A blockchain approach to railway electronic document trust management
By constructing a trust model for unexpected changes in electronic files and using directed acyclic graphs and hash values to form a blockchain, the problem of inability to effectively verify electronic files under physical isolation of the file server is solved, and efficient, accurate verification and batch verification of files are achieved.
Patent Information
- Application Number
- CN202111338924.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-12
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-11-12
AI Technical Summary
The prior art cannot effectively verify electronic files under the physical isolation of file servers, and lacks effective protection against unexpected changes in files and deliberate tampering, making it difficult to support batch verification of electronic files.
By constructing a trust model for unanticipated changes in electronic files, using the validity verification process relationship network to build a directed acyclic graph, calculate the hash value and form a blockchain, and realize data interaction under physical isolation of the file server, traceback determination of invalid files and batch verification of electronic files in computer clusters.
Under the physical isolation of the file server, the validity verification of electronic files is realized, and the unintended changes and deliberate tampering are protected, which improves the efficiency and accuracy of file verification and supports batch verification of electronic files.
Smart Images

Figure CN114065300B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of rail transit technology, and in particular to a blockchain method for railway electronic document trust management. Background Art
[0002] Railway computer systems serve information-based businesses such as train dispatching, transportation information management, and engineering project construction. To verify the effectiveness of computer function upgrades, system managers need to reproduce the existing functions of the transportation production environment in a simulation laboratory, verify the effectiveness of the function upgrade through multiple experiments, and finally deploy the verified electronic files to the transportation production environment. During the verification of the effectiveness of the function upgrade, system managers need to continuously modify, copy, and move various electronic files between the two physically isolated computer clusters of the simulation laboratory and the transportation production environment. This process can easily introduce erroneous data at random, leading to illegal use of files, missing key information, or causing unexpected behavior in the system. System managers usually adopt specific file management methods to verify electronic files to ensure the overall effectiveness of the system.
[0003] During the period of verifying the effectiveness of the function upgrade, the electronic files operated by the system administrator are stored and archived by the file server. The file server records the changed content of the electronic file as well as the attribute information such as the modifier, generation time and size. The initial version, intermediate version and latest version of the same electronic file in different time periods can be represented as a version change record in the form of a timeline, such as Figure 1 When the system administrator believes that a certain electronic file is not the latest version, he or she can access the file server to check whether there is a version record with the same generation time and size in the timeline to verify whether the file content is consistent with the latest version, or determine whether the electronic file has misuse and erroneous data.
[0004] However: 1) When system administrators operate files between the simulation laboratory and the transportation production environment, since the file server only exists in the simulation laboratory, under the existing technical conditions, relevant personnel cannot directly follow the Figure 1 The existing technology cannot be used when the file server is offline, which increases the risk of randomly introducing erroneous data. 2) The existing technology verifies that the electronic file is consistent with the target version content by comparing attribute information. However, the attribute information of the electronic file can be modified through command line tools or attribute windows, and there is no necessary correspondence between the attribute information and the content. The verification process does not have a good error-proofing capability against intentional tampering. 3) The file objects verified by system administrators are usually electronic files of the entire computer cluster, and the existing technology does not support batch verification of electronic files, thereby limiting the work efficiency of relevant personnel. Summary of the invention
[0005] The purpose of this invention is to provide a blockchain method for railway electronic document trust management, which can effectively establish a model with strong trust characteristics and complete tasks in different trust management scenarios on this basis.
[0006] The objective of the present invention is achieved through the following technical solutions:
[0007] A blockchain method for railway electronic document trust management, comprising:
[0008] Constructing a trust model for unexpected changes in electronic documents, including: constructing a directed acyclic graph using the validity verification process relationship network of the electronic documents, and calculating the hash values of the nodes of the directed acyclic graph; taking the directed acyclic graph corresponding to each validity verification process relationship network as a single block, forming a blockchain based on time sequence, and storing the nodes and hash values in a single block using a set information attribute format;
[0009] Based on the trust model of unexpected changes in electronic files, data interaction under physical isolation of file servers, backtracking determination of invalid files, and / or batch verification of electronic files in computer clusters are performed.
[0010] It can be seen from the technical solution provided by the present invention that the existing electronic file verification method is improved through the application of responsibility relationship modeling and hash value calculation scheme for electronic file validity verification; the beneficial effects brought about mainly include: 1) The validity of electronic files can be verified under the condition of physical isolation of the file server, and at the same time, it plays a protective effect against unexpected changes in the electronic file data interaction process. 2) It can find the specific reasons for the failure of the file and the information of the person in charge, which plays an effect of assisting in the determination of responsibility. 3) It can perform batch verification of electronic files, which improves the efficiency of validity verification and problem source location. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0012] Figure 1 A schematic diagram of a version change record of an electronic file provided as background technology;
[0013] Figure 2 A schematic diagram of the responsibility relationship in a file validity verification process provided by an embodiment of the present invention;
[0014] Figure 3 A schematic diagram of a relationship network in a system validity verification process provided by an embodiment of the present invention;
[0015] Figure 4 A schematic diagram of the responsibility relationship in another file validity verification process provided by an embodiment of the present invention;
[0016] Figure 5 A schematic diagram of a relationship network in another system validity verification process provided by an embodiment of the present invention;
[0017] Figure 6 A flowchart of a blockchain method for railway electronic document trust management provided by an embodiment of the present invention;
[0018] Figure 7 A directed acyclic graph schematic diagram of a validity verification process relationship network provided by an embodiment of the present invention;
[0019] Figure 8 A schematic diagram of a hash value calculation scheme applied to directed acyclic graph nodes provided by an embodiment of the present invention;
[0020] Fig. 9 A schematic diagram of a chain reference relationship of a root node provided in an embodiment of the present invention;
[0021] Fig.10 A schematic diagram of a data interaction process under physical isolation provided by an embodiment of the present invention;
[0022] Fig.11 A schematic diagram of a backtracking determination process for an invalid file provided by an embodiment of the present invention;
[0023] Fig.12 A schematic diagram of a relationship network of a validity verification process of a function upgrade provided by an embodiment of the present invention;
[0024] Fig.13 A schematic diagram of batch verification results when a station display terminal program fails provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0025] The following is a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the protection scope of the present invention.
[0026] First, the terms that may be used in this article are explained as follows:
[0027] The term “and / or” means that either or both of them can be realized at the same time. For example, X and / or Y means both “X” or “Y” and “X and Y”.
[0028] The terms "include", "comprises", "contains", "has" or other descriptions with similar semantics should be interpreted as non-exclusive inclusion. For example, including certain technical feature elements (such as raw materials, components, ingredients, carriers, dosage forms, materials, dimensions, parts, components, mechanisms, devices, steps, procedures, methods, reaction conditions, processing conditions, parameters, algorithms, signals, data, products or products, etc.) should be interpreted as including not only certain technical feature elements explicitly listed, but also other technical feature elements known in the art that are not explicitly listed.
[0029] Secondly, the verification principle of validity within railway computer systems is introduced.
[0030] The electronic files used in railway computer systems are electronic archive files that are proven valid by system managers at great expense of work during the functional upgrade of the system's internal components. Introducing invalid or illegal content into the files will lead to a lot of duplication of work and seriously reduce work efficiency.
[0031] Electronic files are specifically divided into system components and technical documents, which are executable programs and their attached files under the operating system framework. Electronic files are created and maintained by computer system managers, and the verification process of their validity is divided into two steps:
[0032] 1) System administrators create or modify executable programs and describe in detail the expected behavior and triggering conditions of computer programs in accompanying documents;
[0033] 2) Relevant personnel use the computer cluster in the simulation laboratory to conduct various debugging and experiments to verify that the program behavior is in line with expectations. After the electronic file completes the validity verification in the simulation laboratory, it is deployed to the computer cluster of the transportation production department by the system management personnel to finally determine the availability and validity of the electronic file content.
[0034] The work content of system managers in the validity verification process is determined according to the responsibilities of their positions, which can be expressed in detail as the assigned responsibility relationship between work items, work categories and electronic files, such as Figure 2 As shown in the figure, the flowchart consists of four symbols: managers, work items, file categories, and files. After the file verification is completed, the overall process can be considered valid. In the actual verification process, multiple executable programs and their attached files are usually deployed in the computer cluster, and the content of each file may be edited by multiple managers, thus forming Figure 3 The complex network shown. Figure 3 yes Figure 3After all executable programs and their attached files in the system are verified, the flowchart as a whole can be considered valid. The behavior of electronic files in a valid state in the computer cluster is completely consistent with the expectations of system administrators.
[0035] Of course, according to the actual needs of the work, the work content of the system administrator in the validity verification process can also be refined into other forms of assignment relationships. Figure 4 It is a variant flow chart of the work content of managers, consisting of managers, work items, hosts and four types of symbols. Figure 4 The host symbol in represents the computer operated by the administrator during the function upgrade process. Figure 4 The process can be further developed into Figure 5 The relationship network of the validity verification process is shown. Similarly, after all executable programs and their attached files in the system are verified, the entire flowchart can be considered valid. The behavior of electronic files in a valid state in the computer cluster is completely consistent with the expectations of the system administrator.
[0036] The following is a detailed description of a blockchain method for railway electronic document trust management provided by the present invention. The contents not described in detail in the embodiments of the present invention belong to the prior art known to professional and technical personnel in the field. If no specific conditions are specified in the embodiments of the present invention, the conventional conditions in the field or the conditions recommended by the manufacturer shall be followed. The instruments used in the embodiments of the present invention, if the manufacturer is not specified, are all conventional products that can be purchased commercially.
[0037] like Figure 6 As shown, a blockchain method for railway electronic document trust management mainly includes the following steps:
[0038] Step 1, constructing a trust model for unexpected changes in electronic documents, including: using the validity verification process relationship network of electronic documents to construct a directed acyclic graph, and calculating the hash values of the nodes of the directed acyclic graph; taking the directed acyclic graph corresponding to each validity verification process relationship network as a single block, forming a blockchain based on time sequence, and storing the nodes and hash values in a single block using a set information attribute format.
[0039] Step 2: Based on the trust model for unexpected changes in electronic files, data interaction under physical isolation of file servers, backtracking determination of invalid files, and / or batch verification of electronic files in computer clusters are performed.
[0040] For ease of understanding, the preferred implementations of the above two steps are described in detail below.
[0041] 1. Build a trust model for unexpected changes to electronic documents.
[0042] The debugging and deployment of electronic files is a process of constantly discovering and verifying functional upgrades within a computer cluster. Before the system as a whole is deemed to be in a valid state, system administrators will repeatedly change the content of electronic files. Because existing electronic file management methods cannot effectively protect against random errors and intentional tampering that damage the validity of files, there is a weak trust relationship between different managers. Especially when multiple system administrators have different expectations for changes to the same electronic file, electronic files are prone to unexpected changes and are deemed invalid. To solve the above problems, the present invention designs a mathematical model with strong trust characteristics, which consists of three parts: 1) A directed acyclic graph of the validity verification process relationship network. 2) A hash value calculation scheme applied to the nodes of the directed acyclic graph. 3) Definition of information attributes of the nodes of the directed acyclic graph. The specific instructions are as follows:
[0043] 1) Directed acyclic graph of the validity verification process relationship network.
[0044] Directed acyclic graph is an effective tool for describing processes. Its characteristic is that all arc edges cannot form a loop in the graph. Figure 3 and Figure 5 The validity verification process relationship network shown is a superposition of multiple unidirectional assignment relationships, and only a cascade relationship exists between adjacent nodes.
[0045] like Figure 7 As shown, the validity verification process relationship network is the corresponding directed acyclic graph. The validity verification process relationship network includes five types of nodes from top to bottom, namely: root node, management personnel node, work item node, file category node or host node, and electronic file node; wherein the root node identifies the valid state of the validity verification process; the work item node describes the relevant work content, the file category node corresponds to a single electronic file category, that is, the category is system component or technical document; the host node corresponds to the computer used to execute the relevant work item.
[0046] It should be noted that when building a trust model for unexpected changes in electronic documents, Figure 3 and Figure 5 The relationship networks shown are all in the same way. Figure 7 Presented Figure 3 Considering that the principles of the related schemes involved in the two relationship networks are the same, for the sake of convenience, the following only uses Figure 3 The relationship network shown is used as an example for introduction.
[0047] 2) A hash value calculation scheme applied to directed acyclic graph nodes.
[0048] In the embodiment of the present invention, a corresponding directed acyclic graph is constructed with a validity verification process relationship network including a root node, a management personnel node, a work item node, a file category node or a host node, and an electronic file node; then, a hash function is used to calculate the hash values of all nodes in the directed acyclic graph from bottom to top, and the corresponding nodes are uniquely marked with the hash values; wherein, when an upper-level node has a connection relationship with several lower-level nodes, the hash values of all the lower-level nodes with the connection relationship are concatenated, and then the hash value of the upper-level node is calculated using the hash function. Specifically:
[0049] After the system validity verification is completed, the administrator can determine the most recent valid state of the electronic file one by one by checking the generation time and file size, or use a hash function to perform file verification. The hash function is a mathematical method that establishes a bijective relationship between any number of byte input information and a fixed number of byte output information (hash value). The characteristic is that when the number of output bytes exceeds a certain value, the calculation results of the original input data of any length are almost impossible to be the same in calculation. Common hash functions include MD5, SHA-256, etc.
[0050] When the input information is an electronic file, the output result of the hash function can uniquely correspond to the file data, which is a "digital fingerprint" that cannot be forged, tampered with, or repeated. When managers perform file verification, they can directly determine the validity of the electronic file by simply checking whether the hash value of the electronic file is consistent with the hash value after verification.
[0051] exist Figure 7 The hash value calculation results of the electronic file, file category, work item, manager and root node are recorded as h f 、h d 、h c 、h p and h root , the hash function is denoted as H(·), and the byte concatenation operation of the hash value is denoted as +. Then the hash value calculation scheme of each node can be expressed as Figure 8 The calculation scheme is based on the reference relationship between different links in the system validity verification, and the hash values of all nodes are calculated one by one from bottom to top through the SHA-256 hash function.
[0052] exist Figure 8 Under the hash value calculation scheme shown, when the directed acyclic graph corresponds to all valid electronic files in the simulation laboratory or transportation production environment, the meanings of the hash values of different types of nodes are shown in Table 1.
[0053]
[0054] Table 1 Meaning of different node hash value tags
[0055] 3) Definition of information attributes of directed acyclic graph nodes.
[0056] The debugging and deployment of electronic files is a process of constantly discovering and verifying functional upgrades within a computer cluster, involving several validity verification processes; the relationship network formed by each validity verification process corresponds to a directed acyclic graph, and each directed acyclic graph is used as a block. The effective state of each block is uniquely marked by the root node in the block, and a chain hash reference relationship is formed in chronological order from front to back. After each functional upgrade, the effective state of the computer cluster is stored in an incremental block manner. Fig. 9 The figure shows a schematic diagram of the chain reference relationship of the root node, which shows the structure of three blocks.
[0057] In the embodiment of the present invention, the directed acyclic graph nodes and related hash values contained in a single block are stored using a set information attribute format; the location and connection relationship of the directed acyclic graph nodes are determined by the node mark, parent node mark, number of layers and type mark, and the hash value, text description and file path are auxiliary information for file management. If the type is a root node, the node additionally stores the completion time of the validity verification (i.e., the verification time), the hash value of the previous block, and the relevant information on the size of the storage space occupied by the current block. Table 2 shows the definition of information attribute format and related attributes, mainly including: node tag, parent node tag, layer number, type, hash value, text description, file path, verification time, previous block hash value, block size; wherein, the node tag is used to uniquely mark the node type, and the node type corresponds to the node type of the validity verification process relationship network; the parent node tag is used to uniquely mark the upper node, indicating the connection relationship between nodes of different levels; the layer number is used to mark the layer number of the node in the directed acyclic graph, and the root node is located at the 0th layer; the type is used to mark the node as a root node, a common node or a leaf node; the hash value is the hash value corresponding to the node; the text description corresponds to the text description of the directed acyclic graph node; the file path marks the location of the electronic file in the computer cluster; the verification time marks the timestamp of the completion of the validity verification; the previous block hash value is the hash value of the root node in the previous block; the block size is the storage space occupied by the block.
[0058]
[0059]
[0060] Table 2 Definition of information attributes of directed acyclic graph nodes
[0061] In the embodiment of the present invention, the text description is mainly for the relevant description of the node. For example, the text description can be "developer" when the node type is a manager, "regular inspection" when the node type is a work item, "requirement specification document" when the node type is a file category, and "code structure description" when the node type is an electronic file; the present invention does not limit the specific content of the text description. In actual applications, the content of the text description can be set according to the situation.
[0062] 2. Electronic document trust management methods.
[0063] The trust management scenarios of the present invention are designed based on the shortcomings of existing methods, and can be specifically described as three types of trust management scenarios: data interaction under physical isolation of file servers, retrospective determination of invalid files, and batch verification of electronic files in computer clusters. The trust model for unexpected changes in electronic files can be expanded to a blockchain-based electronic file trust management method under the three types of trust management scenarios as follows.
[0064] 1. Data interaction under physical isolation of file servers.
[0065] The data interaction under the condition of physical isolation of the file server refers to the data interaction between two physically isolated computer clusters in the simulation laboratory and the transportation production environment. Due to the differences in geographical locations, file transfer methods and workflows of different managers, electronic files are prone to unexpected changes during the data interaction process.
[0066] Fig.10 It is the data interaction process under the physical isolation of computer clusters. In the trust model of unexpected changes in electronic files, each electronic file corresponds to a unique hash value; when the electronic file is transmitted from the simulation laboratory to the transportation production environment, the data received by the transportation production environment includes the electronic file and all hash value records of the corresponding electronic file in the trust model of unexpected changes in electronic files, and the corresponding hash value is calculated using a hash function for the received electronic file; if it is consistent with the hash value corresponding to the latest block in the hash value record of the received electronic file, the received electronic file is deemed to be in a valid state, and the file server in the simulation laboratory is no longer required to perform verification.
[0067] If the electronic file is adjusted (reasonable changes such as parameter fine-tuning or additional instructions) when verifying the functional upgrade in the transportation production environment, the adjusted electronic file and its hash value will be transmitted to the simulation laboratory, and a new block record will be added to update the validity status record of the computer cluster as a whole.
[0068] Exemplarily, the verification tools in the transportation production environment and the simulation laboratory correspond to the terminal instructions provided by the Windows or Linux operating system, and the hash function used for verification is SHA-256.
[0069] 2. Retrospective determination of invalid files.
[0070] In the embodiment of the present invention, each electronic file has a specified expected position in a single block formed during the validity verification process, and the expected position corresponds to a single leaf node in the directed acyclic graph in the block and is uniquely determined by the node label in Table 2; when verifying the electronic file, if the hash value of the electronic file does not match the hash value stored in the latest block and is determined to be an invalid file, the historical hash value record of the corresponding electronic file in the blockchain is backtracked based on the expected position.
[0071] like Fig.11 The figure shows a schematic diagram of the backtracking judgment process. When searching backtracking, the hash value of the node at the expected position in the latest block is first searched. If it does not match, the previous block is searched. The solid box and solid arrow represent the node specified at the expected position of the electronic file and the direction of the backtracking search respectively. The nodes and connection relationships at the unexpected position will not be searched and are marked by virtual boxes and dotted arrows in the figure. The judgment results that may be obtained after the backtracking search are:
[0072] 1) If, during the retrospective search, a node exists in the blockchain that matches the hash value of the electronic file, it is determined that the reason for the file's invalidation is the misuse of an old version of the electronic file.
[0073] 2) If there is no node in the blockchain that matches the hash value of the electronic file, it is determined that the file is invalid due to the introduction of erroneous data.
[0074] The blockchain-based method for backtracking invalid files uses hash values as the basis for judgment, rather than the file attributes such as generation time and file size used by traditional methods. Since the hash value of an electronic file uniquely corresponds to the file data and is almost impossible to tamper with, this method has higher accuracy than traditional methods.
[0075] 3. Batch verification of electronic files in computer clusters.
[0076] In the trust model for unexpected changes in electronic files, each block records the file path (storage path) and hash value of each electronic file in the computer cluster. Both can be understood as the input variables and valid status marks of the hash value calculation scheme at the leaf nodes of the directed acyclic graph. By adjusting the file path parameters, the data of a single block can be used for batch verification of electronic files in the computer cluster. The steps are as follows:
[0077] 1) Obtain block data and transmit it to the target computer cluster;
[0078] 2) The target computer cluster modifies the file paths of the electronic files in the block data one by one; since there is a network connection between the computers in the cluster, the modified file path is a local hard disk path, or a network path connected to a remote computer.
[0079] 3) Referring to the hash value calculation scheme introduced above, use the hash function to automatically calculate the hash value of the electronic file under each file path, and then calculate the hash value of all nodes of the directed acyclic graph one by one from the bottom up by the electronic file node, and check whether the calculated hash value matches the hash value of the corresponding node of the block; the nodes with matching hash values are in a valid state, and the nodes with mismatching hash values are in an invalid state.
[0080] After completing the batch verification, all nodes in the block can be judged as valid or invalid. The valid state means that the work link represented by the node is consistent with expectations and the responsibility relationship has been effectively implemented. Depending on the node type, the node in the invalid state can be interpreted as misuse or data errors in electronic files, invalid components or missing text descriptions in the software and documents in the file category, deviations in the work items during the file operation process, and unexpected changes in the work content of the manager's responsibility.
[0081] In order to more intuitively understand the above-mentioned solutions of the present invention, the following takes the relationship network of the validity verification process of a function upgrade in a computer cluster as an example to introduce the above-mentioned three trust management scenario implementation methods under unexpected changes.
[0082] like Fig.12 The figure shows an example of a relationship network for the validity verification process of a function upgrade. The trust model for unexpected changes in electronic files is constructed in the manner described above.
[0083] 1) Data interaction when file servers are physically isolated.
[0084] Fig.12 The control terminal user manual is a technical document submitted to users after being jointly written by engineers, developers, and testers in the simulation laboratory. The trust management content of this electronic document in validity verification can be described as:
[0085] ① Testers transfer the manual to the transportation production environment, and engineers verify that the changes are the latest valid version.
[0086] ② When verifying the function upgrade in the transportation production environment, the engineering staff will supplement the explanatory text and send the manual back to the simulation laboratory. The test staff will verify the changes and update the validity status record.
[0087] The focus of testers and engineers during data exchange is to ensure that electronic files are not invalidated during transmission due to geographical location, transmission method and workflow. Since hash functions are puzzle-friendly, changes in single-byte data in electronic files (such as adjustments to single punctuation marks, text, and words) will cause significant changes in hash values. When managers use hash values to verify file contents, they can easily find minor changes in document contents and determine that the files are invalid, and then require the sender to resend valid files that meet the requirements of functional upgrades, thereby achieving protection against unexpected changes during data exchange.
[0088] 2) Retrospective determination of invalid files.
[0089] When the electronic file verification result is invalid, the backtracking search method can not only determine the reason for the file invalidation, but also assist in the determination of responsibility. Fig.12 Take the station display terminal program in the example, which is a system component written by developers and deployed to the transportation production environment by testers and engineers. The system component is automatically generated by the compiler after reading the source code and can only be modified by the developer. If the station display terminal program is judged as failed in the data interaction verification operation, the responsibility judgment results corresponding to different failure reasons can be specifically described as follows:
[0090] ① The reason for the failure is the misuse of the old version file, which means that the developer did not introduce unexpected changes in the electronic file. The testers and engineers should be responsible for the failure of the electronic file.
[0091] ②The cause of failure is the introduction of erroneous data. Since testers and engineers cannot change the content of system components, developers should be responsible for the failure of electronic files.
[0092] 3) Batch verification of electronic files in computer clusters.
[0093] The batch verification method of electronic files in computer clusters is an automated method of hash value calculation scheme, which improves work efficiency compared with traditional methods. After the engineering staff completes the deployment of all electronic files in the transportation production environment, they can use the batch verification method to determine whether each electronic file is valid or invalid.
[0094] by Fig.12 Taking all the electronic files included in the functional upgrade as an example, the engineering staff first obtains the block data and modifies the file path to the electronic file storage path in the transportation production environment, and then calculates the hash values of all nodes in the block according to the hash value calculation scheme provided by the trust model. Fig.13It is the batch verification result of electronic files when the station display terminal program fails. The valid nodes and failed nodes are marked by white boxes and shadows respectively. The nodes in the failed state can be interpreted as the status information shown in Table 3. The status information of the failed nodes is the problem indication information during the deployment process of electronic files, which can play a role in locating the source of problems during function upgrade.
[0095]
[0096] Table 3 Status Information of Verification Failed Nodes
[0097] In the above solution of the embodiment of the present invention, by applying the responsibility relationship modeling of electronic file validity verification and the hash value calculation scheme, the existing electronic file verification method is improved; the beneficial effects mainly include:
[0098] 1) It can verify the validity of electronic files in the case of physical isolation of the file server, and at the same time play a protective effect on unexpected changes during the data interaction process of electronic files.
[0099] 2) It can find the specific reasons for file failure and the responsible person information, and play an auxiliary role in responsibility determination.
[0100] 3) It can perform batch verification of electronic files, improving the efficiency of validity verification and problem source location.
[0101] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiments can be implemented by software or by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solutions of the above embodiments can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.), including several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention.
[0102] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A blockchain approach to railway electronic document trust management, It is characterized in that include: Constructing a trust model for unexpected changes in electronic documents, including: constructing a directed acyclic graph using the validity verification process relationship network of the electronic documents, and calculating the hash values of the nodes of the directed acyclic graph; taking the directed acyclic graph corresponding to each validity verification process relationship network as a single block, forming a blockchain based on time sequence, and storing the nodes and hash values in a single block using a set information attribute format; Based on the trust model of unexpected changes in electronic files, data interaction under the condition of physical isolation of file servers, retrospective determination of invalid files, and / or batch verification of electronic files in computer clusters are performed; The validity verification process relationship network is a relationship network formed by the validity verification process; the validity verification process includes: the management personnel make or change the system components, and describe the expected behavior and trigger conditions of the computer program in detail in the corresponding technical documents; various debugging and experiments are carried out through the computer cluster of the simulation laboratory to verify that the system components meet the expectations; wherein the system components and technical documents are both electronic files; the validity verification process relationship network includes five types of nodes from top to bottom, namely: root node, management personnel node, work item node, file category node or host node, and electronic file node; wherein the root node identifies the valid state of the validity verification process; the work item node describes the relevant work content, the file category node corresponds to a single electronic file category, that is, the category is system component or technical document; the host node corresponds to the computer used when executing the relevant work item; The method of calculating the hash value of the directed acyclic graph node comprises: constructing a corresponding directed acyclic graph with a validity verification process relationship network including a root node, a management personnel node, a work item node, a file category node or a host node, and an electronic file node; using a hash function to calculate the hash values of all nodes in the directed acyclic graph from bottom to top, and using the hash value to uniquely mark the corresponding node; wherein, when an upper-layer node has a connection relationship with several lower-layer nodes, concatenating the hash values of all the lower-layer nodes having the connection relationship, and then using the hash function to calculate the hash value of the upper-layer node; The debugging and deployment of electronic files is a process of continuously discovering and verifying functional upgrades within a computer cluster, involving several validity verification processes; The relationship network formed by each validity verification process corresponds to a directed acyclic graph. Each directed acyclic graph is regarded as a block. The valid state of each block is uniquely marked by the root node in the block, and a chain hash reference relationship is formed in chronological order from the beginning to the end. The directed acyclic graph nodes and related hash values contained in a single block are stored using a set information attribute format; the information attribute format includes: node tag, parent node tag, layer number, type, hash value, text description, file path, verification time, previous block hash value and block size; wherein, the node tag is used to uniquely mark the node type, and the node type corresponds to the node type of the validity verification process relationship network; the parent node tag is used to uniquely mark the upper node, indicating the connection relationship between nodes of different levels; the layer number is used to mark the layer number of the node in the directed acyclic graph, and the root node is located at the 0th layer; the type is used to mark the node as a root node, a common node or a leaf node; the hash value is the hash value corresponding to the node; the text description corresponds to the text description of the directed acyclic graph node; the file path marks the location of the electronic file in the computer cluster; the verification time marks the timestamp of the completion of the validity verification; the previous block hash value is the hash value of the root node in the previous block; the block size is the storage space occupied by the block.
2. According to claim 1, a blockchain method for railway electronic document trust management, It is characterized in that Data interaction in the case of physical isolation of file servers based on the trust model for unexpected changes to electronic files includes: The data interaction under the condition of physical isolation of the file server refers to the data interaction between two physically isolated computer clusters in the simulation laboratory and the transportation production environment; In the trust model for unexpected changes in electronic files, each electronic file corresponds to a unique hash value; when an electronic file is transmitted from the simulation laboratory to the transportation production environment, the data received by the transportation production environment includes the electronic file and all hash value records of the corresponding electronic file in the trust model for unexpected changes in electronic files, and the corresponding hash value is calculated for the received electronic file using a hash function; if the hash value is consistent with the hash value corresponding to the latest block in the hash value record of the received electronic file, the received electronic file is deemed to be in a valid state; If the electronic file is adjusted when verifying the functional upgrade in the transportation production environment, the adjusted electronic file and its hash value are transmitted to the simulation laboratory and a new block record is added.
3. According to claim 1, a blockchain method for railway electronic document trust management, It is characterized in that The retrospective determination of invalid files based on the trust model of unexpected changes in electronic files includes: Each electronic file has a specified expected position in a single block formed during the validity verification process. The expected position corresponds to a single leaf node in the directed acyclic graph in the block and is uniquely determined by the node tag in the information attribute. When verifying an electronic file, if the hash value of the electronic file does not match the hash value stored in the latest block and is determined to be an invalid file, the historical hash value record of the corresponding electronic file in the blockchain is traced back based on the expected position. During the backtracking search, first look for the hash value of the node at the expected position in the latest block. If there is no match, look for the previous block. If during the backtracking search, there is a node in the blockchain that matches the hash value of the electronic file, it is determined that the reason for the file's invalidation is the misuse of the old version of the electronic file. If there is no node in the blockchain that matches the hash value of the electronic file, it is determined that the reason for the file's invalidation is the introduction of erroneous data.
4. According to claim 1, a blockchain method for railway electronic document trust management, It is characterized in that The batch verification of electronic files in a computer cluster based on the trust model of unexpected changes in electronic files includes: In the trust model for unexpected changes in electronic files, each block records the file path and hash value of each electronic file in the computer cluster. By adjusting the file path parameters, the data of a single block can be used for batch verification of electronic files in the computer cluster. The steps are as follows: Obtain block data and transmit it to the target computer cluster; The target computer cluster modifies the file paths of the electronic files in the block data one by one; the modified file paths are local hard disk paths, or network paths connected to remote computers; Use the hash function to automatically calculate the hash value of the electronic file under each file path, and then use the electronic file node to calculate the hash value of all nodes in the directed acyclic graph one by one from the bottom up, and check whether the calculated hash value matches the hash value of the corresponding node in the block; nodes with matching hash values are in a valid state, and nodes with mismatched hash values are in an invalid state.
Citation Information
Patent Citations
Cloud data management method based on block chain
CN107196934A
Blockchain credibility verification method and device and blockchain all-in-one machine
CN112333208A