Auditing log processing method and device, equipment and storage medium
By introducing TPCM module and chain hashing operations in the audit log processing, a data fingerprint associated with sequence information, time information and the previous audit log hash value is generated, which solves the problem of order integrity protection of audit logs and achieves efficient and secure protection of audit logs.
Patent Information
- Application Number
- CN202411905557.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-23
- Publication Date
- 2025-05-13
AI Technical Summary
The existing technology is difficult to effectively protect the order integrity of audit logs, resulting in security issues such as log import, loss, and malicious deletion, affecting data recovery, data consistency, security and compliance.
The audit log processing method based on the TPCM module is adopted to generate data fingerprints through chain hashing operations and encrypt and store them to ensure that the data fingerprint is associated with the sequence information, time information and the hash value of the previous audit log. If the change in factors causes the data fingerprint to change, security problems can be detected.
Effectively detect and prevent security issues such as disordered sequence of audit logs, log import, loss, and malicious deletion, improve the integrity, accuracy and security of audit logs, and enhance the overall security level of the system.
Smart Images

Figure CN119989376A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of log security technology, and in particular to a method, device, equipment and storage medium for processing audit logs. Background Art
[0002] Log auditing refers to the process of collecting, storing, analyzing and reporting logs generated by systems, networks and applications. Through log auditing, system anomalies, security threats and violations can be discovered in a timely manner for quick response and disposal. It can also help optimize system performance and improve system stability, thereby protecting system security. Log auditing has become an important guarantee for security and compliance. Therefore, the authenticity and accuracy of audit logs are crucial.
[0003] At present, encryption technology, access control, regular backup, log audit, monitoring mechanism and other measures are often used to protect the integrity of operation logs. However, the above scheme can only protect the integrity of each audit log. If different audit logs are out of order, log import, log loss, malicious deletion and other phenomena occur, the above security issues cannot be effectively checked, thus posing security risks, which in turn brings about data recovery difficulties, data consistency issues, security risks, compliance issues, and affects troubleshooting and resolution.
[0004] Therefore, how to more effectively protect audit logs and improve the integrity, accuracy and security of audit logs is a problem that technical personnel in this field need to solve. Summary of the invention
[0005] The present application provides an audit log processing method, apparatus, device and storage medium to more effectively protect the audit log and improve the integrity, accuracy and security of the audit log.
[0006] In a first aspect, the present application provides a method for processing an audit log, the processing method being based on a TPCM module, and the processing method comprising:
[0007] Get the target audit log to be processed;
[0008] Determining sequence information and time information corresponding to the target audit log;
[0009] Performing a chain hash operation on the target audit log, the initial hash value, the sequence information and the time information to generate a target data fingerprint; the initial hash value is the hash value of the previous audit log;
[0010] The target data fingerprint is encrypted to generate an encrypted data fingerprint, and the encrypted data fingerprint is stored.
[0011] Optionally, obtain the target audit log to be processed, including:
[0012] Get the raw audit logs to be processed;
[0013] Performing format preprocessing on the original audit log to generate a preprocessed audit log;
[0014] The preprocessed audit log is encrypted to obtain the target audit log.
[0015] Optionally, performing a chain hash operation on the target audit log, the initial hash value, the sequence information, and the time information to generate a target data fingerprint includes:
[0016] Performing a chain hash operation on the target audit log, the initial hash value, the sequence information, and the time information to obtain a target hash value;
[0017] The target hash value is combined with relevant information to generate a target data fingerprint; the relevant information includes at least one of sequence information, time information and signature information.
[0018] Optionally, after determining the sequence information and time information corresponding to the target audit log, the method further includes:
[0019] Determine whether the target audit log is the first audit log;
[0020] If yes, the identification information of the TPCM module is used as the initial hash value;
[0021] If not, the hash value of the previous audit log is used as the initial hash value.
[0022] Optionally, the processing method further includes:
[0023] Receive an audit log verification instruction; wherein the audit log verification instruction is used to verify each audit log one by one according to the order in which the audit logs are generated;
[0024] Identify the audit logs to be verified;
[0025] Extracting the original hash value from the encrypted data fingerprint of the audit log to be verified;
[0026] Recalculate the current hash value of the audit log to be verified;
[0027] The original hash value and the current hash value are compared to generate a verification result.
[0028] Optionally, comparing the original hash value with the current hash value to generate a verification result includes:
[0029] Determine whether the original hash value is the same as the current hash value;
[0030] If yes, the verification is deemed successful;
[0031] If not, compare the original hash value with the current hash value to determine the reason for the verification failure; the reason for the verification failure includes: the content, order, generation time of the audit log to be verified are different, and the hash value of the previous audit log of the audit log to be verified is different. At least one of the above.
[0032] Optionally, extracting the original hash value from the encrypted data fingerprint of the audit log to be verified includes:
[0033] Decrypting the encrypted data fingerprint of the audit log to be verified to generate an original data fingerprint;
[0034] An original hash value is extracted from the original data fingerprint.
[0035] In a second aspect, the present application provides a device for processing an audit log, the processing device being based on a TPCM module, and the processing device comprising:
[0036] The acquisition module is used to obtain the target audit log to be processed;
[0037] A determination module, used to determine the sequence information and time information corresponding to the target audit log;
[0038] A calculation module, used to perform a chain hash operation on the target audit log, the initial hash value, the sequence information and the time information to generate a target data fingerprint; the initial hash value is the hash value of the previous audit log;
[0039] An encryption module, used for encrypting the target data fingerprint to generate an encrypted data fingerprint;
[0040] A storage module is used to store the encrypted data fingerprint.
[0041] In a third aspect, the present application provides an electronic device, including:
[0042] A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor executes the steps of the above-mentioned processing method of the present application through the computer program.
[0043] In a fourth aspect, the present application also provides a computer storage medium, which stores computer executable instructions, and the computer executable instructions are used to execute the steps of the above-mentioned processing method of the present application.
[0044] The above technical solution provided by the embodiment of the present application has the following advantages over the prior art: the present application provides an audit log processing solution based on the TPCM module. In this solution, after obtaining the target audit log to be processed, it is necessary to determine the sequence information and time information corresponding to the target audit log, and then perform a chain hash operation on the target audit log, the hash value of the previous audit log, the sequence information and the time information to generate a target data fingerprint, and encrypt and store the target data fingerprint. It can be seen that the present application needs to perform a chain hash operation on the audit log, the sequence information, the time information and the hash value of the previous audit log to generate the target data fingerprint. In this way, the data fingerprint can be associated with the sequence information, the time information and the previous audit log. If one of the factors changes, the data fingerprint will change, so that the audit log can be effectively checked for security issues such as disordered order, log import, log loss, malicious deletion, etc.; and the present application processes the audit log based on the TPCM module, which greatly improves the overall security level of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0046] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0047] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.
[0048] Figure 1 A flowchart of a method for processing an audit log provided in an embodiment of the present application;
[0049] Figure 2 A flowchart of another method for processing an audit log provided in an embodiment of the present application;
[0050] Figure 3 A flow chart of generating a data fingerprint provided in an embodiment of the present application;
[0051] Figure 4 A schematic diagram of a verification process provided in an embodiment of the present application;
[0052] Figure 5 A schematic diagram of the structure of an audit log processing device provided in an embodiment of the present application;
[0053] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0054] Log auditing refers to the process of collecting, storing, analyzing and reporting logs generated by systems, networks and applications. In the face of various security threats and the emergence of new types of threats, log auditing plays a significant role. Through audit logs, security threats can be discovered and traced in a timely manner. Through analysis, abnormal behaviors can be quickly extracted and traced back. Therefore, the authenticity and accuracy of logs are crucial. At present, log auditing is also facing security challenges. The number of illegal behaviors against audit logs is increasing. How to ensure the integrity, credibility and security of logs has become a problem that everyone is paying more and more attention to.
[0055] To solve the above problems, the existing technology provides solutions to the problems to a certain extent. Some common methods to ensure the integrity and credibility of logs and improve the security of logs are to effectively protect the integrity of operation logs and improve security through encryption technology, access control, regular backup, log auditing, monitoring mechanisms and other measures. For example, logs are encrypted and stored using encryption algorithms. For example, symmetric encryption algorithms such as AES (Advanced Encryption Standard) can be used to encrypt logs immediately after they are generated. In this way, even if the log data is stolen, the attacker cannot obtain the content without the decryption key, thereby ensuring the confidentiality and integrity of the log content. For example, digital signatures are used to sign the logs with private keys and add digital signatures to the logs. When the logs are generated, the private key is used to sign the logs, and the corresponding public key is used for verification. For example, the RSA (Rivest-Shamir-Adleman) algorithm is used to generate digital signatures. This can ensure the authenticity of the log source and prevent the logs from being tampered with, because once the log content is modified, the digital signature verification will fail. For example, the hash value of the log is calculated and saved through a hash function. Hash functions such as SHA-256 (Secure Hash Algorithm 256-bit) can generate unique hash values for logs. During log storage and transmission, the hash value is recalculated regularly and compared with the original hash value. If there is any inconsistency, it means that the log may have been tampered with.
[0056] Existing technologies can indeed ensure the integrity of audit logs and prevent them from being tampered with to a certain extent. However, the essence of anti-tampering is to protect the integrity of each log and verify the integrity of a single log, so as to achieve the purpose of protection. However, audit logs still have other security risks, such as disordered order, log import, log loss, malicious deletion and other security issues. Malicious behaviors such as deletion, loss, and disorder of key logs may have the following serious impacts:
[0057] 1. Difficulty in data recovery: Audit logs record key operations and events of a system or application. If these logs are deleted, data recovery will be impossible when a system problem occurs or when a specific operation needs to be backtracked. This may result in an inability to accurately understand the historical status of the system, making problem solving more difficult.
[0058] 2. Data consistency issues: The confusion, deletion, import, etc. of logs may lead to inconsistent data, especially when transaction processing or data updates are involved. If the logs are deleted or confused, then unfinished transactions may not be rolled back correctly, resulting in inconsistent data in the database.
[0059] 3. Security risks: Logs are an important tool for security auditing and monitoring. If logs are maliciously processed, administrators will lose this important means of security monitoring, thereby increasing the risk of system attacks. For example, if the order of log records is disrupted, the timeline of events may be inaccurate, making it difficult to organize and review, which may lead to misunderstandings of attack paths, thereby delaying the response and repair of attacks; if key logs are maliciously deleted, it may lead to the loss of key evidence of security incidents, making it impossible for the security team to conduct effective post-analysis and investigation, and the attackers can cover up their means of activities. The security team will also lose the ability to track attack behaviors and cannot determine the source and scope of the attack.
[0060] 4. Compliance issues: Many industry regulations require companies to retain log records for a certain period of time to meet compliance requirements. If critical logs are deleted, companies may not be able to meet these compliance requirements, facing legal penalties and reputational damage.
[0061] 5. Impact on troubleshooting and resolution: Log files can help administrators quickly identify and resolve system or application failures. If critical logs are maliciously deleted or lost, the troubleshooting and resolution process will become more difficult, which may lead to extended system downtime and affect business operations.
[0062] To solve the above security problems, the embodiments of the present application provide a method, device, equipment and storage medium for processing an audit log. After the audit log is processed by the technical solution provided by the present application, any modification to the log will affect the hash value of all subsequent logs, thereby providing an effective mechanism to detect unauthorized modifications. If a log is tampered with, deleted, or obfuscated, etc., through the verification of the hash chain, the new hash value will not match the original hash value, so that the inconsistency of the data can be quickly detected. Hash operations are highly sensitive and irreversible. Even a small modification to the log data will result in a significant change in the hash value. This method can provide powerful anti-tampering capabilities.
[0063] Before explaining this application, the terms involved in this application are explained first:
[0064] TPCM (Trusted Platform Control Module): Trusted Platform Control Module, a hardware core module integrated in the trusted computing platform, used to establish and protect the trust source point, providing integrity measurement, secure storage, trusted reporting, and cryptographic services for trusted computing.
[0065] Digital signature: A digital signature, also known as a public key digital signature, is a string of numbers that can only be generated by the sender of the information and cannot be forged by others. This string of numbers is also an effective proof of the authenticity of the information sent by the sender. It is a method for identifying digital information similar to an ordinary physical signature written on paper, but it is implemented using technology in the field of public key encryption. A set of digital signatures usually defines two complementary operations, one for signing and the other for verification. Digital signatures are the application of asymmetric key encryption technology and digital summary technology.
[0066] Hash: Hash, generally translated as hash, hash, or transliterated as hash, is to transform an input of any length (also called pre-image) into an output of fixed length through a hash algorithm, and the output is the hash value. This conversion is a compression mapping, that is, the space of hash values is usually much smaller than the space of inputs, and different inputs may hash to the same output, so it is impossible to determine the unique input value from the hash value. Simply put, it is a function that compresses a message of any length into a message digest of a fixed length. Common hash functions include MD5 (Message-DigestAlgorithm 5), SHA-1 (Secure Hash Algorithm 1), SHA-2 (Secure Hash Algorithm 2) (such as SHA-256, SHA-512), etc. These hash functions are widely used in data integrity verification, cryptographic storage, digital signatures, blockchain technology and other fields.
[0067] Hash algorithm: Hash algorithm is also called hash algorithm. Although Hash algorithm is called an algorithm, it is actually more like an idea. There is no fixed formula for Hash algorithm. As long as the algorithm conforms to the hash idea, it can be called Hash algorithm.
[0068] Hash operation: Hash operation is a process of converting an input of any length into a fixed-length output (usually a small integer called a "hash value") through a certain algorithm. This process is irreversible, that is, it is usually impossible to restore the original input data from the hash value. Hash operation is widely used in many fields, including data encryption, data retrieval, error detection, etc.
[0069] Hash Chain: Hash Chain is a data structure that uses hash functions to link a series of data blocks (or blocks), and each data block contains the hash value of the previous data block as part of it. This structure ensures the integrity and immutability of the data on the chain. It is widely used in blockchain technology, data integrity verification, and secure storage.
[0070] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0071] The disclosure below provides many different embodiments or examples to implement different structures of the present invention. In order to simplify the disclosure of the present invention, the parts and settings of specific examples are described below. Of course, they are only examples, and the purpose is not to limit the present invention. In addition, the present invention can repeat reference numbers and / or letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed.
[0072] See also Figure 1 , is a flowchart of a method for processing an audit log provided in an embodiment of the present application. The processing method is based on the TPCM module and specifically includes the following steps:
[0073] S101, obtaining the target audit log to be processed;
[0074] In this application, the processing method of the audit log is implemented based on the TPCM module. In the dual architecture of trusted computing, the TPCM module is the hardware core module for establishing and protecting the trust source point, the core component of the trust root, and the core component for realizing the protection component in the dual architecture. It is responsible for the trusted measurement and protection of the computing component. The TPCM module adds the control function of the trust root on the basis of TCM (Trusted Platform Module), adopts my country's independent cryptographic system as the immune gene, realizes the combination of cryptography and control, and provides a hardware-level security foundation for the trusted system. In the field of trusted computing, the TPCM module is not only responsible for the control of platform resources, but also undertakes advanced functions such as active measurement, so that it plays a vital role in system security. The TPCM module helps to build a safe, reliable and trustworthy computing environment, especially in areas with high security requirements, such as government affairs, finance and other fields. It has important significance in the security of information systems.
[0075] The TPCM module in this application provides integrity measurement, secure storage, cryptographic services, trusted verification and other functions for trusted computing. The cryptographic capabilities provided by the TPCM module can meet the requirements of digital signature / verification, asymmetric / symmetric encryption and decryption, data integrity verification, true random number generation, key generation and management, and can ensure the confidentiality, authenticity, integrity and non-repudiation of sensitive data. Audit logs, as an important tool for recording system activity trajectories, often become the target of attackers. In order to ensure the authenticity, completeness and availability of audit logs, the TPCM module protects them through a series of technologies and mechanisms. These measures include but are not limited to active measurement, data fingerprint generation, trusted verification, encrypted storage, strict access control, secure transmission, distributed storage and blockchain and other technical applications. Through these methods, the TPCM module ensures the authenticity, completeness, confidentiality and availability of audit logs, greatly improving the overall security level of the system.
[0076] Moreover, the TPCM module in this application, as a core component of trusted computing, can provide safe and reliable hardware support and protection. Performing hash operations based on the TPCM module can further enhance the credibility and security of anti-tampering protection; chained hash operations combined with the TPCM module make the management and query of audit logs efficient and secure. This approach is effective in cryptography and data integrity protection because it provides an effective way to verify the authenticity and integrity of data. An example of security effect: For example, if one entry is deleted from the audit log, although the existing logs have not been tampered with, by comparing the hash values, it can be found that the hash chain does not match the original, and it can be traced back to the source in time to find problems in time.
[0077] In addition, the trusted verification of the TPCM module can also be combined with other security measures to further enhance the protection effect. For example, the audit log data can be encrypted, stored and transmitted through the encryption function of the TPCM module. At the same time, the access control function of the TPCM module can be used to limit access rights to the audit log data to prevent unauthorized access and tampering. These protection measures can effectively prevent the audit log from being tampered with or damaged during storage and transmission, and provide strong support for network security and compliance audits. The technology of protecting audit logs through chained hash operations based on the TPCM module has broad application prospects due to its unique algorithm characteristics and significant advantages. By ensuring the integrity and security of the data, this technology can not only meet the current strict security requirements, but also lay a solid foundation for future digital transformation.
[0078] S102, determining the sequence information and time information corresponding to the target audit log;
[0079] In this application, the audit log that needs to be processed currently is called the target audit log. The sequence information is used to indicate the generation order of the target audit log, which can be a sequence number. Each time an audit log is added, its sequence number is increased by one based on the sequence number of the previous audit log. Thus, by verifying the sequence information, it can be determined whether the order of the audit logs has changed, whether there are new audit logs, whether there are deleted audit logs, etc. The time information is specifically the time when the audit log is generated. If the generation time of the audit log changes, it means that the audit log may be a new audit log, or a modified audit log, etc.
[0080] S103, performing a chain hash operation on the target audit log, the initial hash value, the sequence information and the time information to generate a target data fingerprint; the initial hash value is the hash value of the previous audit log;
[0081] After this application determines the sequence information and time information corresponding to the target audit log, it is also necessary to determine whether the target audit log is the first audit log; if so, the identification information of the TPCM module is used as the initial hash value; if not, the hash value of the previous audit log is used as the initial hash value. When generating a data fingerprint, it is necessary to perform a chain hash operation on the target audit log, the initial hash value, the sequence information, and the time information to generate a target data fingerprint. In order to ensure the accuracy of the hash value, in this application, the hash value of the previous audit log can be recalculated. The hash value of the previous audit log needs to be generated after a hash operation based on the hash value, sequence information, and time information of the previous audit log and the previous audit log, and only after verification will it be used to calculate the data fingerprint of the target audit log.
[0082] Among them, when the TPCM module in this application uses a specific chain hash algorithm for hash operation, the hash value calculated by the hash value, sequence information, time information of the previous audit log and the target audit log is unique. As long as any part of the content, sequence and time of the audit log changes, the hash value will change, and the hash values calculated by other subsequent audit logs will also change dramatically. In this way, the hash value of each audit log is associated with the hash value of the previous audit log to form a hash chain. Among them, the sequence information can facilitate the sorting and tracing of logs, and the time information can record the time when the log is generated, which is very important for event sequence judgment and time association in the audit process.
[0083] S104: Encrypt the target data fingerprint, generate an encrypted data fingerprint, and store the encrypted data fingerprint.
[0084] After the target data fingerprint is generated in this application, it can be encrypted and stored to ensure the security of the data fingerprint. In this application, the TPCM module can use an encryption algorithm to encrypt the target data fingerprint. The encryption algorithm can be an SM4 symmetric encryption algorithm or other encryption algorithms, which are not specifically limited here. The purpose of encrypting the target data fingerprint in this application is to protect the confidentiality of the data fingerprint and prevent unauthorized access and tampering. The encrypted data fingerprint will be stored in a secure storage medium, such as a trusted storage area or a protected storage device associated with the TPCM module.
[0085] In summary, this application needs to perform a chain hash operation on the audit log together with the sequence information, time information and the hash value of the previous audit log to generate a target data fingerprint. In this way, the data fingerprint can be associated with the sequence information, time information and the previous audit log. If any one of these factors changes, the data fingerprint will change, thereby effectively detecting security issues such as disordered order, log import, log loss, malicious deletion, etc. in the audit log. In addition, this application processes the audit log based on the TPCM module, which greatly improves the overall security level of the system.
[0086] See also Figure 2 , is a flowchart of another audit log processing method provided in an embodiment of the present application. The processing method is based on the TPCM module and specifically includes the following steps:
[0087] S201, obtaining the original audit log to be processed;
[0088] S202, performing format preprocessing on the original audit log to generate a preprocessed audit log;
[0089] S203, encrypting the preprocessed audit log to obtain a target audit log;
[0090] S204, determining the sequence information and time information corresponding to the target audit log;
[0091] S205, performing a chain hash operation on the target audit log, the initial hash value, the sequence information and the time information to obtain a target hash value;
[0092] S206, combining the target hash value with relevant information to generate a target data fingerprint; the relevant information includes at least one of sequence information, time information and signature information;
[0093] S207: Encrypt the target data fingerprint, generate an encrypted data fingerprint, and store the encrypted data fingerprint.
[0094] In this application, after obtaining the generated original audit log, the original audit log can be first formatted and preprocessed to ensure the standardization and consistency of the data; then the cryptographic operation function of the TPCM module is used to encrypt the preprocessed audit log to protect the content security of the audit log and prevent the data from being illegally accessed and tampered with.
[0095] In addition, after the target hash value is obtained through hash operation, the present application can be combined with other relevant information, such as signature information, sequence information, time information, etc., wherein the sequence information and time information in the relevant information can be doubly protected with the sequence information and time used in the hash operation; the present application generates a target data fingerprint together with the target hash value and related information, which is a unique identifier of the audit log, representing the state of the audit log in a specific order at a specific time, and can provide authentication and integrity verification of the data source. The data fingerprint combined with the hash value can protect the audit log more comprehensively. During the verification process, the integrity and source reliability of the log can be checked at the same time by verifying the relevant information.
[0096] See also Figure 3 , which is a flow chart for generating a data fingerprint provided in the present application. It can be seen from the flow chart that after the nth audit log is generated, the audit log needs to be preprocessed first, and then the preprocessed audit log is encrypted based on the encryption algorithm of the TPCM module, and after adding the sequence number, timestamp and the hash value of the n-1th audit log, the hash value of the nth audit log is calculated based on the hash algorithm of the TPCM module, and the data fingerprint is generated after being combined with other relevant information, and finally the data fingerprint is encrypted and stored based on the encryption algorithm of the TPCM module.
[0097] The generation of the hash value of each audit log in this application depends on the hash value of the previous audit log, thus forming a continuous chain. The system calculates the initial hash value and uses it as part of the new data to perform hash calculations again, and this is done in sequence to form a continuous hash chain, forming an unchangeable chain. For example, if the entries in the audit log are arranged in chronological order, then the hash value of the nth audit log is based not only on its own message content, but also on the hash value of the n-1th audit log. The formula for calculating the hash value is shown below. Here, only the message content Mn of the nth audit log and the hash value H of the n-1th audit log are used. n-1 Take the calculation of the hash value Hn of the nth audit log as an example to illustrate:
[0098] H n =C(M n ||H n-1 )
[0099] Wherein, M represents message, H represents hash, C represents calculation, n is an integer greater than or equal to 1, and H0 is the unique identifier of the TPCM module.
[0100] It can be seen that this application binds the hash value of the audit log with the previous audit log. Each hash value is calculated based on the previous hash value. This method ensures the continuity and uniqueness of the data. In addition, each log entry encryption uses a new authentication key to form an inseparable link, which enhances the overall security and ensures the overall consistency and non-tamperability of the data. Therefore, any tampering with the log will destroy the integrity of the hash chain and achieve effective protection of the audit log.
[0101] In some embodiments of the present application, after the data fingerprint of the audit log is generated, the audit log needs to be verified for integrity. Verifying the integrity of the audit log is an important part of ensuring system security, data integrity and compliance. Trusted verification of the audit log based on the TPCM module is of great significance in multiple scenarios. For example, verifying the audit log can ensure that the log has not been tampered with during transmission or storage; it can help the security team track the source, process and impact of the incident, so as to take effective countermeasures; it can provide detailed records of employee operations to help management discover potential problems and risks; it can ensure the accuracy of log data and provide a reliable basis for system maintenance and optimization; it can ensure that the data provided to the audit agency is true, complete and credible; it can help enterprises quickly restore the system and rebuild data, etc.
[0102] In this embodiment, the verification process of the audit log includes the following steps:
[0103] Receive an audit log verification instruction; wherein the audit log verification instruction is used to verify each audit log one by one according to the order in which the audit logs are generated;
[0104] Determine the audit log to be verified, extract the original hash value from the encrypted data fingerprint of the audit log to be verified, recalculate the current hash value of the audit log to be verified, compare the original hash value with the current hash value, and generate a verification result.
[0105] In the present application, when verifying the audit log, the audit log can be verified after receiving the audit log verification instruction triggered by the user; the audit log verification instruction can also be periodically generated according to the verification requirements to actively verify the audit log.
[0106] In the present application, the received audit log verification instruction will carry the verification scope of the audit log, which can be all audit logs or part of the audit logs. If it is all audit logs, it is necessary to verify the first audit log as the audit log to be verified in the order in which the audit logs are generated, and then verify the second audit log as the audit log to be verified, until the last audit log is verified; if it is a part of the audit log, it is also necessary to verify the first audit log as the audit log to be verified in the order in which the audit logs are generated, and then verify the second audit log as the audit log to be verified, until the last audit log to be verified is verified; for example: the audit log includes 4 audit logs. If you only want to verify the second audit log, since the verification of the second audit log requires the hash value of the first audit log, it is necessary to first calculate the hash value of the first audit log, and then calculate the hash value of the second audit log based on the hash value of the first audit log before the second audit log can be verified.
[0107] When extracting the original hash value from the encrypted data fingerprint of the audit log to be verified, the present application needs to decrypt the encrypted data fingerprint of the audit log to be verified, generate the original data fingerprint, and extract the original hash value from the original data fingerprint.
[0108] Among them, when extracting the original hash value, the present application needs to read the encrypted data fingerprint of the audit log to be verified from the secure storage medium storing the encrypted data fingerprint. The TPCM module uses the corresponding decryption key to decrypt the encrypted data fingerprint. After the decryption is successful, the original data fingerprint can be obtained and the original hash value can be extracted from the data fingerprint. The TPCM module has a decryption algorithm and key management function. In a trusted computing environment, in order to ensure the security and integrity of the data, the TPCM module will store encrypted key information, which includes the data fingerprint of the audit log, and protect this information through the secure storage area and encryption / decryption mechanism of the TPCM module. The TPCM module uses an internal decryption algorithm and corresponding keys to decrypt the encrypted data fingerprint. These keys are usually securely stored inside the TPCM module during the system initialization or security configuration phase, and are protected at the hardware level to prevent key leakage.
[0109] This application also needs to recalculate the current hash value of the audit log to be verified. When calculating the current hash value, the TPCM module needs to use the same hash algorithm and preprocessing steps as when generating the data fingerprint, and recalculate the audit log data that needs to be verified to obtain the hash value. For example: when calculating the original hash value of the first audit log, it is necessary to use the identification information of the TPCM module, the first audit log, the sequence information and time information of the first audit log to perform a chain hash operation to generate it. For the hash values of other audit logs, it is necessary to perform a chain hash operation based on the hash value of the previous audit log, other audit logs, the sequence information and time information of other audit logs.
[0110] In some embodiments of the present application, the original hash value and the current hash value are compared. When the verification result is generated, it is necessary to determine whether the original hash value and the current hash value are the same; if so, the verification is determined to be successful; if not, the original hash value and the current hash value are compared to determine the reason for the verification failure; the reason for the verification failure includes: at least one of the following: the content of the audit log to be verified is different, the order is different, the generation time is different, and the hash value of the previous audit log of the audit log to be verified is different. Figure 4 , which is a verification process diagram provided by the present application. In this embodiment, it is first necessary to follow the access control and security mechanism, obtain the verified audit log, perform data preprocessing on the audit log, encrypt it, add the sequence number, timestamp and the hash value of the previous audit log, and use the same hash algorithm as when generating the data fingerprint to perform the operation to obtain the recalculated current hash value; when obtaining the original hash value, it is necessary to follow the access control and security mechanism, read the stored encrypted data fingerprint, and decrypt the data fingerprint based on the decryption function of the TPCM module to extract the original hash value; compare the current hash value with the original hash value. If they are the same, it means that the audit log has not been tampered with during storage and transmission, and it is determined to be authentic and reliable. If they are not the same, it is determined that the audit log may be at risk. At this time, the reasons for the different hash values can be checked by comparing the hash values. For example, if the contents of the audit logs are different, the audit logs may be tampered with; if the order is different, it can continue to check whether there is a new audit log or the order of the audit logs is disordered.
[0111] After the above verification steps, the TPCM module will generate a verification report. This report records the verification results of the audit log in detail, including hash value comparison results, cryptographic service verification results, trust measurement results, etc. The verification report will be stored in a secure location and may be distributed to relevant security administrators or audit agencies as needed. If any exceptions are found during the verification process (such as hash value mismatch, decryption failure, signature verification failure, etc.), the TPCM module will trigger the exception handling mechanism. According to the type and severity of the exception, the TPCM module will take a series of response measures according to the preset strategy, such as recording abnormal information, issuing alarm notifications, and taking remedial measures (such as re-collecting logs, restoring backups, etc.). Through the above process, the TPCM module can actively verify the trustworthiness of the audit log in real time through cryptographic services, trust measurement, measurement judgment, hash verification and other technologies, ensuring the authenticity, integrity and credibility of the audit log throughout the life cycle, providing reliable technical guarantees for security audits in trusted computing environments, and providing strong support for the security operation and compliance management of the system.
[0112] In summary, this application is based on the fusion of the TPCM module and the hash chain, and uses chained hash operations to encrypt the audit log, generate an irreversible hash value, and also form an irreversible time chain, ensuring that the order cannot be tampered with. When each new log item arrives, a new hash value will be generated in combination with the previous hash value and the new data content, so any change in a log will affect all subsequent hash values, making tampering behavior easy to detect. For example, through the characteristics of the hash chain, any modification of historical data will cause the hash value of all future data to change, making tampering obvious and easy to detect. This fusion mechanism greatly improves the integrity, authenticity of the data and the anti-repudiation and tamper-proof of the system. This feature makes the audit log have extremely high security and credibility. In addition, this application realizes the protection of the audit log through multiple key links such as audit log generation, log format preprocessing, encryption processing, hash calculation, data fingerprint generation, encrypted storage, decryption reading, and trusted verification, ensuring the security and integrity of the audit log throughout the life cycle, thereby providing reliable technical guarantees for security audits in trusted computing environments.
[0113] In addition, the TPCM module in this application is responsible for generating and maintaining the initial trust of the hash chain, ensuring that the entire process is trustworthy, and through periodic active integrity verification, ensuring that all key components are correctly measured and verified, so that the system can quickly discover and report potential tampering attempts. For example, the system can periodically and actively recalculate the entire hash chain from scratch, compare the currently stored hash value to verify the integrity of the chain and the consistency of the data, and can perceive threats in real time. This mechanism not only increases the cost of tampering, but also enhances the overall defense capability of the system. The TPCM module can continuously collect and hash the newly added log data during the operation of the system. Whenever a new audit log entry is generated, the TPCM module dynamically measures it through chain hash operations to ensure that each log is inserted in the appropriate position and correctly linked to ensure that the order cannot be tampered with. This mechanism can dynamically monitor system and network activities in real time, capture and record important audit events, and respond to threats in a timely manner according to management policies, ensure the timeliness and reliability of logs, and enhance the system's anti-attack and self-protection capabilities.
[0114] Furthermore, the TPCM module participates in the establishment of the trust chain from the beginning of system startup to ensure security and trustworthiness throughout the system life cycle. Through key management and encryption functions, the national secret standard algorithm is used to further strengthen the security of data transmission and storage, increase the difficulty of cracking by attackers, and have high security. After preliminary processing locally, the TPCM module sends the verification results to the management platform for unified storage and analysis, which greatly reduces the complexity of management in a distributed environment, can achieve global monitoring and management, and simplify the management of audit logs in large-scale systems.
[0115] The guarantee of non-tamperability and integrity makes these audit logs highly credible, in line with the relevant national laws and regulations on data security and privacy protection, ensuring the legality and compliance of the technology, and can be used as court evidence, especially in highly regulated industries such as finance, medical care, and government. In important fields such as large enterprises, cloud computing, the Internet of Things, and blockchain, the present invention provides a more stable and reliable audit log protection solution. For example, the number of IoT devices is huge and scattered, and traditional log protection methods are difficult to cope with. The TPCM module combined with chained hash operations can provide a simplified, lightweight and effective solution. For example, in the industrial Internet of Things, each device can be equipped with a TPCM module to perform hash operations and protection on the data generated by the device to ensure the authenticity and integrity of the data. This technology is particularly important in areas such as security monitoring and remote control.
[0116] In summary, the technology of protecting audit logs based on TPCM module combined with hash chain technology in this application is innovative not only in the integration of technology, but also in creating new ideas. By introducing TPCM module, double verification mechanism, active measurement and control, active reporting mechanism and strategy, real-time monitoring, dual system architecture, domestic cryptographic algorithm, continuous hash structure, chain hash algorithm and other multi-level security protection, the TPCM module is maximized to maximize the security protection capability of audit logs, significantly enhance the security and audit efficiency of the system, enhance the protection of log data, improve the integrity verification efficiency of log data, realize the traceability of log data and improve the overall security of the system. These innovations achieve a high degree of protection for audit logs, greatly reduce the risk of audit logs being tampered with, have significant innovation and practical application value, and provide more reliable security for various application scenarios.
[0117] See also Figure 5 , Figure 5 A schematic diagram of the structure of an audit log processing device provided in an embodiment of the present application, the processing device is based on a TPCM module, and the device specifically includes:
[0118] The acquisition module 11 is used to acquire the target audit log to be processed;
[0119] A determination module 12, used to determine the sequence information and time information corresponding to the target audit log;
[0120] The operation module 13 is used to perform a chain hash operation on the target audit log, the initial hash value, the sequence information and the time information to generate a target data fingerprint; the initial hash value is the hash value of the previous audit log;
[0121] The encryption module 14 is used to encrypt the target data fingerprint to generate an encrypted data fingerprint;
[0122] The storage module 15 is used to store the encrypted data fingerprint.
[0123] As an optional embodiment, the acquisition module includes:
[0124] An acquisition unit, used for acquiring the original audit log to be processed;
[0125] A processing unit, used to perform format preprocessing on the original audit log to generate a preprocessed audit log;
[0126] The encryption unit is used to encrypt the preprocessed audit log to obtain a target audit log.
[0127] As an optional embodiment, the operation module includes:
[0128] A computing unit, configured to perform a chain hash operation on the target audit log, the initial hash value, the sequence information, and the time information to obtain a target hash value;
[0129] A combining unit is used to combine the target hash value with relevant information to generate a target data fingerprint; the relevant information includes at least one of sequence information, time information and signature information.
[0130] As an optional embodiment, the processing device further includes:
[0131] A judgment module, used to judge whether the target audit log is the first audit log;
[0132] If yes, the identification information of the TPCM module is used as the initial hash value; if no, the hash value of the previous audit log is used as the initial hash value.
[0133] As an optional embodiment, the processing device further includes a verification module:
[0134] The verification module includes:
[0135] A receiving unit, configured to receive an audit log verification instruction; wherein the audit log verification instruction is used to verify each audit log one by one according to the order in which the audit logs are generated;
[0136] A determination unit, used for determining the audit log to be verified;
[0137] An extraction unit, configured to extract an original hash value from the encrypted data fingerprint of the audit log to be verified;
[0138] A calculation unit, used to recalculate the current hash value of the audit log to be verified;
[0139] The verification unit is used to compare the original hash value and the current hash value to generate a verification result.
[0140] As an optional embodiment, the verification unit includes:
[0141] A judgment subunit, used to judge whether the original hash value is the same as the current hash value; if so, the verification is determined to be successful; if not, a comparison subunit is triggered;
[0142] A comparison subunit is used to compare the original hash value with the current hash value to determine the reason for verification failure; the reason for verification failure includes: the content, order, generation time of the audit log to be verified are different, and the hash value of the previous audit log of the audit log to be verified is different. At least one of the above.
[0143] As an optional embodiment, the extraction unit includes:
[0144] The decryption subunit is used to decrypt the encrypted data fingerprint of the audit log to be verified to generate an original data fingerprint;
[0145] The extraction subunit is used to extract the original hash value from the original data fingerprint.
[0146] Regarding the device in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0147] See also Figure 6 , Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application, the electronic device specifically includes:
[0148] A processor 21, a memory 22, and a computer program stored in the memory 22 and executable on the processor 21. The processor 21 executes the steps of the processing method described in any of the above method embodiments through the computer program.
[0149] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.
[0150] The memory 22 may include one or more computer-readable storage media, which may be non-transitory. The memory 22 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory 22 is at least used to store the following computer program 221, wherein, after the computer program is loaded and executed by the processor 21, it can implement the relevant steps in the processing method disclosed in any of the aforementioned embodiments. In addition, the resources stored in the memory 22 may also include an operating system 222 and data 223, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 222 may include Windows, Unix, Linux, etc.
[0151] In some embodiments, the electronic device may further include a display screen 23 , an input / output interface 24 , a communication interface 25 , a sensor 26 , a power source 27 , and a communication bus 28 .
[0152] certainly, Figure 6 The structure of the electronic device shown does not constitute a limitation on the electronic device in the embodiments of the present application. In actual applications, the electronic device may include Figure 6 More or fewer components than shown, or combinations of certain components.
[0153] In another exemplary embodiment, a computer storage medium is also provided, and when the program instructions are executed by the processor, the steps of the processing method described in any of the above method embodiments are implemented. The storage medium may include: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.
[0154] Optionally, the specific examples in this embodiment may refer to the examples described in the above embodiments, and this embodiment will not be described in detail here.
[0155] It can be seen from the above embodiments that the present application performs tamper-proof protection on the audit log based on the cryptographic function of the TPCM module, protects the integrity of each log, and at the same time, through the chain hash operation, makes the hash of the log before and after have correlation, and performs calculation, storage and verification based on the TPCM module. This correlation is achieved through a specific algorithm, which not only considers the content of the current message, but also the hash value of the previous log. If the log content is tampered with and deleted, the new hash value will not match the original hash chain, so that the inconsistency of the data can be quickly detected. By using the hash chain method to increase the correlation verification of the previous and next logs, the tamper-proof detection protection is made stronger. Not only the integrity and credibility of the audit log are enhanced, but also the security of the system and the efficiency of log management are improved, and the protection of the audit log is achieved.
[0156] The technical effects achieved by this application are mainly reflected in the following aspects:
[0157] Protect the integrity of each log: Through the TPCM module and hash chain technology, each audit log is encrypted and assigned a unique hash value, which not only represents the content of the log itself, but also is associated with the hash values of the previous and next logs. Any tampering with the log content will cause its hash value to change, thereby destroying the continuity of the hash chain, making it easy to detect the behavior of tampering with the log.
[0158] Prevent malicious operations such as log deletion: The continuity of the hash chain ensures that logs cannot be deleted. If you try to delete a log or perform malicious operations such as obfuscating or adding logs, the hash value of the subsequent log will not match the hash value of the previous log, thus revealing the malicious deletion behavior.
[0159] Increase the correlation verification between the previous and next logs: Through the hash chain technology, the correlation between the previous and next logs can be easily verified. This correlation not only strengthens the logical connection between the logs, but also further ensures the integrity of the logs.
[0160] Improve the traceability of logs: Since the hash chain records the order and relationship between logs, it is easy to trace the source and evolution of the logs. This is of great significance for investigating security incidents and analyzing system behavior.
[0161] Improve system defense capabilities: This approach not only enhances the security of the system, but also improves the system's defense capabilities against potential threats. By regularly checking and verifying the integrity of the hash chain, potential security risks can be discovered and responded to in a timely manner.
[0162] Simplify the log verification process: Hash chain technology can simplify the log verification process. Administrators only need to verify the continuity and integrity of the hash chain to confirm the authenticity and credibility of all logs.
[0163] Improve log processing speed: Since hash chain technology has efficient data processing capabilities, it can significantly improve the log processing speed. This is especially important for large-scale systems or high-frequency logging scenarios.
[0164] It should be understood that the terms used herein are only for the purpose of describing specific example embodiments and are not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms "one", "an" and "said" as used herein may also be meant to include plural forms. The terms "include", "comprise", "contain", and "have" are inclusive, and therefore specify the existence of stated features, steps, operations, elements and / or parts, but do not exclude the existence or addition of one or more other features, steps, operations, elements, parts, and / or combinations thereof. The method steps, processes, and operations described herein are not interpreted as necessarily requiring them to be performed in the specific order described or illustrated, unless the execution order is clearly indicated. It should also be understood that additional or alternative steps may be used.
[0165] The foregoing is merely a specific embodiment of the present invention, which enables those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A method for processing an audit log, characterized in that: The processing method is based on the TPCM module, and the processing method includes: Get the target audit log to be processed; Determining sequence information and time information corresponding to the target audit log; Performing a chain hash operation on the target audit log, the initial hash value, the sequence information and the time information to generate a target data fingerprint; the initial hash value is the hash value of the previous audit log; The target data fingerprint is encrypted to generate an encrypted data fingerprint, and the encrypted data fingerprint is stored.
2. The processing method according to claim 1, characterized in that: Get the target audit logs to be processed, including: Get the raw audit logs to be processed; Performing format preprocessing on the original audit log to generate a preprocessed audit log; The preprocessed audit log is encrypted to obtain the target audit log.
3. The processing method according to claim 1, characterized in that: Performing a chain hash operation on the target audit log, the initial hash value, the sequence information, and the time information to generate a target data fingerprint, including: Performing a chain hash operation on the target audit log, the initial hash value, the sequence information, and the time information to obtain a target hash value; The target hash value is combined with relevant information to generate a target data fingerprint; the relevant information includes at least one of sequence information, time information and signature information.
4. The processing method according to claim 1, characterized in that: After determining the sequence information and time information corresponding to the target audit log, the method further includes: Determine whether the target audit log is the first audit log; If yes, the identification information of the TPCM module is used as the initial hash value; If not, the hash value of the previous audit log is used as the initial hash value.
5. The processing method according to any one of claims 1 to 4, characterized in that: The processing method also includes: Receive an audit log verification instruction; wherein the audit log verification instruction is used to verify each audit log one by one according to the order in which the audit logs are generated; Identify the audit logs to be verified; Extracting the original hash value from the encrypted data fingerprint of the audit log to be verified; Recalculate the current hash value of the audit log to be verified; The original hash value and the current hash value are compared to generate a verification result.
6. The processing method according to claim 5, characterized in that: The comparing the original hash value and the current hash value to generate a verification result includes: Determine whether the original hash value is the same as the current hash value; If yes, the verification is deemed successful; If not, compare the original hash value with the current hash value to determine the reason for the verification failure; the reason for the verification failure includes: the content, order, generation time of the audit log to be verified are different, and the hash value of the previous audit log of the audit log to be verified is different. At least one of the above.
7. The processing method according to claim 5, characterized in that: Extracting the original hash value from the encrypted data fingerprint of the audit log to be verified includes: Decrypting the encrypted data fingerprint of the audit log to be verified to generate an original data fingerprint; An original hash value is extracted from the original data fingerprint.
8. An audit log processing device, characterized in that: The processing device is based on the TPCM module, and the processing device comprises: The acquisition module is used to obtain the target audit log to be processed; A determination module, used to determine the sequence information and time information corresponding to the target audit log; A calculation module, used to perform a chain hash operation on the target audit log, the initial hash value, the sequence information and the time information to generate a target data fingerprint; the initial hash value is the hash value of the previous audit log; An encryption module, used to encrypt the target data fingerprint to generate an encrypted data fingerprint; A storage module is used to store the encrypted data fingerprint.
9. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor executes the steps of the processing method described in any one of claims 1 to 7 of the present application through the computer program.
10. A computer storage medium, characterized in that: The computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the steps of the processing method described in any one of claims 1 to 7 of the present application.
Citation Information
Cited By
Ciphertext chained auditing method and system for privacy computing platform
CN120811773A
Method for collection, validation and reporting of data for large-scale, accurate, and secure open-source software auditing
US12748678B2
Method for collection, validation and reporting of data for large-scale, accurate, and secure open-source software auditing
US20240296106A1