Data incremental backup restoration method and system based on Merkel tree

By using Merkel tree-based incremental backup method and UKey encrypted communication in the data backup and restore process, the problems of insecure data transmission, large resource consumption and incomplete data restoration in the prior art are solved, and efficient and secure data backup and recovery are achieved.

CN120029826AActive Publication Date: 2025-05-23BEIJING SANSEC TECH DEV
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510115024.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-23
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

The existing data backup methods have problems such as lack of encryption protection in data transmission, high resource consumption during backup, and lack of security verification during data restoration, resulting in low data security and efficiency.

Method used

The incremental backup and restore method based on Merkel tree is adopted to encrypt communication through UKey, and encrypted data blocks, key fingerprints and Merkel trees are generated and managed, and the association relationship is established to realize incremental backup and efficient data restoration.

Benefits of technology

It improves the security and efficiency of the data backup and recovery process, ensures the integrity and encryption and decryption consistency of the backup data, and provides more reliable data protection means.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120029826A_ABST
    Figure CN120029826A_ABST
Patent Text Reader

Abstract

The invention discloses a Merkel tree-based data incremental backup and restoration method, which comprises the following steps of: receiving and verifying a backup request or a restoration request, and correspondingly generating a first instruction or a second instruction if the verification is passed; the business system is in encrypted communication with the UKey based on a corresponding instruction; the UKey queries a first Merkel tree to generate first information; the service system determines a related data block based on the first information and generates an encrypted data block, a key fingerprint and a related Merkel tree; the UKey performs corresponding operation based on the encrypted data block and the related Merkel tree, and stores the association relationship between the key fingerprint and the encrypted data block to complete related backup; the service system sends the reduced data ID and the second Merkel tree; the UKey obtains an encryption change data block and second information thereof based on the reduced data ID, the first Merkel tree and the second Merkel tree; and the service system sequentially performs related verification based on the second information, and completes data restoration based on encryption change data block restoration after the verification is passed. And the security and efficiency of the data backup and recovery process are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and more specifically to a method and system for data incremental backup and restoration based on a Merkle tree. Background Art

[0002] With the rapid development of information technology, data security issues in government agencies, the financial industry, the medical industry, and the cloud computing and big data fields have become increasingly prominent. Various industries have put forward higher requirements for data security, integrity, and recoverability. In order to meet these challenges, different technologies and methods have been introduced into information security protection, including the application of UKey encryption devices, hash-based data integrity verification mechanisms (such as Merkle trees), and various file synchronization and data migration technical solutions.

[0003] Existing offline business data synchronization using UKey and methods: This method emphasizes the role of the encryption and decryption module inside UKey, but has limitations in practical applications, such as the lack of encryption protection during the data transmission stage, which increases the risk of interception in the middle; each backup requires re-encryption of all data, which increases time and resource costs; the lack of necessary security verification steps during data restoration makes it impossible to ensure data consistency. Existing cross-cluster data migration method based on disk-rsync: Although this method realizes the automated migration process, its security depends on the key management and network security status under the SSH protocol. If the local device is attacked or the key management is improper, it may lead to serious security vulnerabilities. Existing file synchronization methods, devices, equipment and storage media: This solution mainly relies on the file name and modification timestamp to generate the hash value, ignoring the changes in the file content itself, which is easy to be bypassed. In addition, performing cloud update operations without appropriate security measures will also face the risk of data leakage or tampering. Traditional data backup methods usually rely on full backup, that is, all data is copied again each time the backup is performed. This method not only takes up a lot of storage space, but also takes a long time for the backup operation. In addition, traditional backup methods lack adequate security protection and are vulnerable to the risk of data leakage, tampering or loss. Especially in remote backup or cloud storage environments, the confidentiality and integrity of data are often difficult to be effectively protected.

[0004] Therefore, how to improve the security and efficiency of the data backup and recovery process and ensure the integrity of the backup data and the consistency of encryption and decryption are problems that technical personnel in this field need to solve urgently. Summary of the invention

[0005] In view of this, the present invention provides a method and system for incremental data backup and restoration based on the Merkle tree, which not only improves the security and efficiency of the data backup and recovery process, but also solves the problems of backup data integrity verification and encryption and decryption consistency that have long plagued the industry, providing a more reliable data protection method for various industries.

[0006] In order to achieve the above object, the present invention adopts the following technical solution:

[0007] A data incremental backup and restoration method based on a Merkle tree, comprising:

[0008] Receiving a backup request or a restore request based on the UKey and performing verification, and generating a first instruction or a second instruction accordingly after the verification; the business system performs encrypted communication with the UKey based on the corresponding instruction;

[0009] The UKey queries whether the first Merkle tree exists locally, and generates first information based on the query result;

[0010] The business system determines a relevant data block based on the first information, generates an encrypted data block, a key fingerprint and a relevant Merkle tree based on the relevant data block, and establishes a corresponding association relationship with the encrypted data block based on the key fingerprint;

[0011] The UKey performs corresponding operations based on the encrypted data block and the related Merkle tree, saves the association relationship, and completes the related backup operations;

[0012] The business system sends the restoration data ID and the second Merkle tree to the UKey based on the second instruction and the restoration request;

[0013] The UKey obtains the encrypted changed data block and the second information thereof based on the restored data ID, the first Merkle tree and the second Merkle tree;

[0014] The business system performs restoration verification and integrity verification in sequence based on the second information, and after passing, performs restoration based on the encrypted changed data block to complete the data restoration operation.

[0015] Preferably, the business system performs encrypted communication with the UKey based on corresponding instructions, specifically including:

[0016] The business system generates a public-private key pair based on the first instruction or the second instruction, and sends the public key to the UKey;

[0017] The UKey generates a key and encrypts it based on the public key to obtain an encryption key, and sends the encryption key to the business system;

[0018] The business system decrypts the encryption key based on the private key to obtain the key;

[0019] The business system encrypts the relevant data block based on the key and sends it to the UKey, thereby realizing encrypted communication between the business system and the UKey.

[0020] Preferably, generating the first information based on the query result specifically includes:

[0021] The UKey determines based on the query result that if the first Merkle tree does not exist locally, it is determined to be the first backup operation, and the encryption key is sent to the business system as the first relevant information;

[0022] If the first Merkle tree exists locally, it is determined to be an incremental backup operation, and the encryption key and the first Merkle tree are sent to the business system as second related information;

[0023] The first information includes the first relevant information or the second relevant information.

[0024] Preferably, the business system determines the relevant data block based on the first information, specifically including:

[0025] The business system makes a judgment based on the first information, and if the first relevant information is received, uses the original data block as the first data block;

[0026] If the second relevant information is received, an integrity comparison is performed based on the first Merkle tree and the second Merkle tree maintained by itself to determine whether the comparison results are consistent. If they are consistent, it indicates that the current backup has not changed compared with the previous backup, and the backup is completed and an end notification is sent;

[0027] If they are inconsistent, comparing the nodes of the first Merkle tree and the second Merkle tree from top to bottom, locating the inconsistent leaf nodes, and determining the data blocks that have changed since the last backup as the second data blocks based on the leaf nodes;

[0028] The related data block includes the first data block or the second data block.

[0029] Preferably, generating an encrypted data block, a key fingerprint and a related Merkle tree based on the related data block specifically includes:

[0030] The business system performs a hash calculation based on the key to obtain the corresponding key fingerprint;

[0031] The business system generates a first related Merkle tree or a second related Merkle tree correspondingly based on the first data block or the second data block;

[0032] The relevant Merkle tree includes the first relevant Merkle tree or the second relevant Merkle tree;

[0033] The business system encrypts the first data block or the second data block based on the key to obtain a first encrypted data block or a second encrypted data block accordingly;

[0034] The encrypted data block includes the first encrypted data block or the second encrypted data block.

[0035] Preferably, establishing a corresponding association relationship between the key fingerprint and the encrypted data block specifically includes:

[0036] The business system associates the first encrypted data block or the second encrypted data block based on the key fingerprint to obtain a first association relationship or a second association relationship accordingly;

[0037] The corresponding association relationship includes the first association relationship or the second association relationship;

[0038] The business system performs a hash calculation based on the first data block or the second data block to generate a first hash value or a second hash value accordingly;

[0039] The first hash value or the second hash value is sent to the UKey as a data block hash value.

[0040] Preferably, the UKey performs corresponding operations based on the encrypted data block and the related Merkle tree, specifically including:

[0041] The UKey makes a judgment based on the received encrypted data block;

[0042] If the first encrypted data block is received, the UKey saves the first encrypted data block and the first related Merkle tree, and marks the first related Merkle tree as the first Merkle tree;

[0043] If the second encrypted data block is received, the UKey saves the second encrypted data block and updates the first Merkle tree stored locally based on the second related Merkle tree.

[0044] Preferably, the UKey obtains the encrypted change data block and the second information thereof based on the restored data ID, the first Merkle tree and the second Merkle tree, specifically including:

[0045] The UKey compares the subtrees related to the restored data ID in the first Merkle tree and the second Merkle tree, and determines the changed encrypted data block as the encrypted changed data block based on the comparison result;

[0046] Obtaining an associated key based on the ID of the encrypted change data block and the associated relationship query;

[0047] Encrypting the associated key based on the public key to obtain an encrypted associated key;

[0048] Obtaining a corresponding data block hash value based on the encrypted changed data block;

[0049] The encryption association key and the data block hash value together constitute the second information.

[0050] Preferably, the business system sequentially performs restoration verification and integrity verification based on the second information, specifically including:

[0051] The business system decrypts the encrypted associated key based on the private key, obtains the associated key and performs hash calculation to obtain a first key fingerprint, and compares the second key fingerprint associated with the ID of the encrypted change data block with the first key fingerprint for consistency. If they are consistent, the restoration verification passes; otherwise, the restoration verification fails and the restoration fails;

[0052] After the restoration verification is passed, the business system decrypts the encrypted changed data block based on the associated key to obtain a changed data block, and performs a hash calculation based on the changed data block to obtain a related hash value;

[0053] The business system compares the relevant hash value with the corresponding data block hash value and determines whether the comparison results are consistent. If they are consistent, the integrity verification is passed. Otherwise, the integrity verification fails and the restoration operation is stopped.

[0054] A data incremental backup and restoration system based on Merkle tree, comprising: a connection verification module, a judgment module, a data processing module, a data backup module, a data transmission module, a data acquisition module and a data restoration module;

[0055] The connection verification module is used to receive a backup request or a restore request based on the UKey and perform verification, and the verification generates a first instruction or a second instruction accordingly; the business system performs encrypted communication with the UKey based on the corresponding instruction;

[0056] The first judgment module is used to query whether the first Merkle tree exists locally based on the UKey, and generate first information based on the query result;

[0057] The data processing module is used to determine the relevant data block based on the first information through the business system, generate an encrypted data block, a key fingerprint and a related Merkle tree based on the relevant data block, and establish a corresponding association relationship with the encrypted data block based on the key fingerprint;

[0058] The data backup module is used to perform corresponding operations based on the encrypted data block and the related Merkle tree through the UKey, save the association relationship, and complete the related backup operations;

[0059] The data transmission module is used to send the restored data ID and the second Merkle tree to the UKey through the business system based on the second instruction and the restoration request;

[0060] The data acquisition module is used to obtain the encrypted change data block and its second information based on the restored data ID, the first Merkle tree and the second Merkle tree through the UKey;

[0061] The data restoration module is used to perform restoration verification and integrity verification in sequence based on the second information through the business system, and then restore based on the encrypted changed data block to complete the data restoration operation.

[0062] It can be seen from the above technical solution that, compared with the prior art, the present invention discloses a method and system for data incremental backup and restoration based on a Merkle tree, which has the following beneficial effects:

[0063] 1. Efficient incremental backup mechanism: The present invention can back up only the changed data by constructing a Merkle tree of data blocks, thereby realizing incremental backup and significantly improving the efficiency of backup.

[0064] 2. Efficient data selection and restoration mechanism: The present invention provides a flexible and efficient data restoration solution. It supports data selection and restoration, allowing users to freely select the target data area to restore part of the data according to actual needs, avoiding unnecessary full data restoration; using the concept of differential restoration, the system only restores data blocks that are inconsistent with the backup file content, thereby significantly reducing the time and resource consumption required for restoration, and greatly improving restoration efficiency; users can perform data restoration more accurately and efficiently, meeting data recovery needs in various complex scenarios.

[0065] 3. Data encryption transmission and storage: The present invention adopts SM2 asymmetric encryption technology to achieve high confidentiality in the data transmission process, ensuring that only the authorized recipient can decrypt and read the data, effectively preventing the data from being stolen or tampered with during the transmission process. In addition, the present invention also combines the UKey hardware device to encrypt and store the data. Even if the attacker obtains the UKey, he cannot directly access or crack the stored sensitive data.

[0066] 4. Data anti-tampering security mechanism: The present invention uses the characteristics of the Merkle tree to ensure data security during the backup and restoration process; any modification of a data block will cause its corresponding hash value to change, thereby changing the tree root hash value; the integrity of the data can be detected during restoration, providing an efficient and reliable integrity check mechanism to ensure that the data has not been tampered with.

[0067] 5. Data encryption and decryption consistency: In the encryption and decryption operation, improper key management may lead to inconsistency between encryption and decryption, thus affecting the correct recovery of data. To ensure the consistency of the encryption and decryption process, the present invention generates a key fingerprint and verifies it during restoration, thereby effectively avoiding potential risks in key management and ensuring that data can be accurately restored. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0069] Figure 1 A flow chart of a method for incremental data backup and restoration based on a Merkle tree provided by the present invention.

[0070] Figure 2 A flow chart of a method for the business system provided by the present invention to determine relevant data blocks based on first information.

[0071] Figure 3 A schematic diagram of a simple Merkle tree structure provided by the present invention.

[0072] Figure 4 A flow chart of a method in which the business system provided by the present invention sequentially performs restoration verification and integrity verification based on second information.

[0073] Figure 5 This is a schematic diagram of the data restoration selection area provided by the present invention.

[0074] Figure 6 A schematic diagram of a Merkle tree constructed for the file system provided by the present invention.

[0075] Figure 7 A schematic diagram of the structure of a data incremental backup and restoration system based on a Merkle tree provided by the present invention. DETAILED DESCRIPTION

[0076] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0077] Example 1

[0078] like Figure 1 As shown, an embodiment of the present invention discloses a method for incremental data backup and restoration based on a Merkle tree, comprising:

[0079] The backup request or restore request is received based on the UKey and verified, and the first instruction or the second instruction is generated accordingly after the verification; the business system performs encrypted communication with the UKey based on the corresponding instruction;

[0080] UKey queries whether the first Merkle tree exists locally, and generates first information based on the query result;

[0081] The business system determines the relevant data block based on the first information, generates an encrypted data block, a key fingerprint and a relevant Merkle tree based on the relevant data block, and establishes a corresponding association relationship between the key fingerprint and the encrypted data block;

[0082] UKey performs corresponding operations based on the encrypted data blocks and related Merkle trees, saves the associations, and completes related backup operations;

[0083] The business system sends the restored data ID and the second Merkle tree to UKey based on the second instruction and the restore request;

[0084] UKey obtains the encrypted changed data block and its second information based on the restored data ID, the first Merkle tree and the second Merkle tree;

[0085] The business system performs restoration verification and integrity verification in sequence based on the second information, and after passing, restores based on the encrypted changed data block to complete the data restoration operation.

[0086] Example 2

[0087] The embodiment of the present invention discloses a method for incremental data backup and restoration based on a Merkle tree, comprising:

[0088] A backup request or a restore request is received based on UKey and verified, and a first instruction or a second instruction is generated accordingly if the verification passes.

[0089] Preferably, a UKey (USB KEY) is a small hardware device that is usually inserted into the USB interface of a computer and is used to enhance the security of a computer system or application. It is a hardware device with encryption functions and can be used for functions such as authentication, data encryption, and digital signatures.

[0090] Preferably, based on the insertion of the UKey into a relevant device, the business system in the relevant device detects the insertion of the UKey and prompts for the input of a PIN code for verification. The UKey verifies the input PIN code. After successful verification, the UKey generates a corresponding first instruction or second instruction based on a backup request or a restoration request; if the verification fails, a backup failure prompt is sent to terminate subsequent operations.

[0091] Preferably, the interaction operations between the business system and the UKey follow the "GMT 0016-2012 Specification for the Application Interface of Smart Cryptographic Keys".

[0092] The business system conducts encrypted communication with the UKey based on the corresponding instruction.

[0093] Preferably, the business system conducts encrypted communication with the UKey based on the corresponding instruction, specifically including:

[0094] The business system generates a public-private key pair based on the first instruction or the second instruction and sends the public key to the UKey;

[0095] The UKey generates a key and encrypts it based on the public key to obtain an encrypted key, and then sends the encrypted key to the business system;

[0096] The business system decrypts the encrypted key based on the private key to obtain the key;

[0097] The business system encrypts the relevant data block based on the key and then sends it to the UKey, thus realizing the encrypted communication between the business system and the UKey.

[0098] Preferably, in this embodiment, the public-private key pair generated by the business system is an SM2 asymmetric key pair, including an SM2 public key and an SM2 private key; the key generated by the UKey is an SM4 symmetric key.

[0099] Preferably, the SM2 algorithm is one of the national cryptographic algorithm standards in China and is mainly used for public key encryption and digital signatures. It is a standard based on the elliptic curve encryption algorithm (ECC) and has high security and low computational complexity; the SM4 algorithm is a symmetric encryption algorithm in the national commercial cryptographic algorithms in China, which uses a 128-bit key and a 128-bit data block and has high encryption efficiency and security.

[0100] The UKey queries whether a first Merkle tree exists locally and generates a first piece of information based on the query result.

[0101] Preferably, generating the first information based on the query result specifically includes:

[0102] Based on the query result, UKey determines that if the first Merkle tree does not exist locally, it is determined to be the first backup operation and the encryption key is sent to the business system as the first relevant information;

[0103] If the first Merkle tree exists locally, it is determined to be an incremental backup operation, and the encryption key and the first Merkle tree are sent to the business system as the second related information;

[0104] The first information includes first related information or second related information.

[0105] The business system determines the relevant data block based on the first information, generates an encrypted data block, a key fingerprint and a related Merkle tree based on the relevant data block, and establishes a corresponding association relationship between the key fingerprint and the encrypted data block.

[0106] Preferably, Figure 2 As shown, the business system determines the relevant data blocks based on the first information, specifically including:

[0107] The business system makes a judgment based on the first information, and if the first relevant information is received, uses the original data block as the first data block;

[0108] If the second relevant information is received, an integrity comparison is performed based on the first Merkle tree and the second Merkle tree maintained by itself to determine whether the comparison results are consistent. If they are consistent, it indicates that the current backup has not changed compared with the previous backup, and the backup is completed and an end notification is sent;

[0109] If they are inconsistent, compare the nodes of the first Merkle tree and the second Merkle tree from top to bottom, locate the inconsistent leaf nodes, and determine the data blocks that have changed since the last backup as the second data blocks based on the leaf nodes;

[0110] The related data block includes the first data block or the second data block.

[0111] Preferably, a Merkle Tree, also known as a hash tree, is a tree structure in which the label of each leaf node is the hash value of the data block, and the label of a non-leaf node is the encrypted hash value of the label of its child node. The Merkle Tree is an efficient and secure way to verify the content of large-scale data structures, which can be seen as an extended form of a hash chain.

[0112] Preferably, Figure 3As shown in the figure, it is a schematic diagram of the simplest version of the Merkle tree structure. Its leaf nodes are the hash values of a file or data blocks in a group of files. The nodes higher up in the tree are the hash values of their respective child nodes. When constructing the Merkle tree, the number of forks of the Merkle tree is determined according to the requirements of specific applications. In most scenarios, a binary tree structure is used. First, the SHA-256 cryptographic hash algorithm is used to calculate the hash values of all data blocks, and these hash values serve as the leaf nodes of the Merkle tree. Next, the hash values of each pair of adjacent leaf nodes are combined and hashed to generate the hash value of the parent node. For the parent nodes of each layer, they are continuously combined in pairs and hashed until only one node remains, which is the root node of the Merkle tree. If the number of leaf nodes is not a power of 2, it may be necessary to fill in virtual leaf nodes in the last layer to ensure the balance of the tree. Suppose the content of a certain data block has changed, the hash value of this leaf node needs to be updated, and it is updated layer by layer through the parent nodes until the root node.

[0113] Preferably, when the business system compares the two Merkle trees maintained by itself and sent by the UKey, it first compares the root hashes of the two trees. If the root hashes are different, it recursively compares the hash values of the left and right subtrees until it compares to the leaf nodes. If it is found during the comparison process that the hash values of a certain pair of subtrees are the same, the subsequent comparison process is terminated to avoid invalid comparisons. Finally, the leaf node with the changed hash value is located, indicating that the data block represented by this leaf node has changed since the last backup, thereby achieving incremental backup.

[0114] Preferably, generating encrypted data blocks, key fingerprints, and related Merkle trees based on relevant data blocks specifically includes:

[0115] The business system performs a hash calculation based on the key to obtain the corresponding key fingerprint;

[0116] The business system generates a first related Merkle tree or a second related Merkle tree based on the first data block or the second data block;

[0117] The related Merkle tree includes a first related Merkle tree or a second related Merkle tree;

[0118] The business system encrypts the first data block or the second data block based on the key to obtain a first encrypted data block or a second encrypted data block correspondingly;

[0119] The encrypted data block includes a first encrypted data block or a second encrypted data block.

[0120] Preferably, in this embodiment, the SHA-256 cryptographic hash function is used to perform a hash calculation on the key, and a 64-bit hexadecimal number is calculated, which is the key fingerprint of the key.

[0121] Preferably, establishing a corresponding association relationship based on the key fingerprint and the encrypted data block specifically includes:

[0122] The business system associates the first encrypted data block or the second encrypted data block based on the key fingerprint, and obtains a first association relationship or a second association relationship accordingly;

[0123] The corresponding association relationship includes a first association relationship or a second association relationship;

[0124] The business system performs a hash calculation based on the first data block or the second data block, and generates a first hash value or a second hash value accordingly;

[0125] The first hash value or the second hash value is sent to UKey as a data block hash value.

[0126] UKey performs corresponding operations based on encrypted data blocks and related Merkle trees, saves the associated relationships, and completes related backup operations.

[0127] Preferably, UKey performs corresponding operations based on the encrypted data block and the related Merkle tree, specifically including:

[0128] UKey makes a judgment based on the encrypted data block received;

[0129] If the first encrypted data block is received, UKey saves the first encrypted data block and the first related Merkle tree, marks the first related Merkle tree as the first Merkle tree, and saves the first association relationship, completing the first backup operation;

[0130] If the second encrypted data block is received, UKey saves the second encrypted data block, updates the locally stored first Merkle tree based on the second related Merkle tree, and saves the second association relationship to complete the incremental backup operation.

[0131] Preferably, the backup method of the present invention is divided into two backup modes: initial backup and incremental backup. The initial backup is a full backup, which requires all data blocks to be protected to be encrypted and transmitted. Each subsequent backup is an incremental backup, which only requires the transmission of data blocks that have changed since the last backup. In addition, if you want to change the business system that UKey is connected to, you can reset UKey and then perform the initial (full) backup again.

[0132] The business system sends the restored data ID and the second Merkle tree to UKey based on the second instruction and the restore request.

[0133] Preferably, the business system obtains the restored data to be restored based on the restore request, and obtains the restored data ID based on the restored data; the second Merkle tree is a Merkle tree stored and maintained by the business system.

[0134] Preferably, the restored data may include multiple groups of data blocks or data areas.

[0135] UKey obtains the encrypted changed data block and its second information based on the restored data ID, the first Merkle tree and the second Merkle tree.

[0136] Preferably, UKey obtains the encrypted change data block and its second information based on the restored data ID, the first Merkle tree and the second Merkle tree, specifically including:

[0137] UKey compares the subtrees related to the restored data ID in the first Merkle tree and the second Merkle tree, and determines the changed encrypted data block as the encrypted change data block based on the comparison result;

[0138] Obtain the associated key based on the ID and associated relationship query of the encrypted changed data block;

[0139] Encrypting the associated key based on the public key to obtain an encrypted associated key;

[0140] Obtaining a corresponding data block hash value based on the encrypted changed data block;

[0141] The encryption association key and the data block hash value together constitute the second information.

[0142] The business system performs restoration verification and integrity verification in sequence based on the second information, and after passing, restores based on the encrypted changed data block to complete the data restoration operation.

[0143] Preferably, Figure 4 As shown, the business system performs restoration verification and integrity verification in sequence based on the second information, specifically including:

[0144] The business system decrypts the encrypted associated key based on the private key, obtains the associated key and performs hash calculation to obtain the first key fingerprint, and determines whether the second key fingerprint associated with the ID of the encrypted change data block is consistent with the first key fingerprint. If they are consistent, the restoration verification passes, otherwise, the restoration verification fails and the restoration fails;

[0145] After the restoration verification is passed, the business system decrypts the encrypted changed data block based on the associated key to obtain the changed data block, and performs hash calculation based on the changed data block to obtain the relevant hash value;

[0146] The business system compares the relevant hash value with the corresponding data block hash value and determines whether the comparison results are consistent. If they are consistent, the integrity verification passes. Otherwise, the integrity verification fails and the restore operation is stopped.

[0147] Preferably, when performing a data restoration operation, the restoration content can be flexibly selected, and no matter how the restoration content is selected, the data restoration can be completed with the minimum transmission cost. Figure 5As shown, the administrator selects two data areas, N3 and N4, for restoration. The business system only needs to focus on the two subtrees, N3 and N4, in the Merkle tree. The business system sends the two subtrees, N3 and N4, to the UKey. The UKey only needs to compare the two subtrees to determine which data blocks need to be transmitted. When making the comparison, if the hash values of a certain non-leaf node in the two trees are the same, the comparison of its left and right child nodes is terminated in advance. In the case of a large amount of data, using this method can further reduce the resource consumption and time for locating the data blocks where the data has changed.

[0148] Embodiment 3

[0149] The first backup method process of the present invention is as follows:

[0150] Based on the connection between the UKey and the business system.

[0151] The PIN code is input through the business system and sent to the UKey. The UKey verifies the input PIN code. After the verification passes, the UKey generates the first instruction based on the backup request.

[0152] If the verification fails, a backup failure prompt is sent to terminate the subsequent operations.

[0153] The business system generates an SM2 key pair based on the first instruction and sends the SM2 public key to the UKey.

[0154] The UKey generates an SM4 key and encrypts it based on the SM2 public key to obtain the encrypted SM4 key, and sends the encrypted SM4 key to the business system.

[0155] The business system generates the first relevant Merkle tree based on the original data blocks.

[0156] The business system performs hash calculation based on the original data blocks to generate the first hash value.

[0157] The business system decrypts the encrypted SM4 key based on the SM2 private key to obtain the SM4 key.

[0158] The business system encrypts the original data blocks based on the SM4 key to obtain the first encrypted data blocks.

[0159] The business system performs hash calculation based on the SM4 key to obtain the corresponding key fingerprint.

[0160] The business system associates based on the key fingerprint and the first encrypted data blocks to obtain the first association relationship, that is, marks the SM4 key fingerprint used for the first encrypted data blocks.

[0161] The business system sends the first relevant Merkle tree, the first hash value, the first encrypted data blocks, and the first association relationship to the UKey.

[0162] UKey stores the first encrypted data block and records the first relevant Merkle tree, the first hash value and the first association relationship, marking that the first encrypted data block received this time is encrypted using the SM4 key, completing the first backup and sending a backup completion prompt to the business system.

[0163] After receiving the backup completion notification, the business system will be prompted to disconnect from UKey, thus completing the first backup.

[0164] The incremental backup method of the present invention has the following process:

[0165] After the first backup of the present invention, each subsequent backup only needs to be an incremental backup, and only the data blocks that have changed since the last backup need to be transmitted, which greatly improves the backup efficiency. The specific steps are as follows:

[0166] Connect with business system based on UKey.

[0167] The PIN code is entered through the business system and sent to UKey. UKey verifies the entered PIN code. After verification, UKey generates the first instruction based on the backup request.

[0168] If the verification fails, a backup failure prompt will be sent and subsequent operations will be terminated.

[0169] The business system generates an SM2 key pair based on the first instruction and sends the SM2 public key to UKey.

[0170] UKey generates an SM4 key and encrypts it based on the SM2 public key to obtain an encrypted SM4 key.

[0171] UKey is sent to the business system based on the locally stored first Merkle tree and the encrypted SM4 key.

[0172] The business system decrypts the encrypted SM4 key based on the SM2 private key to obtain the SM4 key.

[0173] The business system performs an integrity comparison based on the root hash of the first Merkle tree and the root hash of the second Merkle tree it maintains to determine whether the comparison results are consistent. If they are consistent, it means that this backup has not changed compared with the last backup, and the backup ends and sends an end notification; if they are inconsistent, the nodes of the first Merkle tree and the second Merkle tree are compared from top to bottom to locate the inconsistent leaf nodes, and based on the leaf nodes, the data blocks that have changed since the last backup are determined as the second data blocks.

[0174] The business system generates a second related Merkle tree corresponding to the second data block.

[0175] The business system performs a hash calculation based on the second data block to generate a second hash value.

[0176] The business system encrypts the second data block based on the SM4 key, and obtains a corresponding second encrypted data block.

[0177] The business system performs hash calculation based on the SM4 key to obtain the corresponding key fingerprint.

[0178] The business system associates the second encrypted data block based on the key fingerprint to obtain a second association relationship, that is, marking the second encrypted data block with the SM4 key fingerprint used.

[0179] The business system sends the second relevant Merkle tree, the second hash value, the second encrypted data block and the second association relationship to UKey.

[0180] UKey saves the second encrypted data block, updates the first Merkle tree stored locally based on the second related Merkle tree, saves the second association relationship and the second hash value, completes the incremental backup operation and sends a backup completion prompt to the business system.

[0181] The data restoration method of the present invention has the following process:

[0182] The present invention can provide efficient integrity verification, data consistency check and rapid recovery when performing data restoration operations, and improve restoration efficiency while protecting data from tampering. The specific steps are as follows:

[0183] Connect with business system based on UKey.

[0184] The PIN code is entered through the business system and sent to UKey. UKey verifies the entered PIN code. After verification, UKey generates a second instruction based on the restoration request.

[0185] If the verification fails, a restore failure prompt will be sent and subsequent operations will be terminated.

[0186] The business system obtains the restored data to be restored based on the restore request, can select multiple groups of data blocks or data areas for restoration, and obtains the restored data ID based on the restored data.

[0187] The business system generates an SM2 key pair based on the second instruction and sends the SM2 public key to UKey.

[0188] The business system sends the second Merkle tree and restored data ID stored and maintained by itself to UKey.

[0189] UKey compares the subtrees related to the restored data ID in the first Merkle tree and the second Merkle tree, and determines the changed encrypted data block as the encrypted change data block based on the comparison result.

[0190] UKey obtains the associated SM4 key based on the ID and association relationship of the encrypted change data block.

[0191] UKey encrypts the associated SM4 key based on the SM2 public key to obtain the encrypted associated SM4 key.

[0192] UKey obtains the corresponding data block hash value based on the encrypted changed data block.

[0193] UKey sends the encrypted change data block, the encrypted associated SM4 key, and the corresponding data block hash value to the business system.

[0194] The business system decrypts the encrypted associated SM4 key based on the SM2 private key, obtains the associated SM4 key and performs hash calculation to obtain the first key fingerprint. The second key fingerprint associated with the ID of the encrypted change data block is compared with the first key fingerprint for consistency. If they are consistent, the restoration verification passes. Otherwise, the restoration verification fails, a key fingerprint mismatch prompt is generated, and the restoration fails.

[0195] After the restoration verification is passed, the business system decrypts the encrypted change data block based on the associated SM4 key to obtain the change data block, performs hash calculation based on the change data block, and obtains the relevant hash value.

[0196] The business system compares the relevant hash value with the corresponding data block hash value and determines whether the comparison results are consistent. If they are consistent, the integrity verification passes. Otherwise, the integrity verification fails, a data tampering prompt is generated, and the restore operation is stopped.

[0197] After the above verifications are passed, the business system restores based on the changed data blocks to complete the data restoration operation.

[0198] Example 4

[0199] In a large file system, backing up and restoring critical data is not only the basis of data protection, but also an important guarantee for system stability and security.

[0200] For this type of system, the Merkle tree can be constructed using the tree structure of the file system itself. Figure 6 As shown in the figure, each file is regarded as a data block, and the hash value of each file represents the leaf node of the Merkle tree. Each directory is regarded as a data area, and the hash values ​​of its child nodes are concatenated and the hash value of the directory is calculated to represent the non-leaf node of the Merkle tree. Similarly, the hash value of the root directory of the file system represents the hash value of the entire Merkle tree, that is, the root hash.

[0201] When the file system is backed up for the first time, a Merkle tree is constructed, all files are encrypted using the SM4 key sent by UKey, and the encrypted files and Merkle tree are sent to UKey. The file system maintains the Merkle tree and updates it when files are changed or added or deleted.

[0202] In each subsequent backup, the file system is compared with the root hash of the Merkle tree inside UKey to determine whether the file system has changed since the last backup. If it has changed, the child node hash values ​​are recursively compared to locate the changed files. Finally, the Merkle tree of the file system and the changed files are encrypted and passed to UKey, achieving fast incremental backup.

[0203] When a file or directory in the file system is damaged or encounters other abnormal situations, insert UKey to restore the data. For example, if the / opt directory is damaged, specify to restore the / opt data area. The file system sends the subtree with the hash ( / opt) node as the root node in the Merkle tree to UKey. UKey compares the received subtree with the tree stored in itself and locates the data blocks with inconsistent hash values, which means which files in the / opt directory are inconsistent with the UKey backup file. UKey only needs to transfer the ciphertext of these files to the file system for restoration, which greatly improves the restoration efficiency and enables the system to quickly return to normal working state after a disaster, ensuring that key data in the file system will not be lost and business operations can be restored as soon as possible.

[0204] Example 5

[0205] like Figure 7 As shown, a data incremental backup and restoration system based on Merkle tree includes: a connection verification module, a judgment module, a data processing module, a data backup module, a data transmission module, a data acquisition module and a data restoration module;

[0206] A connection verification module is used to receive a backup request or a restore request based on UKey and perform verification, and if the verification is successful, a first instruction or a second instruction is generated accordingly; the business system performs encrypted communication with UKey based on the corresponding instruction;

[0207] A first judgment module is used to query whether the first Merkle tree exists locally based on the UKey, and generate first information based on the query result;

[0208] A data processing module, configured to determine the relevant data block based on the first information through the business system, generate an encrypted data block, a key fingerprint and a relevant Merkle tree based on the relevant data block, and establish a corresponding association relationship with the encrypted data block based on the key fingerprint;

[0209] The data backup module is used to perform corresponding operations based on the encrypted data blocks and related Merkle trees through UKey, save the association relationship, and complete the relevant backup operations;

[0210] A data transmission module, used for sending the restored data ID and the second Merkle tree to UKey through the business system based on the second instruction and the restoration request;

[0211] A data acquisition module, used to obtain the encrypted change data block and its second information based on the restored data ID, the first Merkle tree and the second Merkle tree through UKey;

[0212] The data restoration module is used to perform restoration verification and integrity verification in sequence based on the second information through the business system, and after passing, restore based on the encrypted changed data block to complete the data restoration operation.

[0213] Preferably, the functions implemented by each module in this implementation correspond one-to-one to the above method, and will not be described one by one here.

[0214] Example 6

[0215] Based on the same inventive concept, the present invention also provides a computer device, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus;

[0216] Memory, used to store computer programs;

[0217] The processor, when used to execute a program stored in the memory, can implement a data incremental backup and restoration method based on a Merkle tree as in Embodiment 1, 2 or 3.

[0218] The electronic device may include: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus. The processor may call the logic instructions in the memory to execute a data incremental backup and restore method based on a Merkle tree in Embodiment 1, 2, or 3.

[0219] In addition, the logic instructions in the above-mentioned memory can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.

[0220] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0221] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for incremental data backup and restoration based on a Merkle tree, characterized in that: include: Receiving a backup request or a restore request based on the UKey and performing verification, and generating a first instruction or a second instruction accordingly if the verification passes; The business system performs encrypted communication with the UKey based on the corresponding instructions; The UKey queries whether the first Merkle tree exists locally, and generates first information based on the query result; The business system determines a relevant data block based on the first information, generates an encrypted data block, a key fingerprint and a relevant Merkle tree based on the relevant data block, and establishes a corresponding association relationship with the encrypted data block based on the key fingerprint; The UKey performs corresponding operations based on the encrypted data block and the related Merkle tree, saves the association relationship, and completes the related backup operations; The business system sends the restoration data ID and the second Merkle tree to the UKey based on the second instruction and the restoration request; The UKey obtains the encrypted changed data block and the second information thereof based on the restored data ID, the first Merkle tree and the second Merkle tree; The business system performs restoration verification and integrity verification in sequence based on the second information, and after passing, performs restoration based on the encrypted changed data block to complete the data restoration operation.

2. According to the method of claim 1, the data incremental backup and restoration method based on Merkle tree is characterized in that: The business system performs encrypted communication with the UKey based on the corresponding instructions, specifically including: The business system generates a public-private key pair based on the first instruction or the second instruction, and sends the public key to the UKey; The UKey generates a key and encrypts it based on the public key to obtain an encryption key, and sends the encryption key to the business system; The business system decrypts the encryption key based on the private key to obtain the key; The business system encrypts the relevant data block based on the key and sends it to the UKey, thereby realizing encrypted communication between the business system and the UKey.

3. The method for incremental data backup and restoration based on Merkle tree according to claim 2, characterized in that: Generating first information based on the query result specifically includes: The UKey determines based on the query result that if the first Merkle tree does not exist locally, it is determined to be the first backup operation, and the encryption key is sent to the business system as the first relevant information; If the first Merkle tree exists locally, it is determined to be an incremental backup operation, and the encryption key and the first Merkle tree are sent to the business system as second related information; The first information includes the first relevant information or the second relevant information.

4. The method for incremental data backup and restoration based on Merkle tree according to claim 3 is characterized in that: The business system determines the relevant data block based on the first information, specifically including: The business system makes a judgment based on the first information, and if the first relevant information is received, uses the original data block as the first data block; If the second relevant information is received, an integrity comparison is performed based on the first Merkle tree and the second Merkle tree maintained by itself to determine whether the comparison results are consistent. If they are consistent, it indicates that the current backup has not changed compared with the previous backup, and the backup is completed and an end notification is sent; If they are inconsistent, comparing the nodes of the first Merkle tree and the second Merkle tree from top to bottom, locating the inconsistent leaf nodes, and determining the data blocks that have changed since the last backup as the second data blocks based on the leaf nodes; The related data block includes the first data block or the second data block.

5. The method for incremental data backup and restoration based on Merkle tree according to claim 4, characterized in that: Generating an encrypted data block, a key fingerprint and a related Merkle tree based on the related data block specifically includes: The business system performs a hash calculation based on the key to obtain the corresponding key fingerprint; The business system generates a first related Merkle tree or a second related Merkle tree correspondingly based on the first data block or the second data block; The relevant Merkle tree includes the first relevant Merkle tree or the second relevant Merkle tree; The business system encrypts the first data block or the second data block based on the key to obtain a first encrypted data block or a second encrypted data block accordingly; The encrypted data block includes the first encrypted data block or the second encrypted data block.

6. The method for incremental data backup and restoration based on Merkle tree according to claim 5, characterized in that: Establishing a corresponding association relationship between the key fingerprint and the encrypted data block specifically includes: The business system associates the first encrypted data block or the second encrypted data block based on the key fingerprint to obtain a first association relationship or a second association relationship accordingly; The corresponding association relationship includes the first association relationship or the second association relationship; The business system performs a hash calculation based on the first data block or the second data block to generate a first hash value or a second hash value accordingly; The first hash value or the second hash value is sent to the UKey as a data block hash value.

7. The method for incremental data backup and restoration based on Merkle tree according to claim 6, characterized in that: The UKey performs corresponding operations based on the encrypted data block and the relevant Merkle tree, specifically including: The UKey makes a judgment based on the received encrypted data block; If the first encrypted data block is received, the UKey saves the first encrypted data block and the first related Merkle tree, and marks the first related Merkle tree as the first Merkle tree; If the second encrypted data block is received, the UKey saves the second encrypted data block and updates the first Merkle tree stored locally based on the second related Merkle tree.

8. The method for incremental data backup and restoration based on Merkle tree according to claim 7, characterized in that: The UKey obtains the encrypted change data block and the second information thereof based on the restored data ID, the first Merkle tree and the second Merkle tree, specifically including: The UKey compares the subtrees related to the restored data ID in the first Merkle tree and the second Merkle tree, and determines the changed encrypted data block as the encrypted changed data block based on the comparison result; Obtaining an associated key based on the ID of the encrypted change data block and the associated relationship query; Encrypting the associated key based on the public key to obtain an encrypted associated key; Obtaining a corresponding data block hash value based on the encrypted changed data block; The encryption association key and the data block hash value together constitute the second information.

9. The method for incremental data backup and restoration based on Merkle tree according to claim 8, characterized in that: The business system sequentially performs restoration verification and integrity verification based on the second information, specifically including: The business system decrypts the encrypted associated key based on the private key, obtains the associated key and performs hash calculation to obtain a first key fingerprint, and compares the second key fingerprint associated with the ID of the encrypted change data block with the first key fingerprint for consistency. If they are consistent, the restoration verification passes; otherwise, the restoration verification fails and the restoration fails; After the restoration verification is passed, the business system decrypts the encrypted changed data block based on the associated key to obtain a changed data block, and performs a hash calculation based on the changed data block to obtain a related hash value; The business system compares the relevant hash value with the corresponding data block hash value and determines whether the comparison results are consistent. If they are consistent, the integrity verification is passed. Otherwise, the integrity verification fails and the restoration operation is stopped.

10. A data incremental backup and restoration system based on a Merkle tree, applied to a data incremental backup and restoration method based on a Merkle tree as claimed in any one of claims 1 to 9, characterized in that: include: Connection verification module, judgment module, data processing module, data backup module, data transmission module, data acquisition module and data restoration module; The connection verification module is used to receive a backup request or a restore request based on the UKey and perform verification, and generate a first instruction or a second instruction accordingly if the verification is successful; The business system performs encrypted communication with the UKey based on the corresponding instructions; The first judgment module is used to query whether the first Merkle tree exists locally based on the UKey, and generate first information based on the query result; The data processing module is used to determine the relevant data block based on the first information through the business system, generate an encrypted data block, a key fingerprint and a related Merkle tree based on the relevant data block, and establish a corresponding association relationship with the encrypted data block based on the key fingerprint; The data backup module is used to perform corresponding operations based on the encrypted data block and the related Merkle tree through the UKey, save the association relationship, and complete the related backup operations; The data transmission module is used to send the restored data ID and the second Merkle tree to the UKey through the business system based on the second instruction and the restoration request; The data acquisition module is used to obtain the encrypted change data block and its second information based on the restored data ID, the first Merkle tree and the second Merkle tree through the UKey; The data restoration module is used to perform restoration verification and integrity verification in sequence based on the second information through the business system, and then restore based on the encrypted changed data block to complete the data restoration operation.

Citation Information

Patent Citations

  • Method, device and system for realizing multi-backup-data dynamic updating

    CN104978239A

  • Cross-cluster data migration method based on disk-rsync

    CN117453653A

  • Integrity verification method and system for persistent memory

    CN119323061A

  • Induction heating device having improved user experience and user interface

    KR102734353B1

  • Blockchain-based data processing method, and device

    WO2023115873A1