A digital authorization method for a thermal management system
By constructing a digital authorization method for the thermal management system, the shortcomings of traditional systems in authorization management and data exchange are solved, enabling the effective exchange of aircraft thermal conduction parameters and thermal model data, and improving the system's privacy and application scope.
Patent Information
- Application Number
- CN202411234109.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-04
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-09-04
AI Technical Summary
Traditional thermal management systems are inadequate in terms of authorized management, remote monitoring, and intelligent control, making it difficult to meet the exchange of data such as aircraft thermal conduction parameters and flight process thermal models within the thermal management system.
A digital authorization method for a thermal management system is adopted. By querying the global accumulator instance, a system global accumulator is constructed, and thermal management user accumulators are initialized as needed. Access authorization is performed based on the user accumulators, data VC credentials are issued, and data exchange is realized.
It improves the privacy and application scope of data exchange, and ensures the effective exchange of aircraft thermal conduction parameters and flight process thermal model data within the thermal management system.
Smart Images

Figure CN119357932B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of thermal management technology, and more particularly to a digital authorization method for a thermal management system. Background Technology
[0002] Currently, with the rapid development of aircraft, the importance of thermal management systems is becoming increasingly prominent. However, traditional thermal management systems have shortcomings in terms of authorized management, remote monitoring, and intelligent control, making it difficult to meet the exchange of data such as aircraft thermal transfer parameters and thermal models of the aircraft's flight process within the thermal management system.
[0003] Therefore, it is essential to propose a digital authorization method for the thermal management system that facilitates the exchange of data such as aircraft thermal conduction parameters and thermal models of the aircraft flight process within the thermal management system. Summary of the Invention
[0004] The purpose of this invention is to provide a digital authorization method for a thermal management system, which aims to solve the technical problems of the shortcomings of existing thermal management systems in terms of authorization management, remote monitoring and intelligent control, and the difficulty in meeting the technical requirements for exchanging data such as aircraft thermal conduction parameters and aircraft flight process thermal models within the thermal management system.
[0005] To achieve the above objectives, the present invention employs a digital authorization method for a thermal management system, comprising the following steps:
[0006] Query global accumulator instances, build system global accumulators, and initialize hot management user accumulators as needed;
[0007] Determine the access trust domain relationship based on the membership proof of the hot management user accumulator;
[0008] Access authorization is based on the user accumulator.
[0009] In the step of determining the access trust domain relationship based on the hot management user accumulator member proof:
[0010] Direct access is granted based on the thermal management user accumulator, and data VC credentials are issued.
[0011] Specifically, in the step of direct access based on the thermal management user accumulator and issuing data VC credentials:
[0012] Initiate a network request to apply for aircraft thermal transfer data thermal management system data, submit access parameters, and verify the digital identity of thermal management users; the verification content includes the digital identity membership certificate of the global dynamic accumulator and the user dynamic accumulator;
[0013] Once a member's proof is deemed valid, the data VC is generated.
[0014] In the step of access authorization based on the user accumulator:
[0015] Authorization is requested based on the user accumulator, and permission VC credentials and data VC credentials are issued.
[0016] In the steps of requesting authorization and issuing permission VC credentials and data VC credentials based on the user accumulator:
[0017] Submit the application data list to initiate a VC application; the application data list includes DID verification parameters, including the applicant's ID, the holder's ID, and the accumulator witness value w;
[0018] Perform global accumulator membership verification on the DID of thermal management data applicants, query the DID document of applicant users and perform integrity verification;
[0019] Obtain the DID verification result of the thermal management data applicant, and generate the data permission VC to the thermal management data applicant based on the list of application data submitted by the thermal management data applicant;
[0020] After obtaining the VC permission, perform an integrity check, generate a new request list based on the request list and the permission list, and send a network request.
[0021] The applicant's DID is verified again, and the verification result is sent to the thermal management data holder. The thermal management data holder then generates the data VC and sends it to the applicant.
[0022] Among the steps of querying the global accumulator instance, constructing the system global accumulator, and initializing the hot management user accumulator on demand:
[0023] Query the global accumulator status value and the global accumulator running instance, and perform operations.
[0024] Among the steps involving querying the global accumulator status value, the global accumulator running instance, and performing operations:
[0025] If no global accumulator instance is created, the global accumulator is initialized, and the initial accumulated value is stored on the state value chain.
[0026] Among the steps involving querying the global accumulator status value, the global accumulator running instance, and performing operations:
[0027] If a global accumulator instance already exists, then query the user accumulator status value and the user accumulator running instance based on the hot management user did number chain.
[0028] Among the steps involving querying the global accumulator status value, the global accumulator running instance, and performing operations:
[0029] If no user accumulator instance based on the hot management user's ID number is created, the hot management user accumulator is initialized, and the initial accumulated value is stored on the state value chain.
[0030] This invention discloses a digital authorization method for a thermal management system. It constructs a system global accumulator by querying global accumulator instances and initializes thermal management user accumulators as needed. It determines access trust domain relationships based on thermal management user accumulator member proofs and authorizes access based on the user accumulator. This invention offers high privacy, focuses on data privacy, and has a wide range of applications. Through the above method, it facilitates the exchange of data such as aircraft thermal conduction parameters and aircraft flight process thermal models within the thermal management system. Attached Figure Description
[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 This is a schematic diagram of the thermal management trust domain authorization process of the present invention.
[0033] Figure 2 This is a schematic diagram of the VC authorization process in the thermal management system of this invention.
[0034] Figure 3 This is a schematic diagram of the direct data access process for thermal management according to the present invention.
[0035] Figure 4 This is a schematic diagram of the process for obtaining authorization to apply for access to the thermal management application of this invention.
[0036] Figure 5 This is a flowchart of the steps of the digital authorization method for the thermal management system of the present invention. Detailed Implementation
[0037] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application.
[0038] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0039] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0040] Please see Figures 1-5 ,in Figure 1 This is a flowchart illustrating the authorization process for the thermal management trust domain. Figure 2 This is a flowchart illustrating the VC authorization process in a thermal management system. Figure 3 This is a flowchart illustrating the direct data access process for thermal management. Figure 4 This is a flowchart illustrating the process of requesting authorized access for thermal management. Figure 5 This is a flowchart of the steps involved in the digital authorization method for a thermal management system.
[0041] This invention provides a digital authorization method for a thermal management system, comprising the following steps:
[0042] S100: Query the global accumulator instance, build the system global accumulator, and initialize the hot management user accumulator as needed;
[0043] S200: Determine the access trust domain relationship based on the membership proof of the hot management user accumulator;
[0044] S300: Access authorization based on user accumulator.
[0045] In this embodiment, the global accumulator instance is first queried to construct the system global accumulator and the thermal management user accumulator is initialized as needed. Then, the access trust domain relationship is determined based on the membership proof of the thermal management user accumulator. Finally, access authorization is performed based on the user accumulator. This invention has high privacy, focuses on data privacy, and has a wide range of applications. Through the above method, it is beneficial to exchange data such as aircraft thermal conduction parameters and aircraft flight process thermal models within the thermal management system.
[0046] Furthermore, in the steps of querying the global accumulator instance, constructing the system global accumulator, and initializing the hot management user accumulator on demand:
[0047] Query the global accumulator status value and the global accumulator running instance, and perform operations accordingly;
[0048] If no global accumulator instance is created, the global accumulator is initialized, and the initial accumulated value is stored on the state value chain.
[0049] If a global accumulator instance already exists, the user accumulator status value and the user accumulator running instance are queried from the hot management user did number chain.
[0050] If no user accumulator instance based on the hot management user ID number is created, the hot management user accumulator is initialized, and the initial accumulated value is stored on the state value chain.
[0051] In this implementation, the global accumulator state value and the global accumulator running instance are queried on the chain; if no global accumulator instance has been created, the global accumulator is initialized, referring to the formula. The secret parameter k is a random number, stored by the user, a g This is the initial accumulated value of the global accumulator, which is stored on the state value chain. If a global accumulator instance already exists, the user accumulator state value and the running instance of the user accumulator are queried from the chain based on the user's did number. If not, a user accumulator instance is created based on the user's did number, and the user accumulator is initialized, with the initial accumulated value stored on the state value chain.
[0052] Furthermore, in the step of determining the access trust domain relationship based on the hot management user accumulator membership proof:
[0053] Initiate a network request to apply for aircraft thermal transfer data thermal management system data, submit access parameters, and verify the digital identity of thermal management users; the verification content includes the digital identity membership certificate of the global dynamic accumulator and the user dynamic accumulator;
[0054] Once a member's proof is deemed valid, the data VC is generated.
[0055] In this embodiment, direct access is performed based on the hot management user accumulator, and a data VC certificate is issued. The specific process is as follows: obtain the running instance of the user accumulator and perform membership verification; preset the logical value of the verification result, which includes 1 and 0, where 1 indicates that the verification is successful and 0 indicates that the verification is unsuccessful; if the membership verification result is 1, apply for authorization and issue a permission VC certificate and a data VC certificate; if the membership verification result is not 1, perform direct access and issue a data VC certificate.
[0056] When thermal management user A interacts with thermal management user B, by determining whether the DID entity is within the trust domain of another DID entity, data access permissions with data sovereignty over that entity can be obtained. For example... Figure 1 As shown: s, r, w, d, and c represent data sovereignty, read permission, write permission, delete permission, and create permission, respectively. The scope of the trust relationship includes the r, w, d, and c domains of the user data domain, as described below:
[0057]
[0058] If the heat management user x has s permission, then it means that user x also has r, w, d, and c permissions.
[0059] If hot management user y trusts hot management user x and x has s permission for data A, then hot management user y will have r permission for data A, as described below:
[0060]
[0061] Other permissions require entities to obtain them by requesting authorization to access data; specifically, this involves the application and issuance of VC (Volume Control Provider) permissions. For details on VC authorization rules, please refer to [link / reference needed]. Figure 2 .
[0062] Trusted entities can obtain read permissions (r) for data with the building owner's s permissions through direct data access, while other permissions require requesting authorization for data access, primarily implemented through issuing VCs. Similarly, if an entity is not within another entity's trust domain, data access must be granted through authorization requests.
[0063] In this embodiment of the invention, direct access to reference is available. Figure 4 The specific steps include:
[0064] The applicant initiates a network request for application data and submits access parameters;
[0065] Verify the legitimacy of the DID identity;
[0066] The applicant returns the DID verification result, and the holder obtains the verification result;
[0067] The holder generates data VC after verifying its legitimacy.
[0068] Upload data (VC);
[0069] Applicants obtain data VC.
[0070] The data table for VC is shown in Table 1:
[0071] Fields describe context Context description did User DID identifier type Types of VCs issuer The issuer's did issuranceDate Date of Issuance expirationDate Expiration time credentialSubjectId Certificate payload number proofId Number of integrity encryption proof
[0072] Table 1
[0073] The specific field descriptions for credentailSubject and proof are shown in Tables 2 and 3:
[0074] Fields describe Did User DID identifier shortDescription summary attributes voucher content type Encryption Algorithm Types
[0075] Table 2
[0076] Fields describe Creator Creator's DID identifier type Encryption Algorithm Types signatureValue Signature value
[0077] Table 3
[0078] Furthermore, in the step of granting access based on the user accumulator:
[0079] Submit the application data list to initiate a VC application; the application data list includes DID verification parameters, including the applicant's ID, the holder's ID, and the accumulator witness value w;
[0080] Perform global accumulator membership verification on the DID of thermal management data applicants, query the DID document of applicant users and perform integrity verification;
[0081] Obtain the DID verification result of the thermal management data applicant, and generate the data permission VC to the thermal management data applicant based on the list of application data submitted by the thermal management data applicant;
[0082] After obtaining the VC permission, perform an integrity check, generate a new request list based on the request list and the permission list, and send a network request.
[0083] The applicant's DID is verified again, and the verification result is sent to the thermal management data holder. The thermal management data holder then generates the data VC and sends it to the applicant.
[0084] In this embodiment, requesting authorized access is as follows: Figure 4As shown, the process includes: granting authorization based on the user accumulator, and issuing permission VC credentials and data VC credentials; the specific process is as follows: submitting a request data list to initiate a VC request; the request data list includes DID verification parameters, including the applicant's DID, the holder's DID, and the accumulator witness value w; performing global accumulator membership proof on the thermal management data applicant's DID, querying the applicant's user's DID document and performing integrity verification; if the verification fails, a failure status is returned, and if successful, the next step is executed; the thermal management data holder obtains the thermal management data applicant's DID verification result, generates the data permission VC based on the request data list submitted by the thermal management data applicant, and sends it to the thermal management data applicant; after obtaining the permission VC, the thermal management data applicant performs integrity verification, generates another request list based on the request list and permission list, and sends a network request; the thermal management data applicant's DID is verified again, and the verification result is sent to the thermal management data holder, who then generates the data VC and sends it to the applicant.
[0085] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein.
[0086] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope.
Claims
1. A digital authorization method for a thermal management system, characterized in that, Includes the following steps: Query global accumulator instances, build system global accumulators, and initialize hot management user accumulators as needed; The access trust domain relationship is determined based on the membership proof of the hot management user accumulator; direct access is granted based on the hot management user accumulator, and a data VC certificate is issued. Initiate a network request to apply for aircraft thermal transfer data thermal management system data, submit access parameters, and verify the digital identity of thermal management users; the verification content includes the digital identity membership certificate of the global dynamic accumulator and the user dynamic accumulator; Once the member's proof result is verified as valid, data VC is generated; Access authorization is performed based on the user accumulator, and permission VC credentials and data VC credentials are issued. Submit the application data list to initiate a VC application; the application data list includes DID verification parameters, including the applicant's ID, the holder's ID, and the accumulator witness value w; Perform global accumulator membership verification on the DID of thermal management data applicants, query the DID document of applicant users and perform integrity verification; Obtain the DID verification result of the thermal management data applicant, and generate the data permission VC to the thermal management data applicant based on the list of application data submitted by the thermal management data applicant; After obtaining the VC permission, perform an integrity check, generate a new request list based on the request list and the permission list, and send a network request. The applicant's DID is verified again, and the verification result is sent to the thermal management data holder. The thermal management data holder then generates the data VC and sends it to the applicant.
2. The digital authorization method for the thermal management system as described in claim 1, characterized in that, In the steps of querying the global accumulator instance, building the system global accumulator, and initializing the hot management user accumulator on demand: Query the global accumulator status value and the global accumulator running instance, and perform operations.
3. The digital authorization method for the thermal management system as described in claim 2, characterized in that, In the steps of querying the global accumulator status value, the global accumulator running instance, and performing operations: If no global accumulator instance is created, the global accumulator is initialized, and the initial accumulated value is stored on the state value chain.
4. The digital authorization method for the thermal management system as described in claim 2, characterized in that, In the steps of querying the global accumulator status value, the global accumulator running instance, and performing operations: If a global accumulator instance already exists, then query the user accumulator status value and the user accumulator running instance based on the hot management user did number chain.
5. The digital authorization method for a thermal management system as described in claim 2, characterized in that, In the steps of querying the global accumulator status value, the global accumulator running instance, and performing operations: If no user accumulator instance based on the hot management user's ID number is created, the hot management user accumulator is initialized, and the initial accumulated value is stored on the state value chain.
Citation Information
Patent Citations
Credential verification and issuance through credential service providers
CN113853775A
User data sharing method and device
CN115664759A