Data retrospective verification method and apparatus

The method and apparatus for retrospectively verifying data using MIME or S/MIME standards address the challenge of data integrity and traceability in email systems by generating unique data tags, enhancing verification efficiency and security while reducing storage and simplifying PKI management.

JP2026076979APending Publication Date: 2026-05-12PROMOTE TIMES TECH (BEIJING) CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
PROMOTE TIMES TECH (BEIJING) CO LTD
Filing Date
2025-10-23
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

The challenge lies in effectively preserving, tracing, and verifying evidence for data exchange practices in email systems and instant messaging systems, particularly in scenarios involving MIME and S/MIME standards, where the ability to ensure data integrity and traceability is crucial but currently lacking.

Method used

A method and apparatus for retrospectively verifying data using MIME or S/MIME standards, involving the definition of evidence provider, preservation, and acquisition roles, generating unique data tags with extended information and fingerprint values, and storing these tags with an evidence keeper for later retrieval and verification.

Benefits of technology

This approach enhances data verification efficiency, security, and traceability, reduces storage resources, and simplifies PKI management by using tamper-proof data tags, providing a reliable verification solution for email systems and file transfers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026076979000001_ABST
    Figure 2026076979000001_ABST
Patent Text Reader

Abstract

This invention provides a method and apparatus for retrospectively verifying data in multipurpose internet mail extension (MIME) encapsulated data exchange, such as in email systems. [Solution] A more reliable and efficient retrospective data verification method for MIME and S / MIME application scenarios such as email systems and file transfers involves generating a unique and tamper-proof data tag for the proof data using extended information and proof elements determined by the evidence provider during verification, storing the data tag with the evidence keeper, and the evidence retriever responding to a retrospective data verification request by obtaining the target data tag from the evidence keeper and further verifying the data based on the target data tag.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data inspection and verification, and particularly to a method and apparatus for retroactive verification of data.

Background Art

[0002] With the high development of informatization, various derivative systems in the email system and the technical standard system it follows have become an important platform for carrying important data, and their application scope is becoming wider and wider. These systems are not only widely recognized in the world in terms of legal status, but also have become a core medium for promoting data exchange. In the context of digital transformation in each field, more and more data exchange behaviors are occurring. Inside the application system, data processing between each component in the system is realized through data exchange. Between various application systems or devices, cooperation between systems or devices is realized through data exchange. Between various organizational institutions, business cooperation between organizational institutions is realized through data exchange.

[0003] The data standard for email is MIME (Multipurpose Internet Mail Extensions), which is defined primarily based on the specifications of RFC 2045 (MIME Message Body Structure Definition Specification), RFC 2046 (MIME Media Type Definition Specification), and RFC 2047 (Non-ASCII Mail Header Encoding Definition Specification). Initially used to define and represent the format types of email attachments, it is now widely used in various scenarios related to data exchange on the Internet, such as specifying web page content types in HTTP (HyperText Transfer Protocol) transfers, specifying data transfer formats in Web Services (network services), specifying data formats for requests and responses in API (Application Programming Interface) communication, and restricting file types when application systems upload files. Here, ASCII is a character encoding standard for exchanging text between computers, communication devices, and other electronic devices. Based on MIME, S / MIME (Secure / Multipurpose Internet Mail Extensions) was also developed. By combining MIME with PKI (Public Key Infrastructure) technology, data encryption and signing are achieved, improving the security of data exchange.

[0004] Two typical characteristics of email data standards are data encapsulation and data exchange practices. These are reflected not only in server-to-server and server-to-client application scenarios within the email system scope, but also in instant messaging systems based on MIME encapsulated data exchange. Given the universality of such data exchange practices, the ability to preserve, trace, and verify evidence for such data retention and exchange practices is becoming increasingly important. Therefore, this technical issue needs to be resolved urgently. [Overview of the Initiative] [Problems that the invention aims to solve]

[0005] In view of the above problems, this application proposes to provide a method and apparatus for retrospectively verifying data that overcomes the above problems or solves them at least partially. The technical solution is as follows: [Means for solving the problem]

[0006] In the first aspect, a method for retrospectively verifying data is provided, wherein the data is encapsulated based on the MIME standard or the S / MIME standard, and the method is: The roles of evidence provider, evidence preservation, and evidence acquisition, including one or more evidence providers, must be defined in advance. For any one of the one or more evidence providers, the evidence provider provides proof data, and based on the proof data, an extended information and a proof element containing the complete data fingerprint value and / or segmented data fingerprint value obtained by calculating the proof data based on the MIME standard or S / MIME standard using a pre-configured digest algorithm are determined, and further, the extended information and the proof element are combined to generate a unique data tag for the proof data, the data tag is submitted to the evidence preservator corresponding to the evidence preservation role, and the evidence preservator stores the data tag. This includes, in response to a data retrospective verification request, an evidence retriever querying and retrieving a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieving a verification result based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value.

[0007] In possible implementations, the extended information includes time, identity, and action. The actions involve performing operations on proof data, such as outputting, inputting, retaining, or discarding it. Identity is a value that uniquely identifies the operator performing output, input, retention, or disposal operations on the certification data. Time is the time value of the only data tag that generates proof data.

[0008] In possible implementations, if the providing of proof data by the evidence provider constitutes performing an output operation on the proof data, the extended information further includes the data recipient.

[0009] In possible implementations, if the provider of evidence provides proof data by performing an input operation on the proof data, the extended information further includes the data provider.

[0010] In possible implementations, the method described above is The following are further included: with respect to a set fingerprint element, the evidence provider traverses the data or fingerprint library held by the evidence provider, and if there is current data that matches the set fingerprint element, determines augmented information for the current data based on the matching current data; combines the augmented information for the current data and the set fingerprint element to generate a unique data tag for the current data; submits the data tag to the evidence preservation officer corresponding to the evidence preservation role; and the evidence preservation officer stores the data tag.

[0011] In possible implementations, if a data retrospective verification request includes a request to confirm that the first proof data entered by the first evidence provider is from the second evidence provider, An evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves verification results based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value. The evidence gatherer, in response to a request from the first evidence provider to confirm that the first proof data entered by the first evidence provider is from the second evidence provider, uses a pre-configured digest algorithm to calculate the first proof data based on the MIME standard or S / MIME standard, and obtains the complete data fingerprint value and / or segmented data fingerprint value of the first proof data, The evidence retriever searches for at least one first data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the first proof data, To determine whether the identity of the extended information of at least one first data tag includes the second evidence provider, If the identity of the extended information of at least one first data tag includes a second evidence provider, determine whether the data recipient of the extended information of at least one first data tag includes the first evidence provider, and if so, confirm that the first proof data entered by the first evidence provider is from the second evidence provider; otherwise, confirm that the first proof data entered by the first evidence provider is not from the second evidence provider. This includes verifying that the first proof data entered by the first evidence provider is not from the second evidence provider if the identity of the extended information of at least one first data tag does not include the second evidence provider.

[0012] In possible implementations, if a data retrospective verification request includes a request to verify that a second proof data output by a first evidence provider is sent to a third evidence provider, An evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves verification results based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value. In response to a request for verification that the second proof data output by the first evidence provider is transmitted to the third evidence provider, the evidence provider, using a pre-configured digest algorithm, calculates the second proof data based on the MIME standard or S / MIME standard and obtains the complete data fingerprint value and / or segmented data fingerprint value of the second proof data. The evidence retriever searches for at least one second data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the second proof data, Determining whether the identity of the extended information of at least one second data tag includes the first evidence provider, whether the action of the extended information of at least one second data tag is data output, and whether the data recipient is the third evidence provider, If the identity of the extended information of at least one second data tag includes the first evidence provider, and the action of the extended information of at least one second data tag is data output, and the data recipient is the third evidence provider, then it is determined that the second proof data output by the first evidence provider is transmitted to the third evidence provider. This includes determining that the first evidence provider did not output the second proof data if the identity of the extended information of at least one second data tag does not include the first evidence provider, or if the action of the extended information of at least one second data tag is not the output of data.

[0013] In possible implementations, if a data retrospective verification request includes a request to verify that the first evidence provider possesses or destroys the third proof data, An evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves verification results based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value. The evidence gatherer, in response to a request to verify that the first evidence provider possesses or destroys the third proof data, uses a pre-configured digest algorithm to calculate the third proof data based on the MIME standard or S / MIME standard, and obtains the complete data fingerprint value and / or segmented data fingerprint value of the third proof data. The evidence retriever searches for at least one third data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the third proof data, To determine whether the identity of the extended information of at least one third data tag includes the first evidence provider, If the identity of the extended information of at least one third data tag includes the first evidence provider, the action of the extended information of at least one third data tag is confirmed, and if the action of the extended information of at least one third data tag is data destruction, it is decided that the first evidence provider will destroy the third proof data, and if the action of the extended information of at least one third data tag is data retention, it is decided that the first evidence provider will retain the third proof data, This includes determining that the first evidence provider does not possess or destroy the third evidence data if the identity of the extended information of at least one third data tag does not include the first evidence provider.

[0014] In possible implementations, if a data retrospective verification request includes a request to verify whether the issuance of the fourth data held by the first evidence provider predates the issuance of the fourth data held by the second evidence provider, An evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves verification results based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value. The evidence gatherer, in response to a request to verify whether the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider, uses a pre-configured digest algorithm to calculate the fourth proof data based on the MIME standard or S / MIME standard, and obtains the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data, The evidence retriever searches for a fourth data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the first evidence provider, and searches for a fifth data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the second evidence provider, This includes determining that if the time of the extended information for the fourth data tag is earlier than the time of the extended information for the fifth data tag, the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider.

[0015] In a second aspect, a data retrospective verification device is provided, wherein the data is encapsulated based on a MIME standard or an S / MIME standard, and the device is A definition module for pre-defining evidence-providing roles, evidence-preserving roles, and evidence-acquisition roles, including one or more evidence providers, The system provides proof data, and based on the proof data, determines proof elements that include augmented information and a pre-configured digest algorithm, which calculate the proof data based on the MIME standard or S / MIME standard, and the complete data fingerprint value and / or segmented data fingerprint value obtained from the proof data; further combines the augmented information and proof elements to generate a unique data tag for the proof data; and submits the data tag to one of the one or more evidence providers corresponding to the evidence preservation role. Evidence keeper for storing one or more data tags, This includes an evidence taker corresponding to an evidence taker role to query and retrieve a target data tag from one or more data tags stored by the evidence taker in response to a data retrospective verification request, based on the verification conditions in the data retrospective verification request, and to further obtain verification results based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value.

[0016] In a possible implementation form, the extension information includes time, identity, and actions, where an action is to perform an output, input, possession, or discard operation on the proof data, the identity is a value that uniquely identifies the identity of the operator who performs an output, input, possession, or discard operation on the proof data, and the time is the time value of the only data tag for generating the proof data.

[0017] In a possible implementation form, when the evidence provider provides proof data, which is to perform an output operation on the proof data, the extension information further includes the data recipient.

[0018] In a possible implementation form, when the evidence provider provides proof data, which is to perform an input operation on the proof data, the extension information further includes the data provider.

[0019] In a possible implementation form, the evidence provider further traverses the data or fingerprint library held by the evidence provider for the set fingerprint elements. If there is current data that matches the set fingerprint elements, determines the extension information of the current data based on the matched current data, combines the extension information of the current data and the set fingerprint elements to generate a unique data tag for the current data, submits the data tag to the evidence keeper corresponding to the evidence storage role, and the evidence keeper stores the data tag.

[0020] In a possible implementation form, when a data retrospective verification requirement includes a requirement to confirm that the first proof data input by the first evidence provider is from the second evidence provider, the evidence acquirer further In response to a request to verify that the first proof data entered by the first evidence provider is from the second evidence provider, the system uses a pre-configured digest algorithm to calculate the first proof data based on the MIME standard or S / MIME standard, and obtains the complete data fingerprint value and / or segmented data fingerprint value of the first proof data. From one or more data tags stored by the evidence keeper, search for at least one first data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the first proof data, Determine whether the identity of the extended information of at least one first data tag includes the second evidence provider, If the identity of the extended information of at least one first data tag includes a second evidence provider, determine whether the data recipient of the extended information of at least one first data tag includes the first evidence provider, and if so, confirm that the first proof data entered by the first evidence provider is from the second evidence provider; otherwise, confirm that the first proof data entered by the first evidence provider is not from the second evidence provider. If the identity of the extended information of at least one first data tag does not include the second evidence provider, then it is confirmed that the first proof data entered by the first evidence provider is not from the second evidence provider.

[0021] In possible implementations, if a data retrospective verification request includes a request to verify that a second proof data output by a first evidence provider is transmitted to a third evidence provider, the evidence provider further: In response to a request to verify that the second proof data output by the first evidence provider is transmitted to the third evidence provider, the second proof data is calculated based on the MIME standard or S / MIME standard using a pre-configured digest algorithm, and the complete data fingerprint value and / or segmented data fingerprint value of the second proof data are obtained. From one or more data tags stored by the evidence keeper, search for at least one second data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the second proof data. Determine whether the identity of the extended information of at least one second data tag includes the first evidence provider, whether the action of the extended information of at least one second data tag is data output, and whether the data recipient is the third evidence provider. If the identity of the extended information of at least one second data tag includes the first evidence provider, and the action of the extended information of at least one second data tag is data output, and the data recipient is the third evidence provider, then it is determined that the second proof data output by the first evidence provider is transmitted to the third evidence provider. If the identity of the extended information of at least one second data tag does not include the first evidence provider, or if the action of the extended information of at least one second data tag is not data output, then it is determined that the first evidence provider did not output the second proof data.

[0022] In possible implementations, if a data retrospective verification request includes a request to verify that the first evidence provider possesses or destroys the third proof data, the evidence obtainer can further: In response to a request to verify that the first evidence provider possesses or destroys the third proof data, the third proof data is calculated based on the MIME standard or S / MIME standard using a pre-configured digest algorithm, and the complete data fingerprint value and / or segmented data fingerprint value of the third proof data are obtained. From one or more data tags stored by the evidence keeper, search for at least one third data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the third proof data. Determine whether the identity of the extended information of at least one third data tag includes the first evidence provider. If the identity of the extended information of at least one third data tag includes the first evidence provider, the action of the extended information of at least one third data tag is confirmed, and if the action of the extended information of at least one third data tag is data destruction, it is determined that the first evidence provider will destroy the third proof data, and if the action of the extended information of at least one third data tag is data retention, it is determined that the first evidence provider will retain the third proof data. If the identity of the extended information of at least one third data tag does not include the first evidence provider, it is determined that the first evidence provider does not possess or dispose of the third evidence data.

[0023] In possible implementations, if a request for retrospective verification of data includes a request for verification of whether the issuance of the fourth data held by the first evidence provider predates the issuance of the fourth data held by the second evidence provider, the evidence obtainer can further: In response to a request to verify whether the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider, a pre-configured digest algorithm is used to calculate the fourth proof data based on the MIME standard or S / MIME standard, and the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data are obtained. From one or more data tags stored by the evidence keeper, search for a fourth data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the first evidence provider; search for a fifth data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the second evidence provider; If the timestamp of the extended information for the fourth data tag is earlier than the timestamp of the extended information for the fifth data tag, it is determined that the issuance of the fourth data held by the first evidence provider was earlier than the issuance of the fourth data held by the second evidence provider. [Effects of the Invention]

[0024] Through the above technical solution, the embodiment of this application provides a data retrospective verification method and apparatus. This method generates a unique and tamper-proof data tag for the evidence data using extended information and evidence elements determined by the evidence provider during verification. The data tag is stored by the evidence custodian. The evidence retriever responds to a data retrospective verification request by obtaining the target data tag from the evidence custodian and further verifying the data based on the target data tag. This provides a more reliable and efficient data verification solution for MIME and S / MIME application scenarios such as email systems and file transfers. Furthermore, because verification is performed via data tags, storage resources are effectively saved, the security of data content is enhanced, and the efficiency of verification responses is improved. In addition, by storing the data tag with the evidence custodian, and the evidence retriever obtaining the target data tag from the evidence custodian and further verifying the data based on the target data tag, data traceability is enhanced, and the complexity of PKI management is avoided.

[0025] Furthermore, the extended information in data tags includes time, identity, and action. In other words, data tags record the output, input, retention, or disposal operations performed on the evidence data, as well as the identity of the operator performing these operations. Thus, by having the evidence custodian store these data tags, a logical decoupling between the data state change record and the evidence provider is achieved, allowing for flexible adaptation to various data flow scenarios. During the data verification phase, the evidence custodian can quickly access data tags from the evidence custodian for each stage of the entire process from the creation to the destruction of specific data (including output, input, retention, and disposal). This characteristic fundamentally changes the perspective of traditional operational-level verification, delving deeply into the micro-level of data state changes, significantly enhancing the security, traceability, and accuracy of the data flow process, and providing more effective data protection and verification efficiency in MIME and S / MIME application scenarios such as email systems and file transfers. [Brief explanation of the drawing]

[0026] To more clearly explain the technical solutions of the embodiments of this application, the drawings necessary for describing the embodiments of this application will be briefly described below.

[0027] [Figure 1] This is a flowchart of the data retrospective verification method provided in the embodiment of this application. [Figure 2] This diagram shows the relationship between the evidence provision role, evidence preservation role, and evidence acquisition role provided by the embodiment of this application. [Figure 3] This is a structural diagram of a data retrospective verification device provided in an embodiment of the present invention. [Modes for carrying out the invention]

[0028] The exemplary embodiments of this application will be described in more detail below with reference to the drawings. While exemplary embodiments of this application are shown in the drawings, it should be understood that this application can be carried out in various forms and should not be limited to the embodiments described herein. Conversely, these embodiments are provided to provide a more complete understanding of this application and to fully convey its scope to those skilled in the art.

[0029] Furthermore, terms such as “First,” “Second,” etc., in the specification, claims, and drawings of this application are for distinguishing similar subjects and are not necessarily intended to indicate a specific order or priority. It should be understood that such use is interchangeable in appropriate circumstances so that the embodiments of this application described herein may be carried out in an order other than that illustrated or described herein. In addition, the term “including” and its variations should be interpreted as an open-ended term meaning “including but not limited to.”

[0030] To solve the above technical problems, embodiments of this application provide a data retrospective verification method in which the data is encapsulated based on the MIME standard or S / MIME standard, and as shown in Figure 1, this data retrospective verification method may include the following steps S101 to S103.

[0031] Step S101: Define in advance the roles of evidence provider, evidence preservation, and evidence acquisition, including one or more evidence providers.

[0032] Step S102: For any one of the one or more evidence providers, the evidence provider provides proof data, and based on the proof data, the system determines augmented information and proof elements that include the complete data fingerprint value and / or segmented data fingerprint value obtained by calculating the proof data based on the MIME standard or S / MIME standard using a pre-configured digest algorithm, and further combines the augmented information and proof elements to generate a unique data tag for the proof data, submits the data tag to the evidence preservator corresponding to the evidence preservation role, and the evidence preservator stores the data tag.

[0033] Step S103: The evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves a verification result based on one or more of the target data tag's extended information, complete data fingerprint value, and segmented data fingerprint value.

[0034] In this embodiment, during verification, a unique and tamper-proof data tag is generated for the proof data using extended information and proof elements determined by the evidence provider. The data tag is stored by the evidence custodian, and the evidence retriever, in response to a request for retrospective data verification, obtains the target data tag from the evidence custodian and further verifies the data based on the target data tag. This provides a highly reliable and efficient data verification solution for MIME and S / MIME application scenarios such as email systems and file transfers. Furthermore, because verification is performed via data tags, storage resources are effectively saved, the security of data content is enhanced, and the efficiency of verification responses is improved. In addition, by storing the data tag with the evidence custodian, and the evidence retriever obtaining the target data tag from the evidence custodian and further verifying the data based on the target data tag, data traceability is enhanced, and the complexity of PKI management is avoided.

[0035] In step S102 above, the evidence data provided by the evidence provider is encapsulated based on the MIME standard or S / MIME standard, so that different MIME types and corresponding data content in the evidence data can be obtained based on the MIME standard or S / MIME standard. Furthermore, using a pre-configured digest algorithm, the complete data content of the evidence data can be calculated based on the MIME standard or S / MIME standard, and the complete data fingerprint value can be obtained. Using a pre-configured digest algorithm, the data content of different MIME types in the evidence data can be calculated based on the MIME standard or S / MIME standard, and segmented data fingerprint values ​​corresponding to different MIME types can be obtained.

[0036] MIME types, as used here, are used to define data formats in emails, web pages, or other internet documents. A MIME type consists of two parts: a type and a subtype, separated by a slash ( / ). The type defines a general category of data, while the subtype provides more specific information.

[0037] The following are some examples of common MIME types and their subtypes.

[0038] (1) "text / " indicates text data. "text / plain" refers to a general text file, such as a TXT (Text) file. "text / html" refers to an HTML (HyperText Markup Language) document.

[0039] (2) "image / " indicates image data. "image / jpeg" refers to an image in JPEG (Joint Photographic Experts Group) format. "image / png" refers to an image in PNG (Portable Network Graphics) format. "image / gif" refers to an image in GIF (Graphics Interchange Format) format.

[0040] (3) "audio / " indicates audio data. "audio / mpeg" refers to MPEG (Moving Pictures Experts Group) audio, such as MP3 files. "audio / wav" refers to a WAV (Waveform Audio File Format) audio file.

[0041] (4) "video / " indicates video data. "video / MP4" indicates an MP4 video file.

[0042] (5) "application / " indicates binary data and is typically used for application programs. "application / json" refers to JSON (JavaScript Object Notation, a lightweight data exchange format) data. "application / octet-stream" is a general-purpose type that represents unknown binary data.

[0043] (6) "multipart / " is a composite type that combines multiple different types of data. "multipart / form-data" is used for submitting form data, such as file uploads. "multipart / byteranges" is used to represent multiple parts of a document.

[0044] The above examples are merely illustrative and do not limit this embodiment.

[0045] The pre-configured digest algorithm used here may be MD5 (Message Digest Algorithm), SHA (Secure Hash Algorithm)-1, SHA-2, SHA-128, SHA-256, or a custom algorithm, and this embodiment is not limited to these.

[0046] In embodiments of the present application, possible implementation methods are provided, wherein the extended information referred to in step S102 above may include time, identity and action, wherein action is performing an output, input, retain or discard operation on the proof data; identity is a value that uniquely identifies the identity of the operator performing the output, input, retain or discard operation on the proof data; and time is the time value of the single data tag that generates the proof data.

[0047] An evidence provider, corresponding to the evidence-providing role, can provide data tags of evidence data to an evidence keeper, corresponding to the evidence-preserving role, via network protocols such as HTTP and FTP (File Transfer Protocol), or storage media such as hard disks or USB (Universal Serial Bus). The evidence keeper stores the data tags in a searchable manner (e.g., database, file system, directory), and the data tags stored by the evidence keeper relate to four data states: data output, data input, data retention, and data disposal.

[0048] Here, the act of receiving proof data from the evidence provider is data input, the act of sending proof data from the evidence provider or obtaining it externally is data output, the act of the evidence provider owning proof data is data possession, the act of the evidence provider not owning proof data is data non-possession, and the act of the evidence provider removing proof data is data disposal.

[0049] Figure 2 is a diagram illustrating the relationship between the evidence-providing role, evidence-preserving role, and evidence-acquisition role provided by the embodiment of this application. The evidence-providing role may include one or more evidence providers (e.g., evidence providers A1, AN, etc., where N is a positive integer), and any one of the one or more evidence providers may be the provider of proof data.

[0050] The evidence preservation role may include one or more evidence preservators (e.g., evidence preservators M1, MN, etc.), and these evidence preservators may be present with either party exchanging data, or may be independent of either party exchanging data, as data tag preservators, and this embodiment is not limited thereto.

[0051] The evidence-gathering role may include one or more evidence-gatherers (e.g., evidence-gatherers B1, BN, etc.), and the evidence-gatherers may be various business software, client software, servers, gateways, mail routing devices, management and control systems that query, hold, exchange, manage, control, and route data, data states and actions encapsulated in MIME, S / MIME, or any system that stores, transmits, or processes such data, or may be institutions, entities, and personnel roles, and this embodiment is not limited thereto.

[0052] During verification, the evidence keeper provides the evidence retriever with data tags, and the evidence retriever can query the relevant data tags through searchable fields (e.g., full data fingerprint value, segmented data fingerprint value, identity, activity, etc.) to retrieve a target data tag, and can obtain verification results based on one or more of the target data tag's identity, activity, date, full data fingerprint value, or segmented data fingerprint value.

[0053] In embodiments of the present application, possible implementations are provided in which, in step S102, the provision of proof data by the evidence provider is equivalent to performing an output operation on the proof data, the extended information may further include data receivers or further include data providers, in which case a relationship chain is established between the evidence providers, and further, a clear and verifiable data transmission action chain or data state evolution chain is formed.

[0054] In embodiments of the present application, possible implementations are provided in which, in step S102, the provision of evidence data by the evidence provider is an input operation to the evidence data, the extended information may further include data providers, and similarly, relationship chains may be established between evidence providers, and further, clear and verifiable data transmission action chains or data state evolution chains may be formed.

[0055] In the embodiments of this application, possible implementations are provided, and the extended information may include, in addition to the three essential fields of time, identity, and action, a data recipient or data provider, and may further extend one or more fields as per the actual situation, such as data size and data encryption level, and this embodiment is not limited thereto.

[0056] Step S102 described above specifically how to preserve evidence data provided by one of more evidence providers. However, in possible implementations, the method for preserving a set fingerprint element as evidence may include step a1 as follows:

[0057] Step a1: The evidence provider traverses the data or fingerprint library they possess. If there is current data that matches the configured fingerprint elements, they determine augmented information for the current data based on the matching current data. They combine the augmented information for the current data with the configured fingerprint elements to generate a unique data tag for the current data. They submit the data tag to the evidence preservation officer corresponding to the evidence preservation role, and the evidence preservation officer stores the data tag.

[0058] In this step, the configured fingerprint elements may be provided by the evidence provider, may exist independently, may be obtained by querying, for example, the evidence custodian's system, or may be obtained from an existing fingerprint from another channel, and this embodiment is not limited thereto.

[0059] Using a pre-configured digest algorithm, the system calculates the data held by the evidence provider based on the MIME standard or S / MIME standard, obtains the complete data fingerprint value and / or segmented data fingerprint value, traverses the complete data fingerprint value and / or segmented data fingerprint value of the data held by the evidence provider, and if there is a complete data fingerprint value or segmented data fingerprint value that matches the configured fingerprint element, the data corresponding to the complete data fingerprint value or segmented data fingerprint value that matches the configured fingerprint element is set as the current data that matches the configured fingerprint element.

[0060] For the fingerprint library held by the evidence provider, it is possible to traverse the fingerprint library held by the evidence provider, and if there is a fingerprint that matches the configured fingerprint element, the data corresponding to the fingerprint that matches the configured fingerprint element will be set as the current data that matches the configured fingerprint element.

[0061] Furthermore, the set fingerprint elements are obtained by calculating the data using a pre-configured digest algorithm.

[0062] In embodiments of this application, possible implementations are provided in which, if the data retrospective verification request in step S103 includes a request to confirm that the first proof data entered by the first evidence provider is from the second evidence provider, the evidence retriever corresponding to the evidence acquisition role responds to the data retrospective verification request by querying and retrieving a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further obtains a verification result based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value, in step S103, specifically, Step b1: In response to a request from an evidence gatherer corresponding to the evidence gathering role to confirm that the first proof data entered by the first evidence provider is from the second evidence provider, the evidence gatherer calculates the first proof data based on the MIME standard or S / MIME standard using a pre-configured digest algorithm and obtains the complete data fingerprint value and / or segmented data fingerprint value of the first proof data. Step b2 involves the evidence retriever searching for at least one first data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the first proof data, Step b3 determines whether the identity of the extended information of at least one first data tag includes a second evidence provider, Step b4: If the identity of the extended information of at least one first data tag includes a second evidence provider, determine whether the data recipient of the extended information of at least one first data tag includes the first evidence provider, and if so, verify that the first proof data entered by the first evidence provider is from the second evidence provider, otherwise verify that the first proof data entered by the first evidence provider is not from the second evidence provider. If the identity of the extended information of at least one first data tag does not include the second evidence provider, step b5 may include verifying that the first proof data entered by the first evidence provider is not from the second evidence provider.

[0063] This embodiment allows for the safe, accurate, and efficient confirmation and verification that the first proof data entered by the first evidence provider originates from the second evidence provider.

[0064] In embodiments of this application, possible implementations are provided in which, if the data retrospective verification request in step S103 includes a request to verify that a second proof data output by a first evidence provider is transmitted to a third evidence provider, then step S103, in which an evidence retriever corresponding to an evidence acquisition role responds to the data retrospective verification request by querying and retrieving a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further obtains a verification result based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value, specifically, Step c1: In response to a request from an evidence gatherer corresponding to the evidence gathering role to verify that the second proof data output by the first evidence provider is transmitted to the third evidence provider, the evidence gatherer calculates the second proof data based on the MIME standard or S / MIME standard using a pre-configured digest algorithm and obtains the complete data fingerprint value and / or segmented data fingerprint value of the second proof data. Step c2: The evidence retriever searches for at least one second data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the second proof data. Step c3 involves determining whether the identity of the extended information of at least one second data tag includes the first evidence provider, whether the action of the extended information of at least one second data tag is data output, and whether the data recipient is the third evidence provider. Step c4 determines that if the identity of the extended information of at least one second data tag includes the first evidence provider, and the action of the extended information of at least one second data tag is data output, and the data recipient is the third evidence provider, then the second proof data output by the first evidence provider is transmitted to the third evidence provider. The procedure may include step c5, which determines that the first evidence provider has not output the second proof data if the identity of at least one extended information of the second data tag does not include the first evidence provider, or if the action of at least one extended information of the second data tag is not data output.

[0065] This embodiment can safely, accurately, and efficiently verify that the second proof data output by the first evidence provider is transmitted to the third evidence provider.

[0066] In embodiments of this application, possible implementations are provided in which, if the data retrospective verification request in step S103 includes a request to verify that a first evidence provider possesses or destroys third evidence data, the evidence retriever corresponding to the evidence acquisition role responds to the data retrospective verification request by querying and retrieving a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further obtains a verification result based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value, specifically, Step d1: The evidence gatherer, in response to a request to verify that the first evidence provider possesses or destroys the third proof data, uses a pre-configured digest algorithm to calculate the third proof data based on the MIME standard or S / MIME standard and obtains the complete data fingerprint value and / or segmented data fingerprint value of the third proof data. Step d2 involves the evidence retriever searching for at least one third data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the third proof data, Step d3 determines whether the identity of the extended information of at least one third data tag includes the first evidence provider, Step d4: If the identity of the extended information of at least one third data tag includes the first evidence provider, the action of the extended information of at least one third data tag is confirmed, and if the action of the extended information of at least one third data tag is data destruction, it is determined that the first evidence provider destroys the third proof data, and if the action of the extended information of at least one third data tag is data retention, it is determined that the first evidence provider retains the third proof data. The procedure may include step d5, which determines that the first evidence provider does not possess or dispose of the third evidence data if the identity of the extended information of at least one third data tag does not include the first evidence provider.

[0067] This embodiment allows for safe, accurate, and efficient verification that the first evidence provider possesses or disposes of the third proof data.

[0068] In embodiments of this application, possible implementations are provided in which, if the data retrospective verification request in step S103 includes a verification request for whether the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider, the evidence retriever corresponding to the evidence acquisition role responds to the data retrospective verification request by querying and retrieving a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further obtains a verification result based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value, in step S103, specifically, Step e1: The evidence gatherer, in response to a request to verify whether the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider, uses a pre-configured digest algorithm to calculate the fourth proof data based on the MIME standard or S / MIME standard and obtains the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data. Step e2: The evidence retriever searches for a fourth data tag from one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the first evidence provider; and searches for a fifth data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the second evidence provider. The procedure may include step e3, which determines that if the time of the extended information for the fourth data tag is earlier than the time of the extended information for the fifth data tag, the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider.

[0069] This embodiment allows for safe, accurate, and efficient verification of whether the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider.

[0070] The evidence-providing role may include one or more evidence providers, for example, Evidence Provider 1, Evidence Provider 2, Evidence Provider 3, Evidence Provider 4...Evidence Provider N, where N is a positive integer. The first, second, and third evidence providers mentioned in the above embodiments are merely illustrative and do not necessarily mean that the first evidence provider is Evidence Provider 1, the second evidence provider is Evidence Provider 2, and the third evidence provider is Evidence Provider 3. In actual application scenarios, the first evidence provider may be Evidence Provider 1, Evidence Provider 2, Evidence Provider 3, or Evidence Provider N; the second evidence provider may be any other evidence provider besides the first; and the third evidence provider may be any other evidence provider besides the first or second.

[0071] For example, in a scenario where a data retrospective verification request includes a request to confirm that the first proof data entered by the first evidence provider is from the second evidence provider, the first evidence provider may be evidence provider 2, and the second evidence provider may be evidence provider 4.

[0072] In a scenario where a request for retrospective verification of data includes a request to verify whether the issuance of the fourth data held by the first evidence provider was earlier than the issuance of the fourth data held by the second evidence provider, the first evidence provider may be evidence provider 1, and the second evidence provider may be evidence provider 3.

[0073] The above examples are merely illustrative and do not limit this embodiment.

[0074] The various implementation forms of each stage of the embodiment shown in Figure 1 have been described above. Below, the method for retrospectively verifying the data of the embodiment of this application will be further explained with reference to specific examples.

[0075] Scenario Example 1: Evidence provider A1, corresponding to the evidence-providing role, sends a MIME-formatted message M (e.g., email) to A2, who then automatically retrieves the raw data of the message.

[0076] MIME-formatted email data is as follows: X-ANY-EXTHEADER: Reply-To:“=?gbk?B?wfW24MC8?=”<xxx@anymacro.com> X-Send-Id:1723099968.ac7a1910355639c6904e2993cc20809814719 From:“-?gbk?B?wfW24MC8?=”<xxx@anymacro.com> Date:Thu,08 Aug 2024 14:52:45 +0800(CST) MIME version: 1.0 X-srcuser:xxx@anymacro.com X-ANYWEBIP:IP_K To:“=?utf-8?b?546L5YW16bKB?=”<aaaaa@anymacro.com> Subject:=?gbk?B?d2Fzbc / gudjWqsq2tKKxuA==?= Content-Type: multipart / mixed; boundary=“14719.66b46b402b468.8ffc5632c87b09bc.anymacro” --14719.66b46b402b468.8ffc5632c87b09bc.anymacro Content-Type:text / html;charset=gbk Content-Transfer-Encoding:base64 zfW5pLrDo708ZG12PixzcGFuIHN0eWx1PST3aG10ZS1zcGF iZTpwcmUiPgk8L3NwYW4+uL28 / srHd2Fzbc / gudilxNaqyra0orG4xNrI3aGjPC9kaXY+ --14719.66b46b402b468.8ffc5632c87b09bc.anymacro Content-Type:application / octet-stream;name=“=?gbk?B?d2Fzbdagyra0orG4LmRvY3g=?=” Content-Transfer-Encoding:base64 Content-Disposition:attachment;filename=“=?gbk?B?d2Fzbdagyra0orG4LmRvY3g=?=”

[0077] In the above MIME-formatted email data, X-ANY-EXTHEADER is a non-standard email header typically used by a specific email system or application program. The Reply-To field specifies the address to which replies should be sent, in this case "xxx@anymacro.com," using GBK (Giant Character Encoding Standard) encoded Base64 format. X-Send-Id is the unique identifier generated when sending the email. From is the sender's email address, also "xxx@anymacro.com," using GBK encoded Base64 format. Date is the date and time the email was sent. MIME-version is an identifier of the MIME version the email follows. X-srcuser is the sender's email address. X-ANYWEBIP is the network IP (Internet Protocol) address used when sending the email; IP_K is illustrative and not limited to this embodiment. To is the recipient's email address, using UTF-8 encoded Base64 format. The Subject field is the topic of the email and uses GBK-encoded Base64 format. Content-Type specifies the type of email content, here multipart / mixed, meaning the email contains multiple parts. Boundary is a boundary marker used to separate different parts within the email.

[0078] The email content is divided into two parts. The first part is of type text / html, containing text content in HTML format, which is encoded in Base64 format, and the decoded content is HTML code. The second part is of type application / octet-stream, used to send binary files, where the file name (using GBK-encoded Base64 format) is specified, and the content is also Base64 encoded, indicating that the email contains an attachment, and the specific content of the attachment can be viewed after decoded.

[0079] For evidence provider A1, a pre-configured digest algorithm can be used to encrypt the complete raw data and obtain the complete data fingerprint value H1. The raw data consists of two MIME types, and it is necessary to obtain each MIME type and encrypt the data for each MIME type to obtain segmented data fingerprint values ​​H2 and H3 respectively. Based on the raw data, augmented information is generated, including time, identity (a value that uniquely identifies evidence provider A1), action (data output), and data recipient A2. A data tag is generated by combining the complete data fingerprint value H1, the segmented data fingerprint values ​​H2 and H3, and the augmented information, and then evidence keeper M1 stores the generated data tag.

[0080] The data tags for MIME-formatted email data are as follows: Complete data: Complete data fingerprint value H1; Segmented data: 1) MIME type (text / html) and data content, segmented data fingerprint H2; 2) MIME type (application / octet-stream) and data content, segmented data fingerprint H3; Further information: 1) Time: The time value used to generate the data tag, which may be Thu,08 Aug 2024 14:52:45+0800 (CST). 2) Identity: Sender xxx@anymacro.com; 3) Action: Send an email and output the data. 4) Data recipient: recipientaaaaa@anymacro.com.

[0081] Evidence provider A2 receives message M, saves the data tag of message M as evidence, and evidence saver M1 saves the generated data tag.

[0082] If evidence provider A2 needs to perform a confirmatory verification of evidence provider A1's actions, evidence provider B1, corresponding to the evidence acquisition role, can obtain the complete data fingerprint value H1 in the data tag generated by evidence provider A2, search for at least one data tag matching H1 at evidence custodian M1, and compare whether the identity in at least one data tag includes evidence provider A1 and whether the data recipient includes evidence provider A2. If the identity in at least one data tag includes evidence provider A1 and the data recipient includes evidence provider A2, the confirmatory verification of the actions is successful, and the verification process does not need to rely on PKI and does not need to verify the validity of the digital certificate.

[0083] Scenario Example 2: All historical data held by evidence providers A1 and A2 is stored by the evidence custodian. Both A1 and A2 issue one original image in MIME message format, and upon comparison, the similarity between the two original images reaches 70%. A1 and A2 each have their own opinions and need to determine which work was created earlier. Evidence retrieval B1 intervenes and obtains data tags D(1) and D(2), which were formed at the time of the initial creation of the two works, from evidence custodian M1. Upon comparison, if the time of D(1) is earlier than the time of D(2), it can be determined that the creation time of A2's work is later than that of A1's work.

[0084] Scenario Example 3: All data held and disposed of by evidence provider A is stored by evidence custodian M. The company where evidence provider A is located needs to periodically delete certain data. Evidence retriever B needs to periodically verify whether this specific data has been deleted within a predetermined time. During verification, evidence retriever B obtains the data tag D from evidence custodian M at the time of disposal or deletion of the file and checks whether the time in the extended information of data tag D is within a predetermined time limit.

[0085] Scenario Example 4: In the data exchange scenario, business system (evidence provider) A1 and business system (evidence provider) A2 achieve data exchange through an interaction interface. System A1 is responsible for encapsulating files that need to be archived in MIME message format and calling the interface of system A2 via the interactive protocol to transfer the data. After receiving this encapsulated data, system A2 performs the saving process. All data exchange activities between A1 and A2 are stored by evidence keeper M.

[0086] Recently, an unusual situation was discovered where system A1 claimed that data had already been submitted to a data file in system A2, but did not match the data stored in system A2, making the retrospective search process complex and difficult. To solve this problem, this solution introduces evidence retriever B, who is responsible for obtaining data tag D(A1) generated when system A1 sends a request from evidence keeper M, and data tag D(A2) generated when system A2 saves the data. D(A1) and D(A2) contain important information such as the timestamp of the data exchange and the complete data fingerprint value, and are used to verify the accuracy of the data. By comparing the complete data fingerprint values ​​in D(A1) and D(A2), evidence retriever B can determine whether the data was tampered with during transmission. At the same time, by comparing the timestamps, evidence retriever B can find that the time in D(A1) is earlier than the time in D(A2), which proves that system A1 sent the data to system A2 at the specified time. Furthermore, by analyzing the identity, data recipient, and data provider of the extended information in D(A1) and D(A2), evidence gatherer B can verify whether the data received and stored by the A2 system matches the raw data transmitted by the A1 system, thereby resolving the issue of data mismatch and clarifying responsibility.

[0087] This embodiment provides effective data protection and verification efficiency through MIME and S / MIME application scenarios such as email systems and file transfers, and fully meets the stringent requirements in areas such as legal compliance, historical record retention, and security audits.

[0088] The numbering of each step in the above embodiments does not indicate the order of execution; the execution order of each process should be determined by its function and internal logic, and does not limit the implementation process of the embodiments of this application. In actual applications, all of the above possible embodiments can be arbitrarily combined to form possible embodiments of this application, and such details are omitted here.

[0089] Based on the data retrospective verification methods provided in each of the above embodiments, and based on the same inventive concept, the embodiments of this application further provide a data retrospective verification device.

[0090] Figure 3 is a structural diagram of a data retrospective verification device provided in an embodiment of the present invention. As shown in Figure 3, the data retrospective verification device may specifically include a definition module, one evidence provider from among one or more evidence providers, an evidence custodian, and an evidence custodian corresponding to the evidence acquisition role.

[0091] The definition module pre-defines evidence-providing roles, evidence-preserving roles, and evidence-acquisition roles, including one or more evidence providers. One of the one or more evidence providers provides the proof data, and based on the proof data, determines the proof elements, which include augmented information and a pre-configured digest algorithm, the complete data fingerprint value and / or segmented data fingerprint value obtained by calculating the proof data based on the MIME standard or S / MIME standard, and further combines the augmented information and the proof elements to generate a unique data tag for the proof data, and submits the data tag to the evidence keeper corresponding to the evidence preservation role. The evidence keeper stores one or more data tags. An evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves the verification result based on one or more of the target data tag's extended information, complete data fingerprint value, and segmented data fingerprint value.

[0092] In the embodiments of this application, possible implementations are provided, wherein the extended information includes time, identity and action, The actions involve performing operations on proof data, such as outputting, inputting, retaining, or discarding it. Identity is a value that uniquely identifies the operator performing output, input, retention, or disposal operations on the certification data. Time is the time value of the only data tag that generates proof data.

[0093] In embodiments of this application, possible implementations are provided in which, if the evidence provider provides proof data, the provision of proof data is equivalent to performing an output operation on the proof data, the extended information further includes a data recipient.

[0094] In embodiments of this application, possible implementations are provided in which the evidence provider provides proof data, and the provision of proof data is equivalent to performing an input operation on the proof data, the extended information further includes the data provider.

[0095] The embodiments of this application provide possible implementations, and the present evidence provider further states For each set fingerprint element, the system traverses the data or fingerprint library held by the evidence provider. If there is current data that matches the set fingerprint element, it determines the extended information for the current data based on the matching current data. The extended information for the current data and the set fingerprint element are combined to generate a unique data tag for the current data. The data tag is submitted to the evidence preservation officer corresponding to the evidence preservation role, and the evidence preservation officer stores the data tag.

[0096] In embodiments of this application, possible implementations are provided in which, if a data retrospective verification request includes a request to confirm that a first proof data entered by a first evidence provider is from a second evidence provider, the evidence obtainer further: In response to a request to verify that the first proof data entered by the first evidence provider is from the second evidence provider, the system uses a pre-configured digest algorithm to calculate the first proof data based on the MIME standard or S / MIME standard, and obtains the complete data fingerprint value and / or segmented data fingerprint value of the first proof data. From one or more data tags stored by the evidence keeper, search for at least one first data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the first proof data, Determine whether the identity of the extended information of at least one first data tag includes the second evidence provider, If the identity of the extended information of at least one first data tag includes a second evidence provider, determine whether the data recipient of the extended information of at least one first data tag includes the first evidence provider, and if so, confirm that the first proof data entered by the first evidence provider is from the second evidence provider; otherwise, confirm that the first proof data entered by the first evidence provider is not from the second evidence provider. If the identity of the extended information of at least one first data tag does not include the second evidence provider, then it is confirmed that the first proof data entered by the first evidence provider is not from the second evidence provider.

[0097] In embodiments of this application, possible implementations are provided in which, if a data retrospective verification request includes a request to verify that a second proof data output by a first evidence provider is transmitted to a third evidence provider, the evidence provider further: In response to a request to verify that the second proof data output by the first evidence provider is transmitted to the third evidence provider, the second proof data is calculated based on the MIME standard or S / MIME standard using a pre-configured digest algorithm, and the complete data fingerprint value and / or segmented data fingerprint value of the second proof data are obtained. From one or more data tags stored by the evidence keeper, search for at least one second data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the second proof data. Determine whether the identity of the extended information of at least one second data tag includes the first evidence provider, whether the action of the extended information of at least one second data tag is data output, and whether the data recipient is the third evidence provider. If the identity of the extended information of at least one second data tag includes the first evidence provider, and the action of the extended information of at least one second data tag is data output, and the data recipient is the third evidence provider, then it is determined that the second proof data output by the first evidence provider is transmitted to the third evidence provider. If the identity of the extended information of at least one second data tag does not include the first evidence provider, or if the action of the extended information of at least one second data tag is not data output, then it is determined that the first evidence provider did not output the second proof data.

[0098] In embodiments of this application, possible implementations are provided in which, if a data retrospective verification request includes a request to verify that a first evidence provider possesses or destroys a third proof data, the evidence obtainer further: In response to a request to verify that the first evidence provider possesses or destroys the third proof data, the third proof data is calculated based on the MIME standard or S / MIME standard using a pre-configured digest algorithm, and the complete data fingerprint value and / or segmented data fingerprint value of the third proof data are obtained. From one or more data tags stored by the evidence keeper, search for at least one third data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the third proof data. Determine whether the identity of the extended information of at least one third data tag includes the first evidence provider. If the identity of the extended information of at least one third data tag includes the first evidence provider, the action of the extended information of at least one third data tag is confirmed, and if the action of the extended information of at least one third data tag is data destruction, it is determined that the first evidence provider will destroy the third proof data, and if the action of the extended information of at least one third data tag is data retention, it is determined that the first evidence provider will retain the third proof data. If the identity of the extended information of at least one third data tag does not include the first evidence provider, it is determined that the first evidence provider does not possess or dispose of the third evidence data.

[0099] In embodiments of this application, possible implementations are provided in which, if a request for retrospective verification of data includes a request for verification of whether the issuance of the fourth data held by the first evidence provider was earlier than the issuance of the fourth data held by the second evidence provider, the evidence obtainer further, In response to a request to verify whether the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider, a pre-configured digest algorithm is used to calculate the fourth proof data based on the MIME standard or S / MIME standard, and the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data are obtained. From one or more data tags stored by the evidence keeper, search for a fourth data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the first evidence provider; search for a fifth data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the second evidence provider; If the timestamp of the extended information for the fourth data tag is earlier than the timestamp of the extended information for the fifth data tag, it is determined that the issuance of the fourth data held by the first evidence provider was earlier than the issuance of the fourth data held by the second evidence provider.

[0100] Based on the same inventive concept, embodiments of the present application further provide an electronic device including a processor and memory, wherein a computer program is stored in the memory, and the processor is configured to execute the computer program and perform the data retrospective verification method of any one of the embodiments described above.

[0101] Based on the same inventive concept, embodiments of the present application further provide a storage medium on which a computer program is stored, and which, when executed, is configured to perform the data retrospective verification method of any one of the embodiments described above.

[0102] Those skilled in the art can refer to the corresponding processes in the embodiments of the above methods for detailed operating processes of the above systems, apparatus, and modules, and will clearly understand that for the sake of brevity, such explanations are omitted here.

[0103] As those skilled in the art will understand, the technical solutions of this application may be embodied essentially or in whole or in part in the form of a software product, which is stored on a storage medium and includes a plurality of program instructions such that an electronic device (e.g., a personal computer, server, or network device) executes all or part of the steps of the method described in each embodiment of this application when the electronic device executes the program instructions. The storage medium includes a variety of media capable of storing program code, such as U disks, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0104] Alternatively, all or part of the steps of the embodiments of the above method may be completed by hardware related to the program instruction (e.g., electronic equipment such as a personal computer, server, or network device), the program instruction may be stored in a computer-readable storage medium, and when the program instruction is executed by the processor of the electronic equipment, the electronic equipment performs all or part of the steps of the method according to each embodiment of this application.

[0105] The embodiments described above are merely illustrative of, and not limiting, the technical solutions of this application. While the application has been described in detail with reference to the embodiments above, those skilled in the art should understand that, within the spirit and principles of this application, it is still possible to modify the technical solutions described in the embodiments above, or to make equivalent substitutions for some or all of their technical features. Such modifications or substitutions do not cause the corresponding technical solutions to deviate from the scope of protection of this application.

Claims

1. A method for retrospectively verifying data, wherein the data is encapsulated according to the MIME standard or the S / MIME standard, and the method is The roles of evidence provider, evidence preservation, and evidence acquisition, including one or more evidence providers, must be defined in advance. For any one of the one or more evidence providers, the evidence provider provides proof data, and based on the proof data, the system determines an extended information and a proof element that includes the complete data fingerprint value and / or segmented data fingerprint value obtained by calculating the proof data based on the MIME standard or S / MIME standard using a pre-configured digest algorithm, and further combines the extended information and the proof element to generate a unique data tag for the proof data, submits the data tag to the evidence preservator corresponding to the evidence preservation role, and the evidence preservator stores the data tag. A method for retrospectively verifying data, characterized in that an evidence retriever corresponding to an evidence acquisition role responds to a data retrospective verification request by querying and retrieving a target data tag from one or more data tags stored by an evidence keeper based on the verification conditions in the data retrospective verification request, and further obtains a verification result based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value.

2. The aforementioned extended information includes time, identity and actions, The actions involve performing operations on proof data, such as outputting, inputting, retaining, or discarding it. Identity is a value that uniquely identifies the operator performing output, input, retention, or disposal operations on the certification data. The method according to claim 1, characterized in that the time is the time value of the only data tag that generates the proof data.

3. The method according to 2, wherein the provision of proof data by the evidence provider constitutes performing an output operation on the proof data, the extended information further includes a data recipient.

4. The method according to claim 2, wherein the provision of proof data by the evidence provider constitutes performing an input operation on the proof data, the extended information further includes the data provider.

5. The aforementioned method, With respect to the configured fingerprint element, the evidence provider traverses the data or fingerprint library they possess, and if there is current data that matches the configured fingerprint element, the extended information of the current data is determined based on the matching current data. The current data's extended information and the configured fingerprint elements are combined to generate a unique data tag for the current data, which is then submitted to the evidence keeper corresponding to the evidence preservation role, and the evidence keeper stores the data tag. The method according to claim 2, further comprising:

6. If a request for retrospective verification of data includes a request to confirm that the first proof data entered by the first evidence provider is from the second evidence provider, When an evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves the verification result based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value, The evidence gatherer, in response to a request from the first evidence provider to confirm that the first proof data entered by the first evidence provider is from the second evidence provider, uses a pre-configured digest algorithm to calculate the first proof data based on the MIME standard or S / MIME standard, and obtains the complete data fingerprint value and / or segmented data fingerprint value of the first proof data, The evidence retriever searches for at least one first data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the first proof data, To determine whether the identity of the extended information of at least one first data tag includes the second evidence provider, If the identity of the extended information of at least one first data tag includes a second evidence provider, determine whether the data recipient of the extended information of at least one first data tag includes the first evidence provider, and if so, confirm that the first proof data entered by the first evidence provider is from the second evidence provider; otherwise, confirm that the first proof data entered by the first evidence provider is not from the second evidence provider. The method according to 3, further comprising confirming that if the identity of the extended information of at least one first data tag does not include the second evidence provider, the first proof data entered by the first evidence provider is not from the second evidence provider.

7. If a data retrospective verification request includes a request to verify that a second proof data output by a first evidence provider is transmitted to a third evidence provider, When an evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves the verification result based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value, In response to a request for verification that the second proof data output by the first evidence provider is transmitted to the third evidence provider, the evidence provider, using a pre-configured digest algorithm, calculates the second proof data based on the MIME standard or S / MIME standard and obtains the complete data fingerprint value and / or segmented data fingerprint value of the second proof data. The evidence retriever searches for at least one second data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the second proof data, Determining whether the identity of the extended information of at least one second data tag includes the first evidence provider, whether the action of the extended information of at least one second data tag is data output, and whether the data recipient is the third evidence provider, If the identity of the extended information of at least one second data tag includes the first evidence provider, and the action of the extended information of at least one second data tag is data output, and the data recipient is the third evidence provider, then it is determined that the second proof data output by the first evidence provider is transmitted to the third evidence provider. The method according to claim 3, further comprising determining that the first evidence provider has not outputted the second proof data if the identity of the extended information of at least one second data tag does not include the first evidence provider, or if the action of the extended information of at least one second data tag is not the output of data.

8. If a request for retrospective verification of data includes a request to verify that the first evidence provider possesses or destroys the third evidence data, When an evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves the verification result based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value, The evidence gatherer, in response to a request to verify that the first evidence provider possesses or destroys the third proof data, uses a pre-configured digest algorithm to calculate the third proof data based on the MIME standard or S / MIME standard, and obtains the complete data fingerprint value and / or segmented data fingerprint value of the third proof data, The evidence retriever searches for at least one third data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the third proof data, To determine whether the identity of the extended information of at least one third data tag includes the first evidence provider, If the identity of the extended information of at least one third data tag includes the first evidence provider, the action of the extended information of at least one third data tag is confirmed, and if the action of the extended information of at least one third data tag is data destruction, it is decided that the first evidence provider will destroy the third proof data, and if the action of the extended information of at least one third data tag is data retention, it is decided that the first evidence provider will retain the third proof data, The method according to 2, further comprising determining that if the identity of the extended information of at least one third data tag does not include the first evidence provider, the first evidence provider does not possess or dispose of the third proof data.

9. If the request for retrospective verification of the data includes a request for verification of whether the issuance of the fourth data held by the first evidence provider was earlier than the issuance of the fourth data held by the second evidence provider, An evidence retriever, in response to a data retrospective verification request, queries and retrieves a target data tag from one or more data tags stored by the evidence keeper based on the verification conditions in the data retrospective verification request, and further retrieves verification results based on one or more of the target data tag's extended information, complete data fingerprint value, and segmented data fingerprint value. The evidence gatherer, in response to a request to verify whether the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider, uses a pre-configured digest algorithm to calculate the fourth proof data based on the MIME standard or S / MIME standard, and obtains the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data, The evidence retriever searches for a fourth data tag among one or more data tags stored by the evidence keeper that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the first evidence provider, and searches for a fifth data tag that matches the complete data fingerprint value and / or segmented data fingerprint value of the fourth proof data and whose identity is that of the second evidence provider, The method according to claim 2, characterized in that if the time of the extended information of the fourth data tag is earlier than the time of the extended information of the fifth data tag, it is determined that the issuance of the fourth data held by the first evidence provider is earlier than the issuance of the fourth data held by the second evidence provider.

10. A data retrospective verification device, wherein the data is encapsulated according to the MIME standard or S / MIME standard, and the device is A definition module for pre-defining evidence-providing roles, evidence-preserving roles, and evidence-acquisition roles, including one or more evidence providers, The system provides proof data, and based on the proof data, determines proof elements that include augmented information and a pre-configured digest algorithm, which calculate the proof data based on the MIME standard or S / MIME standard, and / or segmented data fingerprint values, and further combines the augmented information and proof elements to generate a unique data tag for the proof data, and submits the data tag to one of the one or more evidence providers corresponding to the evidence preservation role. Evidence keeper for storing one or more data tags, A data retrospective verification device characterized by including an evidence retrieval agent corresponding to an evidence retrieval role for querying and retrieving a target data tag from one or more data tags stored by an evidence keeper based on the verification conditions in the data retrospective verification request in response to a data retrospective verification request, and further obtaining verification results based on one or more of the extended information of the target data tag, the complete data fingerprint value, and the segmented data fingerprint value.