Data verification method and apparatus, and device and medium
By hashing and adding multiple data, the verification digest is obtained, and the problem of inefficient data verification in the prior art is solved, and fast and efficient data integrity verification is achieved.
Patent Information
- Application Number
- PCT/CN2024/129033
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-23
- Filing Date
- 2024-10-31
- Publication Date
- 2025-05-30
AI Technical Summary
Existing data digest algorithms with keys are less efficient when verifying integrity of multiple data, and have a large amount of calculation, resulting in a reduced verification efficiency.
By obtaining the hash values of the first data and the second data, adding them, performing a preset digest algorithm processing, and obtaining a verification digest, which is used to verify whether the data has been tampered with and improving the verification efficiency of multiple data.
It realizes rapid verification of whether multiple data has been tampered with, improves the efficiency of data integrity verification and reduces the amount of calculation.
Smart Images

Figure CN2024129033_30052025_PF_FP_ABST
Abstract
Description
Data verification method, device, equipment and medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on November 23, 2023, with application number 202311572536.6 and application name "A data verification method, device, equipment and medium", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of information security technology, and in particular to a data verification method, apparatus, device and medium. Background Art
[0004] The key characteristic of a data digest algorithm is that the generated data digest cannot be reverse decrypted. Using the same data digest algorithm on the same data will yield the same data digest. In practice, using the same data digest algorithm on different data often yields different data digests. Therefore, in the field of information security, data digest algorithms can be used to verify whether data has been tampered with.
[0005] To improve the accuracy of verifying whether data has been tampered with, a keyed data digest algorithm is currently commonly used to generate a corresponding data digest. The solution for verifying whether data has been tampered with is to use the same data digest algorithm to calculate the digest of the data again. If the two data digests are the same, it indicates that the data has not been tampered with. If the two data digests are different, it indicates that the data has been tampered with.
[0006] However, due to the large amount of computation required for keyed data digest algorithms, the efficiency of integrity verification of multiple data using this method is low.
[0007] Summary of the Invention
[0008] The present application provides a data verification method, apparatus, device and medium for improving the efficiency of integrity verification of multiple data.
[0009] In a first aspect, the present application provides a data verification method, comprising: obtaining first data and second data; performing hash processing on the first data and the second data according to a hash algorithm to obtain a hash value of the first data and a hash value of the second data; performing digest processing on the sum of the hash values of the first data and the second data according to a preset digest algorithm to obtain a first verification digest; and verifying whether any of the first data and the second data has been tampered with based on the first verification digest.
[0010] Using this method, the present application can verify whether any of the first and second data has been tampered with based on the first verification digest. That is, if the first verification digest is the same as the corresponding standard digest, then it indicates that neither the first nor the second data has been tampered with. Therefore, using this method, it is possible to verify whether any of the multiple data has been tampered with based on the first verification digest, thereby improving the efficiency of verifying whether multiple data have been tampered with.
[0011] In one possible embodiment, verifying whether tampered data exists in the first data and the second data based on the first verification digest includes: obtaining a first standard digest, where the first standard digest is obtained by multiplying a standard digest of the first data and a standard digest of the second data, where the standard digests of the first data and the second data are obtained by digesting a hash value of the first data and a hash value of the second data, respectively, based on a preset digest algorithm. Verifying whether tampered data exists in the first data and the second data based on the first verification digest and the first standard digest.
[0012] Based on this embodiment, the first standard digest is obtained by multiplying the standard digest of the first data by the standard digest of the second data, thereby ensuring the feasibility of the method provided in this application.
[0013] In one possible embodiment, if the first verification digest is not equal to the first standard digest, the method further includes: performing digest processing on the hash value of the first data according to a preset digest algorithm to obtain a verification digest of the first data, and verifying whether the first data has been tampered with based on the verification digest of the first data and the standard digest of the first data. Furthermore, performing digest processing on the hash value of the second data according to the preset digest algorithm to obtain a verification digest of the second data, and verifying whether the second data has been tampered with based on the verification digest of the second data and the standard digest of the second data.
[0014] Based on this embodiment, if the first verification digest and the first standard digest are not equal, it indicates that at least one of the first data and the second data has been tampered with. If tampered data exists between the first data and the second data, whether the data has been tampered with can be determined based on the verification digest and the standard digest of the data, thereby improving the efficiency of determining whether the data has been tampered with.
[0015] In one possible embodiment, a second verification digest is obtained by performing digest processing on the sum of the hash value of the first data, the hash value of the second data, and the hash value of the third data according to a preset digest algorithm. The hash value of the third data is obtained by processing the third data according to the hash algorithm. Based on the second verification digest, the first data, the second data, and the third data are verified to determine whether any tampered data exists.
[0016] Based on this embodiment, the present application can process the three data, obtain the corresponding verification digest, and verify whether there is tampered data in the three data according to the verification digest. It is understandable that the present application can also process more data, and no longer give examples one by one.
[0017] In a possible embodiment, the preset digest algorithm includes a linear homomorphic hash algorithm.
[0018] In a second aspect, the present application provides a data verification device, comprising: a communication module for acquiring first data and second data; a processing module for performing hash processing on the first data and the second data, respectively, according to a hash algorithm to obtain a hash value of the first data and a hash value of the second data; the processing module for performing digest processing on the sum of the hash value of the first data and the hash value of the second data, according to a preset digest algorithm, to obtain a first verification digest; and the processing module for verifying whether any tampered data exists in the first data and the second data, based on the first verification digest.
[0019] In one possible embodiment, the communication module is further configured to obtain a first standard digest, where the first standard digest is obtained by multiplying a standard digest of the first data and a standard digest of the second data. The standard digests of the first data and the second data are obtained by digesting a hash value of the first data and a hash value of the second data, respectively, according to a preset digest algorithm. The processing module is specifically configured to verify whether any of the first data and the second data has been tampered with based on the first verification digest and the first standard digest.
[0020] In one possible embodiment, if the first verification digest is not equal to the first standard digest, the processing module is further configured to: perform digest processing on the hash value of the first data according to a preset digest algorithm to obtain a verification digest of the first data, and verify whether the first data has been tampered with based on the verification digest of the first data and the standard digest of the first data. Furthermore, perform digest processing on the hash value of the second data according to the preset digest algorithm to obtain a verification digest of the second data, and verify whether the second data has been tampered with based on the verification digest of the second data and the standard digest of the second data.
[0021] In one possible embodiment, the processing module is further configured to perform digest processing on the sum of the hash value of the first data, the hash value of the second data, and the hash value of the third data according to a preset digest algorithm to obtain a second verification digest, where the hash value of the third data is obtained by processing the third data according to the hash algorithm. Verifying whether any of the first data, the second data, and the third data has been tampered with is performed based on the second verification digest.
[0022] In a possible embodiment, the preset digest algorithm includes a linear homomorphic hash algorithm.
[0023] In a third aspect, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method of the first aspect and the second aspect and any one of their designs is implemented.
[0024] In a fourth aspect, an embodiment of the present application further provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor. When the computer program is executed by the processor, the processor implements the first aspect and the second aspect and any one of the design methods thereof.
[0025] The technical effects brought about by the second to fourth aspects and any one of their designs can be referred to the technical effects brought about by the corresponding designs in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the implementation methods in the embodiments of the present application or related technologies, the following is a brief introduction to the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0027] FIG1 is a flow chart of a data verification method provided in an embodiment of the present application;
[0028] FIG2 is a schematic diagram of the structure of a data verification system provided in an embodiment of the present application;
[0029] FIG3 is a schematic diagram of grouping a verification summary provided in an embodiment of the present application;
[0030] FIG4 is a schematic diagram of a structure of a storage standard summary provided by an embodiment of the present application;
[0031] FIG5 is a schematic diagram of the structure of a data verification device provided in an embodiment of the present application;
[0032] FIG6 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0033] To make the purpose, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. Obviously, the embodiments described in this application are only some of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0034] It should be noted that the brief descriptions of terms in this application are only for the purpose of facilitating the understanding of the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise specified, these terms should be understood according to their ordinary and usual meanings.
[0035] In the specification and claims of this application and the accompanying drawings, the terms "first," "second," "third," etc. are used to distinguish similar or similar objects or entities, and are not necessarily intended to limit a particular order or sequence, unless otherwise noted. It should be understood that the terms used in this manner are interchangeable under appropriate circumstances.
[0036] The terms "comprise," "include," and "have," and any variations thereof, are intended to cover but not exclude inclusion; for example, a product or device comprising a list of components is not necessarily limited to all the components expressly listed but may include other components not expressly listed or inherent to such product or device.
[0037] The term "module" refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functionality associated with that element.
[0038] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
[0039] The following describes a method for verifying data integrity in combination with existing technologies.
[0040] In the current existing technology, in the field of information security technology, the solution for verifying whether data has been tampered with is usually to verify whether the data has been tampered with based on a data summary algorithm.
[0041] For example, to verify whether transmitted data has been tampered with, the data sender can generate a data digest for the data using a data digest algorithm and send the data and data digest to the data receiver. After receiving the data, the data receiver can generate a data digest for the data using the same data digest algorithm. If the calculated data digest is the same as the received data digest, the data has not been tampered with. If the two data digests are different, the data has been tampered with.
[0042] However, since the data digest algorithm is public, a malicious tamperer can tamper with the data and then process it using the same data digest algorithm to obtain the corresponding data digest. In other words, even if the data is tampered with, the tampered data can still pass the integrity verification, resulting in a decrease in the accuracy of the data integrity verification.
[0043] To prevent both the data and the data digest from being tampered with, a keyed data digest algorithm is typically used to digest the data, obtaining a corresponding data digest. The integrity of the data is then verified based on the two data digests. In other words, if the two data digests are identical, the data has not been tampered with; if they are different, the data has been tampered with.
[0044] However, since this method performs multiple digests on the data, the computational complexity of this method is large. If this method is used to verify the integrity of multiple data, the efficiency of data integrity verification will be low.
[0045] To address the above-mentioned technical deficiencies, the present application provides a data verification and determination method and apparatus. In this method, a first device can perform hash processing on first and second data obtained according to a hash algorithm to obtain a hash value of the first data and a hash value of the second data. The first device can add the hash value of the first data and the hash value of the second data, and then perform digest processing on the added data according to a preset digest algorithm to obtain a first verification digest. The first device can verify whether any of the first and second data has been tampered with based on the first verification digest.
[0046] It is understandable that in this application, the first verification digest can be used to verify whether any of the first and second data has been tampered with. In other words, if the first verification digest is the same as the corresponding standard digest, then it indicates that neither the first nor the second data has been tampered with. Therefore, this method can be used to verify whether any of the multiple data has been tampered with based on the first verification digest, thereby improving the efficiency of verifying whether the data has been tampered with.
[0047] In addition, the first device can be a computer system or a device in a data device for executing the method shown in this application, such as a processor or processing module, etc., which is not specifically limited in this application.
[0048] FIG1 is a flow chart of a data verification method provided by an embodiment of the present invention. Taking the first device as the execution subject as an example, the flow may include the following steps:
[0049] S101: A first device obtains first data and second data.
[0050] Specifically, the first data and the second data may be data to be verified as to whether they have been tampered with. The first device may obtain the first data and the second data by receiving the first data and the second data from other devices. For example, the present application also includes a data-using device. Before using the first data and the second data, the data-using device needs to determine whether the first data and the second data have been tampered with. The data-using device may send the first data and the second data to the first device and send a request to the first device to verify the first data and the second data. Accordingly, the first device receives the first data and the second data from the data-using device, as well as the corresponding request.
[0051] The first data and the second data may also be data stored by the first device itself. For example, FIG2 is a schematic diagram of the structure of a data verification system provided in an embodiment of the present application. As shown in FIG2 , the server can be represented as the first device, and the first data and the second data can be stored in a database. The client can send a request to the first device to verify the integrity of the first data and the second data. Accordingly, the first device receives a request from the client to verify the integrity of the first data and the second data. The first device can obtain the first data and the second data to be verified from the database according to the request.
[0052] For another example, the first data and the second data may be two different system logs stored in a storage unit of the first device. When the first device receives a request to verify whether the system log has been tampered with, it may retrieve the system log from its own storage unit.
[0053] In addition, in this application, the data acquired by the first device may also include other data to be verified whether they have been tampered with (such as third data, fourth data, etc.). This application will not give examples one by one.
[0054] S102: The first device performs hash processing on the first data and the second data respectively according to a hash algorithm to obtain a hash value of the first data and a hash value of the second data.
[0055] Specifically, after obtaining the first data and the second data, the first device may perform hash processing on the first data according to a pre-set hash algorithm to obtain a hash value of the first data. Furthermore, the first device may perform hash processing on the second data according to the pre-set hash algorithm to obtain a hash value of the second data. This application does not distinguish between the order in which the first device obtains the hash value of the first data and the order in which the first device obtains the hash value of the second data.
[0056] It is understandable that if the data to be verified as to whether it has been tampered with in this application includes third data, the first device can perform hash processing on the third data according to a hash algorithm to obtain a hash value of the third data.
[0057] Still taking Figure 2 as an example, as shown in Figure 2, the encryption machine can be used to encrypt data. The server can send first data and second data to the encryption machine. The encryption machine can hash the first data and the second data, respectively, to obtain a hash value of the first data and a hash value of the second data.
[0058] For example, if the data to be verified for tampering includes i data, the i-th data can be expressed as x i , the hash value of the i-th data can be expressed as m i , then the hash value of the i-th data and the i-th data satisfies:
[0059] m i =hash(x i );
[0060] Among them, hash(x) means performing a hash operation on x.
[0061] S103 , the first device performs digest processing on the sum of the hash value of the first data and the hash value of the second data according to a preset digest algorithm to obtain a first verification digest.
[0062] Specifically, after obtaining the hash value of the first data and the hash value of the second data, the first device may add the hash value of the first data and the hash value of the second data to obtain a first aggregate hash value. That is, the first aggregate hash value is the sum of the hash value of the first data and the hash value of the second data.
[0063] Still taking FIG. 2 as an example, after the encryption machine generates the hash value of the first data and the hash value of the second data, it can also accumulate the hash value of the first data and the hash value of the second data to obtain a first aggregate hash value.
[0064] For example, the hash value of the first data can be expressed as m1, the hash value of the second data can be expressed as m2, and the first aggregate hash value can be expressed as m 1,2 , then the hash value of the first data, the hash value of the second data, and the first aggregate hash value satisfy:
[0065] m 1,2 =∑mi,i∈[1,2];
[0066] Wherein, ∑ is the accumulation symbol.
[0067] The preset digest algorithm may be set based on the importance of the data. The preset digest algorithm may also be set based on the computing power of the computing device. Alternatively, the preset digest algorithm may be set based on other requirements, which are not specifically limited in this application.
[0068] After obtaining the first aggregate hash value, the first device may perform digest processing on the first aggregate hash value according to a preset digest algorithm to obtain a first verification digest.
[0069] In one or more embodiments, the preset digest algorithm includes a linear hash homomorphic algorithm.
[0070] Specifically, the Linear Homomorphic Hash (LHH) algorithm can meet the requirements of the hash function, such as unidirectionality, collision resistance, and fixed-length output, while also having the additional homomorphism.
[0071] For example, the preset digest algorithm may be a linear hashing homomorphic algorithm, the hashing algorithm may be an SM3 hashing algorithm, and the algorithm for generating the public parameters may be a parameter initialization LHH.HGen(1 κ ,1 t )→LHHpp. Among them, LHH.HGen(1 κ ,1 t )→LHHpp means that after inputting the security parameter κ and the dimension t of the message vector, the public parameter LHHpp is output. LHHpp includes the cyclic group Order q, generator g, The safety parameters and orders satisfy:
[0072] κ can be determined based on a hash algorithm, and t can be set based on the importance of the data. That is, the more important the data, the higher the value of t. For example, a case of low importance might have t set to 1, while a case of high importance might have t set to 2 or 3. In other words, users can set the value of t based on their needs.
[0073] The first device can t different g are obtained. Among them, g can be used as a parameter of the digest algorithm. t different g can be expressed as g i , i∈[1,t].
[0074] The first verification digest can be expressed as h, and the first aggregate hash value can be expressed as m. Then the first verification digest and the first aggregate hash value satisfy:
[0075] h=∏ i∈[t] g i m[i] ;
[0076] Among them, ∏ is the multiplication symbol.
[0077] Based on step S103, the first device can perform digest processing on the sum of the hash value of the first data and the hash value of the second data using a preset digest algorithm to obtain a first verification digest, which can improve the efficiency of obtaining the first verification digest and thus improve the efficiency of verifying whether multiple data have been tampered with.
[0078] S104: The first device verifies whether there is tampered data in the first data and the second data according to the first verification digest.
[0079] Specifically, before verifying whether there is tampered data in the first data and the second data, the first device may further obtain the first standard digest.
[0080] In one or more embodiments, the first device verifies whether tampered data exists in the first data and the second data based on the first verification digest and the first standard digest.
[0081] Specifically, the first standard digest may be obtained by multiplying the standard digest of the first data and the standard digest of the second data. In other words, the first standard digest may be the product of the standard digest of the first data and the standard digest of the second data. The standard digest of the first data may be obtained by digesting the hash value of the first data according to a preset digest algorithm (such as a linear homomorphic hash algorithm). Similarly, the standard digest of the second data may be obtained by digesting the hash value of the second data according to a preset digest algorithm (such as a linear homomorphic hash algorithm).
[0082] For example, still taking Figure 2 as an example, the server can call the encryption machine to perform hash processing and digest processing on the first data (e.g., system log 1) to obtain a standard digest of the first data. The server can simultaneously store the first data and the standard digest of the first data in the database. Similarly, the server can call the encryption machine to perform hash processing and digest processing on the second data (e.g., system log 2) to obtain a standard digest of the second data. The server can simultaneously store the first data and the standard digest of the first data in the database. The server can also call the encryption machine to multiply the standard digest of the first data and the standard digest of the second data to obtain the first standard digest.
[0083] The first device can receive the first standard digest from other devices. For example, the present application also includes a second device, and the first data and the second data are both sent by the second device to the first device. Then, while the second device sends the first data and the second data to the first device, it can also send the first standard digest to the first device. Accordingly, the first device receives the first standard digest from the second device. The first standard digest can also be obtained by the first device from a storage device. For example, still taking Figure 2 as an example, the first standard digest is pre-stored in the database, and the server can obtain the first standard digest from the database.
[0084] After obtaining the first verification digest and the first standard digest, the first device can determine whether the first verification digest and the first standard digest are equal. If the first verification digest and the first standard digest are equal, it indicates that neither the first data nor the second data has been tampered with. If the first verification digest and the first standard digest are not equal, it indicates that at least one of the first data and the second data has been tampered with.
[0085] Based on this embodiment, the first standard digest is obtained by multiplying the standard digest of the first data by the standard digest of the second data, thereby ensuring the feasibility of the method provided in this application.
[0086] In one or more embodiments, a hash value of the first data, a hash value of the second data, and a hash value of the third data are digested according to a preset digest algorithm to obtain a second verification digest, where the hash value of the third data is obtained by processing the third data according to the hash algorithm. The second aggregate hash value is digested according to a preset digest algorithm to obtain a second verification digest; and the first, second, and third data are verified based on the second verification digest to determine whether any tampered data exists.
[0087] Specifically, as can be seen from the above content, the first aggregate hash value is the sum of the hash value of the first data and the hash value of the second data. If third data is added to the data to be verified in this application, the first aggregate hash value and the hash value of the third data can be accumulated to obtain the second aggregate hash value. In other words, the second aggregate hash value is the sum of the hash value of the first data, the hash value of the second data, and the hash value of the third data. The specific method for obtaining the hash value of the third data can be referred to the specific method for obtaining the hash value of the first data, and will not be repeated here.
[0088] Alternatively, if the data to be verified in the present application includes third data, the hash value of the first data, the hash value of the second data, and the hash value of the third data may be accumulated to obtain a second aggregate hash value.
[0089] It is understandable that the data to be verified in this application may also include more data, and the hash values of the corresponding data are accumulated to obtain the corresponding aggregate hash value, which will not be given one by one here.
[0090] After generating the second aggregate hash value, the first device may perform digest processing on the second aggregate hash value according to a preset digest algorithm to obtain a second verification digest. The specific manner in which the first device obtains the second verification digest can be found in the specific manner in which the first device obtains the first verification digest, and will not be further described here.
[0091] The first device can determine whether any of the first, second, and third data has been tampered with based on the second verification digest and the second standard digest. Specifically, if the second verification digest is equal to the second standard digest, then the first, second, and third data have not been tampered with. If the second verification digest is not equal to the second standard digest, then at least one of the first, second, and third data has been tampered with. The specific method for the first device to obtain the second standard digest can be found in the specific method for the first device to obtain the first standard digest, and will not be further described here.
[0092] Based on this embodiment, the present application can process the three data, obtain the corresponding verification digest, and verify whether there is tampered data in the three data according to the verification digest. It is understandable that the present application can also process more data, and no longer give examples one by one.
[0093] In one or more embodiments, if the first verification digest is not equal to the first standard digest, the first device may perform digest processing on the hash value of the first data according to a preset digest algorithm to obtain a verification digest of the first data, and verify whether the first data has been tampered with based on the verification digest of the first data and the standard digest of the first data. And,
[0094] The first device may perform digest processing on the hash value of the second data according to a preset digest algorithm to obtain a verification digest of the second data, and verify whether the second data has been tampered with according to the verification digest of the second data and the standard digest of the second data.
[0095] Specifically, the specific manner in which the first device obtains the verification digest of the first data and the verification digest of the second data can be found in the specific manner in which the first device obtains the first verification digest, which will not be repeated here.
[0096] If the verification digest of the first data is the same as the standard digest of the first data, it means that the first data has not been tampered with. Otherwise, the first data has been tampered with. Similarly, if the verification digest of the second data is the same as the standard digest of the second data, it means that the second data has not been tampered with. Otherwise, the second data has been tampered with.
[0097] Based on this embodiment, if the first verification digest and the first standard digest are not equal, it indicates that at least one of the first data and the second data has been tampered with. If tampered data exists between the first data and the second data, whether the data has been tampered with can be determined based on the verification digest and the standard digest of the data, thereby improving the efficiency of determining whether the data has been tampered with.
[0098] When there is tampered data among multiple data to be verified, in order to improve the efficiency of determining the tampered data, the present application can set the number of groups according to the number of data to be verified, group the data according to the number of groups, and obtain the corresponding verification summary based on the grouped data.
[0099] For example, Figure 3 is a schematic diagram of grouping a verification summary provided in an embodiment of the present application. As shown in Figure 3, the data to be verified includes 8 data items. The 8 data items can be represented as x1, x2, ..., x7, and x8, respectively. The number of groups is set to 4. The first device can divide the 8 data items to be verified into 4 groups. That is, x1 and x2 are in the same group, ..., x7 and x8 are in the same group.
[0100] When storing data, the first device can perform digest processing on the hash value of the data to be verified according to the linear homomorphic hash algorithm to obtain a standard digest of the corresponding data. The first-level standard digests of the eight data can be represented as h1, h2, ..., h7, and h8 respectively.
[0101] The first device may multiply the standard digest of x1 and the standard digest of x2 to obtain a secondary standard digest h of x1 and x2. 1,2 Similarly, the first device can obtain the secondary standard summary h of x3 and x4 3,4 , x5 and x6 secondary standard summary h 5,6 and the secondary standard summary of x7 and x8 7,8 .
[0102] The first device can 1,2 With h 3,4 Multiply them to obtain the three-level standard summary h of x1, x2, x3 and x4 1,4 Similarly, the first device can 5,6 With h 7,8 Multiply them to obtain the three-level standard summary h of x5, x6, x7 and x8 5,8 .
[0103] The first device can 1,4 With h 5,8 Multiply them to get the four-level standard summary h of x1, x2, x3, x4, x5, x6, x7 and x8 1,8 .
[0104] When the first device verifies the data to be verified, the first device can perform hash calculations on the 8 data according to the hash algorithm to obtain the hash values of the 8 data. The hash values of the 8 data can be expressed as m1, m2, ..., m7, m8 respectively. The first device can accumulate the hash values of the 8 data to obtain the aggregate hash value m of the 8 data. 1,8The hash value of 8 data and the aggregate hash value of 8 data satisfy:
[0105] m 1,8 =∑m i mod q;
[0106] Where i∈[1,8], q is the order in the linear homomorphic hashing algorithm.
[0107] The first device can perform digest processing on the aggregate hash value according to the linear homomorphic hash algorithm to obtain the four-level verification digest of the eight data. The four-level verification digest of the eight data can be expressed as H 1,8 , then the verification summary and aggregate hash value of the 8 data satisfy:
[0108] LHH.Hash(m 1,8 )=H 1,8 .
[0109] The first device can determine whether the four-level verification digest of the eight data is equal to the four-level standard digest of the eight data. 1,8 With h 1,8 Are they equal? If H 1,8 With h 1,8 If H is equal, it means that the 8 data have not been tampered. 1,8 With h 1,8 If they are not equal, it means that at least one of the 8 data has been tampered with.
[0110] If H 1,8 With h 1,8 If they are not equal, the first device can obtain the third-level verification summary H of the first 4 data. 1,4 And the three-level verification summary H of the last four data 5,8 Among them, the first device obtains H 1,4 and H 5,8 For the specific method, please refer to the first device to obtain H 1,8 The specific method will not be described here.
[0111] The first device can determine H 1,4 With h 1,4 Are they equal? If H 1,4 With h 1,4 If they are equal, it means x1, x2, x3, and x4 have not been tampered with. 1,4 With h 1,4 If they are not equal, it means that at least one of the data in x1, x2, x3, and x4 has been tampered with. Similarly, the first device can determine H 5,8 With h 5,8 Are they equal? If H 5,8 With h 5,8If they are equal, it means that none of x5, x6, x7, and x8 have been tampered with. If H 5,8 and h 5,8 are not equal, it means that at least one of the data in x5, x6, x7, and x8 has been tampered with.
[0112] It can be understood that if the three-level verification digest is not equal to the three-level standard digest, the first device can obtain the second-level verification digest. The specific method for the second device to obtain the second-level verification digest can refer to the specific method for the second device to obtain the four-level verification digest, which will not be elaborated here. The first device can determine whether the second-level verification digest is equal to the second-level standard digest. If the second-level verification digest is not equal to the second-level standard digest, the first device can determine the tampered data by comparing whether the first-level verification digest is equal to the first-level standard digest.
[0113] In one or more embodiments, the first device can group the data according to preset grouping parameters and determine the corresponding verification digest based on the grouped data.
[0114] Specifically, the grouping parameters can include the grouping width and the number of grouping levels. Among them, the grouping width is used to indicate the number of data included in a group. The number of grouping levels is used to indicate the number of levels of the grouping.
[0115] To ensure the rationality of the grouping parameters and the efficiency of ensuring the integrity of the verification data, this application can set the relationship that the grouping width and the grouping level satisfy. The grouping width can be expressed as λ, and the number of grouping levels can be expressed as μ, then the grouping width and the number of grouping levels satisfy:
[0116] μ ≤ λ + 1.
[0117] The number of multiple data to be verified can be expressed as i, and the multiple data to be verified can be expressed as x k , k ∈ [1, i]. The grouping level can be expressed as j + 1, 1 < j < μ, and j is an integer. When the grouping width is divisible by the number of data to be verified (i.e., λ|i), multiple levels of verification digests need to be calculated. When then the standard digest of the data in the interval of k ∈ [i - λ j + 1, i] needs to be calculated That is, according to the linear homomorphic hashing algorithm, the hash values of the data in the interval of k ∈ [i - λ j + 1 + b·λ j-1 , i - λ j + (b + 1)·λ j-1 , b ∈ [0, λ) are calculated to obtain the corresponding standard digest.
[0118] That is,
[0119] In addition, the present application can also group and store the primary standard summary and multiple standard summaries according to the grouping method, thereby reducing the number of tags of the standard summaries in the database.
[0120] For example, FIG4 is a schematic diagram of a structure of a storage standard summary provided by an embodiment of the present application. As shown in FIG4, the group width is set to 2, the number of group levels is set to 3, and the data to be verified can be represented as x1, x2, ..., x9, x 10 , the label used to store the first-level standard summary can be expressed as label, and the label used to store the multi-level standard summary (ie, the second-level standard summary and the third-level standard summary) can be expressed as agg_label.
[0121] The first device may process x1, x2, ..., x7, and x8 respectively to obtain corresponding first-level standard digests h1, h2, ..., h7, and h8.
[0122] The first device processes the first-level standard summary according to the grouping width and the number of grouping levels to obtain the corresponding second-level standard summary h 1,2 , h 3,4 , h 5,6 , h 7,8 .
[0123] The first device can process the first-level standard summary according to the grouping width and the number of grouping levels to obtain the corresponding third-level standard summary h 1,4 , h 5,8 .
[0124] The first device may store the first-level standard summary in a field corresponding to label, and store the second-level label and the third-level label in fields corresponding to agg_label.
[0125] Based on the same technical concept, on the basis of the above embodiments, in the embodiments of the present application, a data verification device is provided. FIG5 is a schematic diagram of the structure of a data verification device provided in some embodiments of the present application. As shown in FIG5 , the device includes:
[0126] Communication module 501 is configured to obtain first data and second data. Processing module 502 is configured to perform hash processing on the first data and the second data, respectively, according to a hash algorithm to obtain a hash value of the first data and a hash value of the second data. Processing module 502 is further configured to perform digest processing on the sum of the hash values of the first data and the second data according to a preset digest algorithm to obtain a first verification digest. Processing module 502 is further configured to verify whether any of the first data and the second data has been tampered with, based on the first verification digest.
[0127] In one possible embodiment, processing module 502 is further configured to obtain a first standard digest, where the first standard digest is obtained by multiplying the standard digest of the first data and the standard digest of the second data. The standard digests of the first data and the second data are obtained by digesting the hash values of the first data and the second data, respectively, according to a preset digest algorithm. Processing module 502 is specifically configured to verify whether any of the first data and the second data has been tampered with based on the first verification digest and the first standard digest.
[0128] In one possible embodiment, if the first verification digest is not equal to the first standard digest, the processing module 502 is further configured to: perform digest processing on the hash value of the first data according to a preset digest algorithm to obtain a verification digest of the first data, and verify whether the first data has been tampered with based on the verification digest of the first data and the standard digest of the first data. Furthermore, perform digest processing on the hash value of the second data according to the preset digest algorithm to obtain a verification digest of the second data, and verify whether the second data has been tampered with based on the verification digest of the second data and the standard digest of the second data.
[0129] In one possible embodiment, the processing module 502 is further configured to perform digest processing on the sum of the hash value of the first data, the hash value of the second data, and the hash value of the third data according to a preset digest algorithm to obtain a second verification digest, where the hash value of the third data is obtained by processing the third data according to the hash algorithm. Based on the second verification digest, the first data, the second data, and the third data are verified to determine whether any tampered data exists.
[0130] In a possible embodiment, the preset digest algorithm includes a linear homomorphic hash algorithm.
[0131] Based on the same inventive concept, an embodiment of the present application provides an electronic device that can implement the functions of the data processing device discussed above. FIG6 shows a schematic diagram of the structure of an electronic device provided by an embodiment of the present application.
[0132] The electronic device in the embodiment of the present application may include a processor 601. The processor 601 is the control center of the device, and can use various interfaces and lines to connect the various parts of the device, by running or executing instructions stored in the memory 603 and calling data stored in the memory 603. Optionally, the processor 601 may include one or more processing units. The processor 601 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system and application programs, etc., and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 601. In some embodiments, the processor 601 and the memory 603 may be implemented on the same chip. In some embodiments, they may also be implemented separately on independent chips.
[0133] The processor 601 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor can be a microprocessor or any conventional processor. The method steps disclosed in conjunction with the embodiments of the present application can be directly executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor.
[0134] In the embodiment of the present application, the memory 603 stores instructions that can be executed by at least one processor 601. The at least one processor 601 can be used to execute the method steps disclosed in the embodiment of the present application by executing the instructions stored in the memory 603.
[0135] The memory 603 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 603 may include at least one type of storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (Random Access Memory, RAM), a static random access memory (Static Random Access Memory, SRAM), a programmable read-only memory (Programmable Read Only Memory, PROM), a read-only memory (Read Only Memory, ROM), an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), a magnetic memory, a disk, an optical disk, etc. The memory 603 is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory 603 in the embodiment of the present application can also be a circuit or any other device that can realize a storage function, for storing program instructions and / or data.
[0136] In the embodiment of the present application, the apparatus may further include a communication interface 602 , through which the electronic device may transmit data.
[0137] Optionally, the processing module 502 and / or communication module 501 shown in Figure 5 can be implemented by the processor 601 (or the processor 601 and the communication interface 602) shown in Figure 6, that is, the actions of the processing module 502 and / or communication module 501 can be executed by the processor 601 (or the processor 601 and the communication interface 602).
[0138] Based on the same inventive concept, an embodiment of the present application further provides a computer-readable storage medium, which may store instructions that, when executed on a computer, cause the computer to execute the operating steps provided in the above method embodiment. The computer-readable storage medium may be the memory 603 shown in FIG6 .
[0139] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0140] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.
[0141] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0142] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby executing the program on the computer or other programmable device.
Claims
1. A data verification method, characterized in that: The method comprises: Acquire first data and second data; Perform hash processing on the first data and the second data respectively according to a hash algorithm to obtain a hash value of the first data and a hash value of the second data; Performing digest processing on the sum of the hash value of the first data and the hash value of the second data according to a preset digest algorithm to obtain a first verification digest; Verify whether there is tampered data in the first data and the second data according to the first verification digest.
2. The method according to claim 1, characterized in that The verifying, according to the first verification digest, whether there is tampered data in the first data and the second data includes: Obtaining a first standard digest, where the first standard digest is obtained by multiplying a standard digest of the first data and a standard digest of the second data, where the standard digest of the first data and the standard digest of the second data are obtained by respectively performing digest processing on a hash value of the first data and a hash value of the second data according to the preset digest algorithm; Verify whether tampered data exists in the first data and the second data according to the first verification digest and the first standard digest.
3. The method according to claim 2, characterized in that If the first verification digest is not equal to the first standard digest, the method further includes: Performing digest processing on the hash value of the first data according to the preset digest algorithm to obtain a verification digest of the first data, and verifying whether the first data has been tampered with according to the verification digest of the first data and the standard digest of the first data; and The hash value of the second data is digested according to the preset digest algorithm to obtain a verification digest of the second data, and whether the second data has been tampered with is verified according to the verification digest of the second data and a standard digest of the second data.
4. The method according to claim 1, characterized in that The method further comprises: Performing digest processing on the sum of the hash value of the first data, the hash value of the second data, and the hash value of the third data according to the preset digest algorithm to obtain a second verification digest, wherein the hash value of the third data is obtained by processing the third data according to the hash algorithm; Verify whether any tampered data exists in the first data, the second data, and the third data according to the second verification digest.
5. The method according to any one of claims 1 to 4, characterized in that: The preset digest algorithm includes a linear homomorphic hash algorithm.
6. A data verification device, characterized in that: The device comprises: A communication module, used to obtain first data and second data; A processing module, configured to perform hash processing on the first data and the second data respectively according to a hash algorithm to obtain a hash value of the first data and a hash value of the second data; The processing module is further used to perform digest processing on the sum of the hash value of the first data and the hash value of the second data according to a preset digest algorithm to obtain a first verification digest; The processing module is further used to verify whether there is tampered data in the first data and the second data according to the first verification summary.
7. The device according to claim 6, characterized in that The communication module is further used to obtain a first standard digest, where the first standard digest is obtained by multiplying a standard digest of the first data and a standard digest of the second data, where the standard digest of the first data and the standard digest of the second data are obtained by respectively performing digest processing on a hash value of the first data and a hash value of the second data according to the preset digest algorithm; The processing module is specifically configured to verify whether there is tampered data in the first data and the second data according to the first verification digest and the first standard digest.
8. The device according to claim 7, characterized in that If the first verification digest is not equal to the first standard digest, the processing module is further configured to: Performing digest processing on the hash value of the first data according to the preset digest algorithm to obtain a verification digest of the first data, and verifying whether the first data has been tampered with according to the verification digest of the first data and the standard digest of the first data; and The hash value of the second data is digested according to the preset digest algorithm to obtain a verification digest of the second data, and whether the second data has been tampered with is verified according to the verification digest of the second data and a standard digest of the second data.
9. The device according to claim 6, characterized in that The processing module is also used for: Performing digest processing on the sum of the hash value of the first data, the hash value of the second data, and the hash value of the third data according to the preset digest algorithm to obtain a second verification digest, wherein the hash value of the third data is obtained by processing the third data according to the hash algorithm; Verify whether any tampered data exists in the first data, the second data, and the third data according to the second verification digest.
10. The device according to any one of claims 6 to 9, characterized in that: The preset digest algorithm includes a linear homomorphic hash algorithm.
11. An electronic device, characterized in that: The electronic device comprises at least a processor and a memory, and the processor is used to implement the steps of the data verification method as claimed in any one of claims 1 to 5 when executing a computer program stored in the memory.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program executable by an electronic device. When the program runs on the electronic device, the electronic device executes the steps of the data verification method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Methods, apparatuses and methods for protecting and verifying data integrity
CN102446250A
Electronic evidence storage and verification method and device based on block chain
CN113129145A
Block chain data generation and verification method and device
CN114153849A
Mimicry storage system data verification method, device, equipment, medium and system
CN115913572A
Data verification method and device, equipment and medium
CN117556476A