A method for processing transaction traces
User identity authentication and operation behavior encryption are carried out through asymmetric encryption technology and multi-ring signature chain encryption algorithm, and data consistency is achieved in a distributed environment with a timing consensus algorithm, solving the problem of data tampering in transaction processing and log management in the existing technology, and achieving high security and traceability.
Patent Information
- Application Number
- CN202411301136.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-18
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-09-18
AI Technical Summary
The prior art is difficult to effectively prevent data tampering in transaction processing and log management, ensuring the security and trustworthiness of the system, especially in a multi-user environment.
User identity authentication is carried out through asymmetric encryption technology, and combined with multi-ring signature chain encryption algorithm, the user's operation behavior is encrypted and verified to ensure the legality and undeniability of operation records. At the same time, a time-sequence consensus algorithm is used to realize consistent data storage and processing in a distributed environment to prevent log data from being tampered with.
It realizes the advantages of high security, data immutability and operational behavior traceability, significantly improves the security and credibility of the system, and is especially suitable for security transaction management in multi-user environments.
Smart Images

Figure CN119203254B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of information security and blockchain technology, and in particular to a method for processing transaction trajectories. Background Art
[0002] In modern information systems and distributed networks, transaction processing and log management are key links to ensure system security and data integrity. Transaction processing involves interactive operations of multiple users, especially in the fields of finance, e-commerce, supply chain management, etc., where accurate recording and traceability of transactions are essential. Log management is an important means to monitor system operations and track user behavior. However, existing transaction processing and log management technologies still face many challenges and shortcomings, making it difficult to effectively prevent data tampering and ensure system security and credibility.
[0003] The first is that traditional log management systems often rely on centralized databases or file systems to store and manage operation records. This centralized structure makes log data an easy target for internal administrators or external attackers. Even if the log system takes certain security measures, administrators with high authority may still bypass these measures and modify, delete or forge log data, thereby covering up traces of malicious operations. In this case, the log system loses its core audit and traceability functions, posing a huge hidden danger to the security of the system.
[0004] The second is that existing transaction processing systems usually lack effective anti-tampering mechanisms in a multi-user operating environment. The integrity and immutability of transaction data are difficult to guarantee, especially in scenarios involving multi-party collaboration and data sharing, where each step of the transaction may be threatened by tampering. For example, in financial transactions, any tampering of transaction data by any participant may cause the failure of the entire transaction chain and even cause serious economic losses. Traditional transaction processing methods lack strict verification and chain management of each operation step, making it difficult to ensure the traceability of all operations and the immutability of data.
[0005] Third, with the widespread application of distributed systems and blockchain technology, although blockchain technology has solved the problem of data immutability to a certain extent, the existing blockchain system still has limitations in performance, consensus mechanism and data privacy protection. The consensus algorithms adopted by most blockchain systems, such as proof of work or proof of stake, have performance bottlenecks in ensuring data consistency and are difficult to meet the needs of high-concurrency transaction processing. At the same time, all operation records in the blockchain are public, which is not suitable for some application scenarios that require high privacy and is easy to expose sensitive information of user operation behavior.
[0006] Therefore, how to provide a method for processing transaction traces is an urgent problem that those skilled in the art need to solve. Summary of the invention
[0007] One purpose of the present invention is to propose a method for processing transaction traces. By adopting asymmetric encryption technology for user identity authentication and combining a multi-ring signature chain encryption algorithm, the user's operation behavior is encrypted and verified, ensuring the legitimacy and non-repudiation of the operation record. In addition, the present invention also realizes consistent storage and processing of data in a distributed environment through a time-consistent consensus algorithm to prevent log data from being tampered with. This method has the advantages of high security, data immutability and traceability of operation behavior, and is particularly suitable for secure transaction management in a multi-user environment.
[0008] A method for processing a transaction trace according to an embodiment of the present invention includes the following steps:
[0009] S1. Authenticate the user by obtaining the user's public key and verifying the user's private key signature using asymmetric encryption technology;
[0010] S2. After the user identity authentication is passed, the user's operation behavior is recorded, and each operation behavior is generated into an operation record in the order in which it occurs, and the operation record includes the hash value of the previous operation record;
[0011] S3. Confirm the operation record with a signature, where the signature is generated using the user's private key and verified using the user's public key;
[0012] S4. Use a multi-ring signature chain encryption algorithm to store the signed and confirmed operation records into a chain data structure to form an irreversible operation chain.
[0013] S5. During the transaction processing, the application and approval operations of each transaction are recorded, and all the operations involved are formed into a transaction chain in the order in which they occur. The transaction chain includes the signature of each operation and the hash value of the previous operation record;
[0014] S6. In the process of forming the transaction chain, a time-consistent consensus algorithm is adopted. By introducing a dual verification mechanism of timestamp and geographic location data, each node in the distributed ledger can reach a consensus in different geographic locations and time environments;
[0015] S7. Store the operation chain and transaction chain in a distributed ledger;
[0016] S8. When any attempt to tamper with operation records or transaction data occurs, a multi-dimensional behavior analysis detection algorithm is used to build a multi-dimensional map of operation behavior to conduct all-round anomaly detection, automatically identify and prevent tampering attempts.
[0017] Optionally, the S4 specifically includes:
[0018] S41, performing hash processing on each operation record to generate a hash value uniquely corresponding to the operation record;
[0019] S42, connecting the hash value of the current operation record with the hash value of the previous operation record to generate intermediate data of the operation chain;
[0020] S43, encrypt the generated intermediate data using a multi-ring signature chain encryption algorithm, by selecting a set of public keys, including the public key of the current operating user and the public keys of other system users, and encrypting the intermediate data with a ring signature in combination with the private key of the current operating user, so that the encryption result can ensure the legitimacy of the operation and the identity of the specific signer cannot be reversely deduced;
[0021] S44. The data encrypted by the ring signature and the newly generated hash value are stored in the nodes of the chain data structure. Each node is linked to each other through the hash value of the previous node, and finally an operation chain is formed.
[0022] Optionally, the S43 specifically includes:
[0023] S431. During the encryption process, a set of m public keys is selected, P = {P 1 ,P 2 ,...,P m}, where P 1 is the public key of the current operating user, P 2 ,...,P m Build a set of public keys for the ring signature for the public keys of other users in the system, and use the private key K of the current operating user i As a unique key for signing;
[0024] S432, the intermediate data C of the operation chain i Processing, multi-layer hash mapping of intermediate data, generating a multi-dimensional hash matrix H(C i ), where each dimension of the matrix corresponds to an independent hash function output, the hash matrix H(C i ) is generated as:
[0025] H(C i )=[h 1 (C i ) 2 (C i ) ...h d (C i )];
[0026] Among them, hj (C i ) indicates that for the intermediate data C i The jth independent hash function output of , d is the number of hash functions;
[0027] S433, using the private key K of the current operating user i For the generated hash matrix H(C i ) performs multi-ring signature processing, and generates signatures through the function MultiSign(H(C i ),K i ) Generate a multi-ring signature S i ', multi-ring signature S i 'Not only does it include the irreversibility of the ring signature, but it also optimizes the encryption protection of the signature information by multi-layer hash mapping, where K i Indicates the private key of the current operating user, H(C i ) represents the intermediate data C i Multi-dimensional hash matrix of;
[0028] S434. When generating a multi-ring signature, the identity of the signer in P remains irreversible through the obfuscation effect of the hash functions of each dimension. Even if the attacker obtains the entire public key set and the hash matrix, the specific signer cannot be determined;
[0029] S435, generate the multi-ring signature S i 'With the original intermediate data C i Combined to form the final encrypted data packet E i , and stored in the chain node.
[0030] Optionally, the S5 specifically includes:
[0031] S51. During the transaction processing, each transaction application operation first generates an initial transaction record T 0 , containing basic information of the transaction I 0 and the applicant's signature a , where the applicant's signature S a Through its private key K a Basic information about the transaction 0 Perform signature processing;
[0032] S52, generate initial transaction record T 0 After that, the initial transaction record T 0 As the starting point of the transaction chain, the corresponding transaction record T is generated at each approval stage. i , where T i Contains the signature S of the current approval operation i and the hash matrix H(Ti-1 );
[0033] S53, the hash matrix H(T i-1 ) and the current transaction record T i Fusion is performed to generate encrypted transaction chain intermediate data C t The specific process includes H(T i-1 )’s hash value h for each dimension j (T i-1 ) performs nonlinear mapping and combines the data recorded in the current transaction with T i Generate a multi-layer nested encryption structure:
[0034]
[0035] in, Represents the hash value h j (T i-1) With the current transaction data T i The nonlinear mapping function between , d is the number of dimensions of the hash matrix, Encrypt is the overall encryption function, which is used to generate the encrypted intermediate data C t ;
[0036] S54, generate the transaction chain intermediate data C t Apply the multi-dimensional hash chain encryption algorithm based on ring signature to generate encrypted transaction chain data E t Stored in a distributed ledger;
[0037] S55. After the entire transaction processing process is completed, the final transaction record T is generated. n , transaction record T n The multidimensional signature matrix S containing all participants final And the complete transaction data chain after multi-layer encryption:
[0038]
[0039] Among them, ∑ represents the accumulation process of transaction records, {·} Encrypt Represents the overall encryption process of the chain, S final A matrix representing the combination of signatures of all participants, used to ultimately verify the integrity and legitimacy of the entire transaction chain.
[0040] Optionally, the S6 specifically includes:
[0041] S61. During the generation of the transaction chain, time synchronization is performed on all nodes participating in the transaction to keep the clocks of all nodes consistent. The time synchronization is based on the improved distributed time protocol T sync , so that the timestamp T of each nodei All are synchronized within the allowable error range∈;
[0042] S62. Before reaching consensus, dynamically adjust the consensus algorithm parameter set P according to the current system load and network conditions. cons , where P cons Including consensus round R, node selection strategy N sel and voting weight W v , and according to the system load condition L through machine learning model sys Calculate the optimal parameter set;
[0043] S63. Based on the time-series consensus algorithm, select a node set N from the entire network. cons Participating in consensus, the node set N cons The selection criteria include the geographical location of the node G i 、Current system load L i And the time synchronization result T i ,By combining these parameters, the geographical distribution and load balancing of the selected nodes can achieve the desired goals;
[0044] S64. In the node set N cons The consensus operation is performed in the process, which is based on the time-series consensus algorithm and converts the final record T of the transaction chain into n With node set N cons and parameter set P cons Verify and generate consensus result C res , the consensus results maintain the consistency of time and geographical location at the same time, achieving the global validity of the consensus;
[0045] S65. The final consensus result C res Write it into the distributed ledger and send the signature S of the consensus node cons Stored together with the consensus result.
[0046] Optionally, the S63 specifically includes:
[0047] S631, in the consensus node set N cons When selecting, first perform a geographic location G on all available nodes. i Classification, calculate the geographical distribution distance D between nodes ij , the selected node set N cons Should cover multiple geographical areas, with a distribution distance D ij Should meet D ij ≥D min , where D min is the preset minimum geographical distribution distance;
[0048] S632: Current system load L of all available nodes i The load evaluation is based on the computing power of the node, the number of current tasks, and the network bandwidth. Nodes with lower load are selected to join the set N first. cons , node load L i Should satisfy L i ≤L max , where L max is the maximum allowed system load;
[0049] S633, combined with the time synchronization result T i , preferably the time error ΔT i For nodes within the allowable range, the time error ΔT i Should satisfy ΔT i ≤∈, where ∈ is the maximum allowed time error;
[0050] S634, Geographical distribution i 、System load L i Synchronize with time T i For multi-dimensional fusion, a nonlinear fusion function Ω(G i ,L i ,T i ) to calculate the comprehensive score of the node:
[0051]
[0052] Among them, λ 1 is the geographical distribution weight parameter, controlling the geographical location G i Impact on the comprehensive score, λ 2 is the load weight parameter, controlling the load L of the control system i Impact on the comprehensive score, λ 3 is the time synchronization weight parameter, controlling the time error ΔT i Impact on the comprehensive score, G i represents the geographical location of the node, L i represents the system load of the node, ΔT i Indicates the time synchronization error of the node;
[0053] S635, the comprehensive score Ω(G i ,L i ,T i ) The highest node is determined as the consensus node set N cons , and submit it to the distributed system for consensus operation.
[0054] Optionally, the S8 specifically includes:
[0055] S81. In the transaction chain, a multi-dimensional behavior analysis detection algorithm is used for each operation record and transaction data, and a multi-dimensional behavior map M (A i ), where A i Represents the operation behavior in the system. The behavior graph includes the timestamp T i 、Geographical location i , operating frequency F i and data interaction mode P i Dimension;
[0056] S82. For each operation behavior A i In the graph M(A i ) to model each dimension in the model and generate a multi-dimensional behavior feature vector V i , generated by a multidimensional nonlinear transformation function Ψ, capturing the complex relationships between different dimensions;
[0057] S83, perform anomaly detection on each node in the operation chain, based on the current behavior feature vector V i and historical behavior patterns V hist The nonlinear difference between them is compared to calculate the anomaly score S i , the anomaly score is obtained by adaptive weight ω k and the nonlinear adjustment parameter α k To capture abnormal behavior in a specific dimension, combined with the time-sensitive factor θ k Impact of dynamically adjusting ratings:
[0058]
[0059] Among them, V i,k V is the current operation behavior i The eigenvalue in the kth dimension, V hist,k is the reference value in the kth dimension in the historical behavior pattern, ω k is the adaptive weight, which is used to dynamically adjust the weight of each dimension in the anomaly score, α k is a nonlinear adjustment parameter used to control the sensitivity of the difference between the current operation behavior and the historical pattern, λ k is the coefficient controlling the time decay, reflecting the influence of historical data on the current anomaly score, θ k is a time-sensitive factor that controls the weight adjustment of the operation behavior within a specific time window. t is the current timestamp and is used to dynamically adjust the impact of historical data in the score.
[0060] S84, when the abnormal score S i If the dynamic threshold θ is exceeded, the tampering detection mechanism is triggered and the operation record is marked as suspicious, where the dynamic threshold θ is adjusted based on the real-time system status and historical abnormal data:
[0061] If S i >θ(V hist ), then flag as suspicious;
[0062] Among them, θ(V hist ) is a threshold that is automatically adjusted based on historical behavior data;
[0063] S85. Conduct a detailed audit of suspicious operation records, and use the multi-dimensional graph M(A i ) and combined with the system historical data H(A) to further verify the possibility of tampering, and finally generate the audit conclusion C audit and store it in the system log.
[0064] Optionally, the S82 specifically includes:
[0065] S821, generating a multi-dimensional behavior feature vector V i Before, for timestamp T i 、Geographical location i , operating frequency F i and data interaction mode P i Normalization is performed and an adaptive transformation function Φ is introduced. This function automatically adjusts the normalization parameters according to the current data distribution. The formula is expressed as:
[0066]
[0067] Among them, μ(·) and σ(·) represent the mean and standard deviation of the data in this dimension, respectively, and Φ T , Φ G , Φ F and Φ P It is an adaptive transformation function, which is used to dynamically adjust the normalization result according to the data distribution and capture the nonlinear characteristics of the data;
[0068] S822, input the preprocessed data of each dimension into the multidimensional nonlinear conversion function Ψ to generate a comprehensive feature vector V i , the function Ψ is a piecewise combination of multiple nonlinear sub-functions ψ j Implement and use asymmetric weighting strategy to deal with the unevenness of features in each dimension:
[0069]
[0070] Among them, ψ j (φ j (G' i )) is a nonlinear mapping function used to transform the geographic location G' i Mapped to a specific range to handle geographical distribution characteristics, βj (T' i ) is based on the time dimension T' i The adaptive weight function dynamically adjusts the weight within a specific time range, γ j (F' i ) is the operating frequency dimension F' i Dynamic adjustment factor, γ j It will be dynamically adjusted according to the change of operating frequency to improve the system's sensitivity to high-frequency operations. δ is a parameter for adjusting the nonlinear transformation curve to control the influence of the interaction mode in the feature vector.
[0071] S823, generating a comprehensive feature vector V i In the process, the mapping function φ is dynamically adjusted according to the system context perception mechanism. j and weight β j Parameters to adapt to current environmental changes and operating characteristics:
[0072]
[0073] Among them, γ and δ are parameters for adjusting the nonlinear mapping curve, κ is the context sensitive factor, and C j is the responsiveness of the current sub-function, reflecting the importance of the current dimension data in a specific environment;
[0074] S824, the final generated comprehensive feature vector V i Output and record.
[0075] The beneficial effects of the present invention are:
[0076] (1) The present invention uses asymmetric encryption technology to perform user identity authentication and combines it with a multi-ring signature chain encryption algorithm to ensure the legitimacy and non-repudiation of operation records. Compared with traditional log management systems, the present invention can effectively prevent internal administrators or external attackers from tampering with log data, significantly improving data security and system credibility.
[0077] (2) By storing operation records in a chain data structure and using a time-consistent consensus algorithm in the transaction processing process, the present invention ensures the consistency and security of data in different geographical locations and time environments. Compared with the traditional centralized transaction processing system, the present invention can better achieve the traceability of operation behaviors and the immutability of transaction data in a multi-user environment, thereby improving the transparency and reliability of transaction processing.
[0078] (3) The transaction trace processing method designed by the present invention forms a continuous and irreversible operation chain in the process of recording and managing user operation behaviors. This chain design ensures that any tampering in any link will be discovered in time, thereby ensuring the data integrity of the entire system and the traceability of operation behaviors, and effectively preventing the concealment of malicious operations and the difficulty in tracing erroneous operations. BRIEF DESCRIPTION OF THE DRAWINGS
[0079] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0080] Figure 1 A flowchart of a transaction trace processing method proposed by the present invention;
[0081] Figure 2 This is a flow chart of signature confirmation and encrypted storage in a transaction trace processing method proposed by the present invention. DETAILED DESCRIPTION
[0082] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, which only illustrate the basic structure of the present invention in a schematic manner, and therefore only show the components related to the present invention.
[0083] refer to Figure 1-2 , a transaction trace processing method, comprising the following steps:
[0084] S1. Authenticate the user by obtaining the user's public key and verifying the user's private key signature using asymmetric encryption technology;
[0085] S2. After the user identity authentication is passed, the user's operation behavior is recorded, and each operation behavior is generated into an operation record in the order in which it occurs, and the operation record includes the hash value of the previous operation record;
[0086] S3. Confirm the operation record with a signature, where the signature is generated using the user's private key and verified using the user's public key;
[0087] S4. Use a multi-ring signature chain encryption algorithm to store the signed and confirmed operation records into a chain data structure to form an irreversible operation chain.
[0088] S5. During the transaction processing, the application and approval operations of each transaction are recorded, and all the operations involved are formed into a transaction chain in the order in which they occur. The transaction chain includes the signature of each operation and the hash value of the previous operation record;
[0089] S6. In the process of forming the transaction chain, a time-consistent consensus algorithm is adopted. By introducing a dual verification mechanism of timestamp and geographic location data, each node in the distributed ledger can reach a consensus in different geographic locations and time environments;
[0090] S7. Store the operation chain and transaction chain in a distributed ledger;
[0091] S8. When any attempt to tamper with operation records or transaction data occurs, a multi-dimensional behavior analysis detection algorithm is used to build a multi-dimensional map of operation behavior to conduct all-round anomaly detection, automatically identify and prevent tampering attempts.
[0092] In this implementation, S4 specifically includes:
[0093] S41, performing hash processing on each operation record to generate a hash value uniquely corresponding to the operation record;
[0094] S42, connecting the hash value of the current operation record with the hash value of the previous operation record to generate intermediate data of the operation chain;
[0095] S43, encrypt the generated intermediate data using a multi-ring signature chain encryption algorithm, by selecting a set of public keys, including the public key of the current operating user and the public keys of other system users, and encrypting the intermediate data with a ring signature in combination with the private key of the current operating user, so that the encryption result can ensure the legitimacy of the operation and the identity of the specific signer cannot be reversely deduced;
[0096] S44. The data encrypted by the ring signature and the newly generated hash value are stored in the nodes of the chain data structure. Each node is linked to each other through the hash value of the previous node, and finally an operation chain is formed.
[0097] In this implementation manner, the S43 specifically includes:
[0098] S431. During the encryption process, a set of m public keys is selected, P = {P 1 ,P 2 ,...,P m}, where P 1 is the public key of the current operating user, P 2 ,...,P m Build a set of public keys for the ring signature for the public keys of other users in the system, and use the private key K of the current operating user i As a unique key for signing;
[0099] S432, the intermediate data C of the operation chain i Processing, multi-layer hash mapping of intermediate data, generating a multi-dimensional hash matrix H(Ci ), where each dimension of the matrix corresponds to an independent hash function output, the hash matrix H(C i ) is generated as:
[0100] H(C i )=[h 1 (C i ) 2 (C i ) ... h d (C i )];
[0101] Among them, h j (C i ) indicates that for the intermediate data C i The jth independent hash function output of , d is the number of hash functions;
[0102] S433, using the private key K of the current operating user i For the generated hash matrix H(C i ) performs multi-ring signature processing, and generates signatures through the function MultiSign(H(C i ),K i ) Generate a multi-ring signature S i ', multi-ring signature S i 'Not only does it include the irreversibility of the ring signature, but it also optimizes the encryption protection of the signature information by multi-layer hash mapping, where K i Indicates the private key of the current operating user, H(C i ) represents the intermediate data C i Multi-dimensional hash matrix;
[0103] S434. When generating a multi-ring signature, the identity of the signer in P remains irreversible through the obfuscation effect of the hash functions of each dimension. Even if the attacker obtains the entire public key set and the hash matrix, the specific signer cannot be determined;
[0104] S435, generate the multi-ring signature S i 'With the original intermediate data C i Combined to form the final encrypted data packet E i , and stored in the chain node.
[0105] In this implementation manner, S5 specifically includes:
[0106] S51. During the transaction processing, each transaction application operation first generates an initial transaction record T 0 , containing basic information of the transaction I 0 and the applicant's signature a , where the applicant's signature Sa Through its private key K a Basic information about the transaction 0 Perform signature processing;
[0107] S52, generate initial transaction record T 0 After that, the initial transaction record T 0 As the starting point of the transaction chain, the corresponding transaction record T is generated at each approval stage. i , where T i Contains the signature S of the current approval operation i and the hash matrix H(T i-1 );
[0108] S53, the hash matrix H(T i-1 ) and the current transaction record T i Fusion is performed to generate encrypted transaction chain intermediate data C t The specific process includes H(T i-1 )’s hash value h for each dimension j (T i-1 ) performs nonlinear mapping and combines the data recorded in the current transaction with T i Generate a multi-layer nested encryption structure:
[0109]
[0110] in, Represents the hash value h j (T i-1 ) and the current transaction data T i The nonlinear mapping function between , d is the number of dimensions of the hash matrix, Encrypt is the overall encryption function, which is used to generate the encrypted intermediate data C t ;
[0111] S54, generate the transaction chain intermediate data C t Apply the multi-dimensional hash chain encryption algorithm based on ring signature to generate encrypted transaction chain data E t Stored in a distributed ledger;
[0112] S55. After the entire transaction processing process is completed, the final transaction record T is generated. n , transaction record T n The multidimensional signature matrix S containing all participants final And the complete transaction data chain after multi-layer encryption:
[0113]
[0114] Among them, ∑ represents the accumulation process of transaction records, {·} Encrypt Represents the overall encryption process of the chain, S final A matrix representing the combination of signatures of all participants, used to ultimately verify the integrity and legitimacy of the entire transaction chain.
[0115] In this implementation manner, S6 specifically includes:
[0116] S61. During the generation of the transaction chain, time synchronization is performed on all nodes participating in the transaction to keep the clocks of all nodes consistent. The time synchronization is based on the improved distributed time protocol T sync , so that the timestamp of each node is T i All are synchronized within the allowable error range∈;
[0117] S62. Before reaching consensus, dynamically adjust the consensus algorithm parameter set P according to the current system load and network conditions. cons , where P cons Including consensus round R, node selection strategy N sel and voting weight W v , and according to the system load condition L through machine learning model sys Calculate the optimal parameter set;
[0118] S63. Based on the time-series consensus algorithm, select a node set N from the entire network. cons Participating in consensus, the node set N cons The selection criteria include the geographical location of the node G i 、Current system load L i And the time synchronization result T i ,By combining these parameters, the geographical distribution and load balancing of the selected nodes can achieve the desired goals;
[0119] S64. In the node set N cons The consensus operation is performed in the process, which is based on the time-series consensus algorithm and converts the final record T of the transaction chain into n With node set N cons and parameter set P cons Verify and generate consensus result C res , the consensus results maintain the consistency of time and geographical location at the same time, achieving the global validity of the consensus;
[0120] S65. The final consensus result C res Write it into the distributed ledger and send the signature S of the consensus node cons Stored together with the consensus result.
[0121] In this implementation manner, the S63 specifically includes:
[0122] S631, in the consensus node set N cons When selecting, first perform a geographic location G on all available nodes. i Classification, calculate the geographical distribution distance D between nodes ij , the selected node set N cons Should cover multiple geographical areas, with a distribution distance D ij Should meet D ij ≥D min , where D min is the preset minimum geographical distribution distance;
[0123] S632: Current system load L of all available nodes i The load evaluation is based on the computing power of the node, the number of current tasks, and the network bandwidth. Nodes with lower load are selected to join the set N first. cons , node load L i Should satisfy L i ≤L max , where L max is the maximum allowed system load;
[0124] S633, combined with the time synchronization result T i , preferably the time error ΔT i For nodes within the allowable range, the time error ΔT i Should satisfy ΔT i ≤∈, where ∈ is the maximum allowed time error;
[0125] S634, Geographical distribution i 、System load L i Synchronize with time T i For multi-dimensional fusion, a nonlinear fusion function Ω(G i ,L i ,T i ) to calculate the comprehensive score of the node:
[0126]
[0127] Among them, λ 1 is the geographical distribution weight parameter, controlling the geographical location G i Impact on the comprehensive score, λ 2 is the load weight parameter, controlling the load L of the control system i Impact on the comprehensive score, λ 3 is the time synchronization weight parameter, controlling the time error ΔT i Impact on the comprehensive score, G i represents the geographical location of the node, L irepresents the system load of the node, ΔT i Indicates the time synchronization error of the node;
[0128] S635, the comprehensive score Ω(G i ,L i ,T i ) The highest node is determined as the consensus node set N cons , and submit it to the distributed system for consensus operation.
[0129] In this implementation manner, S8 specifically includes:
[0130] S81. In the transaction chain, a multi-dimensional behavior analysis detection algorithm is used for each operation record and transaction data, and a multi-dimensional behavior map M (A i ), where A i Represents the operation behavior in the system. The behavior graph includes the timestamp T i 、Geographical location i , operating frequency F i and data interaction mode P i Dimension;
[0131] S82. For each operation behavior A i In the graph M(A i ) to model each dimension in the model and generate a multi-dimensional behavior feature vector V i , generated by a multidimensional nonlinear transformation function Ψ, capturing the complex relationships between different dimensions;
[0132] S83, perform anomaly detection on each node in the operation chain, based on the current behavior feature vector V i and historical behavior patterns V hist The nonlinear difference between them is compared to calculate the anomaly score S i , the anomaly score is obtained by adaptive weight ω k and the nonlinear adjustment parameter α k To capture abnormal behavior in a specific dimension, combined with the time-sensitive factor θ k Impact of dynamically adjusting ratings:
[0133]
[0134] Among them, V i,k V is the current operation behavior i The eigenvalue in the kth dimension, V hist,k is the reference value in the kth dimension in the historical behavior pattern, ω k is the adaptive weight, which is used to dynamically adjust the weight of each dimension in the anomaly score, α kis a nonlinear adjustment parameter used to control the sensitivity of the difference between the current operation behavior and the historical pattern, λ k is the coefficient controlling the time decay, reflecting the influence of historical data on the current anomaly score, θ k is a time-sensitive factor that controls the weight adjustment of the operation behavior within a specific time window. t is the current timestamp and is used to dynamically adjust the impact of historical data in the score.
[0135] S84, when the abnormal score S i If the dynamic threshold θ is exceeded, the tampering detection mechanism is triggered and the operation record is marked as suspicious, where the dynamic threshold θ is adjusted based on the real-time system status and historical abnormal data:
[0136] If S i >θ(V hist ), then flag as suspicious;
[0137] Among them, θ(V hist ) is a threshold that is automatically adjusted based on historical behavior data;
[0138] S85. Conduct a detailed audit of suspicious operation records, and use the multi-dimensional graph M(A i ) and combined with the system historical data H(A) to further verify the possibility of tampering, and finally generate the audit conclusion C audit and store it in the system log.
[0139] In this implementation manner, the S82 specifically includes:
[0140] S821, generating a multi-dimensional behavior feature vector V i Before, for timestamp T i 、Geographical location i , operating frequency F i and data interaction mode P i Normalization is performed and an adaptive transformation function Φ is introduced. This function automatically adjusts the normalization parameters according to the current data distribution. The formula is expressed as:
[0141]
[0142] Among them, μ(·) and σ(·) represent the mean and standard deviation of the data in this dimension, respectively, and Φ T , Φ G , Φ F and Φ P It is an adaptive transformation function, which is used to dynamically adjust the normalization result according to the data distribution and capture the nonlinear characteristics of the data;
[0143] S822, input the preprocessed data of each dimension into the multidimensional nonlinear conversion function Ψ to generate a comprehensive feature vector V i , the function Ψ is a piecewise combination of multiple nonlinear sub-functions ψ j Implement and use asymmetric weighting strategy to deal with the unevenness of features in each dimension:
[0144]
[0145] Among them, ψ j (φ j (G' i )) is a nonlinear mapping function used to transform the geographic location G' i Mapped to a specific range to handle geographical distribution characteristics, β j (T' i ) is based on the time dimension T' i The adaptive weight function dynamically adjusts the weight within a specific time range, γ j (F' i ) is the operating frequency dimension F' i Dynamic adjustment factor, γ j It will be dynamically adjusted according to the change of operating frequency to improve the system's sensitivity to high-frequency operations. δ is a parameter for adjusting the nonlinear transformation curve to control the influence of the interaction mode in the feature vector.
[0146] S823, generating a comprehensive feature vector V i In the process, the mapping function φ is dynamically adjusted according to the system context perception mechanism. j and weight β j Parameters to adapt to current environmental changes and operating characteristics:
[0147]
[0148] Among them, γ and δ are parameters for adjusting the nonlinear mapping curve, κ is the context sensitive factor, and C j It is the responsiveness of the current sub-function, reflecting the importance of the current dimension data in a specific environment;
[0149] S824, the final generated comprehensive feature vector V i Output and record.
[0150] Embodiment 1:
[0151] The transaction trace processing system of the present invention is deployed in a large financial institution, Company B. Company B is a large financial enterprise with tens of thousands of employees, which needs to process a large number of user transactions and internal management operations on a daily basis. In order to ensure the security and traceability of operation data and prevent internal personnel or external attackers from tampering with log data, Company B decided to introduce the transaction trace processing method of the present invention.
[0152] Company B's daily operations involve a large number of operations such as user account management, fund transactions, and approval processes. In traditional systems, log data can be easily modified by internal administrators with high authority, resulting in hidden dangers in data integrity and security. In order to solve this problem, Company B deployed the system of the present invention, which aims to prevent any tampering by strengthening the recording and monitoring of operational behaviors.
[0153] After the system was deployed at Company B, all user operations were first authenticated through asymmetric encryption technology to ensure the legitimacy of the operation. The operation behavior was recorded and an operation record was generated. Each record contained the hash value of the previous operation to ensure the continuity and immutability of the chain. Then, these records were signed and confirmed and stored in a chain data structure through a multi-ring signature chain encryption algorithm, thus forming an irreversible operation chain. The system also adopted a time-consistent consensus algorithm to ensure that the operations of all nodes were consistent and the operation chain was stored in a distributed ledger. In the first 12 months of operation, the system processed more than 2 million operations, including user account management, fund transfers, and approval processes. Whenever there was an attempt to tamper with the system, the system would immediately identify the anomaly and prevent the tampering through a multi-dimensional behavior analysis detection algorithm. For operation records marked as suspicious, the system automatically triggers an audit procedure, conducts a detailed analysis, and generates an audit report.
[0154] Table 1 Comparison of operation data before and after the launch of the system of Company B
[0155]
[0156]
[0157] As can be seen from Table 1, the application of the system of the present invention effectively solves the problem of operation log tampering; Company B completely eliminated the operation log tampering incidents within 12 months, improved the audit efficiency of operation data, and reduced the average audit time from 5 minutes to 1 minute, with an efficiency improvement of 80%. In addition, the number of abnormal behaviors has been reduced from 20 cases / year to 2 cases / year, and the response time of abnormal detection has also been shortened from 2 hours to 5 minutes, with a response speed improvement of 96%. Most importantly, through the chain data structure and consensus algorithm in the system, the traceability success rate of operation records has reached 100%, providing strong support for Company B's audit and compliance inspections.
[0158] Through the transaction trace processing method of the present invention, Company B not only improved the security of the system, but also greatly improved the transparency and traceability of operational behaviors, prevented potential safety hazards, and significantly improved operational efficiency. In the future, Company B plans to apply the system to more business areas to further strengthen its information security and data management capabilities.
[0159] Through the implementation of the present invention, Company B has significantly improved the security of the system, improved the transparency and traceability of operational behaviors, effectively prevented potential safety hazards, and improved operational efficiency. The successful application of this system provides valuable experience for Company B's future safety management in other business areas.
[0160] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.
Claims
1. A method for processing transaction traces, characterized in that: The steps include: S1. Authenticate the user by obtaining the user's public key and verifying the user's private key signature using asymmetric encryption technology; S2. After the user identity authentication is passed, the user's operation behavior is recorded, and each operation behavior is generated into an operation record in the order in which it occurs, and the operation record includes the hash value of the previous operation record; S3. Confirm the operation record with a signature, where the signature is generated using the user's private key and verified using the user's public key; S4. Use a multi-ring signature chain encryption algorithm to store the signed and confirmed operation records into a chain data structure to form an irreversible operation chain. The multi-ring signature chain encryption algorithm specifically includes: In the encryption process, a set of m public keys is selected, P = {P1, P2, ..., P m }, where P1 is the public key of the current operating user, P2,...,P m Build a set of public keys for the ring signature for the public keys of other users in the system, and use the private key K of the current operating user i As a unique key for signing; For the intermediate data C of the operation chain i Processing, multi-layer hash mapping of intermediate data, generating a multi-dimensional hash matrix H(C i ), where each dimension of the matrix corresponds to an independent hash function output, the hash matrix H(C i ) is generated as: H(C i )=[h1(C i ) h2(C i ) ... h d (C i )]; Among them, h j (C i ) indicates that for the intermediate data C i The jth independent hash function output of , d is the number of hash functions; Using the current operating user's private key K i For the generated hash matrix H(C i ) performs multi-ring signature processing, and generates signatures through the function MultiSign(H(C i ),K i ) Generate a multi-ring signature S i ', multi-ring signature S i 'Not only does it include the irreversibility of the ring signature, but it also optimizes the encryption protection of the signature information by multi-layer hash mapping, where K i Indicates the private key of the current operating user, H(C i ) represents the intermediate data C i Multi-dimensional hash matrix; When generating a multi-ring signature, the identity of the signer in P remains irreversible through the obfuscation effect of the hash functions in each dimension. Even if the attacker obtains the entire public key set and hash matrix, the specific signer cannot be determined. The generated multi-ring signature S i 'With the original intermediate data C i Combined to form the final encrypted data packet E i , and stored in the chain node; S5. During the transaction processing, the application and approval operations of each transaction are recorded, and all the operations involved are formed into a transaction chain in the order in which they occur. The transaction chain includes the signature of each operation and the hash value of the previous operation record; S6. In the process of forming the transaction chain, a time-consistent consensus algorithm is adopted. By introducing a dual verification mechanism of timestamp and geographic location data, each node in the distributed ledger can reach a consensus in different geographic locations and time environments; S7. Store the operation chain and transaction chain in a distributed ledger; S8. When any attempt to tamper with operation records or transaction data occurs, a multi-dimensional behavior analysis detection algorithm is used to build a multi-dimensional map of operation behavior to conduct all-round anomaly detection, automatically identify and prevent tampering attempts.
2. A transaction trace processing method according to claim 1, characterized in that: The S4 specifically includes: S41, performing hash processing on each operation record to generate a hash value uniquely corresponding to the operation record; S42, connecting the hash value of the current operation record with the hash value of the previous operation record to generate intermediate data of the operation chain; S43, encrypt the generated intermediate data using a multi-ring signature chain encryption algorithm, by selecting a set of public keys, including the public key of the current operating user and the public keys of other system users, and encrypting the intermediate data with a ring signature in combination with the private key of the current operating user, so that the encryption result can ensure the legitimacy of the operation and the identity of the specific signer cannot be reversely deduced; S44. The data encrypted by the ring signature and the newly generated hash value are stored in the nodes of the chain data structure. Each node is linked to each other through the hash value of the previous node, and finally an operation chain is formed.
3. A transaction trace processing method according to claim 1, characterized in that: The S5 specifically includes: S51. During the transaction processing, each transaction application operation first generates an initial transaction record T0, which contains the basic information of the transaction I0 and the signature S of the applicant. a , where the applicant's signature S a Through its private key K a Sign the basic transaction information I0; S52: After the initial transaction record T0 is generated, the initial transaction record T0 is used as the starting point of the transaction chain, and the corresponding transaction record T0 is generated in each approval stage. i , where T i Contains the signature S of the current approval operation i and the hash matrix H(T i-1 ); S53, the hash matrix H(T i-1 ) and the current transaction record T i Fusion is performed to generate encrypted transaction chain intermediate data C t The specific process includes H(T i-1 )’s hash value h for each dimension j (T i-1 ) performs nonlinear mapping and combines the data recorded in the current transaction with T i Generate a multi-layer nested encryption structure: in, Represents the hash value h j (T i-1 ) and the current transaction data T i The nonlinear mapping function between , d is the number of dimensions of the hash matrix, Encrypt is the overall encryption function, which is used to generate the encrypted intermediate data C t ; S54, generate the transaction chain intermediate data C t Apply the multi-dimensional hash chain encryption algorithm based on ring signature to generate encrypted transaction chain data E t Stored in a distributed ledger; S55. After the entire transaction processing process is completed, the final transaction record T is generated. n , transaction record T n The multidimensional signature matrix S containing all participants final And the complete transaction data chain after multi-layer encryption: Among them, ∑ represents the accumulation process of transaction records, {·} Encrypt Represents the overall encryption process of the chain, S final A matrix representing the combination of signatures of all participants, used to ultimately verify the integrity and legitimacy of the entire transaction chain.
4. A transaction trace processing method according to claim 3, characterized in that: The S6 specifically includes: S61. During the generation of the transaction chain, time synchronization is performed on all nodes participating in the transaction to keep the clocks of all nodes consistent. The time synchronization is based on the improved distributed time protocol T sync , so that the timestamp of each node is synchronized within the allowable error range; S62. Before reaching consensus, dynamically adjust the consensus algorithm parameter set P according to the current system load and network conditions. cons , where P cons Including consensus round R, node selection strategy N sel and voting weight W v , and according to the system load condition L through machine learning model sys Calculate the optimal parameter set; S63. Based on the time-series consensus algorithm, select a node set N from the entire network. cons Participating in consensus, the node set N cons The selection criteria include the geographical location of the node G i 、Current system load L i And the time synchronization result T i ,By combining these parameters, the geographical distribution and load balancing of the selected nodes can achieve the desired goals; S64. In the node set N cons The consensus operation is performed in the process, which is based on the time-series consensus algorithm and converts the final record T of the transaction chain into n With node set N cons and parameter set P cons Verify and generate consensus result C res , the consensus results maintain the consistency of time and geographical location at the same time, achieving the global validity of the consensus; S65. The final consensus result C res Write it into the distributed ledger and send the signature S of the consensus node cons Stored together with the consensus result.
5. A transaction trace processing method according to claim 4, characterized in that: The S63 specifically includes: S631, in the consensus node set N cons When selecting, first perform a geographic location G on all available nodes. i Classification, calculate the geographical distribution distance D between nodes ij , the selected node set N cons Should cover multiple geographical areas, with a distribution distance D ij Should meet D ij ≥D min , where D min is the preset minimum geographical distribution distance; S632: Current system load L of all available nodes i The load evaluation is based on the computing power of the node, the number of current tasks, and the network bandwidth. Nodes with lower load are selected to join the set N first. cons , node load L i Should satisfy L i ≤L max , where L max is the maximum allowed system load; S633, combined with the time synchronization result T i , preferably the time error ΔT i For nodes within the allowable range, the time error ΔT i Should satisfy ΔT i ≤∈, where ∈ is the maximum allowed time error; S634, Geographical distribution i 、System load L i Synchronize with time T i For multi-dimensional fusion, a nonlinear fusion function Ω(G i ,L i ,T i ) to calculate the comprehensive score of the node: Among them, λ1 is the geographical distribution weight parameter, which controls the geographical location G i Impact on the comprehensive score, λ2 is the load weight parameter, and the control system load L i Impact on the comprehensive score, λ3 is the time synchronization weight parameter, which controls the time error ΔT i Impact on the comprehensive score, G i represents the geographical location of the node, L i represents the system load of the node, ΔT i Indicates the time synchronization error of the node; S635, the comprehensive score Ω(G i ,L i ,T i ) The highest node is determined as the consensus node set N cons , and submit it to the distributed system for consensus operation.
6. A transaction trace processing method according to claim 1, characterized in that: The S8 specifically includes: S81. In the transaction chain, a multi-dimensional behavior analysis detection algorithm is used for each operation record and transaction data, and a multi-dimensional behavior map M (A i ), where A i Represents the operation behavior in the system. The behavior graph includes the timestamp T i 、Geographical location i , operating frequency F i and data interaction mode P i Dimension; S82. For each operation behavior A i In the graph M(A i ) to model each dimension in the model and generate a multi-dimensional behavior feature vector V i , generated by a multidimensional nonlinear transformation function Ψ, capturing the complex relationships between different dimensions; S83, perform anomaly detection on each node in the operation chain, based on the current behavior feature vector V i and historical behavior patterns V hist The nonlinear difference between them is compared to calculate the anomaly score S i , the anomaly score is obtained by adaptive weight ω k and the nonlinear adjustment parameter α k To capture abnormal behavior in a specific dimension, combined with the time-sensitive factor θ k Impact of dynamically adjusting ratings: Among them, V i,k V is the current operation behavior i The eigenvalue in the kth dimension, V hist,k is the reference value in the kth dimension in the historical behavior pattern, ω k is the adaptive weight, which is used to dynamically adjust the weight of each dimension in the anomaly score, α k is a nonlinear adjustment parameter used to control the sensitivity of the difference between the current operation behavior and the historical pattern, λ k is the coefficient controlling the time decay, reflecting the influence of historical data on the current anomaly score, θ k is a time-sensitive factor that controls the weight adjustment of the operation behavior within a specific time window. t is the current timestamp and is used to dynamically adjust the impact of historical data in the score. S84, when the abnormal score S i If the dynamic threshold θ is exceeded, the tampering detection mechanism is triggered and the operation record is marked as suspicious, where the dynamic threshold θ is adjusted based on the real-time system status and historical abnormal data: IfS i >θ(V hist ); S85. Conduct a detailed audit of suspicious operation records, and use the multi-dimensional graph M(A i ) and combined with the system historical data H(A) to further verify the possibility of tampering, and finally generate the audit conclusion C audit and store it in the system log.
7. A transaction trace processing method according to claim 6, characterized in that: The S82 specifically includes: S821, generating a multi-dimensional behavior feature vector V i Before, for timestamp T i 、Geographical location i , operating frequency F i and data interaction mode P i Normalization is performed and an adaptive transformation function Φ is introduced. This function automatically adjusts the normalization parameters according to the current data distribution. The formula is expressed as: Among them, μ(·) and σ(·) represent the mean and standard deviation of the dimension data respectively, Φ T , Φ G , Φ F and Φ P It is an adaptive transformation function, which is used to dynamically adjust the normalization result according to the data distribution and capture the nonlinear characteristics of the data; S822, input the preprocessed data of each dimension into the multidimensional nonlinear conversion function Ψ to generate a comprehensive feature vector V i , the function Ψ is a piecewise combination of multiple nonlinear sub-functions ψ j Implement and use asymmetric weighting strategy to deal with the unevenness of features in each dimension: Among them, ψ j (φ j (G' i )) is a nonlinear mapping function used to transform the geographic location G' i Mapped to a specific range to handle geographical distribution characteristics, β j (T' i ) is based on the time dimension T' i The adaptive weight function dynamically adjusts the weight within a specific time range, γ j (F' i ) is the operating frequency dimension F' i Dynamic adjustment factor, γ j It will be dynamically adjusted according to the change of operating frequency to improve the system's sensitivity to high-frequency operations. δ is a parameter for adjusting the nonlinear transformation curve to control the influence of the interaction mode in the feature vector. S823, generating a comprehensive feature vector V i In the process, the mapping function φ is dynamically adjusted according to the system context perception mechanism. j and weight β j Parameters to adapt to current environmental changes and operating characteristics: Among them, γ and δ are parameters for adjusting the nonlinear mapping curve, κ is the context sensitive factor, and C j is the responsiveness of the current sub-function, reflecting the importance of the current dimension data in a specific environment; S824, the final generated comprehensive feature vector V i Output and record.
Citation Information
Patent Citations
Block chain processing method and device, equipment and readable storage medium
CN110505067A
Security settlement using group signatures
US11483162B1