Local encryption tamper-proof storage method and system for multi-format remote sensing images

Through standardized processing of multi-format remote sensing images, AES-256-GCM encryption and blockchain evidence storage, the problems of data security and tampering in geoscience big data sharing are solved, and efficient and secure data storage and sharing are achieved.

CN120337262AActive Publication Date: 2025-07-18CHINA UNIV OF GEOSCIENCES (WUHAN)

Patent Information

Application Number
CN202510463427.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-18
Estimated Expiration
2045-04-14

AI Technical Summary

Technical Problem

In the sharing of local big data, there are problems such as data value and security risks coexisting, confusing data formats, high integration costs, data credibility and hidden dangers of tampering. The existing encryption technology and centralized blockchain evidence storage solutions have the risks of centralized key management and user privacy exposure, which cannot meet the needs of large-scale geoscience research.

Method used

The local encryption and tamper-proof storage method for multi-format remote sensing images is adopted. Through standardized processing, metadata binding, AES-256-GCM algorithm encryption, independent storage, key derivation and blockchain evidence storage, combined with the blockchain hash irreversible characteristics and MAC integrity verification mechanism, data security and tamper-freeness are ensured.

Benefits of technology

It realizes the full ciphertext storage of user data, improves data security, prevents data tampering, ensures data authenticity, and meets the security and efficiency needs of large-scale geoscience research.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337262A_ABST
    Figure CN120337262A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of big data storage and management, in particular to a local encryption tamper-proof storage method and system for a multi-format remote sensing image, and the method comprises the steps that a data uploading party carries out the standardization processing and metadata binding processing of a to-be-uploaded remote sensing image, and obtains standardized data and a global unique index; the data uploader cuts the standardized data, and encrypts and encapsulates the standardized data according to an AES-256-GCM algorithm to obtain a plurality of ciphertext blocks; the data uploading party executes independent storage, key derivation and data key encryption operation based on the master key to obtain an encrypted data key; the data uploader performs data signature and hash evidence storage based on the standardized data to form a block chain evidence storage record; a data receiving party stores various data transmitted by a data uploading party according to the forms of {Indexmeta, {E1,..., Ei,..., En}, Ekey and Blockhash} to form storage data, and when a user accesses the storage data, the data is prevented from being tampered based on the data hash irreversible characteristic of blockchain storage evidence and an MAC integrity verification mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of big data storage and management, and particularly to a local encryption and anti-tampering storage method and system for multi-format remote sensing images. Background Art

[0002] As the foundation of earth science research, geoscience big data covers key fields such as geological exploration, environmental monitoring, and disaster warning. Its data has spatial topology (such as geographically sensitive information), heterogeneity (multi-source heterogeneous formats), and multi-scale nature (complex spatio-temporal dimensions). However, the current sharing of geoscience data faces the following core contradictions: 1) Coexistence of data value and security risks; 2) Research collaboration needs and data barriers: Global geoscience research urgently needs cross-institutional collaboration (such as global climate change analysis), but due to chaotic data formats (such as various formats like BSQ, BIL, HDF5 of remote sensing images) and scattered storage (private databases or paper archives of each institution), the cost of data integration is high, hindering the formation of public thematic data sets; 3) Data credibility and tampering risks: Existing sharing platforms lack an effective verification mechanism for data integrity, and centralized storage is vulnerable to attacks or human tampering, resulting in doubts about the credibility of scientific research results. To solve the above problems, existing technologies have considered adopting a solution that combines traditional encryption technology with centralized blockchain evidence storage. Although this method can initially ensure data transmission security and provide basic evidence storage services, there are still problems such as centralized management of keys, high risk of user privacy exposure, single blockchain evidence storage being easily bypassed, low manual conversion efficiency, and high error rate, resulting in the efficiency and security of data sharing being unable to meet the needs of large-scale geoscience research. Summary of the Invention

[0003] In order to build a "confidential - trustworthy - efficient" trinity geoscience big data sharing ecosystem and solve the long-term problem of "data being afraid to be shared and shared being unavailable" in the scientific research field, the purpose of the present invention is to provide a local encryption and anti-tampering storage method and system for multi-format remote sensing images, and the specific technical solutions adopted are as follows:

[0004] In a first aspect, a local encryption and anti-tampering storage method for multi-format remote sensing images disclosed in the present application, the method includes:

[0005] S1. The data uploader performs standardization processing and metadata binding processing on the to-be-uploaded remote sensing image D draw , to obtain standardized data D std , and a globally unique index Index meta ;

[0006] S2. The data uploader uploads the standardized data D stdPerform cutting and seal and package according to the AES-256-GCM algorithm to obtain multiple ciphertext blocks {E1,..., E i ,..., E n};

[0007] S3. The data uploader performs independent storage, key derivation, and data key encryption operations based on the master key K master to obtain the encrypted data key E key ;

[0008] S4. The data uploader performs data signature and hash evidence storage on the basis of the standardized data D std to form a blockchain evidence storage record Block;

[0009] S5. The data receiver stores the data transmitted by the data uploader in the form of {Index meta , {E1,..., E i ,..., E n}, E key , Block hash} to form stored data, and when a user accesses the stored data, based on the irreversible property of the data hash of the blockchain evidence storage and the MAC integrity verification mechanism, to prevent the data from being tampered with.

[0010] Furthermore, in step S1, the data uploader performs standardization processing and metadata binding processing on the remote sensing image D draw to obtain the standardized data D std and the globally unique index Index meta , including:

[0011] S11. The data uploader obtains the standardized metadata M draw and the user ID data UserID for the remote sensing image D to be uploaded; std

[0012] S12. The data uploader generates the standardized data D draw corresponding to the remote sensing image D based on the DFAL library std ;

[0013] S13. The data uploader binds the standardized metadata M std with the user ID data UserID to obtain the globally unique index Index draw that uniquely identifies the remote sensing image D meta and its related information.

[0014] Furthermore, in step S2, the data uploader processes the standardized data D std ​Perform cutting and encrypt and package according to the AES-256-GCM algorithm to obtain multiple ciphertext blocks {E1,...,E i ,...,E n}, including:

[0015] S21. The data uploader cuts the standardized data D std into multiple cut data blocks {B1,...,B size} according to a fixed block size B i ,...,B n ;

[0016] S22. For each cut data block B i , the data uploader performs encryption calculation through the AES-256-GCM algorithm based on the generated random initialization vector IV i , and the data key K data to obtain the corresponding ciphertext C i , and the message authentication code MAC i ;

[0017] S23. For each cut data block B i , splice and package the corresponding random initialization vector IV i , ciphertext C i , and message authentication code MAC i to obtain the corresponding ciphertext block E i .

[0018] Furthermore, in step S3, the data uploader performs independent storage, key derivation, and data key encryption operations based on the master key K master to obtain the encrypted data key E key , including:

[0019] S31. The data uploader obtains the master key K master generated by the user and performs independent storage to store the master key K master locally;

[0020] S32. The data uploader uses the key derivation function HKDF to derive the corresponding encryption key K master from the master key K enc ;

[0021] S33. The data uploader encrypts the data key K enc to be encrypted through the AES-256-GCM algorithm based on the encryption key K data to obtain the encrypted data key E key .

[0022] Further, in step S4, the data uploader forms a blockchain deposit record Block based on the standardized data D std by performing data signature and hash deposit, including:

[0023] S41. The data uploader uses the SHA3-256 algorithm to perform hash processing on the standardized data D std to obtain the corresponding hash value H data ;

[0024] S42. The data uploader uses the ECDSA elliptic curve digital signature algorithm and a preset user private key SK user to sign the hash value H data to obtain the corresponding signature result σ;

[0025] S43. The data uploader writes the hash value H data , the signature result σ, and the current timestamp timestamp together as a transaction tx into the blockchain to form a blockchain deposit record Block.

[0026] Further, in step S5, based on the irreversible property of the data hash in the blockchain deposit and the MAC integrity verification mechanism to prevent data tampering, including:

[0027] S51. Decrypt the obtained stored data to obtain decrypted data D' std , where when decrypting each encapsulated ciphertext block E i , the corresponding random initialization vector IV i , ciphertext C i , and message authentication code MAC i are separated therefrom. By calling the Decrypt method in the AES-256-GCM algorithm and passing in the random initialization vector IV i , ciphertext C i , and message authentication code MAC i as parameters, and based on the decryption validity flag valid, initially determine whether the data has been tampered with;

[0028] S52. Calculate the hash value H' std of the decrypted data D' data through the SHA3-256 hash algorithm;

[0029] S53. Compare the hash value H' data with the hash value H data in the blockchain deposit record to further determine whether the data has been tampered with by verifying hash consistency.

[0030] Further, in step S5, before the data receiver stores D draw , the method further includes: constructing a format mapping table M origin according to the initial format F std and the corresponding parser parser, where M origin = {(F

[0031] , parser)}; draw When the data receiver stores D origin , the method further includes: dynamically loading the corresponding parser parser from the mapping table M std according to the initial format F std , and using the parser parser to process the obtained D draw to obtain the corresponding data D Forigin = parser std (D

[0032] Further, the method further includes: constructing an index tree Tree meta based on the global unique index Index std and a set of key-value pairs {acquisition time t, sensor type S, spatial resolution R} through a B+ tree indexing construction algorithm index for the corresponding mapping table M

[0033] such that the user can quickly retrieve the stored data based on the time and space ranges.

[0034] Further, the method further includes: data After the user uploads the calculation program P, the data receiver starts a read-only Docker container and injects K data into the Docker container through a secure channel for temporary data processing, where the program P will be decrypted in the container and the processing result will be encrypted and returned based on K

[0035] In a second aspect, a local encryption and anti-tampering storage system for multi-format remote sensing images disclosed in the present application includes a client and a server, where:

[0036] The client is used to perform standardization processing and metadata binding processing on the remote sensing image D draw to be uploaded, to obtain standardized data D std and a global unique index Index meta ; cut the standardized data D std and perform encryption and packaging according to the AES-256-GCM algorithm to obtain multiple ciphertext blocks {E1,..., E i ,..., En}; Based on the master key K master Perform independent storage, key derivation, and data key encryption operations to obtain the encrypted data key E key ; Based on the standardized data D std Perform data signature and hash record keeping to form a blockchain record Block;

[0037] The server is used to store the various data transmitted by the data uploader in the form of {Index meta ,{E1,...,E i ,...,E n},E key ,Block hash} to form stored data, and when a user accesses the stored data, based on the irreversible property of the data hash in the blockchain record keeping and the MAC integrity verification mechanism, to prevent data tampering.

[0038] The present invention has the following beneficial effects: On the one hand, by combining cutting and sealing packaging, independent storage, and key derivation to strengthen key management, through the combination of AES-256-GCM block encryption and key separation management, the ciphertext storage of user data throughout the process is ensured, improving data security; on the other hand, by means of data signature and hash record keeping to form an immutable blockchain record, it is possible to combine the irreversible property of the blockchain hash and the MAC integrity verification dual mechanisms during the data storage and access stages, effectively preventing data tampering and double-guaranteeing data authenticity. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0040] Figure 1 It is a flowchart of a method for local encrypted anti-tampering storage of multi-format remote sensing images provided by an embodiment of the present invention;

[0041] Figure 2 It is a system structure diagram of a system for local encrypted anti-tampering storage of multi-format remote sensing images provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] To further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the following specifically describes, in conjunction with the accompanying drawings and preferred embodiments, a local encryption and anti-tampering storage method and system for multi-format remote sensing images according to the present invention, including its specific implementation manners, structures, features, and effects. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures, or characteristics in one or more embodiments may be combined in any suitable form.

[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs.

[0044] The following specifically describes the specific solution of a local encryption and anti-tampering storage method and system for multi-format remote sensing images provided by the present invention in conjunction with the accompanying drawings.

[0045] Please refer to Figure 1 , which shows the method flow chart of a local encryption and anti-tampering storage method for multi-format remote sensing images provided by an embodiment of the present invention. The method includes:

[0046] Step S1, the data uploader performs standardization processing and metadata binding processing on the remote sensing image D to be uploaded draw , obtaining the standardized data D std and the globally unique index Index meta .

[0047] Step S2, the data uploader cuts the standardized data D std and performs encryption and encapsulation according to the AES-256-GCM algorithm, obtaining multiple ciphertext blocks {E1,..., E i ,..., E n}.

[0048] Step S3, the data uploader performs independent storage, key derivation, and data key encryption operations based on the master key K master , obtaining the encrypted data key E key .

[0049] Step S4, the data uploader performs data signature and hash evidence storage based on the standardized data D std to form a blockchain evidence storage record Block.

[0050] Step S5, the data receiver follows {Index meta , {E1,..., E i ,..., E n}, E key , Blockhash} Store each piece of data transmitted by the data uploader in this form to form stored data. When a user accesses the stored data, based on the irreversible feature of the data hash of blockchain evidence storage and the MAC integrity verification mechanism, prevent the data from being tampered with.

[0051] As can be seen from the above, a local encryption and anti-tampering storage method for multi-format remote sensing images disclosed in this application has the following beneficial effects: On the one hand, by combining cutting and encapsulation, independent storage, and key derivation to strengthen key management, and through the combination of AES-256-GCM block encryption and key separation management, ensure the ciphertext storage of user data throughout the process, improving data security; on the other hand, with the help of data signature and hash evidence storage to form an immutable blockchain evidence record, it can combine the irreversible feature of blockchain hash and the MAC integrity verification dual mechanism during the data storage and access stages, effectively prevent the data from being tampered with, and double-guarantee the authenticity of the data.

[0052] In one embodiment, in step S1, the data uploader performs standardization processing and metadata binding processing on the remote sensing image D to be uploaded draw to obtain standardized data D std and a globally unique index Index meta , including:

[0053] Step S11, the data uploader obtains standardized metadata M draw and user ID data UserID for the remote sensing image D to be uploaded. std

[0054] Specifically, the DFAL library is a tool library dedicated to remote sensing image processing, which has a built-in multi-format parser that can automatically match parsing rules according to file header information, and retains the multi-band, spatial reference, and metadata of the original data. The standardized metadata M std includes: 1) Acquisition time t, in the format: t = ISO8601(timestamp), indicating that the time format follows the ISO8601 standard (such as 2023-10-25T14:30:00Z) to ensure cross-platform compatibility; 2) Sensor type S, where the sensor types shown here include optical, radar, and multi-spectral; 3) Spatial resolution R: R = (xres, yres), where xres and yres respectively represent the pixel resolution of the image in the horizontal (longitude) and vertical (latitude) directions, in meters (projection coordinate system) or degrees (geographic coordinate system). Example: If the image resolution is 10 meters per pixel, then R = (10, 10).

[0055] Step S12, the data uploader generates a drawCorresponding standardized data D std 。

[0056] Specifically, if the initial format of the remote sensing image D draw is F origin (such as GeoTIFF, BIL, etc.), and the target standard format formed by conversion is F std (such as HDF5), then the process of conversion based on the DFAL library can refer to the following expression: D std ←DFAL(D raw , F origin →F std ).

[0057] Step S13, the data uploader binds the standardized metadata M std with the user ID data UserID to obtain a globally unique index Index draw for uniquely identifying the remote sensing image D meta and its related information.

[0058] Specifically, the data uploader splices the standardized metadata M std with the user ID data UserID through the SHA256 hashing algorithm to obtain a globally unique index Index draw for uniquely identifying the remote sensing image D meta and its related information. Specifically, it can refer to the following expression: Index meta =SHA256(M std ||UserID). It should be noted that the SHA256 hashing algorithm is a cryptographic hash function that can receive input data and generate a 256-bit hash value. In the current embodiment, by splicing the standardized metadata M std with the user ID data UserID and then processing it through the SHA256 hashing algorithm, it can further ensure the uniqueness of the generated index Index meta globally.

[0059] In one embodiment, in step S2, the data uploader cuts the standardized data D std and encrypts and packages it according to the AES-256-GCM algorithm to obtain multiple ciphertext blocks {E1,..., E i ,..., E n}, including:

[0060] Step S21, the data uploader cuts the standardized data D std into multiple cut data blocks {B1,..., B size} according to a fixed block size Bi ,...,B n}。

[0061] Specifically, the data uploader cuts the standardized data D size (such as 64MB) into multiple cut data blocks {B1,...,B std ,...,B i ,...,B n}, where B i = D std [i*B size :(i + 1)*B size . Here, i represents an integer used to identify and distinguish different cut data blocks. For example, when i = 1, B1 represents the first cut data block of the standardized data D std ; when i = 2, B2 represents the second cut data block of the standardized data D std , and so on. It should be noted that this expression indicates the specific position and range of the cut data block B i in the standardized data D std . For example, when i = 1, the range of the first cut data block B1 is from the B std -th byte of D size to the 2*B size -th byte.

[0062] Step S22: For each cut data block B i , the data uploader performs encryption calculation through the AES-256-GCM algorithm based on the generated random initialization vector IV i , and the data key K data to obtain the corresponding ciphertext C i , and the message authentication code MAC i .

[0063] Specifically, in AES-256-GCM encryption, this application defines the random initialization vector IV i as a 96-bit binary number. In specific implementation, a 128-bit random number will be generated, and then its first 96 bits will be taken to achieve this. The data key K data is the key used to encrypt the data block, and its length is 256 bits. In specific implementation, a 256-bit random number will be generated and used as the data key K data . It should be noted that this application will be based on the expression: (C i , MAC i ) = AES-256-GCM.Encrypt(K data , IV i , B i) Perform encryption calculation, where K data represents the generated 256-bit data key, IVi represents the generated 96-bit random initialization vector, and B i represents the data block to be encrypted, and its output result is the ciphertext C i for transmission or storage with encryption protection and the message authentication code MAC i .

[0064] Step S23, for each data block B i , the corresponding random initialization vector IV i , ciphertext C i , and the message authentication code MAC i are concatenated and encapsulated to obtain the corresponding ciphertext block E i .

[0065] Specifically, for each data block B i , this application will concatenate the corresponding random initialization vector IV i , ciphertext C i , and the message authentication code MAC i in order (such as E i = IV i || C i || MAC i ), and the corresponding ciphertext block E i can be obtained.

[0066] In the above embodiment, after the standardized data is segmented, the AES-256-GCM algorithm is used to independently encrypt each data block and generate a message authentication code, and then the random initialization vector, ciphertext, and message authentication code are encapsulated into a ciphertext block, realizing high-strength encryption, integrity verification, segmented transmission, and flexible expansion, effectively improving the security and reliability of data transmission.

[0067] In one of the embodiments, in step S3, the data uploader performs independent storage, key derivation, and data key encryption operations based on the master key K master to obtain the encrypted data key E key , including:[[]]

[0068] Step S31, the data uploader obtains the master key K master generated by the user and performs independent storage to store the master key K master locally.

[0069] Specifically, the data uploader obtains the master key K master generated by the user and stores it independently locally, so as to further ensure the master key K masterfor security purposes to avoid its leakage or abuse.

[0070] Step S32, the data uploader uses the key derivation function HKDF, based on the master key K master to derive the corresponding encryption key K enc .

[0071] Specifically, the data uploader calls the key derivation function HKDF, which takes the master key K master as input, combines it with a predefined random value salt for enhancing the security of the key derivation process and the context information info parameter, and generates the corresponding derived key K enc , specifically, it can refer to the expression: K enc =HKDF(K master , salt, info='DataKey'), where the context information here is 'DataKey', indicating that the generated key is used for data encryption.

[0072] Step S33, the data uploader encrypts the data key K enc to be encrypted based on the encryption key K data through the AES-256-GCM algorithm to obtain the encrypted data key E key .

[0073] Specifically, the data uploader calls the AES-256-GCM encryption algorithm and uses the derived key K enc to encrypt the data key K data to generate the encrypted data key E key (specifically, it can refer to the expression: E key =AES-256-GCM.Encrypt(K enc , IV key , K data ))), where the data receiver only stores E key , and it cannot obtain K data , because the AES-256-GCM encryption algorithm depends not only on the key K enc , but also on the randomly generated initial vector IV key . During the encryption process, each time the AES-256-GCM algorithm is used to encrypt data, a new random IV is generated. This IV, together with the key K enc and the data key K data to be encrypted, serves as the input to the encryption algorithm to generate the encrypted data key E key . Since the IV is randomly generated and different each time encryption is performed, even if the data receiver stores the encrypted data key E key , it cannot obtain K through Ekey Derive the original data key K by reversing the known encryption algorithm data .

[0074] In the above embodiment, the user generates and independently stores the master key, uses the key derivation function to generate the encryption key based on the master key, and then uses the AES-256-GCM algorithm to encrypt the data key K data to achieve the separate management of the master key and the encryption key, the flexibility of key derivation, and the high-strength encryption protection of the data key.

[0075] In one of the embodiments, in step S4, the data uploader performs data signature and hash evidence preservation based on the standardized data D std to form a blockchain evidence preservation record Block, including:[[]]

[0076] Step S41, the data uploader uses the SHA3-256 algorithm to perform hash processing on the standardized data D std to obtain the corresponding hash value H data .

[0077] Specifically, the data uploader takes the standardized data D std as input and calls the SHA3-256 hash function for hash processing. Specifically, it can refer to the expression: H data =SHA3-256(D std ). It should be noted that after absorbing data blocks and compression processing, this function generates a hash value H with a fixed length of 256 bits data .

[0078] Step S42, the data uploader uses the ECDSA elliptic curve digital signature algorithm and the preset user private key SK user to sign the hash value H data to obtain the corresponding signature result σ.

[0079] Specifically, the data uploader will pre-load the user-preset private key SK user , and select the ECDSA elliptic curve digital signature algorithm to use the private key SK user to sign the hash value H data to generate the corresponding signature result σ. Specifically, it can refer to the expression: σ = ECDSA.Sign(SK user ,H data ). It should be noted that the ECDSA elliptic curve digital signature algorithm realizes efficient digital signatures through elliptic curve cryptography, and combines random number generation and modular inverse element calculation to ensure the uniqueness and non-forgeability of the signature.

[0080] Step S43, the data uploader takes the hash value H data , the signature result σ, and the current timestamp timestamp together as a transaction tx and writes it into the blockchain to form a blockchain evidence record Block.

[0081] Specifically, the transaction tx constructed by the data uploader contains the following fields: hash value H data , the signature σ for H data , and the current timestamp timestamp (ensuring that the evidence time is traceable). Then, the transaction tx is sent to the blockchain network. After the blockchain node verifies the validity of the transaction, it is packed into a block Block and appended to the end of the blockchain. It should be noted that the process of writing (H data , σ) into the blockchain can be referred to the expression: Block = Blockchain.Append(tx = {H data , σ, timestamp}).

[0082] In the above embodiment, first, the standardized data is hashed by the SHA3-256 algorithm, ensuring the uniqueness and anti-tampering property of the data and enhancing the protection of data integrity. Second, the hash value is signed using the ECDSA elliptic curve digital signature algorithm and the user's private key, ensuring the authenticity and non-repudiation of the data and improving the security and trust of the system. Finally, the hash value, signature result, and timestamp are written into the blockchain to form an immutable evidence record, ensuring the traceability and anti-tampering ability of the data.

[0083] In one of the embodiments, in step S5, based on the irreversible property of the data hash in the blockchain evidence and the MAC integrity verification mechanism to prevent data tampering, it includes:

[0084] Step S51, decrypt the obtained stored data to obtain the decrypted data D′ std , where when decrypting each encapsulated ciphertext block E i , the corresponding random initialization vector IV i , ciphertext C i , and message authentication code MAC i are separated from it. By calling the Decrypt method in the AES-256-GCM algorithm and passing in the random initialization vector IV i , ciphertext C i , and message authentication code MAC i as parameters, and based on the decryption validity flag valid, initially judge whether the data has been tampered with.

[0085] Specifically, for each encapsulated ciphertext block Ei , which includes a randomly initialized vector IV i , ciphertext C i and message authentication code MAC i . During the decryption process, first, these components are separated from the ciphertext block, and then the Decrypt method in the AES-256-GCM algorithm is called to decrypt the ciphertext. The specific call is: (B i , valid) = AES-256-GCM.Decrypt(K data , IV i , C i , MAC i ), where K data is the data key, B i is the plaintext block, and valid is a boolean value used to indicate whether the decryption is successful and whether the data has been tampered with. If valid = False, a tampering alert is triggered and access is frozen.

[0086] Step S52, calculate the hash value H' std of the decrypted data D' data .

[0087] Specifically, the currently used SHA3-256 hash algorithm is: H' data = SHA3-256(D std ), where the SHA3-256 hash algorithm preprocesses the input data (such as padding to ensure its length meets the requirements of the algorithm) during the hash value calculation process, and then performs multiple rounds of iterative compression through an internal permutation function, and finally outputs a fixed-length 256-bit hash value.

[0088] Step S53, compare the hash value H' data with the hash value H data in the blockchain deposit record to further determine whether the data has been tampered with by verifying the hash consistency.

[0089] Specifically, the verification rule is as follows:

[0090]

[0091] Among them, if there is a hash value match, that is, H' data = H data , it means that the data has not been tampered with; otherwise, it means that the data has been tampered with.

[0092] In one embodiment, in step S5, before the data recipient stores D draw , the method further includes: according to the initial format F origin, and the corresponding parser construction format mapping table M std ={(F origin , parser)}.

[0093] When the data receiver stores D draw , the method further includes: dynamically loading the corresponding parser from the mapping table M origin according to the initial format F std , and using the parser to process the obtained D std to obtain the corresponding data D draw = parser Forigin (D std ).

[0094] In one embodiment, the method further includes: constructing an index tree Tree meta based on the global unique index Index std and a set of key-value pairs {acquisition time t, sensor type S, spatial resolution R} through a B+ tree index construction algorithm index of the corresponding mapping table M, so that users can quickly retrieve stored data based on the time and space ranges.

[0095] Specifically, first, an empty B+ tree index structure is created to prepare for subsequent insertion of key-value pairs. Then, the global unique index Index meta of each stored data and the key-value pairs {acquisition time t, sensor type S, spatial resolution R} are inserted into the B+ tree in sequence. Through the insertion operation, the B+ tree index tree will be gradually constructed and its structure will be kept balanced. Finally, when users retrieve through the time and space ranges (such as the acquisition time range from t_start to t_end, and the spatial ranges from X_min to X_max, Y_min to Y_max), they can use the B+ tree index to quickly locate and return the stored data that meets the conditions.

[0096] In the above embodiment, by using the orderliness and multi-column combined index ability of the B+ tree, users can quickly locate data based on the composite conditions of acquisition time, sensor type, and spatial resolution, improving the data query efficiency.

[0097] In one embodiment, the method further includes:

[0098] Step S6, after the user uploads the calculation program P, the data receiver starts a read-only Docker container and injects K data into the Docker container through a secure channel for temporary data processing. Among them, the program P will be decrypted in the container and based on Kdata Encrypt the returned processing result.

[0099] Specifically, after the user uploads the computing program P, the data receiver starts a read-only Docker container to ensure that the program P runs in an isolated and secure environment. The command is: Container = Docker.Run(image = sandbox, volumes = E key , network = isolated). Here, sandbox is the name of the Docker image, and isolated represents the network configuration to ensure that the container is isolated from the outside world. Further, K is injected into the Docker container through a secure channel (such as a TLS / SSL encrypted channel). Specifically, inside the container, the AES-256-GCM algorithm is used to decrypt the encryption key K data , and the decrypted K is obtained enc . The command is: K data = AES-256-GCM.Decrypt((K data , IV enc , E key ). Finally, after the processing is completed, the processing result R at this time will be encrypted using the RSA-OAEP algorithm to obtain the encrypted result E key . The command is: E result = RSA-OAEP.Encrypt(PK result , R). Here, PK user represents the public key preset by the user, which is used to encrypt the processing result to ensure that the result can only be decrypted by the user. user

[0100] Please refer to Figure 2 , a local encryption and anti-tampering storage system for multi-format remote sensing images disclosed in the present application, characterized in that the system includes a client and a server, wherein:

[0101] The client is used to perform standardization processing and metadata binding processing on the remote sensing image D to be uploaded draw , to obtain the standardized data D std , and the globally unique index Index meta ; cut the standardized data D std , and perform encryption and packaging according to the AES-256-GCM algorithm to obtain multiple ciphertext blocks {E1,..., E i ,..., E n}; perform independent storage, key derivation, and data key encryption operations based on the master key K master to obtain the encrypted data key E key; Based on the standardized data D std Perform data signature and hash evidence preservation to form a blockchain evidence preservation record Block;

[0102] The server is used to store each piece of data transmitted by the data uploader in the form of {Index meta ,{E1,...,E i ,...,E n},E key ,Block hash} to form stored data, and when a user accesses the stored data, based on the irreversible feature of the data hash of the blockchain evidence preservation and the MAC integrity verification mechanism, prevent the data from being tampered with.

[0103] In one embodiment, the above-mentioned modules are also used to implement a local encryption and anti-tampering storage method for multi-format remote sensing images as described in any one of the foregoing method embodiments, which is not limited in this application.

[0104] As can be seen from the above, a local encryption and anti-tampering storage system for multi-format remote sensing images disclosed in this application has the following beneficial effects: on the one hand, by combining cutting and sealing packaging, independent storage and key derivation to strengthen key management, and combining AES-256-GCM block encryption and key separation management, it ensures the ciphertext storage of user data throughout the process and improves data security; on the other hand, by means of data signature and hash evidence preservation to form an immutable blockchain evidence preservation record, it can combine the irreversible feature of the blockchain hash and the MAC integrity verification dual mechanism during the data storage and access stages, effectively prevent the data from being tampered with, and double-guarantee the authenticity of the data.

[0105] It should be noted that: the above-mentioned sequence of the embodiments of the present invention is only for description and does not represent the superiority or inferiority of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-tasking and parallel processing are also possible or may be advantageous.

[0106] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments.

Claims

1. A local encryption and anti-tampering storage method for multi-format remote sensing images, characterized in that, The method includes: S1. The data uploader performs standardization processing and metadata binding processing on the remote sensing image D to be uploaded, obtaining the standardized data D draw and the global unique index Index std ; meta ; S2. The data uploader cuts the standardized data D std and encrypts and packages it according to the AES-256-GCM algorithm to obtain multiple ciphertext blocks {E1,..., E i ,..., E n}; S3. The data uploader performs independent storage, key derivation, and data key encryption operations based on the master key K master to obtain the encrypted data key E key ; S4. The data uploader performs data signature and hash evidence preservation based on the standardized data D std to form a blockchain evidence preservation record Block; S5. The data recipient stores each piece of data transmitted by the data uploader in the form of {Index meta , {E1,..., E i ,..., E n}, E key , Block hash} to form stored data. When a user accesses the stored data, based on the irreversible feature of the data hash of blockchain evidence storage and the MAC integrity verification mechanism, data tampering is prevented.

2. The method according to claim 1, wherein In step S1, the data uploader performs standardization processing and metadata binding processing on the remote sensing image D to be uploaded, and obtains the standardized data D draw , and the globally unique index Index std , including: meta ​ S11. The data uploader obtains the standardized metadata M draw for the remote sensing image D to be uploaded std and the user ID data UserID. S12. The data uploader generates standardized data D draw corresponding to the remote sensing image D std ; S13. The data uploader binds the standardized metadata M std with the user ID data UserID to obtain a globally unique index Index draw for uniquely identifying the remote sensing image D meta and its related information.

3. The method according to claim 1, characterized in that In step S2, the data uploader cuts the standardized data D std and encrypts and packages it according to the AES-256-GCM algorithm to obtain multiple ciphertext blocks {E1,..., E i ,..., E n}, including: S21. The data uploader uploads the standardized data D std and cuts it into multiple cut data blocks {B1,..., B size} in accordance with a fixed block size B i ,..., B n ; S22. For each cut data block B i , the data uploader performs encryption calculation through the AES-256-GCM algorithm based on the generated random initialization vector IV i , and the data key K data to obtain the corresponding ciphertext C i , and the message authentication code MAC i ; S23. For each cut data block B i , splice and encapsulate the corresponding randomly initialized vector IV i , ciphertext C i , and message authentication code MAC i to obtain the corresponding ciphertext block E i .

4. The method according to claim 1, wherein In step S3, the data uploader is based on the master key K master to perform independent storage, key derivation, and data key encryption operations to obtain the encrypted data key E key , including: S31. The data uploader obtains the master key K generated by the user master and performs independent storage to store the master key K master locally. S32. The data uploader uses the key derivation function HKDF to derive the corresponding encryption key K based on the master key K master enc ;​ S33. The data uploader, based on the encryption key K enc , encrypts the data key K to be encrypted through the AES-256-GCM algorithm data to obtain the encrypted data key E key .

5. The method according to claim 1, characterized in that In step S4, the data uploader performs data signature and hash evidence storage based on the standardized data D std to form a blockchain evidence storage record Block, including: S41. The data uploader uses the SHA3-256 algorithm to perform hashing on the standardized data D std to obtain the corresponding hash value H data ; S42. The data uploader uses the ECDSA elliptic curve digital signature algorithm and the preset user private key SK user to sign the hash value H data to obtain the corresponding signature result σ; S43. The data uploader writes the hash value H data , the signature result σ, and the current timestamp timestamp into the blockchain together as a transaction tx, forming a blockchain deposit record Block.

6. The method according to claim 1, wherein In step S5, based on the irreversible feature of the data hash stored on the blockchain and the MAC integrity verification mechanism to prevent data tampering, it includes: S51. Decrypt the obtained stored data to obtain decrypted data D'. std , where when decrypting each encapsulated ciphertext block E i , the corresponding random initialization vector IV i , ciphertext C i , and message authentication code MAC i are separated therefrom. By calling the Decrypt method in the AES-256-GCM algorithm and passing in the random initialization vector IV i , ciphertext C i , and message authentication code MAC i as parameters, and based on the decrypted validity flag valid, initially determine whether the data has been tampered with; S52. Calculate the hash value H' of the decrypted data D' through the SHA3-256 hash algorithm std ; data ; S53. Compare the hash value H′ data with the hash value H data in the blockchain deposit record, and further determine whether the data has been tampered with by verifying the hash consistency.

7. The method according to claim 6, wherein In step S5, before the data receiver stores D draw , the method further includes: constructing a format mapping table M origin according to the initial format F std and the corresponding parser parser, where M origin = {(F origin , parser)}; The data recipient stores D draw At this time, the method further includes: dynamically loading a corresponding parser from the mapping table M origin according to the initial format F std and using the parser to process the obtained D std to obtain the corresponding data D draw = parser Forigin (D std ).

8. The method according to claim 7, wherein The method further includes: constructing, by means of a B+ tree indexing algorithm, an index tree Tree based on a corresponding mapping table M based on a global unique index Index meta , and a set of key-value pairs {acquisition time t, sensor type S, spatial resolution R} std such that users can quickly retrieve stored data based on time and spatial ranges. index ​ 9. The method according to any one of claims 1-8, characterized in that, The method further includes: After the user uploads the computing program P, the data receiver starts a read-only Docker container and injects K into the Docker container through a secure channel for temporary data processing. Among them, the program P will be decrypted in the container and the processing result will be encrypted and returned based on K. data After the user uploads the computing program P, the data receiver starts a read-only Docker container and injects K into the Docker container through a secure channel for temporary data processing. Among them, the program P will be decrypted in the container and the processing result will be encrypted and returned based on K. data After the user uploads the computing program P, the data receiver starts a read-only Docker container and injects K into the Docker container through a secure channel for temporary data processing. Among them, the program P will be decrypted in the container and the processing result will be encrypted and returned based on K.

10. A local encryption and anti-tampering storage system for multi-format remote sensing images, characterized in that, The system includes a client and a server, where: The client is used for the remote sensing image D to be uploaded draw , perform standardization processing and metadata binding processing to obtain standardized data D std , and the globally unique index Index meta ; cut the standardized data D std , and perform encryption and encapsulation according to the AES-256-GCM algorithm to obtain multiple ciphertext blocks {E1,...,E i ,...,E n}; perform independent storage, key derivation, and data key encryption operations based on the master key K master to obtain the encrypted data key E key ; perform data signature and hash evidence storage based on the standardized data D std to form a blockchain evidence storage record Block; The server is used to store each piece of data transmitted by the data uploader in the form of {Index meta ,{E1,...,E i ,...,E n},E key ,Block hash} to form stored data, and when a user accesses the stored data, based on the irreversible feature of the data hash of blockchain evidence storage and the MAC integrity verification mechanism, to prevent the data from being tampered with.

Citation Information

Patent Citations

  • Electronic evidence preservation system and method based on block chain technology

    CN107888375A

  • A mass remote sensing data efficient organization and fast retrieval method in a cloud computing environment

    CN109635068A

  • Remote sensing metadata chaining method based on alliance chain

    CN112487459A

  • Block chain-based ecological environment supervision method and system

    CN115001700A

  • Method and device for verifying data integrity

    CN115299010A

Cited By

  • Efficient encryption and decryption method for oversized remote sensing image data

    CN121173918A