A method for evaluating the effectiveness of information systems based on blockchain technology
Patent Information
- Application Number
- CN202210315028.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-03-29
- Filing Date
- 2022-03-28
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2042-03-28
AI Technical Summary
[0002]随着信息技术的不断发展,当前各行各业的信息化建设更加迅猛,但是,当前信息化系统建设后:在测试阶段,泄密事件以及测试系统被部署到真实的生产力系统后造成不可预料的破坏事件时有发生;而在使用阶段,往往又面临UI交互不便或功能不完全符合一线使用人员的预期的尴尬境地
[0047]通过上述技术方案,本公开实现了可信的、公正的测评信息化系统并提高信息化系统在测评或使用过程中的健壮性。
Smart Images

Figure CN117155573B_ABST
Abstract
Description
Technical Field
[0001] This disclosure pertains to the field of information technology testing, and specifically relates to a method for evaluating the effectiveness of information systems based on blockchain technology. Background Technology
[0002] With the continuous development of information technology, the informatization construction of various industries is becoming more and more rapid. However, after the construction of current information systems: during the testing phase, there are frequent incidents of data leakage and unpredictable damage caused by the deployment of test systems to real productivity systems; and during the usage phase, there is often an awkward situation where the UI interaction is inconvenient or the functions do not fully meet the expectations of front-line users.
[0003] How to reliably and fairly evaluate information systems and improve their robustness during evaluation or use remains an urgent problem to be solved. Summary of the Invention
[0004] In view of this, this disclosure reveals a method for evaluating the effectiveness of an information system based on blockchain technology, comprising the following steps:
[0005] When a user performs any type of operation in the information system
[0006] S100: The client's U-shield service checks whether a blockchain U-shield has been inserted. If no blockchain U-shield is detected, it prompts the user to insert a blockchain U-shield.
[0007] in,
[0008] The client application is used by users to log in to the information system.
[0009] A blockchain U-shield, used to couple to the client, and the shield can be connected to the blockchain;
[0010] S200: Verify whether the current user's identity information matches the identity information of the legitimate owner of the blockchain U-shield. If the authentication is successful, the U-shield service will construct a transaction proposal using: the username corresponding to the user's identity information, the operation type, the operation content of the current operation, the timestamp, and the unique number of the hardware to which the client belongs.
[0011] The S300 and U-Shield services send the transaction proposal and the signature of the transaction proposal generated for the proposal to the blockchain server in the background so that the transaction proposal and its signature can be recorded in the blockchain ledger.
[0012] The S400 evaluation service reads the blockchain ledger and performs multi-dimensional statistical analysis based on username, operation type, all involved operation content, timestamp, and the unique identifier of the client's hardware to evaluate the effectiveness of the information system, including:
[0013] By utilizing the time difference between different timestamps, the average time taken by each user to perform the same type of operation can be statistically analyzed; and / or,
[0014] Statistics and analysis of frequently used operations;
[0015] Statistical analysis of the number of times each user uses the information system within a certain period of time, and the total time spent on all operations;
[0016] This will provide a basis for further improving the UI or functions of the information system.
[0017] Preferred,
[0018] In step S300, the signature of the transaction proposal generated for this transaction proposal is obtained through the following sub-steps:
[0019] S301. The U-Shield service sends the transaction proposal to the blockchain U-Shield for encryption with its private key, and then sends the encryption result to the blockchain U-Shield for signing to obtain the signature of the transaction proposal generated for that transaction proposal.
[0020] Preferred,
[0021] Following step S300, the following steps are also included:
[0022] S401, the U-Shield service writes the transaction proposal and transaction proposal signature into the storage unit of the blockchain U-Shield.
[0023] Preferred,
[0024] Following step S300, the following steps are also included:
[0025] S402. The U-Shield service re-authenticates the user's identity information to ensure that it matches the identity information of the legitimate owner of the blockchain U-Shield. If the authentication fails, the user will be prompted that the operation failed; if the authentication is successful, the user's operation on the information system will be executed.
[0026] Preferred,
[0027] The identity information includes: fingerprint information, and / or iris information, and / or on-site photograph information.
[0028] Preferred,
[0029] The shield can be a physical hardware U-shield or a software digital shield;
[0030] When it is a hardware physical U-shield, the shield includes a fingerprint module and / or an iris module and / or a camera module;
[0031] When it is a software digital shield, the digital shield includes at least one or more interfaces for interacting with systems or interfaces outside the digital shield, and the client includes a fingerprint module and / or an iris module and / or a camera module.
[0032] Preferred,
[0033] The method further includes the following steps:
[0034] S403. After successful on-chain processing, the U-Shield service deletes the transaction proposal and transaction proposal signature from the blockchain U-Shield storage unit.
[0035] Preferred,
[0036] After step S100 and before step S200, the following steps are also included:
[0037] S101. When the U-Shield service detects the insertion of a blockchain U-Shield, it first checks whether there is a transaction proposal and a transaction proposal signature in the storage unit of the blockchain U-Shield. If there is, it indicates that there is an anomaly that the transaction proposal and transaction proposal signature were not successfully uploaded to the chain. The U-Shield service adds an on-chain task in the background to re-upload the transaction proposal and transaction proposal signature to the chain.
[0038] Preferred,
[0039] Following step S100, the following steps are also included:
[0040] S101: Periodically poll the blockchain U-shield to check if the signature is cached;
[0041] S102: If so, it indicates that there is an exception where the transaction proposal and transaction proposal signature were not successfully uploaded to the blockchain. The U-Shield service will add an on-chain task in the background to re-upload the transaction proposal and transaction proposal signature to the blockchain.
[0042] Preferred,
[0043] The shield also includes:
[0044] A key generation interface is used to generate public and private keys based on the shield's unique number and the first encryption algorithm, and store them in the shield's storage unit.
[0045] When a shield is registered to the blockchain, its unique number is first checked for duplicates by the CA server. If the shield is confirmed to be valid, an ID associated with the shield is obtained based on the unique number of the shield.
[0046] The unique number of the shield can be calculated from the identity information of the legitimate owner, or it can be the unique code of a certain hardware module in the hardware entity U-shield, or it can be the verification code of the corresponding digital file of the digital shield.
[0047] Through the above technical solutions, this disclosure realizes a reliable and impartial evaluation information system and improves the robustness of the information system during the evaluation or use process. Attached Figure Description
[0048] Figure 1 This is a schematic diagram of a method disclosed in one embodiment of this disclosure;
[0049] Figure 2 This is a schematic diagram of a system disclosed in one embodiment of this disclosure. Detailed Implementation
[0050] To enable those skilled in the art to understand the technical solutions disclosed herein, the technical solutions of various embodiments will be described below in conjunction with the embodiments and related drawings. The described embodiments are some, but not all, of the embodiments disclosed herein. The terms "first," "second," etc., used in this disclosure are used to distinguish different objects, not to describe a specific order. Furthermore, "comprising" and "having," and any variations thereof, are intended to be comprehensive and non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, systems, products, or devices.
[0051] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this disclosure. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. Those skilled in the art will understand that the embodiments described herein can be combined with other embodiments.
[0052] See Figure 1 In one embodiment, this disclosure discloses a method for evaluating the effectiveness of an information system based on blockchain technology, comprising the following steps:
[0053] When a user performs any type of operation in the information system
[0054] S100: The client's U-shield service checks whether a blockchain U-shield has been inserted. If no blockchain U-shield is detected, it prompts the user to insert a blockchain U-shield.
[0055] in,
[0056] The client application is used by users to log in to the information system.
[0057] A blockchain U-shield, used to couple to the client, and the shield can be connected to the blockchain;
[0058] S200: Verify whether the current user's identity information matches the identity information of the legitimate owner of the blockchain U-shield. If the authentication is successful, the U-shield service will construct a transaction proposal using: the username corresponding to the user's identity information, the operation type, the operation content of the current operation, the timestamp, and the unique number of the hardware to which the client belongs.
[0059] The S300 and U-Shield services send the transaction proposal and the signature of the transaction proposal generated for the proposal to the blockchain server in the background so that the transaction proposal and its signature can be recorded in the blockchain ledger.
[0060] The S400 evaluation service reads the blockchain ledger and performs multi-dimensional statistical analysis based on username, operation type, all involved operation content, timestamp, and the unique identifier of the client's hardware to evaluate the effectiveness of the information system, including:
[0061] By utilizing the time difference between different timestamps, the average time taken by each user to perform the same type of operation can be statistically analyzed; and / or,
[0062] Statistics and analysis of frequently used operations;
[0063] Statistical analysis of the number of times each user uses the information system within a certain period of time, and the total time spent on all operations;
[0064] This will provide a basis for further improving the UI or functions of the information system.
[0065] It is understood that the above embodiments provide a method for evaluating the effectiveness of an information system based on blockchain technology. User operations are recorded in the blockchain to achieve secure, reliable, and traceable statistics and analysis, thereby achieving a fair and objective evaluation. Thus, this disclosure provides a reliable and fair technical solution for improving information systems, facilitating future improvements to the system's UI or functionality, and benefiting the construction of information systems across various industries. Obviously, this also benefits software system development.
[0066] It should be noted that if authentication fails, the U-Shield service will collect the current user's identity information, operation type, timestamp, and the unique number of the hardware to which the client belongs to construct a transaction proposal—this helps ensure the security of the assessment.
[0067] In one embodiment,
[0068] In step S300, the signature of the transaction proposal generated for this transaction proposal is obtained through the following sub-steps:
[0069] S301. The U-Shield service sends the transaction proposal to the blockchain U-Shield for encryption with its private key, and then sends the encryption result to the blockchain U-Shield for signing to obtain the signature of the transaction proposal generated for that transaction proposal.
[0070] In one embodiment,
[0071] Following step S300, the following steps are also included:
[0072] S401, the U-Shield service writes the transaction proposal and transaction proposal signature into the storage unit of the blockchain U-Shield.
[0073] In one embodiment,
[0074] Following step S300, the following steps are also included:
[0075] S402. The U-Shield service re-authenticates the user's identity information to ensure that it matches the identity information of the legitimate owner of the blockchain U-Shield. If the authentication fails, the user will be prompted that the operation failed; if the authentication is successful, the user's operation on the information system will be executed.
[0076] In one embodiment,
[0077] The identity information includes: fingerprint information, and / or iris information, and / or on-site photograph information.
[0078] In one embodiment,
[0079] The shield can be a physical hardware U-shield or a software digital shield;
[0080] When it is a hardware physical U-shield, the shield includes a fingerprint module and / or an iris module and / or a camera module;
[0081] When it is a software digital shield, the digital shield includes at least one or more interfaces for interacting with systems or interfaces outside the digital shield, and the client includes a fingerprint module and / or an iris module and / or a camera module.
[0082] It is understandable that, typically, a physical hardware shield can be any product with a hardware interface, such as a USB flash drive, a card-type pass with a USB interface, or a physical hardware shield with a Bluetooth or audio interface. However, it is more important to note that a software digital shield can be a digital file of various formats, and its interface is implemented using a file-reading and writing digital interface or other suitable API technology. This allows the software digital shield to interact with systems or interfaces outside the shield by accessing such digital files. Obviously, physical hardware shields generally offer higher security than software digital shields; however, this does not preclude this disclosure from employing existing digital encryption technologies, monitoring technologies, or other digital security technologies to enhance the security of the software digital shield.
[0083] In one embodiment,
[0084] The method further includes the following steps:
[0085] S403. After successful on-chain processing, the U-Shield service deletes the transaction proposal and transaction proposal signature from the blockchain U-Shield storage unit.
[0086] In one embodiment,
[0087] After step S100 and before step S200, the following steps are also included:
[0088] S101. When the U-Shield service detects the insertion of a blockchain U-Shield, it first checks whether there is a transaction proposal and a transaction proposal signature in the storage unit of the blockchain U-Shield. If there is, it indicates that there is an anomaly that the transaction proposal and transaction proposal signature were not successfully uploaded to the chain. The U-Shield service adds an on-chain task in the background to re-upload the transaction proposal and transaction proposal signature to the chain.
[0089] In one embodiment,
[0090] Following step S100, the following steps are also included:
[0091] S101: Periodically poll the blockchain U-shield to check if the signature is cached;
[0092] S102: If so, it indicates that there is an exception where the transaction proposal and transaction proposal signature were not successfully uploaded to the blockchain. The U-Shield service will add an on-chain task in the background to re-upload the transaction proposal and transaction proposal signature to the blockchain.
[0093] In another embodiment, it is performed as follows:
[0094] Users submit operations (login, modification, approval, etc.) in the information system;
[0095] The client runs on the computer. The client's U-shield service detects whether a blockchain U-shield is inserted. If no blockchain U-shield is detected, the user is prompted to insert a blockchain U-shield.
[0096] The user is prompted to authenticate the fingerprint of the blockchain U-shield owner;
[0097] If authentication fails, the U-Shield service will construct a transaction proposal using the fingerprint feature value, operation type, timestamp, and computer hardware number; if authentication succeeds, the U-Shield service will construct a transaction proposal using the username, operation type, operation content, timestamp, and computer hardware number.
[0098] The U-Shield service sends the transaction proposal to the blockchain U-Shield for encryption with a private key, then sends the encryption result to the blockchain U-Shield for signing, and the U-Shield service writes the transaction proposal and the transaction proposal signature into the blockchain U-Shield's storage.
[0099] The U-Shield service re-authenticates the user's identity information to ensure it matches the identity information of the legitimate owner of the blockchain U-Shield. If authentication fails, the user is prompted that the operation has failed; if authentication is successful, the information system executes the user's operation.
[0100] The U-Shield service sends the transaction proposal and transaction proposal signature to the blockchain server in the background.
[0101] After successful on-chain processing, the U-Shield service deletes the transaction proposal and transaction proposal signature from the blockchain U-Shield storage.
[0102] The on-chain process is as follows:
[0103] The U-Shield service calls and reads the certificate from the blockchain U-Shield storage unit;
[0104] The U-Shield service submits the transaction proposal, transaction proposal signature, and certificate to one or more endorsement nodes (Note: the number of endorsement nodes in this system is determined by the agreed endorsement strategy) to conduct simulated transactions;
[0105] After receiving a simulated transaction proposal, the endorsing node first verifies whether the certificate is a legitimate certificate certified by the system's certificate authority: it decrypts the certificate using the public key of the CA server to obtain the public key in the certificate, uses the public key to decrypt the signature of the certificate and compares it with the hash value obtained by hashing the certificate. If they are different, it returns failure; if they are the same, it performs signature verification.
[0106] The transaction proposal signature is decrypted using the public key in the certificate and compared with the hash value obtained by hashing the transaction proposal. If they do not match, the signature verification fails. If the signature verification passes, it is determined whether the current submitter (user) has permission to execute the operation.
[0107] If the certificate is not authorized, it will return failure. If it is authorized, the endorsing node will execute a simulated transaction (without updating the ledger). The endorsing node will return the transaction result, the endorsing node's signature, and the endorsement result as the proposal result to the U-shield service.
[0108] The U-Shield service verifies the signature of the endorsing node. If the signatures do not match, the user is prompted that the operation has failed. If the signature verification is successful, the proposal results returned by each endorsing node are compared to determine whether the proposal results are consistent. If the proposal results are inconsistent, the user is prompted that the operation has failed.
[0109] If the U-Shield service determines that it has received enough endorsement results from endorsement nodes (note: the endorsement strategy determines the corresponding number of standards), it means that the transaction has been correctly endorsed. Then, the U-Shield service will package the responses from each endorsement node into a transaction, sign it, and send it to the sorting node. If it determines that it has not collected enough endorsement information from endorsement nodes, the transaction will be discarded.
[0110] Furthermore, the sorting nodes sort the received transactions, then package a batch of transactions together to generate a new block, which is then sent to the accounting nodes.
[0111] After receiving a block, the ledger node will verify each transaction in the block to check its validity, including checking the format of the transaction message, the validity of the signature, and the validity of the specified endorsement policy. If all verifications pass, the block will be appended to the blockchain.
[0112] In this way, through detailed implementation methods, the blockchain is used to record transactions involving user-represented operations on the information system.
[0113] In one embodiment,
[0114] The shield also includes:
[0115] A key generation interface is used to generate public and private keys based on the shield's unique number and the first encryption algorithm, and store them in the shield's storage unit.
[0116] When a shield is registered to the blockchain, its unique number is first checked for duplicates by the CA server. If the shield is confirmed to be valid, an ID associated with the shield is obtained based on the unique number of the shield.
[0117] The unique number of the shield can be calculated from the identity information of the legitimate owner, or it can be the unique code of a certain hardware module in the hardware entity U-shield, or it can be the verification code of the corresponding digital file of the digital shield.
[0118] It is understood that if the shield is required to be coupled to the hardware of a specific client, such as a specific computer or portable device (e.g., a mobile phone or a tablet), the above embodiments can also generate public and private keys based on the unique number of the hardware and the first encryption algorithm.
[0119] In addition, the key generation interface is called by the first interface; for example, the first interface is the interface of the U-shield service.
[0120] Furthermore, if a legitimate user must specify the use of a particular shield, or must specify the use of a particular hardware associated with the aforementioned client, the above embodiments can also generate public and private keys based on the legitimate user's identity information (e.g., username, fingerprint, iris, or facial recognition) and the first encryption algorithm. It can be seen that these flexible implementation methods can all ensure uniqueness.
[0121] In another embodiment, taking the username of the legitimate owner as an example:
[0122] The key generation interface is used to be called by a first interface outside the shield, and to generate a user's public key and private key based on the username and a first algorithm and store them in the shield's storage unit.
[0123] For example, the first interface is a U-shield service interface, including interfaces provided by various services such as online office U-shield services and sensitive services; and the first algorithm can be the SM2 algorithm or other national cryptographic algorithms (such as SM3, SM4) or any other non-standard or standard algorithm, etc.; more exemplaryly, the first algorithm can be a public-private key generation algorithm supported by a certain encryption chip itself, or a non-standard or standard public-private key algorithm generated by software. If an encryption chip is used, the interface of the encryption chip can be used as the key generation interface of the shield.
[0124] When the shield is registered to the blockchain, the username is checked for duplicates by the CA server in advance. If no duplicate username is found, the username is used as the username associated with the shield. Then the key generation interface is called by the first interface.
[0125] Therefore, the blockchain-based shield is realized through the above embodiments. In this embodiment, the username can only be used as the username associated with the shield after being verified by the blockchain and the CA server. This means that the shield's usage status can be further verified through the blockchain. It can be understood that when the first interface is the corresponding interface of various Web Services, the shield can be used for various Web Services, thereby significantly improving the security of users using various Web Services.
[0126] In another embodiment,
[0127] The shield also includes a first hash value calculation unit and a first signature unit;
[0128] The first hash value calculation unit is used to calculate the first hash value based on the identity information of the legitimate owner (or other information that can ensure uniqueness as mentioned above, such as the hardware to which the client belongs, or even the check code of the digital file mentioned in other embodiments above) and the public key;
[0129] The first signature unit is used to generate a first digital signature based on the first hash value using the private key.
[0130] The above embodiment provides a way to further utilize blockchain hashing technology to implement the first digital signature on the shield, thereby making the shield a product with more blockchain characteristics.
[0131] In another embodiment,
[0132] The shield also includes a first transmitting unit;
[0133] The first sending unit sends the public key and the first digital signature to the CA server via the first interface.
[0134] It is understood that this embodiment sends relevant signatures to the CA server through a first sending unit and a first interface. For example, the first interface is the U-shield service interface. Thus, the shield connects to the CA server through its first interface, which can be an interface for various Web Services or even various applications. This means that the shield can be widely used for various services and / or applications. It should be noted that the CA server can be a server independent of the blockchain, or it can be a blockchain-based CA server.
[0135] In another embodiment, taking the username of the legitimate owner as an example:
[0136] The storage unit of the shield is also used to store the following certificates:
[0137] After the first interface verifies the first digital signature using the public key of the blockchain's CA server, the storage unit stores the username and the certificate generated by the blockchain's CA server.
[0138] This embodiment reveals how the blockchain-based shield described above, as a new type of shield, generates and stores its certificates.
[0139] In another embodiment,
[0140] The shield includes a national cryptographic security chip module, and the national cryptographic security chip includes key generation function, and / or encryption function, and / or signature function.
[0141] It is understandable that when using national cryptographic security chip modules, the aforementioned blockchain-based shield can be implemented more quickly through various existing national cryptographic security chip modules with higher integration.
[0142] In another embodiment,
[0143] The shield also includes a second transmitting unit;
[0144] When the shield is coupled to an external data processing system, at a certain time or time period, the second sending unit sends at least the username stored in the shield, the user's operation on the data processing system, and time information (e.g., timestamp) to the blockchain via a first interface (e.g., the U-shield service mentioned above).
[0145] This embodiment reveals how the shield interacts with the blockchain through a second sending unit when used for secure interaction in a data processing system, for example, how it uploads relevant information to the blockchain.
[0146] In another embodiment,
[0147] The second sending unit also sends the user's operations on the shield to the blockchain above.
[0148] It is understood that this embodiment shows that the shield can record user operations on the shield on the blockchain. For example, assuming the shield includes an OK confirmation button, when the user presses the OK button at a certain moment, this operation on the shield itself is also sent to the blockchain.
[0149] In another embodiment,
[0150] The shield also includes a second hash value calculation unit and a second signature unit;
[0151] The second hash value calculation unit is at least used to calculate the second hash value based on the current user's identity information, the operation of the data processing system, time information, and public key;
[0152] The second signature unit is used to generate a second digital signature based on the second hash value according to the corresponding private key;
[0153] The second sending unit also sends the second digital signature to the blockchain above.
[0154] The above embodiment provides a way to further utilize blockchain hashing technology to implement a second digital signature on the shield, thereby making the shield a product with more blockchain characteristics and realizing the on-chaining of the second digital signature.
[0155] Furthermore, in another embodiment,
[0156] When the blockchain-based shield described in this disclosure is implemented as a digital shield, in addition to the content related to digital shields mentioned above, the data processing capability of the digital shield can utilize the processing capability of the CPU or other processors, sensors (e.g., cameras, fingerprint modules, iris modules, etc.) of the device, equipment, computer, data processing system, or cloud server where the digital shield is located, or the processing capability of the external system that calls the digital shield. The storage capability required by the digital shield can utilize the storage capability of the device, equipment, computer, data processing system, or cloud server where the digital shield is located, or the storage capability of the external system that calls the digital shield. As for the interaction interface required by the digital shield, it can be implemented by I / O reading and writing of digital files. If it is necessary to display such an interaction process, it can be implemented by any display device that can receive the necessary information flow or data flow (e.g., mutual operation information) generated during the interaction between the digital shield and the external system (or external interface). When it is not necessary to display, the information flow or data flow generated during the interaction can also be saved as a file of a certain format (e.g., operation log file).
[0157] Through the blockchain-based shields disclosed in the above embodiments, particularly how to implement a shield that can be invoked by an external system or external interface, this disclosure significantly improves the security of digital or physical shields during use, and can be used for recording and evaluating user operations in various information systems.
[0158] See Figure 2 In another embodiment, this disclosure further discloses an evaluation system that performs the evaluation method described above, thereby being used to evaluate the effectiveness of an information system based on blockchain technology. The evaluation system includes:
[0159] The PC, as a client, allows users to log in to an information system via a browser; and,
[0160] The aforementioned blockchain USB key, coupled to the client, uses the USB key service as an intermediary to coordinate communication between the blockchain USB key and the browser; and,
[0161] Monitoring platform;
[0162] in,
[0163] A browser can access different applications, such as applications A, B, and C, and the databases associated with those applications; obviously, these different applications are an example of an information system.
[0164] A blockchain server includes a blockchain service and its database; it is understood that the database of a blockchain server includes the corresponding data from the blockchain ledger.
[0165] The blockchain server communicates with the monitoring service.
[0166] The blockchain server and monitoring service constitute the core of the monitoring platform.
[0167] In this embodiment, a fair, objective, credible, and traceable evaluation system is built around the monitoring platform, blockchain U-shield, and client to evaluate the construction effect of the information system and provide a basis for UI or functional improvement of the information system.
[0168] For example, a blockchain U-shield is preferred as the hardware physical shield of the shield;
[0169] Preferably, the system further includes:
[0170] Blockchain service module;
[0171] U-Shield service module.
[0172] Preferred,
[0173] The blockchain service module includes CA authentication service, submission node, endorsement node, sorting node, and accounting node.
[0174] Preferred,
[0175] The U-shield service module is used for:
[0176] Provide registration services for blockchain USB tokens;
[0177] When performing important operations on the client, the current operation, username, and timestamp are sent to the blockchain U-shield for encryption to obtain ciphertext. Then, the hash value of the ciphertext is calculated, and the hash value is sent to the blockchain U-shield for signing. Finally, the ciphertext, signature, and blockchain U-shield certificate are sent to the endorsing node to initiate a transaction proposal.
[0178] Preferred,
[0179] The CA authentication service provides registration services for blockchain U-shields and returns a trusted certificate for the blockchain; it also assists endorsing nodes in verifying whether the blockchain U-shield is authorized to be uploaded to the blockchain.
[0180] Preferred,
[0181] The endorsing node receives the transaction proposal initiated by the U-Shield service module, decrypts the certificate using the X509 parsing algorithm to obtain the client's public key, and then uses the client's public key to verify the client's signature and permissions. After successful verification, it performs a simulated transaction and returns the simulated transaction result from the endorsing node to the U-Shield service module.
[0182] Preferred,
[0183] Once the U-Shield service module receives a certain threshold of returned information from the endorsement nodes, it packages the transaction proposal, the simulation results of the endorsement nodes, and the endorsement information and sends them to the sorting node.
[0184] Preferred,
[0185] The sorting service sorts the information sent by the U-shield service module, creates transaction blocks, and broadcasts them to the accounting nodes.
[0186] After receiving a broadcast transaction block, the ledger node verifies whether it meets the endorsement policy. If the verification is successful, the ledger is updated according to the transaction block.
[0187] In another embodiment,
[0188] The method disclosed herein also includes the following steps:
[0189] All of the user's current operations are backed up on the blockchain, including the operation type and operation content.
[0190] More preferably, backups can be made by recording video or taking screenshots.
[0191] More preferably, a snapshot or other form of backup is taken of the object to be operated on before the operation, and a snapshot or other form of backup is taken of the object to be operated on after the operation.
[0192] More preferably, the above backups are uploaded to the blockchain.
[0193] In this way, even if the information system is damaged, it can be restored as quickly as possible.
[0194] Those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions, modules, and units involved are not necessarily essential to the present invention.
[0195] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0196] In the several embodiments provided in this disclosure, it should be understood that the disclosed shield can be implemented as a corresponding functional unit, processor, or even a system, wherein the various parts of the system can be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, each functional unit can be integrated into one processing unit, or each unit can exist independently, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which can be a smartphone, personal digital assistant, wearable device, laptop, or tablet) to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned storage media include: USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks or optical disks, and other media that can store program code, and are not limited to different interfaces or transmission methods such as USB, Bluetooth or audio.
[0197] The above-described embodiments are only used to illustrate the technical solutions of this disclosure, and are not intended to limit it. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this disclosure.
Claims
1. A method for evaluating the effectiveness of an information system based on blockchain technology, comprising the following steps: When a user submits an operation of a certain type in the information system S100: The client's U-shield service checks whether a blockchain U-shield has been inserted. If no blockchain U-shield is detected, it prompts the user to insert a blockchain U-shield. S200: Verify whether the current user's identity information matches the identity information of the legitimate owner of the blockchain U-shield. If the authentication is successful, the U-shield service will construct a transaction proposal using: the username corresponding to the user's identity information, the operation type, the operation content of the current operation, the timestamp, and the unique number of the hardware to which the client belongs. The S300 and U-Shield services send the transaction proposal and the signature of the transaction proposal generated for that proposal to the blockchain server in the background. The S400 evaluation service reads the blockchain ledger and performs multi-dimensional statistical analysis based on username, operation type, all involved operation content, timestamp, and the unique identifier of the client's hardware to evaluate the effectiveness of the information system, including: By utilizing the time difference between different timestamps, the average time taken by each user to perform the same type of operation is statistically analyzed. and, Statistics and analysis of frequently used operations; Statistical analysis of the number of times each user uses the information system within a certain period of time, and the total time spent on all operations; This will provide a basis for further improving the UI or functions of the information system.
2. The method as described in claim 1, wherein, In step S300, the signature of the transaction proposal generated for this transaction proposal is obtained through the following sub-steps: S301. The U-Shield service sends the transaction proposal to the blockchain U-Shield for encryption with its private key, and then sends the encryption result to the blockchain U-Shield for signing to obtain the signature of the transaction proposal generated for that transaction proposal.
3. The method as described in claim 1, wherein, Following step S300, the following steps are also included: S401, the U-Shield service writes the transaction proposal and transaction proposal signature into the storage unit of the blockchain U-Shield.
4. The method of claim 1, wherein, Following step S300, the following steps are also included: S402. The U-Shield service re-authenticates the user's identity information to ensure that it matches the identity information of the legitimate owner of the blockchain U-Shield. If the authentication fails, the user will be prompted that the operation has failed. If authentication is successful, the user's operations on the information system will be executed.
5. The method of claim 1, wherein, The identity information includes: fingerprint information, and / or iris information, and / or on-site photograph information.
Citation Information
Patent Citations
Personal mobile block chain operating system based on USB key
CN110795765A
Electric power Internet of Things service credibility evaluation method and system based on smart contract
CN111581224A