Integrity Checking (CPP-003)

CPP-IdentifierCPP-003
CPP-LabelIntegrity Checking
AuthorJohan Kylander
ContributorsBertrand Caron
EvaluatorsMaria Benauer, Felix Burger, Laura Molloy
Change historyComments
Version 1.0.0 - 2025-08-29Milestone version
Version 1.1.0 - 2025-10-23Migration to XML

1. Description of the CPP

The TDA supports periodic integrity checking, reporting any damaged or missing Files.

Inputs and outputs

Input(s)
Data
Information Package
Metadata
Fixity metadata
Storage management information
Documentation/guidance
Storage management policy - Integrity checking
Storage management policy - Checksum algorithms
Output(s)
Metadata
Fixity metadata
Provenance metadata

Definition and scope

Integrity checking is a periodically performed process where a checksum is calculated for a target Information Package and compared to the existing stored checksum (as calculated in CPP-001 Checksum Generation and Recording). The goal of integrity checking is to confirm that a target Information Package has remained unaltered across its life cycle. A TDA must perform and document periodic checks, and the frequency of the checks should be defined in its policy as part of the Risk Mitigation (CPP-012) approach.

Integrity checking is closely related to the process of Checksum Validation (CPP-002). Whereas Checksum Validation is tied to Ingest (CPP-029), Enabling Access (CPP-025), or Replication (CPP-011) (i.e. processes where Files are transferred or new copies are created), Integrity Checking is related to continuous risk management. Integrity checking aims to mitigate bit rot and provides evidence for trustworthy preservation by maintaining a continuous audit trail verifying that a File has remained unchanged and authentic over time.

Periodic integrity checks are performed separately on all accessible copies of a target Information Package (for example, off-line copies in a dark archive are usually excluded from periodic integrity checks). Copies on different storage media might be subjected to different intervals of checks. The results of the integrity checks, including Fixity Metadata, should be documented as preservation actions.

If integrity checks discover problems in the integrity of the target Information Packages, this information must be clearly documented in a digital archive's system, so that the broken Information Packages can be restored from valid copies (see CPP-004 Data Corruption Management).

Process description

Trigger event(s)

Trigger EventCPP-identifier
Frequency of integrity checks defined in a digital archive's policyCPP-012 (Risk Mitigation)
Suspicion of an error triggering an integrity check on an ad hoc basis

Step-by-step description

NoSupplierInputStepsOutputCustomer
 sequence
1CPP-012 (Risk Mitigation)Storage management policy - Integrity checkingGather a batch of targets to check and their corresponding Fixity metadata (e.g. Information Packages whose last-checked timestamp is older than the specified checking frequency) AIPs
Fixity metadata
2 sequence - Process for each AIP in the selected batch
2.1CPP-001 (Checksum Generation and Recording) Fixity metadata Gather the AIP's fixity metadata Fixity metadata
2.2Fixity metadata (algorithms)Calculate the checksum of the AIP from the specified File path Fixity metadata
2.3 Fixity metadata Compare the calculated checksum with the stored checksumChecksums match: proceed to next step
Alert that any of the checksums does not match: mark broken AIP for repair and proceed to next stepCPP-004 (Data Corruption Management)
2.4Store the new integrity checking event to the AIPProvenance metadata
2.5Update the timestamp of the integrity checkFixity metadata (timestamp)
3Document the event and its timestampProvenance metadata

Rationale(s) and worst case(s)

RationaleImpact of inaction or failure of the process
Periodic integrity checks on all copiesData can get corrupted and degenerate (i.e. the chain of custody is not safeguarded, and the authenticity of IPs may be destroyed)

2. Dependencies and relationships with other CPPs

Dependencies

CPP-IDCPP-TitleRelationship description
CPP-001Checksum Generation and RecordingCPP-001 is responsible for creating checksums that are used in integrity checking.
CPP-012Risk MitigationThe frequency and target of periodic integrity checks (CPP-003) is defined by an institutional storage management policy as part of risk mitigation (CPP-012).

Other relations

RelationCPP-IDCPP-TitleRelationship description
Required byCPP-013Object Management ReportingPeriodic integrity checking provides reports on the integrity of data and reports corrupted AIPs.
Required byCPP-016Metadata Ingest and ManagementThe timestamp of the AIPs' checksums needs to be updated to keep track of the last successful check.
Affinity withCPP-007Virus ScanningBoth processes aim to ensure the "health" of files. However, Integrity Checking focuses on detecting technical corruption of Files (e.g. bit rot), whereas virus scanning looks to mitigate human-made risks ( e.g. malicious code).
Not to be confused withCPP-002Checksum ValidationBoth CPPs can get input from CPP-001, and both calculate a checksum from an Information Package and compare it to a given checksum. The difference is that CPP-002 is done during the Ingest or Access phases (relating to transfer of content, changes in space), while CPP-003 is done periodically during the preservation of the contents in the archival storage (relating to changes over time). Thus, CPP-002 and CPP-003 are not only triggered by different processes, but also trigger different responses.

4. Reference implementations

Publicly available documentation

InstitutionOrganisation typeLanguageHyperlink
TIB - Leibniz Information Centre for Science and Technology and University Library, DENational library
Non-commercial digital preservation service
Research infrastructure
Research performing organisation
English https://wiki.tib.eu/confluence/spaces/lza/pages/93608391/Preservation+of+data+integrity+as+part+of+the+process+routines
TIB - Leibniz Information Centre for Science and Technology and University Library, DENational library
Non-commercial digital preservation service
Research infrastructure
Research performing organisation
English https://wiki.tib.eu/confluence/spaces/lza/pages/93608373/Archival+Storage#ArchivalStorage-Integrityassurance
CSC - IT Center for Science Ltd., FINon-commercial digital preservation serviceEnglishhttps://digitalpreservation.fi/en/services/quality_reports/2024
Archivematica, CADigital preservation systemEnglish https://www.archivematica.org/en/docs/storage-service-0.23/fixity/#fixity-docs
AUSSDA - Austrian Social Science Data Archive, ATDiscipline-specific data repositoryEnglish https://aussda.at/fileadmin/user_upload/p_aussda/Documents/kaczmirek_bischof_2024_preservation_fixity_checks_v1_0-1.pdf