Time backtracking disaster recovery method and device based on quantum random-causal inversion

CN122533930APending Publication Date: 2026-08-07SHENZHEN SHUCUN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-07
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0003]本申请的主要目的在于提供一种基于量子随机-因果反演的时间回溯式容灾方法及装置,旨在解决现有容灾技术恢复粒度粗、效率低、可信验证弱的技术问题

Benefits of technology

[0014]本申请提出的一个或多个技术方案,通过利用量子纠缠标记对构建不可篡改的因果指纹链,为每个关键操作提供唯一且随机的时空锚点,进而结合扩展因果图和反事实虚拟干预分析,能够快速、准确地定位污染源事件和完整的故障传播子图,且追溯过程基于物理随机性,抗预测和伪造,以污染源事件的前一因果锚点单元作为安全回溯边界,并采用同态加密技术生成差异化的补偿事务,实现了精确到事件级别的状态回滚,同时通过生成恢复正确性零知识证明在隔离环境中进行状态恢复,同时恢复操作在隔离环境中进行,实现了细粒度低损恢复,极大提升了恢复过程的可信度和安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122533930A_ABST
    Figure CN122533930A_ABST
Patent Text Reader

Abstract

The application discloses a time backtracking disaster recovery method and device based on quantum random-causal inversion, comprising: before a key state change of a business system is executed, a causal fingerprint chain is constructed based on quantum entanglement marks; a dynamic causal graph is constructed based on the causal fingerprint chain and a multi-path Monte Carlo deduction is performed; an isolation verification sandbox is constructed according to a structured risk deduction report and path verification and dynamic graph expansion are performed; in response to an actually occurred logical error event, a counterfactual virtual intervention is executed based on an expanded causal graph, a pollution source event and an encrypted fault propagation subgraph are identified; a previous causal anchor unit of the pollution source event is taken as a safe backtracking boundary, a homomorphic encryption differential compensation transaction sequence is reversely generated, a recovery correctness zero-knowledge proof is generated; and operation rollback and context reconstruction are performed in an isolation environment, and a to-be-verified reconstructed state is recovered to a production environment. The application can realize accurate tracing, safe verification and fine-grained low-loss recovery of a logical error.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of disaster recovery technology, and in particular to a time-backtracking disaster recovery method and device based on quantum random-causal inversion. Background Technology

[0002] As information systems become increasingly complex, logical errors or failures in business systems can lead to severe data loss and service interruptions. Traditional disaster recovery solutions often rely on redundant backups or snapshot recovery. These methods have significant limitations in terms of recovery granularity and timeliness. For example, redundant backups can typically only restore to a fixed backup point in time and cannot perform precise rollbacks for specific failures; while snapshot recovery can preserve the system state at a certain moment, it falls short in handling the complex causal relationships of failure propagation. Furthermore, traditional methods lack effective means to verify the correctness of the restored state, making it difficult to ensure that the restored system is logically completely consistent with the original system. Summary of the Invention

[0003] The main purpose of this application is to provide a time-backward disaster recovery method and device based on quantum random-causal inversion, which aims to solve the technical problems of existing disaster recovery technologies such as coarse recovery granularity, low efficiency and weak reliable verification.

[0004] To achieve the above objectives, this application proposes a time-backtracking disaster recovery method based on quantum random-causal inversion. The time-backtracking disaster recovery method based on quantum random-causal inversion includes: Before the business system performs a critical state change, a quantum true random number generator is invoked to generate quantum entangled tag pairs, and a causal fingerprint chain is constructed based on the quantum entangled tag pairs; A dynamic causal graph is constructed based on the causal fingerprint chain. When a high-risk operation is detected, a multi-path Monte Carlo simulation is performed on the dynamic causal graph using quantum entangled tag pairs as seeds to obtain a structured risk simulation report. The structured risk simulation report includes a predicted fault propagation path and a set of potentially affected objects. Based on the structured risk simulation report, an isolated verification sandbox identified by quantum markers is constructed. Path verification and dynamic graph expansion are performed based on the isolated verification sandbox to generate an extended causal graph. In response to actual logical error events, counterfactual virtual intervention is performed on suspicious event nodes based on the extended causal graph to identify pollution source events and corresponding encrypted fault propagation subgraphs; Using the previous causal anchor unit of the pollution source event as the safe backtracking boundary, a homomorphic encrypted differential compensation transaction sequence is generated in reverse, and a zero-knowledge proof of recovery correctness is generated based on the encrypted fault propagation subgraph and the homomorphic encrypted differential compensation transaction sequence. Based on the homomorphic encrypted differential compensation transaction sequence, operation rollback and context reconstruction are performed in an isolated environment to generate a reconstructed state to be verified. Based on the zero-knowledge proof of recovery correctness, the reconstructed state to be verified is restored to the production environment.

[0005] In one embodiment, the step of calling a quantum true random number generator to generate quantum entangled tag pairs and constructing a causal fingerprint chain based on the quantum entangled tag pairs before the business system performs a critical state change includes: A nonlinear optical device is driven to generate polarization entangled photon pairs. Projection measurements are performed at the local measurement end and the remote witness end using a synchronous random measurement basis. The measurement results are converted into binary strings to generate local quantum entanglement tags and remote quantum entanglement tags, which constitute the quantum entanglement tag pairs. The operation metadata of the current operation, the hash value of the previous causal anchor unit, and the local quantum entanglement tag are concatenated into a challenge message, and the challenge message is input into the quantum-resistant verifiable delay function in the trusted execution environment. In the trusted execution environment, using the challenge message as the base, modular exponentiation is performed sequentially according to preset delay parameters to generate a time anchor proof; The operation metadata, the hash value of the previous causal anchor unit, the quantum entanglement tag pair, and the time anchor proof are encapsulated into the current causal anchor unit; Based on the chain node commitment value of the previous causal anchor unit, the hash digest of the current causal anchor unit, and the homomorphic commitment random number, the current chain node commitment value is calculated using the elliptic curve homomorphic commitment algorithm. The commitment value of the current chain node is used as the on-chain fingerprint of the current causal anchor unit, and an immutable causal fingerprint chain is recursively constructed.

[0006] In one embodiment, the step of calculating the current chain node commitment value based on the chain node commitment value of the previous causal anchor unit, the hash digest of the current causal anchor unit, and the homomorphic commitment random number, using an elliptic curve homomorphic commitment algorithm, includes: Obtain the chain node commitment value of the previous causal anchor unit, the hash digest of the current causal anchor unit, and the homomorphic commitment random number sampled from the quantum true random number generator; Publicly available base generators and blinded generators are selected on a secure elliptic curve, wherein the order of the elliptic curve is a prime number; The chain node commitment value and hash digest are concatenated into a combined message and then divided into several fixed-length message field blocks; Based on the message field block, perform elliptic curve dot product operations with the basis generators respectively to obtain several dot product result points; The homomorphic commitment random number is multiplied by the blinding generator using an elliptic curve dot product to obtain the blinding component; Perform elliptic curve point addition on each of the dot product results and the blinded component to obtain the encrypted message point set; The encrypted message point set is subjected to elliptic curve point serialization processing to generate a point serialization string; The hash function is used to calculate the serialized string of the point to generate the commitment value of the current chain node.

[0007] In one embodiment, the construction of a dynamic causal graph based on the causal fingerprint chain, and the performing of multi-path Monte Carlo simulation on the dynamic causal graph using quantum entangled tag pairs as seeds when a high-risk operation is detected, to obtain a structured risk simulation report, including: Based on the causal anchor units and operational dependencies in the causal fingerprint chain, a dynamic causal graph is constructed; The system collects multimodal behavior streams in real time and determines the behavior entropy mutation index based on the multimodal behavior streams. The multimodal behavior streams include at least two types of system call sequences, database transaction logs, network traffic characteristics, and inter-process communication relationship graphs. The behavior entropy mutation index is determined based on the Shannon entropy change rate within a sliding time window. When the behavioral entropy mutation index exceeds a preset threshold for three consecutive sliding windows, a high-risk operation signal is triggered. Using the quantum entangled tag pair corresponding to the abnormal event that triggers the high-risk operation signal as a random seed, multiple parallel deduction threads are initialized, wherein each deduction thread is assigned an independent random number sequence derived from the random seed; For each simulation thread, a weighted random walk is performed on the dynamic causal graph, starting from the node corresponding to the abnormal event, to simulate the multi-directional propagation process of the fault along the causal edge and determine the propagation path and the scope of influence. The propagation paths and impact ranges of each inference thread are aggregated and analyzed to determine the probability of each propagation path being valid and the severity of its impact. Based on the probability of each propagation path's establishment and the severity of its impact, predicted fault propagation paths and sets of potentially affected objects are selected, generating a structured risk simulation report.

[0008] In one embodiment, the step of constructing an isolated verification sandbox identified by quantum tags based on the structured risk projection report, and performing path verification and dynamic graph expansion based on the isolated verification sandbox to generate an expanded causal graph includes: The structured risk simulation report is analyzed to extract high-risk operation sequences and potentially affected object sets from the predicted failure propagation path; Using the quantum random tag hash value corresponding to the high-risk operation sequence as an identifier, an operating system-level isolated verification sandbox is created. The isolated verification sandbox achieves a closed execution environment through namespace isolation, resource quota restrictions, and system call interception mechanisms. Extract the latest consistent data snapshot of each object in the potentially affected object set from the production environment, load the consistent data snapshot into the corresponding storage location of the isolation verification sandbox, and obtain the initialized isolation verification sandbox; In the initialized isolation verification sandbox, the high-risk operation sequence is executed according to the original timing sequence to obtain the original monitoring log; Based on the original monitoring logs, event sequence reconstruction and state difference analysis are performed to generate a sandbox execution verification report, which includes the actual execution path, state change list and verification confidence level. Based on the sandbox execution verification report, the verified event sequence within the sandbox is determined, and the verified event sequence within the sandbox is used as the hypothetical causal branch to update the dynamic causal graph, generating an extended causal graph.

[0009] In one embodiment, the response to an actual logical error event involves performing counterfactual virtual intervention on suspicious event nodes based on the extended causal graph to identify the contamination source event and the corresponding encrypted fault propagation subgraph, including: In response to an actual logical error event, the event index corresponding to the logical error event is obtained, and the corresponding event node is located in the extended cause-effect graph based on the event index. From the extended causal graph, a suspicious subgraph region centered on the event node is mapped out; Perform counterfactual virtual intervention on each suspicious event node within the suspicious subgraph region to determine the counterfactual probability of each suspicious event node; The suspicious event nodes are sorted according to their counterfactual probabilities, and the event corresponding to the suspicious event node with the highest counterfactual probability is selected as the pollution source event. Starting from the pollution source event, reverse tracing and forward propagation analysis are performed along the causal edges in the extended causal graph to identify all affected nodes; Homomorphic encryption technology is used to encrypt and encode all affected nodes and causal edges between nodes, generating an encrypted fault propagation subgraph.

[0010] In one embodiment, the step of generating a homomorphic encrypted differential compensation transaction sequence in reverse, using the preceding causal anchor unit of the pollution source event as the security backtracking boundary, and generating a zero-knowledge proof of correctness based on the encrypted fault propagation subgraph and the homomorphic encrypted differential compensation transaction sequence, includes: Locate the reference causal anchor unit corresponding to the pollution source event in the causal fingerprint chain, and extract the previous causal anchor unit of the reference causal anchor unit as the safety backtracking boundary. Extract all causal anchor units from the security backtracking boundary to the contamination event from the causal fingerprint chain, and parse the operation metadata recorded in each causal anchor unit; Based on the operation metadata, the reverse compensation instructions corresponding to each operation are derived in reverse, and the reverse compensation instructions are encrypted using a homomorphic encryption algorithm to generate a homomorphic encrypted differential compensation transaction sequence. Constructing zero-knowledge proof circuits; The node information in the encrypted fault propagation subgraph is associated and mapped with the instruction information in the homomorphic encrypted differential compensation transaction sequence to determine the set of fault propagation nodes corresponding to each compensation instruction. The homomorphic encrypted differential compensation transaction sequence and the fault propagation node set are used as input parameters and input to the zero-knowledge proof circuit to generate a zero-knowledge proof of restored correctness. The zero-knowledge proof of restored correctness includes a proof statement, a verification public key, and verifiable proof credentials.

[0011] In one embodiment, the step of performing operation rollback and context reconstruction in an isolated environment based on the homomorphic encrypted differential compensation transaction sequence to generate a reconstructed state to be verified, and restoring the reconstructed state to the production environment based on the zero-knowledge proof of recovery correctness, includes: Create an isolated recovery environment that includes an operation rollback track and a context reconstruction track, wherein the operation rollback track is used to perform cryptographic compensation transactions, and the context reconstruction track is used to restore the complete execution context of the secure backtrack boundary; The homomorphic encrypted differential compensation transaction sequence is sequentially loaded and executed in the operation rollback track to generate the target rollback state; In the context reconstruction track, all causal anchor units from the initial state of the system to the safe backtracking boundary point are extracted from the causal fingerprint chain. Combined with the pre-stored lightweight incremental checkpoints, the operation metadata is replayed in the sandbox in the original time sequence to generate a reconstructed execution context snapshot. The target rollback state is fused with the reconstructed execution context snapshot to generate a reconstruction state to be verified; Based on the zero-knowledge proof of the recovery correctness, the reconstructed state to be verified is written into the production environment in an atomic transaction manner, overwriting the contaminated state after the security backtracking boundary point, thus completing disaster recovery.

[0012] In one embodiment, the step of writing the reconstructed state to be verified into the production environment using atomic transactions based on the zero-knowledge proof of recovery correctness, overwriting the contaminated state after the security backtracking boundary point, and completing disaster recovery, includes: Perform semantic analysis on the reconstructed state to be verified to determine the reconstructed semantic hash; Read the pre-stored original semantic hash of the security backtracking boundary point from the causal fingerprint chain; The reconstructed semantic hash is compared with the original semantic hash to generate a semantic consistency verification result; If the semantic consistency verification result is passed, then the zero-knowledge proof of recovery correctness is verified, and a zero-knowledge proof verification result is generated. If the zero-knowledge proof verification result is successful, the state to be reconstructed is encapsulated into a single atomic transaction and submitted to the persistent storage layer and runtime state manager of the production environment in one go, overwriting all contaminated data objects and process states written after the security backtracking boundary point, thus completing disaster recovery.

[0013] Furthermore, to achieve the above objectives, this application also proposes a time-backtracking disaster recovery device based on quantum random-causal inversion, which includes: The module is used to call a quantum true random number generator to generate quantum entangled tag pairs before the business system performs critical state changes, and to construct a causal fingerprint chain based on the quantum entangled tag pairs; The deduction module is used to construct a dynamic causal graph based on the causal fingerprint chain, and when a high-risk operation is detected, to perform multi-path Monte Carlo deduction on the dynamic causal graph with quantum entangled tag pairs as seeds to obtain a structured risk deduction report, wherein the structured risk deduction report includes predicted failure propagation paths and a set of potentially affected objects; The extension module is used to construct an isolated verification sandbox identified by quantum markers based on the structured risk simulation report, and to perform path verification and dynamic graph expansion based on the isolated verification sandbox to generate an extended causal graph. The intervention module is used to respond to actual logical error events, and to perform counterfactual virtual intervention on suspicious event nodes based on the extended causal graph, and to identify pollution source events and corresponding encrypted fault propagation subgraphs; The generation module is used to generate a homomorphic encrypted differential compensation transaction sequence in reverse, with the previous causal anchor unit of the pollution source event as the safe backtracking boundary, and generate a zero-knowledge proof of recovery correctness based on the encrypted fault propagation subgraph and the homomorphic encrypted differential compensation transaction sequence. The recovery module is used to perform operation rollback and context reconstruction in an isolated environment based on the homomorphic encrypted differential compensation transaction sequence, generate a reconstruction state to be verified, and restore the reconstruction state to the production environment based on the zero-knowledge proof of recovery correctness.

[0014] The proposed technical solutions, including one or more, utilize quantum entanglement tags to construct an immutable causal fingerprint chain, providing a unique and random spatiotemporal anchor point for each key operation. Combined with extended causal graphs and counterfactual virtual intervention analysis, this enables rapid and accurate location of pollution source events and complete fault propagation subgraphs. Furthermore, the tracing process, based on physical randomness, is resistant to prediction and forgery. Using the preceding causal anchor point unit of the pollution source event as the secure backtracking boundary, and employing homomorphic encryption technology to generate differentiated compensation transactions, it achieves state rollback accurate to the event level. Simultaneously, by generating zero-knowledge proofs of recovery correctness, state recovery is performed in an isolated environment, and the recovery operation is also conducted within this isolated environment, achieving fine-grained, low-loss recovery and significantly improving the credibility and security of the recovery process. Attached Figure Description

[0015] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a flowchart illustrating an embodiment of the time-backtracking disaster recovery method based on quantum random-causal inversion provided in this application. Figure 2 This is a schematic diagram of the module structure of a time-backtracking disaster recovery device based on quantum random-causal inversion, as described in an embodiment of this application.

[0018] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0019] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0020] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0021] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device capable of performing the above functions, such as a time-backtracking disaster recovery device based on quantum random-causal inversion. The following description uses a time-backtracking disaster recovery device based on quantum random-causal inversion as an example to illustrate this embodiment and the subsequent embodiments.

[0022] Based on this, embodiments of this application provide a time-backtracking disaster recovery method based on quantum random-causal inversion, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the time-backtracking disaster recovery method based on quantum random-causal inversion in this application.

[0023] In this embodiment, the time-backtracking disaster recovery method based on quantum random-causal inversion includes steps S10 to S60: Step S10: Before the business system performs a critical state change, call the quantum true random number generator to generate quantum entangled tag pairs, and construct a causal fingerprint chain based on the quantum entangled tag pairs.

[0024] It should be noted that critical state changes refer to operations in a business system that, once executed, will persistently and potentially irreversibly alter the core state of the system, data assets, or business process paths. These include database transactional operations, system configuration changes, critical nodes in business processes, and write operations to external systems.

[0025] Quantum true random number generators generate random numbers based on the inherent, fundamental randomness of quantum mechanics. For example, they utilize the path selection of single photons, phase fluctuations, or the collapse of measurements of entangled photons. These processes are theoretically unpredictable by any classical physical laws, resulting in truly nondeterministic and non-periodic random number sequences. This eliminates the possibility of prediction based on algorithmic reverse engineering or state manipulation from the outset. By providing an unpredictable and unreproducible source of physical randomness for each quantum entanglement pair, the quantum true random number generator ensures the uniqueness and anti-counterfeiting properties of each causal anchor point.

[0026] The quantum entanglement tag consists of a local quantum tag and a remote quantum tag that are spatially correlated and generated by a quantum true random number generator. The local quantum tag is used for in-chain binding and sandbox identification, while the remote quantum tag is submitted to the quantum witness service node for storage.

[0027] A causal fingerprint chain is a quantum-resistant, verifiable, append-only cryptographic log structure formed by sequentially linking causal anchor units through homomorphic commitment functions. Each chain node contains an unforgeable fingerprint of the historical state and the current event.

[0028] In its implementation, before the business system executes a critical state change, the system automatically triggers a quantum true random number generator. This generator uses quantum mechanics principles to produce truly random quantum entangled tag pairs. The local quantum tags in these entangled tag pairs are then bound to the current critical state change operation, forming causal anchor units. Simultaneously, remote quantum tags are sent to a quantum witness service node for storage. Subsequently, using a homomorphic commitment function, the causal anchor units are linked sequentially to form a quantum-resistant, verifiable, and append-only causal fingerprint chain. This structure ensures that each critical state change operation has a unique and immutable spatiotemporal anchor.

[0029] In one feasible implementation, step S10 may include: driving a nonlinear optical device to generate polarization entangled photon pairs; performing projection measurements at a local measurement end and a remote witness end using a synchronous random measurement basis; converting the measurement results into binary strings to generate local quantum entanglement tags and remote quantum entanglement tags, thus forming the quantum entanglement tag pair; concatenating the operation metadata of the current operation, the hash value of the previous causal anchor unit, and the local quantum entanglement tag into a challenge message; and inputting the challenge message into a quantum-resistant verifiable delay function in the trusted execution environment; in the trusted execution... In the environment, using the challenge message as the base, modular exponentiation is performed sequentially according to preset delay parameters to generate a time anchor proof; the operation metadata, the hash value of the previous causal anchor unit, the quantum entanglement tag pair, and the time anchor proof are encapsulated into the current causal anchor unit; based on the chain node commitment value of the previous causal anchor unit, the hash digest of the current causal anchor unit, and the homomorphic commitment random number, the current chain node commitment value is calculated using the elliptic curve homomorphic commitment algorithm; the current chain node commitment value is used as the on-chain fingerprint of the current causal anchor unit, and an immutable causal fingerprint chain is recursively constructed.

[0030] It should be noted that the nonlinear optical device can be a spontaneous parametric down-conversion device based on barium β-borate crystal. Driving this device can generate polarization-entangled photon pairs in a quantum Bell state. A polarization beam splitter separates these photon pairs into a local path and a remote path. At the local measurement end and the remote witness end, a synchronously randomly selected measurement basis, such as a linear polarization basis, a diagonal basis, or a circular polarization basis, is used to perform projection measurements on the entangled photon pairs. The measurement results are then converted into binary strings, generating a local quantum entanglement tag and a remote quantum entanglement tag. The quantum error rate between the local and remote quantum tags is then determined. If the quantum error rate is below a preset threshold, the two tags together constitute a quantum entanglement tag pair. This tag pair possesses quantum non-cloning property and non-local correlation, and can serve as a physical layer anchor for event identity.

[0031] The operation metadata of the current operation refers to the set of data information closely related to the critical state change operation currently in progress. It can be extracted from data sources such as operation logs, configuration files, and transaction records of the business system, and includes, but is not limited to, operation type, operation timestamp, operation initiator identifier, operation object identifier, and data snapshots before and after the operation. The hash value of the previous causal anchor unit is a fixed-length string obtained by hashing the previous causal anchor unit. It uniquely and definitively represents the content of the previous causal anchor unit, ensuring the continuity and immutability of the causal fingerprint chain.

[0032] The challenge message is formed by concatenating the operation metadata of the current operation, the hash value of the previous causal anchor unit, and the local quantum entanglement tag. This challenge message is then input into a quantum-resistant verifiable delay function deployed in a trusted execution environment (TEA). A TEA is a hardware-level secure computing environment that ensures the confidentiality and integrity of code and data, preventing attacks from external malware and the leakage of internal data. A quantum-resistant verifiable delay function is a cryptographic primitive designed to enforce a certain computation time—positively correlated with the input size—while ensuring the verifiability of the computation result, and is resistant to attacks from quantum computers.

[0033] In a trusted execution environment, using the challenge message as the base, modular exponentiation is performed sequentially according to preset delay parameters, such as the number of modular exponentiation steps corresponding to a 60-second computation delay. This generates the final delay output value and the corresponding computation trajectory proof, which together constitute the time anchor proof. The quantum-resistant verifiable delay function mechanism ensures that no entity can complete the computation before the specified time, thereby preventing event forgery or time-running attacks.

[0034] The operation metadata, the hash value of the previous causal anchor unit, the quantum entanglement tag pair, and the time anchor proof are encapsulated into the current causal anchor unit. This unit is a structured, self-contained record of causal events, which contains both semantic information and embedded quantum identity and time evidence.

[0035] Based on the commitment value of the chain node from the previous causal anchor unit, the hash digest of the current causal anchor unit, and the newly sampled homomorphic commitment random number, the elliptic curve homomorphic commitment algorithm can be used to calculate the commitment value of the current chain node. The homomorphic commitment random number is generated by a fresh random bit stream provided by a quantum true random number generator to enhance the randomness and unpredictability of the commitment. The elliptic curve homomorphic commitment algorithm is a commitment scheme based on elliptic curve cryptography, possessing homomorphic properties, meaning it allows specific mathematical operations on the commitment value without revealing the original information, while ensuring the binding and concealment of the commitment. The formula for the elliptic curve homomorphic commitment algorithm is: in, The value committed by the current chain node. The value committed by the previous chain node. For the collision-resistant hash digest of the current causal anchor unit, The random numbers are homomorphically committed, with G, H, and K being pre-defined and linearly independent elliptic curve base points. All operations are performed on the elliptic curve group of prime order to ensure that the committed values ​​possess additive homomorphism, computational hiding, and binding.

[0036] The commitment value of the current chain node calculated by this algorithm serves as the on-chain fingerprint of the current causal anchor unit. Together with the commitment value of the chain node of the previous causal anchor unit, they form a recursive causal fingerprint chain structure. This structure not only ensures the continuity and immutability of the chain, but also provides a complete traceability capability for historical states.

[0037] Because each causal anchor unit contains the hash value of the previous anchor, any tampering with a historical node will cause a mismatch in the hash values ​​of all subsequent nodes, thus being detected immediately. Furthermore, this structure supports efficient on-chain verification; the verifier does not need to obtain all historical data, but only needs to verify the hash relationship between the current chain node's commitment value and adjacent nodes to confirm the integrity of the entire causal fingerprint chain.

[0038] In one feasible implementation, the step of calculating the current chain node commitment value based on the chain node commitment value of the previous causal anchor unit, the hash digest of the current causal anchor unit, and the homomorphic commitment random number, using an elliptic curve homomorphic commitment algorithm, includes: obtaining the chain node commitment value of the previous causal anchor unit, the hash digest of the current causal anchor unit, and the homomorphic commitment random number sampled from a quantum true random number generator; selecting publicly available base generators and blinded generators on a secure elliptic curve, wherein the order of the elliptic curve is a prime number; and concatenating the chain node commitment value and the hash digest into a combined message. The message field is divided into several fixed-length message field blocks; each message field block is multiplied by the base generator to obtain several multiplication result points; the homomorphic commitment random number is multiplied by the blinding generator to obtain a blinding component; each multiplication result point is added to the blinding component by an elliptic curve to obtain an encrypted message point set; the encrypted message point set is serialized by elliptic curve to generate a point serialization string; and a hash function is used to calculate the point serialization string to generate the commitment value of the current chain node.

[0039] It should be noted that the chain node commitment value of the previous causal anchor unit can be obtained by querying historical records or directly reading the storage medium. This value is used to reflect the chained causal dependency, ensuring that any tampering with the history will result in a mismatch in the current commitment value. The hash digest of the current causal anchor unit is a collision-resistant digest of the operation metadata, quantum tokens, time anchor proofs, etc., representing the current event statement. The homomorphic commitment random number comes from a quantum true random number generator, providing an information-theoretically secure blinded entropy source, ensuring that the commitment value is unlinkable, unpredictable, and possesses forward security.

[0040] Secure elliptic curves are mathematical curves widely used in cryptography. The order of an elliptic curve is a large prime number to ensure the computational difficulty of the discrete logarithm problem and to resist subgroup attacks. Two public and linearly independent base points are selected on the secure elliptic curve: a base generator G and a blinding generator H. The base generator G is used to encode the message, and the blinding generator H is used to inject random blinding. The two are linearly independent to prevent commitment collapse.

[0041] The chain node commitment value of the previous causal anchor unit is concatenated with the hash digest to form a combined message, thereby explicitly binding the historical state with the current event. This combined message is then divided into several fixed-length message field blocks of a preset length, such as 256 bits, to adapt to the size of the elliptic curve scalar and avoid information truncation. Furthermore, for each message field block, it is treated as a scalar and subjected to an elliptic curve dot product operation with the basis generator G, yielding several dot product result points. This is equivalent to vectorizing the long message onto an elliptic curve group, preserving all information.

[0042] Simultaneously, the homomorphic commitment random number is multiplied by the blinding generator H using an elliptic curve multiplication operation to generate a blinding component, thereby introducing high-entropy randomness and ensuring that the commitment value is different each time under the same message, thus achieving computational concealment.

[0043] All dot product results are added point-by-point to the blinded component on the elliptic curve group to obtain one or more encrypted message points, forming an encrypted message point set. Elliptic curve point serialization processing is then performed on the encrypted message point set, for example, using a compressed coordinate format, to generate a standardized point serialization string for easy storage and transmission.

[0044] By utilizing cryptographically secure hash functions, such as SHA3-256, the dotted serialized string is computed, outputting a fixed-length hash value as the commitment value of the current chain node. This commitment value is used as the on-chain fingerprint of the current causal anchor unit, and is recursively input from the commitment values ​​of previous chain nodes, successively linking each causal anchor unit to construct an immutable causal fingerprint chain that supports homomorphic operations. Because the construction process of the commitment value incorporates historical states, current event semantics, and quantum randomization, and its underlying operations are performed on elliptic curve groups, this chain not only possesses strong binding and computational hiding properties but also supports linear operations in the ciphertext field, providing a cryptographic foundation for subsequent generation of homomorphic encrypted differential compensation transactions, execution of zero-knowledge verification, and atomic state recovery.

[0045] Through the above mechanism, a complete, secure, and computable commitment encoding of complex structured causal events is achieved, significantly improving the reliability and functionality of causal logs in quantum-resistant environments.

[0046] Step S20: Construct a dynamic causal graph based on the causal fingerprint chain, and when a high-risk operation is detected, perform multi-path Monte Carlo simulation on the dynamic causal graph using quantum entangled tag pairs as seeds to obtain a structured risk simulation report, wherein the structured risk simulation report includes predicted fault propagation paths and a set of potentially affected objects.

[0047] It should be noted that the dynamic causal graph is a directed graph structure constructed from the confirmed causal anchor units and their operational dependencies in the causal fingerprint chain. The nodes in the graph represent a causal event that has occurred, i.e., a causal anchor unit, which contains metadata such as operational semantics, quantum tags, and time anchors. The directed edges represent the causal dependencies between two events, such as "after transaction A is committed, service B is called", which is derived from explicit or implicit dependencies such as input / output objects, resource locks, and message queues in the operational metadata.

[0048] High-risk operations refer to operations that meet any of the following conditions: semantically high risk, such as deleting core tables, disabling security auditing, or escalating privileges to root; abnormal context, i.e., performing batch data migration outside of maintenance windows; behavioral entropy mutation, i.e., the behavioral entropy mutation index calculated by multimodal behavioral flow exceeds a preset threshold; and explicit user marking, i.e., operations and maintenance personnel manually mark changes as high-risk. This embodiment does not impose specific restrictions on this.

[0049] Understandably, multi-path Monte Carlo simulation is a causal path exploration method based on probabilistic sampling. Using quantum entangled marker pairs as joint random seeds on a dynamic causal graph, it simulates various failure propagation scenarios that high-risk operations may trigger, thereby generating a structured risk simulation report containing different failure propagation paths and corresponding potentially affected object sets. The predicted failure propagation path is a sequence of nodes, such as Op_A→Service_B→DB_C, and the potentially affected object set consists of resource identifiers such as data tables, microservices, and user accounts involved in the path's endpoint. The structured risk simulation report may also include path probability distributions, i.e., the frequency or confidence level of each path; and a risk score, which is calculated based on a weighted average of the impact scope, recovery difficulty, and business criticality.

[0050] In one feasible implementation, step S20 may include: constructing a dynamic causal graph based on the causal anchor units and operational dependencies in the causal fingerprint chain; real-time acquisition of the system's multimodal behavior flow, and determining the behavior entropy mutation index based on the multimodal behavior flow, wherein the multimodal behavior flow includes at least two types of system call sequences, database transaction logs, network traffic characteristics, and inter-process communication relationship graphs, and the behavior entropy mutation index is determined based on the Shannon entropy change rate within a sliding time window; triggering a high-risk operation signal when the behavior entropy mutation index exceeds a preset threshold for three consecutive sliding windows; and corresponding abnormal events that trigger the high-risk operation signal. The quantum entanglement pair is used as a random seed to initialize multiple parallel deduction threads. Each deduction thread is assigned an independent random number sequence derived from the random seed. For each deduction thread, a weighted random walk is performed on the dynamic causal graph, starting from the node corresponding to the abnormal event, to simulate the multi-directional propagation process of the fault along the causal edge and determine the propagation path and scope of influence. The propagation paths and scope of influence of each deduction thread are aggregated and analyzed to determine the probability of success and severity of influence of each propagation path. Based on the probability of success and severity of influence of each propagation path, the predicted fault propagation paths and the set of potentially affected objects are selected, and a structured risk deduction report is generated.

[0051] It should be noted that the construction of the dynamic causal graph is based on the confirmed causal anchor units and their operational dependencies in the causal fingerprint chain. In the graph, node weights are calculated based on historical occurrence frequency, and edge weights are dynamically updated based on causal strength and temporal density. Submitted causal anchor units are read from the causal fingerprint chain. Each unit contains operational metadata, quantum tokens, temporal anchor proofs, and preorder hashes. Each causal anchor unit is mapped to a graph node. For any two nodes with dependencies, their causal strength and temporal density are calculated based on explicit or implicit dependencies such as input / output objects, resource lock states, and message queue order in the operational metadata, generating weighted directed edges. All nodes and edges are then integrated to form a directed graph structure with dynamic update capabilities, i.e., the dynamic causal graph.

[0052] When collecting multimodal behavior flows of the system in real time, system call sequences are obtained through system call monitoring tools, database transaction logs are read from the database management system, network traffic characteristics are captured using network traffic analysis tools, and inter-process communication relationship graphs are drawn using process monitoring tools.

[0053] In the calculation of the behavioral entropy mutation index, the size of the sliding time window is first set, for example, every 3 seconds is a window with a step size of 1 second. For each type of behavioral flow, the frequency of symbols is counted, such as the frequency of system call types, and the Shannon entropy is calculated as follows: in, Let be the Shannon entropy at time t. Let be the probability of the occurrence of the i-th type of behavior symbol at time t.

[0054] After calculating the Shannon entropy at each time step using a sliding window, the rate of change of Shannon entropy between adjacent windows is further calculated, i.e., the behavioral entropy mutation index. If this index exceeds a preset threshold in three consecutive sliding windows, it is determined to be an abnormal behavioral entropy mutation, triggering a high-risk operation signal, and locating the nearest causal anchor unit, i.e., the abnormal event, and extracting its quantum entanglement tag pair.

[0055] The local and remote quantum tags in a quantum entangled tag pair are concatenated and hashed, such as using SHA3-256, to obtain the master seed S. Based on the master seed S, a deterministic key derivation function, such as HKDF, is used to generate N sub-seeds, which are independent random number sequences, where N is the number of parallel derivation threads. Each derivation thread initializes its internal random number generator using its assigned independent random number sequence, ensuring that the randomness between threads is independent and reproducible.

[0056] In the dynamic cause-effect graph, starting from the node corresponding to the abnormal event, each inference thread executes a weighted random walk. During this process, the probability of node selection is proportional to the edge weight, meaning that the fault is more likely to propagate along higher-weight edges, simulating the bias of fault propagation in real-world systems. The random walk continues until a preset termination condition is reached, such as the maximum number of propagation steps, an impact range threshold, or encountering a closed loop formed by already visited nodes. During the random walk, each inference thread records the sequence of nodes traversed, i.e., the simulated fault propagation path, as well as resource identifiers such as data tables, microservices, and user accounts involved at the path's endpoint, constituting a set of potentially affected objects.

[0057] After completing the random walks of all simulation threads, the aggregation analysis phase begins. The frequency of each propagation path across all simulation threads is counted. Combining this with the weighted allocation of each thread, the probability of each path's occurrence is calculated. This probability reflects the likelihood of the failure propagation path actually occurring under a given high-risk operation. Simultaneously, the severity of each path's impact is assessed, primarily based on a comprehensive score considering factors such as the importance of the resources involved at the path's endpoint, its business criticality, and the difficulty of recovery.

[0058] Based on the assessment results of the probability of occurrence and severity of impact mentioned above, propagation paths with high probability of occurrence and significant impact severity are selected as predicted fault propagation paths. Simultaneously, all resource identifiers involved in the endpoints of these paths are compiled to form a set of potentially affected objects. This information will be integrated into a structured risk simulation report, providing operations and maintenance personnel with clear and comprehensive risk warnings and response recommendations.

[0059] The structured risk simulation report not only includes predicted failure propagation paths and the set of potentially affected objects, but can also be further expanded to include, but is not limited to, visualization elements such as path probability distribution maps and risk score heatmaps, as well as response strategy recommendations for different risk levels.

[0060] Step S30: Based on the structured risk simulation report, construct an isolation verification sandbox identified by quantum tags, perform path verification and dynamic graph expansion based on the isolation verification sandbox, and generate an extended causal graph.

[0061] It should be noted that the isolation verification sandbox is an operating system-level closed execution environment. Its unique identifier is generated by the quantum entanglement tag hash value corresponding to the high-risk operation sequence in the structured risk simulation report. It is used to safely replay the predicted fault propagation path and verify whether its actual behavior is consistent with the simulation.

[0062] In the isolated verification sandbox, the predicted fault propagation path in the structured risk simulation report, i.e. the high-risk operation sequence, is accurately replayed in the original time sequence. All system calls, file changes, memory writes, and network activities are recorded by kernel-level monitoring tools to generate raw monitoring logs. The state snapshots before and after execution are compared, byte-level differences are calculated, and low-level events are clustered into high-level semantic operations to generate a sandbox execution verification report. If the report indicates that the path does indeed cause logical errors or security policy violations, the path is determined to be a valid risk path.

[0063] For risk paths validated in the sandbox, they are treated as validated hypothetical causal branches. These branches are then linked downstream of the corresponding starting event in the dynamic causal graph as edge-node connections. Newly added nodes inherit the original causal anchor unit structure, thus enabling real-time expansion and updating of the dynamic causal graph. The extended causal graph is an enhanced version of the dynamic causal graph. While retaining all confirmed historical causal events, it integrates sandbox-validated hypothetical causal branches, forming a unified causal knowledge graph containing factual paths and validated hypothetical paths. This real-time expansion and updating mechanism ensures that the dynamic causal graph maintains its effectiveness and accuracy in the face of constantly changing system environments and new potential threats.

[0064] In one feasible implementation, step S30 may include: parsing the structured risk simulation report to extract high-risk operation sequences and potentially affected object sets from the predicted fault propagation path; creating an operating system-level isolated verification sandbox using the quantum random tag hash value corresponding to the high-risk operation sequence as an identifier, wherein the isolated verification sandbox achieves execution environment closure through namespace isolation, resource quota restrictions, and system call interception mechanisms; extracting the latest consistency data snapshot of each object in the potentially affected object set from the production environment, loading the consistency data snapshot into the corresponding storage location of the isolated verification sandbox, and obtaining the initialized isolated verification sandbox; executing the high-risk operation sequence in the initialized isolated verification sandbox according to the original timing to obtain the original monitoring log; performing event sequence reconstruction and state difference analysis based on the original monitoring log to generate a sandbox execution verification report, wherein the sandbox execution verification report includes the actual execution path, state change list, and verification confidence level; determining the verified event sequences within the sandbox based on the sandbox execution verification report, and using the verified event sequences within the sandbox as hypothetical causal branches to update the dynamic causal graph, generating an extended causal graph.

[0065] It should be noted that natural language processing techniques are used to parse the structured risk simulation report. For example, scripts are written or data analysis tools, such as the Pandas library in Python, are used to extract high-risk operation sequences, including operation type, parameters, execution order, and the set of potentially affected objects. This operation sequence is derived from paths in the multi-path Monte Carlo simulation with a probability of success exceeding a preset threshold.

[0066] Understandably, the high-risk operation sequence is concatenated with the local quantum entanglement tag of the original event and hashed to obtain a quantum random tag hash value, which serves as the sandbox ID to ensure that it is globally unique and cannot be forged. Container technologies such as LXC and Docker can be used in Linux systems, while virtualization solutions such as Hyper-V can be considered on Windows to create isolated verification sandboxes.

[0067] Understandably, the isolation verification sandbox achieves complete enclosure of the execution environment within the sandbox through namespace isolation, resource quota limits, and system call interception mechanisms. Namespace isolation refers to allocating independent process IDs, network stacks, and other resources to the sandbox to prevent confusion with other system processes. Resource quota limits refer to setting upper limits on the use of resources such as CPU and memory to avoid activities within the sandbox affecting host performance. The system call interception mechanism refers to allowing only whitelisted system calls to be executed, preventing any unauthorized behavior.

[0068] It is worth noting that the latest consistent snapshots of each object in the potentially affected object set are extracted from the production environment, such as database row-level snapshots and file system CoW snapshots. These snapshots are then loaded into the corresponding path of the sandbox to complete the sandbox initialization and ensure that the initial state is consistent with the inference premise. When loading into the isolation verification sandbox, data verification and integrity verification mechanisms, such as SHA-256 hash comparison, are required to prevent data tampering or transmission errors.

[0069] In the isolated verification sandbox after initialization, high-risk operation sequences are executed according to the original time intervals and dependencies. All system calls, file changes, memory status and network activities in the sandbox are recorded in real time through kernel-level monitoring mechanisms. Non-intrusive data collection is achieved through eBPF technology to obtain raw monitoring logs.

[0070] Event sequence reconstruction refers to clustering the underlying syscall stream into high-level semantic operations. State difference analysis refers to comparing snapshots before and after sandbox execution, calculating byte-level differences, and generating a state change list. If the Jaccard similarity between the actual execution path and the predicted path is ≥0.8 and the state change involves core business objects, then the confidence level is assigned a high value, such as 0.95; otherwise, it is assigned a low value.

[0071] The final output is a sandbox execution verification report, which includes the actual execution path, a list of state changes, and the verification confidence level.

[0072] If the verification confidence exceeds a preset threshold, such as 0.9, the high-risk operation sequence is determined to indeed cause a failure in the current context and is marked as a verified event sequence. Each operation in the sequence is encapsulated in a causal anchor unit format, containing virtual operation metadata, derived quantum tags, simulated time anchor proofs, and serves as a hypothetical causal branch, anchored to the corresponding position in the dynamic causal graph. As a result, the dynamic causal graph is updated to an extended causal graph containing historical facts and verified hypotheses, providing a complete topological basis for subsequent counterfactual interventions, pollution source identification, and homomorphic compensation.

[0073] Step S40: In response to the actual logical error event, perform counterfactual virtual intervention on the suspicious event node based on the extended causal graph to identify the pollution source event and the corresponding encrypted fault propagation subgraph.

[0074] It should be noted that logical error events refer to events in which the system does not crash or exit abnormally during operation, but the business semantics violate expected rules. When the mutation index of any type of behavior flow exceeds a preset threshold for three consecutive windows, that period is marked as a suspicious behavior interval, and the corresponding event index range is recorded. Within the suspicious behavior interval, an operation dependency subgraph is constructed with system entities as nodes, operation dependencies as edges, and operation frequency as weights. A lightweight graph attention network is run to calculate the structural similarity between the current subgraph and historical normal subgraphs. If the similarity is less than 0.65 and lasts for more than 8 seconds, a logical error event is determined to have occurred, and a contamination signal containing the error type and event index is generated.

[0075] A suspicious event node refers to any ancestor node within the suspicious subgraph region of the extended causal graph that could potentially trigger the current logical error.

[0076] Counterfactual intervention is a virtual experiment method based on causal reasoning, exploring the question of "what would have happened if a certain operation had not been performed?" For each suspected event node, its execution is virtually revoked in an isolated sandbox; that is, the operation is not performed, while the remaining operations are executed in their original order. All subsequent operations from the suspected event node to the logical error event are replayed, and it is observed whether the logical error still occurs in the final state, thus identifying the source of the contamination. Starting from the source event, a subgraph is formed along all verified causal paths leading to logical errors in the extended causal graph. This subgraph is homomorphically encrypted during generation, thus generating an encrypted fault propagation subgraph.

[0077] In one feasible implementation, step S40 may include: responding to an actual logical error event, obtaining the event index corresponding to the logical error event, and locating the corresponding event node in the extended causal graph based on the event index; mapping a suspicious subgraph region centered on the event node from the extended causal graph; performing counterfactual virtual intervention on each suspicious event node in the suspicious subgraph region to determine the counterfactual probability of each suspicious event node; sorting the suspicious event nodes based on their counterfactual probabilities and selecting the event corresponding to the suspicious event node with the highest counterfactual probability as the pollution source event; starting from the pollution source event, performing reverse tracing and forward propagation analysis along the causal edges in the extended causal graph to identify all affected nodes; and encrypting all affected nodes and the causal edges between nodes using homomorphic encryption technology to generate an encrypted fault propagation subgraph.

[0078] It should be noted that when the business rule engine or monitoring system detects a logical error event, it obtains the event index of that event in the causal fingerprint chain. This index is typically the on-chain position number of the causal anchor unit or the hash value of its local quantum entanglement tag. Subsequently, based on this event index, the corresponding event node is located in the extended causal graph. Using the event node as the core, a graph traversal algorithm is used to map out the suspicious subgraph region, including reverse traversal and forward constraints. Reverse traversal refers to tracing upstream along the causal edge to the safe backtracking boundary point, i.e., the node corresponding to the most recently known clean state; forward constraints refer to only including branch paths verified as high-risk in the structured risk simulation report, ultimately resulting in a directed acyclic subgraph, i.e., the suspicious subgraph region G. suspicious =(Vs,Es), where Vs is the set of suspicious event nodes and Es is the set of causal dependency edges.

[0079] A structured causal model is constructed based on an extended causal graph, where each event node corresponds to an endogenous variable whose value is jointly determined by operational metadata and the parent node, and uncertainty is introduced through noise variables. For each suspicious event node in a suspicious subgraph region, a counterfactual virtual intervention is performed, i.e., the family do-operator intervenes in the causal model, forcibly setting the event as not having occurred, i.e., its corresponding variable takes a null value or a default safe state, while keeping the observed values ​​of all other non-descendant variables unchanged. Under this intervention condition, inference is performed using the conditional probability distribution of the causal model. Here, Y represents the state of the logical error event, for example, Y=1 indicates an error exists, Y=0 indicates normal operation. Evidence is contextual evidence observed from the production environment, including time anchors, system state snapshots, and multimodal behavioral flow features. Through Bayesian network inference, importance sampling, or variational inference methods, the probability that the system did not experience the current logical error under this intervention is determined; this is the counterfactual probability. The counterfactual probability quantifies the probability of not having experienced the current logical error if the event had not been executed initially. The counterfactual probability of all suspicious event nodes is recorded and used for subsequent contamination source ranking. The higher the counterfactual probability, the greater its causal contribution to the logical error, and the more likely it is to be the root contamination source.

[0080] The suspected event node with the highest counterfactual probability is selected as the pollution source event. This process, based on a quantitative assessment of counterfactual probability, ensures the accuracy of pollution source identification. Starting from the identified pollution source event, a backward tracing is performed along the causal edges in the extended causal graph to confirm whether its preceding dependencies are clean, thus defining the backtracking boundary. Forward propagation analysis, i.e., a depth-first search is performed along all outgoing edges to identify all sets of nodes directly or indirectly affected by it.

[0081] Homomorphic encryption is an encryption method that allows direct computation on encrypted data, and the decrypted result is identical to the result calculated on the original data. When generating an encrypted fault propagation subgraph, homomorphic encryption is used to encrypt all affected nodes and causal edges between nodes, ensuring data security and privacy during transmission and storage.

[0082] Homomorphic encryption is used to encrypt and encode all affected nodes and their connected causal edges, generating an encrypted fault propagation subgraph. Specific steps include: extracting key attributes for each node, such as operation type, affected object, and state change summary; encrypting numerical attributes using an additive homomorphic encryption scheme; hashing and then encrypting string attributes; representing causal edges as triplets (source node ID, target node ID, edge weight), and encrypting the ID and weight; and serializing the encrypted nodes and edges into a ciphertext structure to form an unreadable but computable encrypted fault propagation subgraph.

[0083] Through the above mechanism, a complete closed loop is achieved from the perception of real errors to causal attribution and then to the encapsulation of the scope of impact for privacy protection, which significantly improves the accuracy, automation level and data security of the disaster recovery system.

[0084] Step S50: Using the previous causal anchor unit of the pollution source event as the safe backtracking boundary, generate a homomorphic encrypted differential compensation transaction sequence in reverse, and generate a zero-knowledge proof of correctness based on the encrypted fault propagation subgraph and the homomorphic encrypted differential compensation transaction sequence.

[0085] It should be noted that the security backtracking boundary refers to the last trusted system state before contamination has occurred. It corresponds to the causal anchor point unit written before the contamination source event in the causal fingerprint chain. All operations after this boundary point are considered potential contamination operations and need to be eliminated in reverse through compensation transactions.

[0086] Homomorphic encryption differential compensation transaction sequence refers to the sequence of inverse operations of all causal operations triggered by pollution source events from the security backtracking boundary to the current pollution state. It achieves minimization and computable repair. The sequence is homomorphically encrypted at the time of generation and supports aggregation and verification in the ciphertext domain.

[0087] The zero-knowledge proof of recovery correctness is used to prove to the verifier that the recovery operation indeed correctly restored the system from a corrupted state to a legitimate state after the security backtracking boundary, and only affected the area defined by the cryptographic fault propagation subgraph, without revealing any specific business data. This ensures that the recovery process is verifiable and privacy-secure.

[0088] In one feasible implementation, step S50 may include: locating the reference causal anchor unit corresponding to the pollution source event in the causal fingerprint chain, and extracting the previous causal anchor unit of the reference causal anchor unit as a secure backtracking boundary; extracting all causal anchor units from the secure backtracking boundary to the pollution event from the causal fingerprint chain, and parsing the operation metadata recorded in each causal anchor unit; reverse-deriving the reverse compensation instruction corresponding to each operation based on the operation metadata, and encrypting the reverse compensation instruction using a homomorphic encryption algorithm to generate a homomorphic encrypted differential compensation transaction sequence; constructing a zero-knowledge proof circuit; associating and mapping the node information in the encrypted fault propagation subgraph with the instruction information in the homomorphic encrypted differential compensation transaction sequence to determine the fault propagation node set corresponding to each compensation instruction; inputting the homomorphic encrypted differential compensation transaction sequence and the fault propagation node set as input parameters into the zero-knowledge proof circuit to generate a restore correctness zero-knowledge proof, wherein the restore correctness zero-knowledge proof includes a proof statement, a verification public key, and verifiable proof credentials.

[0089] It should be noted that the reference causal anchor unit corresponding to the contamination source event in the causal fingerprint chain can be located by indexing and matching using the unique identifier of the contamination source event, such as the local quantum entanglement tag hash. Subsequently, the preceding causal anchor unit of this reference causal anchor unit is extracted and used as the safe backtracking boundary. This boundary represents the last uncontaminated and semantically consistent state snapshot point of the system.

[0090] Extract all causal anchor units from the safety backtracking boundary to the pollution source event from the causal fingerprint chain to form a window of operations to be compensated (safety backtracking boundary, pollution source event). For each causal anchor unit within the window, parse its recorded operation metadata, including operation type, target object, parameter value, and context.

[0091] Based on the operation metadata, the reverse compensation instructions corresponding to each operation are derived in reverse. The design of the reverse compensation instructions must ensure that they can completely offset the impact of the original operation on the system state. For example, if the original operation is a database insert operation, the reverse compensation instruction should be the corresponding delete operation; if the original operation is a file modification operation, the reverse compensation instruction should restore the file to the version before modification. All compensation instructions are represented in a structured format, such as JSON or Protocol Buffer, and are labeled with the original causal anchor unit ID to which they belong.

[0092] After deriving the reverse compensation instructions, a homomorphic encryption algorithm is used to encrypt them, generating a homomorphically encrypted differential compensation transaction sequence. Specifically, a partial homomorphic encryption scheme, such as the Paillier encryption algorithm, can be employed to encrypt numerical parameters, such as database field values ​​and file offsets, ensuring that addition operations can be directly performed in the ciphertext field, thus supporting the aggregation of multiple compensation instructions. For non-numerical parameters, such as operation types and object identifiers, a fixed-length digest is generated using a hash function, and the digest is encrypted using a symmetric encryption algorithm, such as AES, balancing security and computational efficiency. All encrypted compensation instructions are then arranged in causal order to generate a homomorphically encrypted differential compensation transaction sequence.

[0093] Furthermore, a zero-knowledge proof circuit is constructed based on the zk-SNARKs framework, whose logic includes the following constraints: consistency of the initial state, i.e., the compensation starting point is equal to the hash of the secure backtracking boundary; legality of the operation range, i.e., the target object of all compensation instructions belongs to the node in the cryptographic fault propagation subgraph; correctness of the net change, i.e., the homomorphic aggregation result of the compensation transaction sequence is equal to the theoretical difference from the current polluted state to the target state; no out-of-bounds writes, i.e., no write instructions are generated for objects outside the subgraph.

[0094] The node information in the encrypted fault propagation subgraph is associated and mapped with the instruction information in the homomorphic encrypted differential compensation transaction sequence. Specifically, the node ID is matched with the original causal anchor unit ID marked in the instruction to determine the set of fault propagation nodes corresponding to each compensation instruction. This process ensures that each compensation instruction is accurately applied to the nodes affected by the contamination, avoiding interference with normal nodes.

[0095] Subsequently, the homomorphic encrypted differential compensation transaction sequence and the set of fault propagation nodes are input parameters to a pre-constructed zero-knowledge proof circuit. This circuit verifies the input parameters based on preset constraints, such as initial state consistency, legality of the operation range, correctness of net changes, and no out-of-bounds writes. If all constraints are met, a zero-knowledge proof of recovery correctness is generated, containing a proof statement, a verification public key, and a verifiable proof credential. The proof statement declares that the homomorphic encrypted differential compensation transaction sequence can correctly restore the corrupted state to the secure backtracking boundary point. The verification public key verifies the authenticity of the proof credential, which is encrypted data calculated based on the zero-knowledge proof circuit. Recovery correctness can be verified without disclosing specific compensation instructions and fault propagation paths. Due to the characteristics of zero-knowledge proofs, the verifier cannot obtain any sensitive information about specific business data during the verification process, thus ensuring the privacy and security of the entire recovery process. This mechanism not only improves the automation and accuracy of system disaster recovery but also strengthens data privacy protection through zero-knowledge proof technology, providing solid technical support for business continuity assurance.

[0096] Step S60: Based on the homomorphic encrypted differential compensation transaction sequence, perform operation rollback and context reconstruction in the isolated environment to generate a reconstruction state to be verified, and restore the reconstruction state to the production environment based on the zero-knowledge proof of recovery correctness.

[0097] It should be noted that operation rollback refers to executing the plaintext reverse compensation instructions corresponding to the homomorphic encrypted differential compensation transaction sequence in reverse order in an isolated environment to undo all illegal or erroneous state changes caused by the contamination source event since the security backtracking boundary. Context reconstruction refers to restoring the runtime context consistent with the security backtracking boundary after completing the operation rollback. The unverified reconstruction state refers to the complete system state image obtained after completing the operation rollback and context reconstruction in the isolated environment, whose correctness has not yet been externally confirmed and is in an unverified state.

[0098] After the zero-knowledge proof of restored correctness is verified, the state to be verified is safely and atomically migrated and activated as a new state in the production environment.

[0099] This embodiment provides a time-backtracking disaster recovery method based on quantum random-causal inversion. By utilizing quantum entanglement tags to construct an immutable causal fingerprint chain, it provides a unique and random spatiotemporal anchor point for each critical operation. Then, combined with extended causal graphs and counterfactual virtual intervention analysis, it can quickly and accurately locate pollution source events and complete fault propagation subgraphs. Moreover, the tracing process is based on physical randomness, resisting prediction and forgery. The previous causal anchor point unit of the pollution source event is used as the safe backtracking boundary, and homomorphic encryption technology is used to generate differentiated compensation transactions, realizing state rollback accurate to the event level. At the same time, state recovery is performed in an isolated environment by generating zero-knowledge proofs of recovery correctness, and the recovery operation is also performed in an isolated environment, realizing fine-grained low-loss recovery, which greatly improves the credibility and security of the recovery process.

[0100] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in the first embodiment described above can be referred to the above description and will not be repeated hereafter. Based on this, step S50 includes steps S601 to S605: Step S601: Create an isolated recovery environment containing an operation rollback track and a context reconstruction track, wherein the operation rollback track is used to execute cryptographic compensation transactions, and the context reconstruction track is used to restore the complete execution context of the secure backtrack boundary.

[0101] It should be noted that the isolated recovery environment runs within the trusted execution environment and contains two logically isolated but collaborative sub-tracks: the operation rollback track and the context reconstruction track. The operation rollback track is used to execute cryptographically compensated transactions, while the context reconstruction track is used to restore the complete execution context of the secure backtracking boundary.

[0102] The operation rollback track and context rebuild track share the same sandbox namespace, but are ensured not to interfere with each other through memory region isolation and access control policies, such as eBPF LSM policy, and are both disconnected from the production network.

[0103] Step S602: Load and execute the homomorphic encrypted differential compensation transaction sequence sequentially in the operation rollback track to generate the target rollback state.

[0104] It should be noted that in the rollback operation, a homomorphic encrypted differential compensation transaction sequence is loaded sequentially. This sequence is read from the storage layer in ciphertext form and then decrypted using a private key within the trusted execution environment to obtain the plaintext reverse compensation instructions. Subsequently, these instructions are executed in reverse causal order to avoid intermediate state conflicts.

[0105] Understandably, after executing each plaintext reverse compensation instruction corresponding to an encrypted compensation transaction, an intermediate rollback state is generated, and it is verified whether the local hash of the intermediate rollback state is consistent with the event hash of the corresponding historical causal anchor unit in the causal fingerprint chain. If they are consistent, the next encrypted compensation transaction is executed until all homomorphic encrypted differential compensation transaction sequences are completed, and the target rollback state is generated.

[0106] Step S603: In the context reconstruction track, extract all causal anchor units from the initial state of the system to the safe backtracking boundary point from the causal fingerprint chain, combine them with the pre-stored lightweight incremental checkpoints, and replay the operation metadata in the sandbox according to the original time sequence to generate a reconstructed execution context snapshot.

[0107] It should be noted that in the context reconstruction track, all causal anchor units from the initial state of the system to the safe backtracking boundary point, i.e., the previous causal anchor unit of the pollution source event, are extracted from the causal fingerprint chain. Combined with pre-stored lightweight incremental checkpoints, which are generated by the system periodically and record the state summary of critical services, the operation metadata in each causal anchor unit is replayed in the sandbox according to the original occurrence sequence, and the incremental checkpoints are applied synchronously to accelerate reconstruction.

[0108] Understandably, during the replay process, a deterministic execution mode is enabled, such as a fixed random seed and disabling non-deterministic system calls, to ensure that the reconstruction results are reproducible and to generate a snapshot of the reconstructed execution context, which includes runtime semantic information such as memory state, session variables, connection pool, and cached content.

[0109] Step S604: Merge the target rollback state with the reconstructed execution context snapshot to generate a reconstructed state to be verified.

[0110] It should be noted that the target rollback state and the reconstructed execution context snapshot are fused. The fusion strategy includes: using the target rollback state as the authoritative data source at the data layer; overriding the default value with the non-persistent state in the context snapshot at the runtime layer; if there is a conflict between the two for the same object, the target rollback state takes precedence, and an audit log is recorded. The fusion result is the reconstructed state to be verified, and its overall hash is calculated and sealed within the trusted execution environment.

[0111] Step S605: Based on the zero-knowledge proof of recovery correctness, write the reconstructed state to be verified into the production environment in an atomic transaction manner, overwriting the contaminated state after the security backtracking boundary point, and complete the disaster recovery.

[0112] It's important to note that before restoring the reconstructed state to the production environment, both the reconstructed state and the zero-knowledge proof of the restoration's correctness need to be verified. After both verifications pass, an atomic transaction mechanism is used to write the reconstructed state to the production environment all at once, ensuring the integrity and consistency of the restoration process. The atomic transaction method guarantees that during the write process, either all operations succeed successfully, or none are executed, avoiding data inconsistencies caused by partial writes.

[0113] In one feasible implementation, step S605 may include: performing semantic analysis on the state to be reconstructed to determine the reconstructed semantic hash; reading the original semantic hash pre-stored at the security backtracking boundary point from the causal fingerprint chain; comparing the reconstructed semantic hash with the original semantic hash to generate a semantic consistency verification result; if the semantic consistency verification result is successful, verifying the zero-knowledge proof of recovery correctness to generate a zero-knowledge proof verification result; if the zero-knowledge proof verification result is successful, encapsulating the state to be reconstructed into a single atomic transaction and submitting it to the persistent storage layer and runtime state manager of the production environment in one go, covering all contaminated data objects and process states written after the security backtracking boundary point, and completing disaster recovery.

[0114] It should be noted that after generating the reconstructed state to be verified in the isolated recovery environment, semantic analysis is performed to extract high-level business semantic features. This analysis is executed by a semantic parsing agent deployed within a trusted execution environment. Its tasks include: traversing the key data objects in the reconstructed state; extracting semantic attribute vectors for each object based on a predefined set of business semantic rules; normalizing and sorting all semantic attribute vectors; and concatenating them into a unified string representation. A collision-resistant cryptographic hash function, such as SHA3-256 or BLAKE3, is applied to this string representation to generate a reconstructed semantic hash. This hash value uniquely represents the fingerprint of the current reconstructed state at the business semantic level, rather than underlying byte differences.

[0115] At the same time, the original semantic hash of the security backtracking boundary point is read from the causal fingerprint chain. This original semantic hash was calculated by the same semantic parsing agent based on the system state at that time when the security backtracking boundary point was written into the causal fingerprint chain, and embedded as metadata into the causal anchor unit to ensure that the source is trustworthy and cannot be tampered with.

[0116] The reconstructed semantic hash is compared byte-by-byte with the original semantic hash. If they are completely identical, a semantic consistency verification result of "pass" is generated; otherwise, it is marked as "fail." This step ensures that the reconstructed state is not only correct in data structure but also strictly consistent with the historical clean state in business logic semantics, preventing hidden failures where data is recovered but the logic remains incorrect.

[0117] If the semantic consistency verification passes, the zero-knowledge proof of recovery correctness is further cryptographically verified, specifically including: using a pre-configured zero-knowledge proof verification algorithm to parse the proof statement and verification public key in the zero-knowledge proof of recovery correctness; using elliptic curve pairing operations or homomorphic encryption verification protocols, without decrypting the homomorphic encryption differential compensation transaction sequence, verifying whether the association between the compensation instruction and the set of fault propagation nodes conforms to the expected logic; if the verification passes, a verification pass certificate is generated, allowing the state to be verified and reconstructed to be written to the production environment in an atomic transaction manner; if the verification fails, an alarm mechanism is triggered, the recovery process is terminated and rolled back to the isolated recovery environment, and the homomorphic encryption differential compensation transaction sequence is regenerated.

[0118] Understandably, the reconstructed state is only allowed to be delivered to the production environment when both verifications pass. At this point, it is encapsulated as a single atomic transaction and committed to the production environment's persistent storage layer and runtime state manager in one go. In the persistent storage layer, all contaminated data objects in the reconstructed state are packaged into a write batch and atomically written, ensuring that either all take effect or all are rolled back. In the runtime state manager, the state injection interface of each microservice is called to push the reconstructed process state to the corresponding runtime. Verification using version number or timestamp ensures that state overwriting occurs in the latest context, triggering service self-check probes to confirm successful state activation.

[0119] After submission, the system automatically cleans up all contaminated data objects and process state copies written since the security backtracking boundary point, and releases isolation and recovery environment resources. At this point, disaster recovery is complete, and the system returns to a semantically correct, causally clean, and auditable state.

[0120] Through the aforementioned dual verification and atomic commit mechanism, a full-stack guarantee from logical correctness to execution atomicity is achieved, which is significantly better than traditional recovery solutions that rely solely on log replay or snapshot overwriting.

[0121] In this embodiment, a high-fidelity, high-security, and low-interference disaster recovery state is achieved by constructing a dual-track isolation recovery mechanism and a dual-verification driven atomic submission process.

[0122] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the time-backtracking disaster recovery method based on quantum random-causal inversion in this application. Any simple transformations based on this technical concept are within the protection scope of this application.

[0123] This application also provides a time-backtracking disaster recovery device based on quantum random-causal inversion. Please refer to [link / reference]. Figure 2 The time-backtracking disaster recovery device based on quantum random-causal inversion includes: Module 10 is used to call a quantum true random number generator to generate quantum entangled tag pairs before the business system performs a critical state change, and to construct a causal fingerprint chain based on the quantum entangled tag pairs.

[0124] The deduction module 20 is used to construct a dynamic causal graph based on the causal fingerprint chain, and when a high-risk operation is detected, to perform multi-path Monte Carlo deduction on the dynamic causal graph with quantum entangled tag pairs as seeds to obtain a structured risk deduction report, wherein the structured risk deduction report includes predicted fault propagation paths and a set of potentially affected objects.

[0125] The extension module 30 is used to construct an isolation verification sandbox identified by quantum markers based on the structured risk simulation report, and to perform path verification and dynamic graph expansion based on the isolation verification sandbox to generate an extended causal graph.

[0126] Intervention module 40 is used to respond to actual logical error events, perform counterfactual virtual intervention on suspicious event nodes based on the extended causal graph, and identify pollution source events and corresponding encrypted fault propagation subgraphs.

[0127] The generation module 50 is used to generate a homomorphic encrypted differential compensation transaction sequence in reverse, using the previous causal anchor unit of the pollution source event as the safe backtracking boundary, and to generate a zero-knowledge proof of recovery correctness based on the encrypted fault propagation subgraph and the homomorphic encrypted differential compensation transaction sequence.

[0128] The recovery module 60 is used to perform operation rollback and context reconstruction in an isolated environment based on the homomorphic encrypted differential compensation transaction sequence, generate a reconstruction state to be verified, and restore the reconstruction state to the production environment based on the zero-knowledge proof of recovery correctness.

[0129] The time-backtracking disaster recovery device based on quantum random-causal inversion provided in this application employs the time-backtracking disaster recovery method based on quantum random-causal inversion described in the above embodiments, which can solve the technical problems of coarse recovery granularity, low efficiency, and weak reliable verification in existing disaster recovery technologies. Compared with the prior art, the beneficial effects of the time-backtracking disaster recovery device based on quantum random-causal inversion provided in this application are the same as those of the time-backtracking disaster recovery method based on quantum random-causal inversion provided in the above embodiments, and other technical features in the time-backtracking disaster recovery device based on quantum random-causal inversion are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0130] The above are only some embodiments of this application and do not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A time-backtracking disaster recovery method based on quantum random-causal inversion, characterized in that, The method includes: Before the business system performs a critical state change, a quantum true random number generator is invoked to generate quantum entangled tag pairs, and a causal fingerprint chain is constructed based on the quantum entangled tag pairs; A dynamic causal graph is constructed based on the causal fingerprint chain. When a high-risk operation is detected, a multi-path Monte Carlo simulation is performed on the dynamic causal graph using quantum entangled tag pairs as seeds to obtain a structured risk simulation report. The structured risk simulation report includes a predicted fault propagation path and a set of potentially affected objects. Based on the structured risk simulation report, an isolated verification sandbox identified by quantum tags is constructed. Path verification and dynamic graph expansion are performed based on the isolated verification sandbox to generate an extended causal graph. In response to actual logical error events, counterfactual virtual intervention is performed on suspicious event nodes based on the extended causal graph to identify pollution source events and corresponding encrypted fault propagation subgraphs; Using the previous causal anchor unit of the pollution source event as the safe backtracking boundary, a homomorphic encrypted differential compensation transaction sequence is generated in reverse, and a zero-knowledge proof of recovery correctness is generated based on the encrypted fault propagation subgraph and the homomorphic encrypted differential compensation transaction sequence. Based on the homomorphic encrypted differential compensation transaction sequence, operation rollback and context reconstruction are performed in an isolated environment to generate a reconstructed state to be verified. Based on the zero-knowledge proof of recovery correctness, the reconstructed state to be verified is restored to the production environment.

2. The method as described in claim 1, characterized in that, The step of calling a quantum true random number generator to generate quantum entangled tag pairs before the business system performs a critical state change, and constructing a causal fingerprint chain based on the quantum entangled tag pairs, includes: A nonlinear optical device is driven to generate polarization entangled photon pairs. Projection measurements are performed at the local measurement end and the remote witness end using a synchronous random measurement basis. The measurement results are converted into binary strings to generate local quantum entanglement tags and remote quantum entanglement tags, which constitute the quantum entanglement tag pairs. The operation metadata of the current operation, the hash value of the previous causal anchor unit, and the local quantum entanglement tag are concatenated into a challenge message, and the challenge message is input into the quantum-resistant verifiable delay function in the trusted execution environment. In the trusted execution environment, using the challenge message as the base, modular exponentiation is performed sequentially according to preset delay parameters to generate a time anchor proof; The operation metadata, the hash value of the previous causal anchor unit, the quantum entanglement tag pair, and the time anchor proof are encapsulated into the current causal anchor unit; Based on the chain node commitment value of the previous causal anchor unit, the hash digest of the current causal anchor unit, and the homomorphic commitment random number, the current chain node commitment value is calculated using the elliptic curve homomorphic commitment algorithm. The commitment value of the current chain node is used as the on-chain fingerprint of the current causal anchor unit, and an immutable causal fingerprint chain is recursively constructed.

3. The method as described in claim 2, characterized in that, The chain node commitment value is calculated using the elliptic curve homomorphic commitment algorithm based on the chain node commitment value of the previous causal anchor unit, the hash digest of the current causal anchor unit, and the homomorphic commitment random number, including: Obtain the chain node commitment value of the previous causal anchor unit, the hash digest of the current causal anchor unit, and the homomorphic commitment random number sampled from the quantum true random number generator; Publicly available base generators and blinded generators are selected on a secure elliptic curve, wherein the order of the elliptic curve is a prime number. The chain node commitment value and hash digest are concatenated into a combined message and then divided into several fixed-length message field blocks; Based on the message field block, perform elliptic curve dot product operations with the basis generators respectively to obtain several dot product result points; The homomorphic commitment random number is multiplied by the blinding generator using an elliptic curve dot product to obtain the blinding component; Perform elliptic curve point addition on each of the dot product results and the blinded component to obtain the encrypted message point set; The encrypted message point set is subjected to elliptic curve point serialization processing to generate a point serialization string; The hash function is used to calculate the serialized string of the point to generate the commitment value of the current chain node.

4. The method as described in claim 1, characterized in that, The process involves constructing a dynamic causal graph based on the causal fingerprint chain, and upon detecting a high-risk operation, performing a multi-path Monte Carlo simulation on the dynamic causal graph using quantum entangled tags as seeds to obtain a structured risk simulation report, including: Based on the causal anchor units and operational dependencies in the causal fingerprint chain, a dynamic causal graph is constructed; The system collects multimodal behavior streams in real time and determines the behavior entropy mutation index based on the multimodal behavior streams. The multimodal behavior streams include at least two types of system call sequences, database transaction logs, network traffic characteristics, and inter-process communication relationship graphs. The behavior entropy mutation index is determined based on the Shannon entropy change rate within a sliding time window. When the behavioral entropy mutation index exceeds a preset threshold for three consecutive sliding windows, a high-risk operation signal is triggered. Using the quantum entangled tag pair corresponding to the abnormal event that triggers the high-risk operation signal as a random seed, multiple parallel deduction threads are initialized, wherein each deduction thread is assigned an independent random number sequence derived from the random seed; For each simulation thread, a weighted random walk is performed on the dynamic causal graph, starting from the node corresponding to the abnormal event, to simulate the multi-directional propagation process of the fault along the causal edge and determine the propagation path and the scope of influence. The propagation paths and impact ranges of each inference thread are aggregated and analyzed to determine the probability of each propagation path being valid and the severity of its impact. Based on the probability of each propagation path's establishment and the severity of its impact, predicted fault propagation paths and sets of potentially affected objects are selected, generating a structured risk simulation report.

5. The method as described in claim 1, characterized in that, The process involves constructing an isolated verification sandbox identified by quantum markers based on the structured risk simulation report, performing path verification and dynamic graph expansion based on the isolated verification sandbox, and generating an expanded causal graph, including: The structured risk simulation report is analyzed to extract high-risk operation sequences and potentially affected object sets from the predicted failure propagation path; Using the quantum random tag hash value corresponding to the high-risk operation sequence as an identifier, an operating system-level isolated verification sandbox is created. The isolated verification sandbox achieves a closed execution environment through namespace isolation, resource quota restrictions, and system call interception mechanisms. Extract the latest consistent data snapshot of each object in the potentially affected object set from the production environment, load the consistent data snapshot into the corresponding storage location of the isolation verification sandbox, and obtain the initialized isolation verification sandbox; In the initialized isolation verification sandbox, the high-risk operation sequence is executed according to the original timing sequence to obtain the original monitoring log; Based on the original monitoring logs, event sequence reconstruction and state difference analysis are performed to generate a sandbox execution verification report, which includes the actual execution path, state change list and verification confidence level. Based on the sandbox execution verification report, the verified event sequence within the sandbox is determined, and the verified event sequence within the sandbox is used as the hypothetical causal branch to update the dynamic causal graph, generating an extended causal graph.

6. The method as described in claim 1, characterized in that, The response to the actual logical error event involves performing counterfactual virtual intervention on suspicious event nodes based on the extended causal graph to identify the contamination source event and the corresponding encrypted fault propagation subgraph, including: In response to an actual logical error event, the event index corresponding to the logical error event is obtained, and the corresponding event node is located in the extended cause-effect graph based on the event index. From the extended causal graph, a suspicious subgraph region centered on the event node is mapped out; Perform counterfactual virtual intervention on each suspicious event node within the suspicious subgraph region to determine the counterfactual probability of each suspicious event node; The suspicious event nodes are sorted according to their counterfactual probabilities, and the event corresponding to the suspicious event node with the highest counterfactual probability is selected as the pollution source event. Starting from the pollution source event, reverse tracing and forward propagation analysis are performed along the causal edges in the extended causal graph to identify all affected nodes; Homomorphic encryption technology is used to encrypt and encode all affected nodes and causal edges between nodes, generating an encrypted fault propagation subgraph.

7. The method as described in claim 1, characterized in that, The process of generating a homomorphic encrypted differential compensation transaction sequence in reverse, using the previous causal anchor unit of the pollution source event as the safe backtracking boundary, and generating a zero-knowledge proof of correctness based on the encrypted fault propagation subgraph and the homomorphic encrypted differential compensation transaction sequence, includes: Locate the reference causal anchor unit corresponding to the pollution source event in the causal fingerprint chain, and extract the previous causal anchor unit of the reference causal anchor unit as the safety backtracking boundary. Extract all causal anchor units from the security backtracking boundary to the contamination event from the causal fingerprint chain, and parse the operation metadata recorded in each causal anchor unit; Based on the operation metadata, the reverse compensation instructions corresponding to each operation are derived in reverse, and the reverse compensation instructions are encrypted using a homomorphic encryption algorithm to generate a homomorphic encrypted differential compensation transaction sequence. Constructing zero-knowledge proof circuits; The node information in the encrypted fault propagation subgraph is associated and mapped with the instruction information in the homomorphic encrypted differential compensation transaction sequence to determine the set of fault propagation nodes corresponding to each compensation instruction. The homomorphic encrypted differential compensation transaction sequence and the fault propagation node set are used as input parameters and input to the zero-knowledge proof circuit to generate a zero-knowledge proof of restored correctness. The zero-knowledge proof of restored correctness includes a proof statement, a verification public key, and verifiable proof credentials.

8. The method as described in claim 1, characterized in that, The process of performing operation rollback and context reconstruction in an isolated environment based on the homomorphic encrypted differential compensation transaction sequence to generate a reconstructed state to be verified, and restoring the reconstructed state to the production environment based on the zero-knowledge proof of recovery correctness, includes: Create an isolated recovery environment that includes an operation rollback track and a context reconstruction track, wherein the operation rollback track is used to perform cryptographic compensation transactions, and the context reconstruction track is used to restore the complete execution context of the secure backtrack boundary; The homomorphic encrypted differential compensation transaction sequence is sequentially loaded and executed in the operation rollback track to generate the target rollback state; In the context reconstruction track, all causal anchor units from the initial state of the system to the safe backtracking boundary point are extracted from the causal fingerprint chain. Combined with the pre-stored lightweight incremental checkpoints, the operation metadata is replayed in the sandbox in the original time sequence to generate a reconstructed execution context snapshot. The target rollback state is fused with the reconstructed execution context snapshot to generate a reconstruction state to be verified; Based on the zero-knowledge proof of the recovery correctness, the reconstructed state to be verified is written into the production environment in an atomic transaction manner, overwriting the contaminated state after the security backtracking boundary point, thus completing disaster recovery.

9. The method as described in claim 8, characterized in that, The process of writing the reconstructed state to be verified into the production environment using atomic transactions based on the zero-knowledge proof of recovery correctness, overwriting the contaminated state after the security backtracking boundary point, and completing disaster recovery includes: Perform semantic analysis on the reconstructed state to be verified to determine the reconstructed semantic hash; Read the pre-stored original semantic hash of the security backtracking boundary point from the causal fingerprint chain; The reconstructed semantic hash is compared with the original semantic hash to generate a semantic consistency verification result; If the semantic consistency verification result is passed, then the zero-knowledge proof of recovery correctness is verified, and a zero-knowledge proof verification result is generated. If the zero-knowledge proof verification result is successful, the state to be reconstructed is encapsulated into a single atomic transaction and submitted to the persistent storage layer and runtime state manager of the production environment in one go, overwriting all contaminated data objects and process states written after the security backtracking boundary point, thus completing disaster recovery.

10. A time-backtracking disaster recovery device based on quantum random-causal inversion, characterized in that, The device includes: The module is used to call a quantum true random number generator to generate quantum entangled tag pairs before the business system performs critical state changes, and to construct a causal fingerprint chain based on the quantum entangled tag pairs; The deduction module is used to construct a dynamic causal graph based on the causal fingerprint chain, and when a high-risk operation is detected, to perform multi-path Monte Carlo deduction on the dynamic causal graph with quantum entangled tag pairs as seeds to obtain a structured risk deduction report, wherein the structured risk deduction report includes predicted failure propagation paths and a set of potentially affected objects; The extension module is used to construct an isolated verification sandbox identified by quantum markers based on the structured risk simulation report, and to perform path verification and dynamic graph expansion based on the isolated verification sandbox to generate an extended causal graph. The intervention module is used to respond to actual logical error events, and to perform counterfactual virtual intervention on suspicious event nodes based on the extended causal graph, and to identify pollution source events and corresponding encrypted fault propagation subgraphs; The generation module is used to generate a homomorphic encrypted differential compensation transaction sequence in reverse, with the previous causal anchor unit of the pollution source event as the safe backtracking boundary, and generate a zero-knowledge proof of recovery correctness based on the encrypted fault propagation subgraph and the homomorphic encrypted differential compensation transaction sequence. The recovery module is used to perform operation rollback and context reconstruction in an isolated environment based on the homomorphic encrypted differential compensation transaction sequence, generate a reconstruction state to be verified, and restore the reconstruction state to the production environment based on the zero-knowledge proof of recovery correctness.