Data element circulation method and system for supply chain management

By using distributed storage and blockchain technology in supply chain management for data signature and verification, the abuse and leakage caused by unknown data ownership is solved, and the secure storage and legal acquisition of data is realized, ensuring the privacy and security of data.

CN120197192APending Publication Date: 2025-06-24LINYI UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510313600.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

There are problems of data abuse or leakage caused by unknown data ownership in the existing supply chain management. Traditional data rights confirmation methods have problems such as centralized management, single point of failure and power abuse, and lack of decentralized management and verification methods.

Method used

By uploading data files in a distributed storage system, and using blockchain technology for digital signature and on-chain storage, combining smart contract verification and distribution of proof data, triggering the corresponding verification search process to obtain data index values, thereby realizing secure storage and legal acquisition of data.

Benefits of technology

The management permissions of the data sharing platform are clarified, public verification and decentralized management of data ownership are realized, data abuse and leaks are avoided, and data privacy and security are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197192A_ABST
    Figure CN120197192A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data element circulation method and system for supply chain management, relates to the technical field of data sharing, and is used for solving the problem of data leakage caused by the fact that the power limit between current data subjects is indefinite. Obtaining a corresponding data index value; the data owning node embeds the management right label of the data sharing platform into a digital signature by using a private key of the data owning node and a public key of the data sharing platform, so as to send the digital signature and a preset verification parameter to the data sharing platform; the data owning node obtains data use node request information through the data sharing platform, generates distribution proof data, sends the distribution proof data to the data sharing platform and carries out uplink; and the data sharing platform verifies and distributes the proof data by using a block chain smart contract, a data index value is obtained through a post-triggering process so as to obtain a data file, and a data use node obtains a data address based on block chain verification and obtains a corresponding data file from the data sharing platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the technical field of data sharing, and in particular, to a method and system for data element circulation in supply chain management. Background Art

[0002] In the process of supply chain operation, data sharing is a key link to achieve upstream and downstream business collaboration. Through an efficient data sharing mechanism, each participating party can obtain detailed information about the required products, and use blockchain to ensure the transparency and traceability of supply chain logistics data, thereby improving collaboration efficiency and ultimately optimizing the overall operation of the supply chain.

[0003] In the current data flow process of supply chain management, there may be data abuse or leakage due to unclear data ownership. The traditional data right confirmation method is to stipulate an authoritative trusted third party to register and verify data ownership. Most of the authoritative institutions in this method are centralized management. When enterprises conduct data sharing and exchange, after the data ownership changes, they can only be verified through a third-party authoritative institution and cannot be publicly verified. Moreover, this method also has problems such as single-point failure and abuse of power caused by power concentration, which affect the management and verification of data ownership. When currently conducting data circulation after autonomously stipulating the data resource holding right, data product operation right, and data processing and use right, there is a lack of a mature and unified method to achieve decentralized management and verification of data ownership, as well as to divide and limit the data usage rights of the subjects corresponding to the three data rights. Therefore, at this time, data may be leaked due to unclear power division among participating subjects, posing a potential threat to the privacy and security of data. Summary of the Invention

[0004] To solve the above technical problems, one or more embodiments of this specification provide a method and system for data element circulation in supply chain management.

[0005] One or more embodiments of this specification adopt the following technical solutions: One or more embodiments of this specification provide a method for data element circulation in supply chain management, the method comprising: Data-owning nodes in the current supply chain upload data files with different attributes to a distributed storage system for storage according to a preset storage policy, so as to obtain a data index value corresponding to the data file returned by the distributed storage system; The data-owning node embeds a management right label of the data sharing platform into a digital signature according to the private key of the data-owning node and the public key of the data sharing platform, and sends the digital signature and preset verification parameters to the data sharing platform, and stores them on the chain; The data-owning node obtains the request information of the data-using node through the data sharing platform, generates a distribution proof data based on the request information, sends the distribution proof data to the data sharing platform, and stores it on the chain. The data sharing platform verifies the distribution proof data based on the smart contract of the blockchain. If the verification passes, it triggers a corresponding verification search process based on the attributes of the data file to obtain the corresponding data index value, and obtains the data file of the distributed storage system according to the corresponding data index value. The data-using node verifies and obtains the corresponding data address based on the blockchain, and obtains the corresponding data file in the data sharing platform based on the data address.

[0006] Optionally, in one or more embodiments of this specification, the data-owning node in the current supply chain uploads data files with different attributes to the distributed storage system for storage according to a preset storage policy, so as to obtain the data index value corresponding to the data file returned by the distributed storage system. Specifically, it includes: The data-owning node determines the data files to be shared based on the relevance between each original data and the business corresponding to the current supply chain. The data-owning node determines the attributes corresponding to each data file by determining whether there is a privacy data type in each data file; wherein, the attributes include: normal type and encrypted type. If it is determined that the attribute is the normal type, the data-owning node performs a hash calculation on the data file to obtain the hash value corresponding to the data file. The data-owning node uploads the hash value and the data file to the distributed storage system for storage, and obtains the data index value corresponding to the data file returned by the distributed storage system; wherein, the distributed storage system is the InterPlanetary File System (IPFS). If it is determined that the attribute is the encrypted type, the data-owning node encrypts the data file based on the public key of the data-owning node to obtain an encrypted data file. The data-owning node uploads the encrypted data file to the distributed storage system for storage, and obtains the data index value corresponding to the encrypted data file returned by the distributed storage system.

[0007] Optionally, in one or more embodiments of this specification, the data-owning node embeds the management right label of the data sharing platform into a digital signature according to the private key of the data-owning node and the public key of the data sharing platform, and sends the digital signature and preset verification parameters to the data sharing platform, and stores them on the chain. Specifically, it includes: The data owner generates a chameleon hash private key based on a random number generator to obtain a chameleon hash public key corresponding to the chameleon hash private key; The data owning node obtains the management right label of the data sharing platform, and hashes the data hash value corresponding to the management right label and the data file according to the chameleon hash public key, so as to controllably embed the management right label to generate a chameleon hash; Based on the chameleon hash private key and the public key of the data sharing platform, sign the chameleon hash to obtain a chameleon signature as a digital signature; Send the digital signature and preset verification parameters to the data sharing platform and store them on the chain.

[0008] Optionally, in one or more embodiments of this specification, after the data owning node embeds the management right label of the data sharing platform into a digital signature according to the private key of the data owning node and the public key of the data sharing platform, sends the digital signature and preset verification parameters to the data sharing platform, and stores them on the chain, the method further includes: The data owning node obtains the public key of the data sharing platform, and encrypts the data index value according to the public key of the data sharing platform to create a searchable encrypted ciphertext corresponding to the data sharing platform; The data owning node uploads the searchable encrypted ciphertext and preset trapdoor search conditions to the blockchain for storage.

[0009] Optionally, in one or more embodiments of this specification, the data owning node obtains the request information of the data using node through the data sharing platform, generates distribution proof data based on the request information, and sends the distribution proof data to the data sharing platform and stores it on the chain. Specifically, it includes: The data owning node obtains the request information of the data using node through the data sharing platform, and determines the requested data attributes of the data using node according to the request information and the attributes corresponding to each data file of the data owning node; If it is determined that the requested data attribute is a regular attribute, the data owning node generates a data user label of the data using node based on the request information; The data owning node signs the data use label based on the private key of the data owning node and registers it in the blockchain; The data owning node processes the request information to generate a one-time permission for the data using node, and sends the one-time permission and the signature of the data use label as distribution proof data to the data sharing platform; If it is determined that the requested data attribute is a ciphertext attribute, a re-encryption key is generated based on the public key of the data requester and the private key of the data owner node; The data owner node processes the request information to generate a one-time permission for the data usage node and a data proof signature; The re-encryption key, the one-time permission, and the digital proof signature are used as distribution proof data and sent to the data sharing platform.

[0010] Optionally, in one or more embodiments of this specification, before the data owner node obtains the request information of the data usage node through the data sharing platform, the method further includes: The data sharing platform determines a multi-level shared directory structure for sharing data files of each data owner based on the upstream and downstream relationships of each data owner within the current supply chain; The data sharing platform generates a shared directory for the current supply chain according to the data tags corresponding to each data owner and the multi-level shared directory structure; The data user determines the data rights party corresponding to the current demand, and based on the data rights party and the data request data of the data user, views the shared directory to generate request information.

[0011] Optionally, in one or more embodiments of this specification, a corresponding verification search process is triggered based on the attributes of the data file to obtain a corresponding data index value, and the data file of the distributed storage system is obtained according to the corresponding data index value, which specifically includes: If the attribute of the data file is a regular type, the data sharing platform obtains the data index value stored on the blockchain, and queries the distributed storage system according to the data index value to obtain the data file within the distributed system; If the attribute of the data file is a ciphertext type, the data sharing platform determines whether the verification result meets the preset search conditions of the data owner. If so, the data sharing platform generates a search trapdoor based on the re-encryption key and the private key of the data sharing platform; Search and decrypt the searchable encrypted ciphertext of the blockchain according to the search trapdoor to obtain the corresponding data index value, and query the distributed storage system according to the corresponding data index value to obtain the encrypted data file within the distributed system; The data sharing center performs proxy re-encryption on the encrypted data file based on the re-encryption key in the distribution proof data to obtain the re-encrypted ciphertext of the data file.

[0012] Optionally, in one or more embodiments of the present specification, the data-owning node verifies based on the blockchain to obtain a corresponding data address, and obtains a corresponding data file in the data sharing platform based on the data address, specifically including: The data-owning node verifies the data usage tag according to the blockchain; If the verification is passed and the attribute of the data file is a regular type, the data usage node obtains a corresponding data address, and obtains a corresponding data file in the data sharing platform according to the data address; If the verification is passed and the attribute of the data file is a ciphertext type, the data usage node obtains a corresponding data address, obtains a corresponding re-encrypted ciphertext in the data sharing platform according to the data address, and decrypts the re-encrypted ciphertext based on the private key of the data user to obtain a corresponding data file.

[0013] Optionally, in one or more embodiments of the present specification, after the data-owning node verifies based on the blockchain to obtain a corresponding data address and obtains a corresponding data file in the data sharing platform based on the data address, the method further includes: The data-owning node obtains a data acquisition success message returned by the data usage node based on the data sharing platform, and records the supply chain tag of the data usage node based on the data acquisition success message; The data-owning node divides each data usage node into groups based on the supply chain tag, and determines a group tag for each data usage node; When the data usage node shares the data file of the data-owning node, the data usage node sends the supply chain tag of the downstream data usage node to the data-owning node; The data-owning node determines whether the downstream usage node can obtain the data file according to the supply chain tag of the downstream usage node, the number of sharing times within the preset time of the data-owning node, and the group tag corresponding to the data usage node.

[0014] One or more embodiments of the present specification provide a data element circulation system for supply chain management, and the system includes: a data-owning node, a data sharing platform, a data usage node, and a distributed storage system; Among them, the data-owning node in the current supply chain uploads data files with different attributes to the distributed storage system for storage according to a preset storage strategy, so as to obtain a data index value corresponding to the data file returned by the distributed storage system; The data-owning node embeds the management right label of the data sharing platform into the digital signature according to the private key of the data-owning node and the public key of the data sharing platform, and sends the digital signature and the preset verification parameters to the data sharing platform, and stores them on the blockchain; The data-owning node obtains the request information of the data-using node through the data sharing platform, generates distribution proof data based on the request information, and sends the distribution proof data to the data sharing platform, and stores it on the blockchain; The data sharing platform verifies the distribution proof data based on the smart contract of the blockchain. If the verification passes, it triggers the corresponding verification search process based on the attributes of the data file to obtain the corresponding data index value, and obtains the data file of the distributed storage system according to the corresponding data index value; The data-using node verifies and obtains the corresponding data address based on the blockchain, and obtains the corresponding data file in the data sharing platform based on the data address.

[0015] The above at least one technical solution adopted in the embodiments of this specification can achieve the following beneficial effects: The data-owning node embeds the management right label of the data sharing platform into the digital signature and stores it on the blockchain. Utilizing the immutable feature of the blockchain, it clarifies the management authority of the data sharing platform, making the division of data ownership among different entities clearer, and effectively avoiding data abuse or leakage caused by unclear data ownership. And this process realizes the public verification of data ownership based on the blockchain. All participating parties can view and verify the data ownership information through the blockchain without relying on a single authoritative institution, solving the problems of inability to publicly verify, single-point failure, and abuse of power in traditional methods, and realizing decentralized data ownership management and verification. In addition, the data-owning node generates distribution proof data based on the request information of the data-using node and stores it on the blockchain. The data sharing platform verifies the distribution proof data based on the blockchain smart contract and triggers different verification search processes according to the data attributes, dividing and restricting the data usage rights of different entities. This avoids data leakage problems caused by unclear power division among participating entities, providing strong guarantees for the privacy and security of data. And the data user obtains the data address through blockchain verification, which ensures that the obtained data is indeed provided with the authorization of the data holder. Description of the Drawings

[0016] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. In the drawings: Figure 1 Schematic diagram of the process of a data element circulation method for supply chain management provided by an embodiment of this specification; Figure 2 Schematic diagram of the entity composition of a data element circulation system for supply chain management provided by an embodiment of this specification. Detailed implementation manners

[0017] The embodiments of this specification provide a data element circulation method and system for supply chain management.

[0018] To enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only some embodiments of this specification, rather than all embodiments. Based on the embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this specification.

[0019] As Figure 1 shown, the embodiments of this specification provide a schematic diagram of the process of a data element circulation method for supply chain management. It can be seen from Figure 1 that in one or more embodiments of this specification, a data element circulation method for supply chain management includes the following steps: S101: The data-owning node in the current supply chain uploads data files with different attributes to the distributed storage system for storage according to a preset storage policy, so as to obtain the data index value corresponding to the data file returned by the distributed storage system.

[0020] In order to enable data owners to flexibly select the nodes participating in storage according to actual needs, improve the autonomy of storage, and avoid risks brought by centralized storage of data on a single server, such as server failures and single-point attacks. In the embodiments of this specification, the data-owning nodes in the current supply chain upload data files with different attributes to a distributed storage system for storage according to a pre-set storage strategy. Thus, a data index value corresponding to the data file is obtained from the distributed storage system. It can be understood that the data index is like a pointer pointing to the data storage location. Through it, the storage location of the required data in the distributed storage system can be quickly located, thus greatly shortening the data search time, improving the data access efficiency, helping all parties participating in the supply chain to quickly obtain detailed information about the required products, and enhancing the business collaboration efficiency.

[0021] Specifically, in one or more embodiments of this specification, the data-owning nodes in the current supply chain upload data files with different attributes to a distributed storage system for storage according to a preset storage strategy to obtain a data index value corresponding to the data file from the distributed storage system. The specific process includes the following: The data-owning node will determine the data files to be shared according to the relevance of each piece of original data to the business corresponding to the current supply chain. Then, since data, as a production factor, is gradually becoming one of the core driving forces in the modern economic system, the security of data is crucial during the circulation process. Data owners do not want the privacy data they store to be leaked. Therefore, in order to avoid the leakage of privacy data, the data-owning node will determine the attributes corresponding to each data file by determining whether there is a privacy data type in each data file, so as to determine whether the data file needs to be encrypted and stored based on the attributes. It can be understood that the attributes include: regular type and encrypted type. If it is determined that the attribute is of the regular type, then the data-owning node performs a hash calculation on the data file to obtain the hash value corresponding to the data file. Then, the data-owning node will upload the hash value and the data file to the distributed storage system for storage, and obtain the data index value corresponding to the data file returned by the distributed storage system. Among them, the distributed storage system is the InterPlanetary File System (IPFS). The combination of the data index and the hash value in this process provides a basis for access control, facilitating subsequent access by only legitimate users who have the correct permissions and can verify the hash value through the data index to obtain the correct data, preventing unauthorized access and data leakage, and helping to ensure that data can only be accessed and used by authorized downstream data requesters in supply chain data sharing.

[0022] If it is determined that the attribute is of the encrypted state type, the data owner node encrypts the data file according to the public key of the data owner node to obtain an encrypted data file. Then, the data owner node uploads the encrypted data file to the distributed storage system for storage and obtains the data index value corresponding to the encrypted data file returned by the distributed storage system. In this process, the data file is encrypted with the public key of the data owner node, and only the node holding the corresponding private key can decrypt it, greatly reducing the risk of the data being illegally obtained and viewed in the distributed storage system. Obtaining the index value corresponding to the encrypted data file facilitates the data owner node and the authorized party to quickly locate and manage the encrypted data stored in the distributed system, improves the data retrieval and call efficiency, and ensures that the data can be normally used in the business process in the encrypted state.

[0023] S102: The data owner node embeds the management right label of the data sharing platform into the digital signature according to the private key of the data owner node and the public key of the data sharing platform, and sends the digital signature and the preset verification parameter to the data sharing platform, and performs on-chain storage.

[0024] Under the framework of "separation of three powers", the ownership, management right and use right of data are allocated among different entities. Once a data leakage event occurs, the accountability mechanism often faces challenges. The unclear division of ownership makes the responsibility attribution ambiguous, and all parties may shift the blame to each other, resulting in the problem being difficult to be solved quickly and effectively. To achieve the protection of data ownership in the process of data sharing, it is necessary to first achieve the controllable embedding and dynamic change of data ownership. Therefore, in the embodiments of this specification, the data owner node embeds the management right label of the data sharing platform into the digital signature according to the private key of the data owner node and the public key of the data sharing platform, and sends the digital signature and the preset verification parameter to the data sharing platform, and performs on-chain storage. It can be understood that in the process of supply chain operation, data sharing is the key link to realize the upstream and downstream business collaboration. Through an efficient data sharing mechanism, each participating party can obtain the detailed information of the required products. Therefore, through data on-chain, the transparency and traceability of supply chain logistics data can be ensured through the blockchain, thereby improving the collaboration efficiency and ultimately optimizing the overall operation of the supply chain.

[0025] In one or more embodiments of this specification, a three-power separation and right confirmation framework with controllable ownership is constructed by using blockchain and chameleon signature. Specifically, the data owner node embeds the management right label of the data sharing platform into the digital signature according to the private key of the data owner node and the public key of the data sharing platform, and sends the digital signature and the preset verification parameter to the data sharing platform, and performs on-chain storage, including the following process: First, the data owner generates a chameleon hash private key based on a random number generator to obtain the corresponding chameleon hash public key. Then, the data-owning node obtains the management right label of the data sharing platform and hashes the management right label and the data hash value corresponding to the data file according to the chameleon hash public key, so as to controllably embed the management right label to generate a chameleon hash. Then, the chameleon hash private key and the public key of the data sharing platform are used to sign the chameleon hash to obtain a chameleon signature as a digital signature. Then, the digital signature and the preset verification parameters are sent to the data sharing platform and stored on the chain.

[0026] In this process, by embedding the management right label of the data sharing platform into the digital signature, the data management right owned by the data sharing platform is clearly identified, making the attribution of the management right clear and definite under the "separation of three powers" framework, and avoiding the problem of responsibility shifting caused by unclear ownership division. Using the chameleon hash to process the management right label and the data hash value realizes the controllable embedding of the management right label. This mechanism not only ensures the close association between the label and the data, but also makes it difficult to tamper with the corresponding relationship between the data and the label through hashing, ensuring the controllability of data ownership. And the digital signature and the preset verification parameters are stored on the chain. The characteristics of the blockchain make this information public, transparent and tamper-proof. All participating parties can view the granting of data management rights through the blockchain, ensuring the fairness and transparency of the whole process.

[0027] Furthermore, in the scenario of data sharing, there may be problems with unclear power boundaries between different data subjects during the circulation of encrypted data, which may lead to ownership disputes during the data sharing process and increase the risk of data leakage. In order to achieve permission control by dividing the scope of powers exercised by each data subject and solve the data leakage problem caused by unclear power boundaries between data subjects. Under the data ownership management framework based on the "separation of three powers" as the basic theory, it is necessary to clearly divide the powers among the data owner, the data manager, and the data requester. At this time, in order to enable the data manager to manage the distribution of data and ensure that it does not obtain data beyond the scope of its authority. In one or more embodiments of this specification, after the data-owning node embeds the management right label of the data sharing platform into the digital signature according to the private key of the data-owning node and the public key of the data sharing platform, and sends the digital signature and the preset verification parameters to the data sharing platform and stores them on the chain, the method further includes the following process: The data-owning node obtains the public key of the data sharing platform to encrypt the data index value according to the public key of the data sharing platform, and creates a searchable encrypted ciphertext corresponding to the data sharing platform; then the data-owning node uploads the searchable encrypted ciphertext and the preset trapdoor search condition to the blockchain for storage. That is, in the distribution management right stage, the data-owning node needs to obtain the public key of the data sharing platform with the management right, use the public key of the data sharing platform to create a searchable encrypted ciphertext that only the data sharing platform can search and verify for the data index, and set the trapdoor search condition so that only the data sharing platform with the trapdoor can obtain the encrypted data index and decrypt it when it meets the trapdoor search condition set by the data owner.

[0028] In this process, by creating a specific searchable encrypted ciphertext and trapdoor search condition for the data sharing platform, the power scope of the data manager is clearly defined. The data manager can only obtain and decrypt the data index when meeting the trapdoor search condition, which clarifies its authority in data distribution management, avoids the blurred power boundaries among the data owner, data requester, and effectively prevents the ownership disputes caused by unclear power definition. This mechanism standardizes the operation process of the data manager in the data distribution process, enabling it to only perform data management-related operations within the established authority, reducing the risk of power overstepping due to non-standard operations, and ensuring the orderly operation of the data ownership management framework. Encrypting the data index value with the public key of the data sharing platform, only the data sharing platform can decrypt it with the corresponding private key, providing high-strength encryption protection for this key information. Even if the data is illegally obtained during storage or transmission, without the private key, it is impossible to obtain the effective data index, and thus it is difficult to obtain the original data, greatly reducing the data leakage risk. In addition, setting the trapdoor search condition adds additional restrictions for the data sharing platform to obtain the data index. Only when meeting the specific trapdoor condition can the data sharing platform obtain and decrypt the data index, further enhancing the security of data access.

[0029] S103: The data-owning node obtains the request information of the data-using node through the data sharing platform, generates distribution proof data based on the request information, sends the distribution proof data to the data sharing platform, and stores it on the chain.

[0030] When a data usage node needs to obtain data from a data owner node, the data owner node will obtain the request information of the data usage node through the data sharing platform, generate distribution proof data based on the request information, send the distribution proof data to the data sharing platform, and store it on the blockchain for subsequent public verification. Specifically, in one or more embodiments of this specification, the data owner node obtains the request information of the data usage node through the data sharing platform, generates distribution proof data based on the request information, sends the distribution proof data to the data sharing platform, and stores it on the blockchain. The specific process includes the following: First, the data owner node obtains the request information of the data usage node through the data sharing platform, and determines the requested data attributes of the data usage node according to the request information and the attributes corresponding to each data file of the data owner node. If it is determined that the requested data attribute is a regular attribute, the data owner node generates a data user label for the data usage node based on the request information. Then, the data owner node signs the data usage label with its private key and registers it on the blockchain, so that subsequent downstream data requesters need to verify their data usage labels according to the ownership information registered on the blockchain to ensure the authenticity of data ownership, and then obtain the data to be shared from the platform. In addition to signing the data usage label, the data owner node also processes the request information to generate a one-time permission for the data usage node, and sends the one-time permission and the signature of the data usage label as distribution proof data to the data sharing platform.

[0031] If it is determined that the requested data attribute is a confidential attribute, the data owner node will generate a re-encryption key based on the public key of the data requester and the private key of the data owner node. Then, the data owner node processes the request information to generate a one-time permission for the data usage node and a data proof signature. The re-encryption key, the one-time permission, and the digital proof signature are sent to the data sharing platform as distribution proof data.

[0032] In the above steps, whether it is data with regular attributes or encrypted attributes, by generating specific tags and signing and registering them on the blockchain, a clear proof of ownership of the data usage right for the data usage node is provided. Downstream data requesters can verify the data usage right tags based on the information on the blockchain to ensure the authenticity of data ownership and guarantee the legality of data usage at the source. For data with encrypted attributes, the method of generating re-encryption keys further enhances data security. The re-encryption keys are generated based on the public key of the data requester and the private key of the data owner node, keeping the data encrypted during transmission and use. Only the data requester with the corresponding private key can decrypt it, reducing the risk of data leakage. Generating a one-time license as part of the distribution proof data restricts the timeliness and applicability in specific scenarios of data usage. Even if the distribution proof data is intercepted during transmission, due to the limitation of the one-time license, it is difficult for illegal acquirers to illegally use the data in other scenarios, enhancing the security and controllability of the data.

[0033] Further, in one or more embodiments of this specification, before the data owner node obtains the request information of the data usage node through the data sharing platform, the method further includes the following process: Based on the upstream and downstream relationships of each data owner within the current supply chain, the data sharing platform determines the multi-level shared directory structure for sharing data files by each data owner. For example, in a manufacturing supply chain, the raw material supplier is upstream, the component manufacturer is in the middle, and the finished product assembler is downstream. The data sharing platform will determine the hierarchical position of the data files shared by each data owner in the entire supply chain according to this upstream and downstream order, thus constructing a multi-level shared directory structure. This structure reflects the flow path and hierarchical relationship of data in the supply chain, helping data users more intuitively understand the source and distribution of data.

[0034] Then, based on the data tags corresponding to each data owner and the multi-level sharing directory structure, the data sharing platform generates a sharing directory for the current supply chain. By combining the data tags with the multi-level sharing directory structure, the sharing directory not only presents the hierarchical relationship of the data but also enables data users to quickly locate the data categories they need through the data tags. For example, the sharing directory may be presented in a tree structure, where each node represents a data owner, and the data tags on the nodes indicate relevant information about the data provided by that data owner, such as "raw material supplier - metal material specification data", "component manufacturer - part dimension data", etc. The data user determines the data rights holder corresponding to the current demand, requests data from the data rights holder according to the data request of the data user, views the sharing directory, and generates a request message. By searching for data related to the data rights holder and their own needs in the sharing directory, the data user can learn information such as the location and acquisition method of the data in the supply chain. Then, based on this information, the data user generates a request message. This request message contains the specific needs of the data user, such as a detailed description of the required data, the purpose of use, etc., in order to accurately convey it to the data owner node and thus obtain the required data.

[0035] S104: The data sharing platform verifies the distribution proof data based on the smart contract of the blockchain. If the verification is passed, it triggers a corresponding verification search process based on the attributes of the data file to obtain the corresponding data index value, and obtains the data file of the distributed storage system according to the corresponding data index value.

[0036] To enable the data sharing platform to obtain the data file to be shared from IPFS through indexing within the management authority, in the embodiments of this specification, the data sharing platform verifies the distribution proof data according to the smart contract of the blockchain. If the verification is passed, it triggers a corresponding verification search process according to the attributes of the data file to obtain the corresponding data index value, and then obtains the data file of the distributed storage system according to the corresponding data index value. In this process, the smart contract can accurately compare and verify the contents of the distribution proof data, such as the data user tag signature, one-time license, etc., with the preset rules, and strictly control the authority and conditions for data acquisition. It ensures the fairness and accuracy of the verification process. Only the distribution proof data generated through legal processes can pass the verification, effectively preventing illegal data requests and data leakage, and ensuring the security and legality of the data.

[0037] Specifically, in one or more embodiments of this specification, triggering a corresponding verification search process based on the attributes of the data file to obtain the corresponding data index value, and obtaining the data file of the distributed storage system according to the corresponding data index value specifically includes the following process: If the attribute of the data file is of the regular type, the data sharing platform will obtain the data index value stored on the blockchain, and then query the distributed storage system according to the data index value to obtain the data file within the distributed system. If the attribute of the data file is of the ciphertext type, the data sharing platform will determine whether the verification result meets the preset search conditions of the data owner. When it is satisfied, the data sharing platform will generate a search trapdoor based on the re-encryption key and the private key of the data sharing platform, and then search and decrypt the searchable encrypted ciphertext of the blockchain according to the search trapdoor to obtain the corresponding data index value, and query the distributed storage system according to the corresponding data index value to obtain the encrypted data file within the distributed system. The data sharing center performs proxy re-encryption on the encrypted data file based on the re-encryption key in the distribution proof data to obtain the re-encrypted ciphertext of the data file. In this process, for ciphertext type data, not only the re-encryption key is used to enhance data confidentiality, but also by setting preset search conditions and generating search trapdoors, the data index value can only be obtained when all strict conditions are met, which greatly increases the security of data acquisition. Even if the data is maliciously attacked during transmission or storage, it is difficult for the attacker to obtain a valid data index without meeting the complex conditions, and thus cannot obtain the encrypted data file, effectively protecting the security of sensitive data. The data sharing center performs proxy re-encryption on the encrypted data file based on the re-encryption key in the distribution proof data, further confusing the data content to ensure that even when the data is flowing in the sharing center, the real data information will not be leaked.

[0038] S105: The data usage node obtains the corresponding data address based on the blockchain verification, so as to obtain the corresponding data file within the data sharing platform based on the data address.

[0039] Based on the above steps S101 - S104, after the data holder ensures that the ownership of the shared data is within its own scope and the data manager ensures that it does not obtain data beyond the authorized scope, in order to enable the data user to confirm that the data obtained is indeed provided by the data holder with authorization. In the embodiments of this specification, the data usage node will obtain the corresponding data address according to the blockchain verification, and then obtain the corresponding data file within the data sharing platform according to the data address.

[0040] Specifically, in one or more embodiments of this specification, the data ownership node obtains the corresponding data address based on the blockchain verification, so as to obtain the corresponding data file within the data sharing platform based on the data address, which specifically includes the following process: First, the data-owning node verifies the data usage label according to the blockchain. If the verification passes and the attribute of the data file is of the regular type, then the data-using node obtains the corresponding data address, and thus obtains the corresponding data file in the data sharing platform according to the data address. If the verification passes and the attribute of the data file is of the encrypted type, then based on the above, after the data-using node obtains the corresponding data address, what is obtained according to the data address is the re-encrypted ciphertext corresponding in the data sharing platform. At this time, it is necessary to decrypt the re-encrypted ciphertext based on the private key of the data user to obtain the corresponding data file.

[0041] In this process, for encrypted-type data, first, the legality of data acquisition is ensured through data usage label verification. What is obtained is the re-encrypted ciphertext, rather than the direct original data, which further enhances the confidentiality of data during transmission and storage. Only the data-using node holding the specific private key can decrypt to obtain the original data file, greatly reducing the risk of data leakage and ensuring the security of sensitive data.

[0042] By verifying the data usage label through the blockchain, the data holder can strictly control the usage rights of the data. Only the authorized and verified data-using nodes can obtain the data, ensuring that the ownership of the shared data is always within their control, preventing the data from being illegally obtained and misused, and safeguarding their own data rights. And this process clarifies the scope of authority of the data manager. The data manager can only assist the data-using node to obtain the corresponding data according to the established rules and cannot obtain data beyond the scope of authority. This avoids the possible over-authorization operations of the data manager due to ambiguous authority, ensuring the standardization and security of data management. And the data user obtains the data address through blockchain verification, which ensures that the obtained data is indeed provided by the data holder with authorization. For encrypted-type data, the method of using re-encrypted ciphertext and private key decryption not only ensures the security of data during transmission and storage, but also enables the data user to normally obtain and use the data under the condition of meeting the requirements.

[0043] Furthermore, in order to avoid the problem that the data-using node shares the shared data file obtained from the data-owning node with the next data-using node, making it impossible for the data-owning node to determine whether its shared data is still within its ownership scope. In one or more embodiments of this specification, after the data-owning node verifies through the blockchain to obtain the corresponding data address and obtains the corresponding data file in the data sharing platform based on the data address, the method further includes the following process: The data-owning node obtains the data usage success information from the data-using node based on the data returned by the data sharing platform, and records the supply chain label of the data-using node based on the data usage success information. By obtaining the data usage success information and recording the supply chain label, the data-owning node can comprehensively understand the information of each data-using node, and know the flow direction and usage objects of the data. This enables the data-owning node to have a comprehensive and accurate control over the entire process of data sharing, and clearly know which nodes have obtained its data. Then, the data-owning node groups the data-using nodes according to the supply chain labels, determines the group labels of each data-using node, and based on the supply chain labels for grouping, can formulate differentiated data sharing strategies according to the characteristics of different groups and the cooperation relationship with itself. For example, more relaxed permissions are given to the core partner group, and relatively strict permissions are set for the general partner group. This helps to effectively control the dissemination scope and frequency of data in combination with the number of sharing times within the preset time, prevent the over-diffusion of data, and protect the rights and interests of the data-owning node.

[0044] When the data-using node shares the data file of the data-owning node, the data-using node will send the supply chain label of the downstream data-using node to the data-owning node, so that each data sharing behavior is under the supervision of the data-owning node. At this time, the data-owning node determines whether the downstream data-using node can obtain the data file based on the supply chain label of the downstream data-using node, the number of sharing times of the data-owning node within the preset time, and the group label corresponding to the data-using node. By comprehensively evaluating the relevant information of the downstream data-using node to determine its data access permission, data security risks can be effectively prevented and controlled. For example, if it is found that the supply chain label of a certain downstream node shows potential security risks, the data-owning node can refuse its access to the data, reducing the risk of data leakage or malicious use, and ensuring the security of data in the supply chain.

[0045] As Figure 2 shown, the embodiment of this specification provides a data element circulation system for supply chain management, which consists of Figure 2 It can be known that in one or more embodiments of this specification, a data element circulation system for supply chain management includes: a data-owning node, a data sharing platform, a data-using node, and a distributed storage system; Among them, the data-owning node in the current supply chain uploads data files with different attributes to the distributed storage system for storage according to the preset storage strategy, so as to obtain the data index value corresponding to the data file returned by the distributed storage system; The data-owning node embeds the management right label of the data sharing platform into a digital signature according to the private key of the data-owning node and the public key of the data sharing platform, and sends the digital signature and the preset verification parameters to the data sharing platform for on-chain storage; The data-owning node obtains the request information of the data-using node through the data sharing platform, generates distribution proof data based on the request information, and sends the distribution proof data to the data sharing platform for on-chain storage; The data sharing platform verifies the distribution proof data based on the smart contract of the blockchain. If the verification passes, it triggers a corresponding verification search process based on the attributes of the data file to obtain the corresponding data index value, and obtains the data file of the distributed storage system according to the corresponding data index value; The data-using node verifies and obtains the corresponding data address based on the blockchain, and obtains the corresponding data file in the data sharing platform based on the data address.

[0046] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiments of the device, equipment, and non-volatile computer storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.

[0047] The specific embodiments of this specification are described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0048] The above is only one or more embodiments of this specification and is not intended to limit this specification. For those skilled in the art, one or more embodiments of this specification can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of one or more embodiments of this specification shall be included within the scope of the claims of this specification.

Claims

1. A data element circulation method for supply chain management, characterized in that: The method comprises: The data-owning nodes in the current supply chain upload data files with different attributes to the distributed storage system for storage according to the preset storage strategy, so as to obtain the data index value corresponding to the data file returned by the distributed storage system; The data-owning node embeds the management rights tag of the data sharing platform into the digital signature according to the private key of the data-owning node and the public key of the data sharing platform, and sends the digital signature and preset verification parameters to the data sharing platform for on-chain storage; The data owning node obtains the request information of the data using node through the data sharing platform to generate distribution proof data based on the request information, and sends the distribution proof data to the data sharing platform for on-chain storage; The data sharing platform verifies the distribution proof data based on the smart contract of the blockchain. If the verification is successful, the corresponding verification search process is triggered based on the attributes of the data file to obtain the corresponding data index value, so as to obtain the data file of the distributed storage system according to the corresponding data index value; The data usage node obtains the corresponding data address based on the blockchain verification, so as to obtain the corresponding data file in the data sharing platform based on the data address.

2. A data element circulation method for supply chain management according to claim 1, characterized in that: The data-owning node in the current supply chain uploads data files with different attributes to the distributed storage system for storage according to the preset storage strategy, so as to obtain the data index value corresponding to the data file returned by the distributed storage system, specifically including: The data owning node determines the data file to be shared based on the relevance of each original data and the business corresponding to the current supply chain; The data owner node determines the attributes corresponding to each of the data files by determining whether there is a privacy data type in each of the data files; wherein the attributes include: a regular type and a secret type; If it is determined that the attribute is of a regular type, the data owning node performs a hash calculation on the data file to obtain a hash value corresponding to the data file; The data owning node uploads the hash value and the data file to the distributed storage system for storage, and obtains the data index value corresponding to the data file returned by the distributed storage system; wherein the distributed storage system is the InterPlanetary File System IPFS; If it is determined that the attribute is of a secret type, the data-owning node encrypts the data file based on the public key of the data-owning node to obtain an encrypted data file; The data owning node uploads the encrypted data file to the distributed storage system for storage, and obtains a data index value corresponding to the encrypted data file returned by the distributed storage system.

3. A data element circulation method for supply chain management according to claim 1, characterized in that: The data-owning node embeds the management rights tag of the data sharing platform into a digital signature according to the private key of the data-owning node and the public key of the data sharing platform, and sends the digital signature and preset verification parameters to the data sharing platform, and stores them on the chain, specifically including: The data owner generates a chameleon hash private key based on a random number generator to obtain a chameleon hash public key corresponding to the chameleon hash private key; The data owning node obtains the management right label of the data sharing platform, and performs hash processing on the management right label and the data hash value corresponding to the data file according to the chameleon hash public key, so as to controllably embed the management right label into the generated chameleon hash; Signing the chameleon hash based on the chameleon hash private key and the public key of the data sharing platform to obtain a chameleon signature as a digital signature; The digital signature and preset verification parameters are sent to the data sharing platform and stored on the chain.

4. A data element circulation method for supply chain management according to claim 1, characterized in that: The data owning node embeds the management right tag of the data sharing platform into the digital signature according to the private key of the data owning node and the public key of the data sharing platform, and sends the digital signature and the preset verification parameters to the data sharing platform, and after the digital signature and the preset verification parameters are stored on the chain, the method further includes: The data owning node obtains the public key of the data sharing platform to encrypt the data index value according to the public key of the data sharing platform, and creates a searchable encrypted ciphertext corresponding to the data sharing platform; The data owning node uploads the searchable encrypted ciphertext and the preset trapdoor search condition to the blockchain for storage.

5. A data element circulation method for supply chain management according to claim 1, characterized in that: The data owning node obtains the request information of the data using node through the data sharing platform to generate distribution proof data based on the request information, and sends the distribution proof data to the data sharing platform for on-chain storage, specifically including: The data owning node obtains the request information of the data using node through the data sharing platform, so as to determine the requested data attribute of the data using node according to the request information and the attribute corresponding to each data file of the data owning node; If it is determined that the requested data attribute is a regular attribute, the data owning node generates a data user label for the data using node based on the request information; The data-owning node signs the data using a tag based on the private key of the data-owning node and registers the tag in the blockchain; The data owning node processes the request information and generates a one-time license for the data using node, and sends the one-time license and the signature of the data using label as distribution proof data to the data sharing platform; If it is determined that the requested data attribute is a confidential attribute, a re-encryption key is generated based on the public key of the data requester and the private key of the data owning node; The data owning node processes the request information and generates a one-time permission and data certification signature of the data using node; The re-encryption key, the one-time license and the digital certificate signature are sent to a data sharing platform as distribution certificate data.

6. A data element circulation method for supply chain management according to claim 4, characterized in that: Before the data owning node obtains the request information of the data using node through the data sharing platform, the method further includes: The data sharing platform determines a multi-level shared directory structure of shared data files among the data owners based on the upstream and downstream relationships among the data owners in the current supply chain; The data sharing platform generates a shared directory of the current supply chain according to the data tags corresponding to each of the data owners and the multi-level shared directory structure; The data user determines the data right holder corresponding to the current demand, requests data from the data right holder and the data user, checks the shared directory, and generates request information.

7. A data element circulation method for supply chain management according to claim 5, characterized in that: Triggering a corresponding verification search process based on the attribute of the data file to obtain a corresponding data index value, so as to obtain the data file of the distributed storage system according to the corresponding data index value, specifically includes: If the attribute of the data file is of a conventional type, the data sharing platform obtains the data index value stored on the blockchain, and queries the distributed storage system according to the data index value to obtain the data file in the distributed system; If the attribute of the data file is of a confidential type, the data sharing platform determines whether the verification result meets the preset search condition of the data owner, and if so, the data sharing platform generates a search trap based on the re-encryption key and the data sharing platform private key; Searching and decrypting the searchable encrypted ciphertext of the blockchain according to the search trapdoor to obtain a corresponding data index value, and querying the distributed storage system according to the corresponding data index value to obtain the encrypted data file in the distributed system; The data sharing center performs proxy re-encryption on the encrypted data file based on the re-encryption key in the distribution proof data to obtain a re-encrypted ciphertext of the data file.

8. A data element circulation method for supply chain management according to claim 1, characterized in that: The data owning node obtains the corresponding data address based on the blockchain verification, so as to obtain the corresponding data file in the data sharing platform based on the data address, specifically including: The data-owning node verifies the data usage label obtained according to the blockchain; If the verification is passed and the attribute of the data file is of a conventional type, the data use node obtains the corresponding data address to obtain the corresponding data file in the data sharing platform according to the data address; If the verification passes and the attribute of the data file is of a confidential type, the data usage node obtains the corresponding data address to obtain the corresponding re-encrypted ciphertext in the data sharing platform according to the data address, and decrypts the re-encrypted ciphertext based on the private key of the data user to obtain the corresponding data file.

9. A data element circulation method for supply chain management according to claim 1, characterized in that: After the data owning node obtains the corresponding data address based on the blockchain verification to obtain the corresponding data file in the data sharing platform based on the data address, the method further includes: The data owning node obtains the data acquisition success information returned by the data using node based on the data sharing platform, and records the supply chain tag of the data using node based on the data acquisition success information; The data owning node groups the data using nodes based on the supply chain label and determines a group label for each data using node; When the data-using node shares the data file of the data-owning node, the data-using node sends the supply chain tag of the downstream data-using node to the data-owning node; The data owning node determines whether the downstream using node can obtain the data file according to the supply chain tag of the downstream using node, the number of sharing times of the data owning node within a preset time and the group tag corresponding to the data using node.

10. A data element circulation system for supply chain management, characterized in that: The system includes: data owning nodes, data sharing platform, data using nodes and distributed storage system; The data-owning node in the current supply chain uploads data files with different attributes to the distributed storage system for storage according to a preset storage strategy, so as to obtain a data index value corresponding to the data file returned by the distributed storage system; The data-owning node embeds the management rights tag of the data sharing platform into the digital signature according to the private key of the data-owning node and the public key of the data sharing platform, and sends the digital signature and preset verification parameters to the data sharing platform for on-chain storage; The data owning node obtains the request information of the data using node through the data sharing platform to generate distribution proof data based on the request information, and sends the distribution proof data to the data sharing platform for on-chain storage; The data sharing platform verifies the distribution proof data based on the smart contract of the blockchain. If the verification is successful, the corresponding verification search process is triggered based on the attributes of the data file to obtain the corresponding data index value, so as to obtain the data file of the distributed storage system according to the corresponding data index value; The data usage node obtains the corresponding data address based on the blockchain verification, so as to obtain the corresponding data file in the data sharing platform based on the data address.