Cloud storage data integrity verification method and system

By building a private audit model based on user and user file audit in a cloud storage system, combining multiple technical means such as file upload, integrity detection and algorithm verification, the problem that the existing technology cannot effectively verify data integrity and prevent illegal access is solved, and efficient data protection and optimized user experience is achieved.

CN120034378AInactive Publication Date: 2025-05-23NANTONG CHONGHAO INTERNET TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510176297.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-23
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art cannot verify data integrity through detailed and complete multiple technical means with high readability, prevent illegal tampering and unauthorized access, cannot filter and recommend the most relevant files based on file activity and access, optimize user experience, and cannot efficiently increase the hierarchy of data protection.

Method used

A cloud storage data integrity verification method is adopted, including collecting IoT data, building a private audit model based on user and user file audits, including file upload unit, integrity detection unit and algorithm verification unit, and verifying the feasibility, security and reliability of the model.

Benefits of technology

Through multiple technical means, ensure the security and integrity of data during uploading and access, reduce the risk of data tampering or loss, optimize user experience, improve the performance and user satisfaction of cloud storage systems, and improve the data protection level through strict audit and verification processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034378A_ABST
    Figure CN120034378A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud storage data integrity verification method and system, and relates to the technical field of integrity verification, and the method comprises the steps: collecting Internet of Things data, constructing an auditing model based on user and user file auditing, the private auditing model based on user and user file auditing comprises a file uploading unit, an integrity detection unit and an algorithm verification unit. And verifying the feasibility, safety and reliability of the similar private auditing model based on user and user file auditing. A local multicast server group is used for managing uploading and access of files, data encryption and integrity are ensured through a group key, the risk of data tampering or loss is reduced through an enhanced auditing model, data integrity verification is carried out through detailed and complete multiple technical means with high readability, illegal tampering and unauthorized access are prevented, and the data security is improved. According to the activeness and the access condition of the file, the most relevant file is filtered and recommended, so that the file can be efficiently managed and accessed, and the data protection hierarchy is efficiently increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of integrity verification, and in particular to a cloud storage data integrity verification method and system. Background Art

[0002] In recent years, cloud storage is the storage of data on remote servers via the Internet, allowing users to access and manage the data anytime and anywhere. It usually consists of multiple data centers, storage servers, and distributed architectures. Cloud storage can provide highly scalable, flexible, and low-cost services, but at the same time, because data is stored on third-party servers, users have less control over their data, which makes data integrity, privacy protection, and security key issues. In cloud storage, data may encounter a variety of threats, such as hardware failures, software vulnerabilities, malicious attacks, and human errors. Therefore, data integrity verification is crucial to ensure that data remains in its original state at each stage of uploading, storing, downloading, and processing.

[0003] At present, a Chinese invention patent with application number CN201910216029.6 discloses a cloud storage revocable dynamic data integrity verification system and method, which uses red-black tree information tables and erasure code cache technology to reduce the overhead of dynamically updating data, and uses new signature technology to reduce the computational overhead when generating data block labels, making file preprocessing faster, and also supporting the revocation of verification parties; however, the existing technology cannot perform data integrity verification through detailed, complete, and highly readable multiple technical means to prevent illegal tampering and unauthorized access, filter and recommend the most relevant files according to the activity and access status of the files, optimize the user experience, and be able to efficiently manage and access files. It is impossible to efficiently increase the data protection level through existing technical means. Summary of the invention

[0004] The technical problem solved by the present invention is that the existing technology cannot perform data integrity verification through detailed, complete and highly readable multiple technical means to prevent illegal tampering and unauthorized access, cannot filter and recommend the most relevant files according to the activity and access status of the files, and optimize the user experience, cannot efficiently manage and access files, and cannot efficiently increase the data protection level through existing technical means.

[0005] To solve the above technical problems, the present invention provides the following technical solutions: a cloud storage data integrity verification method, comprising the following steps:

[0006] Step S1: Collect IoT data and process the IoT data based on a cloud storage platform;

[0007] Step S2: constructing an audit model based on user and user file audit, wherein the private audit model based on user and user file audit includes a file uploading unit, an integrity detection unit and an algorithm verification unit;

[0008] Step S3: Verify the feasibility, security and reliability of the quasi-private audit model based on user and user file audit.

[0009] Preferably, the step S1 comprises:

[0010] Collect IoT data through sensors, the IoT data includes temperature, humidity, pressure, light and device status information, the status information includes switch status and fault warning, read IoT data from the sensors using hardware readers, and send the IoT data to cloud storage platforms for storage, the cloud storage platforms include WS, Google Cloud, Microsoft Azure and Alibaba Cloud, and interact with cloud storage platforms through APIs and SDKs;

[0011] Processing IoT data on a cloud storage platform includes converting the IoT data into a unified data format, where the data format includes JSON and XML.

[0012] Preferably, the file uploading unit includes:

[0013] The processed IoT data is encapsulated into a file format and uploaded to the local multicast server group. The group administrator of the local multicast server group obtains the group key by sending the identity ID, and broadcasts the group key to all local multicast server group members through multicast. The group administrator manages the local multicast server group as the edge forwarding router of the local multicast server group. The management authority includes: performing user joining and revoking operations on the local multicast server group, updating the group key of the local multicast server group, encrypting and segmenting the file data, generating signatures for the file blocks using the group key, and uploading the file data and signatures to the cloud storage platform, and calculating the reward distribution according to the cost size of the communication network nodes that have successfully verified, traded, and written. The mathematical expression of the reward distribution is:

[0014] A=B-αA a -βA b -γA c +εA d ;

[0015] Among them, A is the reward distribution of the node, B is the total reward of the node, α, β, γ and ε are weight constants, A a For payment contracts or compensation contracts, A b is the communication overhead in the communication network, A cis the computational overhead in the communication network, A d For compensation;

[0016] All local multicast server group members assigned with the group key decrypt and access the successfully written file data, set a time status table and a time update threshold, wherein the time status table is used to record and update the time of uploading user files, accessing user files and auditing user files. If the difference between the current time and the latest time among the time of uploading user files, accessing user files and auditing user files exceeds the time update threshold, the user file is audited and updated.

[0017] Preferably, the integrity detection unit includes an initialization algorithm, a key update algorithm, a signature algorithm and a file prediction algorithm:

[0018] The initialization algorithm is used to input security parameters, output a master key and cloud storage data integrity verification system parameters, the master key is privatized by performing bilinear mapping and hash mapping on random elements, and the master key is stored in a preset historical key set, and the cloud storage data integrity verification system parameters include a public key, a private key pair and an initialization vector;

[0019] The key update algorithm is used for pseudonym generation and key extraction, and is executed by the original data owner and the new data owner through a third-party key platform;

[0020] The administrator sends the identity of the group to which he belongs and the local multicast server group members to the third-party key platform, randomly generates k+2 elements according to the identity, encrypts and merges the identity through the third-party key platform to obtain merged information, and calculates the private key and public key according to the merged information. The private key and public key calculation logic includes: inputting the real identity of the original owner of the data and the real identity of the new owner of the data, and inputting the master key and cloud storage data integrity verification system parameters at the same time, and outputting the pseudonym and private key of the original owner of the data and the pseudonym and private key of the new owner, where k is the total number of identity identifiers;

[0021] The third-party key platform publishes the public verification parameters and sends the private key to the group administrator. After the group administrator receives the signed private key, he verifies the correctness of the private key. The verification logic includes:

[0022] When the private key meets the signature rule, the private key is distributed to all local multicast server group members;

[0023] When the private key does not meet the signature rules, the incorrect private key is discarded.

[0024] Preferably, it is characterized in that the signature algorithm is used by the local multicast server group members to divide the file data into n blocks according to the fragmentation rules to obtain a data block set, encrypt the plaintext in the data block using a symmetric encryption algorithm to obtain a ciphertext data block, generate a corresponding signature for each ciphertext data block according to the user's input requirements, the signature represents the virtual index of the ciphertext data block and the updated timestamp, splice the encrypted data block and the corresponding signature into a generalized table form and integrate all generalized tables into a signature data block set, upload the signature data block set to the cloud storage platform, intelligently generate a corresponding contract agreement for the signature data block set during the upload, and upload the contract agreement to the cloud storage platform accordingly;

[0025] The local multicast server group members that can extract the same file data content are defined as a sharing group.

[0026] Preferably, the file prediction algorithm is used to filter valid files received by the sharing group, the valid files are valid file data successfully downloaded by the sharing group, set access cycle thresholds and active cycle thresholds, set a file status table, the file status table includes records of the access status and activity level of the file data by the sharing group, and calculate the life cycle of the file data according to the file status table. The calculation logic includes:

[0027] When new file data is uploaded to the cloud storage platform, the label of the file data is initialized as an inactive file, the shared group access status and activity level in the file status table of the file data are recorded, the file status table of the file data is updated per unit time, and the activity level of the file data within t time is obtained. The activity level is obtained by multiplying the number of shared group accesses, the unit time and the weight constant, where t is a constant;

[0028] Check the file status table at unit time intervals, and when the activity level of the file data recorded in the file status table is greater than the activity period threshold, set a label of the file data as an active file, record a time period in which the file data is an active file, and calculate a time difference Δt of the time period;

[0029] A prediction matrix between users and file data is established, wherein the rows of the prediction matrix represent users and the columns represent file data, wherein each value in the prediction matrix represents the degree of activity of group members of the sharing group on the file data, all prediction matrices are accumulated to obtain a total prediction matrix, and the similarity between any two file data is calculated using Pearson similarity until all similarities between any two file data are calculated, and all similarities are normalized, and the calculation of the recommendation degree of the sharing group as a whole for the file data j includes: calculating the user's score prediction for the file j, calculating the weighted average of the score predictions of all sharing group users for the file j, and obtaining the recommendation degree of the file j;

[0030] Get the specified number of file data that are most similar to the active file based on the recommendation degree.

[0031] Preferably, the algorithm verification unit includes a random challenge algorithm and an evidence verification algorithm:

[0032] The random challenge algorithm includes:

[0033] The user randomly extracts several file data to obtain a challenge file index set, randomly selects several data blocks from each file data as challenge blocks, generates challenge block indexes using a tree, and randomly assigns random coefficients to each challenge block. Each file data generates challenge parameters according to the challenge file index set, challenge block index and random coefficient. The challenge parameter is randomly selected from the challenge file index set, challenge block index and random coefficient, and all challenge parameters are sent to the current data transmission network;

[0034] The evidence verification algorithm includes:

[0035] Input the original owner's private key, file data and file name through the third-party key platform, output the authentication set, input the original owner's private key P and the new owner's private key C, output the conversion value, input the data integrity test challenge, file data and authentication set generated by the cloud storage platform, and output the cloud storage data integrity test certificate;

[0036] If the verification is passed, output "1";

[0037] If the verification fails, "0" and the pseudonym of the new owner of the data are output.

[0038] Preferably, the step S3 comprises:

[0039] Clean and standardize all data transmitted to the cloud storage platform through the IoT gateway;

[0040] Use TLS / SSL encryption protocol to encrypt and protect data during transmission;

[0041] Record all data operations as audit logs, including data collection, transmission, storage and deletion, and including the operator, time of data operation, content of data operation and data source;

[0042] An audit report is generated through the cloud storage platform, and the audit report includes data operation records, audit findings, cloud storage data integrity verification system status and potential risks.

[0043] Preferably, the security includes correctness, storage integrity, data privacy protection, identity privacy protection, resistance to substitution attacks and resistance to replay attacks.

[0044] Feasibility verification includes:

[0045] Conduct integration testing on IoT devices, data transmission channels, cloud storage platforms, and audit cloud storage data integrity verification systems. By simulating the operation and data collection process of IoT devices on computers, verify whether data can be successfully uploaded to the cloud platform, and verify whether all audit activities can be correctly recorded and monitored;

[0046] Verification of security includes:

[0047] Verify the effectiveness of the cloud platform's encryption mechanism and check the access control mechanism;

[0048] Verify the immutability of audit logs by simulating tampering, deletion, and modification of transmitted data;

[0049] Conduct penetration testing to evaluate the cloud storage data integrity verification system's ability to protect against malicious attacks;

[0050] Verification of reliability includes:

[0051] Simulate abnormal situations such as network interruption and cloud storage data integrity verification system crash to verify the recovery capability of the cloud storage data integrity verification system after a failure occurs;

[0052] Perform load testing on the cloud storage data integrity verification system to simulate a scenario where a large number of devices upload data simultaneously.

[0053] A cloud storage data integrity verification system includes a collection module, a construction module and a verification module:

[0054] The acquisition module is used to collect IoT data and process the IoT data based on the cloud storage platform;

[0055] The construction module is used to construct an audit model based on user and user file audit, and the private audit model based on user and user file audit includes a file upload unit, an integrity detection unit and an algorithm verification unit;

[0056] The verification module is used to verify the feasibility, security and reliability of the quasi-private audit model based on user and user file audit.

[0057] The beneficial effects of the present invention are as follows: ensuring that IoT data can be safely and accurately transmitted to the cloud platform, and providing data protection for subsequent integrity verification and auditing. A quasi-private audit model based on user and user file auditing is designed, including modules for file upload, integrity detection, and algorithm verification. The local multicast server group is used to manage file upload and access, and group keys are used to ensure data encryption and integrity. The enhanced audit model ensures the security and integrity of data during upload and access, and reduces the risk of data tampering or loss. Multiple technical means such as initialization algorithm, key update algorithm, signature algorithm, and file prediction algorithm are used to verify data integrity, especially through key update and signature generation mechanisms to prevent illegal tampering and unauthorized access, enhance the security of data storage and transmission, and ensure that only authorized users can access or modify data. A file prediction algorithm is designed to filter and recommend the most relevant files based on the activity and access of the files, optimize the user experience, and be able to efficiently manage and access files, improving the performance and user satisfaction of the cloud storage system. The audit and verification mechanism includes a random challenge algorithm. The method and evidence verification algorithm ensure that the data integrity of the file is effectively verified through the third-party key platform. By generating random challenge parameters and verifying the file data, the data protection level is further improved, making data integrity verification more efficient and secure, avoiding malicious tampering, and improving the transparency and trust of the entire system; in the verification stage, through integration testing, encryption mechanism, penetration testing and other means, the efficient operation, security protection and stability of the system in actual applications are ensured, and the system can be stably operated and provide data security protection when facing various challenges in actual application scenarios; the present invention provides a comprehensive and efficient data protection solution for cloud storage platforms through multi-level technical guarantees, strict auditing and verification processes, and comprehensive considerations of data integrity, transmission security, system reliability, etc. In actual applications, it can greatly improve data security, traceability and audit transparency, and is suitable for wide applications in the fields of Internet of Things and big data. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 A basic flow chart of a cloud storage data integrity verification method provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0059] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings. It is obvious that the described embodiments are only part of the embodiments of the present invention, but not all of the embodiments.

[0060] Reference Figure 1 , as an embodiment of the present invention, provides a cloud storage data integrity verification method, comprising the following steps:

[0061] Step S1: Collect IoT data and process the IoT data based on a cloud storage platform;

[0062] Step S2: constructing an audit model based on user and user file audit, wherein the private audit model based on user and user file audit includes a file uploading unit, an integrity detection unit and an algorithm verification unit;

[0063] Step S3: Verify the feasibility, security and reliability of the quasi-private audit model based on user and user file audit.

[0064] The step S1 comprises:

[0065] Collect IoT data through sensors, including temperature, humidity, pressure, light and device status information, including switch status and fault warnings, read IoT data from the sensors using hardware readers, and send the IoT data to cloud storage platforms for storage. The cloud storage platforms include WS, Google Cloud, Microsoft Azure and Alibaba Cloud, and interact with the cloud storage platforms through APIs and SDKs to ensure that data can be correctly and securely transmitted to the cloud storage platforms;

[0066] Processing IoT data on a cloud storage platform includes converting the IoT data into a unified data format, wherein the data format includes JSON and XML, so as to facilitate unified processing, transmission and storage of data.

[0067] The file uploading unit comprises:

[0068] The processed IoT data is encapsulated into a file format and uploaded to the local multicast server group. The group administrator of the local multicast server group obtains the group key by sending the identity ID, and broadcasts the group key to all local multicast server group members through multicast. The group administrator manages the local multicast server group as the edge forwarding router of the local multicast server group. The management authority includes: performing user joining and revoking operations on the local multicast server group, updating the group key of the local multicast server group, encrypting and segmenting the file data, generating signatures for the file blocks using the group key, and uploading the file data and signatures to the cloud storage platform, and calculating the reward distribution according to the cost size of the communication network nodes that have successfully verified, traded, and written. The mathematical expression of the reward distribution is:

[0069] A=B-αA a -βA b -γA c +εA d ;

[0070] Among them, A is the reward distribution of the node, B is the total reward of the node, α, β, γ and ε are weight constants, A a For payment contracts or compensation contracts, A b is the communication overhead in the communication network, A c is the computational overhead in the communication network, A d For compensation;

[0071] All local multicast server group members assigned with the group key decrypt and access the successfully written file data, set a time status table and a time update threshold, wherein the time status table is used to record and update the time of uploading user files, accessing user files and auditing user files. If the difference between the current time and the latest time among the time of uploading user files, accessing user files and auditing user files exceeds the time update threshold, the user file is audited and updated.

[0072] The integrity detection unit includes an initialization algorithm, a key update algorithm, a signature algorithm and a file prediction algorithm:

[0073] The initialization algorithm is used to input security parameters, output a master key and cloud storage data integrity verification system parameters, the master key is privatized by performing bilinear mapping and hash mapping on random elements, and the master key is stored in a preset historical key set, the cloud storage data integrity verification system parameters include a public key, a private key pair and an initialization vector, the initialization vector is a random value used with the key, and is used to introduce additional randomness in the encryption process;

[0074] The key update algorithm is used for pseudonym generation and key extraction, and is executed by the original data owner and the new data owner through a third-party key platform;

[0075] The administrator sends the identity of the group to which he belongs and the members of the local multicast server group to the third-party key platform, and randomly generates k+2 elements according to the identity. In order to prevent the leakage of the shared group and member information, the identity is encrypted and merged through the third-party key platform to obtain the merged information, and the private key and public key are calculated according to the merged information. The private key and public key calculation logic includes: inputting the real identity of the original owner of the data and the real identity of the new owner of the data, and inputting the master key and cloud storage data integrity verification system parameters at the same time, and outputting the pseudonym and private key of the original owner of the data and the pseudonym and private key of the new owner, and k is the total number of identity identifiers;

[0076] The third-party key platform publishes the public verification parameters and sends the private key to the group administrator. After the group administrator receives the signed private key, he verifies the correctness of the private key. The verification logic includes:

[0077] When the private key meets the signature rule, the private key is distributed to all local multicast server group members;

[0078] When the private key does not meet the signature rules, the incorrect private key is discarded.

[0079] The signature algorithm is used by the local multicast server group members to divide the file data into n blocks according to the fragmentation rule, where n is a constant, to obtain a data block set, to encrypt the plaintext in the data block using a symmetric encryption algorithm, to obtain a ciphertext data block, to generate a corresponding signature for each ciphertext data block according to the user's input requirements, the signature represents the virtual index of the ciphertext data block and the updated timestamp, to splice the encrypted data block and the corresponding signature into a generalized table form and to integrate all generalized tables into a signature data block set, to upload the signature data block set to the cloud storage platform, to intelligently generate a corresponding contract agreement for the signature data block set during the upload, and to upload the contract agreement to the cloud storage platform accordingly;

[0080] When the signature data block set and the contract agreement are uploaded to the cloud storage platform at the same time, users corresponding to the local multicast server group members can all unlock the key and extract the file data content.

[0081] The local multicast server group members that can extract the same file data content are defined as a sharing group.

[0082] The file prediction algorithm is used to filter valid files received by the sharing group. The valid files are valid file data successfully downloaded by the sharing group. The access cycle threshold and the active cycle threshold are manually set. The access cycle threshold is a static value manually set according to the cloud storage data integrity verification system resource situation and the number of files in the sharing group. It is used to determine whether a file is still in its validity period. The active cycle threshold is dynamic. It is a control variable of the unit manually set according to the activity of the file. It is also a standard for determining whether a file is active. A file status table is set. The file status table includes records of the access situation and activity level of the sharing group to the file data, so as to filter the valid files of the sharing group. The life cycle of the file data is calculated according to the file status table. The calculation logic includes:

[0083] When new file data is uploaded to the cloud storage platform, the label of the file data is initialized as an inactive file, the shared group access status and activity level in the file status table of the file data are recorded, the file status table of the file data is updated per unit time, and the activity level of the file data within t time is obtained. The activity level is obtained by multiplying the number of shared group accesses, the unit time and a weight constant, where the weight constant is manually set and t is a constant;

[0084] Check the file status table at unit time intervals, and when the activity level of the file data recorded in the file status table is greater than the activity period threshold, set a label of the file data as an active file, record a time period in which the file data is an active file, and calculate a time difference Δt of the time period;

[0085] A prediction matrix between users and file data is established, wherein the rows of the prediction matrix represent users and the columns represent file data, wherein each value in the prediction matrix represents the degree of activity of group members of the sharing group on the file data, all prediction matrices are accumulated to obtain a total prediction matrix, and the similarity between any two file data is calculated using Pearson similarity until all similarities between any two file data are calculated, and all similarities are normalized, and the calculation of the recommendation degree of the sharing group as a whole for the file data j includes: calculating the user's score prediction for the file j, calculating the weighted average of the score predictions of all sharing group users for the file j, and obtaining the recommendation degree of the file j;

[0086] Get the specified number of file data that are most similar to the active file based on the recommendation degree.

[0087] The algorithm verification unit includes a random challenge algorithm and an evidence verification algorithm:

[0088] The random challenge algorithm includes:

[0089] The user randomly extracts several file data to obtain a challenge file index set, randomly selects several data blocks from each file data as challenge blocks, generates challenge block indexes using a tree, and randomly assigns random coefficients to each challenge block. Each file data generates challenge parameters according to the challenge file index set, challenge block index and random coefficient. The challenge parameter is randomly selected from the challenge file index set, challenge block index and random coefficient, and all challenge parameters are sent to the current data transmission network;

[0090] The evidence verification algorithm includes:

[0091] Input the original owner's private key, file data and file name through the third-party key platform, output the authentication set, input the original owner's private key P and the new owner's private key C, output the conversion value, input the data integrity test challenge, file data and authentication set generated by the cloud storage platform, and output the cloud storage data integrity test certificate;

[0092] If the verification is passed, output "1";

[0093] If the verification fails, "0" and the pseudonym of the new owner of the data are output.

[0094] The step S3 comprises:

[0095] Clean and standardize all data transmitted to the cloud storage platform through the IoT gateway;

[0096] Use TLS / SSL encryption protocol to encrypt and protect data during transmission;

[0097] Record all data operations as audit logs, including data collection, transmission, storage and deletion, and including the operator, time of data operation, content of data operation and data source;

[0098] An audit report is generated through the cloud storage platform. The audit report includes data operation records, audit findings, cloud storage data integrity verification system status and potential risks. The report should be easy to understand and cover relevant information of all audit activities.

[0099] The security includes correctness, storage integrity, data privacy protection, identity privacy protection, resistance to substitution attacks, and resistance to replay attacks.

[0100] Feasibility verification includes:

[0101] The goal of feasibility verification is to ensure that the model can operate normally and achieve the following goals in actual applications:

[0102] Conduct integration testing on IoT devices, data transmission channels, cloud storage platforms, and audit cloud storage data integrity verification systems to ensure that they can work together seamlessly, data flows smoothly, and the audit process is accurate. By simulating the operation and data collection process of IoT devices on computers, verify whether data can be successfully uploaded to the cloud platform, and verify whether all audit activities can be correctly recorded and monitored;

[0103] Verification of security includes:

[0104] Security verification aims to ensure that the cloud storage data integrity verification system has no loopholes in data protection, communication security, identity authentication, etc.:

[0105] Verify the effectiveness of the cloud platform's encryption mechanism to ensure the security of data during transmission and storage, and check the access control mechanism to ensure that only authorized personnel can access data and audit logs;

[0106] Verify the immutability of audit logs by simulating tampering, deletion, and modification of transmitted data;

[0107] Conduct penetration testing to evaluate the cloud storage data integrity verification system's ability to protect against malicious attacks and ensure data security is not violated;

[0108] Verification of reliability includes:

[0109] Reliability verification ensures that the cloud storage data integrity verification system can maintain stability and efficiency in long-term operation:

[0110] Simulate abnormal situations such as network interruption and cloud storage data integrity verification system crash to verify the cloud storage data integrity verification system's ability to recover after a failure. For example, when a problem occurs on the cloud platform, audit whether the cloud storage data integrity verification system can record data normally and whether it can restore data from backups.

[0111] Load testing is performed on the cloud storage data integrity verification system to simulate a scenario where a large number of devices upload data at the same time, ensuring that the cloud storage data integrity verification system can withstand high concurrency pressure and that the audit process is not affected.

[0112] Through the above steps, data can be sent from IoT data collection to the cloud storage platform, and a quasi-private audit model based on user and user file audit can be established. This process ensures the security and traceability of data, and enhances transparency and fairness through user and user file audit. In the verification phase of the cloud storage data integrity verification system, feasibility, security and reliability tests are conducted to ensure the efficiency and robustness of the cloud storage data integrity verification system in actual operation.

[0113] A cloud storage data integrity verification system includes a collection module, a construction module and a verification module:

[0114] The acquisition module is used to collect IoT data and process the IoT data based on the cloud storage platform;

[0115] The construction module is used to construct an audit model based on user and user file audit, and the private audit model based on user and user file audit includes a file upload unit, an integrity detection unit and an algorithm verification unit;

[0116] The verification module is used to verify the feasibility, security and reliability of the quasi-private audit model based on user and user file audit.

[0117] The present invention ensures that IoT data can be safely and accurately transmitted to the cloud platform, providing data protection for subsequent integrity verification and auditing. A quasi-private audit model based on user and user file auditing is designed, including modules for file upload, integrity detection and algorithm verification. The local multicast server group is used to manage file upload and access, and group keys are used to ensure data encryption and integrity. The enhanced audit model ensures the security and integrity of data during upload and access, reducing the risk of data tampering or loss. Multiple technical means such as initialization algorithm, key update algorithm, signature algorithm and file prediction algorithm are used to verify data integrity, especially through key update and signature generation mechanism to prevent illegal tampering and unauthorized access, enhance the security of data storage and transmission, and ensure that only authorized users can access or modify data. A file prediction algorithm is designed to filter and recommend the most relevant files according to the activity and access of the files, optimize the user experience, and can efficiently manage and access files, improving the performance and user satisfaction of the cloud storage system. The audit and verification mechanism includes a random challenge algorithm. The method and evidence verification algorithm ensure that the data integrity of the file is effectively verified through the third-party key platform. By generating random challenge parameters and verifying the file data, the data protection level is further improved, making data integrity verification more efficient and secure, avoiding malicious tampering, and improving the transparency and trust of the entire system; in the verification stage, through integration testing, encryption mechanism, penetration testing and other means, the efficient operation, security protection and stability of the system in actual applications are ensured, and the system can be stably operated and provide data security protection when facing various challenges in actual application scenarios; the present invention provides a comprehensive and efficient data protection solution for cloud storage platforms through multi-level technical guarantees, strict auditing and verification processes, and comprehensive considerations of data integrity, transmission security, system reliability, etc. In actual applications, it can greatly improve data security, traceability and audit transparency, and is suitable for wide applications in the fields of Internet of Things and big data.

[0118] It should be understood by those skilled in the art that the embodiments of the present invention may be provided as a method, a cloud storage data integrity verification system or a computer program product. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program codes. Among them, the storage medium may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (Static Random Access Memory, referred to as SRAM), an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, referred to as EEPROM), an erasable programmable read-only memory (Erasable Programmable Read Only Memory, referred to as EPROM), a programmable read-only memory (Programmable Red-Only Memory, referred to as PROM), a read-only memory (Read-Only Memory, referred to as ROM), a magnetic memory, a flash memory, a disk or an optical disk. These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0119] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A cloud storage data integrity verification method, characterized in that: The following steps are involved: Step S1: Collect IoT data and process the IoT data based on a cloud storage platform; Step S2: constructing an audit model based on user and user file audit, wherein the private audit model based on user and user file audit includes a file uploading unit, an integrity detection unit and an algorithm verification unit; Step S3: Verify the feasibility, security and reliability of the quasi-private audit model based on user and user file audit.

2. The cloud storage data integrity verification method according to claim 1, characterized in that: The step S1 comprises: Collect IoT data through sensors, the IoT data includes temperature, humidity, pressure, light and device status information, the status information includes switch status and fault warning, read IoT data from the sensors using hardware readers, and send the IoT data to cloud storage platforms for storage, the cloud storage platforms include WS, Google Cloud, Microsoft Azure and Alibaba Cloud, and interact with cloud storage platforms through APIs and SDKs; Processing IoT data on a cloud storage platform includes converting the IoT data into a unified data format, where the data format includes JSON and XML.

3. The cloud storage data integrity verification method according to claim 2, characterized in that: The file uploading unit comprises: The processed IoT data is encapsulated into a file format and uploaded to the local multicast server group. The group administrator of the local multicast server group obtains the group key by sending the identity ID, and broadcasts the group key to all local multicast server group members through multicast. The group administrator manages the local multicast server group as the edge forwarding router of the local multicast server group. The management authority includes: performing user joining and revoking operations on the local multicast server group, updating the group key of the local multicast server group, encrypting and segmenting the file data, generating signatures for the file blocks using the group key, and uploading the file data and signatures to the cloud storage platform, and calculating the reward distribution according to the cost size of the communication network nodes that have successfully verified, traded, and written. The mathematical expression of the reward distribution is: A=B-αA a -βA b -γA c +εA d ; Among them, A is the reward distribution of the node, B is the total reward of the node, α, β, γ and ε are weight constants, A a For payment contracts or compensation contracts, A b is the communication overhead in the communication network, A c is the computational overhead in the communication network, A d For compensation; All local multicast server group members assigned with the group key decrypt and access the successfully written file data, set a time status table and a time update threshold, wherein the time status table is used to record and update the time of uploading user files, accessing user files and auditing user files. If the difference between the current time and the latest time among the time of uploading user files, accessing user files and auditing user files exceeds the time update threshold, the user file is audited and updated.

4. The cloud storage data integrity verification method according to claim 3, characterized in that: The integrity detection unit includes an initialization algorithm, a key update algorithm, a signature algorithm and a file prediction algorithm: The initialization algorithm is used to input security parameters, output a master key and cloud storage data integrity verification system parameters, the master key is privatized by performing bilinear mapping and hash mapping on random elements, and the master key is stored in a preset historical key set, and the cloud storage data integrity verification system parameters include a public key, a private key pair and an initialization vector; The key update algorithm is used for pseudonym generation and key extraction, and is executed by the original data owner and the new data owner through a third-party key platform; The administrator sends the identity of the group to which he belongs and the local multicast server group members to the third-party key platform, randomly generates k+2 elements according to the identity, encrypts and merges the identity through the third-party key platform to obtain merged information, and calculates the private key and public key according to the merged information. The private key and public key calculation logic includes: inputting the real identity of the original owner of the data and the real identity of the new owner of the data, and inputting the master key and cloud storage data integrity verification system parameters at the same time, and outputting the pseudonym and private key of the original owner of the data and the pseudonym and private key of the new owner, where k is the total number of identity identifiers; The third-party key platform publishes the public verification parameters and sends the private key to the group administrator. After the group administrator receives the signed private key, he verifies the correctness of the private key. The verification logic includes: When the private key meets the signature rule, the private key is distributed to all local multicast server group members; When the private key does not meet the signature rules, the incorrect private key is discarded.

5. The cloud storage data integrity verification method according to claim 4, characterized in that: The signature algorithm is used by the local multicast server group members to divide the file data into n blocks according to the fragmentation rules to obtain a data block set, encrypt the plaintext in the data block using a symmetric encryption algorithm to obtain a ciphertext data block, generate a corresponding signature for each ciphertext data block according to the user's input requirements, the signature represents the virtual index of the ciphertext data block and the updated timestamp, splice the encrypted data block and the corresponding signature into a generalized table form and integrate all generalized tables into a signature data block set, upload the signature data block set to the cloud storage platform, intelligently generate a corresponding contract agreement for the signature data block set during the upload, and upload the contract agreement to the cloud storage platform accordingly; The local multicast server group members that can extract the same file data content are defined as a sharing group.

6. The cloud storage data integrity verification method according to claim 5, characterized in that: The file prediction algorithm is used to filter valid files received by the sharing group, the valid files are valid file data successfully downloaded by the sharing group, set access cycle thresholds and active cycle thresholds, set a file status table, the file status table includes records of the sharing group's access to the file data and the degree of activity, calculate the life cycle of the file data according to the file status table, and the calculation logic includes: When new file data is uploaded to the cloud storage platform, the label of the file data is initialized as an inactive file, the shared group access status and activity level in the file status table of the file data are recorded, the file status table of the file data is updated per unit time, and the activity level of the file data within t time is obtained. The activity level is obtained by multiplying the number of shared group accesses, the unit time and the weight constant, where t is a constant; Check the file status table at unit time intervals, and when the activity level of the file data recorded in the file status table is greater than the activity period threshold, set a label of the file data as an active file, record a time period in which the file data is an active file, and calculate a time difference Δt of the time period; A prediction matrix between users and file data is established, wherein the rows of the prediction matrix represent users and the columns represent file data, wherein each value in the prediction matrix represents the degree of activity of group members of the sharing group on the file data, all prediction matrices are accumulated to obtain a total prediction matrix, and the similarity between any two file data is calculated using Pearson similarity until all similarities between any two file data are calculated, and all similarities are normalized, and the calculation of the recommendation degree of the sharing group as a whole for the file data j includes: calculating the user's score prediction for the file j, calculating the weighted average of the score predictions of all sharing group users for the file j, and obtaining the recommendation degree of the file j; Get the specified number of file data that are most similar to the active file based on the recommendation degree.

7. The cloud storage data integrity verification method according to claim 6, characterized in that: The algorithm verification unit includes a random challenge algorithm and an evidence verification algorithm: The random challenge algorithm includes: The user randomly extracts several file data to obtain a challenge file index set, randomly selects several data blocks from each file data as challenge blocks, generates challenge block indexes using a tree, and randomly assigns random coefficients to each challenge block. Each file data generates challenge parameters according to the challenge file index set, challenge block index and random coefficient. The challenge parameter is randomly selected from the challenge file index set, challenge block index and random coefficient, and all challenge parameters are sent to the current data transmission network; The evidence verification algorithm includes: Input the original owner's private key, file data and file name through the third-party key platform, output the authentication set, input the original owner's private key P and the new owner's private key C, output the conversion value, input the data integrity test challenge, file data and authentication set generated by the cloud storage platform, and output the cloud storage data integrity test certificate; If the verification is passed, output "1"; If the verification fails, "0" and the pseudonym of the new owner of the data are output.

8. The cloud storage data integrity verification method according to claim 2, characterized in that: The step S3 comprises: Clean and standardize all data transmitted to the cloud storage platform through the IoT gateway; Use TLS / SSL encryption protocol to encrypt and protect data during transmission; Record all data operations as audit logs, including data collection, transmission, storage and deletion, and including the operator, time of data operation, content of data operation and data source; An audit report is generated through the cloud storage platform, and the audit report includes data operation records, audit findings, cloud storage data integrity verification system status and potential risks.

9. The cloud storage data integrity verification method according to claim 8, characterized in that: The security includes correctness, storage integrity, data privacy protection, identity privacy protection, resistance to substitution attacks and resistance to replay attacks; Feasibility verification includes: Conduct integration testing on IoT devices, data transmission channels, cloud storage platforms, and audit cloud storage data integrity verification systems. By simulating the operation and data collection process of IoT devices on computers, verify whether data can be successfully uploaded to the cloud platform, and verify whether all audit activities can be correctly recorded and monitored; Verification of security includes: Verify the effectiveness of the cloud platform's encryption mechanism and check the access control mechanism; Verify the immutability of audit logs by simulating tampering, deletion, and modification of transmitted data; Conduct penetration testing to evaluate the cloud storage data integrity verification system's ability to protect against malicious attacks; Verification of reliability includes: Simulate abnormal situations such as network interruption and cloud storage data integrity verification system crash to verify the recovery capability of the cloud storage data integrity verification system after a failure occurs; Perform load testing on the cloud storage data integrity verification system to simulate a scenario where a large number of devices upload data simultaneously.

10. A cloud storage data integrity verification system, characterized in that: Including acquisition module, construction module and verification module: The acquisition module is used to collect IoT data and process the IoT data based on the cloud storage platform; The construction module is used to construct an audit model based on user and user file audit, and the private audit model based on user and user file audit includes a file upload unit, an integrity detection unit and an algorithm verification unit; The verification module is used to verify the feasibility, security and reliability of the quasi-private audit model based on user and user file audit.

Citation Information

Patent Citations

  • A cloud storage revocable dynamic data integrity verification system and method

    CN110008755B