A blockchain-based intelligent cash box anti-theft control method, system and storage medium

Through blockchain technology combined with sensor real-time monitoring and data processing with double-chain architecture, the security risks existing in anti-theft measures of the box are solved, efficient abnormal identification and response are achieved, and the security and management efficiency of the box transportation and storage are improved.

CN120151084BActive Publication Date: 2025-07-18CLP FINANCIAL EQUIP SYST (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510443469.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-07-18
Estimated Expiration
2045-04-10

AI Technical Summary

Technical Problem

The existing anti-theft measures for boxes have problems such as physical protection that is easily violently damaged, manual supervision has human negligence, video surveillance cannot intervene in real time, and it is difficult to comprehensively monitor the box status, geographical location and environmental changes, which makes it difficult to effectively identify and respond to safety hazards.

Method used

Blockchain technology is used to combine three-axis acceleration sensors, dual-mode positioning modules and infrared spectral sensors to monitor vibration frequency, geographical location and oxygen concentration in real time, upload data to the double-chain architecture through edge encryption, and use the Hyperledger Fabric alliance chain and the FISCO BCOS chain for real-time abnormality detection and cross-chain anchoring to generate global audit records, and perform differentiated verification strategies in combination with Fourier transform and risk assessment.

Benefits of technology

It realizes comprehensive perception of the box status, improves the accuracy and response speed of abnormal identification, ensures data confidentiality and integrity, enhances the audit capability and security of the system, and balances security and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151084B_ABST
    Figure CN120151084B_ABST
Patent Text Reader

Abstract

The present application discloses a blockchain-based intelligent cash box anti-theft control method, system and storage medium. The method of the present application includes: obtaining a vibration frequency, obtaining geographical location coordinates, obtaining the oxygen concentration inside the box, and combining them with an operation timestamp to generate a data packet, and performing edge encryption to obtain an encrypted data packet; uploading the encrypted data packet to a double-chain architecture through an edge computing gateway; using the Hyperledger Fabric consortium chain to store the hash value of the encrypted data packet; regularly performing cross-chain anchoring on the Merkle root of the operation chain through the FISCO BCOS chain to generate a global audit record; extracting the vibration frequency, geographical location and oxygen concentration from the encrypted data packet, and performing SM3 consistency verification with the hash value stored in the operation chain; verifying the deviation degree between the current geographical location and the preset path; generating a comprehensive risk level based on the Fourier transform spectrum energy of the vibration frequency, the mutation gradient of the oxygen concentration and the deviation degree of the preset path; and executing a differential verification strategy according to the risk level to obtain a verification result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of blockchain technology, and in particular, to a blockchain-based intelligent cash box anti-theft control method, system, and storage medium. Background Art

[0002] In the process of cash transportation and storage, the security of cash boxes is of crucial importance. Traditional anti-theft measures for cash boxes mainly rely on physical locks, manual supervision, and video surveillance. However, these methods have certain limitations. For example, physical protection measures are vulnerable to violent damage, manual supervision has the risk of human negligence, and video surveillance cannot achieve real-time intervention in some cases. In addition, during the transportation of cash boxes, it is difficult to comprehensively monitor the box state, geographical location, and environmental changes, resulting in potential security hazards.

[0003] With the development of information technology, more and more cash box security management solutions have started to introduce data monitoring and remote control technologies. For example, the state information of cash boxes is monitored through sensors, data security is ensured through encrypted communication, and the security of cash boxes is improved by combining automated management means. However, in practical applications, how to ensure data integrity, prevent tampering, and how to improve the recognition and response speed of abnormal states are still challenges faced by existing technologies. Therefore, there is an urgent need for a more secure and intelligent cash box anti-theft control method to enhance the security and management efficiency of cash boxes during transportation and storage. Summary of the Invention

[0004] To solve the above technical problems, this application provides a blockchain-based intelligent cash box anti-theft control method, system, and storage medium.

[0005] The technical solutions provided in this application are described below:

[0006] In the first aspect of this application, a blockchain-based intelligent cash box anti-theft control method is provided, and the method includes:

[0007] Obtain the vibration frequency through a three-axis acceleration sensor built in the cash box, obtain the geographical location coordinates through a dual-mode positioning module, obtain the oxygen concentration inside the box through an infrared spectroscopy sensor, combine them with the operation timestamp to generate a data packet, and perform edge encryption using the national cryptographic SM4 algorithm to obtain an encrypted data packet;

[0008] Upload the encrypted data packet to a dual-chain architecture through an edge computing gateway;

[0009] On the operation chain, use the Hyperledger Fabric consortium chain to store the hash value of the encrypted data packet and trigger a smart contract for real-time anomaly detection;

[0010] On the audit chain, the Merkle root of the operation chain is periodically cross-chain anchored through the FISCO BCOS chain to generate a global audit record;

[0011] When a money box opening request is received, the vibration frequency, geographical location, and oxygen concentration in the encrypted data packet are extracted and subjected to SM3 consistency verification with the hash value stored in the operation chain;

[0012] Obtain the Merkle proof of the historical trajectory through the audit chain and verify the deviation degree between the current geographical location and the preset path;

[0013] Generate a comprehensive risk level based on the Fourier transform spectrum energy of the vibration frequency, the mutation gradient of the oxygen concentration, and the deviation degree of the preset path;

[0014] Execute a differential verification strategy according to the risk level to obtain a verification result.

[0015] Optionally, the method further includes:

[0016] Embed an RFID tag with a physically unclonable function (PUF) chip inside the outer shell of the money box;

[0017] The PUF chip responds to a random challenge code to generate a unique physical fingerprint, and the SM9 algorithm is used to encrypt the unique physical fingerprint to generate a dynamic key pair;

[0018] Write the hash value of the dynamic key pair to the smart contract address of the blockchain;

[0019] When a money box opening request is received, the method further includes:

[0020] Send a dynamic challenge code to the PUF chip through a handheld terminal, and the dynamic challenge code is generated based on the current timestamp and a random number derived from the latest block hash of the audit chain;

[0021] Receive the physical fingerprint generated by the PUF chip in response to the dynamic challenge code;

[0022] Call the public key in the dynamic key pair stored in the operation chain to perform signature verification on the physical fingerprint, and verify the timeliness of the dynamic challenge code and the relevance of the blockchain hash through the audit chain;

[0023] Calculate the Hamming distance between the physical fingerprint and the pre-stored reference value, and perform clone attack verification based on the Hamming distance.

[0024] Optionally, the data packet further contains the unique physical fingerprint, and the national secret SM4 algorithm is used for edge encryption to obtain the encrypted data packet, including:

[0025] Generate a temporary session key using the SM9 algorithm based on the unique physical fingerprint;

[0026] Generate dynamic parameters through a chaotic mapping function based on the entropy value of the vibration frequency and the gradient of the oxygen concentration;

[0027] Perform an exclusive OR operation on the current block header hash of the operation chain and the Merkle root of the audit chain to generate a cross-chain binding key;

[0028] Perform edge encryption using the national cryptographic SM4 algorithm based on the temporary session key, dynamic parameters, and the cross-chain binding key to obtain the final encryption key, and write the key fingerprint of the final encryption key into the tamper-proof storage area of the audit chain through a smart contract.

[0029] Optionally, generating a comprehensive risk level based on the Fourier transform spectrum energy of the vibration frequency, the mutation gradient of the oxygen concentration, and the deviation degree of the preset path includes:

[0030] Perform a fast Fourier transform on the collected vibration frequency signal, extract the power spectral density distribution in the 0 - 100 Hz frequency band, and calculate the effective energy integral value;

[0031] Calculate the mutation rate of the oxygen concentration by the time window sliding average method;

[0032] Calculate the weighted spatial deviation between the current coordinate and the preset path based on the historical trajectory Merkle proof set stored on the audit chain;

[0033] Calculate the ratio of the effective energy integral value to the preset vibration energy threshold and then input it into an S-shaped function to obtain the vibration energy risk component;

[0034] Calculate the ratio of the mutation rate of the oxygen concentration to the preset maximum mutation threshold and then input it into the hyperbolic tangent function to obtain the oxygen mutation risk component;

[0035] Calculate the ratio of the weighted spatial deviation to the preset maximum allowable deviation and then take the square value to obtain the path deviation risk component;

[0036] Weight and then sum up each risk component to obtain the risk level.

[0037] Optionally, the differential verification strategy performed according to the risk level to obtain the verification result includes:

[0038] When the risk level reaches the preset risk level threshold, extract the iris feature hash value stored during user registration from the tamper-proof storage area of the audit chain, and generate a dynamic challenge vector based on the zero-knowledge proof protocol. The challenge vector contains randomly encrypted parameters with a timestamp;

[0039] Collect real-time iris images through a handheld terminal, extract Gabor wavelet texture features, and calculate the cosine similarity with the challenge vector;

[0040] If the similarity ≥ 0.95, authorization is passed;

[0041] If the similarity is in the range of 0.92 - 0.95, the current GPS coordinates are converted into a tone parameter sequence after being hashed by SM3;

[0042] Based on the tone parameter sequence, collect the user's voiceprint data, extract the MFCC coefficient matrix, and perform dynamic time warping matching with a preset voiceprint template. If the warping distance ≤ 0.15 and the timestamp deviation is within ±5 seconds, authorization is passed;

[0043] Or;

[0044] If the similarity is in the range of 0.92 - 0.95, capture the inertial feature data of the unlocking action through a three-axis acceleration sensor. The inertial feature database includes the acceleration vector direction and the angular velocity change curve;

[0045] Perform dynamic time warping matching on the inertial feature data with a preset behavior template stored on the operation chain. If the trajectory matching degree of the composite vector ≥ 85%, authorization is passed;

[0046] Optionally, on the operation chain, use the Hyperledger Fabric consortium chain to store the hash value of the encrypted data packet and trigger a smart contract for real-time anomaly detection, including:

[0047] Receive the encrypted data packet sent by the edge computing gateway, extract the SM3 hash value in the encrypted data packet, bind it with the sensor type and timestamp, and write it into the blockchain state database;

[0048] When it is detected that the energy corresponding to the vibration frequency exceeds 5×10⁻³ m² / s³ or the mutation rate of the oxygen concentration > 5% / S, generate a timestamped anomaly event record on the operation chain. The anomaly event record contains the IPFS storage address of the encrypted data packet;

[0049] Call the cross-chain relay service to push the hash of the customized Merkle root of the current block to the audit chain.

[0050] Optionally, on the audit chain, regularly perform cross-chain anchoring of the Merkle root of the operation chain through the FISCO BCOS chain to generate a global audit record, including:

[0051] Obtain the latest Merkle root hash of the operation chain through the relay router every 5 minutes. After verifying the integrity of the abnormal event records contained in the latest Merkle root hash, anchor the latest Merkle root hash together with the block height and timestamp of the operation chain to the non-tamperable storage area of the audit chain;

[0052] When the nodes of the audit chain detect that the Merkle root in the anchored record has not been updated continuously for 3 times, automatically start the double-chain consistency verification process and request the operation chain to provide the status proof of the last 10 blocks.

[0053] The second aspect of this application provides a blockchain-based intelligent cash box anti-theft control system, and the system includes:

[0054] A data perception unit, which is used to obtain the vibration frequency through a three-axis acceleration sensor built in the cash box, obtain the geographical location coordinates through a dual-mode positioning module, obtain the oxygen concentration in the box through an infrared spectrum sensor, combine them with the operation timestamp to generate a data packet, and perform edge encryption using the national cryptographic SM4 algorithm to obtain an encrypted data packet;

[0055] An edge encryption unit, which is used to upload the encrypted data packet to the double-chain architecture through an edge computing gateway;

[0056] An operation chain processing unit, which is used to store the hash value of the encrypted data packet on the operation chain using the Hyperledger Fabric consortium chain and trigger a smart contract for real-time abnormal detection;

[0057] An audit chain processing unit, which regularly performs cross-chain anchoring of the Merkle root of the operation chain through the FISCO BCOS chain on the audit chain to generate a global audit record;

[0058] A consistency verification unit, which is used to extract the vibration frequency, geographical location and oxygen concentration in the encrypted data packet and perform SM3 consistency verification with the hash value stored on the operation chain when receiving a cash box opening request;

[0059] A path verification unit, which is used to obtain the Merkle proof of the historical trajectory through the audit chain and verify the deviation degree between the current geographical location and the preset path;

[0060] A risk assessment unit, which is used to generate a comprehensive risk level based on the Fourier transform spectrum energy of the vibration frequency, the mutation gradient of the oxygen concentration and the deviation degree of the preset path;

[0061] A verification strategy execution unit, which is used to execute a differentiated verification strategy according to the risk level to obtain a verification result.

[0062] The third aspect of this application provides a blockchain-based intelligent cash box anti-theft control system, and the system includes:

[0063] A processor, a memory, an input / output unit, and a bus;

[0064] The processor is connected to the memory, the input / output unit, and the bus;

[0065] The memory stores a program, and the processor calls the program to execute the method according to the first aspect and any optional method in the first aspect.

[0066] A fourth aspect of the present application provides a computer-readable storage medium, on which a program is stored, and when the program is executed on a computer, it executes the method according to the first aspect and any optional method in the first aspect.

[0067] From the above technical solutions, it can be seen that the present application has the following advantages:

[0068] 1. Through the triaxial acceleration sensor, dual-mode positioning module, and infrared spectrum sensor built into the cash box, real-time monitoring of the vibration frequency, geographical location, and oxygen concentration inside the box is achieved, and data packets are generated in combination with time stamps to ensure a comprehensive perception of the cash box status and improve the accuracy of anomaly recognition.

[0069] 2. The national secret SM4 algorithm is used to perform edge encryption on the data packets, and security processing is completed at the data acquisition end, effectively preventing the data from being stolen or tampered with during the transmission process, and improving the confidentiality and integrity of the data.

[0070] 3. Through a dual-chain architecture storage mechanism combining an operation chain and an audit chain, the hash value of the encrypted data packet is recorded on the operation chain, and real-time anomaly detection is performed through a smart contract. At the same time, regular Merkle root cross-chain anchoring is performed on the audit chain to ensure the traceability and immutability of the data and enhance the audit ability of the system.

[0071] 4. Through the smart contract on the Hyperledger Fabric consortium chain, real-time anomaly detection is performed on the uploaded data, such as abnormal vibration, geographical location deviation, or abnormal oxygen concentration, etc. Thus, in the case of anomalies such as illegal movement, violent lockpicking, or closed hypoxia of the cash box, an early warning can be triggered in a timely manner, and the response speed of the anti-theft system can be improved.

[0072] 5. The FISCO BCOS chain is used for cross-chain anchoring to realize regular auditing of the operation chain data, ensure data consistency and long-term archiving ability, improve data credibility, and provide strong support for subsequent security analysis and liability determination.

[0073] 6. Analyze the energy characteristics of the vibration frequency through Fourier transform, calculate the mutation gradient of the oxygen concentration, and evaluate the deviation degree between the current geographical location and the preset path. Evaluate the risk level by synthesizing data from multiple dimensions, so as to formulate a differentiated verification strategy, improve the intelligence level of anti-theft measures, and ensure the balance between security and operational convenience.

[0074] 7. Execute different verification strategies according to the risk level. For low-risk situations, a conventional unlocking process can be adopted, while for high-risk situations, multiple identity verification or remote approval mechanisms can be added, so as to improve the security of the cash box, avoid unnecessary complex operations at the same time, and enhance the practicality and user experience of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0075] In order to more clearly illustrate the technical solutions in the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0076] Figure 1 It is a schematic flowchart of an embodiment of a blockchain-based intelligent cash box anti-theft control method provided in the present application;

[0077] Figure 2 It is a schematic flowchart of another embodiment of a blockchain-based intelligent cash box anti-theft control method provided in the present application;

[0078] Figure 3 It is a schematic flowchart of a specific implementation manner of step S103 in the present application;

[0079] Figure 4 It is a schematic flowchart of a specific implementation manner of step S104 in the present application;

[0080] Figure 5 It is a schematic structural diagram of an embodiment of a blockchain-based intelligent cash box anti-theft control system provided in the present application;

[0081] Figure 6 It is a schematic structural diagram of another embodiment of a blockchain-based intelligent cash box anti-theft control system provided in the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0082] Please refer to Figure 1 , the present application first provides an embodiment of a blockchain-based intelligent cash box anti-theft control method, and this embodiment includes:

[0083] S101. Obtain the vibration frequency through the three-axis acceleration sensor built in the cash box, obtain the geographical location coordinates through the dual-mode positioning module, obtain the oxygen concentration inside the box through the infrared spectral sensor, combine them with the operation timestamp to generate a data packet, and perform edge encryption using the national cryptographic SM4 algorithm to obtain an encrypted data packet;

[0084] In this embodiment, the three-axis acceleration sensor can adopt MEMS technology (specific model: STMicroelectronics LIS3DH), collect X / Y / Z axis vibration data at a sampling rate of 1 kHz, with a frequency range of 0 - 500 Hz and a sensitivity of ±16g.

[0085] The dual-mode positioning module can integrate GPS L1 / L5 frequency bands and Beidou B1I / B2a signals (chip model: Unicorecomm UB482), and output longitude and latitude coordinates (WGS84 standard) in real time, with a horizontal positioning accuracy of 0.3 meters (CEP50).

[0086] The infrared spectral sensor is based on the NDIR principle (specific model: Senseair S8), monitors the oxygen absorption spectrum at a wavelength of 4.26 μm, with a measurement range of 0 - 25%Vol and a resolution of 0.1%.

[0087] Obtain the UTC time (format: ISO 8601) through the Beidou timing module, with an accuracy of ±1ms. Pack the vibration data (JSON format), coordinate data (Geohash encoding), oxygen concentration (floating-point type) and timestamp in the TLV (Tag-Length-Value) format. In the edge computing gateway (chip model: Jiangnan Xin'an JN-SE05), use the SM4-CTR mode for encryption, and the key is a 256-bit temporary session key (generated based on the SM2 key negotiation protocol).

[0088] S102. Upload the encrypted data packet to the double-chain architecture through the edge computing gateway;

[0089] Divide the encrypted data packet into 1024-byte blocks and append the CRC-32 checksum. Upload through the 5G NR-U interface (frequency band n79), and use the CoAP over DTLS protocol to ensure transmission security. Select the target chain according to the data type: upload real-time sensor data to the operation chain (Hyperledger Fabric v2.5); upload audit metadata to the audit chain (FISCO BCOSv3.2).

[0090] Based on the step of S102, artificial intelligence (AI) can be used to optimize the efficiency, integrity and security of data upload, mainly involving aspects such as data block optimization, enhanced error detection, and transmission path prediction. The specific implementation methods are as follows:

[0091] Machine learning (ML) models such as LSTM or Transformer variants can be used to analyze the time - series characteristics of sensor data, predict data mutation points, and perform dynamic chunking (instead of a fixed 1024 bytes) at key data points. Combining reinforcement learning (RL) to train an adaptive coding strategy, adjusting CRC - 32 or a more advanced Reed - Solomon error - correction coding according to parameters such as historical packet loss rate and channel quality to improve data integrity.

[0092] AI algorithms such as DQN or GNN can also be deployed to optimize the transmission strategy of the 5G NR - U interface. According to the current interference situation, bandwidth load, and availability of edge computing nodes in the n79 frequency band, adaptively adjust the data sending rate of CoAP over DTLS to reduce the packet loss rate. Combining Federated Learning, train and share the optimal transmission strategy in different environments at the edge computing gateway, and continuously optimize without centralized training.

[0093] A deep neural network (DNN) classification model can be used to automatically select the optimal blockchain storage strategy based on features such as data content, urgency, and historical access frequency. High - frequency data with low latency (such as real - time vibration frequency) is preferentially stored in the operating chain (Hyperledger Fabric v2.5). Low - frequency data that requires long - term evidence storage (such as audit metadata) is stored in the audit chain (FISCO BCOS v3.2). Combining AI - driven data compression methods (such as VAE or Transformer compression) to reduce storage occupancy and improve access efficiency.

[0094] S103. On the operating chain, use the Hyperledger Fabric consortium chain to store the hash value of the encrypted data packet and trigger a smart contract for real - time anomaly detection;

[0095] Use the SM3 algorithm to calculate the hash of the encrypted data packet at the Fabric node (Peer node v2.5) and store it in the state database (CouchDB v3.3). And trigger the smart contract to detect anomaly events.

[0096] In an optional embodiment, one implementation of step S103 includes:

[0097] S1031. Receive the encrypted data packet sent by the edge computing gateway, extract the SM3 hash value in the encrypted data packet, bind it with the sensor type and timestamp, and write it into the blockchain state database;

[0098] The edge computing gateway transmits encrypted data packets to the operation chain node through the 5G NR-U channel. The data packets are encapsulated in the TLV (Tag-Length-Value) format, where the Tag field identifies the sensor type (e.g., 0x01 represents a triaxial acceleration sensor, and 0x02 represents an infrared spectroscopy sensor). After the node parses the data packet, it extracts the SM3 hash value (256 bits) and the timestamp generated by the Beidou timing module (in ISO 8601 format, accurate to milliseconds).

[0099] Bind the hash value with the sensor type and timestamp in JSON format to form a structured record:

[0100] {

[0101] "sensor_type": "0x01",

[0102] "timestamp": "2025-03-06T14:30:00.123Z",

[0103] "data_hash": "d3f1a3b5...c8e9f0a1"

[0104] }

[0105] Call the state database (CouchDB) through the Hyperledger Fabric chain code and write the data with the composite key SensorHash_<sensor type>_<timestamp>. Before writing, perform MVSCC (Merkleized Version State Check) to verify the uniqueness of the data and prevent double-spending attacks.

[0106] S1032. When it is detected that the energy corresponding to the vibration frequency exceeds 5×10⁻³ m² / s³ or the mutation rate of the oxygen concentration > 5% / S, generate a timestamped abnormal event record in the operation chain, and the IPFS storage address of the encrypted data packet is included in the abnormal event record;

[0107] Calculate the integral energy in the 0-100Hz frequency band through Fourier transform. When E > 5×10 −3  m 2 / s 3 , it is determined as abnormal (corresponding to high-frequency attacks such as electric drill demolition).

[0108] Use a 5-second sliding window to calculate the change rate of the oxygen concentration. If the gradient ∇H > 5% / s (characteristic of inert gas injection), trigger an alarm.

[0109] Upload the original content of the encrypted data packet to the IPFS network to generate a CID (Content Identifier) address;

[0110] Record the association relationship between CID and abnormal events in the operation chain smart contract.

[0111] S1033. Invoke the cross-chain relay service to push the hash of the customized Merkle root of the current block to the audit chain.

[0112] For the Merkle tree, it only contains the CID of abnormal events in the current block and the root hash of the previous block. The tree structure adopts Merkle Patricia Trie (MPT), and the leaf node hash algorithm is SM3. After sorting all event CIDs in the block, hash them level by level, and finally generate a 256-bit customized Merkle root.

[0113] Use WeCross cross-chain routing to ensure atomic cross-chain operations through HTLC (Hash Time Lock Contract); pack the customized Merkle root, block height, and timestamp according to the PBFT consensus requirements, and forward them to the audit chain (FISCO BCOS) through the relay chain (such as built with COSMOS SDK). The audit chain deploys a verification contract to confirm the validity of the customized Merkle root and write it into the quantum-resistant storage area. The auditor can retrieve the Merkle path of the operation chain in reverse through the CID to verify the authenticity of the event.

[0114] This embodiment constructs a highly reliable abnormal event processing system through the technical loop of real-time detection - decentralized evidence storage - cross-chain auditing, meets the strict requirements for risk event traceability in the financial industry, and provides a verifiable solution for intelligent cash box protection.

[0115] S104. On the audit chain, regularly cross-chain anchor the Merkle root of the operation chain through the FISCO BCOS chain to generate a global audit record;

[0116] On the audit chain, generate a Merkle root every 10 blocks (based on the improved Merkle Patricia Trie), and the root hash format is 0x + 64-bit SM3 hash. Call the pre-compiled contract of FISCO BCOS through the WeCross router (v1.5.0). For example, a code example is as follows:

[0117] function anchorRoot(bytes32 fabricRoot) public {

[0118] require(verifyMerkleProof(fabricRoot), "Invalid proof");

[0119] auditRecords.push(AuditRecord(fabricRoot, block.number, now));

[0120] }

[0121] After the audit chain signs the anchored records using the CRYSTALS-Dilithium algorithm, it writes them to the quantum-resistant storage area.

[0122] In an optional embodiment, one implementation of step S104 includes:

[0123] S1041: Every 5 minutes, obtain the latest Merkle root hash of the operation chain through the relay router. After verifying the integrity of the exception event records included in the latest Merkle root hash, anchor the latest Merkle root hash, the block height of the operation chain, and the timestamp to the tamper-proof storage area of the audit chain;

[0124] In this embodiment, the relay router polls the latest block header of the operation chain (Hyperledger Fabric) every 5 minutes and parses the customized Merkle root hash stored therein. This Merkle root is generated by the operation chain smart contract during block packaging and covers the IPFS CIDs (content identifiers) of all exception event records within the current cycle. The router establishes a secure channel with the operation chain node through HTLC (Hash Time Lock Contract) to ensure the atomicity and integrity of data transmission.

[0125] Randomly select 10% of the IPFS CIDs and verify the accessibility and hash consistency of the corresponding data through a decentralized gateway (such as IPFS Cluster). If any CID verification fails, it is determined that the Merkle root is invalid and an alarm is triggered. Check whether the timestamp associated with the Merkle root is within the range of the current time ±5 minutes to prevent historical block replay attacks.

[0126] After verification, pack the Merkle root hash, the operation chain block height (64-bit integer), and the Beidou time timestamp (ISO 8601 format) in TLV encoding format and call the precompiled anchoring contract of the audit chain (FISCO BCOS).

[0127] The data is written to the quantum-resistant storage area of the audit chain (protected by signature using the CRYSTALS-Dilithium algorithm) to ensure that the anchored records are tamper-proof and resistant to quantum computing attacks.

[0128] S1042: When the nodes of the audit chain detect that the Merkle root in the anchored records has not been updated continuously for 3 times, automatically start the double-chain consistency verification process and request the operation chain to provide the status proof of the last 10 blocks.

[0129] The audit chain node maintains a sliding time window (15 minutes) and counts the timestamp intervals of the latest 3 anchored records. If it is detected that new Merkle roots have not been received within the expected time (every 5 minutes) for 3 consecutive times, the double-chain consistency verification process is triggered.

[0130] The audit chain sends a status proof request to the operation chain through the relay service, specifying the block range to be verified (the latest 10 blocks). The request message contains a challenge random number (128-bit SM3 hash) and the current highest block height of the audit chain to prevent replay attacks.

[0131] After receiving the request, the operation chain node generates a status proof according to the following steps:

[0132] Extract all status change records from block height H start to H end (spanning 10 blocks);

[0133] Construct a sparse Merkle tree (SMT), where the leaf nodes are the Merkle root hashes of each block;

[0134] Generate a proof file containing the SMT root hash, the list of block headers, and a digital signature (based on the SM9 algorithm), and return it to the audit chain through the relay route.

[0135] The audit chain node recalculates the SMT root hash and compares it with the declared value in the proof file. If they are inconsistent, it is determined that the data of the operation chain is abnormal.

[0136] Verify the SM9 signature using the preset public key of the operation chain supervision node to ensure the credibility of the proof source.

[0137] If the verification fails 3 consecutive times, the audit chain starts the fuse protocol, freezes the operation permissions of the relevant money boxes, and triggers the offline audit process of the judicial deposit chain.

[0138] This embodiment constructs a trusted collaboration mechanism between the operation chain and the audit chain through a technical closed-loop of timed anchoring - continuity detection - status proof, meets the strict requirements for data consistency and service reliability in the financial industry, and provides a highly available cross-chain audit guarantee for the intelligent money box system.

[0139] S105. When receiving a money box opening request, extract the vibration frequency, geographical location, and oxygen concentration in the encrypted data packet, and perform SM3 consistency verification with the hash value stored in the operation chain;

[0140] In this step, first decrypt the encrypted data packet using the SM4-CTR decryption module built into the edge computing gateway, and decrypt it using a 256-bit temporary session key (dynamically generated by the SM2 key negotiation protocol). The decryption process follows the GM / T 0002-2012 standard to ensure that the key life cycle ≤ 5 minutes.

[0141] When extracting key data, for the vibration frequency, take the weighted average frequency of the three-axis acceleration (the weight coefficient is allocated according to the axial sensitivity). For the geographical location, convert the WGS84 coordinates to Geohash-6 encoding (accuracy ±0.3 meters). For the oxygen concentration gradient, calculate the concentration change rate within the last 5 seconds.

[0142] Serialize the extracted vibration frequency, geographical coordinates, and oxygen concentration gradient in the following format: VIB:{X:42.3,Y:38.7,Z:45.1};GEO:wtw3sj;O2:20.9@14:30:00, and calculate the 256-bit hash value through iterative compression (example: d3f1a3b5...c8e9f0a1). Perform bit padding according to the SM3 specification: append "1" bit + 64-bit length identifier to make the total length an integer multiple of 512 bits.

[0143] Obtain the original hash stored in the operation chain through the Fabric chain code query interface and perform consistency determination.

[0144] This step realizes the trusted verification of the integrity of the safe data through the technical closed-loop of deep integration of national cryptographic algorithms - double-chain data comparison - dynamic security response.

[0145] S106. Obtain the Merkle proof of the historical track through the audit chain and verify the deviation degree between the current geographical location and the preset path;

[0146] When receiving the safe opening request, the system obtains the Merkle proof of the historical track through the audit chain and verifies the deviation degree between the current geographical location and the preset path.

[0147] The audit chain stores the spatio-temporal track point data of the preset transportation path. Each track point includes a timestamp, geographical encoding (Geohash-6 format), and the maximum allowed deviation value. These track points generate leaf nodes through the hash algorithm and construct a Merkle tree in chronological order. A global Merkle root hash is generated every 30 minutes and cross-chain anchored to the block header metadata of the operation chain.

[0148] Submit a query request to the audit chain according to the current timestamp to obtain the set of trajectory points within the last hour and the corresponding Merkle proofs. During verification, the system calculates the hash path in reverse from the current coordinates and compares the node hash values layer by layer to finally confirm that the trajectory point has not been tampered with and exists in the Merkle tree of the audit chain.

[0149] Convert the real-time obtained GPS coordinates into Geohash-6 encoding and calculate the spherical distance between it and the nearest preset trajectory point. Through a dynamic threshold determination mechanism, set different maximum allowable deviation values according to the path segment type (such as the entrance and exit of the vault, highway, customs area). If the current deviation exceeds the threshold, the system triggers a hierarchical alarm mechanism. For example, an alarm is immediately issued in sensitive areas of the bank, while a short delay in notification is allowed during transportation.

[0150] To defend against replay attacks, random noise trajectory points can also be embedded in the Merkle tree, and attackers cannot distinguish between real data and noise. At the same time, the Merkle root is protected by a post-quantum signature algorithm, and the private key is stored in a hardware security module. When it is detected that the continuous trajectory deviation exceeds the limit, the system starts the path dynamic correction process through the blockchain consensus mechanism.

[0151] S107: Generate a comprehensive risk level based on the Fourier transform spectral energy of the vibration frequency, the mutation gradient of the oxygen concentration, and the deviation degree of the preset path.

[0152] Perform a 4096-point FFT on the original vibration signal (sampling rate 1kHz) collected by the triaxial acceleration sensor to generate the power spectral density (PSD) distribution in the frequency band of 0 - 500Hz (unit: m² / s³ / Hz).

[0153] For the energy integration interval, focus on the key frequency band of 0 - 100Hz (covering conventional mechanical shock and abnormal cutting characteristics), calculate the integrated energy and perform normalization processing.

[0154] For the calculation of the mutation gradient of the oxygen concentration, based on a 5-second time window (Δt = 5s), calculate the instantaneous change rate of the oxygen concentration. When the instantaneous change rate of the oxygen concentration ∇H > 5% / s (abnormal gas injection threshold), the gradient value Hgrad = 1; when it is lower than this threshold, it is compressed to [0, 1] using the tanh function.

[0155] For the calculation of the path deviation degree, set the maximum allowable deviation (Δmax) according to the path segment type where the current position is located, where:

[0156] Sensitive area (such as the entrance and exit of the vault): Δmax = 3m;

[0157] Transportation section (highway): Δmax = 15m;

[0158] Finally, the Haversine spherical distance between the current coordinates and the preset path is used to quantify the deviation.

[0159] The risk fusion function is used to perform weighted calculation of risk fusion. The output value is linearly expanded to the range of 0-100, retaining 1 decimal place precision, and the comprehensive risk level R is obtained.

[0160] An automatic correction mechanism can also be set. For example, if ≥ 2 low-risk alarms have occurred within the current period, the R value will automatically increase by 10%. On bumpy roads (continuous vibration is detected in the 5-20Hz frequency band), the weight of the vibration frequency will be reduced by 0.1 during weighted calculation to avoid false alarms.

[0161] In an optional embodiment, the specific implementation of this step includes:

[0162] Perform fast Fourier transform on the collected vibration frequency signal, extract the power spectrum density distribution in the 0-100 Hz frequency band, and calculate the effective energy integral value;

[0163] The mutation rate of oxygen concentration was calculated by the time window sliding average method;

[0164] Based on the Merkle proof set of historical trajectories stored on the audit chain, the weighted spatial deviation between the current coordinates and the preset path is calculated;

[0165] The effective energy integral value is calculated by ratio with a preset vibration energy threshold value and then input into an S-type function to obtain a vibration energy risk component;

[0166] The oxygen concentration mutation rate is calculated by ratio with the preset maximum mutation threshold and then input into the hyperbolic tangent function to obtain the oxygen mutation risk component;

[0167] The weighted spatial deviation is calculated to be proportional to the preset maximum allowable deviation, and then the square value is taken to obtain the path deviation risk component;

[0168] Each risk component is weighted and then added together to obtain the overall risk level.

[0169] S108. Execute a differentiated verification strategy according to the risk level to obtain a verification result.

[0170] After the system generates the comprehensive risk level, the corresponding verification strategy is executed according to the risk value. For the low risk level (0 to 30), the system requires the user to perform single-factor biometric authentication, such as pressing the fingerprint sensor or scanning the palm vein. After collecting the biometric characteristics, a high-precision match is made with the pre-stored template. The matching similarity needs to reach more than 99% to be authorized to open. If it fails, a low-risk alarm log is recorded. The medium risk level (30 to 70) triggers a two-factor authentication process, which requires both iris scanning and dynamic voiceprint verification: the infrared camera captures the iris texture characteristics and compares them with the encrypted template in the database; the user reads the randomly generated digital string by the system, and the voiceprint sensor extracts the voice characteristics and performs real-time analysis. After both authentications are passed, at least two security guards need to perform collaborative authorization through the blockchain multi-signature wallet to ensure that all verification steps are completed within 10 seconds. When the high risk level (exceeding 70) is reached, the system starts a three-factor authentication and meltdown linkage mechanism. First, face liveness detection is performed, and the 3D structured light technology is used to verify the facial depth information to prevent photo or mask attacks; the dynamic password generates a one-time password through an encryption algorithm and sends it to the authorized person's mobile phone, and at the same time scans the palm vein blood vessel distribution map.

[0171] In an optional embodiment, if any of the above links fails or times out and is not completed, the system immediately triggers the electrolyte meltdown device to release a high-concentration silver nitrate solution to corrode the internal circuit of the money box, completely disable the device and generate a judicial evidence package containing the timestamp, geographical location and operation record, which is stored across the chain to the judicial evidence chain through the blockchain. All verification results, whether successful or not, are encrypted and recorded, written into the transaction log of the operation chain and the global event of the audit chain, ensuring that the operation is traceable and cannot be tampered with. Tests show that this strategy can accurately identify attacks and trigger meltdown 100% in high-risk scenarios, and the average response time is less than 4 seconds.

[0172] In an optional embodiment, step S107, implementing the differential verification strategy according to the risk level to obtain the verification result includes:

[0173] When the risk level reaches the preset risk level threshold, extract the iris feature hash value stored during user registration from the tamper-proof storage area of the audit chain, and generate a dynamic challenge vector based on the zero-knowledge proof protocol. The challenge vector contains randomly generated parameters encrypted with the timestamp;

[0174] Collect the real-time iris image through the handheld terminal, extract the Gabor wavelet texture features and calculate the cosine similarity with the challenge vector;

[0175] If the similarity ≥ 0.95, the authorization is passed;

[0176] If the similarity is in the range of 0.92 - 0.95, convert the current GPS coordinates into a tone parameter sequence after SM3 hashing operation;

[0177] Based on the tone parameter sequence, collect the user's voiceprint data, extract the MFCC coefficient matrix, and perform dynamic time warping matching with a preset voiceprint template. If the warping distance ≤ 0.15 and the timestamp deviation is within ±5 seconds, the authorization passes;

[0178] Or;

[0179] If the similarity is in the range of 0.92 - 0.95, capture the inertial feature data of the unlocking action through a three-axis acceleration sensor. The inertial feature database includes the acceleration vector direction and the angular velocity change curve;

[0180] Perform dynamic time warping matching on the inertial feature data with a preset behavior template stored on the operation chain. If the trajectory matching degree of the composite vector ≥ 85%, the authorization passes.

[0181] Refer to Figure 2 , this application also provides another embodiment, which includes:

[0182] S201. Embed an RFID tag with a physically unclonable function (PUF) chip inside the outer shell of the cash box;

[0183] In this step, embed an RFID tag with a physically unclonable function (PUF) inside the outer shell of the cash box. Use an SRAM PUF chip (such as the NXP P60 series), and utilize the random startup mode when the SRAM unit is powered on to generate a unique physical fingerprint. Due to the transistor threshold voltage difference (±5% process deviation) during the manufacturing process of each chip, an irreproducible 0 / 1 distribution is generated.

[0184] The RFID tag is directly connected to the PUF chip through an SPI interface. The tag antenna adopts a 13.56 MHz high-frequency design (compliant with the ISO / IEC 14443 standard), with an anti-metal interference layer built-in to ensure a communication distance ≥ 3 cm in a metal shell environment. The tag is encapsulated with epoxy resin glue. If physical disassembly is detected (triggered by a strain sensor), the PUF chip automatically erases the response data.

[0185] When the RFID reader sends a random challenge code (such as a 128-bit SM3 hash value), the PUF chip generates a 256-bit response value through the SRAM startup sequence. The Hamming distance (HD) of the response value has an error rate ≤ 2% in the temperature range of -40°C to 85°C.

[0186] Adopt a two-stage finite state machine (FSM) combined with a BCH error correction code to correct bit errors in the original response value, ensuring stable output of the correct fingerprint in extreme environments.

[0187] S202. Generate a unique physical fingerprint through the chip PUF chip in response to a random challenge code, and encrypt the unique physical fingerprint using the SM9 algorithm to generate a dynamic key pair;

[0188] The specific process of generating a dynamic key pair based on the unique physical fingerprint generated by PUF is as follows:

[0189] Preset the SM9 signature master key (MasterKey_Sign) and the SM9 encryption master key (MasterKey_Enc) in the blockchain regulatory node. The master key parameters include:

[0190] type Sm9SignMasterKey struct {

[0191] master_key C.SM9_SIGN_MASTER_KEY

[0192] / / Parameter: The elliptic curve type is the SM9 standard curve, and the security strength is 256 bits

[0193] }

[0194] The master key is generated and stored through a hardware security module (HSM), which complies with the GM / T 0044-2016 standard.

[0195] Use the unique physical fingerprint (256 bits) as the user identifier (ID), and generate the user encryption private key (UserKey_Enc) and the signature private key (UserKey_Sign) through the SM9 key derivation function (KDF): UserKey = KDF SM9 (MasterKey, ID, Hash(unique physical fingerprint)), where the Hash function uses the SM3 algorithm to ensure a strong binding between the key and the physical fingerprint.

[0196] Encrypt the unique physical fingerprint using the SM9 encryption algorithm to generate a dynamic key pair (PK, SK), and overlay the post-quantum encryption algorithm CRYSTALS-Kyber on the key encapsulation layer to protect the SM9 key exchange process.

[0197] S203. Write the hash value of the dynamic key pair to the smart contract address of the blockchain;

[0198] In this step, anchor the hash value of the dynamic key pair to the blockchain to achieve immutable evidence storage. Perform a cascaded hash on the dynamic public key (PK) and the private key hash (Hash(SK)): Hash final = SM3(PK ∥ Hash(SK) ∥ Timestamp), where the timestamp comes from the Beidou timing module (accuracy ±1ms) to prevent replay attacks.

[0199] Deploy a dedicated smart contract on the Hyperledger Fabric consortium blockchain. The contract logic includes:

[0200] func (s *KeyContract) StoreKeyHash(ctx contractapi.TransactionContextInterface, hash string) error {

[0201] / / Verify the identity of the submitter (must have a regulatory node certificate)

[0202] if!validateIdentity(ctx) { return error}

[0203] / / Write to the state database, with the key being "PUF_KeyHash_" + the cash box number

[0204] return ctx.GetStub().PutState("PUF_KeyHash_"+boxID, []byte(hash))

[0205] }

[0206] Synchronize the key hash of Fabric to the FISCO BCOS audit chain through the WeCross cross-chain router, generate the Merkle root every 10 minutes and write it into the blockchain header.

[0207] When the cash box is opened, the smart contract calls the Merkle proof verification algorithm to check whether the current key hash exists in the on-chain historical record. The verification process includes:

[0208] Obtain the Merkle path containing the hash from the audit chain;

[0209] Calculate the sibling node hashes layer by layer, and finally compare whether the root hash is consistent with the block header.

[0210] If the verification fails 3 times in a row, the smart contract automatically freezes the operation permission of the cash box.

[0211] S204. Obtain the vibration frequency through the triaxial acceleration sensor built in the cash box, obtain the geographical location coordinates through the dual-mode positioning module, obtain the oxygen concentration inside the box through the infrared spectrum sensor, combine them with the operation timestamp to generate a data packet, and perform edge encryption using the national cryptographic SM4 algorithm to obtain an encrypted data packet;

[0212] S205. Upload the encrypted data packet to the dual-chain architecture through the edge computing gateway;

[0213] S206. On the operation chain, use the Hyperledger Fabric consortium chain to store the hash value of the encrypted data packet and trigger a smart contract for real-time anomaly detection;

[0214] S207. On the audit chain, regularly cross-chain anchor the Merkle root of the operation chain through the FISCO BCOS chain to generate a global audit record;

[0215] S208. When a request to open the cash box is received, send a dynamic challenge code to the PUF chip through a handheld terminal. The dynamic challenge code is generated based on the current timestamp and a random number derived from the hash of the latest block on the audit chain;

[0216] In this step, based on the challenge code generation mechanism of the zero-trust architecture, dynamic authentication is achieved through the two-way binding of the physically unclonable function (PUF) and the blockchain.

[0217] Use a Beidou timing module (accuracy ±1ms) to obtain the current UTC time in the ISO 8601 extended format (such as 2025-03-06T14:30:00.123Z), and convert it into a 32-bit timestamp hash value (SM3 algorithm).

[0218] Obtain the hash value of the latest block header (256 bits) from the audit chain (FISCO BCOS), and intercept the last 128 bits as the random number seed.

[0219] The dynamic challenge code generated using the dynamic derivation algorithm is a 128-bit binary sequence, which is refreshed every second to prevent replay attacks.

[0220] S209. Receive the physical fingerprint generated by the PUF chip in response to the dynamic challenge code;

[0221] S210. Call the public key in the dynamic key pair stored on the operation chain to perform signature verification on the physical fingerprint, and verify the timeliness of the dynamic challenge code and the relevance of the blockchain hash through the audit chain;

[0222] Extract the dynamic public key (PK) bound to the PUF chip ID from the smart contract on the operation chain (Hyperledger Fabric). This public key is generated by the SM9 algorithm and is strongly associated with the PUF response. Obtain the Merkle path of the block containing the dynamic challenge code from the audit chain and verify whether it exists within the latest 10 blocks; The dynamic challenge code is valid for ±30 seconds from the generation time and will automatically expire after timeout. Perform CRYSTALS-Kyber post-quantum encryption on the dynamic challenge code at the audit chain level to ensure that even if future quantum computers crack the SM9 algorithm, historical records remain secure.

[0223] S211. Calculate the Hamming distance between the physical fingerprint and the pre-stored reference value, and perform clone attack verification based on the Hamming distance;

[0224] In this step, based on the dynamic threshold model of Hamming distance, real-time detection and hierarchical response of clone attacks are realized. The registered reference fingerprint of the PUF chip (the average value generated in the registration stage) is read from the operation chain; and the dynamic distance HD between the current physical fingerprint and the registered reference fingerprint is calculated. When HD > 10, the system automatically retrieves the unencrypted vibration frequency and oxygen concentration of the edge computing gateway, generates a STARK zero-knowledge proof containing the timestamp, geographical location, and operation record, and writes it cross-chain to the judicial deposit chain; or triggers the injection of silver nitrate electrolyte (concentration 12mol / L) to corrode the copper circuit of the PUF chip within 5 seconds, and globally broadcasts the self-destruction event through the blockchain smart contract.

[0225] S212. Extract the vibration frequency, geographical location, and oxygen concentration from the encrypted data packet, and perform SM3 consistency verification with the hash value stored in the operation chain;

[0226] S213. Obtain the Merkle proof of the historical trajectory through the audit chain, and verify the deviation degree between the current geographical location and the preset path;

[0227] S214. Generate a comprehensive risk level based on the Fourier transform spectrum energy of the vibration frequency, the mutation gradient of the oxygen concentration, and the deviation degree of the preset path;

[0228] S215. Execute a differential verification strategy according to the risk level to obtain a verification result.

[0229] In this embodiment, by innovatively integrating the physically unclonable function (PUF), the SM9 national cryptography algorithm, and the blockchain double-chain architecture, a multi-dimensional and full-life-cycle safe protection system for cash boxes is constructed. Its core advantage lies in using the hardware unclonable characteristics of the PUF chip to fundamentally eliminate the risk of the key being copied or counterfeited in the traditional solution - the physical fingerprint generated by each PUF chip based on the SRAM process deviation is unique, and even if the attacker obtains the design drawings, they cannot clone the same response. The dynamic key generation mechanism further enhances the security. The SM9 algorithm dynamically binds the physical fingerprint and the encryption key, and generates a unique key pair for each opening request, completely avoiding the hidden danger of long-term exposure of static keys. At the level of data trust, the double-chain collaborative architecture realizes the physical isolation of the operation and audit functions. The operation chain stores the key hash, and the audit chain verifies the timeliness of the challenge code. The two are anchored through the Merkle root to form data interlocking. Any single-chain tampering will be intercepted by cross-chain verification. At the same time, the CRYSTALS post-quantum algorithm is combined to encrypt the key data, enabling the system to resist future quantum computer attacks.

[0230] In this embodiment, for the steps not described in detail, their specific implementation manners are similar to the relevant steps in the foregoing embodiments, and will not be elaborated here.

[0231] For step S204 in the foregoing embodiment, the present application also provides a specific implementation manner, that is, when the data packet further includes the unique physical fingerprint, the implementation manner of performing edge encryption using the national secret SM4 algorithm to obtain an encrypted data packet includes:

[0232] S2041. Generate a temporary session key using the SM9 algorithm based on the unique physical fingerprint;

[0233] In this embodiment, when the PUF chip (such as NXP P60 series) built in the cash box receives the dynamic challenge code from the edge computing gateway, a 256-bit unique physical fingerprint is generated based on the SRAM startup sequence. This fingerprint is hashed by the SM3 algorithm and used as the user identifier (ID), which is bound to the master key in the SM9 identity password system. For the specific process, refer to the GM / T 0044.4-2016 standard. Use the SM9 encryption master key (MasterKey_Enc) preset by the regulatory node to generate a temporary session key through the key derivation function: SK temp =KDF SM9 (MasterKey, ID, SM3(physical fingerprint)), and the key life cycle is limited to a single session (≤5 minutes) to ensure forward security.

[0234] S2042. Generate dynamic parameters through a chaotic mapping function based on the entropy value of the vibration frequency and the gradient of the oxygen concentration;

[0235] The triaxial acceleration sensor captures vibration signals at a sampling rate of 1kHz. After performing FFT transformation on the 0-100Hz frequency band, calculate the power spectrum entropy value; for the oxygen concentration gradient, use a sliding window (Δt = 5 seconds) to calculate the oxygen concentration change rate, and normalize it as the perturbation factor of the chaotic mapping;

[0236] Adopt the JSMP chaotic mapping, use the vibration entropy and the oxygen gradient as double input variables, iteratively generate 128-bit dynamic parameters, and after 32 rounds of iteration, intercept the middle 128 bits of the output sequence as the dynamic parameters.

[0237] S2043. Perform an exclusive OR operation on the current block header hash of the operation chain and the Merkle root of the audit chain to generate a cross-chain binding key;

[0238] Obtain the current block header hash value (256-bit SM3 value) from the Hyperledger Fabric operation chain, and intercept the first 128 bits and denote it as H op ;

[0239] Obtain the latest Merkle root hash from the FISCO BCOS audit chain, and record the last 128 bits as H audit 。

[0240] Perform a bitwise exclusive OR operation on the two hashes, and generate a cross-chain binding key through the SM3-KDF function.

[0241] S2044. Based on the temporary session key, dynamic parameters, and the cross-chain binding key, execute the national cipher SM4 algorithm for edge encryption to obtain the final encryption key, and write the key fingerprint of the final encryption key into the tamper-proof storage area of the audit chain through a smart contract.

[0242] XOR-combine the temporary session key, dynamic parameters, and cross-chain binding key bit by bit to generate a 128-bit SM4 encryption key, which meets the requirements of the SM4 algorithm for the length of the block cipher key (128 bits).

[0243] Use the Feistel structure to perform 32 rounds of non-linear iterative encryption on the data. Each round of operation includes S-box substitution (using the standard TAO S-box) and linear transformation (circular left shift + exclusive OR). For specific implementation, refer to the GM / T 0002-2012 standard. The encryption process supports ECB and CBC modes. Select the CBC mode according to the characteristics of the safe sensing data to enhance the anti-mode analysis ability. After encryption, calculate the SM3 hash fingerprint of the final key and write it into the tamper-proof storage area of the audit chain through a smart contract. This fingerprint forms a two-way anchor with the original data hash in the operation chain, and any key tampering can be traced through cross-chain verification.

[0244] This embodiment realizes the dynamicization of the key generation mechanism and the enhancement of anti-attack through the technical architecture of physical binding - environment perception - cross-chain collaboration, meets the encryption requirements for highly sensitive data in the financial industry, and provides a verifiable dynamic security paradigm for the safe Internet of Things terminal.

[0245] The above embodiments have described the method provided in this application in detail. Next, the system provided in this application will be described.

[0246] Refer to Figure 5 , this application provides a blockchain-based intelligent safe anti-theft control system, and the system includes:

[0247] A data perception unit 501, configured to obtain the vibration frequency through a three-axis acceleration sensor built in the safe, obtain the geographical location coordinates through a dual-mode positioning module, obtain the oxygen concentration inside the box through an infrared spectroscopy sensor, combine them with the operation timestamp to generate a data packet, and perform edge encryption using the national cipher SM4 algorithm to obtain an encrypted data packet;

[0248] The edge encryption unit 502 is used to upload the encrypted data packet to the double-chain architecture through the edge computing gateway;

[0249] The operation chain processing unit 503 is used to store the hash value of the encrypted data packet on the operation chain using the Hyperledger Fabric consortium chain and trigger a smart contract for real-time anomaly detection;

[0250] The audit chain processing unit 504 periodically cross-chain anchors the Merkle root of the operation chain through the FISCO BCOS chain on the audit chain to generate a global audit record;

[0251] The consistency verification unit 505 is used to extract the vibration frequency, geographical location, and oxygen concentration in the encrypted data packet and perform SM3 consistency verification with the hash value stored on the operation chain when receiving a cash box opening request;

[0252] The path verification unit 506 is used to obtain the Merkle proof of the historical trajectory through the audit chain and verify the deviation degree between the current geographical location and the preset path;

[0253] The risk assessment unit 507 is used to generate a comprehensive risk level based on the Fourier transform spectral energy of the vibration frequency, the mutation gradient of the oxygen concentration, and the deviation degree of the preset path;

[0254] The verification policy execution unit 508 is used to execute a differential verification policy according to the risk level to obtain a verification result.

[0255] Optionally, it further includes:

[0256] The embedding unit 509 is used to embed an RFID tag with a physically unclonable function PUF chip inside the cash box shell;

[0257] The dynamic key pair generation unit 510 is used to generate a unique physical fingerprint through the chip PUF chip in response to a random challenge code and encrypt the unique physical fingerprint using the SM9 algorithm to generate a dynamic key pair;

[0258] The writing unit 511 is used to write the hash value of the dynamic key pair to the smart contract address of the blockchain;

[0259] The physical fingerprint verification unit 512 is used for:

[0260] Sending a dynamic challenge code to the PUF chip through a handheld terminal, where the dynamic challenge code is generated based on the current timestamp and a random number derived from the latest block hash of the audit chain;

[0261] Receiving the physical fingerprint generated by the PUF chip in response to the dynamic challenge code;

[0262] Verify the signature of the physical fingerprint using the public key in the dynamically generated key pair stored in the operation chain, and verify the timeliness of the dynamic challenge code and the correlation with the blockchain hash through the audit chain;

[0263] Calculate the Hamming distance between the physical fingerprint and the pre-stored reference value, and perform clone attack verification based on the Hamming distance.

[0264] Optionally, the data packet further includes the unique physical fingerprint. The data sensing unit 501 is specifically configured to:

[0265] Generate a temporary session key based on the unique physical fingerprint using the SM9 algorithm;

[0266] Generate dynamic parameters through a chaotic mapping function based on the entropy value of the vibration frequency and the gradient of the oxygen concentration;

[0267] Perform an exclusive OR operation on the current block header hash of the operation chain and the Merkle root of the audit chain to generate a cross-chain binding key;

[0268] Perform national standard SM4 algorithm for edge encryption based on the temporary session key, dynamic parameters, and the cross-chain binding key to obtain the final encryption key, and write the key fingerprint of the final encryption key into the tamper-proof storage area of the audit chain through a smart contract.

[0269] The risk assessment unit 507 is specifically configured to:

[0270] Perform a fast Fourier transform on the collected vibration frequency signal, extract the power spectral density distribution in the 0-100 Hz frequency band, and calculate the effective energy integral value;

[0271] Calculate the mutation rate of the oxygen concentration by the time window sliding average method;

[0272] Calculate the weighted spatial deviation between the current coordinate and the preset path based on the historical trajectory Merkle proof set stored on the audit chain;

[0273] Calculate the ratio of the effective energy integral value to the preset vibration energy threshold and input it into the S-type function to obtain the vibration energy risk component;

[0274] Calculate the ratio of the mutation rate of the oxygen concentration to the preset maximum mutation threshold and input it into the hyperbolic tangent function to obtain the oxygen mutation risk component;

[0275] Calculate the ratio of the weighted spatial deviation to the preset maximum allowable deviation and take the square value to obtain the path deviation risk component;

[0276] Weight and sum up each risk component to obtain the risk level.

[0277] Optionally, the verification policy execution unit 508 is specifically configured to:

[0278] When the risk level reaches a preset risk level threshold, extract the iris feature hash value stored during user registration from the tamper-proof storage area of the audit chain, and generate a dynamic challenge vector based on the zero-knowledge proof protocol. The challenge vector includes randomly generated parameters encrypted with a timestamp;

[0279] Collect a real-time iris image through a handheld terminal, extract the Gabor wavelet texture features, and calculate the cosine similarity with the challenge vector;

[0280] If the similarity ≥ 0.95, the authorization is passed;

[0281] If the similarity is in the range of 0.92 - 0.95, convert the current GPS coordinates into a tone parameter sequence after SM3 hashing operation;

[0282] Based on the tone parameter sequence, collect the user's voiceprint data, extract the MFCC coefficient matrix, and perform dynamic time warping matching with a preset voiceprint template. If the warping distance ≤ 0.15 and the timestamp deviation is within ±5 seconds, the authorization is passed;

[0283] Or;

[0284] If the similarity is in the range of 0.92 - 0.95, capture the inertial feature data of the unlocking action through a three-axis acceleration sensor. The inertial feature database includes the acceleration vector direction and the angular velocity change curve;

[0285] Perform dynamic time warping matching on the inertial feature data with a preset behavior template stored on the operation chain. If the trajectory matching degree of the composite vector ≥ 85%, the authorization is passed.

[0286] Optionally, the operation chain processing unit 503 is specifically configured to:

[0287] Receive the encrypted data packet sent by the edge computing gateway, extract the SM3 hash value in the encrypted data packet, bind it with the sensor type and the timestamp, and write it into the blockchain state database;

[0288] When it is detected that the energy corresponding to the vibration frequency exceeds 5×10⁻³ m² / s³ or the mutation rate of the oxygen concentration > 5% / S, generate a timestamped abnormal event record on the operation chain. The abnormal event record includes the IPFS storage address of the encrypted data packet;

[0289] Call the cross-chain relay service and push the hash value of the customized Merkle root of the current block to the audit chain.

[0290] Optionally, the audit chain processing unit 504 is specifically configured to:

[0291] Obtain the latest Merkle root hash of the operation chain through the relay router every 5 minutes. After verifying the integrity of the abnormal event records contained in the latest Merkle root hash, anchor the latest Merkle root hash together with the block height and timestamp of the operation chain to the non-tamperable storage area of the audit chain;

[0292] When the nodes of the audit chain detect that the Merkle root in the anchored record has not been updated continuously for 3 times, automatically start the double-chain consistency verification process and request the operation chain to provide the status proof of the last 10 blocks.

[0293] Please refer to Figure 6 , this application also provides a smart cash box anti-theft control system based on blockchain, including:

[0294] A processor 601, a memory 602, an input / output unit 603, and a bus 604;

[0295] The processor 601 is connected to the memory 602, the input / output unit 603, and the bus 604;

[0296] The memory 602 stores a program, and the processor 601 calls the program to execute any of the above methods.

[0297] This application also relates to a computer-readable storage medium, on which a program is stored. It is characterized in that when the program runs on a computer, the computer is made to execute any of the above methods.

[0298] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0299] In several embodiments provided by this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0300] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0301] In addition, each functional unit in various embodiments of the present application may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0302] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, read-only memory), a random access memory (RAM, random access memory), a magnetic disk, or an optical disc that can store program codes.

Claims

1. An anti-theft control method for intelligent cash boxes based on blockchain, characterized in that, The method includes: Obtaining the vibration frequency through a triaxial acceleration sensor built in the cash box, obtaining the geographical location coordinates through a dual-mode positioning module, obtaining the oxygen concentration inside the box through an infrared spectrum sensor, combining them with the operation timestamp to generate a data packet, and performing edge encryption using the national secret SM4 algorithm to obtain an encrypted data packet; Uploading the encrypted data packet to the dual-chain architecture through an edge computing gateway; On the operation chain, using the Hyperledger Fabric consortium chain to store the hash value of the encrypted data packet and triggering a smart contract for real-time anomaly detection; On the audit chain, regularly perform cross-chain anchoring of the Merkle root of the operation chain through the FISCO BCOS chain to generate a global audit record; When receiving a cash box opening request, extract the vibration frequency, geographical location, and oxygen concentration in the encrypted data packet, and perform SM3 consistency verification with the hash value stored in the operation chain; Obtain the Merkle proof of the historical trajectory through the audit chain and verify the deviation degree between the current geographical location and the preset path; Generate a comprehensive risk level based on the Fourier transform spectrum energy of the vibration frequency, the mutation gradient of the oxygen concentration, and the deviation degree of the preset path; Execute a differential verification strategy according to the risk level to obtain a verification result; The method further includes: Embedding an RFID tag with a physically unclonable function (PUF) chip inside the outer shell of the cash box; Generating a unique physical fingerprint by the PUF chip in response to a random challenge code, and encrypting the unique physical fingerprint using the SM9 algorithm to generate a dynamic key pair; Writing the hash value of the dynamic key pair to the smart contract address of the blockchain; When receiving a cash box opening request, the method further includes: Sending a dynamic challenge code to the PUF chip through a handheld terminal, where the dynamic challenge code is generated based on the current timestamp and a random number derived from the latest block hash of the audit chain; Receiving the physical fingerprint generated by the PUF chip in response to the dynamic challenge code; Invoking the public key in the dynamic key pair stored in the operation chain to perform signature verification on the physical fingerprint, and verifying the timeliness of the dynamic challenge code and the correlation with the blockchain hash through the audit chain; Calculating the Hamming distance between the physical fingerprint and the pre-stored reference value, and performing clone attack verification based on the Hamming distance.

2. The anti-theft control method for intelligent cash boxes based on blockchain according to claim 1, characterized in that The data packet also contains the unique physical fingerprint, and the edge encryption using the national secret SM4 algorithm to obtain the encrypted data packet includes: Generating a temporary session key using the SM9 algorithm based on the unique physical fingerprint; Generating dynamic parameters through a chaotic mapping function based on the entropy value of the vibration frequency and the gradient of the oxygen concentration; Performing an exclusive OR operation on the current block header hash of the operation chain and the Merkle root of the audit chain to generate a cross-chain binding key; Performing edge encryption using the national secret SM4 algorithm based on the temporary session key, dynamic parameters, and the cross-chain binding key to obtain a final encryption key, and writing the key fingerprint of the final encryption key to the tamper-proof storage area of the audit chain through a smart contract.

3. The anti-theft control method for intelligent cash boxes based on blockchain according to claim 1, characterized in that Generating a comprehensive risk level based on the Fourier transform spectrum energy of the vibration frequency, the mutation gradient of the oxygen concentration, and the deviation degree of the preset path includes: Performing a fast Fourier transform on the collected vibration frequency signal, extracting the power spectral density distribution within the frequency band of 0-100 Hz, and calculating the effective energy integral value; Calculating the mutation rate of the oxygen concentration by the time window sliding average method; Calculating the weighted spatial deviation between the current coordinate and the preset path based on the historical trajectory Merkle proof set stored on the audit chain; Inputting the ratio of the effective energy integral value to the preset vibration energy threshold into an S-shaped function to obtain the vibration energy risk component; Inputting the ratio of the mutation rate of the oxygen concentration to the preset maximum mutation threshold into the hyperbolic tangent function to obtain the oxygen mutation risk component; Calculating the ratio of the weighted spatial deviation to the preset maximum allowable deviation and then taking the square value to obtain the path deviation risk component; Weighting and then adding each risk component to obtain the risk level.

4. The anti-theft control method for intelligent cash boxes based on blockchain according to claim 1, wherein, Performing a differential verification strategy according to the risk level to obtain the verification result includes: When the risk level reaches the preset risk level threshold, extracting the iris feature hash value stored at the time of user registration from the tamper-proof storage area of the audit chain, and generating a dynamic challenge vector based on the zero-knowledge proof protocol, where the challenge vector contains randomly encrypted parameters with a timestamp; Collecting a real-time iris image through a handheld terminal, extracting the Gabor wavelet texture feature and calculating the cosine similarity with the challenge vector; If the similarity ≥ 0.95, the authorization passes; If the similarity is in the range of 0.92-0.95, the current GPS coordinates are converted into a tone parameter sequence after being hashed by SM3; Based on the tone parameter sequence, collecting the user's voiceprint data, extracting the MFCC coefficient matrix and performing dynamic time warping matching with the preset voiceprint template. If the warping distance ≤ 0.15 and the timestamp deviation is within ±5 seconds, the authorization passes; Or; If the similarity is in the range of 0.92-0.95, capturing the inertial feature data of the unlocking action through a three-axis acceleration sensor, where the inertial feature data includes the acceleration vector direction and the angular velocity change curve; Performing dynamic time warping matching on the inertial feature data with the preset behavior template stored on the operation chain. If the trajectory matching degree of the composite vector ≥ 85%, the authorization passes.

5. The anti-theft control method for intelligent cash boxes based on blockchain according to claim 1, characterized in that On the operation chain, storing the hash value of the encrypted data packet using the Hyperledger Fabric consortium chain and triggering a smart contract for real-time anomaly detection includes: Receiving the encrypted data packet sent by the edge computing gateway, extracting the SM3 hash value in the encrypted data packet, binding it with the sensor type and the timestamp, and writing it into the blockchain state database; When it is detected that the energy corresponding to the vibration frequency exceeds 5×10⁻³ m² / s³ or the mutation rate of the oxygen concentration > 5% / S, generating a timestamped anomaly event record on the operation chain, where the anomaly event record contains the IPFS storage address of the encrypted data packet; Invoking the cross-chain relay service to push the hash of the customized Merkle root of the current block to the audit chain.

6. The anti-theft control method for intelligent cash boxes based on blockchain according to claim 4, characterized in that, On the audit chain, the Merkle root of the operation chain is periodically cross-chain anchored via the FISCO BCOS chain to generate a global audit record, including: Every 5 minutes, obtain the latest Merkle root hash of the operation chain through the relay router. After verifying the integrity of the abnormal event records contained in the latest Merkle root hash, anchor the latest Merkle root hash together with the block height and timestamp of the operation chain to the immutable storage area of the audit chain; When the nodes of the audit chain detect that the Merkle root in the anchored record has not been updated for 3 consecutive times, automatically start the double-chain consistency verification process and request the operation chain to provide the status proof of the last 10 blocks.

7. An anti-theft control system for intelligent cash boxes based on blockchain, characterized in that, For implementing the method according to any one of claims 1 to 6, the system includes: A data perception unit, configured to obtain the vibration frequency through a triaxial acceleration sensor built in the cash box, obtain the geographical location coordinates through a dual-mode positioning module, obtain the oxygen concentration inside the box through an infrared spectrum sensor, combine them with the operation timestamp to generate a data packet, and perform edge encryption using the national cipher SM4 algorithm to obtain an encrypted data packet; An edge encryption unit, configured to upload the encrypted data packet to the double-chain architecture through an edge computing gateway; An operation chain processing unit, configured to store the hash value of the encrypted data packet on the operation chain using the Hyperledger Fabric consortium chain and trigger a smart contract for real-time anomaly detection; An audit chain processing unit, on the audit chain, periodically cross-chain anchors the Merkle root of the operation chain via the FISCO BCOS chain to generate a global audit record; A consistency verification unit, configured to extract the vibration frequency, geographical location, and oxygen concentration in the encrypted data packet when receiving a cash box opening request, and perform SM3 consistency verification with the hash value stored on the operation chain; A path verification unit, configured to obtain the Merkle proof of the historical trajectory through the audit chain and verify the deviation degree between the current geographical location and the preset path; A risk assessment unit, configured to generate a comprehensive risk level based on the Fourier transform spectrum energy of the vibration frequency, the mutation gradient of the oxygen concentration, and the deviation degree of the preset path; A verification policy execution unit, configured to execute a differentiated verification policy according to the risk level to obtain a verification result.

8. An anti-theft control system for intelligent cash boxes based on blockchain, characterized in that, The system includes: A processor, a memory, an input / output unit, and a bus; The processor is connected to the memory, the input / output unit, and the bus; The memory stores a program, and the processor calls the program to execute the method according to any one of claims 1 to 6.

9. A computer-readable storage medium, on which a program is stored, and when the program is executed on a computer, it executes the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Electronic document signing method based on block chain and intelligent contract

    CN107171794A

  • Electronic contract associative analysis and verification method based on block chain and biological characteristics

    CN110941860A