A compliance data auditing processing method, device and equipment based on bidirectional verification
By using a two-way verification method on a blockchain platform, the problem of lack of two-way verification in data compliance auditing is solved. It enables two-way verification between data providers and auditors, ensuring the traceability and immutability of the audit process, and improving the credibility and compliance of the audit.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HEFEI TANOVO INFORMATION SECURITY TECH CO LTD
- Filing Date
- 2026-04-28
- Publication Date
- 2026-07-24
Smart Images

Figure CN122451933A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information processing technology, and in particular to a compliance data auditing processing method, apparatus and equipment based on two-way verification. Background Technology
[0002] With the rapid development of the data element market, data compliance auditing has become a crucial link in ensuring data circulation security and meeting regulatory requirements. Current mainstream auditing solutions primarily rely on centralized third-party auditing institutions, blockchain notarization, or single privacy computing technology. However, these solutions generally suffer from a core problem: the lack of a two-way verification mechanism. They only enable one-way verification between the auditor and the data provider, failing to allow the data provider to effectively verify the auditor's rule execution process and results. Furthermore, the execution of audit rules lacks transparency and verifiability, making it difficult to verify data compliance attributes while protecting the privacy of the original data. The notarization of key audit processes and results lacks immutability, making it susceptible to tampering and repudiation of audit results. In addition, the rigid audit logic is difficult to adapt to dynamic compliance regulatory requirements, and the overall system fails to build a closed-loop mechanism of mutual trust and verification between the auditor and the data provider, severely impacting the credibility and compliance of data audits. Summary of the Invention
[0003] This invention provides a compliance data auditing method, apparatus, and equipment based on two-way verification, which solves the problem that traditional data compliance auditing processes cannot perform two-way verification.
[0004] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows: This invention provides a compliance data auditing method based on two-way verification, applied to a blockchain platform, comprising: Based on the audit session between the data provider and the auditor, the system receives audit rules submitted by the auditor; and receives transaction data submitted by the data provider, which is encapsulated by the data provider based on the data commitment value and compliance proof generated from the original data. A random challenge is initiated to the data provider, and the random challenge value is synchronized to the data provider and the auditing party. The data provider sends the target shard data to the auditing party according to the random challenge value. The auditing party verifies the shard data and transaction data according to the random challenge value, obtains a first verification result, and generates proof data that the audit rule has been executed after the audit rule is executed. Receive the first verification result and proof data sent by the auditor, and forward the proof data to the data provider; The data provider verifies the proof data, and obtains and sends a second verification result. Consensus processing is performed on the first verification result and the second verification result to generate a security audit report.
[0005] Optionally, the process by which the data provider generates data commitment values and compliance certificates based on the raw data includes: Data provider according to Generate data commitment values, where, d represents the data commitment value; g and h are public parameters; d represents the original data; r is the randomization factor; p represents the pre-selected prime modulus; Data provider according to Generate compliance proof, among which, For compliance proof; This indicates the proof generating function; For compliance private keys; For data commitment values; d represents the preset compliance conditions; r represents the original data; and r represents the randomization factor.
[0006] Optionally, a random challenge is initiated to the data provider, and the random challenge value is synchronized to both the data provider and the auditor, including: A verifiable random function on the blockchain is invoked to calculate and generate a random challenge value; The random challenge value is sent to the data provider and the auditor; the data provider obtains sharded data based on the random challenge value, the sharded data includes a target shard selected from multiple data shards and a digital signature attached to each shard; the multiple data shards are obtained by the data provider dividing the original data; the auditor triggers a verification process based on the random challenge value and the sharded data.
[0007] Optionally, the auditor verifies the sharded data and transaction data based on the random challenge value to obtain a first verification result, including: Verify the fragmented data to obtain the signature verification result; When the signature verification result is successful, the target fragment in the fragmented data is reconstructed, and the commitment value of the reconstruction result is compared with the data commitment value in the transaction data to obtain the comparison result; If the comparison is successful, the validity of the compliance certificate is verified, and the first verification result is obtained.
[0008] Optionally, generate proof data demonstrating that the audit rules were executed, including: The auditor based on Generate evidentiary data to verify the correctness of the audit execution process; in, This represents the data used to prove the point. Represents a computational function; Indicates the audit private key; Commitment to data; Indicates the hash value of the audit rule; This represents the result of the audit rule execution; R indicates the audit rule code; This represents reconstructed data; r is the randomization blinding factor.
[0009] Optionally, the receiving data provider verifies the proof data, and obtains and sends a second verification result, including: The receiving data provider according to , The proof data is verified to obtain and send a second verification result; Wherein, result represents the second verification result; This indicates the computation verification function; Indicates the audit public key; For data commitment values; Indicates the hash value of the audit rule; For the results of audit rule execution; This represents the data used to prove the point.
[0010] Optionally, consensus processing is performed on the first verification result and the second verification result to generate a security audit report, including: The final audit result is determined by having multiple nodes vote on the authenticity of the first verification result and the second verification result; Based on the final audit results, a corresponding security audit report is generated.
[0011] This invention also provides a compliance data auditing processing device based on two-way verification, comprising: The processing module is configured to: receive audit rules submitted by the auditor based on the audit session between the data provider and the auditor; receive transaction data submitted by the data provider, wherein the transaction data is encapsulated by the data provider based on the data commitment value and compliance proof generated from the original data; initiate a random challenge to the data provider and synchronize the random challenge value to both the data provider and the auditor, so that the data provider sends the target shard data to the auditor based on the random challenge value, and the auditor verifies the shard data and transaction data based on the random challenge value to obtain a first verification result, and generates proof data for the execution of the audit rule after the audit rule is executed; receive the first verification result and proof data sent by the auditor, and forward the proof data to the data provider; receive the second verification result obtained and sent by the data provider after verifying the proof data. The generation module is used to perform consensus processing on the first verification result and the second verification result to generate a security audit report.
[0012] This invention also provides a computing device, including: a processor and a memory storing a computer program, wherein the computer program, when run by the processor, executes the above-described method.
[0013] This invention also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the above-described method.
[0014] The technical solution of the present invention has at least the following effects: The above-described solution of the present invention, based on the audit session between the data provider and the auditor, receives audit rules submitted by the auditor; and receives transaction data submitted by the data provider, wherein the transaction data is encapsulated by the data provider based on the data commitment value and compliance proof generated from the original data; initiates a random challenge to the data provider and synchronizes the random challenge value to both the data provider and the auditor, so that the data provider sends the target fragment data to the auditor according to the random challenge value, and the auditor verifies the fragment data and transaction data according to the random challenge value, obtains a first verification result, and generates proof data for the execution of the audit rule after the audit rule is executed; receives the first verification result and proof data sent by the auditor, and forwards the proof data to the data provider; receives the second verification result obtained and sent by the data provider after verifying the proof data; and performs consensus processing on the first verification result and the second verification result to generate a security audit report. This enables bidirectional peer-to-peer verification between the auditing parties, ensuring the traceability and immutability of the audit process, and achieving a high degree of trustworthiness in the audit process. Attached Figure Description
[0015] Figure 1 This is a flowchart of a compliance data auditing processing method based on two-way verification provided in an embodiment of the present invention; Figure 2 This is an interactive flowchart of the compliance data auditing processing method based on two-way verification provided in an embodiment of the present invention; Figure 3 This is an audit data flow diagram of the compliance data audit processing method based on two-way verification provided in this embodiment of the invention; Figure 4 This is a structural diagram of the compliance data audit processing device based on two-way verification provided in an embodiment of the present invention; Figure 5 This is a schematic diagram of the structure of the computing device provided in an embodiment of the present invention. Detailed Implementation
[0016] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.
[0017] like Figures 1 to 3 As shown, an embodiment of the present invention proposes a compliance data auditing processing method based on two-way verification, applied to a blockchain platform. The method includes: Step 11: Based on the audit session between the data provider and the auditor, receive the audit rules submitted by the auditor; and receive the transaction data submitted by the data provider, wherein the transaction data is encapsulated by the data provider based on the data commitment value and compliance proof generated from the original data; Step 12: Initiate a random challenge to the data provider and synchronize the random challenge value to the data provider and the auditor. This allows the data provider to send the target shard data to the auditor based on the random challenge value. The auditor then verifies the shard data and transaction data based on the random challenge value to obtain a first verification result. After the audit rule is executed, it generates proof data indicating that the audit rule has been executed. Step 13: Receive the first verification result and proof data sent by the auditor, and forward the proof data to the data provider; Step 14: Receive the verification of the proof data from the data provider, obtain and send the second verification result; Step 15: Perform consensus processing on the first verification result and the second verification result to generate a security audit report.
[0018] In this embodiment, the auditor and the data provider jointly execute a two-way verification process. Based on the data commitment value and compliance proof, the integrity and compliance of the data are verified. The random challenge mechanism is combined to enhance the credibility of the audit. The audit behavior is traceable and verifiable by proving the data. After consensus, the results are stored on the blockchain to ensure that they are non-repudiable. This not only completes the compliance audit without exposing the original data, but also enables reverse verification of the audit execution process. This builds a more credible, secure and traceable data security audit closed loop, effectively improving the fairness of the audit and the ability to protect data privacy.
[0019] In an optional embodiment of the present invention, step 11, receiving audit rules submitted by the auditor based on the audit session between the data provider and the auditor, may include: Step 111: Establish a secure audit session for the data provider and the auditor; Step 112: Receive the audit rules submitted by the auditor in the audit session and store the audit rules in the audit rule smart management contract.
[0020] In this embodiment, in step 111, the blockchain enables the auditor and the data provider to establish a secure audit session. Through this session, both parties jointly negotiate and determine the audit rules, security parameters λ, and compliance conditions for this audit. Audit rule R includes specific audit logic such as data range verification and set attribution verification, for example, verifying whether data is within a certain range. Within the specified interval, to ensure that subsequent auditing activities follow the mutual agreement, the auditing party will upload the audit rule hash value H(R) to the blockchain; the security parameter λ is used to determine data such as cryptographic algorithm strength and secret sharing threshold; the compliance conditions are the specific conditions that need to be met, for example... Interval.
[0021] In step 112, the auditor uses a hash function to calculate the negotiated audit rules, obtaining the audit rules. These audit rules uniquely identify the content of the audit rules, effectively preventing unauthorized tampering. The auditor uploads the generated audit rule hash value to the audit rule management contract on the blockchain for storage, completing on-chain notarization. This ensures the audit rules possess characteristics such as transparency, immutability, and traceability, providing credible evidence for subsequent two-way verification and dispute resolution. After uploading the generated audit rule hash value to the audit rule management contract on the blockchain, the data provider also uploads the hash value H(C_cond) of the preset compliance conditions to the same contract, ensuring consistency between the agreements of both parties.
[0022] In an optional embodiment of the present invention, step 11, in which the data provider encapsulates the transaction data based on the data commitment value and compliance proof generated from the original data, may include: Step 113, the data provider, according to Generate data commitment values, where, d represents the data commitment value; g and h are public parameters; d represents the original data; r is the randomization factor; p represents the pre-selected prime modulus; Step 114, the data provider, according to... Generate compliance proof, For compliance proof; This indicates the proof generating function; For compliance private keys; For data commitment values; d represents the preset compliance conditions; r represents the original data; and r represents the randomization factor.
[0023] In this embodiment, the data provider preprocesses the raw data to generate a random blinding factor, and then... A data commitment value is obtained, which is used to verify data integrity and serves as the basic input for compliance proof, achieving credible auditing and verification without disclosing the original data; wherein, The data commitment value is denoted by d; g and h are public parameters; d is the original data; and r is the randomization blinding factor. Represents the modulus of a pre-selected prime number; and through Generate a compliance certificate, which proves that the original data meets preset compliance conditions and does not disclose the original data; wherein, For compliance proof; This indicates the proof generating function; For compliance private keys; For data commitment values; d represents the preset compliance conditions; r represents the original data; and r represents the randomization factor.
[0024] After the data provider generates a data commitment value and a compliance certificate, they encapsulate these two elements into transaction data and upload them to a data commitment storage contract on the blockchain for storage. After the blockchain pre-stores the compliance certificate, the auditor will... First, verify the validity of the compliance certificate. Once verification is successful, formally store the data commitment value and the compliance certificate, and record the storage timestamp. This indicates the proof and verification results; This represents the first proof verification function; For compliance public keys; For data commitment values; These are the pre-set compliance conditions; This indicates proof of compliance.
[0025] Once the data commitment value and compliance proof are stored on the blockchain, the data can be read from the blockchain through a listening interface to obtain the data commitment value and compliance proof.
[0026] In an optional embodiment of the present invention, in step 12, a random challenge is initiated to the data provider, and the random challenge value is synchronized to both the data provider and the auditor. This allows the data provider to send the target shard data to the auditor based on the random challenge value. The auditor then verifies the shard data and transaction data based on the random challenge value to obtain a first verification result. After the audit rule is executed, proof data demonstrating that the audit rule has been executed is generated, which may include: Step 121: Call the verifiable random function on the blockchain to calculate and generate a random challenge value; Step 122: Send the random challenge value to the data provider and the auditor; Step 123: The data provider submits the sharded data to the auditor based on the random challenge value; Step 124: The auditor receives and verifies the fragmented data to obtain a signature verification result; Step 125: When the signature verification result is successful, the target fragment in the fragmented data is reconstructed, and the commitment value of the reconstruction result is compared with the data commitment value to obtain the comparison result; Step 126: If the comparison result is successful, verify the validity of the compliance certificate to obtain the first verification result; Step 127: The auditor executes the audit logic according to the audit rules, and generates proof data to verify the correctness of the audit execution process based on the audit results obtained from the audit logic.
[0027] In this embodiment, in step 121, according to A random seed is obtained, which is used to generate unpredictable, unmanipulated, but publicly verifiable random challenge values; wherein, H is a random seed; H() represents a hash function; This represents a session identifier used for interaction between the auditor and the data provider. For example, the auditor and the data provider negotiate audit rules through an audit session, and the session identifier is a unique identifier corresponding to the audit session. Indicates the current block height in the blockchain; Indicates the hash value of the audit rule; This represents the hash value of the preset compliance conditions.
[0028] according to This generates a random challenge value and simultaneously generates a challenge value proof used to verify the validity of the random challenge value; where, Indicates a random challenge value; This indicates the challenge value proof; This indicates a verifiable random function; Represents a random private key; The random seed is used. Both the random private key and the random public key are a pair of keys generated by the blockchain. The random private key is stored by the blockchain, while the random public key is distributed externally. It can determine whether a third party can use the random public key to verify the legitimacy of the random challenge value and its proof, ensuring that the challenge value has not been tampered with.
[0029] In step 122, a random challenge value is sent to the data provider, along with the session identifier for this audit, which is used by the data provider to locate the corresponding original data set; the random challenge value is synchronized to the auditor, who then triggers a verification process based on the random challenge value.
[0030] In step 123, after receiving the random challenge value, the data provider performs the following operations: (1) Using random challenge values, the fragment numbers of multiple data fragments obtained by the data provider in the pre-processing of the original data are mapped and calculated. Fragmentation is carried out through threshold secret sharing. When the fragment reaches the preset recovery threshold, the original data can be recovered. Select one or more fragments as target fragments from multiple data fragments. Specifically, the original data is divided into N fragments. The preset recovery threshold is used as the number of fragments to be extracted this time. Then, the random challenge value is used as the random seed to randomly select the preset recovery threshold fragments from the N fragments without repetition as target fragments.
[0031] (2) The data provider digitally signs the target fragment using the generated signing private key to obtain the fragment signature, represented as: ;in, Indicates fragmented signature; Indicates the signature function; This represents the private key used for signing; Indicates the target fragment.
[0032] (3) The target fragment and the fragment signature together constitute fragment data, and the data provider submits the fragment data to the auditing party.
[0033] In step 124, the auditor receives the fragmented data sent by the data provider, and according to... The authenticity of the digital signature of the target fragment is verified, among which, This represents the signature verification function; Indicates the public key for signing; This represents the i-th target fragment; This represents the signature of the i-th shard. If the signature verification of any shard fails, the audit is deemed invalid, and the subsequent process is terminated directly. Only when the signatures of all shards are successfully verified will the next step be initiated to avoid illegal data interfering with the audit.
[0034] In step 125, when signature verification is successful, the data is fully recovered using the received target fragment through Lagrange interpolation, according to... The reconstructed data commitment is obtained; this commitment is then compared with the data commitment value stored on the blockchain. If they match, the comparison is successful. To reconstruct the data commitment value; g and h are public parameters; To reconstruct the data; r is the random blinding factor; This represents the modulus of the pre-selected prime number.
[0035] In step 126, if the comparison is successful, according to: The first verification result was obtained; in, This indicates the first verification result; This represents the second proof verification function; For compliance public keys; For data commitment values; This represents a compliance certificate; it is used to verify whether the compliance certificate corresponds to the current data commitment, that is, to confirm that the reconstructed data meets the preset compliance conditions (e.g., After verification, the verification result is written into the two-way verification execution contract on the blockchain for storage. In step 127, audit logic is executed according to the audit rules, and according to... To determine the reliability of the audit results obtained from the execution of audit logic, proof data is generated to verify the correctness of the audit execution process. This represents the data used to prove the point. Represents a computational function; Indicates the audit private key; Commitment to data; Indicates the hash value of the audit rule; This represents the result of the audit rule execution; R indicates the audit rule code; This represents reconstructed data; r is the randomization blinding factor.
[0036] In an optional embodiment of the present invention, step 13, receiving the first verification result and proof data sent by the auditor, and forwarding the proof data to the data provider, includes: Step 131: Receive the first verification result and proof data sent by the auditor, store the first verification result and proof data in the smart contract, and forward the proof data to the data provider.
[0037] In this embodiment, the blockchain platform receives the first verification result and verifiable proof data submitted by the auditor through the communication interface corresponding to the audit session; performs format and integrity checks on the first verification result and verifiable proof data to confirm that the data is still complete and has not been tampered with; writes the first verification result, proof data, session identifier, random challenge value, and timestamp into the two-way verification execution smart contract for on-chain storage; the blockchain platform reads the proof data from the smart contract and forwards it to the data provider through the audit session channel to trigger the data provider's second-way verification of the audit execution process.
[0038] In an optional embodiment of the present invention, step 14, in which the data provider verifies the proof data to obtain a second verification result, may include: Step 141: The data provider verifies the result of executing the audit rules on the reconstructed data d' based on the audit public key, the calculated verification function, and the proof data verification, indicating that the result is correct. , ; Wherein, result represents the second verification result; This indicates the computation verification function; Indicates the audit public key; For data commitment values; Indicates the hash value of the audit rule; For the results of audit rule execution; This represents the data used to prove the point.
[0039] In this embodiment, the data provider verifies the proof data generated by the auditor after executing the audit rules by calculating the verification function. This verifies whether the auditor strictly follows the agreed audit rules to execute the audit logic, whether the audit results are true and legal, and whether the proof data is valid. Without obtaining the original data or repeating the audit calculation, the provider completes the reverse supervision and credibility verification of the auditor and obtains the second verification result.
[0040] In an optional embodiment of the present invention, step 15, which involves consensus processing of the first verification result and the second verification result to generate a security audit report, may include: Step 151: The first verification result and the second verification result are voted on by multiple nodes to determine their authenticity, and the final audit result is determined. Step 152: Generate the corresponding security audit report based on the final audit results.
[0041] In this embodiment, in step 151, the first verification result and the second verification result are packaged and broadcast to all nodes of the blockchain. The nodes verify and vote on the two sets of verification results and related evidence. When more than two-thirds of the nodes reach a consensus, the final audit result is formed. The final audit result, verification proof, random challenge value and timestamp and other key information are automatically written into the blockchain's audit log storage contract to complete the tamper-proof on-chain storage.
[0042] In step 152, the entire audit process information that has been stored on the blockchain is read through the blockchain node interface, including data commitment, verification results, execution proof, transaction hash and timestamp, etc. The information is organized and generated into a structured security audit report according to a preset structure (PDF and JSON, etc.). The report can be directly used for regulatory verification and third-party traceability to ensure the transparency of the audit process and the credibility of the results.
[0043] The compliance data auditing method based on two-way verification proposed in this invention can complete the verification of data integrity and compliance without exposing the original data by performing two-way peer verification. At the same time, it can realize the reverse verification of the audit execution process, thereby achieving higher credibility of compliance auditing.
[0044] like Figure 2 and Figure 3 As shown, a specific implementation example of the above-described method of the present invention includes: Step 1, Audit Initialization: The two parties involved in the audit (data provider A and auditor B) establish an audit session through a two-way verification coordination module; they negotiate audit rules R (such as "verify whether data d is within the range of [0,1000]"), security parameters λ, and compliance conditions. Auditor B uploads the hash value H(R) of audit rule R to the audit rule management contract; Data provider A submits the compliance conditions. hash value Upload to the same contract to ensure consistency between the agreements of both parties.
[0045] Step 2, Data Preprocessing and Evidence Storage: Data provider A preprocesses the raw data d: generates a random blinding factor r, and calculates the commitment. ; and split d into n pieces Set a recovery threshold t; and generate a compliance certificate π to prove that d satisfies the conditions. Data provider A submits commitment C and proof π to the data commitment notarization contract; the contract verifies the validity of proof π, and upon successful verification, stores C and records the notarization timestamp. .
[0046] Step 3, Initiating an Audit Challenge: The two-way verification coordination module generates a random challenge value (based on the on-chain VRF output); the coordination module sends a challenge request to data provider A, requiring it to provide any t data shards for integrity verification; at the same time, the coordination module sends the challenge to the privacy computing verification module, triggering the compliance verification process.
[0047] Step 4, Data provider responds to the challenge: Data provider A selects t shards from n shards based on the challenge value. Data provider A sends the selected t shards to the privacy computing verification module via a secure channel; to prove the authenticity of the shard source, each shard is accompanied by a digital signature.
[0048] Step 5, execute two-way verification: Verification Direction 1: The auditor verifies the compliance and completeness of the data. The privacy-preserving computation verification module performs integrity verification: it verifies the digital signature of each fragment to confirm the authenticity of the source; and it reconstructs the original data using the received t fragments based on Lagrange interpolation. calculate promise The integrity verification is then compared with the on-chain notarized C. If they match, the integrity verification passes. The privacy computation verification module performs compliance verification: based on the Bulletproofs verification protocol, it verifies the validity of the proof π relative to the commitment C; confirmation. Meet the conditions (like The verification module writes the verification result (pass / fail) into the two-way verification execution contract.
[0049] Verification Direction 2: Data side verifies the correctness of audit execution: Auditor B needs to prove to data provider A that audit rule R was correctly executed: the privacy computation verification module generates verifiable computational proof data. Prove that The result of executing R is correct; The generation includes the circuit execution trace of R; data provider A verifies the data using the verification key disclosed by the verification module. The validity of the audit; if the verification is successful, it confirms that the auditor B did indeed perform the audit in accordance with the agreed rule R and did not act maliciously.
[0050] Step 6, Confirmation and Evidence Storage of Audit Results: The two-way verification execution contract collects the results from each verification node. Consensus is reached if more than 2 / 3 of the nodes agree. The contract will audit the final result (pass / fail) and verify the proof data. The hash, challenge value, timestamp, and other information are written into the audit log storage contract; an audit event ID is generated for subsequent traceability and query. Step 7, Audit Report Generation: The audit result traceability module queries on-chain evidence records based on the audit event ID; the module generates a structured audit report, including: Data Commitment C (as a data fingerprint), and compliance conditions. And the corresponding zero-knowledge proof π, the hash of audit rule R, and the proof of its execution. The report includes a list of key transaction hashes throughout the audit process, the final audit conclusions, and consensus signatures. Formatted output, supports third-party validation.
[0051] like Figure 4 As shown, this embodiment of the invention also provides a compliance data audit processing device 40 based on two-way verification, comprising: Processing module 41 is configured to: receive audit rules submitted by the auditor based on the audit session between the data provider and the auditor; receive transaction data submitted by the data provider, wherein the transaction data is encapsulated by the data provider based on the data commitment value and compliance proof generated from the original data; initiate a random challenge to the data provider and synchronize the random challenge value to the data provider and the auditor, so that the data provider sends the target fragment data to the auditor based on the random challenge value, and the auditor verifies the fragment data and transaction data based on the random challenge value to obtain a first verification result, and generates proof data for the execution of the audit rule after the audit rule is executed; receive the first verification result and proof data sent by the auditor, and forward the proof data to the data provider; receive the second verification result obtained and sent by the data provider after verifying the proof data. The generation module 42 is used to perform consensus processing on the first verification result and the second verification result to generate a security audit report.
[0052] Optionally, the data provider, according to Generate data commitment values, where, d represents the data commitment value; g and h are public parameters; d represents the original data; r is the randomization factor; p represents the pre-selected prime modulus; The data provider, according to Generate compliance proof, among which, For compliance proof; This indicates the proof generating function; For compliance private keys; For data commitment values; d represents the preset compliance conditions; r represents the original data; and r represents the randomization factor.
[0053] Optionally, the processing module 41 is specifically used for: calling a verifiable random function on the blockchain to calculate and generate a random challenge value; sending the random challenge value to the data provider and the auditor; enabling the data provider to obtain sharded data based on the random challenge value, the sharded data including a target shard selected from multiple data shards and a digital signature attached to each shard; the multiple data shards being obtained by the data provider dividing the original data; and the auditor triggering a verification process based on the random challenge value and the sharded data.
[0054] Optionally, the processing module 41 is specifically used to: verify the fragmented data and obtain a signature verification result; When the signature verification result is successful, the target fragment in the fragmented data is reconstructed, and the commitment value of the reconstruction result is compared with the data commitment value in the transaction data to obtain the comparison result; If the comparison is successful, the validity of the compliance certificate is verified, and the first verification result is obtained.
[0055] Optionally, processing module 41 is specifically used for: the auditor to... Generate evidentiary data to verify the correctness of the audit execution process; in, This represents the data used to prove the point. Represents a computational function; Indicates the audit private key; Commitment to data; Indicates the hash value of the audit rule; This represents the result of the audit rule execution; R indicates the audit rule code; This represents reconstructed data; r is the randomization blinding factor.
[0056] Optionally, processing module 41 is specifically used for: receiving data from the data provider according to... , The proof data is verified to obtain and send a second verification result; Wherein, result represents the second verification result; This indicates the computation verification function; Indicates the audit public key; For data commitment values; Indicates the hash value of the audit rule; For the results of audit rule execution; This represents the supporting data.
[0057] Optionally, the generation module 42 is specifically used to: determine the final audit result by having multiple nodes vote on the authenticity of the first verification result and the second verification result; and generate a corresponding security audit report based on the final audit result.
[0058] It should be noted that this device is a device corresponding to the above method. All implementation methods in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.
[0059] like Figure 5 As shown, this embodiment of the invention also provides a computing device 50, including a processor 51, a memory 52, and a program or instructions stored in the memory 52 and executable on the processor 51. When the program or instructions are executed by the processor 51, they implement the various processes of the above-described method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here. It should be noted that the computing device in this embodiment of the invention includes the aforementioned mobile electronic devices and non-mobile electronic devices.
[0060] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0061] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0062] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0063] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0064] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0065] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0066] Furthermore, it should be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of the present invention. Moreover, the steps performing the above series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of the present invention can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof. This is something that those skilled in the art can achieve by using their basic programming skills after reading the description of the present invention.
[0067] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing device. The computing device can be a known general-purpose device. Therefore, the object of the present invention can also be achieved simply by providing a program product containing program code for implementing the method or apparatus. That is, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any known storage medium or any storage medium developed in the future. It should also be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent to the present invention. Furthermore, the steps for performing the above series of processes can naturally be performed in the order described, but are not necessarily required to be performed in chronological order. Some steps can be performed in parallel or independently of each other.
[0068] The above are preferred embodiments of the present invention. It should be noted that, for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A compliance data auditing processing method based on two-way verification, characterized in that, Applied to blockchain platforms, including: Based on the audit session between the data provider and the auditor, the system receives audit rules submitted by the auditor; and receives transaction data submitted by the data provider, which is encapsulated by the data provider based on the data commitment value and compliance proof generated from the original data. A random challenge is initiated to the data provider, and the random challenge value is synchronized to the data provider and the auditing party. The data provider sends the target shard data to the auditing party according to the random challenge value. The auditing party verifies the shard data and transaction data according to the random challenge value, obtains a first verification result, and generates proof data that the audit rule has been executed after the audit rule is executed. Receive the first verification result and proof data sent by the auditor, and forward the proof data to the data provider; The data provider verifies the proof data, and obtains and sends a second verification result. Consensus processing is performed on the first verification result and the second verification result to generate a security audit report.
2. The compliance data auditing processing method based on two-way verification according to claim 1, characterized in that, The process by which a data provider generates data commitment values and compliance certificates based on raw data includes: Data provider according to Generate data commitment values, where, d represents the data commitment value; g and h are public parameters; d represents the original data; r is the randomization factor; p represents the pre-selected prime modulus; Data provider according to Generate compliance proof, among which, For compliance proof; This indicates the proof generating function; For compliance private keys; For data commitment values; d represents the preset compliance conditions; r represents the original data; and r represents the randomization factor.
3. The compliance data auditing processing method based on two-way verification according to claim 1, characterized in that, Initiating a random challenge to the data provider and synchronizing the random challenge value to both the data provider and the auditor includes: A verifiable random function on the blockchain is invoked to calculate and generate a random challenge value; The random challenge value is sent to the data provider and the auditor; the data provider obtains sharded data based on the random challenge value, the sharded data includes a target shard selected from multiple data shards and a digital signature attached to each shard; the multiple data shards are obtained by the data provider dividing the original data; the auditor triggers a verification process based on the random challenge value and the sharded data.
4. The compliance data auditing processing method based on two-way verification according to claim 1, characterized in that, The auditor verifies the sharded data and transaction data based on the random challenge value, and obtains a first verification result, including: Verify the fragmented data to obtain the signature verification result; When the signature verification result is successful, the target fragment in the fragmented data is reconstructed, and the commitment value of the reconstruction result is compared with the data commitment value in the transaction data to obtain the comparison result; If the comparison is successful, the validity of the compliance certificate is verified, and the first verification result is obtained.
5. The compliance data auditing processing method based on two-way verification according to claim 1, characterized in that, Generate evidence data proving that the audit rules have been executed, including: The auditor based on Generate evidentiary data to verify the correctness of the audit execution process; in, This represents the data used to prove the point. Represents a computational function; Indicates the audit private key; Commitment to data; Indicates the hash value of the audit rule; This represents the result of the audit rule execution; R indicates the audit rule code; This represents reconstructed data; r is the randomization blinding factor.
6. The compliance data auditing processing method based on two-way verification according to claim 1, characterized in that, The second verification result, obtained and sent by the data provider after verifying the proof data, includes: The receiving data provider according to , The proof data is verified to obtain and send a second verification result; Wherein, result represents the second verification result; This indicates the computation verification function; Indicates the audit public key; For data commitment values; Indicates the hash value of the audit rule; For the results of audit rule execution; This represents the data used to prove the point.
7. The compliance data auditing processing method based on two-way verification according to claim 1, characterized in that, Consensus processing is performed on the first verification result and the second verification result to generate a security audit report, including: The final audit result is determined by having multiple nodes vote on the authenticity of the first verification result and the second verification result; Based on the final audit results, a corresponding security audit report is generated.
8. A compliance data auditing processing device based on two-way verification, characterized in that, include: The processing module is used to receive audit rules submitted by the auditor based on the audit session between the data provider and the auditor; The system also receives transaction data submitted by a data provider, which is encapsulated from a data commitment value and compliance proof generated by the data provider based on the original data; initiates a random challenge to the data provider and synchronizes the random challenge value to both the data provider and the auditor, enabling the data provider to send the target shard data to the auditor based on the random challenge value. The auditor then verifies the shard data and transaction data based on the random challenge value, obtains a first verification result, and generates proof data indicating that the audit rule has been executed after the audit rule is executed; and receives the first verification result and proof data sent by the auditor, and forwards the proof data to the data provider. The data provider verifies the proof data, and obtains and sends a second verification result. The generation module is used to perform consensus processing on the first verification result and the second verification result to generate a security audit report.
9. A computing device, characterized in that, include: A processor, a memory storing a computer program, wherein the computer program, when executed by the processor, performs the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The system stores instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1 to 7.