Supply chain data security sharing method based on block chain

By defining user roles and permissions in the supply chain system, combining distributed authentication and machine learning models, and adjusting access control policies in real time, the problem of inflexible access control in the existing technology is solved, and efficient and secure data sharing and access control are achieved.

CN119961899APending Publication Date: 2025-05-09容桢森
View PDF 0 Cites 6 Cited by

Patent Information

Application Number
CN202411840995.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The prior art is difficult to achieve efficient and flexible access control in the secure sharing of supply chain data, resulting in a reduction in overall effect.

Method used

By defining user roles and corresponding permissions in the supply chain system, an access control list is generated, and combined with distributed authentication, multi-factor authentication, predefined rules and machine learning models, user roles and permissions are adjusted in real time, hybrid access control policies are used to match, access decisions are generated, and data decryption or maintain encryption operations are performed to perform integrity checks and consistency verification.

Benefits of technology

It realizes dynamic adjustment of permissions and improves the security and flexibility of access control, ensures that the system can quickly respond to user behavior and environmental changes, adapt to complex business needs and changing operating environments, and ensures the efficient operation of the supply chain system under high security requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961899A_ABST
    Figure CN119961899A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of block chains, in particular to a supply chain data security sharing method based on a block chain. The method comprises the following steps: firstly, defining user roles and corresponding permissions in a supply chain system to generate an access control list; and then, collecting historical behavior data, access records and current system states of the requesting users, and adjusting roles and permissions of the users in real time by using predefined rules and a machine learning model. And then, based on the hybrid access control strategy, matching an access request of a user, generating an access decision, then generating an access operation instruction, executing an operation of data decryption or data encryption maintenance, and after the operation is completed, carrying out integrity check and consistency verification. And finally, collecting all record data generated in the access control process to optimize an updating mechanism of the access control list and realize continuous improvement and optimization. According to the invention, through dynamic adjustment of the access authority, the flexibility and efficiency of access control of the supply chain system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain, and in particular to a method for securely sharing supply chain data based on blockchain. Background Art

[0002] Supply chain data security sharing refers to the secure sharing of information and data between different links and participants in the supply chain, which is essential for improving efficiency, reducing errors and preventing fraud. The realization of supply chain data security sharing is inseparable from technologies such as data security, data integrity, data privacy and mutual trust mechanism.

[0003] Blockchain technology, with its high trust and decentralization characteristics, can solve the problems of transparency, security and efficiency of data sharing in the supply chain. Therefore, it is widely used in the application scenarios of secure sharing of supply chain data, such as product traceability and scope, supplier qualification certification, logistics and transportation safety, smart contracts and automation, emergency response and supply chain resilience.

[0004] Existing technologies use blockchain technology to provide solutions to improve supply chain information management and data sharing. For example, by establishing a chain-network hybrid chain distributed architecture, a hybrid consensus mechanism, and smart contracts, information collaborative management of the entire supply chain is achieved, and data consistency, security, and mutual trust are improved. Another example is the use of Fabric-CA center and fine-grained access policies to ensure data encryption and access control, avoid the risks of traditional key management, and improve the security and efficiency of data sharing. In general, existing technologies have improved the management, security, and sharing capabilities of supply chain data through blockchain technology, but there are still defects. Problems such as complex configuration management and authentication mechanisms make it difficult for existing technologies to achieve efficient and flexible access control, reducing the overall effect of secure sharing of supply chain data.

[0005] To this end, a blockchain-based supply chain data security sharing method is proposed. Summary of the invention

[0006] The purpose of the present invention is to provide a supply chain data security sharing method based on blockchain. First, by defining the user roles and corresponding permissions in the supply chain system, an access control list is generated. Receive user access requests, collect user identity information and resource request information, and verify the user identity through distributed identity authentication and multi-factor authentication methods. Then, collect the user's historical behavior data, access records and current system status, and use predefined rules and machine learning models to adjust the user's role and permissions in real time. Then, based on the hybrid access control strategy, match the user's access request and generate an access decision, and then generate an access operation instruction, perform data decryption or keep data encrypted, and perform integrity check and consistency verification after the operation is completed.

[0007] To achieve the above objectives, the present invention provides a supply chain data security sharing method based on blockchain, comprising:

[0008] According to the type of supply chain system, define the user roles and corresponding permissions in the system and generate an access control list.

[0009] Receive user access requests, collect user identity information and resource request information, and verify the user identity through distributed identity authentication and multi-factor authentication methods.

[0010] Collect the user's historical behavior data, historical access records and current system status, adjust the user's role and permissions in real time through predefined rules and machine learning models, and update the latest access control list;

[0011] The user role, dynamic attributes and real-time context information are combined, the user access request is matched with the latest access control list through a hybrid access control strategy, and an access decision is generated; the user access request and the access decision are recorded as an access log.

[0012] Generate a corresponding access operation instruction based on the access decision, and the access operation instruction includes two situations where the access decision is allowed and denied: when the access decision is allowed, the supply chain system data is decrypted; when the access decision is denied, the supply chain system data remains encrypted and is inaccessible.

[0013] After executing the access operation instruction, the supply chain system data is checked for integrity and consistency.

[0014] Collect all record data generated by the supply chain system in the access control process and optimize the update mechanism of the access control list.

[0015] Furthermore, the role of each user is defined according to the participant information in the supply chain system; the role definition is based on the function and business requirements of the user in the supply chain system.

[0016] The initial permissions include:

[0017] Data access rights: the specific data and resources that users can access;

[0018] Data operation permissions: the types of operations that users can perform on data, including reading, creating, modifying, deleting, etc.;

[0019] System function permissions: specify the system function modules that users can access and use, including order management, inventory management, system settings and auditing functions;

[0020] Access time and location permissions: limit the time and location at which users can access the system.

[0021] Based on the defined roles and assigned permissions, an access control list is generated; the access control list is used to associate user request information with the corresponding initial permissions to ensure that users can operate according to their roles and permissions when accessing system resources.

[0022] The access control list structure of the supply chain system is:

[0023] ACL=(ID user ,Role user ,Res,Act,Perm,C);

[0024] ACL stands for Access Control List, ID user Indicates user identity, Role user Res represents the user role, Res represents the resource requested for access, Act represents the requested operation, and Perm represents the permission type for the operation, including P A and P D , respectively indicating that the execution operation is allowed and the execution operation is rejected; C represents an additional condition.

[0025] Furthermore, a user access request is received, user identity information and resource request information are collected, and the user identity is verified through distributed identity authentication and multi-factor authentication methods; the user access request includes information such as user identity, requested resource type, requested operation type, requested timestamp and request source.

[0026] First, identify and classify the types of access requests, including sensitive data access requests, general data access requests, and system function calls.

[0027] After confirming the request type, select an identity security authentication combination method; the identity security authentication includes distributed identity authentication (DID) and multi-factor authentication (MFA).

[0028] Verify the identity credentials provided by the user to ensure the authenticity and validity of the user's identity; if the request type is a sensitive data access request, multi-factor authentication (MFA) is used to further authenticate the user. If the authentication is successful, the next processing stage will be entered; if the authentication fails, the access request will be immediately rejected.

[0029] Furthermore, the updating process of the latest access control list includes data collection and preprocessing, real-time behavior analysis, anomaly detection and risk assessment, and dynamic permission adjustment.

[0030] The data collection and preprocessing includes: collecting user behavior data, historical access patterns and historical system status information to form a first analysis data set.

[0031]

[0032] Among them, D ANA represents the first analysis data set, u i represents the i-th user, B(t) represents user u i The behavioral data at time t, b j (t) represents the jth behavior feature; H(u i ) represents user u i The historical access pattern, S(t) represents the system state at time t, b k (t) represents the kth system state parameter.

[0033] Calculate the mean and standard deviation for each behavioral feature in the behavioral data:

[0034]

[0035] where μ j and σ j Represent the mean and standard deviation of the j-th behavioral feature respectively.

[0036] The real-time behavior analysis includes behavior assessment and pattern matching;

[0037] The behavior evaluation step is to set a threshold and a time window. If the behavior feature score exceeds the threshold within the time window, it is marked as abnormal.

[0038] Abnormal1=(b j (t)-μ j |>T j )∧(t'∈[t,t+Δt]);

[0039] Among them, Abnormal1 represents the abnormal judgment of behavior assessment, T j represents the threshold value, and Δt represents the time window;

[0040] The pattern matching is to calculate the cosine similarity between the behavior data and the historical access pattern, and if it is lower than a preset threshold, it is marked as abnormal;

[0041]

[0042] Among them, Abnormal2 indicates the abnormal judgment of pattern matching, T θ represents the preset threshold, and B'(t) represents the normalized behavior data.

[0043] The anomaly detection and risk assessment include anomaly detection and risk score calculation;

[0044] The steps of anomaly detection are: collecting historical behavior data to train the isolation forest model to obtain an anomaly detection model; evaluating the anomaly score of the behavior data through the anomaly detection model, and if the anomaly score exceeds the anomaly threshold, it is judged as an anomaly.

[0045] E(B(t))=IF(B(t));

[0046] Wherein, E(B(t)) represents the abnormal score of the behavior data.

[0047] The step of calculating the risk score is: comprehensively calculating the behavior evaluation, the pattern matching and the system status to calculate the risk score.

[0048]

[0049] Among them, R(u i ) represents the user u i The risk score of the system is represented by S'(t), S'(t) represents the normalized system state, and the ω1, ω2 and ω3 levels represent the adjustment coefficients of behavior evaluation, pattern matching and system state.

[0050] The process of dynamic permission adjustment includes: setting a risk score threshold, dynamically adjusting the user's permission by comparing the risk score with the risk score threshold, and updating the access control list.

[0051]

[0052] Among them, T R represents the risk score threshold, P(u i ) indicates the adjusted permissions, ACL (u i ) indicates the latest access control list, Perm initial Indicates the initial permission configuration.

[0053] The generation process of the access decision includes: the latest access control list structure of the supply chain system is:

[0054] ACL(u i )=(Sub(u i ),Res(u i ),Act(u i ),Perm(u i ),C(u i ));

[0055] Among them, ACL(u i) indicates the latest access control list, Sub(u i ) represents the request body, Res(u i ) indicates the resource requested for access, Act(u i ) indicates the execution of an operation, Perm(u i ) indicates the permission type for the execution of the operation; C(u i ) indicates additional conditions.

[0056] Further, receiving the access request of the user and collecting the user role and resource request information include:

[0057] AS=(U,R,O,T,A);

[0058] Among them, AS represents the request information of the user, U represents the identifier of the user, R represents the identifier of the resource requested to be accessed, O represents the type of operation requested to be performed, T represents the initiation time of the access request, and A represents the dynamic attribute.

[0059] Dynamic attributes and real-time context information related to the user request are collected, matched with the latest access control list, and an access decision is generated through a hybrid access control strategy.

[0060] The hybrid access control strategy is:

[0061]

[0062] The access request information and the corresponding access decision are recorded as an access log.

[0063] The step of formulating an access operation instruction according to the access decision comprises: receiving the access decision, generating an instruction according to the access decision:

[0064]

[0065] The decryption instruction includes the location of the target data and the corresponding decryption key information;

[0066] The target data is decrypted and converted into plain text by calling a corresponding decryption algorithm according to the decryption key information.

[0067] Furthermore, after executing the access operation instruction on the supply chain system data, the steps of performing integrity check and consistency verification include:

[0068] Performing a hash operation on the original supply chain system data to generate a hash value of the original data;

[0069] Generating a decrypted data hash value for the decrypted supply chain system data;

[0070] The original data hash value and the decrypted data hash value are compared to verify the integrity of the supply chain data.

[0071] When the original data hash value is the same as the decrypted data hash value, the integrity verification passes; when the original data hash value is different from the decrypted data hash value, the integrity verification fails;

[0072] Perform data structure analysis on the decrypted data, perform field verification and extraction; perform multi-source comparison between the decrypted data fields and the original data fields in each node and database in the supply chain system;

[0073] When the decrypted data field is consistent with the original data field in multi-source comparison, the consistency verification passes; when the decrypted data field is inconsistent with the original data multi-source field comparison, the consistency verification fails.

[0074] Furthermore, after the access is completed, all record data generated by the supply chain system in the access control process are collected, including user access behavior logs, abnormal access behavior logs, permission change logs and system status logs; and the update mechanism of the access control list is continuously optimized based on the record data.

[0075] Compared with the prior art, the present invention has the following beneficial effects:

[0076] 1. The present invention collects user behavior data, historical access models, and historical system status information, and analyzes the collected data in real time through predefined rules and machine learning models to evaluate whether the user's current operation conforms to their normal behavior patterns and system requirements. According to the results of the real-time analysis, the user's role and permissions are dynamically adjusted and the access control list is updated. This method ensures that the configuration of permissions matches the user's current behavior, enables the system to quickly respond to user behavior and environmental changes, avoids permission lag problems, and improves the security and flexibility of access control.

[0077] 2. The present invention collects the user's dynamic attributes and real-time context information, combines this information with the user's role and request content, and adopts a hybrid access control strategy to combine role-based access control with basic attribute access control for comprehensive evaluation. For each access request, the system will generate a specific access decision based on the current role, dynamic attributes and context information. This method improves the accuracy and flexibility of access control, can cope with complex business needs and changing operating environments, and ensures the efficient operation of the supply chain system under high security requirements.

[0078] 3. The present invention generates an access control list by defining user roles and permissions, and then confirms the user identity through distributed identity authentication and multi-factor authentication. Then, user behavior data, access patterns and system status information are collected in real time, and user permissions are dynamically adjusted using predefined rules and machine learning models, and the access control list is updated. Then, a hybrid access control strategy is adopted to make access decisions based on roles and dynamic attributes, and perform corresponding data decryption or encryption operations. After performing a data integrity check after the operation is completed, optimization is performed by continuously collecting access logs and system status data. The present invention effectively improves the flexibility and responsiveness of access control, enhances the security and accuracy of the system, and ensures that the system can continue to operate efficiently and safely in a complex environment, adapting to changing business needs and security challenges. BRIEF DESCRIPTION OF THE DRAWINGS

[0079] Figure 1 A flowchart of a blockchain-based supply chain data security sharing method provided in an embodiment of the present invention;

[0080] Figure 2 A schematic diagram of the structure of an aquatic product supply chain system provided by an embodiment of the present invention;

[0081] Figure 3 A schematic diagram of the structure of an access control list update mechanism provided by an embodiment of the present invention;

[0082] Figure 4 A schematic diagram of the structure of a hybrid access control strategy provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0083] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0084] The present invention provides a supply chain data security sharing method based on blockchain. For the specific method flow chart, please refer to Figure 1 .

[0085] Embodiment 1

[0086] As an embodiment of the present invention, refer to Figure 1 S10 in the embodiment is used to define the user roles and corresponding permissions in the system according to the type of the supply chain system and generate an access control list (ACL). This embodiment describes a specific implementation method for the aquatic product supply chain system A.

[0087] Reference Figure 2 , Figure 2 This is a schematic diagram of the structure of an aquatic product supply chain system provided in this embodiment. First, the different participants in the aquatic product supply chain system are determined, the user roles in the system are defined, and initial permissions are assigned according to the roles. Role definition and permission assignment are based on the user's functions and business needs in the aquatic product supply chain system.

[0088] The initial permissions include:

[0089] Data access rights: the specific data and resources that users can access;

[0090] Data operation permissions: the types of operations that users can perform on data, including reading, creating, modifying, deleting, etc.;

[0091] System function permissions: specify the system function modules that users can access and use, including order management, inventory management, system settings and auditing functions;

[0092] Access time and location permissions: limit the time and location at which users can access the system.

[0093] Table 1 is an example of role definition and authority allocation of the aquatic product supply chain system provided in this embodiment.

[0094] Table 1 Example of role definition and authority allocation in aquatic product supply chain system

[0095]

[0096] Based on the defined roles and assigned permissions, an access control list is generated; the access control list is used to associate user request information with the corresponding initial permissions to ensure that users can operate according to their roles and permissions when accessing system resources.

[0097] The access control list structure of the aquatic product supply chain system is:

[0098] ACL=(ID user ,Role user ,Res,Act,Perm,C);

[0099] ACL stands for Access Control List, ID user Indicates user identity, Role user Res represents the user role, Res represents the resource requested for access, Act represents the requested operation, and Perm represents the permission type for the operation, including P A and P D, respectively indicating that the execution operation is allowed and the execution operation is rejected; C represents an additional condition.

[0100] This embodiment first defines each user role and its corresponding permissions according to the type of supply chain system. In combination with the functions and business requirements of each role in the supply chain, the system generates an initial access control list (ACL) to clarify the resources that each role can access, the operations that can be performed, and the restrictions. This approach enables the system to ensure that the permission configuration is highly matched with the functions of each role from the beginning, avoiding the problem of excessive or insufficient permissions. This clear division of permissions not only improves the security of the system, but also simplifies subsequent permission management and adjustment work, allowing each participant in the supply chain to perform their duties efficiently and safely, ensuring the reliability of data and the stability of the system.

[0101] Further, refer to Figure 1 S20 in the example, S20 is used to receive a user access request, collect user identity information and resource request information, and verify the user identity through distributed identity authentication and multi-factor authentication methods; the user access request includes information such as user identity, requested resource type, requested operation type, requested timestamp, and request source.

[0102] First, identify and classify the types of access requests, including sensitive data access requests, general data access requests, and system function calls. After confirming the request type, select a combination of identity security authentication methods; the identity security authentication includes distributed identity authentication (DID) and multi-factor authentication (MFA).

[0103] Verify the identity credentials provided by the user to ensure the authenticity and validity of the user's identity; if the request type is a sensitive data access request, multi-factor authentication (MFA) is used to further authenticate the user. If the authentication is successful, the next processing stage will be entered; if the authentication fails, the access request will be immediately rejected.

[0104] Further, refer to Figure 1 S30 in the example is used to collect users’ historical behavior data, historical access records, and resource request information, adjust users’ roles and permissions in real time through predefined rules and machine learning models, and update access control lists.

[0105] Reference Figure 3 , Figure 3A schematic diagram of the structure of an access control list update mechanism provided for this embodiment. The access control list update mechanism includes data collection and preprocessing, real-time behavior analysis, anomaly detection and risk assessment, and dynamic permission adjustment; wherein, the data collection and preprocessing includes: collecting user behavior data, historical access patterns, and historical system status information to form a first analysis data set. Table 2, Table 3, and Table 4 are partial examples of user behavior data examples, historical access pattern examples, and historical system status information, respectively.

[0106] Table 2 User behavior data examples

[0107]

[0108] Table 3 Historical access pattern examples

[0109]

[0110] Table 4 Historical system status information

[0111]

[0112] The first analysis data set is symbolically represented as:

[0113]

[0114] Among them, D ANA represents the first analysis data set, u i represents the i-th user, B(t) represents user u i The behavioral data at time t, b j (t) represents the jth behavior feature; H(u i ) represents user u i The historical access pattern, S(t) represents the historical system state at time t, b k (t) represents the kth system state parameter.

[0115] Calculate the mean and standard deviation for each behavioral feature in the behavioral data:

[0116]

[0117] where μ j and σ j Respectively represent the mean and standard deviation of the jth behavior feature, b j (t) represents the jth behavior feature.

[0118] This embodiment collects user behavior data, historical access patterns, and system status information, and forms a structured analysis data set after cleaning, formatting, and denoising. These data provide a basis for subsequent behavior analysis, anomaly detection, and permission adjustment, enabling the system to better identify user behavior patterns, detect anomalies, and dynamically adjust access rights, thereby ensuring the effectiveness of access control policies and the overall security of the system.

[0119] The real-time behavior analysis includes behavior assessment and pattern matching;

[0120] The behavior evaluation step is to set a threshold and a time window. If the behavior feature score exceeds the threshold within the time window, it is marked as abnormal.

[0121] Abnormal1=(b j (t)-μ j |>T j )∧(t'∈[t,t+Δt]);

[0122] Among them, Abnormal1 represents the abnormal judgment of behavior assessment, T j represents the threshold value, and Δt represents the time window;

[0123] The pattern matching is to calculate the cosine similarity between the behavior data and the historical access pattern, and if it is lower than a preset threshold, it is marked as abnormal;

[0124]

[0125] Among them, Abnormal2 indicates the abnormal judgment of pattern matching, T θ represents the preset threshold, and B'(t) represents the normalized behavior data.

[0126] This embodiment quickly identifies the rationality of user operations, analyzes whether user behavior is in line with expectations, and determines whether there are potential security threats through comprehensive evaluation of current user behavior, historical access patterns, and contextual information. Through real-time behavior analysis, the system can quickly identify and respond to abnormal behavior to ensure that effective measures are taken before potential risks occur. Real-time analysis not only improves the system's ability to respond to dynamic changes, but also enhances the processing accuracy of complex access requests.

[0127] The anomaly detection and risk assessment include anomaly detection and risk score calculation;

[0128] The steps of anomaly detection are: collecting historical behavior data to train the isolation forest model to obtain an anomaly detection model; evaluating the anomaly score of the behavior data through the anomaly detection model, and if the anomaly score exceeds the anomaly threshold, it is judged as an anomaly.

[0129] E(B(t))=IF(B(t));

[0130] Wherein, E(B(t)) represents the abnormal score of the behavior data.

[0131] The step of calculating the risk score is: comprehensively calculating the behavior evaluation, the pattern matching and the system status to calculate the risk score.

[0132]

[0133] Among them, R(u i ) represents user u i The risk score, S'(t) is the normalized system state, and the levels of ω1, ω2 and ω3 represent the adjustment coefficients of behavior assessment, pattern matching and system state.

[0134] This embodiment uses predefined rules and machine learning models to conduct in-depth analysis of user behavior. First, based on historical data and current behavior, possible abnormal activities are detected; then risk scores are calculated to assess the potential threats of these abnormal behaviors to system security. Finally, based on the risk score, it is decided whether user permissions need to be adjusted or further security measures need to be triggered. This method enables the system to not only capture obvious abnormal behaviors, but also detect more subtle threats. The introduction of risk scores enables the system to accurately measure the severity of each threat and take corresponding protective measures. This stage significantly improves the system's preventive defense capabilities and ensures the security of supply chain data and the accuracy of access control.

[0135] The process of dynamic permission adjustment includes: setting a risk score threshold, dynamically adjusting the user's permission by comparing the risk score with the risk score threshold, and updating the access control list.

[0136]

[0137] Among them, T R represents the risk score threshold, P(u i ) indicates the adjusted permissions, ACL (u i ) indicates the latest access control list, Perm initial Indicates the initial permission configuration.

[0138] This embodiment automatically adjusts the user's access rights based on the results of real-time analysis and risk assessment. First, the user's risk score is compared with the preset threshold, and then the user's role or permission level is dynamically adjusted based on the result, and the access control list (ACL) is updated. This adjustment process is immediate, ensuring that the permission configuration can quickly respond to changes in user behavior and system environment. This method enables the supply chain system to respond to potential security threats in real time and immediately modify the user's access rights, thereby preventing unauthorized access or data leakage. The permission management mechanism enables the system to adapt to changing user behavior and environmental changes, avoiding the problem of outdated or lagging permissions. At the same time, automated permission adjustment reduces the need for manual intervention and improves the overall security and management efficiency of the system. Through dynamic adjustment, the system can always maintain the best permission configuration to ensure data security and the continued smooth operation of the business.

[0139] Further, refer to Figure 1 In S40, S40 is used to combine user roles, dynamic attributes and real-time context information, match user access requests with updated access control lists through hybrid access control policies, and generate access decisions.

[0140] The latest access control list structure of the supply chain system is:

[0141] ACL(u i )=(Sub(u i ),Res(u i ),Act(u i ),Perm(u i ),C(u i ));

[0142] Among them, ACL(u i ) indicates the latest access control list, Sub(u i ) represents the request body, Res(u i ) indicates the resource requested for access, Act(u i ) indicates the execution of an operation, Perm(u i ) indicates the permission type for the execution of the operation; C(u i ) indicates additional conditions.

[0143] Receiving the access request of the user and collecting the user role and resource request information, including:

[0144] AS=(U,R,O,T,A);

[0145] Wherein, AS represents the request information of the user, U represents the identifier of the user, R represents the identifier of the resource requested for access, O represents the type of operation requested for execution, T represents the initiation time of the access request, and A represents the dynamic attribute;

[0146] Dynamic attributes and real-time context information related to the user request are collected, matched with the latest access control list, and an access decision is generated through a hybrid access control strategy.

[0147] Reference Figure 4 , Figure 4 A schematic diagram of the structure of a hybrid access control strategy provided by an embodiment.

[0148] The hybrid access control strategy is:

[0149]

[0150] The access request information and the corresponding access decision are recorded as an access log.

[0151] In this embodiment, after the user submits an access request, the system will conduct a comprehensive evaluation based on the user role, dynamic attributes and context information to generate an access decision. The decision clearly indicates whether the system allows or denies the user access to a specific resource. The generation of access decisions is based on a hybrid access control strategy, which combines role-based and attribute-based control rules to ensure the comprehensiveness and accuracy of the evaluation. By generating access decisions, the system can respond accurately and quickly to each access request. Combined with multi-dimensional control strategies, the system ensures that only requests that meet security requirements are allowed, which greatly improves the security of data access. At the same time, clear access decisions also reduce the risk of misuse of permissions and data leakage, and ensure the stability and reliability of the system when processing complex access requests.

[0152] Reference Figure 1 In S50, S50 is used to generate corresponding access operation instructions according to the access decision, perform data decryption and encryption maintenance operations according to the instructions, and perform integrity check and consistency verification on the supply chain system data after completing the operation.

[0153] The step of formulating an access operation instruction according to the access decision comprises: receiving the access decision, generating an instruction according to the access decision:

[0154]

[0155] The decryption instruction includes the location of the target data and the corresponding decryption key information;

[0156] The target data is decrypted and converted into plain text by calling a corresponding decryption algorithm according to the decryption key information.

[0157] This embodiment generates access operation instructions based on access decisions, so that the system ensures strict implementation of access control policies. Whether decrypting data or keeping data encrypted, the system can operate according to precise access decisions to prevent unauthorized access or data leakage. This mechanism effectively strengthens the security of the system and the consistency of operations, ensuring that sensitive data is accessed only under authorized conditions. At the same time, generating clear operation instructions also improves the efficiency and accuracy of system execution, reduces the possibility of erroneous operations, and ensures the safe flow and reliable sharing of supply chain data.

[0158] Furthermore, after executing the access operation instruction on the supply chain system data, the steps of performing integrity check and consistency verification include:

[0159] Performing a hash operation on the original supply chain system data to generate a hash value of the original data;

[0160] Generating a decrypted data hash value for the decrypted supply chain system data;

[0161] The original data hash value and the decrypted data hash value are compared to verify the integrity of the supply chain data.

[0162] When the original data hash value is the same as the decrypted data hash value, the integrity verification passes; when the original data hash value is different from the decrypted data hash value, the integrity verification fails;

[0163] Perform data structure analysis on the decrypted data, perform field verification and extraction; perform multi-source comparison between the decrypted data fields and the original data fields in each node and database in the supply chain system;

[0164] When the decrypted data field is consistent with the original data field in multi-source comparison, the consistency verification passes; when the decrypted data field is inconsistent with the original data multi-source field comparison, the consistency verification fails.

[0165] This embodiment performs data integrity check and consistency verification after the access operation, so that the system can ensure that the data has not been tampered with or damaged during the access process, thereby ensuring the authenticity and reliability of the data. The integrity check can detect and prevent data tampering caused by transmission errors, malicious attacks or system failures, while the consistency verification ensures that the data remains consistent across multiple nodes or storage locations. This dual verification mechanism significantly improves the security of the system, prevents unauthorized changes, and ensures that the data in the supply chain maintains high quality and credibility throughout its life cycle.

[0166] Further, refer to Figure 1S60 in the example is used to collect all record data generated by the aquatic product supply chain system in the access control process and is used to optimize the update mechanism of the access control list.

[0167] After the access is completed, collect all record data generated by the supply chain system in the access control process, including user access behavior logs, abnormal access behavior logs, permission change logs and system status logs;

[0168] The update mechanism of the access control list is continuously optimized according to the recorded data.

[0169] This embodiment enables the system to conduct a comprehensive analysis and review of the access control process by collecting all recorded data generated in the supply chain system after the access is completed (including user access behavior logs, abnormal access behavior logs, permission change logs, and system status logs). These data provide key support for detecting potential security threats, identifying changes in access patterns, and evaluating the effectiveness of permission adjustments. Based on these recorded data, the system can continuously optimize the update mechanism of the access control list, making the permission configuration more accurate and flexible, and further improving the security, response speed, and adaptability of the system. In addition, the system's adaptive optimization capabilities also enhance the ability to respond to changing business needs and security challenges, ensuring the long-term stable operation of the supply chain system.

[0170] This embodiment first generates an access control list by defining different user roles and corresponding permissions to ensure that the access boundaries of each role are clear. Then, the system confirms the user identity through distributed authentication and multi-factor authentication at each access request to ensure that only verified users can access resources. On this basis, the system collects user behavior data, historical access patterns and system status information in real time, combines predefined rules and machine learning models, dynamically adjusts user permissions, and updates the access control list in a timely manner. Subsequently, the system adopts a hybrid access control strategy to make access decisions based on role information and dynamic attributes, and performs data decryption or encryption operations. After the access operation is completed, the system performs data integrity check and consistency verification. Finally, the access control strategy is optimized by continuously collecting access logs and system status data to ensure the security and operation efficiency of the system. Through this comprehensive access control method, the system realizes all-round management from role definition, identity authentication to dynamic adjustment of permissions, and combines hybrid access control strategies and data integrity checks to ensure the efficient operation and security of the system in various complex scenarios. At the same time, the system's continuous optimization mechanism can continuously improve the flexibility and responsiveness of access control, effectively respond to changes and potential security challenges in the supply chain, and enable the system to maintain stability and reliability in long-term operation.

[0171] Embodiment 2

[0172] As an embodiment of the present invention, refer to Figure 1 S10 in the embodiment is used to define the user roles and corresponding permissions in the system according to the type of the supply chain system and generate an access control list (ACL). This embodiment describes a specific implementation method for the vegetable supply chain system A.

[0173] First, the different participants in the vegetable supply chain system are identified, the user roles in the system are defined, and initial permissions are assigned according to the roles. Role definition and permission assignment are based on the user's functions and business needs in the aquatic product supply chain system.

[0174] The initial permissions include:

[0175] Data access rights: the specific data and resources that users can access;

[0176] Data operation permissions: the types of operations that users can perform on data, including reading, creating, modifying, deleting, etc.;

[0177] System function permissions: specify the system function modules that users can access and use, including order management, inventory management, system settings and auditing functions;

[0178] Access time and location permissions: limit the time and location at which users can access the system.

[0179] Based on the defined roles and assigned permissions, an access control list is generated; the access control list is used to associate user request information with the corresponding initial permissions to ensure that users can operate according to their roles and permissions when accessing system resources.

[0180] The access control list structure of the aquatic product supply chain system is:

[0181] ACL=(ID user ,Role user ,Res,Act,Perm,C);

[0182] ACL stands for Access Control List, ID user Indicates user identity, Role user Res represents the user role, Res represents the resource requested for access, Act represents the requested operation, and Perm represents the permission type for the operation, including P A and P D , respectively indicating that the execution operation is allowed and the execution operation is rejected; C represents an additional condition.

[0183] Further, refer to Figure 1S20 in the example, S20 is used to receive a user access request, collect user identity information and resource request information, and verify the user identity through distributed identity authentication and multi-factor authentication methods; the user access request includes information such as user identity, requested resource type, requested operation type, requested timestamp, and request source.

[0184] First, identify and classify the types of access requests, including sensitive data access requests, general data access requests, and system function calls. After confirming the request type, select a combination of identity security authentication methods; the identity security authentication includes distributed identity authentication (DID) and multi-factor authentication (MFA).

[0185] Verify the identity credentials provided by the user to ensure the authenticity and validity of the user's identity; if the request type is a sensitive data access request, multi-factor authentication (MFA) is used to further authenticate the user. If the authentication is successful, the next processing stage will be entered; if the authentication fails, the access request will be immediately rejected.

[0186] Further, refer to Figure 1 S30 in the example is used to collect users’ historical behavior data, historical access records, and resource request information, adjust users’ roles and permissions in real time through predefined rules and machine learning models, and update access control lists.

[0187] Reference Figure 3 , Figure 3 A schematic diagram of the structure of an access control list update mechanism provided for this embodiment. The access control list update mechanism includes data collection and preprocessing, real-time behavior analysis, anomaly detection and risk assessment, and dynamic permission adjustment; wherein the data collection and preprocessing includes: collecting user behavior data, historical access patterns, and historical system status information to form a first analysis data set.

[0188] The first analysis data set is symbolically represented as:

[0189]

[0190] Among them, D ANA represents the first analysis data set, u i represents the i-th user, B(t) represents user u i The behavioral data at time t, b j (t) represents the jth behavior feature; H(u i ) represents user u i The historical access pattern, S(t) represents the historical system state at time t, b k (t) represents the kth system state parameter.

[0191] Calculate the mean and standard deviation for each behavioral feature in the behavioral data:

[0192]

[0193] where μ j and σ j Represent the mean and standard deviation of the j-th behavioral feature respectively.

[0194] The real-time behavior analysis includes behavior assessment and pattern matching;

[0195] The behavior evaluation step is to set a threshold and a time window. If the behavior feature score exceeds the threshold within the time window, it is marked as abnormal.

[0196] Abnormal1=(b j (t)-μ j |>T j )∧(t'∈[t,t+Δt]);

[0197] Among them, Abnormal1 represents the abnormal judgment of behavior assessment, T j represents the threshold value, and Δt represents the time window;

[0198] The pattern matching is to calculate the cosine similarity between the behavior data and the historical access pattern, and if it is lower than a preset threshold, it is marked as abnormal;

[0199]

[0200] Among them, Abnormal2 indicates the abnormal judgment of pattern matching, T θ represents the preset threshold, and B'(t) represents the normalized behavior data.

[0201] The anomaly detection and risk assessment include anomaly detection and risk score calculation;

[0202] The steps of anomaly detection are: collecting historical behavior data to train the isolation forest model to obtain an anomaly detection model; evaluating the anomaly score of the behavior data through the anomaly detection model, and if the anomaly score exceeds the anomaly threshold, it is judged as an anomaly.

[0203] E(B(t))=IF(B(t));

[0204] Wherein, E(B(t)) represents the abnormal score of the behavior data.

[0205] The step of calculating the risk score is: comprehensively calculating the behavior evaluation, the pattern matching and the system status to calculate the risk score.

[0206]

[0207] Among them, R(u i ) represents user u i The risk score, S'(t) is the normalized system state, and the levels of ω1, ω2 and ω3 represent the adjustment coefficients of behavior assessment, pattern matching and system state.

[0208] The process of dynamic permission adjustment includes: setting a risk score threshold, dynamically adjusting the user's permission by comparing the risk score with the risk score threshold, and updating the access control list.

[0209]

[0210] Among them, T R represents the risk score threshold, P(u i ) indicates the adjusted permissions, ACL (u i ) indicates the latest access control list, Perm initial Indicates the initial permission configuration.

[0211] Further, refer to Figure 1 In S40, S40 is used to combine user roles, dynamic attributes and real-time context information, match user access requests with updated access control lists through hybrid access control policies, and generate access decisions.

[0212] The latest access control list structure of the supply chain system is:

[0213] ACL(u i )=(Sub(u i ),Res(u i ),Act(u i ),Perm(u i ),C(u i ));

[0214] Among them, ACL(u i ) indicates the latest access control list, Sub(u i ) represents the request body, Res(u i ) indicates the resource requested for access, Act(u i ) indicates the execution of an operation, Perm(u i ) indicates the permission type for the execution of the operation; C(u i ) indicates additional conditions.

[0215] Receiving the access request of the user and collecting the user role and resource request information, including:

[0216] AS=(U,R,O,T,A);

[0217] Wherein, AS represents the request information of the user, U represents the identifier of the user, R represents the identifier of the resource requested for access, O represents the type of operation requested for execution, T represents the initiation time of the access request, and A represents the dynamic attribute;

[0218] Dynamic attributes and real-time context information related to the user request are collected, matched with the latest access control list, and an access decision is generated through a hybrid access control strategy.

[0219] Reference Figure 4 , Figure 4 A schematic diagram of the structure of a hybrid access control strategy provided by an embodiment.

[0220] The hybrid access control strategy is:

[0221]

[0222] The access request information and the corresponding access decision are recorded as an access log.

[0223] Reference Figure 1 In S50, S50 is used to generate corresponding access operation instructions according to the access decision, perform data decryption and encryption maintenance operations according to the instructions, and perform integrity check and consistency verification on the supply chain system data after completing the operation.

[0224] The step of formulating an access operation instruction according to the access decision comprises: receiving the access decision, generating an instruction according to the access decision:

[0225]

[0226] The decryption instruction includes the location of the target data and the corresponding decryption key information;

[0227] The target data is decrypted and converted into plain text by calling a corresponding decryption algorithm according to the decryption key information.

[0228] Furthermore, after executing the access operation instruction on the supply chain system data, the steps of performing integrity check and consistency verification include:

[0229] Performing a hash operation on the original supply chain system data to generate a hash value of the original data;

[0230] Generating a decrypted data hash value for the decrypted supply chain system data;

[0231] The original data hash value and the decrypted data hash value are compared to verify the integrity of the supply chain data.

[0232] When the original data hash value is the same as the decrypted data hash value, the integrity verification passes; when the original data hash value is different from the decrypted data hash value, the integrity verification fails;

[0233] Perform data structure analysis on the decrypted data, perform field verification and extraction; perform multi-source comparison between the decrypted data fields and the original data fields in each node and database in the supply chain system;

[0234] When the decrypted data field is consistent with the original data field in multi-source comparison, the consistency verification passes; when the decrypted data field is inconsistent with the original data multi-source field comparison, the consistency verification fails.

[0235] Further, refer to Figure 1 S60 in the example is used to collect all record data generated by the aquatic product supply chain system in the access control process and is used to optimize the update mechanism of the access control list.

[0236] After the access is completed, collect all record data generated by the supply chain system in the access control process, including user access behavior logs, abnormal access behavior logs, permission change logs and system status logs;

[0237] The update mechanism of the access control list is continuously optimized according to the recorded data.

[0238] This embodiment provides a supply chain data security sharing method based on blockchain, which improves the flexibility and efficiency of the supply chain system by dynamically adjusting access control. First, the system defines the access rights of each role according to different user roles in the supply chain. By clarifying the resources that each role can access and the operations performed, an initial access control list (ACL) is generated to ensure that each role can only access data and functions related to its functions. By pre-defining user roles and permissions, the system establishes clear permission boundaries at the beginning to prevent unauthorized access, improve the security of the system, and simplify subsequent permission management. When a user requests access to a resource, the system confirms the user's identity through distributed identity verification (DID) and multi-factor authentication (MFA). This ensures that each user is authentic and their identity is strictly verified to prevent malicious users or imposters from accessing sensitive resources. Through multi-factor authentication, the system can effectively prevent unauthorized users from accessing sensitive data, improve the security of the system and the credibility of user identities. The system collects user behavior data, historical access patterns, and current system status information in real time. Combined with predefined rules and machine learning models, the system can analyze the user's operation behavior and dynamically adjust user permissions based on risk scores. Based on these adjustment results, the access control list (ACL) is updated. Real-time collection and dynamic adjustment of permissions enable the system to respond to changes in user behavior in a timely manner, prevent the accumulation of security risks, and achieve more flexible and accurate permission management. Through hybrid access control strategies, user roles and dynamic attributes are combined to generate access decisions. Based on the decision results, the system performs data decryption or keeps data encrypted to ensure that data is accessed in the correct context. The hybrid access control strategy combines the dual control of roles and attributes, which can more accurately evaluate and respond to access requests in complex scenarios, ensuring the security and adaptability of the system. After executing the access operation, the system performs data integrity checks and consistency verifications to ensure the security and accuracy of the data. The system continuously collects access logs and system status data, optimizes access control lists and policies, and maintains the efficient operation of the system. Data integrity checks and continuous optimization ensure that the system can maintain data accuracy and policy effectiveness during long-term operation, preventing the emergence of security vulnerabilities.

[0239] The present invention significantly improves the security, flexibility and responsiveness of the system through clear permission management, strict identity authentication, real-time permission adjustment, precise access control and continuous system optimization, ensuring that the system can continue to operate efficiently and safely in a complex supply chain environment.

[0240] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A blockchain-based supply chain data security sharing method, characterized in that: include: According to the type of supply chain system, define the user roles and corresponding permissions in the system and generate an access control list; Receive user access requests and collect user identity information and resource request information; Verify user identity through distributed identity verification and multi-factor authentication methods; Collect the user's historical behavior data, historical access records and current system status, adjust the user's role and permissions in real time through the access control list update mechanism, and update the latest access control list; Combining the user role, dynamic attributes and real-time context information, matching the user access request with the latest access control list through a hybrid access control strategy, and generating an access decision; recording the user access request and the access decision as an access log; Generate a corresponding access operation instruction according to the access decision; the access operation instruction includes two situations where the access decision is allowed and denied: when the access decision is allowed, the supply chain system data is decrypted; when the access decision is denied, the supply chain system data remains encrypted and cannot be accessed; After executing the access operation instruction, the supply chain system data is checked for integrity and consistency; Collect all record data generated by the supply chain system in the access control process and optimize the update mechanism of the access control list.

2. According to a blockchain-based supply chain data security sharing method according to claim 1, it is characterized in that: The step of generating the access control list comprises: According to the information of participants in the supply chain system, define the role of each user; the role definition is based on the functions and business requirements of the user in the supply chain system; Assign initial permissions to each role; the initial permissions include data access permissions, data operation permissions, system function permissions, and access time and location permissions; Generate an access control list; the access control list includes the user's request information and the corresponding initial permissions; ACL=(ID user ,Role user ,Res,Act,Perm,C); ACL stands for Access Control List, ID user Indicates user identity, Role user Res represents the user role, Res represents the resource requested for access, Act represents the requested operation, and Perm represents the permission type for the operation, including P A and P D , respectively indicating that the execution operation is allowed and the execution operation is rejected; C represents an additional condition.

3. According to a blockchain-based supply chain data security sharing method according to claim 1, it is characterized in that: The access control list update mechanism includes data collection and preprocessing; Collecting user behavior data, historical access patterns, and historical system status information to form a first analysis data set; D ANA =(B(t),H(u i ),S(t)); Among them, D ANA represents the first analysis data set, u i represents the i-th user, B(t) represents user u i The behavior data vector at time t, H(u i ) represents user u i The historical access pattern vector S(t) represents the system state at time t; Calculate the mean and standard deviation for each behavioral feature in the behavioral data: Among them, μ j and σ j Respectively represent the mean and standard deviation of the jth behavior feature, b j (t) represents the jth behavior feature.

4. According to a blockchain-based supply chain data security sharing method according to claim 1, it is characterized in that: The access control list update mechanism also includes real-time behavior analysis; The real-time behavior analysis includes behavior evaluation and pattern matching; the behavior evaluation step is to set a threshold and a time window, and if the behavior evaluation exceeds the threshold within the time window, it is marked as abnormal; Abnormal1=(b j (t)-μ j |>T j )∧(t'∈[t,t+Δt]); Among them, Abnormal1 represents the abnormal judgment of behavior assessment, T j represents the threshold value, and Δt represents the time window; The pattern matching is to calculate the cosine similarity between the behavior data and the historical access pattern, and if it is lower than a preset threshold, it is marked as abnormal; Abnormal=if(cosθ<T θ ) Among them, Abnormal2 indicates the abnormal judgment of pattern matching, T θ represents the preset threshold, and B'(t) represents the normalized behavior data.

5. According to a blockchain-based supply chain data security sharing method according to claim 1, it is characterized in that: The access control list update mechanism also includes anomaly detection and risk assessment; The anomaly detection and risk assessment include anomaly detection and risk score calculation; The anomaly detection step is: collecting historical behavior data to train the isolation forest model to obtain an anomaly detection model; evaluating the anomaly score of the behavior data through the anomaly detection model, and if the anomaly score exceeds the anomaly threshold, it is judged as an anomaly; E(B(t))=IF(B(t)); Wherein, E(B(t)) represents the abnormal score of the behavior data; The steps of calculating the risk score are: comprehensively evaluating the behavior, pattern matching and system status to calculate the risk score; Among them, R(u i ) represents user u i The risk score is S'(t), S'(t) represents the normalized system state, and ω1, ω2 and ω3 levels represent the adjustment coefficients of behavior evaluation, pattern matching and system state.

6. According to a blockchain-based supply chain data security sharing method according to claim 1, it is characterized in that: The access control list update mechanism also includes dynamic permission adjustment; Setting a risk score threshold, dynamically adjusting the user's permissions by comparing the risk score with the risk score threshold, and updating the access control list; Among them, T R represents the risk score threshold, P(u i ) indicates the adjusted permissions, ACL (u i ) indicates the latest access control list, Perm initial Indicates the initial permission configuration.

7. According to a blockchain-based supply chain data security sharing method according to claim 1, it is characterized in that: The access decision generation process includes: The latest access control list structure of the supply chain system is: ACL(u i )=(Sub(u i ),Res(u i ),Act(u i ),Perm(u i ),C(u i )); Among them, ACL(u i ) indicates the latest access control list, Sub(u i ) represents the request body, Res(u i ) indicates the resource requested for access, Act(u i ) indicates the execution of an operation, Perm(u i ) indicates the permission type for the execution of the operation; C(u i ) indicates additional conditions; Receiving the access request of the user and collecting the user role and resource request information, including: AS=(U,R,O,T,A); Wherein, AS represents the request information of the user, U represents the identifier of the user, R represents the identifier of the resource requested for access, O represents the type of operation requested for execution, T represents the initiation time of the access request, and A represents the dynamic attribute; Collect dynamic attributes and real-time context information related to user requests, match them with the latest access control list, and generate access decisions through hybrid access control strategies; The hybrid access control strategy is: The access request information and the corresponding access decision are recorded as an access log.

8. According to a blockchain-based supply chain data security sharing method according to claim 1, it is characterized in that: The step of formulating an access operation instruction according to the access decision comprises: Receive access decisions and generate instructions based on the access decisions: The decryption instruction includes the location of the target data and the corresponding decryption key information; According to the decryption key information, the corresponding decryption algorithm is called to decrypt the target data and convert it into plain text.

9. The method for secure sharing of supply chain data based on blockchain according to claim 1 is characterized in that: After executing the access operation instruction on the supply chain system data, the steps of performing integrity check and consistency verification include: Performing a hash operation on the original supply chain system data to generate a hash value of the original data; Generating a decrypted data hash value for the decrypted supply chain system data; Compare the original data hash value with the decrypted data hash value to verify the integrity of the supply chain system data; When the original data hash value is the same as the decrypted data hash value, the integrity verification passes; when the original data hash value is different from the decrypted data hash value, the integrity verification fails; Perform data structure analysis on the decrypted data, perform field verification and extraction; perform multi-source comparison between the decrypted data fields and the original data fields in each node and database in the supply chain system; When the decrypted data field is consistent with the original data field in multi-source comparison, the consistency verification passes; when the decrypted data field is inconsistent with the original data multi-source field comparison, the consistency verification fails.

10. According to a blockchain-based supply chain data security sharing method according to claim 1, it is characterized in that: Also includes: After the access is completed, collect all record data generated by the supply chain system in the access control process, including user access behavior logs, abnormal access behavior logs, permission change logs and system status logs; An update mechanism for the access control list is optimized according to the record data.

Citation Information

Cited By

  • Data access authority control method and system based on block chain

    CN120389897A

  • Trusted data sharing system based on identification analysis and data circulation method

    CN120475089A

  • A trusted data sharing system and data flow method based on identification resolution

    CN120475089B

  • Block chain-based trusted data space cross-domain access control method, system and device, and medium

    CN120956446A

  • Online learning platform data security access control method

    CN121765702A