A file integrity monitoring method, an electronic device, and a storage medium

CN120743861BActive Publication Date: 2026-09-22INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510849756.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2026-09-22
Estimated Expiration
2045-06-24

AI Technical Summary

Benefits of technology

[0021]根据本发明的另一方面,提供了一种计算机可读存储介质,所述计算机可读存储介质存储有计算机指令,所述计算机指令用于使处理器执行时实现本发明任一实施例所述的文件完整性监测方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120743861B_ABST
    Figure CN120743861B_ABST
Patent Text Reader

Abstract

The application discloses a file integrity monitoring method, an electronic device and a storage medium. The method comprises the following steps: when a file integrity check condition is triggered, a user node sends a check request to a scheduling node; the scheduling node determines an edge node group according to the load condition of the edge node, and distributes an audit task corresponding to the check request to each edge node in the edge node group; the edge node finds corresponding integrity evidence according to the audit task, and sends the integrity evidence to the scheduling node; the scheduling node performs consistency verification according to the integrity evidence fed back by each edge node, and if the consistency verification is passed, the integrity evidence is sent to the user node; and the user node performs local check according to the integrity evidence, and determines a corresponding file check result. By using the method, the safety, traceability and credibility of file integrity monitoring in a domestic terminal environment are effectively improved, and the method has low resource occupation and high compatibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method for monitoring file integrity, an electronic device, and a storage medium. Background Technology

[0002] File integrity monitoring is a crucial technique in information security, designed to ensure that files are not tampered with, damaged, or modified without authorization during storage, transmission, or processing. This guarantees that files are delivered intact to the user, thereby improving the security and reliability of business systems and reducing the risk of intrusion. With the development of information technology, especially the widespread adoption of domestically developed operating systems, important configuration files, executable files, and system library files have increasingly become targets for attackers. Therefore, integrity monitoring has become an essential component of system security.

[0003] Existing file integrity monitoring tools, such as Tripwire and AIDE, suffer from several drawbacks. Firstly, they exhibit poor compatibility with domestic operating systems, high resource consumption, and complex deployment. Secondly, most of these tools employ centralized fingerprint verification mechanisms, lacking inter-node collaboration mechanisms and anti-tampering capabilities, thus posing risks in the face of distributed intrusions or malicious node forgery. Therefore, developing a file integrity monitoring solution that is compatible with domestic systems, has low resource consumption, and offers enhanced security has become a pressing technical challenge. Summary of the Invention

[0004] This invention provides a file integrity monitoring method, electronic device, and storage medium to achieve full-process file integrity monitoring in a domestic terminal environment, improving the security, traceability, and reliability of file integrity monitoring, while having low resource consumption and strong compatibility.

[0005] According to one aspect of the present invention, a method for monitoring file integrity is provided, the method comprising:

[0006] When a file integrity verification condition is triggered, the user node sends a verification request to the scheduling node.

[0007] The scheduling node determines the edge node group based on the edge node load and distributes the audit task corresponding to the verification request to each edge node in the edge node group;

[0008] The edge nodes locate the corresponding integrity evidence based on the audit task and send the integrity evidence to the scheduling node.

[0009] The scheduling node performs consistency verification based on the integrity evidence fed back by each edge node. If the consistency verification passes, the integrity evidence is sent to the user node.

[0010] User nodes perform local verification based on integrity evidence and determine the corresponding file verification result.

[0011] According to another aspect of the present invention, a document integrity monitoring device is provided, the device comprising:

[0012] The request sending module is used to send a verification request to the scheduling node when the file integrity verification condition is triggered by the user node;

[0013] The task distribution module is used to determine the edge node group based on the edge node load through the scheduling node, and distribute the audit task corresponding to the verification request to each edge node in the edge node group;

[0014] The evidence search module is used to search for the corresponding integrity evidence based on the audit task through the edge node, and send the integrity evidence to the scheduling node;

[0015] The consistency verification module is used to perform consistency verification based on the integrity evidence fed back by each edge node through the scheduling node. If the consistency verification is successful, the integrity evidence is sent to the user node.

[0016] The local verification module is used by user nodes to perform local verification based on integrity evidence and determine the corresponding file verification result.

[0017] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0018] At least one processor; and

[0019] A memory communicatively connected to the at least one processor; wherein,

[0020] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the file integrity monitoring method according to any embodiment of the present invention.

[0021] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the file integrity monitoring method according to any embodiment of the present invention.

[0022] According to another aspect of the present invention, a computer program product is provided, the computer program product comprising a computer program that, when executed by a processor, implements the file integrity monitoring method described in any embodiment of the present invention.

[0023] The file integrity monitoring method provided in this invention is applied to a file integrity monitoring system. The method includes: a user node sending a verification request to a scheduling node when a file integrity verification condition is triggered; the scheduling node determining an edge node group based on the edge node load and distributing the audit task corresponding to the verification request to each edge node in the edge node group; the edge nodes searching for corresponding integrity evidence based on the audit task and sending the integrity evidence to the scheduling node; the scheduling node performing consistency verification based on the integrity evidence fed back by each edge node, and if the consistency verification passes, sending the integrity evidence to the user node; and the user node performing local verification based on the integrity evidence and determining the corresponding file verification result. This method, by adopting a three-level collaborative distributed file integrity monitoring architecture involving user nodes, scheduling nodes, and edge nodes, can support the scheduling of integrity verification requests for large-scale domestic terminals and adapt to heterogeneous systems. Through the consistency verification by the scheduling node and the local verification by the user node, the security, traceability, and reliability of file integrity monitoring are effectively improved.

[0024] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0026] Figure 1 This is a schematic diagram of a document integrity monitoring system provided according to Embodiment 1 of the present invention;

[0027] Figure 2 This is a flowchart of a document integrity monitoring method provided in Embodiment 1 of the present invention;

[0028] Figure 3 This is a flowchart of a document integrity monitoring method provided in Embodiment 2 of the present invention;

[0029] Figure 4 This is a schematic diagram of a document integrity monitoring system provided according to Embodiment 3 of the present invention;

[0030] Figure 5 This is a flowchart of a document integrity monitoring method provided in Embodiment 3 of the present invention;

[0031] Figure 6 This is a flowchart of another document integrity monitoring method provided in Embodiment 3 of the present invention;

[0032] Figure 7 This is a schematic diagram of the structure of a document integrity monitoring device according to Embodiment 4 of the present invention;

[0033] Figure 8 This is a schematic diagram of the structure of an electronic device that implements the file integrity monitoring method of this invention. Detailed Implementation

[0034] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0035] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0036] Example 1

[0037] Figure 1 This is a schematic diagram of a document integrity monitoring system provided in Embodiment 1 of the present invention. Figure 1 As shown, the system includes: user node 10, scheduling node 20, and edge node 30. The number of the three types of nodes can be configured according to the actual application requirements, and this embodiment does not impose specific limitations on this. The functions of the three types of nodes are described in detail below.

[0038] User node 10 can refer to an entity (terminal agent role) deployed on domestic terminal equipment, which directly interacts with the user's business environment and is responsible for real-time monitoring and local verification of file changes.

[0039] Scheduling node 20 can refer to a central scheduling unit deployed on a cloud server or dedicated host. It has certain storage resources and the ability to perform audit tasks on behalf of users, and is responsible for task distribution and multi-node collaborative verification.

[0040] Edge node 30 can refer to a distributed node with data storage and computing capabilities deployed at the network edge or in a local cluster, responsible for maintaining evidence of file integrity.

[0041] This invention, designed for domestic operating system environments, presents a distributed file integrity monitoring architecture that integrates user nodes, scheduling nodes, and edge nodes. This architecture establishes a distributed, collaborative, and tamper-proof integrity monitoring mechanism, effectively improving the security and accuracy of file integrity monitoring on domestic terminals.

[0042] Based on the aforementioned document integrity monitoring system, Figure 2 This is a flowchart of a file integrity monitoring method provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of file integrity monitoring on domestically produced terminals. The method can be executed by a file integrity monitoring device, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 2 As shown in the figure, the document integrity monitoring method provided in this embodiment includes the following steps:

[0043] S110. When the file integrity verification condition is triggered, the user node sends a verification request to the scheduling node.

[0044] Among them, the file integrity verification condition can refer to the conditions used to trigger the file integrity verification request of the user node. The file integrity verification condition may include, but is not limited to: capturing a file change event in the preset monitoring path (event-driven), reaching the system file integrity verification cycle (periodic triggering), etc.

[0045] In this embodiment of the invention, a user node can respond to the triggering of a file integrity verification condition by immediately sending a file integrity verification request for the target file (i.e., the file to be verified) to the scheduling node. The verification request includes, but is not limited to, the following information: terminal identifier (used to identify the user node that initiated the verification request), file number (used to identify the target file to be verified), file version number (used to identify the version status of the target file), timestamp (used to identify the time when the verification request was initiated), etc.

[0046] S120. The scheduling node determines the edge node group based on the edge node load and distributes the audit task corresponding to the verification request to each edge node in the edge node group.

[0047] In this context, edge node load can be understood as the resource occupancy status of each edge node in the file integrity monitoring system, reflecting the remaining processing capacity of each edge node. Edge node load can be measured by performance indicators, but not limited to: Central Processing Unit (CPU) utilization, memory usage, remaining storage space, and network latency. An edge node group can be understood as a set of edge nodes with service capabilities dynamically determined by the scheduling node based on their load. For example, a group can be formed by selecting several edge nodes with relatively low load. An audit task can refer to a standardized task instruction obtained by repackaging a file integrity verification request using the scheduling node. This instruction is used to trigger edge nodes to perform integrity evidence queries. In addition to retaining relevant information from the original verification request, the audit task may also include information such as a task identifier (ID).

[0048] In this embodiment of the invention, the scheduling node can receive task requests from each user node and encapsulate the task request and the unique identifier of the requesting task together into an audit task. At the same time, the scheduling node can periodically collect the performance indicators of all edge nodes in the file integrity monitoring system to measure the load of the edge nodes, and then select several edge nodes with low current load to form an edge node group. The audit task is then distributed to each edge node in the edge node group to request the integrity evidence corresponding to the target file from the edge node.

[0049] S130. The edge node searches for the corresponding integrity evidence based on the audit task and sends the integrity evidence to the scheduling node.

[0050] In this context, integrity evidence can be understood as a combination of data returned by edge nodes to prove that the target file has not been tampered with. These data combinations constitute a verifiable integrity link, which can be used by user nodes to reconstruct the verification path. For example, integrity evidence may include, but is not limited to, the following information: historical hash value of the target file, Merkle tree root node value, path proof, text location information, etc.

[0051] In this embodiment of the invention, after receiving an audit task issued by the scheduling node, each edge node in the edge node group can parse out the terminal ID and file number, and then search for the corresponding integrity evidence in the pre-configured preset evidence database based on the terminal ID and file number, and return the integrity evidence to the scheduling node. Subsequently, the scheduling node and user node will verify based on the integrity evidence returned by each edge node.

[0052] S140. The scheduling node performs consistency verification based on the integrity evidence fed back by each edge node. If the consistency verification passes, the integrity evidence is sent to the user node.

[0053] Consistency verification refers to the process by which the scheduling node compares the integrity evidence returned by multiple edge nodes under the same audit task. The purpose is to prevent edge nodes from being attacked or data from being tampered with, to ensure the credibility of the evidence, and to avoid single points of error from affecting the verification results.

[0054] In this embodiment of the invention, the scheduling node can receive integrity evidence returned by each edge node for the same audit task and perform consistency comparison on each integrity evidence. For example, it can compare information such as the target file historical hash value, Merkle tree root node value, path proof, and text location information in each integrity evidence to determine the number of edge nodes with completely identical evidence. If the number of edge nodes is greater than or equal to a preset threshold, the consistency verification is deemed successful, meaning the returned integrity evidence is considered credible, and the integrity evidence is fed back to the corresponding user node. Further, if the number of edge nodes with completely identical evidence is less than the preset threshold, the consistency verification is deemed unsuccessful, meaning the returned integrity evidence is considered unreliable, indicating that some edge node information synchronization has failed or has undergone abnormal changes. In this case, a verification failure response operation can be triggered, which may include, but is not limited to: sending a real-time alarm to the system administrator, automatically initiating a task rescheduling process, and recording abnormal log comparison records under the same audit task.

[0055] S150. The user node performs local verification based on the integrity evidence and determines the corresponding file verification result.

[0056] Local verification can be understood as the process by which a user node independently completes file integrity verification based on the current hash value of the target file and the received integrity evidence.

[0057] In this embodiment of the invention, the user node can receive integrity evidence returned by the scheduling node and perform local integrity verification by combining it with the current hash value of the target file to obtain the file verification result corresponding to the target file, thereby determining whether the target file has been maliciously tampered with or unauthorizedly modified. Furthermore, if tampering of the target file is detected, corresponding abnormal response operations can be triggered, such as including but not limited to: immediately terminating the relevant process, triggering an alarm pop-up, recording the verification failure event, and generating a risk label.

[0058] Furthermore, based on the above embodiments, the document integrity monitoring method provided in this embodiment further includes:

[0059] The system type is identified by the user node, and the preset policy configuration file corresponding to the operating system type is loaded to parse out the target configuration information. The target configuration information includes at least the preset monitoring path, hash algorithm parameters and anomaly response rules.

[0060] The operating system type can refer to the operating system installed on domestically produced terminal devices, such as, but not limited to, domestic operating systems like Kylin and UnionTech. The preset policy configuration file can be understood as a pre-configured file integrity monitoring policy file for different operating system types, defining configuration information such as preset monitoring paths, hash algorithm parameters, and anomaly response rules. The target configuration information refers to the specific policy parameters parsed from the preset policy configuration file. The preset monitoring path refers to the file or directory path to be monitored, which can be divided into two main categories: general paths and specific paths. General paths can be standardized paths shared across multiple operation types, while specific paths can be monitoring file paths that exist only in certain specific operating systems, such as / etc / deepin / (unique to UnionTech). The hash algorithm parameters refer to the configuration parameters required for file hash calculation in file integrity verification, such as, but not limited to, algorithm type (e.g., SM3), salt value, and number of iterations. Anomaly response rules can refer to tiered handling strategies configured for anomalies such as file tampering. For example, for changes to core configuration files, the verification failure event and its context are recorded in detail, and the account is locked at the same time; for changes to system binary files, the relevant processes are terminated immediately and an alarm pop-up is triggered; if other sensitive file changes are found, the file permissions for ordinary users are set to non-readable and non-writable, the associated processes are terminated, an audit tag is added, and the file is marked as a high-risk object.

[0061] In this embodiment of the invention, the user node may be deployed with a file integrity monitoring component. During the initial loading process of the user node, the component can obtain the type of the currently deployed domestic operating system by executing relevant system commands or interfaces, and load the corresponding preset policy configuration file according to the operating system type. By parsing the preset policy configuration file, the component can extract target configuration information such as preset monitoring path, hash algorithm parameters and abnormal response rules. Subsequently, the file integrity monitoring component will execute the corresponding file integrity monitoring process based on the above target configuration information.

[0062] Furthermore, the file integrity monitoring component will be registered as a system startup item, ensuring that the component starts automatically with the operating system. In addition, to facilitate platform integration, the component also provides a unified script interface, which can be quickly called and integrated by domestic endpoint security platforms.

[0063] Furthermore, based on the above embodiments, the document integrity monitoring method provided in this embodiment further includes:

[0064] The file hash value of each monitored file under the preset monitoring path is determined by calling the preset hash algorithm through the user node;

[0065] User nodes encapsulate the file hash value and file metadata corresponding to each monitored file into a data packet for evidence storage, and then send the data packet to the edge node cluster for distributed storage.

[0066] Merkle trees are constructed based on the terminal identifier and file hash value in the evidence storage data packet from the edge nodes, and the evidence storage information corresponding to each monitoring file is stored.

[0067] The preset hash algorithm can include, but is not limited to, SM3, SHA256, and BLAKE3 algorithms. File metadata refers to file attribute data describing the monitored file, which may include, but is not limited to, file number, file size, modification timestamp, version number, and terminal ID. An edge node cluster refers to a distributed storage network consisting of multiple edge nodes, providing data redundancy and reliability. A Merkle tree is a binary tree structure where leaf nodes are file hash values, non-leaf nodes are concatenated hashes of their child nodes, and the root node is the Merkle root. Evidence information can serve as a benchmark for subsequent file integrity verification and may include, but is not limited to, file hash values, path proof of the file in the Merkle tree, the Merkle tree root node value, and the file's position information in the Merkle tree (such as index number, left and right path markers, etc.).

[0068] In this embodiment of the invention, before performing file integrity monitoring, a baseline generation and distributed evidence storage process is also included, the specific process of which is as follows:

[0069] ① Each user node can traverse all monitoring files under the preset monitoring path, call the preset hash algorithm such as SM3 for each monitoring file to generate a unique file hash value, and record the file metadata of each monitoring file, such as file number, file size, modification timestamp, version number, terminal ID, etc.

[0070] ② User nodes can encapsulate the file hash value and file metadata corresponding to each monitored file into a storage data packet of a specified format, and distribute it to each edge node in the edge node cluster for storage;

[0071] ③ After receiving the evidence storage data packet from the user node, the edge node constructs a Merkle tree in units of terminal ID and stores the evidence storage information of each monitored file, such as file hash value, path proof of the file in the Merkle tree, Merkle tree root node value, and file position information in the Merkle tree (such as index number, left and right path markers, etc.).

[0072] The construction process of the Merkle tree includes: for all monitoring files under the same terminal ID, the file hash value of each monitoring file is used as the leaf node of the Merkle tree. After splicing two leaf nodes, the parent node hash is generated by SM3 calculation. The Merkle tree is constructed from bottom to top until a unique root node hash value (i.e., the Merkle tree root node value) is generated.

[0073] The file integrity monitoring method provided in this invention is applied to a file integrity monitoring system. The method includes: a user node sending a verification request to a scheduling node when a file integrity verification condition is triggered; the scheduling node determining an edge node group based on the edge node load and distributing the audit task corresponding to the verification request to each edge node in the edge node group; the edge nodes searching for corresponding integrity evidence based on the audit task and sending the integrity evidence to the scheduling node; the scheduling node performing consistency verification based on the integrity evidence fed back by each edge node, and if the consistency verification passes, sending the integrity evidence to the user node; and the user node performing local verification based on the integrity evidence and determining the corresponding file verification result. This method, by adopting a three-level collaborative distributed file integrity monitoring architecture involving user nodes, scheduling nodes, and edge nodes, can support the scheduling of integrity verification requests for large-scale domestic terminals and adapt to heterogeneous systems. Through the consistency verification by the scheduling node and the local verification by the user node, the security, traceability, and reliability of file integrity monitoring are effectively improved.

[0074] Example 2

[0075] Figure 3 This is a flowchart of a file integrity monitoring method provided in Embodiment 2 of the present invention. It is further optimized and extended based on the above embodiments and can be combined with various optional technical solutions in the above embodiments. For example... Figure 3 As shown in the figure, the document integrity monitoring method provided in this embodiment includes the following steps:

[0076] S210. When the file integrity verification condition is triggered, the user node sends a verification request to the scheduling node.

[0077] In this embodiment of the invention, the triggering method for the file integrity verification condition may include any of the following: capturing a file change event under a preset monitoring path through a preset file monitoring mechanism; or the system periodic verification timer reaching a preset time threshold. Specifically, when a file change event is detected or the system periodic verification is reached, the user node can trigger the file integrity verification process and send a verification request to the scheduling node. The request content may include terminal ID, file number, file version number, and timestamp, etc.

[0078] The preset file monitoring mechanism refers to a pre-configured mechanism for monitoring whether files have changed. This mechanism can employ a kernel-based file event capture mechanism combined with inotify and epoll multiplexing to achieve real-time monitoring of files under preset monitoring paths. In one specific embodiment, an inotify listener can be registered with the kernel and bound to each preset monitoring path. The inotify file descriptor is polled using the epoll multiplexing mechanism. When the kernel detects a file creation, modification, or deletion event, a file integrity verification process is immediately triggered. The preset file monitoring mechanism can cover critical objects such as configuration files, system executables, and sensitive scripts, achieving real-time and accurate monitoring of all monitored files. Taking the / etc / passwd file as an example, the system can capture its changes in real time through the inotifywait interface, ensuring that file modification, creation, and deletion events are detected immediately. The specific implementation is as follows:

[0079] $inotifywait-me modify,create,delete / etc / passwd

[0080] Setting up watches.

[0081] Watches established.

[0082] Furthermore, a nice priority and CPU affinity taskset can be set for the file monitoring process to avoid competing with business processes for the same core's cache and computing resources. This can reduce system resource consumption while ensuring the real-time performance of file integrity monitoring.

[0083] The system periodic verification timer can be understood as a timer that triggers file integrity verification periodically. The system can trigger integrity verification every 12 hours, every 24 hours, etc. This embodiment does not impose specific restrictions on this.

[0084] S220. Obtain the performance indicators of each edge node in the file integrity monitoring system through the scheduling node, determine the comprehensive load score of each edge node according to the performance indicators, and select edge nodes with comprehensive load scores lower than the preset load score threshold to form an edge node group.

[0085] In this embodiment of the invention, the scheduling node can periodically collect performance indicators of all edge nodes in the file integrity monitoring system, such as CPU utilization, memory usage, remaining storage space, and network latency. Combined with pre-configured weighting coefficients for each performance indicator, a weighted summation is used to determine the comprehensive load score of each edge node. All edge nodes with comprehensive load scores less than or equal to a preset load score threshold are then selected to form an edge node group. In one embodiment, if the number of edge nodes with comprehensive load scores less than or equal to the preset load score threshold is greater than a preset threshold (e.g., 10), then the Top-K edge nodes can be selected to form an edge node group.

[0086] S230. The verification request and task identifier are encapsulated into an audit task by the scheduling node, and the audit task is broadcast to each edge node in the edge node group.

[0087] In this embodiment of the invention, after receiving a verification request sent by a user node, the scheduling node can encapsulate the verification request and the task ID that uniquely identifies the request task into an audit task, and distribute the audit task to each edge node in the edge node group for integrity evidence query.

[0088] S240. Using the edge node, search for the corresponding integrity evidence in the preset evidence database according to the terminal identifier and file number in the audit task, and return the integrity evidence to the scheduling node. The integrity evidence includes: the historical file hash value of the target file, the target root node value, path proof and file location information.

[0089] Among them, the preset evidence storage database can refer to a distributed database that stores evidence storage information on edge nodes, which is used to efficiently store and query massive amounts of document evidence storage information.

[0090] In this embodiment of the invention, after receiving an audit task, the edge node parses out the terminal ID and file number, and then queries and outputs the corresponding integrity evidence in a local preset evidence database based on the terminal ID and file number. The integrity evidence includes the following information: ① the historical file hash value of the target file, i.e., the file hash value generated during the baseline generation stage; ② the target root node value, i.e., the root node hash value of the Merkle tree to which the target file belongs; ③ path proof, i.e., the hash value sequence Proof = [h1, h2, ..., h...] of all sibling nodes along the path from the leaf node to the root node of the target file. n ](h n ④ File location information, i.e., the location identifier of the target file in the Merkle tree (such as index number, left and right path markers, etc.).

[0091] S250: Acquiring, by a scheduling node, integrity evidence returned by each edge node for an audit task, and determining the number of edge nodes with identical evidence among all edge nodes.

[0092] In the embodiment of the present invention, after acquiring the integrity evidence returned by all edge nodes under the same audit task ID, the scheduling node performs consistency verification on the evidence: specifically, parsing each integrity evidence data packet respectively, and extracting the historical file hash value, target root node value, path proof and file location information of the target file; then, performing pairwise comparison on all integrity evidence under the same audit task ID to determine whether the evidence is consistent. If the integrity evidence of a certain edge node is completely consistent with that of other edge nodes, marking the edge node as a valid consistent node, and counting the number of all valid consistent nodes.

[0093] S260: Determining, by the scheduling node, that the consistency verification is passed when the number of nodes is greater than or equal to a preset number threshold, or determining that the consistency verification is not passed when the number of nodes is less than the preset number threshold, and triggering a verification failure response operation.

[0094] In the embodiment of the present invention, after determining the number of nodes with identical integrity evidence, the scheduling node may compare the number with a pre-configured preset number threshold. If the number of nodes is greater than or equal to the preset number threshold, it is determined that the consistency verification is passed, that is, the integrity evidence returned this time is considered credible; if the number of nodes is less than the preset number threshold, it is determined that the consistency verification is not passed, that is, the integrity evidence returned this time is considered incredible, indicating that information synchronization of some edge nodes failed or abnormal changes have occurred. At this time, a verification failure response operation may be triggered, for example, a real-time alarm containing the task ID, inconsistent edge node list and difference analysis result may be sent to a system administrator, and a task rescheduling process is automatically initiated to distribute the audit task associated with the original task ID to another group of edge nodes. In addition, log information such as comparison logs and response states may also be recorded according to the task identification ID, which facilitates subsequent auditing.

[0095] It can be understood that the integrity evidence stored by edge nodes is key information in distributed integrity verification. If an attacker intrudes and modifies this information, it may pollute the trust foundation of the entire distributed verification network. Therefore, the present solution adopts multi-node verification: the consistency verification is considered passed only when at least M (M<N) nodes return identical integrity evidence, which prevents wrong verification caused by tampering of a single node's information. Meanwhile, node verification results are recorded, and an administrator regularly performs audit and investigation on inconsistent verification nodes.

[0096] S270: If the consistency verification is passed, sending the integrity evidence to a user node.

[0097] In this embodiment of the invention, if the scheduling node determines that the consistency verification is successful, it will feed back the corresponding integrity evidence to the user node, which will then continue to perform local verification.

[0098] S280. Reconstruct the Merkle tree by combining the path proof and file location information in the integrity evidence with the current file hash value of the target file through the user node, and determine the value of the reconstructed root node of the Merkle tree.

[0099] In this embodiment of the invention, after receiving the integrity evidence returned by the scheduling node, the user node will parse the path proof Proof = [h1, h2, ..., h n ], file location information, and target root node value h r It then calls a preset hash algorithm to determine the current file hash value h of the target file. C Then, set the current file hash value h. C As the leaf nodes for reconstruction, the Merkle tree is reconstructed from bottom to top using path proof (Proof) and file location information, and the value h′ of the reconstructed Merkle tree root node is determined. r Among them, the root node value h′ is reconstructed. r It can be represented as follows:

[0100] h′ r =SM3(...SM3(SM3(h C ||h1)||h2)...||h n )

[0101] In the formula, SM3(·) represents the national cryptographic SM3 algorithm; the splicing order of sibling nodes can be determined by the file location information.

[0102] S290. When the target root node value in the integrity evidence of the user node is the same as the reconstructed root node value, determine that the file verification result is that the file has not been tampered with; or when the target root node value is different from the reconstructed root node value, determine that the file verification result is that the file has been tampered with, and trigger an abnormal response operation.

[0103] In this embodiment of the invention, the user node can reconstruct the root node value h′. r The target root node value h in the integrity evidence rThe system compares the two data points. If they match, the target file is confirmed to be unaltered, and the system takes no further action. If they do not match, the target file may have been maliciously tampered with or modified without authorization. In this case, a corresponding exception response is triggered. For files that fail integrity verification, log recording, alarm notifications, access control, or process control are performed according to pre-configured exception response rules. For example, for changes to core configuration files, the system records the verification failure event and its context in detail and triggers account locking. For changes to system binary files, the system immediately terminates the relevant processes and triggers an alarm pop-up. If other sensitive file changes are found, the file is set to non-readable and non-writable permissions for ordinary users, the associated processes are terminated, an audit tag is added, and the file is marked as a high-risk object.

[0104] The file integrity monitoring method provided in this invention is applied to a file integrity monitoring system. By adopting a distributed file integrity monitoring architecture with three levels of collaboration among user nodes, scheduling nodes, and edge nodes, it can support the scheduling of integrity verification requests from a large number of domestic terminals and adapt to heterogeneous systems, demonstrating strong compatibility. Through consistency verification by scheduling nodes and local verification by user nodes, it effectively achieves verifiability, non-repudiation, and path traceability of file tampering, providing structural protection for data security traceability.

[0105] Example 3

[0106] Figure 4 This is a schematic diagram of a document integrity monitoring system provided in Embodiment 3 of the present invention. Figure 4 As shown, this system is a further refinement of the file integrity monitoring system in the above embodiments, wherein user node 10 specifically includes:

[0107] ①System compatibility module 101 is responsible for detecting and ensuring compatibility with domestically produced terminal equipment operating systems, and calling different program commands according to the operating system type;

[0108] ② Host policy configuration module 102 loads the corresponding file integrity monitoring policies according to the current operating system type and version. These policies define the scope of integrity constraints, that is, which file paths in the system need to be protected and continuously monitored, such as the system core configuration file paths such as / etc / passwd and / etc / shadow.

[0109] ③ The file monitoring module 103 is responsible for continuously monitoring sensitive paths in the user's file system (such as system configuration files, critical program files, user documents, etc.);

[0110] ④ Communication module 104 is responsible for communicating with other nodes, including sending evidence data packets and receiving integrity results;

[0111] ⑤ Verification module 105 is responsible for calculating file hash values, comparing received integrity evidence, and handling abnormal responses to verification results, taking different response measures according to the type of file that failed verification;

[0112] ⑥ Audit module 106 is responsible for storing verification records in local log files for easy tracing and retrieval later.

[0113] Scheduling node 20 specifically includes:

[0114] The task collection module 201 is responsible for aggregating verification requests from multiple user nodes and encapsulating them into integrity audit tasks.

[0115] Task distribution module 202 is responsible for broadcasting audit tasks to multiple edge nodes;

[0116] The evidence verification module 203 is responsible for verifying the consistency of evidence returned by edge nodes under the same task;

[0117] The communication module 204 is responsible for collecting the verification requests sent by user nodes and the integrity certificates returned by edge nodes, and feeding back the integrity certificates to the corresponding user nodes.

[0118] Edge node 30 specifically includes:

[0119] The evidence storage module 301 is responsible for storing some file summary information and historical integrity metadata (such as Merkle tree roots, hash lists, etc.);

[0120] The integrity proof module 302 is responsible for generating corresponding integrity evidence based on the file information provided by the scheduling node;

[0121] The communication module 303 is responsible for sending messages and transmitting data with other nodes.

[0122] Based on the aforementioned document integrity monitoring system, Figure 5 This is a flowchart of a document integrity monitoring method provided in Embodiment 3 of the present invention. Figure 5 As shown, the solution mainly includes: document storage process, verification request initiation process, audit task distribution process, evidence query process, evidence consistency verification process, and local verification process. The specific implementation process can be referred to the above embodiments, and will not be repeated here.

[0123] This invention presents a distributed file integrity monitoring architecture designed for domestically produced terminals, proposing a comprehensive integrity monitoring method covering the entire process from file change detection, task scheduling, evidence generation, and verification feedback. Firstly, in terms of compatibility, this solution is deeply adapted to mainstream domestic operating systems such as Kylin and UnionTech, fully utilizing their native functions and avoiding the dependency gaps and interface incompatibility issues of traditional tools on domestic platforms, achieving seamless integration and stable operation. Secondly, in terms of security, this solution uses the SM3 hash algorithm and Merkle tree structure to achieve file fingerprint evidence storage and path verification, constructing a non-repudiable integrity verification chain and enhancing the system's anti-tampering and anti-forgery capabilities. Simultaneously, it introduces a multi-node collaborative edge computing architecture to prevent single-point failures and the risk of attacks on the central node, improving system robustness. Finally, this solution uses inotify and epoll to build an event-driven listening mechanism, replacing the traditional full-disk scanning method, resulting in higher detection efficiency and lower resource consumption. Furthermore, this solution can be integrated through lightweight scripts, facilitating rapid deployment in domestic terminal security tools, demonstrating strong adaptability and low maintenance costs.

[0124] Furthermore, the process of integrity detection based on the file integrity monitoring component is as follows: Figure 6 As shown, the main processes include initial loading, baseline generation and storage, file monitoring, distributed integrity verification, and exception handling. The overall process includes:

[0125] S310 automatically identifies the type of domestic operating system, loads the corresponding preset policy configuration file, and registers it as a startup item.

[0126] S320 calls the SM3 hash algorithm to determine the file hash value of each monitoring file under the preset monitoring path, and uploads the file hash value and file metadata to the edge node cluster for distributed storage.

[0127] The S330, based on the kernel-based inotify and epoll file monitoring mechanism, performs real-time monitoring of files in the preset monitoring path and captures file change events.

[0128] S340. After detecting a file change event, send a file integrity verification request to the scheduling node.

[0129] S350: Receive integrity evidence returned by the scheduling node and perform local verification.

[0130] S360. If the target file verification fails, the corresponding exception response operation will be executed according to the file type of the target file.

[0131] This invention proposes a lightweight file integrity monitoring method adapted to domestic terminal environments. It fully leverages the security capabilities integrated into domestic operating systems such as Kylin and UnionTech, and constructs an integrity monitoring architecture through modular design to achieve efficient, low-overhead, and real-time monitoring of critical system files. This technical solution possesses at least the following beneficial effects:

[0132] ① For domestic operating system environments, a distributed file integrity monitoring architecture with user nodes, scheduling nodes and edge nodes working together is designed to support the scheduling of integrity verification requests for large-scale domestic terminals and the adaptation of heterogeneous systems.

[0133] ② Combining the SM3 algorithm with the Merkle tree structure, a hash digest is generated for the terminal's key files, and a tree-shaped evidence storage path is constructed. After receiving the integrity evidence, the user node can independently reconstruct the Merkle tree root node to complete local integrity verification, effectively realizing the verifiability, non-repudiation, and traceability of file tampering, and providing structural protection for data security traceability.

[0134] ③ A lightweight file integrity monitoring component suitable for domestic terminals is proposed, supporting the entire process of system initialization loading, baseline generation and storage, file monitoring, distributed verification and anomaly handling. The component adopts an event-driven model and has standardized interfaces, which facilitates integration and rapid access with domestic security platforms. It has low resource consumption and strong compatibility.

[0135] Example 4

[0136] Figure 7 This is a schematic diagram of a document integrity monitoring device provided in Embodiment 4 of the present invention. Figure 7 As shown, the device includes:

[0137] The request sending module 41 is used to send a verification request to the scheduling node when the file integrity verification condition is triggered by the user node;

[0138] Task distribution module 42 is used to determine the edge node group based on the edge node load through the scheduling node, and distribute the audit task corresponding to the verification request to each edge node in the edge node group;

[0139] Evidence search module 43 is used to search for corresponding integrity evidence based on the audit task through edge nodes and send the integrity evidence to the scheduling node;

[0140] The consistency verification module 44 is used to perform consistency verification based on the integrity evidence fed back by each edge node through the scheduling node. If the consistency verification is successful, the integrity evidence is sent to the user node.

[0141] The local verification module 45 is used to perform local verification based on integrity evidence through user nodes and determine the corresponding file verification result.

[0142] Furthermore, based on the above embodiments of the invention, the file integrity verification condition is triggered, including any one of the following:

[0143] The system captures file change events in the preset monitoring path through a preset file monitoring mechanism.

[0144] The system periodically verifies that the timer has reached the preset time threshold.

[0145] Furthermore, based on the above embodiments of the invention, the task distribution module 42 includes:

[0146] The edge node group determination unit is used to obtain the performance indicators of each edge node in the file integrity monitoring system through the scheduling node, determine the comprehensive load score of each edge node according to the performance indicators, and select edge nodes with comprehensive load scores lower than the preset load score threshold to form an edge node group.

[0147] The task broadcasting unit is used to encapsulate the verification request and task identifier into an audit task through the scheduling node, and broadcast the audit task to each edge node in the edge node group.

[0148] Furthermore, based on the above embodiments of the invention, the evidence search module 43 includes:

[0149] The evidence return unit is used to search for the corresponding integrity evidence in the preset evidence database through the edge node according to the terminal identifier and file number in the audit task, and return the integrity evidence to the scheduling node. The integrity evidence includes: the historical file hash value of the target file, the target root node value, path proof and file location information.

[0150] Furthermore, based on the above embodiments of the invention, the consistency verification module 44 includes:

[0151] The node number determination unit is used to obtain the integrity evidence returned by each edge node for the audit task through the scheduling node, and determine the number of nodes with the same evidence among all edge nodes.

[0152] The consistency verification unit is used to determine whether the consistency verification has passed when the number of nodes is greater than or equal to a preset threshold, or to determine whether the consistency verification has failed when the number of nodes is less than the preset threshold, and to trigger a verification failure response operation.

[0153] Furthermore, based on the above embodiments of the invention, the document integrity monitoring device also includes:

[0154] The initialization loading module is used to identify the operating system type through the user node, load the preset policy configuration file corresponding to the operating system type, and parse out the target configuration information; wherein, the target configuration information includes at least: preset monitoring path, hash algorithm parameters, and abnormal response rules.

[0155] Furthermore, based on the above embodiments of the invention, the document integrity monitoring device also includes:

[0156] The file hash calculation module is used to determine the file hash value of each monitored file under the preset monitoring path by calling the preset hash algorithm through the user node;

[0157] The evidence storage data packet sending module is used to encapsulate the file hash value and file metadata corresponding to each monitored file into an evidence storage data packet through the user node, and send the evidence storage data packet to the edge node cluster for distributed storage;

[0158] The evidence storage module is used to construct a Merkle tree based on the terminal identifier and file hash value in the evidence data packet from the edge node, and to store the evidence information corresponding to each monitoring file.

[0159] The file integrity monitoring device provided in the embodiments of the present invention can execute the file integrity monitoring method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0160] Example 5

[0161] Figure 8 A schematic diagram of an electronic device 50 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0162] like Figure 8As shown, the electronic device 50 includes at least one processor 51 and a memory, such as a read-only memory (ROM) 52 and a random access memory (RAM) 53, communicatively connected to the at least one processor 51. The memory stores computer programs executable by the at least one processor. The processor 51 can perform various appropriate actions and processes based on the computer program stored in the ROM 52 or loaded into the RAM 53 from storage unit 58. The RAM 53 can also store various programs and data required for the operation of the electronic device 50. The processor 51, ROM 52, and RAM 53 are interconnected via a bus 54. An input / output (I / O) interface 55 is also connected to the bus 54.

[0163] Multiple components in electronic device 50 are connected to I / O interface 55, including: input unit 56, such as keyboard, mouse, etc.; output unit 57, such as various types of monitors, speakers, etc.; storage unit 58, such as disk, optical disk, etc.; and communication unit 59, such as network card, modem, wireless transceiver, etc. Communication unit 59 allows electronic device 50 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0164] Processor 51 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 51 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 51 performs the various methods and processes described above, such as file integrity monitoring methods.

[0165] In some embodiments, the file integrity monitoring method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 58. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 50 via ROM 52 and / or communication unit 59. When the computer program is loaded into RAM 53 and executed by processor 51, one or more steps of the file integrity monitoring method described above may be performed. Alternatively, in other embodiments, processor 51 may be configured to perform the file integrity monitoring method by any other suitable means (e.g., by means of firmware).

[0166] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0167] In some embodiments, the document integrity monitoring method may be implemented as a computer program, which is implicitly included in a computer program product. When executed by a processor, the computer program implements the document integrity monitoring method of the present invention. The computer program product can be understood as a software product that primarily implements its solution through a computer program. The computer program used to implement the method of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer program causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer program may be executed entirely on a machine, partially on a machine, partially on a remote machine as a standalone software package, or entirely on a remote machine or server.

[0168] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0169] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0170] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0171] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0172] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0173] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method for monitoring document integrity, characterized in that, The method is applied to a file integrity monitoring system, which includes user nodes, scheduling nodes, and edge nodes. The method includes: When the file integrity verification condition is triggered, the user node sends a verification request to the scheduling node. The scheduling node determines the edge node group based on the edge node load and distributes the audit task corresponding to the verification request to each edge node in the edge node group. The edge node searches for the corresponding integrity evidence based on the audit task and sends the integrity evidence to the scheduling node. The scheduling node performs consistency verification based on the integrity evidence fed back by each edge node. If the consistency verification passes, the integrity evidence is sent to the user node. The user node performs local verification based on the integrity evidence and determines the corresponding file verification result. The integrity evidence includes: historical file hash values ​​of the target file, target root node value, path proof, and file location information. The target root node value is the hash value of the root node of the Merkle tree to which the target file belongs. The path proof is the hash value sequence of all sibling nodes on the path from the leaf node to the root node of the target file. The file location information is the location identifier of the target file in the Merkle tree. The step of performing local verification based on the integrity evidence by the user node and determining the corresponding file verification result includes: The Merkle tree is reconstructed by the user node according to the path proof and file location information in the integrity evidence, combined with the current file hash value of the target file, and the value of the reconstructed root node of the Merkle tree is determined. If the target root node value in the integrity evidence is the same as the reconstructed root node value, the file verification result is determined to be that the file has not been tampered with; or if the target root node value is different from the reconstructed root node value, the file verification result is determined to be that the file has been tampered with, and an abnormal response operation is triggered.

2. The method according to claim 1, characterized in that, The file integrity verification condition is triggered by any of the following: The system captures file change events in the preset monitoring path through a preset file monitoring mechanism. The system periodically verifies that the timer has reached the preset time threshold.

3. The method according to claim 1, characterized in that, The scheduling node determines an edge node group based on the edge node load and distributes the audit task corresponding to the verification request to each edge node in the edge node group, including: The scheduling node obtains the performance index of each edge node in the file integrity monitoring system, determines the comprehensive load score of each edge node according to the performance index, and selects the edge nodes whose comprehensive load score is lower than the preset load score threshold to form the edge node group. The scheduling node encapsulates the verification request and task identifier into the audit task and broadcasts the audit task to each edge node in the edge node group.

4. The method according to claim 1, characterized in that, The process involves the edge node retrieving corresponding integrity evidence based on the audit task and sending the integrity evidence to the scheduling node, including: The edge node searches for the corresponding integrity evidence in the preset evidence database according to the terminal identifier and file number in the audit task, and returns the integrity evidence to the scheduling node.

5. The method according to claim 1, characterized in that, The scheduling node performs consistency verification based on the integrity evidence fed back by each edge node, including: The scheduling node obtains the integrity evidence returned by each edge node for the audit task, and determines the number of nodes with the same evidence among all edge nodes. The scheduling node determines that the consistency verification has passed when the number of nodes is greater than or equal to a preset threshold, or determines that the consistency verification has failed when the number of nodes is less than the preset threshold, and triggers a verification failure response operation.

6. The method according to claim 1, characterized in that, Also includes: The user node identifies the operating system type and loads the preset policy configuration file corresponding to the operating system type to parse out the target configuration information; wherein, the target configuration information includes at least: preset monitoring path, hash algorithm parameters and abnormal response rules.

7. The method according to claim 1, characterized in that, Also includes: The user node invokes a preset hash algorithm to determine the file hash value of each monitored file under the preset monitoring path; The user node encapsulates the file hash value and file metadata corresponding to each monitored file into a data storage data packet, and sends the data storage data packet to the edge node cluster for distributed storage. Based on the edge nodes, a Merkle tree is constructed according to the terminal identifier in the evidence storage data packet and the file hash value, and the evidence storage information corresponding to each monitoring file is stored.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the file integrity monitoring method according to any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the file integrity monitoring method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Security system verification method in edge computing power secure channel

    CN119788332A