Data management method and computing device

By introducing a multi-dimensional security checksum distributed ledger network into the data management method, the problem that key management security depends on key confidentiality in the prior art is solved, and all-round protection of data and transparency and traceability of data operations are achieved.

CN120046202APending Publication Date: 2025-05-27HENAN QINWEI DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510127899.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The prior art relies on encryption technology in data security protection. The security of key management depends on the confidentiality of the key. Once the key is leaked, the security of the entire system will be threatened, and it is difficult to prevent internal attacks and ensure the long-term integrity of the data.

Method used

By introducing a multi-dimensional security checksum distributed ledger network into the data management method, we ensure that the data set can be accessed only after passing the verification before use, and record all access operations and generate transaction records stored in the distributed ledger network.

Benefits of technology

It realizes all-round protection of data, ensuring the integrity and security of data before and after use, while enhancing the transparency and traceability of data operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046202A_ABST
    Figure CN120046202A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the technical field of data security, and particularly provides a data management method and computing equipment. According to the embodiment of the invention, a first request used for requesting to access a first data set by a user can be received, the first data set and first metadata are verified, normal access operation of the user on the first data set is allowed under the condition that the verification is passed, and a transaction record can be generated based on the normal access operation, so that the transaction efficiency is improved. And the transaction record is stored in the distributed account book network. According to the technical scheme provided by the embodiment of the invention, the access security of the data can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technologies, and in particular, to a data management method and a computing device. Background Art

[0002] With the development of information technology, the security of data has become the focus of attention of enterprises and individuals. Especially in the era of cloud computing and big data, the transmission and storage of data face various security threats, such as data tampering, data loss, etc. In related technologies, the protection measures for data security mainly rely on encryption technology to achieve. However, the security of encryption technology depends on key management. Once the key is leaked, it will affect the security of the entire system. Therefore, how to ensure that data is not illegally accessed or tampered with has become a technical problem to be solved urgently in this field. Summary of the Invention

[0003] The embodiments of this application provide a data management method and a computing device, which can improve the security of dataset access.

[0004] According to one aspect of the embodiments of this application, a data management method is provided, including:

[0005] Receiving a first request from a user; the first request is used to request access to a first dataset; the first dataset and first metadata are stored in a secure database; the first metadata is the metadata of the first dataset;

[0006] Verifying the first dataset and the first metadata;

[0007] When the verification passes, allowing the user to perform normal access operations on the first dataset;

[0008] Generating a transaction record based on the normal access operation;

[0009] Storing the transaction record in a distributed ledger network.

[0010] In this embodiment, on the one hand, when receiving the first request from the user for accessing the first data set, the present application performs a multi-dimensional security check on the first data set and the first metadata, and only allows the user to access the first data set normally if the check passes. In this way, the multi-dimensional check process of the data set and metadata can be performed before the data set is used to ensure that the data used by the user is complete, secure, and not tampered with; on the other hand, the embodiment of the present application can also generate transaction records based on normal access operations, and store the transaction records in a distributed ledger network. In this way, the use of a distributed ledger network can not only ensure the traceability and persistence of transaction records, but also increase the transparency and trust of data. In summary, the technical solution provided by the embodiment of the present application can achieve all-round protection of data from two perspectives: before the data is used and after the operation is completed, which not only effectively guarantees the integrity and security of the data, but also enhances the transparency and traceability of data operations.

[0011] In an exemplary embodiment, generating a transaction record based on a normal access operation includes: generating a transaction record based on access information and first metadata; wherein the access information includes the access operation type, data accessor identifier, and timestamp. In this embodiment, the access information can be guaranteed to be secure, transparent, and traceable, which is conducive to ensuring data security.

[0012] In an exemplary embodiment, verifying the first data set and the first metadata includes: verifying the first data set and the first metadata based on a first verification value; wherein the first verification value is generated by the first data set and the first metadata currently stored in the security database. In this embodiment, the first data set and the first metadata can be quickly verified at one time through the first verification value, which is simple, easy and efficient.

[0013] In an exemplary embodiment, before receiving the first request from the user, the method further includes: receiving the first data set and the first metadata; generating a second verification value based on the first data set and the first metadata; and storing the first data set, the first metadata, and the second verification value in a security database. In this embodiment, the second verification value that can be used for security verification is pre-embedded when the data set is initially stored, which is conducive to simplifying subsequent processing and improving verification efficiency and data access efficiency.

[0014] In an exemplary embodiment, verifying the first data set and the first metadata based on the first verification value includes: determining the integrity of the first data set and the first metadata based on the consistency of the first verification value and the second verification value. This embodiment is simple, reliable, highly accurate, and is conducive to ensuring data security.

[0015] In an exemplary embodiment, the method further includes: in the case where the verification fails, rejecting the user's access operation to the first data set and recording it as an abnormal access operation; generating a transaction record based on the abnormal access operation. In this embodiment, it is ensured that all abnormal access operations are also secure, transparent, and traceable, which is beneficial for subsequent utilization or analysis and ensures data security.

[0016] In an exemplary embodiment, the method further includes: receiving a second request; the second request is used to obtain the user's access operation to the first data set; the access operation includes a normal access operation and / or an abnormal access operation; obtaining a transaction record from the distributed ledger network; in response to the second request, returning an audit report; wherein the audit report is generated based on the transaction record. This embodiment can provide data support for data auditing and ensure the accuracy and transparency of the audit report.

[0017] According to one aspect of the embodiments of the present application, another data management method is provided, including:

[0018] Receiving a transaction record, wherein the transaction record is generated based on the user's access operation to the first data set;

[0019] Generating a new block and metadata of the new block based on the transaction record;

[0020] Broadcasting the new block and the metadata of the new block to other nodes in the distributed ledger network.

[0021] In this embodiment, the transaction record is maintained through the distributed ledger network. The distributed ledger network can maintain the transaction record on each distributed node respectively, which can not only ensure the traceability and persistence of the transaction record, but also increase the transparency and trust of the data, and ensure the transparency and traceability of the data operation.

[0022] In an exemplary embodiment, before generating a new block and metadata of the new block based on the access operation, the method further includes: determining the validity of the transaction record based on a consensus mechanism. In this embodiment, the consensus mechanism further ensures the consistency and security of the transaction record stored in the distributed ledger network.

[0023] According to another aspect of the embodiments of the present application, a data processing device is provided, including:

[0024] A transceiver unit, configured to receive a first request from a user; the first request is used to request access to a first data set; the first data set and first metadata are stored in a secure database; the first metadata is the metadata of the first data set;

[0025] A verification unit, configured to verify the first data set and the first metadata;

[0026] An operation unit, used for allowing the user to perform normal access operations on the first data set if the verification passes;

[0027] A generating unit, used for generating a transaction record based on a normal access operation;

[0028] A storage unit used to store transaction records in a distributed ledger network.

[0029] In this embodiment, on the one hand, when receiving the first request from the user for accessing the first data set, the present application performs a multi-dimensional security check on the first data set and the first metadata, and only allows the user to access the first data set normally if the check passes. In this way, the multi-dimensional check process of the data set and metadata can be performed before the data set is used to ensure that the data used by the user is complete, secure, and not tampered with; on the other hand, the embodiment of the present application can also generate transaction records based on normal access operations, and store the transaction records in a distributed ledger network. In this way, the use of a distributed ledger network can not only ensure the traceability and persistence of transaction records, but also increase the transparency and trust of data. In summary, the technical solution provided by the embodiment of the present application can achieve all-round protection of data from two perspectives: before the data is used and after the operation is completed, which not only effectively guarantees the integrity and security of the data, but also enhances the transparency and traceability of data operations.

[0030] In an exemplary embodiment, the generating unit is specifically configured to: generate a transaction record based on the access information and the first metadata; wherein the access information includes the access operation type, the data accessor identifier, and the timestamp. In this embodiment, the access information can be guaranteed to be secure, transparent, and traceable, which is conducive to ensuring data security.

[0031] In an exemplary embodiment, the verification unit is specifically used to verify the first data set and the first metadata based on a first verification value; wherein the first verification value is generated by the first data set and the first metadata currently stored in the security database. In this embodiment, the first data set and the first metadata can be quickly verified at one time through the first verification value, which is simple, easy and efficient.

[0032] In an exemplary embodiment, before receiving the first request from the user, the transceiver unit is further used to receive the first data set and the first metadata; the generation unit is further used to generate the second verification value based on the first data set and the first metadata; the storage unit is further used to store the first data set, the first metadata and the second verification value in a security database. In this embodiment, the second verification value that can be used for security verification is pre-embedded when the data set is initially stored, which is conducive to simplifying subsequent processing and improving verification efficiency and data access efficiency.

[0033] In an exemplary embodiment, the verification unit is specifically configured to: determine the integrity of the first data set and the first metadata based on the consistency between the first verification value and the second verification value. This embodiment is simple, reliable, and highly accurate, which is conducive to ensuring data security.

[0034] In an exemplary embodiment, the operation unit is further configured to, when the verification fails, reject the user's access operation on the first data set and record it as an abnormal access operation; the generation unit is further configured to generate a transaction record based on the abnormal access operation. In this embodiment, it is ensured that all abnormal access operations are also safe, transparent, and traceable, which is conducive to subsequent utilization or analysis and ensures data security.

[0035] In an exemplary embodiment, the transceiver unit is further configured to: receive a second request; the second request is used to obtain the user's access operation on the first data set; the access operation includes a normal access operation and / or an abnormal access operation; obtain a transaction record from the distributed ledger network; and in response to the second request, return an audit report; wherein the audit report is generated based on the transaction record. This embodiment can provide data support for data auditing and ensure the accuracy and transparency of the audit report.

[0036] According to another aspect of the embodiments of the present application, another data processing device is provided, including:

[0037] A transceiver unit, configured to receive a transaction record, where the transaction record is generated based on the user's access operation on the first data set;

[0038] A generation unit, configured to generate a new block and the metadata of the new block based on the transaction record;

[0039] A broadcast unit, configured to broadcast the new block and the metadata of the new block to other nodes in the distributed ledger network.

[0040] In this embodiment, the transaction record is maintained through the distributed ledger network, and the distributed ledger network can maintain the transaction record on each distributed node respectively, which can not only ensure the traceability and persistence of the transaction record, but also increase the transparency and trust of the data, and ensure the transparency and traceability of the data operation.

[0041] In an exemplary embodiment, the generation unit is further configured to: before generating a new block and the metadata of the new block based on the access operation, determine the validity of the transaction record based on the consensus mechanism. In this embodiment, the consensus mechanism further ensures the consistency and security of the transaction record stored in the distributed ledger network.

[0042] According to another aspect of the embodiments of the present application, a data management system is provided, including:

[0043] A storage device for storing a first data set, metadata, and respective check values for verification.

[0044] A distributed ledger network for maintaining transaction records for the storage device.

[0045] A data management device for implementing the data management method of any embodiment of the present application.

[0046] According to another aspect of the embodiments of the present application, a distributed ledger network is provided. The distributed ledger network stores data based on a consensus mechanism.

[0047] The distributed ledger network includes: a plurality of nodes deployed distributively.

[0048] Any one of the nodes maintains a ledger copy, and the ledger copy is used to maintain transaction records for the storage device.

[0049] Any one of the nodes is used to execute the data management method of any of the above embodiments.

[0050] According to another aspect of the embodiments of the present application, a computing device is provided. The computing device includes a memory and a processor.

[0051] The memory and the processor are electrically connected.

[0052] The memory is used to store a computer program.

[0053] The processor is used to execute the computer program so that the computing device implements the data management method provided by any embodiment of the present application.

[0054] According to another aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program / instruction is stored. When the computer program / instruction is executed by a processor, the method of any of the above embodiments is implemented.

[0055] According to another aspect of the embodiments of the present application, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the method of any of the above embodiments is implemented.

[0056] It should be understood that both the foregoing general description and the following detailed description are exemplary and are intended to provide further explanation of the claimed technology. Description of the Drawings

[0057] The embodiments of the present application will become more apparent by describing them in more detail with reference to the accompanying drawings. The above and other objects, features, and advantages of the embodiments of the present application will become more obvious. The drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation to the present application. In the drawings, the same reference numerals generally represent the same components or steps.

[0058] Figure 1 It is a schematic diagram of the architecture of a data management system provided by an embodiment of the present application;

[0059] Figure 2 It is a schematic diagram of the architecture of another data management system provided by an embodiment of the present application;

[0060] Figure 3 It is a schematic flowchart of a data management method provided by an embodiment of the present application;

[0061] Figure 4 It is a schematic flowchart of another data management method provided by an embodiment of the present application;

[0062] Figure 5 It is a schematic flowchart of another data management method provided by an embodiment of the present application;

[0063] Figure 6 It is a schematic flowchart of a process for storing transaction records using a distributed ledger network provided by an embodiment of the present application;

[0064] Figure 7 It is a block diagram of the structure of a data management device provided by an embodiment of the present application;

[0065] Figure 8 It is a block diagram of the structure of another data management device provided by an embodiment of the present application;

[0066] Figure 9 It is a hardware block diagram of a computing device provided by an embodiment of the present application. Detailed implementation manners

[0067] In order to make the objectives, technical solutions, and advantages of the present application more apparent, exemplary embodiments according to the present application will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. It should be understood that the present application is not limited by the exemplary embodiments described herein.

[0068] The embodiments of the present application are directed to data management scenarios, which may include, for example, but are not limited to, specific scenarios such as data storage, data usage, and related data maintenance, and are used to improve the security and traceability of data during use and storage, and ensure the security of the entire data system.

[0069] As described in the background art, the related art relies on encryption technology to protect data, but this data protection mechanism has deficiencies in terms of data security, traceability, etc. For example, in the related art, encryption algorithms are used to secure data, but the security of the encryption algorithm depends on key management, and once the key is leaked, the security of the entire system will be threatened. In addition, this method cannot effectively prevent internal attacks, and its ability to guarantee the long-term integrity of data is limited. Moreover, due to the lack of transparency and traceability, it is difficult to trace the specific responsible person and the time point when data problems occur once they arise.

[0070] In view of the above problems, the embodiments of the present application provide a new design concept: the storage device maintains the data set, and the distributed ledger network maintains the transaction records for the storage device; in the specific data management strategy, multi-dimensional verification is performed on the data set and metadata before data use to comprehensively ensure that each metadata is complete and not tampered with; after any operation on the storage device is completed, the distributed ledger network is used to maintain the transaction records to ensure that any operation on the storage device is transparent and traceable. In this way, the embodiments of the present application can provide a highly secure data processing environment, ensure the integrity and security of data during transmission and storage, and at the same time enhance the transparency and traceability of data operations. The following is a specific description.

[0071] For ease of understanding, please refer to Figure 1 , Figure 1 which is a schematic diagram of the architecture of a data management system provided by an embodiment of the present application. As Figure 1 shown, the data management system 100 includes: a data management device 110, a distributed ledger network 120, and a storage device 130.

[0072] Among them, the storage device 130 is used to store the first data set and the first metadata.

[0073] In a feasible implementation, a secure database is set in the storage device 130 for storing the first data set and the first metadata. The secure database can adopt security measures, such as protecting the security of data storage and access through encryption measures and permission verification, etc.

[0074] The first data set is used to store data, that is, the first data set can include one or more pieces of data. In the embodiments of the present application, there are no specific restrictions on the type, source, data content, etc. of the data stored in the first data set; for example, the first data set can be a business data set for storing business data, or a management data set for storing management data; for another example, the data in the first data set can come from a business party, or a management party, or can be automatically generated by the system; for another example, the data in the first data set can be financial business data, or medical business data, or can also be government business data or others, without exhaustive listing.

[0075] In an exemplary embodiment, the type of the first data set may also include, but is not limited to, one or more of the following: government business data set, financial business data set, medical business data set, Internet of Things data set, enterprise information data set. For example, the first data set can be a data set for banking business data, and the first data set can include various banking business data.

[0076] In the present application, metadata (i.e., Metadata) can be used to describe a data set. In other words, a first data set corresponds to a first metadata, and the first metadata is used to describe the first data set. Specifically, metadata can describe a data set from one or more dimensions such as data set identifier (i.e., data set ID), size, storage location, creation time, creator, latest access time, etc. For example, for a determined data set, the data set name, size, and creation time can be extracted and composed into a piece of metadata, and this metadata is used to describe the data set.

[0077] In addition, in the embodiments of the present application, there are no specific restrictions on the type and storage method of the storage device 130. The storage device 130 can be any hardware or system with data storage capabilities. In addition, in some possible embodiments, a software management system, such as a database system, a security database, etc. (the name is not limited), can also be deployed on the storage device 130, and there are no specific restrictions in the embodiments of the present application.

[0078] As Figure 1 shown in the distributed ledger network 120, it is used to maintain the transaction records for the storage device 130.

[0079] The distributed ledger network 120 is used to maintain a distributed ledger. The distributed ledger can be regarded as a decentralized database, which allows transaction data (in the embodiments of the present application, the transaction data stored using the distributed ledger is specifically: the transaction records for the storage device 130) to be stored and synchronized at multiple locations. Compared with a centralized database, the distributed ledger has no single management agency or central server. Therefore, the distributed ledger can be specifically represented as multiple ledger copies, and the data maintained by any two copies is the same.

[0080] The distributed ledger network 120 generally may include multiple nodes deployed distributively (which may also be referred to as distributed nodes), and any one of the nodes maintains a copy of the distributed ledger (hereinafter simply referred to as the ledger copy), and the ledger copy is used to maintain transaction records for the storage device 130.

[0081] In the embodiments of the present application, the distributed ledger network 120 may store data based on a consensus mechanism. Among them, the consensus mechanism means that the participants in the distributed system (each node of the distributed ledger network 120) can reach a consensus on a certain state (in the embodiments of the present application, that is, the transaction records to be stored). Based on this, in the distributed ledger network 120 involved in the embodiments of the present application, it can be ensured that the data maintained by any two ledger copies (that is, the transaction records for the storage device 130) are the same. The implementation manner will be described in combination with specific management solutions later, and will not be elaborated here.

[0082] As Figure 1 shown, the data management device 110 can perform data interaction with the distributed ledger network 120 and the storage device 130 respectively. In this way, the data management device 110 can not only manage the data stored in the storage device 130 to facilitate providing data services for users, and moreover, the data management device 110 can also record the operation data made by the front end on the storage device 130 and maintain the transaction records in the distributed ledger network 120. In other words, the data management device 110 can be regarded as the data management entity among the user side, the data side (that is, the storage device 130), and the recording side (that is, the distributed ledger network 120), and is used to realize the organic interaction among the three parties. While providing complete and accurate data services for users, it realizes all-round data security management before and after data use, ensuring both data security and its transparency and traceability.

[0083] From the perspective of the hardware architecture, the data management device 110 may include a front-end server and a back-end server. Among them, the front-end server runs a front-end application program, that is, the front-end application program can be carried on the front-end server. In a specific implementation scenario, the front-end server and the back-end server may be the same server, or may also be different servers, and the embodiments of the present application have no special restrictions on this.

[0084] For the convenience of exemplary description, the data management device 110 will be described from two perspectives of the front-end application program and the back-end server below. For the convenience of understanding, please refer to Figure 2 , Figure 2 which is the schematic diagram of the architecture of another data management system provided by the embodiments of the present application. As Figure 2 shown, the data management device 110 includes: a front-end application program 111 and a back-end server 112. AsFigure 2 As shown, the front-end application 111 is carried on the front-end server or can also be carried on the back-end server to provide data services for users; while the back-end server 112 can interact with the front-end application 111 and specifically implement the interaction and data management with the storage device 130 and the distributed ledger network 120.

[0085] As Figure 2 shown, users can initiate requests to the front-end application 111 through the user interface. For example, they can request to upload a data set or, for another example, request to access a data set. The front-end application 111 passes the user request to the back-end server 112. The back-end server 112 performs a security check on the data stored in the storage device 130 and then returns a result to the user through the front-end application 111 after the check passes (such as providing data or returning a stored notification, etc.). In addition, the back-end server 112 also sends a transaction record to the distributed ledger network 120 to store the transaction record using the distributed ledger network 120; after the distributed ledger network 120 completes the storage and maintenance of the transaction record, it can also return a feedback result to the back-end server 112.

[0086] It should be noted that between the distributed ledger network 120 and the data management device 110, they can be two independent systems or devices. Or, the data management device 110 can also be used as any node of the distributed ledger network 120 to achieve the purpose of maintaining transaction records using the distributed ledger network, which will be specifically described later in combination with specific implementation methods.

[0087] An embodiment of the present application provides a data management method, which can be applied to a data management device as Figure 1 or Figure 2 shown. Please refer to Figure 3 , Figure 3 which is a schematic flowchart of a data management method provided by an embodiment of the present application.

[0088] As Figure 3 shown, the data management method includes:

[0089] S301, receiving a first request from a user; the first request is used to request access to a first data set; the first data set and first metadata are stored in a storage device; the first metadata is the metadata of the first data set.

[0090] Among them, the first data set can be any one (or more) of the data sets stored in the storage device. There are no special restrictions on its type, data content, etc. in this application, and reference can be made to the foregoing text. There are various possible situations for providing services externally using the first data set in the storage device, and the data services that can be provided externally may include, but are not limited to, storage services, query services or retrieval services, and editing services (such as modification, deletion). In addition, providing services externally using the first data set in the storage device can be a passive service provided based on the request of the user side or other requesting parties (such as other connected external systems), or an active service (for example, the data management device can automatically retrieve the data stored in the storage device based on any possible situations such as page display and self-executed data analysis). There are no special restrictions in this application.

[0091] In addition, the first request is used to request access to the first data set, and it can specifically be used to request one or more processes such as querying, modifying, and deleting the first data set. In other words, the first request can specifically be a query request, a modification request, a deletion request, etc. for the first data set.

[0092] S302, verify the first data set and the first metadata.

[0093] In the embodiments of this application, multi-dimensional security verification is performed on the first data set and its first metadata, and the purpose is to verify the integrity and security of the first data set. Specifically, the verification principle here is that if the first data set currently stored in the storage device is consistent with the first data set initially stored in the storage device, it indicates that the first data set is complete and has not been tampered with. Based on this principle, both the first data set and the first metadata can be used to achieve the security verification of the first data set in this step.

[0094] Regarding the first data set, if the current first data set is consistent with the first data set initially stored in the storage device, it proves that the first data set is complete and has not been tampered with. Regarding the first metadata, it is specifically used to describe the first data set. If the first data set has been tampered with, its first metadata may also change accordingly. For example, if an illegal user modifies the name of the first data set, the first metadata currently stored in the storage device will be different from the metadata corresponding to the first data set initially stored, and thus it can also be verified whether the first data set has been tampered with.

[0095] Based on the above principle, when performing security verification in this application, it is not limited to a single verification of the data set, but rather multi-dimensional verification is performed on the data set and the metadata corresponding to the data set, and multi-dimensional verification is achieved from two dimensions: the data set dimension and the metadata dimension, so as to ensure that the data set is complete and has not been tampered with.

[0096] Among them, multi-dimensional verification means verifying the data set separately from different data dimensions (i.e., data set dimension, metadata dimension), but this application has no special restrictions on the order of multi-dimensional verification. In other words, when this step is executed, the security verification of the first data set can be performed first, and then the security verification of the first metadata can be performed, or vice versa, first verifying the first metadata and then verifying the first data set, or verifying them simultaneously, all of which are acceptable. When specifically implementing the verification, it can be directly achieved through data direct comparison, or through data processing and then using the processed information for comparison to achieve verification; in addition, the first data set and the first metadata can be verified separately, or the two can be combined for one-time verification, and the embodiments of this application have no special restrictions on this. Specific descriptions will be provided later and will not be elaborated here for the time being.

[0097] S303, in the case where the verification is passed, allow the user to perform normal access operations on the first data set.

[0098] This application verifies the first data set and its first metadata before providing normal data services to the user. Thus, when both the first data set and the first metadata pass the verification and it is determined that the verification is passed, the security of the first data set can be determined, and the first data set can be provided externally, allowing the user to perform normal access operations on the first data set.

[0099] On the contrary, if any one or more of the first data set or the first metadata fail to pass the verification, it indicates that the first data set may have been tampered with. At this time, the data management device can refuse to provide the data externally. In other words, this method may further include: in the case where the verification fails, refusing the user's access operation to the first data set. Specific descriptions will be provided later and will not be elaborated here for the time being.

[0100] For example, when the user requests to access any one of the first data sets stored in the storage device, after receiving the access request, the data management device can perform multi-dimensional verification on the first data set and the first metadata. When the multi-dimensional verification result indicates that the first data set is complete and has not been tampered with, the first data set is provided to the user. In this way, the user can access the first data set and perform operations such as editing, querying, and deleting on it.

[0101] S304, generate a transaction record based on the normal access operation.

[0102] Specifically, based on the foregoing processing, the user can perform normal access operations on the first data set. Based on this, in a possible embodiment of this application, a transaction record can be generated based on the access information and the first metadata.

[0103] Among them, the access information may include, but is not limited to, the access operation type, the data visitor identifier, and the timestamp. Among them, the operation type may include, but is not limited to: access, query, modification, deletion, storage, etc., without exhaustive listing. The data visitor identifier is used to uniquely identify the data visitor and can be uniquely identified by the operator ID, the operator name or surname, the code name, etc. The timestamp is used to represent the data access time. For example, whenever any data set stored in the storage device is accessed or modified, the data management device can record a transaction record containing information such as the operation type, the timestamp, the operator ID, and the metadata, and ensure that all operations on the first data set are traceable through the transaction record to ensure data security.

[0104] In this way, whenever any operation (such as reading, modifying, deleting, etc.) occurs on the data set, the data management device can generate a transaction record containing information such as the operation type, the timestamp, the operator ID, etc. and the necessary metadata, and store it in the distributed ledger network.

[0105] S305, Store the transaction record in the distributed ledger network.

[0106] The embodiment of the present application uses the distributed ledger network to maintain the transaction record for the data stored in the storage device.

[0107] Specifically, a distributed ledger is maintained in the distributed ledger network, and the distributed ledger is used to maintain the transaction record for the data set stored in the storage device. Moreover, the distributed ledger network generally maintains data based on a consensus mechanism. In this way, only when all nodes in the distributed ledger network reach an agreement on the data to be stored, will they record it in the distributed ledger copy they maintain, thereby ensuring that the ledger copy contents maintained by any two nodes in the distributed ledger network are consistent. In this way, even if some nodes may be attacked or the ledger copies of some nodes are tampered with, it will not cause a global impact, and the accurate, transparent, and traceable transaction record information can still be obtained according to the distributed ledger network.

[0108] In specific implementation, the data management device can broadcast the transaction record to all nodes in the distributed ledger network, or send the transaction record to a node in the distributed ledger network. How the distributed ledger network maintains the transaction record will be specifically described later and will not be elaborated here for the time being.

[0109] Thus, this application uses distributed ledger technology to record the transaction records of all data sets, implementing a fully traceable audit mechanism that facilitates administrators or auditors to query the operation history of data sets at any time, ensuring the transparency and credibility of data sets. Moreover, in a distributed ledger network, each node maintains a complete copy of the data set and its transaction records, enhancing data security and redundancy. Even if a node fails, it will not affect the overall integrity of the data. In addition, the distributed ledger network has good scalability and can dynamically expand the number of nodes as the business needs grow to support the maintenance of more data set transaction records.

[0110] In summary, on the one hand, when this application receives a first request from a user to access a first data set, it performs multi-dimensional security verification on the first data set and the first metadata, and only allows the user to perform normal access operations on the first data set when the verification passes. In this way, through the multi-dimensional verification process of the data set and metadata before the data set is used, it can be ensured that the data used by the user is complete, secure, and not tampered with. On the other hand, the embodiments of this application can also generate transaction records based on normal access operations and store the transaction records in a distributed ledger network. In this way, using the distributed ledger network can not only ensure the traceability and persistence of transaction records, but also increase data transparency and trust. Generally speaking, the technical solutions provided by the embodiments of this application can achieve all-round protection of data from two perspectives: before data use and after operation completion, effectively ensuring data integrity and security, and enhancing data operation transparency and traceability.

[0111] Next, it specifically describes how to verify the first data set and the first metadata. As mentioned above, the first data set and the first metadata can be verified separately or verified at one time.

[0112] In one embodiment, the two can be verified separately, and the verification methods can include: direct data comparison, or generating a verification value based on the data and then comparing the verification values.

[0113] Exemplarily, in one embodiment, the first data set currently stored in the storage device is directly compared with the initially stored first data set, the first metadata is extracted from the first data set currently stored in the storage device, and the first metadata is directly compared with the first metadata corresponding to the initially stored first data set. In this way, it is directly verified whether the first data set has been tampered with through the comparison result. It should be understood that if the first data set and the first metadata are consistent after comparison, the verification passes; otherwise, if any one or all of them are inconsistent, the verification fails. In this way, the separate verification of the two is realized, and the verification order is not limited.

[0114] Exemplarily, in another embodiment, the first data set can be verified based on the third verification value, and the first metadata can be verified by the fourth verification value. Wherein, the first verification value is generated from the first data set currently stored in the storage device; the fourth verification value is generated from the first metadata corresponding to the first data set currently stored in the storage device. In this way, the integrity of the first data set and the first metadata can be determined based on the consistency between the third verification value and the fifth verification value, and the consistency between the fourth verification value and the sixth verification value. Wherein, the fifth verification value is generated from the first data set initially stored in the storage device, and the sixth verification value is generated from the first metadata corresponding to the first data set initially stored in the storage device. It should be understood that the generation methods of the third verification value and the fifth verification value, and the fourth verification value and the sixth verification value can be the same, but the generation methods of the third verification value and the fourth verification value can be the same or different.

[0115] Exemplarily, in another embodiment, the first data set can be verified based on the third verification value, and the verification of the first metadata can be achieved by comparing the first metadata corresponding to the first data set currently stored in the storage device with the first metadata corresponding to the first data set initially stored. Alternatively, the first data set can be verified by comparing the first data set currently stored in the storage device with the first data set initially stored, and the first metadata can be verified by the third verification value. In this way, the separate verification of the two is realized, which will not be elaborated.

[0116] In addition, exemplarily, in another embodiment, the first data set and the first metadata can be verified based on the first verification value. Wherein, the first verification value is generated from the first data set and the first metadata currently stored in the storage device.

[0117] In this embodiment, the first data set and the first metadata currently stored in the storage device can be obtained, processed according to a preset data processing method to obtain the first verification value, and thus, the one-time and multi-dimensional security verification of the two can be realized through the first verification value. Specifically, when the first data set is initially stored in the storage device, the processing results of the initially stored first data set and the first metadata by adopting the same data processing method can be obtained to get the second verification value. Thus, the integrity of the first data set and the first metadata can be determined based on the consistency between the first verification value and the second verification value. That is, if the first verification value and the second verification value are consistent, the verification passes; otherwise, if the two are inconsistent, the verification fails.

[0118] In other words, the first verification value and the second verification value are generated based on the first data set and the first metadata in different periods, but their generation methods are the same. There are no special restrictions on the calculation method and data type of the verification value in this application. In the actual implementation scenario, it can be obtained through a hash algorithm or other methods using custom rules or algorithms. In other words, the first verification value may include, but is not limited to: a hash value, a numerical value obtained by processing data (i.e., the first data set and the first metadata) using custom rules or algorithms. Taking the hash value as an example, there are no special restrictions on the hash algorithm in this application, and any hash algorithm that can obtain the hash value based on the original data can be used, such as SHA-256.

[0119] In this application, the integrity of the first data set and its first metadata is verified by using the consistency between the first verification value and the second verification value before data usage. The first verification value is calculated based on the current data stored in the storage device before the data provides services externally. This calculation can be offline or online. The second verification value is the verification value corresponding when the first data set is initially stored in the storage device. Therefore, the second verification value can be calculated when the first data set is initially stored in the storage device and maintained by the storage device or the data management device. When performing this verification step, there is no need to recalculate the second verification value, and the data can be directly read from its storage location.

[0120] In a possible embodiment of this application, the storage device can be used to associatively store the first data set, its metadata, and the second verification value. In other words, when the data set is initially stored, the corresponding metadata and the second verification value of the data set can be stored together.

[0121] At this time, in an exemplary embodiment, before receiving the first request from the user, the method further includes:

[0122] Receiving the first data set and the first metadata;

[0123] Generating a second verification value based on the first data set and the first metadata;

[0124] Storing the first data set, the first metadata, and the second verification value in the storage device.

[0125] In this embodiment, after receiving the first data based on the first metadata, the data management device does not simply store it, but processes the data, generates a second verification value based on the first data set and the first metadata, and thus stores the first data set, the first metadata, and the second verification value in the storage device together. In this way, when a user requests to access the first data set later, the integrity of the first data set and the first metadata can be verified based on the consistency between the first verification value and the second verification value.

[0126] This application has no special restrictions on the storage method of storing the first data set, the first metadata, and the second check value in the storage device. For example, the associated storage can be implemented by the key-Value method. Another example is that it can be stored in tabular form. Another example is that the second check value can be stored as an associated attribute or associated information of the first data set. Another example is that the second check value and the first data set can be stored in an associated manner at a storage location. This is not an exhaustive list.

[0127] Thus, in an embodiment of this application, during the initialization stage of any data set, the data management device can use a secure hash algorithm to calculate the hash value set of the data set and its metadata (as the second check value), and store the hash value set in the storage device. Thus, before using the data set each time, the data management device can use the data set and metadata currently stored in the storage device to recalculate the current hash value set corresponding to the data set (i.e., the first check value), and compare it with the hash value stored in the database to verify the integrity of the data set and metadata.

[0128] In addition, in another possible embodiment, if the first data set and the first metadata initially stored in the storage device can be read through a distributed ledger network or other means, when the data storage device receives the first data set and the first metadata, it can also directly store them in the storage device. When performing the verification of this step, it can directly generate the second check value based on the first data initially stored in the storage device and the first metadata for verification.

[0129] It should be understood that the third check value and the fifth check value, and the fourth check value and the sixth check value in the foregoing embodiments can be processed in a similar manner to the above embodiments, and will not be repeated here.

[0130] In summary, the embodiments of this application can perform security verification on the first data set and the first metadata from the two perspectives of the data set and the metadata before providing normal data services to users. When it is determined that both are complete and not tampered with, it allows normal access operations by users, ensuring that the data accessed by users is true and correct, and effectively ensuring data security. Moreover, this application further generates transaction records based on normal access operations, further ensuring that the operation process for data is transparent and traceable, and ensuring data security.

[0131] In addition, in the embodiments of this application, if the verification in S302 fails, in addition to rejecting the user's access operation to the first data set, a transaction record can also be generated accordingly. In one possible embodiment at this time, the method may further include:

[0132] In the case where the verification fails, reject the user's access operation to the first data set and record it as an abnormal access operation;

[0133] Generate transaction records based on abnormal access operations.

[0134] In other words, in the embodiments of the present application, in addition to generating transaction records for normal access operations, transaction records are also generated for abnormal access operations, and the distributed ledger network is also used to maintain these transaction records, so that all operations on the first data set are recorded, facilitating subsequent use or analysis.

[0135] In addition, in the embodiments of the present application, the data management device further provides a function of querying transaction records externally. In this way, when an administrator or auditor needs to query historical operations, accurate query can also be realized through the data management device, truly realizing traceable query of transaction records. At this time, for the data management device, the data management method it executes may further include the following steps:

[0136] Receive a second request; the second request is used to obtain the access operation of the user on the first data set; the access operation includes normal access operations and / or abnormal access operations;

[0137] Obtain transaction records from the distributed ledger network;

[0138] In response to the second request, return an audit report; wherein, the audit report is generated based on the transaction records.

[0139] Among them, the initiator of the second request in the present application is not limited. For example, it can be an auditor or an administrator or an ordinary user; but in actual scenarios, in order to facilitate data security management, permissions can also be configured for users. For example, some users (not particularly limited in the present application, such as administrators, some managers, auditors, etc.) are configured with the permission to query transaction records. Then, after receiving the second request, the data management device can also verify the identity of the initiator to feedback the query result to the authorized users.

[0140] In the present application, the user can also indicate the type of access operation requested in the second request. For example, the user can only request to obtain the abnormal access operations on the first data set, or only request to obtain the normal access operations on the first data set. Of course, the user can also request to obtain all access operations on the first data set.

[0141] In addition, the form of the query result feedback by the data management device in the present application is not limited. For example, a detailed audit report can be generated according to the query result and presented to the user to ensure the transparency and traceability of the operations on the data set. Another example is that the query result can be directly output to the user without special processing. In addition, presenting the query result can be realized through a front-end application using an interactive interface, which will not be elaborated.

[0142] Another data management method is provided in an embodiment of the present application. This method can be applied to any node in a distributed ledger network such as Figure 1 or Figure 2 shown. Please refer to Figure 4 , Figure 4 , which is a schematic flowchart of another data management method provided in an embodiment of the present application.

[0143] As shown in Figure 4 , this data management method includes:

[0144] S401. Receive a transaction record, where the transaction record is generated based on a user's access operation on a first data set.

[0145] As described above, the transaction record can be sourced from a data management device, which can specifically include: normal access operations and / or abnormal access operations. For relevant descriptions, please refer to the above, and details will not be elaborated.

[0146] S402. Generate a new block and metadata of the new block based on the transaction record.

[0147] S403. Broadcast the new block and the metadata of the new block to other nodes in the distributed ledger network.

[0148] In the present application, any node in the distributed ledger network, after receiving a transaction record, can directly generate a new block and broadcast it across the network in the manner shown in Figure 4 so that the new block and the metadata of the new block are maintained in the distributed ledgers maintained by each node in the distributed ledger network.

[0149] Alternatively, in another possible embodiment, before executing S402, the method may further include: determining the validity of the transaction record based on a consensus mechanism.

[0150] Based on the consensus mechanism, for any node in the distributed ledger network, any node is used to perform data verification on the transaction record, and when the data verification is passed, the transaction record is added to the ledger copy; the data verification includes at least: consensus verification.

[0151] Among them, consensus verification is used to verify whether the data to be processed by each node in the distributed ledger network (i.e., the transaction records to be stored in this application scenario) reaches global consistency. As mentioned above, the standard for achieving global consistency in this application can be: most nodes in the distributed ledger network reach a consensus, which may specifically include, but is not limited to, that the number of nodes reaching a consensus is greater than or equal to a preset number threshold, or the proportion of nodes reaching a consensus among all nodes is greater than or equal to a preset proportion threshold. This is because there may be situations where some nodes in the distributed ledger network fail or are maliciously attacked. Therefore, when most nodes reach a consensus, it is considered that they have passed the consensus verification. In this way, this application uses the consensus mechanism to verify the validity of transaction records, ensuring that only legitimate transaction records can be packaged into blocks and added to the ledger, enhancing the data protection ability.

[0152] In specific implementation, consensus verification can be performed through methods such as proof of work (PoW) and / or proof of stake (PoS) to verify whether the transaction records received by each node are consistent. If, based on consensus verification, the content of the transaction records to be stored by each node in the distributed ledger network is consistent, then each node can add them to the ledger copy it maintains.

[0153] In addition to consensus verification, any node in the distributed ledger network can further process or perform other verifications on the transaction records to be stored.

[0154] In an exemplary embodiment, the data verification that any node in the distributed ledger network can perform on the transaction records to be stored may further include, but is not limited to, at least one of the following: formal verification, validity verification.

[0155] Among them, formal verification is used to verify whether the data to be processed meets the preset formal requirements. For example, verifying whether the format of the transaction record meets the preset requirements (i.e., whether the format is correct), or, for another example, verifying whether the signature of the transaction record is valid, etc. This application has no special restrictions on the specific content and method of formal verification, and it can be customized in the actual scenario. For example, if the preset formal requirement is that the transaction record needs to have a timestamp and metadata, then during the verification stage, it can be verified whether the transaction record has these two pieces of information. This kind of verification is a formal preliminary verification.

[0156] Among them, validity verification is used to verify whether the data to be processed is valid. Validity verification is specifically used to verify whether the transaction records to be stored meet the preset system rules and logics, which can be regarded as a content verification method. Among them, the system rules and logics can also be customized, and there are no special restrictions in this application. Still taking the timestamp in the above text as an example, in this step, it is to verify whether the time of the timestamp is valid and whether it conforms to the time rule. For example, if the timestamp is a time that has not arrived after the current moment, then the timestamp is invalid and fails the validity verification.

[0157] Therefore, in a possible embodiment, for any node in the distributed ledger network, when it is used to perform formal verification, validity verification, and consensus verification on the transaction records to be stored, the order of the three verifications is not limited, and they can be executed simultaneously or sequentially; however, it should be understood that only when the transaction records to be stored meet all the above three verifications, each node will add them to the ledger copy; if one of the verifications fails, there is no need to store the transaction record.

[0158] In addition, as mentioned above, the distributed ledger copies maintained by each node are used to maintain transaction records, and the maintenance method is not limited.

[0159] In a possible embodiment, in order to further ensure the security of the transaction records maintained by the distributed ledger network, in this application, the distributed ledger copy can maintain data in the form of blocks or blockchains. In other words, any ledger copy includes at least one block, and any block includes: transaction records, identification information of the previous block. Among them, the identification information of the previous block can have various possible forms. For example, it can include but is not limited to: the hash value of the previous block, the transaction record list, etc., without exhaustive listing.

[0160] In this way, in this embodiment, for any node, if the transaction record to be stored has passed the aforementioned data verification, the node can be used to package the transaction record into a new block and save it.

[0161] Alternatively, in another possible embodiment, to further ensure the security of the new block, the nodes in the distributed ledger network can also be used to package the transaction records into a new block, perform data verification on the new block, and save the new block when the data verification is passed. Among them, the description of the data verification method is the same as before and will not be elaborated here; however, the data verification method for the new block here and the data verification method for the transaction records to be stored can be the same or different, but both can include consensus verification. For example, in an actual implementation scenario, the nodes in the distributed ledger network can perform data verification on the transaction records in the aforementioned three ways. After passing, the nodes can also package the transaction records into a new block, broadcast the new block to the network, and further perform one or more of the above three ways to perform data verification on the new block. When the verification is passed, each node in the distributed ledger network saves the new block in the ledger copy maintained by itself, realizing the secure maintenance of the transaction records.

[0162] In addition, there is no special restriction on the relationship between the distributed ledger network and the data management device in the embodiments of the present application. For example, the data management device can be used as a node in the distributed ledger network to execute the foregoing method and use the distributed ledger network to store transaction records. At this time, as Figure 4 shown, S401 can be specifically: obtaining transaction records based on normal access operations and / or abnormal access operations; or, the data management device and the distributed ledger network can also be independent of each other. The data management device can have the ability to store data in the distributed ledger network, but does not participate in the data verification and storage processing as one of the nodes.

[0163] Based on these two situations, when the data management device specifically implements the foregoing S304, there are two possible implementation methods as follows:

[0164] In the first implementation method, the data management device and the distributed ledger network are independent of each other. At this time, for any transaction record of the storage device, the data management device can broadcast the transaction record in the distributed ledger network, or send the transaction record to a node in the distributed ledger network. Thus, the nodes in the distributed ledger network can receive the broadcast and perform subsequent data verification and storage and other related processing, and then realize maintaining the transaction records in the distributed ledger.

[0165] In the second implementation, the data management device can be a node of the distributed ledger network. At this time, for any transaction record of the storage device, as a node of the distributed ledger network, the data management device can broadcast the transaction record in the distributed ledger network and perform data verification on the transaction record. Thus, when the data verification is passed, the transaction record is added to the ledger copy. In other words, when the data management device is a node in the distributed ledger network, it can perform related processes such as data verification of transaction records, packaging new blocks, data verification of new blocks, and storing new blocks in the manner described above, which will not be repeated here.

[0166] This application maintains transaction records through a distributed ledger network. The distributed ledger network can maintain transaction records on each distributed node respectively, which can not only ensure the traceability and persistence of transaction records, but also increase the transparency and trust of data, and guarantee the transparency and traceability of data operations.

[0167] Generally speaking, through the interaction and cooperation between the data management device and the distributed ledger network, the secure recording of the transaction records of the storage device can be realized based on the consensus mechanism. Thus, it is ensured that all transaction records for the storage device are transparent and traceable.

[0168] This application combines hash technology, storage device management, and distributed ledger technology to give full play to the technical advantages and provide users with a more comprehensive and efficient data integrity verification and security management solution. This data management solution can not only be used in the IT field, but also be extended to information systems in other important industries such as government data sharing systems, financial data exchange platforms, and medical information systems, and can ensure the security and integrity of data without affecting system performance.

[0169] To understand this solution more clearly, this application further provides the following possible embodiments.

[0170] Exemplarily, please refer to Figure 5 , Figure 5 which is a schematic flowchart of another data management method provided by an embodiment of this application. As Figure 5 shown, this method includes:

[0171] In the dataset initialization stage:

[0172] S1, the user uploads a dataset through the front-end application.

[0173] The front-end application can pass the dataset and its upload request (or storage request, that is, the first request mentioned above) to the back-end server.

[0174] S2, the back-end server receives the dataset and calculates the hash value set (that is, the second verification value mentioned above).

[0175] S3. The backend server stores the calculated hash value (i.e., the second check value) together with the metadata of the dataset in the storage device. In this way, the storage device can associate and store the dataset, metadata, and the second check value.

[0176] Before using the dataset, perform a security check on the dataset. Specifically, it may include the following steps:

[0177] S4. The user requests to access or use a certain dataset and sends a usage request (i.e., the first request mentioned above) through the front-end application.

[0178] S5. The backend server recalculates the hash value set (i.e., the first check value) corresponding to the dataset based on the data currently stored in the storage device.

[0179] S6. The backend server verifies the integrity and security of the dataset and metadata based on the first check value. That is: compare the current hash value with the hash value stored in the storage device, that is, compare the first check value with the second check value.

[0180] S7. The backend server gives feedback on the usage request based on the verification result, that is, gives the feedback result. Specifically, if the hash values are the same, the user is allowed to use the dataset, that is, respond to the user's usage request; otherwise, if the hash values do not match, access is refused and the abnormal situation is recorded.

[0181] After the operation on the storage device is completed, use the distributed ledger network to maintain the transaction record, including the following steps:

[0182] S8. Whenever a dataset is accessed or modified, the backend server can record a transaction record (which can also be called an operation record) containing information such as the operation type, timestamp, operator ID, metadata, etc.

[0183] S9. The backend server broadcasts the transaction record in the distributed ledger network so that the distributed ledger network can maintain the transaction record.

[0184] S10. Each node in the distributed ledger network verifies the transaction record through the consensus mechanism. As mentioned above, in addition, the nodes in the distributed ledger network can further perform other data validations on the transaction record.

[0185] S11. When the data verification is passed, the node packs the transaction record into a new block and broadcasts it to all nodes in the distributed ledger network.

[0186] S12. Each node in the distributed ledger network adds the new block to the copy of the distributed ledger it maintains, that is, stores the new block, to ensure the integrity and immutability of the transaction records for the storage device.

[0187] Further, the data management device can also provide data tracking and auditing functions, which may include the following operations:

[0188] S13. The administrator or auditor can send a query request (i.e., the second request mentioned above) through the query interface provided by the front-end application to request to query or trace the transaction records for the storage device or one or more data sets.

[0189] S14. The back-end server generates a detailed audit report based on the query results and displays it through the front-end application, that is, displays the query results, to ensure the authenticity and transparency of the data set operations.

[0190] In addition, please also refer to Figure 6 , Figure 6 which is a schematic flowchart of a process for storing transaction records using a distributed ledger network provided in an embodiment of this application. Before this process is implemented, a distributed ledger network structure composed of multiple nodes is constructed in advance. Each node is deployed with the same software environment, and each node maintains a copy of the distributed ledger by itself. This ledger copy is used to maintain the transaction records for the storage device. The distributed ledger copy is established based on a consensus mechanism and can be used to record the transaction records that all nodes have reached an agreement on.

[0191] In this way, the subsequent storage process can be executed. As Figure 6 shown, this process may specifically include the following steps:

[0192] S1. When a data set is accessed or modified in the data set initialization phase, the back-end server (or data management device) generates a transaction record containing information such as the operation type, timestamp, operator ID, etc. and attaches metadata.

[0193] S2. The back-end server broadcasts this transaction record to all nodes in the distributed ledger network.

[0194] S3. The nodes in the distributed ledger network receive the transaction record and start data verification.

[0195] Specifically, each node first performs a preliminary verification on the transaction record (i.e., the formal verification mentioned above) to ensure that its format is correct, the signature is valid, etc. Then, it performs a validity verification on the transaction record to ensure that it conforms to the system rules and logic. After the verification passes, a consensus verification is performed. When specifically implemented, a node (as a consensus node) can be used to make a comparison and judgment, or, a global broadcast method where each node makes a comparison and judgment separately can be used to implement the consensus verification.

[0196] The node compares the data of all nodes received, and determines whether the received data is consistent; if the data of all nodes (or most nodes) in the network is consistent, it is considered that the transaction record passes the consensus verification.

[0197] S4. The node packages the transaction record into a new block. The new block carries the aforementioned transaction record and may further append information such as the hash value of the previous block.

[0198] S5. The node broadcasts the new block to all nodes and the consensus ledger in the network.

[0199] S6. The node performs data verification on the new block.

[0200] Specifically, it includes: the node makes a preliminary verification on the new block to ensure that its format is correct and the signature is valid, etc., and then further verifies the validity of the transaction record to ensure that it conforms to the system rules and logic.

[0201] In addition, the consensus ledger compares all node data received, that is, consensus verification.

[0202] S7. If it passes the verification, it is considered that the new block is valid and stores the new block to ensure the immutability of the data. In the specific implementation process, data backup processing can also be performed to ensure the security of the data.

[0203] In summary, this application combines the advantages of hash value verification and distributed ledger technology. The present invention provides an efficient data verification and management system, which can ensure the security and integrity of data without affecting the system performance.

[0204] In addition to the above data management system and data management method, this application further provides a distributed ledger network, which stores data based on a consensus mechanism;

[0205] Such as Figure 1 or Figure 2 shown, the distributed ledger network includes: multiple nodes deployed distributively;

[0206] Any one of the nodes maintains a ledger copy, and the ledger copy is used to maintain transaction records for storage devices;

[0207] Any one of the nodes is used to execute the data management method performed by the distributed node in any of the foregoing embodiments.

[0208] In this embodiment, any one of the nodes in the distributed ledger network can be used as a data management device to implement the foregoing data management method. For other descriptions, please refer to the foregoing, and details are not described herein.

[0209] In addition, the present application also provides a data management device. Figure 7 It is a structural block diagram of a data management device provided by an embodiment of the present application. As Figure 7 shown, the data management device 700 includes:

[0210] A transceiver unit 710, configured to receive a first request from a user; the first request is used to request access to a first data set; the first data set and first metadata are stored in a storage device; the first metadata is the metadata of the first data set;

[0211] A verification unit 720, configured to verify the first data set and the first metadata;

[0212] An operation unit 730, configured to, when the verification is passed, allow the user to perform a normal access operation on the first data set;

[0213] A generation unit 740, configured to generate a transaction record based on the normal access operation;

[0214] A storage unit 750, configured to store the transaction record in a distributed ledger network.

[0215] In this embodiment, on the one hand, when the present application receives a first request from a user for requesting access to a first data set, it performs multi-dimensional security verification on the first data set and the first metadata, and only when the verification is passed, will it allow the user to perform a normal access operation on the first data set. In this way, through the multi-dimensional verification process of the data set and metadata before the data set is used, it can be ensured that the data used by the user is complete, secure, and not tampered with; on the other hand, the embodiment of the present application can also generate a transaction record based on the normal access operation and store the transaction record in a distributed ledger network. In this way, using the distributed ledger network can not only ensure the traceability and persistence of the transaction record, but also increase the transparency and trust of the data. Generally speaking, the technical solution provided by the embodiment of the present application can achieve all-round protection of data from two perspectives: before data use and after operation completion, which not only effectively ensures the integrity and security of the data, but also enhances the transparency and traceability of data operations.

[0216] In an exemplary embodiment, the generation unit 740 is specifically configured to: generate a transaction record based on the access information and the first metadata; wherein, the access information includes an access operation type, a data visitor identifier, and a timestamp. In this embodiment, it can ensure the security, transparency, and traceability of the access information, which is beneficial to ensuring data security.

[0217] In an exemplary embodiment, the verification unit 720 is specifically configured to: verify the first data set and the first metadata based on the first verification value; wherein, the first verification value is generated from the first data set and the first metadata currently stored in the storage device. In this embodiment, it is possible to quickly verify the first data set and the first metadata at one time through the first verification value, which is simple and easy to implement and has high efficiency.

[0218] In an exemplary embodiment, before receiving the first request from the user, the transceiver unit 710 is further configured to receive the first data set and the first metadata; the generation unit 740 is further configured to generate a second verification value based on the first data set and the first metadata; the storage unit 750 is further configured to store the first data set, the first metadata, and the second verification value in the storage device. This embodiment is simple, reliable, and highly accurate, which is conducive to ensuring data security.

[0219] In an exemplary embodiment, the verification unit 720 is specifically configured to: determine the integrity of the first data set and the first metadata based on the consistency of the first verification value and the second verification value. In this embodiment, it is ensured that all abnormal access operations are also safe, transparent, and traceable, which is conducive to subsequent utilization or analysis and ensures data security.

[0220] In an exemplary embodiment, the operation unit 730 is further configured to, when the verification fails, reject the user's access operation to the first data set and record it as an abnormal access operation; the generation unit 740 is further configured to generate a transaction record based on the abnormal access operation. In this embodiment, it is ensured that all abnormal access operations are also safe, transparent, and traceable, which is conducive to subsequent utilization or analysis and ensures data security.

[0221] In an exemplary embodiment, the transceiver unit 710 is further configured to: receive a second request; the second request is used to obtain the user's access operation to the first data set; the access operation includes a normal access operation and / or an abnormal access operation; obtain a transaction record from the distributed ledger network; and in response to the second request, return an audit report; wherein, the audit report is generated based on the transaction record. This embodiment can provide data support for data auditing and ensure the accuracy and transparency of the audit report.

[0222] In addition, the present application also provides a data management device. Figure 8 As shown in the structural block diagram of another data management device provided by the embodiment of the present application, Figure 8 the data management device 800 includes:

[0223] A transceiver unit 810, configured to receive a transaction record, wherein the transaction record is generated based on the user's access operation to the first data set;

[0224] A generating unit 820, configured to generate a new block and metadata of the new block based on a transaction record;

[0225] A broadcasting unit 830, configured to broadcast the new block and the metadata of the new block to other nodes of the distributed ledger network.

[0226] In this embodiment, the transaction record is maintained by a distributed ledger network, which can maintain the transaction record on each distributed node respectively, ensuring the traceability and persistence of the transaction record, increasing the transparency and trust of the data, and ensuring the transparency and traceability of data operations.

[0227] In an exemplary embodiment, the generating unit 820 is further configured to: determine the validity of the transaction record based on a consensus mechanism before generating a new block and metadata of the new block based on an access operation. In this embodiment, the consensus mechanism further ensures the consistency and security of the transaction record stored in the distributed ledger network.

[0228] For parts not described in detail, please refer to the foregoing text.

[0229] Figure 9 This is a hardware block diagram of a computing device provided by an embodiment of the present application. The computing device 900 according to the embodiment of the present application includes a memory 901 and a processor 902; the memory 901 and the processor 902 are electrically connected; the memory 901 is used to store a computer program; the processor 902 is used to execute the computer program so that the computing device implements the data management method of any foregoing embodiment of the present application.

[0230] In a feasible manner, the computing device may specifically include a central processing unit (CPU), a graphics processing unit (GPU), and a memory. These units are interconnected through a bus. The central processing unit and / or the graphics processing unit may be used as the foregoing processor, and the memory may be used as the memory for storing computer-readable instructions. In addition, the computing device may further include a communication unit, an output unit, and an input unit, and these units are also connected to the bus.

[0231] The embodiment of the present application further provides a computer-readable storage medium, on which a computer program / instructions is stored. When the computer-readable instructions are executed by a processor, the data management method of any foregoing embodiment of the present application is implemented. The computer-readable storage medium includes, but is not limited to, for example, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory and / or cache memory, etc. Non-volatile memory may include, for example, read-only memory, etc.

[0232] The embodiments of the present application also provide a computer program product, including a computer program which, when executed by a processor, implements the data management method of any of the foregoing embodiments of the present application.

[0233] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present application are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present application. In addition, the specific details of the above application are only for the purpose of illustration and facilitating understanding, rather than limitations. The above details do not limit the present application to necessarily adopt the above specific details for implementation.

[0234] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present application are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or" and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with each other.

[0235] In addition, as used herein, the "or" used in the enumeration of items starting with "at least one" indicates a separate enumeration. For example, the enumeration of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). In addition, the term "exemplary" does not mean that the described examples are preferred or better than other examples.

[0236] It should also be noted that in the systems and methods of the present application, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present application.

[0237] Various changes, substitutions, and alterations to the technologies described herein can be made without departing from the teachings of the technology defined by the appended claims. In addition, the scope of the claims of the present application is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Current or later-developed processes, machines, manufactures, compositions of events, means, methods, or acts that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Thus, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.

[0238] The foregoing description of the claimed aspects is provided to enable any person skilled in the art to make or use the present application. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present application. Thus, the present application is not intended to be limited to the aspects shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.

[0239] The foregoing description has been presented for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present application to the forms disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.

Claims

1. A data management method, characterized in that: The method comprises: receiving a first request from a user; the first request is used to request access to a first data set; the first data set and first metadata are stored in a secure database; the first metadata is metadata of the first data set; Verifying the first data set and the first metadata; If the verification is passed, the user is allowed to access the first data set normally; generating a transaction record based on the normal access operation; The transaction records are stored in a distributed ledger network.

2. The method according to claim 1, characterized in that The generating a transaction record based on the normal access operation includes: The transaction record is generated based on access information and the first metadata; wherein the access information includes an access operation type, a data accessor identifier, and a timestamp.

3. The method according to claim 1 or 2, characterized in that: The verifying the first data set and the first metadata includes: Verify the first data set and the first metadata based on a first verification value; The first verification value is generated by the first data set and first metadata currently stored in the security database.

4. The method according to any one of claims 1 to 3, characterized in that: Before receiving the first request from the user, the method further includes: receiving the first data set and the first metadata; generating a second check value based on the first data set and the first metadata; The first data set, the first metadata, and the second verification value are stored in the secure database.

5. The method according to claim 3 or 4, characterized in that: The verifying the first data set and the first metadata based on the first verification value includes: Based on the consistency between the first check value and the second check value, the integrity of the first data set and the first metadata is determined.

6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: If the verification fails, denying the user access to the first data set and recording it as an abnormal access operation; The transaction record is generated based on the abnormal access operation.

7. The method according to any one of claims 1 to 6, characterized in that: The method further comprises: receiving a second request; the second request is used to obtain an access operation of a user to the first data set; the access operation includes the normal access operation and / or the abnormal access operation; Obtaining the transaction record from the distributed ledger network; In response to the second request, an audit report is returned; wherein the audit report is generated based on the transaction record.

8. A data management method, characterized in that: The method comprises: Receiving a transaction record, wherein the transaction record is generated based on an access operation of a user to a first data set; Generate a new block and metadata of the new block based on the transaction record; Broadcast the new block and metadata of the new block to other nodes of the distributed ledger network.

9. The method according to claim 8, characterized in that Before generating a new block and metadata of the new block based on the access operation, the method further includes: The validity of the transaction record is determined based on a consensus mechanism.

10. A computing device, characterized in that: The computing device includes a memory and a processor; The memory is electrically connected to the processor; The memory is used to store computer programs; The processor is configured to execute the computer program so that the computing device implements the method according to any one of claims 1 to 7 or 8 to 9.