A blockchain-based security credit management method and related equipment
Through the blockchain-based security and information management method, the problem of difficult security data sharing and security of outsourcing units is solved, and the secure sharing and reliable storage of data are realized.
Patent Information
- Application Number
- CN202111293656.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-03
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2041-11-03
AI Technical Summary
In the prior art, the source of security information data of outsourcing units is scattered and difficult to share, and data leakage or tampering is prone to occur during data storage and transmission, resulting in security risks.
The blockchain-based security information management and control method is adopted, and the data of the outsourcing unit is obtained, and hashing is used to calculate hashing, generate hash values, and generate public and private keys through the key exchange algorithm, encrypt and decrypt operations, and store the data to the blockchain server.
It realizes the secure sharing and reliable storage of outsourcing unit data, and uses the decentralized and immutable characteristics of blockchain to ensure the security and credibility of data.
Smart Images

Figure CN114003955B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a blockchain-based security credit management method and related equipment. Background Art
[0002] With the rapid development of the economy, more and more companies choose to outsource their business to reduce their operating costs. At the same time, with the continuous increase in business volume, some large companies often need multiple outsourcing units to handle different business operations. How to effectively manage these outsourcing units has become an urgent problem for companies to solve.
[0003] In order to reduce business risks, enterprises manage each outsourcing unit, which mainly involves the management of their security credit data. In the prior art, since the security credit data sources corresponding to different outsourcing units are relatively scattered, it is difficult to share the security credit data of outsourcing units. At the same time, during the storage and transmission of data, data leakage or tampering may occur, which is very likely to cause security risks. Summary of the invention
[0004] In view of this, the present invention provides a blockchain-based security credit management method, through which the data of the outsourcing unit can be stored in the blockchain platform, thereby ensuring the sharing, security and reliability of the unit data of the outsourcing unit. The present invention also provides a blockchain-based security credit management device to ensure the implementation and application of the above method in practice.
[0005] A blockchain-based security credit management method, comprising:
[0006] Obtain unit data for all outsourced units that the enterprise is responsible for managing;
[0007] Performing hash calculation on each of the unit data using a preset hash function to obtain a hash value corresponding to each of the unit data;
[0008] Sending a public-private key pair generation request to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server;
[0009] Generate the public key and private key of the user end according to the public key and private key of the blockchain server end and based on the key exchange algorithm;
[0010] Generate a first symmetric key according to the public key of the blockchain server and the private key of the user, and use the first symmetric key to encrypt the hash value corresponding to each unit data to generate encrypted information corresponding to each hash value;
[0011] Send each of the encrypted information and the public key of the user end to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and applies the second symmetric key to decrypt the encrypted information, and sends the hash value corresponding to the decrypted encrypted information to the smart contract module and stores it.
[0012] In the above method, optionally, the unit data includes unit credit data, personnel data and operation data;
[0013] The using of a preset hash function to perform hash calculation on each of the unit data to obtain a hash value corresponding to each of the unit data includes:
[0014] Using the hash function to perform hash calculation on the unit credit data in each of the unit data to obtain a hash value corresponding to the unit credit data;
[0015] Using the hash function to perform hash calculation on the personnel data in each of the unit data to obtain a hash value corresponding to the personnel data;
[0016] The hash function is used to perform hash calculation on the operation data in each unit data to obtain a hash value corresponding to the operation data.
[0017] In the above method, optionally, the using of a preset hash function to perform hash calculation on each of the unit data to obtain a hash value corresponding to each of the unit data includes:
[0018] Divide each acquired unit data into its corresponding business domain according to preset division conditions to generate a business outsourcing information database;
[0019] A hash operation is performed on each unit data in each business domain in the business outsourcing information library using a preset hash function to obtain a hash value corresponding to each unit data.
[0020] The above method may optionally further include:
[0021] In response to a violation behavior determination request sent by a user, obtaining on-site personnel data and on-site operation data generated in on-site operations of an outsourcing unit to be processed corresponding to the violation behavior determination request;
[0022] Using the hash function to perform hash calculations on the on-site personnel data and the on-site operation data, respectively, to obtain a first hash value corresponding to the on-site personnel data and a second hash value corresponding to the on-site operation data;
[0023] Obtaining the hash value corresponding to the outsourcing unit to be processed stored on the blockchain server as a reference hash value;
[0024] Determine whether the first Hash value is equal to the Hash value corresponding to the personnel data in the comparison Hash value, and whether the second Hash value is equal to the Hash value corresponding to the job data in the comparison Hash value;
[0025] If the hash value corresponding to the personnel data in the comparison hash value is equal to the first hash value, and the hash value corresponding to the operation data in the comparison hash value is equal to the second hash value, then the outsourcing unit to be processed does not have any illegal behavior;
[0026] If the hash value corresponding to the personnel data in the comparison hash value is not equal to the first hash value, or the hash value corresponding to the job data in the comparison hash value is not equal to the second hash value, then the outsourcing unit to be processed has violated regulations.
[0027] The above method may optionally further include:
[0028] When the outsourcing unit to be processed has violated regulations, the first hash value, the second hash value, and the hash value corresponding to the unit credit data in the comparison hash value are combined to form a hash value to be processed corresponding to the outsourcing unit to be processed;
[0029] The hash value to be processed is sent to the smart contract module and stored, and the smart contract module is triggered to count the number of violations of the outsourcing unit to be processed according to preset rules;
[0030] When the number of violations reaches a specified value, the smart contract module is triggered to store the outsourcing unit to be processed into a pre-established blacklist.
[0031] A security credit management and control device based on blockchain, comprising:
[0032] A first acquisition unit is used to acquire unit data of all outsourced units that the enterprise is responsible for managing;
[0033] A first calculation unit, used for performing hash calculation on each of the unit data using a preset hash function to obtain a hash value corresponding to each of the unit data;
[0034] A first generating unit is used to send a public-private key pair generation request to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server;
[0035] A second generating unit is used to generate a public key and a private key of a user terminal according to the public key and the private key of the blockchain server terminal and based on the key exchange algorithm;
[0036] A third generating unit is used to generate a first symmetric key according to the public key of the blockchain server and the private key of the user, and use the first symmetric key to encrypt the hash value corresponding to each of the unit data to generate encrypted information corresponding to each of the hash values;
[0037] A sending unit is used to send each of the encrypted information and the public key of the user end to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and applies the second symmetric key to decrypt the encrypted information, and sends the hash value corresponding to the decrypted encrypted information to the smart contract module for storage.
[0038] In the above device, optionally, the unit data includes unit credit data, personnel data and operation data;
[0039] The first computing unit comprises:
[0040] A first calculation subunit is used to perform a hash calculation on the unit credit data in each of the unit data using the hash function to obtain a hash value corresponding to the unit credit data;
[0041] A second calculation subunit is used to use the hash function to perform hash calculation on the personnel data in each of the unit data to obtain a hash value corresponding to the personnel data;
[0042] The third calculation subunit is used to use the hash function to perform hash calculation on the operation data in each of the unit data to obtain a hash value corresponding to the operation data.
[0043] The above device may optionally further include:
[0044] A second acquisition unit is used to respond to the violation behavior determination request sent by the user, and acquire the on-site personnel data and on-site operation data generated in the on-site operation of the outsourcing unit to be processed corresponding to the violation behavior determination request;
[0045] A second calculation unit, used to use the hash function to perform hash calculations on the on-site personnel data and the on-site operation data respectively, to obtain a first hash value corresponding to the on-site personnel data and a second hash value corresponding to the on-site operation data;
[0046] A third acquisition unit is used to acquire a hash value corresponding to the outsourcing unit to be processed stored on the blockchain server as a comparison hash value;
[0047] A judgment unit is used to judge whether the first hash value is equal to the hash value corresponding to the personnel data in the comparison hash value, and whether the second hash value is equal to the hash value corresponding to the job data in the comparison hash value; if the hash value corresponding to the personnel data in the comparison hash value is equal to the first hash value, and the hash value corresponding to the job data in the comparison hash value is equal to the second hash value, then the outsourcing unit to be processed has no illegal behavior; if the hash value corresponding to the personnel data in the comparison hash value is not equal to the first hash value, or the hash value corresponding to the job data in the comparison hash value is not equal to the second hash value, then the outsourcing unit to be processed has illegal behavior.
[0048] A storage medium, comprising stored instructions, wherein when the instructions are executed, the device where the storage medium is located is controlled to execute the above-mentioned blockchain-based security credit management method.
[0049] An electronic device includes a memory and one or more instructions, wherein the one or more instructions are stored in the memory and are configured to be executed by one or more processors to execute the above-mentioned blockchain-based security credit management method.
[0050] Compared with the prior art, the present invention has the following advantages:
[0051] Based on the embodiment provided by the present invention, in the process of security credit management and control, the unit data of all outsourced units managed by the enterprise are obtained; a hash calculation is performed on each unit data using a preset hash function to obtain a hash value corresponding to each unit data; a public-private key pair generation request is sent to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server; based on the public key and the private key of the blockchain server and based on the key exchange algorithm, a public key and a private key of the user end are generated; based on the public key of the blockchain server and the private key of the user end, a first symmetric key is generated and the hash value corresponding to each unit data is encrypted using the first symmetric key to generate encrypted information corresponding to each hash value; each encrypted information and the public key of the user end are sent to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and the second symmetric key is used to decrypt the encrypted information, and the hash value corresponding to the decrypted encrypted information is sent to the smart contract module and stored.
[0052] By applying the method provided in the embodiment of the present invention, the unit data of each outsourced unit collected is hashed, and then the public key and private key of the blockchain server and the public key and private key of the user are generated through a key exchange algorithm, and a symmetric encryption key is generated based on the public-private key pair of the blockchain server and the public-private key pair of the user, and then the hash value of the unit data is encrypted using the symmetric encryption algorithm, and the encrypted data is sent to the blockchain server for decryption and storage on the chain, thereby realizing the sharing of the unit data of the business outsourcing units, and utilizing the decentralization, transparency and data immutability of blockchain technology to ensure the reliability and security of the unit data. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0054] Figure 1 A flowchart of a blockchain-based security credit management method provided by an embodiment of the present invention;
[0055] Figure 2 Another method flow chart of a blockchain-based security credit management method provided by an embodiment of the present invention;
[0056] Figure 3 A flowchart of another method of a blockchain-based security credit management method provided in an embodiment of the present invention;
[0057] Figure 4 A device structure diagram of a blockchain-based security credit management device provided in an embodiment of the present invention;
[0058] Figure 5 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0059] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0060] In this application, the terms "comprises", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element.
[0061] It should be noted that the professional names involved in this application document are as follows:
[0062] Blockchain: A distributed ledger that combines data blocks in a sequential manner in chronological order to form a chain data structure and is cryptographically guaranteed to be tamper-proof and unforgeable.
[0063] Internet Key Exchange Protocol (IKE): A hybrid protocol consisting of Internet Security Association and Key Management Protocol (ISAKMP) and two key exchange protocols, OAKLEY and SKEME. IKE is built on the framework defined by ISAKMP, using the key exchange mode of OAKLEY and the sharing and key update technology of SKEME, and also defines its own two key exchange modes: main mode and aggressive mode.
[0064] Symmetric encryption algorithm: In a symmetric encryption algorithm, the data sender processes the plaintext and encryption key together through a special encryption algorithm, turning it into a complex encrypted ciphertext and sending it out. After the recipient receives the ciphertext, if he wants to interpret the original text, he needs to use the encryption key and the inverse algorithm of the same algorithm to decrypt the ciphertext to restore it to readable plaintext.
[0065] Hash function: It transforms an input of any length into an output of fixed length through a hash algorithm. The output is the hash value. This conversion is a compression mapping, that is, the space of hash values is usually much smaller than the space of inputs. Different inputs may hash to the same output, so it is impossible to determine the unique input value from the hash value.
[0066] Smart contract: A computer protocol designed to communicate, verify or execute contracts in an information-based manner. Smart contracts allow for trusted transactions without a third party, which are traceable and irreversible.
[0067] The embodiment of the present invention provides a blockchain-based security credit management method, which can be applied to a variety of system platforms, and its execution subject can be a computer terminal or a processor of various mobile devices. The method flow chart of the method is as follows: Figure 1 As shown, specifically including:
[0068] S101: Acquire unit data of all outsourced units managed by the enterprise.
[0069] In the embodiment provided by the present invention, the unit data of all outsourced units managed by the enterprise are collected, and the unit data of the outsourced units can be obtained in the relevant system used by the enterprise to manage the outsourced units.
[0070] Specifically, the unit data of the outsourced unit includes unit credit data, personnel data and operation data.
[0071] S102: Performing hash calculation on each of the unit data using a preset hash function to obtain a hash value corresponding to each of the unit data.
[0072] In the embodiment provided by the present invention, a preset hash function is used to perform hash calculation on the unit data of each outsourcing unit to obtain a hash value corresponding to each unit data, specifically:
[0073] Using the hash function to perform hash calculation on the unit credit data in each of the unit data to obtain a hash value corresponding to the unit credit data;
[0074] Using the hash function to perform hash calculation on the personnel data in each of the unit data to obtain a hash value corresponding to the personnel data;
[0075] The hash function is used to perform hash calculation on the operation data in each unit data to obtain a hash value corresponding to the operation data.
[0076] S103: Sending a public-private key pair generation request to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server.
[0077] In the embodiment provided by the present invention, in order to ensure the security of data transmission between the user end and the blockchain server end, it is necessary to use a symmetric key to encrypt the data when transmitting the data. The blockchain server end executes a key exchange algorithm according to the generation request of the public-private key pair sent by the user end to generate the public key and private key of the blockchain server end.
[0078] S104: Generate the public key and private key of the user end according to the public key and private key of the blockchain server end and based on the key exchange algorithm.
[0079] In the embodiment provided by the present invention, the public key and private key of the blockchain server are obtained, and the public key and private key of the user are generated according to the public key and private key of the blockchain server and a preset key exchange algorithm.
[0080] S105: Generate a first symmetric key based on the public key of the blockchain server and the private key of the user, and use the first symmetric key to encrypt the hash value corresponding to each unit data to generate encrypted information corresponding to each hash value.
[0081] S106: Send each of the encrypted information and the public key of the user end to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and applies the second symmetric key to decrypt the encrypted information, and sends the hash value corresponding to the decrypted encrypted information to the smart contract module and stores it.
[0082] In the embodiment provided by the present invention, each encrypted information and the public key of the user end are sent to the blockchain server end. The blockchain server end generates a second symmetric key based on the public key of the user end and its own private key, that is, the private key of the blockchain server end. According to the symmetric key algorithm and the network key exchange protocol, the first symmetric key and the second symmetric key are equal. The blockchain server end uses the second symmetric key to decrypt each encrypted information to obtain the hash value corresponding to each encrypted information, that is, the hash value corresponding to each unit data. The blockchain server end sends each decrypted hash value to the smart contract module to store the hash value corresponding to each unit data to the blockchain server end, thereby completing the chain operation.
[0083] Based on the embodiment provided by the present invention, in the process of security credit management and control, the unit data of all outsourced units managed by the enterprise are obtained; a hash calculation is performed on each unit data using a preset hash function to obtain a hash value corresponding to each unit data; a public-private key pair generation request is sent to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server; based on the public key and the private key of the blockchain server and based on the key exchange algorithm, a public key and a private key of the user end are generated; based on the public key of the blockchain server and the private key of the user end, a first symmetric key is generated and the hash value corresponding to each unit data is encrypted using the first symmetric key to generate encrypted information corresponding to each hash value; each encrypted information and the public key of the user end are sent to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and the second symmetric key is used to decrypt the encrypted information, and the hash value corresponding to the decrypted encrypted information is sent to the smart contract module and stored.
[0084] By applying the method provided in the embodiment of the present invention, the unit data of each outsourced unit collected is hashed, and then the public key and private key of the blockchain server and the public key and private key of the user are generated through a key exchange algorithm, and a symmetric encryption key is generated based on the public-private key pair of the blockchain server and the public-private key pair of the user, and then the hash value of the unit data is encrypted using the symmetric encryption algorithm, and the encrypted data is sent to the blockchain server for decryption and storage on the chain, thereby realizing the sharing of the unit data of the business outsourcing units, and utilizing the decentralization, transparency and data immutability of blockchain technology to ensure the reliability and security of the unit data.
[0085] The blockchain-based security credit management method provided by an embodiment of the present invention may optionally use a preset hash function to perform hash calculation on each of the unit data to obtain a hash value corresponding to each of the unit data, including:
[0086] Divide each acquired unit data into its corresponding business domain according to preset division conditions to generate a business outsourcing information database;
[0087] A hash operation is performed on each unit data in each business domain in the business outsourcing information library using a preset hash function to obtain a hash value corresponding to each unit data.
[0088] By dividing the business domains, the unit data of different entities in the enterprise's business lines are divided to form a business outsourcing information library, and then the hash function is used to perform hash operations on each unit data in each business domain in the business outsourcing information library, so as to generate hash values corresponding to each unit data in an orderly manner, so as to facilitate the subsequent storage of the hash values corresponding to each unit data on the blockchain server to complete the chain.
[0089] like Figure 2 As shown, the blockchain-based security credit management method provided by the embodiment of the present invention may optionally further include:
[0090] S201: In response to a violation determination request sent by a user, obtaining on-site personnel data and on-site operation data generated in on-site operations of an outsourcing unit to be processed corresponding to the violation determination request.
[0091] In the embodiment provided by the present invention, when it is necessary to determine whether the outsourcing unit has violated regulations, it is necessary to compare the hash value of the relevant data generated in the on-site operation of the unit to be processed with the hash value of the corresponding data stored on the blockchain server. Therefore, firstly obtain the on-site personnel data and on-site operation data generated in the on-site operation of the unit to be processed according to the violation determination request.
[0092] S202: Use the hash function to perform hash calculations on the on-site personnel data and the on-site operation data respectively to obtain a first hash value corresponding to the on-site personnel data and a second hash value corresponding to the on-site operation data.
[0093] The hash function is consistent with the hash function in S102.
[0094] S203: Obtain the hash value corresponding to the outsourcing unit to be processed stored on the blockchain server as a comparison hash value.
[0095] In the embodiment provided by the present invention, the hash value corresponding to the outsourcing unit to be processed stored on the blockchain server side is used as the filing data of the outsourcing unit to be processed, that is, the reference hash value, which can be compared with the hash value corresponding to the unit data generated during the on-site operation process to determine whether the two are equal.
[0096] S204: Determine whether the first Hash value is equal to the Hash value corresponding to the personnel data in the comparison Hash value, and whether the second Hash value is equal to the Hash value corresponding to the job data in the comparison Hash value.
[0097] In the embodiment provided by the present invention, if the hash value corresponding to the personnel data in the comparison hash value is equal to the first hash value, and the hash value corresponding to the job data in the comparison hash value is equal to the second hash value, S205 is executed; if the hash value corresponding to the personnel data in the comparison hash value is not equal to the first hash value, or the hash value corresponding to the job data in the comparison hash value is not equal to the second hash value, S206 is executed.
[0098] S205: The outsourcing unit to be processed has not committed any violation of regulations.
[0099] Specifically, if the hash value corresponding to the personnel data in the comparison hash value is exactly the same as the first hash value, and the hash value corresponding to the job data in the comparison hash value is exactly the same as the second hash value, it means that the outsourcing unit to be processed has not committed any illegal behavior.
[0100] S206: The outsourcing unit to be processed has committed illegal acts.
[0101] Specifically, if the hash value corresponding to the personnel data in the comparison hash value is not equal to the first hash value by one or more digits, or the hash value corresponding to the job data in the comparison hash value is not equal to the second hash value by one or more digits, it means that the outsourced unit to be processed has illegal behavior problems.
[0102] By obtaining and calculating the hash value of the on-site personnel data and the hash value of the on-site operation data generated in the on-site operation of the unit to be processed, the hash value of the on-site personnel data and the hash value of the on-site operation data are compared with the hash value of the personnel data and the hash value of the on-site operation data corresponding to the outsourced unit to be processed stored on the blockchain server, and the hash value is used as a pointer to the unit data and stored and saved together with the data to identify whether the on-site operation situation is consistent with the filing, and to determine whether the outsourced unit has any illegal behavior, which to a certain extent reduces the burden on enterprises to verify the unit data of outsourced units during the operation process.
[0103] like Figure 3 As shown, the blockchain-based security credit management method provided by the embodiment of the present invention may optionally further include:
[0104] S301: When the outsourcing unit to be processed has violated regulations, the first hash value, the second hash value, and the hash value corresponding to the unit credit data in the comparison hash value are combined into a hash value to be processed corresponding to the outsourcing unit to be processed;
[0105] S302: Send the hash value to be processed to the smart contract module and store it, and trigger the smart contract module to count the number of violations of the outsourcing unit to be processed according to preset rules.
[0106] In the embodiment provided by the present invention, when the outsourced unit to be processed has illegal behavior, the first hash value, the second hash value, and the hash value corresponding to the unit credit data of the unit to be processed in the reference hash value are combined and sent to the smart contract module as the hash value corresponding to the new unit data to store it in the blockchain server, and the smart contract module is triggered to record the illegal behavior of the outsourced unit and count the number of breaches of contract by the outsourced unit.
[0107] S303: When the number of violations reaches a specified value, the smart contract module is triggered to store the outsourcing unit to be processed into a pre-established blacklist.
[0108] In the embodiment provided by the present invention, a blacklist evaluation mechanism for outsourcing units based on blockchain is established. In combination with the violation records of the outsourcing team at the safety operation site, the blockchain smart contract technology is used for intelligent judgment. When the number of violations of the outsourcing unit to be processed reaches the specified value, the smart contract module is triggered to store the outsourcing unit to be processed in the pre-established blacklist list. Optionally, if the number of violations of the outsourcing unit to be processed meets the standard, an outsourcing unit blacklist evaluation report is generated and the evaluation report is automatically pushed to the management platform.
[0109] The hash value corresponding to the relevant unit data generated during the on-site operation of the outsourcing unit with violations is uploaded to the blockchain server as the proof material for the subsequent credit rating assessment of the outsourcing unit. In addition, the outsourcing unit is scored and the number of violations is recorded through the smart contract module. The smart contract technology in the blockchain is used to establish a blockchain-based outsourcing unit blacklist assessment mechanism. In combination with the violation records of the outsourcing unit at the safety operation site, the blockchain smart contract technology is used for intelligent judgment to generate an outsourcing unit blacklist assessment report, which is automatically pushed to the management platform to achieve the purpose of efficiency and intelligence.
[0110] According to the embodiment provided by the present invention, a security credit management mechanism for outsourcing units is established through blockchain and cryptography technology. Relevant data of outsourcing units, such as unit credit data, personnel data and operation data, as well as work performance evaluation and outsourcing unit scoring data, can be stored on the blockchain server side, and evidence can be stored on the chain to achieve penetrating supervision of the entire process of safe operations, effectively plugging regulatory loopholes and ensuring that investigations have a basis to follow. First, collect the unit credit data, personnel data and operation data of each outsourcing unit in the existing system of the enterprise to form unit data; divide the unit data of different outsourcing units into business domains according to the business lines of the enterprise to form a business outsourcing information database; secondly, use the hash function to perform hash operation on each unit data in the business outsourcing information database to obtain the hash value corresponding to each unit data; and rely on the key exchange protocol and symmetric encryption algorithm in cryptography to store the encrypted hash value corresponding to each unit data on the blockchain to ensure the security and reliability of the data transmission process; then, use the characteristics of blockchain technology such as openness, transparency, collective maintenance, and difficulty in tampering to achieve the security, reliability and sharing of unit credit data, personnel data, operation data, work performance evaluation and outsourcing unit scoring data in the unit data; finally, when it is necessary to compare whether the data has been tampered with, use the hash value verification technology to compare and verify the data in the on-site operation management process with the data stored on the chain to confirm whether the evidence is consistent with the original. The present invention applies blockchain and cryptography technology to the security supervision of outsourcing units, uploads relevant information such as the qualifications and security credit of the outsourcing units to the blockchain server, establishes a blockchain-based outsourcing unit blacklist evaluation mechanism, and realizes the safe and reliable sharing of the unit data of the outsourcing units throughout the entire life cycle.
[0111] and Figure 1 Corresponding to the method described above, the embodiment of the present invention also provides a security credit management and control device based on blockchain, which is used to Figure 1 In the specific implementation of the method, the blockchain-based security credit management device provided by the embodiment of the present invention can be applied to computer terminals or various mobile devices, and its structural diagram is as follows Figure 4 As shown, specifically including:
[0112] The first acquisition unit 401 is used to acquire unit data of all outsourced units managed by the enterprise;
[0113] The first calculation unit 402 is used to perform hash calculation on each unit data using a preset hash function to obtain a hash value corresponding to each unit data;
[0114] The first generating unit 403 is used to send a public-private key pair generation request to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server;
[0115] The second generating unit 404 is used to generate the public key and private key of the user end according to the public key and private key of the blockchain server end and based on the key exchange algorithm;
[0116] The third generating unit 405 is used to generate a first symmetric key according to the public key of the blockchain server and the private key of the user, and use the first symmetric key to encrypt the hash value corresponding to each unit data to generate encrypted information corresponding to each hash value;
[0117] The sending unit 406 is used to send each of the encrypted information and the public key of the user end to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and applies the second symmetric key to decrypt the encrypted information, and sends the hash value corresponding to the decrypted encrypted information to the smart contract module and stores it.
[0118] Based on the blockchain-based security credit management device provided by the embodiment of the present invention, in the process of security credit management, the first acquisition unit acquires the unit data of all outsourced units managed by the enterprise; the first calculation unit uses a preset hash function to perform hash calculation on each unit data to obtain the hash value corresponding to each unit data; the first generation unit sends a public-private key pair generation request to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server; the second generation unit generates a public key and a private key based on the public key and the private key of the blockchain server. Based on the key exchange algorithm, the public key and private key of the user end are generated; the third generating unit generates a first symmetric key according to the public key of the blockchain server end and the private key of the user end, and uses the first symmetric key to encrypt the hash value corresponding to each unit data, and generates encrypted information corresponding to each hash value; finally, the sending unit sends each encrypted information and the public key of the user end to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and uses the second symmetric key to decrypt the encrypted information, and sends the hash value corresponding to the decrypted encrypted information to the smart contract module and stores it.
[0119] By using the device provided by the embodiment of the present invention, the unit data of each outsourced unit collected is hashed, and then the public key and private key of the blockchain server and the public key and private key of the user are generated through a key exchange algorithm, and a symmetric encryption key is generated based on the public-private key pair of the blockchain server and the public-private key pair of the user, and then the hash value of the unit data is encrypted using the symmetric encryption algorithm, and the encrypted data is sent to the blockchain server for decryption and storage on the chain, thereby realizing the sharing of the unit data of the business outsourcing units, and utilizing the decentralization, transparency and data immutability of blockchain technology to ensure the reliability and security of the unit data.
[0120] Optionally, in the device provided by an embodiment of the present invention, the unit data includes unit credit data, personnel data and operation data;
[0121] The first computing unit comprises:
[0122] A first calculation subunit is used to perform a hash calculation on the unit credit data in each of the unit data using the hash function to obtain a hash value corresponding to the unit credit data;
[0123] A second calculation subunit is used to use the hash function to perform hash calculation on the personnel data in each of the unit data to obtain a hash value corresponding to the personnel data;
[0124] The third calculation subunit is used to use the hash function to perform hash calculation on the operation data in each of the unit data to obtain a hash value corresponding to the operation data.
[0125] Optionally, the device provided in the embodiment of the present invention further includes:
[0126] A second acquisition unit is used to respond to the violation behavior determination request sent by the user, and acquire the on-site personnel data and on-site operation data generated in the on-site operation of the outsourcing unit to be processed corresponding to the violation behavior determination request;
[0127] A second calculation unit, used to use the hash function to perform hash calculations on the on-site personnel data and the on-site operation data respectively, to obtain a first hash value corresponding to the on-site personnel data and a second hash value corresponding to the on-site operation data;
[0128] A third acquisition unit is used to acquire a hash value corresponding to the outsourcing unit to be processed stored on the blockchain server as a comparison hash value;
[0129] A judgment unit is used to judge whether the first hash value is equal to the hash value corresponding to the personnel data in the comparison hash value, and whether the second hash value is equal to the hash value corresponding to the job data in the comparison hash value; if the hash value corresponding to the personnel data in the comparison hash value is equal to the first hash value, and the hash value corresponding to the job data in the comparison hash value is equal to the second hash value, then the outsourcing unit to be processed has no illegal behavior; if the hash value corresponding to the personnel data in the comparison hash value is not equal to the first hash value, or the hash value corresponding to the job data in the comparison hash value is not equal to the second hash value, then the outsourcing unit to be processed has illegal behavior.
[0130] For the specific working process of each unit and sub-unit in the blockchain-based security credit management device disclosed in the above embodiment of the present invention, please refer to the corresponding content in the blockchain-based security credit management method disclosed in the above embodiment of the present invention, which will not be repeated here.
[0131] An embodiment of the present invention also provides a storage medium, which includes stored instructions, wherein when the instructions are executed, the device where the storage medium is located is controlled to execute the above-mentioned blockchain-based security credit management method.
[0132] The embodiment of the present invention further provides an electronic device, the structural diagram of which is shown in FIG. Figure 5As shown, it specifically includes a memory 501 and one or more instructions 502, wherein the one or more instructions 502 are stored in the memory 501 and are configured to be executed by one or more processors 503 to perform the following operations:
[0133] Obtain unit data for all outsourced units that the enterprise is responsible for managing;
[0134] Performing hash calculation on each of the unit data using a preset hash function to obtain a hash value corresponding to each of the unit data;
[0135] Sending a public-private key pair generation request to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server;
[0136] Generate the public key and private key of the user end according to the public key and private key of the blockchain server end and based on the key exchange algorithm;
[0137] Generate a first symmetric key according to the public key of the blockchain server and the private key of the user, and use the first symmetric key to encrypt the hash value corresponding to each unit data to generate encrypted information corresponding to each hash value;
[0138] Send each of the encrypted information and the public key of the user end to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and applies the second symmetric key to decrypt the encrypted information, and sends the hash value corresponding to the decrypted encrypted information to the smart contract module and stores it.
[0139] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can refer to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system or system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiment. The system and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without creative work.
[0140] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0141] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A security credit management method based on blockchain, characterized in that: include: Obtain unit data for all outsourced units that the enterprise is responsible for managing; Performing hash calculation on each of the unit data using a preset hash function to obtain a hash value corresponding to each of the unit data; Sending a public-private key pair generation request to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server; Generate the public key and private key of the user end according to the public key and private key of the blockchain server end and based on the key exchange algorithm; Generate a first symmetric key according to the public key of the blockchain server and the private key of the user, and use the first symmetric key to encrypt the hash value corresponding to each unit data to generate encrypted information corresponding to each hash value; Send each of the encrypted information and the public key of the user end to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and uses the second symmetric key to decrypt the encrypted information, and sends the hash value corresponding to the encrypted information obtained by decryption to the smart contract module and stores it; The method of performing hash calculation on each unit data by using a preset hash function to obtain a hash value corresponding to each unit data includes: Divide each acquired unit data into its corresponding business domain according to preset division conditions to generate a business outsourcing information database; A hash operation is performed on each unit data in each business domain in the business outsourcing information library using a preset hash function to obtain a hash value corresponding to each unit data.
2. The method according to claim 1, characterized in that: The unit data includes unit credit data, personnel data and operation data; The using of a preset hash function to perform hash calculation on each of the unit data to obtain a hash value corresponding to each of the unit data includes: Using the hash function to perform hash calculation on the unit credit data in each of the unit data to obtain a hash value corresponding to the unit credit data; Using the hash function to perform hash calculation on the personnel data in each of the unit data to obtain a hash value corresponding to the personnel data; The hash function is used to perform hash calculation on the operation data in each unit data to obtain a hash value corresponding to the operation data.
3. The method according to claim 2, characterized in that Also includes: In response to a violation behavior determination request sent by a user, obtaining on-site personnel data and on-site operation data generated in on-site operations of an outsourcing unit to be processed corresponding to the violation behavior determination request; Using the hash function to perform hash calculations on the on-site personnel data and the on-site operation data, respectively, to obtain a first hash value corresponding to the on-site personnel data and a second hash value corresponding to the on-site operation data; Obtaining the hash value corresponding to the outsourcing unit to be processed stored on the blockchain server as a reference hash value; Determine whether the first Hash value is equal to the Hash value corresponding to the personnel data in the comparison Hash value, and whether the second Hash value is equal to the Hash value corresponding to the job data in the comparison Hash value; If the hash value corresponding to the personnel data in the comparison hash value is equal to the first hash value, and the hash value corresponding to the operation data in the comparison hash value is equal to the second hash value, then the outsourcing unit to be processed does not have any illegal behavior; If the hash value corresponding to the personnel data in the comparison hash value is not equal to the first hash value, or the hash value corresponding to the job data in the comparison hash value is not equal to the second hash value, then the outsourcing unit to be processed has violated regulations.
4. The method according to claim 3, characterized in that Also includes: When the outsourcing unit to be processed has violated regulations, the first hash value, the second hash value, and the hash value corresponding to the unit credit data in the comparison hash value are combined to form a hash value to be processed corresponding to the outsourcing unit to be processed; The hash value to be processed is sent to the smart contract module and stored, and the smart contract module is triggered to count the number of violations of the outsourcing unit to be processed according to preset rules; When the number of violations reaches a specified value, the smart contract module is triggered to store the outsourcing unit to be processed into a pre-established blacklist.
5. A security credit management and control device based on blockchain, characterized in that: include: A first acquisition unit is used to acquire unit data of all outsourced units that the enterprise is responsible for managing; A first calculation unit, used for performing hash calculation on each of the unit data using a preset hash function to obtain a hash value corresponding to each of the unit data; A first generating unit is used to send a public-private key pair generation request to a preset blockchain server to trigger the blockchain server to execute a preset key exchange algorithm based on the public-private key pair generation request to generate a public key and a private key of the blockchain server; A second generating unit is used to generate a public key and a private key of a user terminal according to the public key and the private key of the blockchain server terminal and based on the key exchange algorithm; A third generating unit is used to generate a first symmetric key according to the public key of the blockchain server and the private key of the user, and use the first symmetric key to encrypt the hash value corresponding to each of the unit data to generate encrypted information corresponding to each of the hash values; A sending unit, configured to send each of the encrypted information and the public key of the user end to the blockchain server end, so that the blockchain server end generates a second symmetric key according to the public key of the user end and the private key of the blockchain server end, and applies the second symmetric key to decrypt the encrypted information, and sends the hash value corresponding to the encrypted information obtained by decryption to the smart contract module for storage; Wherein, the first computing unit is specifically used for: Divide each acquired unit data into its corresponding business domain according to preset division conditions to generate a business outsourcing information database; A hash operation is performed on each unit data in each business domain in the business outsourcing information library using a preset hash function to obtain a hash value corresponding to each unit data.
6. The device according to claim 5, characterized in that The unit data includes unit credit data, personnel data and operation data; The first computing unit comprises: A first calculation subunit is used to perform a hash calculation on the unit credit data in each of the unit data using the hash function to obtain a hash value corresponding to the unit credit data; A second calculation subunit is used to use the hash function to perform hash calculation on the personnel data in each of the unit data to obtain a hash value corresponding to the personnel data; The third calculation subunit is used to use the hash function to perform hash calculation on the operation data in each of the unit data to obtain a hash value corresponding to the operation data.
7. The device according to claim 6, characterized in that Also includes: A second acquisition unit is used to respond to the violation behavior determination request sent by the user, and acquire the on-site personnel data and on-site operation data generated in the on-site operation of the outsourcing unit to be processed corresponding to the violation behavior determination request; A second calculation unit, used to use the hash function to perform hash calculations on the on-site personnel data and the on-site operation data respectively, to obtain a first hash value corresponding to the on-site personnel data and a second hash value corresponding to the on-site operation data; A third acquisition unit is used to acquire a hash value corresponding to the outsourcing unit to be processed stored on the blockchain server as a comparison hash value; A judging unit, used for judging whether the first hash value is equal to the hash value corresponding to the personnel data in the comparison hash value, and whether the second hash value is equal to the hash value corresponding to the operation data in the comparison hash value; if the hash value corresponding to the personnel data in the comparison hash value is equal to the first hash value, and the hash value corresponding to the operation data in the comparison hash value is equal to the second hash value, then the outsourcing unit to be processed does not have any illegal behavior; If the hash value corresponding to the personnel data in the comparison hash value is not equal to the first hash value, or the hash value corresponding to the job data in the comparison hash value is not equal to the second hash value, then the outsourcing unit to be processed has violated regulations.
8. A storage medium, characterized in that: The storage medium includes stored instructions, wherein when the instructions are executed, the device where the storage medium is located is controlled to execute the blockchain-based security credit management method as described in any one of claims 1 to 4.
9. An electronic device, characterized in that: It includes a memory and one or more instructions, wherein one or more instructions are stored in the memory and are configured to be executed by one or more processors as described in any one of claims 1 to 4 as a blockchain-based security credit management method.
Citation Information
Patent Citations
Method and system capable of dynamically protecting user private data
CN103166757A
Following method and device, electronic equipment, and medium
CN108259183A