A logistics security management method and system based on a big data environment application
By using public key ring and QR code technology based on big data environment, the problems of user information protection and low last-mile delivery efficiency in logistics system are solved, and secure receipt and real-time logistics traceability are realized, thereby improving the service quality of logistics companies and user trust.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 梁金锋
- Filing Date
- 2022-02-09
- Publication Date
- 2026-04-28
AI Technical Summary
In existing logistics security management systems, issues such as user information protection and data security have not been effectively addressed. The delivery efficiency of last-mile logistics nodes is low, and the problem of lost goods occurs frequently. In particular, the issues of defective signature authentication and fake signatures caused by human factors cannot be effectively resolved.
A logistics security management method based on big data environment is adopted. By using public key ring and QR code technology, identity authentication and ring signature are performed by generating a first public key sequence and a second public key sequence. Combined with hash ring to construct a virtual ring storage space, the unique allocation and identity verification of user public keys are realized, ensuring the anonymity and security of receipt.
It enables secure receipt of goods during the logistics process, prevents loss and misdelivery, improves delivery efficiency, protects user privacy, and enhances user trust in logistics companies through real-time logistics tracking and identity authentication.
Smart Images

Figure CN114462944B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent logistics technology, specifically to a logistics safety management method and system based on big data environment applications. Background Technology
[0002] In recent years, with the rapid development of economic integration and computer network communication technology, the logistics industry has been greatly promoted, and the level of logistics services has been significantly improved. Especially with the emergence of large e-commerce platforms such as Taobao, Tmall, JD.com, and Amazon, the logistics industry has rapidly grown into a new service industry in today's society. Along with the dramatic increase in e-commerce transaction volume, the volume of logistics business has also grown exponentially. Taking the 2020 Double Eleven shopping festival as an example, the total number of logistics orders on Tmall's "Double Eleven" reached 2.321 billion, exceeding the total national express delivery volume for the entire year of 2010. Meanwhile, between November 1st and 11th of that year, postal and express delivery companies nationwide handled a total of 3.965 billion parcels, of which 675 million parcels were handled on November 11th alone, a year-on-year increase of 26.16%, setting a new historical record. However, in the context of big data, the service quality of logistics companies has been increasingly questioned. User information leakage, low delivery efficiency at last-mile logistics nodes, and lost goods have become major challenges facing logistics companies.
[0003] Unlike traditional logistics, the Logistics Internet of Things (IoT) utilizes numerous network communication technologies such as RFID, QR codes, NFC, and D2D to achieve intelligent management and a highly efficient modern logistics system. For user information privacy protection and data security, encryption technology is commonly used, or the traditional data carrier format is further reconstructed, and the final logistics information is decrypted by terminals with specific permissions. For example, Wei Qian et al. proposed a method for protecting the privacy of express delivery information based on the RSA algorithm (cited in: Wei Qian, Wang Chen, Li Xingyi, Electronic Technology Application. 2014, 40(07)), defining a variant of rebalancing-RSA to encrypt personal information to improve the encryption rate; Du Chenjie et al. proposed a new express delivery management system based on encrypted QR code labels (Du Chenjie, Zhang Shaozhong, Yao Yingbiao, Journal of Zhejiang Wanli University. 2017, 3). The personal privacy protection logistics system based on QR code technology proposed by Zhang Xinwen et al. (Zhang Xinwen, Li Huakang, Yang Yitao, Sun Guozi Computer Application Research. 2016, 33(11)) both encapsulate personal privacy information into QR codes after encryption and redefine the data format to avoid privacy information from being leaked. Yu Qi proposed a personal privacy protection system for express delivery industry consumers based on K-anonymity (Yu Qi, Modern Business. 2017, (30)). By introducing the K-anonymity model to generalize customer privacy information, attackers need to exclude at least k-1 sets of data to determine the relevant information of the corresponding target.
[0004] The above technologies have solved the problems of user information protection and data security to a certain extent, but the operation process is too cumbersome and it is not convenient for timely updates and tracking of logistics progress. In particular, the lack of strict verification of the last node recipients and the frequent occurrence of fake signatures that are not of the recipient due to the delivery personnel's irregular operation have led to the "impersonation" or "misdelivery" of express packages, and even the loss of goods due to the absence of any signature record. Summary of the Invention
[0005] To address the issues of flawed goods recipient authentication caused by human error and procedural imperfections at logistics delivery nodes, and the overly complex nature of existing security and confidentiality measures, this invention provides a logistics security management method and system based on a big data environment. This invention can optimize existing logistics management system processes and provide a more reasonable security supervision mechanism.
[0006] The present invention relates to a logistics safety management method based on a big data environment application, the method specifically comprising:
[0007] The sender uses the shipping terminal to generate a shipping order and sends the shipping order to the logistics management center;
[0008] The logistics management center confirms the recipient's identity information and public key based on the shipping order. It then generates a first public key sequence based on the position of the recipient's public key in the public key ring. This first public key sequence is a set of public keys of registered users who are not the recipient, extracted from the public key ring. The first public key sequence is then sent to the recipient's receiving terminal. At the same time, an order identifier encrypted with the recipient's public key is generated based on the shipping order. The encrypted data is then converted into a QR code and sent to the sending terminal and the receiving terminal.
[0009] The sender uses the sending terminal to print and affix a QR code to the goods, and then sends the QR code to the next level transit station terminal according to the designated logistics forwarding route;
[0010] When the goods arrive at the next level of transit station, the terminal of the next level of transit station scans the QR code on the goods and matches it with the QR code stored locally. After a successful match, the local identity information and the QR code are uploaded to the logistics management center and the terminal continues to send the QR code to the terminal of the next level of transit station until the goods arrive at the delivery terminal.
[0011] The logistics management center records the local identity information of each level of transit station corresponding to the QR code, which constitutes the forwarding path log of the goods;
[0012] The recipient scans the QR code on the goods through the receiving terminal, decrypts the QR code using the local private key to obtain the order identifier, extracts the first public key sequence bound to the order identifier, selects a portion of the public key sequence and the recipient's public key to form the second public key sequence, uses the second public key sequence to perform a ring signature for the order identifier, and sends the ring signature data to the logistics management center.
[0013] The logistics management center uses the second public key sequence in the ring signature data to identify the signer's true identity. After successful verification, it extracts the order identifier corresponding to the signer's identity information and compares it with the signature content. If they match, it records a successful receipt message locally and forwards the message to the delivery terminal and the receiving terminal. Otherwise, it sends a receipt failure message to the delivery terminal and the receiving terminal.
[0014] More preferably, the public key ring is a virtual ring-shaped storage space constructed with a hash ring. The logistics management center assigns a unique user public key to each registered user. The storage address of the user public key is indexed by the hash value obtained by hashing the user's identity and mapped to the value space of the hash ring.
[0015] More preferably, the specific process for generating the first public key sequence is as follows:
[0016] The logistics management center extracts the order number and recipient identification recorded in the delivery note, performs a hash operation on the recipient identification, and uses the generated hash value to index the recipient's public key in the hash ring. In the hash ring, the zero and middle bits of the hash ring divide it into two half rings. The user's public key is selected from the other half ring opposite to the half ring where the recipient's public key is located and added to the first public key sequence.
[0017] Perform several hash iterations on the order number, determine the position of the hash value for each iteration. If the current position does not contain a user's public key, select the user's public key at the adjacent position clockwise as the candidate for this hash operation. Further determine whether the candidate is located within the selected semi-ring. If it is, extract the candidate and add it to the first public key sequence; otherwise, discard the candidate and continue with the next hash operation. Repeat the user public key selection operation until a set number of user public keys that meet the selection criteria are obtained.
[0018] More preferably, the process by which the logistics management center identifies the signer using the second public key sequence is as follows: extract all public keys in the second public key sequence, find and record the storage location of each public key in the public key ring, if there is a unique public key located in one half-ring and all the other public keys are located in the other half-ring, then the unique public key in the half-ring is determined to be the signer's public key, and the signer's identity information is further obtained using the signer's public key; otherwise, it indicates that the ring signature data is an invalid signature.
[0019] More preferably, the process also includes a second public key sequence verification process: After identifying the signer's identity information, the logistics management center extracts the first public key sequence corresponding to the signer's identity identifier stored locally, and determines whether all user public keys other than the signer's public key in the second public key sequence are included in the first public key sequence. If so, the second public key sequence is true; otherwise, the second public key sequence is false.
[0020] More preferably, the specific process of the transit station terminal delivering goods according to the designated logistics forwarding route is as follows:
[0021] After receiving the identity information and QR code from the terminal of the next-level transit station, the logistics management center obtains the recipient's identity information based on the QR code, selects the next-level transit station on the optimal forwarding path based on the address of the next-level transit station and the address of the recipient, and sends an authorization letter containing the identity information of the next and next-level transit stations to the terminal of the next-level transit station. The authorization letter is an electronic authorization certificate signed by the logistics management center.
[0022] The higher-level transfer station terminal sends the authorization letter and QR code to the lower-level transfer station terminal based on the lower-level transfer station identity information in the authorization letter;
[0023] When goods arrive at the next-level transit station, the terminal at the next-level transit station scans the QR code on the goods and matches it with the QR code stored locally. If the match is successful, the authorization letter is further verified to determine whether the authorization letter contains local identity information. If it does, it indicates that the transit station is indeed the authorized recipient of the goods by the center, and the local identity information and QR code are sent to the logistics management center. Otherwise, it indicates that the transit station does not have the authority to receive the goods, and an error message is sent to the logistics management center.
[0024] More preferably, the logistics management center automatically assigns or allows delivery stations with delivery capabilities to actively apply for delivery terminals based on the logistics forwarding route;
[0025] When the delivery terminal initiates the application, the delivery station sends a delivery request message containing the goods' QR code to the logistics management center through its local terminal. The logistics management center determines whether the recipient's address is located within the delivery station's delivery jurisdiction. If so, the delivery station is confirmed as a delivery terminal, and the delivery terminal's identity information is associated with the goods' QR code. A delivery confirmation message is then sent to the delivery terminal. Otherwise, a delivery rejection request message is sent to the delivery station's terminal.
[0026] More preferably, it also includes a delivery terminal identity authentication process:
[0027] The recipient receives the delivery terminal's identity information and signature displayed by the delivery terminal through the receiving terminal, and sends it to the logistics management center along with the QR code. The delivery station then signs the delivery terminal's identity information with its private key.
[0028] The logistics management center uses the public key of the delivery station to verify the signature. After successful verification, it compares the delivery terminal identity information associated with the QR code stored locally with the signature content. If they are the same, it indicates that the delivery terminal identity authentication is true; otherwise, it indicates that the delivery terminal identity authentication is false, and the signing confirmation operation is terminated.
[0029] The present invention also provides a logistics safety management system, which specifically includes: a logistics management center, a database, a parcel sending terminal, a parcel receiving terminal, a transit station terminal, and a delivery terminal;
[0030] The Logistics Management Center is responsible for user terminal registration, user account management, and user public key negotiation and allocation. It maintains the forwarding operations of various levels of transit station terminals along designated logistics forwarding paths and the delivery and receipt operations of delivery terminals. Based on the shipping order, it confirms the recipient's identity information and public key. It further generates a first public key sequence based on the position of the recipient's public key in the public key ring. This first public key sequence is a set of registered user public keys extracted from the public key ring, and is then sent to the receiving terminal. Simultaneously, it generates an order identifier encrypted with the recipient's public key based on the shipping order, converts the encrypted data into a QR code, and sends it to the sending and receiving terminals. It records the local identity information of each level of transit station corresponding to the QR code, forming a forwarding path log for the goods. It uses the second public key sequence in the ring signature data to identify the signer's true identity. After successful verification, it extracts the order identifier corresponding to the signer's identity information and compares it with the signature content. If they match, it records a successful receipt message locally and forwards the message to the delivery and receiving terminals; otherwise, it sends a receipt failure message to both terminals.
[0031] Database: Used to store delivery notes, as well as order identifiers derived from the delivery notes, recipient public keys, QR codes, first public key sequences, forwarding path logs of goods, and delivery status messages;
[0032] Parcel drop-off terminal: Used to generate shipping orders and send them to the logistics management center, receive QR codes sent by the logistics management center and print them, and send QR codes to the next level transit station terminal according to the specified logistics forwarding path;
[0033] Receiving terminal: Used to scan the QR code on the goods, decrypt the QR code with the local private key to obtain the order identifier, extract the first public key sequence bound to the order identifier, select a part of the public key sequence and the recipient's public key to form the second public key sequence, use the second public key sequence to perform a ring signature for the order identifier, and send the ring signature data to the logistics management center, and receive the goods receipt status message from the logistics management center;
[0034] Transit station terminal: Used to scan the QR code on the goods arriving at this transit station and match it with the QR code stored locally. After a successful match, the local identity information and the QR code are uploaded to the logistics management center and the terminal continues to send the QR code to the next level transit station terminal until the goods arrive at the delivery terminal.
[0035] Delivery terminal: Receives goods delivery tasks assigned by delivery stations, completes goods delivery based on the recipient address provided by the logistics management center, and receives goods receipt status messages from the logistics management center.
[0036] The advantages of the logistics safety management method and system provided by this invention are as follows:
[0037] Each user is assigned a unique public key. When a user is confirmed as the recipient, a first public key sequence is generated based on the position of the recipient's public key in the public key ring. The recipient further extracts a portion of the public key from the sequence to generate a second public key sequence for performing the signature authentication function. The recipient then uses the second public key sequence to sign the associated order identifier. The logistics management center confirms the signer's identity using the ring signature data fed back by the recipient's terminal. The center compares the locally stored order identifier associated with the signer's identity information with the signature content. If they match, it can be determined that the current logistics order was indeed signed for by the recipient. Using ring signatures to complete the logistics signing operation provides unconditional anonymity to the outside world, while only the logistics management center can identify the signer's true identity internally. This achieves secure signing while preventing the leakage of signer information and preventing signature forgery.
[0038] A public key ring is constructed using a hash ring to create a virtual ring-shaped storage space. The user's public key is mapped to a corresponding position in the hash ring through a hash value. The hash ring is divided into two half-rings. The user's public key in the first public key sequence is selected from the half-ring where the non-recipient's public key is located. This allows the logistics management center to determine the signer's public key by verifying the position of each public key in the second public key sequence within the public key ring after receiving the ring signature. However, the signer's identity remains unknown to any third party other than the logistics management center.
[0039] This invention utilizes QR codes as the tracking object for logistics orders, hiding the actual order information within the QR code. The security of the order information is protected by encryption using the recipient's public key, effectively protecting the user's personal privacy. By scanning the QR codes at various levels, the logistics management center can obtain the logistics routes assigned by the logistics management center in real time. The logistics management center can learn the location of the goods by receiving the electronic data from the QR codes, record the local identity information of the various transit stations corresponding to the QR codes, and form a forwarding path log for the goods, thus realizing logistics traceability.
[0040] The receiving terminal receives the delivery terminal's identity information and signature, which is then sent to the logistics management center along with a QR code. This allows the logistics management center to simultaneously authenticate both the recipient and the delivery party, ensuring the security of the final delivery link in the logistics process. The identity authentication mechanism prevents adverse consequences such as lost or misdelivered goods due to human error during delivery, thereby improving delivery efficiency and user trust in logistics companies. Attached Figure Description
[0041] Figure 1 Flowchart of the logistics safety management method provided by the present invention;
[0042] Figure 2 This is a schematic diagram of the public key ring structure provided in an embodiment of the present invention;
[0043] Figure 3 This is a flowchart illustrating the operation of generating the first public key sequence using a public key ring in an embodiment of the present invention.
[0044] Figure 4 This is a schematic diagram of the spatial structure for generating the first public key sequence using a public key ring in an embodiment of the present invention;
[0045] Figure 5 This invention provides an architecture diagram for a logistics safety management system based on a big data environment. Detailed Implementation
[0046] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0047] like Figure 1 The present invention provides a logistics security management method based on a big data environment, the method comprising:
[0048] The sender generates a shipping order using the shipping terminal and sends it to the logistics management center. This shipping order can be obtained from shopping orders provided by the e-commerce platform and mainly includes: order number, item type (e.g., documents, fresh produce, or clothing), shipping method (e.g., courier service point, locker, or door-to-door pickup), insured value, weight of goods, sender's identification, sender's address and contact information, recipient's identification, recipient's address and contact information, payment method (prepaid or cash on delivery), payment amount, delivery method (e.g., courier service point / locker self-pickup or door-to-door delivery), scheduled delivery / delivery time, etc. In this embodiment, the mobile phone number added during user registration is used as the sender's and recipient's identification. Users can log in to the terminal using their mobile phone number as their user ID and complete verification functions such as SMS verification. The shipping order can be encrypted using the sender's private key and decrypted by the logistics management center using the sender's public key to obtain the plaintext, or secure data transmission can be achieved through a temporary key exchanged between the two parties.
[0049] After decrypting the ciphertext, the logistics management center confirms the recipient's identity based on the recipient's identification recorded in the shipping document, extracts the recipient's public key stored locally, and further generates a first public key sequence based on the position of the recipient's public key in the public key ring. This first public key sequence is a set of public keys of registered users who are not the recipient, extracted from the public key ring. The first public key sequence is then sent to the recipient's receiving terminal, which can encrypt the first public key sequence using the recipient's public key and decrypt it using its own private key to obtain the plaintext.
[0050] The public key ring is a virtual ring-shaped storage space constructed with a defined hash value field; in this embodiment, a hash ring storage structure is specifically adopted. The logistics management center assigns a unique user public key to each registered user. The storage address of the user public key is indexed by the hash value obtained through a hash operation on the user's identity, and the hash value is mapped to the value space of the hash ring. For example... Figure 2 As shown, the constructed hash ring has a value range of 0 to 2. 32 Between the binary values, the hash values are distributed in ascending clockwise circular order. The identity identifiers of users A through E are hashed using a 32-bit hash operation, each corresponding to a different position in the ring space. These hash values point to the storage area where the public keys of users A through E are located, thus forming a virtual ring-shaped storage structure. 32 The value range ensures that no two calculated hash values are likely to collide, and is sufficient to meet the registration needs of a large number of users. Furthermore, the value range can be extended to 2 to meet the needs of big data environments. 48 It can reduce collisions to even higher ranges, and there is no need to adjust the specific location of each user's public key for the entire ring space, making expansion convenient.
[0051] Additionally, for routine maintenance of user public keys, when a user logs out, the corresponding public key data in the public key space needs to be deleted, and the storage location in the ring space needs to be set to NULL. Alternatively, the specific location of certain public keys can be manually set, such as setting A to 2. 22 -1 position, B in 2 22 -2 position, C in 2 22 -3 position, D in 2 22 At position -4, there is no need to calculate the hash value of the user identity identifier or establish a secondary index relationship between the calculated hash value and the manually selected hash value. This method can meet the requirement of batch verification of user identities with unified attribute relationships. If the positions are not adjacent, a loop query operation needs to be performed every time the identity with the same attribute is verified. For batch lookup of public keys with adjacent positions, only one loop query needs to be performed, which improves work efficiency.
[0052] There are several ways to distribute user public keys. One method is for the logistics management center to generate a public-private key pair during user registration, which can then be verified and downloaded via SMS or email from the user's mobile phone. Another method is for both parties to negotiate and obtain the public key, such as using the commonly used RSA public key generation mechanism. The user terminal selects two large prime numbers p and q locally, calculates their product n = pq, and further calculates the Euler's totient function Φ(n) = (p-1)(q-1). An integer e is randomly selected, satisfying the condition 1 < e < Φ(n) and e and Φ(n) being coprime. The value of d is calculated using the equation edmod Φ(n) = 1. {e, n} is sent as the public key to the logistics management center via the local terminal, and {d} is stored locally as the user's private key. The elements p and q can be derived from the user's biometric data collected during terminal registration. Compared to the method of distributing keys entirely by the logistics management center, the public-private key pair derived from user registration has higher security performance, while the operation of distributing key pairs by the logistics management center is simpler. The two can be selected based on the actual use scenario and security requirements.
[0053] Then, the logistics management center generates an order identifier based on the shipping order. Specifically, the hash value obtained by hashing the summary information in the shipping order is used as the order identifier. This encrypted data is then converted into QR code format data using the recipient's public key and sent to the sending and receiving terminals. The logistics management center locally stores a data table related to logistics orders, including at least the following entries. The objects stored in these entries are interconnected in the database, forming a linked list structure.
[0054] Order Number First public key sequence Order Identifier QR code Path logs Order No. n First PK Sequence Order ID QR code Path Log
[0055] When the receiving terminal receives the QR code and the corresponding first public key sequence, it first uses its local private key to decrypt the encrypted data converted from the QR code to obtain the order identifier. The order identifier is then associated with and stored with the first public key sequence for use in the subsequent acceptance operation when the goods are actually received.
[0056] Once the sender receives the QR code data, they use the sending terminal to print the QR code and affix it to the goods. The printing process can be completed through a printer connected to the sending terminal's network interface. Then, the QR code is sent to the next-level transit station terminal according to the designated logistics forwarding path.
[0057] When goods arrive at the next level of transit station, the terminal at the next level of transit station scans the QR code on the goods and matches it with the QR code stored locally. If the match is successful, the local identity information and the QR code are uploaded to the logistics management center together, and the terminal continues to send the QR code to the next level of transit station until the goods arrive at the delivery terminal. If the match is unsuccessful, the QR code data obtained by scanning and the local identity information are sent to the logistics management center along with the error report, and the logistics management center verifies the reason for the error.
[0058] At each stage of cargo forwarding, the logistics management center records the local identity information of each level of transit station corresponding to the QR code, forming a cargo forwarding path log. Taking the above data table format as an example, when the logistics management center receives QR code data sent by a logistics intermediate node, it matches the table entry that matches the QR code stored in the database. The order identifier confirms the logistics order to which the QR code belongs. Under the condition that the transit station node's identity authentication is successful and the data is complete, the local identity information of the transit station node, including the transit station merchant's physical store name, identity identifier, address and contact information, goods inspector, and inspection time, is recorded in the table entry log for real-time tracking and monitoring of cargo flow. Taking the recipient as an example, the receiving terminal sends an order logistics tracking message containing identity authentication data to the logistics management center. After successfully verifying the recipient's identity, the logistics management center sends back the specified forwarding path log message to the receiving terminal, enabling the recipient to view the logistics progress in real time.
[0059] Once goods arrive at the delivery station, the delivery service terminal can be configured for pickup at the courier point, pickup from an electronic locker, or door-to-door delivery, depending on the delivery method. If the courier places the goods in a locker, the locker's scanning area scans the QR code on the goods, and the QR code and the locker's identification information are uploaded to the logistics management center. The logistics management center first verifies the locker's identity information. After confirming its accuracy, it uses the QR code to verify the recipient's detailed address in the shipping order information. If the locker is located near or within the recipient's area, it is authorized as the delivery terminal for this logistics order, and an authorization code is simultaneously sent to both the locker's server and the recipient's terminal. The recipient, based on the storage message received at the terminal, goes to the designated locker. After successful matching by entering the authorization code, the locker displays the electronic QR code of the goods on its screen. For pickup at a courier point or door-to-door delivery, the courier only needs to show the recipient the QR code attached to the goods to complete the scanning.
[0060] The recipient scans the QR code on the goods or screen using the receiving terminal, decrypts the QR code using the local private key to obtain the order identifier, extracts the first public key sequence bound to the order identifier, if there is no associated first public key sequence, sends an authentication error message to the logistics management center, otherwise selects a portion of the public key from the first public key sequence and combines it with the recipient's public key to form a second public key sequence, uses the second public key sequence to perform a ring signature on the order identifier, and sends the ring signature data to the logistics management center.
[0061] A ring signature is generated for the order identifier using the second public key sequence. Assume the signer arbitrarily selects N users when creating the ring signature, and each user A... i Each has a public key PK i and private key SK i We can define a blending function, such as C k,v (y1,y2,…,y N For any set of inputs (y1, y2, ..., y...) N All of these can be solved, but for the attacker, if the trapdoor functions g1, g2, ..., g cannot be found... N The inverse function of C, then given C k,v (g1(x1),g2(x2),…,g N (x N Unable to find x1, x2, ..., x N This process specifically requires executing the following three algorithms: keyGen(), Sign(), and Verify().
[0062] Key generation algorithm: keyGen()
[0063] Suppose keyGen() is a probabilistic multinomial function, where the input is the set security parameter λ, and the output is the public key PK. i and private key SK i This key pair is generated and distributed to the user terminal by the logistics management center, or obtained through negotiation between the two parties. That is, the public and private key pair is local to the user terminal and can be generated using classic public key encryption algorithms such as RSA and ElGamal.
[0064] Signature algorithm: Sign()
[0065] The receiving terminal u uses its own private key SK u The information M is signed using the second public key sequence set, where M is the order identification data, and a ring signature σ is generated.
[0066] 1. The logistics management center provides the signer with the first public key sequence set L1 = {PK1, PK2, ..., PK}. N}, where each PK i With a transformation of y i Related;
[0067] 2. The receiving terminal extracts a portion of the public key from the first public key sequence set L1 to obtain the public key set {PK1, PK2, ..., PK}. T}, T≤N, add its own public key to further obtain the second public key sequence set L2={PK1,PK2,…PK T PK u The extraction method can be random or obtained through sorting by various logical relationships.
[0068] 3. Calculate k = H(M), where H represents the hash operation and k is the symmetric encryption algorithm E. k The key;
[0069] 4. Select a random number v, with an initial value v∈{0,1} b ;
[0070] 5. Generate a random number x i (i = 1, 2, ..., N, i ≠ u), meaning the signer assigns a random number x to the public keys of all users except themselves. i According to x i Calculate the corresponding y i =g(x i );
[0071] 6. Solve equation C k,v (y1,y2,…,y N ) = v, thus obtaining the corresponding value y for the signer. u ;
[0072] 7. The signer uses trapdoor knowledge to solve the corresponding...
[0073] 8. Generate a ring signature σ = (PK1, PK2, ..., PK) of a (2T+3) tuple. T PK u ,v,x1,x2,…,x T ,x u ).
[0074] For an attacker, even if they obtain the private keys of all ring members, the probability of correctly identifying the true signer is no more than 1 / T+1. During the ring signing process, the receiving terminal can send the user's handwritten signature data, bound to an order identifier on an electronic board, to the logistics management center. The order identifier and the handwritten signature data are separated by a special string to facilitate identification of the order identifier field. Additionally, data containing the user's biometric characteristics, such as facial images or fingerprints, can be added to the signature; these unique parameters are also isolated by relevant special fields.
[0075] The logistics management center uses the second public key sequence in the ring signature data to identify the signer's true identity. First, the set of public key sequences {PK1, PK2, ..., PK1} in the ring signature σ is extracted. T PK u The public key (PK) of the ring signer is identified by locating the position of each public key in the set within the public key ring. u Then, the Verify() algorithm is executed on the ring signature:
[0076] 1. Based on x i Calculate y i =g(x i ), obtain (y1, y2, ..., y T ,y u );
[0077] 2. Calculate k = H(M);
[0078] 3. Substitute the above parameters into the ring equation C k,v (y1,y2,…,y T ,y u ) = v, verify whether this equation is true. If it is true, it means the signature verification is successful and output "True"; otherwise, it means the verification has failed and output "False".
[0079] After successful signature verification, the order identifier associated with the signer's public key is extracted and compared with the order identifier in the signature content M. If they match, it indicates that the order was indeed signed for by the recipient, and a successful signature message is recorded locally and forwarded to the delivery terminal and the receiving terminal. If they do not match, it indicates that the recipient of the order does not match the actual signer, and a signature failure message is sent to the delivery terminal and the receiving terminal, recording the reason for refusal. The courier or user then takes appropriate action based on the message displayed on the terminal. For signature content M that also contains handwritten signature data, the order identifier needs to be extracted from the signature content M before verification is performed.
[0080] Utilizing the aforementioned public key ring structure, this invention provides a method for generating a first public key sequence, identifying the signer's public key from the public key set by utilizing the different positions of the user's public key within the public key ring. For example... Figure 4 As shown, in a hash ring, the zero bit and the middle value 2 of the hash ring are... 32 Divide it into two semi-rings using 2 bits, and distribute the public key using the semi-rings.
[0081] The specific process for generating the first public key sequence is as follows:
[0082] like Figure 3As shown, the logistics management center extracts the order number and recipient identification from the shipping document. It performs a hash operation on the recipient identification and uses the generated hash value to index the recipient's public key in the hash ring. Within the hash ring, it selects a user public key from the opposite half of the half-ring containing the recipient's public key and adds it to the first public key sequence. Several hash iterations are performed using the order number. Each hash value points to a user public key. The position of each hash value is checked. If the current position does not contain a user public key, a user public key at an adjacent position clockwise is selected as a candidate for the current hash operation. It is further determined whether the candidate is located within the selected half-ring. If it is, the candidate is extracted and added to the first public key sequence; otherwise, the candidate is discarded, and the next hash operation is performed. This process of selecting user public keys is repeated until a set number of user public keys meeting the selection criteria are obtained. The selection of elements in the first public key sequence allows for collisions, meaning that it allows for the occurrence of two or more identical elements. This is because the probability of repeated collisions is extremely low, and even if such a situation occurs, it will not affect the signature as long as the number of elements in the set meets the security requirements.
[0083] by Figure 3 Taking the case shown as an example, within the value range of 0 to 2 32 In the hash ring, bits 0 and 2 32 The position / 2 is empty, and the line connecting these two nodes visually divides it into two semi-rings, dividing the value range into 1 to 2. 32 / 2-1 and 2 32 / 2+1~2 32First, a hash operation is performed on the recipient's identity to obtain a hash value R. It is known that the public key corresponding to hash value R is located within the first half-ring. Therefore, the user's public key needs to be extracted from the second half-ring as an element in the first public key sequence set. When calculating the hash value H1 for a certain order number for the first time, NULL is displayed at the H1 storage location, indicating that no user public key exists there. The user public key UserPK No. 1 at the adjacent location H2 is selected clockwise as the candidate for this hash operation. It is further confirmed that UserPK No. 1 is located within the second half-ring and is added to the first public key sequence. Then, a second hash iteration operation is performed on hash value H1 to obtain hash value H3. It is confirmed that the user public key UserPK No. 2 stored at H3 is located within the second half-ring and is added to the first public key sequence. Similarly, a third hash iteration operation is performed on hash value H3 to obtain hash value H4. At this time, H4 is also NULL, and the user public key UserPK No. 3 at the adjacent location H5 is located within the first half-ring, which does not meet the selection criteria. The next hash operation is then performed. Similarly, in the 5th hash operation, the user public key UserPK No.5 corresponding to H7 is found to be also located in the first half-ring. Therefore, the hash value H7 is used to jump to the 6th hash operation to obtain H8. This process continues until all user public keys that meet the conditions are selected. In this embodiment, the number of user public keys is set to 6, so the generated public key sequence is {UserPK No.1, UserPK No.2, UserPK No.4, UserPK No.6, UserPK No.7, UserPK No.8}, and all elements are located in the second half-ring.
[0084] After receiving the first public key sequence, the receiving terminal binds it to the order identifier. When the scanned goods' QR code matches the order identifier, it looks up the corresponding public key sequence and selects a portion of the public key from the first public key sequence to participate in the ring signature. Assume the generated second public key sequence is:
[0085] {UserPK No1,UserPK No4,UserPK No6,UserPK No8,RecipientPK}
[0086] Using the algorithm mentioned above, perform ring signature, and the ring signature σ = (UserPK No1, UserPK No4, UserPK No6, UserPK No8, RecipientPK, v, x1, x4, x6, x8, x R The scanned QR code is sent to the logistics management center along with the signed order identifier and other data. If, after decryption locally, the first public key sequence bound to the order identifier is not found, an authentication error message is sent to the logistics management center.
[0087] After receiving the aforementioned signature data, the logistics management center extracts all public keys from the second public key sequence, locates and records the storage location of each public key within the public key ring. UserPK No. 1, UserPK No. 4, UserPK No. 6, and UserPK No. 8 are located in the second half-ring, while only RecipientPK is located in the first half-ring. Therefore, the user identifier corresponding to RecipientPK is the true identity of the signer. Conversely, if no unique public key is located in one half-ring, and all other public keys are located in the other half-ring, the specific signer's identity cannot be determined, and the signature data for that ring is deemed invalid.
[0088] Alternatively, based on the received second public key sequence, another different authentication method can be provided. The logistics management center first searches the database for a related entry based on the order identifier in the signature content. If not found, an authentication error message is sent to the receiving terminal. Otherwise, the first public key sequence is extracted from the entry, and the second public key sequence in the ring signature is compared with this first public key sequence. If only one user public key in the second public key sequence is not included in the first public key sequence, it is further determined that this user public key is not within the same hash half-ring as other user public keys in the second public key sequence. This indicates that the user corresponding to this user public key is the signer's true identity. Finally, after confirming the true identity, the aforementioned ring signature verification operation is performed. Upon successful verification, it is determined that the recipient has signed for the package, and a corresponding confirmation message is sent.
[0089] In another embodiment of the present invention, the logistics forwarding path specified by the transit station terminal can be directly assigned by the logistics management center. Each transit station forwards goods to the next-level logistics node according to the assigned path. The specific process is as follows:
[0090] After receiving the identity information and QR code from the terminal of the next-level transit station, the logistics management center obtains the recipient's identity information based on the QR code, selects the next-level transit station on the optimal forwarding path based on the address of the next-level transit station and the address of the recipient, and sends an authorization letter containing the identity information of the next and next-level transit stations to the terminal of the next-level transit station. The authorization letter is an electronic authorization certificate signed by the logistics management center.
[0091] The higher-level transfer station terminal sends the authorization letter and QR code to the lower-level transfer station terminal based on the identity information of the lower-level transfer station in the authorization letter; the lower-level transfer station terminal will associate and store the QR code and authorization letter received from the same terminal, and use the QR code to retrieve the relevant authorization letter.
[0092] When goods arrive at the next-level transit station, the terminal at the next-level transit station scans the QR code on the goods and matches it with the QR code stored locally. If the match is successful, the authorization letter is further verified to determine whether the authorization letter contains local identity information. If it does, it indicates that the transit station is indeed the authorized recipient of the goods by the center, and the local identity information and QR code are sent to the logistics management center. Otherwise, it indicates that the transit station does not have the authority to receive the goods, and an error message is sent to the logistics management center.
[0093] This invention authorizes and designates delivery routes through a logistics management center, enabling the rational optimization of delivery resources based on delivery range, station cargo throughput, and other factors. It can also hide the recipient's address and contact information. For each level of transit station, they can only obtain the forwarding address of the next transit station for the logistics order from the logistics management center, but cannot know the recipient's contact information, thereby protecting user privacy and preventing the risk of user information leakage.
[0094] In addition, it can be automatically assigned as a delivery terminal based on the logistics forwarding route or by delivery stations with delivery capabilities applying on their own initiative.
[0095] When the delivery terminal initiates the application, the delivery station sends a delivery request message containing the goods' QR code to the logistics management center through its local terminal. The logistics management center determines whether the recipient's address is located within the delivery station's delivery jurisdiction. If so, the delivery station is confirmed as a delivery terminal, and the delivery terminal's identity information is associated with the goods' QR code. A delivery confirmation message is then sent to the delivery terminal. Otherwise, a delivery rejection request message is sent to the delivery station's terminal.
[0096] The distribution terminals are automatically assigned by the logistics management center based on the optimal selection of the logistics forwarding route. Generally, the end node of the route is designated as the distribution terminal, or the node with less workload in the vicinity can be selected as the distribution terminal by referring to the daily cargo flow volume, so as to improve the utilization rate of distribution resources.
[0097] To further enhance system security, the method of this invention also includes a delivery terminal authentication process:
[0098] The recipient receives the delivery terminal's identity information and signature displayed by the delivery terminal through the receiving terminal, and sends it to the logistics management center along with the QR code. The delivery station then signs the delivery terminal's identity information with its private key.
[0099] The logistics management center uses the public key of the delivery station to verify the signature. After successful verification, it compares the delivery terminal identity information associated with the locally stored QR code with the signature content. If they match, it indicates that the delivery terminal's identity authentication is genuine, meaning that the authorized delivery party for the current logistics order is indeed that delivery terminal. Otherwise, it indicates that the delivery terminal's identity authentication is false, meaning that the delivery terminal does not have delivery task authorization, and the signature confirmation operation is terminated. Adding delivery terminal identity authentication can effectively prevent couriers from managing and delivering packages on behalf of each other. Packages can only be managed and delivered by designated personnel, avoiding situations where goods are delivered incorrectly or lost due to delivery chaos, making it impossible to trace the goods.
[0100] To achieve the above method, the present invention also provides a logistics safety management system, such as... Figure 5 As shown, the system specifically includes: a logistics management center, a database, a parcel sending terminal, a parcel receiving terminal, a transit station terminal, and a delivery terminal.
[0101] The Logistics Management Center is responsible for user terminal registration, user account management, and user public key negotiation and allocation. It maintains the forwarding operations of various levels of transit station terminals along designated logistics forwarding paths and the delivery and receipt operations of delivery terminals. Based on the shipping order, it confirms the recipient's identity information and public key. It further generates a first public key sequence based on the position of the recipient's public key in the public key ring. This first public key sequence is a set of registered user public keys extracted from the public key ring, and is then sent to the receiving terminal. Simultaneously, it generates an order identifier encrypted with the recipient's public key based on the shipping order, converts the encrypted data into a QR code, and sends it to the sending and receiving terminals. It records the local identity information of each level of transit station corresponding to the QR code, forming a forwarding path log for the goods. It uses the second public key sequence in the ring signature data to identify the signer's true identity. After successful verification, it extracts the order identifier corresponding to the signer's identity information and compares it with the signature content. If they match, it records a successful receipt message locally and forwards the message to the delivery and receiving terminals; otherwise, it sends a receipt failure message to both terminals.
[0102] Database: Used to store delivery notes, as well as order identifiers derived from the delivery notes, recipient public keys, QR codes, first public key sequences, forwarding path logs of goods, and delivery status messages;
[0103] Parcel drop-off terminal: Used to generate shipping orders and send them to the logistics management center, receive QR codes sent by the logistics management center and print them, and send QR codes to the next level transit station terminal according to the specified logistics forwarding path;
[0104] Receiving terminal: Used to scan the QR code on the goods, decrypt the QR code with the local private key to obtain the order identifier, extract the first public key sequence bound to the order identifier, select a part of the public key sequence and the recipient's public key to form the second public key sequence, use the second public key sequence to perform a ring signature for the order identifier, and send the ring signature data to the logistics management center, and receive the goods receipt status message from the logistics management center;
[0105] Transit station terminal: Used to scan the QR code on the goods arriving at this transit station and match it with the QR code stored locally. After a successful match, the local identity information and the QR code are uploaded to the logistics management center and the terminal continues to send the QR code to the next level transit station terminal until the goods arrive at the delivery terminal.
[0106] Delivery terminal: Receives goods delivery tasks assigned by delivery stations, completes goods delivery based on the recipient address provided by the logistics management center, and receives goods receipt status messages from the logistics management center.
[0107] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
Claims
1. A logistics safety management method based on big data environment applications, characterized in that, The method includes: The sender uses the shipping terminal to generate a shipping order and sends the shipping order to the logistics management center; The logistics management center confirms the recipient's identity information and public key based on the shipping order. It then generates a first public key sequence based on the position of the recipient's public key in the public key ring. This first public key sequence is a set of public keys of registered users who are not the recipient, extracted from the public key ring. The first public key sequence is then sent to the recipient's receiving terminal. At the same time, an order identifier encrypted with the recipient's public key is generated based on the shipping order. The encrypted data is then converted into a QR code and sent to the sending terminal and the receiving terminal. The sender uses the sending terminal to print and affix a QR code to the goods, and then sends the QR code to the next level transit station terminal according to the designated logistics forwarding route; When the goods arrive at the next level of transit station, the terminal of the next level of transit station scans the QR code on the goods and matches it with the QR code stored locally. After a successful match, the local identity information and the QR code are uploaded to the logistics management center and the terminal continues to send the QR code to the terminal of the next level of transit station until the goods arrive at the delivery terminal. The logistics management center records the local identity information of each level of transit station corresponding to the QR code, which constitutes the forwarding path log of the goods; The recipient scans the QR code on the goods through the receiving terminal, decrypts the QR code using the local private key to obtain the order identifier, extracts the first public key sequence bound to the order identifier, selects a portion of the public key sequence and the recipient's public key to form the second public key sequence, uses the second public key sequence to perform a ring signature for the order identifier, and sends the ring signature data to the logistics management center. The logistics management center uses the second public key sequence in the ring signature data to identify the signer's true identity. After successful verification, it extracts the order identifier corresponding to the signer's identity information and compares it with the signature content. If they match, it records a successful receipt message locally and forwards the message to the delivery terminal and the receiving terminal. Otherwise, it sends a receipt failure message to the delivery terminal and the receiving terminal.
2. The logistics safety management method based on big data environment application according to claim 1, characterized in that, The public key ring is a virtual ring-shaped storage space constructed from hash rings. The logistics management center assigns a unique user public key to each registered user. The storage address of the user public key is indexed by the hash value obtained by hashing the user's identity and mapped to the value space of the hash ring.
3. The logistics safety management method based on big data environment application according to claim 2, characterized in that, The specific process for generating the first public key sequence is as follows: The logistics management center extracts the order number and recipient identification recorded in the delivery note, performs a hash operation on the recipient identification, and uses the generated hash value to index the recipient's public key in the hash ring. In the hash ring, the zero and middle bits of the hash ring divide it into two half rings. The user's public key is selected from the other half ring opposite to the half ring where the recipient's public key is located and added to the first public key sequence. Perform several hash iterations on the order number, determine the position of the hash value for each iteration. If the current position does not contain a user's public key, select the user's public key at the adjacent position clockwise as the candidate for this hash operation. Further determine whether the candidate is located within the selected semi-ring. If it is, extract the candidate and add it to the first public key sequence; otherwise, discard the candidate and continue with the next hash operation. Repeat the user public key selection operation until a set number of user public keys that meet the selection criteria are obtained.
4. The logistics safety management method based on big data environment application according to claim 3, characterized in that, The process by which the logistics management center identifies the signer using the second public key sequence is as follows: extract all public keys in the second public key sequence, find and record the storage location of each public key in the public key ring, and if there is a unique public key located in one half of the ring and all the other public keys are located in the other half of the ring, then the unique public key in the half of the ring is determined to be the signer's public key, and the signer's identity information is further obtained using the signer's public key; otherwise, it indicates that the ring signature data is an invalid signature.
5. The logistics safety management method based on big data environment application according to claim 4, characterized in that, It also includes a second public key sequence verification process: After identifying the signer's identity information, the logistics management center extracts the first public key sequence corresponding to the signer's identity identifier stored locally, and determines whether all user public keys other than the signer's public key in the second public key sequence are included in the first public key sequence. If so, the second public key sequence is true; otherwise, the second public key sequence is false.
6. The logistics safety management method based on big data environment application according to claim 1, characterized in that, The specific process of the transit station terminal delivering goods according to the designated logistics forwarding route is as follows: After receiving the identity information and QR code from the terminal of the next-level transit station, the logistics management center obtains the recipient's identity information based on the QR code, selects the next-level transit station on the optimal forwarding path based on the address of the next-level transit station and the address of the recipient, and sends an authorization letter containing the identity information of the next and next-level transit stations to the terminal of the next-level transit station. The authorization letter is an electronic authorization certificate signed by the logistics management center. The higher-level transfer station terminal sends the authorization letter and QR code to the lower-level transfer station terminal based on the lower-level transfer station identity information in the authorization letter; When goods arrive at the next-level transit station, the terminal at the next-level transit station scans the QR code on the goods and matches it with the QR code stored locally. If the match is successful, the authorization letter is further verified to determine whether the authorization letter contains local identity information. If it does, it indicates that the transit station is indeed the authorized recipient of the goods by the center, and the local identity information and QR code are sent to the logistics management center. Otherwise, it indicates that the transit station does not have the authority to receive the goods, and an error message is sent to the logistics management center.
7. The logistics safety management method based on big data environment application according to claim 1, characterized in that, The logistics management center automatically assigns delivery terminals based on the logistics forwarding route, or delivery stations with delivery capabilities can apply to become delivery terminals. When the delivery terminal initiates the application, the delivery station sends a delivery request message containing the goods' QR code to the logistics management center through its local terminal. The logistics management center determines whether the recipient's address is located within the delivery station's delivery jurisdiction. If so, the delivery station is confirmed as a delivery terminal, and the delivery terminal's identity information is associated with the goods' QR code. A delivery confirmation message is then sent to the delivery terminal. Otherwise, a delivery rejection request message is sent to the delivery station's terminal.
8. The logistics safety management method based on big data environment application according to claim 7, characterized in that, It also includes the delivery terminal identity authentication process: The recipient receives the delivery terminal's identity information and signature displayed by the delivery terminal through the receiving terminal, and sends it to the logistics management center along with the QR code. The delivery station then signs the delivery terminal's identity information with its private key. The logistics management center uses the public key of the delivery station to verify the signature. After successful verification, it compares the delivery terminal identity information associated with the QR code stored locally with the signature content. If they are the same, it indicates that the delivery terminal identity authentication is true; otherwise, it indicates that the delivery terminal identity authentication is false, and the signing confirmation operation is terminated.
9. A logistics safety management system, characterized in that, The system includes: a logistics management center, a database, a parcel sending terminal, a parcel receiving terminal, a transit station terminal, and a delivery terminal; The Logistics Management Center is responsible for user terminal registration, user account management, and user public key negotiation and allocation. It maintains the forwarding operations of various levels of transit station terminals along designated logistics forwarding paths and the delivery and receipt operations of delivery terminals. Based on the shipping order, it confirms the recipient's identity information and public key. It further generates a first public key sequence based on the position of the recipient's public key in the public key ring. This first public key sequence is a set of registered user public keys extracted from the public key ring, and is then sent to the receiving terminal. Simultaneously, it generates an order identifier encrypted with the recipient's public key based on the shipping order, converts the encrypted data into a QR code, and sends it to the sending and receiving terminals. It records the local identity information of each level of transit station corresponding to the QR code, forming a forwarding path log for the goods. It uses the second public key sequence in the ring signature data to identify the signer's true identity. After successful verification, it extracts the order identifier corresponding to the signer's identity information and compares it with the signature content. If they match, it records a successful receipt message locally and forwards the message to the delivery and receiving terminals; otherwise, it sends a receipt failure message to both terminals. Database: Used to store delivery notes, as well as order identifiers derived from the delivery notes, recipient public keys, QR codes, first public key sequences, forwarding path logs of goods, and delivery status messages; Parcel drop-off terminal: Used to generate shipping orders and send them to the logistics management center, receive QR codes sent by the logistics management center and print them, and send QR codes to the next level transit station terminal according to the specified logistics forwarding path; Receiving terminal: Used to scan the QR code on the goods, decrypt the QR code with the local private key to obtain the order identifier, extract the first public key sequence bound to the order identifier, select a part of the public key sequence and the recipient's public key to form the second public key sequence, use the second public key sequence to perform a ring signature for the order identifier, and send the ring signature data to the logistics management center, and receive the goods receipt status message from the logistics management center; Transit station terminal: Used to scan the QR code on the goods arriving at this transit station and match it with the QR code stored locally. After a successful match, the local identity information and the QR code are uploaded to the logistics management center and the terminal continues to send the QR code to the next level transit station terminal until the goods arrive at the delivery terminal. Delivery terminal: Receives goods delivery tasks assigned by delivery stations, completes goods delivery based on the recipient address provided by the logistics management center, and receives goods receipt status messages from the logistics management center.
Citation Information
Patent Citations
Security access method for cloud controller based on cloud computing platform
CN103166969A
Logistic encryption signing method and system
CN103473661A