Full-chain Trusted Archiving Method for Data Element Circulation

Through the dual recording and hash value verification methods, the credibility problem of the transmission link during the data element flow is solved, and the trustworthiness of the full link is realized to ensure the security and authenticity of data transmission.

CN120281486BActive Publication Date: 2025-08-05JIANGSU RONGZE INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510751183.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-08-05
Estimated Expiration
2045-06-06

AI Technical Summary

Technical Problem

In the prior art, during the data element flow, the credibility of the evidence storage of the transmission link cannot be effectively guaranteed, which can easily lead to data leakage.

Method used

The dual recording and hash value verification method is used to double-link proof storage of data transmission requirements and actual paths, and a hash algorithm is used to ensure the credibility of the transmission path. Combining the encryption module and the traceability record module, a full-link credible proof storage is achieved.

Benefits of technology

It improves the credibility of evidence during data transmission, ensures the authenticity and integrity of the data circulation link, and avoids data leakage during transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281486B_ABST
    Figure CN120281486B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of trusted evidence storage for data circulation, and is used to solve the problem that during the data circulation process, the credibility of transmission link evidence cannot be guaranteed, which easily leads to data leakage. Specifically, it is a full-link trusted evidence storage method for data element circulation, including an encrypted element circulation module, an element tail chain overwriting module, a circulation traceability recording module and a credibility confirmation module; when transmitting data, the present invention performs dual recording according to the transmission requirements of the data and the actual transmission path of the data, thereby realizing dual-chain evidence storage at the demand side and the actual segment, increasing the recording means of the entire circulation link during data transmission, improving the comprehensiveness of the circulation link coverage, and being able to compare the transmission requirements and the actual transmission path by means of hash value verification, thereby determining whether the transmission requirements and the actual transmission path are the same, ensuring that during dual-chain evidence storage, link evidence credibility verification can be performed, and the authenticity of the data circulation link evidence can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of trusted evidence storage for data circulation, and specifically to a method for trusted evidence storage for the entire link of data element circulation. Background Art

[0002] Data elements include personal information, trade secrets, technical data, financial information, and other sensitive information. With the development of big data and intelligent technology, the demand for the circulation of data elements has increased. However, the circulation of data elements needs to ensure the security, privacy, and legality of the data. Therefore, the compliance and traceability of the circulation of data elements have become issues that must be addressed and guaranteed.

[0003] Hash algorithms, also known as digest algorithms, generally refer to the SHA family. They are a family of cryptographic hash functions and are FIPS-certified secure hash algorithms. They can calculate the fixed-length string corresponding to a digital message. If the input messages are different, the probability of them corresponding to different strings is very high. Therefore, by comparing hash values, it is possible to confirm whether two sets of original information are the same without accessing the original information.

[0004] In existing technologies, the compliance and traceability of data element circulation are mostly addressed through single-mode evidence storage methods. Path evidence information is generally stored unencrypted or reversibly encrypted using symmetric or asymmetric encryption, leaving it vulnerable to tampering or subsequent manipulation after decryption. This makes it impossible to guarantee the credibility of evidence stored in the data circulation link.

[0005] In response to the above technical problems, this application proposes a solution. Summary of the Invention

[0006] When transmitting data, the present invention performs dual recording based on the transmission requirements of the data and the actual transmission path of the data, thereby realizing dual-chain evidence storage at the demand side and the actual segment, increasing the recording means of the entire circulation link during data transmission, improving the comprehensive coverage of the circulation link, and can also compare the transmission requirements and the actual transmission path by means of hash value verification to determine whether the transmission requirements and the actual transmission path are the same, ensuring that the credibility of the link evidence can be verified during dual-chain evidence storage, and can ensure the authenticity of the data circulation link evidence, thereby solving the problem that the credibility of the transmission link evidence cannot be guaranteed during data circulation, which easily leads to data leakage, and proposes a full-link trusted evidence storage method for data element circulation.

[0007] The purpose of the present invention can be achieved through the following technical solutions:

[0008] The full-link trusted evidence storage method for data element circulation includes the following steps:

[0009] Step 1: Classify and encrypt the original data elements to obtain the initial ciphertext information;

[0010] Step 2: Obtain the circulation requirements of data elements and perform hash encryption;

[0011] Step 3: Record the actual circulation path of the data elements and perform hash encryption as well;

[0012] Step 4: Each time a data circulation requirement is obtained, the original hash value and the new circulation requirement are combined and hashed and encrypted;

[0013] Step 5: Each time the actual circulation path is obtained, the original hash value and the new actual circulation path are combined and hashed and encrypted;

[0014] Step 6: Compare the hash values in step 4 and step 5 to determine the credibility of the path evidence.

[0015] As a preferred embodiment of the present invention, the device further includes a data element encryption module, an encryption element circulation module, an element tail chain overwriting module, a circulation traceability recording module, and a credibility confirmation module. The data element encryption module is used to encrypt the data element and send the encrypted ciphertext to the encryption element circulation module.

[0016] After the encrypted element circulation module obtains the ciphertext, it encapsulates the ciphertext and obtains the data circulation demand through the network. At the same time, the encrypted element circulation module sends the circulation demand to the element tail chain overwriting module;

[0017] After receiving the circulation demand, the element tail chain overwriting module creates a path tail chain according to the circulation demand, adds the path tail chain to the end of the encapsulated ciphertext, stores it as a tracer ciphertext, and feeds the tracer ciphertext back to the encryption element circulation module;

[0018] The circulation traceability recording module records the circulation path of the tracer ciphertext and feeds the circulation path record back to the cloud each time it circulates;

[0019] After obtaining the tracer ciphertext, the encryption element circulation module sends the tracer ciphertext according to the circulation demand;

[0020] The credibility confirmation module obtains the circulation path record through the cloud, obtains the path tail chain through the element tail chain overwriting module, matches the path tail chain with the circulation path, and generates credibility data according to the matching result.

[0021] As a preferred embodiment of the present invention, the data element encryption module first splits the data elements when encrypting the data elements, thereby splitting the data elements into two areas: basic data and usage rights data, and applies different encryption methods and encryption weights to the data elements in the two areas when encrypting.

[0022] As a preferred embodiment of the present invention, the encryption element circulation module obtains the data element ciphertexts of the basic data and usage right data areas and then integrates and encapsulates them to transform them into a complete ciphertext;

[0023] The circulation requirements obtained by the encryption element circulation module include the previous holder, the current holder and the next holder, where the previous holder is the source direction of the ciphertext and the next holder is the data sending direction. When the previous holder does not exist, it is replaced by placeholder data.

[0024] As a preferred embodiment of the present invention, the element tail chain overwriting module creates a path tail chain after first acquiring the circulation demand. When creating the path tail chain, the circulation demand is hashed to obtain a string of determined hash values, and the hash values are combined with the encapsulated ciphertext to obtain the tracer ciphertext.

[0025] When the element tail chain overwriting module obtains the circulation demand again in the future, it merges the existing hash value path tail chain in the tracer ciphertext and the new circulation demand, and hashes the merged data again to obtain a new hash value, and overwrites the original hash value path tail chain with the new hash value path tail chain to form a new tracer ciphertext.

[0026] As a preferred embodiment of the present invention, the circulation traceability recording module records the actual circulation path of the data when the tracer ciphertext is circulated for the first time, and also obtains a set of actual circulation paths including the previous holder, the current holder, and the next holder. The actual circulation paths are hashed to obtain a set of hash values, which are recorded as path records;

[0027] When the circulation traceability recording module subsequently circulates data, it also merges the original hash value and the new actual circulation path, and records the path again, thereby obtaining a new hash value again;

[0028] The circulation traceability record module feeds back the latest hash value to the cloud in real time.

[0029] As a preferred embodiment of the present invention, when generating credibility, the credibility confirmation module obtains the latest tracer ciphertext through the element tail chain overwrite module, extracts the hash value at the end of the tracer ciphertext, and obtains the latest hash value feedback through the cloud at the same time. The two sets of hash values are compared. If the hash values are the same, the path evidence is judged to be credible. If the hash values are different, the path evidence is judged to be unreliable.

[0030] Compared with the prior art, the present invention has the following beneficial effects:

[0031] 1. In the present invention, when data is transmitted, dual records are made based on the data transmission requirements and the actual data transmission path, thereby realizing dual-chain evidence storage at the demand side and the actual segment, and then realizing traceability evidence storage during data transmission based on the dual-chain evidence results, thereby increasing the recording means of the entire circulation link during data transmission and improving the comprehensive coverage of the circulation link.

[0032] 2. In the present invention, the transmission requirement and the actual transmission path are compared by hash value verification to determine whether the transmission requirement and the actual transmission path are the same, ensuring that the credibility of the link evidence can be verified when the dual chain evidence is stored, and the authenticity of the data flow link evidence can be guaranteed.

[0033] 3. In the present invention, the hash algorithm is used to output a fixed number of bytes that is independent of the number of input bytes. This ensures that during high-frequency long-link data transmission, the number of bytes used to store the transmission link will not increase with the increase in the number of transmissions, effectively avoiding the byte expansion of the file path record part during multiple transmissions. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] To facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings.

[0035] Figure 1 is a system block diagram of the present invention;

[0036] Figure 2 It is a system flow chart of the present invention. DETAILED DESCRIPTION

[0037] The following is a clear and complete description of the technical solutions of the present invention in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0038] Example 1: Please refer to Figure 1 - Figure 2 As shown in the figure, the full-link trusted evidence storage method for data element circulation includes the following steps:

[0039] Step 1: Classify and encrypt the original data elements to obtain the initial ciphertext information;

[0040] Step 2: Obtain the circulation requirements of data elements and perform hash encryption;

[0041] Step 3: Record the actual circulation path of the data elements and perform hash encryption as well;

[0042] Step 4: Each time a data circulation requirement is obtained, the original hash value and the new circulation requirement are combined and hashed and encrypted;

[0043] Step 5: Each time the actual circulation path is obtained, the original hash value and the new actual circulation path are combined and hashed and encrypted;

[0044] Step 6: Compare the hash values in step 4 and step 5 to determine the credibility of the path evidence.

[0045] Example 2: Please refer to Figure 1 - Figure 2 As shown, it also includes a data element encryption module, an encrypted element circulation module, an element tail chain overwriting module, a circulation traceability recording module and a credibility confirmation module. The data element encryption module is used to encrypt data elements;

[0046] When the data element encryption module encrypts the data elements, it first splits the data elements, thereby dividing the data elements into two areas: basic data and usage rights data. When encrypting, different encryption methods and encryption weights are applied to the data elements in the two areas, and the encrypted ciphertext is sent to the encryption element circulation module.

[0047] After obtaining the ciphertext of the data elements in the basic data and usage rights data areas, the encrypted element circulation module integrates and encapsulates them to transform them into a complete ciphertext, and obtains the data circulation requirements through the network. At the same time, the encrypted element circulation module sends the circulation requirements to the element tail chain overwriting module;

[0048] The circulation requirements obtained by the encryption element circulation module include the previous holder, the current holder, and the next holder. The previous holder is the source of the ciphertext, and the next holder is the data sending direction. If the previous holder does not exist, it is replaced by placeholder data.

[0049] After receiving the circulation demand, the element tail chain overwriting module creates a path tail chain according to the circulation demand, adds the path tail chain to the end of the encapsulated ciphertext, stores it as a tracer ciphertext, and feeds the tracer ciphertext back to the encryption element circulation module;

[0050] The specific creation process is:

[0051] After obtaining the circulation demand for the first time, the element tail chain overwriting module creates the path tail chain. When creating the path tail chain, the circulation demand is hashed to obtain a string of fixed hash values, and the hash value is combined with the encapsulated ciphertext to obtain the tracer ciphertext.

[0052] Each time the element tail chain overwriting module obtains the circulation demand, it merges the existing hash value path tail chain in the tracer ciphertext with the new circulation demand, and hashes the merged data again to obtain a new hash value. The new hash value path tail chain overwrites the original hash value path tail chain to form a new tracer ciphertext, thereby overwriting the hash value path tail chain at the end of the tracer ciphertext.

[0053] After obtaining the tracer ciphertext, the encryption element circulation module sends the tracer ciphertext according to the circulation requirements;

[0054] When the tracer ciphertext circulates data for the first time, the circulation traceability record module records the actual circulation path of the data and obtains a set of actual circulation paths including the previous holder, current holder, and next holder. The actual circulation path is hashed and encrypted to obtain a set of hash values, which are recorded as path records and fed back to the cloud.

[0055] When the circulation traceability record module subsequently circulates data, it will also merge the original hash value and the new actual circulation path, and record the path again to obtain a new hash value;

[0056] The circulation traceability record module then feeds back the latest hash value to the cloud in real time;

[0057] The credibility confirmation module obtains the records of the circulation path through the cloud, and obtains the latest tracer ciphertext through the element tail chain overwriting module, and extracts the hash value of the path tail chain at the end of the tracer ciphertext. At the same time, it obtains the latest hash value feedback through the cloud and compares the two sets of hash values. If the hash values are the same, the path evidence is judged to be credible. If the hash values are different, the path evidence is judged to be unreliable, thereby generating credibility data.

[0058] The preferred embodiments of the present invention disclosed above are intended only to help illustrate the present invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the present invention to specific embodiments. Obviously, many modifications and variations are possible based on the contents of this specification. These embodiments are selected and described in detail in this specification to better explain the principles and practical applications of the present invention, thereby enabling those skilled in the art to better understand and utilize the present invention. The present invention is limited only by the claims and their full scope and equivalents.

Claims

1. A trusted evidence storage method for the entire chain of data element circulation, characterized by: The following steps are involved: Step 1: Classify and encrypt the original data elements to obtain the initial ciphertext information; Step 2: Obtain the circulation requirements of data elements and perform hash encryption; Step 3: Record the actual circulation path of the data elements and perform hash encryption as well; Step 4: Each time a data circulation requirement is obtained, the original hash value and the new circulation requirement are combined and hashed and encrypted; Step 5: Each time the actual circulation path is obtained, the original hash value and the new actual circulation path are combined and hashed and encrypted; Step 6: Compare the hash values in step 4 and step 5 to determine the credibility of the path evidence; It also includes a data element encryption module, an encryption element circulation module, an element tail chain overwriting module, a circulation traceability recording module and a credibility confirmation module. The data element encryption module is used to encrypt the data elements and send the encrypted ciphertext to the encryption element circulation module; After the encrypted element circulation module obtains the ciphertext, it encapsulates the ciphertext and obtains the data circulation demand through the network. At the same time, the encrypted element circulation module sends the circulation demand to the element tail chain overwriting module; After receiving the circulation demand, the element tail chain overwriting module creates a path tail chain according to the circulation demand, adds the path tail chain to the end of the encapsulated ciphertext, stores it as a tracer ciphertext, and feeds the tracer ciphertext back to the encryption element circulation module; The circulation traceability recording module records the circulation path of the tracer ciphertext and feeds the circulation path record back to the cloud each time it circulates; After obtaining the tracer ciphertext, the encryption element circulation module sends the tracer ciphertext according to the circulation demand; The credibility confirmation module obtains the circulation path record through the cloud, obtains the path tail chain through the element tail chain overwriting module, matches the path tail chain with the circulation path, and generates credibility data based on the matching results; When encrypting data elements, the data element encryption module first splits the data elements into two areas: basic data and usage rights data. Different encryption methods and encryption weights are applied to the data elements in the two areas during encryption. The encryption element circulation module obtains the data element ciphertexts of the basic data and usage right data areas, integrates and packages them, and thus transforms them into a complete ciphertext; The circulation requirements obtained by the encryption element circulation module include the previous holder, the current holder and the next holder, where the previous holder is the source direction of the ciphertext and the next holder is the data sending direction. When the previous holder does not exist, it is replaced by placeholder data.

2. The method for credible evidence storage of the entire data element circulation chain according to claim 1 is characterized in that: The element tail chain overwriting module creates a path tail chain after first acquiring the circulation demand. When creating the path tail chain, the circulation demand is hashed to obtain a string of determined hash values, and the hash values are combined with the encapsulated ciphertext to obtain the tracer ciphertext. When the element tail chain overwriting module obtains the circulation demand again in the future, it merges the existing hash value path tail chain in the tracer ciphertext and the new circulation demand, and hashes the merged data again to obtain a new hash value, and overwrites the original hash value path tail chain with the new hash value path tail chain to form a new tracer ciphertext.

3. The method for credible evidence storage of the entire data element circulation chain according to claim 1 is characterized in that: The circulation traceability recording module records the actual circulation path of the data when the tracer ciphertext circulates data for the first time, and also obtains a set of actual circulation paths including the previous holder, the current holder, and the next holder. The actual circulation paths are hashed to obtain a set of hash values, which are recorded as path records; When the circulation traceability recording module subsequently circulates data, it also merges the original hash value and the new actual circulation path, and records the path again, thereby obtaining a new hash value again; The circulation traceability record module feeds back the latest hash value to the cloud in real time.

4. The method for credible evidence storage of the entire data element circulation chain according to claim 1 is characterized in that: When generating credibility, the credibility confirmation module obtains the latest tracer ciphertext through the element tail chain overwriting module, extracts the hash value at the end of the tracer ciphertext, and obtains the latest hash value feedback through the cloud at the same time. The two sets of hash values are compared. If the hash values are the same, the path evidence is judged to be credible. If the hash values are different, the path evidence is judged to be unreliable.

Citation Information

Patent Citations

  • Method, system and device for storing electronic archives based on block chain, and medium

    CN115982764A

  • Trusted data tracing method and system based on block chain trust root thought

    CN117852103A