Checksum Generation and Recording (CPP-001)

CPP-IdentifierCPP-001
CPP-LabelChecksum Generation and Recording
AuthorKris Dekeyser
ContributorsJohan Kylander, Bertrand Caron
EvaluatorsFelix Burger, Maria Benauer, Fen Zhang
Change historyComments
Version 1.0.0 - 2025-08-29Milestone version
Version 1.1.0 - 2025-10-16Migration to XML

1. Description of the CPP

The TDA (Trustworthy Digital Archive) records checksums for every File.

Inputs and outputs

Input(s)
Data
File
Documentation/guidance
Storage management policy - Checksum algorithms
Output(s)
Metadata
Fixity metadata (one or multiple checksum(s) for the File as well as their associated algorithms)
Provenance metadata (a timestamp or event that describes the checksum calculation)

Definition and scope

A checksum or message digest is a fixed size stream of data generated by a transformation of the File data by means of an algorithm. Any change to the data would result in a change to the calculated digest. The algorithm can be a cyclic redundancy check or a cryptographic hash function.

The File checksums form an important part of the fixity information which is the cornerstone for performing bit-level digital preservation. The system must keep track of this message digest for each File. Due to the possibility of collisions (multiple data streams having the same checksum), storing multiple message digests generated by different algorithms is recommended. The TDA policy should define a list of required algorithms.

The Checksum Generation and Recording process is the action of acquiring and storing the message digests associated with any File that the system needs to keep track of. Files should come with any number of checksums generated prior to their submission. In that case, the system should store those checksums and use them as-is and new checksums should be generated for those algorithms that are missing.

Process description

Trigger event(s)

Trigger EventCPP-identifier
A new SIP is submitted and processedCPP-029 (Ingest)
File update or replacement due to Preservation Action (e.g. migration)CPP-014 (File Migration)
Any other action that results in a new or updated File being added to the system

Step-by-step description

NoSupplierInputStepsOutputCustomer
 sequence
1Storage management policy - Checksum algorithmsGet the list of accepted checksum algorithmsList of accepted checksum algorithms
2 File Calculate the checksum for each algorithmList of checksums for the File based on different algorithms
List of checksum algorithms
3List of checksums for the File based on different algorithmsStore the checksums in the Fixity metadata for the FileUpdated Fixity metadata of the File in the TDA databaseCPP-002 (Checksum Validation)
CPP-003 (Integrity Checking)
4 File Document the event and its datetimeDatetime for the checksum generation and other related Provenance metadata

Rationale(s) and worst case(s)

RationaleImpact of inaction or failure of the process
Keeping track of the fixity information of each FileCorrupted data can get undetected or be detected when it is too late to take corrective action
Event datetime for checksum generationNo starting point from when the fixity can be checked (and guaranteed)
Multiple checksums for each FileCollisions where changes to a File produce the same checksum, are more likely with a single checksum algorithm than with multiple checksum algorithms

2. Dependencies and relationships with other CPPs

Dependencies

CPP-IDCPP-TitleRelationship description
///

Other relations

RelationCPP-IDCPP-TitleRelationship description
Required byCPP-002Checksum ValidationCPP-002 relies on fixity information as produced and stored by CPP-001, when triggered by CPP-025 Enabling Access and CPP-006 AIP Batch Export. When triggered by CPP-029 Ingest CPP-002 rather relies on the fixity information supplied in the SIP.
Required byCPP-003Integrity CheckingThe integrity checking process relies on the fixity information as produced and stored by CPP-001.
Required byCPP-006AIP Batch ExportFixity metadata is used to verify the integrity of data written into the exported AIP.
Required byCPP-016Metadata Ingest and ManagementThe checksums and associated algorithms need to be stored in the File’s Fixity metadata.

4. Reference implementations

Publicly available documentation

InstitutionOrganisation typeLanguageHyperlink
TIB – Leibniz Information Centre for Science and Technology and University Library, DENational library
Non-commercial digital preservation service
Research infrastructure
Research performing organisation
English https://wiki.tib.eu/confluence/spaces/lza/pages/93608951/Metadata#Metadata-TMDTechnicalmetadata
CSC – IT Center for Science Ltd., FINon-commercial digital preservation serviceEnglish https://wiki.tib.eu/confluence/spaces/lza/pages/93608951/Metadata#Metadata-TMDTechnicalmetadata
(section 2.4.4.2)
Archivematica, CADigital preservation systemEnglish https://www.archivematica.org/en/docs/archivematica-1.17/user-manual/transfer/transfer/#transfer-tab-microservices