Security authentication and intelligent matching method and application based on block chain technology
By integrating blockchain technology with a distributed authentication protocol that combines elliptic curve digital signatures and the PBFT consensus mechanism, and combining the KNN algorithm with an intelligent matching method based on smart contracts, the problems of identity forgery and low matching efficiency in recruitment scenarios are solved, the credibility of identity authentication and the automation of the matching process are achieved, and the transparency and security of the recruitment process are improved.
Patent Information
- Application Number
- CN202511135704.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-10-17
AI Technical Summary
Existing recruitment technologies have problems such as identity forgery and unreliable data, low matching efficiency and insufficient accuracy, significant limitations of centralized platforms, and the separation of authentication and matching processes. They cannot meet the comprehensive needs of recruitment scenarios for identity credibility and matching automation.
A blockchain-based security authentication and intelligent matching method is adopted. Through a distributed authentication protocol that integrates elliptic curve digital signatures and PBFT consensus mechanism, identity authentication is achieved by combining SHA-256 hash summary and ECDSA signature. A matching mechanism that combines the KNN algorithm with smart contracts is used to construct a multi-dimensional feature vector and use weighted Euclidean distance and weighted cosine similarity to calculate matching similarity. Formal matching conditions are defined and automatically executed at the blockchain contract layer.
It achieves the unforgeability of identity information and data integrity protection, improves the credibility of identity authentication and matching accuracy, ensures the transparency and credibility of the recruitment process, prevents identity fraud and data tampering, improves the unforgeability and traceability of matching results, and enhances anti-attack capabilities.
Smart Images

Figure CN120811733A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of blockchain, especially the technical branches of security authentication, digital signature, consensus mechanism, hash algorithm, Byzantine fault tolerance mechanism, smart contract and the like in blockchain, in particular, a security authentication and intelligent matching method based on blockchain technology and application. BACKGROUND
[0002] With the rapid development of digital economy and the increasing complexity of the job market, the traditional recruitment mode is facing the key bottleneck of the lack of trust mechanism. The digital transformation of the global human resources market is accelerating, but there are problems such as untrustworthy data, untrustworthy identity, and lack of trust between employers and job seekers in the recruitment field, which directly reduces the efficiency of human resources allocation and the quality of employment. Many employers find that job seekers have different degrees of fraud in their resumes, and the two-way information asymmetry between job seekers' resume fraud, fake education background and the distortion of enterprise job description and salary information leads to a significant decrease in recruitment matching efficiency and increases the transaction costs of both parties.
[0003] Secondly, the current recruitment process has the outstanding problem of difficulty in finding high-matching-degree post talents. Job seekers usually obtain job information through channels such as campus recruitment and recruitment websites and submit resumes for review, which has obvious limitations. The main problem is that job seekers have difficulty finding jobs with high matching degrees, the process is cumbersome and time-consuming, and employers also have difficulty accurately screening high-matching-degree talents. Therefore, the traditional manual screening mode is not only inefficient, but also difficult to handle large-scale recruitment demand, and is easily disturbed by subjective factors, leading to frequent mismatching of talents and posts.
[0004] On the other hand, existing recruitment platforms mostly use centralized architecture, which has significant technical limitations. Centralized platforms have all user data, which not only faces the risk of single point of failure and data monopoly, but also may cause data leakage and privacy infringement. In addition, the black box operation of platform algorithms may affect the fairness of matching, users cannot verify the transparency of the matching process, and it is difficult to protect their own rights and interests. Therefore, the existing centralized mode lacks effective decentralized trust mechanism and cannot fundamentally solve the credibility problem in the recruitment process.
[0005] In recent years, emerging technologies such as blockchain technology, smart contracts and artificial intelligence have provided a new path to solve the above problems. The decentralized and tamper-proof characteristics of blockchain can provide a basis for trusted data storage and identity authentication, and the automatic execution characteristics of smart contracts can realize a transparent and fair matching process. However, existing researches mostly focus on the construction of blockchain trust mechanism or the optimization of matching algorithm itself, and the research on the deep integration and systematic application of the two in the recruitment scene is limited, and a mature systematic solution has not yet been formed, which cannot meet the comprehensive needs of identity credibility and matching automation in the recruitment scene.
[0006] In summary, the existing recruitment technology has the problems of identity forgery and untrustworthy data, low matching efficiency and insufficient precision, significant limitations of centralized platform, and fragmented authentication and matching process. SUMMARY
[0007] The present application aims to provide a blockchain-based secure authentication and intelligent matching method and application, which realizes identity trustworthiness improvement and matching process automation in the recruitment scenario by integrating cryptography, consensus mechanism and intelligent matching algorithm, and provides technical support for a decentralized human resource trust network.
[0008] Based on the first main aspect of the present application, a blockchain-based secure authentication and intelligent matching method is provided, wherein the secure authentication adopts a distributed authentication protocol integrating elliptic curve digital signature and PBFT consensus mechanism (i.e. Byzantine fault-tolerant mechanism), which generates a unique identity identifier through ECC key, realizes identity authentication, data integrity guarantee and non-repudiation by combining SHA-256 hash digest and ECDSA signature, and completes consensus through four stages of request, pre-preparation, preparation and submission in the authentication process.
[0009] The intelligent matching adopts a matching mechanism based on KNN algorithm and smart contract cooperation, calculates the matching similarity by constructing a multi-dimensional feature vector and using weighted Euclidean distance and weighted cosine similarity, and defines formalized matching conditions in the contract layer of the blockchain, including similarity threshold, comprehensive matching score and automatic execution trigger strategy.
[0010] As a further preferred scheme, in the aforementioned method, a complete secure authentication process based on the distributed authentication protocol integrating elliptic curve digital signature and PBFT consensus mechanism includes the following steps executed by a computer hardware system:
[0011] Generating an ECC key pair based on elliptic curve encryption algorithm, wherein the private key is used for digital signature and the public key is used as a unique identity identifier;
[0012] Performing SHA-256 hash digest calculation on the identity data of the participant to obtain a data hash value; using the private key to perform ECDSA digital signature on the data hash value to generate a digital signature data packet;
[0013] Submitting the identity data, public key and digital signature data packet to a blockchain network based on PBFT consensus mechanism;
[0014] The blockchain network sequentially performs a consensus process of a request processing stage, a pre-preparation stage, a preparation stage, and a submission stage, wherein the request processing stage verifies the validity of a digital signature, the pre-preparation stage broadcasts a message containing a sequence number and a view ID by a master node, the preparation stage collects at least 2f+1 valid preparation messages, and the submission stage collects at least 2f+1 valid submission messages to reach consensus, wherein f represents the number of Byzantine nodes;
[0015] The authentication result through the consensus is packaged as a block and stored in the blockchain.
[0016] As a further preferred solution, in the foregoing method, the ECC key pair generation is to generate a public-private key pair by performing point operation on an elliptic curve; wherein the private key is a random scalar in the elliptic curve domain, and the public key is the scalar multiplication operation result of the private key and the base point of the elliptic curve.
[0017] The specific calculation steps include: inputting elliptic curve parameters in a computer system, determining the parameter length according to the curve parameters, generating an elliptic curve key pair, extracting a private key scalar, extracting a public key point coordinate, converting the private key to hexadecimal, converting the public key to an uncompressed format, and finally outputting the private key and the public key.
[0018] As a further preferred solution, in the foregoing method, the SHA-256 hash digest calculation is to convert input data of any length into a 256-bit fixed-length hash value; including inputting original data containing byte sequences into a computer system, performing data format conversion, creating a SHA-256 hash object, calculating a hash digest, and finally verifying the digest length and outputting the hash digest and the hash object.
[0019] As a further preferred solution, in the foregoing method, the ECDSA digital signature is executed according to the following steps: inputting a private key object and a hash object in a computer system, creating a FIPS-186-3 standard signer, generating an elliptic curve digital signature and performing Base64 encoding processing, and finally verifying the signature format and outputting the Base64 encoded digital signature.
[0020] As a further preferred solution, in the foregoing method, the PBFT consensus process is executed according to the following four stages:
[0021] The request stage, the blockchain network receives an identity data packet, a signature, and a public key, verifies the validity of the ECDSA signature, the timeliness of the timestamp, and the uniqueness of the random number, and forwards the request to the master node after verification;
[0022] The pre-preparation stage, the master node assigns a sequence number and a view ID to the request, generates a pre-preparation message containing a view ID, a sequence number, a data hash value, and its own signature, and broadcasts it to all backup nodes;
[0023] In the preparation phase, after verifying the consistency between the pre-prepare message and the local request, the backup node generates and broadcasts a prepare message containing the view ID, sequence number, data hash value, and its own signature. When the node collects at least 2f+1 valid prepare messages, it enters the preparation state.
[0024] In the submission phase, after the node is in the preparation state, it generates and broadcasts a submission message containing the same view ID, sequence number, data hash value and its own signature. When at least 2f+1 valid submission messages are collected, consensus is reached and the authentication results are packaged into a block for storage.
[0025] As a further preferred solution, in the aforementioned method, the matching mechanism based on the KNN algorithm and the smart contract is implemented by the following steps:
[0026] Construct multi-dimensional feature vectors of participating entities and target objects, normalize numerical features, and perform encoding conversion on categorical features;
[0027] The matching similarity between feature vectors is calculated using weighted Euclidean distance and weighted cosine similarity. The weight of each feature dimension is dynamically configured according to the application scenario.
[0028] Setting smart contract definitions at the blockchain contract layer to formalize matching conditions, including: setting a similarity threshold, calculating a comprehensive matching score using a weighted sum formula, and setting a minimum score standard. In the weighted sum formula, the weights of each dimension must be non-negative and sum to 1.
[0029] Call the KNN algorithm to filter out candidate results that meet both the similarity threshold and the comprehensive scoring criteria, sort them in descending order of similarity, and select the top K matches, where K is a configurable parameter ranging from 1 to 10;
[0030] The smart contract performs matching according to the preset automatic execution trigger strategy and stores the results on the chain;
[0031] The preset automatic execution triggering strategies include real-time triggering based on data increment, conditional triggering based on matching quality, and timed triggering based on time interval.
[0032] Based on the second main aspect of the present invention, a blockchain-based security authentication and intelligent matching method is provided for application in a recruitment scenario, including the following steps:
[0033] Obtain the identity information, educational background, work experience and skills of job seekers, as well as the company's job requirements, including educational requirements, experience requirements, and skills requirements;
[0034] An ECC key pair based on an elliptic curve encryption algorithm is generated, an ECDSA digital signature is performed on a SHA-256 hash digest of the information using a private key, and the information, a public key, and signature data are submitted to a consortium chain based on a PBFT consensus mechanism, and after consensus in the request processing, pre-preparation, preparation, and submission stages, the authentication result is packaged as a block and stored on the chain;
[0035] The intelligent contract monitors the consortium chain for new authentication information, constructs a multi-dimensional feature vector of the job seeker and the post when the accumulated number of new information reaches a preset number, calculates the similarity by using a weighted cosine similarity, sorts the results filtered by a threshold, and selects the top K matching items;
[0036] The matching result is packaged as a new block and stored on the chain after being verified by the PBFT consensus of the consortium chain.
[0037] As a further preferred solution, in the foregoing application, the nodes of the consortium chain include enterprise nodes, human resource service agency nodes, and authentication agency nodes;
[0038] The enterprise nodes submit post demand information, the human resource service agency nodes provide matching algorithm support, and the authentication agency nodes verify the authenticity of the education information;
[0039] Moreover, each node identifies its identity by using its own ECC public key.
[0040] According to a third main aspect of the present application, a computer readable storage medium is provided, which stores computer program instructions, and the computer program instructions are executed by a processor to implement the foregoing method for secure authentication and intelligent matching based on a blockchain technology or the foregoing application of the method for secure authentication and intelligent matching based on a blockchain technology in a recruitment scenario.
[0041] Compared with the prior art, the present application combines an elliptic curve encryption algorithm and a PBFT consensus mechanism, and achieves remarkable results in the secure authentication link. The ECC key pair is used to generate a unique identity, and the SHA-256 hash digest and the ECDSA digital signature are combined to realize the non-falsifiability of identity information and the guarantee of data integrity, effectively preventing identity fraud and information tampering of job seekers or enterprises.
[0042] Meanwhile, the PBFT consensus mechanism ensures that the authentication data reaches an agreement among multiple nodes through a four-stage process of request, pre-preparation, preparation, and submission, even if there are no more than 1 / 3 of the total number of malicious nodes, the reliability of the authentication result can still be maintained, and the credibility of identity authentication in a distributed environment is significantly improved.
[0043] In terms of consensus performance, the PBFT consensus algorithm of the present application exhibits good stability and adaptability. Experimental results show that, under the recommended configuration of 7-13 nodes, the consensus success rate always remains 100%, and under the extreme condition of network delay of 1000ms, consensus can still be reached stably at the cost of acceptable time extension. This feature enables the scheme to reliably operate in different network environments, meeting the needs of recruitment scenarios for the timeliness and stability of authentication responses, and overcoming the limitations of traditional centralized authentication modes that are vulnerable to single point failures.
[0044] The intelligent matching link of the present application effectively improves the matching accuracy and automation level through the cooperative design of KNN algorithm and smart contract. By constructing the multi-dimensional feature vector of job seekers and positions, the present application comprehensively considers attributes such as age, education, experience and skills, and uses weighted Euclidean distance and weighted cosine similarity calculation strategy, so that the matching result is more in line with the business needs of the recruitment scenario.
[0045] The introduction of the smart contract in the present application provides automation and credibility guarantee for the matching process. By formally defining matching conditions such as similarity threshold and comprehensive quality score, and implementing three types of automatic execution strategies, i.e. real-time triggering, high-quality triggering and timing triggering, the transparency of matching rules and the non-intervention of execution are realized. The integration of smart contract and KNN algorithm has little effect on core performance, and the execution efficiency is comparable to that of traditional algorithms, but it adds the non-tamperability and traceability of matching results, reducing the bias and risk caused by human operation.
[0046] The present application realizes the credibility and traceability of the whole recruitment process. The authentication results and matching results are stored in the blockchain, and the block contains business data, hash value, timestamp and consensus node signature, ensuring that any modification of data in any link can be detected, forming a full-link credible closed loop from identity authentication to matching result storage. This design enables job seekers and enterprises to trace the authentication and matching process at any time, effectively improving the transparency and credibility of the recruitment process.
[0047] In terms of security defense capability, the present application exhibits strong resistance to typical attacks. Experimental data show that the defense success rate of the scheme against three types of attacks, i.e. fake signature, replay attack and data tampering, all reaches 100%. The ECDSA signature mechanism effectively prevents signature forgery, the timestamp and random number strategy prevents replay attacks, and the hash digest and consensus verification ensure that data cannot be tampered with. For malicious node attacks, thanks to the Byzantine fault tolerance feature of PBFT consensus, when the number of malicious nodes does not exceed the threshold, the system can still reach consensus normally, significantly enhancing the anti-attack ability of the scheme. BRIEF DESCRIPTION OF DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the description of the embodiments or the prior art will be briefly introduced. Obviously, the accompanying drawings in the following description only constitute some embodiments of the present application, and for those skilled in the art, other drawings can be obtained according to these drawings without creative labor.
[0049] Figure 1 The overall flow of the security authentication and intelligent matching method based on the blockchain technology in an embodiment of the present application is shown.
[0050] Figure 2 The overall framework of the security authentication protocol in which the ECDSA and the PBFT consensus mechanism are deeply integrated in an embodiment of the present application is shown.
[0051] Figure 3 The security authentication flow in an embodiment of the present application is shown.
[0052] Figure 4 The complete flow from key generation to signature verification in an embodiment of the present application is shown.
[0053] Figure 5 The contract condition system diagram in a recruitment scenario in an embodiment of the present application is shown.
[0054] Figure 6 The two-way matching decision flowchart in an embodiment of the present application is shown.
[0055] Figure 7 The intelligent contract automatic execution mechanism diagram in an embodiment of the present application is shown.
[0056] Figure 8 The module interaction schematic diagram based on the blockchain in an embodiment of the present application is shown.
[0057] Figure 9 The blockchain structure schematic diagram in an embodiment of the present application is shown.
[0058] Figure 10 The business processing flowchart in a recruitment scenario in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0059] The preferred embodiments of the present application will be described in detail below, so as to more clearly understand the purposes, characteristics and advantages of the present application. It should be understood that the following embodiments are not a limitation on the scope of the present application, but only for illustrating the essential content of the technical solutions of the present application.
[0060] In the following description, for purposes of explanation, specific details are set forth to provide a thorough understanding of various disclosed embodiments. However, one of ordinary skill in the art will appreciate that embodiments can be practiced without one or more of the specific details or with other methods, components, materials, and so forth. In other instances, well-known structures, materials, or operations are not shown or described in detail in order to avoid obscuring the description.
[0061] Reference throughout this specification to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, the appearances of the phrase "in one embodiment" or "in an embodiment" in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0062] From the overall concept, the main purpose of the present application is to propose a secure authentication and intelligent matching scheme based on blockchain technology, combining cryptography, PBFT consensus mechanism and KNN algorithm, to build a "authentication-on-chain-matching-on-chain" trusted business process. This scheme aims to improve the identity trustworthiness and matching process automation in the recruitment scenario, and provides algorithm support for building a decentralized human resource trust network.
[0063] As shown in Figure 1 The main content of the present application includes a secure authentication protocol and its execution process, as well as an intelligent matching mechanism based on KNN algorithm, and both are built into a complete scheme, so as to propose a trusted matching process scheme suitable for the recruitment scenario by integrating secure authentication and intelligent matching algorithm, and provide an algorithm path for solving identity fraud and talent shortage.
[0064] In the present application, the secure authentication adopts a distributed authentication protocol combining elliptic curve digital signature and PBFT consensus mechanism. The protocol generates a unique identity identifier through ECC key, realizes identity authentication, data integrity guarantee and non-repudiation by combining SHA-256 hash digest and ECDSA signature, and the authentication process completes the consensus through four stages of request, pre-preparation, preparation and submission.
[0065] The intelligent matching adopts a matching mechanism based on KNN algorithm and smart contract cooperation, calculates the matching similarity by constructing a multi-dimensional feature vector and using weighted Euclidean distance and weighted cosine similarity; and defines the formalized matching conditions in the contract layer of the blockchain, including similarity threshold, comprehensive matching score and automatic execution trigger strategy.
[0066] In one possible embodiment of the present application, a complete security authentication process based on the fusion of elliptic curve digital signature and PBFT consensus mechanism of the distributed authentication protocol includes the following steps S110-S150 executed by the computer hardware system:
[0067] S110, generating an ECC key pair based on the elliptic curve encryption algorithm, wherein the private key is used for digital signature and the public key is used as a unique identity;
[0068] S120, performing SHA-256 hash digest calculation on the identity data of the participants to obtain data hash value; using the private key to perform ECDSA digital signature on the data hash value to generate a digital signature data packet;
[0069] S130, submitting the identity data, public key and digital signature data packet to a blockchain network based on the PBFT consensus mechanism;
[0070] S140, the blockchain network sequentially performs the consensus process of request processing, pre-preparation, preparation and submission stage, wherein the request processing stage verifies the validity of the digital signature, the pre-preparation stage broadcasts the message containing the sequence number and view ID by the master node, the preparation stage collects at least 2f+1 valid preparation messages, and the submission stage collects at least 2f+1 valid submission messages to reach consensus;
[0071] S150, packing the authentication result passed through the consensus as a block and storing it in the blockchain.
[0072] In one possible embodiment, the present application provides a security authentication protocol deeply fused with ECDSA and PBFT consensus mechanism, which is designed by the cooperation of cryptographic security mechanism and distributed consensus algorithm, lays a solid trust foundation for the constructed blockchain security authentication and intelligent matching scheme, and ensures that the subsequent intelligent matching algorithm can be executed in a trusted environment.
[0073] Figure 2The overall framework of the security authentication protocol in which the ECDSA and the PBFT consensus mechanism are deeply integrated in a feasible embodiment is shown. The design of the security authentication protocol is carried out around three core objectives. In the aspect of identity authentication, the protocol ensures that the identity of each participant (job seeker, enterprise post, and verification node) is real and credible, prevents identity forgery and impersonation attacks, and generates a unique digital identity for each participant based on the public and private key system of the elliptic curve encryption algorithm. In the aspect of data integrity guarantee, the protocol calculates the original data by using the SHA-256 hash digest algorithm to ensure that the identity information and the certificate data transmitted in the authentication process are not tampered with in the storage and transmission process. In the aspect of non-repudiation implementation, the protocol uses digital signature technology to ensure that any authenticated operation cannot be denied by the participant, and each authentication operation produces a non-forgable digital signature to form a complete operation audit trail.
[0074] To achieve the above three core objectives, the protocol mainly considers the main security threats in actual application in the design, including signature forgery attack, replay attack, data tampering attack, etc., and provides multi-layer security protection through time stamp verification, random number mechanism, hash digest calculation, etc.
[0075] On the basis of the above security authentication protocol, the above one embodiment of the present application organically integrates cryptography and consensus algorithm, generates a unique digital identity for each participant through an ECC key pair, ensures data integrity by using the SHA-256 hash algorithm, and realizes identity authentication and non-repudiation by using the ECDSA digital signature mechanism. The PBFT algorithm ensures the consistency of authentication decisions in a multi-node environment, reaches consensus on authentication results through the four-stage consensus process of request, pre-preparation, preparation, and submission, and effectively prevents interference of malicious nodes.
[0076] As shown in the security authentication process in one embodiment, Figure 3 In the identity authentication process, after receiving the authentication request, the protocol calls the ECC key generation algorithm to create a private key and a public key for the participant, which are used in the subsequent signature and signature verification steps, wherein the public key and the associated identity information constitute an identity data packet. After the identity data packet is subjected to hash digest calculation and digital signature, it is submitted to the PBFT consensus network for verification. Multiple verification nodes verify the identity information to ensure the validity and consistency of the identity data. After verification, the data is packaged.
[0077] When the protocol is used again later, the authenticity of the participant's identity needs to be verified. At this stage, the private key is used to digitally sign the information containing the timestamp and random number, and the verification node verifies the validity of the signature through the public key. The core of the authentication process is to prove that the participant actually possesses the private key corresponding to the established public key. This method effectively prevents replay attacks. The timestamp limits the validity period of the authentication request, and the random number ensures the uniqueness of each authentication. The authentication process specifically includes: the verification node generates information containing a timestamp and a random number; then calls a function to receive the information and uses the private key to digitally sign it; the signed response information is submitted to the verification node; the verification node uses the participant's public key to verify the validity of the signature, and at the same time checks the legitimacy of the timestamp and random number; after the verification is passed, the participant's identity is confirmed and can enter the subsequent business process.
[0078] Based on the above process design, the security of the authentication process is guaranteed from multiple angles. The confidentiality of the ECC private key ensures that only legitimate participants can generate valid digital signatures. The difficulty of the elliptic curve discrete logarithm problem provides a solid mathematical foundation for identity authentication. The SHA-256 hash digest calculation ensures data integrity. Any tampering with the original data will cause the hash value to change, which will be detected and rejected by the protocol. The PBFT consensus mechanism ensures the consistency of authentication results in a distributed environment. Even in the presence of malicious nodes, as long as the number of malicious nodes does not exceed 1 / 3 of the total number of nodes, the protocol can still correctly complete the authentication. The timestamp and random number mechanism prevent replay attacks to a certain extent, ensuring the uniqueness and timeliness of each authentication request.
[0079] The following feasible embodiment further illustrates the aforementioned steps S110-S150, and elaborates on the design and implementation of the identity authentication mechanism based on ECC, including the core algorithms such as key generation, hash digest calculation, digital signature and verification. Figure 4 The complete process from key generation to signature verification is shown, including key steps such as hash calculation, signature generation, and verification.
[0080] The following is a feasible implementation method to realize the generation of the ECC key pair in step S110.
[0081] This embodiment uses the P-256 curve, which provides 128-bit security, resists most currently known cryptographic attacks, and boasts high computational efficiency. The core concept of the key generation algorithm in this embodiment is based on the intractability of the elliptic curve discrete logarithm problem. Public-private key pairs are generated by performing point operations on the elliptic curve. The private key is a random scalar within the elliptic curve domain, while the public key is the result of scalar multiplication of the private key and the elliptic curve base point.
[0082] In the embodiment, the public key point coordinates are stored in uncompressed format, which increases the storage overhead but simplifies subsequent cryptographic calculations, improves the efficiency and reliability of algorithm implementation.
[0083] The specific calculation process is as follows:
[0084] Input: elliptic curve parameters ;
[0085] Output: private key d, public key Q
[0086] 1. Determine the parameter length para len according to the curve parameters;
[0087] P-256: 32 bytes, P-384: 48 bytes, P-521: 66 bytes;
[0088] 2. Generate an elliptic curve key pair key = ECC.generate(curve);
[0089] 3. Extract the private key scalar d = key.d;
[0090] 4. Extract the public key point coordinates Q = (x, y) = key.pointQ;
[0091] 5. Convert the private key to hexadecimal:
[0092] private_key = hex(d).zfill(para_len 2) ;
[0093] 6. Convert the public key to uncompressed format:
[0094] public_key = '04' + hex(x).zfill(para_len 2) +hex(y).zfill(para_len 2);
[0095] 7. Return (private_key, public_key)。
[0096] The following is a possible implementation of step S120 SHA-256 hash digest calculation.
[0097] Before digital signature, the original data needs to be summarized by a hash function, which is a key step to ensure the security of signature. In this embodiment, SHA-256 algorithm is used to convert input data of any length into a hash value of fixed length of 256 bits. SHA-256 has good avalanche effect and anti-collision property, which ensures that even a slight change in the original data will cause a significant difference in the hash value, providing a reliable data fingerprint for digital signature.
[0098] In the present application, the use of hash summary not only improves the security of the signature algorithm, but also solves the problem of the length limitation of input data for elliptic curve signature algorithm, making the protocol able to sign any length of identity information and authentication data.
[0099] The data hash summary calculation algorithm is designed as follows:
[0100] Input: original data data (byte sequence);
[0101] Output: hash summary data_hash (32 bytes), hash object (hash_object);
[0102] 1. Data format conversion:
[0103] if data is a string: data = data.encode('utf-8');
[0104] 2. Create SHA-256 hash object: hash_object = SHA256.new(data);
[0105] 3. Calculate hash summary: data_hash = hash_obj.digest();
[0106] 4. Verify the length of the summary: assert len(data_hash) == 32;
[0107] 5. Return (data_hash, hash_object).
[0108] The following is a possible implementation of the execution process of ECDSA digital signature in step S120.
[0109] In the embodiment, when designing and implementing the ECDSA digital signature algorithm, the hash digest of data is signed instead of directly signing the original data, which ensures security and improves signature efficiency. The ECDSA signature process involves complex mathematical operations on elliptic curves, including modular operations, point multiplication, etc. In the embodiment, the FIPS-186-3 standard is used to ensure the security and interoperability of the signature algorithm.
[0110] The core idea of the signature algorithm in the embodiment is based on the elliptic curve discrete logarithm problem and the one-wayness of the hash function to generate a digital signature that can prove the possession of a specific private key by the signer. It must also ensure that a different random number is used for each signature to prevent private key leakage.
[0111] In the embodiment, the ECDSA digital signature algorithm is designed as follows:
[0112] Input: private key object private_key_obj, hash object hash_object;
[0113] Output: digital signature digital_signature (Base64 encoding);
[0114] 1. Create a FIPS-186-3 standard signer: signer = DSS.new(private_key_obj, 'fips-186-3');
[0115] 2. Generate an elliptic curve digital signature: signature_bytes = signer.sign(hash_object);
[0116] 3. Base64 encoding processing:
[0117] digital_signature = base64.b64encode(signature_bytes).decode();
[0118] 4. Verify the signature format: assert len(signature) > 0;
[0119] 5. Return digital_signature.
[0120] The following is a possible implementation of the execution process of verifying the digital signature in step S140.
[0121] Signature verification is the core step of identity authentication, which confirms the identity of the signer by verifying the validity of the digital signature. The verification process uses public keys to verify the authenticity of the signature. The security of the verification algorithm is based on the difficulty of solving the elliptic curve discrete logarithm problem, that is, without the private key, an attacker cannot forge a valid digital signature. The protocol binds each participant's identity information with their public key to establish an unalterable correspondence. Once this binding relationship is established, it cannot be maliciously modified, thereby providing a reliable basis for subsequent identity verification.
[0122] In this embodiment, the ECDSA signature verification algorithm is designed as follows:
[0123] Input: public key object public_key_obj, hash object hash_object, digital signature digital_signature;
[0124] Output: verification result ;
[0125] 1. Base64 decode signature: signature_bytes = base64.b64decode(signature);
[0126] 2. Create a FIPS-186-3 standard verifier:
[0127] verifier = DSS.new(public_key_obj, 'fips-186-3') ;
[0128] 3. Perform signature verification:
[0129] try: verifier.verify(hash_object, signature_bytes)
[0130] return True
[0131] except: return False;
[0132] 4. Record the verification result and return.
[0133] The following feasible embodiment shows the steps S130 and S140 about the PBFT consensus mechanism and consensus process.
[0134] In this embodiment, the PBFT consensus process contains four core stages: Request, Pre-Prepare, Prepare, and Commit. Each stage is embedded with strict signature verification mechanisms, tightly integrating cryptographic verification with distributed consensus to ensure network consistency while guaranteeing authentication security, forming a multi-level security system.
[0135] In this embodiment, the protocol uses a 4-node configuration, capable of tolerating 1 malicious node, meeting the security requirements of the PBFT algorithm n≥3f+1. The primary node is responsible for receiving participant authentication requests and initiating the consensus process, while the backup nodes are responsible for verifying primary node messages and participating in consensus decisions. Each node maintains an independent ECC key pair, ensuring message authenticity and non-repudiation through digital signatures.
[0136] In this embodiment, the PBFT consensus process is designed as follows:
[0137] Input: participant authentication request request_data;
[0138] Output: consensus result consensus_result;
[0139] 1. Request Phase:
[0140] (1) Participants generate authentication requests containing identity information and digital signatures.
[0141] (2) The primary node receives the request and verifies the participant's signature.
[0142] (3) After verification, the primary node prepares to enter the consensus process.
[0143] 2. Pre-Prepare Phase:
[0144] (1) The primary node protects the authentication data integrity and signs it.
[0145] (2) The primary node broadcasts the Pre-Prepare message to all backup nodes.
[0146] (3) The message contains sequence number, view ID, signature, and other information.
[0147] 3. Prepare Phase:
[0148] (1) Backup nodes verify the signature and integrity of the Pre-Prepare message.
[0149] (2) After verification, the node broadcasts the Prepare message.
[0150] (3) After collecting enough Prepare messages (> 2f+1), enter the commit phase.
[0151] 4. Commit Phase:
[0152] (1) The node verifies the Prepare message and broadcasts the Commit message;
[0153] (2) After collecting enough Commit messages (> 2f+1), consensus is reached;
[0154] (3) Return the authentication success result.
[0155] The following feasible embodiment shows the execution process of the request processing and pre-preparation phase in step S140.
[0156] In this embodiment, the request processing phase is the starting point of the consensus process, and the master node receives the authentication request of the participant and performs preliminary verification, first verifying the digital signature in the request to ensure that the request comes from a legal participant, and then performing integrity protection on the authentication data to prepare for the subsequent consensus process.
[0157] The pre-preparation phase is the first formal phase of PBFT consensus, and the master node encapsulates the verified authentication request into a Pre-Prepare message and broadcasts it to all backup nodes. The key of this phase is the design of data integrity protection and tamper-proof mechanism to ensure that the authentication data is not maliciously modified during the consensus process.
[0158] In this embodiment, the request processing and pre-preparation phase are executed by the computer system according to the following steps:
[0159] Input: authentication request request_data;
[0160] Output: Pre-Prepare message pre_prepare_msg;
[0161] 1. Request verification:
[0162] signature = request_data.signature
[0163] public_key = request_data.public_key
[0164] if not verify_signature(request_data.data, signature, public_key):
[0165] return ERROR("signature verification failed") ;
[0166] 2. Data integrity protection:
[0167] content_hash = SHA256(request_data.data)
[0168] field_signatures = sign_all_fields(request_data.data)
[0169] protected_data = {
[0170] "original_data": request_data.data,
[0171] "content_hash": content_hash,
[0172] "field_signatures": field_signatures,
[0173] "timestamp": current_time(),
[0174] "verification_code": "VERIFIED"}
[0175] 3. Generate Pre-Prepare message:
[0176] seq_num = get_next_sequence_number()
[0177] pre_prepare_msg = create_message(
[0178] type="PRE_PREPARE",
[0179] view_id=current_view_id,
[0180] seq_num=seq_num,
[0181] content=protected_data)
[0182] pre_prepare_msg.signature = sign_message(pre_prepare_msg)
[0183] return pre_prepare_msg.
[0184] The following one feasible embodiment shows the execution process of the preparation phase and the submission phase in step S140.
[0185] In this embodiment, the preparation phase is the core verification link of the PBFT consensus. After the backup node receives the Pre-Prepare message of the master node, it needs to comprehensively verify the signature, data integrity, field signature, etc. of the message. Only the message that passes all verification checks will be accepted, and the node will then generate a Prepare message and broadcast it to other nodes.
[0186] The submission phase is the final confirmation link of the consensus. After the node collects a sufficient number of Prepare messages, it verifies the consistency and validity of these messages, and then generates a Commit message. When a sufficient number of Commit messages are collected, the node reaches a final consensus and confirms the validity of the authentication request.
[0187] In this embodiment, the preparation phase and the submission phase execute the following steps:
[0188] Input: Pre-Prepare / Prepare message input_msg;
[0189] Output: Prepare / Commit message output_msg or consensus result consensus_result;
[0190] 1. Preparation phase processing:
[0191] (1) Message signature verification:
[0192] If not verify_message_signature(input_msg):
[0193] Return ERROR("Message signature verification failed")
[0194] (2) Data integrity verification:
[0195] expected_hash=SHA256(input_msg.content.original_data)
[0196] If in put_msg.content.content_hash!=expected_hash:
[0197] returnERROR("Data integrity verification failed")
[0198] (3) Field signature verification:
[0199] For field,signature in input_msg.content.field_signatures:
[0200] If not verify_field_signature(field,signature):
[0201] Return ERROR("field signature verification failed")
[0202] (4) Generate Prepare message:
[0203] prepare_content={
[0204] "data_hash":input_msg.content.content_hash,
[0205] "data_signature":sign(input_msg.content.original_data),
[0206] "integrity_verified":true}
[0207] prepare_msg=create_signed_message("PREPARE",prepare_content)
[0208] 2. Commit phase processing:
[0209] (1) Collect Prepare messages:
[0210] If count(prepare_messages)>=2f+1:
[0211] create_and_broadcast_commit_message()
[0212] (2) Reach consensus:
[0213] If count(commit_messages)>=2f+1:
[0214] Return CONSENSUS_REACHED(original_data).
[0215] The following one of the feasible embodiments provides a data matching method combining KNN algorithm and smart contract technology to realize the application of the application in the recruitment scene.
[0216] In this embodiment, the data similarity between users is calculated by KNN algorithm, the matching conditions are defined by smart contract and the matching rules are automatically executed, and a complete decentralized matching algorithm is constructed. As shown in Figure 5 , the design of contract conditions focuses on three core dimensions: similarity threshold, matching degree ranking and business rule verification, to ensure that only matching results that meet the pre-defined conditions can pass the contract verification and be recorded.
[0217] The following one of the feasible embodiments shows the design process of the similarity threshold condition.
[0218] The similarity threshold condition is the core judgment criterion of the matching contract, which defines the minimum similarity requirement for effective matching. In this embodiment, let the similarity between job seeker s and job j be sim(s, j), and the similarity threshold be , then the basic matching condition can be expressed as:
[0219]
[0220] The threshold needs to balance the requirements of matching accuracy and recall rate. Too low threshold will produce a large number of low-quality matches, increasing noise; too high threshold may miss effective matching opportunities. The contract supports dynamic threshold adjustment mechanism, allowing to modify the threshold parameter according to actual application requirements, in this embodiment, the default setting is .
[0221] The following one of the feasible embodiments shows the matching quality evaluation condition.
[0222] In this embodiment, the education matching degree is , the experience matching degree is , the skill matching degree is , and the comprehensive matching quality evaluation function is:
[0223]
[0224] where the weight parameters satisfy and . In this embodiment, based on the characteristics analysis of the recruitment scene, the weight configuration is , , , highlighting the important position of skill matching in recruitment decision-making.
[0225] To ensure the matching results reach an acceptable quality level, the contract sets a minimum threshold for the comprehensive quality score. The quality evaluation condition of the contract requires the comprehensive quality score to exceed a preset standard: .
[0226] wherein, is the minimum quality requirement, which is set as 0.7 by default in this embodiment. Only the matching results that meet both the similarity threshold and the quality evaluation condition can pass the contract verification.
[0227] The following feasible embodiment shows the contract automatic execution trigger condition.
[0228] The contract defines three types of automatic execution trigger conditions to ensure that the matching process can respond to different business scenarios. The real-time trigger condition monitors data update events, and when a new job seeker joins or a new job is published, the matching is automatically started if the following conditions are met:
[0229]
[0230] wherein, represents the new job seeker joining event, represents the new job publishing event, is the minimum data volume required to start the matching, which is set as 10 in this embodiment.
[0231] The following feasible embodiment shows the implementation of KNN-based data matching, which uses the KNN algorithm to realize data matching between participants, including key links such as feature vector construction, similarity calculation, and matching decision.
[0232] In this embodiment, the multi-dimensional feature vector construction method is as follows:
[0233] In view of the heterogeneous characteristics of recruitment data, this embodiment designs a unified feature vector representation method to convert job seeker information and job requirements into calculable numerical vectors. The feature vector includes four core dimensions: age, education, experience, and skills. The age feature is normalized using the min-max normalization method, and the specific formula is:
[0234]
[0235] This formula maps the age range of 18-60 to the interval [0, 1]. For job objects, the age feature is set to the middle value 0.5, indicating no specific preference for age.
[0236] In this embodiment, the education feature establishes a six-level mapping system, and this embodiment defines a mapping relationship from "junior high school" to "doctorate" corresponding to numerical values 1-6:
[0237]
[0238] Where: is the educational level mapping function, specifically: junior high school and below is 1, high school is 2, junior college is 3, bachelor's degree is 4, master's degree is 5, and doctorate is 6.
[0239] In this embodiment, the work experience feature is also normalized, with the experience range being 0-20 years, and experience exceeding 20 years being uniformly mapped to 1. The calculation formula is:
[0240]
[0241] In this embodiment, the skill features are encoded using one-hot encoding based on a predefined 25-dimensional skill vocabulary. For binary marking, the encoding formula of skill features is:
[0242]
[0243] The following feasible embodiment shows the weighted cosine similarity calculation steps.
[0244] In this embodiment, two complementary similarity calculation methods are provided to meet the needs of different matching scenarios. Both methods take feature weights into account to ensure that important features play a greater role in similarity calculation. The weight configuration follows the following design principles:
[0245] The calculation of weighted Euclidean distance first applies weights to different dimensions and then calculates the distance:
[0246]
[0247] Where: is the weight of the i-th feature. The formula for converting distance to similarity is:
[0248]
[0249] The calculation formula of weighted cosine similarity is:
[0250]
[0251] In this embodiment, the weight parameter configuration is: age weight , academic weight , experience weight , skill weight When designing the weight parameter configuration, the skill dimension has the largest weight for skill matching, and the weights for education and experience are equal, reflecting the balanced importance of education background and work experience; age has the smallest weight, which is in line with the trend of downplaying age factors in modern recruitment.
[0252] In the following feasible embodiment, the present invention also provides a two-way matching decision mechanism.
[0253] The recruitment matching process is essentially a two-way selection problem, involving both job seekers searching for suitable positions and recruiters screening for ideal candidates. This embodiment designs a flexible two-way matching mechanism that supports two matching modes through a unified similarity calculation framework, ensuring symmetry and fairness in matching decisions.
[0254] The matching decision process utilizes a three-stage pipeline design: similarity calculation, threshold screening, and ranking selection. First, the present invention calculates similarity scores for all possible job seeker-position pairings. This step utilizes the aforementioned weighted cosine similarity algorithm, comprehensively considering multi-dimensional characteristics such as age, education, experience, and skills. Then, a preliminary screening is performed using a preset similarity threshold to filter out clearly mismatched candidates, reducing computational overhead and improving result quality. Finally, the matching results that pass the threshold screening are ranked, and the top K optimal candidates are selected as the final recommendations.
[0255] like Figure 6 As shown, in this embodiment, for the scenario where a job seeker is searching for a job, the algorithm first constructs a set of job candidates that meet the threshold requirements according to the designed matching strategy. Specifically, for job seeker s, the set of matching jobs is defined as:
[0256]
[0257] Where J is the set of all available positions. Based on the candidate set, the algorithm sorts the candidate set in descending order by similarity score and extracts the K most similar positions as the recommended results. This design ensures that the recommended positions for job seekers meet basic matching requirements and are optimized according to matching quality.
[0258] In this embodiment, for the reverse matching scenario of job screening candidates, the algorithm uses the same logical framework but swaps the matching subjects, following the symmetric matching principle to build a candidate pool of qualified job seekers for each position j:
[0259]
[0260] Where S is the set of job seekers. The candidate pool is also sorted by similarity, providing the top K candidates with the best quality to the recruiter.
[0261] To improve the overall efficiency of the algorithm, some embodiments also support a batch matching mode, employing a parallel processing strategy. In this mode, the present invention generates matching recommendations for all job seekers simultaneously, forming a global set of matching results. Batch processing not only reduces recalculation but also facilitates subsequent statistical analysis and performance optimization.
[0262] This batch matching design is particularly suitable for smart contract environment, which can handle a large number of matching requests through a single contract call, significantly reducing the cost and execution time of blockchain transactions. The algorithm collects all matching results and performs global sorting, providing rich data support for decision analysis, facilitating matching quality analysis, algorithm parameter tuning, and business decision support.
[0263] In the following feasible embodiment, the present application provides a smart contract automatic execution method. The core design concept of the smart contract automatic execution mechanism is to minimize human intervention and achieve fully automated management of the matching process through pre-set rules and trigger conditions.
[0264] In this embodiment, the smart contract automatic execution mechanism in one feasible implementation is shown in the following figure Figure 7 The design of the contract data structure needs to balance the requirements of storage efficiency, query performance, and data integrity. According to the business characteristics of recruitment matching, each matching result needs to record the identity of the participating parties, the matching quality score, and the time information of the matching, providing support for subsequent statistical analysis and audit tracing.
[0265] In this embodiment, the core data structure of the contract MatchResult contains four key fields: the job seeker identifier jobSeeker_id for uniquely identifying the participating job seeker, the job identifier job_id for identifying the target position, the matching score score for quantifying the matching quality, and the timestamp timestamp for recording the specific time of the matching. This structure design meets the needs of business queries and maintains the simplicity of data.
[0266] In the prior art, one technical challenge of blockchain storage is floating-point number processing. Since blockchain natively supports integer operations but has limited support for floating-point numbers, this embodiment adopts an integer conversion strategy, multiplying the similarity score in the range of 0 to 1 by 1000 to convert it to an integer in the range of 0 to 1000 for storage. This scheme maintains sufficient precision and ensures cross-platform compatibility. The original precision is restored by the corresponding division operation when reading, and the entire conversion process is transparent to the application layer.
[0267] The following embodiment provides the smart contract condition judgment and automatic execution logic.
[0268] The automatic execution logic of the smart contract is based on a multi-layer condition judgment mechanism, ensuring that only matching results that meet the quality requirements can be recorded on the blockchain. This design avoids the impact of low-quality data on the credibility of the entire matching scheme, while reducing unnecessary storage overhead.
[0269] In this embodiment, the conditional judgment mechanism adopts a three-layer verification architecture, each layer assuming specific verification responsibilities. The first layer is basic format verification, mainly checking the basic legality of input data, including whether the score range is within the valid interval, whether the participant identifier meets the format requirements, etc. The purpose of this layer of verification is to quickly filter out obviously incorrect inputs and avoid wasting resources on subsequent complex verification.
[0270] The second layer is business rule checking, focusing on verifying whether the matching results meet the business logic requirements. This mainly includes two aspects of checking: whether the matching score reaches the preset minimum threshold, and whether the same pair of job seekers and positions already exists a matching record. Threshold checking ensures that the recorded matching results have practical value, and repetitive checking avoids data redundancy and resource waste.
[0271] The third layer is quality standard evaluation, which is relatively complex and needs to consider multiple dimensions of matching. The verification process not only considers the similarity score itself, but also evaluates the position of the matching result in the overall quality distribution, ensuring that the recorded matching result indeed represents a high-quality matching relationship.
[0272] The following embodiment provides an event-driven trigger strategy for the smart contract.
[0273] The automatic execution of the smart contract relies on carefully designed trigger strategies that need to find the best balance between response real-time, processing efficiency, and resource consumption. This embodiment designs three complementary trigger mechanisms, each suitable for different business scenarios and performance requirements.
[0274] The real-time trigger strategy is specifically designed for scenarios with high timeliness requirements. When new job seekers join or new positions are published, if the accumulated new data reaches the preset batch processing threshold, the contract will immediately start the matching process. This design not only ensures a quick response to new data, but also improves execution efficiency through batch processing. The batch threshold needs to consider the processing capacity of the blockchain network and transaction costs, and this embodiment sets it to 10 new entries.
[0275] The threshold trigger strategy focuses on the priority processing needs of matching quality. When the algorithm identifies matches with similarity scores exceeding a certain high-quality threshold, the contract will immediately process these high-value matches regardless of the regular batch processing period. This design ensures that high-quality matches can be processed in a timely manner, improving the response speed of the entire scheme to key matching opportunities.
[0276] The timing trigger strategy provides a bottom-up guarantee, ensuring that the matching process can be executed regularly even if the data is not updated frequently. This strategy automatically triggers the matching process at a preset time interval, which can be flexibly configured according to business needs, such as regular processing once a day or deep analysis once a week. The timing strategy is particularly suitable for processing accumulated long-tail data and conducting regular matching quality evaluation.
[0277] The coordination of the three trigger strategies forms a complete automatic execution system, which not only ensures rapid response to emergency situations, but also ensures stable processing of regular business. The contract records the type of each trigger, the number of processes, the execution time and resource consumption in detail, providing detailed data support for performance optimization and problem diagnosis.
[0278] This multi-level trigger mechanism design fully considers the characteristics of recruitment matching business: there is a real-time response demand for new opportunities, a strict requirement for matching quality, and a need to consider cost control in the blockchain environment. Through reasonable strategy combination, the efficiency, reliability and economy of automatic execution are achieved.
[0279] In order to evaluate the advantages and limitations of the intelligent matching algorithm of the present application, an embodiment of the present application compares it with a traditional centralized matching algorithm in multiple dimensions. The comparison covers five dimensions: security, credibility, decentralization, efficiency and scalability. Experimental evaluation shows that the intelligent matching algorithm has obvious advantages in security, credibility and decentralization. This advantage is due to the data encryption protection mechanism and distributed storage architecture of the blockchain technology, which helps to prevent single point failure and data leakage risk, while the transparency of the smart contract execution process and the verifiability of the results also improve the overall credibility.
[0280] In addition, the present application also finds that the intelligent matching algorithm faces certain challenges in efficiency and scalability. These challenges come from three aspects: the consensus mechanism verification required by the execution of the smart contract increases the processing time; the distributed storage architecture requires more network communication when accessing data; and the computational resource limitations of the current blockchain platform also affect the running efficiency of the algorithm to some extent. However, for actual job seeker-job matching application scenarios, the impact of these efficiency gaps on user experience is relatively limited. The security and credibility improvements brought by the smart contract technology have certain value for some specific application scenarios.
[0281] The following feasible embodiment integrates the security authentication protocol of the present application with the intelligent matching algorithm to build a complete recruitment matching scheme based on fusion blockchain.
[0282] In this embodiment, the interaction process between the authentication module and the matching module is based on blockchain, such as Figure 8The flow follows the complete cycle of "authentication - on-chain - matching - on-chain". After the new data is verified by the consensus of the authentication module, the authentication result is packaged into a block and stored on the chain. Through the batch processing mechanism and real-time triggering strategy set by the smart contract, after 10 new additions, the matching module is automatically triggered to execute the matching algorithm. When the matching calculation is completed, the matching result is recorded on the blockchain through the smart contract, forming an unalterable matching record. This design ensures the integrity and traceability of data throughout the processing flow.
[0283] The blockchain structure designed in this embodiment is optimized and improved for the special needs of the recruitment scene, while maintaining the basic properties of the blockchain, it strengthens the identity authentication and data traceability capability. The block structure is composed of block index, business data, data hash value, timestamp, consensus node signature set and previous block signature. The block index uses an incremental integer identifier to ensure the unique position and time sequence relationship of the block in the chain. The business data field includes job seeker personal information, enterprise job information and matching results generated by the intelligent matching algorithm. The data structure is stored in JSON format. The data hash value is the result of SHA-256 calculation on the business data, generating a 32-byte hash digest. The consensus signature set records the signatures of all nodes participating in the PBFT consensus process, reflecting the collective confirmation of the distributed network on the block data.
[0284] In this embodiment, the previous block signature is used to store the digital signature of the complete content of the previous block, which strengthens the close association between blocks and achieves double protection of data traceability and identity authentication. For the matching results of successful intelligent matching, the data will be processed again through the consensus algorithm to ensure that only the consensus is successful can it be packaged into a block and stored on the chain.
[0285] As shown in Figure 9 Each block is connected in a chain through the previous block signature. The data hash value provides a quick integrity check mechanism, and the consensus node signature set guarantees the network recognition of the data. This structure design makes any modification of historical data detected in the subsequent verification process.
[0286] This embodiment constructs a complete business processing flow, as shown in Figure 10 From the authentication and on-chain storage of job seeker and job data, to the execution of intelligent matching, and then to the block-based on-chain storage of matching results after successful matching, it shows the deep integration process of secure authentication and intelligent matching. The entire flow follows the complete chain of data security authentication, block on-chain, intelligent matching and result on-chain storage.
[0287] The entire scheme provided by the above embodiments realizes end-to-end automated processing from data input to result output. Through the organic combination of technical components, the scheme realizes the intelligentization and automation of recruitment matching on the premise of ensuring security.
[0288] In the above embodiments, the technical terms, technical principles or technical means related to the technical solutions of the present application are involved, and those not described in detail in the above are known technologies or common means mastered by those skilled in the art.
[0289] The above shows and describes the basic principles and main features of the present application and the advantages of the present application. Those skilled in the art should understand that the present application is not limited to the above embodiments, and the above embodiments and descriptions in the specification are only to illustrate the principles of the present application. Without departing from the content and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.
Claims
1. A security authentication and intelligent matching method based on blockchain technology, characterized in that: The security authentication adopts a distributed authentication protocol that combines elliptic curve digital signatures with the Byzantine Fault Tolerance (PBFT) mechanism. This protocol generates a unique identity through ECC keys, and combines SHA-256 hash digests with ECDSA signatures to achieve identity authentication, data integrity protection, and non-repudiation. The authentication process reaches consensus through four stages: request, pre-preparation, preparation, and submission. The smart matching adopts a matching mechanism based on the KNN algorithm and the collaboration of smart contracts. By constructing a multi-dimensional feature vector, it uses two methods, weighted Euclidean distance and weighted cosine similarity, to calculate the matching similarity. It also defines formal matching conditions at the blockchain contract layer, including similarity thresholds, comprehensive matching scores, and automatic execution trigger strategies.
2. The blockchain-based security authentication and intelligent matching method according to claim 1, characterized in that: A complete security authentication process based on the distributed authentication protocol integrating elliptic curve digital signature and PBFT consensus mechanism includes the following steps executed by the computer hardware system: Generate an ECC key pair based on the elliptic curve cryptography algorithm, where the private key is used for digital signature and the public key is used as a unique identity; Perform SHA-256 hash digest calculation on the participant's identity data to obtain the data hash value; Use the private key to perform ECDSA digital signature on the data hash value to generate a digital signature data packet; Submit the identity data, public key and digital signature data package to the blockchain network based on the PBFT consensus mechanism; The blockchain network sequentially executes the consensus process of request processing, pre-preparation, preparation, and submission phases. In the request processing phase, the validity of the digital signature is verified. In the pre-preparation phase, the master node broadcasts a message containing a sequence number and a view ID. In the preparation phase, at least 2f+1 valid preparation messages are collected. In the submission phase, consensus is reached after collecting at least 2f+1 valid submission messages, where f represents the number of Byzantine nodes. The authentication results that pass the consensus are packaged into blocks and stored in the blockchain.
3. The security authentication and intelligent matching method based on blockchain technology according to claim 2 is characterized in that: The ECC key pair is generated by performing point operations on an elliptic curve to generate a public-private key pair; wherein the private key is a random scalar in the elliptic curve domain, and the public key is the result of a scalar multiplication of the private key and the elliptic curve base point; The specific calculation steps include: inputting elliptic curve parameters into the computer system, determining the parameter length according to the curve parameters, generating an elliptic curve key pair, extracting the private key scalar, extracting the public key point coordinates, converting the private key into hexadecimal, converting the public key into an uncompressed format, and finally outputting the private key and the public key.
4. The blockchain-based security authentication and intelligent matching method according to claim 2, characterized in that: The SHA-256 hash digest calculation converts input data of any length into a 256-bit fixed-length hash value; it includes inputting original data containing a byte sequence into a computer system, performing data format conversion, creating a SHA-256 hash object, calculating the hash digest, and finally verifying the digest length and outputting the hash digest and hash object.
5. The security authentication and intelligent matching method based on blockchain technology according to claim 2 is characterized in that: The ECDSA digital signature is executed according to the following steps: inputting a private key object and a hash object into a computer system, creating a FIPS-186-3 standard signer, generating an elliptic curve digital signature and performing Base64 encoding, and finally verifying the signature format and outputting a Base64-encoded digital signature.
6. The blockchain-based security authentication and intelligent matching method according to claim 2, characterized in that: The PBFT consensus process is performed in four phases: During the request phase, the blockchain network receives the identity data packet, signature, and public key. The verification node verifies the validity of the ECDSA signature, the timeliness of the timestamp, and the uniqueness of the random number. If passed, the request is forwarded to the master node. In the pre-prepare phase, the master node assigns a sequence number and view ID to the request, generates a pre-prepare message containing the view ID, sequence number, data hash value, and its own signature, and broadcasts it to all backup nodes. In the preparation phase, after verifying the consistency between the pre-prepare message and the local request, the backup node generates and broadcasts a prepare message containing the view ID, sequence number, data hash value, and its own signature. When the node collects at least 2f+1 valid prepare messages, it enters the preparation state. In the submission phase, after the node is in the preparation state, it generates and broadcasts a submission message containing the same view ID, sequence number, data hash value and its own signature. When at least 2f+1 valid submission messages are collected, consensus is reached and the authentication results are packaged into a block for storage.
7. The blockchain-based security authentication and intelligent matching method according to claim 2, characterized in that: The matching mechanism based on the KNN algorithm and smart contract collaboration is implemented through the following steps: Construct multi-dimensional feature vectors of participating entities and target objects, normalize numerical features, and perform encoding conversion on categorical features; The matching similarity between feature vectors is calculated using weighted Euclidean distance and weighted cosine similarity. The weight of each feature dimension is dynamically configured according to the application scenario. Setting smart contract definitions at the blockchain contract layer to formalize matching conditions, including: setting a similarity threshold, calculating a comprehensive matching score using a weighted sum formula, and setting a minimum score standard. In the weighted sum formula, the weights of each dimension must be non-negative and sum to 1. Call the KNN algorithm to filter out candidate results that meet both the similarity threshold and the comprehensive scoring criteria, sort them in descending order of similarity, and select the top K matches, where K is a configurable parameter ranging from 1 to 10; The smart contract performs matching according to the preset automatic execution trigger strategy and stores the results on the chain; The preset automatic execution triggering strategies include real-time triggering based on data increment, conditional triggering based on matching quality, and timed triggering based on time interval.
8. An application of a secure authentication and intelligent matching method based on blockchain technology in recruitment scenarios, characterized in that: The following steps are involved: Obtain the identity information, educational background, work experience and skills of job seekers, as well as the company's job requirements, including educational requirements, experience requirements, and skills requirements; Generate an ECC key pair based on the elliptic curve cryptography algorithm, use the private key to perform an ECDSA digital signature on the SHA-256 hash summary of the above information, submit the information, public key and signature data package to the consortium chain based on the PBFT consensus mechanism, and after consensus in the request processing, pre-preparation, preparation and submission stages, package the authentication results into blocks and store them on the chain; The smart contract monitors the newly added authentication information on the alliance chain. When the cumulative amount of newly added information reaches a preset number, it constructs a multi-dimensional feature vector of the job seeker and the position, calculates the similarity using weighted cosine similarity, sorts the results that pass the threshold screening, and selects the top K matches; The matching results are submitted to the alliance chain and verified by PBFT consensus, and then packaged as a new block on the chain.
9. The application of the blockchain technology-based security authentication and intelligent matching method in recruitment scenarios according to claim 8 is characterized in that: The nodes of the alliance chain include enterprise nodes, human resources service agency nodes and certification agency nodes; Among them, the enterprise node submits job demand information, the human resources service agency node provides matching algorithm support, and the certification agency node verifies the authenticity of academic information; In addition, each node is identified by its own ECC public key.
10. A computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, implement the secure authentication and intelligent matching method based on blockchain technology as described in any one of claims 1 to 7, or the application of the secure authentication and intelligent matching method based on blockchain technology as described in claim 8 or 9 in a recruitment scenario.