System and method for backing up electronic archival data offline

CN122655824APending Publication Date: 2026-08-28FUJIAN YIRONG INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610851625.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-12
Publication Date
2026-08-28

AI Technical Summary

Technical Problem

[0009]为了解决上述问题,本发明的目的在于提供一种离线备份电子档案数据的系统及方法,以解决现有电子档案离线备份缺乏凭证级固化、隔离与自动化矛盾、介质管理不可追溯、长期可用性失控、恢复验证不闭环的技术问题

Benefits of technology

1-本发明采用归档态凭证固化结合国密双层哈希链机制,突破现有固化技术瓶颈,打破现有数据拷贝式备份偏见,实现归档瞬间原始数据、元数据、签名、日志一体化固化,国密双层哈希链生成司法级可信标识,备份数据不可篡改、可直接司法采信,以解决长期凭证效力弱的问题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122655824A_ABST
    Figure CN122655824A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of smart grid and industrial automation, and particularly relates to a system and method for offline backup of electronic archive data. The present application comprises an electronic archive credentialized offline backup service layer, an isolated automation execution layer and a trusted medium storage layer. The electronic archive credentialized offline backup service layer comprises an archiving state solidification engine, a national secret hash chain generation module, a medium full life cycle trusted management module and a judicial level four-property verification module. The isolated automation execution layer comprises a physical isolation mechanical arm controller, a dual-frequency RFID trusted authentication reader-writer and an archiving snapshot directional packaging service. The present application aims to provide a system and method for offline backup of electronic archive data to solve the technical problems of lack of credential level solidification, contradiction between isolation and automation, untraceable medium management, uncontrollable long-term usability and unclosed-loop recovery verification in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of smart grid and industrial automation technology, and in particular to a system and method for offline backup of electronic archive data. Background Technology

[0002] Electronic archives, as core legal evidentiary assets of government agencies and enterprises, possess irreplaceable significance for long-term secure preservation and judicial acceptance. Compared to ordinary data backup, the core requirements for electronic archive backup are evidentiary authenticity, integrity, availability, and security (four properties). Offline backup is the ultimate security defense against cyberattacks, ransomware, and system failures. However, existing offline backup technologies for electronic archives suffer from six long-standing unresolved industry pain points and a severe lack of innovation: 1. Lack of archival status certificate solidification mechanism makes judicial acceptance difficult: Existing technology only performs simple data copying, lacking the integrated solidification of original data, metadata, signatures, and logs at the moment of archiving. Offline data is separated from the original archived state and cannot be used as judicial acceptance certificate, resulting in the loss of long-term certificate value.

[0003] 2. Weak solidification mechanism, difficult to trace tampering: Existing technology only uses a single SHA-256 hash, without the support of national cryptographic algorithms, without timestamps and identity binding, and cannot generate globally unique and tamper-proof credential identifiers. The risk of tampering is high during offline storage, and there is no basis for traceability.

[0004] 3. The contradiction between offline isolation and automation leads to an imbalance between security and efficiency: Existing technologies are either purely manual (low efficiency and high human risk) or online automated (high risk of network attack penetration), and cannot simultaneously achieve physical isolation and full-process automation, which has been a long-standing problem for the industry.

[0005] 4. Disconnected media management and lack of traceability: Existing technologies rely on manual registration or simple RFID. Physical media, data, hash, and evidence information are independent of each other. There is no four-dimensional binding ledger. Media aging, migration, and destruction are not closed-loop, making retrieval difficult and traceability ineffective.

[0006] 5. Long-term uncontrollable availability and high risk of technological obsolescence: Existing technologies lack media aging detection, automated migration, and destruction and traceability mechanisms, making it impossible to cope with the risks of media aging, outdated formats, and technological iterations. The long-term readability and usability of electronic archives are not guaranteed.

[0007] 6. The recovery verification is not closed-loop, and the validity of the certificate is unreliable: The existing technology only verifies the integrity of the data, without medium-credible authentication, hash chain comparison, on-chain evidence verification, and four-property audit. After recovery, the validity of the certificate cannot be self-proven, and the legal risks are extremely high.

[0008] Therefore, there is an urgent need for a system and method for offline backup of electronic archive data that can break through existing technological bottlenecks, possess strong creativity, and resolve the core contradictions in the industry. Summary of the Invention

[0009] To address the aforementioned problems, the present invention aims to provide a system and method for offline backup of electronic archive data, thereby resolving the technical issues of existing offline backup of electronic archives, such as lack of credential-level solidification, contradiction between isolation and automation, untraceable media management, loss of long-term availability control, and lack of closed-loop recovery verification.

[0010] In a first aspect, the present invention provides a system for offline backup of electronic archive data, the solution comprising an electronic archive voucher offline backup service layer, an isolated automated execution layer, and a trusted media storage layer; The electronic record credential offline backup service layer includes an archive state solidification engine, a national cryptographic hash chain generation module, a media lifecycle trusted management module, and a judicial-level four-property verification module. The isolated automated execution layer includes a physically isolated robotic arm controller, a dual-frequency RFID trusted authentication reader / writer, and an archive snapshot targeted packaging service; The trusted media storage layer includes a write-once read-only media interface and a tamper-proof RFID smart media library.

[0011] Furthermore, the national cryptographic hash chain generation module is specifically as follows: The system reads the original data, native metadata, digital signatures, and operation logs of electronic archives and integrates them into an immutable archived snapshot package. At the same time, the inner layer uses SHA-256 to generate a data fingerprint, and the outer layer uses the national cryptographic SM3 algorithm to integrate the timestamp, the unique ID of the medium, and the identity of the operating entity to generate a globally unique credential hash chain, which serves as a judicial-grade trusted identifier for the snapshot package.

[0012] Furthermore, the physically isolated robotic arm controller adopts an offline independent power supply and a one-way encrypted command transmission architecture to achieve isolation from the online network; and the physically isolated robotic arm controller is used to perform physical operations such as blank media grabbing, media insertion into a one-time write-only media interface, and media return to the tamper-proof RFID smart media library after backup. The dual-frequency RFID trusted authentication reader includes a low-frequency identification unit and a high-frequency reading and writing unit. Specifically, the low-frequency identification unit is used to identify the unique physical identity identifier that is written to the read-only medium once, and the high-frequency reading and writing unit is used to write the credential hash chain and blockchain evidence receipt to the medium, and read the above information during the verification stage to realize the four-dimensional trusted binding of physical medium, logical data, hash fingerprint and on-chain evidence. The archive snapshot-oriented packaging service only responds to the encryption command of the solidification engine and generates archive-state snapshot packages according to the command, and the archive snapshot-oriented packaging service does not have an external data interface.

[0013] Furthermore, the write-once read-only medium interface is used to write archived snapshot packages, credential hash chains, and blockchain evidence receipts to the write-once read-only medium; after the write operation is completed, the write-once read-only medium interface performs hardware-level read-only locking on the write-once read-only medium, and the locked medium is prohibited from any erase, write, or modification operations.

[0014] The tamper-proof RFID smart media library includes real-time temperature and humidity monitoring, tamper-proof physical alarm, and centimeter-level precise positioning module. It stores backed-up snapshot packages and synchronizes them in real time with a four-dimensional binding trusted ledger.

[0015] Secondly, the present invention provides a method for offline backup of electronic archive data, which includes the following steps: Step S1: After the archive management system completes the electronic archive archiving, it sends a backup trigger signal to the electronic archive voucher offline backup service layer through the national cryptographic encryption interface. The dedicated service layer starts the archived state snapshot solidification process, synchronously capturing the original data, native metadata, operation logs, and digital signatures to generate an unchangeable archived state snapshot package. Step S2: The offline backup service layer for electronic archive credentials issues an encryption command, the archive snapshot targeted packaging service reads the snapshot package, the national cryptographic hash chain generation module executes the inner layer SHA-256 to generate a data fingerprint and the outer layer SM3 to generate a certificate hash chain, and synchronously uploads the evidence to the chain to obtain an immutable blockchain receipt; Step S3: The media lifecycle trusted management module queries the anti-tamper RFID smart media library and automatically matches blank one-time write-only media; the physically isolated robotic arm controller grabs the blank media and inserts it into the one-time write-only media interface, and writes the snapshot package, credential hash chain and blockchain receipt in a targeted manner. Step S4: The robotic arm controller puts the written and hardware-locked read-only media back into the designated location in the media library. The media lifecycle trusted management module establishes a trusted ledger with four-dimensional binding of media ID, credential hash chain, blockchain ID, and archived version and archives it. Step S5: Perform media integrity verification and aging status detection according to the preset cycle, automatically trigger cross-media trusted migration and update the four-dimensional ledger, mark old media for secure destruction and retain the full-process audit log; Step S6: After receiving the judicial-grade recovery request, locate the target medium and load the data. The judicial-grade four-property verification module performs four-level closed-loop verification: medium trust authentication, credential hash chain comparison, blockchain evidence verification, and archive four-property compliance audit, and automatically generates a judicial-acceptable verification report.

[0016] Furthermore, in step S4, the metadata of the four-dimensional binding trusted ledger record includes the file package ID, data fingerprint, credential hash chain, blockchain transaction ID, backup time, media ID, storage location, media status, migration record, destruction log, and operation subject identity.

[0017] The present invention has the following beneficial effects: 1- This invention adopts the archiving state certificate solidification combined with the national cryptographic double-layer hash chain mechanism, which breaks through the bottleneck of existing solidification technology, breaks the bias of existing data copy backup, and realizes the integrated solidification of original data, metadata, signature and log at the moment of archiving. The national cryptographic double-layer hash chain generates a judicial-grade trusted identifier, and the backup data is tamper-proof and can be directly accepted by the judiciary, so as to solve the problem of weak long-term certificate validity.

[0018] 2- This invention employs an offline independent power supply and a robotic arm with encrypted one-way command transmission, achieving full physical isolation and eliminating network penetration paths. It also achieves full-process automation, completely solving the industry's unsolvable problem of offline security versus automation efficiency, demonstrating significant innovation.

[0019] 3- This invention constructs a trusted ledger that binds media, data, hash chain, and blockchain in four dimensions. During recovery, it performs a judicial-level four-level closed-loop verification. In the data recovery stage, it performs a four-level progressive verification of trusted media authentication, credential hash chain comparison, blockchain evidence verification, and archive compliance audit, realizing full-link trusted traceability and solving the technical problems of broken recovery verification and unreliable credential validity in the prior art.

[0020] 4. This invention enables trusted management and control of the entire lifecycle of media, integrating media aging detection, automated trusted migration, secure destruction and record keeping, and national cryptographic encryption disaster recovery ledger functions. It proactively addresses the risks brought about by media aging, outdated formats, and technological iterations, and systematically ensures that electronic archives are readable, usable, and traceable for a long time.

[0021] 5. This invention adopts the national cryptographic SM3 algorithm, write-once read-only media, and national cryptographic encrypted ledger, which is suitable for the localization and cryptographic security compliance requirements of key fields such as government affairs, power grid, and finance. Attached Figure Description

[0022] Figure 1 This is a schematic diagram of Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of Embodiment 2 of the present invention. Detailed Implementation

[0023] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments: Example 1 See Figure 1As shown, the embodiment provides a system for offline backup of electronic archive data. The solution includes an electronic archive voucher offline backup service layer, an isolated automated execution layer, and a trusted media storage layer. The electronic record credential offline backup service layer includes an archive state solidification engine, a national cryptographic hash chain generation module, a media lifecycle trusted management module, and a judicial-level four-property verification module. The isolated automated execution layer includes a physically isolated robotic arm controller, a dual-frequency RFID trusted authentication reader / writer, and an archive snapshot targeted packaging service; The trusted media storage layer includes a write-once read-only media interface and a tamper-proof RFID smart media library.

[0024] Furthermore, the national cryptographic hash chain generation module is specifically as follows: The system reads the original data, native metadata, digital signatures, and operation logs of the electronic archives and integrates them into an immutable archived snapshot package. At the same time, it adopts a national cryptographic double-layer hash chain solidification mechanism: the inner layer generates a data fingerprint using SHA-256, and the outer layer uses the national cryptographic SM3 algorithm to fuse the timestamp, the unique ID of the medium, and the identity of the operating entity to generate a globally unique credential hash chain, which serves as a judicial-grade trusted identifier for the snapshot package.

[0025] Furthermore, the outer hash uses the national cryptographic algorithm SM3, which is compatible with domestic compliance and cryptographic security requirements.

[0026] Furthermore, the physically isolated robotic arm controller adopts an offline independent power supply + encrypted command unidirectional transmission architecture, without connecting to the online network throughout the entire process, and completes the physical operations of media grabbing, inserting into the backup server and returning to the media library, completely eliminating network attack penetration paths and resolving the industry contradiction between offline isolation and automation.

[0027] The dual-frequency RFID trusted authentication reader uses low-frequency identification of the physical identity of the medium and high-frequency reading of the credential hash chain and blockchain evidence receipt to achieve a four-dimensional trusted binding of physical medium, logical data, hash fingerprint, and on-chain evidence. The archive snapshot targeted packaging service only responds to the encryption command of the solidification engine and generates archive snapshot packages in a targeted manner. It has no external data interface to prevent data leakage and tampering.

[0028] Furthermore, the write-once read-only medium interface locks the read-only state at the hardware level after the write is completed, preventing erasure, rewriting, or modification, thus eliminating the risk of secondary tampering with the offline medium; The tamper-proof RFID smart media library has built-in modules for real-time temperature and humidity monitoring, tamper-proof physical alarms, and centimeter-level precise positioning. It stores backed-up snapshot media and synchronizes four-dimensional binding trusted ledgers in real time.

[0029] Example 2 See Figure 2 As shown, the embodiment provides a method for offline backup of electronic archive data, which includes the following steps: Step S1: After the archive management system completes the electronic archive archiving, it sends a backup trigger signal to the electronic archive voucher offline backup service layer through the national cryptographic encryption interface. The dedicated service layer starts the archived state snapshot solidification process, synchronously capturing the original data, native metadata, operation logs, and digital signatures to generate an unchangeable archived state snapshot package. Step S2: The offline backup service layer for electronic archive credentials issues an encryption command, the archive snapshot targeted packaging service reads the snapshot package, the national cryptographic hash chain generation module executes the inner layer SHA-256 to generate a data fingerprint and the outer layer SM3 to generate a certificate hash chain, and synchronously uploads the evidence to the chain to obtain an immutable blockchain receipt; Step S3: The media lifecycle trusted management module queries the anti-tamper RFID smart media library and automatically matches blank one-time write-only media; the physically isolated robotic arm controller grabs the blank media and inserts it into the one-time write-only media interface, and writes the snapshot package, credential hash chain and blockchain receipt in a targeted manner. Step S4: The robotic arm controller puts the written and hardware-locked read-only media back into the designated location in the media library. The media lifecycle trusted management module establishes a trusted ledger with four-dimensional binding of media ID, credential hash chain, blockchain ID, and archived version and archives it. Step S5: Perform media integrity verification and aging status detection according to the preset cycle, automatically trigger cross-media trusted migration and update the four-dimensional ledger, mark old media for secure destruction and retain the full-process audit log; Step S6: After receiving the judicial-grade recovery request, locate the target medium and load the data. The judicial-grade four-property verification module performs four-level closed-loop verification: medium trust authentication → credential hash chain comparison → blockchain evidence verification → archive four-property compliance audit, and automatically generates a judicial-acceptable verification report.

[0030] Furthermore, in step S4, the metadata of the backup ledger records includes the file package ID, hash value, blockchain transaction ID, backup time, media ID, and storage location.

[0031] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0032] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0033] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0034] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0035] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any other way. Any person skilled in the art may make changes or modifications to the above-disclosed technical content to create equivalent embodiments. However, any simple modifications, equivalent changes, and modifications made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the protection scope of the present invention.

Claims

1. A system for offline backup of electronic archive data, characterized in that: This includes an electronic record credentialing offline backup service layer, an isolated automated execution layer, and a trusted media storage layer; The electronic record credential offline backup service layer includes an archive state solidification engine, a national cryptographic hash chain generation module, a media lifecycle trusted management module, and a judicial-level four-property verification module. The isolated automated execution layer includes a physically isolated robotic arm controller, a dual-frequency RFID trusted authentication reader / writer, and an archive snapshot targeted packaging service; The trusted media storage layer includes a write-once read-only media interface and a tamper-proof RFID smart media library.

2. The system for offline backup of electronic archive data according to claim 1, characterized in that: The national cryptographic hash chain generation module is as follows: The system reads the original data, native metadata, digital signatures, and operation logs of electronic archives and integrates them into an immutable archived snapshot package. At the same time, the inner layer uses SHA-256 to generate a data fingerprint, and the outer layer uses the national cryptographic SM3 algorithm to integrate the timestamp, the unique ID of the medium, and the identity of the operating entity to generate a globally unique credential hash chain, which serves as a judicial-grade trusted identifier for the snapshot package.

3. The system for offline backup of electronic archive data according to claim 1, characterized in that: The physically isolated robotic arm controller adopts an offline independent power supply and a one-way encrypted command transmission architecture to achieve isolation from the online network; and the physically isolated robotic arm controller is used to perform physical operations such as blank media grabbing, media insertion into a one-time write-only media interface, and media return to the tamper-proof RFID smart media library after backup. The dual-frequency RFID trusted authentication reader includes a low-frequency identification unit and a high-frequency reading and writing unit. Specifically, the low-frequency identification unit is used to identify the unique physical identity identifier that is written to the read-only medium once, and the high-frequency reading and writing unit is used to write the credential hash chain and blockchain evidence receipt to the medium, and read the above information during the verification stage to realize the four-dimensional trusted binding of physical medium, logical data, hash fingerprint and on-chain evidence. The archive snapshot-oriented packaging service only responds to the encryption command of the solidification engine and generates archive snapshot packages according to the command, and the archive snapshot-oriented packaging service does not have an external data interface.

4. The system for offline backup of electronic archive data according to claim 1, characterized in that: The write-once read-only medium interface is used to write archived snapshot packages, credential hash chains, and blockchain evidence receipts to the write-once read-only medium. After the write operation is completed, the write-once read-only medium interface performs hardware-level read-only locking on the write-once read-only medium, and the locked medium is prohibited from any erase, write, or modification operations.

5. The tamper-proof RFID smart media library includes a real-time temperature and humidity monitoring module, an anti-tamper physical alarm, and a centimeter-level precise positioning module. It stores backed-up snapshot packages and synchronizes them in real time with a four-dimensional binding trusted ledger. A method for offline backup of electronic archive data, characterized in that: Includes the following steps: Step S1: After the archive management system completes the electronic archive archiving, it sends a backup trigger signal to the electronic archive voucher offline backup service layer through the national cryptographic encryption interface. The dedicated service layer starts the archived state snapshot solidification process, synchronously capturing the original data, native metadata, operation logs, and digital signatures to generate an unchangeable archived state snapshot package. Step S2: The offline backup service layer for electronic archive credentials issues an encryption command, the archive snapshot targeted packaging service reads the snapshot package, the national cryptographic hash chain generation module executes the inner layer SHA-256 to generate a data fingerprint and the outer layer SM3 to generate a certificate hash chain, and synchronously uploads the evidence to the chain to obtain an immutable blockchain receipt; Step S3: The media lifecycle trusted management module queries the anti-tamper RFID smart media library and automatically matches blank one-time write-only media; the physically isolated robotic arm controller grabs the blank media and inserts it into the one-time write-only media interface, and writes the snapshot package, credential hash chain and blockchain receipt in a targeted manner. Step S4: The robotic arm controller puts the written and hardware-locked read-only media back into the designated location in the media library. The media lifecycle trusted management module establishes a trusted ledger with four-dimensional binding of media ID, credential hash chain, blockchain ID, and archived version and archives it. Step S5: Perform media integrity verification and aging status detection according to the preset cycle, automatically trigger cross-media trusted migration and update the four-dimensional ledger, mark old media for secure destruction and retain the full-process audit log; Step S6: After receiving the judicial-grade recovery request, locate the target medium and load the data. The judicial-grade four-property verification module performs four-level closed-loop verification: medium trust authentication, credential hash chain comparison, blockchain evidence verification, and archive four-property compliance audit, and automatically generates a judicial-acceptable verification report.

6. The method for offline backup of electronic archive data according to claim 6, characterized in that: In step S4, the metadata of the four-dimensional binding trusted ledger record includes file package ID, data fingerprint, credential hash chain, blockchain transaction ID, backup time, media ID, storage location, media status, migration record, destruction log, and operation subject identity.