Low-altitude cloud outsourcing data integrity auditing and error recovery method based on a blockchain system
Patent Information
- Application Number
- CN202611241765.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-17
- Publication Date
- 2026-09-25
AI Technical Summary
传统的完整性审计方案在验证阶段通常需要云服务器传输大量的辅助验证数据,或者需要终端设备进行密集的双线性配对等复杂密码学运算
[0044]1)本申请采用无证书密码体制结合轻量级同态验证标签,避免了低空终端设备(如无人机)在验证阶段进行密集的双线性配对等复杂密码学运算;大幅降低了系统的计算负载与通信带宽需求,有效突破了低空网络环境下带宽窄、算力弱的技术瓶颈。
Smart Images

Figure CN122824499A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, specifically to a method for auditing the integrity of outsourced low-altitude cloud data and recovering from errors based on a blockchain system. Background Technology
[0002] With the rapid development of the low-altitude economy and the Internet of Things (IoT) for unmanned aerial vehicles (UAVs), UAVs and various low-altitude terminal sensor devices are widely used in inspection, logistics, security, and other fields, generating massive amounts of low-altitude observation data. Due to the extremely limited physical size, battery capacity, and storage capacity of low-altitude terminal devices, users typically choose to upload and outsource the collected massive amounts of low-altitude data to low-altitude cloud servers with abundant computing and storage resources for hosting and storage. However, outsourcing storage means that data owners physically lose direct control over their data. Due to the complexity of cloud storage environments and the profit-driven nature of the business, cloud servers may experience data loss due to hardware failures, software errors, or internal personnel negligence; or, to save storage costs, they may deliberately delete or tamper with cold data that users haven't accessed for a long time, concealing the fact that the data is corrupted from users.
[0003] To address the aforementioned issues, the industry has proposed numerous cloud storage data integrity auditing solutions. However, these existing solutions generally face the following prominent technical bottlenecks and pain points when deployed in resource-constrained low-altitude network environments. First, the communication bandwidth and computational overhead are too high, making them unsuitable for resource-constrained low-altitude IoT environments. Low-altitude network environments (such as drone swarm communication) often suffer from narrow bandwidth, unstable communication links, and limited computing power of terminal devices. Traditional integrity auditing solutions typically require cloud servers to transmit large amounts of auxiliary verification data during the verification phase, or require terminal devices to perform complex cryptographic operations such as intensive bilinear pairing. This high communication bandwidth overhead and computational load exceed the capacity of low-altitude IoT devices, severely hindering the implementation of the solutions. Second, the lack of an effective time-state binding mechanism makes it difficult to resist historical state replay attacks. In cloud storage scenarios involving dynamic operations such as data updates and recovery, the system state is constantly changing. Many existing dynamic auditing solutions fail to effectively isolate data states at different times during their design. When a malicious cloud server loses the latest version of data blocks, it can maliciously exploit previously saved older versions (when they were not corrupted) of data and homomorphic verification tags to generate deceptive proofs (i.e., historical state replay attacks) when facing audit challenges. Due to the lack of a mechanism for strongly binding "timestamps" and "verification tags" at the underlying level, these schemes are easily deceived by cloud servers, rendering audit results invalid. Third, they emphasize detection over recovery, lacking efficient error localization and self-healing capabilities in malicious environments. Most existing auditing solutions only provide binary judgments of "data integrity" or "data corruption." Once data corruption is discovered during batch audits, due to the lack of an effective game and constraint mechanism with malicious cloud servers, the system struggles to accurately locate which concurrent data blocks were corrupted when the cloud server passively resists (refuses to cooperate with the investigation). Furthermore, existing solutions often lack deep integration of efficient fault-tolerant coding and on-chain / off-chain state synchronization mechanisms at the underlying level, making it difficult to quickly and consistently recover corrupted data.
[0004] Therefore, while securely outsourcing the storage of massive amounts of low-altitude data, ensuring continuous and reliable integrity auditing has become a critical challenge that urgently needs to be addressed. Summary of the Invention
[0005] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method for auditing the integrity of low-altitude cloud outsourcing data and recovering from errors based on a blockchain system.
[0006] The objective of this invention is achieved through the following technical solution:
[0007] This application discloses a method for data integrity auditing and error recovery in low-altitude cloud outsourcing based on a blockchain system, including the following steps:
[0008] System initialization and key generation phase: The key generation center generates public system parameters and the master private key, and generates a partial private key based on the user's identity; the user selects a secret value to generate a certificateless public key, and combines it with the partial private key to construct a complete private key;
[0009] Outsourced upload stage: The user performs symmetric encryption on the original file to obtain the encrypted file. Based on erasure coding technology, the encrypted file is segmented and encoded to generate a set of encoded data blocks containing redundant data. A certificateless homomorphic verification tag is generated for each encoded data block. A rank Merkle tree is constructed, and the file metadata containing the root hash is uploaded to the blockchain. The encoded data blocks and tags are outsourced to a low-altitude cloud server.
[0010] Integrity audit phase: Users initiate batch audit challenges based on files or timestamps through blockchain smart contracts; after receiving the challenge, the cloud server performs linear combination of the requested data blocks and tags to generate aggregate audit proofs; the smart contract uses bilinear pairing equations to automatically verify the aggregate audit proofs, and if the verification fails, error location is triggered.
[0011] Error localization phase: When smart contract verification fails, a stack-based binary search algorithm is used to continuously halve the challenge set into left and right subsets and request the cloud server to generate sub-proofs; the smart contract verifies the sub-proofs in parallel, and locks and outputs the index set of all damaged data blocks through push and pop operations;
[0012] Data recovery and state synchronization phase: The user retrieves the undamaged data blocks from the cloud server, constructs a full-rank submatrix and calculates its inverse matrix, decodes and recovers the damaged original data blocks; uses the latest timestamp to generate new homomorphic verification labels for the recovered data blocks, reconstructs the rank Merkle tree, updates the metadata state on the blockchain through smart contracts, and finally overwrites the erroneous data in the cloud with the recovered data blocks and new labels.
[0013] Furthermore, the system initialization and key generation phase specifically includes the following steps:
[0014] S21. Key Generation Center (KGC) sets up bilinear pairing mapping. ,in, yes First-order multiplicative cyclic group yes Second-order multiplicative cyclic group yes Third-order multiplicative cyclic group yes generator, yes Generators;
[0015] S22, KGC in finite field of order Select non-zero random numbers from As the master private key And calculate the master public key. ;
[0016] S23, KGC sets up four secure hash functions , , , ,in Indicates the output length. For a finite field;
[0017] S24, System users identify themselves Submitted to KGC, KGC calculates the hash function value. Generate the first part of the private key and will Return to system user DO;
[0018] S25, System User DO received Then, through the formula Verify the correctness of the first part of the private key; if the verification fails, DO will reject the first part of the private key and request it again;
[0019] S26, DO finite field of order Select a non-zero random number x as the second part of the private key, and calculate its certificateless public key. Set the final private key of DO to ;
[0020] S27, KGC publishes system public parameter set And secretly store the master private key .
[0021] Preferably, the outsourced upload stage specifically includes the following steps:
[0022] S31, DO via symmetric key and symmetric encryption algorithms Given the original file Encrypt to obtain the ciphertext file ;
[0023] S32, transfer the encrypted file Divided into Each original data block is represented as a column vector, i.e. , Let represent the transpose matrix, where Represents each raw data block;
[0024] S33. To achieve data fault tolerance and recoverability, the system user DO adopts a system based on... finite field of order Erasure coding matrix ;DO in finite field of order Openly select two disjoint sets of nonzero elements: containing A collection of distinct elements and including A collection of distinct elements And guarantee ,in Let represent the empty set; then construct the following... Cauchy matrix: ;DO performs matrix multiplication to generate extended vectors Furthermore, all addition and multiplication operations are performed within a finite field. Next step: The calculated extended vector Includes One encoded data block, i.e. ;matrix any of the following Lines All submatrices are of full rank;
[0025] S34. Calculate the hash function value To hide the original timestamp In the first multiplication cycle group Randomly select elements Calculate the encoded data block Homomorphic verifiable tags ,in Indicates the file name. Indicates the sequence number of the encoded data block;
[0026] S35. Construct a rank-merck hash tree whose leaf nodes are hash function values. Calculate the hash value of the root node sequentially upwards. Then calculate the file metadata. ;
[0027] S36, DO creates a hash value and transaction address The transaction is processed and the payment amount is deposited; then, DO sends the transaction to the blockchain and stores the data. The data is sent to the low-altitude cloud storage server CS; finally, the low-altitude cloud storage server CS stores the data. To store, among which This represents the set of homomorphic verifiable tags for encoded data blocks.
[0028] Preferably, in the integrity audit phase, the DO performs probabilistic checks on the integrity of the outsourced data using a batch verification method. First, the DO initiates an audit request and sends the corresponding data to the blockchain. Then, the CS responds to the audit request according to the DO's requirements and generates proof information. Finally, the smart contract verifies that the CS provides proof information and publishes the verification result on the blockchain. If the verification fails, an error location algorithm is triggered to accurately locate the index of the corrupted data block.
[0029] Preferably, the file-based batch audit challenge described in the integrity audit phase specifically includes the following steps:
[0030] S401, DO finite field of order Selected from non-zero random numbers ( ) and the corresponding non-zero random number and will set up challenges Send to the low-altitude cloud server CS;
[0031] S402, When CS receives a set of challenges Then, calculate the linear combination value of the data blocks. , Indicates the sequence number is Calculate the aggregate label for the corresponding encoded data block. ,in Indicates being challenged The corresponding homomorphic verification label As the base, and the challenged The corresponding serial number is The random challenge coefficient is an exponentiation operation; for the th Each encoded data block, CS calculates auxiliary information. Based on the first For each leaf node to the root node, the CS collects information about all adjacent nodes that are not part of the path but are connected to the path node; if the CS honestly stores the user data, then the proof can be calculated through the equation. Then forward containing The transactions, among which, Indicates the calculation of the root hash Required auxiliary path information Represents the set of homomorphic verifiable labels for the coded data blocks that are being sampled and challenged;
[0032] S403, the smart contract uses the auxiliary path information provided by CS. and the calculated bottom leaf nodes Recalculate the root hash value of the Merck hash tree from bottom to top. and check Check if the condition is met; if not, the verification fails, and the smart contract is deactivated. identity and public key Verify equation Check if the equation is true; if it is true, output verification result 1; otherwise, output verification result 0; finally, write the final verification result into the block and trigger the error location and data recovery procedure.
[0033] Preferably, the timestamp-based batch audit challenge in the integrity audit phase specifically includes the following steps:
[0034] S411, Regarding timestamps Below, CS stores the system users' data. There are 1 file, and the file collection is 1 Each file Contains several coded data blocks and its corresponding certificateless homomorphic tag ;
[0035] S412, When a validator initiates a request targeting a specific timestamp When submitting an audit request, instead of challenging a single file, a global challenge set is generated for all files under that timestamp. ,in In response to The first challenge subset of each file, for any file Its second challenge subset is defined as ,in Represents a file The randomly selected first One coded data block Index; Represented as encoded data blocks The challenge level is randomly assigned. The total number of data blocks sampled from this file; the validator will use the global challenge set. Published to the blockchain network;
[0036] S413, The blockchain network forwards the challenge set to CS, and CS receives the challenge requests. Next, verify the timestamp. Is it valid? Once valid, generate an aggregated audit certificate based on the file blocks and tags under the corresponding timestamps stored locally. CS performs a global linear combination of all involved file blocks using a formula. Calculate aggregated data blocks ,in Indicates that the index is The encoded data block; CS aggregates all corresponding certificateless homomorphic verification tags, using the formula Calculate global aggregation tags ,in Indicates the coded data block that is being challenged. The homomorphic label is used as the base, and the corresponding challenge coefficient is used as the exponent for power operation; after the calculation is completed, CS will conduct batch audits to prove it. Return to the verifier;
[0037] S414. The verifier receives the audit certificate. Then, using DO's certificateless public key and the system's master public key Perform batch verification to test the equations. Whether it holds true, among which, the aggregation challenge coefficient Aggregate hashing for replay prevention If the equation is true, output verification result 1, proving that all outsourced file data under this timestamp is intact; otherwise, output verification result 0 and trigger the location and data recovery program; finally, write the final verification result into the block.
[0038] Preferably, the error localization stage specifically includes the following steps:
[0039] S501. Assume that the initial global challenge set currently found to be compromised in terms of integrity is as follows: The smart contract initializes an empty stack and an error set to store indices of corrupted data blocks. ; Set the initial global challenge set Push onto the stack; when the stack is not empty, pop the top set from the stack. If set Size Divide it into two disjoint left subsets at its physical midpoint. and right subset ;
[0040] S502, the smart contract sends a partitioning instruction to the CS. After receiving the subset partitioning instruction, it calculates the local aggregation proofs respectively; for the left subset... Calculate the linear combination value of the data blocks in the left subset. and aggregation tags For the right subset Calculate the linear combination value of its data blocks. With aggregation tags ; then CS will prove the left subset. Proof with right subset Return to the smart contract;
[0041] S503, smart contracts are based on the latest on-chain timestamp. Calculate the left subset Local challenge coefficient and local hash aggregation Calculate the right subset Local challenge coefficient and local hash aggregation Then, using equations and Perform independent verification; if both equations fail verification, it indicates that both the left and right halves contain errors. The smart contract will first process the right half of the set. Push it onto the stack, then move the left half of the set. Push it onto the stack; if only one equation fails to be verified, it means that the error only exists in the subset of equations that failed to be verified, and then the smart contract pushes it onto the stack.
[0042] S504, When the pop-up collection Size Furthermore, if the equation verification fails, it is determined that the individual data block corresponding to that set is corrupted, and its index is recorded in the corrupted index set. In the middle; when the stack is empty, all damaged branches are exhausted, and the algorithm outputs a complete set of damaged indices. The process then enters the data recovery and status synchronization phase.
[0043] The beneficial effects of this invention are:
[0044] 1) This application adopts a certificateless cryptographic system combined with a lightweight homomorphic verification tag, which avoids the need for low-altitude terminal devices (such as drones) to perform complex cryptographic operations such as intensive bilinear pairing during the verification stage; it significantly reduces the system's computational load and communication bandwidth requirements, and effectively breaks through the technical bottleneck of narrow bandwidth and weak computing power in low-altitude network environments.
[0045] 2) This application addresses the characteristic of constantly changing system states in dynamic cloud storage environments by strongly binding timestamps and homomorphic verification tags at the underlying level; thereby effectively isolating data states at different times, preventing malicious cloud servers from using old versions of data and tags from the past when they were not damaged to generate deceptive proofs, and ensuring the absolute timeliness and reliability of data auditing.
[0046] 3) This application completely breaks through the limitations of traditional solutions that prioritize detection over recovery. When data corruption is detected, a stacked binary search algorithm combined with smart contract constraints is used to efficiently and accurately lock the indexes of all damaged data blocks in parallel, even in a malicious environment where the cloud server passively resists. Simultaneously, the outsourcing phase introduces Cauchy matrix erasure coding technology. Users only need to obtain a sufficient number of undamaged encoded blocks from the cloud to construct a full-rank submatrix and find its inverse, thus restoring the original data losslessly and quickly, giving the system extremely strong fault tolerance and self-healing capabilities.
[0047] 4) This application replaces the traditional third-party auditing institution with a blockchain network, stores file metadata (such as the root hash of the Rank Merkle Tree RMHT) on the chain to ensure that core parameters are not tampered with; at the same time, it uses smart contracts to realize the automated verification of proofs and the real-time synchronization and updating of status, and directly triggers economic penalties when the cloud server refuses to cooperate with the error location, thus constructing a constraint mechanism for malicious cloud environments.
[0048] 5) Provides two modes: general file auditing and timestamp-based batch auditing; in particular, timestamp-based batch auditing allows users to launch a global challenge for all outsourced files within a specific billing cycle or lifecycle; by aggregating data blocks and aggregate tags, smart contracts only need to perform batch verification once to confirm the integrity of all data under that timestamp, which greatly improves the auditing efficiency of massive amounts of data. Attached Figure Description
[0049] Figure 1 This is a schematic diagram illustrating the steps of a low-altitude cloud outsourcing data integrity audit and error recovery method based on a blockchain system, according to an embodiment of the present invention. Detailed Implementation
[0050] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0051] This application discloses a method for low-altitude cloud outsourcing data integrity auditing and error recovery based on a blockchain system, the steps of which are illustrated in the diagram below. Figure 1 As shown, it includes the following steps:
[0052] S1. System Initialization and Key Generation Phase: The key generation center generates public system parameters and the master private key, and generates a partial private key based on the user's identity; the user selects a secret value to generate a certificateless public key, and combines it with the partial private key to construct a complete private key;
[0053] S2, Outsourced Upload Stage: The user performs symmetric encryption on the original file to obtain the encrypted file. Based on erasure coding technology, the encrypted file is segmented and encoded to generate a set of encoded data blocks containing redundant data. A certificateless homomorphic verification tag is generated for each encoded data block. A rank Merkle tree is constructed, and the file metadata containing the root hash is uploaded to the blockchain. The encoded data blocks and tags are outsourced to a low-altitude cloud server.
[0054] S3, Integrity Audit Phase: Users initiate batch audit challenges based on files or timestamps through blockchain smart contracts; after receiving the challenge, the cloud server performs linear combination of the requested data blocks and tags to generate aggregate audit proofs; the smart contract uses bilinear pairing equations to automatically verify the aggregate audit proofs, and if the verification fails, error location is triggered;
[0055] S4, Error Localization Phase: When the smart contract verification fails, the stack-based binary search algorithm is used to continuously halve the challenge set into left and right subsets and request the cloud server to generate sub-proofs; the smart contract verifies the sub-proofs in parallel, and locks and outputs the index set of all damaged data blocks through push and pop operations;
[0056] S5, Data Recovery and State Synchronization Phase: The user retrieves undamaged data blocks from the cloud server, constructs a full-rank submatrix and calculates its inverse matrix, decodes and recovers the damaged original data blocks; uses the latest timestamp to generate new homomorphic verification tags for the recovered data blocks, reconstructs the rank Merkle tree, updates the metadata state on the blockchain through smart contracts, and finally overwrites the erroneous data in the cloud with the recovered data blocks and new tags.
[0057] For example, in the system initialization and key generation phase, the Key Generation Center (KGC) generates public system parameters and a master private key. System users authenticate their identities with the KGC, specifically including the following steps:
[0058] S21, KGC sets up bilinear pairing mapping ,in, yes First-order multiplicative cyclic group yes Second-order multiplicative cyclic group yes Third-order multiplicative cyclic group yes generator, yes Generators;
[0059] S22, KGC in finite field of order Select non-zero random numbers from As the master private key And calculate the master public key. ;
[0060] S23, KGC sets up four secure hash functions , , , ,in Indicates the output length. For a finite field;
[0061] S24, System users identify themselves Submitted to KGC, KGC calculates the hash function value. Generate the first part of the private key and will Return to system user DO;
[0062] S25, System User DO received Then, through the formula Verify the correctness of the first part of the private key; if the verification fails, DO will reject the first part of the private key and request it again;
[0063] S26, DO finite field of order Select a non-zero random number x as the second part of the private key, and calculate its certificateless public key. Set the final private key of DO to ;
[0064] S27, KGC publishes system public parameter set And secretly store the master private key .
[0065] For example, in the outsourced upload stage, the user encrypts and encodes the outsourced data in blocks, calculates the corresponding tags, and outsources the data to the low-altitude cloud storage server, specifically including the following steps:
[0066] S31, DO via symmetric key and symmetric encryption algorithms Given the original file Encrypt to obtain the ciphertext file ;
[0067] S32, transfer the encrypted file Divided into Each original data block is represented as a column vector, i.e. , Let represent the transpose matrix, where Represents each raw data block;
[0068] S33. To achieve data fault tolerance and recoverability, the system user DO adopts a system based on... finite field of order Erasure coding matrix ;DO in finite field of order Openly select two disjoint sets of nonzero elements: containing A collection of distinct elements and including A collection of distinct elements And guarantee ,in Let represent the empty set; then construct the following... Cauchy matrix: ;DO performs matrix multiplication to generate extended vectors Furthermore, all addition and multiplication operations are performed within a finite field. Next step: The calculated extended vector Includes One encoded data block, i.e. ;matrix any of the following Lines All submatrices are of full rank;
[0069] S34. Calculate the hash function value To hide the original timestamp In the first multiplication cycle group Randomly select elements Calculate each coded data block Homomorphic verifiable tags ,in Indicates the file name. Indicates the sequence number of the encoded data block;
[0070] S35. Construct a rank-merck hash tree whose leaf nodes are hash function values. Calculate the hash value of the root node sequentially upwards. Then calculate the file metadata. ; It contains all the core parameters required for auditing, and by attaching a signature, it ensures that this metadata will not be tampered with when it is in the cloud or recorded on the blockchain;
[0071] S36, DO creates a hash value and transaction address The transaction is processed and the payment amount is deposited; then, DO sends the transaction to the blockchain and stores the data. The data is sent to the low-altitude cloud storage server CS; finally, the low-altitude cloud storage server CS stores the data. To store, among which This represents the set of homomorphic verifiable tags for encoded data blocks.
[0072] For example, in the integrity audit phase, the DO performs probabilistic checks on the integrity of outsourced data using a batch verification method. First, the DO initiates an audit request and sends the corresponding data to the blockchain. Then, the CS responds to the audit request according to the DO's requirements and generates proof information. Finally, the smart contract verifies the proof information provided by the CS and publishes the verification result on the blockchain. If the verification fails, an error location algorithm is triggered to accurately locate the index of the corrupted data block. This phase has two methods: general file audit and timestamp-based batch audit. Users can choose the appropriate audit method according to their needs.
[0073] For example, when DO wants to check the file name is When determining whether the data in a file is complete, the file-based batch auditing challenge specifically includes the following steps:
[0074] S401, DO finite field of order Selected from non-zero random numbers ( ) and the corresponding non-zero random number and will set up challenges Send to the low-altitude cloud server CS;
[0075] S402, When CS receives a set of challenges Then, calculate the linear combination value of the data blocks. , Indicates the sequence number is Calculate the aggregate label for the corresponding encoded data block. ,in Indicates being challenged The corresponding homomorphic verification label As the base, and the challenged The corresponding serial number is The random challenge coefficient is an exponentiation operation; for the th Each encoded data block, CS calculates auxiliary information. Based on the first For each leaf node to the root node, the CS collects information about all adjacent nodes that are not part of the path but are connected to the path node; if the CS honestly stores the user data, then the proof can be calculated through the equation. Then forward containing The transactions, among which, Indicates the calculation of the root hash Required auxiliary path information Represents the set of homomorphic verifiable labels for the coded data blocks that are being sampled and challenged;
[0076] S403, the smart contract uses the auxiliary path information provided by CS. and the calculated bottom leaf nodes Recalculate the root hash value of the Merck hash tree from bottom to top. and check Check if the condition is met; if not, the verification fails, and the smart contract is deactivated. identity and public key Verify equation Check if the equation is true; if it is true, output verification result 1; otherwise, output verification result 0; finally, write the final verification result into the block and trigger the error location and data recovery procedure.
[0077] For example, in actual outsourced storage billing and management, users typically need to verify the integrity of all outsourced files within a specific timestamp (i.e., a billing period or storage lifecycle). Relying solely on homomorphic aggregate signatures bound to strong timestamps, the challenges of timestamp-based batch auditing specifically include the following steps:
[0078] S411, Regarding timestamps Below, CS stores the system users' data. There are 1 file, and the file collection is 1 Each file Contains several coded data blocks and its corresponding certificateless homomorphic tag ;
[0079] S412, When a validator initiates a request targeting a specific timestamp When submitting an audit request, instead of challenging a single file, a global challenge set is generated for all files under that timestamp. ,in In response to The first challenge subset of each file, for any file Its second challenge subset is defined as ,in Represents a file The randomly selected first One coded data block Index; Represented as encoded data blocks The challenge level is randomly assigned. The total number of data blocks sampled from this file; the validator will use the global challenge set. Published to the blockchain network;
[0080] S413, The blockchain network forwards the challenge set to CS, and CS receives the challenge requests. Next, verify the timestamp. Is it valid? Once valid, generate an aggregated audit certificate based on the file blocks and tags under the corresponding timestamps stored locally. CS performs a global linear combination of all involved file blocks using a formula. Calculate aggregated data blocks ,in Indicates that the index is The encoded data block; CS aggregates all corresponding certificateless homomorphic verification tags, using the formula Calculate global aggregation tags ,in Indicates the coded data block that is being challenged. The homomorphic label is used as the base, and the corresponding challenge coefficient is used as the exponent for power operation; after the calculation is completed, CS will conduct batch audits to prove it. Return to the verifier;
[0081] S414. The verifier receives the audit certificate. Then, using DO's certificateless public key and the system's master public key Perform batch verification to test the equations. Whether it holds true, among which, the aggregation challenge coefficient Aggregate hashing for replay prevention If the equation holds true, output verification result 1 (verification passed), proving that all outsourced file data under this timestamp is intact (in the tag). The timeliness of the data has been implicitly verified. (No additional MHT path transmission is required); otherwise, output verification result 0 (verification failed) and trigger the location and data recovery procedure; finally, write the final verification result to the block.
[0082] For example, if the verification result is 0 (verification failed), it indicates that one or more corrupted ciphertext data blocks exist in the data set stored on the server. In an untrusted cloud environment, a malicious client (CS) may refuse to cooperate in executing the location procedure. Therefore, this solution adopts a strategy combining smart contract detection and a stack-based binary search method. The smart contract forces the CS to perform homomorphic aggregation proofs for a specific subset. If the CS refuses to respond, an economic penalty is directly executed through the smart contract, and the entire subset is determined to be corrupted. If the CS cooperates, multiple concurrent errors are efficiently located. The error location stage (taking general file auditing as an example) specifically includes the following steps:
[0083] S501. Assume that the initial global challenge set currently found to be compromised in terms of integrity is as follows: The smart contract initializes an empty stack and an error set to store indices of corrupted data blocks. ; Set the initial global challenge set Push onto the stack; when the stack is not empty, pop the top set from the stack. If set Size Divide it into two disjoint left subsets at its physical midpoint. and right subset ;
[0084] S502, the smart contract sends a partitioning instruction to the CS. After receiving the subset partitioning instruction, it calculates the local aggregation proofs respectively; for the left subset... Calculate the linear combination value of the data blocks in the left subset. and aggregation tags For the right subset Calculate the linear combination value of its data blocks. With aggregation tags ; then CS will prove the left subset. Proof with right subset Return to the smart contract;
[0085] S503, smart contracts are based on the latest on-chain timestamp. Calculate the left subset Local challenge coefficient and local hash aggregation Calculate the right subset Local challenge coefficient and local hash aggregation Then, using equations and Perform independent verification; if both equations fail verification, it indicates that both the left and right halves contain errors. The smart contract will first process the right half of the set. Push the left half of the set onto the stack (as a backtracking marker), then push the left half of the set onto the stack. Push it onto the stack (prioritize further searching); if only one equation fails verification, it means the error exists only in the subset corresponding to the failed equations, and then the smart contract pushes it onto the stack;
[0086] S504, When the pop-up collection Size Furthermore, if the equation verification fails, it is determined that the individual data block corresponding to that set is corrupted, and its index is recorded in the corrupted index set. In the middle; when the stack is empty, all damaged branches are exhausted, and the algorithm outputs a complete set of damaged indices. The process then enters the data recovery and status synchronization phase.
[0087] For example, the correctness analysis of this application is as follows:
[0088] File-based batch audit verification of correctness: In the file-based batch audit phase, the smart contract needs to verify the validity of the aggregate audit proof generated by the Low Altitude Cloud Storage Server (CS); assuming the smart contract receives a file named... of Aggregation label of each encoded data block and linear combination value To efficiently verify the integrity of encrypted data, smart contracts utilize bilinear pairwise computation to verify the validity of equations. The specific derivation process is as follows:
[0089]
[0090] The correctness of timestamp-based batch audit verification: In timestamp-based batch auditing, smart contracts verify specific timestamps. The integrity of all files under this time. Assume the low-altitude cloud storage server returns the contents of all files under this timestamp. Global aggregation tags for files Aggregated data blocks Aggregate challenge coefficient And aggregate hashing for replay prevention Smart contracts also utilize bilinear pairing to verify whether their equations strictly hold true. The specific derivation process is as follows:
[0091]
[0092] The above description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the concept described herein through the above teachings or related technologies or knowledge. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.
Claims
1. A method for data integrity auditing and error recovery in low-altitude cloud outsourcing based on a blockchain system, characterized in that: Includes the following steps: System initialization and key generation phase: The key generation center (KGC) generates the system's public parameters and master private key, and generates a partial private key based on the user's identity. The user selects a secret value to generate a certificateless public key, and combines it with a portion of the private key to construct a complete private key. Outsourced upload stage: The user symmetrically encrypts the original file to obtain the encrypted file. The encrypted file is then segmented and encoded based on erasure coding technology to generate a set of encoded data blocks containing redundant data. Generate a certificateless homomorphic verification tag for each encoded data block; Construct a Merkle tree and upload the file metadata containing the root hash to the blockchain, while outsourcing the encoded data blocks and tags to a low-altitude cloud server; Integrity audit phase: Users initiate batch audit challenges based on files or timestamps via blockchain smart contracts; After receiving the challenge, the cloud server performs a linear combination of the requested data blocks and tags to generate an aggregate audit proof; the smart contract uses a bilinear pairing equation to automatically verify the aggregate audit proof, and if the verification fails, it triggers error location. Error localization phase: When smart contract verification fails, a stack-based binary search algorithm is used to continuously halve the challenge set into left and right subsets and request the cloud server to generate sub-proofs; the smart contract verifies the sub-proofs in parallel, and locks and outputs the index set of all damaged data blocks through push and pop operations; Data recovery and state synchronization phase: The user retrieves the undamaged data blocks from the cloud server, constructs a full-rank submatrix and calculates its inverse matrix, and decodes and recovers the damaged original data blocks; The latest timestamp is used to generate new homomorphic verification labels for the recovered data blocks, the rank Merkle tree is reconstructed, the metadata state on the blockchain is updated through smart contracts, and finally the erroneous data in the cloud is overwritten by the recovered data blocks and new labels.
2. The method for low-altitude cloud outsourcing data integrity auditing and error recovery based on a blockchain system according to claim 1, characterized in that, The system initialization and key generation phase specifically includes the following steps: S21. Key Generation Center (KGC) sets up bilinear pairing mapping. ,in, yes First-order multiplicative cyclic group yes Second-order multiplicative cyclic group yes Third-order multiplicative cyclic group yes generator, yes Generators; S22, KGC in finite field of order Select non-zero random numbers from As the master private key And calculate the master public key. ; S23, KGC sets up four secure hash functions , , , ,in Indicates the output length. For a finite field; S24, System users identify themselves Submitted to KGC, KGC calculates the hash function value. Generate the first part of the private key and will Return to system user DO; S25, System User DO received Then, through the formula Verify the correctness of the first part of the private key; if the verification fails, DO will reject the first part of the private key and request it again; S26, DO finite field of order Select a non-zero random number x as the second part of the private key, and calculate its certificateless public key. Set the final private key of DO to ; S27, KGC publishes system public parameter set And secretly store the master private key .
3. The method for low-altitude cloud outsourcing data integrity auditing and error recovery based on a blockchain system according to claim 2, characterized in that: The outsourced upload stage specifically includes the following steps: S31, DO via symmetric key and symmetric encryption algorithms Given the original file Encrypt to obtain the ciphertext file ; S32, transfer the encrypted file Divided into Each original data block is represented as a column vector, i.e. , Let represent the transpose matrix, where Represents each raw data block; S33. To achieve data fault tolerance and recoverability, the system user DO adopts a system based on... finite field of order Erasure coding matrix ;DO in finite field of order Openly select two disjoint sets of nonzero elements: containing A collection of distinct elements and including A collection of distinct elements And guarantee ,in Let represent the empty set; then construct the following... Cauchy matrix: ;DO performs matrix multiplication to generate extended vectors Furthermore, all addition and multiplication operations are performed within a finite field. Next step: The calculated extended vector Includes One encoded data block, i.e. ;matrix any of the following Lines All submatrices are of full rank; S34. Calculate the hash function value To hide the original timestamp In the first multiplication cycle group Randomly select elements Calculate the encoded data block Homomorphic verifiable tags ,in Indicates the file name. Indicates the sequence number of the encoded data block; S35. Construct a rank-merck hash tree whose leaf nodes are hash function values. Calculate the hash value of the root node sequentially upwards. Then calculate the file metadata. ; S36, DO creates a hash value and transaction address The transaction is processed and the payment amount is deposited; then, DO sends the transaction to the blockchain and stores the data. The data is sent to the low-altitude cloud storage server CS; finally, the low-altitude cloud storage server CS stores the data. To store, among which This represents the set of homomorphic verifiable tags for encoded data blocks.
4. The method for low-altitude cloud outsourcing data integrity auditing and error recovery based on a blockchain system according to claim 3, characterized in that: During the integrity audit phase, the DO performs probabilistic checks on the integrity of outsourced data using a batch verification method. First, the DO initiates an audit request and sends the corresponding data to the blockchain. Then, the CS responds to the audit request according to the DO's requirements and generates proof information. Finally, the smart contract verifies the proof information provided by the CS and publishes the verification result on the blockchain. If the verification fails, an error location algorithm is triggered to accurately locate the index of the corrupted data block.
5. The method for low-altitude cloud outsourcing data integrity auditing and error recovery based on a blockchain system according to claim 4, characterized in that: The file-based batch audit challenges described in the integrity audit phase specifically include the following steps: S401, DO finite field of order Selected from non-zero random numbers ( ) and the corresponding non-zero random number and will set up challenges Send to the low-altitude cloud server CS; S402, When CS receives a set of challenges Then, calculate the linear combination value of the data blocks. , Indicates the sequence number is Calculate the aggregate label for the corresponding encoded data block. , among which Indicates being challenged The corresponding homomorphic verification label As the base, and the challenged The corresponding serial number is The random challenge coefficient is an exponentiation operation; for the first... Each encoded data block, CS calculates auxiliary information. Based on the first For each leaf node to the root node, the CS collects information about all adjacent nodes that are not part of the path but are connected to the path node; if the CS honestly stores the user data, then the proof can be calculated through the equation. Then forward containing The transactions, among which, Indicates the calculation of the root hash Required auxiliary path information Represents the set of homomorphic verifiable labels for the coded data blocks that are being sampled and challenged; S403, the smart contract uses the auxiliary path information provided by CS. and the calculated bottom leaf nodes Recalculate the root hash value of the Merck hash tree from bottom to top. and check Check if the condition is met; if not, the verification fails, and the smart contract is deactivated. identity and public key Verify equation Check if the equation is true; if it is true, output verification result 1; otherwise, output verification result 0; finally, write the final verification result into the block and trigger the error location and data recovery procedure.
6. The method for low-altitude cloud outsourcing data integrity auditing and error recovery based on a blockchain system according to claim 4, characterized in that: The timestamp-based batch audit challenges described in the integrity audit phase specifically include the following steps: S411, Regarding timestamps Below, CS stores the system users' data. There are 1 file, and the file collection is 1 Each file Contains several coded data blocks and its corresponding certificateless homomorphic tag ; S412, When a validator initiates a request targeting a specific timestamp When submitting an audit request, instead of challenging a single file, a global challenge set is generated for all files under that timestamp. ,in In response to The first challenge subset of each file, for any file Its second challenge subset is defined as ,in Represents a file The randomly selected first One coded data block Index; Represented as encoded data blocks The challenge level is randomly assigned. The total number of data blocks sampled from this file; the validator will use the global challenge set. Published to the blockchain network; S413, The blockchain network forwards the challenge set to CS, and CS receives the challenge requests. Next, verify the timestamp. Is it valid? Once valid, generate an aggregated audit certificate based on the file blocks and tags under the corresponding timestamps stored locally. CS performs a global linear combination of all involved file blocks using a formula. Calculate aggregated data blocks ,in Indicates that the index is The encoded data block; CS aggregates all corresponding certificateless homomorphic verification tags, using the formula Calculate global aggregation tags ,in Indicates the coded data block that is being challenged. The homomorphic label is used as the base, and the corresponding challenge coefficient is used as the exponent for power operation; after the calculation is completed, CS will conduct batch audits to prove it. Return to the verifier; S414. The verifier receives the audit certificate. Then, using DO's certificateless public key and the system's master public key Perform batch verification to test the equations. Whether it holds true, among which, the aggregation challenge coefficient Aggregate hashing for replay prevention If the equation is true, output verification result 1, proving that all outsourced file data under this timestamp is intact; otherwise, output verification result 0 and trigger the location and data recovery program; finally, write the final verification result into the block.
7. The method for low-altitude cloud outsourcing data integrity auditing and error recovery based on a blockchain system according to claim 5, characterized in that, The error localization stage specifically includes the following steps: S501. Assume that the initial global challenge set currently found to be compromised in terms of integrity is as follows: The smart contract initializes an empty stack and an error set to store indices of corrupted data blocks. ; Set the initial global challenge set Push onto the stack; when the stack is not empty, pop the top set from the stack. If set Size Divide it into two disjoint left subsets at its physical midpoint. and right subset ; S502, the smart contract sends a partitioning instruction to the CS. After receiving the subset partitioning instruction, it calculates the local aggregation proofs respectively; for the left subset... Calculate the linear combination value of the data blocks in the left subset. and aggregation tags For the right subset Calculate the linear combination value of its data blocks. With aggregation tags ; then CS will prove the left subset. Proof with the right subset Return to the smart contract; S503, smart contracts are based on the latest on-chain timestamp. Calculate the left subset Local challenge coefficient and local hash aggregation Calculate the right subset Local challenge coefficient and local hash aggregation Then, using equations and Perform independent verification; if both equations fail verification, it indicates that both the left and right halves contain errors. The smart contract will first process the right half of the set. Push it onto the stack, then move the left half of the set. Push it onto the stack; if only one equation fails to be verified, it means that the error only exists in the subset of equations that failed to be verified, and then the smart contract pushes it onto the stack. S504, When the pop-up collection Size Furthermore, if the equation verification fails, it is determined that the individual data block corresponding to that set is corrupted, and its index is recorded in the corrupted index set. In the middle; when the stack is empty, all damaged branches are exhausted, and the algorithm outputs a complete set of damaged indices. The process then enters the data recovery and status synchronization phase.