Access method and system of inland shipping data trusted space under zero trust
By constructing a trusted space using blockchain and federated learning technologies, the problems of static trust assessment and information silos in inland waterway shipping data security governance have been solved. This has enabled precise traceability and real-time access control throughout the entire data lifecycle, thereby enhancing the security and collaborative defense capabilities of the Jianghuai inland waterway shipping ecosystem.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ANHUI UNIV
- Filing Date
- 2026-04-25
- Publication Date
- 2026-06-23
AI Technical Summary
Existing technologies in inland waterway shipping data security governance suffer from problems such as static trust assessment, isolated security information, rigid security strategies, disconnected security processes, and disconnect between technology and business scenarios. These issues result in insufficient security system effectiveness and an inability to meet security needs in complex and open environments.
By employing blockchain, zero-trust strategy, and federated learning technology, a trusted space is constructed to achieve dynamic trust assessment and hierarchical access control. Through blockchain evidence storage and verification, and federated learning to optimize risk scoring, information silos are broken down and security collaboration capabilities are enhanced.
It enables precise traceability and reliable evidence storage throughout the entire data lifecycle, improves the real-time nature and accuracy of access control, breaks down security silos, enhances overall defense capabilities, and meets the security and business needs of the Jianghuai inland waterway shipping ecosystem.
Smart Images

Figure CN122093198B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of trusted and shared authentication technology for inland waterway shipping data in the Jianghuai region, and particularly to a method and system for accessing a trusted space for inland waterway shipping data under zero trust. Background Technology
[0002] With the accelerated digitalization of inland waterway transportation, the Jianghuai inland waterway transportation system has evolved into a complex digital ecosystem deeply interconnected with ships, shore-based facilities, sensing networks, and management platforms. The static network boundaries relied upon by traditional security models have largely disappeared in this environment. Data flows frequently between ships, ports, cargo, and pipelines, dramatically expanding the entry paths and impact scope of security threats. Zero-trust architecture, as a security paradigm centered on identity and context, provides theoretical guidance for addressing the inherent risks in such open environments. However, applying the zero-trust concept to the specific field of shipping faces unique challenges that transcend general IT scenarios: First, the objects of trust assessment are extremely diverse, including not only user accounts but also entities such as smart ships, shipboard terminals, and IoT sensors, requiring a comprehensive judgment based on both physical status and network behavior. Second, risks exhibit spatiotemporal correlation and group diffusion; for example, an abnormal trajectory of a single ship may indicate risks to regional navigation order, and traditional isolated detection methods struggle to perceive such related threats from a global perspective. Third, security strategies must be seamlessly coupled with the highly real-time nature of shipping operations (such as dynamic scheduling, dangerous goods supervision, and emergency command), and any access control decisions must be completed within a very short time while ensuring business continuity. Therefore, building a trusted data space that deeply integrates the characteristics of shipping operations and enables dynamic trust measurement and collaborative risk perception has become a key infrastructure and urgent technological requirement for promoting the high-quality development of inland waterway shipping in the Jianghuai region.
[0003] Existing technologies for inland waterway shipping data security governance suffer from systemic deficiencies, which are interconnected and collectively hinder the development of a comprehensive solution. First, data trust assessment mechanisms are generally weak, relying mostly on pre-set, static identity credentials. They lack dynamic collection and quantitative analysis of multi-dimensional signals such as the compliance of continuous entity behavior, equipment health, and operational context, resulting in delayed and one-sided trust judgments and an inability to accurately identify "malicious behavior under a legitimate identity." Second, participating entities exist in a state of security information silos, lacking effective mechanisms to reach consensus on regional and group risks while protecting data privacy. This prevents the rapid transformation of locally discovered new attack patterns or abnormal situations into shared defense knowledge across the entire shipping ecosystem, hindering the collaborative evolution of security capabilities. Third, security policy engines are rigid, typically based on simple static "role-permission" mappings or coarse-grained conditional rules. They cannot automatically implement fine-grained, differentiated access authorization based on real-time calculated dynamic trust scores, global risk profiles, and data resource sensitivity, resulting in severely insufficient adaptive adjustment capabilities in the face of advanced persistent threats. Furthermore, security processes ranging from identity verification and access control to behavior auditing are often disconnected, failing to achieve reliable recording and correlation analysis of data throughout the entire process through an immutable trust foundation. This leads to difficulties in post-incident tracing, unclear liability definition, and a lack of reliable data support for optimizing security strategies. Finally, and most importantly, many existing solutions are simple transplants of general security technologies, failing to deeply adapt to the specific constraints of inland waterway shipping in terms of business processes, data formats, communication environments, and regulatory standards. This can easily cause friction between security measures and business operations, even affecting normal navigation safety and operational efficiency, fundamentally limiting the actual effectiveness and practical value of the security system. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention provides a method and system for accessing a trusted space for inland waterway shipping data under a zero-trust framework. It solves the problems of static and one-sided trust assessment, isolated and uncoordinated security information, rigid and insufficiently adaptive security strategies, disconnected security processes and difficulties in traceability, and disconnect between technology and inland waterway shipping business scenarios. This invention addresses the characteristics of inland waterway shipping scenarios, including diverse participating entities, high data sensitivity, and a complex and open business environment. It abandons simply stacking security technologies and deeply integrates three major technological pillars: blockchain, zero-trust strategy, and federated learning. This constructs a complete closed-loop shipping data governance framework. Based on blockchain, it builds a verifiable trusted shipping space including shipping trust status and transformation rules, enabling precise traceability and reliable evidence storage throughout the entire data lifecycle. Dynamic risk assessment and hierarchical access decisions enable access control, achieving real-time and fine-grained access control. Simultaneously, the federated learning architecture improves the accuracy of shipping behavior risk scoring, thereby breaking down information silos and achieving the collaborative evolution and proactive improvement of the security defense capabilities of the entire Jianghuai inland waterway shipping ecosystem.
[0005] To achieve the above technical objectives, the present invention provides the following technical solution: a method for accessing a trusted space for inland waterway shipping data under zero trust, comprising the following steps:
[0006] Define the shipping trust state of participating entities; the shipping trust state includes: baseline trust, shipping behavior credit score, shipping ecosystem reputation value, and entity shipping attribute vector;
[0007] The baseline trust includes the on-chain hash storage and verification status of ship registration certificates and crew competency certificates; the entity shipping attribute vector includes ship tonnage, route permits, cargo dangerous goods class, and company safety rating.
[0008] Define conversion rules, which combine compliance proofs and shipping trust events to update the shipping trust status of participating entities;
[0009] A risk scoring model is constructed to calculate the risk score of flight behavior. At the same time, the risk scoring model is optimized and updated based on federated learning to improve the accuracy of flight behavior risk scoring and update the logs.
[0010] A trust calculation function is constructed based on shipping context sequence, shipping behavior risk score, and combined with baseline trust, shipping behavior credit score and shipping ecosystem reputation value to calculate the dynamic trust value when participating entities request access to shipping data resources.
[0011] The shipping context sequence includes the geographical location initiating the data access request, the timestamp of the data access request, the security status of the device initiating the data access request, and the shipping business operation stage.
[0012] Design hierarchical access decision rules, define decision boundary thresholds, and perform hierarchical authorization based on dynamic trust values calculated by the trust calculation function to generate access decisions and realize access control.
[0013] Access logs are accessed, and the hash value of the logs is submitted to the blockchain, driving the shipping trust status of participating entities to be updated based on the conversion rules, forming a closed loop of credit update and access control.
[0014] Optionally, the transition rule updates the shipping trust state based on the following state transition function:
[0015] ;
[0016] in, This indicates the shipping trust status of the participating entities. This refers to trusted shipping events, including shipping operations and secure transactions. A certificate indicating compliance with shipping regulatory requirements. This represents a state transition function specific to shipping. Indicates time, Indicates the type index of the participating entity;
[0017] The shipping-specific state transition function, designed based on a shipping rule smart contract, includes the following:
[0018] When shipping trusted events For a compliant shipping transaction to be completed and compliance certification When effective, the participating entity's shipping behavior credit score will be increased;
[0019] When shipping trusted events When a safety violation occurs, the participating entity's shipping behavior credit score is reduced;
[0020] The shipping ecosystem reputation score is updated by aggregating feedback from other participating entities.
[0021] Optionally, the risk scoring model is used to assess the participating entities at time [time]. Flight behavior sequence characteristics As input, output is an operational risk score;
[0022] The optimization and updating of the risk scoring model based on federated learning includes:
[0023] A risk scoring dataset is constructed based on the collection of local privacy data held by each participating entity; after each output is run as a risk score, a learning cycle is entered, and the risk scoring model is trained by federated learning using the risk scoring dataset. The updated risk scoring model is used for the next run as a risk score calculation, and the risk scoring model is optimized and updated in real time.
[0024] The risk scoring dataset includes flight behavior sequence features and labels;
[0025] The labels represent the true values of the flight behavior risk scores for each participating entity.
[0026] Optionally, the optimization and updating of the risk scoring model based on federated learning further includes: within each learning cycle:
[0027] Distribute the global model parameters of the risk scoring model to each participating entity;
[0028] Each participating entity calculates the loss function and gradient locally, performs privacy protection processing on the gradient, and submits the gradient contribution proof to the blockchain.
[0029] The privacy-preserving gradients are securely aggregated to update the global model parameters. The mathematical representation of this secure aggregation is as follows:
[0030] ;
[0031] in, Indicates the first Global model parameters for each learning cycle. After privacy protection processing The gradient of shipping participants This indicates the total number of shipping participants. Indicates the first Local privacy data held by each shipping participant This represents a risk scoring dataset. Indicates the learning rate. Indicates the first The percentage of local privacy data samples from each shipping participant in the total risk scoring dataset;
[0032] Update global model parameters The hash value is anchored to the blockchain;
[0033] The risk scoring model is deployed in the dynamic trust assessment engine of each participating entity;
[0034] The dynamic trust assessment engine updates the log and provides feedback on the updated labels in the risk score dataset. The updated risk score dataset is then used for federated learning in the next learning cycle.
[0035] Optionally, the loss function is the mean squared error loss calculated between the flight behavior risk score output by the risk scoring model and the label in the current risk score dataset.
[0036] Optionally, the log is defined as follows:
[0037] ;
[0038] in, Represents a log. Indicates participating entities, Represents shipping data resources. Indicates dynamic trust value. Indicates the access decision. This indicates a shipping context sequence.
[0039] Optionally, the trust calculation function is described by the following equation:
[0040] ;
[0041] in, Indicates participating entities At any moment Request to access shipping data resources Dynamic trust value; Indicates participating entities Baseline trust; Indicates participating entities The airline's credit score; Indicates participating entities The shipping ecosystem reputation value; Indicates time The shipping context sequence is defined as:
[0042] ;
[0043] in, Indicates the geographical location from which the data access request was initiated. Indicates the timestamp of the data access request. This indicates the security status of the device that initiated the data access request. Indicates the stage of shipping operations; Represents the shipping context factor function, in the form of a shipping context sequence. As input, output normalized shipping context trust contribution; Indicates participating entities At any moment The flight behavior risk score, and ; Indicates credit score based on airline behavior With shipping ecosystem reputation value The reward function is defined as: ;in , These represent the weighting coefficients for shipping behavior credit score and shipping ecosystem reputation value, respectively. This represents the maximum credit score for airline operations; The weighting coefficients for baseline trust. The weighting coefficients contributing to shipping context trust. Weighting coefficients for risk scoring of air travel behavior. This represents the weighting coefficient for the reward item.
[0044] Optionally, the hierarchical access decision rules include:
[0045] Define decision boundary thresholds, including the high-level trust threshold required to grant full access. The minimum trust threshold required to grant any access rights ;
[0046] like Grant full access to the data;
[0047] like Grant data anonymization access permissions or access permissions for certain data fields;
[0048] like ,access denied;
[0049] in This represents the dynamic trust value calculated by the trust computation function.
[0050] This invention also provides an access system for a trusted space for inland waterway shipping data under zero trust, used to apply the access method for the trusted space for inland waterway shipping data under zero trust, including:
[0051] The federated learning collaboration layer is used to build a risk scoring model to calculate the risk score of flight behavior, and at the same time optimizes and updates the risk scoring model based on federated learning to improve the accuracy of flight behavior risk scoring and update the logs.
[0052] The zero-trust dynamic trust layer includes a dynamic trust calculation function module and a hierarchical access decision module. It is used to receive the flight behavior risk score from the federated learning collaboration layer, calculate the dynamic trust value, perform hierarchical authorization, realize access control, and output access decisions to the blockchain trusted base layer.
[0053] The blockchain trusted base layer is used to store shipping rule smart contracts, store and update shipping trust status based on transformation rules, store access decisions from the zero-trust dynamic trust layer, access logs, and submit the hash values of the logs to the blockchain.
[0054] Optionally, the federated learning collaboration layer is equipped with a coordinator node for distributing and securely aggregating global model parameters;
[0055] The dynamic trust calculation function module is used to construct a trust calculation function, which calculates the dynamic trust value when a participating entity requests access to shipping data resources based on the shipping context sequence, shipping behavior risk score, baseline trust, shipping behavior credit score and shipping ecosystem reputation value.
[0056] The hierarchical access decision module is used to design hierarchical access decision rules, perform hierarchical authorization based on the shipping data security level and the dynamic trust value calculated by the trust calculation function, and generate access decisions.
[0057] By employing the above technical solution, the present invention provides a method and system for accessing the trusted space of inland waterway shipping data under zero trust, which has at least the following beneficial effects:
[0058] (1) This invention constructs a verifiable shipping trust space based on blockchain, including shipping trust status and conversion rules. By utilizing the distributed ledger and smart contract technology of blockchain, the digital identities and key behaviors of ships, equipment and users are stored and verified on the chain, establishing an immutable trust anchor point. This provides shipping data with an immutable trust anchor point and full life cycle traceability capability, fundamentally ensuring the credibility of the data source and the transparency of the flow process, and realizing accurate traceability and credible storage of data throughout its entire life cycle.
[0059] (2) This invention achieves access control by performing dynamic risk assessment and hierarchical access decision-making. Relying on a multi-factor fusion trust calculation function, it quantifies and integrates on-chain credit, real-time behavioral risk and contextual environment, realizing the transformation from static identity authentication to continuous behavioral trust assessment, significantly improving the accuracy of access control decision-making and context awareness, and realizing the real-time and fine-grained nature of access control.
[0060] (3) This invention improves the accuracy of shipping behavior risk scoring by leveraging the privacy computing advantages of federated learning, enabling all shipping participants to jointly train and update the risk scoring model without aggregating raw data and with data privacy strictly protected. This achieves simultaneous improvement in security sharing and overall defense capabilities, effectively breaking down security silos.
[0061] (4) By constructing a system that organically integrates a three-layer architecture of “model training-evaluation control-credible evidence storage and status assessment”, this invention transforms the zero-trust principle into a measurable, auditable and adaptive operating system, providing a systematic solution for the Jianghuai inland waterway shipping that takes into account strict safety, business efficiency and compliance requirements, and realizing the coordinated evolution and proactive improvement of the entire Jianghuai inland waterway shipping ecosystem's security defense capabilities. Attached Figure Description
[0062] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0063] Figure 1 This is a flowchart of the method for accessing the trusted space of inland waterway shipping data under zero trust in this invention;
[0064] Figure 2 This is a structural framework diagram of the access system for the trusted space of inland waterway shipping data under zero trust in this invention;
[0065] Figure 3 This is a schematic diagram of the actual process for inland waterway vessel data access and sharing under a zero-trust architecture based on the method and system of this invention. Detailed Implementation
[0066] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. This will allow for a full understanding of how the present application uses technical means to solve technical problems and achieve technical effects, and to facilitate its implementation.
[0067] Those skilled in the art will understand that all or part of the steps in the implementation of the methods of the embodiments can be implemented by a program instructing related hardware. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0068] Please refer to Figures 1-3This illustration demonstrates a specific implementation of this embodiment. This embodiment defines the shipping trust status and transition rules of participating entities, introduces federated learning to improve the accuracy of shipping behavior risk scoring, constructs a trust calculation function to calculate dynamic trust values in real time, designs hierarchical access decision rules for hierarchical authorization, realizes access control, submits the hash value of the log to the blockchain to drive the update of shipping trust status, and forms a closed loop of credit update and access control. This provides a systematic solution for the Jianghuai inland waterway shipping that takes into account strict security, business efficiency and compliance requirements, and realizes the coordinated evolution and proactive improvement of the security defense capabilities of the entire Jianghuai inland waterway shipping ecosystem.
[0069] Please refer to Figure 1 This embodiment proposes a method for accessing the trusted space of inland waterway shipping data under zero trust, which includes the following steps:
[0070] S1. Define the shipping trust status of the participating entities.
[0071] As a preferred embodiment of step S1, it specifically includes:
[0072] At any moment Shipping trust status Composed of all participating entities (the types of participating entities include ships, shipping companies, port users, etc., represented by the type index). The set of trust vectors constitutes the set of trust vectors, mathematically represented as:
[0073] ;
[0074] in, Indicates time Participating entities The trust vector, where any entity Trust vector Represented as:
[0075] ;
[0076] in, It represents the baseline trust based on blockchain digital identity (DID) or compliant digital certificates, such as the on-chain hash storage and verification status of ship registration certificates and seafarer competency certificates; It represents the credit score of shipping behavior, which is dynamically calculated and adjusted based on the participating entity's historical compliance in shipping activities (such as AIS track compliance, accuracy of declaration information, security inspection records, etc.). It represents the reputation value of the shipping ecosystem, which is aggregated from evaluation feedback from other related entities (such as ports, cargo owners, insurance companies, etc.) through on-chain smart contracts; This represents a vector of shipping attributes, such as vessel tonnage, route permits, cargo hazard class, and company safety rating.
[0077] S2. Define the transformation rules to update the shipping trust status.
[0078] As a preferred embodiment of step S2, it specifically includes:
[0079] The updating of the shipping trust state is driven by shipping rule smart contracts deployed on the blockchain; the updating of the shipping trust state is completed based on the following state transition function:
[0080] ;
[0081] in, This refers to trusted shipping events, including shipping operations and secure transactions. Proof of compliance that meets shipping regulatory requirements (such as electronic visa signatures, etc.). This represents a state transition function specific to shipping. Indicates time, Indicates the type index of the participating entity.
[0082] Shipping-specific state transition functions Based on the design of on-chain shipping rule smart contracts, according to the shipping trusted events and compliance certification State of trust in shipping The components in the document are updated, and the specific content includes:
[0083] When shipping trusted events For a compliant shipping transaction to be completed and compliance certification When effective, the participating entity's shipping behavior credit score will be increased;
[0084] When shipping trusted events When a safety violation occurs, the participating entity's shipping behavior credit score is reduced;
[0085] The shipping ecosystem reputation value is updated by aggregating evaluation feedback from other participating entities through shipping rule smart contracts.
[0086] The update of the shipping trust state is driven by a shipping rules smart contract deployed on the blockchain, which encodes the specific transition rules mentioned above.
[0087] The participating entities and conversion rules defined in steps S1 and S2 constitute a verifiable shipping trust space based on blockchain. This aims to establish a globally synchronized and tamper-proof trust anchor and audit traceability layer for the Jianghuai inland waterway shipping ecosystem. By constructing a verifiable shipping trust space based on blockchain, including shipping trust status and conversion rules, and utilizing blockchain's distributed ledger and smart contract technology, the digital identities and key behaviors of ships, equipment, and users are stored and verified on-chain. This establishes an tamper-proof trust anchor, providing shipping data with an tamper-proof trust anchor and full lifecycle traceability capabilities. This fundamentally ensures the credibility of the data source and the transparency of the flow process, achieving accurate traceability and credible storage of data throughout its entire lifecycle.
[0088] S3. Construct a risk scoring model to calculate the risk score of flight behavior. At the same time, optimize and update the risk scoring model based on federated learning to improve the accuracy of flight behavior risk scoring and update the logs.
[0089] As a preferred embodiment of step S3, the specific process includes:
[0090] S31. Construct a risk scoring dataset based on the collection of local privacy data held by each shipping participant (i.e., participating entity). , of which The local privacy data held by each shipping participant is denoted as Risk scoring dataset Including all participating entities Flight behavior sequence characteristics and tags (The true value of the continuous shipping behavior risk score is generated by each shipping participant based on the security events in their local audit logs through preset assessment rules.)
[0091] S32. Define the risk scoring model This is a model based on shipping anomaly detection, used to identify potential risk patterns from shipping behavior sequences. Its specific structure can be selected or constructed according to needs, using machine learning models suitable for sequence data processing, such as Recurrent Neural Networks (RNNs), Long Short-Term Memory Networks (LSTMs), or Transformer encoders, and then collaboratively trained and optimized through a subsequent federated learning process. Risk scoring model. The input is the participating entity At any moment Flight behavior sequence characteristics (e.g., AIS trajectory sequence deviation, cargo declaration and inspection record timing, frequency and pattern of access to sensitive data), outputting the corresponding air traffic behavior risk score. .
[0092] S33. After each output flight behavior risk score, a learning cycle begins. The risk score model is trained using federated learning on the risk score dataset. Specifically, within each learning cycle:
[0093] S331, Global model parameters of the risk scoring model are sent to each shipping participant.
[0094] S332. Each shipping participant calculates the loss function locally. With gradient , for gradient Privacy protection measures will be implemented, and gradient contribution proofs will be used. Submit to the blockchain to ensure that gradient contributions are auditable;
[0095] The loss function used in this invention is the mean squared error loss calculated between the flight behavior risk score output by the risk scoring model and the label in the current risk score dataset, and its mathematical expression is as follows:
[0096] ;
[0097] in Represents global model parameters; Indicates the first Local privacy data held by each shipping participant The number of samples; This represents the first [item] in the risk score dataset. The label of each sample (i.e., the true value of the flight behavior risk score); This indicates the risk scoring model in terms of global model parameters. The output of the following is a risk score for the running behavior.
[0098] S333. Securely aggregate the privacy-preserving gradients and update the global model parameters. The mathematical representation of the secure aggregation is as follows:
[0099] ;
[0100] in, Indicates the first Global model parameters for each learning cycle. After privacy protection processing A tiered structure of shipping participants This indicates the total number of shipping participants. This represents the learning rate, used to control the step size of parameter updates during training; Indicates the first The proportion of the number of samples of local privacy data of each shipping participant in the total number of samples in the risk scoring dataset is used as the weight coefficient of that shipping participant's gradient contribution.
[0101] S334. Update the global model parameters. The hash value is anchored to the blockchain to ensure that the risk scoring model version is trustworthy and its updates are traceable.
[0102] S335. The updated risk scoring model is deployed in the dynamic trust assessment engine of each shipping participant for use in the next run to calculate risk scores, thereby calculating more accurate shipping behavior risk scores.
[0103] S336, the dynamic trust assessment engine updates the log and provides feedback on the updated labels in the risk score dataset. The updated risk score dataset is then used for federated learning in the next learning cycle.
[0104] In this invention, "shared authentication" is a concise term that refers both to the trusted sharing and mutual recognition of risk intelligence in federated learning, and to the zero-trust data resource access authentication based on this. It fully encompasses the core value of this solution, from "capability co-construction" to "secure sharing."
[0105] The goal of step S3 is to collaboratively optimize the risk scoring model among all stakeholders in the Jianghuai inland waterway shipping industry through federated learning techniques. This will continuously improve the operational risk score. The accuracy of risk scores is ensured. Each time the system outputs a risk score, it uses the currently deployed, fixed model generated from the previous federated learning cycle, rather than initiating a new federated learning process. In actual operation, federated learning acts as a "background batch job" for model optimization, while the risk score acts as a "foreground real-time service" for the model's capabilities. By leveraging the privacy-preserving computational advantages of federated learning to improve the accuracy of shipping behavior risk scores, all shipping participants can jointly train and update the risk scoring model while ensuring strict data privacy protection. This achieves simultaneous improvement in security sharing and overall defense capabilities, effectively breaking down security silos.
[0106] S4. Construct a trust calculation function to calculate the dynamic trust value when participating entities request access to shipping data resources.
[0107] As a preferred embodiment of step S4, it specifically includes:
[0108] The trust calculation function is described by the following equation:
[0109] ;
[0110] in, Indicates participating entities At any moment Request to access shipping data resources Dynamic trust values (such as channel water temperature, ship position, cargo information, etc.); Indicates participating entities Baseline trust; Indicates participating entities The airline's credit score; Indicates participating entities The shipping ecosystem reputation value; Indicates time The shipping context sequence is defined as:
[0111] ;
[0112] in, Indicates the geographical location from which the data access request was initiated. Indicates the timestamp of the data access request. This indicates the security status of the device that initiated the data access request. Indicates the stage of shipping operations; Represents the shipping context factor function, in the form of a shipping context sequence. Using this as input, calculate the normalized shipping context trust contribution; shipping behavior risk score. From the risk scoring model ; Indicates credit score based on airline behavior With shipping ecosystem reputation value The reward function is defined as: ;in , These represent the weighting coefficients for shipping behavior credit score and shipping ecosystem reputation value, respectively. This represents the maximum credit score for airline operations; The weighting coefficients for baseline trust; The weighting coefficients for the contribution of shipping context trust, determined by the current shipping context sequence, to the output of the shipping context factor function; The weighting coefficients for the aviation behavior risk score are intended to transform and characterize the aviation behavior risk score as a trust contribution value brought about by aviation behavior risk; For reward items The weighting coefficients, , , , It can be dynamically configured based on the sensitivity of shipping data resources.
[0113] In practical applications, flight behavior risk scoring factor functions can be used. Air traffic as a risk score This translates into trust contributions for risk scoring in the aviation industry.
[0114] S5. Design hierarchical access decision rules, define decision boundary thresholds, perform hierarchical authorization based on the dynamic trust value calculated by the trust calculation function, generate access decisions, and realize access control.
[0115] As a preferred embodiment of step S5, the hierarchical access decision rule specifically includes:
[0116] Define the high-level trust threshold required to grant full access. The minimum trust threshold required to grant any access rights (i.e., the admission threshold), and The threshold and The specific value can be dynamically configured according to the security level of the shipping data resources.
[0117] like Grant full access to the data;
[0118] like Grant data anonymization access permissions or access permissions for certain data fields;
[0119] like Access will be denied, and a second strong authentication may be required.
[0120] in This represents the dynamic trust value calculated by the trust computation function. and These constitute the decision boundary threshold.
[0121] Steps S4 and S5 are based on a dynamic trust calculation function specific to the shipping scenario. This function performs real-time, quantitative risk assessment and authorization decisions for each shipping data access request. By conducting dynamic risk assessment and hierarchical access decisions, access control is achieved. Relying on a multi-factor integrated trust calculation function, on-chain credit, real-time behavioral risks, and contextual environment are quantitatively integrated, realizing the transformation from static identity authentication to continuous behavioral trust assessment. This significantly improves the accuracy and contextual awareness of access control decisions, achieving real-time and fine-grained access control.
[0122] S6. Access log: Submit the hash value of the log to the blockchain to drive the shipping trust status of participating entities to be updated based on the conversion rules, forming a closed loop of credit update and access control.
[0123] The log definition used in this invention is as follows:
[0124] ;
[0125] in, Represents a log. Represents shipping data resources. Indicates dynamic trust value. Indicates the access decision. This indicates a shipping context sequence.
[0126] This invention constructs a blockchain-based verifiable shipping trust space, integrating a dynamic trust computing engine with real-time risk perception and a privacy-preserving federated collaborative learning mechanism. This enables trusted verification of data sources, formation of cross-domain risk consensus, and adaptive optimization of access policies. Ultimately, it builds a secure, collaborative, and closed-loop governance trust space for inland waterway shipping data in the Jianghuai region under a zero-trust architecture.
[0127] Please refer to Figure 2 This application also provides an access system for a trusted space for inland waterway shipping data under zero trust, used to apply the access method for the trusted space for inland waterway shipping data under zero trust, including:
[0128] The federated learning collaboration layer has a coordinator node, which is used to build a risk scoring model to calculate the risk score of air traffic behavior. At the same time, it optimizes and updates the risk scoring model based on federated learning to improve the accuracy of air traffic behavior risk scoring and update the logs.
[0129] Specifically, the federated learning collaboration layer receives real-time data from participating entities (such as ships). ,shipping company Port users The shipping behavior sequence features (e.g., port users provide port data, and each shipping participant calculates the loss function locally) are analyzed. With gradient This enables local model training; during training, the global model parameters are securely aggregated and updated at the coordinator node, and the aggregated and updated global model parameters are deployed to the risk scoring model to obtain a global risk model, thereby achieving real-time federated learning collaborative risk model training and real-time output of flight behavior risk scores.
[0130] The zero-trust dynamic trust layer includes a dynamic trust calculation function module and a hierarchical access decision module. It is used to receive the flight behavior risk score from the federated learning collaboration layer, calculate the dynamic trust value, perform hierarchical authorization, realize access control, and output access decisions to the blockchain trusted base layer.
[0131] Specifically, the dynamic trust calculation function module is used to construct a dynamic trust calculation function, which calculates the dynamic trust value when a participating entity requests access to shipping data resources based on the shipping context sequence and shipping behavior risk score, thereby realizing dynamic trust assessment.
[0132] Specifically, the hierarchical access decision module is used to design hierarchical access decision rules, combine the information in the trust vector, and perform hierarchical authorization based on the shipping data security level and the dynamic trust value calculated by the trust calculation function to generate access decisions (including full access, de-identified access, denial of access, etc.) to form a control engine.
[0133] The blockchain trusted foundation layer is used to store shipping rule smart contracts, store and update shipping trust status (composed of a set of trust vectors of participating entities) based on transformation rules, store access decisions from the zero-trust dynamic trust layer, access logs, and submit the hash values of the logs to the blockchain to achieve on-chain notarization of logs, establish tamper-proof trust anchors, perform blockchain identity and behavior notarization, and achieve blockchain trusted notarization and auditing.
[0134] This invention constructs a system that organically integrates a three-layer architecture of "model training-evaluation control-credible evaluation," transforming the zero-trust principle into a measurable, auditable, and adaptive operating system. It provides a systematic solution for the Jianghuai inland waterway shipping that balances strict safety, business efficiency, and compliance requirements, thereby achieving the coordinated evolution and proactive enhancement of the entire Jianghuai inland waterway shipping ecosystem's security defense capabilities.
[0135] Figure 3 This paper demonstrates a practical process for inland waterway vessel data access and sharing under a zero-trust architecture based on the method and system of this invention. The process begins with the vessel terminal initiating a data access request as the requester; subsequently, the system extracts the shipping context sequence of this request. And extract the ship's trust vector. The request and its features are then submitted to the dynamic trust assessment engine. The dynamic trust assessment engine then performs a dynamic trust assessment, which involves comprehensively querying the ship's shipping trust status on the blockchain, obtaining its real-time shipping behavior risk score, and calculating a dynamic trust value based on the current context sequence. Based on this dynamic trust value, a tiered decision is made to grant full access, anonymized access, or deny access. Based on this decision, access to the data resource pool (including waterway, cargo, and vessel data) is initiated, generating an access response. Depending on the access decision, the system obtains the original data, anonymized data, or generates a denial message. Subsequently, the system generates a log containing the entire event and submits its hash value to the blockchain for trusted storage. This storage automatically triggers a pre-built shipping rule smart contract on the blockchain, driving an update to the vessel's shipping trust status. Finally, the updated labels in the risk score dataset are fed back, and the updated risk score dataset is used for federated learning in the next learning cycle. This process fully demonstrates a closed loop from request, evaluation, decision, execution to storage, updating, and model evolution, reflecting the principle of continuous verification with zero trust and the synergistic effect of blockchain and federated learning in the shipping trust space.
[0136] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of those different embodiments or examples.
[0137] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus or device (such as a computer-based system, a processor-included system or other system that can fetch and execute instructions from, an instruction execution system, apparatus or device).
[0138] The above embodiments provide a detailed description of the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A method for accessing a trusted space for inland waterway shipping data under zero-trust conditions, characterized in that, include: Define the shipping trust status of participating entities; The shipping trust status includes: baseline trust, shipping behavior credit score, shipping ecosystem reputation value, and entity shipping attribute vector; The baseline trust includes the on-chain hash storage and verification status of ship registration certificates and crew competency certificates; the entity shipping attribute vector includes ship tonnage, route permits, cargo dangerous goods class, and company safety rating. Define conversion rules, which combine compliance proofs and shipping trust events to update the shipping trust status of participating entities; A risk scoring model is constructed to calculate the risk score of flight behavior. At the same time, the risk scoring model is optimized and updated based on federated learning to improve the accuracy of flight behavior risk scoring and update the logs. A trust calculation function is constructed based on shipping context sequence, shipping behavior risk score, and combined with baseline trust, shipping behavior credit score and shipping ecosystem reputation value to calculate the dynamic trust value when participating entities request access to shipping data resources. The shipping context sequence includes the geographical location initiating the data access request, the timestamp of the data access request, the security status of the device initiating the data access request, and the shipping business operation stage. Design hierarchical access decision rules, define decision boundary thresholds, and perform hierarchical authorization based on dynamic trust values calculated by the trust calculation function to generate access decisions and realize access control. Access logs are accessed, and the hash value of the logs is submitted to the blockchain, driving the shipping trust status of participating entities to be updated based on the conversion rules, forming a closed loop of credit update and access control.
2. The access method according to claim 1, characterized in that: The aforementioned transition rule updates the shipping trust state based on the following state transition function: ; in, This indicates the shipping trust status of the participating entities. This refers to trusted shipping events, including shipping operations and secure transactions. A certificate indicating compliance with shipping regulatory requirements. This represents a state transition function specific to shipping. Indicates time, Indicates the type index of the participating entity; The shipping-specific state transition function, designed based on a shipping rule smart contract, includes the following: When shipping trusted events For a compliant shipping transaction to be completed and compliance certification When effective, the participating entity's shipping behavior credit score will be increased; When shipping trusted events When a safety violation occurs, the participating entity's shipping behavior credit score is reduced; The shipping ecosystem reputation score is updated by aggregating feedback from other participating entities.
3. The access method according to claim 1, characterized in that: The risk scoring model is based on the participating entities at time... Flight behavior sequence characteristics As input, output is an operational risk score; The optimization and updating of the risk scoring model based on federated learning includes: A risk scoring dataset is constructed based on the collection of local privacy data held by each participating entity; After each output is a risk score, a learning cycle is entered. The risk score model is trained by federated learning using the risk score dataset. The updated risk score model is used for the next run to solve the risk score, and the risk score model is optimized and updated in real time. The risk scoring dataset includes flight behavior sequence features and labels; The labels represent the true values of the flight behavior risk scores for each participating entity.
4. The access method according to claim 3, characterized in that: The optimization and updating of the risk scoring model based on federated learning also includes: within each learning cycle: Distribute the global model parameters of the risk scoring model to each participating entity; Each participating entity calculates the loss function and gradient locally, performs privacy protection processing on the gradient, and submits the gradient contribution proof to the blockchain. The privacy-preserving gradients are securely aggregated to update the global model parameters. The mathematical representation of this secure aggregation is as follows: ; in, Indicates the first Global model parameters for each learning cycle. After privacy protection processing The gradient of shipping participants This indicates the total number of shipping participants. Indicates the first Local privacy data held by each shipping participant This represents a risk scoring dataset. Indicates the learning rate. Indicates the first The percentage of local privacy data samples from each shipping participant in the total risk scoring dataset; Update global model parameters The hash value is anchored to the blockchain; The risk scoring model is deployed in the dynamic trust assessment engine of each participating entity; The dynamic trust assessment engine updates the log and provides feedback on the updated labels in the risk score dataset. The updated risk score dataset is then used for federated learning in the next learning cycle.
5. The access method according to claim 4, characterized in that: The loss function is the mean squared error loss calculated between the flight behavior risk score output by the risk scoring model and the label in the current risk score dataset.
6. The access method according to claim 1, characterized in that: The log is defined as follows: ; in, Represents a log. Indicates participating entities, Represents shipping data resources. Indicates dynamic trust value. Indicates the access decision. This indicates a shipping context sequence.
7. The access method according to claim 1, characterized in that: The trust calculation function is described by the following equation: ; in, Indicates participating entities At any moment Request to access shipping data resources Dynamic trust value; Indicates participating entities Baseline trust; Indicates participating entities The airline's credit score; Indicates participating entities The shipping ecosystem reputation value; Indicates time The shipping context sequence is defined as: ; in, Indicates the geographical location from which the data access request was initiated. Indicates the timestamp of the data access request. Indicates the security status of the device that initiated the data access request. Indicates the stage of shipping operations; Represents the shipping context factor function, using the shipping context sequence. As input, output normalized shipping context trust contribution; Indicates participating entities At any moment The flight behavior risk score, and ; Indicates credit score based on airline behavior With shipping ecosystem reputation value The reward function is defined as: ;in , These represent the weighting coefficients for shipping behavior credit score and shipping ecosystem reputation value, respectively. This represents the maximum credit score for airline operations; The weighting coefficients for baseline trust. The weighting coefficients contributing to shipping context trust. Weighting coefficients for risk scoring of air travel behavior. This represents the weighting coefficient for the reward item.
8. The access method according to claim 1, characterized in that: The hierarchical access decision rules include: Define decision boundary thresholds, including the high-level trust threshold required to grant full access. The minimum trust threshold required to grant any access rights ; like Grant full access to the data; like Grant data anonymization access permissions or access permissions for certain data fields; like ,access denied; in This represents the dynamic trust value calculated by the trust computation function.
9. A system for accessing a trusted space for inland waterway shipping data under zero trust, used to apply the access method for a trusted space for inland waterway shipping data under zero trust as described in any one of claims 1-8, characterized in that, include: The federated learning collaboration layer is used to build a risk scoring model to calculate the risk score of flight behavior, and at the same time optimizes and updates the risk scoring model based on federated learning to improve the accuracy of flight behavior risk scoring and update the logs. The zero-trust dynamic trust layer includes a dynamic trust calculation function module and a hierarchical access decision module. It is used to receive the flight behavior risk score from the federated learning collaboration layer, calculate the dynamic trust value, perform hierarchical authorization, realize access control, and output access decisions to the blockchain trusted base layer. The blockchain trusted base layer is used to store shipping rule smart contracts, store and update shipping trust status based on transformation rules, store access decisions from the zero-trust dynamic trust layer, access logs, and submit the hash values of the logs to the blockchain.
10. The access system for the trusted space of inland waterway shipping data under zero trust as described in claim 9, characterized in that: The federated learning collaboration layer is equipped with a coordinator node, which is used for the distribution and secure aggregation of global model parameters. The dynamic trust calculation function module is used to construct a trust calculation function, which calculates the dynamic trust value when a participating entity requests access to shipping data resources based on the shipping context sequence, shipping behavior risk score, baseline trust, shipping behavior credit score and shipping ecosystem reputation value. The hierarchical access decision module is used to design hierarchical access decision rules, perform hierarchical authorization based on the shipping data security level and the dynamic trust value calculated by the trust calculation function, and generate access decisions.
Citation Information
Patent Citations
Marine satellite Internet of Things block chain lightweight storage and recovery method and device
CN117806876A
Abnormal state detection method and system for shore-based driving and controlling inland ship group
CN119603680A