Data storage integrity verification system and method based on whole ring
Through the data storage integrity verification system based on the whole loop, the security threat of artificial intelligence and quantum computing to data storage is solved by using the whole loop mathematical principles and random basis selection, and unconditional and secure data integrity verification is achieved.
Patent Information
- Application Number
- CN202510784894.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-12
AI Technical Summary
The existing technology is difficult to effectively resist cryptographic attacks brought about by artificial intelligence and quantum computing, especially cracking of classic cryptographic systems, resulting in security threats such as forgery and tampering during data storage.
The data storage integrity verification system based on the whole ring is adopted, and the data encoding, basis generation and measurement modules are used to verify data integrity through the whole ring mathematical principles, and the base space is randomly selected to resist password attacks.
It realizes unconditional and secure data integrity verification, can withstand password attacks from artificial intelligence and quantum computing, and improves the security of data storage.
Smart Images

Figure CN120277729A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a data storage integrity verification system and method based on integral domain, belonging to the technical field of data security. Background Art
[0002] The waves of artificial intelligence and quantum computing, as the core forces of the new generation of technological revolution, are profoundly changing human society. While promoting social progress, artificial intelligence and quantum computing have also had a profound impact on the field of network security. Artificial intelligence has improved the automated defense level of information systems, and quantum computing has promoted the computing revolution and achieved secure distribution of encryption keys. However, while artificial intelligence and quantum computing contribute to the development of network security, they also pose huge challenges to network security. Especially in the field of cryptography, artificial intelligence and quantum computing will reshape the pattern of cryptanalysis. Artificial intelligence breaks through the limits of cryptanalysis through deep learning, realizing autonomous identification of encryption mechanisms and automated mining of vulnerabilities in cryptographic protocols. Quantum computing severely reduces the security level of classical cryptographic systems. The quantum Shor algorithm can directly crack RSA and Elliptic Curve Cryptography (ECC) through the parallelism and superposition state characteristics of quantum computing. The quantum Grover algorithm can directly halve the security strength of symmetric encryption and hash algorithms. Currently, a wave of Post-Quantum Cryptography (PQC) has swept the globe. The United States will fully replace it with PQC by 2035. The Commercial Cryptography Standards Research Institute of China officially launched a call for new generation quantum-resistant cryptographic algorithms in February 2025.
[0003] Currently, the country is making all-out efforts to develop a trusted data space. Trusted data storage is the foundation for ensuring data security and building a trusted data space. Since data faces many security threats such as forgery and tampering during storage, it is of great significance to establish a highly trusted integrity verification algorithm for data storage to verify the trustworthiness of stored data in real time.
[0004] In view of the huge threats of artificial intelligence and quantum computing to cryptographic systems, the present invention proposes a data storage integrity verification method based on integral domain, which resists cryptanalysis with random distribution and its security only depends on mathematical principles, having unconditional security. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a data storage integrity verification system and method based on integral domain, which is different from the design of conventional cryptography based on mathematical problems. It designs an integrity verification mechanism only relying on mathematical principles to resist various cryptographic attacks based on artificial intelligence and quantum computing, and improves the security of data integrity verification to resist security threats from artificial intelligence and quantum computing.
[0006] To solve the above technical problems, the technical solution adopted by the present invention is as follows: A data storage integrity verification system based on an integral domain includes a data encoding module, a basis generation module, a standard value library, and a metric module; the data encoding module and the basis generation module are respectively connected to the standard value library and the metric module; the data encoding module is used to convert the data to be verified in binary format into an integer to prepare for the subsequent integrity verification by the metric module; the basis generation module is used to select a basis space and generate a basis in a random selection manner for the subsequent metric calculation by the metric module; the metric module completes the integrity verification of the data by calling the basis generation module and the standard value library to ensure that the data is not tampered with; the standard value library is used to store the standard integrity verification values of the input data. The data involved in this technical solution refers to the data stored in computing devices and network communication data.
[0007] Let be an integral domain (the set of integers), be the set of natural numbers, and mod be the standard modulo (remainder) operation on
[0008] Preferably, the data encoding module converts the input data to be integrity-verified into an element in the integral domain . Let the input data to be integrity-verified be , where is the data label of this data, is the length of the data, and the data content is . The data encoding module converts into the element in . At this time, the element group is formed.
[0009] Preferably, the basis generation module is responsible for the selection of the basis space and the basis. The basis space is a set with elements. The basis is an element in the basis space and is randomly generated.
[0010] Preferably, the standard value library stores the standard integrity verification values of the input data to be integrity-verified, stored according to entries, and the specific structure of each entry is as follows:
[0011]
[0012] is the data label, is the length of this data, are respectively the basis and the standard verification value selected for this data. is the number of data entries in the standard value library. All data in the reference value library is stored confidentially and is only used internally by the integrity verification system of the present invention.
[0013] Preferably, the metric module receives an element group , and checks whether it is in the standard value library.
[0014] 1) If is not in the standard value library, then the base generation module is called. The base generation module randomly selects in the base space A and returns it to the metric module. The metric module calculates
[0015]
[0016] Stores in the reference library. At the same time, the output data T = 2 is output, indicating that the input data is new data and the data integrity verification value has been generated and stored.
[0017] 2) If is in the standard value library, the metric module reads out the corresponding data from the standard value library. For symbolic distinction, let the data read from the standard value library corresponding to be . If , then the output data T = 0, indicating that the input data has changed relative to the original data. If , then calculate the new verification value
[0018]
[0019] If , then the output data T = 1, indicating that the input data has not changed relative to the original data. Otherwise, the output data T = 0, indicating that the input data has changed relative to the original data.
[0020] A data storage integrity verification method based on integral domains includes the following steps:
[0021] Initialization stage: The standard value library data is empty and the number of data entries is 0. The base generation module selects the base space A.
[0022] Step 1: Input data, and the data encoding module converts the data content of the input data into an element in the integral domain and generates an element group, and sends the element group to the metric module.
[0023] Step 2: After receiving the element group, the metric module checks whether the data label in the element group exists in the standard value library. If it exists, go to Step 5.
[0024] Step 3: If the data tag in this element group does not exist in the standard value library, call the base generation module to generate a base.
[0025] Step 4: The measurement module takes the modulus of the element with respect to the base, stores the data tag, data length, base, and check value in the standard value library, and increments the number of entries in the standard value library by 1. At the same time, output data T = 2, indicating that the input data is new data and the data integrity check value has been generated and stored.
[0026] Step 5: If the data tag in this element group exists in the standard value library. The measurement module reads the entry corresponding to this data tag from the standard value library using the data tag as an index.
[0027] Step 6: Check whether the data length in this element group is equal to the data length in this entry. If not, output data T = 0, indicating that the input data has been changed relative to the original data.
[0028] Step 7: If the data length in this element group is equal to the data length in this entry, use the element to take the modulus of the base in this entry to obtain a new check value. Compare the new check value with the standard check value in this entry. If they are equal, output data T = 1, indicating that the input data has not changed relative to the original data.
[0029] Step 8: If the new check value is not equal to the check value in this entry, output data T = 0, indicating that the input data has been changed relative to the original data.
[0030] The beneficial effects of the present invention are:
[0031] 1. Different from conventional passwords designed based on mathematical problems and difficult to resist password analysis based on artificial intelligence and quantum computing, the present invention only relies on mathematical principles to design an integrity verification mechanism, performs data integrity verification based on the random selection of bases in integral domains, so as to resist various password attacks based on artificial intelligence and quantum computing.
[0032] 2. The security of the present invention only depends on mathematical principles and does not depend on any mathematical problems, having the property of unconditional security. Description of the Drawings
[0033] Figure 1 is the framework diagram of the integrity verification system based on integral domains;
[0034] Figure 2 is the working flow diagram of the integrity verification system based on integral domains. Detailed Embodiments
[0035] The framework diagram of the system in the present invention is as Figure 1As shown, the working flowchart of the integrity verification system based on the integral domain is as Figure 2 shown.
[0036] Next, two specific examples are combined to illustrate the technical solution of the present invention in detail.
[0037] Example 1: Integrity verification of data storage in the cloud environment
[0038] Suppose in a cloud computing environment, a user needs to transfer a large number of encrypted data blocks from a local terminal to the cloud environment for storage. To ensure that the data is not maliciously tampered with or damaged during storage or subsequent use, an integrity verification method is required. The method of the present invention focuses on solving the integrity verification after data storage
[0039] Initialization stage: The cloud environment initializes its standard value library. The standard value library is used to store the verification information of data blocks. In the initial state, it is empty and does not contain any data entries, and the data entry counter is set to 0. The base generation module of the cloud server pre-selects a suitable base space A, for example ( ) the set of all prime numbers in as the base space. The elements in the base space will be used as the basis for generating verification values in the subsequent steps.
[0040] Step 1: The cloud environment receives the input data. The data encoding module converts the data content of each data block into an element in the integral domain . For example, assume that the data content is 300-bit binary data "100...001", and the data encoding module converts it into the element , where the data length is required. The data encoding module generates an element group for the data block, which respectively represents the ID of the data block, the data length, and the converted element, and sends the generated element group to the metric module of the cloud server.
[0041] Step 2: The metric module on the cloud environment receives the element group sent by the user terminal. The metric module first checks whether the data block ID in the element group exists in the standard value library.
[0042] Step 3: If the data label in the element group does not exist in the standard value library, the base generation module is called. The base generation module randomly selects a base q from uniformly at random and returns it to the metric module.
[0043] Step 4: The metric module performs a modulo (remainder) operation on the element with the selected base q to obtain a remainder r, and creates a new data entry , which is stored in the standard value library, where is the data label. is the data length of this data. is the base selected for this data. is the calculated remainder, which serves as the standard check value for this data block. All data in the standard value library is stored confidentially and is only used internally by the integrity check system of the present invention. The measurement module outputs data T = 2, indicating to the user terminal or other systems that the received data block is a new data block and its integrity check value has been generated and securely stored.
[0044] Step Five: When the cloud environment receives new data, repeat the processes of Step One to Step Four. When the cloud environment needs to verify the integrity of a stored data block (for example, before the data is used or during regular integrity checks), the measurement module will perform the following steps.
[0045] Step Six: The measurement module uses the ID of the data block as an index to read the corresponding stored data entry from the standard value library in the cloud environment. For distinction, the data entry read from the standard value library is denoted as , where is the stored data length, is the stored base, is the stored check value. The measurement module in the cloud environment compares the length of the retrieved data block with the data length in the corresponding data entry read from the standard value library. If , the measurement module outputs data T = 0, indicating that the length of the retrieved data block has changed compared to the previously stored data block, which usually means the data may have been tampered with.
[0046] Step Seven: If the data length in this element group is equal to the data length in this entry, use the element to calculate the new check value by taking the modulus of the base in this entry, and compare the new check value with the standard check value in this entry. If they are equal, output data T = 1, indicating that the retrieved data block is exactly the same as the previously stored data block and no changes have occurred.
[0047] Step Eight: If the new check value is not equal to the check value in this entry, output data T = 0, indicating that the content of the retrieved data block has changed compared to the previously stored data block, which usually means the data may have been tampered with.
[0048] Example 2: Data Integrity Check Based on TPCM
[0049] The following introduces an enhanced trusted boot scheme based on TPCM. TPCM is the integrity check system.
[0050] Initialization phase: The TPCM initializes its standard value library. The standard value library is used to store the check information of data blocks. In the initial state, it is empty and does not contain any data entries. The basis generation module pre-selects a suitable basis space A. For example, the set consisting of all prime numbers in ( ) is used as the basis space. The elements in the basis space will be used as the basis for generating check values in subsequent steps.
[0051] Step 1: In the phase of generating check information, key startup components such as BIOS / UEFI firmware, boot loader, and operating system kernel are divided into data blocks of a fixed size. The data tag, data length, and data block are regarded as an input data . The data encoding module converts the data content of each data block into an element in the integral ring . Taking BIOS as an example, assuming the data content is 300-bit binary data "100...001", the data encoding module converts it into the element , where the data length is required. The data encoding module generates an element group for this data block, representing the ID of the data block, the data length, and the converted element respectively.
[0052] Step 2: In the phase of generating check information, the measurement module calls the basis generation module. The basis generation module randomly selects a basis from uniformly at random and returns it to the measurement module. The measurement module calculates the check value of the BIOS data block and stores it in the standard value library. The entry value is , representing the data tag, data length, basis, and check value respectively. At the same time, it outputs data T = 2, indicating to the user terminal or other systems that the received data block is a new data block and its integrity check value has been generated and securely stored.
[0053] Step 3: In the trusted startup phase, for each data block of the key startup components to be loaded and executed, its integrity is verified in turn. Taking BIOS as an example, the data encoding module receives and encodes the BIOS data into an element in the integral ring , with the same operation as in Step 1.
[0054] Step 4: The measurement module accepts the result of the data encoding module , and retrieves the corresponding entry from the standard value library according to the data tag . For distinction, the data entry read from the standard value library is denoted as , where is the original length of the data, is the check value of the original data. If indicates that the data lengths are inconsistent, the measurement module outputs data T = 0, indicating that the retrieved data block has changed in length compared to the previously stored data block, and the trusted boot process terminates.
[0055] Step Five: If the length of the input data is equal to the data length in the standard value library entry, recalculate the check value of the input data , and compare the new check value with the standard check value in this entry . If they are equal, output data T = 1, indicating that the retrieved data block is exactly the same as the previously stored data block without any changes, and the trusted chain continues to be passed. If the calculated check value is not equal to the stored check value, output data T = 0, indicating that the content of the retrieved data block has changed compared to the previously stored data block, and the trusted boot process terminates.
[0056] Implement the algorithm of the present invention on Xilinx FPGA 100MHZ and conduct comparative experiments with mainstream algorithms SM3, SHA2-256, and SHA3-256. The results are as follows:
[0057] The present invention SM3 SHA2-256 SHA3-256 Throughput 10Gbps 3.5Gbps 3Gbps 4Gbps Resource occupancy (LUT) 300 600 650 450 Resource occupancy (FF) 230 500 500 380
[0058] It can be seen that the present invention is superior to the existing algorithms both in throughput and resource occupation.
[0059] The data involved in this technical solution refers to any record of information in electronic or other forms, especially the data stored in computing devices and network communication data.
Claims
1. A data storage integrity verification system based on an integral domain, characterized in that It includes a data encoding module, a basis generation module, a standard value library, and a metric module; the data encoding module, the basis generation module, and the standard value library are respectively connected to the metric module; the data involved refers to the data stored in the computing device and the network communication data; the data encoding module is used to convert the data to be integrity-verified in binary format into an integer to prepare for the subsequent integrity verification by the metric module, and the data to be integrity-verified is information recorded electronically; the basis generation module is used to select a basis space and generate a basis by means of random selection for the subsequent metric by the metric module. The metric module completes the integrity verification of the data by calling the basis generation module and the standard value library; the standard value library is used to store the standard integrity verification values of the input data to be integrity-verified.
2. The data storage integrity verification system based on an integral domain according to claim 1, wherein The data encoding module converts the input data to be integrity-checked into elements in the integral ring Let the input data to be integrity-checked be , where is the data label of the data to be integrity-checked, is the data length of the data to be integrity-checked, is the data content of the data to be integrity-checked. The data encoding module converts into the element to form an element group .
3. The data storage integrity verification system based on an integral domain according to claim 1, characterized in that, Base space is a set with elements, and the basis is an element in the base space and is randomly generated.
4. The data storage integrity verification system based on an integral domain according to claim 1, wherein The standard value library stores the standard integrity verification values according to entries, and the specific structure of each entry is as follows: A data tag for the standard integrity check value The data length of the standard integrity check value They are respectively the base selected for the standard integrity check value and the standard check value Is the number of data entries in the standard value library. All standard integrity check values in the reference value library are stored confidentially and used within the integrity check system 5. The data storage integrity verification system based on an integral domain according to claim 1, wherein The measurement module receives the element group , checks whether it is in the standard value library; 1) If is not in the standard value library, the base generation module is called. The base generation module randomly selects in the base space A and returns it to the metric module. The metric module uses to perform a modulo operation on the base to generate a standard check value . is stored in the reference library. At the same time, the data T = 2 is output, indicating that the data to be integrity-checked is new data, and the standard integrity check value of the data to be integrity-checked has been generated and stored; 2) If In the standard value library, the measurement module reads out the corresponding standard integrity check value; assume the standard integrity check value read out from the standard value library is ; if , then the output data T = 0, indicating that the data to be integrity-checked has changed relative to the standard integrity check value; if , then use to perform a modulo operation on the base to generate a new standard check value ; if , then the output data T = 1, indicating that the data to be integrity-checked has not changed relative to the standard integrity check value, otherwise, the output data T = 0, indicating that the data to be integrity-checked has changed relative to the standard integrity check value. 6. A data storage integrity verification method using the system according to any one of claims 1-5, characterized in that, It includes the following steps: Initialization stage: The data in the standard value library is empty, the number of data entries is 0, and the basis generation module selects the basis space A. Step 1: Input the data to be integrity-checked. The data encoding module converts the data content of the input data to be integrity-checked into elements in the integral ring and generates an element group, and sends the element group to the metric module; Step 2: After the metric module receives the element group, it checks whether the data label of the data to be integrity-verified in the element group exists in the standard value library; if it exists, go to Step 5. Step 3: If the data label of the data to be integrity-verified in the element group does not exist in the standard value library, call the basis generation module to generate a basis. Step 4: The metric module takes the modulus of the element with the basis, stores the data label, data length, basis, and standard verification value of the standard integrity verification value in the standard value library, and increments the number of entries in the standard value library by 1; output data T = 2, indicating that the data to be integrity-verified is new data, and the standard integrity verification value of this data to be integrity-verified has been generated and stored. Step 5: If the data label of the data to be integrity-verified in the element group exists in the standard value library, the metric module reads out the entry corresponding to this data label from the standard value library using the data label of the data to be integrity-verified as the index. Step 6: Check whether the data length of the data to be integrity-verified in the element group is equal to the data length in this entry; if not, output data T = 0, indicating that the input data to be integrity-verified has been changed relative to the standard integrity verification value. Step 7: If the data length of the data to be integrity-verified in the element group is equal to the data length of the standard integrity verification value in this entry, take the modulus of the element with the basis in this entry to obtain a new standard integrity verification value; compare the new standard integrity verification value with the standard verification value in this entry. If they are equal, output data T = 1, indicating that the input data to be integrity-verified has not been changed relative to the standard integrity verification value. Step 8: If the new standard integrity verification value and the standard verification value in this entry are not equal, output data T = 0, indicating that the input data to be integrity-verified has been changed relative to the standard integrity verification value.
Citation Information
Patent Citations
Method for realizing information integrity based on continuous quantum walk hash algorithm
CN112564886A
Security management method based on data storage
CN113536396A
Data encryption and dynamic key management method based on quantum security protocol
CN119921951A
Method and system for remote verification of the integrity of a computer program in a computing unit to be checked
US20230333964A1