Quick data recovery method based on block chain
By deploying blockchain nodes in hyper-converged devices and combining host hardware authentication with blockchain consensus mechanisms, the problems of slow data recovery and insufficient security are solved, and rapid data recovery and secure storage are achieved.
Patent Information
- Application Number
- CN202510976506.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-16
- Publication Date
- 2025-10-17
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the existing technology, the recovery time is slow when a data node fails, and it cannot be quickly recovered when the data volume is large. In addition, there is a lack of physical node security authentication when the node is expanded, resulting in a lack of security guarantee.
By deploying blockchain nodes in hyper-converged devices, utilizing host hardware information authentication and blockchain consensus mechanisms, hardware trusted access to nodes is achieved. Distributed storage and encrypted backup are used to quickly restore data, and encrypted data is stored on backup nodes to ensure data consistency and security.
It achieves minute-level rapid data recovery, improves security, avoids virtual machine migration and malicious node disguise, and ensures the data's immutability and traceability.
Smart Images

Figure CN120803816A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of block chain, in particular to a rapid data recovery method based on block chain. BACKGROUND
[0002] The block chain is a data structure that combines valid data blocks in a chain form in time sequence, and is a decentralized shared ledger that can be attached and is guaranteed to be non-tamperable and non-repudiable by means of cryptography. The broad sense of block chain technology is a brand-new decentralized infrastructure and distributed computing paradigm that uses a chain of encrypted blocks to verify and store data, uses a distributed node consensus algorithm to generate and update data, and uses automatic script code (smart contract) to program and operate data. Hyper-converged is a technology architecture based on standard general-purpose hardware platforms. It realizes the fusion of computing, storage and network through software definition, and builds a software-defined data center centered on virtualization. The hyper-converged architecture integrates the basic elements of the data center, such as computing, storage, network and management tools, uses general server hardware to replace expensive special hardware in traditional architectures, and solves the problems of complex management and difficult expansion. The core technologies of hyper-converged architecture include computing virtualization, distributed storage and network virtualization. When the current medical health data sharing application platform uses the block chain technology, the data cluster is chained to the block chain cluster, and the business acquires and transmits data according to the identification through the regional chain cluster. The business manages the data on the data cluster through the block chain cluster.
[0003] In the current prior art, when a data node fails, data needs to be downloaded from the historical data of the cluster or from other nodes to recover the data. When the data volume is large, the recovery time is slow, and the rapid recovery of data cannot be realized, which greatly affects the business. When the node is expanded, the new server can be added to the cluster by deploying the block chain distributed software on the new server, but there is a lack of security authentication of the physical node, which leads to a lack of security guarantee. SUMMARY
[0004] The present application provides a rapid data recovery method based on block chain, which can effectively solve the problem of slow recovery time when the data volume is large, and the lack of security authentication of the physical node when the node is expanded, which leads to a lack of security guarantee.
[0005] To achieve the above purpose, the present application provides the following technical scheme: a rapid data recovery method based on block chain, comprising a block chain module, a data module and a host processing module.
[0006] The blockchain module is used for recording and authenticating nodes, is responsible for node identity authentication, permission management and consensus record of data operation, the data module is used for data storage and management, manages storage, retrieval and backup strategy of data assets, and the host processing module is responsible for coordinating the work of each module, specifically coordinating the joining and exiting of nodes, data backup and recovery operations;
[0007] The detailed processing process of data recovery includes the following steps:
[0008] S1, adding nodes and authentication process;
[0009] S2, data asset entry and marking process;
[0010] S3, data backup and encrypted storage process;
[0011] S4, host failure, fault node replacement and rapid recovery process.
[0012] According to the above technical solution, the S1, adding nodes and authentication includes the following steps:
[0013] S101, obtaining the hardware features of the host;
[0014] S102, applying to join the blockchain;
[0015] S103, blockchain consensus authentication;
[0016] S104, node registration and marking.
[0017] According to the above technical solution, the S101, when the host processing module obtains the hardware features of the host, taking the CPU serial number as an example, the network card MAC address can also be used, and the unique hardware identifier of the host is obtained through the Linux system interface: #cat / sys / devices / virtual / dmi / id / product_serial, the unique hardware identifier is: 210235A3M46221VM000Z;
[0018] The hardware identifier has uniqueness and non-tamperability to prevent virtual machine migration or malicious node disguise;
[0019] Uniqueness refers to that the hardware identifier is globally unique to avoid node identity conflict;
[0020] Non-tamperability refers to that the hardware identifier is physically fixed in the hardware and cannot be modified by software;
[0021] S102, the host processing module sends a request information of applying for joining to the blockchain module, the sending command is: add 210235A3M46221VM000Z, the request information contains hardware identification and node metadata;
[0022] S103, the blockchain module determines whether to agree to join according to the rules, the determination rule is that more than 2 / 3 of the nodes in the cluster agree, after agreeing to join, the blockchain module replies to the host processing module to agree;
[0023] S104, after receiving the feedback information of the blockchain module agreeing to join, the host processing module counts the host information of host1 210235A3M46221VM000Z cluster node number into the data module;
[0024] The host processing module calculates the key through host1 210235A3M46221VM000Z cluster node number, and the key is used as an identifier to be chained into the blockchain module.
[0025] According to the above technical scheme, the S2, the input and marking of data assets includes the following steps:
[0026] S201, data distributed storage;
[0027] S202, blockchain marked data ownership.
[0028] According to the above technical scheme, the S201, the data module stores the business data according to certain rules, and the data module determines to store in host1, and specifically adopts a distributed file system to store the business data in the cluster node host1 according to the rules;
[0029] Storage rule: adopt a distributed file system to store data, data ID retrieval obtains a location of data storage, and the host node where the data is located is retrieved;
[0030] S202, the data module submits data ID, storage location and hash value to the blockchain module, the blockchain generates a unique data marking key and chains it, ensures that the data source is traceable, the key is only stored in the blockchain and the data module, and is not exposed to the host processing module;
[0031] The host attribute record of the data asset is host1.
[0032] According to the above technical scheme, the S3, data backup and encrypted storage includes the following steps:
[0033] S301, initiate a backup request;
[0034] S302, the blockchain authorizes backup;
[0035] S303, backup ciphertext.
[0036] According to the above technical solution, the S301, the host processing module applies to the blockchain module for backup action, sends a command containing the host number, and the sent command is backup host1;
[0037] The S302, the blockchain module determines whether to agree to backup according to a rule, and the determination rule is that more than 2 / 3 nodes of the blockchain cluster agree to join;
[0038] If the backup is agreed, the backup operation is allowed, and the backup event is recorded, and the host processing module receives the information that the blockchain module agrees to backup, and obtains the data assets of host1 from the data module;
[0039] The S303, the host processing module pulls the original data from the data module, backs up the host1 data assets to the backup node, uses a symmetric encryption algorithm for encryption processing, generates ciphertext, and stores the backup data in the form of ciphertext in the backup node. The backup node is another server physically isolated to ensure that it cannot be directly accessed and used after being separated from the system.
[0040] According to the above technical solution, the S4, host failure, fault node replacement and rapid recovery includes the following steps:
[0041] S401, fault detection and trigger replacement;
[0042] S402, blockchain authorization recovery;
[0043] S403, ciphertext data recovery;
[0044] S404, data consistency check.
[0045] According to the above technical solution, the S401, the new host processing module applies to the blockchain module for replacement action, sends a command containing the new host serial number, and the command is replace host1 hostnew, the new host serial number is 210235A3M46221VM000N;
[0046] The S402, the blockchain module determines whether to agree to replace according to a rule, and the rule is that more than 2 / 3 nodes of the blockchain cluster agree to join;
[0047] After the new host processing module receives the information that the blockchain module agrees to replace, the new host processing module recovers data through the backup node.
[0048] According to the technical scheme, the S403 adds a new data node to a data module cluster, and a new host processing module sends a check action to the data module, and the sending command is check hostnew host1;
[0049] The new node obtains encrypted data from the backup node, decrypts the encrypted data using a preset key, and restores the service data;
[0050] The S404 calculates a key for data assets by a data processing module, compares the key with a key of a block chain, and returns a detection result to a host processing module and the block chain;
[0051] If the detection passes, the block chain module and the data module are updated, a key of the original host1 is replaced by a key of the new node, a node ID is updated to hostnew 210235A3M46221VM000N, a cluster node number is calculated as a key, the key is chained as an identifier, original host1 data is updated to hostnew data, other data is the same, and the host1 key is deleted.
[0052] Compared with the prior art, the present application has the following beneficial effects:
[0053] When the block chain information system is deployed on the hyper-converged product, the hyper-converged product integrates computing, storage, network and security capabilities, the block chain node is deployed in the hyper-converged device, network services, computing services and storage services and security services can be provided for the distributed nodes of the block chain, the block chain node and the data node are physically integrated, that is, they are deployed on the same physical machine, but are logically isolated, that is, the data is stored through different resource pools and is completely logically isolated, the three goals of hardware trusted access, fast data recovery and block chain trusted evidence are achieved, and the application is suitable for industry scenarios with high requirements for data security and timeliness.
[0054] Meanwhile, the host is authenticated through host hardware information, the security is improved, the process of backing up and restoring data needs to be applied to the block chain, the security is ensured, and the data is restored through backup data instead of data cluster, and the recovery speed is improved. BRIEF DESCRIPTION OF DRAWINGS
[0055] The accompanying drawings are included to provide a further understanding of the application, and constitute a part of the specification, illustrate the application together with the embodiments of the application, and do not constitute a limitation on the application.
[0056] In the drawings:
[0057] Figure 1 is a step flow chart of the data recovery method of the application;
[0058] Figure 2is a schematic diagram of the blockchain information system of the present application deployed on a hyper-converged product;
[0059] Figure 3 is a schematic diagram of the core process of the data recovery method of the present application;
[0060] Figure 4 is a schematic diagram of the use of the blockchain by the existing medical health data sharing application platform;
[0061] Figure 5 is an abstract schematic diagram of the existing blockchain information system. DETAILED DESCRIPTION
[0062] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings, and it should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application.
[0063] Embodiment: As shown in the figure, the present application provides a technical solution, a fast data recovery method based on blockchain, including a blockchain module, a data module and a host processing module; Figures 1-3
[0064] The blockchain module is used for recording and authenticating nodes, responsible for node identity authentication, permission management and consensus record of data operation, the data module is used for data storage and management, managing the storage, retrieval and backup strategy of data assets, and the host processing module is responsible for coordinating the work of each module, specifically coordinating the joining and exiting of nodes, the operation of data backup and recovery;
[0065] The detailed processing process of data recovery includes the following steps:
[0066] S1, adding nodes and authentication process;
[0067] S2, data asset entry and marking process;
[0068] S3, data backup and encrypted storage process;
[0069] S4, host failure, fault node replacement and fast recovery process.
[0070] Based on the above technical solution, S1, adding nodes and authentication includes the following steps:
[0071] S101, obtaining the hardware features of the host;
[0072] S102, applying to join the blockchain;
[0073] S103, blockchain consensus authentication;
[0074] S104, node registration and marking.
[0075] Based on the above technical solution, in S101, the host processing module obtains the host hardware characteristics, taking the CPU serial number as an example, or the network card MAC address, through the Linux system interface: #cat / sys / devices / virtual / dmi / id / product_serial to obtain the host's unique hardware identifier. The unique hardware identifier is: 210235A3M46221VM000Z;
[0076] The hardware identifier is unique and cannot be tampered with to prevent virtual machine migration or malicious node impersonation;
[0077] Uniqueness means that the hardware identifier is globally unique, avoiding node identity conflicts;
[0078] Immutability means that the hardware identifier is physically fixed in the hardware and cannot be modified through software;
[0079] S102: The host processing module sends a request to the blockchain module to join. The command sent is: add210235A3M46221VM000Z. The request includes the hardware identifier and node metadata.
[0080] S103: The blockchain module determines whether to agree to join according to the rules. The judgment rule is: more than 2 / 3 of the nodes in the cluster agree. After agreeing to join, the blockchain module replies to the host processing module.
[0081] S104, after the host processing module receives the feedback information that the blockchain module agrees to join, the host processing module records the host information into the data module with the cluster node number host1 210235A3M46221VM000Z;
[0082] The host processing module calculates the key using the cluster node number of host1 210235A3M46221VM000Z. The key is used as an identifier and uploaded to the blockchain module.
[0083] Based on the above technical solution, S2, the entry and labeling of data assets includes the following steps:
[0084] S201, data distributed storage;
[0085] S202. Blockchain marks data ownership.
[0086] Based on the above technical solution, S201, the data module stores the business data according to certain rules, and the data module determines to store it on host1. Specifically, a distributed file system is used to store the business data on the cluster node host1 according to the rules;
[0087] Storage rule: data is stored in a distributed file system, and data ID retrieval obtains a data storage location, and the host node where the data is located is retrieved;
[0088] S202, the data module submits the data ID, storage location and hash value to the blockchain module to the blockchain, the blockchain generates a unique data marker key and chains it, ensures traceability of data sources, the key is only stored in the blockchain and the data module, and is not exposed to the host processing module;
[0089] The host attribute record of the data asset is the host number, and the host number is host1.
[0090] Based on the above technical solution, S3, data backup and encrypted storage includes the following steps:
[0091] S301, initiate a backup request;
[0092] S302, the blockchain authorizes backup;
[0093] S303, ciphertext backup.
[0094] Based on the above technical solution, S301, the host processing module applies for backup action to the blockchain module, sends a command containing the host number, and sends the command as backup host1;
[0095] S302, the blockchain module determines whether to agree to backup according to the rules, and the determination rule is that more than 2 / 3 nodes of the blockchain cluster agree to join;
[0096] If the backup is agreed, the backup operation is allowed, and the backup event is recorded, and the host processing module receives the information that the blockchain module agrees to backup, and obtains the data asset of host1 from the data module;
[0097] S303, the host processing module pulls the original data from the data module, backs up the host1 data asset to the backup node, uses a symmetric encryption algorithm for encryption processing, generates ciphertext, and stores the backup data in the form of ciphertext in the backup node. The backup node is another server physically isolated to ensure that it cannot be directly accessed and used after being separated from the system.
[0098] Based on the above technical solution, S4, host failure, fault node replacement and rapid recovery includes the following steps:
[0099] S401, fault detection and trigger replacement;
[0100] S402, the blockchain authorizes recovery;
[0101] S403, ciphertext data recovery;
[0102] S404, data consistency check.
[0103] Based on the above technical solution, S401, the new host processing module applies for replacement to the blockchain module, sends a command containing the new host serial number, the command is: replace host1 hostnew, and the new host serial number is: 210235A3M46221VM000N;
[0104] S402, the blockchain module determines whether to agree to replace according to the rules, the rules are: more than 2 / 3 nodes of the blockchain cluster agree to join;
[0105] After the new host processing module receives the information that the blockchain module agrees to replace, the new host processing module restores the data through the backup node.
[0106] Based on the above technical solution, S403, the new data node is added to the data module cluster, and the new host processing module sends a check action to the data module, and the command sent is: check hostnew host1;
[0107] The new node obtains encrypted data from the backup node, and restores the business data after decryption using the preset key;
[0108] S404, the data processing module calculates the key of the data asset and compares it with the key of the blockchain, and replies to the host processing module and the blockchain with the detection result;
[0109] If the detection is passed, the blockchain module and the data module are updated, the key of the original host1 is replaced with the key of the new node, the node ID is updated to: hostnew 210235A3M46221VM000N, the cluster node number is calculated key, the key is chained as an identifier, the original host1 data is updated to hostnew data, and other data is the same, and the host1 key is deleted.
[0110] As shown in Figures 4-5 , the current prior art chains the data cluster to the blockchain cluster, the business obtains and transmits data through the regional chain cluster according to the identifier, and the business manages the data on the data cluster through the blockchain cluster. However, the existing method needs to download data from the historical data of the cluster or from other nodes to recover the data when the node fails, and the recovery time is slow when the data volume is large, which affects the business. When the node is expanded, the new server can be deployed only by deploying the blockchain distributed software to join the cluster, and there is a lack of security authentication for the physical node.
[0111] The technical solution of the present application is compared with the prior art as shown in the following table: Problems exist Prior art solutions The technical solutions of the present application Slow data recovery Dependence on full node data synchronization Fast recovery of encrypted files in backup nodes Lack of physical node authentication Joining the cluster only through software authorization Hardware feature binding + blockchain consensus authentication Data consistency risk Dependence on centralized verification mechanism Distributed storage + blockchain verification
[0112] As can be seen from the above table, compared with the prior art scheme, the technical scheme of the present application has the following advantages: the present application realizes minute-level recovery by redundant storage of the backup node's ciphertext data, bypasses the traditional blockchain full node data synchronization, prevents virtual machine migration or malicious node disguise based on the physical binding of CPU serial number and other hardware features, records the mapping relationship between the blockchain data Key and the node identifier, ensures the consistency within the data life cycle, and adopts a double protection mechanism of encrypted storage and verification to avoid data tampering or leakage.
[0113] Finally, it should be noted that: the above only for the preferred examples of the present application, and not for limiting the present application, although the foregoing embodiments of the present application are described in detail, for those skilled in the art, it still can be modified, or part of the technical features of the equivalent replacement of the technical scheme recorded in the foregoing embodiments. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included within the scope of protection of the present application.
Claims
1. A blockchain-based rapid data recovery method, characterized by: Includes blockchain module, data module and host processing module; The blockchain module is used to record and authenticate nodes, and is responsible for node identity authentication, authority management, and consensus recording of data operations. The data module is used for data storage and management, managing the storage, retrieval, and backup strategies of data assets. The host processing module is responsible for coordinating the work of various modules, specifically coordinating the entry and exit of nodes, data backup, and recovery operations. The detailed process of data recovery includes the following steps: S1, adding nodes and authentication process; S2. Data asset entry and tagging process; S3, data backup and encrypted storage process; S4: Host failure, faulty node replacement and rapid recovery process.
2. The blockchain-based rapid data recovery method according to claim 1, characterized in that: S1, adding nodes and authentication, includes the following steps: S101, obtaining hardware characteristics of the host; S102. Apply to join the blockchain; S103, blockchain consensus certification; S104: Node registration and marking.
3. The blockchain-based rapid data recovery method according to claim 2, characterized in that: In step S101, when acquiring hardware characteristics of the host, the host processing module acquires a unique hardware identifier of the host through a Linux system interface; The hardware identifier is unique and cannot be tampered with to prevent virtual machine migration or malicious node impersonation; Uniqueness means that the hardware identifier is globally unique, avoiding node identity conflicts; Immutability means that the hardware identifier is physically fixed in the hardware and cannot be modified through software; In step S102, the host processing module sends a request message for joining the blockchain module, where the request message includes a hardware identifier and node metadata; In step S103, the blockchain module determines whether to agree to join according to the rules. The determination rule is: more than 2 / 3 of the nodes in the cluster agree. After agreeing to join, the blockchain module replies to the host processing module with an approval; In step S104, after the host processing module receives the feedback information from the blockchain module that it agrees to join, the host processing module enters the host information into the data module as a cluster node number; The host processing module calculates the key through the cluster node number, and the key is used as an identifier to be uploaded to the chain and enter the blockchain module.
4. The blockchain-based rapid data recovery method according to claim 1, characterized in that: The step S2, data asset entry and labeling, includes the following steps: S201, data distributed storage; S202. Blockchain marks data ownership.
5. The blockchain-based rapid data recovery method according to claim 4, characterized in that: In S201, the data module stores the business data according to certain rules, and the data module determines to store the data on host1. Specifically, the distributed file system is used to store the business data on the cluster node host1 according to the rules. Storage rules: Use a distributed file system to store data. Retrieve the data ID to find the location where the data is stored, and then retrieve the host node where the data is located. In step S202, the data module submits the data ID, storage location, and hash value to the blockchain module. The blockchain generates a unique data identification key and uploads it to the blockchain to ensure that the data source is traceable. The key is only stored in the blockchain and the data module and is not exposed to the host processing module. The host attribute of the data asset is recorded as the host number, and the host number is host1.
6. The blockchain-based rapid data recovery method according to claim 1, characterized in that: The S3 data backup and encrypted storage includes the following steps: S301, initiate a backup request; S302, blockchain authorization backup; S303, ciphertext backup.
7. The blockchain-based rapid data recovery method according to claim 6, characterized in that: In step S301, the host processing module applies for a backup action to the blockchain module and sends a command including the host number; In step S302, the blockchain module determines whether to agree to the backup according to the rules. The determination rule is: more than 2 / 3 of the nodes in the blockchain cluster agree to join; If the backup is approved, the backup operation is allowed and the backup event is recorded. The host processing module receives the backup approval information from the blockchain module and obtains the data assets of host1 from the data module. In S303, the host processing module pulls the original data from the data module, backs up the host1 data assets to the backup node, encrypts them using a symmetric encryption algorithm, generates ciphertext, and stores the backup data in ciphertext form on the backup node. The backup node is another physically isolated server to ensure that it cannot be directly accessed and used after leaving the system.
8. The blockchain-based rapid data recovery method according to claim 1, characterized in that: S4, host failure, fault node replacement and rapid recovery, includes the following steps: S401, fault detection and triggering replacement; S402, blockchain authorization recovery; S403, ciphertext data recovery; S404: Data consistency check.
9. The blockchain-based rapid data recovery method according to claim 8, characterized in that: In step S401, the new host processing module applies to the blockchain module for a replacement action and sends a command including the new host serial number; In step S402, the blockchain module determines whether to agree to the change according to the rules, where the rules are: more than two-thirds of the nodes in the blockchain cluster agree to join; After the new host processing module receives the information that the blockchain module agrees to replace it, the new host processing module restores the data through the backup node.
10. The blockchain-based rapid data recovery method according to claim 8, characterized in that: The S403, adding the new data node to the data module cluster, and the new host processing module sends a check action to the data module; The new node obtains encrypted data from the backup node, decrypts it using the preset key, and then restores the business data; In step S404, the data processing module calculates the key of the data asset, compares it with the key of the blockchain, and responds to the host processing module and the blockchain with the detection result. If the test passes, the blockchain module and data module will be updated, the original host1 key will be replaced with the new node key, the node ID will be updated, the cluster node number will be used to calculate the key, the key will be used as the identifier on the chain, the original host1 data will be updated to hostnew data, and other data will be the same, and the host1 key will be deleted.