Audit log verification method and device, equipment, storage medium and program product

CN122490515BActive Publication Date: 2026-09-08CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610953597.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-06-30
Publication Date
2026-09-08
Estimated Expiration
2046-06-30

AI Technical Summary

Technical Problem

[0007]本申请实施例提供一种审计日志的校验方法、装置、设备、存储介质和程序产品,用以解决现有的对审计日志文件进行校验的方法具有审计证据持久性差、审计追溯的连续性差的问题

Benefits of technology

本申请方案提供的审计日志的校验方法,由第一设备根据审计日志,生成校验文件,所述校验文件存储有所述审计日志的第一哈希校验值,根据审计日志文件和校验文件对所述审计日志进行第一次校验,得到所述审计日志的第一次校验结果,在所述第一次校验结果指示所述审计日志校验失败的情况下,获取备份存储的备份审计日志文件和备份校验文件;其中,所述备份审计日志文件存储有所述审计日志,所述备份校验文件存储有所述审计日志的第一哈希校验值,根据所述备份审计日志文件和所述备份校验文件,对所述审计日志进行第二次校验,得到所述审计日志的第二次校验结果,即本实施例中,在第一次校验失败的情况下,通过备份审计日志文件和备份校验文件进行第二次校验,保障了审计追溯的持续性,并且通过备份审计日志文件备份保存审计日志、通过备份校验文件备份保存审计日志的第一哈希校验值,提高审计证据的持久性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122490515B_ABST
    Figure CN122490515B_ABST
Patent Text Reader

Abstract

The application discloses an audit log verification method and device, equipment, a storage medium and a program product, and belongs to the technical field of big data. The audit log verification method comprises the following steps: generating a verification file according to an audit log, wherein the verification file stores a first hash check value of the audit log; performing first verification on the audit log according to an audit log file and the verification file, and obtaining a first verification result of the audit log, wherein the audit log file stores the audit log; in the case that the first verification result indicates that the audit log fails to pass the verification, obtaining a backup audit log file and a backup verification file which are stored in backup; performing second verification on the audit log according to the backup audit log file and the backup verification file, and obtaining a second verification result of the audit log. The application guarantees the continuity of audit tracing, and improves the durability of audit evidence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of big data technology, specifically relating to a method, apparatus, device, storage medium, and program product for verifying audit logs. Background Technology

[0002] Database audit logs are structured log data that record all sensitive operations in a database system. Sensitive operations include, but are not limited to, user login / logout, data query, data modification, permission changes, and Data Definition Language (DDL) operations.

[0003] Audit logs are a core component of database security systems, with primary functions including: tracing actions, ensuring compliance, and providing risk warnings. Tracing actions refers to reconstructing the operational chain and identifying responsible parties after a data breach, misoperation, or malicious attack. Ensuring compliance means that audit logs meet the mandatory legal requirements of "operation traceability and non-repudiation." Providing risk warnings involves analyzing abnormal patterns in audit logs to prevent incidents during the event or issue alerts afterward.

[0004] In enterprise-level database systems, audit logs are typically stored persistently in the form of text files, database tables, or dedicated log services, and can be retrieved and exported by time, user, operation type, and other dimensions.

[0005] While audit logs play a crucial role in security systems, their integrity and reliability face serious challenges, including internal threats and external attacks. Internal threats include high-privilege database administrators (DBAs) or system administrators potentially tampering with or deleting audit logs to cover up unauthorized operations. External attacks include attackers who, after compromising the database host, often prioritize deleting audit logs to destroy evidence. If audit logs can be tampered with or deleted, they lack legal validity in judicial evidence collection, liability determination, and compliance audits.

[0006] Therefore, verifying audit log files to ensure their tamper-proof nature is a prerequisite for building a trusted database security system. However, existing methods for verifying audit log files suffer from poor persistence of audit evidence and poor continuity of audit traceability. Summary of the Invention

[0007] This application provides a method, apparatus, device, storage medium, and program product for verifying audit logs, in order to solve the problems of poor persistence of audit evidence and poor continuity of audit traceability in existing methods for verifying audit log files.

[0008] Firstly, this application provides a method for verifying audit logs, executed by a first device, the method comprising: Based on the audit log, a verification file is generated, which stores the first hash verification value of the audit log. The audit log is first verified based on the audit log file and the verification file to obtain the first verification result of the audit log, wherein the audit log file stores the audit log; If the first verification result indicates that the audit log verification failed, the backup audit log file and the backup verification file stored in the backup are obtained; wherein, the backup audit log file stores the audit log, and the backup verification file stores the first hash verification value of the audit log; Based on the backup audit log file and the backup verification file, the audit log is verified a second time to obtain the second verification result of the audit log.

[0009] Optionally, the step of generating a verification file based on the audit log, wherein the verification file stores a first hash verification value of the audit log, includes: If the audit log is the first audit log in the audit log file, the first hash check value of the audit log is obtained using a hash function, and the first hash check value of the audit log is written into the check file; When the audit log is any audit log other than the first audit log in the audit log file, a hash function is used to obtain the first hash verification value of the first audit log based on the second hash verification value and the first audit log, and the first hash verification value of the first audit log is written into the verification file; wherein, the first audit log is any audit log other than the first audit log in the audit log file, the second hash verification value is the hash verification value of the second audit log, and the second audit log is the audit log adjacent to the first audit log in the audit log file.

[0010] Optionally, the audit log file and the verification file satisfy at least one of the following: The audit log file and the verification file are physically isolated from each other. The audit log file and the verification file are isolated via a system path; The audit log file and the verification file have independent access control permissions.

[0011] Optionally, the step of performing a first verification of the audit log based on the audit log file and the verification file to obtain the first verification result of the audit log includes: Based on the first audit log in the audit log file and the first hash check value in the verification file, perform a hash check on the first audit log in the audit log to obtain the first verification result of the first audit log in the audit log file; The first verification result of the nth audit log in the audit log file is obtained based on the nth first hash check value in the verification file and the (n-1)th first hash check value in the verification file, where n is an integer greater than 1.

[0012] Optionally, the step of performing a hash check on the first audit log in the audit log file based on the first audit log in the audit log file and the first hash check value in the check file to obtain the first check result of the first audit log in the audit log file includes: Using a hash function, a third hash verification value corresponding to the first audit log is obtained; if the first hash verification value is equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has been successfully verified; if the first hash verification value is not equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has failed to be verified. And / or, Based on the nth audit log in the audit log file, the nth first hash check value in the verification file, and the (n-1)th first hash check value in the verification file, the first verification result of the nth audit log in the audit log file is obtained, including: Using a hash function, a fourth hash verification value is obtained corresponding to the nth audit log based on the nth audit log in the audit log file and the (n-1)th first hash verification value in the verification file. If the nth first hash verification value is equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has been successfully verified. If the nth first hash verification value is not equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has failed to be verified.

[0013] Optionally, the step of performing a first verification of the audit log based on the audit log file and the verification file to obtain the first verification result of the audit log includes: The audit logs are counted based on the number of audit logs in the audit log file and the number of first hash check values ​​in the check file to obtain the first check result of the audit logs.

[0014] Optionally, the backup audit log file is stored locally on the first device or on the second device; And / or, The backup verification file is stored locally on the first device or on the second device.

[0015] Secondly, embodiments of this application also provide an audit log verification device, the device comprising: The first processing module is used to generate a verification file based on the audit log, wherein the verification file stores the first hash verification value of the audit log; The second processing module is used to perform a first verification on the audit log based on the audit log file and the verification file, and obtain the first verification result of the audit log, wherein the audit log file stores the audit log; The third processing module is used to obtain a backup audit log file and a backup verification file stored in the backup storage when the first verification result indicates that the audit log verification has failed; wherein, the backup audit log file stores the audit log, and the backup verification file stores the first hash verification value of the audit log; The fourth processing module is used to perform a second verification on the audit log based on the backup audit log file and the backup verification file, and obtain the second verification result of the audit log.

[0016] Thirdly, embodiments of this application also provide an electronic device, including: a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, it implements the steps in the audit log verification method as described in any one of the first aspects.

[0017] Fourthly, embodiments of this application also provide a readable storage medium storing a program that, when executed by a processor, implements the steps in the audit log verification method as described in any one of the first aspects.

[0018] Fifthly, embodiments of this application also provide a computer program product, including computer instructions, which, when executed by a processor, implement the steps in the audit log verification method as described in any one of the first aspects.

[0019] The beneficial effects of this application are: The audit log verification method provided in this application involves a first device generating a verification file based on the audit log. The verification file stores a first hash verification value of the audit log. The audit log is then verified using the audit log file and the verification file to obtain a first verification result. If the first verification result indicates that the audit log verification failed, a backup audit log file and a backup verification file are retrieved. The backup audit log file stores the audit log, and the backup verification file stores the first hash verification value of the audit log. A second verification is then performed on the audit log based on the backup audit log file and the backup verification file to obtain a second verification result. In this embodiment, in the event of a first verification failure, a second verification is performed using the backup audit log file and the backup verification file, ensuring the continuity of audit traceability. Furthermore, the backup audit log file and the backup verification file both store the first hash verification value of the audit log, improving the durability of audit evidence. Attached Figure Description

[0020] Figure 1 This is a flowchart of the audit log verification method provided in the embodiments of this application; Figure 2 This is a schematic diagram illustrating the calculation process of the first hash check value of the first audit log provided in an embodiment of this application; Figure 3 This is an overall flowchart of the audit log verification method provided in the embodiments of this application; Figure 4 This is a schematic diagram of the structure of the audit log verification device provided in the embodiments of this application; Figure 5 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0021] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0022] In the following description, specific details such as particular configurations and components are provided merely to aid in a comprehensive understanding of the embodiments of this application. Therefore, those skilled in the art will understand that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Furthermore, for clarity and brevity, descriptions of known functions and constructions have been omitted.

[0023] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.

[0024] In the various embodiments of this application, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0025] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and are not used to describe a specified order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, a first object can be one or more. Furthermore, in the specification and claims, "and" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0026] Furthermore, the "or" in this application indicates at least one of the connected objects. For example, "A or B" covers three scenarios: Scenario 1: includes A but excludes B; Scenario 2: includes B but excludes A; Scenario 3: includes both A and B. The character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0027] The term "instruction" in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction). A direct instruction can be understood as one in which the sender explicitly informs the receiver of specific information, the operation to be performed, or the requested result, etc., in the instruction sent. An indirect instruction can be understood as one in which the receiver determines the corresponding information based on the instruction sent by the sender, or makes a judgment and determines the operation to be performed or the requested result, etc., based on the judgment result.

[0028] Before describing the specific implementation methods of this application, the following will be explained first: In existing technologies, the following methods are used to prevent audit logs from being tampered with: Relying on proprietary hardware: Providing physical or firmware-level tamper protection through proprietary hardware, such as independent audit servers, write-once-read-many (WORM) data tape storage devices, etc.

[0029] Digital signatures: Periodically or in batches, digitally sign audit log files (e.g., using Rivest–Shamir–Adleman (RSA) / Elliptic Curve Digital Signature Algorithm (ECDSA) private key signatures, or using RSA / ECDSA public key verification), and recalculate the hash and compare it with the signature during verification.

[0030] Blockchain / distributed ledger technology: Each audit log entry is submitted as a "transaction" to a consortium blockchain or private blockchain, using consensus mechanisms and hash chain structures to ensure immutability.

[0031] The existing technology has the following limitations: Relying on proprietary hardware: Providing physical or firmware-level tamper protection through proprietary hardware can guarantee physical tamper protection and meet high compliance requirements. However, it is costly, has a highly invasive architecture (requiring modification of the existing database deployment architecture), poor flexibility, and can easily become a bottleneck for audit log writing.

[0032] Digital signatures: Audit log files are digitally signed periodically or in batches. During verification, the hash is recalculated and compared with the signature to verify the integrity of the content and support legal validity. However, the granularity is coarse, usually signing the entire file, making it impossible to pinpoint which specific record has been tampered with; the real-time performance is poor, as signing is usually performed asynchronously, and tampering may occur before signing; key management is complex, and preventing leakage is costly.

[0033] Blockchain / distributed ledger technology: Each audit log entry is submitted as a "transaction" to a consortium blockchain or private blockchain, utilizing consensus mechanisms and hash chain structures to ensure immutability. This approach incurs significant performance overhead; the consensus process and on-chain latency impact database real-time performance; the architecture is complex, requiring the deployment of independent blockchain nodes, resulting in high operational costs; furthermore, for tamper-proof scenarios within a single machine or cluster, it suffers from high redundancy and over-design.

[0034] To address the problems of poor audit evidence persistence and poor audit traceability in existing methods for verifying audit log files, embodiments of this application provide an audit log verification method, apparatus, device, storage medium, and program product.

[0035] like Figure 1 As shown in the figure, this application embodiment provides a method for verifying audit logs, executed by a first device, the method including: Step 101: Generate a verification file based on the audit log, wherein the verification file stores the first hash verification value of the audit log.

[0036] In the embodiments of this application, the first device may be referred to or understood as a data node, or the first device may be referred to or understood as a coordinator.

[0037] In this step, based on the audit log, a first hash checksum of the audit log is generated, and a separate checksum file (e.g., named audit.log.checksum) is designed. The first hash checksum is then written into this separate checksum file.

[0038] Specifically, when the database kernel of the first device performs sensitive operations, it generates structured audit logs (or audit log entries) in real time. The audit logs include at least one of the following key fields: operation time, user, client Internet Protocol (IP), Structured Query Language (SQL) statement, and number of rows affected.

[0039] The generated audit logs (or audit log entries) are written to the audit log file (e.g., the file name is audit.log).

[0040] When writing audit logs to the audit log file, the first hash check value of the audit log is calculated in real time, and the first hash check value of the audit log is stored in a separate check file.

[0041] For example, sensitive operations include at least one of the following: Data Definition Language (DDL), Data Manipulation Language (DML), login, and logout.

[0042] Step 102: Perform the first verification on the audit log based on the audit log file and the verification file to obtain the first verification result of the audit log, wherein the audit log file stores the audit log.

[0043] Optionally, in this embodiment, the first hash checksum of the audit log stored in the audit log file corresponds to the first hash checksum of the audit log stored in the verification file. For example, the m-th (or m-th entry) first hash checksum in the verification file is the first hash checksum corresponding to the m-th audit log stored in the audit log file, where m is a positive integer.

[0044] In this step, the audit log is first verified based on the audit log file and the verification file to obtain the first verification result of the audit log. This first verification result is used to indicate whether the audit log verification was successful or failed.

[0045] Step 103: If the first verification result indicates that the audit log verification failed, obtain the backup audit log file and the backup verification file stored in the backup storage; wherein, the backup audit log file stores the audit log, and the backup verification file stores the first hash verification value of the audit log.

[0046] Optionally, after the first device generates the audit log file and the verification file, the two are automatically backed up to obtain a backup audit log file and a backup verification file stored in the backup.

[0047] In one alternative embodiment, for example, the audit log file is copied to obtain a backup audit log file, and the verification file is copied to obtain a backup verification file.

[0048] In another optional embodiment, while storing the audit log to the audit log file in the manner described above, the audit log is also stored to the backup audit log file in the same manner. Furthermore, while storing the first hash value of the audit log to the verification file in the manner described above, the first hash value of the audit log is also stored to the backup verification file in the same manner described above.

[0049] Optionally, the audit logs stored in the backup audit log file correspond to the first hash checksums of the audit logs stored in the backup verification file. For example, the m-th (or m-th entry) first hash checksum in the backup verification file is the first hash checksum corresponding to the m-th audit log stored in the backup audit log file, where m is a positive integer.

[0050] In this embodiment of the application, if the first verification result indicates that the audit log verification has failed, the backup audit log file and the backup verification file are obtained (or understood as automatically restoring the audit log file and the verification file).

[0051] Step 104: Perform a second verification on the audit log based on the backup audit log file and the backup verification file to obtain the second verification result of the audit log.

[0052] In this embodiment of the application, if the first verification result indicates that the audit log verification is successful, the audit log is verified a second time (or re-verified or re-verified) using the backup audit log file and the backup verification file to obtain the second verification result of the audit log (or re-verified result or re-verified result).

[0053] In this embodiment of the application, the method further includes: determining the final verification result of the audit log based on the second verification result of the audit log, that is, determining whether the audit log is secure, complete, or tampered with based on the second verification result of the audit log.

[0054] In this embodiment of the application, the method further includes: if the first verification result indicates that the audit log verification is successful, determining that the audit log verification is successful, that is, the audit log can be considered to be safe, complete, or that the audit log has not been tampered with.

[0055] In this embodiment of the application, if the first verification fails, a second verification is performed by backing up the audit log file and the backup verification file, which ensures the continuity of audit traceability. Furthermore, the first hash verification value of the audit log is backed up and saved by backing up the audit log file and the first hash verification value of the audit log, thereby improving the durability of audit evidence.

[0056] In some embodiments of this application, generating a verification file based on the audit log, wherein the verification file stores a first hash verification value of the audit log, includes: If the audit log is the first audit log in the audit log file, a first hash check value of the audit log is obtained using a hash function, and the first hash check value of the audit log is written into the check file.

[0057] Optionally, the hash function includes at least one of the following: SM3 cryptographic hash algorithm (abbreviated as SM3); Secure Hash Algorithm 256-bit (SHA-256).

[0058] Specifically, in this embodiment, for the first audit log (or the first audit log) in the audit log file, a hash function is used to calculate the first hash verification value of the first audit log (or the first audit log), and the first hash verification value of the first audit log (or the first hash verification value of the first audit log) is written into a verification file. Optionally, the first hash verification value of the first audit log (or the first hash verification value of the first audit log) is written into a backup verification file.

[0059] When the audit log is any audit log other than the first audit log in the audit log file, a hash function is used to obtain the first hash verification value of the first audit log based on the second hash verification value and the first audit log, and the first hash verification value of the first audit log is written into the verification file; wherein, the first audit log is any audit log other than the first audit log in the audit log file, the second hash verification value is the hash verification value of the second audit log, and the second audit log is the audit log adjacent to the first audit log in the audit log file.

[0060] The second audit log is the audit log file that is adjacent to the first audit log. It can be understood that the first audit log and the second audit log belong to the same audit log file, the second audit log is the audit log that precedes the first audit log, and the second audit log is adjacent to the first audit log.

[0061] Optionally, the hash function includes at least one of the following: SM3 cryptographic hash algorithm (abbreviated as SM3); Secure hash algorithm 256 (SHA-256).

[0062] Specifically, for the calculation process of the first hash checksum of the first audit log, please refer to... Figure 2 In this embodiment, the calculation method for the hash value of the chained structure for audit logs other than the first audit log in the audit log file is exemplarily shown in the following formula:

[0063] in, This refers to the nth (or nth) audit log entry in the audit log file. This represents the first hash checksum of the nth audit log. This represents the hash check value of the previous (n-1th, or n-1th) audit log (i.e., the first hash check value of the second audit log). This indicates a splicing operation. This indicates the selected hash checksum generation function (i.e., hash function), such as SM3, SHA-256, etc.

[0064] In this embodiment of the application, the first hash verification value can also be referred to as the first hash chain verification value.

[0065] After calculating the first hash check value of the first audit log, the first hash check value of the first audit log is written to the check file. Optionally, the first hash check value of the first audit log is written to the backup check file.

[0066] In some embodiments of this application, the audit log file and the verification file satisfy at least one of the following A, B, and C: A. The audit log file and the verification file are data isolated through physical devices, that is, the audit log file and the verification file are path-isolated; B. The audit log file and the verification file are isolated through a system path, that is, the audit log file and the verification file are physically separated; C. The audit log file and the verification file have independent access control permissions, that is, the audit log file and the verification file have independent permissions (set independent access permissions).

[0067] In some embodiments of this application, the backup audit log file is stored locally on the first device or stored on a second device; And / or, The backup verification file is stored locally on the first device or on the second device.

[0068] The second device can also be referred to as or understood as a backup node or other node.

[0069] In an optional embodiment of this application, in a distributed database environment, a second device can be introduced to back up the audit log file and / or verification file. The first device generates a local audit log file and a verification file, and the audit log file and / or verification file are synchronized (or backed up) to the second device through a secure channel.

[0070] In another optional embodiment of this application, audit log files and / or backup verification files can also be backed up in the first device, that is, the audit log files and / or backup verification files are locally backed up in the first device.

[0071] In another optional embodiment of this application, audit log files and / or backup verification files can be backed up in both the first device and the second device. That is, the audit log files and / or backup verification files are stored locally on the first device and are also stored in the second device.

[0072] Optionally, in this embodiment, the backup audit log file and the backup verification file also satisfy at least one of A, B, and C above. That is, they satisfy at least one of the following: Backup audit log files and backup verification files are isolated from each other through physical devices, meaning that backup audit log files and backup verification files are path-isolated. Backup audit log files and backup verification files are isolated through system paths, meaning they are physically separated. The backup audit log file and the backup verification file have independent access control permissions, meaning that the backup audit log file and the backup verification file have independent permissions (set independent access permissions).

[0073] In this embodiment, the audit log is backed up using a second device, and the verification file is backed up using a verification file. Even if the disk of the first device fails or is maliciously wiped, the complete audit evidence chain can still be restored from the second device, thus preventing loss. Furthermore, the multi-node evidence storage forms a "distributed evidence chain," enhancing legal validity and preventing repudiation. During the verification process, if the first verification fails, the backup audit log file and the verification file can be obtained or read from the second device for a second verification, avoiding single-point verification bottlenecks.

[0074] In some embodiments of this application, the step of performing a first verification of the audit log based on the audit log file and the verification file to obtain the first verification result of the audit log includes: Based on the first audit log in the audit log file and the first hash check value in the verification file, perform a hash check on the first audit log in the audit log to obtain the first verification result of the first audit log in the audit log file.

[0075] In this embodiment, during verification, the first device provides an integrity verification interface (interface name, for example: verify_audit_log(start_time, end_time, ...)) as needed or periodically for verification. During the first verification, the audit logs in the audit log file are read one by one. That is, for each audit log file, the audit logs are checked and compared one by one from the beginning.

[0076] In an optional embodiment, the step of performing a hash check on the first audit log in the audit log file based on the first audit log in the audit log file and the first hash check value in the check file to obtain the first check result of the first audit log in the audit log file includes: Using a hash function, a third hash verification value corresponding to the first audit log is obtained; if the first hash verification value is equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has been successfully verified; if the first hash verification value is not equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has failed to be verified.

[0077] Specifically, based on the first hash verification value in the first audit log and the first audit log file, a hash verification is performed on the first audit log in the audit log to obtain the first verification result of the first audit log in the audit log file.

[0078] When the hash function is used to perform a hash calculation on the first audit log to obtain the calculated third hash verification value, if the calculated third hash verification value is equal to the first first hash verification value in the verification file, then the first verification result of the first audit log is considered to indicate that the verification was successful. If the calculated third hash verification value is not equal to the first first hash verification value in the verification file, then the first verification result of the first audit log is considered to indicate that the verification failed.

[0079] In some embodiments of this application, the step of performing a first verification of the audit log based on the audit log file and the verification file to obtain the first verification result of the audit log includes: The first verification result of the nth audit log in the audit log file is obtained based on the nth first hash check value in the verification file and the (n-1)th first hash check value in the verification file, where n is an integer greater than 1.

[0080] In this embodiment, when verifying audit logs other than the first audit log, the verification is performed based on the nth audit log, the nth first hash verification value, and the (n-1)th first hash verification value.

[0081] In an optional embodiment, the first verification result of the nth audit log in the audit log file is obtained based on the nth audit log in the audit log file, the nth first hash check value in the verification file, and the (n-1)th first hash check value in the verification file, including: Using a hash function, a fourth hash verification value is obtained corresponding to the nth audit log based on the nth audit log in the audit log file and the (n-1)th first hash verification value in the verification file. If the nth first hash verification value is equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has been successfully verified. If the nth first hash verification value is not equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has failed to be verified.

[0082] Specifically, the formula for the first verification of the nth audit log is as follows:

[0083] in, This represents the nth (or nth) audit log entry. This represents the first hash checksum of the nth (or nth) audit log entry. This is the first hash checksum of the previous (n-1th, or n-1th) audit log entry. This indicates a splicing operation. This represents the corresponding hash checksum verification function, and the result of the first verification, including success or failure. During verification, the hash checksum is... "call" Generate a fourth hash check value and combine it with... The comparison is performed; if they are completely identical, the verification is successful; otherwise, the verification fails. If any verification fails, the audit log entry is considered to have been tampered with.

[0084] In some embodiments of this application, the step of performing a first verification of the audit log based on the audit log file and the verification file to obtain a first verification result of the audit log includes: The audit logs are counted based on the number of audit logs in the audit log file and the number of first hash check values ​​in the check file to obtain the first check result of the audit logs.

[0085] In this embodiment, if a discrepancy in the number of records is detected between the audit log file and the verification file (i.e., the number of audit logs in the audit log file is not equal to the number of first hash checksums in the verification file), it is assumed that the audit logs have been added or deleted, and the integrity verification of the audit logs fails, resulting in the first verification result of the audit logs, which indicates a verification failure. If a discrepancy in the number of records is detected between the audit log file and the verification file (i.e., the number of audit logs in the audit log file is equal to the number of first hash checksums in the verification file), the first verification result of the audit logs is obtained, which indicates a successful verification.

[0086] In this embodiment of the application, even if an attacker deletes several audit log records at the end of the audit log file, since the verification file still retains a complete sequence of first hash verification values, the inconsistency can be found by comparing the "length of the first hash value in the verification file" with the "actual number of records in the audit log file" during verification, thereby accurately identifying the deletion behavior at the end and completely solving the "end blind spot" problem of traditional hash chains.

[0087] It should be noted that the method described in this application embodiment further includes: generating alarm information when the first verification result indicates that the verification has failed, such as through log recording or email notification.

[0088] The following is combined with Figure 3 This application describes in detail the complete process of the audit log verification method provided in the embodiments, including: Step 301: Obtain the verification request, then proceed to step 302; Step 302: Read the audit log file, then proceed to step 303; Step 303: Read the verification file corresponding to the audit log file, and then proceed to step 304; Step 304: Determine whether the audit logs in the audit log file have been completely read. If yes, proceed to step 305; otherwise, proceed to step 309. Step 305: Determine whether the first hash check value in the verification file has been read. If yes, proceed to step 306; otherwise, proceed to step 307. Step 306: Determine whether all audit log files have been read. If yes, confirm successful verification; otherwise, return to step 302. Step 307: Trigger an alarm, then proceed to step 308; Step 309: Read the audit log, then proceed to step 310; Step 310: Read the first hash check value, then proceed to step 311; Step 311: Determine whether the audit log read in step 309 is the first audit log. If not, proceed to step 312; if yes, proceed to step 313. Step 312: Concatenate the audit log read by 309 with the previous first hash check value, and then execute step 313; Step 313: Generate a hash verification value using a hash function, then proceed to step 314; Step 314: Based on the hash verification value generated in step 313 and the first hash verification value read in step 310, determine whether the verification was successful. If yes, return to step 304; otherwise, proceed to step 307. Step 308: Determine whether to obtain the backup file. The backup file includes the backup audit log file and the backup verification file. If not, determine that the verification failed. If yes, proceed to step 315. Step 315: Obtain the backup files, which include the backup audit log file and the backup verification file. Then proceed to step 316. Step 316: Perform a second verification based on the backup audit log file and backup verification file, then return to step 302.

[0089] The audit log verification method provided in this application adopts file-level hash chain verification to ensure high integrity and immutability of audit files, while maintaining the independence of individual audit files and providing strong operational flexibility. It also physically separates the original audit log text from the hash chain verification value for storage, preventing the audit file from being truncated at the end, thus solving the inherent defect of hash chain technology—the inability to defend against end-deletion—and preventing the audit file from being deleted from the end. In a distributed database environment, a cross-node automatic backup mechanism is further introduced, automatically synchronizing the local audit log file and verification file to at least one other node or a dedicated backup node through a secure channel, achieving collaborative automatic backup of audit files and verification files in the distributed cluster. During verification, if any verification failure occurs, an alarm is triggered, and the audit log file is automatically restored from the audit log file backup (local backup or remote node backup) and re-verified, thereby constructing a four-in-one anti-tampering system of "data-verification-backup-recovery". It does not require proprietary hardware devices, does not rely on external systems, and is a lightweight, highly secure, and database kernel-integrated audit log anti-tampering method. This application takes into account integrity, immutability, automatic recovery, loss prevention, and adaptability to distributed environments, and is suitable for various deployment scenarios such as single machine, master-slave, and distributed database clusters.

[0090] This application can quickly restore trusted data without manual intervention when logs are abnormal or tampered with, which not only ensures the continuity of audit traceability, but also significantly reduces operation and maintenance costs and response delays.

[0091] Specifically, this application utilizes file-level hash chain verification to ensure high integrity and immutability of audit files while maintaining the independence of individual audit files, resulting in strong operational flexibility. By storing verification files independently, it achieves precise defense against "end-of-file deletion" attacks, overcoming the structural defects of traditional hash chain technology. It implements collaborative automatic backup of "audit files + verification files" in a distributed database cluster, ensuring the persistence and high availability of audit evidence and meeting compliance requirements in scenarios such as finance and government. It provides an automatic recovery mechanism for audit log files; in the event of verification failure, the audit log files can be automatically restored from local backups or remote node backups and re-verified, ensuring the continuity of audit traceability while significantly reducing operational costs and response latency. It is implemented purely in software, with database kernel integration, requiring no proprietary hardware (such as WORM, audit servers, etc.) or external blockchain systems (such as Fabric), resulting in low deployment costs and compatibility with existing database architectures, making it particularly suitable for cloud-native and SME environments.

[0092] like Figure 4 As shown in the figure, this application embodiment also provides an audit log verification device, the device comprising: The first processing module 401 is used to generate a verification file based on the audit log, wherein the verification file stores the first hash verification value of the audit log; The second processing module 402 is used to perform a first verification on the audit log based on the audit log file and the verification file, and obtain the first verification result of the audit log, wherein the audit log file stores the audit log; The third processing module 403 is used to obtain a backup audit log file and a backup verification file stored in the backup storage when the first verification result indicates that the audit log verification has failed; wherein, the backup audit log file stores the audit log, and the backup verification file stores the first hash verification value of the audit log; The fourth processing module 404 is used to perform a second verification on the audit log based on the backup audit log file and the backup verification file, and obtain the second verification result of the audit log.

[0093] Optionally, the first processing module 401 includes: The first processing unit is configured to, when the audit log is the first audit log in the audit log file, use a hash function to obtain a first hash verification value of the audit log, and write the first hash verification value of the audit log into the verification file. The second processing unit is configured to, when the audit log is any audit log other than the first audit log in the audit log file, use a hash function to obtain a first hash verification value of the first audit log based on a second hash verification value and the first audit log, and write the first hash verification value of the first audit log into the verification file; wherein, the first audit log is any audit log other than the first audit log in the audit log file, the second hash verification value is the hash verification value of the second audit log, and the second audit log is the audit log in the audit log file that is adjacent to the first audit log.

[0094] Optionally, the audit log file and the verification file satisfy at least one of the following: The audit log file and the verification file are physically isolated from each other. The audit log file and the verification file are isolated via a system path; The audit log file and the verification file have independent access control permissions.

[0095] Optionally, the second processing module 402 includes: The third processing unit is used to perform hash verification on the first audit log in the audit log file based on the first audit log in the audit log file and the first first hash verification value in the verification file, so as to obtain the first verification result of the first audit log in the audit log file. The fourth processing unit is used to obtain the first verification result of the nth audit log in the audit log file based on the nth audit log in the audit log file, the nth first hash verification value in the verification file, and the (n-1)th first hash verification value in the verification file, where n is an integer greater than 1.

[0096] Optionally, the third processing unit is specifically used for: Using a hash function, a third hash verification value corresponding to the first audit log is obtained; if the first hash verification value is equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has been successfully verified; if the first hash verification value is not equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has failed to be verified. And / or, The fourth processing unit is specifically used for: Using a hash function, a fourth hash verification value is obtained corresponding to the nth audit log based on the nth audit log in the audit log file and the (n-1)th first hash verification value in the verification file. If the nth first hash verification value is equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has been successfully verified. If the nth first hash verification value is not equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has failed to be verified.

[0097] Optionally, the second processing module 402 includes: The fifth processing unit is used to perform quantity verification on the audit logs based on the number of audit logs in the audit log file and the number of first hash check values ​​in the verification file, and obtain the first verification result of the audit logs.

[0098] Optionally, the backup audit log file is stored locally on the first device or on the second device; And / or, The backup verification file is stored locally on the first device or on the second device.

[0099] It should be noted that the audit log verification device provided in this application embodiment is a device capable of executing the above-described audit log verification method. Therefore, all embodiments of the above-described audit log verification method are applicable to this device and can achieve the same or similar technical effects.

[0100] like Figure 5 As shown in the figure, this application embodiment also provides an electronic device, including: a processor 501; and a memory 503 connected to the processor 501 via a bus interface 502, the memory 503 being used to store programs and data used by the processor 501 when performing operations, and the processor 501 calling and executing the programs and data stored in the memory 503.

[0101] The transceiver 504 is connected to the bus interface 502 and is used to receive and send data under the control of the processor 501. Specifically, the processor 501 is used to read the program in the memory 503 and to execute the following processes: Based on the audit log, a verification file is generated, which stores the first hash verification value of the audit log. The audit log is first verified based on the audit log file and the verification file to obtain the first verification result of the audit log, wherein the audit log file stores the audit log; If the first verification result indicates that the audit log verification failed, the backup audit log file and the backup verification file stored in the backup are obtained; wherein, the backup audit log file stores the audit log, and the backup verification file stores the first hash verification value of the audit log; Based on the backup audit log file and the backup verification file, the audit log is verified a second time to obtain the second verification result of the audit log.

[0102] Optionally, the processor 501 is used for: If the audit log is the first audit log in the audit log file, the first hash check value of the audit log is obtained using a hash function, and the first hash check value of the audit log is written into the check file; When the audit log is any audit log other than the first audit log in the audit log file, a hash function is used to obtain the first hash verification value of the first audit log based on the second hash verification value and the first audit log, and the first hash verification value of the first audit log is written into the verification file; wherein, the first audit log is any audit log other than the first audit log in the audit log file, the second hash verification value is the hash verification value of the second audit log, and the second audit log is the audit log adjacent to the first audit log in the audit log file.

[0103] Optionally, the audit log file and the verification file satisfy at least one of the following: The audit log file and the verification file are physically isolated from each other. The audit log file and the verification file are isolated via a system path; The audit log file and the verification file have independent access control permissions.

[0104] Optionally, the processor 501 is used for: Based on the first audit log in the audit log file and the first hash check value in the verification file, perform a hash check on the first audit log in the audit log to obtain the first verification result of the first audit log in the audit log file; The first verification result of the nth audit log in the audit log file is obtained based on the nth first hash check value in the verification file and the (n-1)th first hash check value in the verification file, where n is an integer greater than 1.

[0105] Optionally, the processor 501 is specifically used for: Using a hash function, a third hash verification value corresponding to the first audit log is obtained; if the first hash verification value is equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has been successfully verified; if the first hash verification value is not equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has failed to be verified. And / or, Using a hash function, a fourth hash verification value is obtained corresponding to the nth audit log based on the nth audit log in the audit log file and the (n-1)th first hash verification value in the verification file. If the nth first hash verification value is equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has been successfully verified. If the nth first hash verification value is not equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has failed to be verified.

[0106] Optionally, the processor 501 is used for: The audit logs are counted based on the number of audit logs in the audit log file and the number of first hash check values ​​in the check file to obtain the first check result of the audit logs.

[0107] Optionally, the backup audit log file is stored locally on the first device or on the second device; And / or, The backup verification file is stored locally on the first device or on the second device.

[0108] Among them, Figure 5 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 501) and memory (memory 503). The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides a user interface 505. A transceiver 504 may be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over a transmission medium. Processor 501 is responsible for managing the bus architecture and general processing, and memory 503 may store data used by processor 501 during operation.

[0109] In addition, specific embodiments of this application also provide a readable storage medium having a computer program stored thereon, wherein when the program is executed by a processor, it implements the steps in the audit log verification method as described above.

[0110] In the several embodiments provided in this application, it should be understood that the disclosed methods and apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0111] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can be physically included separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0112] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions that cause a computer device (which may be a personal computer, server, or network device, etc.) to execute partial steps of the resource selection method described in the various embodiments of this application, or to execute partial steps of the information transmission method described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0113] A specific embodiment of this application also provides a computer program product, including computer instructions, which, when executed by a processor, implement the above-described functionality. Figure 1 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.

[0114] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. A method for verifying audit logs, characterized in that, Performed by a first device, the method includes: Based on the audit log, a verification file is generated, which stores the first hash verification value of the audit log. The audit log is first verified based on the audit log file and the verification file to obtain the first verification result of the audit log, wherein the audit log file stores the audit log; If the first verification result indicates that the audit log verification failed, the backup audit log file and the backup verification file stored in the backup are obtained; wherein, the backup audit log file stores the audit log, and the backup verification file stores the first hash verification value of the audit log; Based on the backup audit log file and the backup verification file, the audit log is verified a second time to obtain the second verification result of the audit log; The step of generating a verification file based on the audit log, wherein the verification file stores a first hash verification value of the audit log, includes: If the audit log is the first audit log in the audit log file, the first hash check value of the audit log is obtained using a hash function, and the first hash check value of the audit log is written into the check file; When the audit log is any audit log other than the first audit log in the audit log file, a hash function is used to obtain the first hash verification value of the first audit log based on the second hash verification value and the first audit log, and the first hash verification value of the first audit log is written into the verification file; wherein, the first audit log is any audit log other than the first audit log in the audit log file, the second hash verification value is the hash verification value of the second audit log, and the second audit log is the audit log adjacent to the first audit log in the audit log file; Wherein, the audit log file and the verification file satisfy at least one of the following: The audit log file and the verification file are physically isolated from each other. The audit log file and the verification file are isolated via a system path; The audit log file and the verification file have independent access control permissions.

2. The method according to claim 1, characterized in that, The first verification of the audit log based on the audit log file and the verification file, to obtain the first verification result of the audit log, includes: Based on the first audit log in the audit log file and the first hash check value in the verification file, perform a hash check on the first audit log in the audit log to obtain the first verification result of the first audit log in the audit log file; The first verification result of the nth audit log in the audit log file is obtained based on the nth first hash check value in the verification file and the (n-1)th first hash check value in the verification file, where n is an integer greater than 1.

3. The method according to claim 2, characterized in that, The step of performing a hash verification on the first audit log in the audit log file based on the first audit log in the audit log file and the first hash verification value in the verification file to obtain the first verification result of the first audit log in the audit log file includes: Using a hash function, a third hash verification value corresponding to the first audit log is obtained; if the first hash verification value is equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has been successfully verified; if the first hash verification value is not equal to the third hash verification value, the first verification result of the first audit log indicates that the first audit log has failed to be verified. And / or, Based on the nth audit log in the audit log file, the nth first hash check value in the verification file, and the (n-1)th first hash check value in the verification file, the first verification result of the nth audit log in the audit log file is obtained, including: Using a hash function, a fourth hash verification value is obtained corresponding to the nth audit log based on the nth audit log in the audit log file and the (n-1)th first hash verification value in the verification file. If the nth first hash verification value is equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has been successfully verified. If the nth first hash verification value is not equal to the fourth hash verification value, the first verification result of the nth audit log indicates that the nth audit log has failed to be verified.

4. The method according to any one of claims 1 to 3, characterized in that, The first verification of the audit log based on the audit log file and the verification file, to obtain the first verification result of the audit log, includes: The audit logs are counted based on the number of audit logs in the audit log file and the number of first hash check values ​​in the check file to obtain the first check result of the audit logs.

5. The method according to claim 1, characterized in that, The backup audit log file is stored locally on the first device or on the second device; And / or, The backup verification file is stored locally on the first device or on the second device.

6. A verification device for audit logs, characterized in that, The device includes: The first processing module is used to generate a verification file based on the audit log, wherein the verification file stores the first hash verification value of the audit log; The second processing module is used to perform a first verification on the audit log based on the audit log file and the verification file, and obtain the first verification result of the audit log, wherein the audit log file stores the audit log; The third processing module is used to obtain a backup audit log file and a backup verification file stored in the backup storage when the first verification result indicates that the audit log verification has failed; wherein, the backup audit log file stores the audit log, and the backup verification file stores the first hash verification value of the audit log; The fourth processing module is used to perform a second verification on the audit log based on the backup audit log file and the backup verification file, and obtain the second verification result of the audit log. The first processing module includes: The first processing unit is configured to, when the audit log is the first audit log in the audit log file, use a hash function to obtain a first hash verification value of the audit log, and write the first hash verification value of the audit log into the verification file. The second processing unit is configured to, when the audit log is an audit log other than the first audit log in the audit log file, use a hash function to obtain a first hash verification value of the first audit log based on a second hash verification value and the first audit log, and write the first hash verification value of the first audit log into the verification file; wherein, the first audit log is an audit log other than the first audit log in the audit log file, the second hash verification value is the hash verification value of the second audit log, and the second audit log is the audit log in the audit log file that is adjacent to the first audit log; Wherein, the audit log file and the verification file satisfy at least one of the following: The audit log file and the verification file are physically isolated from each other. The audit log file and the verification file are isolated via a system path; The audit log file and the verification file have independent access control permissions.

7. An electronic device, characterized in that, include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the audit log verification method as described in any one of claims 1 to 5.

8. A readable storage medium, characterized in that, The readable storage medium stores a program that, when executed by a processor, implements the steps of the audit log verification method as described in any one of claims 1 to 5.

9. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps in the audit log verification method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Data verification method and device

    CN108763358A

  • Log processing method, device and equipment and readable storage medium

    CN118244989A