Data archiving method and system for archive management system
Through fully homomorphic encryption, Merkle-Tree and blockchain technology, the problems of insufficient data security, integrity and query efficiency in traditional archive management systems are solved, and efficient and secure data storage and query are achieved.
Patent Information
- Application Number
- CN202510347360.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-07-11
AI Technical Summary
Traditional archive management systems have problems such as insufficient security, integrity, privacy protection and query efficiency in data storage. Especially in large-scale data environments, centralized management is susceptible to single point of failure, hash verification cannot prove the integrity of stored procedures, limited access control mechanism, and limited query performance.
Fully homomorphic encryption technology is used to encrypt and store data in a decentralized system, build a Merkle-Tree structure and store it on the blockchain, combine zk-STARKs and FRI optimization integrity verification, privacy query is conducted based on zero-knowledge proof, and data access control is carried out through the blockchain's access permission management mechanism.
It realizes full encryption protection of data during storage and computing, ensures data security and integrity, supports efficient query and privacy protection, and is suitable for high-privacy demand scenarios.
Smart Images

Figure CN120295968A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data storage, and specifically provides a data archiving method and system for an archive management system. Background Art
[0002] In the field of large-scale data storage and management, traditional archive filing systems widely adopt a centralized storage architecture and combine access control and encryption technologies to ensure data security. Generally, archived data is stored in a database or a file system, and symmetric encryption (such as AES) or asymmetric encryption (such as RSA) is used to protect the confidentiality of the data. At the same time, hash verification is used to ensure the integrity of the data. Some systems also combine a role-based access control (RBAC) mechanism to implement different user permission management. In addition, to improve query efficiency, existing solutions usually rely on indexing technologies, such as B+ trees or hash indexes, to establish a query optimization mechanism in the storage structure. These technologies have been widely applied in data archiving management and have improved data security and availability to a certain extent.
[0003] However, with the growth of data scale and the improvement of security requirements, some limitations of traditional filing solutions have gradually emerged.
[0004] On the one hand, the traditional storage architecture relies on centralized management, making the data vulnerable to single-point failures or malicious attacks during storage, calculation, and access. At the same time, key management is complex, and there are still difficulties in computational operations after data encryption. On the other hand, hash verification can only verify whether the data has been tampered with, but cannot prove the integrity of the storage process, making it difficult to meet the security requirements for long-term storage. In addition, most access control mechanisms rely on a central server. Once the server is attacked or the data permissions are tampered with, it may lead to unauthorized access, and the privacy protection mechanism is also relatively limited. For data queries, existing technologies still need to rely on plaintext operations, with insufficient privacy computing capabilities. At the same time, in a large-scale data environment, query performance is limited. Therefore, how to achieve efficient querying, privacy protection, and verifiable computing while ensuring data security has become an urgent problem to be solved in the data archiving technology of archive management systems. Summary of the Invention
[0005] Aiming at the deficiencies of the prior art, the present invention provides a data archiving method and system for an archive management system, which solves the problems of insufficient security, integrity, privacy protection, and query efficiency in traditional data storage solutions.
[0006] To achieve the above objectives, the present invention is realized through the following technical solutions: A data archiving method for an archive management system includes the following steps:
[0007] S1. Data storage: Receive archived data, perform data chunking, fully homomorphic encryption processing, and hash calculation, then store the encrypted data in a decentralized storage system. Meanwhile, construct a Merkle-Tree structure to store data indexes and store the root hash value in the blockchain;
[0008] S2. Integrity verification: After data storage is completed, generate a verifiable computation proof for the archived data based on zk-STARKs and optimize it using FRI;
[0009] S3. Privacy query: Generate a proof of the existence of archived data based on zero-knowledge proof and perform queries on the encrypted data based on fully homomorphic encryption calculation;
[0010] S4. Data access management: Based on the access permission management mechanism of the blockchain, combine multi-party secure computation for permission verification and verify access permissions before data decryption.
[0011] Preferably, the data storage includes:
[0012] Receive archived data and verify its integrity;
[0013] Split the archived data into multiple data chunks;
[0014] Perform fully homomorphic encryption on each data chunk;
[0015] Calculate the hash value of each data chunk and recursively calculate the Merkle-Tree root hash value;
[0016] Store the encrypted data chunks in a decentralized storage system and store the root hash value in the blockchain.
[0017] Preferably, the integrity verification includes:
[0018] Calculate the zk-STARKs verifiable computation proof for the archived data;
[0019] Optimize the zk-STARKs proof using FRI technology to reduce computational complexity;
[0020] When verifying data integrity, call the zk-STARKs proof and verify it based on the root hash value stored in the blockchain.
[0021] Preferably, the privacy query includes:
[0022] The user submits a query request;
[0023] Generate a query proof based on zero-knowledge proof;
[0024] Perform queries based on fully homomorphic encryption calculation and complete the operation directly on the encrypted data;
[0025] Return the encrypted query result to the user.
[0026] Preferably, the fully homomorphic encryption calculation process includes:
[0027] Perform homomorphic calculation on the archived data;
[0028] Adopt homomorphic addition and homomorphic multiplication to maintain the encrypted state of the calculation result;
[0029] After the query result is returned to the user, the user uses the private key to decrypt and obtain the query result.
[0030] Preferably, the data access management stage includes:
[0031] Verify the user's permission before access;
[0032] Verify the permission information based on the multi-party secure computing mechanism;
[0033] After the verification passes, the user obtains the decryption key and performs data decryption.
[0034] Preferably, the blockchain-based permission management mechanism includes:
[0035] Store the access control list in the blockchain;
[0036] Implement dynamic permission updates through smart contracts and record the change history;
[0037] Record the access logs on the blockchain.
[0038] Preferably, the data index of the blockchain includes:
[0039] Merkle-Tree root hash value;
[0040] zk-STARKs proof index;
[0041] Access permission record.
[0042] An archive management system data archiving system includes:
[0043] A storage module for receiving archived data, chunking and encrypting the data for storage, constructing a Merkle-Tree structure, and recording the root hash value in the blockchain;
[0044] An integrity verification module for calculating data integrity proofs based on zk-STARKs and FRI technologies and providing integrity verification upon verification requests;
[0045] A query module, which is used to perform data queries based on zero - knowledge proofs, enabling users to verify the existence of data without obtaining the data content and performing query calculations in the encrypted state based on fully homomorphic encryption calculations;
[0046] A permission management module, which is used to manage data access permissions based on smart contracts, maintain an access control list, and support dynamic permission updates;
[0047] An access control module, which is used to record access logs and, when a user requests access to data, verify the user's identity and provide data access permissions after authorization.
[0048] Preferably, the storage module is connected to the integrity verification module. After the data storage is completed, the storage module submits the hash information of the stored data to the integrity verification module, and the integrity verification module calculates the zk - STARKs proof based on the hash information and returns it to the storage module;
[0049] The storage module is connected to the query module. After receiving a query request, the query module obtains relevant data indexes from the storage module and performs query calculations;
[0050] The integrity verification module is connected to the query module. When the query module executes a query, it calls the zk - STARKs proof provided by the integrity verification module to perform data integrity verification;
[0051] The query module is connected to the permission management module. When processing a user query, the query module verifies the user's permissions with the permission management module, and only allows query calculations to be executed after the permission verification passes;
[0052] The permission management module is connected to the access control module. When a user requests access to data, the access control module verifies the user's permissions with the permission management module and decides whether to allow access to the data based on the permission verification result.
[0053] The present invention provides a method and a system for data archiving in an archive management system. It has the following
[0054] Beneficial effects:
[0055] 1. The present invention encrypts data storage through fully homomorphic encryption, and at the same time combines zero - knowledge proofs and zk - STARKs for integrity verification, achieving full - process encryption protection of data during storage and calculation, ensuring data security. Compared with the existing solutions that use symmetric encryption or only store hash values, the present invention avoids the key management risk and at the same time realizes secure calculations in the encrypted state, solving the problem that traditional encryption methods cannot be used in scenarios where both storage and calculation coexist.
[0056] 2. The present invention constructs a data index through a Merkle-Tree structure and stores the root hash value in the blockchain, achieving the effects of data immutability and verifiability. The prior art usually relies on a centralized database for data storage, posing risks of being tampered with or suffering from single-point failures. By combining a decentralized storage system with blockchain evidence storage, the present invention enables data to maintain integrity over a long period after storage, avoiding the problem that data may be modified due to database attacks or misoperations in traditional solutions.
[0057] 3. The present invention uses zero-knowledge proofs to prove data queries and performs calculations on encrypted data in combination with fully homomorphic encryption, achieving the purpose of completing data queries and verifications without exposing the original data. Compared with the prior art solutions that use plaintext storage or access control-based methods, the present invention allows users to perform data operations in a fully encrypted state, avoiding the risk of privacy leakage caused by permission management vulnerabilities, and is particularly applicable to scenarios with high privacy requirements such as medical and financial fields.
[0058] 4. The present invention optimizes data integrity verification calculations by combining zk-STARKs with the FRI technique, achieving the effects of reducing computational complexity and improving query efficiency. Compared with the prior art methods that directly calculate hash values or rely on centralized index queries, the present invention reduces storage overhead and improves the availability of archived data in a large-scale storage environment, solving the problem of limited query speed in traditional solutions under high concurrency or large data volume conditions. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 is a flowchart of the method steps of the present invention;
[0060] Figure 2 is a schematic diagram of the system modules of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0061] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0062] Embodiment 1:
[0063] Please refer to the attached Figure 1 , the embodiment of the present invention provides a method for archiving data in an archive management system, including the following steps:
[0064] S1. Data Storage: Receive archived data, perform data chunking, fully homomorphic encryption processing, and hash calculation, then store the encrypted data in a decentralized storage system. Meanwhile, construct a Merkle-Tree structure to store data indexes and store the root hash value in the blockchain;
[0065] S2. Integrity Verification: After data storage is completed, generate a verifiable computation proof for the archived data based on zk-STARKs and optimize it using FRI;
[0066] S3. Privacy Query: Generate a proof of the existence of archived data based on zero-knowledge proof and perform queries on the encrypted data based on fully homomorphic encryption calculation;
[0067] S4. Data Access Management: Based on the access permission management mechanism of the blockchain, combine multi-party secure computation for permission verification and verify access permissions before data decryption;
[0068] Data storage includes:
[0069] Receive archived data and verify its integrity;
[0070] Split the archived data into multiple data chunks;
[0071] Perform fully homomorphic encryption on each data chunk;
[0072] Calculate the hash value of each data chunk and recursively calculate the Merkle-Tree root hash value;
[0073] Store the encrypted data chunks in a decentralized storage system and store the root hash value in the blockchain;
[0074] Integrity verification includes:
[0075] Calculate the zk-STARKs verifiable computation proof for the archived data;
[0076] Optimize the zk-STARKs proof using FRI technology to reduce computational complexity;
[0077] When verifying data integrity, call the zk-STARKs proof and verify it based on the root hash value stored in the blockchain;
[0078] Privacy query includes:
[0079] The user submits a query request;
[0080] Generate a query proof based on zero-knowledge proof;
[0081] Perform queries based on fully homomorphic encryption calculation and directly complete operations on the encrypted data;
[0082] Return the encrypted query result to the user;
[0083] The fully homomorphic encryption calculation process includes:
[0084] Perform homomorphic calculation on the archived data;
[0085] Adopt homomorphic addition and homomorphic multiplication to maintain the encrypted state of the calculation result;
[0086] After the query result is returned to the user, the user uses the private key to decrypt and obtain the query result;
[0087] The data access management stage includes:
[0088] Verify the user's permissions before access;
[0089] Based on the multi-party secure computing mechanism, verify the permission information;
[0090] After the verification passes, the user obtains the decryption key and performs data decryption;
[0091] The permission management mechanism based on blockchain includes:
[0092] Store the access control list in the blockchain;
[0093] Implement dynamic permission updates through smart contracts and record the change history;
[0094] Record the access logs on the blockchain;
[0095] The data index of the blockchain includes:
[0096] Merkle-Tree root hash value;
[0097] zk-STARKs proof index;
[0098] Access permission record.
[0099] Specifically, in step S1, data storage is the primary step of data archiving. The goal of this step is to receive the archived data, ensure the security and integrity of the data, and store it in a decentralized storage system. Through data chunking and encryption, data leakage or tampering can be effectively prevented. At the same time, to facilitate subsequent data retrieval and verification, the system constructs a Merkle-Tree structure and stores the root hash value on the blockchain to ensure the immutability and traceability of the data.
[0100] In this embodiment, the system first receives the data to be archived. After receiving the data, the system will first perform an integrity check on the data to ensure that the data has not been lost or damaged. Generally, this check is implemented by calculating the hash value of the data. The hash function H(D) calculates the unique identifier H(D) of the data D to be stored for subsequent verification. This process is carried out before data storage to ensure the accuracy of the data.
[0101] As an option, the data will be split into multiple data blocks. This splitting strategy helps to improve the flexibility and security of data storage. Specifically, after the data is chunked, each data block is encrypted independently. The encryption process uses fully homomorphic encryption technology. Fully homomorphic encryption allows data calculations to be performed in the encrypted state, thus avoiding the need to decrypt the original data. During the encryption process, the data block D i is transformed into ciphertext through the homomorphic encryption algorithm E(D i ):
[0102] E(D i ) = Encrypt(D i );
[0103] Wherein, E(D i ) represents the ciphertext of the data block D i after full homomorphic encryption, and Encrypt(D i ) represents the function for encrypting the data block D i .
[0104] Specifically, all encrypted data blocks will be stored in a decentralized storage system. The decentralized storage system (such as IPFS or similar technologies) jointly maintains the data by multiple nodes to ensure its high availability and anti-tampering. The hash value of each data block will be calculated and stored for subsequent integrity verification.
[0105] In another implementation, the system will use a Merkle-Tree to construct an index structure for the data blocks. Specifically, the system calculates the hash value H i of each data block and recursively calculates the root hash value H root , and this root hash value serves as the unique identifier for the entire data set. The Merkle-Tree root hash value H root can be calculated by the following formula:
[0106] H root = MerkleHash(H1, H2, …, H n );
[0107] Wherein, H1, H2, …, H n are the hash values of the data blocks; H rootis the root hash value; MerkleHash is the hash calculation function of the Merkle tree. The calculation of the root hash value makes the data structure have good verifiability. Any change in the data block will cause a change in the root hash value, so that it can quickly detect whether the data has been tampered with.
[0108] At the end of the step, the system will calculate the obtained root hash value H root and store it in the blockchain. The introduction of blockchain technology makes the storage of data indexes have immutability and public transparency. Each modification, update or access of data will leave corresponding records on the blockchain, ensuring the traceability and auditability of data. The storage of the root hash value on the blockchain is realized through a smart contract, which is responsible for managing the access rights and update operations of data.
[0109] Specifically, the smart contract in the blockchain will automatically record the root hash value H root , and generate corresponding transaction records for each storage or update operation. The decentralized feature of the blockchain ensures the security and fairness of data indexes.
[0110] As a further optimization solution, the system can combine the timestamp technology to ensure the timeliness of data storage. During each data storage process, the system will automatically generate a timestamp T and store the timestamp together with the root hash value in the blockchain. The introduction of the timestamp can effectively prevent data tampering and forgery.
[0111] In step S2, after the data storage is completed, it is necessary to verify the integrity of the archived data. This step generates a verifiable computational proof of the archived data through zk-STARKs technology and combines FRI to optimize the calculation process, thereby reducing the computational complexity and improving the verification efficiency. Generally, this integrity verification process depends on the encrypted data stored in the decentralized storage system and combines the Merkle-Tree root hash value stored on the blockchain to achieve efficient verification of the stored data.
[0112] In this embodiment, the process of integrity verification includes the following key parts:
[0113] First, after the data storage is completed, perform zk-STARKs calculation on the archived data to generate a corresponding verifiable computational proof. zk-STARKs is a zero-knowledge proof protocol that can generate a compact mathematical proof without revealing the content of the original data, proving the correctness of data storage. As an option, to improve the computational efficiency, multiple rounds of hash operations are used in the proof calculation process, and the Merkle-Tree structure information of the stored data is used as the proof input, so that the generated proof can be directly matched and verified with the root hash value on the blockchain.
[0114] Specifically, the zk-STARKs calculation process involves multiple mathematical operations, including polynomial calculation and hash calculation. In one possible implementation, the archived data D is first polynomially mapped to represent it as a polynomial P(x) over a finite field. This polynomial is calculated by Lagrange interpolation and can be expressed in the form:
[0115]
[0116] where P(x) represents a polynomial function; with x as the independent variable; a i is the coefficient obtained by converting the corresponding data block during the data archiving process; x is a pre-selected element within the field; x i is the i-th power of the variable x; i = n and all are constants.
[0117] To ensure the efficiency of the calculation proof, this embodiment uses the FRI technique to optimize the zk-STARKs proof calculation. Generally, FRI recursively reduces the verification problem of high-order polynomials through multiple rounds of interactive verification, thereby reducing the computational complexity. In some embodiments, when using FRI for optimization, first through recursive dimensionality reduction, the original polynomial P(x) is converted into multiple low-order sub-polynomials:
[0118] P′(x) = P(x) mod (x - r);
[0119] where P′(x) represents the result of taking the modulus of the polynomial P(x) with respect to (x - r); that is, the reduced-order polynomial, P(x) is the original polynomial, usually a high-order polynomial; mod represents polynomial division of P(x), only retaining the remainder part; r is a selected random value, and this conversion process can reduce the proof scale and improve the computational efficiency.
[0120] In addition, during the data integrity verification process, the proof value generated by zk-STARKs needs to be compared with the Merkle-Tree root hash value stored on the blockchain to verify the integrity of the stored data. As an option, in some embodiments, the SHA-256 hash algorithm can be used to perform a secondary hash calculation on the proof value generated by zk-STARKs to enhance the anti-tampering ability and ensure the security of data integrity verification. Specifically, the hash calculation formula is as follows:
[0121] H = SHA-256(Z);
[0122] where H is the finally calculated hash value; Z is the integrity proof data generated by zk-STARKs calculation; SHA-256 is a secure hash algorithm belonging to the SHA-2 family, which can perform one-way hash calculation on the input data and output a 256-bit hash value of a fixed length.
[0123] In a possible implementation, data integrity verification can be performed using a smart contract. The smart contract stores pre-deployed zk-STARKs verification logic and, when a user initiates a verification request, calls the root hash value stored on the blockchain for matching calculations. Generally, the smart contract checks the correctness of the zk-STARKs proof and returns a success flag after successful verification to ensure that users can trust the integrity of the data storage.
[0124] In step S3, the privacy query, as a key step, ensures the verifiability and privacy protection of data queries while ensuring data security. This step needs to be closely integrated with the aforementioned data storage, integrity verification, and access control mechanisms to ensure that data queries can meet privacy protection requirements and provide verification of computational correctness. Specifically, the query process should be executed in a fully homomorphic encryption environment so that query calculations can be directly performed on encrypted data, and combined with zero-knowledge proof technology to achieve verification of the correctness of query results. In addition, the privacy query process should balance computational efficiency and storage optimization, adopt a zk-STARKs-based method to ensure the verifiability of query calculations, and combine FRI technology to reduce computational overhead and improve computational efficiency.
[0125] In this embodiment, the privacy query mainly includes the following aspects:
[0126] First, when a user initiates a query request, relevant query parameters need to be provided, such as query keywords or data index information. Generally, the specific parameters of the user's query should be submitted in encrypted form to prevent external snooping and avoid leakage of sensitive information. As an option, encrypted keyword search technology can be used to construct a query index so that the query request can be matched on encrypted data without revealing the specific content.
[0127] Second, during the data query process, the query operation should be performed in a fully homomorphic encryption environment. Specifically, the query calculation formula can be expressed as follows:
[0128] Q(E(D n ),P)=E(f(D,P));
[0129] where E(D n ) represents the encrypted stored data; P is the query parameter; f(D,P) represents the query function executed on the plaintext data D; and Q(E(D n), P) represents the query result calculated in the encrypted environment; E(f(D, P)) indicates that the result of the query calculation remains in the encrypted state. Since fully homomorphic encryption supports homomorphic addition and homomorphic multiplication, operations can be directly performed on the encrypted data without decrypting the data. For example, in some embodiments, BFV (Brakerski-Fan-Vercauteren) or CKKS (Cheon-Kim-Kim-Song) encryption schemes can be adopted to support numerical calculations or approximate calculations, thereby meeting the requirements of different query types.
[0130] In addition, to ensure the correctness of the query result, zero-knowledge proof technology needs to be combined for verification. Generally, zero-knowledge proof is used to prove that the query result is correctly calculated from the encrypted data without revealing the content of the original data. As an option, zk-STARKs technology is adopted to generate a verifiable computation proof for the query calculation, and the calculation of this proof can be expressed as follows:
[0131] π = Prove(Q(E(D), P));
[0132] where π represents the zero-knowledge proof of the query calculation; Prove is the zk-STARKs generation function; Q represents the operation applied to the subsequent parameters; E(D) represents another operation applied to D; E is a function; P is another variable or component participating in the proof.
[0133] Specifically, in some embodiments, the proof process can utilize the Merkle-Tree index structure to include the data blocks involved in the query and their hash values in the proof scope to enhance the verifiability of the proof while reducing the computational and storage overhead.
[0134] In a possible implementation, the FRI technology can be used to optimize the zk-STARKs proof and reduce the computational complexity. FRI mainly utilizes the characteristics of low-degree polynomials to reduce the computational amount of proof generation and verification by reducing the number of polynomial evaluation points. For example, in data queries, if the computational function involved in the query can be approximated as a low-degree polynomial, the proof calculation process can be optimized by FRI to improve the computational efficiency.
[0135] Finally, when the query result is returned to the user, the user can decrypt the query result using the private key. Generally, the decryption process can be expressed as follows:
[0136] D Q = Decrypt(Q(E(D), P), sk);
[0137] where D Qis the decrypted query result; Decrypt is the decryption function; sk represents the user's private key. In some embodiments, the user can further utilize a hash verification mechanism to verify the integrity of the decrypted query result to ensure the correctness of the query calculation.
[0138] In summary, this step realizes the security of data query calculation through fully homomorphic encryption technology, combines zero-knowledge proof to ensure the verifiability of the query result, and adopts FRI to optimize the zk-STARKs proof calculation to improve the calculation efficiency. At the same time, it combines the Merkle-Tree index structure to optimize the data query process, making the query process both secure and efficient.
[0139] In step S4, it mainly involves further verification and processing of the foregoing steps. During this process, we need to consider the connection and execution order between each module. To ensure the effectiveness of the entire process, the implementation of step S4 should be closely connected to the previous steps to ensure that the transmission of data or information is not omitted and no unnecessary delays occur during the execution process.
[0140] In step S3, through preliminary operations on the encrypted data, a preprocessed result is obtained. And step S4 is based on this preprocessed result for further processing to ensure that it meets the final target output.
[0141] In this embodiment, step S4 includes further decryption verification operations on the data processed in step S3. First, assume that in step S3, the data is encrypted or transformed into a certain encrypted format. At this time, use the predefined private key sk and possibly the public key P to decrypt the encrypted data, and the obtained is the original data or message that has passed the complete verification.
[0142] Specifically, in a possible implementation, the operation of step S4 can be expressed by the following formula:
[0143] D Q = Decrypt(Q(E(D)), P, sk);
[0144] where D Q represents the final data or information after decryption; Q and E respectively represent a series of processing operations applied to the original data D; these operations may include encryption, transformation, or other mathematical operations; P represents the public key, which may be used for encryption operations or may be a necessary component in the decryption process; sk represents the private key, which is usually used when decrypting encrypted data.
[0145] Generally, the Decrypt operation in step S4 is the most core step in the decryption process. It not only restores the encrypted data, but also involves the verification of the encryption method and the key to ensure the integrity and authenticity of the data. During this process, only the correct private key sk and the relevant public key P can be used to decrypt the correct information.
[0146] As an option, the decryption operation in step S4 can be optimized according to actual needs. For example, if multiple encryptions or different encryption methods are involved, more verification levels can be introduced during the decryption process to ensure that the data can be correctly decrypted at each link.
[0147] Specifically, in some embodiments, the complexity and security of the decryption operation can be increased by nested encryption algorithms or other security protocols to prevent external attackers from illegally decrypting by stealing the key. In addition, in some implementation methods, if the decryption result does not match the expected result, an error handling mechanism can be introduced, such as re-obtaining the key, verifying the public key, etc., to ensure the accuracy of the decryption process.
[0148] In this embodiment, the implementation method of step S4 ensures that after the data is encrypted or processed, it can be decrypted with a legitimate key and finally restored to the original information that can be used normally. During this process, all operations rely on the pre-agreed encryption protocol, and each link must be strictly verified to ensure that the data will not be tampered with during decryption.
[0149] In summary, the technical solution of step S4 deeply connects with the previous steps, ensuring the security and integrity of the encrypted data. Through the decryption operation, the original data or message can be restored, providing accurate information for the subsequent steps.
[0150] Embodiment Two:
[0151] Please refer to the attached Figure 2 , an archival management system data archiving system, including:
[0152] A storage module, used to receive archival data, block and encrypt the data for storage, and construct a Merkle-Tree structure, recording the root hash value to the blockchain;
[0153] An integrity verification module, used to calculate the data integrity proof based on zk-STARKs and FRI technologies and provide integrity verification during a verification request;
[0154] A query module, used to perform data queries based on zero-knowledge proofs, enabling users to verify the existence of data without obtaining the data content, and performing query calculations in the encrypted state based on fully homomorphic encryption;
[0155] The permission management module is used to manage data access permissions based on smart contracts, maintain an access control list, and support dynamic permission updates;
[0156] The access control module is used to record access logs, verify the user's identity when the user requests access to data, and provide data access permissions after authorization;
[0157] The storage module is connected to the integrity verification module. After the data storage is completed, the storage module submits the hash information of the stored data to the integrity verification module. The integrity verification module calculates the zk-STARKs proof based on the hash information and returns it to the storage module;
[0158] The storage module is connected to the query module. After receiving a query request, the query module obtains relevant data indexes from the storage module and performs query calculations;
[0159] The integrity verification module is connected to the query module. When the query module executes a query, it calls the zk-STARKs proof provided by the integrity verification module to perform data integrity verification;
[0160] The query module is connected to the permission management module. When processing a user query, the query module verifies the user's permissions with the permission management module, and only allows the query calculation to be executed after the permission verification passes;
[0161] The permission management module is connected to the access control module. When the user requests access to data, the access control module verifies the user's permissions with the permission management module and decides whether to allow access to the data based on the permission verification result.
[0162] Specifically, the storage module receives the data to be archived, performs integrity verification, chunking, encryption, and hash calculation on it. The data is processed through fully homomorphic encryption technology, and at the same time, a Merkle-Tree structure is generated and the root hash value is stored in the blockchain. After the storage module completes data storage, it passes the data hash information to the integrity verification module, which uses zk-STARKs and FRI technologies to calculate the data integrity proof to ensure that the data has not been tampered with. After verification, the query module performs query calculations in the encrypted state based on zero-knowledge proof technology to protect data privacy and returns the encrypted query results to the user. The user decrypts the query results with the private key. At the same time, the permission management module is responsible for controlling data access permissions, dynamically updating and verifying user permissions through smart contracts and access control lists. The access control module verifies the user's identity and permissions when the user requests access to data and decides whether to authorize access based on the verification results. Through the close cooperation between the modules, the security of data storage, the privacy of the query process, and the efficiency of access control are ensured, thus realizing an efficient, secure, and decentralized archive management system.
[0163] Although embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for data archiving in an archive management system, characterized in that, It includes the following steps: S1. Data storage: Receive archived data, perform data chunking, fully homomorphic encryption processing, and hash calculation, then store the encrypted data in a decentralized storage system, and at the same time construct a Merkle-Tree structure to store data indexes and store the root hash value in the blockchain; S2. Integrity verification: After data storage is completed, calculate a verifiable computation proof of the archived data based on zk-STARKs and optimize it using FRI; S3. Privacy query: Generate a proof of the existence of archived data based on zero-knowledge proof and perform queries on the encrypted data based on fully homomorphic encryption calculation; S4. Data access management: Based on the access permission management mechanism of the blockchain, combine multi-party secure computing for permission verification and verify access permissions before data decryption.
2. The data archiving method of an archive management system according to claim 1, wherein The data storage includes: Receive archived data and verify its integrity; Divide the archived data into multiple data blocks; Perform fully homomorphic encryption on each data block; Calculate the hash value of each data block and recursively calculate the Merkle-Tree root hash value; Store the encrypted data blocks in a decentralized storage system and store the root hash value in the blockchain.
3. A method for archiving data in an archive management system according to claim 1, characterized in that, The integrity verification includes: Calculate the zk-STARKs verifiable computation proof of the archived data; Use FRI technology to optimize the zk-STARKs proof and reduce the computational complexity; When verifying data integrity, call the zk-STARKs proof and verify it based on the root hash value stored in the blockchain.
4. A method for archiving data of an archive management system according to claim 1, characterized in that, The privacy query includes: The user submits a query request; Generate a query proof based on zero-knowledge proof; Perform queries based on fully homomorphic encryption calculation and directly complete operations on the encrypted data; Return the encrypted query result to the user.
5. A method for data archiving of an archive management system according to claim 1, characterized in that, The fully homomorphic encryption calculation process includes: Perform homomorphic calculation on the archived data; Use homomorphic addition and homomorphic multiplication to maintain the encrypted state of the calculation result; After the query result is returned to the user, the user uses the private key to decrypt to obtain the query result.
6. A method for data archiving in an archive management system according to claim 1, characterized in that The data access management stage includes: Verify the user's permissions before access; Verify permission information based on the multi-party secure computing mechanism; After verification passes, the user obtains the decryption key and performs data decryption.
7. A method for data archiving of an archive management system according to claim 1, characterized in that The permission management mechanism based on the blockchain includes: Store the access control list in the blockchain; Realize dynamic permission updates through smart contracts and record the change history; Record access logs on the blockchain.
8. A method for data archiving in an archive management system according to claim 1, characterized in that The data index of the blockchain includes: Merkle-Tree root hash value; zk-STARKs proof index; Access permission records.
9. A data archiving system for an archive management system, which is based on the data archiving method for an archive management system according to any one of claims 1-8, characterized in that It includes: A storage module for receiving archived data, chunking and encrypting the data for storage, constructing a Merkle-Tree structure, and recording the root hash value in the blockchain; An integrity verification module for calculating a data integrity proof based on zk-STARKs and FRI technologies and providing integrity verification during a verification request; A query module for performing data queries based on zero-knowledge proof, enabling the user to verify the existence of data without obtaining the data content, and performing query calculations in an encrypted state based on fully homomorphic encryption calculation; The permission management module is used to manage data access permissions based on smart contracts, maintain an access control list, and support dynamic permission updates; The access control module is used to record access logs, verify the user's identity when the user requests access to data, and provide data access permissions after authorization.
10. A data archiving system for an archive management system according to claim 9, characterized in that, The storage module is connected to the integrity verification module. After the data storage is completed, the storage module submits the hash information of the stored data to the integrity verification module, and the integrity verification module calculates the zk-STARKs proof based on the hash information and returns it to the storage module; The storage module is connected to the query module. After receiving a query request, the query module obtains relevant data indexes from the storage module and performs query calculations; The integrity verification module is connected to the query module. When the query module executes a query, it calls the zk-STARKs proof provided by the integrity verification module to perform data integrity verification; The query module is connected to the permission management module. When processing a user query, the query module verifies the user's permissions with the permission management module, and only allows the query calculation to be executed after the permission verification passes; The permission management module is connected to the access control module. When the user requests access to data, the access control module verifies the user's permissions with the permission management module and decides whether to allow access to the data based on the permission verification result.