Data security protection method for digital twin system of logistics transfer field
By adopting a comprehensive security verification method of elliptic curve cryptography and proof of work mechanism in logistics transit, the problem of full-link security protection of the logistics transit data is solved, end-to-end encryption, distributed storage and zero-trust access of data are realized, data security and consistency are ensured, and efficient security traceability is provided.
Patent Information
- Application Number
- CN202510499830.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-04-21
AI Technical Summary
The prior art is difficult to achieve the security protection of full-link data in logistics transit, especially in the process of data collection, transmission, storage and access, and cannot meet the needs of data consistency, tamper-proof and secure traceability.
A comprehensive security verification method based on elliptic curve cryptography and proof of work mechanism is adopted, and a full-link data security protection system is built through data encryption, digital signature, key protection and blockchain technology, including data preprocessing, end-to-end encryption, zero-trust access control and distributed storage. A high-quality cryptographic random number generator, SHA-256 hashing processing and dynamic Nonce adjustment mechanism is used to realize real-time security verification and tamper-proof of data.
It realizes end-to-end encryption protection of logistics transit data, ensures data confidentiality and integrity, reduces the risk of encryption vulnerabilities, provides solid digital identity authentication and encrypted communication support, realizes secure exchange and storage of data, and conducts secure traceability through blockchain technology.
Smart Images

Figure CN120378096A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of logistics, and particularly to a method for data security protection of a digital twin system in a logistics transfer yard. Background Art
[0002] In the current logistics industry, digital twin technology has been widely applied in intelligent devices such as logistics transfer yards and sorting machines. The data generated at the logistics site includes, but is not limited to: user waybill number (UTN), which involves customer privacy and waybill tracking information; sorting capacity, which reflects the scheduling and operation performance of the logistics transfer yard; personnel arrangement information, which involves the arrangement and management information of on-site staff; sorting machine resource information, which includes the status and operation data of key equipment; shift sorting performance and sorting duration, which directly affect logistics efficiency and scheduling rationality. However, traditional centralized security protection solutions for specific links often only focus on data transmission encryption or single-point storage, and it is difficult to meet the requirements of data consistency, anti-tampering, and security traceability in the entire link (data collection, transmission, storage, access) and multi-node distributed systems. In recent years, based on mature encryption technologies such as AES-256, SHA-256, ECDSA (based on the secp256k1 elliptic curve), and ECIES used in decentralized public chains, combined with distributed storage, consensus mechanisms, and blockchain design, it is possible to provide end-to-end security protection for sensitive data at the logistics site. Summary of the Invention
[0003] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a method for data security protection of a digital twin system in a logistics transfer yard, which can effectively realize the information exchange and storage between the digital twins of the blockchain logistics transfer yard and encrypt and protect the data.
[0004] The purpose of the present invention is achieved by the following technical solutions: A method for data security protection of a digital twin system in a logistics transfer yard includes the following steps: S1. Construct the heterogeneous sensitive data in the digital twin of the logistics transfer yard into a data set, and perform preprocessing to obtain the original data set ; S2. Perform end-to-end data encryption on the original data set and perform digital signature and key protection; S3. Construct the information exchange and storage between the digital twins of the blockchain logistics transfer yard, and perform zero-trust access and data decryption.
[0005] The beneficial effects of the present invention are as follows: The present invention constructs a comprehensive security verification method based on elliptic curve cryptography and the proof-of-work mechanism. By introducing a high-quality cryptographic random number generator, modular arithmetic, SHA-256 hash processing, and a dynamic Nonce adjustment mechanism during the digital signature and key negotiation processes, real-time security verification and anti-tampering of digital identity authentication, data transmission, and transaction records are achieved. During the signature generation process, the random number generator is used to generate a high-entropy private key and a temporary random number. At the same time, the elliptic curve scalar multiplication is applied to integrate the private key with the fixed generator, and the x-coordinate value is extracted and taken modulo the order of the elliptic curve to generate the signature parameters. During the shared key negotiation phase, the shared elliptic curve point is obtained through the multiplication operation of the temporary private key and the recipient's public key, and then the SHA-256 hash function is applied to it to generate a symmetric key with a fixed length for subsequent communication encryption. In addition, in the proof-of-work mechanism, by continuously adjusting the Nonce value, the block data meets a specific difficulty target after being subjected to the SHA-256 operation, realizing the verification of data integrity and real-time anti-tampering. This method not only greatly improves the security of each link of signature, key sharing, and proof-of-work, but also effectively reduces the risk of encryption vulnerabilities caused by insufficient randomness through a multiple cryptographic operation mechanism, providing a solid and efficient technical support for blockchain security, digital identity authentication, and encrypted communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0006] Figure 1 It is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0007] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings, but the protection scope of the present invention is not limited to the following.
[0008] As Figure 1 shown, a method for data security protection of a digital twin system of a logistics transfer yard includes the following steps: S1. Construct the heterogeneous sensitive data sorted inside the digital twin body of the logistics transfer yard into a data set, and perform preprocessing to obtain the original data set ; Suppose the digital twin system of the logistics transfer yard includes digital twin bodies of multiple logistics transfer yards. Each digital twin body of the logistics transfer yard synchronously accesses the data of the logistics transfer yard and simulates the operation of the logistics transfer yard. From each digital twin body of the logistics transfer yard, obtain the heterogeneous sensitive data sorted inside the logistics transfer yard and construct it into a data set to obtain the logistics sorting sensitive data set : Among them, is the user waybill number, is the production capacity value of the current sorting shift, is the sorting personnel arrangement information, is the sorting data collected in real time by the current sorter, is the number of packages sorted in the current shift, is the sorting market information in the current shift; For the logistics sorting sensitive data set Encapsulate it in JSON format and convert it to binary data using UTF-8 encoding to achieve the preprocessing of the logistics sorting sensitive data set to obtain the original data set .
[0009] S2. Perform end-to-end data encryption on the original data set and perform digital signature and key protection; End-to-end data encryption includes: A1. Symmetric key generation: Use a cryptographically secure random number generator to generate a 256-bit symmetric key and a 128-bit initialization vector : ; A2. AES-256-CBC encryption: Encrypt the original data set as follows: First, calculate the padding length , where, | | represents the byte length of the original data set , and 16 is the fixed 16-byte length; Then pad the data : ; where, || represents the binary concatenation operation, that is, concatenate the data with the padding bits padding to form a complete encryption input; Finally, encrypt the padded to obtain the ciphertext ; refers to performing the AES-256-CBC encryption operation; A3. Data integrity check value calculation: Calculate the hash value of a 256-bit data with a fixed length as the integrity check value, represents performing a hash operation on the ciphertext using SHA-256.
[0010] Digital signature and key protection Digital Signature (ECDSA Signature): The ECDSA algorithm based on the secp256k1 elliptic curve is used to implement the digital signature. Specifically: First, a 256-bit private key is randomly generated , and the corresponding public key is calculated , where is the generator, and the curve parameters and order are defined by secp256k1.
[0011] Signature Process: Perform ECDSA signature on the hash value . Let the random number be selected from , and calculate where the point lies on the elliptic curve, and its coordinates can be expressed as , and take the modulus of with respect to to obtain : If , then reselect , and calculate If , then reselect . The signature result is .
[0012] Symmetric Key Protection (Implemented by ECIES): Assume that the public key is provided by the authorized person who can access the digital twin data. Use ECIES (Elliptic Curve Integrated Encryption Scheme) for encryption: First, generate a temporary elliptic curve key pair , where is the temporary private key, ; then calculate the shared key ; encrypt it with using AES-256-CBC to obtain is the 128-bit initialization vector for encrypting the shared key .
[0013] S3. Construct information exchange and storage between digital twins of blockchain logistics transfer yards, and perform zero-trust access and data decryption.
[0014] Construct information exchange and storage between digital twins of blockchain logistics transfer yards Information Exchange It includes the following fields: the ciphertext of the encrypted data , its corresponding hash value , digital signature , the encrypted symmetric key information , encrypted initialization vector (used to decrypt data with AES-256-CBC ), and the transaction generation timestamp , that is Distributed storage: Considering the capacity of each data component collected by the digital twin in the actual logistics transfer yard, the data is stored in blocks: , for each calculate the hash value , and combine them in pairs calculate the combined hash recursively until a single root hash is generated ; represents the Merkle root. By constructing a Merkle tree, the block hashes are combined in pairs and calculated recursively to finally generate the root hash ; The input is a set of hash values of data blocks , and the process is: combine the hash values in pairs, calculate their hash, and continuously merge upward until only one hash value remains, which is the MR root.
[0015] Block structure and consensus: Block structure and consensus: A block for storing the information of each digital twin of the logistics transfer yard is constructed, and a blockchain is formed among the blocks; Let the block be the block structure running in the private chain of the logistics network under construction. Each digital twin of the logistics transfer yard can be used as a node in the blockchain network. Nodes are deployed at each transfer yard using the Quorum open-source platform to form a permission-controlled consortium chain. Each node is responsible for generating, broadcasting, verifying, and storing blocks . The block is deployed in the private chain / structure. Each digital twin node of the logistics transfer yard, as a participant in the blockchain, is responsible for the generation, consensus, and storage of blocks.
[0016] For each block it contains a block header and a transaction list. The block header includes the hash of the previous block , the Merkle root of the current block , timestamp , and Nonce (Proof of Work value). Among them, Nonce (Number used once) is a non-repeating random number, usually added as a variable parameter to the data during each operation to change the hash result. The information exchange of the digital twins in this block is saved in the transaction list ; Zero-Trust Access and Data Decryption Access Request Model and Risk Assessment: For access requests to the data of the digital twin system of the logistics transfer yard, it is defined as a vector: Among them, is the identity of the requester (user or device ID), is the data resource requested (such as the status of the sorting machine, shift record), is the context information (such as the sorting equipment environment, geographical location information of the transfer yard), is the request time. On this basis, a risk assessment function is defined: And a security threshold is set for determining whether to authorize the current access (access is not allowed if it is lower than the threshold).
[0017] And a security threshold is set for determining whether to authorize the current access, and access is not allowed if it is lower than the threshold; ~ are preset weights; Identity Risk Function The calculation method is as follows: Among them, is the user level, administrator =0, visitor =1; is the account activity, active =0, abnormal access =1; is the abnormal access frequency, , , are preset weights; Abnormal access means that the account has not appeared in the last 20 historical records, otherwise it is active; Resource Access Risk Function The calculation method is as follows: Among them, is the sensitivity level of the resource, public data =0, sensitive information = 1, indicating whether each resource needs to be accessed frequently. If it needs to be accessed frequently = 0, it does not need to be accessed frequently = 1, , are preset weights; whether it needs to be accessed frequently means that if the average number of resource accesses within the historical unit time is greater than the preset value, it needs to be accessed frequently, otherwise it does not need to be accessed frequently, and this parameter is dynamically adjusted regularly; Context access function The calculation method is as follows: Among them, Geographical location risk score, access within the same province = 0, access outside the province = 1, is the credibility of the access device, registered device = 0, unknown device = 1, are preset weights; Time risk function The calculation method is as follows: Among them, is the normal access peak time, is the attenuation coefficient.
[0018] Authorization and decryption process Authorization and decryption process: After the access request passes the risk assessment, the authorized visitor obtains the key protection information stored in the blockchain transaction ; Use its own private key to decrypt the ECIES-encrypted key information ; Indicates decryption; () indicates the use of algorithm for decryption; Using the obtained , and to decrypt the stored data ciphertext using AES-256-CBC to recover the plaintext sorting data : Among them, Indicates the execution of the AES-256-CBC decryption operation; Theoretically, it should be equal to , but due to the possibility of data tampering or transmission errors, it is necessary to verify for integrity at the same time. The verification method is as follows: Recalculate the ciphertext = SHA256( ); Compare with the stored on the chain: If == : It means the data is complete and the decryption is trustworthy; if ≠ : The data may be tampered with or there may be a transmission error. Reject the access and record the audit log.
[0019] In summary, the present invention achieves: full-link data encryption protection: end-to-end encryption is adopted for sensitive data (such as UTN, sorting capacity, personnel arrangement, shift performance, sorting duration, etc.) generated by logistics transfer yards and sorting machines during the entire process of collection, transmission, storage, and access to ensure data confidentiality and integrity.
[0020] Data consistency and anti-tampering in distributed storage: In a multi-node distributed storage system, the encrypted data is stored in blocks. How to use the distributed consensus and Merkle tree mechanism to ensure data consistency and anti-tampering, and achieve secure traceability through blockchain logging.
[0021] Zero-trust access control and dynamic key management: Facing the risks in the logistics field with multi-device, cross-platform data access, and heterogeneous environments, a zero-trust access model is constructed based on multi-factor dynamic risk assessment. At the same time, a key encryption scheme similar to ECIES is adopted to achieve secure key distribution and management to ensure that only authorized accessors can call the data decryption operation.
[0022] Security audit and event traceability: Record every encryption, key distribution, and data access operation through blockchain technology, and at the same time, combine digital signature and hash technology to achieve security auditing and accident liability traceability.
[0023] The above is the preferred implementation manner of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, and should not be regarded as excluding other embodiments. Instead, it can be used in other combinations, modifications, and environments, and can be changed within the scope of the concept described herein through the above teachings or the technology or knowledge in related fields. Any changes and variations made by those skilled in the art without departing from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.
Claims
1. A method for data security protection of a digital twin system for a logistics transfer yard, characterized in that: Including the following steps: S1. Construct the sensitive data with heterogeneous sorting in the digital twin body of the logistics transfer yard into a data set, and perform preprocessing to obtain the original data set ; S2. Perform end-to-end data encryption on the original data set and perform digital signature and key protection; S3. Build the information exchange and storage between the digital twins of the blockchain logistics transfer yard, and perform zero-trust access and data decryption.
2. The data security protection method of a digital twin system for a logistics transfer yard according to claim 1, wherein: The step S1 includes: Suppose the digital twin system of the logistics transfer yard includes digital twins of multiple logistics transfer yards. Each digital twin of the logistics transfer yard synchronously accesses the data of the logistics transfer yard and simulates the operation of the logistics transfer yard. From the digital twins of each logistics transfer station, obtain the sensitive data with heterogeneous sorting within the logistics transfer station and construct it into a data set to obtain the logistics sorting sensitive data set : Among them, is the user waybill number, is the production capacity value of the current sorting shift, is the sorting personnel arrangement information, is the sorting data collected in real time by the current sorter, is the number of packages sorted in the current shift, is the sorting market information of the current shift; The set of sensitive data for logistics sorting Encapsulate it in JSON format and convert it to binary data using UTF-8 encoding to achieve the preprocessing of the set of sensitive data for logistics sorting and obtain the original data set .
3. A data security protection method for a digital twin system of a logistics transfer yard according to claim 1, characterized in that: In the step S2, for the original data set Performing end-to-end data encryption includes: A1. Symmetric key generation: Generate a 256-bit symmetric key using a cryptographically secure random number generator and a 128-bit initialization vector : ; A2. AES-256-CBC Encryption: Encrypt the original data set as follows: First, calculate the padding length , where, | | represents the byte length of the original data set ; 16 is the fixed 16-byte length; Then fill the data as follows: ; where, || represents the binary concatenation operation, that is, concatenating the data with the padding bits padding to form a complete encrypted input; the padding bits refer to the positions where data needs to be filled when it is less than 16 bits; each padding bit is filled with 0; Finally, encrypt the filled to obtain the ciphertext ; It refers to performing the AES-256-CBC encryption operation; A3. Data Integrity Check Value Calculation: Calculate the hash value of 256-bit data with a fixed length as the integrity check value , which is used as the integrity check value indicating that the ciphertext is hashed using SHA-256 for the hashing operation 4. A method for data security protection of a digital twin system for a logistics transfer yard according to claim 3, characterized in that: In the step S2, performing digital signature and key protection includes: B1. Digital Signature: Implement digital signature using the ECDSA algorithm based on the secp256k1 elliptic curve. First, randomly generate a 256-bit private key , and calculate the corresponding public key , where is the generator, represents the order; B2. Signing process: For the hash value perform ECDSA signing, and let the random number be selected from , and calculate the point R: Among them, the point is located on the elliptic curve, and its coordinate representation is , and for take modulo to obtain : Mod represents the modulo operation. If , then reselect and calculate If , then reselect ; If and both do not hold, then the signature result is ; B3. Symmetric Key Protection: Assume that the authorized person who can access the digital twin data provides the public key , and use ECIES for encryption: First, generate a temporary elliptic curve key pair , where is the temporary private key, ; then calculate the shared key ; use to perform AES-256-CBC encryption to obtain: A 128-bit initialization vector for encrypting the shared key 5. A data security protection method for a digital twin system of a logistics transfer yard according to claim 4, characterized in that: In the step S3, building the information exchange and storage between the digital twins of the blockchain logistics transfer yard includes: Set information exchange Contains the following fields: encrypted data ciphertext , its corresponding hash value , digital signature , encrypted symmetric key information , encrypted initialization vector , and the transaction generation timestamp , that is Distributed storage: Considering the capacity of each data component collected by the digital twin in the actual logistics transfer yard, the data is stored in chunks: , for each calculate the hash value , and combine them in pairs to calculate the combined hash, and recursively generate a single root hash ; represents the calculation of the Merkle root; Block structure and consensus: Build a block for each digital twin of the logistics transfer yard to store the information of the digital twin, and form a blockchain between the blocks. Each block contains a block header and a list of transactions. The block header includes the hash of the previous block , the Merkle root of the current block , the timestamp and the Nonce. Among them, the Nonce represents the proof-of-work value and is a non-repeating random number; the list of transactions stores the information exchange of the digital twins in this block .
6. A data security protection method for a digital twin system of a logistics transfer yard according to claim 1, characterized in that: In the step S3, performing zero-trust access and data decryption includes: Access request model and risk assessment: For the access request to the data of the digital twin system of the logistics transfer yard, it is defined as a vector: Among them, is the identity of the requester, is the requested data resource, is the context information, is the request time; on this basis, a risk assessment function is defined as follows: And set a security threshold Used to determine whether to authorize the current access. Access is not allowed if it is below the threshold; ~ Is a preset weight; Identity risk function The calculation method is as follows: Among them, is the user level, and the administrator = 0, visitor = 1; is the account activity, and active = 0, abnormal access = 1; is the abnormal access frequency, , , are preset weights; An abnormal access means that the account has not appeared in the historical 20 records, otherwise it is active. Resource access risk function The calculation method is as follows: Among them, is the sensitivity level of the resource, and the public data = 0, sensitive information = 1, indicates whether each resource needs to be frequently accessed. If it needs to be frequently accessed = 0, does not need to be frequently accessed = 1, and are preset weights; if the average number of resource accesses within the historical unit time is greater than the preset value, it needs to be frequently accessed, otherwise it does not need to be frequently accessed; Context access function The calculation method is as follows: Among them, The geographical location risk score, access from the same province = 0, access from other provinces = 1, is the credibility of the access device, registered device = 0, unknown device = 1, is the preset weight; Time risk function The calculation method is as follows: Among them, is the normal peak access time, is the attenuation coefficient; Authorization and decryption process: After the access request passes the risk assessment, the authorized visitor obtains the key protection information stored in the blockchain transaction ; Use one's own private key Decrypt the key information encrypted by ECIES ; Indicates decryption; () indicates using The algorithm for decryption; Using the obtained , and perform AES-256-CBC decryption on the stored data ciphertext to recover the plaintext sorting data : Among them, represents the execution of AES-256-CBC decryption operation; Meanwhile, verify for integrity: For the ciphertext Recalculate = SHA256( ); Compare with the stored on the chain: If == : It means the data is complete and the decryption is trustworthy; If ≠ : The data has been tampered with or there is a transmission error. Reject access and record the audit log.
Citation Information
Patent Citations
Decentralized encrypted communication and transaction system
CN113256290A
Logistics sorting method based on reinforcement learning and digital twins
CN117114524A
Communication security management method and system based on block chain nodes
CN118381613A
Data access control method and system based on attribute encryption and zero-trust architecture
CN119094137A
Method and apparatus for providing a universal deterministically reproducible cryptographic key pair representation for all skus shipping cartons and items
IN201737026443A
Cited By
Intelligent marketing terminal electric power data communication security protection method and system
CN121000528A