A method, apparatus, device, medium and product for protecting item-related information
By performing multiple encryption and identification code access based on transportation route information during the transportation process, combined with alliance chain identity verification, the problem of information security in the supply chain is solved, and efficient and secure transmission of item-related information is achieved.
Patent Information
- Application Number
- CN202411856254.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2044-12-17
AI Technical Summary
In the prior art, during the multiple transfers of items in the supply chain, a single encryption method causes the security of item-related information to be effectively guaranteed.
Based on the item transportation route information, multiple encryption algorithms are used to multiple encryption information. The private chain is accessed through identification code to obtain the encryption information, and the encryption sequence is redetermined in each transit node according to the actual logistics speed, and identity verification is carried out in combination with the alliance chain.
It improves the security of items-related information in logistics and transportation, reduces the risk of data leakage, improves data processing efficiency and security, and reduces the cost of identity verification time.
Smart Images

Figure CN119312371B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of logistics information management, and particularly to a method, apparatus, device, medium and product for protecting item-related information. Background Art
[0002] A supply chain refers to a network structure formed by the connection of upstream and downstream members including suppliers, manufacturers, distributors, and consumers involved in the entire process from producing parts, manufacturing intermediate products and final products, and finally delivering them to consumers. During the transportation process of items in the supply chain, the item-related information exposed for display is prone to information leakage. Therefore, it is necessary to encrypt the item-related information during transportation.
[0003] However, since items often need to go through multiple transfers in the supply chain, the single encryption method adopted by the prior art has a poor encryption effect during multiple transfers of items, and the security of item-related information cannot be guaranteed. Summary of the Invention
[0004] To solve the above technical problems, the present application provides a method, apparatus, device, medium and product for protecting item-related information, which can perform multiple encryptions on item-related information based on the transportation route information of the item using multiple encryption algorithms, improving the security of information during transportation.
[0005] An embodiment of the present application provides a method for protecting item-related information, including:
[0006] Obtaining the actual transportation route of the item from the previous node to the target node; the previous node is the starting node or the previous node of the target node;
[0007] Determining the encryption order of several encryption algorithms according to the speeds of the item on different segmented routes of the actual transportation route; wherein, there is a corresponding relationship between the segmented routes and the encryption algorithms;
[0008] Performing multiple encryptions on the first item-related information of the item regarding the target node according to the encryption order to obtain the first encrypted information.
[0009] As an improvement of the above solution, the determining the encryption order of several encryption algorithms according to the speeds of the item on different segmented routes of the actual transportation route includes:
[0010] Dividing the actual transportation route into several segmented routes, and calculating the speed of the item on each segmented route;
[0011] Sorting several segmented routes according to the speed to obtain the order of several segmented routes;
[0012] According to the corresponding relationship and the order of several of the segmented routes, obtain the encryption order of several encryption algorithms.
[0013] As an improvement to the above solution, after obtaining the first encrypted information, the method further includes:
[0014] Upload and store the first encrypted information and its corresponding first multi-decryption algorithm to a private chain built based on the nodes of the item.
[0015] Identify the next node of the target node and grant the next node the decryption permission of the target node.
[0016] Set the link address of the private chain as the identification code, so that when the item reaches the next node and the next node has the decryption permission of the target node, by scanning the identification code, access the private chain to obtain the first encrypted information and the first multi-decryption algorithm.
[0017] As an improvement to the above solution, before multi-encrypting the first item-related information of the item with respect to the target node according to the encryption order to obtain the first encrypted information, the method further includes:
[0018] In the case of having the decryption permission granted by the previous node, scan the identification code of the item to obtain the private chain address, and through the private chain address, obtain the second encrypted information of the item with respect to the previous node and the corresponding second multi-decryption algorithm.
[0019] Decrypt the second encrypted information according to the second multi-decryption algorithm to obtain the second item-related information of the item with respect to the previous node.
[0020] Store the second item-related information in the information library of the target node.
[0021] As an improvement to the above solution, the method further includes:
[0022] When the user signs for the item, for each node, determine whether the item-related information about the previous node stored in its information library is consistent with the information after decrypting the encrypted information uploaded by the previous node to the private chain.
[0023] If so, delete all the encrypted information stored in the private chain, and encrypt the information of the item stored in the information library of each node respectively according to the several encryption algorithms.
[0024] As an improvement to the above solution, the first item-related information includes at least one of the following:
[0025] The basic information of the item
[0026] The logistics information of the item from the previous node to leaving the target node;
[0027] The logistics information of the item from the starting node to leaving the target node.
[0028] As an improvement to the above solution, before obtaining the transportation route of the item from the previous node to the target node, the method further includes:
[0029] Taking a number of certification units as nodes of the consortium blockchain, building a consortium blockchain, and deploying a smart contract for the consortium blockchain; the smart contract is used to generate a DID identity for the user;
[0030] Authenticating the DID identity of the user to whom the item belongs through the consortium blockchain, and starting the transportation of the item when the DID identity authentication is passed.
[0031] The embodiment of the present application also provides an item-related information protection device, including:
[0032] A route acquisition module, configured to acquire the actual transportation route of the item from the previous node to the target node; the previous node is the starting node or the previous node of the target node;
[0033] An encryption order module, configured to determine the encryption order of a number of encryption algorithms according to the speed of the item on different segmented routes of the actual transportation route; wherein, there is a corresponding relationship between the segmented route and the encryption algorithm;
[0034] A multiple encryption module, configured to perform multiple encryption on the first item-related information of the item regarding the target node according to the encryption order to obtain the first encrypted information.
[0035] The embodiment of the present application also provides an item-related information protection device, including a processor and a memory, a computer program is stored in the memory, and the computer program is configured to be executed by the processor, and when the processor executes the computer program, it implements the item-related information protection method described in any one of the above.
[0036] The embodiment of the present application also provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the item-related information protection method described in any one of the above.
[0037] The embodiment of the present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the item-related information protection method described in any one of the above.
[0038] Compared with the prior art, the beneficial effects of an article-related information protection method, device, equipment, medium and product provided by an embodiment of the present application are as follows:
[0039] By determining the encryption order based on the speeds of different sections in the article transportation route and using multiple encryption algorithms to perform multiple encryptions on the article-related information, the problem of single encryption method is solved, and the security of the article-related information in logistics transportation is improved. It can re-determine the encryption order for encryption according to the actual logistics speed at each transfer node, greatly improving the encryption effect of the article-related information; by setting an identification code, the node needs to scan the identification code to access the private chain to obtain the article-related information, further reducing the risk of data leakage and ensuring the security of the article-related information;
[0040] After the article transportation is completed, by clearing the private chain data to avoid data bloat and improve data processing efficiency, and at the same time storing the article-related information out of position in the information libraries of each node and encrypting the article-related information stored in the information library of each node, diversified and secure storage of data is achieved;
[0041] By using the logistics nodes of the article as private chain nodes to construct a private chain for article transportation and building an alliance chain with several certification units, and authenticating the identity of the user to whom the article belongs through the alliance chain to start article transportation when the authentication is passed, it can enable each node in the supply chain to quickly and securely authenticate the identity without going through a centralized institution, reducing the time cost of identity authentication and ensuring the security of operations while reducing the risk of key data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 is a schematic flowchart of an article-related information protection method provided by an embodiment of the present application;
[0043] Figure 2 is a schematic structural diagram of an article-related information protection device provided by an embodiment of the present application;
[0044] Figure 3 is a schematic structural diagram of an article-related information protection equipment provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0046] Please refer toFigure 1 , Figure 1 is a schematic flowchart of a method for protecting item-related information provided by an embodiment of the present application. The method for protecting item-related information includes:
[0047] S1: Obtain the actual transportation route of the item from the foregoing node to the target node; the foregoing node is the starting node or the previous node of the target node;
[0048] S2: Determine the encryption order of a number of encryption algorithms according to the speeds of the item on different segmented routes of the actual transportation route; wherein, there is a corresponding relationship between the segmented routes and the encryption algorithms;
[0049] S3: Perform multiple encryptions on the first item-related information of the item regarding the target node according to the encryption order to obtain the first encrypted information.
[0050] Specifically, when an item needs to be transported in the supply chain, according to the expected transportation route generated from the item order information, obtain the starting node, the terminating node of the item transportation route, and several transit nodes passed by the route. When the item is transported between nodes, there is a risk of data leakage of the item-related information. Therefore, in the embodiment of the present application, before the item leaves the node and starts to be transported, multiple encryptions are performed on the item-related information to ensure the security of the item-related information.
[0051] In a specific example, after the item arrives at the target node, obtain the actual transportation route of the item from the starting node to the target node from the item transportation end. In another specific example, after the item arrives at the target node, obtain the actual transportation route of the item from the previous node of the target node to the target node from the item transportation end. Among them, the item transportation end records the coordinate information of the actual transportation route during the item transportation process and the time information for obtaining the corresponding coordinate information. The target node can be any node among the terminating node of the item transportation route and several transit nodes.
[0052] As an optional embodiment, the determining the encryption order of a number of encryption algorithms according to the speeds of the item on different segmented routes of the actual transportation route includes:
[0053] Divide the actual transportation route into several segmented routes, and calculate the speed of the item on each segmented route;
[0054] Sort the several segmented routes according to the speed to obtain the order of the several segmented routes;
[0055] According to the corresponding relationship and the order of the several segmented routes, obtain the encryption order of the several encryption algorithms.
[0056] Specifically, the article transportation terminal stores a preset password book or obtains a preset password book from a private chain. The password book consists of N encryption algorithms, where N ≥ 2. The N encryption algorithms in the password book are arranged in an initial order. For example, the encryption algorithms in the password book are successively A1, A2, …, A N .
[0057] The actual transportation route is divided into M segments to obtain M sub-routes, successively S1, S2, …, S M , where M can be equal to, greater than, or less than N, and no specific limitation is made here. Then, a correspondence between the encryption algorithms A1, A2, …, A N and the sub-routes S1, S2, …, S M is established to associate their arrangement orders, so that the encryption order of multiple encryptions can be determined according to the sorting of the sub-routes. Among them, the correspondence between the two can be one-to-one, one-to-many, or many-to-one, and no specific limitation is made here.
[0058] Exemplarily, taking the establishment of a one-to-one correspondence as an example, when M = N, a one-to-one mapping relationship can be established between the M sub-routes and the N encryption algorithms; when M > N, N sub-routes can be selected from the M sub-routes, and a one-to-one mapping relationship can be established between the selected N sub-routes and the N encryption algorithms; when M < N, M encryption algorithms can be selected from the N encryption algorithms, and a one-to-one mapping relationship can be established between the M sub-routes and the selected M encryption algorithms.
[0059] Furthermore, according to the coordinate information and time information recorded by the article transportation terminal, the speed of the article on each sub-route is calculated. Then, all the sub-routes are sorted according to the magnitude order of the speeds to obtain a sorting result. And according to this sorting result and the correspondence between the sub-routes and the encryption algorithms, the encryption order of several encryption algorithms is obtained. Furthermore, when the article is about to leave the target node, the several encryption algorithms are used to perform multiple encryptions on the first article-related information of the article about the target node according to the encryption order to obtain the first encrypted information, and then the article transportation is carried out.
[0060] Among them, performing multiple encryptions on the first article-related information according to the encryption order specifically means: using the encryption algorithm at the first position in the encryption order to encrypt the first article-related information to obtain the first-level encrypted information, and then using the encryption algorithm at the second position in the encryption order to encrypt the first-level encrypted information to obtain the second-level encrypted information, and so on. If N encryption algorithms are used, the encryption operation is repeated N times according to the encryption order to obtain the final encrypted information, that is, the first encrypted information.
[0061] It should be noted that before the item at the starting node begins transportation, since the item does not have an actual transportation route yet, the relevant information of the item is initially encrypted at this time to obtain the initial encrypted information, and then the item is transported. Among them, the initial encryption is performed according to a preset encryption algorithm, or the initial order of N encryption algorithms in the password book is used as the encryption order to perform multiple encryptions on the relevant information of the item at the starting node.
[0062] As one of the optional embodiments, after obtaining the first encrypted information, the method further includes:
[0063] Upload and store the first encrypted information and its corresponding first multiple decryption algorithm to a private chain built based on the nodes of the item.
[0064] Confirm the next node of the target node and grant the next node the decryption permission of the target node.
[0065] Set the link address of the private chain as the identification code, so that when the item arrives at the next node and the next node has the decryption permission of the target node, the private chain can be accessed by scanning the identification code to obtain the first encrypted information and the first multiple decryption algorithm.
[0066] Specifically, in the embodiment of the present application, the nodes in the supply chain are used as individual nodes to build a private chain, and at the same time, a terminal APP (Application) corresponding to the private chain is also built. When the item passes through the node, the node stores the relevant information of the item on the chain, ensuring the authenticity and effectiveness of the relevant information of the item.
[0067] After obtaining the first encrypted information of the item, upload the first encrypted information and its corresponding first multiple decryption algorithm (constituted by the decryption algorithms corresponding to several encryption algorithms and their decryption order) to the private chain for storage; at the same time, confirm the next node of the target node according to the expected transportation route of the item and grant the next node the decryption permission of the target node, that is, the decryption permission for the first encrypted information, so that when the item is transported to the next node, the next node can decrypt the first encrypted information.
[0068] In addition, in the embodiments of the present application, an identification code is placed on the item packaging. The identification code includes, but is not limited to, a two-dimensional code, a bar code, and a digital code. The identification code serves as a port for data connection to the private chain. Before the item leaves the target node, the private chain address corresponding to the first encrypted information is embedded in the identification code, and then the item is transported. When the item reaches the next node of the target node, if the next node has the decryption permission of the target node, the private chain is accessed by scanning the identification code to obtain the first encrypted information and the corresponding first multiple decryption algorithm. Furthermore, the next node can decrypt the first encrypted information to obtain the first item-related information.
[0069] For example, the private chain address of the identification code can be obtained only when the identification code is scanned and the next node has the decryption permission of the target node, and then the private chain is accessed to obtain the first encrypted information and the corresponding first multiple decryption algorithm; or, the private chain is accessed by scanning the identification code, and when the next node has the decryption permission of the target node, the first encrypted information and the corresponding first multiple decryption algorithm are obtained; or, the private chain is accessed by scanning the identification code to obtain the first encrypted information. If the next node has the decryption permission of the target node, the next node also obtains the first multiple decryption algorithm from the private chain, which can be set according to actual needs and will not be specifically limited here.
[0070] By setting the identification code, the embodiments of the present application can avoid leaking the information of the item and its corresponding user during the transportation of the item, ensuring the security of the item-related information.
[0071] As one optional embodiment, before the first item-related information of the item about the target node is encrypted multiple times in the encryption order to obtain the first encrypted information, the method further includes:
[0072] When having the decryption permission granted by the previous node, scan the identification code of the item to obtain the private chain address, and through the private chain address, obtain the second encrypted information of the item about the previous node and the corresponding second multiple decryption algorithm;
[0073] Decrypt the second encrypted information according to the second multiple decryption algorithm to obtain the second item-related information of the item about the previous node;
[0074] Store the second item-related information in the information library of the target node.
[0075] Specifically, when the item arrives at the target node from the previous node, the identification code on the item package is scanned. With the decryption permission granted by the previous node, the second encrypted information of the item and the corresponding second multiple decryption algorithm are obtained through the private chain address corresponding to the identification code, and the second encrypted information is decrypted using the second multiple decryption algorithm to obtain the second item-related information of the item regarding the previous node; the second item-related information is stored in the information database of the target node.
[0076] In the embodiment of the present application, the item-related information of the item at each node, after being encrypted and decrypted, will be stored in the information database of the next node, that is, the item-related information is stored out of position, realizing collaborative supervision between different nodes, facilitating data right confirmation, and at the same time enabling distributed data storage.
[0077] As one optional embodiment, the method further includes:
[0078] When the user signs for the item, for each node, it is judged whether the item-related information regarding the previous node stored in its information database is consistent with the information after decrypting the encrypted information uploaded by the previous node to the private chain;
[0079] If so, all the encrypted information stored in the private chain is deleted, and the information of the item stored in the information database of each node is encrypted respectively according to the several encryption algorithms.
[0080] Specifically, the item starts from the starting node and passes through several transfer nodes. When the item arrives at each transfer node, each node will re-encrypt the item-related information using a new encryption order and then transport it to the next node until it reaches the termination node. When the item arrives at the termination node, the user can grant the termination node permission to enable the termination node to obtain the user's signing method information for the user to sign for the item.
[0081] After the user signs for the item, sequentially query the item-related information uploaded by each node stored on the private chain and the item-related information stored in the information database of each node, and respectively judge whether the item-related information regarding the previous node stored in the information database of each node is consistent with the information after decrypting the encrypted information uploaded by the previous node on the private chain, that is, judge whether the information after decrypting the encrypted information uploaded by the starting node on the private chain is consistent with the item-related information in the information database of the second node, whether the information after decrypting the encrypted information uploaded by the second node on the private chain is consistent with the item-related information in the information database of the third node, and so on, and perform a one-by-one comparison on the item information stored on the private chain. If the item information on the private chain is consistent with the item information in the information database, the item information (i.e., the encrypted information) on the private chain is deleted to avoid data bloat and improve data processing efficiency.
[0082] Further, after clearing the item information in the private chain, several encryption algorithms in the password book are used to finally encrypt the item-related information in each information library, so as to encrypt and package the verified item data for storage, thereby ensuring the authenticity of data storage and effectively avoiding the occurrence of unauthorized data tampering.
[0083] It should be noted that the final encryption specifically includes: obtaining the actual transportation route of the item from the starting node to the ending node, obtaining the corresponding encryption order in the same way as in step S2, and performing multiple encryptions on the item-related information in each information library according to this encryption order; or, for the information library of each node, obtaining the actual transportation route from the previous node of this node to this node, obtaining the corresponding encryption order in the same way as in step S2, and performing multiple encryptions on the item-related information in the information library of this node according to this encryption order. Among them, the multiple decryption algorithms corresponding to the final encrypted information are stored in the private chain.
[0084] As one of the optional embodiments, the first item-related information includes at least one of the following:
[0085] The basic information of the item;
[0086] The logistics information of the item from leaving the previous node to leaving the target node;
[0087] The logistics information of the item from leaving the starting node to leaving the target node.
[0088] Specifically, the logistics information of the item from leaving the previous node to leaving the target node includes: the actual transportation route information of the item from the previous node to the target node, and the process information of the item at the target node. This process information includes, but is not limited to, the relevant information of processes such as processing and packaging of the item at the target node. When the first item-related information is the logistics information of the item from leaving the previous node to leaving the target node, the item-related information about the target node does not include the actual transportation route information and process information of the nodes before the target node.
[0089] The logistics information of the item from leaving the starting node to leaving the target node includes: the actual transportation route information of the item from the starting node to the target node, and the process information of the item at the target node. When the first item-related information is the logistics information of the item from leaving the starting node to leaving the target node, each time new information (including the actual transportation route information between nodes and the process information at nodes) is generated, the new information is added to the original information to update the item-related information.
[0090] As one of the optional embodiments, before obtaining the transportation route of the item from the foregoing node to the target node, the method further includes:
[0091] Taking a number of certification units as nodes of the consortium chain, building a consortium chain, and deploying a smart contract for the consortium chain; the smart contract is used to generate a DID identity for the user;
[0092] Authenticating the DID identity of the user to whom the item belongs through the consortium chain, and starting the transportation of the item when the DID identity authentication is passed.
[0093] Specifically, after building a private chain and building the corresponding terminal APP of the private chain, introduce a number of certification units to sign a smart contract, build a consortium chain, configure a consensus mechanism (such as the Byzantine fault tolerance algorithm PBFT, etc.), network permission management, and data privacy policies to ensure that all certification units join the consortium chain as authoritative nodes. Among them, the certification units include but are not limited to official certification units such as banks, schools, and shopping malls.
[0094] When the user registers the terminal APP, the consortium chain verifies each other among the associated several certification units according to the relevant attributes of the user in several certification units, and generates the DID (Distributed Identity) identity of the user, that is, the distributed digital identity. Among them, the relevant attributes are data corresponding to the user's real identity information. For example, the user's degree certificate in a certain school, registered membership in a certain shopping mall, etc. information. By comparing the degree certificate and the registered membership information, the authenticity of the user's identity can be verified. The DID identity is at least one electronic certificate issued by the certification unit to the user after passing the qualification review of the user according to the relevant attributes of the user. The electronic certificate is encrypted and distributed to each node in the supply chain after passing the qualification review. Each electronic certificate carries a mark representing the type of the certificate. When a verification requirement event occurs, the authorized encrypted electronic certificate is sent to the certificate verification party (that is, the certification unit), and after the certificate verification party decrypts the encrypted electronic certificate, the original text of the electronic certificate is verified to obtain the verification result.
[0095] When the user sends an item purchase request from the APP, authenticate the user through the consortium chain. Each certification unit issues a statement according to the DID identity of the user. When a verified statement is received, start the item transportation.
[0096] In this application, by using the logistics nodes of the item as the private chain nodes, building a private chain for item transportation, and building a consortium chain with several certification units, authenticating the identity of the user to whom the item belongs through the consortium chain, and starting the item transportation when the verification is passed, it can enable each node in the supply chain to quickly and securely verify the identity, without passing through a centralized agency, reducing the time cost of identity verification, while reducing the risk of key data leakage and ensuring the security of operations.
[0097] As one of the optional embodiments, the method further includes:
[0098] Obtaining the expected transportation route of the item from the foregoing node to the target node;
[0099] Calculating the similarity between the actual transportation route and the expected transportation route;
[0100] When the similarity is less than a preset threshold, outputting a warning message for item transportation error.
[0101] Specifically, generate the route required for transporting the item to the consumer according to the order information of the item, that is, the expected transportation route of the item from the starting node to the ending node. Both the order information and the expected transportation route information belong to the basic information of the item.
[0102] During the process of transporting the item along the expected transportation route by the item transportation terminal, according to the coordinate information of the actual transportation route recorded by the item transportation terminal and the time information corresponding to the coordinate information, use the path matching algorithm to calculate the similarity between the actual transportation route and the expected transportation route, so as to perform early warning of item transportation errors. Among them, the similarity is calculated according to the following formula:
[0103]
[0104] Wherein, represents the i-th point on the actual transportation route, represents the i-th point on the expected transportation route, represents the distance between two points, represents the total number of points on the route.
[0105] When the calculated similarity is less than the preset threshold, output a warning message for item transportation error to ensure the smooth transportation of the item.
[0106] The present application determines the encryption order based on the speeds of different sections in the item transportation route, and uses multiple encryption algorithms to perform multiple encryptions on the item-related information, solving the problem of single encryption method and enhancing the security of the item-related information in logistics transportation. It can re-determine the encryption order for encryption according to the actual logistics speed at each transfer node, greatly enhancing the encryption effect of the item-related information; by setting an identification code, the node needs to scan the identification code to access the private chain to obtain the item-related information, further reducing the risk of data leakage and ensuring the security of the item-related information; after the item transportation is completed, the data on the private chain is cleared to avoid data bloat and improve data processing efficiency, and at the same time, the item-related information is misaligned and stored in the information databases of each node, and the item-related information stored in the information database of each node is encrypted, realizing diverse and secure storage of data; by using the logistics nodes of the item as the private chain nodes to construct a private chain for item transportation and building an alliance chain with several certification units, and authenticating the identity of the user to whom the item belongs through the alliance chain, and starting the item transportation when the authentication is passed, it can enable each node in the supply chain to quickly and securely authenticate the identity without passing through a centralized institution, reducing the time cost of identity authentication, and ensuring the security of operations while reducing the risk of key data leakage.
[0107] Correspondingly, the present application also provides an item-related information protection device, which can implement all the processes of the item-related information protection method in the above embodiments.
[0108] Please refer to Figure 2 , Figure 2 which is a schematic structural diagram of an item-related information protection device provided by an embodiment of the present application. The item-related information protection device includes:
[0109] A route acquisition module 201, configured to acquire the actual transportation route of the item from the foregoing node to the target node; the foregoing node is the starting node or the previous node of the target node;
[0110] An encryption order module 202, configured to determine the encryption order of several encryption algorithms according to the speeds of the item on different segmented routes of the actual transportation route; wherein, there is a corresponding relationship between the segmented route and the encryption algorithm;
[0111] A multiple encryption module 203, configured to perform multiple encryptions on the first item-related information of the item regarding the target node according to the encryption order to obtain first encrypted information.
[0112] Preferably, the encryption order module 202 is specifically configured to:
[0113] Divide the actual transportation route into several segmented routes, and calculate the speed of the item on each segmented route;
[0114] Sort several of the segmented routes according to the speed to obtain the order of several of the segmented routes;
[0115] According to the corresponding relationship and the order of several of the segmented routes, obtain the encryption order of several encryption algorithms.
[0116] Preferably, the item-related information protection device further includes:
[0117] An information uploading module, configured to upload and store the first encrypted information and its corresponding first multi-decryption algorithm to a private chain built based on nodes of the item;
[0118] A decryption permission module, configured to confirm the next node of the target node and grant the decryption permission of the target node to the next node;
[0119] An identification code module, configured to set the link address of the private chain as an identification code, so that when the item reaches the next node and the next node has the decryption permission of the target node, the private chain is accessed by scanning the identification code to obtain the first encrypted information and the first multi-decryption algorithm.
[0120] Preferably, the item-related information protection device further includes:
[0121] An information acquisition module, configured to scan the identification code of the item to obtain a private chain address and, through the private chain address, obtain second encrypted information of the item about the previous node and a corresponding second multi-decryption algorithm when having the decryption permission granted by the previous node;
[0122] An information decryption module, configured to decrypt the second encrypted information according to the second multi-decryption algorithm to obtain second item-related information of the item about the previous node;
[0123] An information storage module, configured to store the second item-related information in an information library of the target node.
[0124] Preferably, the item-related information protection device further includes:
[0125] An information verification module, configured to, when the user signs for the item, for each node, determine whether the item-related information about the previous node stored in its information library is consistent with the information after decrypting the encrypted information uploaded by the previous node to the private chain; if so, delete all the encrypted information stored in the private chain, and encrypt the information of the item stored in the information library of each node respectively according to the several encryption algorithms.
[0126] Preferably, the first item-related information includes at least one of the following:
[0127] The basic information of the item;
[0128] The logistics information of the item from the previous node to leaving the target node;
[0129] The logistics information of the item from the starting node to leaving the target node.
[0130] Preferably, the item-related information protection device further includes:
[0131] A consortium blockchain module, which is used to take several certification units as consortium blockchain nodes, build a consortium blockchain, and deploy a smart contract for the consortium blockchain; the smart contract is used to generate a DID identity for the user;
[0132] An identity authentication module, which is used to perform DID identity authentication on the user to whom the item belongs through the consortium blockchain, and start the transportation of the item when the DID identity authentication is passed.
[0133] In specific implementation, the working principle, control process and achieved technical effects of the item-related information protection device provided in the embodiment of the present application are correspondingly the same as those of the item-related information protection method in the above embodiment, and will not be elaborated here.
[0134] See Figure 3 , Figure 3 is a schematic structural diagram of an item-related information protection device provided in an embodiment of the present application. The item-related information protection device includes: a processor 301, a memory 302, and a computer program stored in the memory 302 and executable on the processor 301. When the processor 301 executes the computer program, the steps in the embodiment of the above item-related information protection method are implemented. Or, when the processor 301 executes the computer program, the functions of each module / unit in the above device embodiments are implemented.
[0135] Exemplarily, the computer program can be divided into one or more modules / units. The one or more modules / units are stored in the memory 302 and executed by the processor 301 to complete the present application. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the item-related information protection device.
[0136] The article-related information protection device may include, but is not limited to, a processor 301 and a memory 302. Those skilled in the art can understand that the schematic diagram is only an example of the article-related information protection device, and does not constitute a limitation on the article-related information protection device. It may include more or fewer components than those shown in the figure, or combine certain components, or different components. For example, the article-related information protection device may also include input / output devices, network access devices, buses, etc.
[0137] The processor 301 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor 301 is the control center of the article-related information protection device, and connects various parts of the entire article-related information protection device through various interfaces and lines.
[0138] The memory 302 can be used to store the computer programs and / or modules. The processor 301 realizes various functions of the article-related information protection device by running or executing the computer programs and / or modules stored in the memory 302, and by calling the data stored in the memory 302. The memory 302 mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc.; the data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory 302 may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0139] Among them, if the modules / units integrated in the item-related information protection device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-described embodiment methods of the present application, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor 301, the steps of the above-described method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc.
[0140] The embodiment of the present application also provides a computer-readable storage medium, and the computer-readable storage medium includes a stored computer program. Among them, when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the item-related information protection method described in any one of the above embodiments.
[0141] The embodiment of the present application also provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the item-related information protection method described in any one of the above embodiments is implemented.
[0142] The method in the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in the form of a computer program product in whole or in part. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, or other programmable devices.
[0143] The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that a computer can access, or a data storage device such as a server or data center integrating one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc; it can also be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile types of storage media.
[0144] The computer programs / instructions described herein can be downloaded to various computing / processing devices from a computer-readable storage medium or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing / processing device.
[0145] The computer program instructions for performing the operations of the present application may be assembly instructions, instruction set architecture instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages and conventional procedural programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network or a wide area network, or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, by using the state information of the computer-readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field programmable gate array, or a programmable logic array, the electronic circuit can execute the computer-readable program instructions to implement various aspects of the present application.
[0146] Aspects of the present application are described herein with reference to the flowchart and / or block diagram according to embodiments of the present application. It should be understood that each block of the flowchart and / or block diagram, and the combination of blocks in the flowchart and / or block diagram, can be implemented by computer-readable program instructions.
[0147] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions, when executed by the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in one or more boxes of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that causes a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable medium storing the instructions comprises a manufacture, the instructions therein implementing various aspects of the functions / acts specified in one or more boxes of the flowchart and / or block diagram.
[0148] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other devices to produce a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other devices implement the functions / acts specified in one or more boxes of the flowchart and / or block diagram.
[0149] Each box in the flowchart or block diagram may represent a module, a segment of a program, or a part of an instruction, the module, segment of a program, or part of an instruction containing one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the boxes may occur in a different order than noted in the figures. For example, two consecutive boxes may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending upon the functions involved. It should also be noted that each box of the block diagrams and / or flowchart diagrams, and combinations of boxes in the block diagrams and / or flowchart diagrams, may be implemented by a special-purpose hardware-based system that performs the specified function or act, or by a combination of special-purpose hardware and computer instructions. It is well-known to those skilled in the art that implementation by hardware, implementation by software, and implementation by a combination of software and hardware are equivalent.
[0150] The embodiments of the present application provide a method, apparatus, device, medium and product for protecting article-related information. The beneficial effects are as follows: By determining the encryption order based on the speeds of different sections in the article transportation route and using multiple encryption algorithms to perform multiple encryptions on the article-related information, the problem of single encryption method is solved, and the security of the article-related information in logistics transportation is improved. It can re-determine the encryption order according to the actual logistics speed at each transfer node for encryption, greatly improving the encryption effect of the article-related information; By setting an identification code, nodes need to scan the identification code to access the private chain to obtain the article-related information, further reducing the risk of data leakage and ensuring the security of the article-related information; After the article transportation is completed, the private chain data is cleared to avoid data bloat and improve data processing efficiency. At the same time, the article-related information is misaligned and stored in the information databases of each node, and the article-related information stored in the information database of each node is encrypted, realizing diversified and secure storage of data; By using the logistics nodes of the article as the private chain nodes to construct a private chain for article transportation and building a consortium chain with several certification units, and authenticating the identity of the user to whom the article belongs through the consortium chain to start the article transportation when the authentication is passed, it can enable each node in the supply chain to quickly and securely authenticate the identity without passing through a centralized institution, reducing the time cost of identity authentication and ensuring the security of operations while reducing the risk of key data leakage.
[0151] The above is the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present application.
Claims
1. A method for protecting item-related information, characterized in that Including: Obtain the actual transportation route of the item from the aforementioned node to the target node; The aforementioned node is the starting node or the previous node of the target node; Determine the encryption order of a number of encryption algorithms according to the speed of the item on different segmented routes of the actual transportation route; wherein, there is a corresponding relationship between the segmented route and the encryption algorithm; Perform multiple encryption on the first item-related information of the item regarding the target node according to the encryption order to obtain the first encrypted information; Among them, the determining the encryption order of a number of encryption algorithms according to the speed of the item on different segmented routes of the actual transportation route includes: Divide the actual transportation route into several segmented routes, and calculate the speed of the item on each segmented route; Sort several segmented routes according to the speed to obtain the order of several segmented routes; According to the corresponding relationship and the order of several segmented routes, obtain the encryption order of a number of encryption algorithms; Among them, the item starts from the starting node, passes through several transfer nodes. When the item arrives at each transfer node, the transfer node re-encrypts the item-related information and then transports it to the next node until it reaches the termination node; the actual transportation route includes the coordinate information and the time information of the coordinate information during the item transportation process.
2. The method for protecting article-related information according to claim 1, wherein After obtaining the first encrypted information, the method further includes: Upload and store the first encrypted information and its corresponding first multiple decryption algorithm to a private chain built based on the nodes of the item; Confirm the next node of the target node and grant the decryption permission of the target node to the next node; Set the link address of the private chain as the identification code, so that when the item arrives at the next node and the next node has the decryption permission of the target node, access the private chain by scanning the identification code to obtain the first encrypted information and the first multiple decryption algorithm.
3. The method for protecting item-related information according to claim 2, characterized in that, Before performing multiple encryption on the first item-related information of the item regarding the target node according to the encryption order to obtain the first encrypted information, the method further includes: When having the decryption permission granted by the previous node, scan the identification code of the item to obtain the private chain address, and through the private chain address, obtain the second encrypted information of the item regarding the previous node and the corresponding second multiple decryption algorithm; Decrypt the second encrypted information according to the second multiple decryption algorithm to obtain the second item-related information of the item regarding the previous node; Store the second item-related information in the information library of the target node.
4. The method for protecting article-related information according to claim 3, characterized in that, The method further includes: When the user signs for the item, for each node, judge whether the item-related information stored in its information library regarding the previous node is consistent with the information after decrypting the encrypted information uploaded by the previous node to the private chain; If so, delete all the encrypted information stored in the private chain, and encrypt the information of the item stored in the information library of each node respectively according to the number of encryption algorithms.
5. The method for protecting item-related information according to claim 1, characterized in that, Before obtaining the transportation route of the item from the foregoing node to the target node, the method further includes: Using a number of certification units as nodes of a consortium blockchain, building a consortium blockchain, and deploying a smart contract to the consortium blockchain; the smart contract is used to generate a DID identity for a user; Authenticating the DID identity of the user to whom the item belongs through the consortium blockchain, and starting the transportation of the item when the DID identity authentication is passed.
6. An article-related information protection device, characterized in that, It includes: A route acquisition module, configured to acquire the actual transportation route of the item from the foregoing node to the target node; The foregoing node is the starting node or the previous node of the target node; An encryption order module, configured to determine the encryption order of a number of encryption algorithms according to the speed of the item on different segmented routes of the actual transportation route; wherein, there is a corresponding relationship between the segmented route and the encryption algorithm; A multiple encryption module, configured to perform multiple encryption on the first item-related information of the item with respect to the target node according to the encryption order to obtain first encrypted information; Among them, determining the encryption order of a number of encryption algorithms according to the speed of the item on different segmented routes of the actual transportation route includes: Dividing the actual transportation route into a number of segmented routes, and calculating the speed of the item on each segmented route; Sorting a number of the segmented routes according to the speed to obtain the order of a number of the segmented routes; According to the corresponding relationship and the order of a number of the segmented routes, obtaining the encryption order of a number of encryption algorithms; Among them, the item starts from the starting node, passes through a number of transit nodes. When the item reaches each transit node, the transit node re-encrypts the item-related information and then transports it to the next node until it reaches the termination node; the actual transportation route includes the coordinate information and the time information of the coordinate information during the item transportation process.
7. An item-related information protection device, characterized in that, It includes a processor and a memory. A computer program is stored in the memory, and the computer program is configured to be executed by the processor. When the processor executes the computer program, it implements the item-related information protection method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program. When the device where the computer-readable storage medium is located executes the computer program, it implements the item-related information protection method according to any one of claims 1 to 5.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the item-related information protection method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Article transaction method based on block chain, computer device and storage medium
CN113657972A
Multi-website route planning issuing method and device, computer equipment and storage medium
CN118278847A