Data auditing system and data auditing method
The data audit system that generates user keys through the multi-key server mechanism solves the data corruption and credibility problems of cloud storage artificial intelligence model, realizes efficient and secure data auditing, and reduces the risk of single point of failure and bandwidth consumption.
Patent Information
- Application Number
- CN202510664492.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-08-12
AI Technical Summary
When the prior art stores artificial intelligence models in the cloud, there are problems such as data corruption risk, cyber attack risk and model credibility reduction, and traditional TEE solutions are limited by secure memory capacity and channel attack threats.
The multi-key server mechanism is used to generate user keys, and data audits are performed in the cloud through user equipment and audit servers, and the target model is checked using file tags and file authentication character sets to reduce the risk of single point of failure. In the data audit process, only verification is required based on the proof information and numerical value Z.
It reduces the risk of single point of failure, reduces bandwidth resource consumption, improves the efficiency and credibility of data audits, ensures data integrity and credibility, and is not affected by the scale of audited data.
Smart Images

Figure CN120474700A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security, and in particular to a data auditing system and a data auditing method. Background Art
[0002] Currently, artificial intelligence (AI) companies are increasingly relying on cloud storage technology to store AI models and provide related services externally. Through this cloud hosting approach, AI models can be deployed on remote servers, allowing users to access and manage the models over the internet, thus overcoming the capacity and computing power bottlenecks inherent in traditional local storage-based solutions. However, this technical solution also presents two major challenges: First, once an AI model is deployed to a cloud server, the AI company loses direct control over the model, increasing the risk of data corruption and cyberattacks; second, due to commercial interests and other reasons, AI operators or cloud service providers may deploy AI models that do not meet the stated specifications, resulting in reduced credibility and reliability, which in turn may trigger a crisis of trust in the service among users.
[0003] The traditional solution to these data security and model credibility issues is to obtain AI models from the cloud through a trusted third party and verify the data integrity and content locally to ensure it conforms to the declared specifications. However, this approach requires transmitting the complete model data over the network, which not only consumes significant bandwidth resources but also increases the risk of data leakage.
[0004] To address this issue, researchers have proposed deploying AI models using a Trusted Execution Environment (TEE) to enhance their security and trustworthiness. However, existing TEE solutions (such as Intel SGX technology) are limited by secure memory capacity and face security threats such as channel attacks. Summary of the Invention
[0005] The purpose of the present invention is to provide a data auditing system and a data auditing method, which can utilize a multi-key server mechanism to generate user keys, thereby minimizing the risk of single point failure, and in the data auditing process, only the target model needs to be verified based on the proof information and the value z. The bandwidth consumption and verification efficiency of the entire auditing process are independent of the scale of the audited data and are not affected by the size of the audited data.
[0006] In a first aspect, a data audit system is provided, comprising: a key generation center having a first number of key servers, a user device, a cloud server, and an audit server;
[0007] The user device is used to send the user ID and user public key A to each key server. The user public key is obtained based on the random number a; and random number a, user ID to calculate the key server Based on the second number of key servers , their respective unique identity and random number a, calculate the user's private key b, where, Indicates the second number of key servers ; According to the file block and the user private key b, the file authentication code corresponding to the file block is determined to obtain a file authentication code set, the file authentication code set is composed of the file authentication codes of the third number of file blocks obtained by segmenting the target model; according to , a second number of key servers' respective unique identities, the user ID, the system public key, the user public key A, and a hash value to determine a numerical value Z, wherein the hash value is determined based on metadata of the target model; obtaining a file tag based on the user ID, the file unique identifier, the third number, and the numerical value Z; and sending the file tag, the target model of the third number of file blocks, and the file authentication character set to the cloud server;
[0008] Key server, used to , user ID, hash value, user public key and own private key, determine and , and send and to user equipment;
[0009] The audit server is used to obtain the file label corresponding to the target model from the cloud server, build and send the challenge information and random number To the cloud server, so that the cloud server can generate a response based on the challenge information, the file authentication character set, the third number of text blocks, the random number , generate proof information; verify the target model based on the proof information and value Z sent by the cloud server.
[0010] In a preferred embodiment of the present invention, the user equipment may be further configured as follows: and Then, based on the public key, user ID, user public key, hash value, and random number a of each key server, and Perform verification; if verification fails, send resend information to each key server.
[0011] In a preferred example, the present invention can be further configured as follows: the user equipment executes the respective , their respective unique identity and random number a, when calculating the user's private key b, specifically used for:
[0012] Based on the unique identifications of the second number of key servers, determine ;
[0013] Based on the second number of key servers 、 And random number a, calculate the user private key b.
[0014] In a preferred example, the present invention can be further configured as follows: when the user device obtains the file tag based on the user ID, the file unique identifier, the third quantity, and the value Z, it is specifically configured to:
[0015] Calculate a signature based on the user ID, the file unique identifier, the third quantity, and the value Z;
[0016] The file signature is obtained according to the calculated signature, the user ID, the file unique identifier, the third quantity and the value Z.
[0017] In a preferred embodiment, the present invention may be further configured to include:
[0018] The blockchain server is used to store the user ID and hash value uploaded by the user device;
[0019] The key server is also used to read the hash value from the blockchain server based on the user ID.
[0020] In a preferred embodiment, the present invention can be further configured as a key server, further configured to:
[0021] Generate a polynomial based on the second quantity; and calculate an identification value of each key management server based on the unique identification of each key management server and the polynomial, and send the identification value to the corresponding other key management servers;
[0022] Determine its own private key and public key based on the identification value of the key server calculated by each key server;
[0023] Correspondingly, the key generation center is further used to determine the system private key based on the constant value of the polynomial of the first number of key servers; and determine the system public key based on the system private key.
[0024] In a preferred embodiment, the present invention can be further configured as a cloud server, further configured to:
[0025] After receiving the file tag, the target model of the third number of file chunks, and the file authenticator set, it is determined whether the user has permission to upload the file according to the user ID in the file signature.
[0026] In a preferred embodiment, the present invention may be further configured such that when the cloud server generates the certification information based on the challenge information, the file authentication character set, the third number of text blocks, and the third random number, it is configured to:
[0027] Determine the first sub-proof information based on the challenge information and the text block;
[0028] Determine the second sub-certification information based on the challenge information, the third random number, and the file authentication character set;
[0029] The certification information includes: first sub-certification information and second sub-certification information.
[0030] In a preferred example, the present invention may be further configured as follows: the user device is further configured to: send a request to update metadata to a first number of key servers; and determine a new hash value based on the new metadata;
[0031] Each key server is further used to: determine a new second random number and a new hash value, determine a new and new , recorded as ;
[0032] Correspondingly, the user equipment is also used to: Determine a new file tag and a new file authentication character set; and send the new file tag and the new file authentication character set to the cloud server so that the cloud server can update.
[0033] In a second aspect, a data audit method is provided, which is applied to the data audit system according to any one of the first aspects, comprising:
[0034] The user device sends the user ID and user public key A to each key server. The user public key is obtained based on the random number a;
[0035] The key server uses the random number , user ID, hash value, user public key and own private key, determine and , and send and to user equipment;
[0036] User equipment according to and random number a, user ID to calculate the key server Based on the second number of key servers , their respective unique identity and random number a, calculate the user's private key b, where, Indicates the second number of key servers ; According to the file block and the user private key b, the file authentication code corresponding to the file block is determined to obtain a file authentication code set, the file authentication code set is composed of the file authentication codes of the third number of file blocks obtained by segmenting the target model; according to , a second number of key servers' respective unique identities, the user ID, the system public key, the user public key A, and a hash value to determine a numerical value Z, wherein the hash value is determined based on metadata of the target model; obtaining a file tag based on the user ID, the file unique identifier, the third number, and the numerical value Z; and sending the file tag, the target model of the third number of file blocks, and the file authentication character set to the cloud server;
[0037] After the audit server obtains the file tag corresponding to the target model from the cloud server, it constructs and sends the challenge information and random number To the cloud server;
[0038] The cloud server uses the challenge information, the file authentication character set, the third number of text blocks, and the random number , generate certification information;
[0039] The audit server verifies the target model based on the proof information and value Z sent by the cloud server.
[0040] In a third aspect, a data audit method is provided, which is executed by an audit server and includes:
[0041] After obtaining the file tag corresponding to the target model from the cloud server, construct and send the challenge information and random number To the cloud server, so that the cloud server can generate a response based on the challenge information, the file authentication character set, the third number of text blocks, the random number , generate certification information;
[0042] Verify the target model based on the certification information and value Z sent by the cloud server;
[0043] The file tag of the cloud server, the target model of the third number of file blocks, and the file authentication character set are sent by the user device.
[0044] The user equipment can and random number a, user ID to calculate the key server Based on the second number of key servers , their respective unique identity and random number a, calculate the user's private key b, where, Indicates the second number of key servers ; According to the file block and the user private key b, the file authentication code corresponding to the file block is determined to obtain a file authentication code set, the file authentication code set is composed of the file authentication codes of the third number of file blocks obtained by segmenting the target model; according to , a second number of unique identifications of key servers, the user ID, the system public key, the user public key A, and a hash value to determine a value Z, where the hash value is determined based on metadata of the target model; and a file tag is obtained based on the user ID, the file unique identifier, the third number, and the value Z;
[0045] The key server can , user ID, hash value, user public key and own private key, determine and , and send and to the user device.
[0046] In a fourth aspect, a data auditing device is provided, comprising:
[0047] The construction module is used to obtain the file label corresponding to the target model from the cloud server, build and send the challenge information and random number To the cloud server, so that the cloud server can generate a response based on the challenge information, the file authentication character set, the third number of text blocks, the random number , generate certification information;
[0048] The verification module is used to verify the target model based on the proof information and value Z sent by the cloud server.
[0049] In a fifth aspect, an audit server is provided, comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor executes the method described in the third aspect when running the computer program.
[0050] In a sixth aspect, a computer-readable storage medium is provided, wherein at least one program code is stored in the computer-readable storage medium, and the program code is loaded and executed by a processor to implement the method described in the third aspect.
[0051] In a seventh aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed by a processor, implements the method described in the third aspect.
[0052] In summary, the data audit system provided by the present invention has the following beneficial technical effects:
[0053] The present invention provides a data auditing system, comprising: a key generation center having a first number of key servers, user devices, a cloud server, and an audit server, capable of verifying the integrity and credibility of data. A multi-key server mechanism is used to generate user keys, thereby minimizing the risk of single point failures. Furthermore, the user device sends a file tag, a target model of a third number of file blocks, and a file authentication character set to the cloud server. When the audit server conducts an audit, it only needs to construct a challenge message and a random number. To the cloud server; the audit server verifies the target model based on the proof information and value Z sent by the cloud server, ensuring that during the data audit process, only the target model needs to be verified based on the proof information and value z. The bandwidth consumption and verification efficiency of the entire audit process are independent of the scale of the audited data and are not affected by the size of the audited data.
[0054] In addition, the present invention also provides a data auditing method, which has the above-mentioned beneficial technical effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] In order to more clearly illustrate the embodiments of the present invention or the technical solutions of the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0056] Figure 1 This is a schematic diagram of the structure of a data audit system provided by an embodiment of the present invention;
[0057] Figure 2 This is a system model diagram of an AI-Auditor provided by an embodiment of the present invention;
[0058] Figure 3 is a schematic diagram of an audit process provided by an embodiment of the present invention;
[0059] Figure 4 It is a flowchart of a data audit method provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0060] This specific embodiment is merely an explanation of the present invention and is not intended to limit the present invention. After reading this specification, those skilled in the art may make non-creative modifications to this embodiment as needed. However, as long as they are within the scope of the present invention, they are protected by patent law.
[0061] It should be noted that in the optional embodiments of the present invention, the object information and other related data involved, when the embodiments of the present invention are applied to specific products or technologies, need to obtain the permission or consent of the object, and the collection, use and processing of the relevant data need to comply with the relevant laws, regulations and standards of the relevant countries and regions. In other words, if the embodiments of the present invention involve data related to the object, it needs to be obtained with the permission of the object, the permission of the relevant department, and in compliance with the relevant laws, regulations and standards of the country and region. If personal information is involved in the embodiments, the acquisition of all personal information needs to obtain the consent of the individual. If sensitive information is involved, the separate consent of the information subject needs to be obtained. The embodiments also need to be implemented with the permission of the object.
[0062] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0063] In this document, the term "and / or" simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document, unless otherwise specified, generally indicates an "or" relationship between the related objects.
[0064] This invention proposes a new AI model credibility audit method and system, which can not only ensure the integrity of AI model data content, but also provide credibility credentials, and can provide credentials for subsequent model use, model supervision and other operations.
[0065] To more efficiently verify the credibility of AI models, this paper proposes a new data auditing framework, called AI-Auditor, based on the Provable Data Possession (PDP) algorithm. AI-Auditor enables auditors to remotely verify the integrity and credibility of cloud-based AI model data without having to download the entire data, thereby significantly reducing the consumption of network bandwidth resources. In addition, the verification efficiency of AI-Auditor is not affected by the size of the audited data, and the execution efficiency is O(1). To further improve security, AI-Auditor uses multiple key management servers (KMS) to distribute sub-private keys. Even if some sub-private keys are leaked, the security of the system can still be ensured, and the risk of single point failure can be effectively eliminated. At the same time, AI-Auditor uses metadata to verify the credibility of AI model data to ensure that it complies with the declared specifications, such as version number, copyright, and other information.
[0066] Specifically, an embodiment of the present invention provides a data audit system, including: a key generation center 100 having a first number of key servers 110, a user device 200, a cloud server 300, and an audit server 400.
[0067] The user device 200 is used to send the user ID and the user public key A to each key server 110. The user public key is obtained according to the random number a.
[0068] Among them, the user ID is the user's identification information, which is used to verify the user's authority and find the data corresponding to the user ID. To obtain the user's public key A, the user selects a random number , and calculate the user's public key , where g represents a generator, and then the user ID and user public key A are sent to each key server 110.
[0069] The key server 110 is used to , user ID, hash value, user public key and own private key, determine and , and send and To user device 200.
[0070] Among them, the key generation center 100 (Key generation center, KGC) consists of the first number It consists of 110 key servers (Key Management Server, KMS), which are marked as , whose corresponding unique identifier is , First, KGC selects a bilinear map ,in and There are two prime numbers of order The multiplicative cyclic group of yes The generator of . The key servers 110 are responsible for storing subkey information respectively, wherein the second number Each key server 110 can restore the system master key information using the subkey information it stores.
[0071] Each key server 110 Get the hash value from the blockchain based on the user ID , or, receiving a hash value sent by the user device 200, the hash value being calculated based on the metadata of the target model. Pick a random number , express The set of all elements in that are coprime to q, for example, , (all non-zero elements). Calculated as well as , yes own private key, Then it will and Sent to user equipment 200.
[0072] Correspondingly, the user equipment 200 is also used according to and random number a, user ID to calculate the key server 110 Based on the second number of key servers 110 respective , their respective unique identity and random number a, calculate the user's private key b, where, represents the second number of key servers 110 ; According to the file block and the user private key b, the file authentication code corresponding to the file block is determined to obtain a file authentication code set, the file authentication code set is composed of the file authentication codes of the third number of file blocks obtained by segmenting the target model; according to , the unique identity identifier, user ID, system public key, user public key A and hash value of each of the second number of key servers 110 are used to determine the numerical value Z; the file tag is obtained according to the user ID, the file unique identifier, the third number and the numerical value Z; the file tag, the target model of the third number of file blocks and the file authentication character set are sent to the cloud server 300.
[0073] Among them, since each Will send and To the user equipment 200, therefore, the user equipment 200 receives and Afterwards, based on , calculate each Corresponding , when the user equipment 200 calculates the second number t After that, you don’t need to calculate again , which is recorded as , Indicates that the t The tth , the corresponding index set is , Indicates the t obtained The tth The index of .
[0074] The user device 200 executes the respective , their respective unique identifications and random number a, when calculating the user private key b, specifically for: determining based on the second number of unique identifications of the key servers 110 Based on the second number of key servers 110 respective 、 and random number a, calculate the user private key b. Specifically, in the embodiment of the present invention, according to Calculated ,use , calculate the user private key b.
[0075] User uploads model file When the file is in the cloud, it is necessary to obtain information such as file labels and file authenticators required for the subsequent audit process.
[0076] Specifically, the user calculates each file block of the target model F (1≤i≤n) corresponding file authentication code , and then get the model file Corresponding file authentication character set .
[0077] The target model is not limited in the embodiment of the present invention and can be a digital twin model, a power grid fault identification model or other network models. The embodiment of the present invention is not limited in the embodiment of the present invention.
[0078] User Computing , get Z.
[0079] Furthermore, when the user device 200 obtains the file tag according to the user ID, the file unique identifier, the third number and the value Z, it is specifically used to: calculate the signature according to the user ID, the file unique identifier, the third number and the value Z; and obtain the file signature according to the calculated signature, the user ID, the file unique identifier, the third number and the value Z. Specifically, the user calculates the signature , and then get the file label . The user will then Send to the cloud.
[0080] Audit server 400 is used to obtain the file tag corresponding to the target model from cloud server 300, build and send challenge information and random number To the cloud server 300. The specific audit server 400 generates a random number set , in ,and , that is, Q is The c values in the TPA file are then Constructing a challenge message , that is, to associate a random coefficient with each index i in Q , then choose a random number , and calculate .
[0081] The cloud server 300 is configured to process the file authentication code according to the challenge information, the file authentication code set, the third number of text blocks, and the random number. , generate proof information.
[0082] Specifically, when the cloud server 300 generates the certification information according to the challenge information, the file authentication character set, the third number of text blocks, and the third random number, it is used to: determine the first sub-certification information according to the challenge information and the text block; determine the second sub-certification information according to the challenge information, the third random number, and the file authentication character set; the certification information includes: the first sub-certification information and the second sub-certification information. Calculate Cloud Utilization and calculate , get proof information .
[0083] The audit server 400 is used to verify the target model based on the certification information and value Z sent by the cloud server 300.
[0084] Audit server 400 obtains the certification information Then, using equation A verification is performed. If the verification fails, it indicates that the target model stored in the cloud server 300 is a damaged model, or does not match the specified metadata.
[0085] Furthermore, when the verification fails, a prompt message is generated to prompt the user device corresponding to the target model uploaded by the user to be damaged and to prompt the user using the model that the model is not a reliable model.
[0086] It can be seen that in an embodiment of the present invention, a data audit system is provided, comprising: a key generation center having a first number of key servers, a user device, a cloud server, and an audit server, which can verify the integrity and credibility of data. The multi-key server 110 mechanism is used to generate user keys, thereby minimizing the risk of single point failure; then, the user device sends the file tag, the target model of the third number of file blocks, and the file authentication character set to the cloud server; when the audit server performs an audit, it only needs to construct the challenge information and the random number. To the cloud server; the audit server verifies the target model based on the proof information and value Z sent by the cloud server, ensuring that during the data audit process, only the target model needs to be verified based on the proof information and value Z. The bandwidth consumption and verification efficiency of the entire audit process are independent of the scale of the audited data and are not affected by the size of the audited data.
[0087] In a possible implementation of the embodiment of the present invention, the user equipment 200 is further configured to receive and Then, based on the public key of each key server 110, user ID, user public key, hash value, random number a, and If the verification fails, a resend message is sent to each key server 110. Specifically, the user receives and Then, use the formula Validate the data. If validation fails, each All must be resent . Security is further ensured through verification.
[0088] One possible implementation of this embodiment of the present invention further includes: a blockchain server for storing the user ID and hash value uploaded by user device 200; and a key server 110 for reading the hash value from the blockchain server based on the user ID. Storing the hash value on the blockchain server ensures that the hash value obtained by the key server 110 is accurate and tamper-proof, thereby improving security.
[0089] In a possible implementation of an embodiment of the present invention, the key server 110 is further used to: generate a polynomial based on the second number; and calculate the identification value of each key management server based on the unique identity identifier and polynomial of each key management server, and send it to the corresponding other key management servers; determine its own private key and its own public key based on the identification value of the key server 110 calculated by each key server 110; correspondingly, the key generation center 100 is further used to determine the system private key based on the constant value of the polynomial of the first number of key servers 110; and determine the system public key based on the system private key.
[0090] Each key server 110 Randomly generate a number of The polynomial is expressed as , where randomly selected , ,and .in As Each calculate Elements and transmit each Transfer to the corresponding . Each Calculate your own private key and its own public key The system private key is calculated as , the system public key is KGC publishes public parameters .
[0091] In a possible implementation of an embodiment of the present invention, the cloud server 300 is further used to: after receiving the file tag, the target model of the third number of file blocks and the file authentication character set, determine whether the user has the authority to upload the file based on the user ID in the file signature.
[0092] In a possible implementation of the embodiment of the present invention, the user device 200 is further configured to: send a request to update metadata to a first number of key servers 110; and determine a new hash value based on the new metadata; each key server 110 is further configured to: determine a new random number and the new hash value, determine the new and new , recorded as 、 ; Correspondingly, the user equipment 200 is further used to: 、 Determine a new file tag and a new file authentication character set; and send the new file tag and the new file authentication character set to the cloud server 300 so that the cloud server 300 can be updated.
[0093] Specifically, the user device 200 and KGC update the model file by executing this algorithm Corresponding metadata information, set the new hash value corresponding to the metadata of the new model file ,user The old hash value has been Upload to the blockchain server. User device 200 Key server 110 (KMS) sends and update metadata request. The key server 110 receives After that, each key server 110 Authenticate User Whether to authorize the execution of the update algorithm, namely the UptModel algorithm. If not authorized, the algorithm terminates. Otherwise, Choose a new random number , and calculate as well as . Then Will and Send to user equipment 200. User equipment 200 receives and Then, use the equation To verify its correctness. If the verification fails, the algorithm terminates. Otherwise, the user equipment 200 calculates , and then collect share , recorded as , the corresponding index set is User Computing ,in , and then get the user's new private key , public key Remain unchanged. User device 200 is a cloud data block Calculate a new file authenticator , and then get a new file authentication character set . User equipment 200 calculates , and Finally, the user device 200 sends the data from the cloud server 300 to Updated to .
[0094] Based on any of the above embodiments, see Figure 2 , Figure 2This is a system model diagram of an AI-Auditor provided by an embodiment of the present invention. For AI-Auditor, the user first needs to use the user device 200 to download the model file. Divide into file blocks, then It can be expressed as ,in , is a large prime number. The user device 200 needs to calculate the model file Hash value corresponding to metadata , where metadata information includes model version number and copyright information. User device 200 needs to The data is stored in the blockchain server to ensure that it cannot be tampered with. The following is the specific algorithm process, which mainly includes seven processes: Setup, GenKey, StorF, Chal, Resp, Verf, and UptModel. Figure 3 shown.
[0095] 1. Setup: In this step, the key server 110 generates the system public key, system private key, and public parameter information. The specific steps are as follows:
[0096] The Key Generation Center 100 (KGC) is composed of It consists of 110 key servers (Key Management Server, KMS), which are marked as , whose corresponding unique identifier is , First, KGC selects a bilinear map ,in and are two prime numbers of order The multiplicative cyclic group of yes The generator of . Each key server 110 is responsible for storing subkey information, wherein: Each key server 110 can restore the system master key information using the subkey information it stores.
[0097] KGC selects two hash functions , To ensure the integrity of the file tag, the key generation center 100 needs to select a secure identity-based digital signature function, such as the national secret algorithm SM9, which is recorded here as .
[0098] Each key server 110 Randomly generate a number of The polynomial is expressed as , where randomly selected , ,and .in As Each calculate Elements and transmit each Transfer to the corresponding .
[0099] Each Calculate your own private key and its own public key The system private key is calculated as , the system public key is .
[0100] KGC publishes public parameters .
[0101] 2. GenKey: In this step, the user device 200 cooperates with the KGC to generate the user public key and the user private key. For the sake of discussion, the user is marked as .
[0102] To obtain the public key , the user device 200 selects a random number , and calculate Then the user device 200 retrieves the hash value corresponding to the metadata of the AI model file F from the blockchain , and Send to A key server 110.
[0103] Each key server 110 Obtained from the blockchain server based on user ID , each Pick a random number , and calculate as well as , Then it will and Sent to user equipment 200.
[0104] User equipment 200 receives and Then, use the formula Validate the data. If validation fails, each All must be resent and Afterwards, the user calculates . User device 200 successfully collected share , denoted as , the corresponding index set is . User equipment 200 calculates ,in The user device 200 then obtains the user's private key and the user's public key .
[0105] 3.StorF: User device 200 uploads the model file When the file arrives at the cloud server 300, the algorithm needs to be executed to obtain information such as the file label and file authentication code required for the subsequent audit process.
[0106] The user device 200 calculates each file block Corresponding file authentication code , and then get the model file Corresponding file authentication character set User Computing . User device 200 calculates the signature , and then get the file label . Then the user equipment 200 will Send to cloud server 300.
[0107] The cloud server 300 uses ID and To check whether the user has the authorization to upload the file. If yes, the cloud server 300 uses the ID to check the signature After successful verification, the cloud storage Otherwise, the cloud server 300 rejects the file upload request of the user device 200.
[0108] 4. Chal: To verify the model file of the cloud server 300 To verify the integrity and credibility of the audit server, 400TPA calculates the corresponding challenge information and sends it to the cloud to obtain proof information.
[0109] TPA retrieves the file tag information tag corresponding to the model file and user ID from the cloud server 300. If this step fails, the algorithm terminates.
[0110] After obtaining the tag information, TPA uses the ID to verify the signature If the signature verification fails, the algorithm terminates. TPA generates a random number set , in ,and . Then TPA is the model file Constructing a challenge message , then choose a random number , and calculate . TPA will and Send to cloud server 300.
[0111] 5. Resp: When the cloud server 300 receives the challenge information, the cloud server 300 uses the stored model file to construct the corresponding proof information, and then sends it back to the TPA.
[0112] Cloud server 300 uses Calculate . Cloud server 300 uses and calculate . Cloud Server 300 will prove Sent to TPA for authenticity and integrity verification.
[0113] 6. Verf: After receiving the proof information, TPA verifies it to ensure the integrity and credibility of the model file stored in the cloud server 300.
[0114] TPA obtains certification information Then, using equation A verification is performed. If the verification fails, it indicates that the AI model stored in the cloud server 300 is either damaged or does not match the specified metadata.
[0115] This paper proposes a new data auditing framework, AI-Auditor, that verifies data integrity and credibility. Built on the PDP algorithm, AI-Auditor ensures that the bandwidth consumption and verification efficiency of the data audit process are independent of the size of the audited data. Furthermore, AI-Auditor incorporates a multi-key server 110 mechanism to manage user keys, minimizing the risk of single points of failure.
[0116] The following is an introduction to a method provided by an embodiment of the present invention. The method described below and the system described above can be referenced to each other. Figure 4 , Figure 4 : is a flow chart of a method according to one embodiment of the present invention. The present invention provides a data auditing method applied to the above-mentioned data auditing system, comprising:
[0117] S101. The user device sends the user ID and user public key A to each key server. The user public key is obtained based on the random number a.
[0118] S102, the key server uses the random number , user ID, hash value, user public key and own private key, determine and , and send and to user equipment;
[0119] S103, the user equipment and random number a, user ID to calculate the key server Based on the second number of key servers , their respective unique identity and random number a, calculate the user's private key b, where, Indicates the second number of key servers ; According to the file block and the user private key b, the file authentication code corresponding to the file block is determined to obtain a file authentication code set, the file authentication code set is composed of the file authentication codes of the third number of file blocks obtained by segmenting the target model; according to , a second number of key servers' respective unique identities, the user ID, the system public key, the user public key A, and a hash value to determine a numerical value Z, wherein the hash value is determined based on metadata of the target model; obtaining a file tag based on the user ID, the file unique identifier, the third number, and the numerical value Z; and sending the file tag, the target model of the third number of file blocks, and the file authentication character set to the cloud server;
[0120] S104, the audit server obtains the file tag corresponding to the target model from the cloud server, constructs and sends the challenge information and random number To the cloud server;
[0121] S105, the cloud server uses the challenge information, the file authentication character set, the third number of text blocks, the random number , generate certification information;
[0122] S106. The audit server verifies the target model based on the certification information and the value Z sent by the cloud server.
[0123] It can be seen that in the embodiment of the present invention, the multi-key server 110 mechanism is used to generate user keys, thereby minimizing the risk of single point failure; then, the user device sends the file tag, the target model of the third number of file blocks and the file authentication character set to the cloud server; when the audit server performs an audit, it only needs to construct the challenge information and the random number. To the cloud server; the audit server verifies the target model based on the proof information and value Z sent by the cloud server, ensuring that during the data audit process, only the target model needs to be verified based on the proof information and value Z. The bandwidth consumption and verification efficiency of the entire audit process are independent of the scale of the audited data and are not affected by the size of the audited data.
[0124] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0125] The above are only some of the embodiments of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A data audit system, characterized in that: include: A key generation center having a first number of key servers, user devices, cloud servers, and an audit server; The user device is used to send the user ID and user public key A to each key server. The user public key is obtained based on the random number a; and random number a, user ID to calculate the key server ; Based on the second number of key servers , their respective unique identity and random number a, calculate the user's private key b, where, Indicates the second number of key servers ; According to the file block and the user private key b, the file authentication code corresponding to the file block is determined to obtain a file authentication code set, the file authentication code set is composed of the file authentication codes of the third number of file blocks obtained by segmenting the target model; according to , a second number of key servers' respective unique identities, the user ID, the system public key, the user public key A, and a hash value to determine a numerical value Z, wherein the hash value is determined based on metadata of the target model; obtaining a file tag based on the user ID, the file unique identifier, the third number, and the numerical value Z; and sending the file tag, the target model of the third number of file blocks, and the file authentication character set to the cloud server; Key server, used to , user ID, hash value, user public key and own private key, determine and , and send and to user equipment; The audit server is used to obtain the file label corresponding to the target model from the cloud server, build and send the challenge information and random number To the cloud server, so that the cloud server can generate a response based on the challenge information, the file authentication character set, the third number of text blocks, the random number , generate proof information; verify the target model based on the proof information and value Z sent by the cloud server.
2. The system according to claim 1, wherein: The user equipment is further configured to receive and Then, based on the public key, user ID, user public key, hash value, and random number a of each key server, and Perform verification; if verification fails, send resend information to each key server.
3. The system according to claim 1, wherein: The user equipment executes the respective , their respective unique identity and random number a, when calculating the user's private key b, specifically used for: Based on the unique identifications of the second number of key servers, determine ; Based on the second number of key servers 、 And random number a, calculate the user private key b.
4. The system according to claim 1, wherein: When the user device obtains the file tag according to the user ID, the file unique identifier, the third quantity, and the value Z, it is specifically configured to: Calculate a signature based on the user ID, the file unique identifier, the third quantity, and the value Z; The file signature is obtained according to the calculated signature, the user ID, the file unique identifier, the third quantity and the value Z.
5. The system according to claim 1, wherein: Also includes: The blockchain server is used to store the user ID and hash value uploaded by the user device; The key server is also used to read the hash value from the blockchain server based on the user ID.
6. The system according to claim 1, wherein: Key servers are also used to: Generate a polynomial based on the second quantity; and calculate an identification value of each key management server based on the unique identification of each key management server and the polynomial, and send the identification value to the corresponding other key management servers; Determine its own private key and public key based on the identification value of the key server calculated by each key server; Correspondingly, the key generation center is further used to determine the system private key according to the constant value of the polynomial of the first number of key servers; and determine the system public key according to the system private key.
7. The system according to claim 1, wherein: Cloud servers are also used for: After receiving the file tag, the target model of the third number of file chunks, and the file authenticator set, it is determined whether the user has permission to upload the file according to the user ID in the file signature.
8. The system according to claim 1, wherein: When the cloud server generates the certification information based on the challenge information, the file authentication character set, the third number of text blocks, and the third random number, it is used to: Determine the first sub-proof information based on the challenge information and the text block; Determine the second sub-certification information based on the challenge information, the third random number, and the file authentication character set; The certification information includes: first sub-certification information and second sub-certification information.
9. The system according to claim 1, wherein: The user device is further configured to: send a request to update metadata to a first number of key servers; and determine a new hash value based on the new metadata; Each key server is further used to: determine a new second random number and a new hash value, determine a new and new , recorded as ; Correspondingly, the user equipment is also used to: Determine a new file tag and a new file authentication character set; and send the new file tag and the new file authentication character set to the cloud server so that the cloud server can update.
10. A data audit method, characterized in that: The data audit system according to any one of claims 1 to 9 comprises: The user device sends the user ID and user public key A to each key server. The user public key is obtained based on the random number a; The key server uses the random number , user ID, hash value, user public key and own private key, determine and , and send and to user equipment; User equipment according to and random number a, user ID to calculate the key server Based on the second number of key servers , their respective unique identity and random number a, calculate the user's private key b, where, Indicates the second number of key servers ; According to the file block and the user private key b, the file authentication code corresponding to the file block is determined to obtain a file authentication code set, the file authentication code set is composed of the file authentication codes of the third number of file blocks obtained by segmenting the target model; according to , a second number of key servers' respective unique identities, the user ID, the system public key, the user public key A, and a hash value to determine a numerical value Z, wherein the hash value is determined based on metadata of the target model; obtaining a file tag based on the user ID, the file unique identifier, the third number, and the numerical value Z; and sending the file tag, the target model of the third number of file blocks, and the file authentication character set to the cloud server; After the audit server obtains the file tag corresponding to the target model from the cloud server, it constructs and sends the challenge information and random number To the cloud server; The cloud server uses the challenge information, the file authentication character set, the third number of text blocks, and the random number , generate certification information; The audit server verifies the target model based on the proof information and value Z sent by the cloud server.