Electronic archive data tracking and multi-party cooperative auditing method based on block chain smart contract
By adopting blockchain and smart contract technology in the electronic archive management system, the data security and operation tracking problems in electronic archive management are solved, the transparency and efficiency of multi-party collaborative audits are achieved, and the overall security and credibility of archive management are improved.
Patent Information
- Application Number
- CN202510216875.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-26
AI Technical Summary
The electronic archive management system has a single point of failure risk, data tampering and leakage risk, operation records are opaque and difficult to trace, traditional audit processes are inefficient and lack automation support, making it difficult to meet the needs of multi-party collaboration and cross-institutional data sharing.
Use blockchain technology for distributed storage, use smart contracts to realize dynamic permission management and operational behavior recording, ensure data integrity and security through hashing algorithms and multi-level encryption mechanisms, support multi-party collaborative audits and ensure the objectivity and transparency of audit results through consensus mechanisms.
It effectively solves the problems of data security, operation tracking and multi-party collaborative audit in electronic archive management, improves the security and credibility of archive data, and realizes the full traceability of operational behaviors and the transparency and efficiency of audits.
Smart Images

Figure CN120067213A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical fields of electronic file management and artificial intelligence blockchain, and particularly relates to an electronic file data tracking and multi-party collaborative auditing method based on blockchain smart contracts. Background Art
[0002] With the acceleration of the social digitalization process, electronic files, as an important digital asset, are widely used in government administration, enterprise management, education, scientific research and other fields, gradually replacing traditional paper files. However, the development of electronic file management also faces many challenges and pain points. For example, electronic file systems usually rely on centralized databases for storage and management. However, the biggest weakness of this centralized architecture lies in the risk of single-point failure. Once the database is breached, attacked by hackers, or due to the abuse of permissions by internal operators, the file data may be tampered with or deleted. In this case, the authenticity and integrity of the file data will be difficult to effectively guarantee. In addition, sensitive files may lead to information leakage during storage and transmission due to unencrypted or insufficient encryption strength. Electronic files involve various operation behaviors (such as creation, modification, transmission, deletion, etc.) during their life cycle. However, in traditional file management systems, the records of operation behaviors usually rely on independent log systems. This log recording method is not only easily modified or deleted by humans, but also lacks a systematic traceability mechanism, unable to ensure the comprehensiveness and accuracy of the records. Especially when file disputes or security incidents occur, it is often extremely difficult to restore the operation history of the files.
[0003] Traditional audit processes often rely on manual operations or external audit agencies for offline analysis, making it difficult to identify problems in real time. The audit report generation cycle is relatively long and is easily interfered by human subjective factors, resulting in problems such as objectivity and comprehensiveness of the audit results. In addition, traditional methods lack automated support for the permission verification of file operations and the legality audit of operation records, with low audit efficiency and credibility. File management systems usually involve multiple roles, including file administrators, auditors, file users, and regulatory agencies. Different roles have different permission requirements and collaboration needs. Traditional centralized systems often have problems such as permission abuse and information silos when coordinating trust and collaboration among multiple parties. In addition, it is difficult to effectively supervise data sharing across institutions and audit collaboration, reducing the transparency and credibility of the file management system. In summary, electronic file management urgently needs a technical means that can not only improve the security of file data storage and management, but also achieve comprehensive tracking and transparent recording of operation behaviors, while enhancing the efficiency and credibility of multi-party collaborative auditing.
[0004] As an emerging distributed ledger technology, blockchain has been widely applied in recent years in fields such as finance, healthcare, and supply chain due to its characteristics of decentralization, anti-tampering, and traceability. By storing data records on multiple nodes, blockchain technology can effectively prevent single-point failures and data tampering problems. For example, blockchain platforms such as Hyperledger and Ethereum support distributed storage and smart contract functions, providing high transparency and automated support for data management. However, the application of blockchain technology in electronic file management is still in the exploratory stage. Existing research has focused more on fields such as financial transactions and product traceability, and has not provided a systematic solution for the diverse needs of file management.
[0005] Smart contract is one of the core functions of blockchain technology. By writing executable contract code, it can automatically execute operations when preset conditions are triggered. For example, in supply chain management, smart contracts can automatically verify transaction conditions and complete payments. However, current research on smart contracts for file management mainly focuses on simple permission verification and data access control, lacking support for complex operation scenarios (such as dynamic permission adjustment and behavior auditing). In addition, existing contract designs still have deficiencies in terms of efficiency and security, especially there may be performance bottlenecks when dealing with massive file data.
[0006] Most current electronic file management systems adopt a centralized architecture, relying on database technology for data storage, permission control, and operation recording. Although this architecture has a certain degree of maturity, it has the risk of single-point failure and is vulnerable to malicious attacks. In addition, the log recording system for file operations is independent of the data storage system, resulting in a lack of linkage between the two. Tracking operation history often requires additional manual processing. More importantly, centralized systems are difficult to meet the trust issues in multi-party collaboration scenarios. Especially in cross-institutional audits, transparency and data consistency cannot be effectively guaranteed.
[0007] Distributed collaboration technologies have been applied in multiple fields in recent years, such as remote work and cloud computing collaboration. However, these technologies usually rely on trusted third parties or centralized services to coordinate data sharing and collaborative operations, and there are still trust risks. In addition, in the field of auditing, traditional distributed auditing methods mainly rely on external auditing agencies, and the authenticity of data and the transparency of the auditing process cannot be fully guaranteed, unable to meet the needs of multi-party collaboration in electronic file management. Summary of the Invention
[0008] In view of the above background problems, the present invention proposes an electronic file data tracking and multi-party collaborative auditing method based on blockchain smart contracts. The file data is stored through the blockchain distributed ledger, and its anti-tampering feature is used to ensure the authenticity and immutability of the file records. At the same time, a unique identifier is generated for each file data through the hash algorithm to quickly detect data tampering. Dynamic permission management and operation behavior records are realized based on smart contracts. All file operations need to verify permissions through smart contracts and automatically generate operation logs to be recorded on the blockchain, ensuring the comprehensiveness, transparency, and non-forgeability of the operation records. Utilizing the consensus mechanism and distributed characteristics of the blockchain, multiple auditing parties are supported to participate in file auditing. Each party independently verifies the authenticity of the data and the compliance of the operations based on the operation records on the blockchain, and reaches a consistent result through the consensus algorithm to ensure the objectivity and transparency of the auditing. In the data storage and transmission links, a multi-level encryption mechanism is adopted for file data. Sensitive data is protected through asymmetric encryption technology, and ordinary data is encrypted through symmetric encryption technology to improve efficiency. At the same time, dynamic hash values are generated through random salts and metadata to further enhance the security and anti-collision ability of the data. Through the organic combination of blockchain technology, smart contracts, and encryption mechanisms, the present invention fundamentally solves the problems of data security, operation tracking, and multi-party collaborative auditing in electronic file management, providing a new technical path for the digital transformation of the file management field.
[0009] In order to solve the above technical problems, the technical solution adopted by the present invention is as follows:
[0010] An electronic file data tracking and multi-party collaborative auditing method based on blockchain smart contracts, comprising the following steps:
[0011] S1, encrypt the electronic file data before storage, and use asymmetric encryption technology to protect the security of sensitive information; generate a unique identifier hash value for each file through the hash algorithm to mark and verify the integrity and authenticity of the file;
[0012] S2, construct an operation record system for file management on the blockchain, and use smart contracts to automatically record each operation behavior, including access, modification, and transfer operation details; the operation records cover key information such as the operator's identity, operation time, and operation type, and are appended with timestamps and digital signatures to ensure that the records are immutable and verifiable;
[0013] S3, design a fine-grained permission management and real-time auditing mechanism based on smart contracts to ensure that the access and operation of file data comply with preset rules; the smart contract dynamically verifies the user's permissions according to the operation request, automatically generates an operation audit log, and stores it on the blockchain for multi-party verification; through the automated execution of the smart contract, the transparency and credibility of permission management are improved, providing guarantee for the security and compliance of the file;
[0014] S4. Design an audit process for multi-party collaboration relying on the distributed storage characteristics of the blockchain. The auditor can independently verify the authenticity and operation compliance of the file data based on the operation records on the blockchain, summarize the audit results through the distributed consensus mechanism and reach a consensus, preventing tampering or bias by a single auditor. The results of the collaborative audit are stored in the form of the blockchain.
[0015] In S1, the use of asymmetric encryption technology to protect the security of sensitive information and generating a unique identifier for each file through the hash algorithm is as follows:
[0016] S11. Perform data classification processing on the electronic file data D, classify it into a sensitive information part D s and a general information part D n , satisfying:
[0017] For the sensitive information D s use asymmetric encryption technology. Let K pub and K pri be the public key and private key for encryption respectively. The encryption of the sensitive information is expressed as: E s = Enc(D s , K pub ), where Enc represents the encryption operation. Only the authorized user holding the private key K pri can restore D s through the decryption operation Dec(E pri , K s ); for the general information D n use symmetric encryption technology. Let the symmetric key be K s . The encrypted general information is expressed as E n = Enc(D n , K s ), and the corresponding decryption operation is D n = Dec(E n , K s );
[0018] S12. Store the encrypted data E s and E n together with its unique identifier H. The unique identifier is generated through the hash function H = Hash(D); among them, the hash function ensures the integrity and immutability of the file data;
[0019] Store E s , E n and H as transaction data into the blockchain. Each record contains the following information:
[0020] T = {E s , E n , H, Metadata}
[0021] Among them, Metadata includes the operation timestamp and the operator's identity information to ensure the traceability of data.
[0022] The construction of the operation record system for file management on the blockchain in S2 is as follows:
[0023] S21. During file management operations, key operation behaviors are captured and extracted in real time, including the operator's identity U, operation type O, operation target D, timestamp T, and the unique identifier E of the operation device; they are normalized according to a preset format to form a structured operation record R = {U, O, D, T, E};
[0024] To ensure the authenticity and immutability of the operation record, a digital signature σ is generated for each record R using the private key K pri Sign the record:
[0025] σ = Sign(R, K pri )
[0026] Among them, Sign is the digital signature algorithm, and only the operator's public key K pub can verify the signature;
[0027] S22. When the operation occurs, the smart contract automatically triggers the verification of the operation behavior, including user permission verification and data consistency check; after the verification passes, the smart contract stores the record R and the signature σ in the blockchain, and the operations that fail the verification will be rejected by the smart contract and the abnormal events will be recorded;
[0028] The operation records verified by the smart contract are packaged into a transaction T and stored on the blockchain; each transaction contains the following fields T = {R, σ, Block ID, Prev Hash, T s}, where R is the operation record data, σ is the digital signature, BlockID is the block number, Prev Hash is the hash value of the previous block, used to link the blockchain, and T s is the timestamp of the current transaction;
[0029] On the blockchain, each block contains multiple transaction records, and each transaction has an independent signature and hash value; the block structure is Block = {Block ID, Prev Hash, Merkle Root, {T 1 , T 2 , …, T n}}, where Merkle Root is the Merkle tree root node of the transaction record hash value, used to efficiently verify the record integrity.
[0030] The fine-grained rights management and real-time audit mechanism designed based on smart contracts in S3 is:
[0031] S31, fine-grained classification of user permissions, according to the needs of file management, the permissions are divided into different levels; each level of permissions corresponds to a specific operation scope and restriction conditions, and the permission set is P = {p 1 ,p 2 ,…,p n}, the permission set of user U is
[0032] Smart contracts dynamically assign user permissions and adjust the scope of permissions based on the operation content and context. When a user requests to operate a profile D, the smart contract verifies whether the user has the corresponding permissions. The conditions include time limits, geographical restrictions, and operation frequency. The permission verification results are returned to the operator in real time. Role-based access control is implemented through smart contracts, and users are grouped into different roles. Each role has a different set of permissions P. R , the permissions of user U are determined by its role R U Decide,
[0033] S32, each user operation is recorded in real time by the smart contract. Details include user identity U, operation type O, target profile D, timestamp T, and additional metadata; the operation record is defined as R = {U, O, D, T, Metadata};
[0034] After the recording is completed, the smart contract verifies the legitimacy of the operation to ensure that the operation complies with the authority rules and audit requirements; the smart contract generates an audit log in real time, hashes the recorded data R and stores it on the blockchain, and the log generation formula is L = Hash (R);
[0035] S32, the transaction format stored in the blockchain is T = {R, L, σ, T s}, where σ is the digital signature, T s To record timestamps; smart contracts have built-in anomaly detection rules, which automatically identify potential anomalies by analyzing the legality and frequency of operation behaviors; if users frequently attempt to unauthorized access or operate from abnormal IP addresses, the smart contract triggers an alarm and records abnormal operations;
[0036] The auditor uses smart contracts to call the operation records in the blockchain in real time to verify the authenticity and compliance of user operations; the audit results automatically generate a report and store it in the blockchain. The report content includes the number of legal operations, abnormal operation records, audit time range and statistical summary.
[0037] The multi-party collaborative audit process designed in S4 is as follows:
[0038] S41. The multi-party collaborative audit process includes the following participating roles: The archive management party M is responsible for the generation and maintenance of archive data. The audit party set A = {A 1 , A 2 , …, A n} includes the internal audit team and external regulatory agencies to verify the compliance of archive operations. The blockchain nodes N = {N 1 , N 2 , …, N m}, a distributed storage and consensus network jointly constructed by all parties;
[0039] The blockchain system stores the archive operation records. The data structure of block B i is B i = {Block ID, Prev Hash, Merkle Root, t, σ i}, where Merkle Root = H(H(T 1 ) || H(T 2 ) || … || H(T j ))), T = {T 1 , T 2 , …, T j} is the transaction set, which contains the archive operation logs, and σ i is the digital signature of the block generating node;
[0040] S42. The operation log R generated by the archive management system includes the following fields: R = {U, O, D, T, Metadata, σ U}, where U is the user identity, O is the operation type, D is the operation target, i.e., the archive data, T is the timestamp, Metadata is the additional metadata, is the user signature used to verify the operation source; The log generates a unique identifier H(R) = Hash(U || O || D || T || Metadata) through the hash function and is stored in the blockchain in the form of a transaction T j = {H(R), σ j , T U , T s};
[0041] The audit party extracts the operation log R from the blockchain. The data integrity verification recalculates the log hash value H′(R) = Hash(U || O || D || T || Metadata) and verifies that H ′ (R) = H(R). If they do not match, it is marked as tampered;
[0042] S43. The permission compliance verification verifies whether the user U has the permission p to perform the operation O. If then it is marked as a violation, where, P Uis the permission set of user U, determined by role R U Decided Statistical operation frequency F(U,T) of user U within the audit scope range ):
[0043]
[0044] Among them, Total Ops(U,T range ) represents the total number of operations performed by user U within the specified time range T range ; In the pre - preparation stage, the master node broadcasts the audit proposal, and in the preparation stage, other nodes verify the proposal and broadcast the prepare message; In the commit stage, consensus is reached after receiving at least 2f + 1 prepare messages; Generate the final audit report Audit Report = {Audit ID, Summary, Details, σ final ,T s}, where Audit ID is the unique identifier of the audit task, Summary is the summary of the audit result, Details is the audit details, σ final is the final signature, and the report is stored as a blockchain transaction for the authorized party to query and traceability.
[0045] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0046] The present invention utilizes the distributed storage and immutability characteristics of the blockchain to fundamentally ensure the security and credibility of the archive data and operation records. Each archive operation will generate a detailed record through the smart contract and be stored in the blockchain in the form of a transaction, ensuring that any record cannot be tampered with or forged. Sensitive information is protected through multi - level encryption technology, and combined with the hash algorithm to generate a unique identifier, which can quickly detect the risk of data tampering. In addition, the digital signature technology is used to verify the authenticity of the operation source, effectively preventing the common data leakage and permission abuse risks in the centralized system, and comprehensively improving the security of archive management.
[0047] Through the smart contract mechanism of the present invention, each archive operation will be recorded in real - time, including key information such as the operator's identity, operation type, target archive, timestamp, etc., ensuring that the operation behavior is traceable throughout the process. The smart contract automatically performs permission verification and operation legality check, and triggers an alarm when an abnormal operation occurs, ensuring the compliance of archive operations. At the same time, the present invention supports multi - party collaborative auditing. Each auditing party can independently verify the log and use the blockchain consensus mechanism to generate a consistent audit result, thereby ensuring the transparency of the audit process and the objectivity of the result. It realizes the dynamic tracking and real - time auditing of archive operations, effectively improving the transparency of management and the supervision efficiency.
[0048] Through the consensus mechanism of blockchain and the automated execution of smart contracts, the present invention significantly improves the efficiency of multi-party collaborative auditing. Audit tasks and log records are shared through blockchain, supporting cross-institutional audit collaboration and effectively eliminating the problem of information silos in traditional systems. The distributed storage and multi-party participation mechanism avoid single-point failures and unilateral biases, and all audit results are agreed upon through the consensus mechanism to ensure the fairness of the audit. After the audit is completed, the system automatically generates an audit report containing a result summary, detailed records, and digital signatures, supporting quick query and traceability, greatly simplifying the audit process and operation complexity, and providing an efficient and reliable solution for file auditing in complex scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings described below are merely exemplary, and for those of ordinary skill in the art, without creative efforts, other implementation drawings can also be obtained based on the provided drawings.
[0050] The structures, ratios, sizes, etc. illustrated in this specification are only used to cooperate with the content disclosed in the specification for those familiar with this technology to understand and read, and are not used to limit the limiting conditions under which the present invention can be implemented. Therefore, they do not have technical substance. Any modification of the structure, change in the proportional relationship, or adjustment of the size, without affecting the effects that the present invention can produce and the purposes that can be achieved, should still fall within the scope covered by the technical content disclosed in the present invention.
[0051] Figure 1 It is a flowchart of an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0052] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of them. These descriptions are only to further illustrate the features and advantages of the present invention, rather than a limitation on the claims of the present invention; based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.
[0053] The following will further describe in detail the specific implementation manners of the present invention in combination with the drawings and embodiments. The following embodiments are used to illustrate the present invention but are not used to limit the scope of the present invention.
[0054] As Figure 1As shown, the framework of the present invention mainly includes the following four steps, which are connected layer by layer and finally integrated. The process mainly includes the following steps:
[0055] S1. Encrypt the electronic file data before storage, and use asymmetric encryption technology to protect the security of sensitive information; generate a unique identification hash value for each file through the hash algorithm to mark and verify the integrity and authenticity of the file;
[0056] In S1, the use of asymmetric encryption technology to protect the security of sensitive information and the generation of a unique identifier for each file through the hash algorithm are as follows:
[0057] S11. Data classification processing: Classify the electronic file data D, and divide it into a sensitive information part D s and a general information part D n , satisfying:
[0058] For the sensitive information D s Use asymmetric encryption technology. Let K pub and K pri be the public key and private key for encryption respectively. The encryption of sensitive information is expressed as: E s = Enc(D s , K pub ), where Enc represents the encryption operation. Only authorized users holding the private key K pri can restore D s through the decryption operation Dec(E pri , K s ); For the general information D n Use symmetric encryption technology. Let the symmetric key be K s . The encrypted general information is expressed as E n = Enc(D n , K s ), and the decryption operation corresponds to D n = Dec(E n , K s );
[0059] S12. Store the encrypted data E s and E n together with its unique identifier H. The unique identifier is generated through the hash function H = Hash(D); among them, the hash function ensures the integrity and immutability of the file data;
[0060] Store E s , E n and H as transaction data in the blockchain. Each record contains the following information:
[0061] T = {E s,E n ,H,Metadata}
[0062] Among them, Metadata includes the operation timestamp and the operator's identity information to ensure the traceability of data.
[0063] S2. Build an operation record system for file management on the blockchain, and use smart contracts to automatically record each operation behavior, including access, modification, and transfer operation details; the operation records cover key information such as the operator's identity, operation time, and operation type, and are appended with timestamps and digital signatures to ensure the immutability and verifiability of the records;
[0064] S21. In file management operations, capture and extract key operation behaviors in real time, including the operator's identity U, operation type O, operation target D, timestamp T, and the unique identifier E of the operation device; normalize them according to a preset format to form a structured operation record R = {U, O, D, T, E};
[0065] To ensure the authenticity and immutability of the operation records, generate a digital signature σ for each record R using the private key K pri Sign the record:
[0066] σ = Sign(R, K pri )
[0067] Among them, Sign is the digital signature algorithm, and only the operator's public key K pub can verify the signature;
[0068] S22. When an operation occurs, the smart contract automatically triggers the verification of the operation behavior, including user permission verification and data consistency check; after the verification passes, the smart contract stores the record R and the signature σ in the blockchain, and the operations that do not pass the verification will be rejected by the smart contract and abnormal events will be recorded;
[0069] Package the operation records verified by the smart contract into a transaction T and store it on the blockchain; each transaction contains the following fields T = {R, σ, Block ID, Prev Hash, T s}; among them, R is the operation record data, σ is the digital signature, BlockID is the block number, Prev Hash is the hash value of the previous block used to link the blockchain, and T s is the timestamp of the current transaction;
[0070] On the blockchain, each block contains multiple transaction records, and each transaction has an independent signature and hash value; the block structure is Block = {Block ID, Prev Hash, Merkle Root, {T 1 , T 2,…,T n}}, where the Merkle Root is the root node of the Merkle tree of the transaction record hash value, which is used to efficiently verify the record integrity.
[0071] S3. Design a fine-grained permission management and real-time auditing mechanism based on smart contracts to ensure that the access and operations of archival data comply with the preset rules; the smart contract dynamically verifies the user permissions according to the operation requests, automatically generates operation audit logs, and stores them in the blockchain for multi-party verification; through the automated execution of the smart contract, the transparency and credibility of permission management are improved, providing guarantees for the security and compliance of the archives.
[0072] S31. Perform fine-grained grading of user permissions. According to the archival management requirements, divide the permissions into different levels; each level of permission corresponds to specific operation scopes and restrictive conditions. Let the permission set be P = {p 1 , p 2 , …, p n}, and the permission set of user U is
[0073] The smart contract dynamically allocates user permissions and adjusts the permission scope according to the operation content and context; when the user requests to operate on the archive D, the smart contract verifies whether it has the corresponding permissions; the conditions include time limit, geographical limit, operation frequency, etc., and the permission verification result is returned to the operator in real time. Implement role-based access control through the smart contract, group users into different roles, and each role has a different permission set P R , and the permission of user U is determined by its role R U .
[0074] S32. Each user operation is recorded in real time by the smart contract with operation details, including user identity U, operation type O, target archive D, timestamp T, and additional metadata; the operation record is defined as R = {U, O, D, T, Metadata}.
[0075] After the record is completed, the smart contract verifies the legality of the operation behavior to ensure that the operation complies with the permission rules and auditing requirements; generate an audit log in real time through the smart contract, hash the recorded data R and store it on the blockchain, and the log generation formula is L = Hash(R).
[0076] S32. The transaction format stored in the blockchain is T = {R, L, σ, T s}, where σ is the digital signature, and T sTo record the timestamp; the smart contract has built-in anomaly detection rules that can automatically identify potential anomalies by analyzing the legality of operation behaviors and operation frequencies; if a user frequently attempts unauthorized access or operates from an abnormal IP address, the smart contract triggers an alarm and records the abnormal operation;
[0077] The auditing party can, through the smart contract, call the operation records in the blockchain in real time to verify the authenticity and compliance of user operations; the audit results are automatically generated into a report and stored in the blockchain, and the report content includes the number of legal operations, abnormal operation records, audit time range, and statistical summary.
[0078] S4. Relying on the distributed storage feature of the blockchain, design an auditing process for multi-party collaboration; the auditing party can independently verify the authenticity of the file data and the compliance of operations based on the operation records on the blockchain, summarize the audit results through a distributed consensus mechanism and reach a consensus, preventing tampering or bias by a single auditing party, and the results of the collaborative audit are stored in the form of a blockchain.
[0079] S41. The auditing process for multi-party collaboration includes the following participating roles: the file management party M is responsible for the generation and maintenance of file data, the auditing party set A = {A 1 , A 2 , …, A n} includes the internal audit team and external regulatory agencies to verify the compliance of file operations, and the blockchain nodes N = {N 1 , N 2 , …, N m}, and all parties jointly construct a distributed storage and consensus network;
[0080] The blockchain system stores the file operation records, and the data structure of block B i is B i = {Block ID, Prev Hash, Merkle Root, T, σ i}, where Merkle Root = H(H(T 1 ) || H(T 2 ) || … || H(T j )), T = {T 1 , T 2 , …, T j} is the transaction set, which contains the file operation logs, and σ i is the digital signature of the block generation node;
[0081] S42. The operation log R generated by the file management system includes the following fields: R = U, O, D, T, Metadata, σ U}, where U is the user identity, O is the operation type, D is the operation target, i.e., the file data, T is the timestamp, Metadata is the additional metadata, It is the user's signature, used to verify the source of the operation; the log generates a unique identifier H(R) = Hash(U||O||D||T||] through a hash function and is stored in the blockchain T in the form of a transaction j Stored in the blockchain T j ={H(R), σ U ,T s};
[0082] The auditor extracts the operation log R from the blockchain, and the data integrity verification recalculates the log hash value H'(R) = Hash(U||O||D||T||Metadata) to verify H ′ (R) = H(R). If they do not match, it is marked as tampered;
[0083] S43. The permission compliance verification verifies whether the user U has the permission p to perform the operation O. If Then it is marked as a violation, where P U Is the permission set of the user U, determined by the role R U Decided Statistical operation frequency F(U, T of user U within the audit scope range ):
[0084]
[0085] Among them, Total Ops(U, T range ) represents the total number of operations performed by the user U within the specified time range T range ; In the pre - preparation stage, the primary node broadcasts the audit proposal, and in the preparation stage, other nodes verify the proposal and broadcast the preparation message; in the commit stage, consensus is reached after receiving at least 2f + 1 preparation messages; generate the final audit report Audit Report = {Audit ID, Summary, Details, σ final ,T s}, where Audit ID is the unique identifier of the audit task, Summary is the summary of the audit result, Details is the audit details, and σ final Is the final signature, and the report is stored as a blockchain transaction for the authorized party to query and traceability.
[0086] The experiments of the present invention used the operation logs and data storage records in the simulated electronic file management system. The data sources included: Enterprise document system: Based on the file collaboration and auditing scenarios within the enterprise, involving multi-party sharing and tracking operations of sensitive information. Data scale: Archive records: 50,000 documents. 1,000,000 operation logs were generated under each scenario, and the operation types included reading, modifying, deleting, approving, etc. Multi-party collaboration participants: Simulated 10 - 20 distributed nodes, and each node stored a complete blockchain copy.
[0087] To verify the effectiveness of the present invention, it was compared with the following methods: (1) Traditional centralized file management system: Stored and managed file operation records based on a centralized database, lacking distributed characteristics and anti-tampering capabilities. (2) Blockchain + storage solution (without smart contract): Stored file operation logs on the blockchain, but did not use smart contracts for permission management and audit automation. (3) Distributed database + permission control system: Used a distributed database to record operation logs and combined static permission verification for auditing. (4) The method of the present invention: Based on blockchain and smart contracts, supporting distributed storage, multi-party collaboration auditing, dynamic permission management, and real-time tracking. The specific experimental results are compared in Table 1.
[0088] Table 1 Comparison of experimental results of different methods
[0089]
[0090] The experimental results show that the present invention performs excellently in multiple key indicators, especially reaching a leading level in terms of tampering detection rate and audit efficiency. Benefiting from the anti-tampering characteristics of the blockchain, the present invention achieved a 100% tampering detection rate, significantly superior to the 76% of the traditional centralized file management system. In addition, through the automated execution of smart contracts, the average execution time of the audit task was only 5 seconds, which was 50% and 66% higher than that of the blockchain + storage solution (10 seconds) and the distributed database solution (15 seconds) respectively, and far superior to the 60 seconds of the traditional system. In terms of multi-party collaboration tasks, the present invention coordinated the auditing parties through the consensus mechanism, and the completion time was 20 seconds, with significantly higher efficiency than the blockchain + storage solution (30 seconds) and the distributed database solution (25 seconds), while solving the limitation that the traditional system could not support multi-party collaboration.
[0091] In terms of system performance and real-time performance, the present invention exhibits a high level of optimization. Its TPS reaches 500, which is lower than 2,000 of the centralized system, but significantly better than 600 of the blockchain + storage solution and 1,500 of the distributed database solution. The log record latency is 150 ms, slightly higher than that of the distributed database solution (100 ms), but significantly lower than 200 ms of the blockchain + storage solution. Overall, while ensuring data security and collaboration efficiency, the present invention balances system performance and operation real-time performance, providing an efficient, secure, and transparent solution for complex file management scenarios.
[0092] Only the preferred embodiments of the present invention are described in detail above. However, the present invention is not limited to the above embodiments. Within the scope of knowledge possessed by those of ordinary skill in the art, various changes can be made without departing from the gist of the present invention, and all such changes should be included within the protection scope of the present invention.
Claims
1. A method for electronic archive data tracking and multi-party collaborative auditing based on blockchain smart contracts, characterized in that: The following steps are involved: S1, encrypt electronic archive data before storage, use asymmetric encryption technology to protect sensitive information security; generate a unique identification hash value for each archive through a hash algorithm to mark and verify the integrity and authenticity of the archive; S2, build an operation record system for archive management on the blockchain, and use smart contracts to automatically record each operation, including access, modification and transfer operation details; the operation record covers the key information of the operator's identity, operation time, and operation type, and is attached with a timestamp and digital signature to ensure that the record is tamper-proof and verifiable; S3, based on smart contracts, designs fine-grained permission management and real-time audit mechanisms to ensure that the access and operation of archival data comply with preset rules; smart contracts dynamically verify user permissions based on operation requests, automatically generate operation audit logs, and store them in the blockchain for multi-party verification; Through the automated execution of smart contracts, the transparency and credibility of rights management are improved, providing guarantees for the security and compliance of archives; S4, relying on the distributed storage characteristics of blockchain, designs a multi-party collaborative audit process; Auditors can independently verify the authenticity and operational compliance of archival data based on the operation records on the blockchain, summarize the audit results and reach a consensus through a distributed consensus mechanism, prevent tampering or bias by a single auditor, and store the results of collaborative audits in the form of blockchain.
2. According to claim 1, a method for electronic archive data tracking and multi-party collaborative auditing based on blockchain smart contracts is characterized in that: The S1 uses asymmetric encryption technology to protect sensitive information security and generates a unique identifier for each file through a hash algorithm: S11, data classification processing classifies the electronic archive data D and divides it into sensitive information part D s and General Information Section D n , satisfying: D = D s ∪D n , Sensitive information D s Using asymmetric encryption technology, let K pub and K pri They are the encrypted public key and private key respectively. The encryption of sensitive information is expressed as: E s =Enc(D s ,K pub ), where Enc represents the encryption operation. Only the private key K pri Only authorized users can decrypt the Dec(E s ,K pri )Restore D s ; For general information D n Using symmetric encryption technology, let the symmetric key be K s , the encrypted ordinary information is represented by E n =Enc(D n ,K s ), the decryption operation corresponds to D n = Dec(E n ,K s ); S12, the encrypted data E s and E n It is stored together with its unique identifier H, which is generated by a hash function H = Hash (D); wherein the hash function ensures the integrity and non-tamperability of the archive data; E s 、E n and H are stored as transaction data in the blockchain, and each record contains the following information: T={E s ,E n ,H,Metadata} Among them, Metadata includes operation timestamp and operator identity information to ensure data traceability.
3. According to the electronic archive data tracking and multi-party collaborative auditing method based on blockchain smart contracts according to claim 1, it is characterized in that: The operation record system for archive management in S2 is constructed on the blockchain as follows: S21, in the archive management operation, real-time capture and extraction of key operation behaviors, including operator identity U, operation type O, operation target D, timestamp T, and unique identifier E of the operation device; normalization according to the preset format to form a structured operation record R = {U, O, D, T, E}; To ensure the authenticity and non-tamperability of the operation records, a digital signature σ is generated for each record R using the private key K pri Sign the record: σ=Sign(R,K pri ) Among them, Sign is a digital signature algorithm, only the operator's public key K pub Ability to verify signatures; S22, when the operation occurs, the smart contract automatically triggers the verification of the operation behavior, including user authority verification and data consistency check; after the verification, the smart contract will store the record R and signature σ in the blockchain. The operation that fails to pass the verification will be rejected by the smart contract and the abnormal event will be recorded; The operation records verified by the smart contract are packaged into transactions T and stored on the blockchain; each transaction contains the following fields T = {R, σ, Block ID, Prev Hash, T s }, where R is the operation record data, σ is the digital signature, Block ID is the block number, Prev Hash is the hash value of the previous block, which is used to link the blockchain, and T s is the timestamp of the current transaction; In the blockchain, each block contains multiple transaction records, and each transaction has an independent signature and hash value; the block structure is Block = {Block ID, Prev Hash, Merkle Root, {T1, T2, …, T n }}, where Merkle Root is the Merkle tree root node of the transaction record hash value, which is used to efficiently verify the integrity of the record.
4. According to claim 1, a method for electronic archive data tracking and multi-party collaborative auditing based on blockchain smart contracts is characterized in that: The fine-grained rights management and real-time audit mechanism designed based on smart contracts in S3 is: S31, fine-grained classification of user permissions, according to the needs of file management, the permissions are divided into different levels; each level of permissions corresponds to a specific operation scope and restriction conditions, and the permission set is P = {p1, p2, ..., p n }, the permission set of user U is Smart contracts dynamically assign user permissions and adjust the scope of permissions based on the operation content and context. When a user requests to operate a profile D, the smart contract verifies whether the user has the corresponding permissions. The conditions include time limits, geographical restrictions, and operation frequency. The permission verification results are returned to the operator in real time. Role-based access control is implemented through smart contracts, and users are grouped into different roles. Each role has a different permission set P. R , the permissions of user U are determined by its role R U Decide, S32, each user operation is recorded in real time by the smart contract. Details include user identity U, operation type O, target profile D, timestamp T, and additional metadata; the operation record is defined as R = {U, O, D, T, Metadata}; After the recording is completed, the smart contract verifies the legitimacy of the operation to ensure that the operation complies with the authority rules and audit requirements; the smart contract generates an audit log in real time, hashes the recorded data R and stores it on the blockchain, and the log generation formula is L = Hash (R); S32, the transaction format stored in the blockchain is T = {R, L, σ, T s }, where σ is the digital signature, T s To record timestamps; smart contracts have built-in anomaly detection rules that automatically identify potential anomalies by analyzing the legality and frequency of operation behaviors; If a user frequently attempts to access beyond their authority or operates from an abnormal IP address, the smart contract triggers an alarm and records the abnormal operation; The auditor uses smart contracts to call the operation records in the blockchain in real time to verify the authenticity and compliance of user operations; the audit results automatically generate a report and store it in the blockchain. The report content includes the number of legal operations, abnormal operation records, audit time range and statistical summary.
5. According to claim 1, a method for electronic archive data tracking and multi-party collaborative auditing based on blockchain smart contracts is characterized in that: The multi-party collaborative audit process designed in S4 is as follows: S41, the multi-party collaborative audit process includes the following participants: the archive management party M is responsible for the generation and maintenance of archive data, and the audit party set A = {A1, A2, …, A n }Including internal audit teams and external regulators to verify the compliance of archive operations, blockchain nodes N = {N1, N2, ..., N m }, a distributed storage and consensus network jointly built by all parties; The blockchain system stores archive operation records, block B i The data structure is B i ={Block ID,Prev Hash,Merkle Root,T,σ i }, where Merkle Root = H(H(T1)||H(T2)||…||H(T j )), T={T1,T2,…,T j } is a transaction set, including archive operation logs, σ i It is the digital signature of the block generation node; S42, the operation log R generated by the archive management system includes the following fields: R = U, O, D, T, Metadata, σ U }, where U is the user identity, O is the operation type, D is the operation target, i.e., the archive data, T is the timestamp, and Metadata is the additional metadata. It is the user signature, which is used to verify the source of the operation; the log generates a unique identifier H(R)=Hash(U||O||D||T||] through a hash function, and is in the form of a transaction T j Stored on blockchain T j ={H(R),σ U ,T s }; The auditor extracts the operation log R from the blockchain, verifies the data integrity, and recalculates the log hash value H′(R)=Hash(U||O||D||T||Metadata) to verify H ′ (R) = H(R), if it does not match, mark it as tampered; S43, permission compliance verification verifies whether user U has permission p to perform operation O. If Then mark the violation, where P U is the permission set of user U, which is composed of role R U Decide, Count the operation frequency F(U,T of user U within the audit scope) of user U range ): Among them, Total Ops (U,T range ) represents user U in the specified time range T range The total number of operations performed within the audit report; in the pre-preparation phase, the master node broadcasts the audit proposal, and in the preparation phase, other nodes verify the proposal and broadcast the preparation message; in the submission phase, consensus is reached after receiving at least 2f+1 preparation messages; the final audit report is generated Audit Report = {Audit ID, Summary, Details, σ final ,T s }, where Audit ID is the unique identifier of the audit task, Summary is the audit result summary, Details is the audit details, σ final For the final signature, the report is stored as a blockchain transaction for query and traceability by authorized parties.
Citation Information
Patent Citations
Archive information security management system and method based on blockchain
CN110781525A
Multi-cloud collaborative data security storage and auditing method based on VRF and block chain
CN114091061A
Electronic archive management system based on block chain
CN115329392A
Block chain data management method and system
CN119397578A
Method and system for tuning blockchain scalability for fast and low-cost payment and transaction processing
US10102265B1
Cited By
Financial user digital archive encryption management system and method based on block chain
CN120354436A
Financial user digital file encryption management system and method based on blockchain
CN120354436B
Financial sharing platform based on block chain technology
CN120707137A
Financial sharing platform based on blockchain technology
CN120707137B
File electronic information tamper-proofing system based on block chain
CN120707139A