Client information encryption protection method in pork transaction process
By dynamically adjusting the key path and encryption strategy, combined with multiple digest checks and digital signature verification, the static strategy of customer information encryption protection in pork transactions is solved, real-time information protection and risk response capabilities are achieved, and transaction security and data protection effects are improved.
Patent Information
- Application Number
- CN202510821541.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-07-22
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, the customer information encryption protection method during pork transactions has static key distribution and fixed encryption strategies, lacks dynamic adjustment capabilities, and cannot block abnormal nodes in time. The encryption strength of sensitive fields is not adaptively adjusted with the change of risk. Identity verification is limited to a single data fragment, which leads to the difficulty of timely discovery and containment of information leakage and forgery.
Through dynamic key path sorting and encoding, the circulation link is adjusted in real time, combined with transaction behavior data-driven encryption strategy switching, sensitive field keys are dynamically updated with changes in operation characteristics, multiple digest combinations are used to cross-check customer identity, digital signatures are synchronized into the double verification of multi-source digests and transaction content, actively interrupt the abnormal process and automatically mark risk.
It realizes multi-level full-process information protection during pork trading, enhances transaction link security and real-time customer data protection, and significantly reduces the possibility of forgery and leakage of sensitive information.
Smart Images

Figure CN120358080A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information encryption, and particularly to a method for encrypting and protecting customer information during the pork trading process. Background Art
[0002] The technical field of information encryption involves taking encryption measures for digital information during transmission, storage, and processing to prevent unauthorized access, leakage, or tampering of information. This technical field includes core matters such as key generation and management, application of encryption algorithms, identity authentication mechanisms, and data access control, aiming to protect information security and ensure user privacy, and is widely applied in various scenarios such as finance, healthcare, and e-commerce. Among them, the method for encrypting and protecting customer information during the pork trading process refers to encrypting sensitive information such as customer identity, contact information, and transaction data during the pork circulation and trading links, performing encryption and decryption operations on the information through keys, and combining digital signature technology or information desensitization technology during the information transmission and storage links to ensure that sensitive data is encrypted and encapsulated when flowing within the trading system, and only authorized parties can decrypt and obtain customer information through keys.
[0003] The prior art adopts static key distribution and fixed encryption strategies, the node path does not have the ability to dynamically adjust, lacks data discrimination means based on behavioral characteristics, abnormal nodes cannot block key circulation in the first time, the encryption intensity of sensitive fields does not adaptively adjust with risks, identity verification is limited to a single data segment, digital signature verification depends on single-source content comparison, the risk signal response speed is limited, and it is difficult to provide closed-loop protection for complex trading behaviors and diverse risk scenarios, resulting in the risks of information leakage and forgery being difficult to detect and contain in a timely manner. Summary of the Invention
[0004] The purpose of the present invention is to solve the deficiencies existing in the prior art, and to propose a method for encrypting and protecting customer information during the pork trading process.
[0005] To achieve the above purpose, the present invention adopts the following technical scheme: A method for encrypting and protecting customer information during the pork trading process, including the following steps: S1: Based on the pork trading data, analyze the previous key distribution time and the node key segment hash sequence, encrypt and encode them respectively, calculate the encoding segment sorting, judge the node path order, compare the consistency between the selected node number and the registered number on the chain, and obtain the node mapping order parameter; S2: Based on the node mapping order parameter, obtain the key segment number uploaded by the current receiving node, compare the two groups of numbers, if the numbers do not match, then abort the key forwarding, record the abnormal node and the distribution time point, and obtain the distribution consistency determination flag; S3: Based on the distribution consistency determination identifier, combined with the operation frequency of the client terminal, compare the number of abnormal requests, transaction operation time period, and transaction device IP address with the reference standard, filter out abnormal data, perform key replacement, and obtain encryption policy switching information; S4: Based on the encryption policy switching information, analyze the basic information, contact information, and identity authorization code in the customer identity data, perform digest encryption on each piece of data, combine the two groups of digests, compare the generation time and content consistency, and obtain identity digest verification parameters.
[0006] The improvements of the present invention are that the node mapping sequence parameter includes a path selection number, node sorting information, and link mapping characteristics; the distribution consistency determination identifier includes an abnormal record mark, a transfer status category, and node response information; the encryption policy switching information includes a policy adjustment category, a key replacement identifier, and a behavior screening label; the identity digest verification parameter includes a digest comparison result, a segment combination feature, and a time correlation information.
[0007] The improvements of the present invention are that the obtaining steps of the node mapping sequence parameter are specifically as follows: S111: Based on the pork transaction data, call the previous key distribution time and the node key segment hash sequence, perform encryption coding on each group of data according to time, compare the encryption coding order between nodes, and determine the sorting order of each node through number marking to obtain a node coding order index; S112: Based on the node coding order index, compare it with the node path structure data registered in the blockchain, judge the correspondence between the sorted number of each node and the path structure number, analyze the connection order and number change of the node paths, and adjust the front-back association order between nodes to obtain path sorting mapping information; S113: Based on the path sorting mapping information, perform a consistency judgment on it and the registered number on the chain, analyze the response frequency and structural level distribution of nodes in the link, calculate the number offset direction and node level coverage range, and optimize the node combination relationship to obtain a node mapping sequence parameter.
[0008] The improvements of the present invention are that the obtaining steps of the distribution consistency determination identifier are specifically as follows: S211: Based on the node mapping sequence parameter, analyze the path selection number and link mapping characteristics, compare the key segment number uploaded by the current receiving node with the node sorting information, judge the consistency between the uploaded number and the corresponding number in the mapping path, and calculate the difference quantity to obtain a node number matching difference quantity; S212: Based on the node number matching difference quantity, according to the registered number on the chain, identify the uploaded number and receiving time of each node with inconsistent numbers, and sort out the node sequence with number differences to obtain a node abnormal mark information set; S213: Based on the node anomaly marking information set, calculate the numbering mapping offset, screen for anomaly nodes with critical offsets, and record their distribution time points to obtain a distribution consistency determination identifier.
[0009] The improvement of the present invention is that the step of obtaining the encryption policy switching information is specifically as follows: S311: Based on the distribution consistency determination identifier, obtain the operation frequency, transaction operation time period, and device IP address of the client terminal, compare them with the reference standard, identify behaviors with frequent requests, abnormal time operations, or unauthorized IPs, and obtain the classification of the number of abnormal behaviors. S312: According to the classification of the number of abnormal behaviors, analyze the categories and occurrence frequencies of associated sensitive fields, compare the distribution status of each sensitive field type in the records, and adjust the matching relationship between the sensitive fields and the encryption policy to obtain the policy matching strength amplitude. S313: According to the policy matching strength amplitude, combined with the data level to which the field belongs, obtain the field policy change amplitude, adjust the encryption policy of the sensitive field, and perform the key replacement operation to obtain the encryption policy switching information.
[0010] The improvement of the present invention is that the step of obtaining the identity summary verification parameter is specifically as follows: S411: Based on the encryption policy switching information, analyze the identity authorization code and contact information in the customer identity information, compare the time interval between the field generation time and the current time, judge the completeness and content consistency of the two pieces of information, screen out the data that does not meet the requirements, and generate a field screening result. S412: Invoke the field screening result, perform the digest encryption of each piece of data, optimize the label information and time attributes of the digest content, judge the combination method of multiple groups of digest fragments, and adjust their mapping relationship to obtain the digest combination structure data. S413: Based on the digest combination structure data, obtain the digest content hash number and generation time, combine any two groups of digest fragments, obtain the digest combination consistency result, and obtain the identity summary verification parameter.
[0011] The improvement of the present invention also includes: S5: Based on the identity summary verification parameter, combined with the fragment combination and the current transaction content, use it as the input encryption for signature generation, mark the fragment combination, and the server side receives the signature analysis of the original data, performs hash calculation and verifies the signature content to obtain the signature consistency verification result. The signature consistency verification result includes the hash verification result, signature structure information, and server-side consistency status.
[0012] The improvement of the present invention is that the step of obtaining the signature consistency verification result is specifically as follows: S511: Analyze the correspondence between the fragment combination and the current transaction content based on the identity summary verification parameter, determine the order of the generation time of each fragment and the content hash result, optimize the pairing order of the fragments and the transaction fields, and obtain a combined order comparison sequence; S512: Based on the combined order comparison sequence, detect the source location of the corresponding fields of each group of fragment combinations in the original transaction data, analyze the cooperation between the fragment generation order and the actual field location, calculate the difference performance between the content hash result and the fragment hash result, and obtain a structure corresponding difference data set; S513: According to the structure corresponding difference data set, optimize the position mapping of each fragment combination in the transaction content, compare the content consistency and order matching situation, adjust the time correlation and structure distribution between the fragments, and then judge the data consistency performance to obtain a signature consistency verification result.
[0013] Compared with the prior art, the advantages and positive effects of the present invention are as follows: In the present invention, through the dynamic key path, sorting and encoding between nodes are carried out to achieve real-time adjustment of the transfer link, the encryption policy is switched in a timely manner driven by transaction behavior data, the keys of sensitive fields can be dynamically updated according to the changes of operation characteristics, the customer identity is confirmed in segments through multiple summary combinations and cross-verification, the digital signature is synchronously incorporated into the dual verification of multi-source summaries and transaction content, and when abnormal behaviors or abnormal nodes are found, the relevant processes are actively interrupted and risk marking is automatically completed. Information can obtain multi-level and whole-process protection in the links of distribution, storage, transaction, etc. The security of the transaction link, the real-time performance of customer data protection and the system response ability are enhanced, and the possibility of forgery and leakage of sensitive information is significantly reduced. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 is the main process flow chart of the present invention; Figure 2 is the flow chart for obtaining the node mapping order parameter in the present invention; Figure 3 is the flow chart for obtaining the distribution consistency determination identifier in the present invention; Figure 4 is the flow chart for obtaining the encryption policy switching information in the present invention; Figure 5 is the flow chart for obtaining the identity summary verification parameter in the present invention; Figure 6 is the flow chart for obtaining the signature consistency verification result in the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0015] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely used to explain the present invention and are not intended to limit the present invention.
[0016] In the description of the present invention, it should be understood that the orientation or positional relationships indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. are based on the orientation or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as limiting the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more, unless otherwise specifically defined.
[0017] Embodiment: Please refer to Figure 1 , the present invention provides a technical solution: a method for encrypting and protecting customer information during the pork trading process, including the following steps: S1: Based on the pork trading data, analyze the previous key distribution time and the node key segment hash sequence, perform encryption encoding on each group of data respectively, calculate the order of each encoding segment, judge the node path order through the sorting result, and compare the consistency between the selected node number and the registered number on the chain to obtain the node mapping order parameter; S2: Based on the node mapping order parameter, obtain the key segment numbers uploaded by the current receiving node, compare whether the two groups of numbers are the same. If it is found that the numbers do not match, stop the key forwarding, and record the abnormal node information and the distribution time point to obtain the distribution consistency determination flag; S3: Based on the distribution consistency determination flag, according to the customer terminal operation frequency data, compare the abnormal request times, trading operation time periods, and trading device IP addresses with the reference standards respectively, screen out the data items with deviations, adjust the encryption policy for sensitive fields, and perform the key replacement operation to obtain the encryption policy switching information; S4: Based on the encryption policy switching information, analyze the basic information structure in the customer identity data, obtain the contact information and the customer identity authorization code, perform digest encryption on each item of data, combine any two groups of digest segments, and compare the generation time and content consistency to obtain the identity digest verification parameter; S5: Based on the identity digest verification parameter, encrypt it as an input item for signature generation according to the segment combination and the current trading content, mark the used segment combination. When the server receives the signature, analyze the original data, perform hash calculation, and then proofread the matching situation of the signature content to obtain the signature consistency verification result.
[0018] The node mapping order parameters include path selection numbers, node sorting information, and link mapping characteristics. The distribution consistency determination identifiers include exception record marks, transfer status categories, and node response information. The encryption policy switching information includes policy adjustment categories, key replacement identifiers, and behavior screening tags. The identity digest verification parameters include digest comparison results, segment combination characteristics, and time correlation information. The signature consistency verification results include hash verification results, signature structure information, and server-side consistency status.
[0019] In S1, the node key segment refers to the local segment of the key held by each participating node during key distribution in the pork trading blockchain network. Each node only stores the part of the key data assigned to itself to improve distribution security. The encoded segment refers to the data segment generated by processing the above node key segments and distribution time data through encryption algorithms (such as hashing). It is mainly used as the basis for sorting and path selection. The node path order refers to the order in which each node participates in key transfer after analyzing the key distribution parameters and sorting the encoded segments, which is used to determine the transfer path of key distribution. The node number refers to the unique number assigned to each node in the blockchain network, which is used for node identification and task distribution identification. The on-chain registration number refers to the node number information pre-recorded in the blockchain system for verification, which is used to compare the consistency with the node number selected during actual execution.
[0020] In S2, the receiving node refers to the participating node that is currently receiving the key segment during key transfer. The abnormal node refers to the node that is found to have inconsistent uploaded number and on-chain registration number during number matching, that is, the node with abnormalities during key distribution.
[0021] In S3, the client terminal refers to the terminal device used by users who initiate or participate in pork trading, such as computers, mobile phones, tablets, etc. The reference standard refers to the normal range or rules for security behaviors such as operation frequency, request quantity, time period, IP, etc. preset by the system, which is used to determine whether there are abnormalities in behaviors. The deviated data item refers to the data that shows abnormal fluctuations or does not conform to the rules after comparison with the reference standard, such as high-frequency operations, requests during abnormal time periods, or abnormal IP sources. The sensitive field encryption policy refers to the encryption method and intensity of sensitive information dynamically adjusted by the system according to actual security risks, including different encryption algorithms, key lengths, or key replacement strategies.
[0022] In S4, the basic information structure refers to the structured data of the basic identity information in the customer identity data, such as name, ID number, company name, etc.
[0023] In S5, fragment combination refers to combining the aforementioned various types of identity-related data (such as basic information, contact information, identity authorization codes, etc.) after encrypted digest pairwise to form a data group for verification and signature; the signature content refers to the digital signature information generated by combining the fragment combination with the current transaction data, and this content will be used by the server for subsequent hash and consistency verification.
[0024] Please refer to Figure 2 , and the steps for obtaining the node mapping order parameter are specifically as follows: S111: Based on the pork transaction data, call the previous key distribution time and the node key fragment hash sequence, encrypt and encode each group of data according to time, compare the encrypted encoding order between nodes, and determine the sorting order of each node through number marking to obtain the node encoding order index; Select the most recent 30 transaction data, extract the key distribution events according to the time points recorded in each transaction, uniformly set the time accuracy to the second level, and sort them in ascending order of time stamp. For example, the time of the first transaction is "08:01:02, June 1, 2025", and the second is "08:02:45, June 1, 2025", then the sorting numbers are 1 and 2. Subsequently, extract the key fragment digests held by the nodes involved in these 30 transactions respectively. The digest form is a 32-bit hexadecimal string. For example, the digest corresponding to node N101 is "f2ab843c…", and node N102 is "3a2b1c4e…". When processing the digest, perform a sorting operation by comparing each bit of the ASCII code characters. For example, when comparing the strings "3a2b…" and "f2ab…", compare the first character 3 (ASCII value 51) with f (ASCII value 102) and conclude that the former takes precedence. Complete the sorting of this batch of digests in sequence. After sorting, mark the corresponding node numbers for each digest. In the case of the same digest value, refer to the node number value. For example, the one with a smaller number is sorted first. The generated order after sorting is [N102, N101, N104, N103], indicating the order of the nodes according to their encrypted encoding of the digest in the current key distribution event. In practice, if a total of 5 nodes are involved in a certain transaction round, and the obtained encoding priority order through sorting is N108, N105, N106, N102, N109, record this order as the node encoding order index for the next step of structure path comparison.
[0025] S112: Based on the node encoding order index, compare it with the node path structure data registered in the blockchain, judge the corresponding relationship between the sorted numbers of each node and the path structure numbers, analyze the connection order and number change of the node paths, and adjust the front-back association order between nodes to obtain the path sorting mapping information; After using the node coding sequence index, start comparing this sequence item by item with the path structure registered in the blockchain. Assume that the standard connection relationships between nodes are recorded in the blockchain structure, such as path segments [N102→N105], [N105→N108], [N108→N110], etc. There are a total of 52 path structure data. Construct new path segments according to the sorting result, such as [N108, N105, N106, N102, N109], as [N108→N105], [N105→N106], [N106→N102], [N102→N109], and check one by one whether they exist in the path structure registered on the chain. In this example, the path segment [N106→N102] does not exist in the registered structure, so mark this segment as an "unregistered path", and trace the hierarchical structures of nodes N106 and N102. Assume that N106 is at level 3 and N102 is at level 2, and the transfer direction is upward. Read the hierarchical situations of each node from the node level distribution table, where the root node level is 1 and the maximum level is 5. If a path segment connection jumps from level 3 to level 1 and then to level 4, such a jump is recorded as a structurally discontinuous path; count the direction changes in all path segment connection relationships. For example, if 3 out of 10 paths have a direction reversal, the reversal rate is 30%. Use this ratio as a reference value for judging the rationality of the connection structure. When the number of nodes exceeds 4 and the hierarchical span is greater than 3, mark this path segment as a "cross-level connection segment", and output path sorting mapping information including connection direction information, whether it is registered and matched, whether there is a reversal, and the hierarchical span, etc.
[0026] S113: Based on the path sorting mapping information, judge its consistency with the registration number on the chain, analyze the response frequency of nodes in the link and the structural level distribution, calculate the number offset direction and the node level coverage range, optimize the node combination relationship, and obtain the node mapping sequence parameter; Further perform consistency verification on the node numbers, retrieve the blockchain registration form, which registers a total of 100 node numbers from N101 to N200. If numbers such as N212 or N045 appear in the path, since they are not within the valid range, they are immediately marked as illegal nodes and excluded. Among the remaining nodes, read their response times and the last response time within the past 24 hours. For example, the response times of N105 are 12 times, and the last response time is "June 2, 2025, 10:15:03". Classify all nodes according to the following criteria: Nodes with a response times of not less than 10 times and a last response time within 3 hours are high-frequency active nodes; nodes with a response times of less than 3 times and a last response time earlier than 24 hours are low-frequency nodes. After classification, if the proportion of high-frequency nodes in the current path exceeds 60%, it is recorded as an "active path segment"; otherwise, it is recorded as a "low-active path segment". Then, compare the sequence relationship between the sorted numbers and the original numbers. For example, the original order is N101, N102, N103, N104, N105, and after sorting, it is N104, N101, N105, N102, N103. Then N104 moves forward from the 4th position to the 1st position, with an offset of -3. Nodes with an offset value exceeding ±2 are marked as "sequentially offset nodes". Count the total number of offset nodes and the average offset value. Finally, after comprehensive sorting based on multiple dimensions such as offset, activity, and illegal node exclusion, output the node mapping sequence parameters. This parameter set exists in the form of a structured table, recording the optimized sorting results, the status of each connection relationship, the node behavior characteristics, and the comparison results of the numbers.
[0027] Please refer to Figure 3 , and the specific steps for obtaining the distribution consistency determination identifier are as follows: S211: Based on the node mapping sequence parameters, analyze the path selection numbers and link mapping characteristics, compare the key fragment numbers uploaded by the current receiving node with the node sorting information, judge the consistency between the uploaded numbers and the corresponding numbers in the mapping path, calculate the difference quantity, and obtain the node number matching difference quantity; Extract the path selection number, which is used to identify the position order of each node in the current key distribution path. The path number is an integer data type. For example, the node order corresponding to path 1 is N105→N108→N112. Then, parse the link mapping feature, which is a string field used to describe the connection direction and path segment position in each path. For example, "N105↘N108, direct connection; N108↘N112, cross jump". Traverse each receiving node from start to end according to the path order. When a node receives a key fragment, read the key fragment number uploaded by it. This number is generated and submitted by each node during the upload operation. For example, node N108 uploads a number "108-20250602-03", and take the first three digits as 108, corresponding to the sorting position of the receiving node. Subsequently, retrieve the node sorting information, that is, the mapping order obtained in the previous step. If the mapping order in a certain transaction link is N105, N106, N108, N110, N112, check whether the node corresponding to the uploaded number is consistent with the number at this position in the mapping path. When performing this judgment, use a one-by-one comparison method to compare the equality of the number field values. If the current receiving node is the 3rd in order and the mapping number is N108, and the uploaded number field is 108, it is considered consistent. If a node uploads a number 109 and the node at this position in the sorting is N106, it is determined to be inconsistent. After each judgment, generate a binary judgment result, "1" for consistent and "0" for inconsistent. After the current key distribution cycle ends, count the number comparison results of all receiving nodes. By accumulating the number of times of all "inconsistent" marks, obtain the total number of times of inconsistent uploaded numbers and mapping path numbers in this cycle. For example, the total number of receiving nodes is 10, and among them, 3 nodes have inconsistent uploaded numbers and mapping numbers, then record the node number matching difference amount as 3.
[0028] S212: Based on the node number matching difference amount, according to the on-chain registration number, identify the uploaded number and receiving time of each node with inconsistent numbers each time, sort out the node sequence with number differences, and obtain the node anomaly marking information set; Based on the difference in node number matching, start to check each node record with inconsistent numbers item by item. Retrieve the complete number field information and upload time record submitted by the node during the upload process. For example, if the node upload number is "110-20250602-09", extract the field value "110" as the number and "20250602-09" as the time. Create a separate entry for each abnormal record, display its actual upload number side by side with the number in the expected sorting, and record the upload time point accurate to the minute level. For example, the record format is: expected number "N106", actual upload "110", time "June 2, 2025 09:45". Subsequently, form a list of information for all nodes with inconsistent numbers. Each item in the list includes the node number, abnormal type, upload time, and sequential position difference. The sequential difference is compared through the sorting position information. For example, if N106 should be ranked second and N110 appears in the second place, the sequential difference is +4, indicating that the number uploaded in advance comes from the node that was originally ranked later. Generate a marking information for each abnormal node, and the field structure is "node number - abnormal type - sequential offset value - upload time", for example, "N110 - number mismatch - +4 - 09:45". By traversing all abnormal items, generate a complete set of node abnormal marking information, which will be used as the trigger basis for subsequent key transfer interruption control and behavior screening mechanisms.
[0029] S213: Based on the set of node abnormal marking information, use the formula: ; Calculate the number mapping offset , screen for abnormal nodes with critical offsets, and record their distribution time points to obtain the distribution consistency determination identifier. Among them, represents the node number uploaded by the th abnormal node, represents the node number that the th node should be registered, represents the response time of the th node, represents the sorting number of the th node in the path, represents the processing cycle of the upload number of the th node, represents the expected number position of the th node in the link mapping, represents the path position number of the th node when it is actually uploaded, represents the number of nodes identified as abnormal nodes.
[0030] The number mapping offset refers to a numerical index used to measure the deviation between the number uploaded by an abnormal node and its registered number during key distribution in the pork trading process. Considering factors such as the node's response behavior and link position, it quantifies the deviation of number consistency. The offset reflects the severity of number anomalies and provides a quantitative reference for subsequent screening of abnormal nodes and aborting key forwarding operations.
[0031] represents the response time (unit: ms), is the sorting number of the node in the path structure (dimensionless). Since and have time units and need to unify the dimension, so is normalized to The normalization rule is: Similarly, for the processing period represents the processing period of the node for the number upload task (unit: ms), which is normalized to where represents the preset number position of the node in the link, represents the actually uploaded path position number. Both are dimensionless serial numbers used to describe the node position offset. is the total number of identified abnormal nodes. Suppose 5 nodes participate in key transfer, among which: The number uploaded by the node is ; The corresponding registered number is ; The response time ; The path sorting number ; The processing period ; The expected number position ; The uploaded position number .
[0032] The normalization process is as follows: ; ; For nodes with inconsistent numbers (Group 2 and Group 4), calculate the offset: Calculation for Group 2: ; For the numerator part: ; For the denominator part: ; Offset term: ; Group 4 calculation: ; Numerator part: ; Denominator part: ; Offset term: ; The upload numbers of the remaining nodes are the same as the registration numbers, and the offset is 0.
[0033] The number mapping offset is: ; The result shows that there are two significant deviation points in the number consistency of the current key distribution process. The number mapping offset is , from which a distribution consistency determination identifier can be generated to mark the above offset key nodes and their corresponding distribution time points. The formula corrects the square of the number difference through the normalized response behavior and the structure position parameter, and can accurately screen the nodes with problems such as structural offset, abnormal response or position mismatch in the number upload process, and has a fine-grained description ability for the node consistency verification in blockchain key distribution.
[0034] Please refer to Figure 4 , and the specific steps for obtaining the encryption policy switching information are as follows: S311: Based on the distribution consistency determination identifier, obtain the operation frequency, transaction operation time period and device IP address of the client terminal, compare them with the reference standard, identify the behaviors of frequent requests, abnormal time operations or unauthorized IPs, and obtain the grading of the number of abnormal behaviors; First, extract the corresponding transaction record number and the associated customer terminal device identifier. Retrieve all interaction records of this terminal in the past 24 hours by querying the transaction log table. The operation frequency is composed of the number of requests within a unit of time. For example, for a device with a customer terminal number of C13245, a total of 13 data submission requests were initiated between 08:00 and 08:05 on June 2, 2025. Then its 5-minute request frequency is 13 times. Compare this frequency with the reference standard. The set security threshold in the reference standard is no more than 8 requests within 5 minutes. If the number of requests is greater than 8, it is determined as a frequent request. Continue to analyze the daily operation time period of this terminal, extract all transaction time points in its records, and classify and count according to the time period. For example, the number of operations between 0:00 and 4:00 in the early morning is 4 times. The preset safe operation time period at night is from 22:00 to 6:00. If the number of operations during this time period exceeds 3 times, it is recognized as an operation in an abnormal time period. Extract the IP address information carried in each request of this device from the log again, and compare it with the authorized IP address list. The registered IP address segment allowed to log in to this terminal is "192.168.3.0 / 24". If it is found that the source IP of a certain request is "116.XX.XXX.213", which is not within the authorized segment, it is recorded as an unauthorized IP behavior. After completing the identification of the above three types of behaviors, count and statistically analyze according to the total number of actual abnormal behaviors. If there is only 1 abnormal behavior, it is classified as a first-level abnormality. If there are 2 abnormal behaviors, it is classified as a second-level abnormality. If all three are abnormal, it is classified as a third-level abnormality. For example, if the C13245 terminal has a high frequency, a normal IP, and an abnormal time, it is a second-level abnormality. Output the corresponding relationship between the number of abnormalities and the level to obtain the classification of the number of abnormal behaviors.
[0035] S312: According to the classification of the number of abnormal behaviors, analyze the categories and occurrence frequencies of associated sensitive fields, compare the distribution status of each sensitive field type in the records, and adjust the matching relationship between the sensitive fields and the encryption policy to obtain the intensity range of the policy matching; Call the terminal data access logs corresponding to the exception levels, identify and classify the sensitive fields involved in each data record. The classification results of sensitive fields are divided into three categories: identity (such as ID card number, contact information), transaction (such as transaction amount, account number), and authentication (such as authorization code, certificate number). Set the field identification rules and make classification judgments based on the keyword of the field name, field length, and structural characteristics. For example, if the field name contains "id", "mobile", or "cert", they are classified into the identity category, contact information category, and authentication category respectively. Count the occurrence frequencies of the three types of fields in the exception records of this terminal. If 7 out of 10 exception records involve the transaction amount field, 3 involve the contact information field, and 2 involve the ID card field, record the occurrence frequency of the transaction type field as 70%, the identity type field as 20%, and the authentication type field as 20%. Subsequently, retrieve and compare the current encryption policies used for these three types of fields. The encryption policy levels are divided into 3 levels: basic encryption, enhanced encryption, and forced desensitization. For example, if the current policy for the transaction type field is enhanced encryption and the corresponding field frequency is higher than 50%, it should be switched to forced desensitization. The current policies for the identity and authentication type fields remain unchanged. According to the policy adaptation relationship, re-match the field types and policy levels, and set the classification rules for the matching strength range in accordance with the given matching weight range in the standard policy matching table. If the policy level is one level lower than the field frequency level, record it as a 1-level decrease in strength. If the policy levels are equal, the strength range is 0. If the policy level is higher than the field frequency level, it is an increase in level. Finally, generate the strength deviation value between the current policy and frequency for each field type and form a structured matching result list, outputting the policy matching strength range.
[0036] S313: According to the policy matching strength range, combined with the data level to which the field belongs, use the formula: ; Obtain the policy change range of the field , and adjust the encryption policy of the sensitive field, perform the key replacement operation, and obtain the encryption policy switching information, where represents the policy matching strength range, indicating the adaptation degree between the sensitive field and the selected encryption policy, represents the th item in the set of field sensitive factors, reflecting the influence of different sensitive fields on the selection of encryption policies, represents the data level code to which the field belongs, indicating the level attribution of the sensitive field in the data classification system, represents the total number of items in the set of sensitive factors, represents the time interval adjustment parameter, which is used to adjust the influence of the policy replacement cycle on the overall adjustment range, represents the current timestamp, representing the time point when this step is currently executed, It is the time of the last policy change, representing the time point of the last encryption policy adjustment. It is the abnormal fluctuation situation, indicating the change intensity of the detected abnormal behavior.
[0037] The field policy change amplitude refers to the intensity and tendency of the encryption policy adjustment required for the sensitive field in the current security environment, and is the quantitative basis for evaluating and triggering the encryption policy switch.
[0038] According to the policy matching intensity amplitude and combined with the data level to which the field belongs, calculate the field policy change amplitude. First, normalize the original score 82 of the policy matching intensity amplitude to the interval , which is expressed as: ; Secondly, set the data level code to which the field belongs, indicating that the field is at the middle level in the data classification standard (the level is divided into 1 for ordinary, 3 for important, and 5 for core). The sensitive factor set contains three key factors, namely field dependency, sensitivity, and exposure, and their original values are: , , ; Assume the normalization interval is , then the normalization results of the three are: ; ; ; Calculate the weighted product sum of the sensitive factor and the field level: ; Set the time interval adjustment parameter to , the current timestamp is , and the last replacement timestamp is , calculate the time interval as: ; The original value of the abnormal behavior fluctuation situation is 6, set the average value to , and the standard deviation to , after standardization: ; The denominator term in the calculation formula: ; Calculate the field policy change amplitude : ; The result shows that the change range of the field policy is , and the value is close to the upper limit of the matching strength normalization, indicating that the matching deviation between the current policy configuration and the field characteristics is extremely small. The existing policy configuration can be maintained, but the policy maintenance process is still entered to monitor the subsequent change trend. The formula constructs a weighted difference structure by normalizing and unifying the dimensions of multi-dimensional sensitive factors, data levels, time differences, behavior fluctuations, etc., effectively realizing the quantifiable and controllable calculation and judgment of the dynamic adjustment behavior of the encryption policy.
[0039] Please refer to Figure 5 , and the specific steps for obtaining the identity summary verification parameters are as follows: S411: Based on the encryption policy switching information, analyze the identity authorization code and contact information in the customer identity information, compare the interval between the field generation time and the current time, judge the completeness and content consistency of the two pieces of information, screen out the data that does not meet the requirements, and generate a field screening result; Read the identity authorization code and contact information fields in the customer information in sequence, extract the generation time for each field and perform a time difference operation with the current time. If the time difference exceeds 48 hours, it is marked as "overdue". For example, if the generation time of a customer's contact information is 08:30 on June 1, 2025, and the current time is 10:00 on June 3, and the interval exceeds 48 hours, it is marked as abnormal. Then judge the field integrity. The identity authorization code should be a 12-digit alphanumeric mixed string. If it is less than 12 digits or all digits, it is marked as incomplete. The contact information should be 11 digits and the first three digits are legal. If the field is "1361234567", it is identified as abnormal due to insufficient digits. Then judge the content consistency of the two fields. For example, if the authorization code is "AB981234XY12" and the contact information is "13812345678", there is a "1234" overlap at the end. If the proportion of the overlapping characters exceeds 30% of the field length, it is recorded as "partially consistent". Summarize the integrity, generation time status and content consistency of the field. If any two items are abnormal, screen out the field as "unqualified data". For example, if the authorization code length is only 8 digits and the generation time is 72 hours ago, it is unqualified. Finally, record the analysis situation of each customer field as a field screening result. The field result item includes the field name, generation time, whether it is overdue, whether it is complete, the format status and the consistency score.
[0040] S412: Call the field screening result, perform the digest encryption of each piece of data, optimize the label information and time attributes of the digest content, judge the combination method of multiple groups of digest fragments, and adjust their mapping relationship to obtain the digest combination structure data; Perform summary encryption operations on each piece of data passed through the screening. The processing objects are the customer's authorization code and contact information fields. Generate a fixed-length summary string and append tag content. The tag consists of the field category and the generation time. For example, if the contact information field is generated on June 2nd, the tag is set to "Contact Information-0602". After synthesizing the summary and the tag, it is like "9cfb8a...#Contact Information-0602". After sorting out the encrypted field summaries of all users, combine the fields from the same source pairwise by user dimension. For example, the authorization code summary and the contact information summary are spliced into a group. If a customer has three field information, three groups of combinations are performed and recorded separately. After combination, compare the time differences generated by each group. If the time difference is less than 6 hours, mark it as "Time Consistent", and if it is greater than 48 hours, mark it as "Time Conflict". It is set that the field types in the combination cannot be repeated. If both fields in the combination pair are contact information fields, adjust the combination order and preferentially combine different types of fields. For example, the pairing of contact information and authorization code is a legal combination. After the combination is generated, further analyze whether the content between the tags is repeated. If the date fields in the tags are the same, mark it as "Tag Coincidence". Finally, output the combined summary structure, including the original field type, tag time difference, tag matching status, and combination order of each group of summaries. The structure data format is uniformly in the form of record items, with each combined record as one item.
[0041] S413: Based on the combined structure data of the summaries, obtain the hash number and generation time of the summary content, combine any two groups of summary fragments, and use the formula: ; Obtain the summary combination consistency result , and obtain the identity summary verification parameter. Among them, is the hash number of the first group of summary fragments, is the hash number of the second group of summary fragments, and both reflect the encryption characteristics of their respective summary contents. is the generation time of the first group of summary fragments, is the generation time of the second group of summary fragments, and the two are used to measure the generation time sequence relationship between the summary fragments. is the structural difference number of the two groups of summary fields, which is used to reflect the associative changes in aspects such as the field source and structural level of the combined fragments.
[0042] The summary combination consistency result refers to the quantitative comparison result obtained by comparing the content, time, and structural differences of any two groups of summary fragments (such as the encrypted summaries of identity authorization codes and contact information), and is a comparative index used to measure the similarity degree between the two groups of summary fragments in terms of content, time, and structure.
[0043] The content hash number of the abstract is generated by a standard encryption algorithm, which is a variable-length numerical result. The generation time is represented by a UNIX timestamp. The structural source coding difference is determined by the structural level position of the field in the original data. For example, the authorization code field is located in the user registration information, and the contact information is located in the device binding information. The structural coding difference between the two is quantified as a structural coding difference of 12 units. After obtaining the above three pieces of participating data, it is necessary to unify the dimension of the data to avoid deviation and perform dimension normalization processing. Among them, the normalization range of the hash number is set as the relative ratio within the range of 0 to 20,000, the timestamp is scaled to between 0 and 1 based on the maximum difference within the current interval, and the structural difference uses the set maximum structural coding difference of 20 as the normalization benchmark. After all numerical values are normalized, they are uniformly calculated as dimensionless numbers. Among them, and represent the normalized hash numbers of the first and second groups of abstract fragments respectively, and are the normalized generation times of the two groups of fragments, is the normalized structural difference number. When participating in the calculation, first map the original hash numbers 18472 and 17845 to the range of 0 to 1. The processing method is: ; ; The generated timestamps 1682351100 and 1682350500 are within the current analysis window range of 600 seconds, and the maximum time difference is set to 1200 seconds. The normalized results are: ; ; The structural difference value is 12, and the set maximum difference is 20. After normalization: ; Substitute into the formula for step-by-step calculation: ; This result indicates that under the combined action of the normalized abstract hash number, generation time, and structural difference, this combined fragment shows extremely high consistency in content and structure. It can be marked according to the set consistency judgment reference interval (such as: marked as consistent) to obtain the identity abstract verification parameter. The formula improves the sensitivity through squaring processing and introduces the structural difference to enhance the binding force of the field source structure, realizing a more robust evaluation of the stability of the field abstract combination.
[0044] Please refer to Figure 6 for the specific steps to obtain the signature consistency verification result: S511: Analyze the correspondence between the fragment combination and the current transaction content based on the identity summary verification parameter, judge the order of the generation time of each fragment and the content hash result, optimize the pairing order of the fragments and the transaction fields, and obtain the combined order comparison sequence; First, retrieve the summary content and generation time information corresponding to each group of fragment combinations, and extract all the field contents in the current transaction record. The transaction fields include information such as transaction number, user identity identifier, product category, amount, and operation time. Sort the summary contents of each group of fragments in order, arranging the summary combinations in ascending order of generation time. For example, if the generation times of the two fragments of a certain combination are 09:30 and 10:05 on June 2, 2025 respectively, the sorting order is fragment A → fragment B. Then, read the original field contents based on which each group of fragments is generated, calculate its hash value and compare it character by character with the summary value to judge whether the summary content is indeed generated from the field content. If the first 8 bits of the hash string are exactly the same, it is marked as "matched"; if there are more than 3 bits of difference, it is marked as "not matched". Based on this, judge the correctness of the fragment content. Subsequently, compare the semantic correspondence between the fragment summary content and the current transaction field type. For example, the fragment summary is a contact information field, and in the transaction where it is located, this field is in the 4th position, while the order of the summary in the combination is the 2nd. Record the pairing offset as +2. After summarizing all the offset results, if the offset value between the combined order and the transaction field arrangement order is less than or equal to 1, it is recorded as "order consistent"; otherwise, it is marked as "order misaligned". Finally, make a one-to-one comparison of all combined fragments and transaction fields, summarize and generate three indicators: order offset amount, summary matching status, and generation time sorting information, and form a combined order comparison sequence.
[0045] S512: Based on the combined order comparison sequence, detect the source location of the corresponding fields of each group of fragment combinations in the original transaction data, analyze the cooperation between the fragment generation order and the actual field positions, calculate the difference performance between the content hash result and the fragment hash result, and obtain the structural correspondence difference data set; Retrieve the original transaction data item by item, locate the field positions corresponding to each group of abstract segments. The retrieval method is to cross-confirm through field name comparison and position indexing. For example, if the abstract segment tag is "Contact Information - 0602", locate that the "Contact Information" field is in the 5th position. Then, retrieve the generation time in the segment combination and judge the chronological relationship with the field submission time in the transaction record. For example, if the segment generation time is 09:50 on June 2, 2025, and the field submission time is 09:52, then it is considered that the abstract is earlier than the field generation and is marked as "Generated in Advance". If the time difference between the two exceeds 5 minutes, it is recorded as "Time Difference Deviation". The time consistency is judged by whether it falls within the ±3-minute interval. Further, calculate the character matching degree between the hash result of the abstract content and the hash value of the actual value of this field. Compare the first 16 characters in the 64-bit abstract in a character-by-character comparison manner. If the number of matching characters is 14 or more, it is judged as "High Consistency"; if the number of matching characters is less than 10, it is "Low Consistency". Set the consistency interval based on the number of matching bits. 14 bits and above are considered completely consistent, 10 - 13 bits are moderately consistent, and less than 10 bits are inconsistent. Finally, summarize the three indicators of the position mapping relationship, generation time difference, and hash matching degree between each segment combination and the original field, and mark the position adaptation level of the combination in the transaction content to generate a structure corresponding difference data set.
[0046] S513: According to the structure corresponding difference data set, optimize the position mapping of each segment combination in the transaction content, compare the content consistency and order matching situation, adjust the time correlation and structure distribution between segments, and then judge the data consistency performance to obtain the signature consistency verification result; Optimize and adjust the corresponding field positions of the segment combinations in the transaction content. First, sort them in turn according to the time generation difference, hash matching degree, and field arrangement position of each group of combinations. Prioritize and select the combination with the closest generation time, the most hash matching bits, and the smallest position offset for fixed pairing. Then, try to rearrange the remaining segments with the unmatched fields. Update the pairing list and recalculate the offset after each rearrangement. If the total offset value in the new combination order decreases by more than 30%, accept this rearrangement. Set the offset threshold to 20% of the total number of transaction fields. For example, if there are 10 fields in total, the total allowable offset is not more than 2. If it exceeds, it is judged as an incorrect order. After optimization, evaluate the time interval between each group of segments. If the generation time interval of consecutive combined segments exceeds 1 hour, it is regarded as weak time correlation. If the interval is within 15 minutes, it is regarded as strong correlation. Summarize all the combination time differences, structure pairing serial numbers, and hash matching statuses to judge whether they meet the consistency requirements. If the consistency score value is not lower than the set standard value, for example, the matching field ratio reaches 80%, the hash consistency reaches 70%, and the average time interval is less than 20 minutes, it is recorded as consistent; otherwise, it is inconsistent. Finally, generate the signature consistency verification result.
[0047] The above are only the preferred embodiments of the present invention, and do not limit the present invention in other forms. Any person skilled in the relevant art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change, and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. A method for encrypting and protecting customer information during the pork trading process, characterized in that, It includes the following steps: S1: Based on the pork transaction data, analyze the previous key distribution time and the node key fragment hash sequence, encrypt and encode them respectively, calculate the encoding fragment sorting, judge the node path order, compare the consistency between the selected node number and the on-chain registered number, and obtain the node mapping order parameter; S2: Based on the node mapping order parameter, obtain the key fragment number uploaded by the current receiving node, compare the two groups of numbers. If the numbers do not match, abort the key forwarding, record the abnormal node and the distribution time point, and obtain the distribution consistency determination flag; S3: Based on the distribution consistency determination flag, combined with the operation frequency of the customer terminal, compare with the reference standard for the abnormal request times, transaction operation time period, and transaction device IP address, screen the abnormal data, and perform key replacement to obtain the encryption policy switching information; S4: Based on the encryption policy switching information, analyze the basic information, contact information, and identity authorization code in the customer identity data, perform digest encryption on each piece of data, combine the two groups of digests, compare the generation time and content consistency, and obtain the identity digest verification parameter.
2. The method for encrypting and protecting customer information during the pork trading process according to claim 1, wherein The node mapping order parameter includes the path selection number, node sorting information, and link mapping characteristics. The distribution consistency determination flag includes the abnormal record mark, transfer status category, and node response information. The encryption policy switching information includes the policy adjustment category, key replacement flag, and behavior screening label. The identity digest verification parameter includes the digest comparison result, fragment combination characteristics, and time correlation information.
3. The method for encrypting and protecting customer information during the pork trading process according to claim 1, wherein The specific steps for obtaining the node mapping order parameter are as follows: S111: Based on the pork transaction data, call the previous key distribution time and the node key fragment hash sequence, encrypt and encode each group of data according to the time, compare the encryption and encoding order between nodes, and determine the sorting order of each node through number marking to obtain the node encoding order index; S112: Based on the node encoding order index, compare it with the node path structure data registered on the blockchain, judge the corresponding relationship between the sorted number of each node and the path structure number, analyze the node path connection order and number change, and adjust the front-back association order between nodes to obtain the path sorting mapping information; S113: Based on the path sorting mapping information, judge its consistency with the on-chain registered number, analyze the response frequency and structure level distribution of nodes in the link, calculate the number offset direction and node level coverage range, and optimize the node combination relationship to obtain the node mapping order parameter.
4. The method for encrypting and protecting customer information during the pork trading process according to claim 1, wherein, The specific steps for obtaining the distribution consistency determination flag are as follows: S211: Based on the node mapping order parameter, analyze the path selection number and link mapping characteristics, compare the key fragment number uploaded by the current receiving node with the node sorting information, judge the consistency between the uploaded number and the corresponding number in the mapping path, calculate the difference quantity, and obtain the node number matching difference quantity; S212: Based on the node number matching difference quantity, according to the on-chain registered number, identify the uploaded number and receiving time of each node with inconsistent numbers, and sort out the node sequence with number differences to obtain the node abnormal mark information set; S213: Based on the node anomaly marking information set, calculate the numbering mapping offset, screen out the anomaly nodes with critical offsets, and record their distribution time points to obtain the distribution consistency determination identifier.
5. The method for encrypting and protecting customer information during the pork trading process according to claim 1, characterized in that, The specific steps for obtaining the encryption policy switching information are as follows: S311: Based on the distribution consistency determination identifier, obtain the operation frequency, transaction operation time period, and device IP address of the client terminal, compare them with the reference standards, identify behaviors with frequent requests, abnormal time operations, or unauthorized IPs, and obtain the classification of the number of abnormal behaviors. S312: According to the classification of the number of abnormal behaviors, analyze the categories and occurrence frequencies of the associated sensitive fields, compare the distribution status of each sensitive field type in the records, and adjust the matching relationship between the sensitive fields and the encryption policies to obtain the policy matching strength amplitude. S313: According to the policy matching strength amplitude, combined with the data level to which the fields belong, obtain the field policy change amplitude, adjust the encryption policies of the sensitive fields, and perform the key replacement operation to obtain the encryption policy switching information.
6. The method for encrypting and protecting customer information during the pork trading process according to claim 1, wherein The specific steps for obtaining the identity summary verification parameters are as follows: S411: Based on the encryption policy switching information, analyze the identity authorization code and contact information in the customer identity information, compare the time interval between the field generation time and the current time, judge the completeness and content consistency of the two pieces of information, screen out the data that does not meet the requirements, and generate the field screening result. S412: Invoke the field screening result, perform the digest encryption of each piece of data, optimize the tag information and time attributes of the digest content, judge the combination method of multiple groups of digest fragments, and adjust their mapping relationship to obtain the digest combination structure data. S413: Based on the digest combination structure data, obtain the digest content hash number and generation time, combine any two groups of digest fragments, obtain the digest combination consistency result, and obtain the identity summary verification parameters.
7. The method for encrypting and protecting customer information during the pork trading process according to claim 1, wherein The steps further include: S5: Based on the identity summary verification parameters, combined with the fragment combination and the current transaction content, use it as the input encryption for signature generation, mark the fragment combination, and the server side receives the signature analysis of the original data, performs hash calculation and verifies the signature content to obtain the signature consistency verification result. The signature consistency verification result includes the hash verification result, signature structure information, and server-side consistency status.
8. The method for encrypting and protecting customer information during the pork trading process according to claim 7, wherein, The specific steps for obtaining the signature consistency verification result are as follows: S511: Based on the identity summary verification parameters, analyze the correspondence between the fragment combination and the current transaction content, judge the order of the generation time of each fragment and the content hash result, optimize the pairing order of the fragments and the transaction fields, and obtain the combination order comparison sequence. S512: Based on the combination order comparison sequence, detect the source location of the corresponding fields of each group of fragment combinations in the original transaction data, analyze the cooperation between the fragment generation order and the actual field location, and calculate the difference performance between the content hash result and the fragment hash result to obtain the structure corresponding difference data set. S513: According to the structure-corresponding difference data set, optimize the position mapping of each segment combination in the transaction content, compare the content consistency and sequence matching situation, adjust the temporal correlation and structural distribution among segments, and then judge the data consistency performance to obtain the signature consistency verification result.
Citation Information
Patent Citations
File verification system and method
CN115699003A
Key sorting method and system in block chain
CN116015659A
Dynamic encryption protection method for vehicle transaction customer information
CN117574413A
Salary secrecy method and system based on block chain
CN117910012A
Insurance identity information transmission protection method and system
CN118014742A
Cited By
Logistics data transmission verification method and system based on hierarchical priority
CN120750492A
A Method and System for Verifying Logistics Data Transmission Based on Hierarchical Priority
CN120750492B
Password evaluation method and system for data encryption and decryption
CN120811763A
Verifiable random encryption generation method and system for privacy data protection
CN121485920A