Government affair data security sharing method and system based on block chain technology

By using blockchain technology to construct multi-dimensional technical problems in e-government, and through semantic analysis and smart contract-driven strategies, multi-department chain-based collaborative processing of government data is achieved, solving the balance between data security and processing efficiency, and improving the user experience and efficiency of e-government.

CN120671196AActive Publication Date: 2025-09-19GUANGDONG CREATE TECH CO LTD

Patent Information

Application Number
CN202511181633.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-09-19
Estimated Expiration
2045-08-22

AI Technical Summary

Technical Problem

Existing e-government technologies cannot effectively ensure the balance between data security and government processing efficiency during data sharing between departments at different levels, resulting in poor public experience and affecting the progress of the popularization of e-government.

Method used

By adopting blockchain technology, semantic analysis is performed on user business processing information to accurately match the corresponding government affairs processing departments, build multi-level department chain information, and use smart contract-driven strategies to carry out multi-department chain collaborative processing, realizing encrypted anchored chain storage and cross-department data sharing.

Benefits of technology

It improves the security of data sharing between departments at different levels in the process of government affairs processing, ensures a good balance between data security and government affairs processing, improves user efficiency and experience, and promotes the process of e-government and the efficient allocation of social resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671196A_ABST
    Figure CN120671196A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data sharing security, in particular to a government affair data security sharing method and system based on a block chain technology. The method comprises the following steps: acquiring user service handling information, analyzing user service requirements according to the user service handling information, and determining target multi-level department chain information; according to the target multi-level department chain information, performing multi-level encryption anchoring uplink storage on the user service handling information, and determining service multi-level department chain information; and based on an intelligent contract driving strategy, according to the user service demand and the service multi-level department chain information, performing multi-department chain type cooperative processing on the user service demand, and determining and outputting a government affair processing result. According to the application, the data sharing security among different hierarchy departments in the government affair processing process is improved, good balance between data security and government affair processing is effectively guaranteed, the working efficiency and experience of users are improved, and the government affair electronization process and efficient configuration of social resources are promoted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data sharing security technology, and in particular to a method and system for securely sharing government data based on blockchain technology. Background Art

[0002] E-government, that is, the digital and intelligent transformation of government services, is an inevitable trend in the development of modern society. Through the e-government platform, repetitive work can be reduced, service time can be shortened, information asymmetry can be reduced, the interaction between the government and the public can be optimized, and the efficient allocation of social resources can be promoted.

[0003] However, existing e-government technologies are unable to effectively ensure a balance between data security and government processing efficiency during data sharing between departments at different levels, resulting in a poor public experience and a negative impact on the progress of the popularization of e-government. Summary of the Invention

[0004] This application provides a method and system for securely sharing government data based on blockchain technology to solve the above technical problems.

[0005] In a first aspect, the present application provides a method for securely sharing government data based on blockchain technology, the method comprising: Obtain user business processing information, analyze user business needs based on the user business processing information, and determine the target multi-level department chain information; According to the target multi-level department chain information, the user business processing information is multi-level encrypted and anchored on the chain for storage to determine the business multi-level department chain information; Based on the smart contract driven strategy, according to the user's business needs and the multi-level department chain information of the business, the user's business needs are processed in a multi-department chain collaborative manner to determine and output the government affairs processing results.

[0006] Through this solution, semantic analysis is performed on user business processing information, and the corresponding government affairs processing departments are accurately matched according to user business needs, and the target multi-level department chain information is constructed. In this way, the user business processing information is encrypted and anchored on the chain for storage, forming a multi-level department chain information of business. On this basis, the smart contract-driven strategy is used to conduct multi-department chain collaborative processing of user business needs, and the corresponding government affairs processing results are provided to users, thereby improving the data sharing security between departments at different levels in the government affairs processing process, effectively ensuring a good balance between data security and government affairs processing, improving user efficiency and experience, and promoting the electronic government affairs process and the efficient allocation of social resources.

[0007] Optionally, the user business processing information includes the user's unique identifier, biometric information, digital identity certificate, target business processing information and a list of submitted materials; The biometric information is identified through a liveness detection feature fusion algorithm integrated in the e-government all-in-one machine. The biometric information and the digital identity certificate are stored in each data node in the blockchain composed of relevant departments in the form of irreversible feature vector hash values.

[0008] Through this solution, user business processing information is constructed based on the user's unique identification, biometric information, digital identity certificate, target business information and submitted materials list, and the biometric information and digital identity certificate are stored in each data node in the blockchain composed of relevant departments in the form of irreversible feature vector hash values. A distributed user identity authentication mechanism based on blockchain technology is constructed to prevent the leakage of user identity due to single point failure or risk.

[0009] Optionally, analyzing the user's business needs based on the user's business handling information and determining target multi-level department chain information includes: Based on the preset administrative department node association information set, a tree-like topology diagram of administrative departments is constructed with the provincial node as the root node, the municipal node, district and county node, and township node as branch nodes, and the village and community node as the leaf node. Analyze the administrative department tree topology diagram based on the target business information and the list of submitted materials to determine the local tree topology structure of the business-related departments; Based on the biometric information and the digital identity certificate provided by the user, the biometric information and the digital identity certificate stored in each department node in the local tree topology structure of the business-related department are jointly verified. If the verification is successful, the user's unique identifier is used as an index, and the target multi-level department chain information is constructed according to the corresponding department nodes and node relationships in the local tree topology structure of the business-related department.

[0010] Through this solution, the tree topology data structure is used to accurately reflect the relationship between different departments, and a tree topology diagram of administrative departments is constructed. Combined with a local structure screening mechanism targeting business needs, the local tree topology structure of business-related departments that accurately corresponds to the user's business needs is extracted from the administrative department tree topology diagram. On this basis, the user identity is jointly verified according to the biometric vector and the digital certificate. If the verification is passed, the target multi-level department chain information is constructed to break down departmental barriers and avoid verification fragmentation, improve the collaborative processing efficiency of various departments, and provide accurate target department node information for subsequent data security protection in the government affairs processing process.

[0011] Optionally, performing multi-level encryption, anchoring, and chain storage on the user business processing information based on the target multi-level department chain information to determine the business multi-level department chain information includes: Separating the structured data from the unstructured data in the submitted materials list, and breaking the submitted materials list into independent data block sets corresponding to the departments at each level according to the business authority scope of the departments at different levels in the target multi-level department chain information; For each independent data block in the set of independent data blocks, calling the blockchain key generation module of the relevant department node at the corresponding level to generate a unique asymmetric key pair; The private key in the unique asymmetric key pair is encrypted and stored locally by the department node, and the public key in the unique asymmetric key pair is broadcast to the associated department nodes at adjacent levels through a preset key distribution channel; Based on the public key, dynamically hierarchically encrypt each of the independent data blocks to generate a plurality of hierarchically encrypted data packets with departmental hierarchical identifiers, and anchor the hash values ​​of the hierarchically encrypted data packets to the distributed ledger of the corresponding department node in the blockchain; Performing a cascade hash operation on the hash value of each layered encrypted data packet according to the department chain order in the target multi-level department chain information to generate a global data integrity check value, and storing the global data integrity check value in the genesis block of the blockchain to form an unalterable cross-departmental data association evidence chain; Based on the distributed ledger and the cross-departmental data association evidence chain, a cross-departmental data association verification mechanism and a dynamic data update strategy are introduced to construct the business multi-level department chain information.

[0012] Through this solution, by disassembling independent data blocks and hierarchical encryption, it is ensured that departments can only access the minimum data set required for approval, achieving "minimized data exposure" and reducing the risk of unauthorized access. Through the cascade hash and genesis block storage mechanism, a cross-departmental data association evidence chain is formed, so that any data tampering will trigger a global checksum value anomaly, avoiding abnormal tampering of data by a single department or multiple departments. By introducing a cross-departmental data association verification mechanism and a dynamic data update strategy, the corresponding business multi-level department chain information is constructed, further improving data sharing security.

[0013] Optionally, the cross-departmental data association verification mechanism includes: Constructing a data block index mapping table based on the node topology relationship in the target multi-level department chain information; Binding each of the layered encrypted data packets with the corresponding department node public key, generation timestamp and superior department verification identifier; Through the smart contract, the public keys of the adjacent department nodes stored on the chain are called to jointly sign the hash value of the encrypted data packet of the lower-level department to generate cross-department data consistency verification parameters.

[0014] Through this solution, the data block index mapping table can be used to trace the operation of each data packet accurately to the specific department node. The operation time, permission relationship and identity credentials are fused into an indivisible evidence unit through the three-in-one binding mechanism. The hash value corresponding to the encrypted data packet of the lower-level department is jointly signed using the joint signature mechanism to generate cross-department data consistency verification parameters. Through the cross-department data association verification mechanism, distributed verification of shared data among multiple departments is achieved, avoiding the systemic risks brought about by centralized verification strategies.

[0015] Optionally, the cross-departmental data association verification mechanism further includes: For the independent data block set involving joint approval by multiple departments, the public key of at least one upper-level department node is selected as a verification factor, and the combined hash value of the lower-level data block is twice encrypted to generate a composite digital envelope containing a hierarchical relationship; When any department node initiates a data call request, it must be collaboratively decrypted by department nodes with a preset verification factor number threshold or above in the composite digital envelope in order to obtain the associated verification parameters of the original data block.

[0016] Through this solution, by constructing a composite digital envelope, we can ensure that data that requires joint approval from multiple departments is under joint encryption protection during the circulation process. Even if attacked by advanced persistent threats, attackers cannot crack the private keys corresponding to multiple verification factors at the same time, significantly reducing the risk of data leakage. Through the verification factor threshold, multiple departments are forced to substantially participate in the joint approval process, eliminating the process irregularities caused by "formal counter-signing".

[0017] Optionally, the dynamic data update strategy includes: When the encrypted data stored in a department node at a certain level needs to be modified, the key rotation protocol is triggered. The department node generates a new generation of asymmetric key pairs and re-encrypts the modified data blocks using the new public key. Creating a data update transaction record in the blockchain, wherein the data update transaction record includes the original data block hash, the new data block hash, the key version number, and the data timestamp; According to the node hierarchical relationship in the target multi-level department chain information, the update notification is propagated upward step by step, and each upper-level department node performs chain requantization processing on the stored associated hash value according to the update notification; For data changes involving the coordination of multiple departments, a distributed consensus verification process is initiated: the department node that initiates the update sends a difference verification request to the adjacent level nodes. After collecting digital signatures from more than two-thirds of the associated nodes, the updated data hash value is appended to the original blockchain in the form of an incremental block, and the global data integrity check value is updated synchronously.

[0018] This solution utilizes a chain-based requantization mechanism to ensure that the data update process implements real-time cascade updates from lower-level nodes to higher-level nodes, eliminating the version split phenomenon of "the base layer has been modified, but the upper level is unknown", ensuring data consistency, and using a key rotation mechanism to form an independent cryptographic space for each data update, thereby improving data resistance to attacks and preventing single-point tampering risks through a distributed consensus verification mechanism.

[0019] Optionally, the smart contract-driven strategy performs multi-department chain collaborative processing on the user's business needs according to the user's business needs and the multi-level department chain information of the business, and determines and outputs the government affairs processing results, including: According to the department hierarchy sequence in the multi-level department chain information of the business, a chain processing state machine is preset in the smart contract. The chain processing state machine includes the business processing stage identifiers corresponding to the department nodes at each level and the trigger conditions for the flow between stages; When the user's business needs trigger the inter-stage flow triggering condition, an initial transaction processing token is generated according to the smart contract. The transaction processing token carries the user's unique identifier, the current business processing stage identifier, and the hash value of the completed department node processing result; According to the department hierarchy order, the transaction processing token is pushed to the corresponding department node step by step; Each relevant department node calls the corresponding independent data block in the layered encrypted data packet for decryption verification based on the business authority of the current level, and performs preset business rule verification on the decrypted data to generate a local processing result with the department's digital signature; When all levels of department nodes have completed processing, based on the smart contract, the local processing results returned by each node are aggregated, and the local processing results are cross-verified with the global data integrity check value to generate and output the government affairs processing results.

[0020] Through this solution, the chain state machine is utilized to automatically transfer the business processing process along the corresponding departmental hierarchical path, preventing chain breakage problems and improving the anti-breakpoint capability of the government service processing process. On this basis, the dual verification mechanism of the local result hash chain and the global checksum value is combined to ensure that tampering with shared data is exposed even if it occurs, thereby improving the security of shared data.

[0021] Optionally, the method further includes: If the smart contract identifies that the local processing result returned by the hierarchical department node conflicts with the preset business rules, a backtracking verification mechanism is triggered; The backtracking verification mechanism includes: Freeze the current state of the transaction token and generate a backtracking request event containing a conflict description; Broadcast the backtracking request event to the upstream processed department node and the associated supervisory node, requesting joint re-verification of the intermediate data of the historical processing link; When the verification signatures of more than half of the associated nodes are received, the frozen state of the transaction processing token is released and the current conflicting node is skipped to continue the flow; If the verification fails, the data correction process is triggered, the abnormal data block is marked as pending correction, and a transaction rollback instruction containing correction instructions is generated and pushed to the user. At the same time, the associated encrypted data packet hash value stored in the blockchain is deleted until the user resubmits compliant data and restarts the processing process.

[0022] Through this solution, when the local processing results conflict with the preset business rules, the retrospective verification mechanism is triggered. Through the joint re-verification process of multiple departments, it is determined whether to continue the flow. When the verification signatures of more than half of the related nodes are received, the business processing efficiency is improved by continuing the flow. If the verification fails, the data correction process is triggered to ensure the standardization of government processing procedures.

[0023] In a second aspect, the present application provides a government data security sharing system based on blockchain technology, the system comprising: The demand analysis module is used to obtain user business processing information, analyze user business needs based on the user business processing information, and determine the target multi-level department chain information; A multi-level anchoring module is used to perform multi-level encryption, anchoring and chain storage of the user business processing information according to the target multi-level department chain information, and determine the business multi-level department chain information; The collaborative processing module is used to perform multi-department chain collaborative processing on the user's business needs based on the smart contract-driven strategy and the multi-level department chain information of the business, and determine and output the government affairs processing results. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0025] Figure 1 A schematic diagram of an application scenario provided in one embodiment of the present application; Figure 2 A flowchart of a method for securely sharing government data based on blockchain technology provided in one embodiment of the present application; Figure 3A schematic diagram of the structure of a government data security sharing system based on blockchain technology provided in one embodiment of the present application. DETAILED DESCRIPTION

[0026] To make the purpose, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0027] In this document, the term "and / or" simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document, unless otherwise specified, generally indicates an "or" relationship between the related objects.

[0028] The embodiments of the present application are described in further detail below with reference to the accompanying drawings.

[0029] Existing e-government technologies are unable to effectively ensure a balance between data security and government processing efficiency during data sharing between departments at different levels, resulting in a poor public experience and a negative impact on the progress of the popularization of e-government.

[0030] Based on this, this application provides a method and system for secure sharing of government data based on blockchain technology. It performs semantic analysis on user business processing information, accurately matches the corresponding government processing departments according to user business needs, and constructs the target multi-level department chain information. This information is then encrypted and anchored on the chain for storage, forming a multi-level department chain information for business. On this basis, it utilizes smart contract-driven strategies to perform multi-department chain-style collaborative processing of user business needs, and provides the corresponding government processing results to users, thereby improving the data sharing security between departments at different levels during government processing, effectively ensuring a good balance between data security and government processing, improving user efficiency and experience, and promoting the electronicization of government affairs and the efficient allocation of social resources.

[0031] Figure 1 This is a schematic diagram of an application scenario provided by this application. In the process of electronic government affairs, the method provided by this application can effectively ensure a good balance between data security and government affairs processing, improve user efficiency and experience, and promote the progress of electronic government affairs and the efficient allocation of social resources.

[0032] Specifically, the method of the present application is applied to any server, which communicates with the e-government platform, obtains user behavior data provided by the e-government platform through the server, performs semantic analysis on user business processing information, accurately matches the corresponding government processing related departments according to user business needs, and constructs the target multi-level department chain information, thereby encrypting and anchoring the user business processing information on the chain for storage, forming a business multi-level department chain information, and on this basis, using the smart contract-driven strategy, performs multi-department chain collaborative processing on user business needs, and provides the corresponding government processing results to the user, thereby improving the data sharing security between departments at different levels in the government processing process, effectively ensuring a good balance between data security and government processing, improving user efficiency and experience, and promoting the electronic government process and the efficient allocation of social resources. For specific implementation methods, please refer to the following embodiments.

[0033] Figure 2 This is a flowchart of a method for securely sharing government data based on blockchain technology provided in one embodiment of this application. The method of this embodiment can be applied to the server in the above scenario. Figure 2 As shown, the method includes: S201. Obtain user business processing information, analyze user business needs based on the user business processing information, and determine target multi-level department chain information.

[0034] User business processing information can be a collection of government affairs processing materials submitted by users through the e-government platform.

[0035] User business needs can be core government affairs goals that users need to handle, which are obtained based on semantic analysis of user business handling information or based on user customized selections.

[0036] The target multi-level department chain information can be a department collaboration chain constructed according to the administrative level (province → city → district → township → village), reflecting the departments and hierarchical relationships that the business needs to reach.

[0037] Specifically, when facing cross-departmental government affairs processing needs, the existing electronic government affairs processing system has the problem of strong inter-departmental coordination lag, resulting in low efficiency in cross-level government affairs flow processing, and the data island problem between departments easily leads to users having to submit corresponding processing materials to multiple levels of departments respectively, resulting in lengthy government affairs processing processes and requiring a lot of time; based on blockchain technology, through the collection and automatic semantic analysis of user business processing information, user business needs are derived, and according to user business needs, the corresponding relevant departments are accurately matched, and the blockchain sub-chain composed of relevant department nodes that matches the current user needs is accurately located in the pre-built blockchain.

[0038] S202. Based on the target multi-level department chain information, the user business processing information is multi-level encrypted and anchored on the chain for storage to determine the business multi-level department chain information.

[0039] Multi-level encrypted anchored chain storage can be an operation in which the information submitted by users is disassembled and encrypted according to the corresponding relevant departments and anchored to the corresponding blockchain node.

[0040] The business multi-level department chain information can be a multi-level department chain chain that includes anchored data, a global verification mechanism, and a cross-department verification mechanism.

[0041] Specifically, in the process of collaborative government affairs processing, multi-level departments lack an efficient cross-department verification mechanism, which makes it difficult to detect potential unauthorized access behaviors in a timely manner, resulting in data security risks in the process of collaborative government affairs processing by multiple departments. According to the corresponding several relevant departments in the target multi-level department chain information, department correlation analysis is performed on user business processing information, and the user business processing information is disassembled and encrypted in blocks. The corresponding disassembled and encrypted information is anchored to the blockchain nodes corresponding to the relevant departments. Combined with the introduced global verification mechanism and cross-department verification mechanism, a multi-level department blockchain chain is constructed to avoid the problem of data islands while improving the security of the government data sharing process.

[0042] S203. Based on the smart contract driven strategy, according to the user's business needs and the multi-level department chain information of the business, the user's business needs are processed in a multi-department chain collaborative manner to determine and output the government affairs processing results.

[0043] Smart contract-driven policies can be pre-set automated government processing rules.

[0044] Multi-department chain collaborative processing can be a process of passing transaction tokens in departmental hierarchy order based on chain relationships, and performing business verification and processing at each level.

[0045] The government affairs processing result can be the processing result information obtained after the current blockchain chain performs chain-coordinated processing on the current government affairs processing needs and is pushed to the user.

[0046] Specifically, after clarifying the user's government affairs processing needs and the corresponding relevant processing departments, according to the pre-built smart contract rules (based on the standard processing procedures for government affairs business), through blockchain technology, using the blockchain links corresponding to the multi-level business department chain information, the user's business needs are processed in a multi-department chain-like collaborative manner. The blockchain nodes of the corresponding departments of the business exit integrate the government affairs processing results obtained after consensus is reached by each blockchain node, and the government affairs processing results are visualized through data visualization technology. The government affairs processing results are pushed to the corresponding users through the electronic government affairs integrated machine or user device terminal, so that users can grasp the processing progress in a timely manner.

[0047] Through this solution, semantic analysis is performed on user business processing information, and the corresponding government affairs processing departments are accurately matched according to user business needs, and the target multi-level department chain information is constructed. In this way, the user business processing information is encrypted and anchored on the chain for storage, forming a multi-level department chain information of business. On this basis, the smart contract-driven strategy is used to conduct multi-department chain collaborative processing of user business needs, and the corresponding government affairs processing results are provided to users, thereby improving the data sharing security between departments at different levels in the government affairs processing process, effectively ensuring a good balance between data security and government affairs processing, improving user efficiency and experience, and promoting the electronic government affairs process and the efficient allocation of social resources.

[0048] In some embodiments, user business processing information includes user unique identification, biometric information, digital identity certificate, target business information and a list of submitted materials; biometric information is identified through a liveness detection feature fusion algorithm integrated in the e-government all-in-one machine, and both biometric information and digital identity certificate are stored in the form of irreversible feature vector hash values ​​in each data node in the blockchain composed of relevant departments.

[0049] The user's unique identifier may be identification data used to refer to the current user's identity, such as an ID number.

[0050] Biometric information can be unique authentication data generated through a user's physiological characteristics (such as face, fingerprint, etc.).

[0051] A digital identity credential can be an electronic identity certificate issued by a government processing agency (such as a digital ID card, CA certificate).

[0052] The target business information may be the target business information that the user currently needs to handle.

[0053] The submitted materials list may be a collection of materials submitted by the user for handling the current business.

[0054] The e-government integrated machine can be an intelligent terminal device used to interact with users and collect user applications.

[0055] The liveness detection feature fusion algorithm can be a mathematical algorithm that integrates biometric information from different sources or modalities to improve the system's ability to distinguish real organisms from counterfeit attacks, such as Multi-modal CNN.

[0056] The irreversible feature vector hash value can be a unique string of fixed length obtained by converting the feature vector of biometric information or digital identity credentials through a cryptographic hash function (such as SHA-256 / SM3).

[0057] Data nodes can be distributed server nodes operated by departments at all levels, jointly maintaining the same ledger.

[0058] Specifically, in the process of government affairs processing, the identification of user identity is of vital importance. Through the user's unique identification, biometric information and digital identity certificate, the user identity is represented from the application dimension, biometric dimension and security dimension respectively, to achieve multi-dimensional identification of the user identity. The existing technology usually adopts a centralized database approach for the storage and identification of user identity, which has the risk of single point failure. Especially in the process of government affairs coordination and processing involving multiple departments, users need to submit key information representing their identity to different departments, which significantly increases the risk of identity information leakage. The user's biometric information is obtained by analyzing the liveness detection feature fusion algorithm integrated in the electronic government all-in-one machine, and this is used as the basis for extracting the user's digital identity certificate, and the user's biometric information and digital identity certificate are converted into irreversible feature vector hash values ​​using cryptographic hash functions, and the corresponding irreversible feature vector hash values ​​are stored in each data node in the blockchain composed of relevant departments, thereby constructing a distributed user identity authentication mechanism based on blockchain technology.

[0059] Through this solution, user business processing information is constructed based on the user's unique identification, biometric information, digital identity certificate, target business information and submitted materials list, and the biometric information and digital identity certificate are stored in each data node in the blockchain composed of relevant departments in the form of irreversible feature vector hash values. A distributed user identity authentication mechanism based on blockchain technology is constructed to prevent the leakage of user identity due to single point failure or risk.

[0060] In some embodiments, based on a preset administrative department node association information set, a tree topology diagram of administrative departments is constructed with provincial nodes as root nodes, municipal nodes, district and county nodes, and township nodes as branch nodes, and village and community nodes as leaf nodes; based on the target business information and the list of submitted materials, the administrative department tree topology diagram is analyzed to determine the local tree topology structure of the business-related departments; based on the biometric information and digital identity credentials provided by the user, the biometric information and digital identity credentials stored in each department node in the local tree topology structure of the business-related departments are jointly verified; if the verification is successful, the user's unique identifier is used as an index, and based on the corresponding department nodes and node relationships in the local tree topology structure of the business-related departments, the target multi-level department chain information is constructed.

[0061] The preset administrative department node association information set may be a structured data set that stores the hierarchical relationships of departments at all levels, including department affiliations, functional scope, and node unique codes.

[0062] The provincial node may be a data node used to refer to a provincial / municipal-level department.

[0063] The root node may be a starting node of a tree topology.

[0064] The city-level node may be a data node used to refer to a prefecture-level city-level department.

[0065] The district / county level node may be a data node used to refer to a county / district level department.

[0066] The township-level node may be a data node used to refer to a township / street-level department.

[0067] A branch node may be an intermediate node used to associate an upper-level node with a lower-level node in a tree topology structure.

[0068] The village-level node may be a data node used to refer to a village / community-level department.

[0069] A leaf node may be a data node located at the end of a branch in a tree topology structure and has no corresponding subordinate nodes.

[0070] The administrative department tree topology diagram may be structured data used to represent the hierarchical tree relationship between different departments.

[0071] The local tree topology structure of the business-related departments may be a subgraph structure of department nodes and associated paths directly related to the target business, extracted from the complete tree topology diagram.

[0072] Specifically, existing electronic government processing technologies face departmental barriers and verification fragmentation when faced with government affairs that require collaboration among multiple levels of departments. Specifically, it is difficult for dispersed department nodes to accurately and efficiently communicate and collaborate with their superior and subordinate nodes, and it is difficult to conduct cross-departmental joint verification when disputes arise. All node data is loaded from the preset administrative department node association information set. With the provincial node as the root, parent-child relationship edges are established in the hierarchical order of city → district → township → village to generate a complete administrative department tree topology diagram. The business type code corresponding to the target business information in the target business information is parsed (such as the "pension insurance transfer" code GB123). Combined with the submitting department mapped in the submitted materials list, the preset business-department mapping table is queried to extract the list of department nodes that need to participate. Based on the association relationship of the above department node list in the administrative department tree topology diagram, the local tree topology structure of the business-related departments is extracted. The collected biometric feature vectors and digital certificates are hashed separately, and a verification request is initiated to the blockchain ledger of each department node in the local topology structure: each node compares the received hash value with the pre-stored hash value stored in the node. If all nodes return verification as passed, the joint verification is determined to be successful. The user's unique identifier is used as the index, and the nodes in the local topology structure are sorted from high to low according to the department level to generate the target multi-level department chain information.

[0073] Through this solution, the tree topology data structure is used to accurately reflect the relationship between different departments, and a tree topology diagram of administrative departments is constructed. Combined with a local structure screening mechanism targeting business needs, the local tree topology structure of business-related departments that accurately corresponds to the user's business needs is extracted from the administrative department tree topology diagram. On this basis, the user identity is jointly verified according to the biometric vector and the digital certificate. If the verification is passed, the target multi-level department chain information is constructed to break down departmental barriers and avoid verification fragmentation, improve the collaborative processing efficiency of various departments, and provide accurate target department node information for subsequent data security protection in the government affairs processing process.

[0074] In some embodiments, the structured data and unstructured data in the submitted materials list are separated and processed, and the submitted materials list is disassembled into a set of independent data blocks corresponding to departments at each level according to the business authority scope of departments at different levels in the target multi-level department chain information; for each independent data block in the independent data block set, the blockchain key generation module of the relevant department node at the corresponding level is called to generate a unique asymmetric key pair; the private key in the unique asymmetric key pair is encrypted and stored locally by the department node, and the public key in the unique asymmetric key pair is broadcast to the related department nodes at the adjacent level through a preset key distribution channel; based on the public key, each independent data block in the independent data block set is encrypted and stored locally by the department node, and the public key in the unique asymmetric key pair is broadcast to the related department nodes at the adjacent level through a preset key distribution channel; based on the public key, the blockchain key generation module of the relevant department node at the corresponding level is called to generate a unique asymmetric key pair; the private key in the unique asymmetric key pair is encrypted and stored locally by the department node, and the public key in the unique asymmetric key pair is broadcast to the related department nodes at the adjacent level through a preset key distribution channel; based on the public key, the blockchain key generation module of the relevant department node at the corresponding level is called to generate a unique asymmetric key pair; ... blockchain key generation module of the blockchain key generation module The data blocks are dynamically hierarchically encrypted to generate several hierarchical encrypted data packets with departmental hierarchical identifications, and the hash values ​​of the hierarchical encrypted data packets are anchored to the distributed ledgers of the corresponding department nodes in the blockchain; the hash values ​​of each of the hierarchical encrypted data packets are subjected to cascade hash operations according to the departmental chain order in the target multi-level departmental chain information to generate a global data integrity check value, and the global data integrity check value is stored in the genesis block of the blockchain to form an unalterable cross-departmental data association evidence chain; based on the distributed ledger and the cross-departmental data association evidence chain, a cross-departmental data association verification mechanism and a dynamic data update strategy are introduced to construct the business multi-level departmental chain information.

[0075] Structured data can be data with a regular format in the list of submitted materials, such as ID number, social security number, etc.

[0076] Unstructured data can be data in irregular formats in the list of submitted materials, such as scanned documents, pictures, etc.

[0077] The scope of business authority may be the scope of administrative affairs processing authority of the corresponding relevant departments.

[0078] A set of independent data blocks is a set of encrypted units formed by breaking down the set according to the business authority of each department. Each data block only contains a subset of the submitted materials required for approval by a single department.

[0079] The blockchain key generation module can be a functional module that encrypts data blocks based on an asymmetric encryption algorithm.

[0080] The unique asymmetric key pair may be an asymmetric key pair generated according to an asymmetric encryption algorithm, including a private key and a public key.

[0081] A private key may be the key in a key pair that is held and controlled only by the owner.

[0082] A public key is a key that can be freely distributed publicly, does not need to be kept secret, and is available to anyone.

[0083] Local encrypted storage can be the process of encrypting and storing data within a department's data node.

[0084] The preset key distribution channel can be a communication path preset in the blockchain for securely transmitting encryption keys, and a communication path between nodes can be established through the TLS / SSL protocol.

[0085] The associated department node may be another node that has a superior-subordinate relationship with the current department node.

[0086] Dynamic layered encryption can be a process of encrypting a set of independent data blocks at the department level as a layered unit.

[0087] The layered encrypted data packet may be an encrypted data unit carrying a departmental level identifier, which is generated by encrypting an original data block with a public key.

[0088] The department level identifier may be identifying information used to refer to the current department and the level to which it belongs (such as "Municipal-Social Security Bureau").

[0089] A distributed ledger can be a database in a blockchain that is jointly maintained, tamper-proof, and transparently shared by all participants.

[0090] The cascade hash operation can be a calculation process of recursively concatenating the hash values ​​of adjacent data packets in the order of the department chain and then rehashing them.

[0091] The global data integrity check value can be the final output value of the cascade hash operation, serving as the only proof of the data association of the entire chain.

[0092] The genesis block can be the starting block created by the blockchain, serving as the only starting point and trust anchor point of the entire chain data structure.

[0093] The cross-departmental data association evidence chain can be a tamper-proof data association system composed of hierarchical hash anchors in the distributed ledger and the global checksum value of the genesis block.

[0094] The cross-departmental data association verification mechanism can be a logical rule that automatically verifies the consistency of multi-department data through smart contracts.

[0095] A dynamic data update strategy can be a key rotation and hash recalculation protocol that is triggered when encrypted data needs to be revised.

[0096] Specifically, the existing government data sharing adopts the method of encrypting all data and uploading it to the chain, which may cause low-level department nodes to be exposed to highly sensitive data beyond their approval scope, and irrelevant data increases the decryption burden. Departments need to filter out valid content from redundant information; by parsing the submitted material list, the structured data (ID number, social security code) is stored in the JSON template, and the unstructured data (scanned copy of the real estate certificate) is converted into a binary stream. According to the target multi-level department chain information (such as "Provincial Human Resources and Social Security Department-Municipal Social Security Bureau-District Service Center"), the authority mapping table is called, and independent data blocks are disassembled based on the department's business authority scope to obtain a set of independent data blocks to achieve "minimized data exposure"; for each independent data block, the key engine of the corresponding department node is called to generate an SM2 asymmetric key pair, where the private key is stored in the department's local security area through the HSM encryption module, and the public key is broadcast to the adjacent level nodes through the government dedicated network. The data block is encrypted using the received public key to generate a layered encrypted data packet with a hierarchical label, and each encrypted data packet is input into the SHA-256 hash. The hasher generates a unique summary value (such as "a1b2c3..."), and writes the summary value into the distributed ledger of the corresponding department node through the anchor smart contract; further, if the decentralized encrypted data packet lacks a mandatory association mechanism, it will cause a single department to tamper with the local data and be unable to quickly locate the abnormality of the associated node, which will significantly increase the time cost of tracing the joint operation of multiple departments. Therefore, cascade hashing is performed according to the order of different relevant departments in the chain: the first-level hash value H0=Hash(village level package), the second-level hash value H1=Hash(H0+township level package), the second-level hash value H2=Hash(H1+district and county level package), and the third-level hash value H3=Hash(H2+city level package); the final-level hash value H_global=Hash(H3+provincial level package), and the final-level hash value is used as the global data integrity check value and stored in the genesis block to form a cross-department data association evidence chain; on this basis, the cross-department data association verification mechanism and dynamic data update strategy are introduced respectively to construct the corresponding business multi-level department chain information.

[0097] Through this solution, by disassembling independent data blocks and hierarchical encryption, it is ensured that departments can only access the minimum data set required for approval, achieving "minimized data exposure" and reducing the risk of unauthorized access. Through the cascade hash and genesis block storage mechanism, a cross-departmental data association evidence chain is formed, so that any data tampering will trigger a global checksum value anomaly, avoiding abnormal tampering of data by a single department or multiple departments. By introducing a cross-departmental data association verification mechanism and a dynamic data update strategy, the corresponding business multi-level department chain information is constructed, further improving data sharing security.

[0098] In some embodiments, a data block index mapping table is constructed based on the node topology relationship in the target multi-level department chain information; each layered encrypted data packet is bound to the corresponding department node public key, generation timestamp and upper-level department verification identifier; the adjacent department node public key stored on the chain is called through a smart contract, and the hash value of the lower-level department encrypted data packet is jointly signed to generate cross-department data consistency verification parameters.

[0099] Node topology relationships can be structured data that describes the affiliation between nodes in a multi-level department chain, such as the association path between a parent node (provincial level) and a child node (municipal level).

[0100] The data block index mapping table may be a metadata table that records the topological relationship between the layered encrypted data packets and the department nodes.

[0101] The department node public key may be an asymmetric encryption public key generated by the department node, which is used for data encryption and signature verification.

[0102] The adjacent department node public key may be a department node public key that is directly topologically associated with the current node.

[0103] The generation timestamp can be an authoritative time record of the moment the packet was created (with UTC millisecond accuracy).

[0104] The superior department verification identifier may be a unique verification code issued by the superior department node, representing the review authorization of the subordinate data packet.

[0105] Joint signature can be an operation in which multiple department nodes use private keys to jointly sign the same data hash value.

[0106] The cross-department data consistency verification parameter may be a verification credential set including a joint signature result, participating node IDs, and a time stamp.

[0107] Specifically, cross-departmental data verification in the existing technology relies on centralized institutions (such as government big data centers) to act as trust intermediaries, which means that once the central institution fails or is attacked, the verification process will be paralyzed, and the responsible node cannot be accurately located when there are disputes over operations among multiple departments; based on the node topology relationship in the target multi-level department chain information, a unique index entry is generated for each layered encrypted data packet, and a metadata tag is added to each layered encrypted data packet: the generation timestamp is obtained by calling the timing center API, a digital signature is applied for from the directly superior department, a verification identifier of the superior department is generated, and the MD5 fingerprint of the public key of the department is extracted, the hash value of the subordinate data packet is received through the smart contract, the public keys of adjacent nodes stored on the chain are automatically retrieved, and a multi-party collaborative signature process is triggered. The superior department signs the signature information of the subordinate department for a second time, and so on, and the final signature information is used as the cross-departmental data consistency verification parameter.

[0108] Through this solution, the data block index mapping table can be used to trace the operation of each data packet accurately to the specific department node. The operation time, permission relationship and identity credentials are fused into an indivisible evidence unit through the three-in-one binding mechanism. The hash value corresponding to the encrypted data packet of the lower-level department is jointly signed using the joint signature mechanism to generate cross-department data consistency verification parameters. Through the cross-department data association verification mechanism, distributed verification of shared data among multiple departments is achieved, avoiding the systemic risks brought about by centralized verification strategies.

[0109] In some embodiments, for a set of independent data blocks involving joint approval by multiple departments, the public key of at least one upper-level department node is selected as a verification factor, and the combined hash value of the lower-level data blocks is encrypted twice to generate a composite digital envelope containing a hierarchical relationship; when any department node initiates a data call request, it must be collaboratively decrypted by department nodes with a preset verification factor number threshold in the composite digital envelope in order to obtain the associated verification parameters of the original data block.

[0110] Multi-department joint approval can be a business approval process that requires the participation of two or more departments.

[0111] The verification factor may be a superior department public key certificate used to decrypt the composite digital envelope.

[0112] The combined hash value may be a root hash value generated by aggregating hash values ​​of multiple subordinate data blocks through a Merkle tree.

[0113] The composite digital envelope can be a secure container containing the encrypted combined hash value, the verification factor list, and the hierarchical identifier.

[0114] A data call request can be a data sharing demand from one department node to another department node.

[0115] The preset verification factor number threshold may be the minimum number of cooperating departments required for decryption.

[0116] Department node collaborative decryption can be an operation in which multiple verification factor holding departments use private keys to jointly decrypt.

[0117] The associated verification parameter may be the verification credential of the original data block obtained after decryption.

[0118] Specifically, when dealing with businesses that require joint approval from multiple departments, existing technologies have the risk of "the lead department's approval influence being too great", and the data security risk in the process of shared data flowing between different departments is significantly increased; through smart contracts, the joint approval tags of multiple departments are identified, and a set of related independent data blocks are extracted to construct a Merkle tree to calculate the combined hash value, and the public key of at least one superior department node is selected as the verification factor. The current combined hash value is encrypted twice through the SM2 encryption algorithm to generate a composite digital envelope. When any department node initiates a data call request, it needs to send a collaborative decryption request to the number of departments corresponding to the preset verification factor threshold. After the above-mentioned departments complete the collaborative decryption operation, the department node that currently initiates the data call request can obtain the associated verification parameters of the original data block.

[0119] Through this solution, by constructing a composite digital envelope, we can ensure that data that requires joint approval from multiple departments is under joint encryption protection during the circulation process. Even if attacked by advanced persistent threats, attackers cannot crack the private keys corresponding to multiple verification factors at the same time, significantly reducing the risk of data leakage. Through the verification factor threshold, multiple departments are forced to substantially participate in the joint approval process, eliminating the process irregularities caused by "formal counter-signing".

[0120] In some embodiments, when the encrypted data stored in a department node at a certain level needs to be modified in content, a key rotation protocol is triggered, and the department node generates a new generation of asymmetric key pairs and uses the new public key to re-encrypt the modified data block; a data update transaction record is created in the blockchain, and the data update transaction record includes the original data block hash, the new data block hash, the key version number and the data timestamp; according to the node hierarchy relationship in the target multi-level department chain information, the update notification is propagated upward step by step, and each upper-level department node performs chain re-quantization on the stored associated hash value according to the update notification; for data changes involving multi-department linkage, a distributed consensus verification process is started: the department node initiating the update sends a difference verification request to the adjacent level nodes, and after collecting the digital signatures of more than two-thirds of the associated nodes, the updated data hash value is appended to the original blockchain in the form of an incremental block, and the global data integrity check value is updated synchronously.

[0121] A key rotation protocol can be a standard process for periodically replacing encryption keys to ensure data security.

[0122] The new generation asymmetric key pair can be a public-private key combination newly generated using the SM2 algorithm.

[0123] Data update transaction records can be blockchain data certificates that record the data change process.

[0124] The hash of the original data block may be a SHA-256 digest value of the data block before modification.

[0125] The new data block hash may be a SHA-256 digest value of the amended data block.

[0126] The key version number can be a sequential number that identifies the key iteration number (such as "VER_2.1").

[0127] The data timestamp may be authoritative timestamp data of when the data update occurs.

[0128] Chain requantization processing can be an operation in which the upper-level department nodes update the associated hash values ​​in hierarchical order.

[0129] The distributed consensus verification process can be a collaborative verification process of data differences among distributed department nodes.

[0130] The difference verification request may be a request for comparing the difference between new and old data.

[0131] Incremental blocks can be lightweight blockchain units that only record data changes.

[0132] Specifically, based on the data collaborative verification mechanism, when the data under the same processing business changes, the corresponding data in the chain composed of the corresponding relevant departments needs to be dynamically associated and updated to ensure data consistency and avoid the problems of "island-style changes", "trust gaps" and "collaboration deadlocks"; when the encrypted data stored in the node of a certain level of department needs to be modified, the key rotation protocol is triggered, the asymmetric encryption algorithm is called, a new generation of asymmetric key pairs is generated, and the modified data block is re-encrypted. The new private key is locally encrypted and stored, and a data update transaction record is generated, recording the original data block hash, new data block hash, key version number and data timestamp to provide data support for data change traceability. The modification of the above data block will be passed up the chain level by level in the form of update notification to realize chain re-quantization processing, and the distributed formula verification mechanism is used to constrain the process of data changes involving multi-department linkage. The department node initiating the update is required to append the updated data to the original blockchain after collecting the digital signatures of more than two-thirds of the related nodes, and simultaneously update the global data integrity check value to prevent the problem of single point tampering.

[0133] This solution utilizes a chain-based requantization mechanism to ensure that the data update process implements real-time cascade updates from lower-level nodes to higher-level nodes, eliminating the version split phenomenon of "the base layer has been modified, but the upper level is unknown", ensuring data consistency, and using a key rotation mechanism to form an independent cryptographic space for each data update, thereby improving data resistance to attacks and preventing single-point tampering risks through a distributed consensus verification mechanism.

[0134] In some embodiments, a chain processing state machine is preset in the smart contract based on the department hierarchy order in the business multi-level department chain information. The chain processing state machine contains the business processing stage identifiers and inter-stage flow trigger conditions corresponding to the department nodes at each level; when the user's business needs trigger the inter-stage flow trigger conditions, an initial transaction processing token is generated according to the smart contract. The transaction processing token carries the user's unique identifier, the current business processing stage identifier and the completed department node processing result hash value; according to the department hierarchy order, the transaction processing token is pushed to the corresponding department node step by step; each relevant department node calls the corresponding independent data block in the layered encrypted data packet for decryption verification based on the business authority of this level, and performs preset business rule verification on the decrypted data to generate a local processing result with the department digital signature; when the processing of department nodes at all levels is completed, the local processing results returned by each node are aggregated based on the smart contract, and the local processing results are cross-verified with the global data integrity check value to generate and output the government affairs processing results.

[0135] The chain processing state machine can be a departmental business flow logic controller preset in the smart contract.

[0136] The business processing stage identifier can be a code that marks the current processing link (for example, "STAGE_TAX_VERIFY" indicates the tax verification stage).

[0137] The trigger conditions for inter-stage transfers can be rules that drive the flow of transactions across departments.

[0138] A transaction token may be a secure digital certificate that carries transaction context.

[0139] The processing result hash value may be a hash value used to verify whether the processing result has been tampered with.

[0140] The preset business rule verification can be the compliance check logic preset in the smart contract.

[0141] The local processing result can be the business output of a single department node.

[0142] Cross-validation can be an automated verification process that compares local results with global credentials.

[0143] Specifically, in the existing multi-department collaborative government affairs processing process, chain breaks are prone to occur, leading to the collapse of the collaborative processing process; the multi-level department chain of the business is loaded through the smart contract to create a chain processing state machine, where the chain processing state machine contains stage identification and stage flow conditions. When the user's business needs trigger the flow trigger conditions between stages, the initial transaction processing token is generated according to the smart contract, and the business is called with the corresponding business authority of each department according to the department hierarchy order. The transaction processing tokens carried by different departments are used to perform chain hierarchical flow decryption processing on the business, and local processing results with digital signatures of each department are generated. The local processing results are cross-verified with the global data integrity check value. After the verification is passed, the corresponding government affairs processing results are generated through the aggregated visualization processing of different local processing results.

[0144] Through this solution, the chain state machine is utilized to automatically transfer the business processing process along the corresponding departmental hierarchical path, preventing chain breakage problems and improving the anti-breakpoint capability of the government service processing process. On this basis, the dual verification mechanism of the local result hash chain and the global checksum value is combined to ensure that tampering with shared data is exposed even if it occurs, thereby improving the security of shared data.

[0145] In some embodiments, if the smart contract identifies that the local processing results returned by the hierarchical department node conflict with the preset business rules, a backtracking verification mechanism is triggered; the backtracking verification mechanism includes: freezing the circulation status of the current transaction processing token, generating a backtracking request event containing a conflict description; broadcasting the backtracking request event to the upstream processed department node and the associated supervisory node, requesting joint re-verification of the intermediate data of the historical processing link; when the verification signature of more than half of the associated nodes is received, the frozen state of the transaction processing token is released and the current conflicting node is skipped to continue the circulation; if the verification fails, the data correction process is triggered, the abnormal data block is marked as to be corrected, and a transaction rollback instruction containing correction instructions is generated and pushed to the user, and the associated encrypted data packet hash value stored in the blockchain is deleted at the same time until the user resubmits the compliant data and restarts the processing process.

[0146] The preset business rules may be government affairs processing rules in the business standard processing specifications.

[0147] The retrospective verification mechanism can be a cross-level joint review process triggered when data conflicts occur.

[0148] The flow status can be a transfer status mark of the transaction token between department nodes.

[0149] The conflict description may be description information pointing to the conflict between the current business process and the standard business process.

[0150] The backtracking request event may be a data re-verification trigger instruction including conflict details.

[0151] The processed department node may be a department node that has processed the business before the current conflict node.

[0152] The associated supervisory node may be a data node corresponding to an independent organization with audit authority.

[0153] The historical processing link can be the processing process information of the processed department nodes.

[0154] Joint revalidation can be a process of revalidating data by multiple departments.

[0155] The conflict node may be a department node where the business processing rule situation currently occurs.

[0156] The correction guide may be information suggesting corrections to conflicting rules.

[0157] Compliant data may be data that complies with standard business processing rules.

[0158] Specifically, in the process of multiple departments jointly handling government affairs, there may be a situation where some data conflicts with some node processing rules due to non-standard data submitted by users. When this happens, the backtracking verification mechanism is triggered to freeze the circulation status of the current transaction processing token to prevent the further spread of the faulty node and pollute the processing results of other departments. On this basis, according to the partial conflict rule information obtained by matching, a backtracking request event containing a conflict description is generated, and the backtracking request event is broadcast to the upstream processed department nodes and associated supervision nodes through the data sharing channel. According to the cross-departmental data association verification mechanism, the intermediate data is jointly reviewed by multiple departments. Verification: When verification signatures are received from more than half of the associated nodes, it means that the current conflict situation has a small impact and the impact is relatively independent. In order to ensure efficiency, the transaction processing token is unfrozen and the current conflict node is skipped to continue the flow. After the flow is completed, the user can submit some modified materials. If the verification fails, it means that the current conflict situation has a small impact and has a chain effect. The abnormal data block is marked as pending correction, and a transaction rollback instruction containing correction instructions is generated and pushed to the user. At the same time, the associated encrypted data packet hash value stored in the blockchain is deleted until the user resubmits the compliant data and restarts the processing flow to ensure the standardization of government processing procedures.

[0159] Through this solution, when the local processing results conflict with the preset business rules, the retrospective verification mechanism is triggered. Through the joint re-verification process of multiple departments, it is determined whether to continue the flow. When the verification signatures of more than half of the related nodes are received, the business processing efficiency is improved by continuing the flow. If the verification fails, the data correction process is triggered to ensure the standardization of government processing procedures.

[0160] Figure 3 A schematic diagram of a government data security sharing system based on blockchain technology is provided in one embodiment of the present application. Figure 3 As shown, a government data security sharing system 300 based on blockchain technology in this embodiment includes: a demand analysis module 301, a multi-level anchoring module 302 and a collaborative processing module 303.

[0161] The demand analysis module 301 is used to obtain user business processing information, analyze user business needs based on the user business processing information, and determine target multi-level department chain information; The multi-level anchoring module 302 is used to perform multi-level encryption, anchoring and chain storage of the user business processing information according to the target multi-level department chain information, and determine the business multi-level department chain information; The collaborative processing module 303 is used to perform multi-department chain collaborative processing on the user's business needs based on the smart contract-driven strategy and the multi-level department chain information of the business, and determine and output the government affairs processing results.

[0162] Optionally, in the demand analysis module 301, the user business processing information includes the user's unique identifier, biometric information, digital identity certificate, target business processing information, and a list of submitted materials; The biometric information is identified through a liveness detection feature fusion algorithm integrated in the e-government all-in-one machine. The biometric information and the digital identity certificate are stored in each data node in the blockchain composed of relevant departments in the form of irreversible feature vector hash values.

[0163] Optionally, the demand analysis module 301 is specifically configured to: Based on the preset administrative department node association information set, a tree-like topology diagram of administrative departments is constructed with the provincial node as the root node, the municipal node, district and county node, and township node as branch nodes, and the village and community node as the leaf node. Analyze the administrative department tree topology diagram based on the target business information and the list of submitted materials to determine the local tree topology structure of the business-related departments; Based on the biometric information and the digital identity certificate provided by the user, the biometric information and the digital identity certificate stored in each department node in the local tree topology structure of the business-related department are jointly verified. If the verification is successful, the user's unique identifier is used as an index, and the target multi-level department chain information is constructed according to the corresponding department nodes and node relationships in the local tree topology structure of the business-related department.

[0164] Optionally, the multi-level anchoring module 302 is specifically configured to: Separating the structured data from the unstructured data in the submitted materials list, and breaking the submitted materials list into independent data block sets corresponding to the departments at each level according to the business authority scope of the departments at different levels in the target multi-level department chain information; For each independent data block in the set of independent data blocks, calling the blockchain key generation module of the relevant department node at the corresponding level to generate a unique asymmetric key pair; The private key in the unique asymmetric key pair is encrypted and stored locally by the department node, and the public key in the unique asymmetric key pair is broadcast to the associated department nodes at adjacent levels through a preset key distribution channel; Based on the public key, dynamically hierarchically encrypt each of the independent data blocks to generate a plurality of hierarchically encrypted data packets with departmental hierarchical identifiers, and anchor the hash values ​​of the hierarchically encrypted data packets to the distributed ledger of the corresponding department node in the blockchain; Performing a cascade hash operation on the hash value of each layered encrypted data packet according to the department chain order in the target multi-level department chain information to generate a global data integrity check value, and storing the global data integrity check value in the genesis block of the blockchain to form an unalterable cross-departmental data association evidence chain; Based on the distributed ledger and the cross-departmental data association evidence chain, a cross-departmental data association verification mechanism and a dynamic data update strategy are introduced to construct the business multi-level department chain information.

[0165] Optionally, in the multi-level anchoring module 302, the cross-department data association verification mechanism is used to: Constructing a data block index mapping table based on the node topology relationship in the target multi-level department chain information; Binding each of the layered encrypted data packets with the corresponding department node public key, generation timestamp and superior department verification identifier; Through the smart contract, the public keys of the adjacent department nodes stored on the chain are called to jointly sign the hash value of the encrypted data packet of the lower-level department to generate cross-department data consistency verification parameters.

[0166] Optionally, in the multi-level anchoring module 302, the cross-department data association verification mechanism is specifically used to: For the independent data block set involving joint approval by multiple departments, the public key of at least one upper-level department node is selected as a verification factor, and the combined hash value of the lower-level data block is twice encrypted to generate a composite digital envelope containing a hierarchical relationship; When any department node initiates a data call request, it must be collaboratively decrypted by department nodes with a preset verification factor number threshold or above in the composite digital envelope in order to obtain the associated verification parameters of the original data block.

[0167] Optionally, in the multi-level anchoring module 302, the dynamic data update strategy is specifically used to: When the encrypted data stored in a department node at a certain level needs to be modified, the key rotation protocol is triggered. The department node generates a new generation of asymmetric key pairs and re-encrypts the modified data blocks using the new public key. Creating a data update transaction record in the blockchain, wherein the data update transaction record includes the original data block hash, the new data block hash, the key version number, and the data timestamp; According to the node hierarchical relationship in the target multi-level department chain information, the update notification is propagated upward step by step, and each upper-level department node performs chain requantization processing on the stored associated hash value according to the update notification; For data changes involving the coordination of multiple departments, a distributed consensus verification process is initiated: the department node that initiates the update sends a difference verification request to the adjacent level nodes. After collecting digital signatures from more than two-thirds of the associated nodes, the updated data hash value is appended to the original blockchain in the form of an incremental block, and the global data integrity check value is updated synchronously.

[0168] Optionally, the collaborative processing module 303 is specifically configured to: According to the department hierarchy sequence in the multi-level department chain information of the business, a chain processing state machine is preset in the smart contract. The chain processing state machine includes the business processing stage identifiers corresponding to the department nodes at each level and the trigger conditions for the flow between stages; When the user's business needs trigger the inter-stage flow triggering condition, an initial transaction processing token is generated according to the smart contract. The transaction processing token carries the user's unique identifier, the current business processing stage identifier, and the hash value of the completed department node processing result; According to the department hierarchy order, the transaction processing token is pushed to the corresponding department node step by step; Each relevant department node calls the corresponding independent data block in the layered encrypted data packet for decryption verification based on the business authority of the current level, and performs preset business rule verification on the decrypted data to generate a local processing result with the department's digital signature; When all levels of department nodes have completed processing, based on the smart contract, the local processing results returned by each node are aggregated, and the local processing results are cross-verified with the global data integrity check value to generate and output the government affairs processing results.

[0169] Optionally, the system further includes a retrospective verification module 304, specifically configured to: If the smart contract identifies that the local processing result returned by the hierarchical department node conflicts with the preset business rules, a backtracking verification mechanism is triggered; The backtracking verification mechanism includes: Freeze the current state of the transaction token and generate a backtracking request event containing a conflict description; Broadcast the backtracking request event to the upstream processed department node and the associated supervisory node, requesting joint re-verification of the intermediate data of the historical processing link; When the verification signatures of more than half of the associated nodes are received, the frozen state of the transaction processing token is released and the current conflicting node is skipped to continue the flow; If the verification fails, the data correction process is triggered, the abnormal data block is marked as pending correction, and a transaction rollback instruction containing correction instructions is generated and pushed to the user. At the same time, the associated encrypted data packet hash value stored in the blockchain is deleted until the user resubmits compliant data and restarts the processing process.

[0170] The system of this embodiment can be used to execute the method of any of the above embodiments. Its implementation principles and technical effects are similar and will not be described in detail here.

Claims

1. A method for securely sharing government data based on blockchain technology, characterized in that: include: Obtain user business processing information, analyze user business needs based on the user business processing information, and determine the target multi-level department chain information; According to the target multi-level department chain information, the user business processing information is multi-level encrypted and anchored on the chain for storage to determine the business multi-level department chain information; Based on the smart contract driven strategy, according to the user's business needs and the multi-level department chain information of the business, the user's business needs are processed in a multi-department chain collaborative manner to determine and output the government affairs processing results.

2. The method according to claim 1, characterized in that The user business processing information includes the user's unique identification, biometric information, digital identity certificate, target business processing information and a list of submitted materials; The biometric information is identified through a liveness detection feature fusion algorithm integrated in the e-government all-in-one machine. The biometric information and the digital identity certificate are stored in each data node in the blockchain composed of relevant departments in the form of irreversible feature vector hash values.

3. The method according to claim 2, characterized in that Analyzing user business needs based on the user business processing information and determining target multi-level department chain information includes: Based on the preset administrative department node association information set, a tree-like topology diagram of administrative departments is constructed with the provincial node as the root node, the municipal node, district and county node, and township node as branch nodes, and the village and community node as the leaf node. Analyze the administrative department tree topology diagram based on the target business information and the list of submitted materials to determine the local tree topology structure of the business-related departments; Based on the biometric information and the digital identity certificate provided by the user, the biometric information and the digital identity certificate stored in each department node in the local tree topology structure of the business-related department are jointly verified. If the verification is successful, the user's unique identifier is used as an index, and the target multi-level department chain information is constructed according to the corresponding department nodes and node relationships in the local tree topology structure of the business-related department.

4. The method according to claim 3, characterized in that According to the target multi-level department chain information, the user business processing information is multi-level encrypted and anchored on the chain for storage, and the business multi-level department chain information is determined, including: Separating the structured data from the unstructured data in the submitted materials list, and breaking the submitted materials list into independent data block sets corresponding to the departments at each level according to the business authority scope of the departments at different levels in the target multi-level department chain information; For each independent data block in the set of independent data blocks, calling the blockchain key generation module of the relevant department node at the corresponding level to generate a unique asymmetric key pair; The private key in the unique asymmetric key pair is encrypted and stored locally by the department node, and the public key in the unique asymmetric key pair is broadcast to the associated department nodes at adjacent levels through a preset key distribution channel; Based on the public key, dynamically hierarchically encrypt each of the independent data blocks to generate a plurality of hierarchically encrypted data packets with departmental hierarchical identifiers, and anchor the hash values ​​of the hierarchically encrypted data packets to the distributed ledger of the corresponding department node in the blockchain; Performing a cascade hash operation on the hash value of each layered encrypted data packet according to the department chain order in the target multi-level department chain information to generate a global data integrity check value, and storing the global data integrity check value in the genesis block of the blockchain to form an unalterable cross-departmental data association evidence chain; Based on the distributed ledger and the cross-departmental data association evidence chain, a cross-departmental data association verification mechanism and a dynamic data update strategy are introduced to construct the business multi-level department chain information.

5. The method according to claim 4, characterized in that The cross-departmental data association verification mechanism includes: Constructing a data block index mapping table based on the node topology relationship in the target multi-level department chain information; Binding each of the layered encrypted data packets with the corresponding department node public key, generation timestamp and superior department verification identifier; Through the smart contract, the public keys of the adjacent department nodes stored on the chain are called to jointly sign the hash value of the encrypted data packet of the lower-level department to generate cross-department data consistency verification parameters.

6. The method according to claim 5, characterized in that The cross-departmental data association verification mechanism also includes: For the independent data block set involving joint approval by multiple departments, the public key of at least one upper-level department node is selected as a verification factor, and the combined hash value of the lower-level data block is twice encrypted to generate a composite digital envelope containing a hierarchical relationship; When any department node initiates a data call request, it must be collaboratively decrypted by department nodes with a preset verification factor number threshold or above in the composite digital envelope in order to obtain the associated verification parameters of the original data block.

7. The method according to claim 5, characterized in that The dynamic data update strategy includes: When the encrypted data stored in a department node at a certain level needs to be modified, the key rotation protocol is triggered. The department node generates a new generation of asymmetric key pairs and re-encrypts the modified data blocks using the new public key. Creating a data update transaction record in the blockchain, wherein the data update transaction record includes the original data block hash, the new data block hash, the key version number, and the data timestamp; According to the node hierarchical relationship in the target multi-level department chain information, the update notification is propagated upward step by step, and each upper-level department node performs chain requantization processing on the stored associated hash value according to the update notification; For data changes involving the coordination of multiple departments, a distributed consensus verification process is initiated: the department node that initiates the update sends a difference verification request to the adjacent level nodes. After collecting digital signatures from more than two-thirds of the associated nodes, the updated data hash value is appended to the original blockchain in the form of an incremental block, and the global data integrity check value is updated synchronously.

8. The method according to claim 7, characterized in that The smart contract-driven strategy performs multi-department chain collaborative processing on the user's business needs according to the user's business needs and the multi-level department chain information of the business, and determines and outputs the government affairs processing results, including: According to the department hierarchy sequence in the multi-level department chain information of the business, a chain processing state machine is preset in the smart contract. The chain processing state machine includes the business processing stage identifiers corresponding to the department nodes at each level and the trigger conditions for the flow between stages; When the user's business needs trigger the inter-stage flow triggering condition, an initial transaction processing token is generated according to the smart contract. The transaction processing token carries the user's unique identifier, the current business processing stage identifier, and the hash value of the completed department node processing result; According to the department hierarchy order, the transaction processing token is pushed to the corresponding department node step by step; Each relevant department node calls the corresponding independent data block in the layered encrypted data packet for decryption verification based on the business authority of the current level, and performs preset business rule verification on the decrypted data to generate a local processing result with the department's digital signature; When all levels of department nodes have completed processing, based on the smart contract, the local processing results returned by each node are aggregated, and the local processing results are cross-verified with the global data integrity check value to generate and output the government affairs processing results.

9. The method according to claim 8, characterized in that The method further comprises: If the smart contract identifies that the local processing result returned by the hierarchical department node conflicts with the preset business rules, a backtracking verification mechanism is triggered; The backtracking verification mechanism includes: Freeze the current state of the transaction token and generate a backtracking request event containing a conflict description; Broadcast the backtracking request event to the upstream processed department node and the associated supervisory node, requesting joint re-verification of the intermediate data of the historical processing link; When the verification signatures of more than half of the associated nodes are received, the frozen state of the transaction processing token is released and the current conflicting node is skipped to continue the flow; If the verification fails, the data correction process is triggered, the abnormal data block is marked as pending correction, and a transaction rollback instruction containing correction instructions is generated and pushed to the user. At the same time, the associated encrypted data packet hash value stored in the blockchain is deleted until the user resubmits compliant data and restarts the processing process.

10. A government data security sharing system based on blockchain technology, characterized by: include: The demand analysis module is used to obtain user business processing information, analyze user business needs based on the user business processing information, and determine the target multi-level department chain information; A multi-level anchoring module is used to perform multi-level encryption, anchoring and chain storage of the user business processing information according to the target multi-level department chain information, and determine the business multi-level department chain information; The collaborative processing module is used to perform multi-department chain collaborative processing on the user's business needs based on the smart contract-driven strategy and the multi-level department chain information of the business, and determine and output the government affairs processing results.

Citation Information

Patent Citations

  • Government affair information processing method and device based on block chain, equipment and medium

    CN110826992A

  • System, method and device for realizing government affair information resource sharing and exchange based on blockchain technology, processor and storage medium thereof

    CN112702402A

  • Government affair cloud cross-department data security sharing method and device

    CN120474681A

Cited By

  • Cloud computing operation settlement platform intelligent contract processing system based on government affair system

    CN121032501A

  • Electronic component manufacturing production data traceability system based on block chain

    CN121304198A

  • A government affair reminding and interfacing system based on communication interaction

    CN122367422A

  • A government affair reminding and interfacing system based on communication interaction

    CN122367422B

  • Method for extracting and parsing bitcoin transaction autonomy information

    US12626253B2