An administrative file tamper-proof storage method and system
By associating and coupling the content features and structural description information of administrative archives to generate digital fingerprints, and combining them with unique identifier binding and blockchain consensus mechanism for storage, the problem of insufficient correlation of archive content features in existing technologies is solved, realizing the immutability and traceability of archives, and improving storage security and management efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUIZHOU BUSINESS SCHOOL
- Filing Date
- 2026-01-28
- Publication Date
- 2026-05-08
AI Technical Summary
Existing technologies for tamper-proof storage of administrative archives suffer from insufficient correlation between the characteristics of archive content and structural information. Digital fingerprint generation relies on single-dimensional data processing, making it difficult to fully map the core attributes of the archives. This results in tampering behavior being difficult to accurately capture, and the lack of rigorous uniqueness verification and encryption processing leads to insufficient decentralized verification of the evidence storage results. Consequently, it is impossible to quickly locate the root cause of tampering, affecting the security and reliability of storage.
Digital fingerprints are generated by associating and coupling the content feature set and structural description information of the target file. They are then stored on the blockchain using unique identifier binding, block encoding, and blockchain consensus mechanisms. Multi-level verification and automated response are performed, including real-time feature summary verification, permission locking, and audit tracking, forming a closed-loop anti-tampering system throughout the entire process.
It enhances the security and reliability of administrative archives storage, ensures the uniqueness and integrity of archive identification, realizes the immutability and traceability of archive data, and significantly improves the efficiency and intelligence level of security management.
Smart Images

Figure CN121580452B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of archival storage technology, and in particular to a method and system for tamper-proof storage of administrative archives. Background Technology
[0002] As an important data carrier with legal validity and historical value, the security and integrity of administrative archives are directly related to the standardization and traceability of administrative management activities. Existing technologies for tamper-proof storage of administrative archives lack sufficient exploration of the correlation between the characteristics and structural information of the archive content. Digital fingerprint generation often relies on single-dimensional data processing, making it difficult to comprehensively map the core attributes of the archives. This makes it difficult to accurately detect tampering and fails to form an effective front-end protection barrier. At the same time, the binding method between archive identifiers and feature information lacks rigorous uniqueness verification and encryption processing, which easily leads to problems such as identity confusion and feature tampering, seriously affecting the credibility of archive storage.
[0003] In the evidence preservation and verification of archival data, the existing storage architecture lacks an efficient consensus mechanism, the collaborative decision-making ability of verification nodes during data upload is weak, and the degree of decentralized verification of evidence preservation results is insufficient, making it difficult to resist the risk of centralized tampering. In addition, the multi-level verification system is imperfect, and the comparative analysis of the feature summary of instantly accessible archives and historical evidence records relies on a single indicator, lacking a comprehensive assessment of similarity, difference fluctuations, and node credibility, resulting in insufficient accuracy of status verification results. Moreover, after anomalies occur, the accuracy of access control and the completeness of audit trails are lacking, making it impossible to quickly locate the root cause of tampering and form a closed-loop management system, which significantly reduces the security protection efficiency and emergency response capability of administrative archive storage. Therefore, how to improve the security of administrative archive storage has become an urgent problem to be solved. Summary of the Invention
[0004] This invention provides a method and system for preventing tampering with administrative archives, in order to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides a method for tamper-proof storage of administrative archives, comprising:
[0006] S1. Correlate and couple the content feature set and structural description information of the target file to obtain the digital fingerprint of the target file;
[0007] S2. Bind the unique identifier of the target file to the digital fingerprint to obtain the feature binding record of the target file;
[0008] S3. The metadata of the target file and the feature binding record are divided into blocks and encoded to obtain the data block of the target file. Based on the blockchain consensus mechanism of the target file, the data block is stored on the chain to obtain the evidence storage chain record of the target file.
[0009] S4. When the target file is detected to be accessed, the real-time feature summary of the target file is verified with the evidence storage chain record at multiple levels to obtain the status verification result of the target file.
[0010] S5. Based on the status verification result, automatically respond to the target file:
[0011] S51. When the status verification result passes, the access log of the target file is archived into the evidence storage chain record;
[0012] S52. When the status verification result fails, the access permissions of the target file are locked, the access permission lock record of the target file is obtained, and the access permission lock record is audited and traced to generate an audit report of the target file.
[0013] In a preferred embodiment, the step of associating and coupling the content feature set and structural description information of the target file to obtain the digital fingerprint of the target file includes:
[0014] Collect the raw data of the target file;
[0015] The original data is subjected to structured parsing to obtain the content feature set and structural description information of the target file;
[0016] Tensor synthesis is performed on the content features in the content feature set to obtain the content feature vector of the target file;
[0017] Based on the relationships between data texts in the target file, the structural description information is topologically constructed to obtain a structural relationship map of the target file;
[0018] The content feature vectors are mapped to the structural relationship graph, and the mapped graph is dimensionality reduced to obtain the fusion features of the target file.
[0019] Based on the timestamp of the target file, the fusion feature is associated and encoded to obtain the digital fingerprint of the target file.
[0020] In a preferred embodiment, binding the unique identifier of the target file to the digital fingerprint to obtain the feature binding record of the target file includes:
[0021] The entity attributes of the target file are formatted to obtain the standard identifier of the target file;
[0022] By concatenating the standard identifiers in chronological order, a unique identifier for the target file is obtained.
[0023] The unique identifier is verified to obtain the verified identifier of the target file;
[0024] Based on the private key of the target file, the digital fingerprint is digitally signed to obtain the signed fingerprint of the target file;
[0025] By fusing the verified identifier, the signature fingerprint, and the timestamp of the target file, a structured data object of the target file is obtained;
[0026] The structured data object is jointly encapsulated to obtain the feature binding record of the target file.
[0027] In a preferred embodiment, the step of dividing and encoding the metadata of the target file and the feature binding record into blocks to obtain the data blocks of the target file includes:
[0028] The administrative management data of the original data in the target file is used as the metadata of the target file;
[0029] Semantic parsing of the metadata yields a structured metadata dataset of the target file;
[0030] The feature binding record is serialized to obtain the feature byte sequence of the target file;
[0031] The structured metadata dataset and the feature byte sequence are heterogeneously associated to obtain the structural description information of the target file;
[0032] Based on the data volume of the structured metadata dataset and the byte length of the feature byte sequence, erasure coding is performed on the structure description information to obtain the data block of the target file.
[0033] In a preferred embodiment, the blockchain consensus mechanism based on the target file, which stores the data block on the blockchain to obtain the evidence storage chain record of the target file, includes:
[0034] Based on the information of the custodian institution of the target file, determine the evidence storage alliance chain of the target file;
[0035] The data block is distributed to the verification area on the evidence storage consortium chain, and the verification area is hash-verified to obtain the local verification result of the target file;
[0036] Based on the blockchain consensus mechanism of the target file, the verification area is assigned a corresponding decision weight to obtain the weighted verification area of the target file;
[0037] Based on the local verification results, multiple rounds of collaborative decision-making are performed on the weighted verification region to obtain the decision results for the target file;
[0038] Based on the decision result, the hash value, block description information and consensus timestamp in the data block are packaged and jointly stored in the storage node of the storage alliance chain to obtain the storage chain record of the target file.
[0039] In a preferred embodiment, the step of performing multi-level verification between the real-time feature summary of the target file and the evidence storage chain record to obtain the status verification result of the target file includes:
[0040] Multidimensional feature deconstruction is performed on the evidence storage chain records to obtain the historical feature summary and node comprehensive credibility of the evidence storage chain records;
[0041] The similarity between the historical feature summary and the real-time feature summary of the target file is evaluated to obtain the similarity index of the target file;
[0042] The difference between the historical feature summary and the real-time feature summary is quantified to obtain the difference fluctuation of the target file;
[0043] A consistency assessment is performed on the similarity index and the difference fluctuation to obtain the consistency confidence level of the target file;
[0044] Based on the node's overall credibility, the similarity index, the difference fluctuation, and the consistency confidence, the instant feature summary and the evidence storage chain record are comprehensively evaluated to obtain the status verification result of the target file.
[0045] In a preferred embodiment, the formula for calculating the state verification result is: ;
[0046] in, This indicates the result of the status verification. This represents the preset weighting coefficient. Indicates the first The consistency confidence level of each dimension. Indicates the first The similarity metrics of the dimensions, Indicates the first The difference in the dimensional fluctuations. This indicates the overall credibility of the node. This indicates the preset positive control parameter. Represents the arctangent function. Represents an exponential function. This represents the natural logarithm function.
[0047] In a preferred embodiment, the step of locking the access permissions of the target file and obtaining the access lock record of the target file when the status verification result fails includes:
[0048] Anomaly pattern matching is performed on the status verification results to obtain anomaly feature descriptions of the target file;
[0049] The abnormal feature description and the encryption level of the target file are encoded into instructions to obtain the initial locking operation instruction for the target file;
[0050] Obtain the real-time access context, active session identifier, and concurrent operation request list of the target file to obtain a context snapshot of the target file;
[0051] The initial locking operation command and the context snapshot are analyzed in real time, and the scope and timing of the initial locking operation command are optimized and adjusted based on the analysis results to obtain the final locking command for the target file.
[0052] The final locking command is applied to precisely control access permissions to the target file and to record the execution feedback of the target file.
[0053] The anomaly description, the context snapshot, the final lock instruction, and the execution feedback are encapsulated into a permission lock record for the target file.
[0054] In a preferred embodiment, the step of auditing the access lock records to generate an audit report for the target file includes:
[0055] By combining the permission lock records, the operation trajectory of the final lock command in the target file, and the real-time status data of the target file, an audit evidence set for the target file is obtained;
[0056] A causal relationship analysis was performed on the audit evidence set to obtain the root cause inference results of the audit evidence set;
[0057] Based on the root cause inference results, the administrative management attributes and general security principles of the target file are mapped to obtain a multi-dimensional judgment strategy for the target file.
[0058] Based on the aforementioned multi-dimensional analysis strategy, the access control records are analyzed in a targeted manner to obtain a draft audit report for the target file.
[0059] The audit report for the target file is obtained by performing a chain-of-evidence closure verification on the draft audit report and the audit evidence set.
[0060] To address the above problems, the present invention also provides an administrative archive anti-tampering storage system, the system comprising:
[0061] The digital fingerprint generation module is used to correlate and couple the content feature set and structural description information of the target file to obtain the digital fingerprint of the target file.
[0062] The feature binding module is used to bind the unique identifier of the target file to the digital fingerprint to obtain the feature binding record of the target file;
[0063] The data storage module is used to encode the metadata of the target file and the feature binding record in blocks to obtain the data block of the target file, and store the data block on the blockchain based on the blockchain consensus mechanism of the target file to obtain the storage chain record of the target file.
[0064] The feature verification module is used to perform multi-level verification between the real-time feature summary of the target file and the evidence storage chain record when the target file is detected to be accessed, so as to obtain the status verification result of the target file.
[0065] An automated response module is used to automatically respond to the target file based on the status verification result. When the status verification result passes, the access log of the target file is archived to the evidence storage chain record. When the status verification result fails, the access permissions of the target file are locked to obtain the access lock record of the target file, and the access lock record is audited to generate an audit report of the target file.
[0066] Compared with the prior art, the present invention has the following beneficial effects:
[0067] 1. This invention generates digital fingerprints by associating and coupling the content feature set and structural description information of the target archives. Combined with technologies such as unique identifier binding, block encoding, and on-chain storage using blockchain consensus mechanisms, it constructs a closed-loop anti-tampering system that significantly improves the security and reliability of administrative archive storage. The deep integration of digital fingerprints and feature binding records ensures the uniqueness and integrity of the archive identity, while the combination of block encoding and blockchain evidence storage achieves the immutability and traceability of archive data, blocking the possibility of illegal tampering from the source of storage.
[0068] 2. This invention significantly improves the efficiency of administrative archive security management through a multi-level verification mechanism and automated response process; real-time feature summary verification during access can quickly and accurately determine the archive status; access log archiving when access is approved and permission locking and audit tracking when access is denied form dynamic protection, which not only ensures the smoothness of legitimate access but also promptly curbs abnormal operations. At the same time, the generated audit report provides accurate basis for archive management, effectively improving the intelligence and standardization level of administrative archive storage management. Attached Figure Description
[0069] Figure 1 This is a flowchart illustrating an embodiment of an administrative archive anti-tampering storage method according to the present invention.
[0070] Figure 2 A functional module diagram of an administrative archive anti-tampering storage system provided in an embodiment of the present invention;
[0071] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0072] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0073] This application provides a method for preventing tampering in the storage of administrative archives. The executing entity of this method includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the method provided in this application: a server, a terminal, etc. In other words, the method for preventing tampering in the storage of administrative archives can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0074] Reference Figure 1 The diagram shown is a flowchart illustrating an embodiment of an administrative file anti-tampering storage method according to the present invention. In this embodiment, the administrative file anti-tampering storage method includes:
[0075] S1. Correlate and couple the content feature set and structural description information of the target file to obtain the digital fingerprint of the target file;
[0076] In this embodiment of the invention, the step of associating and coupling the content feature set and structural description information of the target file to obtain the digital fingerprint of the target file includes:
[0077] Collect the raw data of the target file;
[0078] The original data is subjected to structured parsing to obtain the content feature set and structural description information of the target file;
[0079] Tensor synthesis is performed on the content features in the content feature set to obtain the content feature vector of the target file;
[0080] Based on the relationships between data texts in the target file, the structural description information is topologically constructed to obtain a structural relationship map of the target file;
[0081] The content feature vectors are mapped to the structural relationship graph, and the mapped graph is dimensionality reduced to obtain the fusion features of the target file.
[0082] Based on the timestamp of the target file, the fusion feature is associated and encoded to obtain the digital fingerprint of the target file.
[0083] When collecting raw data from the target archive, the storage location of the target archive is clearly defined, including all storage media such as local servers and cloud storage nodes. A stable connection is established with the storage media through standard data transmission protocols to directly read all types of data content, such as text, tables, and images, contained in the target archive. All kinds of raw information generated during the formation and circulation of the archive are completely captured, ensuring that the collected raw data fully covers every data segment of the target archive without missing any key information.
[0084] When performing structured analysis on the raw data, the raw data is first divided into categories such as text data, tabular data, and image data according to data type. Text data is split according to the natural separation of paragraphs and sentences. Tabular data is broken down according to the regular structure of rows and columns. For image data, text information is extracted through optical character recognition technology and graphic elements are extracted through graphic contour recognition. From the split or extracted data, key information reflecting the core attributes of the archives is selected to form a content feature set. At the same time, the system sorts out the organization form, hierarchical classification, and storage format of various types of data, and records this information in detail to form structural description information.
[0085] When performing tensor synthesis on the content features in the content feature set, each content feature in the set is regarded as an independent basic element. They are arranged in an orderly manner according to the category to which the feature belongs and the inherent logical relationship between the features. All the arranged feature elements are integrated to form a multi-dimensional tensor structure. Then, through a processing method with a unified dimensional standard, the multi-dimensional tensor structure is transformed into a one-dimensional numerical sequence. This one-dimensional numerical sequence is the content feature vector of the target file. Each content feature has a unique corresponding position in the vector, accurately reflecting its own attribute information.
[0086] When constructing a topology based on the relationships between data texts in the target archive, the various types of relationships, such as reference relationships, subordinate relationships, and logical deduction relationships, are systematically identified among the data texts in the target archive. Each data text is treated as an independent node in the topology, and the relationships between data texts are used as edges connecting the nodes. The connection form of the edges is determined according to the specific type of the relationship, and the presentation weight of the edges is determined according to the tightness of the relationship. A complete network structure is built according to the hierarchical relationships and organization methods recorded in the structural description information, ultimately forming a structural relationship graph that can clearly show the relationship between all data texts.
[0087] When mapping content feature vectors to a structural relationship graph and performing dimensionality reduction on the mapped graph, the correspondence between the content features corresponding to each value in the content feature vector and the data text of each node in the structural relationship graph is first clarified. Each value in the vector is precisely matched to the corresponding node in the graph, so that each node is accompanied by a corresponding feature value. Then, the feature values that appear repeatedly in the graph and the secondary feature values that have little effect on reflecting the core attributes of the archive are filtered out. These redundant information are completely removed, and only the core feature values of key nodes and their relationships are retained. Finally, a fused feature that simultaneously covers the content features and structural relationship information of the target archive is obtained.
[0088] When encoding the fusion features based on the timestamp of the target file, the timestamp information of the target file when it was generated or when it was last modified is extracted. The specific time information such as year, month, day, hour, minute, and second contained in the timestamp is converted into a character sequence of fixed length and fixed format. This character sequence is combined with the core information in the fusion features in the order of time sequence first and feature information second, following the preset encoding rules. The combined complete information is converted into a unique string, which is the digital fingerprint of the target file. The timestamp information and the fusion features are closely combined and cannot be separated or tampered with separately.
[0089] The beneficial effect is that the implementation process, through a step-by-step operation, fully realizes the generation of digital fingerprints for target archives. The generated digital fingerprints simultaneously integrate the content characteristics, structural association information, and timestamp information of the archives, ensuring the uniqueness and integrity of the digital fingerprints. They can accurately map the core attributes of the target archives, providing a reliable basis for subsequent anti-tampering verification of the target archives, and effectively avoiding the problem of anti-tampering protection failure caused by one-sided or inaccurate digital fingerprint information.
[0090] S2. Bind the unique identifier of the target file to the digital fingerprint to obtain the feature binding record of the target file;
[0091] In this embodiment of the invention, the step of binding the unique identifier of the target file to the digital fingerprint to obtain the feature binding record of the target file includes:
[0092] The entity attributes of the target file are formatted to obtain the standard identifier of the target file;
[0093] By concatenating the standard identifiers in chronological order, a unique identifier for the target file is obtained.
[0094] The unique identifier is verified to obtain the verified identifier of the target file;
[0095] Based on the private key of the target file, the digital fingerprint is digitally signed to obtain the signed fingerprint of the target file;
[0096] By fusing the verified identifier, the signature fingerprint, and the timestamp of the target file, a structured data object of the target file is obtained;
[0097] The structured data object is jointly encapsulated to obtain the feature binding record of the target file.
[0098] When formatting the entity attributes of the target archives, the core entity attributes of the target archives are first fully extracted, including key information such as archive number, generating unit, archive category, and retention period. A unified expression standard is formulated for each type of entity attribute. The archive number adopts a fixed format of "administrative division code - organization code - year - serial number". The generating unit uses the full name without abbreviations or acronyms. The archive category is clearly named according to the national administrative archive classification standard. The retention period is presented in standard expressions such as "permanent", "30 years", and "10 years". After adjusting all entity attributes according to this standard, a standard identifier with a unified format and complete information is formed.
[0099] When concatenating standard identifiers in chronological order, first extract the associated time information corresponding to each standard identifier. This time information is the generation time of the entity attribute corresponding to the standard identifier or the occurrence time of file-related operations. Sort all standard identifiers in chronological order from earliest to latest. Then, concatenate the sorted standard identifiers end to end in sequence without adding any separator characters to form a continuous character sequence with time correlation. This character sequence is the unique identifier of the target file.
[0100] When verifying the uniqueness of a unique identifier, the system calls the database of unique identifiers for all administrative files stored in the system. The newly generated unique identifier is compared with each record in the database one by one to check if there are any cases where the character sequences are completely identical. If no duplicate records are found, the unique identifier is directly determined as the verified identifier. If a duplicate is found, the system returns to regenerate the unique identifier until it is confirmed that the generated unique identifier has no matching items in the database, and finally the verified identifier is obtained.
[0101] When digitally signing a digital fingerprint based on the private key of the target file, the private key of the target file is a unique encryption key for that file, held only by authorized personnel of the file storage institution. The private key is associated with the digital fingerprint, and each character of the digital fingerprint is encrypted using the private key, transforming the digital fingerprint into an encrypted character sequence that can only be decrypted and verified by the corresponding public key. This encrypted character sequence after being encrypted by the private key is the signature fingerprint of the target file.
[0102] When merging the verified identifier, signature fingerprint, and timestamp to obtain a structured data object, the storage hierarchy of the three types of information is first defined. The verified identifier is used as the core identifier field, the signature fingerprint as the security verification field, and the timestamp as the time traceability field. The data is organized according to the hierarchical structure of "core identifier field - security verification field - time traceability field". A clear field name is added to each field, so that the three types of information form a data set with a clear relationship and hierarchical structure. This data set is the structured data object of the target file.
[0103] When jointly encapsulating structured data objects, an encapsulation protocol conforming to the administrative archive data transmission and storage standards is adopted. First, the field names and corresponding data in the structured data object are integrated, and redundant format information is removed. A header identifier is added at the beginning of the data to identify the encapsulation type. The header identifier is a fixed code corresponding to "administrative archive feature binding data". A check code is added at the end of the data. The check code is calculated based on all characters of the structured data object and is used to verify the integrity of the data later. After the header identifier, integrated data and check code are combined, the feature binding record of the target archive is formed.
[0104] The beneficial effects of this implementation process are that, through a series of operations including standardization, uniqueness verification, encrypted signing, structured integration, and standardized encapsulation, it ensures the uniqueness, security, and integrity of the feature-bound records. It deeply binds the identity of the target file with the encrypted digital fingerprint and incorporates timestamp information, which not only avoids the problem of file identity confusion, but also strengthens the immutability of the digital fingerprint through private key signing, providing a secure and reliable basic data support for the subsequent evidence storage and tamper-proof verification of the file.
[0105] S3. The metadata of the target file and the feature binding record are divided into blocks and encoded to obtain the data block of the target file. Based on the blockchain consensus mechanism of the target file, the data block is stored on the chain to obtain the evidence storage chain record of the target file.
[0106] In this embodiment of the invention, the step of dividing and encoding the metadata of the target file and the feature binding record into blocks to obtain the data blocks of the target file includes:
[0107] The administrative management data of the original data in the target file is used as the metadata of the target file;
[0108] Semantic parsing of the metadata yields a structured metadata dataset of the target file;
[0109] The feature binding record is serialized to obtain the feature byte sequence of the target file;
[0110] The structured metadata dataset and the feature byte sequence are heterogeneously associated to obtain the structural description information of the target file;
[0111] Based on the data volume of the structured metadata dataset and the byte length of the feature byte sequence, erasure coding is performed on the structure description information to obtain the data block of the target file.
[0112] The blockchain consensus mechanism based on the target file stores the data blocks on the chain to obtain the evidence storage chain record of the target file, including:
[0113] Based on the information of the custodian institution of the target file, determine the evidence storage alliance chain of the target file;
[0114] The data block is distributed to the verification area on the evidence storage consortium chain, and the verification area is hash-verified to obtain the local verification result of the target file;
[0115] Based on the blockchain consensus mechanism of the target file, the verification area is assigned a corresponding decision weight to obtain the weighted verification area of the target file;
[0116] Based on the local verification results, multiple rounds of collaborative decision-making are performed on the weighted verification region to obtain the decision results for the target file;
[0117] Based on the decision result, the hash value, block description information and consensus timestamp in the data block are packaged and jointly stored in the storage node of the storage alliance chain to obtain the storage chain record of the target file.
[0118] When performing multi-dimensional feature deconstruction on the evidence storage chain records, the core data such as hash values, block description information, and consensus timestamps contained in the evidence storage chain records are fully extracted. Historical storage information directly related to the characteristics of the target archive is screened out and integrated to form a historical feature summary that can reflect the original state of the archive. At the same time, historical verification data of all participating nodes in the evidence storage consortium chain are collected, including information such as the node's past verification accuracy, data transmission stability, and data storage integrity. These data are comprehensively evaluated and integrated to obtain the node's comprehensive credibility, which can reflect the node's reliability.
[0119] When evaluating the similarity between historical feature summaries and real-time feature summaries of target files, the feature dimensions of the two are first clearly defined. Each feature dimension corresponds to a core attribute of the file. The feature content of historical feature summaries and real-time feature summaries on the same dimension is compared one by one. The number of feature content that is completely matched on each dimension is counted. The proportion of the number of matching dimensions to the total number of feature dimensions is calculated. This proportion is the similarity index of the target file.
[0120] When quantifying the differences between historical feature summaries and real-time feature summaries, the differences between the two in each feature dimension are examined one by one. The specific manifestations of the differences in each dimension are recorded, including the addition or subtraction of feature content and changes in feature values. Based on the degree of impact of different feature dimensions on the integrity of the archives, corresponding weights are assigned to each difference. The weights of all differences are accumulated to obtain the difference fluctuation amount that can reflect the overall degree of difference.
[0121] When assessing the consistency of similarity indicators and variance fluctuations, a unified consistency judgment standard is set. This standard clearly defines the reasonable range of variance fluctuations corresponding to different similarity indicators. The currently obtained similarity indicators and variance fluctuations are compared with the judgment standard. If the variance fluctuations are within the reasonable range corresponding to the similarity indicators, the two are judged to be consistent. The consistency confidence of the target file is calculated based on the degree of conformity. If it exceeds the reasonable range, the consistency confidence is low.
[0122] When comprehensively evaluating instant feature summaries and evidence chain records based on the fluctuation of differences in the node comprehensive credibility similarity index and the consistency confidence index, four indicators are used as core evaluation dimensions. Each dimension is assigned a preset fixed weight. The weight allocation is determined based on the importance of each indicator to the judgment of the archive status. After standardizing the indicator values of each dimension, they are weighted and summed according to their weights. The final weighted result is compared with a preset qualified threshold. If the weighted result is higher than the threshold, the status verification result is passed; if it is lower than the threshold, the status verification result is failed. Finally, the status verification result of the target archive is obtained.
[0123] When the status verification result passes, all access information of the target file during this access process is collected, including visitor identity information, access time, access device identifier, access operation type, etc. This information is organized into a standardized access log in a unified format, and the storage location of the access log in the evidence storage chain record is determined. This location is associated with the file data block corresponding to this access. Through the data writing mechanism of the blockchain, the access log is permanently stored in the evidence storage chain record, realizing the association and archiving of access log and file evidence storage information.
[0124] When performing anomaly pattern matching on the status verification results, a preset anomaly pattern library is invoked. This library contains common anomaly types such as file tampering anomalies and access anomalies, as well as their corresponding characteristic manifestations. The anomaly information reflected in the current status verification results is compared one by one with the anomaly patterns in the pattern library to find the anomaly patterns that match perfectly. Based on the definition of the anomaly pattern, the key information such as the type of anomaly, the dimension of occurrence, and the scope of influence are described in detail to obtain the anomaly feature description of the target file.
[0125] When encoding instructions for abnormal feature descriptions and the encryption level of target files, the security protection requirements corresponding to the encryption level of target files are clearly defined. The abnormal feature descriptions are transformed into standardized abnormal codes that the system can recognize. Combined with the access control rules corresponding to the encryption level, and in accordance with the preset instruction encoding specifications, the abnormal codes and access control rules are integrated into a sequence of instructions with execution logic. This sequence of instructions is the initial locking operation instruction for the target file.
[0126] When obtaining the real-time access context active session identifier and concurrent operation request list of the target file to obtain a context snapshot, the current access environment information of the target file is captured in real time, including the access network environment, access terminal system information, etc., to form a real-time access context. The unique identifiers of all sessions currently accessing the target file are extracted to form active session identifiers. All operation requests initiated for the target file within the same time period are collected and organized in the order of request initiation time to form a concurrent operation request list. These three types of information are integrated to form a complete context snapshot.
[0127] When performing real-time linkage analysis between the initial locking operation command and the context snapshot, and optimizing and adjusting the initial locking operation command based on the analysis results to obtain the final locking command, the relationship between the locking scope of the initial locking operation command and the list of concurrent operation requests of active sessions in the context snapshot is analyzed to determine whether the initial command will affect legitimate access operations. If it does, the locking scope is narrowed to lock only abnormal related sessions and requests. At the same time, the timing of the command's activation is determined based on the real-time access context to ensure that it takes effect immediately without interfering with normal system operation. After optimizing and adjusting the scope and timing, the final locking command is obtained.
[0128] When applying the final lock command to precisely control access permissions to the target file and record execution feedback, according to the requirements of the final lock command, the access permissions of abnormal access sessions are closed, prohibiting them from reading, modifying, downloading or performing any other operations on the target file. At the same time, abnormal requests in the concurrent operation request list are rejected, while legitimate requests are allowed to execute normally. The execution process of the command is monitored in real time, and information such as whether the command has taken effect successfully, the number of locked sessions and the number of abnormal requests blocked are recorded, forming the execution feedback of the target file.
[0129] When encapsulating the anomaly description, context snapshot, final lock command, and execution feedback into the target file's permission lock record, the four types of information are arranged in the order of "anomaly description - context snapshot - final lock command - execution feedback" according to a fixed storage structure. The arranged information is then formatted and standardized to remove redundant spaces and invalid characters, forming a complete data set with a well-organized structure and clear logic. This data set is the target file's permission lock record.
[0130] When the audit evidence set of the target file is obtained by aggregating the operation trajectory of the final locking instruction from the permission locking record and the real-time status data of the target file, the entire process record of the final locking instruction from generation to execution is completely extracted, including the decision basis related to each step of the instruction adjustment, etc., to form the operation trajectory. Information such as the current data status, storage location and access permission status of the target file after the permission is locked is collected as real-time status data. The three types of information, namely permission locking record, operation trajectory and real-time status data, are comprehensively collected to ensure that no key evidence is omitted, thus forming the audit evidence set of the target file.
[0131] When performing causal correlation analysis on the audit evidence set to obtain the root cause inference results, the logical relationships between various types of information in the audit evidence set are sorted out one by one. Starting from the abnormal feature descriptions in the access control records, combined with the reasons for the instruction adjustments in the operation trajectory and the abnormal performance of the files in the real-time status data, the source factors that caused the status verification to fail are traced back to determine whether the abnormality was caused by external illegal tampering, internal operational errors, or system failures. The specific links and core causes of the abnormality are identified, and the root cause inference results are obtained.
[0132] When mapping the administrative attributes of target files to general security principles based on root cause inference results to obtain a multi-dimensional assessment strategy for target files, the administrative attributes of target files are clarified, including the confidentiality level of the files and the scope of use by the management responsible parties. General security principles at the national and industry levels are retrieved, and the directions that need to be focused on assessment are determined based on the root cause inference results. The management requirements corresponding to the administrative attributes are matched with the protection standards in the general security principles, and a multi-dimensional assessment strategy covering aspects such as the determination of abnormal nature, the division of responsibilities, and suggestions for rectification measures is formulated.
[0133] When conducting targeted analysis of access control records based on a multi-dimensional analysis strategy to obtain a draft audit report for the target file, the abnormal characteristics and lock execution status of the access control records are analyzed item by item according to the requirements of the multi-dimensional analysis strategy. The severity of the abnormality is determined by combining the root cause inference results to determine whether it violates relevant regulations, the relevant responsible parties are identified, and targeted rectification suggestions and preventive measures are proposed. These analysis results are organized according to the standard format of the audit report to form a draft audit report for the target file.
[0134] When obtaining the audit report for the target file by performing evidence chain closure verification on the draft audit report and the audit evidence set, check whether each conclusion analysis and recommendation in the draft audit report is supported by corresponding evidence in the audit evidence set, verify whether the logical connection between the evidence and the conclusion is rigorous, and ensure that there is no missing evidence or logical loopholes. If it is found that there is content in the draft that lacks evidence support, return to supplement the analysis and improve the evidence until all conclusions can be fully verified through the evidence chain, forming a logically complete and conclusive audit report for the target file.
[0135] The beneficial effects of this implementation process are that it ensures the accuracy of target file status judgment through a multi-level and multi-dimensional verification mechanism, accurately identifies whether files have been tampered with, and achieves differentiated automated responses based on verification results. Access log archiving ensures the traceability of file access, and precise permission locking and complete audit trails quickly curb abnormal risks and clarify root cause responsibilities, forming a closed-loop management of "verification-response-audit", which significantly improves the security, reliability and management efficiency of administrative file anti-tampering storage.
[0136] S4. When the target file is detected to be accessed, the real-time feature summary of the target file is verified with the evidence storage chain record at multiple levels to obtain the status verification result of the target file.
[0137] In this embodiment of the invention, the step of performing multi-level verification between the real-time feature summary of the target file and the evidence storage chain record to obtain the status verification result of the target file includes:
[0138] Multidimensional feature deconstruction is performed on the evidence storage chain records to obtain the historical feature summary and node comprehensive credibility of the evidence storage chain records;
[0139] The similarity between the historical feature summary and the real-time feature summary of the target file is evaluated to obtain the similarity index of the target file;
[0140] The difference between the historical feature summary and the real-time feature summary is quantified to obtain the difference fluctuation of the target file;
[0141] A consistency assessment is performed on the similarity index and the difference fluctuation to obtain the consistency confidence level of the target file;
[0142] Based on the node's overall credibility, the similarity index, the difference fluctuation, and the consistency confidence, the instant feature summary and the evidence storage chain record are comprehensively evaluated to obtain the status verification result of the target file.
[0143] The formula for calculating the status verification result is as follows:
[0144] ;
[0145] in, This indicates the result of the status verification. This represents the preset weighting coefficient. Indicates the first The consistency confidence level of each dimension Indicates the first The similarity metrics of the dimensions, Indicates the first The difference in fluctuation across each dimension This indicates the overall credibility of the node. This indicates the preset positive control parameter. Represents the arctangent function. Represents an exponential function. This represents the natural logarithm function.
[0146] When performing multi-dimensional feature deconstruction on the evidence storage chain records, core data such as hash value block description information and consensus timestamps contained in the evidence storage chain records are comprehensively extracted. Key information directly related to the original features of the target archive is screened out, including feature records corresponding to the hash identifier structure description associated with the archive content features. This information is integrated and sorted according to the original feature dimensions of the archive to form a historical feature summary that can completely reflect the historical storage status of the archive. At the same time, historical verification performance data of all participating nodes in the evidence storage consortium chain are collected, covering the accuracy of past verification results of nodes, the stability of data transmission process, the integrity of data storage, and the existence of abnormal operation records. This data is comprehensively summarized and analyzed to assess the reliability of each node, and finally integrated to form the overall trustworthiness of the nodes.
[0147] When evaluating the similarity between historical feature summaries and real-time feature summaries of target files, the common feature dimensions of the two types of summaries are first identified. Each feature dimension corresponds to a fixed core attribute of the file, including key information fragments corresponding to content features and logical associations corresponding to structural features. The specific content of the historical feature summaries and real-time feature summaries on the same feature dimension is compared one by one. The number of dimensions with completely identical content among all feature dimensions is counted, and the proportion of the number of identical dimensions to the total number of feature dimensions is calculated. This proportion is the similarity index of the target file.
[0148] When quantifying the differences between historical and real-time feature summaries, the content differences between the two types of summaries are examined one by one across each feature dimension. The specific manifestations of the differences in each dimension are recorded in detail, including the addition or replacement of feature content or missing feature information. Based on the degree of impact of different feature dimensions on the overall integrity and authenticity of the archives, a fixed weight is assigned to each discovered difference. The weight values corresponding to all differences are accumulated to obtain the difference fluctuation that can comprehensively reflect the overall degree of difference between the two types of summaries.
[0149] When assessing the consistency of similarity indicators and difference fluctuations, a unified consistency judgment standard is pre-set. This standard clearly defines the reasonable range of difference fluctuations corresponding to different numerical ranges of similarity indicators. The currently obtained similarity indicators and difference fluctuations are substituted into this judgment standard for comparison. If the difference fluctuations are within the reasonable range corresponding to the similarity indicators, the two types of summaries are judged to be consistent in feature performance. The specific value is determined as the consistency confidence of the target file based on the actual degree of matching. If the difference fluctuations exceed the reasonable range, a lower consistency confidence is directly assigned.
[0150] When comprehensively evaluating instant feature summaries and evidence chain records based on the fluctuation of differences in node comprehensive credibility similarity indicators and consistency confidence, these four indicators are used as core evaluation dimensions. According to the importance of each indicator to the judgment of the archive status, a preset fixed weight is assigned to each dimension. The original values of each indicator are standardized to eliminate the differences in dimensions between different indicators. Then, the standardized indicator values are multiplied by their corresponding weights, and all product results are summed to obtain a comprehensive evaluation score. This score is compared with a preset pass threshold. If the comprehensive evaluation score is higher than or equal to the pass threshold, the status verification result is passed; if the comprehensive evaluation score is lower than the pass threshold, the status verification result is failed. Finally, the status verification result of the target archive is obtained.
[0151] The preset weighting coefficients are fixed values set in advance to balance the influence of different dimensions in the comprehensive evaluation. The consistency confidence comes from the consistency assessment of the similarity index and the difference fluctuation. The assessment process involves first obtaining the similarity index and the difference fluctuation separately, and then analyzing the degree of fit between the two to obtain the result. The similarity index is obtained by assessing the similarity between the historical feature summary of the evidence storage chain record and the real-time feature summary of the target file. The degree of fit is calculated by comparing the feature overlap of the two in the corresponding dimensions. The difference fluctuation is obtained by quantifying the difference between the historical feature summary and the real-time feature summary. The quantification process involves comparing the feature differences of the two in each dimension one by one, converting the differences into calculable values and statistically analyzing the fluctuation range. The node comprehensive credibility comes from the multi-dimensional feature deconstruction of the evidence storage chain record. The deconstruction process involves breaking down the feature information in the evidence storage chain record and combining the node's historical operating status and data processing accuracy to obtain the credibility value. The preset positive value adjustment parameter is a fixed positive value set in advance to adjust the influence intensity of the related calculation part of the difference fluctuation.
[0152] The formula aims to synthesize multiple relevant evaluation results to calculate the status verification result of the target file, thereby determining whether the current status of the target file when accessed is consistent with the historical status in the evidence storage chain. The calculation process involves first multiplying the consistency confidence score of each dimension by a preset weighting coefficient, then calculating the arctangent function's processing result for the similarity index of that dimension, simultaneously subtracting one from the result of the exponential function's processing result for the difference fluctuation of that dimension, dividing by one plus the square of the difference fluctuation of that dimension, multiplying the result by a preset positive control parameter, subtracting this product from the result processed by the arctangent function, multiplying the previously obtained product by this difference, summing the calculation results for all dimensions, then calculating the natural logarithm function's processing result for one plus the node's comprehensive confidence score, adding the summation result to the natural logarithm function's processing result, and finally calculating the square root of one plus the sum of the squares of the difference fluctuations of all dimensions. Dividing the previous sum by this square root yields the status verification result, which directly reflects the consistency between the current status of the target file and its historical evidence storage status.
[0153] When the consistency confidence increases, the corresponding calculation result increases, thus increasing the final state verification result. When the similarity index increases, the result processed by the arctangent function increases, leading to an increase in the value of the relevant calculation part, ultimately increasing the state verification result. When the difference fluctuation increases, the ratio of the result processed by the exponential function minus one to the value of one plus its square increases, causing the value of the relevant calculation part to decrease, ultimately decreasing the state verification result. When the node comprehensive confidence increases, the result of the natural logarithm function processing one plus that confidence increases, thus increasing the final state verification result. When the preset weight coefficient increases, the proportion of the calculation result of the corresponding dimension in the sum increases. If the relevant evaluation result of that dimension is positive, it will increase the final state verification result. When the preset positive value adjustment parameter increases, the influence of the difference fluctuation related calculation part will be enhanced. If the difference fluctuation is positive, it will cause the value of the relevant calculation part to decrease more significantly, thus decreasing the final state verification result.
[0154] The beneficial effects are that the implementation process comprehensively extracts key information through multi-dimensional feature deconstruction, and constructs a multi-level verification mechanism by using multi-dimensional similarity assessment, difference quantification, consistency assessment and comprehensive weighted analysis. This ensures the comprehensiveness and accuracy of the status verification results, and can accurately identify whether the target file has been tampered with. It provides a reliable basis for subsequent automated response based on the verification results, and effectively improves the accuracy and effectiveness of administrative file anti-tampering verification.
[0155] S5. Based on the status verification result, automatically respond to the target file:
[0156] S51. When the status verification result passes, the access log of the target file is archived into the evidence storage chain record;
[0157] S52. When the status verification result fails, the access permissions of the target file are locked, the access permission lock record of the target file is obtained, and the access permission lock record is audited and traced to generate an audit report of the target file.
[0158] In this embodiment of the invention, the step of locking the access permissions of the target file and obtaining the access lock record of the target file when the status verification result fails includes:
[0159] Anomaly pattern matching is performed on the status verification results to obtain anomaly feature descriptions of the target file;
[0160] The abnormal feature description and the encryption level of the target file are encoded into instructions to obtain the initial locking operation instruction for the target file;
[0161] Obtain the real-time access context, active session identifier, and concurrent operation request list of the target file to obtain a context snapshot of the target file;
[0162] The initial locking operation command and the context snapshot are analyzed in real time, and the scope and timing of the initial locking operation command are optimized and adjusted based on the analysis results to obtain the final locking command for the target file.
[0163] The final locking command is applied to precisely control access permissions to the target file and to record the execution feedback of the target file.
[0164] The anomaly description, the context snapshot, the final lock instruction, and the execution feedback are encapsulated into a permission lock record for the target file.
[0165] The audit tracing of the access lock records to generate an audit report for the target file includes:
[0166] By combining the permission lock records, the operation trajectory of the final lock command in the target file, and the real-time status data of the target file, an audit evidence set for the target file is obtained;
[0167] A causal relationship analysis was performed on the audit evidence set to obtain the root cause inference results of the audit evidence set;
[0168] Based on the root cause inference results, the administrative management attributes and general security principles of the target file are mapped to obtain a multi-dimensional judgment strategy for the target file.
[0169] Based on the aforementioned multi-dimensional analysis strategy, the access control records are analyzed in a targeted manner to obtain a draft audit report for the target file.
[0170] The audit report for the target file is obtained by performing a chain-of-evidence closure verification on the draft audit report and the audit evidence set.
[0171] When the status verification result passes, all key access information during the access process of the target file is collected in a comprehensive manner, including the visitor's identity authentication information, the specific time of the access, the unique identifier of the device used for the access, the specific type of access operation, and the specific scope of the files involved in the access operation. This collected access information is organized and arranged in a preset unified format, the order of information arrangement and expression standards are clarified, redundant and invalid record content is removed, and a complete and standardized access log is formed.
[0172] The system queries the storage path of the data block corresponding to the target file in the evidence storage chain record to determine the exclusive archiving location of the access log. This location is directly associated with the corresponding data block to ensure traceability consistency. Through the distributed data writing mechanism of the blockchain, the organized access log is transmitted to the designated archiving location in the evidence storage chain record to complete the permanent storage of the access log. This enables the synchronous association and archiving of the access log with the evidence storage information of the target file, ensuring that the access trajectory can be traced throughout the entire process.
[0173] When performing anomaly pattern matching on the status verification results, a preset anomaly pattern library is invoked. This library stores various common anomaly types and corresponding characteristics of administrative archives, covering specific characteristics of scenarios such as data tampering, unauthorized access, data transmission anomalies, and damage to storage integrity. The anomaly information presented in the status verification results is compared one by one with each anomaly pattern in the pattern library to accurately locate the perfectly matching anomaly pattern. Based on the definition of the anomaly pattern, the specific type of anomaly, the archive feature dimensions involved, and the possible scope of impact are described in detail to obtain the anomaly feature description of the target archive.
[0174] When encoding instructions for anomaly descriptions and the encryption level of target files, the security control requirements corresponding to the encryption level of the target files are clearly defined. Different encryption levels correspond to different access restriction standards. The anomaly descriptions are transformed into standardized anomaly codes that the system can directly recognize. These codes can accurately represent the core attributes and key information of the anomaly. Combined with the access control rules corresponding to the encryption level, and in accordance with the preset instruction encoding specifications, the standardized anomaly codes and access control rules are integrated and matched to transform them into an instruction sequence with clear execution logic and operation direction. This instruction sequence is the initial locking operation instruction for the target file.
[0175] When obtaining the real-time access context active session identifier and concurrent operation request list of the target file to obtain a context snapshot, the system captures relevant information about the current access environment of the target file in real time, including network environment parameters that the access depends on, system configuration information of the access terminal, and transmission status of the access link to form a real-time access context. It extracts the unique identifiers of all sessions that are currently establishing a connection with the target file and performing access operations to form an active session identifier. It collects all operation requests initiated for the target file within the same time interval, organizes and sorts them according to the order in which the requests were initiated to form a concurrent operation request list. It integrates the three types of information—real-time access context active session identifier and concurrent operation request list—to obtain a context snapshot of the target file.
[0176] When performing real-time linkage analysis between the initial locking operation command and the context snapshot, and optimizing and adjusting the initial locking operation command based on the analysis results to obtain the final locking command, the correlation and matching between the locking scope set by the initial locking operation command and the list of concurrent operation requests of active sessions in the context snapshot is analyzed in depth to determine whether the initial locking operation command will cause unnecessary impact on legitimate access sessions and normal operation requests. If there is an impact, the locking scope is narrowed in a targeted manner, locking only sessions and requests directly related to the anomaly. At the same time, the timing of the command's activation is determined by combining the environmental state of the real-time access context and the system operation status to ensure that the command takes effect immediately without interfering with the normal operation of the system and legitimate access. After precise optimization and adjustment of the effective scope and activation timing, the final locking command for the target file is obtained.
[0177] When applying the final lock command to precisely control access permissions to the target file and record execution feedback, strictly follow the requirements of the final lock command to terminate permissions for access sessions related to anomalies, prohibiting these sessions from performing any form of operation on the target file, such as reading, modifying, downloading, copying, or transmitting. At the same time, reject abnormal operation requests in the concurrent operation request list, allow legitimate requests that meet the permission requirements to be executed normally, monitor the entire execution process of the final lock command in real time, and record key information such as whether the command was successfully effective, the number of terminated abnormal sessions, the number of intercepted abnormal requests, and the accuracy of permission control, forming execution feedback for the target file.
[0178] When encapsulating the anomaly description, context snapshot, final lock command, and execution feedback into the target file's access control record, the four types of information are arranged in a fixed order: "anomaly description - context snapshot - final lock command - execution feedback". The arranged information is then formatted to remove redundant invalid characters, extra format content, and duplicate information, so that all types of information form a unified data set with a well-structured, logically clear, complete, and non-redundant structure. This data set is the access control record of the target file.
[0179] When compiling the operation trajectory of the final lock command from the permission lock record and the real-time status data of the target file to obtain the audit evidence set of the target file, a complete detailed record of the entire process of the final lock command from generation to optimization and adjustment to execution is extracted. This includes information such as the specific direction of the initial content adjustment, the judgment conditions on which the adjustment is based, and the specific steps of execution, forming the operation trajectory of the final lock command. Data such as the current data integrity status, storage location information, access control status, and data content changes of the target file after permission lock are collected as real-time status data. The operation trajectory of the final lock command from the permission lock record and the real-time status data are comprehensively collected to ensure that no key evidence related to abnormal events is missed, thus forming the audit evidence set of the target file.
[0180] When conducting causal correlation analysis on the audit evidence set to obtain the root cause inference results, the inherent logical relationships and temporal sequence among various types of information in the audit evidence set are systematically reviewed. The abnormal characteristics described in the access control record are taken as the core starting point for analysis. Combined with the reasons for instruction adjustment recorded in the operation trajectory of the final lock instruction and the abnormal file performance presented in the real-time status data, the timeline and logical chain of the abnormal event are traced layer by layer to clarify the root cause of the status verification failure. It is determined whether the abnormality is caused by external illegal tampering, internal personnel operation errors, or system malfunctions, etc. The specific links, core inducing factors, and propagation paths of the abnormality are identified to obtain the root cause inference results of the audit evidence set.
[0181] When mapping the administrative attributes of target archives to general security principles based on root cause inference results to obtain a multi-dimensional assessment strategy for target archives, the administrative attributes of target archives are fully clarified, including key information such as the confidentiality level of the archives, the management responsibility entity, the scope of use allowed, and archiving requirements. General security principles for administrative archive management formulated at the national level and within the industry are retrieved. Based on the root cause inference results, the core directions and key dimensions that need to be focused on assessment are determined. The specific management requirements corresponding to the administrative attributes of target archives are accurately matched with the relevant protection standards and compliance requirements in the general security principles. A multi-dimensional assessment strategy is formulated, covering multiple dimensions such as accurate determination of abnormal nature, division of responsibilities, rectification measures, establishment of prevention mechanisms, and improvement of compliance assessment.
[0182] When conducting targeted analysis of access control records based on a multi-dimensional analysis strategy to obtain the draft audit report for the target file, the requirements and standards of the multi-dimensional analysis strategy are strictly followed. A thorough analysis is conducted on each core element of the access control records, including descriptions of abnormal characteristics, execution of lock commands, and execution feedback. Combined with root cause inference results, the severity and scope of the anomaly are accurately determined to determine whether it violates relevant administrative regulations and safety guidelines. The responsible parties and standards for assigning responsibility related to the anomaly are clearly identified. Targeted and actionable rectification suggestions and long-term preventative measures are proposed based on the root causes and actual circumstances of the anomaly. All analysis results, judgments, conclusions, responsibility determinations, and recommendations are systematically organized and presented in a standardized format according to the standard structure of an audit report, resulting in the draft audit report for the target file.
[0183] When obtaining the audit report for the target file by performing a closed-loop verification of the audit report draft and the audit evidence set, each analytical conclusion, judgment result, responsibility division, and rectification suggestion in the audit report draft is checked one by one. It is confirmed that each item is directly supported by corresponding evidence in the audit evidence set. The logical connection between the evidence and the conclusion is verified to be rigorous and unassailable. It is ensured that there are no isolated evidences lacking supporting evidence, logical connections, or logical contradictions. If it is found that the audit report draft has insufficient evidence support, is not logically rigorous, or has missing content, it is returned to the targeted analysis stage to supplement and improve the relevant analysis content and supplement the corresponding evidence materials until all the contents of the audit report draft can be supported by a complete and rigorous closed-loop evidence chain through the audit evidence set. Finally, an audit report for the target file with logical integrity, conclusive evidence, and standardized content is formed.
[0184] The beneficial effects of this implementation process are that it enables rapid anomaly identification through precise matching of abnormal patterns, builds an efficient risk containment mechanism by dynamically optimizing locking instructions and precisely controlling permissions, and ensures that the spread of risks can be stopped in time when anomalies occur. At the same time, through comprehensive collection of audit evidence, in-depth causal analysis, multi-dimensional strategy judgment, and evidence chain closure verification, it achieves accurate positioning of the root cause of anomalies and rigorous generation of audit reports, forming a complete management link of "anomaly locking - evidence collection - root cause tracing - responsibility determination - rectification closure". This significantly improves the emergency response speed, risk control accuracy, and compliance management level of the anti-tampering storage of administrative archives, and provides full-process protection for the secure storage and standardized management of administrative archives.
[0185] like Figure 2 The diagram shown is a functional block diagram of an administrative archive anti-tampering storage system provided in an embodiment of the present invention.
[0186] The administrative file anti-tampering storage system 100 described in this invention can be installed in an electronic device. Depending on the functions implemented, the administrative file anti-tampering storage system 100 may include a digital fingerprint generation module 101, a feature binding module 102, a data storage module 103, a feature verification module 104, and an automated response module 105. The modules described in this invention can also be referred to as units, which are a series of computer program segments that can be executed by the processor of an electronic device and perform a fixed function, and are stored in the memory of the electronic device.
[0187] In this embodiment, the functions of each module / unit are as follows:
[0188] The digital fingerprint generation module 101 is used to associate and couple the content feature set and structural description information of the target file to obtain the digital fingerprint of the target file.
[0189] The feature binding module 102 is used to bind the unique identifier of the target file to the digital fingerprint to obtain the feature binding record of the target file;
[0190] The data storage module 103 is used to encode the metadata of the target file and the feature binding record in blocks to obtain the data block of the target file, and store the data block on the blockchain based on the blockchain consensus mechanism of the target file to obtain the storage chain record of the target file.
[0191] The feature verification module 104 is used to perform multi-level verification between the real-time feature summary of the target file and the evidence storage chain record when the target file is detected to be accessed, so as to obtain the status verification result of the target file.
[0192] The automated response module 105 is used to automatically respond to the target file based on the status verification result. When the status verification result passes, the access log of the target file is archived to the evidence storage chain record. When the status verification result fails, the access permissions of the target file are locked to obtain the access lock record of the target file, and the access lock record is audited to generate an audit report of the target file.
[0193] In the several embodiments provided by this invention, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.
[0194] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0195] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.
[0196] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0197] This application embodiment can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0198] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A method for tamper-proof storage of administrative archives, characterized in that, The method includes: S1. Correlate and couple the content feature set and structural description information of the target file to obtain the digital fingerprint of the target file; S2. Bind the unique identifier of the target file to the digital fingerprint to obtain the feature binding record of the target file; S3. The metadata of the target file and the feature binding record are divided into blocks and encoded to obtain the data block of the target file. Based on the blockchain consensus mechanism of the target file, the data block is stored on the chain to obtain the evidence storage chain record of the target file. S4. When access to the target file is detected, the real-time feature summary of the target file is compared with the evidence storage chain record through multi-level verification to obtain the status verification result of the target file, including: Multidimensional feature deconstruction is performed on the evidence storage chain records to obtain the historical feature summary and node comprehensive credibility of the evidence storage chain records; The similarity between the historical feature summary and the real-time feature summary of the target file is evaluated to obtain the similarity index of the target file; The difference between the historical feature summary and the real-time feature summary is quantified to obtain the difference fluctuation of the target file; A consistency assessment is performed on the similarity index and the difference fluctuation to obtain the consistency confidence level of the target file; Based on the node's overall credibility, the similarity index, the difference fluctuation, and the consistency confidence, the instant feature summary and the evidence storage chain record are comprehensively evaluated to obtain the status verification result of the target file. The calculation formula for the status verification result is as follows: ; in, This indicates the result of the status verification. This represents the preset weighting coefficient. Indicates the first The consistency confidence level of each dimension. Indicates the first The similarity metrics of the dimensions, Indicates the first The difference in the dimensional fluctuations. This indicates the overall credibility of the node. This indicates the preset positive control parameter. Represents the arctangent function. Represents an exponential function. Represent the natural logarithm function; S5. Based on the status verification result, automatically respond to the target file: S51. When the status verification result passes, the access log of the target file is archived into the evidence storage chain record; S52. When the status verification result fails, the access permissions of the target file are locked, the access permission lock record of the target file is obtained, and the access permission lock record is audited and traced to generate an audit report of the target file.
2. The method for preventing tampering with administrative archives as described in claim 1, characterized in that, The process of associating and coupling the content feature set and structural description information of the target file to obtain the digital fingerprint of the target file includes: Collect the raw data of the target file; The original data is subjected to structured parsing to obtain the content feature set and structural description information of the target file; Tensor synthesis is performed on the content features in the content feature set to obtain the content feature vector of the target file; Based on the relationships between data texts in the target file, the structural description information is topologically constructed to obtain a structural relationship map of the target file; The content feature vectors are mapped to the structural relationship graph, and the mapped graph is dimensionality reduced to obtain the fusion features of the target file. Based on the timestamp of the target file, the fusion feature is associated and encoded to obtain the digital fingerprint of the target file.
3. The method for preventing tampering with administrative archives as described in claim 1, characterized in that, The step of binding the unique identifier of the target file to the digital fingerprint to obtain the feature binding record of the target file includes: The entity attributes of the target file are formatted to obtain the standard identifier of the target file; By concatenating the standard identifiers in chronological order, a unique identifier for the target file is obtained. The unique identifier is verified to obtain the verified identifier of the target file; Based on the private key of the target file, the digital fingerprint is digitally signed to obtain the signed fingerprint of the target file; By fusing the verified identifier, the signature fingerprint, and the timestamp of the target file, a structured data object of the target file is obtained; The structured data object is jointly encapsulated to obtain the feature binding record of the target file.
4. The method for preventing tampering with administrative archives as described in claim 1, characterized in that, The step of dividing and encoding the metadata and feature binding records of the target file into blocks to obtain data blocks of the target file includes: The administrative management data of the original data in the target file is used as the metadata of the target file; Semantic parsing of the metadata yields a structured metadata dataset of the target file; The feature binding record is serialized to obtain the feature byte sequence of the target file; The structured metadata dataset and the feature byte sequence are heterogeneously associated to obtain the structural description information of the target file; Based on the data volume of the structured metadata dataset and the byte length of the feature byte sequence, erasure coding is performed on the structure description information to obtain the data block of the target file.
5. The method for preventing tampering with administrative archives as described in claim 1, characterized in that, The blockchain consensus mechanism based on the target file stores the data blocks on the chain to obtain the evidence storage chain record of the target file, including: Based on the information of the custodian institution of the target file, determine the evidence storage alliance chain of the target file; The data block is distributed to the verification area on the evidence storage consortium chain, and the verification area is hash-verified to obtain the local verification result of the target file; Based on the blockchain consensus mechanism of the target file, the verification area is assigned a corresponding decision weight to obtain the weighted verification area of the target file; Based on the local verification results, multiple rounds of collaborative decision-making are performed on the weighted verification region to obtain the decision results for the target file; Based on the decision result, the hash value, block description information and consensus timestamp in the data block are packaged and jointly stored in the storage node of the storage alliance chain to obtain the storage chain record of the target file.
6. The method for preventing tampering with administrative archives as described in claim 1, characterized in that, When the status verification result fails, the access permissions of the target file are locked, and the access lock record of the target file is obtained, including: Anomaly pattern matching is performed on the status verification results to obtain anomaly feature descriptions of the target file; The abnormal feature description and the encryption level of the target file are encoded into instructions to obtain the initial locking operation instruction for the target file; Obtain the real-time access context, active session identifier, and concurrent operation request list of the target file to obtain a context snapshot of the target file; The initial locking operation command and the context snapshot are analyzed in real time, and the scope and timing of the initial locking operation command are optimized and adjusted based on the analysis results to obtain the final locking command for the target file. The final locking command is applied to precisely control access permissions to the target file and to record the execution feedback of the target file. The anomaly description, the context snapshot, the final lock instruction, and the execution feedback are encapsulated into a permission lock record for the target file.
7. The method for preventing tampering with administrative archives as described in claim 1, characterized in that, The audit trail of the access lock records to generate an audit report for the target file includes: By combining the permission lock records, the operation trajectory of the final lock command in the target file, and the real-time status data of the target file, an audit evidence set for the target file is obtained; A causal relationship analysis was performed on the audit evidence set to obtain the root cause inference results of the audit evidence set; Based on the root cause inference results, the administrative management attributes and general security principles of the target file are mapped to obtain a multi-dimensional assessment strategy for the target file. Based on the aforementioned multi-dimensional analysis strategy, the access control records are analyzed in a targeted manner to obtain a draft audit report for the target file. The audit report for the target file is obtained by performing a chain-of-evidence closure verification on the draft audit report and the audit evidence set.
8. An administrative archive anti-tampering storage system, characterized in that, The system for implementing the tamper-proof storage method for administrative archives as described in claim 1 includes: The digital fingerprint generation module is used to correlate and couple the content feature set and structural description information of the target file to obtain the digital fingerprint of the target file. The feature binding module is used to bind the unique identifier of the target file to the digital fingerprint to obtain the feature binding record of the target file; The data storage module is used to encode the metadata of the target file and the feature binding record in blocks to obtain the data block of the target file, and store the data block on the blockchain based on the blockchain consensus mechanism of the target file to obtain the storage chain record of the target file. The feature verification module is used to perform multi-level verification between the real-time feature summary of the target file and the evidence storage chain record when access to the target file is detected, to obtain the status verification result of the target file, including: Multidimensional feature deconstruction is performed on the evidence storage chain records to obtain the historical feature summary and node comprehensive credibility of the evidence storage chain records; The similarity between the historical feature summary and the real-time feature summary of the target file is evaluated to obtain the similarity index of the target file; The difference between the historical feature summary and the real-time feature summary is quantified to obtain the difference fluctuation of the target file; A consistency assessment is performed on the similarity index and the difference fluctuation to obtain the consistency confidence level of the target file; Based on the node's overall credibility, the similarity index, the difference fluctuation, and the consistency confidence, the instant feature summary and the evidence storage chain record are comprehensively evaluated to obtain the status verification result of the target file. The calculation formula for the status verification result is as follows: ; in, This indicates the result of the status verification. This represents the preset weighting coefficient. Indicates the first The consistency confidence level of each dimension Indicates the first The similarity metrics of the dimensions, Indicates the first The difference in fluctuation across each dimension This indicates the overall credibility of the node. This indicates the preset positive control parameter. Represents the arctangent function. Represents an exponential function. Represent the natural logarithm function; An automated response module is used to automatically respond to the target file based on the status verification result. When the status verification result passes, the access log of the target file is archived to the evidence storage chain record. When the status verification result fails, the access permissions of the target file are locked to obtain the access lock record of the target file, and the access lock record is audited to generate an audit report of the target file.
Citation Information
Patent Citations
Digital archive security management method and system
CN118013493A
Electronic archive data tracking and multi-party cooperative auditing method based on block chain smart contract
CN120067213A