Government affair service system based on block chain
By introducing blockchain technology and digital signature secondary encryption methods into the government service system, the problem of the risk of isolated and forging of certificate information in the traditional government service architecture is solved, efficient management and security verification of electronic certificate information is realized, and the efficiency and credibility of government service are improved.
Patent Information
- Application Number
- CN202510089601.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-30
AI Technical Summary
The field of license management in traditional government service architecture faces the risks of information isolation, data inconsistency and high falsification, which makes it difficult to effectively interconnect license information.
The blockchain-based government service system is adopted to store and manage electronic certificate information through the certificate chain platform, and combine it with the key management system, exception handling module, user authorization and access control module, government service module, user module and supervision module to achieve issuance, update, cancellation and verification of certificates.
It improves the credibility and security of electronic certificate information, realizes data transparency and interoperability, simplifies the certificate verification process, and improves the efficiency of government services.
Smart Images

Figure CN120070131A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of government service, and specifically to a government service system based on blockchain. Background Art
[0002] Government services refer to various administrative service activities provided by the government to citizens, legal persons and other organizations, aiming to improve the efficiency of government services and meet the diverse needs of the people. As an important function of the government, government services cover various administrative service activities provided by the government to the public. These services include but are not limited to: Administrative approval: refers to the administrative authority's review of the application submitted by the counterparty in accordance with the law and making a decision on whether to allow the counterparty to engage in specific activities; Administrative licensing: refers to the administrative authority's approval of the application of citizens, legal persons or other organizations to engage in specific activities after review in accordance with the law, such as the establishment of an enterprise, construction project construction permits, etc.; Public services: refers to the public and universal services provided by the government to meet the needs of citizens, legal persons or other organizations, such as services in the fields of education, medical care, culture, sports, etc.; Inquiry replies: refers to the government's provision of relevant policy answers, information provision and other services in response to inquiries from citizens, legal persons or other organizations; government services aim to provide the public with more convenient and efficient services by optimizing service processes and improving service quality.
[0003] Under the traditional government service architecture, the field of certificate management faces a series of severe challenges, especially information isolation, data inconsistency and high risk of forgery. Government service processes often span multiple administrative departments and institutions, and each institution is independent and has built its own certificate management system. This decentralized management architecture, coupled with the lack of unified data standards and interactive platforms, has resulted in certificate information being scattered like isolated islands, making it difficult to effectively interconnect. Therefore, we propose a government service system based on blockchain. Summary of the invention
[0004] The purpose of the present invention is to provide a blockchain-based government service system that solves the problems raised in the background technology.
[0005] To achieve the above-mentioned purpose, the present invention provides the following technical solutions: a blockchain-based government service system, comprising: a license chain platform;
[0006] Certificate chain platform: used to store and manage electronic certificate information. The platform includes a key management system, an exception handling module, and a user authorization and access control module.
[0007] Key management system: used for the generation, storage, distribution and update of secondary encryption keys. It uses secure hardware or distributed key management mechanisms to ensure the security and availability of keys, and updates keys regularly or according to security policies.
[0008] Exception handling module: used to detect and handle exceptions during the secondary encryption process of digital signatures, and trigger an alarm mechanism to notify relevant personnel for handling;
[0009] User authorization and access control module: used to strictly control the access rights of user nodes to ensure that only authorized user nodes can access and verify electronic license information and its corresponding digital signatures, adopting strategies such as role-based access control and attribute-based access control;
[0010] Government service module: connected to the license chain platform, responsible for the issuance, update, and cancellation of licenses; when issuing electronic licenses, generate an original digital signature based on the license information and perform the first encryption using an asymmetric encryption algorithm;
[0011] User module: connected to the license chain platform, used to query and authorize the use of electronic licenses;
[0012] Supervision module: connected to the license chain platform, supervising and auditing the operation of the license chain platform.
[0013] As a preferred embodiment of the present invention, the government service module includes a first encryption generation digital signature module, which is used to generate an original digital signature based on the license information and perform the first encryption using an asymmetric encryption algorithm.
[0014] As a preferred embodiment of the present invention, the government service module includes a secondary encryption processing module, which is used to perform secondary encryption processing on the digital signature generated by the first encryption, adopting a symmetric encryption algorithm. The encryption key is dynamically generated and managed by the security module of the license chain platform, and is securely stored or destroyed after encryption.
[0015] As a preferred embodiment of the present invention, the government service module further includes a storage and transmission module, which is used to package the digitally signed information after secondary encryption and the electronic license information into a block, perform consensus confirmation through the blockchain network and store it; during transmission, ensure the secure transmission of the secondary encryption key.
[0016] As a preferred embodiment of the present invention, the government service module further includes a verification module, which is used in the electronic license verification stage. The government service agency or user node obtains the electronic license information and its corresponding secondary encrypted digital signature through the blockchain network, decrypts it using the secondary decryption key provided by the license chain platform, restores the digitally signed information encrypted for the first time, and verifies the validity of the digital signature using the corresponding asymmetric encryption algorithm.
[0017] As a preferred embodiment of the present invention, the key management system uses secure hardware to achieve the secure storage and management of keys, improving the security and availability of keys.
[0018] As a preferred embodiment of the present invention, the exception handling module can detect abnormal situations in the process of double encryption of digital signatures in real time, trigger an alarm mechanism in a timely manner to notify relevant personnel for handling, and record the abnormal information for subsequent analysis.
[0019] As a preferred embodiment of the present invention, the certificate chain platform further includes a data storage module and a data update module. The data storage module is used for storing data, and the data update module is used for updating data in a timely manner.
[0020] As a preferred embodiment of the present invention, the supervision module includes an audit module and a log recording module. The audit module is used for auditing the entire process of double encryption of digital signatures by the certificate chain platform, and the log recording module is used for recording the process.
[0021] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0022] The present invention utilizes the distributed ledger and consensus mechanism of blockchain technology. All electronic certificate information and its related operations are recorded on an immutable blockchain. This feature not only improves the transparency of data but also enables any illegal modification of data to be quickly discovered and traced, thus greatly enhancing the credibility of electronic certificate information;
[0023] By introducing a method of double encryption of digital signatures, double encryption protection of electronic certificate information is achieved. The first encryption uses an asymmetric encryption algorithm to ensure the confidentiality and integrity of data; the second encryption uses a symmetric encryption algorithm to further enhance the data security protection layer, making it more difficult for electronic certificate information to be cracked and tampered with during storage and transmission;
[0024] Through the secondary decryption key and digital signature verification mechanism provided by the certificate chain platform, government service agencies or user nodes can quickly obtain and verify the authenticity and integrity of electronic certificate information. This feature simplifies the certificate verification process, shortens the processing time, and improves the efficiency of government services;
[0025] The user authorization and access control module adopts flexible access control strategies, such as role-based access control and attribute-based access control. This enables only authorized user nodes to access and verify electronic certificate information, ensuring both the confidentiality of data and providing a convenient access method. At the same time, as the user roles and attributes change, the access permissions can be dynamically adjusted, further enhancing the flexibility and adaptability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Other features, objectives, and advantages of the present invention will become more apparent by reading the following detailed description of non - restrictive embodiments with reference to the accompanying drawings:
[0027] Figure 1 This is an operation diagram of a government service system based on blockchain according to the present invention;
[0028] Figure 2 This is a government service module diagram of a government service system based on blockchain according to the present invention. Detailed Embodiments
[0029] To make the technical means, creative features, achieved objectives, and effects of the present invention easy to understand, the present invention will be further described below in conjunction with specific embodiments.
[0030] Embodiment
[0031] A government service system based on blockchain includes: a certificate chain platform;
[0032] The certificate chain platform: used to store and manage electronic certificate information, and this platform includes a key management system, an exception handling module, and a user authorization and access control module;
[0033] The certificate chain platform further includes a data storage module and a data update module. The data storage module is used to store data, and the data update module is used to update data in a timely manner;
[0034] The key management system: used for the generation, storage, distribution, and update of secondary encryption keys, ensuring the security and availability of keys, and performing key updates regularly or according to security policies;
[0035] The exception handling module: capable of detecting abnormal situations in the secondary encryption process of digital signatures in real - time, triggering an alarm mechanism in a timely manner, notifying relevant personnel for handling, and recording abnormal information for subsequent analysis;
[0036] The user authorization and access control module: used to strictly control the access permissions of user nodes, ensuring that only authorized user nodes can access and verify electronic certificate information and its corresponding digital signatures, and adopting strategies such as role - based access control and attribute - based access control;
[0037] The government service module: connected to the certificate chain platform, responsible for the issuance, update, and cancellation of certificates; when issuing an electronic certificate, a raw digital signature is generated according to the certificate information, and the first - level encryption is performed using an asymmetric encryption algorithm;
[0038] The government service module includes a first - level encryption digital signature generation module, which is used to generate a raw digital signature according to the certificate information and perform the first - level encryption using an asymmetric encryption algorithm;
[0039] The government service module includes a secondary encryption processing module, which is used to perform secondary encryption processing after the digital signature generated by the first encryption. The symmetric encryption algorithm is adopted, and the encryption key is dynamically generated and managed by the security module of the certificate chain platform. After encryption, it is securely stored or destroyed;
[0040] The government service module also includes a storage and transmission module, which is used to package the digitally signed and secondarily encrypted data together with the electronic certificate information into a block, perform consensus confirmation through the blockchain network, and store it; during transmission, ensure the secure transmission of the secondary encryption key;
[0041] The government service module also includes a verification module, which is used in the electronic certificate verification stage. The government service agency or user node obtains the electronic certificate information and its corresponding secondarily encrypted digital signature through the blockchain network, decrypts it using the secondary decryption key provided by the certificate chain platform, restores the digitally signed and first encrypted data, and uses the corresponding asymmetric encryption algorithm to verify the validity of the digital signature;
[0042] User module: Connected to the certificate chain platform, used to query and authorize the use of electronic certificates;
[0043] Supervision module: Connected to the certificate chain platform, used to supervise and audit the operation of the certificate chain platform;
[0044] The supervision module includes an audit module and a log recording module. The audit module is used to audit the entire process of the certificate chain platform's secondary encryption of the digital signature, and the log recording module is used to record the process.
[0045] A blockchain-based government service system has the following specific operation process:
[0046] Certificate issuance process: The government service agency module receives the certificate application information submitted by the user. The government service agency module generates an original digital signature based on the certificate information and performs the first encryption using an asymmetric encryption algorithm (such as RSA, ECDSA, etc.);
[0047] The key management system of the certificate chain platform generates a symmetric encryption key for secondary encryption of the digital signature generated by the first encryption. This key is dynamically generated and managed by the security module of the certificate chain platform;
[0048] The certificate chain platform performs secondary encryption processing on the digitally signed and first encrypted data. After encryption, the secondary encryption key is securely stored or destroyed. The government service module packages the digitally signed and secondarily encrypted data together with the electronic certificate information into a block, submits it to the blockchain network for consensus confirmation, and stores it;
[0049] Electronic Certificate Inquiry and Authorization Usage Process: The user module submits an electronic certificate inquiry request to the certificate chain platform. The user authorization and access control module of the certificate chain platform verifies the access rights of the user module to ensure that the user module has the right to inquire about electronic certificates. The certificate chain platform obtains the corresponding electronic certificate information and the digitally signed second encryption from the blockchain network according to the request of the user module. The certificate chain platform decrypts the digital signature using the stored second decryption key to restore the first encrypted digital signature. The user module uses the corresponding asymmetric encryption algorithm to verify the validity of the digital signature, thereby confirming the authenticity and integrity of the electronic certificate. If the user module needs to authorize the use of the electronic certificate, the certificate chain platform generates authorization information according to the request of the user module, and packages the authorization information and the electronic certificate information into a block and stores it in the blockchain network;
[0050] Supervision Process: The supervision module conducts real-time supervision and auditing on the operation of the certificate chain platform. The supervision module regularly or according to the security policy checks and evaluates the key management system, exception handling module and user authorization and access control module of the certificate chain platform. The supervision module records and analyzes the operation of the certificate chain platform, and discovers and handles potential security risks in a timely manner;
[0051] Exception Handling Process: During the second encryption of the digital signature, if an abnormal situation occurs (such as encryption failure, decryption failure, key loss, etc.), the exception handling module will detect and trigger the alarm mechanism in real time. The exception handling module records the exception information and notifies the relevant personnel for handling. The relevant personnel take corresponding measures according to the exception information to ensure the normal operation of the system and the security of the data.
[0052] Audit and Log Recording Process: The certificate chain platform audits and records the entire process of the second encryption of the digital signature. The audit and log recording include information such as the time, operator, and operation result of operations such as key generation, encryption, decryption, and verification. The relevant personnel can trace and analyze the operation of the system according to the audit and log recording, and discover and handle potential problems in a timely manner.
[0053] In summary, the present invention utilizes the distributed ledger and consensus mechanism of blockchain technology. All electronic certificate information and its related operations are recorded on an immutable blockchain. This feature not only improves the transparency of data, but also enables any illegal modification of the data to be quickly discovered and traced, thus greatly enhancing the credibility of electronic certificate information;
[0054] By introducing a digital signature secondary encryption method, double encryption protection of electronic certificate information is achieved. The first encryption uses an asymmetric encryption algorithm to ensure the confidentiality and integrity of the data; the secondary encryption uses a symmetric encryption algorithm to further enhance the data security protection layer, making it more difficult for electronic certificate information to be cracked and tampered with during storage and transmission;
[0055] Through the secondary decryption key and digital signature verification mechanism provided by the certificate chain platform, government service agencies or user nodes can quickly obtain and verify the authenticity and integrity of electronic certificate information. This feature simplifies the certificate verification process, shortens the processing time, and improves the efficiency of government services;
[0056] The user authorization and access control module adopts flexible access control policies, such as role-based access control and attribute-based access control. This enables only authorized user nodes to access and verify electronic certificate information, ensuring both data confidentiality and providing a convenient access method. At the same time, as the user roles and attributes change, the access permissions can be dynamically adjusted, further enhancing the flexibility and adaptability of the system.
[0057] The above shows and describes the basic principles, main features, and advantages of the present invention. For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic features of the present invention, the present invention can be implemented in other specific forms. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present invention.
[0058] In addition, it should be understood that although this specification is described according to embodiments, not every embodiment only contains an independent technical solution. This narrative way of the specification is only for clarity. Those skilled in the art should regard the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.
Claims
1. A blockchain-based government service system, characterized in that: include: Certificate chain platform; Certificate chain platform: used to store and manage electronic certificate information. The platform includes a key management system, an exception handling module, and a user authorization and access control module. Key management system: used for the generation, storage, distribution and update of secondary encryption keys, ensuring the security and availability of keys, and updating keys regularly or according to security policies; Exception handling module: used to detect and handle abnormal situations in the secondary encryption process of digital signatures, and trigger the alarm mechanism to notify relevant personnel to handle; User authorization and access control module: used to strictly control the access rights of user nodes, ensuring that only authorized user nodes can access and verify electronic certificate information and its corresponding digital signature, using strategies such as role-based access control and attribute-based access control; Government service module: connected to the certificate chain platform, responsible for the issuance, renewal and cancellation of certificates; when issuing electronic certificates, an original digital signature is generated based on the certificate information, and an asymmetric encryption algorithm is used for the first encryption; User module: connected to the certificate chain platform, used to query and authorize the use of electronic certificates; Supervision module: connected to the license and certificate chain platform to supervise and audit the operation of the license and certificate chain platform.
2. A blockchain-based government service system according to claim 1, characterized in that: The government service module includes a first encryption digital signature generation module, which is used to generate an original digital signature based on the certificate information and use an asymmetric encryption algorithm for the first encryption.
3. A blockchain-based government service system according to claim 1, characterized in that: The government service module includes a secondary encryption processing module, which is used to perform secondary encryption processing after the digital signature generated by the initial encryption. A symmetric encryption algorithm is used, and the encryption key is dynamically generated and managed by the security module of the certificate chain platform. After the encryption is completed, it is securely stored or destroyed.
4. A blockchain-based government service system according to claim 1, characterized in that: The government service module also includes a storage and transmission module, which is used to package the digital signature and electronic certificate information that have been encrypted twice into blocks, and confirm and store them through consensus through the blockchain network; during transmission, the secure transmission of the secondary encryption key is ensured.
5. A blockchain-based government service system according to claim 1, characterized in that: The government service module also includes a verification module, which is used in the electronic certificate verification stage. The government service agency or user node obtains the electronic certificate information and its corresponding secondary encrypted digital signature through the blockchain network, decrypts it using the secondary decryption key provided by the certificate chain platform, restores the first encrypted digital signature, and uses the corresponding asymmetric encryption algorithm to verify the validity of the digital signature.
6. A blockchain-based government service system according to claim 1, characterized in that: The key management system adopts secure hardware to realize the secure storage and management of keys, thereby improving the security and availability of keys.
7. A blockchain-based government service system according to claim 1, characterized in that: The exception handling module can detect abnormal situations in the digital signature secondary encryption process in real time, trigger the alarm mechanism in time, notify relevant personnel to handle it, and record the abnormal information for subsequent analysis.
8. A blockchain-based government service system according to claim 1, characterized in that: The certificate chain platform also includes a data storage module and a data update module. The data storage module is used to store data, and the data update module is used to update data in a timely manner.
9. A blockchain-based government service system according to claim 1, characterized in that: The supervision module includes an audit module and a log recording module. The audit module is used to audit the entire process of secondary encryption of digital signatures by the certificate chain platform, and the log recording module is used to record the process.
Citation Information
Cited By
Data encryption system
CN121217481A
A data encryption system
CN121217481B