An online processing method and system for information security data based on blockchain

By adopting a blockchain-based online processing method in information security data processing, the problem of data backup strategies in the prior art lack of flexibility and centralized storage is susceptible to single point of failure, flexible backup and efficient storage of data are realized, and the security and integrity of data are guaranteed.

CN119760757BActive Publication Date: 2025-06-24SHANDONG YUNQING INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510271863.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-06-24
Estimated Expiration
2045-03-10

AI Technical Summary

Technical Problem

The prior art has problems such as lack of flexibility in data backup strategies during the processing of information security data, centralized storage is susceptible to single point of failure, and it is difficult to ensure data integrity and confidentiality during data transmission.

Method used

The blockchain-based information security data online processing method is adopted, and data blocking model is built by acquiring and comparing data, key data packets are split and encrypted, and backup and on-chain processing is carried out. The blockchain's distributed storage and smart contract technology is used to dynamically adjust the backup strategy and storage nodes to ensure the security and integrity of the data.

Benefits of technology

It realizes a flexible backup strategy for data, reduces the risk of single point of failure, ensures the integrity and confidentiality of data in transmission and storage processes, and improves the ability of data recovery and storage management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119760757B_ABST
    Figure CN119760757B_ABST
Patent Text Reader

Abstract

The present invention discloses an online processing method and system for information security data based on blockchain, including: acquiring information security data and performing packaging processing to obtain key and non-key data packets, and splitting the key data packets to obtain key sub-data packets; combining the key sub-data packets with other data packets and uploading them to the blockchain; obtaining the data packets by downloading from the blockchain, and analyzing the storage situation of the non-key data packets to determine whether backup is required; if backup is required, uploading the non-key data packets to the blockchain again; judging the key sub-data packets to determine whether the data packets can be restored; if they cannot be restored, obtaining the backup data volume and the corresponding data invalid value for fitting analysis, determining the minimum backup volume, and adjusting the number of backup files of the key sub-data packets to ensure the restoration ability of the key data packets. The present invention utilizes blockchain technology to optimize the problems of data storage, integrity verification, and backup optimization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to an online processing method and system for information security data based on blockchain. Background Art

[0002] In today's digital age, the processing of information security data is of crucial importance. Traditional data processing technologies have many defects in data storage, transmission, and management.

[0003] In the prior art, there are also deficiencies in the data backup link of existing data processing methods. The commonly used fixed backup strategy lacks flexibility and cannot be intelligently adjusted according to the importance, volatility of data, and dynamic changes in the storage environment. For example, some non-critical business data may be over-backup, wasting storage resources; while for some important data, in the face of a high-risk storage environment, there may be insufficient backup, increasing the risk of data loss.

[0004] In the prior art, in terms of data storage, using a centralized storage system is vulnerable to the risk of single-point failure. Once the storage server has a hardware failure, software vulnerability, or is attacked, the data may be lost, leaked, or tampered with. Moreover, in the data transmission process, the traditional method relies on a centralized storage architecture, and the data is easily stolen or tampered with during transmission, and the integrity and confidentiality of the data are difficult to guarantee.

[0005] Therefore, the present invention provides an online processing method and system for information security data based on blockchain. Summary of the Invention

[0006] The purpose of the present invention is to provide an online processing method and system for information security data based on blockchain to solve at least one of the above-mentioned prior art problems.

[0007] In a first aspect, the present invention provides an online processing method for information security data based on blockchain, including:

[0008] Step 1: Obtain information security data, perform comparison analysis and packaging processing to obtain key data packets and non-key data packets, construct a data block model, and split the key data packets to obtain key sub-data packets;

[0009] Step 2: Encrypt all key sub-data packets, back up the key sub-data packets, and perform on-chain processing on the encrypted key sub-data packets, the backed-up key sub-data packets, and the non-key data packets;

[0010] Step 3: Based on the data packets processed for uploading to the blockchain, through the download processing of the blockchain, obtain the downloaded data packets, mark the storage nodes of the data packets that cannot be obtained by the blockchain as volatile storage nodes, perform numerical analysis on the non-critical data packets of the volatile storage nodes to obtain the non-critical backup value Bf, and based on the non-critical backup value Bf, determine whether it is necessary to perform backup processing on the non-critical data packets;

[0011] Step 4: If it is necessary to perform backup processing on the non-critical data packets, perform upload processing again on the data packets that cannot be obtained from the volatile storage nodes and the backed-up non-critical data packets;

[0012] Step 5: Perform hash verification on the critical sub-packets to determine whether the critical sub-packets have been tampered with. If the critical sub-packets have been tampered with, perform numerical analysis on the tampered critical sub-packets to obtain the data invalidation value Wx, and determine whether the critical sub-packets can be restored to critical packets;

[0013] Step 6: If the critical sub-packets cannot be restored to critical packets, obtain the backup data volume of each critical sub-packet within the historical monitoring period, and the corresponding data invalidation value Wx of the backup data volume. Perform fitting analysis on the backup data volume and the data invalidation value to obtain the data backup volume that minimizes the data invalidation value Wx. Based on the minimum backup volume, adjust the number of backup files of the critical sub-packets on the blockchain so that the critical sub-packets on the blockchain can be restored to critical packets.

[0014] In a second aspect, the present invention provides an information security data online processing system based on a blockchain, including:

[0015] Data splitting module: Obtain information security data and perform comparison analysis and packaging processing to obtain critical packets and non-critical packets, construct a data block model, and split the critical packets to obtain critical sub-packets;

[0016] Upload calculation module: Encrypt and number all critical sub-packets, and back up the critical sub-packets. Perform upload processing on the critical sub-packets, the backed-up critical sub-packets, and the non-critical packets;

[0017] Download judgment module: Based on the data packets processed for uploading to the blockchain, through the download processing of the blockchain, obtain the downloaded data packets, mark the storage nodes of the data packets that cannot be obtained by the blockchain as volatile storage nodes, perform numerical analysis on the non-critical data packets of the volatile storage nodes to obtain the non-critical backup value Bf, and based on the non-critical backup value Bf, determine whether it is necessary to perform backup processing on the non-critical data packets;

[0018] Secondary upload module: If it is necessary to perform backup processing on the non-critical data packets, perform upload processing again on the data packets that cannot be obtained from the volatile storage nodes and the backed-up non-critical data packets;

[0019] Down-chain judgment module: Perform down-chain processing on key sub-data packets of the distributed storage of the blockchain, perform hash verification on the key sub-data packets to determine whether the key sub-data packets are tampered with. If the key sub-data packets are tampered with, perform numerical analysis on the tampered key sub-data packets to obtain a data invalid value Wx, and determine whether the key sub-data packets can be restored to key data packets;

[0020] Backup adjustment module: If the key sub-data packets cannot be restored to key data packets, obtain the backup data volume of each key sub-data packet within the historical monitoring period, and the corresponding data invalid value Wx of the backup data volume. Perform fitting analysis on the backup data volume and the data invalid value to obtain the data backup volume that minimizes the data invalid value Wx. Based on the minimum backup volume, adjust the number of backup files of the key sub-data packets of the blockchain so that the key sub-data packets of the blockchain can be restored to key data packets.

[0021] Advantages of the present invention:

[0022] 1. By means of encryption algorithms, encrypt and perform integrity verification on key sub-data packets, ensuring data integrity during data transmission and storage processes, or when data is stored on blockchain nodes for a long time, reducing the possibility of external malicious tampering; through monitoring and analysis of blockchain storage nodes, identifying volatile storage nodes, calculating non-redundant backup values, and a dynamic backup decision mechanism, improving the ability to restore key sub-data packets after splitting into key data packets;

[0023] 2. For non-key data packets, flexibly adjust the backup strategy according to the actual risk situation, reducing excessive occupation and waste of storage resources while ensuring data security, which is beneficial to improving the efficiency of data storage management. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0025] Figure 1 is a flowchart of the data splitting and up-chain method provided in Embodiment 1 of the present invention;

[0026] Figure 2 is a flowchart of the method for analyzing and optimizing key sub-data packets provided in Embodiment 2 of the present invention;

[0027] Figure 3It is a module diagram of an information security data online processing method and processing system based on blockchain provided in Embodiment 3 of the present invention;

[0028] Figure 4 It is a schematic structural diagram of a computer device provided in Embodiment 4 of the present invention. Detailed implementation manners

[0029] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0030] Embodiment 1 Figure 1 It is a flowchart of a data splitting and uploading method provided in Embodiment 1 of the present invention. The embodiments of the present invention are applicable to the situation of data splitting and uploading. The data splitting and uploading method can be executed by an information security data online processing system based on blockchain. The information security data online processing system based on blockchain can be implemented by software and / or hardware, and the information security data online processing system based on blockchain can be configured in a computer device. Optionally, the computer device can be an electronic device, and the electronic device can be a notebook, a desktop computer, a smart tablet, etc. The embodiments of the present invention do not limit this.

[0031] As Figure 1 shown, the data splitting and uploading method provided in the embodiments of the present invention specifically includes the following steps:

[0032] Step 1: Obtain information security data, perform comparison analysis and packaging processing to obtain key data packets and non-key data packets, construct a data block model, and split the key data packets to obtain key sub-data packets;

[0033] Obtain the business process generated by the information security data, compare the business process with the key process library to obtain key information data and non-key information data;

[0034] It should be noted that the key process library is set by domain professional technicians based on experience;

[0035] Among them, each business process generates multiple information security data, and each information security data includes the timeliness of the data;

[0036] Exemplarily, in the transfer business process, it includes processes such as customer information acquisition, balance confirmation, transfer application, risk assessment, transfer confirmation, and bill receipt. The key process library includes customer information acquisition, balance confirmation, transfer confirmation, etc.;

[0037] If the business process in which information security data is generated is within the business processes included in the key process library, mark the information security data as key information data;

[0038] If the business process in which information security data is generated is not within the business processes included in the key process library, mark the information security data as non-key information data;

[0039] Package the key information data and non-key information data through the Transmission Control Protocol (TCP) to obtain key data packets and non-key data packets;

[0040] Based on the Content-Defined Chunking (CDC) protocol and the Rabin fingerprint algorithm, establish a data chunking model to chunk the key data packets;

[0041] The specific method for establishing the data chunking model is as follows:

[0042] A1. Calculate the size of the data packet file of the key data packet, determine the file window size, read the key data packet according to the file window size, and use the Rabin fingerprint algorithm to calculate the hash value of the key data packet;

[0043] Exemplarily, for a key data packet with a size of 2MB, using the Rabin fingerprint algorithm, read the file content with a file window size of 4KB and calculate the hash value. For every 4KB of data content read, substitute it into the Rabin polynomial hash function to calculate the hash value. After hashing the 4KB data, a 32-bit hash value "0x12345678" is obtained;

[0044] A2. Move the file window, repeat A1, calculate the remaining file size of the key data packet. When a preset value appears at the end of the hash value, take the end of the file window where the preset value appears as the window boundary;

[0045] A3. Split the key data packet according to the window boundary to obtain multiple key sub-data packets;

[0046] Exemplarily, when calculating to the 12KB position of the key data packet, the hash value is "0xabcdef00", and the preset value "00" appears at the end. The end of the 12KB file window is used as the first window boundary; starting from after the 12KB, the file window is moved, and the hash value of the file within the next file window is continuously calculated. When calculating to the 20KB position of the key data packet, the hash value is "0x11111100", and the preset value "00" at the end appears again. The 20KB position is used as the second window boundary. Until the 8MB key data packet is processed, multiple window boundaries are determined. The key data packet is split according to the window boundaries to obtain multiple key sub - data packets. The key sub - data packets are described in the order of the byte size range of the file. The file size range of the key sub - data packets of 0 - 20KB is: [0, 12KB], [13KB, 20KB];

[0047] Step 2: Encrypt all key sub - data packets, assign numbers to them, and back up the key sub - data packets. Then, perform an on - chain process on the key sub - data packets, the backed - up key sub - data packets, and the non - key data packets;

[0048] Use the asymmetric encryption algorithm (RSA) to encrypt each key sub - data packet, and number the asymmetric - encrypted key sub - data packets according to the splitting order of the key data packet to obtain key split numbers;

[0049] Store the key split numbers at the starting endpoints of each encrypted key sub - data packet;

[0050] And use the SHA - 256 algorithm to calculate the hash value of each encrypted key sub - data packet, and store the hash value at the end endpoints of each key sub - data packet;

[0051] It should be noted that using the SHA - 256 algorithm to calculate the hash value of the key sub - data packet is used to verify the integrity of the data subsequently;

[0052] According to the order of packing the key data packet and the non - key data packet by the Transmission Control Protocol (TCP), calculate and number the non - key data packet and the key sub - data packet again to obtain data restoration numbers, and store the data restoration numbers at the starting endpoints of the non - key data packet and the key sub - data packet;

[0053] Perform a backup process on the encrypted key sub - data packets to generate backup files for each key sub - data packet;

[0054] The key sub - data packets that have been numbered and calculated using SHA - 256, the backup files of each key sub - data packet, and the non - key data packets are stored on the distributed nodes of the blockchain using blockchain technology, that is, the key sub - data packets, the backup files of each key sub - data packet, and the non - key data packets are processed to be uploaded to the blockchain;

[0055] The technical solution of this embodiment is as follows: Obtain information security data, perform comparison analysis and packaging processing to obtain key data packets and non - key data packets, construct a data chunking model, split the key data packets to obtain key sub - data packets, encrypt and number all the key sub - data packets, back up the key sub - data packets, and perform an upload - to - blockchain process on the key sub - data packets, the key sub - data packets after backup processing, and the non - key data packets. Through the distributed storage technology of the blockchain, reduce the degree of dependence on the centralized data storage method.

[0056] Embodiment 2, as Figure 2 shown, the method for analysis and optimization of key sub - data packets provided by the second embodiment of the present invention includes the following steps:

[0057] Step 3: Based on the data packets processed to be uploaded to the blockchain, through the download - from - blockchain process of the blockchain, obtain the downloaded data packets, mark the storage nodes of the data packets that cannot be obtained by the blockchain as volatile storage nodes, perform numerical analysis on the non - key data packets of the volatile storage nodes to obtain a non - key backup value Bf, and based on the non - key backup value Bf, determine whether it is necessary to back up the non - key data packets;

[0058] Based on the key sub - data packets processed to be uploaded to the blockchain, through the download - from - blockchain process of the blockchain, obtain the downloaded data packets;

[0059] Among them, the downloaded data packets include: non - key data packets, key sub - data packets;

[0060] If a data packet cannot be obtained on the distributed storage nodes of the blockchain, mark the storage node of the data packet that cannot be obtained as a volatile storage node;

[0061] It should be noted that in the blockchain distributed storage environment, the stability of storage nodes varies. By marking the storage nodes that cannot obtain data packets as volatile storage nodes, the risk of data loss in specific nodes can be clearly identified.

[0062] Obtain the storage quantity of non - key data packets in the volatile storage nodes and the quantity of non - key data packets;

[0063] Perform a ratio process on the storage quantity of non - key data packets in the volatile storage nodes and the quantity of non - key data packets to obtain a non - key volatile ratio, and mark the non - key volatile ratio as Ys;

[0064] Obtain the number of volatile storage nodes and the number of all distributed storage nodes, calculate the ratio of the number of volatile storage nodes to the number of all distributed nodes to obtain the volatile node ratio, and mark the volatile node ratio as Yj;

[0065] Based on the non-duplicate volatile ratio Ys and the volatile node ratio Yj, calculate the non-duplicate backup value Bf;

[0066] Through the formula: Obtain the data backup value Bf, where a = 1.25 and b = 0.762;

[0067] Compare the non-duplicate backup value Bf with the non-duplicate backup threshold to determine whether to perform backup processing on non-critical data;

[0068] If the non-duplicate backup value Bf is higher than the non-duplicate backup threshold, it indicates that the number of times non-critical data packets are lost exceeds the expectation, and backup processing for non-critical data is required;

[0069] If the non-duplicate backup value Bf is lower than the non-duplicate backup threshold, it indicates that the number of times non-critical data packets are lost is lower than the expectation, and backup processing for non-critical data is not required. It is still necessary to continuously monitor the change of the non-duplicate backup value Bf;

[0070] It should be noted that comparing the non-duplicate backup value Bf with the non-duplicate backup threshold is flexibly determined according to the actual risk situation whether to perform backup processing on non-critical data. When the non-duplicate backup value Bf is higher than the threshold, it indicates that the number of times data is lost exceeds the expectation, and timely backup can effectively prevent further data loss;

[0071] Step Four: If backup processing for non-critical data packets is required, re-upload the packets that cannot be obtained from the volatile storage nodes and the backed-up non-critical data packets to the blockchain;

[0072] If backup processing for non-critical data packets is required, exclude the volatile storage nodes from the blockchain distributed storage nodes to obtain storable nodes;

[0073] Through the numbers of non-critical data packets and key sub-packets, put the non-critical data packets, key sub-packets, and backed-up non-critical data packets that cannot be obtained from the volatile storage nodes into the storable nodes of the blockchain, that is, re-upload them to the blockchain;

[0074] Step Five: Download the key sub-packets of the blockchain distributed storage, perform hash verification on the key sub-packets to determine whether the key sub-packets are tampered with. If the key sub-packets are tampered with, perform numerical analysis on the tampered key sub-packets to obtain the data invalid value Wx, and determine whether the key sub-packets can be restored to key packets;

[0075] Obtain the key sub - data packets and non - key data packets of the distributed storage of the blockchain, that is, perform off - chain processing on the data stored in the blockchain;

[0076] Obtain the key sub - data packets after off - chain processing, read the SHA - 256 hash value stored at the end point of the key sub - data packets, perform hash verification processing on the key sub - data packets, and determine whether the key sub - data packets have been tampered with;

[0077] Specifically, the method of hash verification processing is as follows:

[0078] S1. Remove the number stored at the start point and the hash value stored at the end point of the key sub - data packets;

[0079] S2. For the encrypted part of the key sub - data packets, calculate the hash value again using the SHA - 256 algorithm;

[0080] S3. Compare the hash value calculated again with the hash value stored at the end point to determine whether the key sub - data packets have been tampered with;

[0081] If the hash value calculated again is the same as the hash value stored at the end point, it indicates that the key sub - data packets have not been tampered with;

[0082] If the hash value calculated again is different from the hash value stored at the end point, it indicates that the key sub - data packets have been tampered with, and obtain the backup key sub - data packets;

[0083] If both the key sub - data packets and the backup key sub - data packets have been tampered with, mark the corresponding key sub - data packets as invalid data packets, and obtain the number of invalid data packets;

[0084] Sum up the number of all key data packets and the number of backup key sub - data packets to obtain the total number of data packets;

[0085] Take the difference between the number of invalid data packets and the total number of data packets, and then take the ratio of the obtained calculation result to the total number of data packets to obtain the invalid data ratio, and mark the invalid data ratio as Pw;

[0086] If one of the key sub - data packets or the backup key sub - data packets has been tampered with, mark the corresponding key data packets as single - sided data packets;

[0087] Obtain the number of all single - sided data packets, take the ratio of the number of single - sided data packets to the total number of data packets to obtain the single - sided data ratio, and mark the single - sided data ratio as Pd;

[0088] Based on the invalid data ratio Pw and the single - sided data ratio Pd, calculate the data invalid value Wx;

[0089] Through the formula: Obtain the invalid value Wx of the data, where c = 0.78 and d = 0.32;

[0090] Compare the invalid value Wx of the data with the data invalid threshold to determine whether the key sub-packet can be restored to the key packet;

[0091] If the invalid value Wx of the data is higher than the data invalid threshold, the key sub-packet cannot be restored to the key packet;

[0092] If the invalid value Wx of the data is lower than the data invalid threshold, the key sub-packet can be restored to the key packet;

[0093] Step 6: If the key sub-packet cannot be restored to the key packet, obtain the backup data volume of each key sub-packet in the historical monitoring period, and the corresponding invalid value Wx of the backup data volume. Perform fitting analysis on the backup data volume and the invalid value to obtain the data backup volume that minimizes the invalid value Wx. Based on the minimum backup volume, adjust the number of backup files of the key sub-packets in the blockchain so that the key sub-packets in the blockchain can be restored to the key packet;

[0094] If the key sub-packet cannot be restored to the key packet, obtain the backup data volume of each key sub-packet in the blockchain during the historical monitoring period;

[0095] Mark the backup data volume of each key sub-packet in the blockchain in each monitoring period as Bs i , and construct a data sequence Bs of the backup data volume according to the backup data volume Bs i in ascending order i , Bs i = [Bs1, Bs2,..., Bs n , where i is the number of the backup data, i = 1, 2,..., n, and n is the total number of the numbers;

[0096] Obtain the corresponding invalid value Wx of the backup data volume and construct a change sequence Wx of the invalid value i , Wx i = [Wx1, Wx2,..., Wx n ;

[0097] Based on the data sequence Bs of the backup data volume i and the change sequence Wx of the invalid value i , calculate the correlation coefficient Through the formula: Obtain the correlation coefficient , where x is the data sequence Bs of the backup data volume i and the change sequence Wx of the invalid value iThe x-th data point, where x = 1, 2, ..., n, and ρ is the discrimination coefficient with ρ = 0.75, represents the absolute value of the minimum difference between two levels, represents the absolute value of the maximum difference between two levels;

[0098] It should be noted that the minimum difference and the maximum difference between two levels reflect the data sequence Bs of the backup data volume i and the change sequence Wx of data invalid values i of the difference degree;

[0099] Through the formula: Obtain the mean value S of the correlation coefficient, compare the mean value S of the correlation coefficient with the correlation coefficient threshold, and judge the data sequence Bs of the backup data volume i and the change sequence Wx of data invalid values i whether they are relevant;

[0100] It should be noted that the correlation coefficient threshold is set by professionals in the field based on experience;

[0101] If the mean value S of the correlation coefficient is higher than the correlation coefficient threshold, it indicates that the changes in the data sequence Bs of the backup data volume i and the change sequence Wx of data invalid values i show correlation;

[0102] Use the least squares method to fit the data sequence Bs of the backup data volume i and the change sequence Wx of data invalid values i In the two-dimensional rectangular coordinate system, with the backup data volume as the X-axis and the data invalid value as the Y-axis, draw the fitting line of the backup data volume - data invalid value;

[0103] Calculate the goodness of fit R 2 of the fitting line, and judge whether the goodness of fit R 2 is within the range of [0.75, 1];

[0104] If the goodness of fit is within the range of [0.75, 1], it is considered that the fitting effect of the fitting line meets the expectation;

[0105] Calculate the slope of the fitting line. If the slope of the fitting line is less than 0, the fitting line is in a linearly decreasing trend. Calculate the intersection point of the fitting line and the X-axis to obtain the minimum backup data volume that makes the data invalid value 0;

[0106] If the mean value S of the correlation coefficient is lower than the correlation coefficient threshold, the goodness of fit of the fitting line is not within the range of [0.75, 1], and the slope of the fitting line is not less than 0;

[0107] Obtain the change sequence Wx of data invalid values iInvalid data value Wx in the data i The data backup volume corresponding to the minimum value is obtained to get the minimum backup volume;

[0108] Based on the minimum backup volume, the number of backup files of the key sub-packets of the blockchain is increased so that the key sub-packets of the blockchain can be restored to key packets;

[0109] The technical solution of this embodiment is as follows: Based on the data packets processed for on-chain, through the off-chain processing of the blockchain, the off-chain data packets are obtained. The storage nodes of the data packets that the blockchain cannot obtain are marked as volatile storage nodes. Numerical analysis is performed on the non-key data packets of the volatile storage nodes to obtain the non-key backup value Bf. Based on the non-key backup value Bf, it is judged whether it is necessary to perform backup processing on the non-key data packets. If it is necessary to perform backup processing on the non-key data packets, the data packets that cannot be obtained by the volatile storage nodes and the backed-up non-key data packets are processed for on-chain again. The key sub-packets of the distributed storage of the blockchain are processed for off-chain, and the key sub-packets are subjected to hash verification to determine whether the key sub-packets are tampered with. If the key sub-packets are tampered with, numerical analysis is performed on the tampered key sub-packets to obtain the invalid data value Wx, and it is determined whether the key sub-packets can be restored to key packets. If the key sub-packets cannot be restored to key packets, the backup data volume of each key sub-packet within the historical monitoring period and the corresponding invalid data value Wx of the backup data volume are obtained, and a fitting analysis is performed on the backup data volume and the invalid data value to obtain the data backup volume that minimizes the invalid data value Wx. Based on the minimum backup volume, the number of backup files of the key sub-packets of the blockchain is adjusted so that the key sub-packets of the blockchain can be restored to key packets, and the backup strategy is flexibly adjusted according to the actual risk situation. On the premise of ensuring data security, the excessive occupation and waste of storage resources are reduced, which is beneficial to improving the efficiency of data storage management.

[0110] Embodiment 3, as Figure 3 shown, an information security data online processing system based on a blockchain, including:

[0111] Data splitting module: Obtain information security data and perform comparison analysis and packaging processing to obtain key packets and non-key packets, construct a data block model, and split the key packets to obtain key sub-packets;

[0112] On-chain calculation module: Encrypt and number all key sub-packets, and back up the key sub-packets. Perform on-chain processing on the key sub-packets, the key sub-packets processed for backup, and the non-key packets;

[0113] Down-chain judgment module: Based on the data packets processed on the up-chain, through the down-chain processing of the blockchain, obtain the down-chain data packets, mark the storage nodes of the data packets that cannot be obtained by the blockchain as volatile storage nodes, perform numerical analysis on the non-key data packets of the volatile storage nodes to obtain the non-key backup value Bf, and based on the non-key backup value Bf, determine whether it is necessary to perform backup processing on the non-key data packets;

[0114] Secondary up-chain module: If it is necessary to perform backup processing on the non-key data packets, perform up-chain processing again on the data packets that cannot be obtained from the volatile storage nodes and the backed-up non-key data packets;

[0115] Down-chain judgment module: Perform down-chain processing on the key sub-data packets of the distributed storage of the blockchain, perform hash verification on the key sub-data packets to determine whether the key sub-data packets are tampered with. If the key sub-data packets are tampered with, perform numerical analysis on the tampered key sub-data packets to obtain the data invalidation value Wx, and determine whether the key sub-data packets can be restored to key data packets;

[0116] Backup adjustment module: If the key sub-data packets cannot be restored to key data packets, obtain the backup data volume of each key sub-data packet within the historical monitoring period, and the data invalidation value Wx corresponding to the backup data volume, perform fitting analysis on the backup data volume and the data invalidation value to obtain the data backup volume that minimizes the data invalidation value Wx, and based on the minimum backup volume, adjust the number of backup files of the key sub-data packets of the blockchain so that the key sub-data packets of the blockchain can be restored to key data packets.

[0117] Example 4, refer to Figure 4 Moreover, an embodiment of the present invention also provides a computer device 3, including: a memory 302, a processor 301, and a computer program 303 stored on the memory 302. When the computer program 303 is executed on the processor 301, it implements a method for online processing of information security data based on the blockchain as described in any one of the above methods.

[0118] The computer device 3 may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The computer device 3 may include, but is not limited to, a processor 301 and a memory 302. Those skilled in the art can understand.

[0119] Figure 4 This is only an example of the computer device 3 and does not constitute a limitation on the computer device 3. It may include more or fewer components than shown in the figure, or combine some components, or different components. For example, it may also include input / output devices, network access devices, etc.

[0120] The so-called processor 301 may be a central processing unit (CPU), and the processor 301 may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0121] In some embodiments, the memory 302 may be an internal storage unit of the computer device 3, such as the hard disk or memory of the computer device 3. In other embodiments, the memory 302 may also be an external storage device of the computer device 3, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 3. Further, the memory 302 may also include both the internal storage unit and the external storage device of the computer device 3. The memory 302 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 302 may also be used to temporarily store data that has been output or is to be output.

[0122] Embodiment 5, The embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it implements a method for online processing of information security data based on a blockchain as described in any one of the above methods.

[0123] In this embodiment, if the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-described embodiment methods of the present application, a computer program can be used to instruct relevant hardware to complete the operations. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can at least include: any entity or device capable of carrying the computer program code to the photographing device / terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a portable hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.

[0124] In the above embodiments, the descriptions of the various embodiments have their own focuses. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0125] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0126] In the embodiments disclosed in the present application, it should be understood that the disclosed device / terminal device and method can be implemented in other ways. For example, the device / terminal device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another

[0127] point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.

[0128] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0129] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0130] The above has described in detail an embodiment of the present invention, but the content described is only a preferred embodiment of the present invention and cannot be considered as limiting the scope of implementation of the present invention. All equivalent changes and improvements made within the scope of the application of the present invention should still fall within the scope covered by the patent of the present invention.

Claims

1. A method for online processing of information security data based on blockchain, characterized in that: The following steps are involved: Step 1: Obtain information security data and conduct comparative analysis to obtain key data packets and non-key data packets, build a data block model, and obtain key sub-data packets; Step 2: Encrypt and back up all key sub-data packets, and upload the encrypted key sub-data packets, the backed-up key sub-data packets, and the non-key data packets to the chain; Step 3: Based on the data packets processed on the chain, obtain the data packets on the chain, mark the storage nodes of the data packets that the blockchain cannot obtain as volatile storage nodes, perform numerical analysis on the non-key data packets of the volatile storage nodes, obtain the non-re-backup value Bf, and determine whether the non-key data packets need to be backed up; Step 4: If it is necessary to back up non-critical data packets, the unobtainable data packets of the volatile storage node and the backed-up non-critical data packets are uploaded to the chain again; Step 5: Perform a hash check on the key sub-data packet to determine whether the key sub-data packet has been tampered with. If the key sub-data packet has been tampered with, perform a numerical analysis on the tampered key sub-data packet to obtain a data invalid value Wx, and determine whether the key sub-data packet can be restored to the key data packet; Step 6: If the key sub-data package cannot be restored to the key data package, obtain the backup data volume of each key sub-data package in the historical monitoring period, and the data invalid value Wx corresponding to the backup data volume, perform fitting analysis on the backup data volume and the data invalid value, and adjust the number of backup files of the key sub-data package of the blockchain so that the key sub-data package of the blockchain can be restored to the key data package; The method of fitting and analyzing the backup data volume and the invalid data value is as follows: The backup data volume of each key sub-data packet of the blockchain in each monitoring cycle is marked as Bs i , construct the data sequence Bs of the backup data volume i , where i is the number of the backup data, i=1,2,...,n, and n is the total number of numbers; Get the invalid data value Wx corresponding to the backup data volume, and construct the change sequence Wx of the invalid data value i ; In the data sequence Bs of the backup data volume i The sequence of changes with invalid values ​​of data Wx i When the changes in the backup data are correlated, the least squares method is used to calculate the backup data sequence Bs. i , the changing sequence of invalid data values ​​Wx i Perform fitting and draw a fitting straight line of backup data volume-invalid data value; The method for adjusting the number of backup files of the key sub-data packets of the blockchain is as follows: Calculate the goodness of fit of the fitted line. If the goodness of fit is within a preset range, calculate the slope of the fitted line. If the slope of the fitted line is less than 0, calculate the intersection of the fitted line and the X-axis to obtain the minimum backup data volume that makes the data invalid value 0. If the correlation coefficient mean S is lower than the correlation coefficient threshold, the goodness of fit of the fitting line is not within the preset range, and the slope of the fitting line is not less than 0; Get the change sequence Wx of invalid data value i Invalid data value Wx i The data backup amount corresponding to the minimum value of is obtained to obtain the minimum backup amount; Based on the minimum backup amount, the number of backup files of the key sub-data packets of the blockchain is increased, and the data invalid value Wx is reduced, so that the key sub-data packets of the blockchain can be restored to the key data packets.

2. According to the method of online processing of information security data based on blockchain in claim 1, it is characterized in that: The key sub-data packet is obtained in the following manner: Obtain the business process generated by information security data, compare the business process with the key process library, and obtain key information data and non-key information data; If the business process generated by the information security data is in the business process included in the key process library, the information security data is marked as key information data, otherwise, it is marked as non-key information data; Packing key information data and non-key information data to obtain key data packets and non-key data packets; Construct a data block model to split the key data packets to obtain multiple key sub-data packets.

3. According to the blockchain-based information security data online processing method of claim 1, it is characterized in that: The method for determining whether to perform backup processing on non-key data packets is as follows: Numerical analysis is performed on non-critical data packets of volatile storage nodes to obtain the non-critical volatile ratio Ys and volatile node ratio Yj; Based on the non-repetitive volatile ratio Ys and the volatile node ratio Yj, the non-repetitive backup value Bf is calculated; By formula: Get the data backup value Bf, where a and b are preset proportional coefficients; If the non-re-backup value Bf is higher than the non-re-backup threshold, non-critical data needs to be backed up.

4. According to claim 3, a method for online processing of information security data based on blockchain is characterized in that: The non-volatile ratio Ys is obtained as follows: Obtain the data packet from the blockchain. If the data packet cannot be obtained on the distributed storage node of the blockchain, the storage node of the data packet that cannot be obtained is marked as a volatile storage node. Obtain the storage quantity of non-key data packets in the volatile storage node and the quantity of non-key data packets; The number of non-critical data packets stored in the volatile storage node is processed by ratio with the number of non-critical data packets to obtain a non-critical volatile ratio, and the non-critical volatile ratio is marked as Ys; The number of volatile storage nodes and the number of all distributed storage nodes are obtained, and the number of volatile storage nodes is ratioed to the number of all distributed nodes to obtain a volatile node ratio, which is marked as Yj.

5. According to the blockchain-based information security data online processing method of claim 1, it is characterized in that: Whether the key sub-data packet can be restored to the key data packet is determined in the following manner: Numerical analysis is performed on the tampered key sub-data packets to obtain the invalid data ratio Pw and the unilateral data ratio Pd; Based on the invalid data ratio Pw and the one-sided data ratio Pd, the data invalid value Wx is calculated; By formula: Get the data invalid value Wx, where c and d are preset proportional coefficients; If the data invalid value Wx is higher than the data invalid threshold, the key sub-data packet cannot be restored to the key data packet.

6. According to claim 5, a method for online processing of information security data based on blockchain is characterized in that: The invalid data ratio Pw is obtained as follows: If both the key sub-data packet and the backup key sub-data packet are tampered with, the corresponding key sub-data packet is marked as an invalid data packet, and the number of invalid data packets is obtained; The number of all key data packets and the number of backed-up key sub-data are summed to obtain the total number of data packets; The number of invalid data packets is processed as a difference from the total number of data packets, and the calculated result is processed as a ratio with the total number of data packets to obtain an invalid data ratio, which is the invalid data ratio Pw; The unilateral data ratio Pd is obtained as follows: If one of the key sub-data packets or the backup key sub-data packets is tampered with, the corresponding key data packet is marked as a unilateral data packet; The number of all unilateral data packets is obtained, and the ratio of the number of unilateral data packets to the total number of data packets is processed to obtain a unilateral data ratio, which is marked as Pd.

7. According to claim 6, a method for online processing of information security data based on blockchain is characterized in that: The method for judging whether the key sub-data packet has been tampered with is as follows: Obtain the key sub-data packet processed by the downlink, read the hash value stored at the end endpoint of the key sub-data packet, perform hash verification on the key sub-data packet, and determine whether the key sub-data packet has been tampered with.

8. According to the method of online processing of information security data based on blockchain in claim 1, it is characterized in that: Get the invalid data value Wx corresponding to the backup data volume, and construct the change sequence Wx of the invalid data value i ; Data sequence Bs based on backup data volume i , the changing sequence of invalid data values ​​Wx i , calculate the correlation coefficient ; By formula: Get the correlation coefficient , where x is the data sequence Bs of the backup data volume i , the changing sequence of invalid data values ​​Wx i The xth data point in the equation, x=1,2,...,n, ρ is the resolution coefficient, ρ=0.75, Represents the absolute value of the minimum difference between the two levels, Indicates the absolute value of the maximum difference between the two levels; By formula: Get the mean value S of the correlation coefficient; If the correlation coefficient mean S is higher than the correlation coefficient threshold, it indicates that the data sequence Bs of the backup data volume i , the changing sequence of invalid data values ​​Wx i The changes in are related.

9. An information security data online processing system based on blockchain, characterized in that: Used to execute the blockchain-based information security data online processing method described in any one of claims 1-8.

Citation Information

Patent Citations

  • Data access method and system, computer storage medium and terminal equipment

    CN117473020A

  • Digital management method and system based on enterprise archives

    CN118885441A