Data storage method, data verification method, equipment, storage medium and product

By setting the data unit of the file to be stored as elements in the first elliptic curve group and generating signatures and verification tags, and verifying them in combination with bilinear pairing relationships, the data integrity verification problem in cloud storage is solved, and efficient and secure data storage and verification are achieved.

CN119995893APending Publication Date: 2025-05-13BEIJING OCEANBASE TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510065938.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the cloud storage scenario, it is difficult for enterprises to effectively verify the data integrity stored in third-party data centers, especially due to the huge overhead of network communication and huge data volume.

Method used

By setting the data unit of the file to be stored as an element in the first elliptic curve group, and combining the randomly acquired group elements, a signature tag and a verification tag are generated and stored in the server. This method uses a bilinear pairing relationship for verification and constructs verification equations to judge file integrity.

Benefits of technology

It realizes efficient verification of file integrity, improves the security and reliability of data storage procedures, reduces the risk of data leakage, and does not require obtaining document plaintext.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995893A_ABST
    Figure CN119995893A_ABST
Patent Text Reader

Abstract

One or more embodiments of the invention provide a data storage method, a data verification method, equipment, a storage medium and a product. The data storage method comprises the steps of obtaining a to-be-stored file, wherein a data unit in the to-be-stored file is an element in a first elliptic curve group; randomly acquiring group elements from the first elliptic curve group; signing based on the file size of the to-be-stored file and the group element, generating a signature tag of the to-be-stored file, and generating a verification tag of the to-be-stored file based on the data unit and the group element in the to-be-stored file; storing the to-be-stored file, the signature tag and the verification tag in a server; wherein the signature tag and the verification tag are applied to the integrity verification process of the to-be-stored file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present specification relate to the field of data storage technology, and in particular, to a data storage method, a data verification method, an electronic device, a computer-readable storage medium, and a computer program product. Background Art

[0002] With the development of computer technology, the data volume of virtual assets of enterprises or institutions has increased rapidly, which requires enterprises to expand the storage space for the rapidly growing data volume. However, storage devices are expensive, and their maintenance and upgrades also generate a lot of additional expenses. Therefore, using cloud storage, where a third-party company's data center stores the company's data, has become an effective way for enterprises to reduce costs.

[0003] However, in the cloud storage scenario, enterprises transfer data to data centers via cloud storage services, allowing cloud providers to gain full control over the data sent by enterprises. Therefore, when storing data in a third-party company's data center, enterprises need to consider data security issues, including data integrity issues. Data integrity means that enterprises need to ensure that the data they store in the data center is not lost or tampered with. However, due to the huge overhead of network communication in data reading, especially when the amount of data stored in the data center is huge, it is difficult for enterprises to verify the integrity of the data by reading the data completely. Summary of the invention

[0004] In view of this, one or more embodiments of the present specification provide a data storage method, a data verification method, an electronic device, a computer-readable storage medium, and a computer program product.

[0005] To achieve the above objectives, one or more embodiments of this specification provide the following technical solutions:

[0006] According to a first aspect of one or more embodiments of this specification, a data storage method is proposed, including:

[0007] Acquire a file to be stored, wherein the data unit in the file to be stored is an element in a first elliptic curve group;

[0008] randomly obtaining a group element from the first elliptic curve group;

[0009] Performing a signature based on the file size of the file to be stored and the group element to generate a signature tag of the file to be stored, and generating a verification tag of the file to be stored based on the data unit in the file to be stored and the group element;

[0010] The file to be stored, the signature tag and the verification tag are stored in a server; wherein the signature tag and the verification tag are applied to the integrity verification process of the file to be stored.

[0011] According to a second aspect of an embodiment of this specification, a data verification method is provided for verifying the integrity of a file stored in a server, wherein the file is stored based on the data storage method described in the first aspect; the method comprises:

[0012] Sending a verification request carrying a file identifier of a file to be verified to the server, so that the server returns a verification response based on the verification request; the verification response includes a signature tag of the file to be verified and verification data, the verification data being obtained based on processing the file to be verified and its verification tag;

[0013] When the signature tag is verified, a preset bilinear pairing relationship of the first elliptic curve group is obtained, where the bilinear pairing relationship is used to describe elements in the first elliptic curve group and elements in the second elliptic curve group, and is mapped to a third elliptic curve group through a bilinear pairing operation;

[0014] Performing a bilinear pairing operation on the verification data according to the bilinear pairing relationship to construct a verification equation;

[0015] If the verification equation holds true, it is determined that the file to be verified is completely stored in the server; otherwise, it is determined that the file to be verified is invalid.

[0016] According to a third aspect of the embodiments of this specification, there is provided an electronic device, including:

[0017] processor;

[0018] a memory for storing processor-executable instructions;

[0019] When the processor executes the executable instructions, it is used to implement the method described in the first aspect or the second aspect.

[0020] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the steps of the method described in the first aspect or the second aspect are implemented.

[0021] According to a fifth aspect of the embodiments of this specification, a computer program product is provided, including a computer program, which implements the steps of the method described in the first aspect or the second aspect when executed by a processor.

[0022] The technical solutions provided by the embodiments of this specification may have the following beneficial effects:

[0023] The data storage method provided in this embodiment generates a signature tag based on the file size and group element of the file to be stored by setting the data unit of the file to be stored as an element in the first elliptic curve group and combining the group element randomly obtained from the first elliptic curve group, and generates a verification tag based on the data unit and group element of the file to be stored. The combination of the signature tag and the verification tag can realize efficient verification of file integrity and improve the security and reliability of the data storage process.

[0024] The data verification method provided in this embodiment combines the signature tag of the file to be verified and the verification data, performs a bilinear pairing operation on the verification data through a bilinear pairing relationship, constructs a verification equation and determines whether it holds, thereby efficiently verifying the integrity of the stored file. This method utilizes the characteristics of bilinear pairing to enhance the security and accuracy of the verification process, and can complete the verification operation without obtaining the plain text of the file, reducing the risk of data leakage.

[0025] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 It is a structural diagram of an interactive system provided by an exemplary embodiment.

[0027] Figure 2 It is an interactive schematic diagram of a data storage process provided by an exemplary embodiment.

[0028] Figure 3 It is a flowchart of a data storage method provided by an exemplary embodiment.

[0029] Figure 4 It is an interactive schematic diagram of a data verification process provided by an exemplary embodiment.

[0030] Figure 5 It is a flow chart of a data verification method provided by an exemplary embodiment.

[0031] Figure 6 It is a schematic structural diagram of an electronic device provided by an exemplary embodiment. DETAILED DESCRIPTION

[0032] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with one or more embodiments of this specification. Instead, they are merely examples of devices and methods consistent with some aspects of one or more embodiments of this specification as detailed in the appended claims.

[0033] It should be noted that: in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may be combined into a single step for description in other embodiments.

[0034] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this manual are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0035] Here is an explanation of the terms mentioned in this manual:

[0036] 1. Cyclic group.

[0037] A group is an algebraic structure (G,·) containing a binary operation such that the set G satisfies the following properties on the operation ·:G×G→G:

[0038] a) Closure: The result of any operation between two elements of a group is still an element of the group, that is,

[0039] b) Satisfy the associative law:

[0040] c) With identity element: There exists an element e in the group whose result of operation with any group element is the same group element, that is,

[0041] d) Has inverse elements: Any element in a group has an inverse element under this group operation, that is,

[0042] In particular, if any element in G can be expressed as the exponent of one of its elements, that is Then this group is called a cyclic group.

[0043] 2. Elliptic Curve Group

[0044] An elliptic curve is a class of curves that satisfies the equation y 2 =x 3 +ax+b curve, when satisfying 4a 3 +27b 2 ≠ 0, it is called a non-singular elliptic curve. For points on a non-singular elliptic curve over a finite field and an additional point at infinity, binary operations can be defined to form a group structure, called an elliptic curve group.

[0045] 3. Bilinear pairing

[0046] Let groups G1, G2, G T is a p-order cyclic group, and the identity element in each group is 1, and the pairing function is called e:G1×G2→G T is a bilinear pairing if the function e satisfies the following properties:

[0047] a) Bilinearity:

[0048] b) Non-degenerate:

[0049] c) Computability: Function e can be computed in polynomial time;

[0050] This pairing function is called a bilinear pairing. Let (e, G1, G2, G T ,g1,g2,g T ), and among them g1,g2,g T They are groups G1, G2, G T The generator of .

[0051] We further classify bilinear pairings according to the relationship between G1 and G2. Note that cyclic groups of order p must be isomorphic to each other, but this isomorphism is not necessarily computable.

[0052] If G1=G2, it is called a bilinear pairing of the first kind; if there exists an isomorphism mapping ρ:G2→G1 that can be calculated in polynomial time, and the calculation of its inverse mapping is difficult, it is called a bilinear pairing of the second kind; if the calculation of bidirectional isomorphism mappings between G1 and G2 is difficult, it is called a bilinear pairing of the third kind.

[0053] Currently, on elliptic curves, bilinear pairing instances that satisfy the above properties can be constructed, so that the three groups involved are all elliptic curve groups.

[0054] 4. DLIN hypothesis: The DLIN (Decisional Linear) hypothesis is a complexity theory hypothesis, mainly used in cryptography to prove the security of certain encryption schemes. It is based on the mathematical properties of cyclic groups, especially the assumption that the adversary (attacker) has difficulty distinguishing specific mathematical constructions.

[0055] Let group G be a cyclic group of order p, and let its generator be g. Select five elements independently and evenly from And let Z0 = g ax+by ,Z1=g z , then the DLIN problem on the group G is that given an input (G,p,g,g x ,g y ,g a ,g b ,Z b ), the problem of outputting the correct value of b, where b is independently and uniformly chosen from the set {0,1}.

[0056] For some prime p-order cyclic group G, the DLIN assumption on the group G holds if and only if for any probabilistic polynomial-time adversary The probability of correctly answering DLIN questions has a non-negligible advantage over random output, namely:

[0057]

[0058] negl(λ) is a negligible function of the security parameter λ (it grows slower than any polynomial function). In fact, for a second-class bilinear pairing (e,G1,G2,G T ,p,g1,g2,g T ), DLIN assumes that in G1, G2, G T All of the above are considered to be established.

[0059] 5. SDP assumption (Symmetric External Diffie-Hellman Pairing).

[0060] For a bilinear pairing P = (e, G1, G2, G T ,p,g1,g2,g T ), select four generators independently and randomly in G2 Then the SDP problem on the bilinear pairing is that, given the input (P, g z ,g u ,h z ,g u ), output a set So that the following is true:

[0061] e(z,g z )e(u,g u )=1∧e(z,h z )e(v,h v )=1,

[0062] The solution of (z,u,v)≠(1,1,1) is called a non-trivial solution to the SDP problem.

[0063] For some bilinear pairing P, the SDP assumption on the group P holds if and only if for any probabilistic polynomial-time adversary The advantage of correctly answering a set of non-trivial solutions to the SDP problem is not negligible, that is, for a set of adversaries returning

[0064] Pr[(z,g z )e(u,g u )=1∧e(z,h z )e(v,h v )=1∧(z,u,v)≠(1,1,1)]=negl(λ).

[0065] In fact, Cathalo et al. proved in 2009 that the SDP hypothesis can be derived from the DLIN hypothesis, that is, the following theorem:

[0066] For a bilinear pairing P = (e, G1, G2, G T ,p,g1,g2,g T ), if the DLIN assumption above it holds, then the SDP assumption above it holds.

[0067] 6. Key.

[0068] A key refers to a parameter used to convert plaintext into ciphertext, or ciphertext into plaintext during the encryption or decryption process of an encryption algorithm, or a parameter used in other cryptographic scheme execution processes (such as used for signature and signature verification processes in digital signature algorithms); among them, a private key refers to a key that is privately kept by one of the participating parties and is not disclosed; a public key is a key that is disclosed after it is generated.

[0069] 7. Public key encryption.

[0070] Public key encryption refers to a type of encryption algorithm that uses different keys when encrypting and decrypting data, and the key used for encryption is a public parameter.

[0071] 8. Digital signature algorithm.

[0072] Digital signature algorithm is a type of public key cryptography scheme, which mainly includes two steps: signing and verification. For a message, the holder of the private key can use the digital signature algorithm to sign the message and send the message and the signature together; the recipient of the message can verify the signature through the public key.

[0073] The security of a digital signature algorithm is usually characterized by its EUF-CMA (Existence Unforgeable Under Chosen Message Attack) security. This security will ensure that if the recipient outputs a pass when verifying the signature, then it can prove that:

[0074] a) The message is indeed sent by the holder of the private key;

[0075] b) The message has not been tampered with after being sent by the holder of the private key.

[0076] 9. Partially homomorphic encryption.

[0077] Partially homomorphic encryption algorithms are encryption algorithms that additionally include a homomorphic computation algorithm Eval, which satisfies the condition Dec(Eval(Enc(x), Enc(y))) = x·y with overwhelming probability for any plaintext x, y and a binary operation x·y. Enc is the encryption algorithm and Dec is the decryption algorithm. This shows that using the algorithm Eval, the party holding the ciphertext can perform computations on the ciphertext and obtain the computation result of the corresponding plaintext after decryption.

[0078] Eval (homomorphic computation algorithm): performs a specific operation on two ciphertexts Enc(x) and Enc(y), and outputs a new ciphertext nc(z): Eval(Enc(x), Enc(y)) = Enc(z), where z = x·y.

[0079] (Supported binary operations): These are specific operations supported by the encryption scheme, such as addition or multiplication.

[0080] 10. Proof of Data Possession (PDP) protocol.

[0081] PDP protocol is a general term for a class of protocols used to prove file integrity. For such protocols that support public verification, the protocol will be carried out between the user, the server and the verifier, and the execution process of the protocol is divided into two stages, called the storage stage and the proof stage. The first stage is the storage stage, in which the protocol is executed between the user and the server; the second stage is the proof stage, which is executed between the verifier and the server.

[0082] In the storage phase, the PDP system is initialized, and then the files that need to be stored in the cloud are processed and sent to the server; in the proof phase, the verifier initiates a storage proof challenge to the server, the server responds to the challenge and asks the verifier to verify its response.

[0083] The security of the PDP protocol requires that for the challenge initiated by the verifier, as long as the server can output a verifiable response with overwhelming probability, it can be guaranteed to preserve the original file intact. More formally, there must be a polynomial time extractor algorithm that can extract the complete original file from the memory snapshot of the server at this moment.

[0084] 11. Random Oracle model.

[0085] The random oracle model assumes that all parties executing the cryptographic scheme can access and query the same random oracle H, and use this random oracle to perform calculations and run the cryptographic scheme; among them, the random oracle is a class of theoretical oracles that can predict the random oracle H for any finite input s∈{0,1} * , can return an independent random infinite length reply H(s)∈{0,1} ∞ , the distribution of each bit value is uniform and independent, and the random oracle's response to the same input is always the same.

[0086] In actual use, the random oracle model is often used to characterize and prove the security of the scheme. Generally speaking, this model regards the cryptographic secure hash function (such as SHA2, SM3, etc.) used in the scheme as a random oracle, and proves the security of the scheme under this condition. From a practical perspective, the security characterized and proved under this model is guaranteed and widely recognized and used.

[0087] 12. Describe the meaning of some symbols used in the plan.

[0088] (1) Indicates that an element is uniformly randomly selected from the set S as the value of x

[0089] (2) represents the remainder field modulo p.

[0090] Based on the problems in the related technology, the embodiments of this specification provide a data storage method and a data verification method for data stored in the form of elements on an elliptic curve group. Before the file is stored, a signature is performed on the file to be stored and a verification tag is generated to ensure that the authenticity of the file can be verified through the signature tag after storage, and the integrity of the file can be verified through the verification tag, thereby effectively preventing the file from being tampered with or lost during transmission or storage.

[0091] See also Figure 1 , shows an interactive system, which includes a user terminal 10, a server 20 and a verification terminal 30.

[0092] The user terminal 10 can be a terminal used by an enterprise user. The user terminal 10 includes but is not limited to a PC (Personal Computer), a mobile phone, a tablet device, a laptop computer, a PDA (Personal Digital Assistants), a wearable device (such as smart glasses, a smart watch, etc.), etc. One or more embodiments of this specification are not limited to this.

[0093] The server 20 may be a storage device provided by a cloud, the server 20 may be a physical server including an independent host, or the server 20 may be a virtual server hosted by a host cluster.

[0094] The verification terminal 30 can be a terminal used to verify the integrity of files stored on the server 20. The verification terminal 30 and the user terminal 10 can be the same or different. The verification terminal 30 includes but is not limited to PC (Personal Computer), mobile phones, tablet devices, laptops, PDAs (Personal Digital Assistants), wearable devices (such as smart glasses, smart watches, etc.), etc., and one or more embodiments of the present specification do not limit this.

[0095] During the data storage stage, the user terminal 10 is initialized to obtain relevant publicly available parameters for generating relevant verification information of the file to be stored (such as signature tags and verification tags), and then processes the file to be stored in the cloud to obtain the relevant verification information of the file, and sends the file and its relevant verification information to the server 20.

[0096] During the data verification phase, the verification terminal 30 initiates a storage proof challenge to the server, and the server responds to the challenge and instructs the verification terminal 30 to verify its response.

[0097] For example, see Figure 2,In the data storage phase, the user terminal first runs the initialization algorithm to obtain the following relevant public parameters:

[0098] (1) Select a second type of bilinear pairing e:G1×G2→G where the SDP assumption is considered to hold T , which has a polynomial time computable homomorphism ρ:G2→G1. Let the order of the three groups |G1|=|G2|=|G T |=p satisfies p~2 λ . Suppose the generators in the three groups are g1, g2, g T , and satisfy g T =e(g1,g2) and g1=ρ(g2). Let this bilinear structure be the main public parameter pp0=(e,p,G1,G2,G T ,g1,g2,g T ), where G1 represents the first elliptic curve group, G2 represents the second elliptic curve group, G T represents the third elliptic curve group, e represents that the three elliptic curve groups have a second-kind bilinear pairing relationship, p represents the order of the three elliptic curve groups, g1 represents the generator of the first elliptic curve group, g2 represents the generator of the second elliptic curve group, and g T Represents the generators of the third elliptic curve group.

[0099] Of course, three elliptic curve groups that satisfy the first type of bilinear pairing relationship or the third type of bilinear pairing relationship may also be selected, and this embodiment does not impose any limitation on this.

[0100] (2) Select a hash function H: {0,1} * →G1. In actual use, hash functions such as SHA2 and SM3 are usually used to perform hash operations on the input string, and then the results of the hash operations are further encoded on the elliptic curve G1. In the security proof of the embodiments of this specification, the hash function will be regarded as a random oracle.

[0101] (3) Select a digital signature protocol, denoted as DS. For the digital signature protocol DS, run its initialization algorithm to obtain the public parameter pp s ←DS.Setup(1 λ ).pp s Used to determine the public key and private key in the digital signature process of this illustrated embodiment.

[0102] (4) Optionally, the user terminal can input an additional parameter n as the vector length for running the encryption algorithm. This parameter will affect the length of the key generated and the length of the reply in the proof phase.

[0103] That is to say, all the public parameters obtained in the initialization phase are pp=(pp0,pp s ,n). These parameters can be exposed to the server or other terminals.

[0104] Among them, see Figure 2 , after obtaining the public parameter pp of the digital signature protocol s Afterwards, the user terminal can call the key generation algorithm in the digital signature protocol to obtain the public key pk and private key sk for digital signature. The public key pk for digital signature can be made public to the server or other terminals.

[0105] After initialization, see Figure 2 as well as Figure 3 , the data storage method provided in the embodiment of this specification can be performed, and the data storage method can be executed by the above-mentioned user terminal. It can be understood that the data storage method describes the storage process for a file to be stored. If there are multiple storage files that need to be stored in the server, the data storage method provided in the embodiment of this specification can be executed for each storage file. The data storage method includes:

[0106] In S301, a file to be stored is obtained, where the data units in the file to be stored are elements in a first elliptic curve group.

[0107] In one possible implementation, the file to be stored includes a matrix of m rows and n columns, where m and n are both integers greater than 0, and each value in the matrix of m rows and n columns is an element in the first elliptic curve group. In this case, there is no need to perform any processing on the file to be stored, and direct storage eliminates additional data encoding steps, simplifies the operation process, and improves storage efficiency.

[0108] In another possible implementation, each data unit in the first original file to be stored is not an element in the first elliptic curve group and needs to be encoded into the first elliptic curve group first. Specifically, the user terminal can obtain the first original file, which includes a matrix of m rows and n columns, where m and n are both integers greater than 0, and then encode the values ​​in the matrix of m rows and n columns into the first elliptic curve group to obtain the file to be stored. The encoding algorithm in the relevant technology can be used for encoding, and this embodiment does not impose any restrictions on this. By encoding the data unit in the first original file into the first elliptic curve group, it is possible to be compatible with subsequent data integrity verification requirements without changing the data structure, thereby adapting to more storage scenarios.

[0109] In another possible implementation, in order to meet the needs of homomorphic computing, the user terminal can encrypt data using a homomorphic encryption algorithm, and then store the encrypted data using the data storage method provided in the embodiments of this specification. When it is necessary to perform a calculation, the server can use the characteristics of the homomorphic encryption algorithm to perform homomorphic computing on the encrypted data stored in the server, and then the server sends the result of the homomorphic computing back to the user terminal; the user terminal decrypts it to obtain the plain text of the calculation result.

[0110] Specifically, the user terminal can obtain the second original file, and the second original file includes a matrix of m rows and n-1 columns, where m is an integer greater than 0 and n is an integer greater than 1. In the case where each data unit in the second original file is not an element in the first elliptic curve group, it is necessary to first encode it into the first elliptic curve group, that is, the user terminal can encode each value in the matrix of m rows and n-1 columns into the first elliptic curve group to obtain a file to be encrypted, and the file to be encrypted includes a matrix of m rows and n-1 columns, and the values ​​in the matrix are elements in the first elliptic curve group. In the case where each data unit in the second original file is an element in the first elliptic curve group, the above encoding step is not required, that is, the second original file is directly used as the file to be encrypted to perform the following encryption processing process.

[0111] Then, the user terminal can encrypt the file to be encrypted based on the pre-generated n-1 public keys to obtain the file to be stored; wherein the n-1 public keys are generated based on the order of the first elliptic curve group and the number of columns in the second original file, and the n-1 public keys correspond one-to-one to the n-1 columns in the file to be encrypted.

[0112] In the n-1 public key generation stage, the user terminal can obtain n-1 private key exponents within a preset value range; the preset value range is determined based on the order of the first elliptic curve group. Exemplarily, the minimum value of the preset value range is 0, and the maximum value is the result of subtracting 1 from the order of the first elliptic curve group; then the user terminal performs an exponential operation on the generator of the first elliptic curve group and each private key exponent to obtain n-1 public keys; wherein, the n-1 public keys and the n-1 private key exponents constitute a private key.

[0113] In the encryption stage, the user terminal can randomly generate m calculation exponents corresponding to m rows in the file to be encrypted respectively; then, based on the calculation exponent of each row and n - 1 public keys, encrypt the values in the file to be encrypted to obtain an encrypted matrix with m rows and n - 1 columns; specifically, each value in each row of the encrypted matrix is the product of the value to be encrypted at the same position in the file to be encrypted and a specified power, and the specified power is the power between the public key corresponding to the column where the value to be encrypted is located and the calculation exponent of this row. And the user terminal performs exponentiation operations based on the generator of the first elliptic curve group and the calculation exponent of each row to obtain a matrix with m rows and 1 column; finally, the user terminal combines the encrypted matrix with m rows and n - 1 columns and the matrix with m rows and 1 column to obtain the file to be stored. In this embodiment, the file to be stored can take into account the process of homomorphic encryption and integrity verification. In the subsequent integrity verification process, verification can be performed based on the second type of bilinear pairing relationship or the third type of bilinear pairing relationship.

[0114] Among them, the encrypted matrix with m rows and n - 1 columns can be decrypted based on the private key obtained by combining n - 1 public keys and n - 1 private key exponents.

[0115] For example, in the key generation stage, randomly select n - 1 private key exponents denoted as s=(s1, s2, …, s n-1 ); then, calculate the public key where g1 represents the generator of the first elliptic curve group, denoted as h=(h1, h2, …, h n-1 ). Take h as an additional public key and (h, s) as an additional private key.

[0116] The file to be encrypted is a matrix encoded on G1 with m rows and n - 1 columns, denoted as F′={f′ ij} m×(n-1) , and then perform the encryption operation on the file to be encrypted. First, for each row of the file to be encrypted, randomly select a calculation exponent r i , 1 ≤ i ≤ m, 1 ≤ j ≤ n - 1, and then calculate Finally, let Finally, an m - row and n - column file to be stored F={f ij} m×n can be obtained.

[0117] If it is necessary to retrieve the file from the server, after retrieving the file, perform the decryption step of this algorithm on the file. That is, for 1 ≤ i ≤ m, 1 ≤ j < n, calculate That's it.

[0118] For data encrypted by the homomorphic encryption algorithm for elements on the elliptic curve group, this embodiment will not break the homomorphic computing properties of the algorithm during execution. That is, the file obtained by the data storage method of this embodiment can be directly homomorphically calculated without any processing after reading. For example, homomorphic multiplication operations can be performed between the rows of the storage file obtained from the above-mentioned second original file, so that the result of the direct multiplication of the ciphertext is the product between the rows of the second original file after decryption. The needs of simultaneously integrating homomorphic computing and storage proof on elliptic curves are realized.

[0119] In S302, a group element is randomly obtained from the first elliptic curve group.

[0120] In this step, at least one group element is randomly obtained from the first elliptic curve group as the designated generator of the verification tag; for each designated generator, an exponent set containing n+1 exponents is randomly selected for the designated generator, and the designated generator and each exponent in the exponent set are subjected to exponential operation to obtain a target set containing n+1 target group elements corresponding to the designated generator.

[0121] Using the above example, if the integrity verification is based on the SDP assumption, based on the characteristics of the SDP assumption, and based on the first type of bilinear pairing relationship or the second type of bilinear pairing relationship for the subsequent integrity verification process, it is necessary to select two additional specified generators in the first elliptic curve group G1 Then for each specified generator, we select an index set containing n+1 indices, and we have the following two index sets:

[0122]

[0123] Then, perform exponential operations on each index set and calculate There are two target sets. The first target set u={u0,u1,…,u n}; The second target set v = {v0,v,…,v n}.

[0124] It is understandable that the number of designated generators can be specifically set according to the actual application scenario. For example, in some integrity verification scenarios, only one designated generator may be required. For example, in the subsequent integrity verification process, if the verification is based on the third type of bilinear pairing relationship, only one designated generator is required, so that a verification label set is obtained later. Or in some integrity verification scenarios, three or more designated generators may be required, so that three or more verification label sets are obtained in the subsequent processing process. This embodiment does not impose any limitation on this.

[0125] In S303, a signature is performed based on the file size and group elements of the file to be stored to generate a signature tag of the file to be stored, and a verification tag of the file to be stored is generated based on the data units and group elements in the file to be stored.

[0126] Here, the generation process of the signature tag is illustrated as follows: the user terminal can randomly generate a character string within a preset range, and determine the combination result of the file size of the file to be stored (such as the number of rows of the matrix) and the character string as the file identifier of the file to be stored; then, based on the pre-generated signature private key generated above, the combination result of the file identifier of the file to be stored, at least one specified generator and at least one target set is signed to obtain signature data; finally, the combination result of the signature data, the file identifier of the file to be stored, at least one specified generator and at least one target set is determined as the signature tag of the file to be stored.

[0127] Using the above example, the user terminal randomly generates a string Then, a mark for the file length (e.g., the number of rows in the matrix, m) is added to obtain the file identifier name = name0‖m; then the file identifier name, two instruction generators u, v, and two target sets can be combined to obtain the combined result: τ0 = name‖u‖v‖u0‖u1‖…‖u n ‖v0‖v1‖…‖v n Then, the above-mentioned signature private key is used to sign the combined result τ0 to obtain the signature data sig, and finally τ0 and sig are combined to obtain the final signature tag: τ=τ0‖sig.

[0128] Here, the generation process of the verification tag is exemplified: the user terminal can obtain the file identifier of the file to be stored, and the file identifier is the combination result of the file size of the file to be stored and the randomly generated string. Then, for each index set, based on the n numerical values ​​in each row of the file to be stored, the index set and the file identifier, the verification tag of each row in the file to be stored is determined, thereby obtaining a verification tag set containing m verification tags; at least one verification tag set of the file to be stored is determined as the verification tag of the file to be stored. In other words, the number of verification tag sets is equal to the number of index sets, and there is a one-to-one correspondence between the two.

[0129] Here, the process of obtaining a verification tag set corresponding to a certain index set is exemplarily described: for each line in the file to be stored, the user terminal obtains the target combination result between the file identifier, the specified identifier value and the line number of the current line; wherein different index sets correspond to different specified identifier values; a hash operation is performed on the power between the target combination result and the first index in the index set, and then the result of the hash operation is encoded based on the first elliptic curve group to obtain an intermediate value; exemplarily, the process of obtaining the intermediate value based on the target combination result can be performed based on the above-mentioned predefined hash function H (or random oracle). In addition, the user terminal performs an exponential operation on each value of each line in the file to be stored and the exponent in the index set corresponding to the column where the value is located to obtain n powers; wherein the n column values ​​in the file to be stored correspond to the remaining exponents in the index set except the first index; finally, the user terminal determines the product between the intermediate value and the n powers as the verification tag corresponding to the line. After calculating the verification tag corresponding to each line in the file to be stored, a verification tag set containing m verification tags can be obtained.

[0130] Continuing with the above example, there are 2 index sets: Assume that the designated identification value corresponding to the index set α is 0, and the designated identification value corresponding to the index set β is 1. Then each row corresponds to 2 verification labels σ i and π i , 1≤i≤m; calculated by the following method: Among them, name‖0‖i represents the target combination result between the file identifier, the specified identifier value corresponding to the index set α, and the line number of the current line; Represents the power between the target combination result and the first exponent α0 in the exponent set α, To obtain the intermediate value obtained by processing the power using the above random oracle, represents the jth value in the i-th row of the file to be stored and the jth index α in the index set α j The power between represents the continuous multiplication operation of n powers of the ith row of the file to be stored. Finally, the verification tag of the file to be stored includes the following two verification tag sets: σ = (σ1, σ2, ..., σ m ),π=(π1,π2,…,π m ).

[0131] In S304, the file to be stored, the signature tag and the verification tag are stored in the server; wherein the signature tag and the verification tag are applied to the integrity verification process of the file to be stored.

[0132] In this step, the file to be stored, the signature tag and the verification tag are sent to the server for storage in the server, ensuring that the authenticity of the file can be verified by the signature tag after storage, and its integrity can be verified by the verification tag, thereby effectively preventing the file from being tampered with or lost during transmission or storage.

[0133] Exemplarily, in addition to the file to be stored, the signature tag and the verification tag, the file identifier of the file to be stored obtained above can also be sent to the server, and the server stores the file to be stored, the file identifier, the signature tag and the verification tag. The file identifier is used in the index access process of the file to be stored, and any one of the contents of the file to be stored, the signature tag and the verification tag can be accessed through the file identifier.

[0134] The data storage method provided in this embodiment sets the data unit of the file to be stored as an element in the first elliptic curve group, combines the group element randomly obtained from the first elliptic curve group, generates a signature tag according to the file size and the group element, and generates a verification tag based on the data unit and the group element. The combination of the signature tag and the verification tag can not only realize efficient verification of the integrity of the file, but also improve the security and reliability of the data storage process.

[0135] In some embodiments, see Figure 4 and Figure 5 The embodiment of this specification also provides a data verification method for verifying the integrity of a file stored in a server, the file is stored based on the above data storage method; it can be executed by any verification terminal, the method includes:

[0136] In S401, a verification request carrying a file identifier of a file to be verified is sent to a server, so that the server returns a verification response based on the verification request; the verification response includes a signature tag of the file to be verified and verification data, and the verification data is obtained by processing the file to be verified and its verification tag.

[0137] Exemplarily, the verification terminal can construct a verification vector based on the file size of the file to be verified. For example, if the file to be verified includes a matrix of m rows and n columns, the verification terminal can obtain m first verification indices within a preset value range, and form the verification vector with the m first verification indices; the preset value range is determined based on the order of the first elliptic curve group, for example, the minimum value of the preset value range is 0, and the maximum value is the result of the order of the first elliptic curve group minus 1.

[0138] The verification terminal then sends a verification request carrying the file identification and verification vector of the file to be verified to the server, so that the server returns a verification response based on the verification request; the verification response includes the signature tag and verification data of the file to be verified, and the verification data is obtained by the server processing the file to be verified and the verification tag of the file to be verified based on the verification vector.

[0139] Exemplarily, the file to be verified corresponds to at least one verification tag set, and each verification tag set includes m verification tags corresponding one-to-one to m rows; then the verification data calculated by the server includes at least one first verification value and n second verification values; the number of first verification values ​​is equal to the number of verification tag sets, and the two have a one-to-one correspondence. The first verification value is the product of m powers obtained based on the m verification tags in the verification tag set and the m first verification indices, and the m verification tags have a one-to-one correspondence with the m first verification indices. Each second verification value is the product of m powers obtained based on m values ​​of each column of the matrix of the file to be verified and the m first verification indices, and the m values ​​of each column of the matrix of the file to be verified have a one-to-one correspondence with the m first verification indices.

[0140] Using the above example, the verification terminal parses the file identifier name of the file to be verified as (name0,m), extracts the number of lines m from it, and randomly generates Construct verification vector Q = (η1, η2, ..., η m ), and then sends a verification request containing the file identifier name and the verification vector Q to the server.

[0141] The verification tags of the files to be verified stored in the server are two verification tag sets, each of which includes m verification tags corresponding to m rows, σ=(σ1,σ2,…,σ m ),π=(π1,π2,…,π m ). The server can calculate two first verification values ​​(∑, Π) and n second verification values ​​(μ1, μ2, …, μ n ), then:

[0142]

[0143] The final verification response returned by the server is R = (μ1, μ2, …, μ n ,∑,Π,τ), τ is the signature tag of the file to be verified.

[0144] Exemplarily, after receiving the verification response, the verification terminal first performs a signature verification process based on the signature tag of the file to be verified. The verification tag can be divided into a combination result (from the description of the above data storage method, it can be seen that the combination result consists of the file identifier of the file to be verified, at least one specified generator and at least one target set) and the signature data, and then the signature data is decrypted based on the above signature public key. If the decrypted data is consistent with the above combination result, the signature verification is passed, and the following verification process continues; if not, the signature verification fails, and the verification process ends.

[0145] In S402, when the signature tag is verified, a preset bilinear pairing relationship of the first elliptic curve group is obtained, where the bilinear pairing relationship is used to describe elements in the first elliptic curve group and elements in the second elliptic curve group, and is mapped to the third elliptic curve group through a bilinear pairing operation.

[0146] For example, the preset bilinear pairing relationship may be the second type of bilinear pairing e:G1×G2→G obtained in the above initialization process, in which the SDP assumption is considered to be valid. T , the verification terminal can obtain the relevant public parameters pp0 = (e, p, G1, G2, G T ,g1,g2,g T ).

[0147] In S403, a bilinear pairing operation is performed on the verification data according to the bilinear pairing relationship to construct a verification equation.

[0148] Exemplarily, the verification terminal can obtain at least one intermediate set, the intermediate set including m combination results, each combination result is obtained by combining the file identifier of the file to be verified, the designated identifier value and the line number of each line of the file to be verified; the number of intermediate sets is equal to the number of verification label sets corresponding to the files to be verified, different verification label sets correspond to different designated identifier values, and there is a one-to-one correspondence between the two.

[0149] For each intermediate set, the verification terminal obtains m powers based on the m combination results and m first verification exponents in the intermediate set, and there is a one-to-one correspondence between the m combination results and the m first verification exponents. Then, the m powers are hashed respectively, and then the results of the m hash operations are encoded respectively based on the first elliptic curve group to obtain m encoding results; illustratively, the process of obtaining the m encoding results can be performed based on the hash function (or random oracle) determined in the initialization phase. Then, the verification terminal determines the product of the m encoding results as the intermediate verification value; then obtains at least one designated generator and at least one target set from the signature tag; and performs a bilinear pairing operation on at least one first verification value, n second verification values, at least one intermediate verification value, at least one designated generator, and at least one target set according to a bilinear pairing relationship to construct a verification equation.

[0150] Using the above example, if the verification tags of the files to be verified stored on the server are two sets of verification tags, then two intermediate verification values ​​need to be determined. and First intermediate verification value The corresponding specified identification value is 0, and the intermediate set is {name‖0‖1, name‖0‖2, …, name‖0‖m}; the second intermediate verification value The corresponding specified identification value is 1, and the intermediate set is {name‖1‖1, name‖1‖2, …, name‖1‖m}; the two intermediate verification values ​​can be calculated by the following formula and

[0151]

[0152] In a possible implementation, the corresponding number of verification equations can be determined based on the number of verification label sets corresponding to the file to be verified. For example, if there are two verification label sets corresponding to the file to be verified, two verification equations need to be constructed. That is, in the case where the file to be verified corresponds to at least one verification label set, the verification equation includes at least one verification equation; the left side of the verification equation includes: the bilinear pairing operation result between the first verification value and the specified generator; the right side of the verification equation includes the product between the following multiple bilinear pairing operation results: the bilinear pairing operation result between the intermediate verification value and the specified group element in the target set, and the product between the bilinear pairing operation results of n pairs of matching pairs; the n pairs of matching pairs are obtained by one-to-one pairing of n second verification values ​​with n remaining group elements in the target set except the specified group element.

[0153] Using the above example, there are two specified generators u and v, and two target sets u = {u0,u1,…,u n} and v={v0,v1,…,v n}, 2 verification label sets σ=(σ1,σ2,…,σ m ) and π=(π1,π2,…,π m ), there are two verification equations based on the second-class bilinear pairing e, which are:

[0154]

[0155] It can be seen that the left side of the first verification equation is the result of the bilinear pairing operation between one of the first verification values ​​Σ and one of the specified generators u; the right side of the verification equation includes the product of the following multiple bilinear pairing operation results: one of the intermediate verification values The product of the bilinear pairing operation result between the specified group element u0 in one of the target sets and the bilinear pairing operation result of n pairs of matching pairs; the n pairs of matching pairs are composed of n second verification values ​​(μ1, μ2, …, μ n ) and the n remaining group elements (u1,u2,…,u n ) are matched one by one.

[0156] The left side of the second verification equation is the bilinear pairing operation result between another first verification value Π and another specified generator v; the right side of the verification equation includes the product of the following multiple bilinear pairing operation results: another intermediate verification value The product of the bilinear pairing operation result between the specified group element v0 in another target set and the bilinear pairing operation result of n pairs of matching pairs; the n pairs of matching pairs are composed of n second verification values ​​(μ1, μ2, …, μ n ) and the n remaining group elements (v1, v2, …, v n ) are matched one by one.

[0157] In another possible implementation, in order to save computational overhead, when there are two or more verification tag sets corresponding to the file to be verified, the verification processes of the two verification tag sets can be combined into one group, thereby saving computational overhead. Exemplarily, there are two first verification values, intermediate verification values, designated generators, and target sets, and only one verification equation can be constructed for verification.

[0158] The left side of the verification equation includes the product of the result of a bilinear pairing operation between one of the first verification values ​​and one of the specified generators, raised to a power of the result of a bilinear pairing operation between the other first verification value and the other specified generator.

[0159] The right side of the verification equation includes the product of the following multiple items: a bilinear pairing operation result between one of the intermediate verification values ​​and a specified group element in one of the target sets, a bilinear pairing operation result between another power of the first intermediate verification value and a specified group element in another target set, and a bilinear pairing operation result of n pairs of matching pairs; the n pairs of matching pairs are obtained by pairing the n second verification values ​​with the n products one by one, and the n products are the results of correspondingly multiplying the n residual group elements in one of the target sets with the powers of the n residual group elements in another target set one by one;

[0160] In which, all power operations in the verification equation use a second verification exponent, and the second verification exponent is randomly selected from a preset value range, and the preset value range is determined based on the order of the first elliptic curve group; exemplarily, the minimum value of the preset value range is 0, and the maximum value is the result of subtracting 1 from the order of the first elliptic curve group.

[0161] Using the above example, if two specified generators u and v are used in the data storage process, and two target sets u = {u0, u1, ..., u n} and v={v0,v1,…,v n}, 2 verification label sets σ=(σ1,σ2,…,σ m ) and π=(π1,π2,…,π m ), the verification terminal can receive the verification response R = (μ1, μ2, …, μ n ,∑,Π,τ), and then a second verification index can be randomly selected In order to construct the following verification equation:

[0162]

[0163] In S404, if the verification equation holds true, it is determined that the file to be verified is completely stored in the server; otherwise, it is determined that the file to be verified stored in the server is invalid.

[0164] Exemplarily, when at least one verification equation is constructed, it is necessary that all verification equations are satisfied before determining that the file to be verified is completely stored in the server.

[0165] As long as the above SDP assumption is valid in the selected bilinearity, it can be proved that the above constructed verification equation is valid, then the server passes the integrity verification with an overwhelming probability, and the verification terminal can determine that the server stores the complete original file.

[0166] The data verification method provided in this embodiment combines the signature tag of the file to be verified and the verification data, performs a bilinear pairing operation on the verification data through a bilinear pairing relationship, constructs a verification equation and determines whether it holds, thereby efficiently verifying the integrity of the stored file. This method utilizes the characteristics of bilinear pairing to enhance the security and accuracy of the verification process, and can complete the verification operation without obtaining the plain text of the file, reducing the risk of data leakage.

[0167] In the data storage method and data verification method provided in the embodiments of this specification, a storage proof protocol is designed based on the algebraic structure property of elements on elliptic curves, in order to solve the problem of storage proof of such data. In this process, the DLIN assumption on the bilinear pairing group and the SDP assumption implied therein are introduced, making it the basis of the security of the scheme. Based on this new assumption, the embodiments of this specification have a completely new design in the data storage process and the data verification process, including the generation process of the signature tag and the verification tag, and the subsequent verification process for the signature tag and the verification tag.

[0168] The data storage method and data verification method provided in the embodiments of this specification realize the extractability security of the PDP protocol under the SDP assumption and the random oracle model, that is: the collision-resistant hash function H used in the scheme is regarded as a random oracle, if the SDP assumption holds in the selected bilinear pairing, and the digital signature algorithm selected in the protocol satisfies EUF-CMA security, then in a round of proof challenge of this protocol, if the probability that the prover can pass the proof challenge is overwhelming, then there must be a polynomial time extractor that can extract the complete original file from the prover's memory snapshot.

[0169] In layman's terms, this security means that, under the premise that the computationally difficult assumption SDP assumption we chose holds true, as long as the server can pass the verification in a certain round of challenges, then during the process of that round of challenges, the server must have all the information of the document to be proved and can efficiently obtain the complete original file content from it.

[0170] The various technical features in the above embodiments can be combined arbitrarily as long as there is no conflict or contradiction between the combinations of features. However, due to space limitations, they are not described one by one. Therefore, any combination of the various technical features in the above embodiments also falls within the scope of this specification.

[0171] In some embodiments, the embodiments of this specification also provide an electronic device, including: a processor; a memory for storing processor executable instructions; wherein the processor implements any of the above methods by running the executable instructions.

[0172] Figure 6 is a schematic structural diagram of a device provided by an exemplary embodiment. Figure 6 At the hardware level, the device includes a processor 602, an internal bus 604, a network interface 606, a memory 608, and a non-volatile memory 610, and may also include hardware required for other functions. One or more embodiments of this specification may be implemented based on software, such as the processor 602 reading the corresponding computer program from the non-volatile memory 610 into the memory 608 and then running it. Of course, in addition to the software implementation, one or more embodiments of this specification do not exclude other implementations, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0173] In some embodiments, the data storage device may be used in Figure 6 The device shown in the figure is used to implement the technical solution of this specification. The data storage device may include:

[0174] A file acquisition module, used to acquire a file to be stored, wherein the data unit in the file to be stored is an element in the first elliptic curve group;

[0175] A group element acquisition module, used to randomly acquire a group element from the first elliptic curve group;

[0176] a label generation module, configured to generate a signature label of the file to be stored based on the file size of the file to be stored and the group element, and to generate a verification label of the file to be stored based on the data unit in the file to be stored and the group element;

[0177] A storage module is used to store the file to be stored, the signature tag and the verification tag in a server; wherein the signature tag and the verification tag are applied to the integrity verification process of the file to be stored.

[0178] In some embodiments, the data verification device can be applied to Figure 6 The device shown in the figure is used to implement the technical solution of this specification. The data verification device may include:

[0179] A verification request sending module, used to send a verification request carrying a file identifier of a file to be verified to the server, so that the server returns a verification response based on the verification request; the verification response includes a signature tag of the file to be verified and verification data, and the verification data is obtained based on processing the file to be verified and its verification tag;

[0180] A bilinear pairing relationship acquisition module, used to acquire a preset bilinear pairing relationship of the first elliptic curve group when the signature tag is verified, wherein the bilinear pairing relationship is used to describe elements in the first elliptic curve group and elements in the second elliptic curve group, and is mapped to a third elliptic curve group through a bilinear pairing operation;

[0181] A verification equation construction module, used for performing a bilinear pairing operation on the verification data according to the bilinear pairing relationship to construct a verification equation;

[0182] The verification conclusion determination module is used to determine that the file to be verified is completely stored in the server if the verification equation is established; otherwise, determine that the file to be verified is invalid.

[0183] The implementation process of the functions and effects of each module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, which will not be repeated here.

[0184] Based on the same concept as the above method, this specification also provides a computer-readable storage medium on which computer instructions are stored. When the instructions are executed by a processor, the steps of the method described in any of the above embodiments are implemented.

[0185] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. Information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, disk storage, quantum memory, graphene-based storage media or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include temporary computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0186] Based on the same concept as the above method, this specification also provides a computer program product, including a computer program / instruction, which implements the steps of the method described in any of the above embodiments when executed by a processor.

[0187] The above description is merely a preferred embodiment of one or more embodiments of the present specification and is not intended to limit one or more embodiments of the present specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of the present specification shall be included in the scope of protection of one or more embodiments of the present specification.

Claims

1. A data storage method, comprising: Acquire a file to be stored, wherein the data unit in the file to be stored is an element in a first elliptic curve group; randomly obtaining a group element from the first elliptic curve group; Performing a signature based on the file size of the file to be stored and the group element to generate a signature tag of the file to be stored, and generating a verification tag of the file to be stored based on the data unit in the file to be stored and the group element; The file to be stored, the signature tag and the verification tag are stored in a server; wherein the signature tag and the verification tag are applied to the integrity verification process of the file to be stored.

2. According to the method of claim 1, the obtaining of the file to be stored comprises: Acquire a first original file, where the first original file includes a matrix of m rows and n columns, where m and n are both integers greater than 0; The values ​​in the matrix of m rows and n columns are encoded into the first elliptic curve group to obtain the file to be stored.

3. According to the method of claim 1, the obtaining of the file to be stored comprises: Acquire a second original file, where the second original file includes a matrix of m rows and n-1 columns, where m is an integer greater than 0, and n is an integer greater than 1; Encoding the values ​​in the matrix of m rows and n-1 columns into the first elliptic curve group to obtain a file to be encrypted; The file to be encrypted is encrypted based on n-1 pre-generated public keys to obtain the file to be stored; wherein the n-1 public keys are generated based on the order of the first elliptic curve group and the number of columns in the second original file, and the n-1 public keys correspond one-to-one to the n-1 columns in the file to be encrypted.

4. The method according to claim 3, wherein encrypting the file to be encrypted based on the n-1 public keys to obtain the file to be stored comprises: Randomly generate m calculation indexes corresponding to the m lines in the file to be encrypted; Based on the calculation index of each row and the n-1 public keys, encrypt the values ​​in the to-be-encrypted file to obtain an encryption matrix of m rows and n-1 columns; Performing exponential operation based on the generator of the first elliptic curve group and the calculated exponent of each row to obtain a matrix with m rows and 1 column; The encryption matrix of m rows and n-1 columns and the matrix of m rows and 1 column are combined to obtain the file to be stored.

5. According to the method of claim 4, the n-1 public keys are obtained by: Obtain n-1 private key exponents within a preset value range; the preset value range is determined based on the order of the first elliptic curve group; Performing an exponential operation on a generator of the first elliptic curve group and each of the private key exponents to obtain the n-1 public keys; in, The encryption matrix of m rows and n-1 columns can be decrypted based on a private key obtained by combining the n-1 public keys and the n-1 private key exponents.

6. According to the method of claim 4, each value in each row of the encryption matrix is ​​the product of the value to be encrypted at the same position in the file to be encrypted and a specified power, and the specified power is the power between the public key corresponding to the column where the value to be encrypted is located and the calculated exponent of the row.

7. The method according to any one of claims 1 to 6, wherein the file to be stored comprises a matrix of m rows and n columns, and m and n are both integers greater than 0; The randomly obtaining a group element from the first elliptic curve group includes: Randomly obtain at least one group element from the first elliptic curve group as a designated generator of the verification tag; For each of the designated generators, an index set containing n+1 indices is randomly selected for the designated generator, and exponential operations are performed on the designated generator and each of the indices in the index set to obtain a target set containing n+1 target group elements corresponding to the designated generator.

8. The method according to claim 7, wherein generating the signature tag of the file to be stored based on the file size of the file to be stored and the group element comprises: Randomly generate a character string, and determine a combination result of the file size of the file to be stored and the character string as the file identifier of the file to be stored; Using a pre-generated signature private key, signing a combination result of the file identifier of the file to be stored, at least one of the specified generators, and at least one of the target sets to obtain signature data; A combination result of the signature data, the file identifier of the file to be stored, at least one of the specified generators, and at least one of the target sets is determined as a signature tag of the file to be stored.

9. The method according to claim 8, wherein storing the to-be-stored file, the signature tag and the verification tag in a server comprises: The file to be stored, the file identifier, the signature tag and the verification tag are stored in a server; wherein the file identifier is applied to an index access process of the file to be stored.

10. The method according to claim 7, wherein generating a verification tag of the file to be stored based on the data unit in the file to be stored and the group element comprises: Obtaining a file identifier of the file to be stored, where the file identifier is a combination of a file size of the file to be stored and a randomly generated character string; For each of the index sets, based on the n values ​​in each row of the file to be stored, the index set and the file identifier, determine the verification tag of each row of the file to be stored, thereby obtaining a verification tag set including m verification tags; At least one of the verification tag sets of the file to be stored is determined as the verification tag of the file to be stored.

11. The method according to claim 10, wherein for each of the index sets, based on n values ​​in each line of the file to be stored, the index set and the file identifier, determining the verification tag of each line of the file to be stored, thereby obtaining a verification tag set including m verification tags, comprises: For each line of the file to be stored, obtain a target combination result between the file identifier, the specified identifier value and the line number of the current line, perform a hash operation on the power between the target combination result and the first exponent in the exponent set, and then encode the result of the hash operation based on the first elliptic curve group to obtain an intermediate value; Performing exponential operations on each value in each row of the file to be stored and the exponents in the exponent set corresponding to the column where the value is located, to obtain n powers; wherein the n columns of values ​​in the file to be stored correspond one to one with the remaining exponents in the exponent set except the first exponent; The product of the intermediate value and the n powers is determined as the verification label corresponding to the row.

12. A data verification method for verifying the integrity of a file stored in a server, wherein the file is stored based on the data storage method according to any one of claims 1 to 11; the method comprising: Sending a verification request carrying a file identifier of a file to be verified to the server, so that the server returns a verification response based on the verification request; The verification response includes the signature tag of the file to be verified and verification data, wherein the verification data is obtained based on processing the file to be verified and its verification tag; When the signature tag is verified, a preset bilinear pairing relationship of the first elliptic curve group is obtained, where the bilinear pairing relationship is used to describe elements in the first elliptic curve group and elements in the second elliptic curve group, and is mapped to a third elliptic curve group through a bilinear pairing operation; Performing a bilinear pairing operation on the verification data according to the bilinear pairing relationship to construct a verification equation; In the case where the verification equation holds true, determining that the file to be verified is completely stored in the server; Otherwise, it is determined that the file to be verified is invalid.

13. The method according to claim 12, further comprising: Constructing a verification vector based on the file size of the file to be verified; The step of sending the verification request carrying the file identification of the file to be verified to the server includes: A verification request carrying the file identification of the file to be verified and the verification vector is sent to the server; wherein the verification data is obtained by the server processing the file to be verified and the verification tag of the file to be verified based on the verification vector.

14. The method according to claim 13, wherein the file to be verified comprises a matrix of m rows and n columns; the file to be verified corresponds to at least one verification label set, and each of the verification label sets comprises m verification labels corresponding to the m rows one by one; The step of constructing a verification vector based on the file size of the file to be verified includes: Within a preset value range, m first verification exponents are obtained, and the m first verification exponents are combined into the verification vector; the preset value range is determined based on the order of the first elliptic curve group; The verification data includes at least one first verification value and n second verification values; the first verification value is the product of m powers obtained based on m verification tags in the verification tag set and the m first verification indices, and the m verification tags and the m first verification indices have a one-to-one correspondence; Each of the second verification values ​​is a product of m powers obtained by the m numerical values ​​of each column of the matrix and the m first verification indices, and the m numerical values ​​of each column have a one-to-one correspondence with the m first verification indices.

15. The method according to claim 14, wherein the performing a bilinear pairing operation on the verification data according to the bilinear pairing relationship to construct a verification equation comprises: Acquire at least one intermediate set, the intermediate set including m combination results, each of which is obtained by combining the file identifier of the file to be verified, the designated identifier value, and the line number of each line of the file to be verified; For each intermediate set, m powers are obtained based on the m combination results in the intermediate set and the m first verification exponents, hash operations are performed on the m powers respectively, and then the results of the m hash operations are respectively encoded based on the first elliptic curve group to obtain m encoding results, and the product of the m encoding results is determined as an intermediate verification value; wherein there is a one-to-one correspondence between the m combination results and the m first verification exponents; Retrieving at least one designated generator and at least one target set from the signature tag; A bilinear pairing operation is performed on the at least one first verification value, the n second verification values, the at least one intermediate verification value, the at least one designated generator, and the at least one target set according to the bilinear pairing relationship to construct a verification equation.

16. The method of claim 15, wherein the verification equation comprises at least one verification equation; The left side of the verification equation includes: a bilinear pairing operation result between the first verification value and the specified generator; The right side of the verification equation includes the product of the following multiple bilinear pairing operation results: the product of the bilinear pairing operation result between the intermediate verification value and the specified group element in the target set, and the product of the bilinear pairing operation results of n pairs of matching pairs; the n pairs of matching pairs are obtained by pairing the n second verification values ​​with the n remaining group elements in the target set except the specified group element one by one.

17. The method according to claim 15, wherein the number of the first verification value, the intermediate verification value, the designated generator, and the target set is 2; The left side of the verification equation includes the product of the following two items: a power of a bilinear pairing operation result between one of the first verification values ​​and one of the specified generators and a bilinear pairing operation result between another of the first verification values ​​and another of the specified generators; The right side of the verification equation includes the product of the following items: a bilinear pairing operation result between one of the intermediate verification values ​​and a specified group element in one of the target sets, a bilinear pairing operation result between another power of the first intermediate verification value and another specified group element in the target set, and a bilinear pairing operation result of n pairs of matching pairs; the n pairs of matching pairs are obtained by pairing the n second verification values ​​with n products one by one, and the n products are the results of correspondingly multiplying the n remaining group elements in one of the target sets with the powers of n remaining group elements in another of the target sets; in, All exponentiation operations in the verification equation use a second verification exponent, and the second verification exponent is randomly selected from a preset value range, and the preset value range is determined based on the order of the first elliptic curve group.

18. An electronic device, comprising: processor; A memory for storing processor-executable instructions; wherein the processor implements the steps of the method according to any one of claims 1 to 17 by executing the executable instructions.

19. A computer-readable storage medium having computer instructions stored thereon, which, when executed by a processor, implement the steps of the method according to any one of claims 1 to 17.

20. A computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the steps of the method according to any one of claims 1 to 17.