that the digital signature does not contain abnormal information.
[0055] From the above description, during analysis, the data with irregular behavior can be limited according to the behavior information in the digital signature, and the data security can be effectively guaranteed.
[0056] Further, according to the data structure in the data shell, the data is verified and the original data is released, comprising:
[0057] According to the data verification information in the data shell, the original data is verified, and the original data is compared byte by byte, if the original data contains preset restriction information, the data shell is unloaded, otherwise, the original data is released to the execution space.
[0058] From the above description, after the digital signature verification passes, the data also needs to be verified, and the data security is further improved.
[0059] The above-mentioned data verification unloading method and system based on a distributed network are suitable for improving the data management and control ability in the distributed network, and improving the security of data publishing, which will be described below through specific implementation manners:
[0060] Embodiment one
[0061] Please refer to Figure 1 , Figure 3 and Figure 4 , a data verification unloading method based on a distributed network, comprising the steps of:
[0062] S1, a data shell is established for the original data of each node data end by a distributed network, the data shell comprises the original data, the data structure and the digital signature of the original data, and the data shell is published to a data receiving end.
[0063] S11, for the original data of each node in the distributed network, record the data type of the original data, and store the data information of the original data, the data type and the data information of the original data are taken as the data structure of the original data, the data type includes the system environment and the corresponding format to which the original data belongs, and the data information includes the data size and the data check information.
[0064] Specifically, the distributed network can pre-store the corresponding data format rules according to different categories of data system environments, for example: store the exe format and dll format in the Windows system environment, and store the apk format in the Android system environment.
[0065] Then record the system environment to which the original data of each node in the distributed network belongs and the corresponding format, store the data size and data check information of the original data.
[0066] The system environment and the corresponding format of the data, and the size and the check information of the data are taken as the data structure of the data.
[0067] S12, for the original data of each node in the distributed network, according to the behavior data of the original data, the original data is issued a digital signature of the corresponding data type.
[0068] Specifically, the distributed network issues a certificate or a digital signature according to the information of the data publishing end and the operation behavior of the original data, and the digital signature is a digital signature of the data type specified for the original data. That is, the windows system has a corresponding digital signature, and the distributed network has another signature mechanism on this basis.
[0069] In this embodiment, the digital signature is the signature of the data shell owner rather than the signature of the original data owner, because the data may have repeatability, but the data shell is unique.
[0070] S13, combining the original data and its data structure and digital signature to obtain a data shell.
[0071] Specifically, if the original data is in the exe format of the Windows system environment, the original data stored in the data shell also needs to be in the exe format of the Windows system environment.
[0072] In this way, the data publishing end can be restricted by adding a digital signature in the data shell, and the data end of the original data can be restricted by adding data information in the data shell.
[0073] It can be seen that each system environment has its own shell data type, and if it is common, it needs to be made for each system environment. In each system environment, there are corresponding system file types, and each file type has its own execution rule or reading rule, so in a distributed network, the data type needs to be informed that the data shell is suitable for what kind of system. The subsequent parser can perform related operations (execution, release, reading, etc.) on the data through the data type.
[0074] S2, the data receiving end parses the received data shell, obtains the digital signature of the data shell, judges whether the digital signature contains abnormal information, if yes, unloads the data shell, otherwise, according to the data structure in the data shell, the data is checked and the original data is released.
[0075] Among them, the parser of the data receiving end parses the received data shell, and the digital signature of the data shell is obtained. The signature containing the data publisher information and the original data operation information can be obtained from the digital signature. The parsed digital signature is restricted by the distributed network signature rule, that is, the abnormal operation behavior of the data publisher or the original data corresponding to the digital signature is limited. In addition to unloading, the method of restriction can also be deletion and disablement.
[0076] For example: AA publishes data 1 (real data), BB publishes data 2 (real data), data 1 and data 2 are of the same type, but AA violates the operation, and the distributed network signature rule records that if AA is encountered, the data will be deleted, so the data shell can be deleted according to the digital signature, that is, the parser can judge the shell through the digital signature in the data shell.
[0077] When the digital signature does not contain abnormal information, the original data is checked according to the data check information in the data shell, and the original data is compared byte by byte. If the original data contains preset restriction information, the data shell is unloaded, otherwise, the original data is released to the execution space.
[0078] Specifically, the original data is obtained according to the data shell, that is, the data is obtained according to the data type in the stored data structure, for example: exe format in Windows system environment, then the corresponding format data is parsed.
[0079] Further, the data size and data check information in the data shell are obtained, the original data is checked through the data check information, and the byte-by-byte comparison is performed. When the preset restriction information is matched, the result is returned, and the related setting conditions are executed. For example: the parser reads the real data containing the segment of data, and then executes the prohibited operation.
[0080] When the preset restriction information is not matched, the original data in the data shell is released into the execution space of the executor, a corresponding memory area is applied according to the size of the original data, and the original data is filled into the memory area, and the memory area is executed.
[0081] Therefore, in the embodiment, since the data uses the executor for execution, the shell in which the data is matched is identified as the unique identifier of the executor. When the data or signature in the shell does not match the system setting, it will be intercepted, which is equivalent to that the shell has not been released and the internal data has not been executed and is intercepted. The data information in the shell and the digital signature of the data publishing end can manage the data publishing end and the data, that is, the user operation can be limited by the data, or the program execution can be limited by the operation of the data publishing end.
[0082] Embodiment two
[0083] Please refer to Figure 2 A system for data verification and offloading based on a distributed network, comprising a distributed network and a data receiving end:
[0084] A data shell is established for the original data of each node data end by the distributed network, the data shell comprises the original data, the data structure and the digital signature of the original data, and the data shell is published to the data receiving end;
[0085] Among them, for the original data of each node in the distributed network, the data type of the original data is recorded, and the data information of the original data is stored, the data type and the data information of the original data are taken as the data structure of the original data, the data type comprises the system environment to which the original data belongs and the corresponding format, and the data information comprises the data size and the data verification information; For the original data of each node in the distributed network, a digital signature of the corresponding data type is issued for the original data according to the information of the data publishing end and the behavior data of the original data; The data shell is obtained by combining the original data, the data structure and the digital signature.
[0086] The data shell received by the data receiving end is analyzed to obtain the digital signature of the data shell, it is judged whether the digital signature contains abnormal information, if yes, the data shell is unloaded, otherwise, the data verification and the original data release are performed according to the data structure in the data shell:
[0087] If the preset violation behavior is contained in the digital signature, it is determined that the digital signature contains abnormal information; otherwise, it is determined that the digital signature does not contain abnormal information, the original data is checked according to the data checking information in the data shell, the original data is compared byte by byte, if the preset restriction information is contained in the original data, the data shell is unloaded, otherwise, the original data is released to the execution space.
[0088] In summary, the present application provides a kind of data verification unloading method and system based on distributed network, and the data shell of the original data of each node data end is established by distributed network, wherein the data shell includes original data, data structure and digital signature, and the data shell is published to data receiving end, so that the data in distributed network can be uniformly managed by establishing data shell. The digital signature of the received data shell is obtained by analyzing the received data shell by data receiving end, if the digital signature contains abnormal information, the data shell is unloaded, otherwise, the data checking and original data release are carried out according to the data structure in the data shell, so that the data can be checked and unloaded immediately, to achieve the effect of instant management. And when the data or signature in the data shell does not match, the data will be unloaded, which is equivalent to that the data shell has not been released during the analysis process, and the internal data has been intercepted before execution, which can effectively improve the data management ability in distributed network and improve the security of data release.
[0089] The above is only an embodiment of the present application, and does not limit the patent scope of the present application, any equivalent transformation or direct or indirect application in related technical field based on the content of the present application specification and drawings is also included in the patent protection scope of the present application.
Claims
1. A method for data verification offload based on a distributed network, the method comprising: The method comprises the steps of: establishing a data shell for original data of each node data end by the distributed network, the data shell comprising the original data, a data structure and a digital signature of the original data, and publishing the data shell to a data receiving end; analyzing the received data shell by the data receiving end, obtaining the digital signature of the data shell, judging whether the digital signature contains abnormal information, if yes, uninstalling the data shell, otherwise, verifying the data according to the data structure in the data shell and releasing the original data; establishing a data shell for original data of each node data end by the distributed network, the data shell comprising the original data, a data structure and a digital signature of the original data, comprising: recording the data type of the original data for the original data of each node in the distributed network, and storing the data information of the original data, taking the data type and the data information of the original data as the data structure of the original data, the data type comprising the system environment and the corresponding format to which the original data belongs, and the data information comprising the data size and the data verification information; issuing a digital signature for the original data according to the data type of the original data for the original data in the distributed network; and obtaining a data shell in combination with the original data, the data structure and the digital signature; issuing a digital signature for the original data according to the data type of the original data, comprising: issuing a digital signature of the corresponding data type for the original data according to the information of the data publishing end and the behavior data of the original data, specifically, issuing a digital signature for the original data by the distributed network according to the information of the data publishing end and the operation behavior of the original data, the digital signature being a digital signature of the data type specified for the original data; verifying the data according to the data structure in the data shell and releasing the original data, comprising: obtaining the original data according to the data type in the stored data structure, verifying the original data according to the data verification information in the data shell, comparing the original data byte by byte, if the original data contains preset restricted information, uninstalling the data shell, otherwise, releasing the original data to the execution space.
2. The method of claim 1, wherein, judging whether the digital signature contains abnormal information, comprising: if the digital signature contains a preset illegal behavior, it is determined that the digital signature contains abnormal information, otherwise, it is determined that the digital signature does not contain abnormal information.
3. A system for data verification offload based on a distributed network, the system comprising: The method comprises a distributed network and a data receiving end: establishing a data shell for original data of each node data end by the distributed network, the data shell comprising the original data, a data structure and a digital signature of the original data, and publishing the data shell to a data receiving end; analyzing the received data shell by the data receiving end, obtaining the digital signature of the data shell, judging whether the digital signature contains abnormal information, if yes, uninstalling the data shell, otherwise, verifying the data according to the data structure in the data shell and releasing the original data; The data shell of the original data of each node data end is established by the distributed network, and the data shell includes the original data, the data structure and the digital signature of the original data, including: recording the data type of the original data of each node in the distributed network, and storing the data information of the original data, taking the data type and the data information of the original data as the data structure of the original data, the data type including the system environment and the corresponding format to which the original data belongs, and the data information including the data size and the data verification information; The digital signature of the original data of each node in the distributed network is issued according to the data type of the original data; and the data shell is obtained by combining the original data, the data structure and the digital signature of the original data; The digital signature of the original data is issued according to the data type of the original data, including: issuing the digital signature of the corresponding data type for the original data according to the information of the data publishing end and the behavior data of the original data, specifically, the digital signature is issued by the distributed network according to the information of the data publishing end and the operation behavior of the original data, and the digital signature is the digital signature of the data type specified for the original data; The verification of the data and the release of the original data are performed according to the data structure in the data shell, including: obtaining the original data according to the data structure, that is, obtaining the data according to the data type in the stored data structure, verifying the original data according to the data verification information in the data shell, performing byte-by-byte comparison on the original data, if the original data contains the preset restriction information, the data shell is unloaded, otherwise, the original data is released to the execution space.
4. The system for data verification offloading based on distributed network according to claim 3, wherein, It is judged whether the digital signature contains abnormal information, including: If the digital signature contains the preset illegal behavior, it is judged that the digital signature contains abnormal information, otherwise, it is judged that the digital signature does not contain abnormal information.
Citation Information
Patent Citations
Data processing method and device, server and storage medium
CN114124404A
Method And An Apparatus For Securely Signing Application Data
US20140195811A1