Data storage and auditing method, electronic equipment, storage medium and product

By employing time-layered storage and parallel auditing, the problem of low data storage and auditing efficiency under the Merkle tree architecture is solved, achieving efficient and secure data auditing, which is suitable for data storage and auditing in the fintech field.

CN121807837APending Publication Date: 2026-04-07INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-06
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Traditional Merkle tree architectures suffer from low data storage and audit verification efficiency. As the amount of data increases, the verification path length also increases, failing to meet the high-efficiency auditing requirements of large-scale data. Furthermore, the cost of dynamically updating historical data under long-term storage is high, and it faces the threat of quantum computing while lacking the credibility of centralized services.

Method used

Data is stored in time-layered manner, time locks are generated, and parallel audit tasks of one or more time layers are constructed according to audit requests. The validity of data is verified through time locks, and security is enhanced by prime field mapping and post-quantum signature algorithms, supporting offline verification.

Benefits of technology

It improves data auditing efficiency, reduces complexity, achieves long-term security and independent verification, meets the real-time auditing needs of large-scale data, reduces storage costs, and resists quantum computing attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121807837A_ABST
    Figure CN121807837A_ABST
Patent Text Reader

Abstract

The invention discloses a data storage and auditing method, electronic equipment, a storage medium and a product, relates to the technical field of data processing, and can be applied to the field of financial science and technology. The method comprises the following steps: dividing to-be-stored data into a plurality of time layers, and generating a corresponding time lock for each time layer; constructing a to-be-executed audit task of a to-be-audited time layer according to the audit request, wherein the to-be-executed audit task comprises a data item audit task of a single to-be-audited time layer or a time layer audit task executed by a plurality of to-be-audited time layers in parallel; and based on the to-be-executed auditing task, verifying the validity of the time lock of the to-be-audited time layer, and determining a target auditing result. According to the scheme, the complexity of data auditing is optimized from being related to the total data volume to being related to the single-time-layer data volume, the auditing verification efficiency is improved, and the efficient auditing requirement of large-scale data can be met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of data processing technology and can be applied to the field of financial technology, particularly to a data storage and auditing method, electronic device, storage medium and product. Background Technology

[0002] Currently, the common approach for storing and auditing large-scale data is a combination of Merkle trees and digital timestamps. However, auditing under the traditional Merkle tree architecture requires verification to be performed on the entire tree, and the verification path length is proportional to the logarithm of the total data volume. As the amount of data accumulates over a long period, the verification path length increases significantly, resulting in a continuous decrease in auditing efficiency. Summary of the Invention

[0003] This invention provides a data storage and auditing method, electronic device, storage medium, and product that can improve audit verification efficiency and meet the needs of efficient auditing of large-scale data.

[0004] In a first aspect, embodiments of the present invention provide a data storage and auditing method, including:

[0005] The data to be stored is divided into multiple time layers, and a corresponding time lock is generated for each time layer;

[0006] Based on the audit request, an audit task to be executed for the time layer to be audited is constructed. The audit task to be executed includes a single data item audit task for the time layer to be audited, or multiple time layer audit tasks to be audited in parallel.

[0007] Based on the audit task to be executed, verify the validity of the time lock of the time layer to be audited, and determine the target audit result.

[0008] Secondly, embodiments of the present invention provide a data storage and auditing apparatus, comprising:

[0009] The data partitioning module is used to divide the data to be stored into multiple time layers and generate a corresponding time lock for each time layer;

[0010] The task construction module is used to construct audit tasks to be executed for the audit time layer according to the audit request. The audit tasks to be executed include a single data item audit task for the audit time layer, or multiple time layer audit tasks to be executed in parallel for the audit time layer.

[0011] The audit verification module is used to verify the validity of the time lock of the time layer to be audited based on the audit task to be executed, and to determine the target audit result.

[0012] Thirdly, embodiments of the present invention provide an electronic device, including:

[0013] At least one processor; and

[0014] A memory communicatively connected to the at least one processor; wherein,

[0015] The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the method as described in the first aspect.

[0016] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing computer instructions that cause a processor to execute the method described in the first aspect.

[0017] Fifthly, embodiments of the present invention provide a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the method described in the first aspect.

[0018] The technical solution of this invention divides the data to be stored into multiple time layers and generates a corresponding time lock for each time layer. Based on the audit request, it constructs audit tasks to be executed for each time layer, including audit tasks for a single data item in that time layer or audit tasks for multiple time layers executed in parallel. Based on the audit tasks to be executed, it verifies the validity of the time locks for each time layer and determines the target audit result. This solution stores data in time layers during the data storage phase, providing an efficient data query foundation for the subsequent data audit phase. During the data audit phase, auditing of data items is located within the individual time layer to which the data item belongs, while auditing of data in multiple time layers is executed independently and in parallel by each time layer. This optimizes the complexity of data auditing from being related to the total amount of data to being related to the amount of data in a single time layer, improving audit verification efficiency and meeting the high-efficiency auditing needs of large-scale data.

[0019] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is a flowchart of a data storage and auditing method provided in Embodiment 1 of the present invention;

[0022] Figure 2 This is a flowchart of a data storage and auditing method provided in Embodiment 2 of the present invention;

[0023] Figure 3 This is a schematic diagram of the structure of a data storage and auditing device according to Embodiment 3 of the present invention;

[0024] Figure 4 This is a schematic diagram of the structure of an electronic device that implements an embodiment of the present invention. Detailed Implementation

[0025] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0026] It should be noted that the terms "first," "second," etc., used in this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0027] Currently, a combination of Merkle trees and digital timestamps is commonly used to ensure the reliability of historical data. However, with data accumulating at a rate of 20%-40% per year, traditional solutions face serious challenges in long-term storage and auditing scenarios.

[0028] Audit verification efficiency is positively correlated with data volume, making it unsuitable for real-time requirements. The verification path length of traditional Merkle trees is... Total data volume It is proportional to the logarithm, that is Assume a bank's average annual transaction volume is... Item, storage period In that year, the total data volume would be If an audit of a single transaction record for a specific year is required, verification must be performed on the entire tree, including the path length. Approximately 30 steps; if you need to calculate a specific year's... A comprehensive review of all transaction records was conducted, with theoretical verification time. Will reach , For single hash computation time (e.g.) The total time taken exceeded one hour, which was insufficient to meet the needs of efficient auditing of large-scale data.

[0029] Dynamic updates to historical data trigger global reconstruction, resulting in high operational costs. Business operations may require error correction or supplementation of historical records. In a traditional static tree, modifying any historical leaf node necessitates reconstructing the entire path from that node to the root node and updating all associated timestamp signatures. For The time complexity of a single update for the year's data is O(n). Furthermore, it will trigger a chain of re-signing operations, a complex process that can easily become a system bottleneck.

[0030] Long-term encryption security faces threats from quantum computing. For financial data that needs to be stored for decades, encryption systems must be designed to withstand future quantum computer attacks, a capability that traditional solutions lack.

[0031] Verifying the state at a specific point in time involves complex paths and relies on centralized services. Verifying the state of a data snapshot on a specific day, month, and year requires the Merkel root at that moment and its associated centralized timestamp agency signature. This process not only involves a long verification path but also places long-term reliability on the continuous availability of a single centralized timestamp agency service, creating a single point of failure and trust risks.

[0032] Therefore, a novel data integrity storage and verification architecture is needed that is optimized for the time dimension, supports efficient local verification and updates, and possesses long-term quantum security characteristics.

[0033] Example 1

[0034] Figure 1 This is a flowchart of a data storage and auditing method according to Embodiment 1 of the present invention. This embodiment is applicable to situations involving data storage and auditing. The method can be executed by a data storage and auditing device, which can be implemented in software and / or hardware and integrated into an electronic device. Furthermore, the electronic device includes, but is not limited to, computers, laptops, etc.

[0035] like Figure 1 As shown, the method includes:

[0036] S110. Divide the data to be stored into multiple time layers and generate a corresponding time lock for each time layer.

[0037] The data to be stored can be financial data, etc., and there are no restrictions here. The data to be stored can be stored in the dataset in ascending order of timestamps, so as to build a time-indexed hierarchical model based on the data to be stored.

[0038] The construction process of the time-indexed hierarchical model is as follows: An equal-time-span hierarchical method is adopted, assuming the total time span of the data to be stored is... Divide it into There are 1 time layer, and the time span of each layer is 1. In practical applications, the time span of each layer can be aligned with the audit cycle, such as one year. layer( (Representing the most recent time layer) contains all timestamps that satisfy... The number of data entries in this layer is denoted as . .

[0039] A corresponding time lock is generated for each time layer. For each time layer, the following operations can be performed: Within that time layer, a time-layered dynamic hash chain (referred to as a dynamic hash chain) is constructed using a hash chain construction algorithm. This involves chaining all data within that time layer according to time or logic, enabling subsequent auditing of the data within that time layer based on this dynamic hash chain. The root hash value of the dynamic hash chain for that time layer is immutably bound to a trusted timestamp, generating a self-contained, cryptographically bound evidence tuple, i.e., a time lock. This lock can independently prove the complete state of the data in that time layer at a specific moment. The hash chain construction algorithm can be an algorithm for constructing a time-layered dynamic hash chain, the core of which lies in dividing data into layers according to time rules, and achieving data integrity verification and traceability within each layer through a dynamically growing hash chain.

[0040] S120. Construct audit tasks to be executed for the audited time layer according to the audit request. The audit tasks to be executed include a single data item audit task for the audited time layer, or multiple time layer audit tasks to be executed in parallel for the audited time layers.

[0041] An audit request can be a request for key information required for the audit, such as the audit target and audit time.

[0042] The auditable time layer can be the time layer to be audited, such as the time layer obtained by division. One or more time layers in a time layer, without limitation here.

[0043] Audit tasks to be performed can be generated based on audit requests and the time layer to be audited, specifying how to perform the audit.

[0044] In this step, when the audit request specifies the data item to be audited (i.e., the single data item to be audited) and the timestamp to be audited (i.e., the precise timestamp of the single data item to be audited), the time layer to be audited is the time layer to which the data item to be audited belongs, and its time layer index... , That is, the current timestamp. This refers to the timestamp to be audited. The audit tasks to be executed at the time layer to be audited are constructed; that is, a single data item audit task is constructed at the time layer to be audited. This data item audit task instructs the audit of the data item to be audited to be performed within the time layer to be audited.

[0045] In this step, if the audit request specifies the time range to be audited, such as by the audit start timestamp... and audit termination timestamp Time range of formation Determine the set of consecutive time layers covered within this time range. All time layers within this time layer set are considered as auditable time layers. Constructing the audit tasks to be executed for each auditable time layer in the aforementioned time layer set involves creating a time layer audit task for each auditable time layer. The number of time layer audit tasks is... Each time-layer audit task instructs the auditing of all data in the corresponding time layer, and multiple time-layer audit tasks are executed in parallel.

[0046] S130. Based on the audit task to be executed, verify the validity of the time lock of the time layer to be audited, and determine the target audit result.

[0047] When the audit tasks to be performed include auditing a single data item at a specific time layer, the data item audit task is executed. Specifically, the verification path required to verify the data item is extracted from the dynamic hash chain of the time layer to be audited. Based on this verification path and the data item to be audited, the root hash value is reconstructed. Then, the validity of the time lock of the time layer to be audited is verified based on the reconstructed root hash value to determine the target audit result for the data item. At this point, the target audit result indicates whether the audit of the data item has passed or failed. Passing the audit means that the data status is complete, authentic, and has not been tampered with.

[0048] When the audit tasks to be executed include multiple time-layer audit tasks, these tasks are executed in parallel. For each time-layer audit task, the root hash value is reconstructed based on all data in the corresponding time layer. Then, the validity of the time lock for the corresponding time layer is verified based on the reconstructed root hash value. The audit results of multiple time-layer audit tasks are then aggregated to obtain the target audit result. At this point, the target audit result indicates whether the audit of multiple time layers to be audited has passed or failed.

[0049] The technical solution of this invention divides the data to be stored into multiple time layers and generates a corresponding time lock for each time layer. Based on the audit request, it constructs audit tasks to be executed for each time layer, including audit tasks for a single data item in that time layer or audit tasks for multiple time layers executed in parallel. Based on the audit tasks to be executed, it verifies the validity of the time locks for each time layer and determines the target audit result. This solution stores data in time layers during the data storage phase, providing an efficient data query foundation for the subsequent data audit phase. During the data audit phase, auditing of data items is located within the individual time layer to which the data item belongs, while auditing of data in multiple time layers is executed independently and in parallel by each time layer. This optimizes the complexity of data auditing from being related to the total amount of data to being related to the amount of data in a single time layer, improving audit verification efficiency and meeting the high-efficiency auditing needs of large-scale data.

[0050] Example 2

[0051] Figure 2 This is a flowchart of a data storage and auditing method according to Embodiment 2 of the present invention. This embodiment is a further refinement based on Embodiment 1 described above, such as... Figure 2 As shown, the method includes:

[0052] S111. Divide the data to be stored into multiple time layers. For each time layer, construct a dynamic hash chain using a hash chain construction algorithm that includes prime number field mapping and hotspot identification optimization, and generate the layer root hash value.

[0053] For each time level, a dynamic hash chain is constructed using a hash chain building algorithm. When constructing the dynamic hash chain: for each time level... Choose independent, greater than large prime numbers The prime field hash map used for this time layer data This enhances the independence between different time layers. For recent time layers that require frequent auditing (such as the past 3 years), hotspot identification algorithms can be further applied to optimize the data within the layer and build a more efficient internal hash structure, such as placing frequently accessed data items closer to the root node. The dynamic hash chain construction process of each time layer can be executed in parallel.

[0054] For each time layer, a unique root hash value, i.e., the layer root hash value, is calculated using a hash chain construction algorithm for the dynamic hash chain of each layer. .

[0055] S112. Obtain a timestamp token based on the root hash value. The timestamp token is obtained by a trusted timestamp organization by concatenating the root hash value with the solidification time of the layer data and performing digital signature.

[0056] In the root hash value Once the calculation is complete, timestamp tokens can be requested in batches from a trusted timestamp authority. The trusted timestamp authority can be the root hash value. Inject precise layer data curing time , the root hash value With layer data solidification time Concatenate and digitally sign Obtain the timestamp token .

[0057] S113. Construct a time lock based on the root hash value, the timestamp token, the layer data persistence time, and the public key certificate of the trusted timestamp authority; execute S121 or S122.

[0058] Time Lock It is a publicly verifiable structure, which can be represented as , This can be a public key certificate (or fingerprint) from a trusted timestamp authority.

[0059] The advantage of this setup is that it uses cryptographic methods to immutably bind the hash digest of each layer of data to an authoritative timestamp, generating a self-contained time lock that supports offline and rapid verification of data status at any given time, reducing continuous dependence on centralized services.

[0060] In one embodiment, quantum-resistant enhancement is performed using at least two strategies: the trusted timestamp authority generates the timestamp token using a post-quantum cryptography algorithm; and the timestamp token is generated based on performing a multi-layer quantum-resistant hash mapping on the root hash value.

[0061] Policy A (post-quantum signatures): requires trusted timestamping authorities to use post-quantum cryptography algorithms to generate signatures. Strategy B (post-hash signature): Using a quantum-resistant hash function... Perform multi-layer quantum-resistant hash mapping, such as ,right conduct Iteration of the prime field mapping, then... Submit to a trusted timestamp authority for signing and generate This increases the quantum complexity of hash cracking to [number missing]. .

[0062] The advantage of this setup is that it enables long-term quantum-resistant data integrity protection, inherits and enhances the prime field mapping mechanism of the hierarchical dynamic hash chain, and combines it with post-quantum cryptographic signature algorithms to strengthen time locks, ensuring the integrity of data throughout its entire lifecycle and resisting classical and quantum computing attacks.

[0063] S121. Construct a data item audit task for a single auditable time layer based on the audit request, wherein the auditable time layer is determined by the auditable data item and auditable timestamp indicated by the audit request; execute S131-S133.

[0064] S131. Execute the data item auditing task, extract the hash node sequence required to verify the data item to be audited from the dynamic hash chain of the time layer to be audited, and generate a verification path.

[0065] S132. Generate the root hash value of the reconstruction layer of the time layer to be audited through the verification path and the data item to be audited.

[0066] S133. Based on the root hash value of the reconstructed layer, verify the validity of the time lock of the time layer to be audited, and determine the target audit result of the data item to be audited.

[0067] The following explanation is provided for S131-S133:

[0068] The auditable time layer is determined by the data item to be audited and its timestamp. Within the dynamic hash chain structure of the auditable time layer, a unique identifier for the data (such as a transaction identifier or hash value) is used to search the hash tree to locate the data item to be audited. From the dynamic hash chain of the auditable time layer, the sequence of hash nodes required to verify the data item to be audited is extracted, represented as... , This is the verification path, and the nodes it contains are the hash nodes required for verification.

[0069] Verification path Reconstructing the root hash value of the data item to be audited involves performing a step-by-step hash calculation along the verification path to obtain the reconstructed root hash value of the audited time layer. .

[0070] Verify the validity of the time lock at the time layer to be audited, i.e., verify the timestamp token using the public key certificate of a trusted timestamp authority. Validity; inspection Is the message signed by the Chinese signer? Compare the calculated root hash values ​​of the reconstructed layer. The root hash value stored in the time lock If all verifications pass, the data is valid, and the target audit result for the data item to be audited is determined to be audit passed; otherwise, the audit fails.

[0071] It should be noted that the verification of time locks ensures data integrity; any tampering with data within a layer will result in recalculation. Stored in the time lock Inconsistent, verification failed; however, the accuracy of the time information can be guaranteed. The validity check ensures exist The signature is unforgeable because it existed before the time and has not been tampered with. The security of the signature depends on the security of the private key of the trusted timestamp authority or the post-quantum signature algorithm used. It can guarantee independent verifiability. The verifier only needs to hold the time lock and the public key of the trusted timestamp authority to complete the verification independently without querying the original database or other layers of information, thus realizing offline verification.

[0072] The advantage of this setup is that when it's necessary to validate auditable data items located at the auditable time layer, the validation operation is confined to that layer. The average path shortening factor resulting from hotspot optimization within that layer's internal structure is [value missing]. (If we take 0.85), then the hash calculation step size required to verify the data item to be audited is... , For the amount of data at this layer, compared to the global Merkle tree verification path length The path is shortened, the verification efficiency is improved, and the loading and processing of data from time layers not involved in the verification are avoided, resulting in a significant reduction in computational overhead.

[0073] In one embodiment, the dynamic hash chain of the time layer to be audited adopts a binary tree structure; extracting the hash node sequence required to verify the data item to be audited from the dynamic hash chain of the time layer to be audited includes: traversing upwards from the leaf node corresponding to the data item to be audited to the root node in the dynamic hash chain of the time layer to be audited, recording the hash values ​​of the sibling nodes of the traversed nodes, and obtaining the hash node sequence.

[0074] Assume the dynamic hash chain of the time layer to be audited adopts a binary tree structure, where each leaf node corresponds to the hash value of a data item. Starting from the leaf node corresponding to the data item to be audited, traverse upwards to the root node. At each node reached, record the hash value of its sibling node, and arrange them in traversal order to obtain the hash node sequence. For example, if the leaf node corresponding to the data item to be audited is the left child node, then record the hash value of the right sibling node.

[0075] The advantage of this setup is that verification can be achieved by traversing from the leaf node corresponding to the data item to be audited to the sibling node of the root node, making verification more lightweight and efficient.

[0076] S122. Construct multiple time-layer audit tasks to be audited in parallel according to the audit request, wherein the time layer to be audited is determined by the time range to be audited indicated by the audit request; execute S134-S137.

[0077] S134. Execute multiple time-layer audit tasks in parallel. For each time-layer audit task, read all data of the corresponding time layer to be audited to generate a reconstruction layer root hash value. Verify the validity of the time lock of the corresponding time layer to be audited based on the reconstruction layer root hash value, and determine the single-layer audit result.

[0078] S135. Summarize the single-level audit results of multiple time-level audit tasks to obtain the summarized audit results.

[0079] S136. Based on the hash values ​​of the time locks of all time layers, generate a reconstructed global time state root and compare it with the baseline global time state root to obtain the global state audit result.

[0080] S137. Determine the target audit result based on the summarized audit result and the global status audit result.

[0081] The following explanation is provided for S134-S137:

[0082] Create m time-layer audit tasks and add them to the task queue. Multiple worker threads in the thread pool retrieve tasks from the task queue and execute single-layer verification. That is, one worker thread executes one time-layer audit task. Specifically, it reads all data blocks of the corresponding time layer to be audited, recalculates the hash chain within the layer according to the dynamic hash chain construction rules, and obtains the root hash value of the reconstructed layer. ,pass Verify the validity of the time lock corresponding to the time layer to be audited (the verification process is basically the same as the time lock validity verification of the data item audit task mentioned above), and determine the single-layer audit result, i.e., whether the audit passes or fails. The main thread collects the single-layer audit results of all m tasks. When all single-layer audit results indicate that the audit has passed, the audit result is summarized as audit passed, completing the integrity verification of the data within each time layer.

[0083] Baseline global time state root The system is constructed as follows: The system maintains a baseline global time state root. It is the root hash of another Merkle tree constructed from the hash values ​​of time locks across all layers as leaf nodes, represented as: After the audit is completed, the Merkle root of all current time lock hashes can be calculated, thus reconstructing the global time state root. This will reconstruct the global time state root. With reference global time state root If the comparison is consistent, it proves that the entire time-layered structure has not been tampered with, the global state audit result is that the audit has passed, and the final system-level consistency confirmation is completed.

[0084] In practical applications, the summary audit results can be used as the target audit results; alternatively, the summary audit results and the global status audit results can be used as the target audit results, and the global time status audit can be performed only when the summary audit results indicate that the audit has passed.

[0085] The advantage of this setup is that it leverages the independence between time layers to decompose batch audit tasks spanning different time periods into subtasks that can be executed in parallel, thus reducing the time complexity of parallel verification. Approximately Compared to the time complexity of traditional verification When the audit time span m is large, the advantages of parallel verification are extremely significant, and a near-linear speedup can be achieved.

[0086] In one embodiment, the method further includes: taking the time layer where data updates occur as the target time layer, regenerating the root hash value and time lock of the target time layer, and retaining the time lock of the target time layer before the data update as a historical time lock; and updating the baseline global time state root based on the regenerated time lock of the target time layer.

[0087] If the data update involves inserting new data, the time layer where the new data was inserted is designated as the target time layer. Incremental updates are performed within the target time layer, the root hash value of the target time layer is regenerated, and a new time lock version is requested. Other time layers are unaffected. If the data update involves correcting historical data, the time layer where the historical data was corrected is designated as the target time layer. The historical data to be modified is located within the target time layer, modified, the root hash value of the target time layer is regenerated, and a new time lock version is requested.

[0088] It should be noted that the time lock at the target time level before the data update is retained as a historical version time lock, forming a complete data change audit trail. When verifying the historical state of the data, the corresponding version's time lock and verification path must be used.

[0089] When updating the time lock at the target time level, update the base global time state root. The corresponding leaf node hash value; this operation only involves... Updating a path in a Merkle tree incurs minimal overhead.

[0090] The advantage of this setup is that it only regenerates the time lock for the target time layer where data updates exist, without affecting the security state of other time layers; the overhead of updating the global time state root when updating the time lock for the target time layer is minimal; and it retains the time locks of historical versions, enabling complete data change audit trail tracing.

[0091] The technical solution of this invention, by introducing time-dimensional layering, time lock binding, and parallel audit verification core mechanisms, brings the following improvements to long-term data storage and audit verification:

[0092] Improved audit verification efficiency: The time complexity of audit verification of historical data for a specific time period is optimized from being related to the total amount of data to being related only to the amount of data in a single time period. Combined with parallel computing, the full audit task that used to take several hours or even days is shortened to minutes, meeting the requirements of real-time supervision.

[0093] Supports efficient and traceable historical data updates: It realizes local updates of the target time layer, which only affects one path of the target time layer and the global time state root, avoiding the huge overhead of global tree reconstruction in traditional solutions, while retaining the old time lock to fully record all change history;

[0094] Providing long-term quantum-resistant security: By combining prime field mapping with post-quantum signature algorithms, the strength of data integrity protection is enhanced. At the quantum level and above, it can resist quantum attacks and ensure the security of data throughout its entire lifecycle;

[0095] Enables offline, independent point-in-time status verification: The time lock mechanism makes the verification of data status at any historical moment no longer dependent on online databases or centralized timestamp services, providing a self-contained evidence package, which greatly enhances the convenience and credibility of auditing;

[0096] System scalability and cost optimization: The combination of time-tiered architecture and hot / cold data separation strategy allows infrequently accessed historical data to be migrated to low-cost storage media while maintaining its verifiability, achieving an optimal balance between storage cost and access performance.

[0097] Example 3

[0098] Figure 3 This is a schematic diagram of a data storage and auditing device according to Embodiment 3 of the present invention. This embodiment is applicable to situations involving data storage and auditing, such as... Figure 3 As shown, the specific structure of the device includes:

[0099] The data partitioning module 31 is used to partition the data to be stored into multiple time layers and generate a corresponding time lock for each time layer;

[0100] Task construction module 32 is used to construct audit tasks to be executed for the audit time layer according to the audit request. The audit tasks to be executed include a single data item audit task for the audit time layer, or multiple time layer audit tasks to be executed in parallel for the audit time layers.

[0101] The audit verification module 33 is used to verify the validity of the time lock of the time layer to be audited based on the audit task to be executed, and to determine the target audit result.

[0102] The data storage and auditing device provided in this embodiment divides the data to be stored into multiple time layers through a data partitioning module and generates a corresponding time lock for each time layer. A task construction module constructs audit tasks to be executed for each time layer based on audit requests. These audit tasks include auditing a single data item within the audited time layer, or auditing multiple time layers executed in parallel. An audit verification module verifies the validity of the time locks for each audited time layer based on the audit tasks to be executed, thus determining the target audit result. This solution stores data in time-layered manner during the data storage phase, providing an efficient data query foundation for the subsequent data auditing phase. During the data auditing phase, auditing of data items is located within the individual time layer to which the data item belongs, while auditing of data across multiple time layers is executed independently and in parallel by each time layer. This optimizes the complexity of data auditing from being related to the total amount of data to being related to the amount of data in a single time layer, improving audit verification efficiency and meeting the high-efficiency auditing needs of large-scale data.

[0103] Furthermore, the data partitioning module 31 is specifically used for:

[0104] For each time layer, a dynamic hash chain is constructed using a hash chain construction algorithm optimized with prime number field mapping and hotspot identification, and a layer root hash value is generated.

[0105] A timestamp token is obtained based on the root hash value of the layer. The timestamp token is obtained by a trusted timestamp organization by concatenating the root hash value of the layer with the solidification time of the layer data and performing digital signature.

[0106] A time lock is constructed based on the root hash value, the timestamp token, the layer data persistence time, and the public key certificate of the trusted timestamp authority.

[0107] Furthermore, anti-quantum enhancement processing is performed through at least the following two strategies:

[0108] The trusted timestamp mechanism generates the timestamp token using a post-quantum cryptography algorithm.

[0109] The timestamp token is generated based on performing a multi-level quantum-resistant hash mapping on the root hash value.

[0110] Furthermore, the auditable time layer is determined by the auditable data item and auditable timestamp indicated by the audit request; the audit verification module 33 is specifically used for:

[0111] Execute the data item auditing task, extract the hash node sequence required to verify the data item to be audited from the dynamic hash chain of the time layer to be audited, and generate a verification path;

[0112] The root hash value of the reconstructed time layer to be audited is generated using the verification path and the data item to be audited.

[0113] Based on the root hash value of the reconstructed layer, the validity of the time lock of the time layer to be audited is verified, and the target audit result of the data item to be audited is determined.

[0114] Furthermore, the dynamic hash chain of the time layer to be audited adopts a binary tree structure; extracting the hash node sequence required to verify the data item to be audited from the dynamic hash chain of the time layer to be audited includes:

[0115] In the dynamic hash chain of the time layer to be audited, starting from the leaf node corresponding to the data item to be audited, traverse upwards to the root node, record the hash values ​​of the sibling nodes of the traversed nodes, and obtain the hash node sequence.

[0116] Furthermore, the auditable time layer is determined by the auditable time range indicated by the audit request; the audit verification module 33 is specifically used for:

[0117] Multiple time-layer audit tasks are executed in parallel. For each time-layer audit task, all data of the corresponding time layer to be audited is read to generate a reconstruction layer root hash value. The validity of the time lock of the corresponding time layer to be audited is verified based on the reconstruction layer root hash value to determine the single-layer audit result.

[0118] The audit results of multiple time-layer audit tasks are summarized to obtain the summarized audit results;

[0119] Based on the hash values ​​of the time locks of all time layers, a reconstructed global time state root is generated and compared with the baseline global time state root to obtain the global state audit result.

[0120] The target audit result is determined based on the summarized audit results and the global status audit results.

[0121] Furthermore, the device also includes:

[0122] The reconstruction module is used to take the time layer where data is updated as the target time layer, regenerate the root hash value and time lock of the target time layer, and retain the time lock of the target time layer before the data update as a historical time lock.

[0123] The state update module is used to update the baseline global time state root based on the regenerated time lock of the target time layer.

[0124] The data storage and auditing apparatus provided in the embodiments of the present invention can execute the data storage and auditing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0125] Example 4

[0126] Figure 4 This is a schematic diagram of the structure of an electronic device implementing embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0127] like Figure 4As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory 12 or a random access memory 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the read-only memory 12 or loaded from storage unit 18 into the random access memory 13. The random access memory 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, read-only memory 12, and random access memory 13 are interconnected via a bus 14. An input / output interface 15 is also connected to the bus 14.

[0128] Multiple components in electronic device 10 are connected to input / output interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of monitors, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0129] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, central processing units, graphics processing units, various special-purpose artificial intelligence computing chips, various processors running machine learning model algorithms, digital signal processors, and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as data storage and auditing methods.

[0130] In some embodiments, the data storage and auditing method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via read-only memory 12 and / or communication unit 19. When the computer program is loaded into random access memory 13 and executed by processor 11, one or more steps of the data storage and auditing method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the data storage and auditing method by any other suitable means (e.g., by means of firmware).

[0131] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays, application-specific integrated circuits (ASICs), application-specific standard products (ASICs), systems-on-a-chip (SoCs), payload programmable logic devices, computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0132] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0133] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory, read-only memory, erasable programmable read-only memory, optical fibers, portable compact disk read-only memory, optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0134] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a cathode ray tube or liquid crystal display) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0135] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0136] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product within the cloud computing service system. This addresses the shortcomings of traditional physical hosts and virtual private servers, such as high management difficulty and weak business scalability.

[0137] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0138] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A data storage and auditing method, characterized in that, include: The data to be stored is divided into multiple time layers, and a corresponding time lock is generated for each time layer; Based on the audit request, an audit task to be executed for the time layer to be audited is constructed. The audit task to be executed includes a single data item audit task for the time layer to be audited, or multiple time layer audit tasks to be audited in parallel. Based on the audit task to be executed, verify the validity of the time lock of the time layer to be audited, and determine the target audit result.

2. The method according to claim 1, characterized in that, Generate a corresponding time lock for each time layer, including: For each time layer, a dynamic hash chain is constructed using a hash chain construction algorithm optimized with prime number field mapping and hotspot identification, and a layer root hash value is generated. A timestamp token is obtained based on the root hash value of the layer. The timestamp token is obtained by a trusted timestamp organization by concatenating the root hash value of the layer with the solidification time of the layer data and performing digital signature. A time lock is constructed based on the root hash value, the timestamp token, the layer data persistence time, and the public key certificate of the trusted timestamp authority.

3. The method according to claim 2, characterized in that, Anti-quantum enhancement processing can be performed using at least two of the following strategies: The trusted timestamp mechanism generates the timestamp token using a post-quantum cryptography algorithm. The timestamp token is generated based on performing a multi-level quantum-resistant hash mapping on the root hash value.

4. The method according to claim 1, characterized in that, The auditable time layer is determined by the auditable data item and auditable timestamp indicated by the audit request; based on the audit task to be executed, the validity of the time lock of the auditable time layer is verified, and the target audit result is determined, including: Execute the data item auditing task, extract the hash node sequence required to verify the data item to be audited from the dynamic hash chain of the time layer to be audited, and generate a verification path; The root hash value of the reconstructed time layer to be audited is generated using the verification path and the data item to be audited. Based on the root hash value of the reconstructed layer, the validity of the time lock of the time layer to be audited is verified, and the target audit result of the data item to be audited is determined.

5. The method according to claim 4, characterized in that, The dynamic hash chain of the time layer to be audited adopts a binary tree structure; the hash node sequence required to verify the data item to be audited is extracted from the dynamic hash chain of the time layer to be audited, including: In the dynamic hash chain of the time layer to be audited, starting from the leaf node corresponding to the data item to be audited, traverse upwards to the root node, record the hash values ​​of the sibling nodes of the traversed nodes, and obtain the hash node sequence.

6. The method according to claim 1, characterized in that, The auditable time layer is determined by the auditable time range indicated by the audit request; based on the audit task to be executed, the validity of the time lock of the auditable time layer is verified, and the target audit result is determined, including: Multiple time-layer audit tasks are executed in parallel. For each time-layer audit task, all data of the corresponding time layer to be audited is read to generate a reconstruction layer root hash value. The validity of the time lock of the corresponding time layer to be audited is verified based on the reconstruction layer root hash value to determine the single-layer audit result. The audit results of multiple time-layer audit tasks are summarized to obtain the summarized audit results; Based on the hash values ​​of the time locks of all time layers, a reconstructed global time state root is generated and compared with the baseline global time state root to obtain the global state audit result. The target audit result is determined based on the summarized audit results and the global status audit results.

7. The method according to claim 1, characterized in that, Also includes: Take the time layer where data is updated as the target time layer, regenerate the root hash value and time lock of the target time layer, and retain the time lock of the target time layer before the data update as a historical time lock. Update the baseline global time state root based on the regenerated time lock of the target time layer.

8. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the method as described in any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the method as described in any one of claims 1-7.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the method as described in any one of claims 1-7.