Accounting file data management method and system and storage medium

By combining blockchain technology, encryption algorithms, digital watermarks and layered storage strategies, the contradiction between accounting archive data management efficiency and privacy security in the existing technology is solved, and efficient and secure data management is achieved.

CN119989403AInactive Publication Date: 2025-05-13CHUZHOU VOCATIONAL & TECHN COLLEGE
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510050023.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art fails to ensure the efficiency of archival data management while ensuring the privacy, security and authenticity of accounting archive data.

Method used

Through blockchain technology combining encryption algorithms, digital watermarks and layered storage strategies, efficient and secure management of accounting archive data is achieved. Specific measures include dual encryption of homomorphic algorithms and ABE algorithms, embedding of digital watermarks, data integrity verification of verifiable random functions, and hierarchical storage strategies based on sensitivity and access frequency.

Benefits of technology

It realizes efficient and secure management of accounting archive data during storage and transmission, ensures the privacy, security and integrity of data, and improves the flexibility and management efficiency of data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989403A_ABST
    Figure CN119989403A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of archive data management, in particular to an accounting archive data management method and system and a storage medium. A block chain network architecture comprising a main chain and a plurality of side chains is constructed, the main chain is used for recording a transaction process, and the side chains are used for storing data; performing double encryption on the accounting file data through a homomorphic encryption algorithm and an attribute-based encryption algorithm; adopting a digital watermark to track data flow and verify data ownership; formulating a hierarchical storage strategy for the accounting archive data according to the sensitivity degree and the access frequency; a verifiable random function is introduced for data integrity verification; according to the invention, the block chain technology is combined with the encryption algorithm, the digital watermark and the hierarchical storage strategy, so that efficient and safe management of accounting archive data is realized; on the basis, the traceability of the data processing operation is improved, and the privacy security and the true integrity of the sensitive information in the accounting file data are further guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of archive data management, and in particular to a data management method, system and storage medium for accounting archives. Background Art

[0002] Accounting archives refer to documents and materials related to economic activities that are generated, collected, preserved and managed in accounting work. They are intended to record and reflect the financial status and operating results of the enterprise, including accounting vouchers, accounting books, financial statements, tax audits and other additional materials. Due to the particularity of their content and purpose of use, the authenticity, integrity, security, efficient availability and compliance of accounting archives require more comprehensive data management technology to ensure.

[0003] In the existing technology, accounting archive management usually relies on general archive management system technology, and the research goals are mainly to improve the data processing efficiency of the management system and enhance data security. Various studies have introduced advanced algorithms, distributed systems and blockchain technology to solve problems such as data duplication, low query efficiency and data tampering in archive management. The existing technology has improved the efficiency of accounting archive management to a certain extent, but it still has shortcomings. In view of the particularity of accounting archives, the existing technology has failed to ensure the efficiency of archive data management while ensuring data privacy security and authenticity integrity.

[0004] To this end, a data management method, system and storage medium for accounting archives are proposed. Summary of the invention

[0005] The purpose of the present invention is to provide a data management method, system and storage medium for accounting archives, which realizes efficient and safe management of accounting archive data by combining blockchain technology with encryption algorithm, digital watermark and hierarchical storage strategy. It mainly includes: realizing double encryption of accounting archive data by homomorphic algorithm and ABE algorithm; using embedded digital watermark to verify data ownership according to data flow; formulating hierarchical storage strategy for accounting archive data according to sensitivity and access frequency; introducing verifiable random function in consensus mechanism to verify data integrity.

[0006] To achieve the above-mentioned purpose, the present invention provides a data management method, system and storage medium for accounting files, including:

[0007] Constructing a blockchain network, including a main chain and a side chain; obtaining accounting file data, encrypting the accounting file data using a homomorphic encryption algorithm, and generating homomorphic ciphertext; dividing the homomorphic ciphertext into multiple data blocks, and storing them in different blocks of the side chain;

[0008] Define access rights according to user roles and attributes and formulate access policies; use attribute-based encryption technology to perform secondary encryption on the homomorphic ciphertext to generate ABE ciphertext; store the ABE ciphertext on the side chain;

[0009] Extracting the homomorphic ciphertext from the ABE ciphertext to generate watermark information, embedding it into the ABE ciphertext, and replacing the ABE ciphertext with the ABE ciphertext with the digital watermark on the side chain; introducing a verifiable random function to verify the integrity of the ABE ciphertext with the digital watermark;

[0010] According to the combination of sensitivity and access frequency, several storage layers are defined; each storage layer includes specific storage media and access permissions; the sensitivity and access frequency of the accounting archive data are evaluated, and according to the sensitivity and the access frequency, the accounting archive data are stored in corresponding storage layers, and the accounting archive data are classified and stored in layers; data storage and migration are defined according to the life cycle of the accounting archive data.

[0011] Furthermore, the step of storing the homomorphic ciphertext in the side chain includes:

[0012] Encrypting the accounting file data using a homomorphic encryption algorithm to obtain the homomorphic ciphertext; dividing the homomorphic ciphertext into a plurality of data blocks and storing them in different blocks of the side chain;

[0013] Calculate a transaction hash value for each of the data blocks, record the transaction hash value and related audit logs on the main chain; add the related audit logs and transaction records to the next block of the main chain to form a chain structure.

[0014] Further, the accounting file data is encrypted using a homomorphic encryption algorithm to obtain the homomorphic ciphertext; the homomorphic ciphertext is divided into a plurality of data blocks, and a data hash value of each data block is calculated;

[0015] The homomorphic ciphertext, the data hash value and related metadata are stored in the side chain, and each block of the side chain contains the hash value of the previous block to form a chain structure.

[0016] Furthermore, the secondary encryption process includes: defining access rights for the user according to the user's role to form user attribute information; formulating an access control policy according to the user attribute information;

[0017] Using attribute-based encryption technology to generate a unique ABE private key for each user;

[0018] Using the homomorphic ciphertext as the plaintext of the attribute-based encryption, performing secondary encryption on the plaintext through the public parameters in the attribute-based encryption, the ABE private key and the access control policy to generate the ABE ciphertext;

[0019] The ABE ciphertext is stored on the side chain.

[0020] Furthermore, the step of embedding a digital watermark into the ABE ciphertext includes:

[0021] Extracting the homomorphic ciphertext from the ABE ciphertext to be embedded with a watermark, and generating watermark information;

[0022] In combination with the data characteristics of the accounting archives, watermark bits are embedded in specific locations of the data to generate new ciphertext with the digital watermark;

[0023] The new ciphertext is stored in the block of the side chain, replacing the ABE ciphertext.

[0024] Furthermore, the step of verifying the integrity of the new ciphertext includes: performing a hash calculation on the new ciphertext to generate a ciphertext data hash value;

[0025] Using a verifiable random function to process the hash value of the ciphertext data to generate a random number and a verification certificate;

[0026] Storing the random number, the verification certificate and the data hash value together in the transaction record of the blockchain network;

[0027] When performing data integrity verification on the new ciphertext, obtaining the new ciphertext, the random number and the verification certificate from the blockchain network;

[0028] Recalculating the hash of the new ciphertext to obtain a new hash value; checking whether the random number and the verification certificate match the new hash value through the publicly verifiable random function;

[0029] If the match is successful, the new ciphertext passes the data integrity verification; if the match is not successful, the new ciphertext fails the data integrity verification.

[0030] Furthermore, the process of formulating the tiered storage strategy includes:

[0031] Define the sensitivity level classification and access frequency level classification of data; the sensitivity level classification includes high sensitivity, medium sensitivity and low sensitivity, and the access frequency level classification includes high frequency access, medium frequency access and low frequency access;

[0032] Defining a number of storage tiers based on a combination of the sensitivity level classification and the access frequency level classification; the storage tiers include specific storage media settings, access rights, and storage requirements;

[0033] Acquire the accounting archive data to be stored, define the sensitivity and access frequency, and store the accounting archive data to be stored in the corresponding storage layer. Evaluate the sensitivity and access frequency of the accounting archive data, and store the accounting archive data in the corresponding storage layer according to the sensitivity and the access frequency.

[0034] Furthermore, the steps of defining data storage and migration according to the life cycle of the accounting archive data include:

[0035] During the life cycle stage of the accounting archive data, the sensitivity and access frequency of the accounting archive data in each storage layer are evaluated, and the storage layer of the accounting archive data is adjusted according to the evaluation results.

[0036] Furthermore, the step of adjusting the storage layer of the accounting archive data according to the evaluation result includes:

[0037] Extract the ABE ciphertext data block to be migrated from the current storage layer, recalculate the hash value, and match the new hash value with the transaction hash value of the ABE ciphertext data block stored on the main chain; when the match is successful, transmit the ABE ciphertext data block to the target storage layer through the transmission network and store it in the storage medium of the target storage layer;

[0038] Performing hash value calculation again on the ABE ciphertext data block after migration to generate an audit log; the audit log includes an owner identifier, a migration timestamp, a data identifier, and the hash value after migration;

[0039] The audit log containing the migration record and the reverse hash calculation are performed to generate a migration record hash value; the migration record hash value is digitally signed using a private key to generate a verification certificate; the migration record hash value, the audit log and the verification certificate are stored as transaction records in the next block of the main chain.

[0040] The present invention also provides a data management system for accounting files, comprising:

[0041] Network construction unit: used to construct a blockchain network architecture including a main chain and at least one side chain; the main chain is used to store the audit log of the transaction hash value, and the side chain is used to store the encrypted accounting file data;

[0042] Access control unit: used to formulate access policies for the encrypted accounting file data and define access rights; use attribute-based encryption technology to perform secondary encryption on the homomorphic ciphertext to generate ABE ciphertext;

[0043] Digital watermark embedding unit: used for embedding a digital watermark in the encrypted accounting file data to indicate the owner and source of the data;

[0044] Data integrity verification unit: used to verify the integrity of transactions and data by introducing verifiable random functions into the consensus mechanism;

[0045] Hierarchical storage strategy unit: used to classify the accounting archive data into sensitivity levels and access frequency levels according to the sensitivity level and access frequency, and define and migrate storage layers according to the levels.

[0046] The present invention also proposes a data management storage medium for accounting archives, wherein the accounting archive data management medium stores a computer program, and when the computer program is executed by a processor, the processor executes the steps of any one of the methods described above.

[0047] Compared with the prior art, the present invention has the following beneficial effects:

[0048] 1. The present invention ensures the security of accounting archive data during storage and transmission through a double encryption mechanism. First, the original accounting archive data is encrypted using a homomorphic encryption algorithm, so that some operations can be performed directly on the encrypted data instead of decrypting it first and then operating it, which ensures the privacy of the accounting archive data during transmission and storage; then the homomorphic encrypted data is encrypted based on user attributes, and only users who meet specific access conditions can decrypt and access the corresponding data, which prevents the risk of unauthorized access and data leakage. The double encryption mechanism not only ensures the privacy and security of accounting archive data during storage and transmission, but also improves the flexibility of data processing.

[0049] 2. The present invention ensures the transparency of the data management process by embedding invisible digital watermark information in the double-encrypted accounting archive data. The digital watermark identifies the owner and source information of the data, which can prevent the data from being forged or misused, which can enhance the legal effect and credibility of the accounting archive data to a certain extent; by tracking the use and circulation of accounting archive data through watermark information, unauthorized copying and distribution can be discovered in a timely manner, which improves the traceability of accounting archive management. When the watermark in the data is tampered with or destroyed, it is also possible to detect whether the accounting archive data has been illegally modified by extracting and verifying the watermark, thereby ensuring the integrity and security of the accounting archive data.

[0050] 3. The present invention builds a blockchain architecture combining a main chain and a side chain, and formulates a hierarchical storage strategy to balance the security and storage efficiency of accounting archive data. The main chain is used to store transactions and audit logs, and the side chain is used to store encrypted data; according to the sensitivity and access frequency, the accounting archive data is classified into different levels of data and stored in different storage levels, and highly sensitive data is stored in a more secure location, and the storage resources on the blockchain are flexibly adjusted according to different data requirements. All key operations and audit logs are recorded on the main chain to ensure that data operations cannot be tampered with; combined with the hierarchical storage of the side chain, the security and management efficiency of accounting archive data are comprehensively improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 A flowchart of a data management method for accounting files provided by an embodiment of the present invention;

[0052] Figure 2 A schematic diagram of the structure of a data management system for accounting files provided by an embodiment of the present invention;

[0053] Figure 3 A schematic diagram of the structure of a tiered storage strategy provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0054] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0055] In order to ensure the privacy security and authenticity integrity of accounting archive data during transmission and storage, the present invention provides a data management method, system and storage medium for accounting archives. In order to illustrate the effectiveness of the method provided by the present invention in detail, the specific implementation method will be described through the following examples.

[0056] Embodiment 1

[0057] Accounting firm A has a large amount of accounting file data to be managed on a daily basis, including core financial files such as financial statements, tax-related documents, and audit reports. In order to ensure the confidentiality and integrity of these data, this embodiment provides a data management method for accounting files. The flow chart of the method is shown in Figure 1 .

[0058] Reference Figure 1S10 in the paper builds a blockchain network architecture consisting of a main chain and a side chain; the main chain is used to record the transaction hash values ​​and audit logs of all data blocks; the side chain is used to store encrypted data.

[0059] Further, refer to Figure 1 S20 in the example obtains accounting archive data D and uses homomorphic encryption algorithm E HE (·) Encrypt the accounting file data D to generate homomorphic ciphertext C HE ;

[0060] C HE =E HE (D)=(g m ·r n )mod n 2

[0061] [E HE (m1)×E HE (m2)]mod n 2 =E HE (m1+m2);

[0062] Among them, m is plain text data, indicating the specific content in the accounting file data; g is the generator of the homomorphic algorithm, n is the modulus of the homomorphic algorithm, and in this embodiment, g=n+1 is selected; r is the random number of the homomorphic algorithm.

[0063] The homomorphic ciphertext C HE Divide into multiple data blocks C = {C HE-1 ,C HE -2,...,C HE-c}, stored in different blocks of the side chain; for each data block C HE-i , through H CHE-i =SHA-256(C HE-i ) Calculate its transaction hash value H CHE-i , SHA-256(·) is the hash function.

[0064] The transaction hash value and audit log corresponding to each data block are recorded on the main chain. The audit log is added to the next block of the main chain as part of the transaction record. The audit log recording formula is:

[0065] AuditLog={Timestamp,UploaderID,H CHE-i};

[0066] In the above formula, AuditLog represents the audit log, Timestamp represents the data upload time, and records the data block C. HE-i Uploaded to the side chain and recorded on the main chain CHE-iThe specific time point; UploaderID represents the identity of the user who performs the upload operation.

[0067] The main chain record update formula is:

[0068] Blockchain={Previou BlockHash,H CHE-i ,AuditLog}

[0069] Among them, Blockchain represents the main chain, and Previous BlockHash represents the data block C HE-i The hash value of the previous block.

[0070] In this example, the accountant with ID ACCT-05 uploaded an annual financial statement at 14:35:22 on October 12, 2024, which includes the income, expenditure, assets, liabilities and tax status of the firm's client company. After data encryption, data block division and storage, the generated audit log is:

[0071] AuditLog={2024-10-1214:35:22,ACCT-05,H CHE-i};

[0072] This embodiment uses a homomorphic encryption algorithm to preliminarily encrypt accounting file data, protecting the privacy and security of the data and preventing unauthorized access and leakage; homomorphic encryption also allows data to be calculated and processed in an encrypted state, ensuring the flexibility of data processing. A chain structure is used to divide the homomorphic ciphertext into multiple data blocks and store them in a distributed manner on the side chain, ensuring the security and integrity of the data transmission and storage process.

[0073] Further, refer to Figure 1 In S30, access rights are defined according to the user's role and attribute, and access policies are formulated. In this embodiment, some attribute categories and attribute value definitions in accounting firm A, as well as access rights definitions of some roles are given in Table 1 and Table 2, respectively.

[0074] Table 1A Attribute categories and attribute values ​​of accounting firms

[0075] Attribute Category Property Value department Finance Department, Audit Department, IT Department, Compliance Department, Management Department Permission levels Beginner, Intermediate, Advanced Data Sensitivity Low sensitivity, medium sensitivity, high sensitivity Access Type Read, Write, Modify, Delete, Approve

[0076] Table 2 Some examples of access rights definition

[0077] Role Data Sensitivity Access Type R1(Accountant) Low Read, Write R1(Accountant) middle Read R2(Auditor) middle Read R2(Auditor) high Read R3 (IT staff) all Read, Write, Modify, Delete R4(Senior Management) all Read, approve

[0078] After defining access rights according to the user's role and attributes, an access policy is formulated. In this embodiment, the access policy formulated by Accounting Firm A according to the user attributes is shown in Table 3;

[0079] Table 3 Attribute-based access policies

[0080]

[0081] The encrypted data is re-encrypted using attribute-based encryption technology; the specific steps include:

[0082] Use the CP-ABE system to initialize Setup()→(PK,MK) to generate public parameters PK and master key MK; generate a unique ABE private key for each role based on its attribute information; the key generation formula is as follows:

[0083] SK u =KeyGen(MK,Attributes u );

[0084] Among them, SK u represents the ABE private key of user u, KeyGen(·) is the attribute-based encryption function, Attributes u Represents the attribute set of user u.

[0085] In this embodiment, the attributes of auditor R6 are defined as shown in Table 4;

[0086] Table 4R6 defines attributes

[0087]

[0088] The exclusive ABE private key generated for R6 is:

[0089] SK R1 =KeyGen(MK,Attribute R1 )

[0090]

[0091] In the above R6 exclusive ABE private key SK R1 In the generation formula, KeyGen(·) represents the private key generation function, Attributes R6 It is the attribute set of R6.

[0092] The homomorphic ciphertext C HE As the plaintext data of ABE, use the public parameter PK and the ABE private key SK of user u u and access policy A to ABE plaintext data C HE Perform secondary encryption to generate ABE ciphertext CT;

[0093]

[0094] Among them, C1 and C2 are ABE encryption components, {C 3,j} represents the encryption components related to each attribute in access policy A, m attr is the number of attributes defined in access policy A, E ABE (C HE ,A) is the ABE encryption function.

[0095] According to the sensitivity of accounting archive data, the ABE ciphertext CT is stored in a block of the side chain. i They all contain the hash value of the previous block, the ABE ciphertext CT, and the data identifier DataID corresponding to CT. CT And store time Timestamp;

[0096] SidechainBlock i ={PreviousBlockHash,CT,DataID CT ,Timestamp};

[0097] Synchronously update the main chain:

[0098]

[0099] When a data access request occurs, the user's exclusive private key and attribute matching mechanism are used to verify whether the user's role and attributes comply with the corresponding access policy; if they do, decryption is performed to restore the plaintext data. The decryption steps include:

[0100] Step 1: Confirm that the attribute set of user u satisfies its corresponding access policy A;

[0101] Step 2: Through e(C1,SK u )=e(g s ,SK u ) calculates the pairing of the exclusive private key and the ABE encryption component; in this formula, e(·) is a bilinear mapping function, g is a generator used to construct the ciphertext component in the ABE encryption process, and s is a random number generated in the ABE encryption process;

[0102] Step 3: Pass Recover homomorphic ciphertext;

[0103] Step 4: Pass Restore the original data file D.

[0104] This embodiment uses an attribute-based algorithm to perform secondary encryption on homomorphic encrypted ciphertext to improve the security of data access control. This embodiment first defines the user's permissions according to the user's role to form user attribute information, and then formulates an access policy; then the attribute-based algorithm is used to perform secondary encryption on the homomorphic ciphertext; this step allows only users with specific attributes to decrypt and access specific data, achieving fine-grained access control and improving the access control and security of accounting files.

[0105] Further, refer to Figure 1 S40 in which a digital watermark is embedded in the ABE ciphertext CT to generate a new ciphertext with a watermark includes the following steps:

[0106] Extracting homomorphic ciphertext C from ABE ciphertext CT HE , used to generate watermark information;

[0107] Generate watermark information W = {OwnerID, Timestamp, DataID, Copyright}; the watermark information structure example is shown in Table 5;

[0108] Table 5 Watermark information structure example

[0109]

[0110] This embodiment adopts a block-based watermark embedding method; first, the watermark information W is converted into a binary bit sequence W using UTF-8 encoding and hash function. b ;

[0111] W b ={OwnerID||Timestamp||DataID||Copyright};

[0112] Select the non-key byte position in the ABE ciphertext and use the least significant bit (LSB) embedding method to embed the binary bit sequence W b Embed into the ABE ciphertext CT to generate a new ciphertext CT';

[0113]

[0114] In the above watermark embedding formula, p i is the embedding position, k is the length of the watermark bit sequence; |W b [i] indicates that the watermark bit W b [i] Embedded in p i Position; CT[p i ]&0xFE is used to convert p i The least significant bit (LSB) of the position is cleared to zero.

[0115] In this embodiment, the embedding position is selected as Position = {10, 20, ..., 60}, and the watermark bit is W b =101010; embed the watermark bit at the selected position to generate a new ciphertext CT'; the watermark embedding process is:

[0116]

[0117] According to the sensitivity of the data, the new ciphertext CT' is stored in the appropriate side chain to replace the original ABE ciphertext CT;

[0118] SidechainBlock i ={CT',D050104,A1-03154,2024-10-1416:56:37};

[0119] Calculate the hash value of the new ciphertext CT' and generate an audit log; update the main chain block.

[0120]

[0121] When a situation arises where data security needs to be verified, the block storing the new ciphertext CT' is obtained from the side chain, and the watermark bit W is extracted from the specified position of CT' using the LSB extraction method. b ';

[0122]

[0123] The original watermark field is restored through decoding and inverse hashing process to verify whether the watermark information is consistent with the original information; and the data integrity is verified by hash value calculation.

[0124] This embodiment embeds a digital watermark in the non-key byte position of the ABE ciphertext to ensure the security and reliability of accounting archive data during storage and transmission, and the addition of the digital watermark will not affect the normal decryption and use of the data. The digital watermark protects the ownership and copyright protection of the accounting archive data, thereby improving the security verification and traceability of the accounting archive data.

[0125] Further, refer to Figure 1 In S50, the step of verifying the integrity of the new ciphertext includes performing a hash calculation on CT' to generate a hash value H of the text data. CT' ;

[0126] Using Verifiable Random Function (VRF) to CT' Perform calculations to generate random numbers r1 and verification proof π1, and then use r1, π1 and H CT' Stored together in the transaction record of the blockchain network. The storage format is as follows:

[0127] {r1,π1,H CT' ,Timestamp,DataID};

[0128] When the integrity of the stored data needs to be verified, the above transaction records and the corresponding new ciphertext CT' are first extracted from the blockchain network, and the hash value H' is recalculated for CT'. CT' ;

[0129] Use the public VRF to verify the ABE ciphertext data hash value H CT' and H' CT' Whether it matches;

[0130] Verify(H CT' |H' CT' ,r1,π1)=True / False;

[0131] If the verification is True, the verification data is complete; if the verification is False, the verification fails and the data may be tampered with or the watermark may be removed.

[0132] This embodiment verifies the ABE ciphertext embedded with the watermark through data integrity verification to ensure the credibility of the accounting archive data. When the integrity of the stored data needs to be verified, the transaction record and the corresponding watermark ABE ciphertext are extracted, and a new data hash value is generated; VRF is used to match and verify the new data hash value. If the verification is successful, the ciphertext data is safe; if the verification fails, it indicates that the data may be tampered with or damaged. This mechanism provides an efficient verification method, improves the monitoring capability in the archive management process, and ensures the overall security and reliability of accounting archive data.

[0133] Further, refer to Figure 3 , a hierarchical storage strategy is formulated according to the sensitivity of accounting archive data, and the specific steps include: defining multiple storage layers according to the combination of data sensitivity and access frequency; each storage layer has a specific storage medium and access rights. The following is an example of the storage description defined in the accounting archive data management of A accounting affairs of the present invention;

[0134] Highly sensitive data: stored in a private sidechain to ensure confidentiality and integrity;

[0135] Medium-sensitivity data: stored in a permissioned sidechain, with moderate security and privacy protection;

[0136] Low-sensitivity data: stored on the public side chain to reduce storage costs.

[0137] Storage layer 1: High sensitivity & high-frequency access, the storage medium is solid-state drive (SSD), which is accessible to authorized senior financial personnel and auditors and stored in a high-security data center;

[0138] Storage Tier 2: Medium sensitivity & high-frequency access, storage media is high-performance SSD or hybrid storage, authorized financial analysts and business analysts can access, stored in a high-performance computing environment, support fast data access;

[0139] Storage layer 3: low sensitivity & high frequency access, the storage medium is a high-performance mechanical hard disk (HDD) or a standard SSD, which is accessible to authorized business personnel and stored in a standard enterprise data center, supporting regular data backup and management.

[0140] It should be noted that the above storage example description is a partial example of the storage description defined in the accounting archive data management of A accounting affairs of the present invention, and is not a complete combination of sensitivity and access frequency; the selection of storage media, the definition of access rights and the configuration of storage nodes are not limited to the above examples, but are reasonably planned according to actual conditions. In addition, the security measures and security mechanisms required for different storage layers are also formulated according to the management requirements of the user, and will not be described in detail in this embodiment.

[0141] This embodiment first classifies accounting archive data based on the sensitivity and access frequency of the data, and formulates classification levels corresponding to different needs, so that accounting archive data of different sensitivities and access frequencies can be allocated to reasonable storage levels; each storage layer defines corresponding storage media and access permissions according to data characteristics, thereby optimizing data storage efficiency, security and management costs.

[0142] As the life cycle of accounting archive data changes, the sensitivity and access frequency of accounting archive data also change accordingly, and the storage location and storage level of the archives should also be adjusted accordingly to ensure the reasonable allocation of storage space. The main steps include:

[0143] During the life cycle stage of the accounting archival data, the sensitivity and access frequency of the accounting archival data in each storage layer are evaluated; when the sensitivity and access frequency of a piece of archival data changes, it is migrated to the corresponding storage layer.

[0144] The migration steps are as follows:

[0145] Extract the ABE ciphertext data block to be migrated from the current storage layer, recalculate the hash value, and match the new hash value with the transaction hash value of the ABE ciphertext data block stored on the main chain; when the match is successful, transmit the ABE ciphertext data block to the target storage layer through the transmission network and store it in the storage medium of the target storage layer;

[0146] Performing hash value calculation again on the ABE ciphertext data block after migration to generate an audit log; the audit log includes an owner identifier, a migration timestamp, a data identifier, and the hash value after migration;

[0147] Perform hash calculation on the audit log containing the migration record to generate a migration record hash value; use a private key to digitally sign the migration record hash value to generate a verification certificate; store the migration record hash value, the audit log and the verification certificate as transaction records in the next block of the main chain.

[0148] According to the above-mentioned tiered storage strategy, this embodiment evaluates the sensitivity and access frequency of 10,000 accounting file data of accounting firm A to determine the migration storage level of the data; Table 6 gives some examples.

[0149] Table 6 Some examples of migrating storage tiers

[0150] Data No. Sensitivity Frequency of visit Current level Migration level Storage Media Transaction Hash D0056 high high 3 1 High-performance SSD H_D0056_1 D0057 middle Low 3 6 Enterprise HDD H_D0057_1 D058 middle high 5 4 High-performance SSD H_D0058_1 D0059 Low Low 5 9 Cloud Archive H_D0059_1 D0101 high middle 3 2 High-performance SSD H_D01019_1 D0102 Low middle 5 8 Standard HDD H_D0102_1

[0151] In Table 6, data D0056 is currently stored in storage layer 3. Due to project changes and other reasons, its sensitivity and usage frequency have changed to a high level, so it is migrated to storage layer 1 and stored in the corresponding high-performance SSD. Data D0059 is currently stored in storage layer 5. With the end of the project and other reasons, its sensitivity and usage frequency have changed to a low level, so it is migrated to storage layer 9 and stored in cloud archiving mode.

[0152] This embodiment defines the data storage and migration strategy according to the life cycle management strategy of the accounting archive data. As the life cycle of the accounting archive changes, the sensitivity and access frequency of the accounting archive change accordingly. This embodiment sets up a dynamic adjustment mechanism to achieve data level migration and optimize the utilization of storage resources; while migrating data, the records on the main chain are updated synchronously to enhance the traceability and security of the data management process.

[0153] This embodiment extracts the ABE ciphertext data block to be migrated from the current storage layer, first verifies its integrity to ensure that it is migrated in a complete and authentic state, and then transfers the ABE ciphertext data block to the storage medium of the target storage layer. An audit log is generated based on the migration record, and the latest information of the ABE ciphertext data block is updated on the main chain. This migration method ensures the integrity and security of the data during the migration process, and the audit log ensures that the migration operation is transparent and compliant. This method optimizes the efficiency and reliability of data management and improves the overall accounting archive data management capabilities.

[0154] This embodiment improves the efficiency and security of accounting archive data management of the financial management party of Company B through homomorphic encryption, attribute-based encryption, blockchain technology and dynamic storage management. Homomorphic encryption allows accounting archives to be calculated and processed in an encrypted state, which improves the flexibility of data management; attribute-based encryption ensures that data can only be accessed by people with corresponding attributes and permissions, ensuring the security and privacy of data; the introduction of blockchain technology separates the management of operation records and data, which not only improves storage efficiency, but also ensures the traceability of data during storage and transmission; dynamic storage management allows data of different sensitivities and access frequencies to be reasonably allocated to different levels for storage, improving the confidentiality and rapid access of archive management. In addition, the addition of digital watermarks protects the ownership and copyright of data and reduces the possibility of data being tampered with or destroyed.

[0155] Embodiment 2

[0156] In order to ensure that the financial management of Enterprise B can efficiently and safely manage the accounting file data within the enterprise, this embodiment provides a data management system for accounting files. Figure 2 , the system includes:

[0157] Network construction unit: used to construct a blockchain network architecture including a main chain and at least one side chain; the main chain is used to store the audit log of the transaction hash value, and the side chain is used to store the encrypted accounting file data;

[0158] Access control unit: used to formulate access policies for the encrypted accounting file data and define access rights; use attribute-based encryption technology to perform secondary encryption on the homomorphic ciphertext to generate ABE ciphertext;

[0159] Digital watermark embedding unit: used for embedding a digital watermark in the encrypted accounting file data to indicate the owner and source of the data;

[0160] Data integrity verification unit: used to verify the integrity of transactions and data by introducing verifiable random functions into the consensus mechanism;

[0161] Hierarchical storage strategy unit: used to classify the accounting archive data into sensitivity levels and access frequency levels according to the sensitivity level and access frequency, and define storage layers and configure storage nodes according to the levels.

[0162] Further, obtaining accounting file data, encrypting the accounting file data using a homomorphic encryption algorithm Paillier to generate a homomorphic ciphertext;

[0163] Divide the homomorphic ciphertext into multiple data blocks and store them in different blocks of the side chain; calculate the transaction hash value for each data block. Record the transaction hash value and audit log corresponding to each data block on the main chain. The audit log is added to the next block of the main chain as part of the transaction record.

[0164] Furthermore, access rights are defined according to the user's role and attributes, and access policies are formulated; attribute-based encryption technology is used to perform secondary encryption on the homomorphic ciphertext to generate ABE ciphertext.

[0165] The encrypted data is re-encrypted using attribute-based encryption technology; the specific steps include:

[0166] Use the CP-ABE system for initialization to generate public parameters and master keys; generate a unique ABE private key for each role based on its attribute information.

[0167] Use homomorphic ciphertext as ABE plaintext data, use public parameters, user's ABE private key and access policy to encrypt ABE plaintext data twice to generate ABE ciphertext;

[0168] According to the sensitivity of accounting archive data, the ABE ciphertext is stored in a block of the side chain. Each side chain block contains the ABE ciphertext, the data identifier corresponding to the ciphertext and the storage time; the main chain is updated synchronously.

[0169] When a data access request occurs, the user's exclusive private key and attribute matching mechanism are used to verify whether the user's role and attributes comply with the corresponding access policy; if they do, the plaintext data is decrypted and restored.

[0170] Furthermore, a digital watermark is embedded in the ABE ciphertext to generate a new ciphertext with the watermark; the steps include:

[0171] Extract homomorphic ciphertext from ABE ciphertext to generate watermark information;

[0172] This embodiment adopts a block-based watermark embedding method; first, the watermark information is converted into a binary bit sequence using UTF-8 encoding and a hash function;

[0173] Select the non-key byte position in the ABE ciphertext, and use the least significant bit (LSB) embedding method to embed the binary bit sequence into the ABE ciphertext to generate a new ciphertext;

[0174] According to the sensitivity of the data, the new ciphertext is stored in the appropriate side chain to replace the original ABE ciphertext;

[0175] Calculate the hash value of the new ciphertext and generate an audit log; update the main chain block.

[0176] When a situation arises where data security needs to be verified, the block storing the new ciphertext is obtained from the side chain, and the watermark bit is extracted from the specified position using the LSB extraction method.

[0177] The original watermark field is restored through decoding and inverse hashing process to verify whether the watermark information is consistent with the original information; and the data integrity is verified by hash value calculation.

[0178] Furthermore, the step of verifying the integrity of the new ciphertext includes performing hash calculation on the new ciphertext to generate a hash value of the text data; using a verifiable random function (VRF) to perform calculations to generate a random number and a verification certificate, and storing the random number, the verification certificate and the new ciphertext hash value together in the transaction record of the blockchain network.

[0179] When integrity verification of stored data is required, the above transaction records and corresponding ABE ciphertexts are first extracted from the blockchain network, and the hash value is recalculated;

[0180] Use the public VRF to verify whether the hash value of the ABE ciphertext data matches; if the verification is a match, the data is verified to be complete; if the verification is not a match, the verification fails and the data may be tampered with or the watermark removed.

[0181] Furthermore, a hierarchical storage strategy is formulated according to the sensitivity of accounting archive data, and the specific steps include: defining multiple storage layers according to the combination of data sensitivity and access frequency; each storage layer has a specific storage medium and access rights. The following is an example of the storage description defined in the accounting archive data management of the financial management party of Enterprise B of the present invention;

[0182] Highly sensitive data: stored in a private sidechain to ensure confidentiality and integrity;

[0183] Medium-sensitivity data: stored in a permissioned sidechain, with moderate security and privacy protection;

[0184] Low-sensitivity data: stored on the public side chain to reduce storage costs.

[0185] Storage Tier 1: Highly sensitive & frequently accessed, with enterprise-class SSD storage media, accessible only to authorized senior financial personnel and auditors, stored in a high-security data center with redundant power supplies and network connections;

[0186] Storage layer 2: High sensitivity & low-frequency access, the storage medium is encrypted tape or offline storage, only a few authorized personnel can access it, stored in physically isolated storage devices, fireproof and waterproof;

[0187] Storage layer 3: low sensitivity & low frequency access, the storage medium is ordinary HDD or cloud archive, which can be accessed by authorized business personnel and stored in cloud archive storage service or local archive storage device.

[0188] As the life cycle of accounting archive data changes, the sensitivity and access frequency of accounting archive data also change accordingly, and the storage location and storage level of the archives should also be adjusted accordingly to ensure the reasonable allocation of storage space. According to the above-mentioned tiered storage strategy, this embodiment evaluates the sensitivity and access frequency of 2,000 accounting archive data of the financial management party of Enterprise B to determine the migration storage level of the data; Table 7 gives some examples.

[0189] Table 7 Examples of some migration storage tiers

[0190] Data No. Sensitivity Frequency of visit Current level Migration level D001 high high 0 1 D002 high Low 0 3 D003 Low high 0 7 D004 middle Low 0 6

[0191] In Table 7, the current 2000 pieces of data are all initially allocated to the tier, so the current tier is 0; in the data management cycle, the storage tier of the data is dynamically adjusted according to the access frequency and the sensitivity. In addition, in the subsequent process, the user can re-evaluate and migrate the data in a regular manner, including but not limited to.

[0192] In addition, to achieve the above-mentioned purpose, the present invention also proposes a data management storage medium for accounting archives, wherein the accounting archive data management medium stores a computer program, and when the computer program is executed by a processor, the processor executes the steps of the method described above.

[0193] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A data management method for accounting files, characterized in that: include: Build a blockchain network, including the main chain and side chain; Acquire accounting file data, encrypt the accounting file data using a homomorphic encryption algorithm, and generate homomorphic ciphertext; Dividing the homomorphic ciphertext into multiple data blocks and storing them in different blocks of the side chain; Define access rights and formulate access policies based on user roles and attributes; The homomorphic ciphertext is encrypted twice using attribute-based encryption technology to generate an ABE ciphertext; Storing the ABE ciphertext on the side chain; Extracting the homomorphic ciphertext from the ABE ciphertext to generate watermark information, embedding it into the ABE ciphertext, and replacing the ABE ciphertext with the ABE ciphertext with the digital watermark on the side chain; Introducing a verifiable random function to verify the integrity of the ABE ciphertext with a digital watermark; Defining several storage tiers based on a combination of sensitivity and access frequency; each of the storage tiers includes specific storage media and access rights; The accounting archival data is evaluated for sensitivity and access frequency, and according to the sensitivity and access frequency, the accounting archival data is stored in a corresponding storage layer, and the accounting archival data is classified and stored in layers; data storage and migration are defined according to the life cycle of the accounting archival data.

2. A data management method for accounting files according to claim 1, characterized in that: The step of storing the homomorphic ciphertext in the side chain comprises: Encrypting the accounting file data using a homomorphic encryption algorithm to obtain the homomorphic ciphertext; dividing the homomorphic ciphertext into a plurality of data blocks and storing them in different blocks of the side chain; Calculate a transaction hash value for each of the data blocks, record the transaction hash value and related audit logs on the main chain; add the related audit logs and transaction records to the next block of the main chain to form a chain structure.

3. The data management method for accounting files according to claim 1 is characterized in that: The secondary encryption process includes: According to the role of the user, define access rights for the user to form user attribute information; formulate access control policies according to the user attribute information; Using attribute-based encryption technology to generate a unique ABE private key for each user; Using the homomorphic ciphertext as the plaintext of the attribute-based encryption, performing secondary encryption on the plaintext through the public parameters in the attribute-based encryption, the ABE private key and the access control policy to generate the ABE ciphertext; The ABE ciphertext is stored on the side chain.

4. The data management method for accounting files according to claim 1, characterized in that: The steps of embedding a digital watermark into the ABE ciphertext include: Extracting the homomorphic ciphertext from the ABE ciphertext to be embedded with a watermark, and generating watermark information; In combination with the data characteristics of accounting archives, watermark bits are embedded in specific positions of the data to generate new ciphertext with the digital watermark; the new ciphertext is stored in the block of the side chain to replace the ABE ciphertext.

5. The data management method for accounting files according to claim 1 is characterized in that: The steps to verify the integrity of the new ciphertext include: Performing hash calculation on the new ciphertext to generate a ciphertext data hash value; processing the ciphertext data hash value using a verifiable random function to generate a random number and a verification certificate; storing the random number, the verification certificate and the data hash value together in the transaction record of the blockchain network; When performing data integrity verification on the new ciphertext, obtaining the new ciphertext, the random number and the verification certificate from the blockchain network; Recalculating the hash of the new ciphertext to obtain a new hash value; checking whether the random number and the verification certificate match the new hash value through the publicly verifiable random function; If the match is successful, the new ciphertext passes the data integrity verification; if the match is not successful, the new ciphertext fails the data integrity verification.

6. The data management method for accounting files according to claim 1, characterized in that: The process of formulating the tiered storage strategy includes: Define the sensitivity level classification and access frequency level classification of data; the sensitivity level classification includes high sensitivity, medium sensitivity and low sensitivity, and the access frequency level classification includes high frequency access, medium frequency access and low frequency access; Defining a number of storage tiers based on a combination of the sensitivity level classification and the access frequency level classification; the storage tiers include specific storage media settings, access rights, and storage requirements; Acquire the accounting file data to be stored, define the sensitivity and access frequency, and store the accounting file data to be stored in the corresponding storage layer.

7. The data management method for accounting files according to claim 1, characterized in that: The steps for defining data storage and migration according to the life cycle of the accounting archive data include: During the life cycle stage of the accounting archive data, the sensitivity and access frequency of the accounting archive data in each storage layer are evaluated, and the storage layer of the accounting archive data is adjusted according to the evaluation results.

8. The data management method for accounting files according to claim 7, characterized in that: The step of adjusting the storage layer of the accounting archive data according to the evaluation result comprises: Extract the ABE ciphertext data block to be migrated from the current storage layer, recalculate the hash value, and match the new hash value with the transaction hash value of the ABE ciphertext data block stored on the main chain; when the match is successful, transmit the ABE ciphertext data block to the target storage layer through the transmission network and store it in the storage medium of the target storage layer; Performing hash value calculation again on the ABE ciphertext data block after migration to generate an audit log; the audit log includes an owner identifier, a migration timestamp, a data identifier, and the hash value after migration; The audit log containing the migration record and the reverse hash calculation are performed to generate a migration record hash value; the migration record hash value is digitally signed using a private key to generate a verification certificate; the migration record hash value, the audit log and the verification certificate are stored as transaction records in the next block of the main chain.

9. A data management system for accounting files, characterized in that: include: Network construction unit: used to build a blockchain network architecture including a main chain and at least one side chain; The main chain is used to store the audit log and operation information of the transaction hash value, and the side chain is used to store encrypted data; Access permission control unit: used to formulate access policies and define access permissions for the accounting file data after homomorphic encryption; The accounting file data after homomorphic encryption is re-encrypted using attribute-based encryption technology to generate ABE ciphertext; Digital watermark embedding unit: used to embed digital watermarks in ABE ciphertext to indicate the owner and source of data and track data transmission and storage; Data integrity verification unit: used to introduce verifiable random functions to verify the integrity of transactions and data; Hierarchical storage strategy unit: used to classify the accounting archive data into sensitivity levels and access frequency levels according to the sensitivity level and access frequency, and define and migrate storage layers according to the levels.

10. A data management storage medium for accounting archives, characterized in that: The accounting archive data management medium stores a computer program, and when the computer program is executed by a processor, the processor executes the steps of the method as claimed in any one of claims 1 to 8.

Citation Information

Cited By

  • Finance and tax data intelligent management method and system based on encrypted storage

    CN120277699A

  • Block chain-based big data information security management method

    CN120512235A

  • Big data information security management method based on blockchain

    CN120512235B