Trusted monitoring and auditing system fusing TEE and block chain

By generating and signing transaction instantaneous state summary in a trusted execution environment, and combining blockchain and physical sensor data, the problems of state capture incompleteness and verification path splitting of existing audit systems are solved, and efficient and trustworthy verification in cross-institutional collaboration scenarios are achieved.

CN120471723AActive Publication Date: 2025-08-12CHANGSHA SHALONAO INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510980905.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-16
Publication Date
2025-08-12
Estimated Expiration
2045-07-16

AI Technical Summary

Technical Problem

The existing audit system captures audit blind spots and inefficiency problems caused by incomplete capture of instantaneous states of key transaction nodes, single trusted proof dimensions, and splitting of on-chain verification paths.

Method used

By generating a transaction instantaneous state summary and digital signature in a trusted execution environment, recording and verification is performed using the blockchain network, and cryptographic correlation is achieved by generating perturbation characteristic codes in combination with physical sensor data, multi-level cryptographic correlation between transaction logic and environmental state.

Benefits of technology

It realizes lightweight trusted verification in cross-organization collaboration scenarios, can verify the authenticity and integrity of transactions in real time, improves the supervision efficiency of multi-step business processes, and can identify potential physical attacks or abnormal operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120471723A_ABST
    Figure CN120471723A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of transaction processing systems, and particularly discloses a trusted monitoring auditing system fusing TEE and a block chain, which comprises the following steps: generating a transaction instantaneous state abstract containing a key information field at a key node of a business process through a trusted execution environment, signing, anchoring a hash value of the transaction instantaneous state abstract to a block chain network, and storing the signature abstract under the chain; and during auditing, by comparing integrity verification of on-chain hash and under-chain abstract and TEE signature verification, dual authentication of transaction authenticity and environment reliability is realized. Through the collaborative architecture of the TEE and the block chain, the transaction core data state and the credible environment proof are deeply fused, so that the audit verification can be independently completed without depending on a centralized database, the problem that post-event tracing depends on the credibility of the log in the traditional audit is fundamentally avoided, and the audit verification efficiency is improved. And a lightweight credible verification basis is provided for a cross-mechanism cooperation scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention is a trusted monitoring and auditing system that integrates TEE and blockchain, and belongs to the technical field of transaction processing systems. Background Art

[0002] In key business processes such as administrative supervision, financial transactions, and commercial contract execution, ensuring the auditability and credibility of the entire operation chain has always been a core challenge in the technology field. Traditional audit systems generally rely on centralized databases to store transaction logs and use digital signatures to ensure data integrity. However, this model has two inherent flaws: 1. The centralized storage architecture is susceptible to single-point tampering risks, making it difficult to establish mutual trust and consensus in cross-institutional collaboration scenarios; 2. The post-event traceability mechanism relies on the authenticity of log records, but the security of the log generation environment and the physical operating status lack effective verification methods, making it difficult to cope with attack scenarios where malicious nodes forge environmental information.

[0003] In recent years, the industry has attempted to introduce blockchain technology to achieve tamper-proof storage of audit data. However, simple on-chain evidence storage has problems with data expansion and low verification efficiency, and is unable to penetrate and verify the trusted state of the local computing environment when the transaction occurs. In addition, existing solutions generally ignore the accuracy of instantaneous state capture of key nodes in the business process, resulting in a disconnect between audit granularity and business logic, making it difficult to meet the regulatory needs of highly sensitive scenarios such as administrative approval decision tracing and supply chain financial performance verification.

[0004] On a deeper level, existing technologies have a systematic design gap in the coordination mechanism between trusted environments and distributed ledgers: although the trusted execution environment (TEE) can ensure the verifiability of key code execution, the trusted proof it generates lacks dynamic association with business processes and does not establish a cryptographic binding with the state of the physical environment; although the blockchain network provides tamper-resistant data storage, the verification path of on-chain and off-chain data is separated, and end-to-end closed-loop verification of transaction logic, environmental status and stored data cannot be achieved. Such limitations are particularly prominent in cross-domain multi-party collaboration scenarios. For example, in cross-border trade settlement, participants need to simultaneously verify the correctness of the contract execution logic, the credibility of the clearing instruction generation environment, and the compliance of the equipment operating status. However, existing technical solutions cannot achieve collaborative auditing of multi-dimensional trust factors while ensuring verification efficiency. Therefore, how to achieve full-dimensional trusted capture of the instantaneous state of key transaction nodes under a distributed architecture, build a lightweight and environmentally aware audit and verification system, and establish a multi-level cryptographic association mechanism between transaction logic, trusted environment and physical state, so as to avoid the technical bottlenecks of traditional audit systems in real-time, trusted proof completeness and cross-system verification efficiency, has become the technical problem to be solved by the present invention. Summary of the Invention

[0005] The present invention provides a trusted monitoring and auditing system that integrates TEE and blockchain. Its main purpose is to solve the problems of audit blind spots and low efficiency caused by incomplete capture of the instantaneous status of key transaction nodes, single dimension of trusted proof, and fragmented on-chain and off-chain verification paths in existing audit systems.

[0006] To achieve the above objectives, the present invention provides a trusted monitoring and auditing system that integrates TEE and blockchain, the system comprising: A transaction processing module, configured with a trusted execution environment, is configured to generate a transaction instantaneous state summary containing preset key information fields based on the current transaction context when the business process runs to a predefined key transaction node; and digitally sign the transaction instantaneous state summary using the trusted execution environment. The transaction processing module is further configured to perform a hash calculation on the digitally signed transaction instantaneous state summary to generate an instantaneous state hash value; An on-chain anchoring module, connected to the transaction processing module, for submitting the instantaneous state hash value to the blockchain network for recording; The off-chain storage module is connected to the transaction processing module and is used to store the digitally signed transaction state summary; An audit verification module is used to obtain the instantaneous state hash value of the target transaction from the blockchain network and obtain the corresponding digitally signed transaction instantaneous state summary from the off-chain storage module; the audit verification module is also used to compare the obtained instantaneous state hash value with the hash value of the recalculated transaction instantaneous state summary to verify the integrity of the transaction instantaneous state summary; and use the trusted public key corresponding to the trusted execution environment to verify the digital signature to confirm the source authenticity of the transaction instantaneous state summary and the reliability of the generation environment.

[0007] Preferably, when the transaction processing module generates a transaction transient state summary within a trusted execution environment, it is also used to obtain a unique identifier of the current trusted execution environment instance and encapsulate the unique identifier into the transaction transient state summary to enhance the traceability and uniqueness of the transaction transient state summary.

[0008] Preferably, the key transaction node is at least one of the following: a decision node in an administrative approval process, a performance confirmation node in commercial contract execution, or a settlement instruction issuance node in a financial transaction.

[0009] Preferably, the blockchain network is a consortium chain, or a lightweight private chain optimized for recording instantaneous state hash values, and the consensus mechanism of the lightweight private chain is configured to prioritize recording efficiency and low-cost operation.

[0010] Preferably, the transaction processing module also includes an environment perception unit, which is used to obtain the original signal of the current physical environment state through at least one physical sensor deployed on the device carrying the trusted execution environment; the transaction processing module is also used to process the original signal into a standardized physical environment perturbation feature code; the physical environment perturbation feature code is included in the transaction instantaneous state summary, or is cryptographically associated with the transaction instantaneous state summary or its instantaneous state hash value, and then processed or signed by the trusted execution environment, so that the instantaneous state hash value anchored to the blockchain network can simultaneously reflect the state of the physical environment perturbation feature code.

[0011] Preferably, the transaction processing module, when a plurality of key transaction nodes predefined in the processing system constitute a transaction cluster with a preset execution order, generates a corresponding transaction instantaneous status summary for any current transaction node other than the first one in the transaction cluster in a trusted execution environment, and is further used to obtain a hash value of a preceding transaction instantaneous status summary generated by a key transaction node immediately preceding the current transaction node in the transaction cluster; the hash value of the preceding transaction instantaneous status summary serves as preceding anchor information and is included in the current transaction instantaneous status summary; the on-chain anchoring module is configured to submit only the instantaneous status hash value of the transaction instantaneous status summary generated by the last key transaction node in the transaction cluster, or a hash value of an aggregate summary representing all transaction instantaneous status summaries of the entire transaction cluster, to the blockchain network for recording.

[0012] Preferably, the audit verification module verifies the integrity of the transaction instantaneous state summary based on the following conditions: , in, Represents the hash value recalculated from the transaction instantaneous state summary obtained from the off-chain storage module; Represents the instantaneous state hash value of the target transaction obtained from the blockchain network.

[0013] Preferably, when generating a transaction instantaneous status summary, the transaction processing module is configured to dynamically adjust the composition of key information fields according to the business type corresponding to the key transaction node to ensure that the transaction instantaneous status summary can accurately capture the core trust elements in different business scenarios.

[0014] Preferably, the audit verification module is configured to trigger a review or early warning mechanism for a transaction based on the indication of the physical environment perturbation signature code; the judgment condition for the triggering threshold is: ,in, Indicates the abnormality level indicated by the physical environment perturbation signature code, Indicates the preset minimum abnormality level threshold that triggers the review or warning mechanism.

[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. Through the collaborative architecture of TEE and blockchain, the system generates and signs the transaction instantaneous state summary (TISD) in real time at key nodes of the business process, and only anchors its hash value to the chain. This mechanism deeply integrates the core data status at the time of the transaction with the trusted environment proof, so that audit verification does not need to rely on a centralized database. By comparing the on-chain hash and the off-chain summary, the authenticity and integrity of the transaction can be independently verified. This design avoids the problem of retrospective reliance on log credibility in traditional audits, and provides a lightweight trusted verification foundation for cross-institutional and cross-system collaboration scenarios.

[0016] 2. By integrating physical sensor data into TEE to generate a perturbation signature (MPS) and cryptographically associating it with the transaction summary, the system can simultaneously capture abnormal signals in the device operating environment while ensuring the trustworthiness of the logical level. This two-dimensional trusted binding mechanism enables the audit process to not only verify the correctness of the transaction logic, but also trace the physical environment status when the transaction occurred, effectively identifying potential physical attacks or abnormal operation scenarios, and providing multi-dimensional trustworthy guarantees for highly sensitive administrative decisions or financial transactions; and for sequentially associated transaction clusters, the system embeds the hash value of the previous transaction when generating each transaction summary to form an endogenous time chain, which can be verified by the anchor hash at the end of the chain during auditing. Looking back on the integrity of the entire transaction chain, this chain structure combined with the tamper-proof nature of the blockchain allows the full-cycle status of complex business processes to be quickly and penetrably verified, significantly improving the regulatory efficiency of scenarios such as multi-step administrative approval and supply chain finance. Through predefined key information field templates and dynamic adjustment strategies, the system can automatically capture the core trust elements of different scenarios based on business types, such as the decision-making basis for administrative approval and the settlement instruction parameters for financial transactions. This flexibility ensures that the transaction summary can accurately reflect business characteristics while avoiding redundant data storage. While ensuring audit granularity, it maintains the lightweight of the overall architecture and adapts to the diverse scenario requirements from government supervision to commercial contracts. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 A timing diagram of transaction summary generation and dual verification based on a multi-layer structure in the trusted monitoring and auditing system of the present invention; Figure 2 This is a flowchart of the transaction summary generation, blockchain anchoring, and audit verification interaction based on the trusted execution environment of the present invention; Figure 3 A flowchart for generating a summary of the instantaneous state of a transaction based on business type and environment perception at a key transaction node of the present invention; Figure 4 This is a schematic diagram of the transaction summary chain generation and storage structure based on hash links and physical perception in the present invention.

[0018] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0019] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0020] This embodiment of the application provides a trusted monitoring and auditing system that integrates TEE and blockchain, and includes: A transaction processing module, configured with a trusted execution environment, is configured to generate a transaction instantaneous state summary containing preset key information fields based on the current transaction context when the business process runs to a predefined key transaction node; and digitally sign the transaction instantaneous state summary using the trusted execution environment. The transaction processing module is further configured to perform a hash calculation on the digitally signed transaction instantaneous state summary to generate an instantaneous state hash value; An on-chain anchoring module, connected to the transaction processing module, for submitting the instantaneous state hash value to the blockchain network for recording; The off-chain storage module is connected to the transaction processing module and is used to store the digitally signed transaction state summary; An audit verification module is used to obtain the instantaneous state hash value of the target transaction from the blockchain network and obtain the corresponding digitally signed transaction instantaneous state summary from the off-chain storage module; the audit verification module is also used to compare the obtained instantaneous state hash value with the hash value of the recalculated transaction instantaneous state summary to verify the integrity of the transaction instantaneous state summary; and use the trusted public key corresponding to the trusted execution environment to verify the digital signature to confirm the source authenticity of the transaction instantaneous state summary and the reliability of the generation environment.

[0021] Preferably, when the transaction processing module generates a transaction transient state summary within a trusted execution environment, it is also used to obtain a unique identifier of the current trusted execution environment instance and encapsulate the unique identifier into the transaction transient state summary to enhance the traceability and uniqueness of the transaction transient state summary.

[0022] Preferably, the key transaction node is at least one of the following: a decision node in an administrative approval process, a performance confirmation node in commercial contract execution, or a settlement instruction issuance node in a financial transaction.

[0023] Preferably, the blockchain network is a consortium chain, or a lightweight private chain optimized for recording instantaneous state hash values, and the consensus mechanism of the lightweight private chain is configured to prioritize recording efficiency and low-cost operation.

[0024] Preferably, the transaction processing module also includes an environment perception unit, which is used to obtain the original signal of the current physical environment state through at least one physical sensor deployed on the device carrying the trusted execution environment; the transaction processing module is also used to process the original signal into a standardized physical environment perturbation feature code; the physical environment perturbation feature code is included in the transaction instantaneous state summary, or is cryptographically associated with the transaction instantaneous state summary or its instantaneous state hash value, and then processed or signed by the trusted execution environment, so that the instantaneous state hash value anchored to the blockchain network can simultaneously reflect the state of the physical environment perturbation feature code.

[0025] Preferably, the transaction processing module, when a plurality of key transaction nodes predefined in the processing system constitute a transaction cluster with a preset execution order, generates a corresponding transaction instantaneous status summary for any current transaction node other than the first one in the transaction cluster in a trusted execution environment, and is further used to obtain a hash value of a preceding transaction instantaneous status summary generated by a key transaction node immediately preceding the current transaction node in the transaction cluster; the hash value of the preceding transaction instantaneous status summary serves as preceding anchor information and is included in the current transaction instantaneous status summary; the on-chain anchoring module is configured to submit only the instantaneous status hash value of the transaction instantaneous status summary generated by the last key transaction node in the transaction cluster, or a hash value of an aggregate summary representing all transaction instantaneous status summaries of the entire transaction cluster, to the blockchain network for recording.

[0026] Preferably, the audit verification module verifies the integrity of the transaction instantaneous state summary based on the following conditions: , in, Represents the hash value recalculated from the transaction instantaneous state summary obtained from the off-chain storage module; Represents the instantaneous state hash value of the target transaction obtained from the blockchain network.

[0027] Preferably, when generating a transaction instantaneous status summary, the transaction processing module is configured to dynamically adjust the composition of key information fields according to the business type corresponding to the key transaction node to ensure that the transaction instantaneous status summary can accurately capture the core trust elements in different business scenarios.

[0028] Preferably, the type of the trusted execution environment (TEE) is selected from: Intel SGX compatible technology on the server side, or ARM TrustZone in an embedded device; the audit verification module is configured to trigger a review or early warning mechanism for the transaction based on an indication of a physical environment perturbation signature code; and the judgment condition for the triggering threshold is: ,in, Indicates the abnormality level indicated by the physical environment perturbation signature code, It represents the preset minimum abnormality level threshold that triggers the review or early warning mechanism; at the same time, in order to improve the consistency of the system's technical expression and structural readability, in the description of each module of the present invention, all intermediate data involving the capture of the status of key nodes in the business process are uniformly referred to as the transaction instantaneous state summary (hereinafter referred to as TISD). TISD covers all transaction state snapshots generated, signed, and participating in on-chain anchoring and off-chain verification through the trusted execution environment. Its summary, signature summary, and other expressions in different application contexts all refer to the same concept. To ensure the integrity of the time chain, when constructing the hash nested structure of the transaction cluster, the system uses the method of embedding the previous summary hash value into the current TISD to achieve endogenous anchoring association. The terms such as intrinsic time sequence chain and previous anchor information mentioned in the article are all used to describe this structured hash link mechanism, which aims to enhance the continuity and traceability of the transaction status at each stage. In addition, for the core judgment formula used for integrity comparison in the audit verification module: ,in Represents the recalculated hash function, Represents the target hash of the on-chain record. This formula is applicable to scenarios where the consistency of data on and off the chain for any target transaction is verified, ensuring that the mathematical basis of the verification process is clear and easy to implement in engineering.

[0029] Example 1: To further clarify the specific engineering implementation path of the trusted monitoring and auditing system that integrates TEE and blockchain, the operating logic, data interaction mechanism, and configuration basis of key parameters of each functional module of the system are elaborated in detail based on typical application examples in financial transaction clearing scenarios. In this embodiment, the system is deployed in a collaborative network jointly participated by banks, third-party clearing institutions, and regulatory agencies. Each participating entity achieves ledger consistency through a blockchain network built on a consortium chain. At the same time, all core transaction processing terminals are integrated with a trusted execution environment that supports Intel SGX technology to generate, sign, and anchor the key status of the transaction in real time during the processing of each clearing instruction. When the clearing node receives an inter-bank funds transfer instruction with a unique business number, the system enters the trusted monitoring process. First, the transaction processing module deployed on the node generates a transaction instantaneous status summary that conforms to a predefined format within its trusted execution environment based on the business context data of the current instruction (including but not limited to the initiating bank number, the receiving bank number, the transfer amount, the timestamp, etc.). The summary is constructed based on the system's built-in field template, and the filled field content It comes directly from the transaction context being processed. After the generation is completed, the trusted execution environment digitally signs the above summary content and calculates the hash value of the signature summary. The hash value is then submitted to the consortium chain network by the on-chain anchoring module for each node in the network to record the account in accordance with the preset consensus mechanism. It should be noted that in order to avoid on-chain data expansion and improve processing efficiency, the system design does not directly upload the original summary to the chain, but only submits its hash value; the original summary signature is stored in a local secure container through the off-chain storage module and is regularly backed up off-site to ensure that it can be fully retrieved and verified during future audits.

[0030] To further enhance the credibility of summary data, this embodiment introduces an environment perception unit, which is deployed in the device that hosts the trusted execution environment. It automatically collects typical physical disturbance information (such as electromagnetic interference, vibration spectrum characteristics, or ambient temperature and humidity) during the operation of the device through physical sensors, and forms a physical environment perturbation feature code after standardization of the collected results. The feature code is encapsulated in the summary structure when the summary is generated, or a key-level association is established with the summary or its hash value through cryptographic methods, and then uniformly processed and signed by the trusted execution environment to ensure that changes in the external environment are reflected at the summary level and cannot be forged. After the entire clearing process is completed, The audit verification module can initiate authenticity verification of the target transaction at any time. The verification process includes: obtaining the hash value of the target transaction from the blockchain network, and retrieving the corresponding signature summary text from the off-chain storage module, recalculating the hash value of the summary text and comparing it. If the two are consistent, the verification engine is called to verify the summary signature using the preset trusted execution environment public key to confirm that the summary is indeed generated by the trusted environment and the content has not been tampered with. If the audit process has verification requirements for the physical environment status, the system can further extract the physical disturbance feature code in the summary and compare it with the pre-set model parameters to determine whether there is an abnormal physical state.

[0031] Furthermore, considering that some business processes involve multi-step, highly sequential transactions, this embodiment introduces a transaction clustering mechanism. Taking inter-period batch funds transfer as an example, this process includes multiple transaction steps, executed at different time points. When generating each sub-transaction summary, the system embeds the hash value of the previous sub-transaction into the current summary, thereby constructing an internal chronological chain. Ultimately, the system anchors only the hash value of the last sub-transaction to the blockchain network. During audits, the sequential integrity of the entire transaction cluster can be verified by verifying the final anchor node and combining it with the pre-order chain relationship embedded in the summary. The specific settings of the various key parameters involved in this embodiment are based on extensive testing and data analysis conducted on a real financial transaction simulation platform during the system development phase. For example, the physical disturbance signature code is encoded using a five-dimensional composite structure, an optimal structure determined after verifying its anti-interference and identifiability across devices and multiple scenarios. The summary field template adopts a fixed-length structure, an engineering choice made after multiple rounds of optimization experiments to balance summary computational efficiency and audit clarity.

[0032] Example 2: In a typical financial clearing network, multiple key nodes of business processing (including clearing instruction initiation, fund arrival confirmation, cross-system settlement execution, etc.) have extremely high requirements for the credibility of the operating environment. In order to verify whether the system that integrates the trusted execution environment (TEE) and blockchain mechanism in the present invention has the ability to achieve high-reliability capture and verification of instantaneous status at key transaction nodes, this experiment was carried out based on the combination of a simulation platform and a physical device deployment environment, and the data used was exemplary data that had been desensitized.

[0033] The system deployment environment constructed a test system on a simulated financial transaction clearing platform, with a simulated transaction flow of approximately 250 transactions per second. The system deployment included nodes supporting two types of TEEs, Intel SGX and ARM TrustZone, and set up standard non-TEE nodes as a control group. The blockchain network structure adopted a consortium chain architecture, with a total of 5 accounting nodes and a PBFT consensus mechanism. The MPS perception and acquisition module selected three types of disturbance factors as input sources: electromagnetic interference (EMI), environmental temperature and humidity changes, and micro-mechanical vibration. The sampling frequency was set to 200Hz, and the disturbance signature used a five-dimensional combination encoding structure. The transaction model was set to construct a complete transaction cluster process consisting of four consecutive key nodes. Each node generated an independent TISD and embedded a preamble summary hash value. Under the set business concurrency conditions, the system continuously processed 1,000 valid clearing instruction transactions, recording the following performance data: Table 1: Shows the time statistics of different task processing steps.

[0034] Analysis: The average total time required to execute the entire process of TISD generation, signing, and hashing within the TEE environment is less than 10 milliseconds, which can meet the processing capacity requirement of more than 50 transactions per second. The test method is to inject known interference sources into the system in a standard working environment and different disturbance scenarios, and repeat the test 100 times; the anti-interference stability indicator is the RMS variation rate of MPS under normal conditions; the anomaly recognition rate is the probability that MPS correctly identifies and triggers the audit mechanism.

[0035] Table 2: Shows the sensor data analysis table under different environments.

[0036] Analysis: MPS exhibits an extremely low mutation rate under normal conditions and an identification rate of over 90% under complex physical interference conditions. It has good stability and sensitivity, meeting the system's perception of physical disturbance changes in highly sensitive business environments. The test method is for the system to construct a transaction cluster containing 4 consecutive key transaction nodes. Each node generates an independent TISD and embeds the hash value of the previous node. Finally, only the hash value of the last node TISD is anchored to the chain; the verification process is for the audit module to trace back step by step from the last node to compare whether the previous hash chain in the summary is continuous, and verify the validity of the signature and the consistency of MPS.

[0037] Table 3: Verification result table for each node in the transaction process.

[0038] It can be seen that the transaction chain constructed under the nested hash mechanism does not experience chain breaks or verification failures in the multi-step transaction process. The chain summary structure combined with the blockchain can achieve complete and continuous backtracking verification, with good sequentiality and consistency guarantees. This experiment comprehensively verifies the practical engineering feasibility of the solution of the present invention from three core dimensions: transaction summary generation efficiency, physical disturbance feature code recognition capability, and cross-node transaction chain consistency. The experiment shows that: the system has the ability to generate TISD in real time and stably and complete signature and hash processing in a high-concurrency environment; the MPS mechanism can effectively capture environmental anomaly information, with good anti-interference ability and recognition accuracy; the summary chain structure, combined with the on-chain anchoring design, has efficient backtracking and consistency verification capabilities in multi-step processes.

[0039] Example 3: This example combines Figures 1 to 4 , describes the implementation of a trusted monitoring and auditing system that integrates TEE and blockchain. Figure 1 As shown in the figure, the physical perception layer includes a temperature sensor and a power monitoring module, which respectively collect temperature signals (±0.5°C) and voltage fluctuation data as the basic input of the physical environment status; these data are then transmitted to the trusted execution environment of the trusted computing layer. In this trusted execution environment, the summary generator generates a summary containing a feature code based on the transaction context + environmental data, and calculates its hash value (SHA-256); the generated signature summary and hash value will be sent to the alliance chain node of the blockchain layer for block confirmation; the alliance chain layer adopts the alliance chain configuration: consensus mechanism: PBFT, block interval: 2 seconds to ensure the immutability and real-time nature of the data; after completing the on-chain record, the audit verification module on the audit end obtains the anchor hash from the blockchain layer, and performs double verification in combination with the off-chain data, that is, verifying the validity of the summary hash value and signature, and finally returning the verification result.

[0040] like Figure 2As shown, first, in the trusted execution environment, the system collects raw data such as temperature sensor signals, power monitoring data, and device fingerprint collection through the physical environment perception module; combining the transaction context data in the business input with the preset key fields, the core processing module generates an instantaneous state summary, embeds the environment feature code, and then executes the digital signature; finally, the hash value (SHA-256) and signature summary (ECC) are generated through cryptographic output; the above-mentioned signature summary is provided as "Signature Summary" to the audit verification end, and the audit verification end further obtains the on-chain hash, verifies the off-chain summary, and verifies the reliability of the environment; at the same time, the hash value (SHA-256) calculated in the trusted execution environment is anchored as "Instantaneous Hash" to the blockchain network, which receives and stores the hash and provides a verification interface; finally, the hash comparison verification is completed at the audit verification end, and the integrity of the transaction and the reliability of the trusted execution environment are ensured by comparing the on-chain and off-chain data and verifying the legitimacy of the signature summary (ECC) with the consistency of the generation environment.

[0041] like Figure 3 As shown, the system first distinguishes between administrative approval, financial transactions and other businesses in the stage of judging the business type: for the administrative approval path, the key information field is dynamically adjusted to capture the decision basis; for the financial transaction path, the key information field is dynamically adjusted to capture the clearing instruction parameters; and other businesses use the default or universal key information field, and then enters the step of generating the transaction instantaneous state summary, and determines whether the environmental perception unit is enabled. If enabled, the original signal of the physical environment is obtained, and then the original signal is processed to generate a physical environment perturbation feature code, which will be cryptographically associated with the summary; if not enabled, TEE processing is performed directly, and finally, the trusted execution environment is processed or signed to complete the generation of the transaction instantaneous state summary.

[0042] like Figure 4 As shown in the figure, the generation and organization method of the transaction summary chain structure implemented in the transaction processing module (TEE environment) of the present invention in combination with the environment perception unit and the off-chain storage module. In the transaction processing module, the environment perception unit first collects environmental data, including physical disturbance information such as temperature and power supply at the time of the device. The environmental data is embedded in the transaction instantaneous state summaries such as TISD-T1, TISD-T2, TISD-T3 and TISD-T4 generated in each stage to form a data package associated with the actual operating environment. At the same time, each summary (such as TISD-T1) will calculate its hash value H(T1) after generation, and the hash value will be embedded in the next summary (such as TISD-T2) as the pre-order anchor information to realize chain hash link. This chain structure is TISD-T1, H(T1), TISD-T2, H(T2), TISD-T3, H(T3), and TISD-T4 from top to bottom.

[0043] Example 4: In the government process supervision scenario, a monitoring and auditing system integrating a trusted execution environment and blockchain is deployed to implement full-process trusted recording and dynamic audit verification of key nodes in the construction project approval process. The system is configured in multiple core processing nodes such as administrative approval terminals, on-site inspection equipment, and third-party evaluation platforms. This embodiment takes the decision-making nodes in the approval process of major infrastructure projects as a typical application scenario, and systematically explains the specific operation process, parameter response logic, and coordination mechanism between modules of each component of the system in the scenario. In this scenario, when the project application completes the preliminary material review and enters the final approval stage, the system automatically starts the confirmation process when the approval personnel start the confirmation process. While confirming the approval interface, the transaction processing module deployed in the approval terminal is activated. This module first calls the transaction summary construction engine in the trusted execution environment, and extracts seven core information fields including approval number, project code, funding scale, assessment rating, approval personnel identification, terminal location code and approval timestamp from the current approval context based on the field template preset in the system for infrastructure approval scenarios. The above field template system is formed in the early process testing phase through field usage frequency analysis, audit reference value assessment and data consistency modeling optimization. The field order and type are uniformly set by the system to ensure that the data structure is clear and consistent during the audit parsing process.

[0044] Afterwards, the environmental perception submodule deployed in the trusted execution environment will automatically collect disturbance signals in the current operating environment of the approval terminal. The disturbance sources selected in this embodiment include three types of physical indicators: power supply voltage fluctuation, background electromagnetic intensity, and micro-vibration of the equipment casing. The system collects data for two consecutive seconds at a sampling frequency of one hundred times per second, and obtains a total of six hundred groups of original signal data. The disturbance processing engine processes the collected data based on Fourier transform and amplitude deviation analysis methods to generate a set of five-dimensional disturbance feature codes, which include voltage fluctuation distribution code, electromagnetic spectrum main peak code, acceleration waveform density code, equipment stability score code and disturbance balance index code. The five-dimensional feature coding structure is determined by the system through disturbance distinguishability evaluation and summary signature compatibility analysis in more than three hundred groups of typical physical interference scenarios to ensure disturbance The embedding of data in the summary structure has stability and traceability; then, the transaction processing module encapsulates the above seven field data and the disturbance feature code together into a summary of the instantaneous state of the transaction. The summary structure adopts a fixed-length splicing and field sequence signature strategy to ensure the consistency of cross-platform verification. After the summary is constructed, the private key signature engine embedded in the trusted execution environment is called to digitally sign it. The signature algorithm used is a verifiable signature algorithm based on the elliptic curve cryptography system. The overall signing process takes no more than five milliseconds to ensure the interactive experience during the user operation; the signed transaction summary is then generated by the hash calculator to generate a unique hash value, which is broadcast to the alliance chain network through the on-chain anchoring module. The alliance chain adopts a delegated Byzantine fault-tolerant consensus mechanism to optimize the processing delay of government data, and the recording time is controlled within three seconds. At the same time, the off-chain storage module generates an index path based on the hash value, writes the original signature summary package into an encrypted storage container with access control, and records the approval event ID, terminal ID, signature timestamp and field template version number in the metadata index table. This design supports subsequent combined queries by approval number, hash value or timestamp. The system uses an inverted index tree structure to improve retrieval efficiency. In actual applications, it supports the rapid positioning and calling of any summary package in one thousand data within two seconds.

[0045] During a regulatory spot check, the auditor initiated an authenticity audit request for a certain infrastructure approval event through the regulatory platform. The system then called the off-chain storage interface through the audit verification module to retrieve the signature summary package corresponding to the approval item, and simultaneously retrieved the corresponding anchor hash value from the consortium chain network. First, the audit module recalculated the hash value of the summary package in the verification engine and compared it with the on-chain record value for consistency. When the comparison results are consistent, the system continues to call the registered trusted execution environment public key to verify the summary signature. If the physical perturbation verification function is enabled for the audit task, the system further extracts the perturbation feature code embedded in the summary and compares it with the standard perturbation model registered with the approval terminal device. If the match rate exceeds the preset trust threshold, the system returns a physical status trust mark. Otherwise, it is marked as an environmental anomaly awaiting review status and a warning log is recorded simultaneously. For the parallel sub-processes involving multiple departments such as finance and technology in the project approval process, the system adopts a transaction cluster organization strategy to integrate them. When each sub-transaction node generates its summary, it automatically embeds the previous sub-transaction node. The hash value of the point summary is used as the preceding anchoring information to form a sequential nested structure. Ultimately, only the summary hash value generated by the summary node (i.e., the decision-making and approval node) is submitted to the blockchain for anchoring. This mechanism constructs a chain summary structure with a clear structure and reasonable nesting. During the audit call, the audit verification module traces back and compares the nested hash chain in the summary from the last node in sequence. The verification path is clear, and the system can support up to eight layers of transaction nesting and ensure that the verification depth does not affect the front-end operation response performance. The measured results show that under the condition of six layers of transaction nesting, the system takes an average of no more than five seconds to complete the full chain backtracking and verification process, and the verification accuracy rate reaches 100%. In summary, this embodiment deploys a trusted execution environment and a physical disturbance perception mechanism at high-sensitivity nodes for government approval to construct a transaction trusted recording process with a clear structure, controllable traceability, and real-time response capabilities. Combined with the dual-path mechanism of on-chain anchoring and off-chain verification, it effectively realizes the authenticity verification and environmental status review of the entire approval process without relying on a centralized log system. These are all extended implementation methods that are known to ordinary technicians in this field.

[0046] Example 5: The present invention provides a deterministic procedure for determining physical environment perturbation signature codes and audit thresholds to ensure the integrity of the physical environment of unattended financial clearing servers at the time of issuing key transaction instructions, thereby effectively defending against attacks on internal operations of a trusted execution environment through physical means such as applying transient power interference or inducing slight vibrations in the chassis. This includes servers deployed in remote data centers that, due to the lack of continuous manual supervision, must establish a quantifiable and reproducible mechanism when processing large-scale fund clearing instructions. This mechanism determines whether there are abnormal disturbances in the physical environment caused by malicious attacks at the moment of generating a transaction instantaneous status summary.

[0047] To this end, the transaction processing module performs a one-time offline environmental baseline calibration procedure after the system is first deployed or a major hardware change occurs. When the procedure starts, the environmental perception unit continuously collects raw signals from multiple physical sensors for no less than 10,000 sample cycles under baseline conditions where the server is at a standard idle load and the environment is stable. The sources include electromagnetic interference, ambient temperature and humidity, and slight mechanical vibrations. For the raw time series signals collected by each sensor, the calibration program uses short-time Fourier transform to calculate the energy mean and standard deviation within the preset frequency band. These statistical values are solidified into a device-specific structured standard physical environment model and securely stored in the encrypted storage area of the trusted execution environment. The model establishment process provides a stable and statistically significant reference benchmark for subsequent quantitative comparison of real-time environmental status.

[0048] During system operation, when the business process triggers the issuance of a clearing instruction at this critical transaction node, the environmental perception unit immediately initiates real-time disturbance analysis. This analysis captures the current physical sensor signal with a two-second sliding time window and executes the same feature extraction algorithm as the offline calibration phase to calculate the real-time energy mean. Subsequently, the system calculates the difference between the real-time energy mean and the corresponding baseline mean in the standard physical environment model and divides it by the standard deviation in the model to obtain the standard score of each sensor's deviation from the baseline state, that is, the normalized deviation score. This score is then quantized and mapped to a certain integer interval to form the encoding of each dimension of the physical environment perturbation feature code. The system then calculates the overall physical environment anomaly level based on this. This level is determined by the following weighted summation formula: , in this formula, is the total number of physical sensors, For the Quantized encoding of the normalized deviation scores of each sensor, For the The weight of the sensor, It is not an empirical setting, but rather determined during the offline calibration phase by applying a set of known types of simulated attacks including power supply noise injection and ranking and analyzing the resulting signal response sensitivity, thereby amplifying the influence of sensors that are most sensitive to known attack patterns.

[0049] Accordingly, the judgment threshold for triggering the review or early warning mechanism Following a deterministic process setting, the system uses 10,000 sets of benchmark environmental data collected during the offline calibration phase to calculate the corresponding Historical distribution. It is set to the 99.9th percentile value of the historical distribution. This setting ensures that the system false alarm rate is at an acceptably low level under normal environmental fluctuations while maintaining high sensitivity to significant abnormal disturbances that exceed this statistical boundary. Calculated and confirmed to be lower than When a transaction is executed, the level value, along with the signature itself, is encapsulated into the transaction's instantaneous state summary and signed by the trusted execution environment. This mechanism cryptographically binds the instantaneous physical environment state to the transaction logic, enabling subsequent audits to not only verify the authenticity of the transaction content but also trace the integrity of the physical environment at the moment of its generation. This effectively addresses traditional audit blind spots and provides a deep level of trusted assurance for high-security scenarios.

[0050] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0051] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not limiting. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A trusted monitoring and auditing system integrating TEE and blockchain, characterized by: The system comprises: A transaction processing module, configured with a trusted execution environment, is configured to generate a transaction instantaneous state summary containing preset key information fields based on the current transaction context when the business process runs to a predefined key transaction node; and digitally sign the transaction instantaneous state summary using the trusted execution environment. The transaction processing module is further configured to perform a hash calculation on the digitally signed transaction instantaneous state summary to generate an instantaneous state hash value; An on-chain anchoring module, connected to the transaction processing module, for submitting the instantaneous state hash value to the blockchain network for recording; An off-chain storage module, connected to the transaction processing module, for storing digitally signed transaction instantaneous status summaries; An audit verification module is used to obtain the instantaneous state hash value of the target transaction from the blockchain network and the corresponding digitally signed transaction instantaneous state summary from the off-chain storage module; the audit verification module is also used to compare the obtained instantaneous state hash value with the hash value of the recalculated transaction instantaneous state summary to verify the integrity of the transaction instantaneous state summary; and use the trusted public key corresponding to the trusted execution environment to verify the digital signature to confirm the source authenticity of the transaction instantaneous state summary and the reliability of the generation environment.

2. A trusted monitoring and auditing system integrating TEE and blockchain according to claim 1, characterized in that: When generating the transaction transient state summary in the trusted execution environment, the transaction processing module is further configured to obtain a unique identifier of the current trusted execution environment instance and encapsulate the unique identifier into the transaction transient state summary.

3. A trusted monitoring and auditing system integrating TEE and blockchain according to any one of claims 1 or 2, characterized in that: A key transaction node is at least one of the following: a decision-making node in an administrative approval process, a performance confirmation node in commercial contract execution, or a settlement instruction issuance node in a financial transaction.

4. A trusted monitoring and auditing system integrating TEE and blockchain according to claim 1, characterized in that: The blockchain network is a consortium chain or a lightweight private chain optimized for recording instantaneous state hash values.

5. A trusted monitoring and auditing system integrating TEE and blockchain according to claim 1, characterized in that: The transaction processing module also includes an environment perception unit, which is used to obtain the original signal of the current physical environment state through at least one physical sensor deployed on the device that carries the trusted execution environment; the transaction processing module is also used to process the original signal into a standardized physical environment perturbation signature code; the physical environment perturbation signature code is included in the transaction instantaneous state summary, or is cryptographically associated with the transaction instantaneous state summary or its instantaneous state hash value, and then processed or signed by the trusted execution environment.

6. A trusted monitoring and auditing system integrating TEE and blockchain according to claim 1, characterized in that: The transaction processing module is configured to, when a transaction cluster having a preset execution order is formed by a plurality of predefined key transaction nodes in the processing system, generate a corresponding transaction transient state summary for any current transaction node other than the first in the transaction cluster within the trusted execution environment, and further to obtain a hash value of a preceding transaction transient state summary generated by a key transaction node immediately preceding the current transaction node in the transaction cluster; The hash value of the preceding transaction state summary is included in the current transaction state summary as the preceding anchor information; the on-chain anchoring module is configured to submit only the instantaneous state hash value of the transaction state summary generated by the last key transaction node in the transaction cluster, or the hash value of an aggregate summary representing the instantaneous state summaries of all transactions in the entire transaction cluster, to the blockchain network for recording.

7. A trusted monitoring and auditing system integrating TEE and blockchain according to claim 1, characterized in that: The audit verification module verifies the integrity of the transaction instantaneous state summary based on the following conditions: , in, Represents the hash value recalculated from the transaction instantaneous state summary obtained from the off-chain storage module; Represents the instantaneous state hash value of the target transaction obtained from the blockchain network.

8. A trusted monitoring and auditing system integrating TEE and blockchain according to claim 1, characterized in that: The audit verification module is configured to trigger a review or early warning mechanism for a transaction based on the indication of the physical environment perturbation signature code; the judgment conditions for the trigger threshold are: ,in, Indicates the abnormality level indicated by the physical environment perturbation signature code, Indicates the preset minimum abnormality level threshold that triggers the review or warning mechanism.

Citation Information

Patent Citations

  • Data storage method and device based on blockchain network, related equipment and medium

    CN111885050A

  • Software service process legality design method by referring to block chain signature technology

    CN112580109A

  • TEE-based privacy protection distributed account book auditing method and system

    CN114881650A

  • RPA robot process automation implementation method and system

    CN115422601A

  • Application operation environment detection method and device

    CN116956298A

Cited By

  • Cross-domain computing task processing method, program product, equipment and medium

    CN120856354A

  • Tax declaration data verification method based on block chain

    CN121190227A

  • Hierarchical collaborative optimization and settlement method for large-scale industrial demand response

    CN121352145A

  • A hierarchical collaborative optimization and settlement method for large-scale industrial demand response

    CN121352145B

  • Log management method and device, electronic equipment and computer program product

    CN121585480A