Security auditing system and auditing method based on distributed block chain credible evidence storage
By dividing the blockchain network into multiple shards and designing a task queue management system, the blockchain performance limitation and transaction throughput problems are solved, and the efficiency and credibility of the audit process are improved.
Patent Information
- Application Number
- CN202411946037.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-09
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Blockchain performance limitations and transaction throughput problems lead to inefficiency in the audit process, especially in large-scale evidence storage and auditing, which makes it difficult to meet the growing demand.
The blockchain network is divided into multiple shards, each shard is allocated an independent shard chain, allowing data exchange and communication between different shards, and a task queue management system is designed to optimize task execution.
Through fragmentation, reduce network burden, improve system scalability, reduce system complexity, accelerate data processing and audit process, improve audit efficiency and accuracy, and ensure the credibility of audit results.
Smart Images

Figure CN119966599A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security auditing, and in particular to a security auditing system and an auditing method based on distributed blockchain trusted evidence. Background Art
[0002] The security audit technology of the distributed blockchain trusted evidence is an audit method based on distributed network and blockchain technology. It records the evidence data on the blockchain in an unalterable way, and the audit nodes distributed in the network verify and audit the evidence to ensure the integrity, authenticity and security of the evidence, thereby providing highly reliable audit services. However, the performance limitations and transaction throughput issues of the blockchain may lead to inefficient audit processes, especially in the case of large-scale evidence storage and auditing, which may also limit the scalability of the blockchain network and make it difficult to meet the growing demand. Summary of the invention
[0003] The purpose of the present invention is to provide a security audit system and audit method based on distributed blockchain trusted evidence to address the deficiencies in the background technology.
[0004] In order to achieve the above object, the present invention provides the following technical solution: a security audit method based on distributed blockchain trusted evidence, comprising the following steps:
[0005] S1: Divide the blockchain network into multiple shards, assign an independent shard chain to each shard, and use the shard chain to maintain the evidence data and audit records within the shard, allowing data exchange and communication between different shards;
[0006] S2: When data is exchanged between different shards, the network communication status between different shards is judged, and the network stability when data is exchanged between different shards is evaluated;
[0007] S3: Design a task queue management system to queue and manage evidence storage requests and audit tasks according to priority, determine the degree of management anomalies in the task execution process, and evaluate the management efficiency in the task execution process;
[0008] S4: Comprehensively analyze the network stability when exchanging data between different shards and the management efficiency during task execution, evaluate the efficiency and stability of the audit process between different shards, and issue timely warnings for abnormal conditions.
[0009] In a preferred embodiment, in S2, when data is exchanged between different shards, the network communication status between the different shards is determined, and the network stability when data is exchanged between the different shards is evaluated;
[0010] The method for obtaining the network communication stability value is:
[0011] Set a sliding window of fixed size to store the ping command results in the recent period of time;
[0012] Use the ping command to periodically send requests to the target address and record the results, saving information such as the delay and packet loss rate of each ping command in a sliding window;
[0013] Perform weighted calculation on each ping result in the sliding window to obtain the stable value of network communication; weight each ping result according to its time interval in the sliding window, the delay value is Li, the time interval is Ti, the weight coefficient is Wi, where i represents the i-th ping result, and calculate the weighted average delay. The specific calculation expression is: Where n is the number of ping results in the sliding window;
[0014] The network communication stability value is calculated by comprehensively calculating the weighted average delay and weighted average packet loss rate. The delay weight coefficient is W. 延迟 , the packet loss rate weight coefficient is W 丢包率 , the network communication stability value calculation expression is: comprehensive stability value = (W 延迟 *weighted average delay)+(W 丢包率 *weighted packet loss rate), and calculate the network communication stability value based on the result obtained by weighted calculation.
[0015] In a preferred implementation, in S3, a task queue management system is designed to queue and manage evidence storage requests and audit tasks according to priority, determine the degree of management abnormality in the task execution process, and evaluate the management efficiency in the task execution process;
[0016] The method for obtaining the task management efficiency anomaly index is as follows: obtain real-time feedback data of the task processing process in the task queue, obtain the task processing time, task waiting time, and task completion rate in the real-time feedback data, standardize the task processing time, task waiting time, and task completion rate obtained in real time, obtain the task processing time, task waiting time, and task completion rate under the expected standard state, compare the real-time task processing time, task waiting time, and task completion rate with the corresponding task processing time, task waiting time, and task completion rate under the standard state, calculate the standard deviation of the task processing time, the standard deviation of the task waiting time, and the standard deviation of the task completion rate, respectively, calculate the ratio of the standard deviation of the task processing time, the standard deviation of the task waiting time, and the standard deviation of the task completion rate to the real-time task processing time, the task waiting time, and the task completion rate, that is, calculate the task management efficiency anomaly index.
[0017] In a preferred embodiment, the network communication stability value and the task management efficiency abnormality index are normalized, and the efficiency stability coefficient of the audit process between different shards is calculated by the normalized network communication stability value and the task management efficiency abnormality index. The calculation expression is: In the formula, ct k is the stability coefficient, np d is the stable value of network communication, rm s is the task management efficiency abnormality index, a1 and a2 are the network communication stability value and the proportional coefficient of the task management efficiency abnormality index, and a2>a1>0.
[0018] In a preferred embodiment, the efficiency stability coefficient of the audit process between different shards is compared with the stability threshold. If the efficiency stability coefficient of the audit process between different shards is greater than or equal to the stability threshold, a normal signal is issued; if the efficiency stability coefficient of the audit process between different shards is less than the stability threshold, an abnormal signal is issued.
[0019] The present invention also provides a security audit system based on distributed blockchain trusted evidence, including a sharding module, a network monitoring module, a task management monitoring module, and an analysis and early warning module;
[0020] Sharding module: divides the blockchain network into multiple shards, assigns an independent shard chain to each shard, and the shard chain maintains the evidence data and audit records within the shard, allowing data exchange and communication between different shards;
[0021] Network monitoring module: when data is exchanged between different shards, it determines the network communication status between different shards and evaluates the network stability when data is exchanged between different shards;
[0022] Task management monitoring module: Design a task queue management system to queue and manage evidence storage requests and audit tasks according to priority, determine the degree of management anomalies in the task execution process, and evaluate the management efficiency in the task execution process;
[0023] Analysis and early warning module: Comprehensively analyze the network stability when exchanging data between different shards and the management efficiency during task execution, evaluate the efficiency and stability of the audit process between different shards, and issue timely early warnings for abnormal conditions.
[0024] In the above technical solution, the technical effects and advantages provided by the present invention are:
[0025] 1. The present invention divides the blockchain network into multiple shards, assigns an independent shard chain to each shard, and the shard chain maintains the evidence data and audit records in the shard. Sharding can reduce the burden of the entire network and improve the scalability of the system. Each shard has an independent chain, which can independently process evidence data and audit tasks, thereby reducing the overall complexity of the system and accelerating the data processing and audit process. When data is exchanged between different shards, the network communication status between different shards is judged, and the network stability when data is exchanged between different shards is evaluated. The evaluation of the network stability between different shards helps to discover and solve network communication problems, thereby optimizing network communication efficiency. Reasonable shard design and task queue management can reduce network congestion and delay, improve the speed and stability of data exchange, design a task queue management system, queue and manage evidence requests and audit tasks according to priority, judge the degree of management anomalies in the task execution process, and evaluate the management efficiency in the task execution process. By evaluating the management efficiency of the task execution process, task execution anomalies can be discovered and handled in a timely manner, ensuring that audit tasks are carried out in an orderly manner according to priority. This helps to improve audit efficiency and accuracy and ensure the credibility of audit results.
[0026] 2. The present invention conducts a comprehensive analysis of the network stability when exchanging data between different shards and the management efficiency during task execution, evaluates the efficiency and stability of the audit process between different shards, and promptly warns of abnormal conditions. Comprehensive analysis of network stability and task management efficiency can help identify and resolve factors that may cause system instability, thereby improving the stability and reliability of the entire audit system. According to the results of the comprehensive analysis, resource allocation can be reasonably optimized and adjusted to ensure that data exchange and task execution processes between different shards can proceed smoothly and maximize the use of system resources. By timely warning and handling of abnormal conditions, user satisfaction and trust in the audit system can be improved, providing users with a more stable and efficient audit service experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0028] Figure 1 The figure is a flow chart of the method of the present invention.
[0029] Figure 2 It is a system module diagram of the present invention. DETAILED DESCRIPTION
[0030] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0031] Example 1
[0032] See also Figure 1 and Figure 2 As shown, the security audit method based on distributed blockchain trusted evidence in this embodiment includes the following steps:
[0033] S1: Divide the blockchain network into multiple shards, assign an independent shard chain to each shard, and use the shard chain to maintain the evidence data and audit records within the shard, allowing data exchange and communication between different shards;
[0034] S2: When data is exchanged between different shards, the network communication status between different shards is judged, and the network stability when data is exchanged between different shards is evaluated;
[0035] S3: Design a task queue management system to queue and manage evidence storage requests and audit tasks according to priority, determine the degree of management anomalies in the task execution process, and evaluate the management efficiency in the task execution process;
[0036] S4: Comprehensively analyze the network stability when exchanging data between different shards and the management efficiency during task execution, evaluate the efficiency and stability of the audit process between different shards, and issue timely warnings for abnormal conditions.
[0037] In S1, the blockchain network is divided into multiple shards, and each shard is assigned an independent shard chain. The shard chain maintains the evidence data and audit records in the shard, allowing data exchange and communication between different shards. Specifically:
[0038] Define sharding rules: Determine the rules for sharding, which can be based on factors such as geographic location, evidence type, and audit requirements.
[0039] Determine the number of shards: Determine the number of shards based on the network scale and evidence audit requirements, and reasonably balance the number of shards and network load.
[0040] Shard chain node configuration: Create an independent shard chain for each shard and configure the corresponding shard nodes to ensure the stable operation of the shard chain.
[0041] Initial shard chain state: Initialize the genesis block of the shard chain and set the initial state of the shard chain, including the consensus mechanism, initial node, initial parameters, etc.
[0042] Cross-shard communication protocol: Design a cross-shard communication protocol to allow data exchange and communication between different shards. The protocol may include message format, network transmission method, data verification mechanism, etc.
[0043] Data exchange interface: defines the data exchange interface, specifies the method and format of data exchange between shards, and ensures data security and consistency.
[0044] Data synchronization mechanism: Implement data synchronization mechanism between shards to ensure consistency of evidence data and audit records within the shards. Data synchronization can be performed by polling, broadcasting, subscription, etc.
[0045] Communication node configuration: Configure cross-shard communication nodes as a bridge for data exchange and communication to ensure information transmission and exchange between shards.
[0046] Cross-shard audit strategy: Develop a cross-shard audit strategy, define the process and methods of cross-shard auditing, and ensure a comprehensive audit of the evidence data and audit records of the entire network.
[0047] Data consistency verification: Design a data consistency verification mechanism to verify and confirm data exchanged across shards to ensure the integrity and authenticity of the data.
[0048] Monitoring system construction: Establish a network monitoring system to monitor the operating status and performance indicators of the shard chain in real time, and promptly detect and handle abnormal situations.
[0049] Fault handling mechanism: Design a fault handling mechanism for the shard chain, including node fault handling, data recovery, shard reorganization, etc., to ensure the stable operation of the network.
[0050] Among them, when data is exchanged between different shards, the network communication status between different shards is judged, and the network stability when data is exchanged between different shards is evaluated, specifically:
[0051] Perform periodic network connection tests to determine the connection status between different shards. You can use the ping command or a dedicated network connection test tool to test network latency, packet loss rate, and other indicators.
[0052] Monitor the network delay and packet loss rate between different shards in real time. Increased delay and packet loss rate may affect the efficiency and stability of data exchange, so abnormal situations need to be discovered and handled in a timely manner.
[0053] Measure the data transfer rate between different shards to evaluate the efficiency and performance of data exchange. A low transfer rate may cause delays and blockages in the data exchange process.
[0054] Monitor the network load between different shards to ensure the reasonable allocation and utilization of network bandwidth and resources. Excessive network load may cause network congestion and increase transmission delay.
[0055] Implement fault detection mechanisms to promptly detect and handle network failures and anomalies. Evaluate the self-healing capabilities between different shards, including network recovery time and data integrity assurance after node failure.
[0056] Use the ping command test tool to test network latency, packet loss rate and other indicators, including:
[0057] Open a terminal or command prompt window to enter the command line interface.
[0058] To execute the ping command, enter the command in the command line interface:
[0059] Wait for the test results. After executing the command, the system will send the specified number of ping requests to the target address and display the delay and packet loss of each request. Wait for all tests to complete.
[0060] Analyze the test results. After the test is completed, analyze the displayed results. Focus on the following indicators: Average delay: Displays the average delay time of each ping request, usually in milliseconds (ms).
[0061] Packet Loss: Shows the percentage of ping requests that were lost. The lower the packet loss rate, the better, and it should usually be close to 0%.
[0062] Minimum and Maximum delays: Displays the minimum and maximum delays of all ping requests.
[0063] Take appropriate actions based on the test results. If you find that the latency is too high or the packet loss rate is high, you may need to investigate and resolve network issues, such as increasing bandwidth, improving network connections, etc.
[0064] You can perform the ping command test as many times as needed to obtain more stable and accurate results. You can perform the test at different time periods and under different conditions to understand how network performance changes.
[0065] The method for obtaining the network communication stability value is:
[0066] Set a fixed-size sliding window to store the ping command results in the most recent period of time. The window size can be adjusted as needed, usually selecting a suitable time range, such as the results in the past 10 minutes.
[0067] Use the ping command to send requests to the target address regularly (for example, every 30 seconds), record the results, and save information such as the delay and packet loss rate of each ping command in a sliding window;
[0068] Perform weighted calculation on each ping result in the sliding window to obtain the stable value of network communication. The following weighted algorithm can be used: weight each ping result according to its time interval in the sliding window. Assuming the delay value is Li, the time interval is Ti, and the weight coefficient is Wi, where i represents the i-th ping result, calculate the weighted average delay. The specific calculation expression can be: Where n is the number of ping results in the sliding window. The weighted average packet loss rate can be obtained in the same way, which will not be described here.
[0069] The network communication stability value is calculated by combining the weighted average delay and the weighted average packet loss rate. For example, a simple weighted average method or a comprehensive calculation based on a certain weight ratio can be used. Assume that the delay weight coefficient is W 延迟 , the packet loss rate weight coefficient is W 丢包率 , the network communication stability value calculation expression is: comprehensive stability value = (W 延迟 *weighted average delay)+(W 丢包率 *weighted packet loss rate), and calculate the network communication stability value based on the result obtained by weighted calculation.
[0070] The larger the network communication stability value, the higher the efficiency and stability of the audit process between different shards. This is because the calculation of the network communication stability value is based on a comprehensive evaluation of indicators such as weighted average delay and weighted average packet loss rate, which directly affect the stability and reliability of the network connection. Therefore, when the network communication stability value is large, the following inferences can be drawn:
[0071] A larger network communication stability value means a lower average delay, that is, the data transmission delay between different shards is smaller. The data exchange and information transmission operations involved in the audit process can be completed more quickly, which improves the efficiency of the audit process.
[0072] A larger network communication stability value indicates a lower average packet loss rate, which means that the probability of data loss during transmission is lower. This means that data transmission during the audit process is more reliable, reducing the risk of data loss or corruption, and helping to ensure the accuracy and completeness of the audit results.
[0073] The increase in the network communication stability value reflects the improved stability of the network connection. The data exchange process between different shards is more stable and reliable, and is not easily disturbed or fluctuated by external factors, thus ensuring the stability and continuity of the audit process.
[0074] In general, when the network communication stability value is large, the efficiency and stability of the audit process between different shards are higher. Audit operations can be performed faster and more reliably, and the performance and efficiency of the entire audit system are improved, which helps to improve the efficiency and quality of audit work.
[0075] Therefore, the increase in the network communication stability value has a positive impact on the efficiency and stability of the audit process between different shards, and helps to improve the overall performance and reliability of the audit system.
[0076] In S3, a task queue management system is designed to queue and manage evidence storage requests and audit tasks according to priority, determine the degree of management anomalies in the task execution process, and evaluate the management efficiency in the task execution process. Specifically:
[0077] Design a task queue system to store evidence requests and audit tasks. The task queue can use a first-in-first-out (FIFO) or priority queue method to ensure that tasks are queued and managed according to priority.
[0078] Define priority rules for evidence storage requests and audit tasks. Priority can be determined based on factors such as task importance, urgency, and processing time. For example, urgent evidence storage requests may have a higher priority.
[0079] When a new evidence storage request or audit task arrives, add the task to the task queue according to its priority. Ensure that the tasks are arranged in order of priority and process the tasks with higher priority first.
[0080] Monitor the task execution process, including the start, execution, and completion of the task. Record the task execution time, processing progress and results, and whether any abnormalities occur.
[0081] Design an exception handling mechanism to detect and handle abnormal situations during task execution. For example, task execution timeout, execution failure, insufficient resources, etc. may lead to task management exceptions.
[0082] Regularly evaluate the management efficiency during task execution. You can evaluate management efficiency based on indicators such as task processing time, priority, and abnormal situations, and analyze the timeliness and accuracy of task execution.
[0083] According to the evaluation results, timely optimize and adjust the task queue management system. It may be necessary to adjust the task priority rules, adjust the capacity of the task queue, improve the exception handling mechanism, etc., to improve management efficiency and reduce the possibility of abnormal situations.
[0084] Continuously monitor the operation of the task queue management system and collect data and feedback information from the task execution process. Improve and optimize according to actual conditions to ensure the stability and efficiency of the task management process.
[0085] The method for obtaining the task management efficiency anomaly index is as follows: obtain real-time feedback data of the task processing process in the task queue, obtain the task processing time, task waiting time, and task completion rate in the real-time feedback data, standardize the task processing time, task waiting time, and task completion rate obtained in real time, obtain the task processing time, task waiting time, and task completion rate under the expected standard state, compare the real-time task processing time, task waiting time, and task completion rate with the corresponding task processing time, task waiting time, and task completion rate under the standard state, calculate the standard deviation of the task processing time, the standard deviation of the task waiting time, and the standard deviation of the task completion rate, respectively, calculate the ratio of the standard deviation of the task processing time, the standard deviation of the task waiting time, and the standard deviation of the task completion rate to the real-time task processing time, the task waiting time, and the task completion rate, that is, calculate the task management efficiency anomaly index.
[0086] The larger the abnormal index of task management efficiency, the more abnormal situations there are in the task management process, which leads to the worse efficiency and stability of the audit process between different shards. Specifically:
[0087] A large abnormal index of task management efficiency indicates that there are large fluctuations or abnormalities in indicators such as task processing time, waiting time, and completion rate. This may mean that the task execution process is unstable and the execution efficiency between different shards during the audit process will also be affected.
[0088] The increase in abnormal situations may lead to a decrease in the efficiency of audit task execution. For example, long processing time, long waiting time or low task completion rate will affect the timely completion of audit tasks, thereby reducing audit efficiency.
[0089] Abnormal task management efficiency may lead to uneven resource allocation, where some shards may face task backlogs or insufficient resources, while other shards may be idle. This uneven resource allocation will affect the overall efficiency and stability of the audit process.
[0090] Abnormal task management efficiency may lead to an increase in errors or abnormalities in the task execution process, thus affecting the accuracy of the audit results. For example, long processing time may lead to data loss or processing errors, and long waiting time may lead to task timeouts, which will affect the credibility of the audit results.
[0091] Therefore, when the task management efficiency anomaly index is large, it means that there are more anomalies in the task management process, which may lead to poor efficiency and stability of the audit process between different shards. It is necessary to adjust and optimize the task management system in time to improve audit efficiency and stability.
[0092] In S4, the network stability during data exchange between different shards and the management efficiency during task execution are comprehensively analyzed to evaluate the efficiency and stability of the audit process between different shards, and to provide timely warnings for abnormal conditions, including:
[0093] The network communication stability value and the task management efficiency anomaly index are normalized, and the efficiency stability coefficient of the audit process between different shards is calculated based on the normalized network communication stability value and the task management efficiency anomaly index.
[0094] For example, the present invention can use the following formula to calculate the efficiency stability coefficient of the audit process between different shards, and the calculation expression is: In the formula, ct k is the stability coefficient, np d is the stable value of network communication, rm s is the task management efficiency abnormality index, a1 and a2 are the network communication stability value and the proportional coefficient of the task management efficiency abnormality index, and a2>a1>0;
[0095] By normalizing the network communication stability value and task management efficiency anomaly index, they can be converted to the same scale, making them easier to compare and comprehensively evaluate. By calculating the efficiency stability coefficient of the audit process between different shards, the stability of the audit efficiency between each shard can be more accurately measured and compared, providing a clearer reference for system managers, helping to optimize resource allocation and adjust audit strategies, and further improving the efficiency and stability of the overall audit system.
[0096] Compare the efficiency stability coefficient of the audit process between different shards with the stability threshold. If the efficiency stability coefficient of the audit process between different shards is greater than or equal to the stability threshold, it means that the efficiency stability of the audit process between different shards is higher, and a normal signal is issued at this time; if the efficiency stability coefficient of the audit process between different shards is less than the stability threshold, it means that the efficiency stability of the audit process between different shards is lower, and an abnormal signal is issued at this time. After receiving the abnormal signal, the staff should immediately confirm and check the abnormal information.
[0097] In this embodiment, by dividing the blockchain network into multiple shards, assigning an independent shard chain to each shard, the shard chain maintains the evidence data and audit records in the shard, allowing data exchange and communication between different shards, judging the network communication status between different shards when exchanging data between different shards, evaluating the network stability when exchanging data between different shards, designing a task queue management system, queuing evidence requests and audit tasks according to priority, judging the management abnormality of the task execution process, evaluating the management efficiency during the task execution process, comprehensively analyzing the network stability when exchanging data between different shards and the management efficiency during the task execution process, evaluating the efficiency and stability of the audit process between different shards, and timely warning of abnormal states, comprehensively analyzing the network stability and task management efficiency, can help identify and solve factors that may cause system instability, thereby improving the stability and reliability of the entire audit system. According to the results of the comprehensive analysis, resource allocation can be reasonably optimized and adjusted to ensure that data exchange and task execution processes between different shards can proceed smoothly and maximize the use of system resources. By timely warning and handling of abnormal conditions, users' satisfaction and trust in the audit system can be improved, providing users with a more stable and efficient audit service experience.
[0098] Example 2
[0099] The security audit system based on distributed blockchain trusted evidence in this embodiment includes a sharding module, a network monitoring module, a task management monitoring module, and an analysis and early warning module;
[0100] in,
[0101] Sharding module: divides the blockchain network into multiple shards, assigns an independent shard chain to each shard, and the shard chain maintains the evidence data and audit records within the shard, allowing data exchange and communication between different shards;
[0102] Network monitoring module: when data is exchanged between different shards, it determines the network communication status between different shards and evaluates the network stability when data is exchanged between different shards;
[0103] Task management monitoring module: Design a task queue management system to queue and manage evidence storage requests and audit tasks according to priority, determine the degree of management anomalies in the task execution process, and evaluate the management efficiency in the task execution process;
[0104] Analysis and early warning module: Comprehensively analyze the network stability when exchanging data between different shards and the management efficiency during task execution, evaluate the efficiency and stability of the audit process between different shards, and issue timely early warnings for abnormal conditions.
[0105] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters in the formula are set by technicians in this field according to actual conditions.
[0106] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented by software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state hard disk.
[0107] It should be understood that the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship, but it may also indicate an "and / or" relationship. Please refer to the context for specific understanding.
[0108] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can be represented by: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.
[0109] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0110] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0111] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0112] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0113] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0114] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0115] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage media include: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks or optical disks.
[0116] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A security audit method based on distributed blockchain trusted evidence, characterized by: The following steps are involved: S1: Divide the blockchain network into multiple shards, assign an independent shard chain to each shard, and use the shard chain to maintain the evidence data and audit records within the shard, allowing data exchange and communication between different shards; S2: When data is exchanged between different shards, the network communication status between different shards is judged, and the network stability when data is exchanged between different shards is evaluated; S3: Design a task queue management system to queue and manage evidence storage requests and audit tasks according to priority, determine the degree of management anomalies in the task execution process, and evaluate the management efficiency in the task execution process; S4: Comprehensively analyze the network stability when exchanging data between different shards and the management efficiency during task execution, evaluate the efficiency and stability of the audit process between different shards, and issue timely warnings for abnormal conditions.
2. The security audit method based on distributed blockchain trusted evidence according to claim 1 is characterized by: In S2, when data is exchanged between different shards, the network communication status between different shards is judged, and the network stability when data is exchanged between different shards is evaluated; The method for obtaining the network communication stability value is: Set a sliding window of fixed size to store the ping command results in the recent period of time; Use the ping command to periodically send requests to the target address and record the results. The information such as the delay and packet loss rate of each ping command is saved in a sliding window. Perform weighted calculation on each ping result in the sliding window to obtain a stable value of network communication; Each ping result is weighted according to its time interval in the sliding window. The delay value is Li, the time interval is Ti, and the weight coefficient is Wi, where i represents the i-th ping result. The weighted average delay is calculated. The specific calculation expression is: Where n is the number of ping results in the sliding window; The network communication stability value is calculated by comprehensively calculating the weighted average delay and weighted average packet loss rate. The delay weight coefficient is W. 延迟 , the packet loss rate weight coefficient is W 丢包率 , the network communication stability value calculation expression is: comprehensive stability value = (W 延迟 *weighted average delay)+(W 丢包率 *weighted packet loss rate), and calculate the network communication stability value based on the result obtained by weighted calculation.
3. The security audit method based on distributed blockchain trusted evidence according to claim 2 is characterized by: In S3, a task queue management system is designed to queue and manage evidence storage requests and audit tasks according to priority, determine the degree of management anomalies in the task execution process, and evaluate the management efficiency in the task execution process; The method for obtaining the task management efficiency anomaly index is as follows: obtain real-time feedback data of the task processing process in the task queue, obtain the task processing time, task waiting time, and task completion rate in the real-time feedback data, standardize the task processing time, task waiting time, and task completion rate obtained in real time, obtain the task processing time, task waiting time, and task completion rate under the expected standard state, compare the real-time task processing time, task waiting time, and task completion rate with the corresponding task processing time, task waiting time, and task completion rate under the standard state, calculate the standard deviation of the task processing time, the standard deviation of the task waiting time, and the standard deviation of the task completion rate, respectively, calculate the ratio of the standard deviation of the task processing time, the standard deviation of the task waiting time, and the standard deviation of the task completion rate to the real-time task processing time, the task waiting time, and the task completion rate, that is, calculate the task management efficiency anomaly index.
4. The security audit method based on distributed blockchain trusted evidence according to claim 3 is characterized by: The network communication stability value and the task management efficiency anomaly index are normalized. The efficiency stability coefficient of the audit process between different shards is calculated through the normalized network communication stability value and the task management efficiency anomaly index. The calculation expression is: In the formula, ct k is the stability coefficient, np d is the stable value of network communication, rm s is the task management efficiency abnormality index, a1 and a2 are the network communication stability value and the proportional coefficient of the task management efficiency abnormality index, and a2>a1>0.
5. The security audit method based on distributed blockchain trusted evidence according to claim 4 is characterized by: Compare the efficiency stability coefficient of the audit process between different shards with the stability threshold. If the efficiency stability coefficient of the audit process between different shards is greater than or equal to the stability threshold, a normal signal is issued; If the efficiency stability coefficient of the audit process between different shards is less than the stability threshold, an abnormal signal is issued.
6. A security audit system based on distributed blockchain trusted evidence, used to implement the security audit method based on distributed blockchain trusted evidence as described in any one of claims 1 to 5, characterized in that: It includes sharding module, network monitoring module, task management monitoring module and analysis and early warning module; Sharding module: divides the blockchain network into multiple shards, assigns an independent shard chain to each shard, and the shard chain maintains the evidence data and audit records within the shard, allowing data exchange and communication between different shards; Network monitoring module: when data is exchanged between different shards, it determines the network communication status between different shards and evaluates the network stability when data is exchanged between different shards; Task management monitoring module: Design a task queue management system to queue and manage evidence storage requests and audit tasks according to priority, determine the degree of management anomalies in the task execution process, and evaluate the management efficiency in the task execution process; Analysis and early warning module: Comprehensively analyze the network stability when exchanging data between different shards and the management efficiency during task execution, evaluate the efficiency and stability of the audit process between different shards, and issue timely early warnings for abnormal conditions.