Product oil supervision data security protection method and system based on block chain

By establishing a blockchain-based end-to-end security protection system, the problems of easy data tampering, low efficiency of cross-departmental collaboration, and delayed early warning in the refined oil supervision system have been solved, thereby improving data security, credibility, and regulatory efficiency.

CN120934734APending Publication Date: 2025-11-11浪潮智慧城市科技有限公司

Patent Information

Application Number
CN202511048566.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-29
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

The existing refined oil regulatory system suffers from problems such as easy data tampering, low efficiency of cross-departmental collaboration, and delayed early warning, making it difficult to meet the needs of precise, efficient, and reliable regulation.

Method used

It adopts a blockchain-based consortium blockchain architecture, combining end-to-end encryption, identity registration, real-time evidence storage and verification mechanisms, and anomaly detection using a relational graph model and a spatiotemporal graph convolutional network, and executes a tiered response strategy to form a regulatory closed loop.

Benefits of technology

It has achieved security protection in all aspects of data collection, transmission, storage and application, improved the credibility and response efficiency of regulatory data, and solved the problems of data tampering, cross-departmental collaboration trust barriers and delayed early warning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934734A_ABST
    Figure CN120934734A_ABST
Patent Text Reader

Abstract

The invention discloses a block chain-based product oil supervision data security protection method and system, and relates to the technical field of data security. Aiming at the problems of easy data tampering, early warning lag and the like in a traditional product oil supervision system, the scheme is adopted as follows: deploying an alliance chain architecture and realizing distributed storage to provide bottom support for a subsequent process; full-link encryption is carried out in the links of data acquisition, data transmission and evidence storage, and safe data is provided for block chain storage; identity registration and authority configuration of equipment and a user are completed, and a safety basis is provided for safe access and subsequent operation of encrypted data; the consistency of on-chain and off-chain data is ensured by establishing a real-time evidence storage mechanism, a terminal verification mechanism and a full-amount verification mechanism, full-amount data identification abnormity is analyzed in combination with an association graph model and a space-time graph convolutional network, and an abnormity detection basis is provided for intelligent early warning; and executing a hierarchical response strategy based on an on-chain early warning rule and an anomaly detection result to form a supervision closed loop. The method and the device are used for realizing data full-link security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, specifically a blockchain-based method and system for protecting the data security of refined oil product supervision. Background Technology

[0002] In the field of refined oil product regulation, the existing regulatory system faces multiple technical bottlenecks, which seriously restrict the improvement of regulatory efficiency. Specifically, the current refined oil product regulatory system has significant problems in data security, cross-departmental collaboration, data integrity throughout the entire lifecycle, access management, and early warning response: data is easily tampered with, and traditional encryption methods are insufficient to guarantee the integrity of data throughout the entire lifecycle; cross-departmental collaboration has trust barriers, affecting regulatory efficiency; access control relies on centralized management, which can easily lead to abuse of power; and the early warning mechanism is lagging behind and has low response efficiency.

[0003] In-depth analysis reveals that the core causes of these technical defects include:

[0004] 1. The risk of data tampering is severe. Traditional centralized systems have a "super administrator vulnerability," which provides an opportunity for data tampering. At the same time, the pulse parameters of fuel dispensers can be illegally modified through physical interfaces, and the tampered data can even be used to create a false "zero error" status, seriously interfering with the accuracy of supervision.

[0005] 2. Low efficiency in cross-departmental collaboration. Data from departments such as taxation, market supervision, and commerce are stored independently, lacking a unified sharing and verification mechanism. This leads to reliance on manual reconciliation during collaborative audits, which is not only inefficient but also prone to disputes due to data inconsistencies. Furthermore, the reliance on centralized databases for departmental access control further exacerbates trust barriers in the collaboration process.

[0006] 3. The early warning mechanism suffers from significant lag. Traditional rule engines trigger early warnings based on fixed thresholds, making it difficult to identify new attack patterns or mutated violations. At the same time, the early warning response process lacks a closed-loop design, resulting in the inability to quickly coordinate and handle issues after they are discovered, affecting the timeliness and effectiveness of supervision.

[0007] The combination of these problems makes it difficult for the existing refined oil regulatory system to meet the needs of precise, efficient, and reliable regulation, and there is an urgent need to build a more reliable regulatory system through technological innovation. Summary of the Invention

[0008] This invention addresses the problems of easy data tampering, low efficiency of cross-departmental collaboration, and delayed early warning in traditional refined oil regulatory systems. It provides a blockchain-based method and system for protecting the security of refined oil regulatory data, achieving full lifecycle security protection for data collection, transmission, storage, and application, and improving the credibility and response efficiency of regulatory data.

[0009] Firstly, this invention provides a blockchain-based method for protecting the security of refined oil regulatory data. The technical solution adopted to solve the above-mentioned technical problems is as follows:

[0010] A blockchain-based method for protecting the security of refined oil regulatory data includes the following steps:

[0011] S1. Deploy the consortium blockchain architecture and implement distributed storage to provide underlying support for subsequent processes;

[0012] S2. Full-link encryption is implemented in the data collection, data transmission and evidence storage stages to provide secure data for blockchain storage;

[0013] S3. Complete the device and user identity registration and permission configuration to provide a security basis for secure access to encrypted data and subsequent operations;

[0014] S4. By establishing real-time evidence storage, terminal verification and full verification mechanisms, we ensure the consistency of on-chain and off-chain data. By combining the correlation graph model and spatiotemporal graph convolutional network to analyze the full data and identify anomalies, we provide anomaly detection basis for intelligent early warning.

[0015] S5. Based on on-chain early warning rules and anomaly detection results, a tiered response strategy is implemented to form a regulatory closed loop.

[0016] Optionally, step S1 specifically includes:

[0017] The consortium blockchain is built using the Hyperledger Fabric architecture, with regulatory authorities as consensus nodes and gas stations as data submission nodes. The PBFT consensus algorithm is used to ensure the consistency of on-chain data.

[0018] Data hashes and key metadata are stored on-chain, while raw business data is encrypted and stored in a distributed database. Smart contracts are used to link on-chain and off-chain data, laying the foundation for subsequent data encryption and identity authentication processes.

[0019] Further optionally, step S2 specifically includes:

[0020] S2.1 During the data acquisition phase, when the two types of equipment, fuel dispenser encoders and level gauges, generate raw business data, they use the AES-256 algorithm for block encryption. At the same time, the equipment's built-in SE security chip generates a hardware fingerprint based on ECC private key hash, and the PUF chip synchronously generates a unique response value bound to the hardware.

[0021] S2.2 In the data transmission and storage stage, the encrypted data is first symmetrically encrypted using the SM4 algorithm to improve transmission efficiency, and then the SM4 key is encrypted using the SM2 asymmetric encryption algorithm to ensure key security, forming an SM2-SM4 hybrid encryption protocol processing flow. The processed encrypted data generates a SHA-256 hash value, which is signed by the data submission node with the SM2 private key and then uploaded to the chain, ensuring the confidentiality and integrity of the original business data from generation to uploading to the chain, and providing encrypted original data support for blockchain storage and subsequent anti-tampering detection.

[0022] Further optionally, step S3 specifically includes:

[0023] Each fuel dispenser is assigned a unique ID based on the ECC algorithm. After being bound to the hardware fingerprint generated by the SE security chip and the unique response value generated by the PUF chip, it is registered on the blockchain. The blockchain smart contract verifies the consistency between the unique response value and the fingerprint registered on the chain, thus confirming the identity of the device.

[0024] For user identity verification, regulators use a "digital certificate + blockchain address" system, with the certificate issued by the consortium blockchain CA node.

[0025] During user authentication, the user's biometric features are first entered. The terminal generates a biometric hash, the SE security chip sends a zero-knowledge proof request, the blockchain verifies the user's identity credentials, and the smart contract returns a verification result containing an authorization token. After successful verification, the terminal accesses the data with the blockchain token. At the same time, role-based access control is implemented through access control smart contracts to ensure that only authenticated and authorized entities can operate the data, providing identity and authorization guarantees for subsequent data use and early warning response.

[0026] Further optionally, step S4 specifically includes:

[0027] S4.1 Establish a real-time evidence storage mechanism. Calculate the hash value and upload it to the blockchain within 5 seconds of each fuel transaction being generated. Blocks form a chain structure through forward hash links to achieve streaming hash comparison and verify the integrity of individual data in real time.

[0028] S4.2. Each time the fuel dispenser encoder makes a measurement, it generates a hash of "measurement value + device ID + timestamp" and uploads it to the blockchain. The terminal compares the local data with the hash value on the blockchain in real time. When the number of out-of-tolerance times reaches 5 or more in a continuous operation cycle, the machine is automatically locked. At the same time, the abnormal log is recorded and uploaded to the blockchain for evidence storage.

[0029] S4.3 The supervisory node triggers full data verification daily, comparing the hash value of the data stored in the distributed database with the on-chain evidence record. If they are inconsistent, they are marked as abnormal, and hardware fingerprint verification is performed at set intervals.

[0030] S4.4. Based on the full amount of data accumulated through daily real-time and periodic verification, a relational graph model is constructed. The relational graph model uses three types of data—fueling flow, liquid level data, and tax invoices—as the core nodes in the graph, and quantitative business logic as the relational edges. The GNN algorithm is used to traverse and analyze all nodes and relational edges to identify abnormal data chains. In addition, combined with spatiotemporal data, the spatiotemporal dynamic features of the data are extracted through a spatiotemporal graph convolutional network to identify time-series anomalies and capture state mutations.

[0031] Further optionally, step S5 specifically includes:

[0032] S5.1 Predefine early warning rules through smart contracts and store them on the blockchain;

[0033] S5.2 When the refueling machine sends data encrypted with SM4 and signed with SM2, the edge gateway submits the data and signature, and the blockchain executes the smart contract for verification;

[0034] S5.3 When verification fails, the tampering event is recorded in the block, a real-time alarm is sent via WebSocket, and the event is handled according to the hierarchical response strategy.

[0035] S5.4 After an early warning event is triggered, logs are recorded on the chain and external systems are called to send alarms. At the same time, a rectification work order is generated and stored on the chain, forming a complete regulatory closed loop from anomaly detection to handling.

[0036] Preferably, the warning rules involved include the following risk calculation formula:

[0037] Risk value=α·ΔT+β·(dP / dt)+γ·Hlevel+δ·f(weather),

[0038] Where α, β, γ, and δ are dynamic coefficients optimized through reinforcement learning; ΔT is the rate of change of tank temperature; dP / dt is the rate of change of tank pressure; H level is the oil level; f(weather) is the weather risk factor.

[0039] Preferably, the hierarchical response strategy involved includes:

[0040] A single device malfunction triggers a Level 1 warning, which activates a pop-up window on the large screen and an on-site audible and visual alarm.

[0041] Multiple device malfunctions trigger a Level 2 warning, automatically locking the devices and sending an SMS notification to the responsible person.

[0042] The regional anomaly is classified as a Level 3 warning, triggering an emergency response and freezing the account.

[0043] Secondly, this invention provides a blockchain-based data security protection system for refined oil product supervision, and the technical solution adopted to solve the above-mentioned technical problems is as follows:

[0044] A blockchain-based data security protection system for refined oil regulatory data, used to implement the data security protection method for refined oil regulatory data as described in the first aspect, includes the following structure:

[0045] The blockchain infrastructure module is used to deploy the consortium blockchain architecture and implement distributed storage, providing underlying support for subsequent processes;

[0046] The end-to-end data encryption module is used to perform end-to-end encryption in the data acquisition, data transmission and evidence storage stages, providing secure data for blockchain storage;

[0047] The identity authentication and access control module is used to complete the identity registration and permission configuration of devices and users, and to provide a security basis for secure access to encrypted data and subsequent operations;

[0048] The data verification and anomaly detection module is used to ensure the consistency of on-chain and off-chain data by establishing real-time evidence storage, terminal verification and full verification mechanisms. It combines the correlation graph model and spatiotemporal graph convolutional network to analyze the full data to identify anomalies and provide anomaly detection basis for intelligent early warning.

[0049] The strategy execution module is used to execute tiered response strategies based on on-chain early warning rules and anomaly detection results, forming a regulatory closed loop.

[0050] Thirdly, the present invention provides a blockchain-based data security protection device for refined oil supervision, and the technical solution adopted to solve the above-mentioned technical problems is as follows:

[0051] A blockchain-based data security protection device for refined oil supervision includes: at least one memory and at least one processor;

[0052] The at least one memory is used to store a machine-readable program;

[0053] The at least one processor is used to invoke the machine-readable program to implement the refined oil regulatory data security protection method described in the first aspect.

[0054] The present invention provides a blockchain-based method and system for protecting the security of refined oil regulatory data, which has the following advantages compared with the prior art:

[0055] This invention constructs a full-link security protection system based on a consortium blockchain architecture and smart contracts. It achieves encrypted protection, trusted identity authentication, real-time anti-tampering detection, and intelligent early warning response in all stages of data collection, transmission, storage, and application. This improves the security, credibility, and efficiency of refined oil regulatory data and solves technical problems in existing refined oil regulatory systems, such as data being easily tampered with, trust barriers in cross-departmental collaboration, the inability of traditional encryption methods to guarantee data integrity throughout the entire lifecycle, access control relying on centralized management which can easily lead to abuse of permissions, and lagging early warning mechanisms with low response efficiency. Attached Figure Description

[0056] Appendix Figure 1 This is a flowchart of the method according to Embodiment 1 of the present invention;

[0057] Appendix Figure 2 This is a flowchart of the user authentication process in step S3 of embodiment one of the present invention;

[0058] Appendix Figure 3 This is a flowchart of the early warning information uploading and evidence storage process in step S5 of embodiment one of the present invention;

[0059] Appendix Figure 4 This is a system module connection block diagram of Embodiment 2 of the present invention. Detailed Implementation

[0060] To make the technical solution, the technical problem solved, and the technical effect of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with specific embodiments.

[0061] The word memory in the embodiments is now explained as follows:

[0062] SE Security Element: A hardware security module with independent computing and storage capabilities, mainly used for data encryption, key management, and identity authentication. It can generate encryption keys (such as ECC private keys), store sensitive information, and provide logical-level security protection.

[0063] PUF chip (Physically Unclonable Function Chip): Based on hardware physical characteristics (such as differences in circuit manufacturing), it generates a unique and uncopyable "physical fingerprint" for unique authentication of device identity, belonging to the physical layer of anti-cloning security mechanism.

[0064] Example 1:

[0065] Combined with appendix Figure 1 This embodiment proposes a blockchain-based method for protecting the security of refined oil regulatory data, which includes the following steps:

[0066] S1. Deploy the consortium blockchain architecture and implement distributed storage to provide underlying support for subsequent processes.

[0067] This process specifically includes:

[0068] The consortium blockchain is built using the Hyperledger Fabric architecture, with regulatory authorities as consensus nodes and gas stations as data submission nodes. The PBFT consensus algorithm is used to ensure the consistency of on-chain data.

[0069] Data hashes and key metadata are stored on-chain, while raw business data is encrypted and stored in a distributed database. Smart contracts are used to link on-chain and off-chain data, laying the foundation for subsequent data encryption and identity authentication processes.

[0070] S2. Full-link encryption is implemented in the data collection, data transmission and evidence storage stages to provide secure data for blockchain storage.

[0071] This process specifically includes:

[0072] S2.1 During the data acquisition phase, when the two types of equipment, fuel dispenser encoders and level gauges, generate raw business data, they use the AES-256 algorithm for block encryption. At the same time, the equipment's built-in SE security chip generates a hardware fingerprint based on ECC private key hash, and the PUF chip synchronously generates a unique response value bound to the hardware.

[0073] S2.2 In the data transmission and storage stage, the encrypted data is first symmetrically encrypted using the SM4 algorithm to improve transmission efficiency, and then the SM4 key is encrypted using the SM2 asymmetric encryption algorithm to ensure key security, forming an SM2-SM4 hybrid encryption protocol processing flow. The processed encrypted data generates a SHA-256 hash value, which is signed by the data submission node with the SM2 private key and then uploaded to the chain, ensuring the confidentiality and integrity of the original business data from generation to uploading to the chain, and providing encrypted original data support for blockchain storage and subsequent anti-tampering detection.

[0074] S3. Complete the registration of device and user identities and the configuration of permissions, providing a security basis for secure access to encrypted data and subsequent operations.

[0075] This process specifically includes:

[0076] Each fuel dispenser is assigned a unique ID based on the ECC algorithm. After being bound to the hardware fingerprint generated by the SE security chip and the unique response value generated by the PUF chip, it is registered on the blockchain. The blockchain smart contract verifies the consistency between the unique response value and the fingerprint registered on the chain, thus confirming the identity of the device.

[0077] For user identity verification, regulators use a "digital certificate + blockchain address" system, with the certificate issued by the consortium blockchain CA node.

[0078] Combined with appendix Figure 2 When authenticating users, users first input their biometric features (fingerprint / face). The terminal generates a biometric hash, the SE security chip sends a zero-knowledge proof request, the blockchain verifies the user's identity credentials, and the smart contract returns a verification result containing a permission token. After successful verification, the terminal accesses the data with the blockchain token. At the same time, role-based permission management is implemented through access control smart contracts to ensure that only authenticated and authorized entities can operate the data, providing identity and permission guarantees for subsequent data use and early warning response.

[0079] S4. By establishing real-time evidence storage, terminal verification, and full verification mechanisms, the consistency of on-chain and off-chain data is ensured. By combining the correlation graph model and spatiotemporal graph convolutional network analysis, the full data is used to identify anomalies, providing a basis for anomaly detection for intelligent early warning.

[0080] This process specifically includes:

[0081] S4.1 Establish a real-time evidence storage mechanism. Calculate the hash value and upload it to the blockchain within 5 seconds of each fuel transaction being generated. Blocks form a chain structure through forward hash links to achieve streaming hash comparison and verify the integrity of individual data in real time.

[0082] S4.2. Each time the fuel dispenser encoder makes a measurement, it generates a hash of "measurement value + device ID + timestamp" and uploads it to the blockchain. The terminal compares the local data with the hash value on the blockchain in real time. When the number of out-of-tolerance times reaches 5 or more in a continuous operation cycle, the machine is automatically locked. At the same time, the abnormal log is recorded and uploaded to the blockchain for evidence storage.

[0083] S4.3 The supervisory node triggers full data verification daily, comparing the hash value of the data stored in the distributed database with the on-chain evidence record. If they are inconsistent, they are marked as abnormal, and hardware fingerprint verification is performed at set intervals.

[0084] S4.4. Based on the daily accumulation of full data through real-time and periodic verification, a correlation graph model is constructed. The correlation graph model uses three types of data—fueling transaction records, liquid level data, and tax invoices—as the core nodes in the graph. Quantitative business logic (such as the deviation threshold between fueling volume and liquid level consumption ≤ 3%, and the matching error between invoice amount and transaction amount ≤ 5%) is used as the correlation edges. The GNN algorithm is used to traverse and analyze all nodes and correlation edges to identify abnormal data chains (such as excessive deviation between fueling volume and liquid level consumption, and mismatch between invoice amount and transaction record). Combined with spatiotemporal data (such as fueling time series and tank temperature / pressure change curves), the spatiotemporal dynamic features of the data are extracted through a spatiotemporal graph convolutional network to identify time-series anomalies (such as frequent deviations in measurement data within a short period of time, sudden temperature changes and deviations from historical curves, etc.) and capture state mutations.

[0085] The aforementioned real-time evidence storage, terminal verification, and full verification mechanisms are implemented in parallel or interleaved time, and support each other in terms of data, forming a multi-dimensional, full-cycle anti-tampering verification system.

[0086] S5. Based on on-chain early warning rules and anomaly detection results, a tiered response strategy is implemented to form a regulatory closed loop.

[0087] Combined with appendix Figure 3 This process specifically includes:

[0088] S5.1 Predefine early warning rules through smart contracts and store them on the blockchain;

[0089] S5.2 When the refueling machine sends data encrypted with SM4 and signed with SM2, the edge gateway submits the data and signature, and the blockchain executes the smart contract for verification;

[0090] S5.3 When verification fails, the tampering event is recorded in the block, a real-time alarm is sent via WebSocket, and the event is handled according to the hierarchical response strategy.

[0091] S5.4 After an early warning event is triggered, logs are recorded on the chain and external systems are called to send alarms. At the same time, a rectification work order is generated and stored on the chain, forming a complete regulatory closed loop from anomaly detection to handling.

[0092] The warning rules involved include the following risk calculation formulas:

[0093] Risk value=α·ΔT+β·(dP / dt)+γ·Hlevel+δ·f(weather),

[0094] Where α, β, γ, and δ are dynamic coefficients optimized through reinforcement learning; ΔT is the rate of change of tank temperature; dP / dt is the rate of change of tank pressure; H level is the oil level; f(weather) is the weather risk factor.

[0095] The tiered response strategies involved include:

[0096] A single device malfunction triggers a Level 1 warning, which activates a pop-up window on the large screen and an on-site audible and visual alarm.

[0097] Multiple device malfunctions trigger a Level 2 warning, automatically locking the devices and sending an SMS notification to the responsible person.

[0098] The regional anomaly is classified as a Level 3 warning, triggering an emergency response and freezing the account.

[0099] Example 2:

[0100] Combined with appendix Figure 4This embodiment proposes a blockchain-based data security protection system for refined oil regulatory data, which is used to implement the data security protection method for refined oil regulatory data described in Embodiment 1. Its structure includes:

[0101] The blockchain infrastructure module is used to deploy the consortium blockchain architecture and implement distributed storage, providing underlying support for subsequent processes;

[0102] The end-to-end data encryption module is used to perform end-to-end encryption in the data acquisition, data transmission and evidence storage stages, providing secure data for blockchain storage;

[0103] The identity authentication and access control module is used to complete the identity registration and permission configuration of devices and users, and to provide a security basis for secure access to encrypted data and subsequent operations;

[0104] The data verification and anomaly detection module is used to ensure the consistency of on-chain and off-chain data by establishing real-time evidence storage, terminal verification and full verification mechanisms. It combines the correlation graph model and spatiotemporal graph convolutional network to analyze the full data to identify anomalies and provide anomaly detection basis for intelligent early warning.

[0105] The strategy execution module is used to execute tiered response strategies based on on-chain early warning rules and anomaly detection results, forming a regulatory closed loop.

[0106] Example 3:

[0107] This embodiment also provides a blockchain-based data security protection device for refined oil supervision, which includes: at least one memory and at least one processor;

[0108] The at least one memory is used to store a machine-readable program;

[0109] The at least one processor is used to call the machine-readable program to implement the refined oil regulatory data security protection method described in Embodiment 1.

[0110] The processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor can be a microprocessor or any conventional processor.

[0111] Memory is used to store computer programs and / or modules. The processor implements various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory, and by accessing data stored in the memory. Memory can mainly include a program storage area and a data storage area. The program storage area can store the operating system, at least one application program required for a function, etc.; the data storage area can store data created based on the use of the terminal, etc. In addition, memory can also include high-speed random access memory, and can also include non-volatile memory, such as hard disks, RAM, plug-in hard disks, smart memory cards (SMC), secure digital cards (SD cards), flash memory cards, at least one disk storage device, flash memory devices, or other volatile solid-state storage devices.

[0112] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A blockchain-based method for protecting the security of refined oil regulatory data, characterized in that, Includes the following steps: S1. Deploy the consortium blockchain architecture and implement distributed storage to provide underlying support for subsequent processes; S2. Full-link encryption is implemented in the data collection, data transmission and evidence storage stages to provide secure data for blockchain storage; S3. Complete the device and user identity registration and permission configuration to provide a security basis for secure access to encrypted data and subsequent operations; S4. By establishing real-time evidence storage, terminal verification and full verification mechanisms, we ensure the consistency of on-chain and off-chain data. By combining the correlation graph model and spatiotemporal graph convolutional network to analyze the full data and identify anomalies, we provide anomaly detection basis for intelligent early warning. S5. Based on on-chain early warning rules and anomaly detection results, a tiered response strategy is implemented to form a regulatory closed loop.

2. The method for protecting the security of refined oil regulatory data based on blockchain according to claim 1, characterized in that, Step S1 specifically includes: The consortium blockchain is built using the Hyperledger Fabric architecture, with regulatory authorities as consensus nodes and gas stations as data submission nodes. The PBFT consensus algorithm is used to ensure the consistency of on-chain data. Data hashes and key metadata are stored on-chain, while raw business data is encrypted and stored in a distributed database. Smart contracts are used to link on-chain and off-chain data, laying the foundation for subsequent data encryption and identity authentication processes.

3. The method for protecting the security of refined oil regulatory data based on blockchain according to claim 2, characterized in that, Step S2 specifically includes: S2.1 During the data acquisition phase, when the two types of equipment, fuel dispenser encoders and level gauges, generate raw business data, they use the AES-256 algorithm for block encryption. At the same time, the equipment's built-in SE security chip generates a hardware fingerprint based on ECC private key hash, and the PUF chip synchronously generates a unique response value bound to the hardware. S2.2 In the data transmission and storage stage, the encrypted data is first symmetrically encrypted using the SM4 algorithm to improve transmission efficiency, and then the SM4 key is encrypted using the SM2 asymmetric encryption algorithm to ensure key security, forming an SM2-SM4 hybrid encryption protocol processing flow. The processed encrypted data generates a SHA-256 hash value, which is signed by the data submission node with the SM2 private key and then uploaded to the chain, ensuring the confidentiality and integrity of the original business data from generation to uploading to the chain, and providing encrypted original data support for blockchain storage and subsequent anti-tampering detection.

4. The method for protecting the security of refined oil regulatory data based on blockchain according to claim 3, characterized in that, Step S3 specifically includes: Each fuel dispenser is assigned a unique ID based on the ECC algorithm. After being bound to the hardware fingerprint generated by the SE security chip and the unique response value generated by the PUF chip, it is registered on the blockchain. The blockchain smart contract verifies the consistency between the unique response value and the fingerprint registered on the chain, thus confirming the identity of the device. For user identity verification, regulators use a "digital certificate + blockchain address" system, with the certificate issued by the consortium blockchain CA node. During user authentication, the user's biometric features are first entered. The terminal generates a biometric hash, the SE security chip sends a zero-knowledge proof request, the blockchain verifies the user's identity credentials, and the smart contract returns a verification result containing an authorization token. After successful verification, the terminal accesses the data with the blockchain token. At the same time, role-based access control is implemented through access control smart contracts to ensure that only authenticated and authorized entities can operate the data, providing identity and authorization guarantees for subsequent data use and early warning response.

5. A method for protecting the security of refined oil regulatory data based on blockchain according to claim 4, characterized in that, Step S4 specifically includes: S4.1 Establish a real-time evidence storage mechanism. Calculate the hash value and upload it to the blockchain within 5 seconds of each fuel transaction being generated. Blocks form a chain structure through forward hash links to achieve streaming hash comparison and verify the integrity of individual data in real time. S4.

2. Each time the fuel dispenser encoder makes a measurement, it generates a hash of "measurement value + device ID + timestamp" and uploads it to the blockchain. The terminal compares the local data with the hash value on the blockchain in real time. When the number of out-of-tolerance times reaches 5 or more in a continuous operation cycle, the machine is automatically locked. At the same time, the abnormal log is recorded and uploaded to the blockchain for evidence. S4.3 The supervisory node triggers full data verification daily, comparing the hash value of the data stored in the distributed database with the on-chain evidence record. If they are inconsistent, they are marked as abnormal, and hardware fingerprint verification is performed at set intervals. S4.

4. Based on the full amount of data accumulated through daily real-time and periodic verification, a relational graph model is constructed. The relational graph model uses three types of data—fueling flow, liquid level data, and tax invoices—as the core nodes in the graph, and quantitative business logic as the relational edges. The GNN algorithm is used to traverse and analyze all nodes and relational edges to identify abnormal data chains. In addition, combined with spatiotemporal data, the spatiotemporal dynamic features of the data are extracted through a spatiotemporal graph convolutional network to identify time-series anomalies and capture state mutations.

6. A method for protecting the security of refined oil regulatory data based on blockchain according to claim 5, characterized in that, Step S5 specifically includes: S5.

1. Predefine early warning rules through smart contracts and store them on the blockchain; S5.2 When the refueling machine sends data encrypted with SM4 and signed with SM2, the edge gateway submits the data and signature, and the blockchain executes the smart contract for verification; S5.3 When verification fails, the tampering event is recorded in the block, a real-time alarm is sent via WebSocket, and the event is handled according to the hierarchical response strategy. S5.4 After an early warning event is triggered, logs are recorded on the chain and external systems are called to send alarms. At the same time, a rectification work order is generated and stored on the chain, forming a complete regulatory closed loop from anomaly detection to handling.

7. A method for protecting the security of refined oil regulatory data based on blockchain according to claim 6, characterized in that, The early warning rules include the following risk calculation formula: Risk value=α·ΔT+β·(dP / dt)+γ·Hlevel+δ·f(weather), Where α, β, γ, and δ are dynamic coefficients optimized through reinforcement learning; ΔT is the rate of change of tank temperature; dP / dt is the rate of change of tank pressure; H level is the oil level; f(weather) is the weather risk factor.

8. A method for protecting the security of refined oil regulatory data based on blockchain according to claim 6, characterized in that, The hierarchical response strategy includes: A single device malfunction triggers a Level 1 warning, which activates a pop-up window on the large screen and an on-site audible and visual alarm. Multiple device malfunctions trigger a Level 2 warning, automatically locking the devices and sending an SMS notification to the responsible person. The regional anomaly is classified as a Level 3 warning, triggering an emergency response and freezing the account.

9. A blockchain-based data security protection system for refined oil product supervision, characterized in that, The method for protecting the data security of refined oil supervision as described in any one of claims 1-8 has the following structure: The blockchain infrastructure module is used to deploy the consortium blockchain architecture and implement distributed storage, providing underlying support for subsequent processes; The end-to-end data encryption module is used to perform end-to-end encryption in the data acquisition, data transmission and evidence storage stages, providing secure data for blockchain storage; The identity authentication and access control module is used to complete the identity registration and permission configuration of devices and users, and to provide a security basis for secure access to encrypted data and subsequent operations; The data verification and anomaly detection module is used to ensure the consistency of on-chain and off-chain data by establishing real-time evidence storage, terminal verification and full verification mechanisms. It combines the correlation graph model and spatiotemporal graph convolutional network to analyze the full data to identify anomalies and provide anomaly detection basis for intelligent early warning. The strategy execution module is used to execute tiered response strategies based on on-chain early warning rules and anomaly detection results, forming a regulatory closed loop.

10. A blockchain-based data security protection device for refined oil product supervision, characterized in that, include: At least one memory and at least one processor; The at least one memory is used to store a machine-readable program; The at least one processor is used to invoke the machine-readable program to implement the data security protection method for refined oil supervision as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Intelligent suspicious transaction monitoring method based on semi-supervised graph neural network

    CN110400220A

  • Intelligent supervisory system for circulation data of product oil and tamper-resistant method of intelligent supervisory system

    CN117313169A

Cited By

  • Data acquisition method and device based on block chain tamper-proofing

    CN121302445A