A blockchain-based early warning decision method, system, device and storage medium

By deploying blockchain consensus nodes and smart contracts in a consortium blockchain, the problems of chaotic processing and resource competition caused by each organization's independent early warning response in the consortium blockchain are solved. This achieves effective and efficient unified coordination of early warning levels and reduces overall costs.

CN116599834BActive Publication Date: 2025-11-21CHINA ASEAN INFORMATION PORT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310559191.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-17
Publication Date
2025-11-21
Estimated Expiration
2043-05-17

AI Technical Summary

Technical Problem

In consortium blockchain scenarios, the independent early warning response by each organization leads to problems such as chaotic processing, resource competition, and high costs. Existing technologies have failed to effectively utilize blockchain voting mechanisms for refined early warning level conversion and upgrade management.

Method used

Deploy blockchain consensus nodes in the alliance, obtain anomaly logs and warning levels through smart contracts, broadcast them and conduct multi-system consensus voting, define the conversion rules from anomalies to warnings, and use the blockchain consensus mechanism to ensure the effectiveness and consistency of warning levels.

Benefits of technology

It achieved group acceptance and effectiveness at the early warning level, improved overall execution efficiency, and reduced response costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116599834B_ABST
    Figure CN116599834B_ABST
Patent Text Reader

Abstract

The application discloses a kind of early warning decision-making methods based on blockchain, belong to blockchain early warning technical field, solve the technical problem that existing blockchain early warning level is unreliable, method includes: each organization in alliance is deployed a blockchain consensus node;When the business system of certain organization in alliance is abnormal, the abnormal log of the organization is obtained, and early warning level is obtained by analysis;The abnormal log and early warning level are chained, and broadcast;Each blockchain consensus node in alliance receives abnormal log and early warning level, and automatically executes smart contract, completes voting, reaches early warning level consensus by voting;Early warning level consensus is written into blockchain by smart contract, and broadcast to each blockchain consensus node in the whole network based on blockchain consensus mechanism, each blockchain consensus node will start early warning response according to the abnormal log and early warning level consensus of itself.The application further discloses a kind of early warning decision-making systems based on blockchain, equipment and storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of blockchain early warning, more specifically, it relates to a blockchain-based early warning decision method, system, device and storage medium. BACKGROUND

[0002] As a new distributed storage service, the blockchain technology has the characteristics of "unforgeable", "full trace", "traceable", "open and transparent", "collective maintenance", etc. The blockchain technology has the characteristics of decentralization. In the scene of group decision-making, the application of the blockchain technology can improve the credibility of group decision-making.

[0003] For the alliance chain scene, multiple organizations form an alliance, and in the case of abnormality of the system of a certain organization, it may affect the overall alliance. In this case, if each organization responds to the early warning according to its own rules, each organization is independent, and there is no unified coordination. On the one hand, the processing process may be messy, and even new problems may be caused. On the other hand, the overall alliance lacks a unified interface to the outside world, and each organization responds and resource scheduling according to its own early warning level, which may lead to resource competition and make it difficult to achieve the overall optimal effect. On the other hand, the cost of overall abnormal handling response may be high. Therefore, the organizations need to negotiate unified measures and solutions to respond to abnormalities, and the nodes respond to system abnormalities according to the coordinated measures and overall resources, and invest the lowest cost to obtain the optimal solution from the perspective of the overall alliance. For example, in the field of politics and law, the political and legal committee is the guidance and supervision unit, and the public security, procuratorate and court are the execution units, which cooperate with each other to handle cases. When the business system of a certain unit has a problem, it may only affect its internal business, or it may affect the execution of certain cases. If it is not handled through unified consultation, the problem solving efficiency may be low. In this case, the units need to jointly consult a unified early warning level, and the supervision unit needs to coordinate and supervise the solution and processing after reaching a certain early warning level. Then each unit responds consistently under supervision, which can improve the problem solving efficiency and achieve the optimal effect.

[0004] The blockchain technology is suitable for multi-system collaboration. In such a scenario, the blockchain technology is introduced into the log-based early warning system, the original log and early warning information are chained, and early warning voting is performed based on multi-system consensus. The reliability of the original data can be guaranteed, and the early warning level can be supported by the majority of the group, thereby ensuring the effectiveness of the early warning level, which is highly recognized by the relevant business parties to the greatest extent. The overall execution efficiency can be improved, and the response cost can be reduced.

[0005] The patent application CN110932892B designs a kind of information early warning method, device, related node based on block chain and storage medium, wherein it is proposed that the abnormal information of block chain is broadcasted in block chain network, and the abnormal information in multiple nodes is compared with consistency, and all consistent triggers the method of alarm.In the method, although the block chain technology is applied, the conversion rule of exception to alarm is not defined clearly, all exceptions can trigger alarm, not enough refinement, in addition, the voting mechanism of block chain is not fully utilized, just carries out simple consistency comparison, and alarm is not upgraded and managed, and the applicability of complex application scene is insufficient.

[0006] The patent application CN1130551718 designs a kind of log security analysis and storage method based on block chain, wherein log review information is chained, original log is stored in cloud, is broadcasted to whole network, log storage needs to be confirmed back to original system before being chained, increases network load, and original log is not chained, and reliability is insufficient. SUMMARY

[0007] The technical problem to be solved by the present application is to solve the above-mentioned deficiencies of the prior art, and the purpose of the present application is to provide a kind of early warning decision method based on block chain.

[0008] The second purpose of the present application is to provide a kind of early warning decision system based on block chain.

[0009] The third purpose of the present application is to provide a kind of computer equipment.

[0010] The fourth purpose of the present application is to provide a kind of computer storage medium.

[0011] In order to achieve the above-mentioned first purpose, the present application provides a kind of early warning decision method based on block chain, comprising:

[0012] Each organization in the alliance is deployed with a block chain consensus node;

[0013] When the business system of a certain organization in the alliance is abnormal, the abnormal log of the organization is obtained, and the warning level is analyzed;

[0014] The abnormal log and warning level are chained and broadcasted;

[0015] Each block chain consensus node in the alliance receives the abnormal log and warning level, and automatically executes the smart contract, completes the voting, and reaches the consensus of warning level through voting;The smart contract writes the consensus of warning level into the block chain, and broadcasts it to each block chain consensus node in the whole network based on the block chain consensus mechanism, and each block chain consensus node will start the early warning response according to the consensus of the abnormal log and warning level.

[0016] As a further improvement, the smart contract Si of the i-th blockchain consensus node includes three types of data:

[0017] (1) the current input abnormal log L;

[0018] (2) the current input warning level W;

[0019] (3) the current warning rule set Ri of the business system, Ri={(Ej, W)=Wj}, Ej is the abnormal type defined by the current business system, Wj is the warning level output by the current rule, i∈{1, 2, 3, …, N}, j∈{1, 2, 3, …, M};

[0020] After Si is started, L is converted into corresponding Ej, and Ej is matched with Ri; if a specific rule is matched, the Wj of the rule is output as the warning level Wi; if no rule is matched, it means that no rule is defined for this exception, and this exception has no impact on the current business system, and the input W is output as the warning level Wi.

[0021] Further, the smart contract Si writes the warning level Wi into the blockchain, and after consensus is completed, each blockchain consensus node obtains the voting list V={W1, W2, …, Wn} of each blockchain consensus node;

[0022] The smart contract of each blockchain consensus node performs unified distributed computing to obtain the final voting result.

[0023] Further, if there are more than or equal to N / 2 warning levels in V that are consistent, i.e. the consistent result of the vote is more than half of the number of nodes, it is considered that the warning level has been recognized by the majority of nodes, and the warning level is taken as the voting consensus and is chained again;

[0024] Otherwise, the consensus has not been recognized by half of the nodes, and the largest voting Wmax is found, and the warning level one level higher than Wmax is output as the warning level.

[0025] Further, the blockchain consensus node internally stores the blockchain ledger, and the blockchain ledgers between the blockchain consensus nodes are kept consistent through the consensus mechanism; the blockchain consensus node installs the smart contract.

[0026] Further, the abnormal types defined by the business system include user behavior anomaly, policy violation, internal threat, external attack, and data theft.

[0027] Further, the logs of the business system and the infrastructure on which the business system depends are collected in real time, summarized and analyzed, and when an anomaly is found, the log is classified as an abnormal log and an abnormal alarm is issued.

[0028] In order to achieve the second purpose, the application provides a warning decision system based on a block chain, comprising a log collection module, an abnormality analysis module, a warning module and a block chain consensus node arranged in a business system of each organization in an alliance.

[0029] The log collection module is used for collecting logs of the business system and infrastructure logs relied on by the business system in real time, performing summarization and uniformly outputting to the abnormality analysis module.

[0030] The abnormality analysis module is used for performing real-time analysis on the collected logs, detecting various system abnormal behaviors, and once detecting an abnormality, the abnormality detection module sends original logs related to the abnormality to the warning module for warning level determination, and after obtaining the warning level, the abnormality detection system writes the original abnormality logs and the warning level into a block chain ledger, and the two types of information are broadcasted in the alliance network through a block chain consensus mechanism.

[0031] The warning module is used for defining warning levels and abnormality models according to unified agreements of the alliance, and the abnormality models include user behavior abnormality, policy violation, internal threat, external attack and data theft, which can be defined and modeled by the organization according to its own scene; the warning module analyzes the input abnormality logs according to the abnormality model, obtains a warning level, and outputs the warning level to the abnormality analysis module.

[0032] The block chain consensus node is used for storing the block chain ledger, and the block chain ledgers between the block chain consensus nodes are consistent through the consensus mechanism; the block chain consensus node installs a warning decision smart contract, and when the block chain consensus node receives a warning broadcast, the smart contract is voted, and finally the voting result is chained.

[0033] In order to achieve the third purpose, the application provides a computer device comprising a memory and a processor, the memory stores a computer program, and the processor implements the above-mentioned warning decision method based on the block chain when executing the computer program.

[0034] In order to achieve the fourth purpose, the application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by the processor to implement the above-mentioned warning decision method based on the block chain.

[0035] Advantages

[0036] Compared with the prior art, the application has the following advantages:

[0037] The application introduces blockchain technology into a log-based early warning system, chains abnormal logs, and defines a multi-system consensus early warning level decision mechanism based on a smart contract, which can guarantee the reliability of original abnormal logs, ensure that a specific early warning level obtains the support of the majority of systems in the group, thereby ensuring the effectiveness of the early warning level, and can be recognized by relevant business parties to the greatest extent, and can improve execution efficiency and reduce execution cost. BRIEF DESCRIPTION OF DRAWINGS

[0038] Fig. 1 is the early warning flowchart of the application;

[0039] Fig. 2 is the overall network architecture diagram of the early warning system of the application. DETAILED DESCRIPTION

[0040] The application will be further described below in combination with specific embodiments in the drawings.

[0041] Referring to Figs. 1-2 A blockchain-based early warning decision method, comprising:

[0042] Each organization in the alliance deploys a blockchain consensus node;

[0043] When an abnormality occurs in the business system of an organization in the alliance, the abnormal log of the organization is obtained, and the early warning level is obtained by analysis;

[0044] The abnormal log and the early warning level are chained and broadcasted;

[0045] Each blockchain consensus node in the alliance receives the abnormal log and the early warning level, and automatically executes the smart contract to complete voting and reach consensus on the early warning level through voting; the smart contract writes the early warning level consensus into the blockchain, broadcasts it to each blockchain consensus node in the entire network based on the blockchain consensus mechanism, and each blockchain consensus node will start the early warning response according to its own consensus on the abnormal log and the early warning level.

[0046] The entire voting process is completed through the smart contract installed on the blockchain node of each organization.

[0047] The smart contract Si of the i-th blockchain consensus node includes three types of data:

[0048] (1) the current input abnormal log L;

[0049] (2) the current input early warning level W;

[0050] (3) the early warning rule set Ri of the current business system, Ri={(Ej, W)=Wj}, Ej is an abnormal type defined by the current business system, Wj is an early warning level output by the current rule, i∈{1, 2, 3, …, N}, j∈{1, 2, 3, …, M};

[0051] After Si is started, L is first converted into the corresponding Ej, and Ej is matched with Ri; if a specific rule is matched, the Wj of the rule is output as the early warning level Wi; if no rule is matched, it indicates that no rule is defined for this abnormality, and the input W is output as the early warning level Wi, which has no impact on the current business system.

[0052] The smart contract Si writes the early warning level Wi into the blockchain, and after consensus is completed, each blockchain consensus node obtains the voting list V={W1, W2, …, Wn} of each blockchain consensus node;

[0053] The smart contracts of each blockchain consensus node perform unified distributed computing to obtain the final voting result.

[0054] If there are more than or equal to N / 2 early warning levels consistent in V, that is, more than half of the node number of the consistent result of voting, it is considered that the early warning level has been recognized by the majority of nodes, and the early warning level is taken as the voting consensus and is chained again;

[0055] Otherwise, the consensus is not recognized by half of the nodes, and the largest voting Wmax (i.e. the early warning level Wmax) is found out, and the early warning of the next highest level of Wmax is output as the early warning level, which ensures the majority of votes while improving the early warning level by one, so that the entire alliance responds to a higher level.

[0056] In the embodiment, the blockchain consensus nodes internally store the blockchain ledger, and the blockchain ledgers between the blockchain consensus nodes are consistent through the consensus mechanism; the blockchain consensus nodes install smart contracts. The abnormal types defined by the business system include user behavior abnormalities, policy violations, internal threats, external attacks, and data theft. The logs of the business system and the infrastructure on which the business system depends are collected in real time, summarized and analyzed, and when an abnormality is found, the log is classified as an abnormal log and an abnormal alarm is issued.

[0057] A blockchain-based early warning decision system includes a log collection module, an abnormality analysis module, an early warning module, and a blockchain consensus node of a business system set in each organization in an alliance;

[0058] Each organization in the alliance deploys an independent business system for organizing business-related and processing business logic within the organization, and it is possible that various system abnormalities occur, and these abnormalities are first reflected through logs;

[0059] The log collection module is used for collecting logs of a business system and infrastructure logs relied on by the business system in real time, performing summarization, and uniformly outputting to the abnormality analysis module;

[0060] The abnormality analysis module is used for performing real-time analysis on the collected logs, detecting various system abnormal behaviors, and once detecting an abnormality, sending the abnormality-related original logs to the early warning module for early warning level determination, obtaining the early warning level, and writing the original abnormality logs and the early warning level into a blockchain ledger. The two types of information are broadcasted within an alliance network through a blockchain consensus mechanism.

[0061] The early warning module is used for defining early warning levels, such as P1, P2, P3, and P4, and abnormality models, including user behavior abnormality, policy violation, internal threat, external attack, and data theft, which can be defined and modeled by an organization according to its own scene. The early warning module analyzes the input abnormality logs according to the abnormality model, obtains the early warning level, and outputs the early warning level to the abnormality analysis module.

[0062] The blockchain consensus node is used for storing the blockchain ledger, and the blockchain ledgers between the blockchain consensus nodes are kept consistent through a consensus mechanism. The blockchain consensus node installs an early warning decision smart contract, and when the blockchain consensus node receives a warning broadcast, it votes on the smart contract and finally uploads the voting result.

[0063] A computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the above-mentioned early warning decision method based on a blockchain when executing the computer program.

[0064] A computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the above-mentioned early warning decision method based on a blockchain.

[0065] The above is only a preferred embodiment of the present application, and it should be noted that for those skilled in the art, without departing from the structure of the present application, a number of modifications and improvements can be made, which will not affect the effect and practicality of the present application.

Claims

1. A blockchain-based early warning decision method, characterized in that, The application relates to a blockchain-based pre-warning system for a business system. Each organization in the alliance deploys a blockchain consensus node; When an abnormality occurs in a business system of an organization in the alliance, the abnormality log of the organization is obtained, and a pre-warning level is analyzed; The abnormality log and the pre-warning level are chained and broadcasted; Each blockchain consensus node in the alliance receives the abnormality log and the pre-warning level, and automatically executes an intelligent contract to complete voting and reach a pre-warning level consensus through voting; The intelligent contract writes the pre-warning level consensus into a blockchain, and broadcasts the pre-warning level consensus to all blockchain consensus nodes in the network based on a blockchain consensus mechanism; each blockchain consensus node starts a pre-warning response according to the consensus of the abnormality log and the pre-warning level; The intelligent contract Si of the i-th blockchain consensus node comprises three types of data: (1) the current input abnormality log L; (2) the current input pre-warning level W; (3) the current pre-warning rule set Ri of the business system, Ri={(Ej, W)=Wj}, Ej is an abnormality type defined by the current business system, and Wj is a pre-warning level output by the current rule, i belongs to {1, 2, 3,..., N}, and j belongs to {1, 2, 3,..., M}; After the Si is started, L is converted into corresponding Ej, and Ej is matched with Ri; if a specific rule is matched, the Wj of the rule is taken as the pre-warning level Wi; if no rule is matched, it is indicated that no rule is defined for the abnormality, and the input W is taken as the pre-warning level Wi, which has no influence on the current business system; The intelligent contract Si writes the pre-warning level Wi into the blockchain, and after the consensus is completed, each blockchain consensus node obtains a voting list V={W1, W2,..., Wn} of each blockchain consensus node; The intelligent contracts of the blockchain consensus nodes perform unified distributed calculation to obtain a final voting result; The abnormality types defined by the business system include user behavior abnormality, policy violation, internal threat, external attack and data theft. 2.The early warning decision method based on blockchain of claim 1, characterized in that, If the number of pre-warning levels consistent in V is greater than or equal to N / 2, that is, the consistent result of voting is greater than half of the number of nodes, it is considered that the pre-warning level is recognized by the majority of nodes, and the pre-warning level is taken as the voting consensus and chained again; Otherwise, the consensus is not recognized by half of the nodes, the largest voting Wmax is found, and a pre-warning of a higher level of Wmax is taken as the pre-warning level output. 3.The early warning decision method based on blockchain of claim 1, characterized in that, The blockchain consensus node internally stores a blockchain ledger, and the blockchain ledgers of the blockchain consensus nodes are kept consistent through a consensus mechanism; the blockchain consensus node is installed with an intelligent contract. 4.The early warning decision method based on blockchain of claim 1, characterized in that, The logs of the business system and the infrastructure relied on by the business system are collected in real time, are summarized and analyzed, and when an abnormality is found, the log is classified as an abnormality log, and an abnormality alarm is sent. 5.A blockchain-based early warning decision system, characterized in that, The application comprises a log collection module, an abnormality analysis module, a pre-warning module and a blockchain consensus node arranged in the business system of each organization in the alliance; The log collection module is used for collecting the logs of the business system and the infrastructure relied on by the business system in real time, summarizing the logs and uniformly outputting the logs to the abnormality analysis module. The anomaly analysis module is used for real-time analysis of the collected logs, detects various system abnormal behaviors, and once an anomaly is detected, the anomaly detection module sends the anomaly-related original logs to the early warning module for early warning level determination. After obtaining the early warning level, the anomaly detection system writes the original anomaly logs and the early warning level into the blockchain ledger. These two types of information are broadcasted within the alliance network through the blockchain consensus mechanism. The early warning module is used to define the early warning level and anomaly model according to the alliance agreement, including user behavior anomaly, policy violation, internal threat, external attack, and data theft, which can be defined and modeled by the organization according to its own scene. The early warning module analyzes the input anomaly logs according to the anomaly model and obtains the early warning level, which is output to the anomaly analysis module. The blockchain consensus node is used to store the blockchain ledger, and the blockchain ledgers between the blockchain consensus nodes are consistent through the consensus mechanism. The blockchain consensus node installs the early warning decision smart contract, and when the blockchain consensus node receives the early warning broadcast, it votes on the smart contract, and finally the voting results are uploaded. 6.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-5 when the computer program is executed by the processor. The processor executes the computer program to realize the early warning decision method based on the blockchain in any one of claims 1-4.

7. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the early warning decision method based on the blockchain in any one of claims 1-4.

Citation Information

Patent Citations

  • Information early warning methods, devices, related nodes, and storage media based on blockchain.

    CN110932892B

  • Abnormal node detection method and device, computer equipment and storage medium

    CN115174129A