Enterprise trusted data authorization and backtracking method based on dynamic two-dimensional code

By generating dynamic QR codes and topological entropy analysis, combining device attributes and chain structure storage, the problem of authorization credentials being easily copied and abused in enterprise data authorization is solved, real-time access control and efficient behavioral traceability are realized, and the security and credibility of data access are improved.

CN120498897AInactive Publication Date: 2025-08-15SHUZU TECHNOLOGY (NANJING) CO LTD

Patent Information

Application Number
CN202510941318.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-09
Publication Date
2025-08-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art authorization certificates are easily copied and abused in enterprise data authorization, lack fine-grained real-time access control and abnormal detection capabilities, and the authorization process is difficult to meet the real-time security monitoring and integrity guarantee.

Method used

By generating a dynamic QR code containing access permissions and key identification, combining dynamic time factors and device attribute information, multi-factor access control is realized; topological entropy analysis is used for behavior scoring, a chain structure is used to store access logs and introduce zero-knowledge proofs to ensure the security and traceability of the authorization process.

Benefits of technology

It enhances the timeliness and uniqueness of authorization credentials, improves the accuracy of access control and anti-attack capabilities, realizes in-depth modeling of access behavior and efficient log backtracking, and ensures the security and credibility of data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498897A_ABST
    Figure CN120498897A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of access control, in particular to an enterprise trusted data authorization and backtracking method based on a dynamic two-dimensional code, which comprises the steps of setting an enterprise access authority rule, generating a short-time effective two-dimensional code in combination with a dynamic time factor and a key, and supporting security code scanning access control. Behavior feature vector modeling and topological entropy analysis are introduced for behavior scoring, so that the exception recognition capability is improved; access logs are collected to construct a chain structure, and traceability and privacy security of the whole data access process are realized in combination with zero-knowledge proof and differential privacy protection. According to the method, the two-dimensional code containing the access permission and the key identifier is dynamically generated, so that real-time authorization control and full-link behavior tracing of enterprise data access are realized, and the security of data access is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of access control technology, and in particular to an enterprise trusted data authorization and backtracking method based on dynamic QR codes. Background Art

[0002] With the continuous development of the digital economy, trusted authorization and secure access management of data between enterprises have become critical. In scenarios such as supply chain management, financial credit, and government affairs, data demanders need to quickly and securely obtain relevant data information authorized by data providers to ensure the legal and compliant access rights.

[0003] Current dynamic QR code technology enables the carrying of large amounts of dynamic authorization data within a limited size by segmenting information and displaying it as a multi-frame image sequence. This provides a technical foundation for the dynamic generation and verification of data access credentials. Existing technologies often rely on centralized authorization platforms combined with encryption algorithms or blockchain technology to implement authorization management. These technologies achieve tamper-proof recording and traceability of data authorization by writing authorization actions into the blockchain or binding them to digital identities.

[0004] However, traditional authorization methods still lack flexibility and security. Authorization credentials are easily copied and abused, difficult to dynamically update, and the authorization process lacks fine-grained, real-time access control and anomaly detection capabilities. Furthermore, the backtracking of data authorization often relies on offline queries, making it difficult for enterprises to meet their needs for real-time security monitoring and integrity assurance throughout the entire authorization process.

[0005] To this end, an enterprise trusted data authorization and backtracking method based on dynamic QR code is proposed. Summary of the Invention

[0006] The purpose of the present invention is to provide an enterprise trusted data authorization and backtracking method based on dynamic QR codes. By dynamically generating QR codes containing access rights and key identifiers, real-time authorization control and full-link behavior tracing of enterprise data access can be achieved, thereby ensuring the security of data access.

[0007] To achieve the above object, the present invention provides the following technical solutions: The enterprise trusted data authorization and traceability method based on dynamic QR codes includes: Set enterprise access rights rules, generate dynamic QR codes based on access rights rules, current timestamp, session key and dynamic time factor, and embed access rights scope, validity period and key identification parameters to limit the short-term validity of the QR codes; Receive enterprise access requests and authorize them based on access control rules; set QR code usage parameters, determine the QR code status based on configuration rules, and trigger the self-destruction mechanism; Collect enterprise access behavior data and construct behavior feature vectors, and calculate behavior scoring results based on the behavior complexity modeling method of topological entropy analysis combined with the preset security policy model; collect access behavior logs, store them in a chain structure in chronological order, form an access record chain, and form a full-link backtracking trace through hash cumulative values and hash reverse indexes.

[0008] The enterprise access rights rules include access subject identification, access object ID, permission level, available time period and access frequency threshold; Formatting and encoding the enterprise access permission rules to form a dynamic QR code information data block; A dynamic time factor is calculated using the current timestamp and a randomly generated window offset to perturb the data block; the data block is encrypted using an internal enterprise key derivation function and bound to a key identification parameter; The encrypted data block is embedded in the QR code, and the access permission range, valid time period and key identification parameters are attached in plain text to the QR code auxiliary information area to generate a dynamic QR code image.

[0009] The specific process of authorizing an access request includes: Receive a scan code access request, the scan code access request including decoded QR code data and device attribute information; the QR code data includes an encrypted permission data block and plaintext meta information; the device attribute information includes system type, IP address, and device identification; Locate the session key. If the key is invalid, the request is rejected. If it is valid, the access control rules are executed. The access control rules include access subject rules, access resource rules, operation authority rules, time constraint rules, frequency constraint rules and environment consistency rules. All of them are judged to be legal.

[0010] The usage parameters include the QR code generation timestamp, valid time window, maximum number of scans, key identification parameters, and QR code unique number; The binding environment summary and the disturbance time factor are introduced to form the QR code anti-copying fingerprint; After receiving an access request, the QR code status is judged according to the configuration rules. The configuration rules include time validity rules, scan count limit rules, key status judgment rules, device environment consistency rules, QR code replay protection rules and risk scoring rules. When any rule is judged to be abnormal, the QR code self-destruction processing flow is triggered and subsequent access operations are prohibited.

[0011] The constructing of the behavior feature vector specifically includes: collecting access behavior data, standardizing it according to preset dimensions and constructing a behavior feature vector, and inputting the behavior feature vector into the security policy model to calculate a matching score; According to the preset access security rule library, the behavioral characteristics are checked one by one to see if they meet the requirements of each rule. The judgment results of each rule will be assigned different weights and summarized and calculated to form the rule matching score.

[0012] The security policy model is based on a behavioral complexity modeling method based on topological entropy analysis, which is used to calculate the orderliness and complexity indicators of behavioral sequences, extract topological entropy features that reflect the degree of abnormal disturbance in behavioral patterns, and identify implicit unstable trends in behavioral changes; The behavior sequence includes a user access path jump sequence, an operation command sequence, and a request frequency change sequence. The model performs topological mapping based on a window segmentation method, constructs a corresponding behavior state transition graph, and calculates its topological entropy value. The topological entropy feature is used as a complexity factor and is weighted and fused with the rule matching score to generate the final behavior scoring result.

[0013] The specific process of chain structure association storage is as follows: collecting behavior log data in real time and arranging them in timestamp order to generate log blocks. Taking each access behavior as the smallest unit, a unique digest value is generated through a hash function as the identifier of the log block. Each log block contains the hash digest of the previous log block to form a chain structure. Synchronously build an incremental hash cumulative value and submit the cumulative value as the global summary of the chain record to a trusted external anchor point. At the same time, generate a local zero-knowledge proof for each access log and build a hash reverse index based on the resource identifier to accelerate the on-chain backtracking process.

[0014] Compared with the prior art, the present invention has the following beneficial effects: 1. The present invention enhances the timeliness and uniqueness of authorization credentials by introducing a QR code perturbation encryption method that incorporates access rights rules and dynamic time factors. Compared to existing technologies, traditional static QR codes are easily intercepted, copied, or forged during the authorization transfer process, lack effective lifecycle control and access protection mechanisms, and present significant security risks. The present invention combines the current timestamp with a random window offset to generate a dynamic perturbation factor, and uses a key derivation function to encrypt access rights data. Key identifiers and permission parameters are bound during the QR code generation process, effectively enhancing the unpredictability and short-term validity of QR codes, preventing the QR codes from being illegally reused or tampered with, and realizing a high-intensity, real-time updated authorization credential construction method. 2. This invention implements a dynamic multi-factor access control mechanism through an access authorization process based on the combined verification of device attribute information, access control rules, and key status. Existing authorization systems often rely on static user identities or single keys to determine access rights, making it difficult to flexibly adjust authorization policies based on context. During the access request process, this invention collects the device attributes of the scanning terminal (including system type, IP address, device ID, etc.) and comprehensively determines the legitimacy of the request based on multiple dimensions, including subject rules, resource rules, and time / frequency constraints in the access control rule base. It also verifies the key status and QR code-attached information to ensure that access is permitted under the conditions of a legitimate identity, valid key, and trusted environment, significantly improving the accuracy and anti-attack capabilities of access control.

[0015] 3. This invention improves the sensitivity and predictive power of access behavior security assessments by constructing a behavioral complexity modeling method based on topological entropy analysis. Traditional access behavior analysis typically relies on rule-based judgment or threshold detection, which cannot capture the gradual nature and potential abnormal trends in complex behavioral patterns and is prone to misjudgment or omission. This invention proposes a topological entropy feature extraction method that maps user operation sequences into state transition diagrams and calculates the complexity index of the behavior sequence. This method combines dimensions such as behavioral path jumps and request frequency fluctuations to achieve in-depth modeling of access behavior. By integrating rule matching scores to form behavioral risk scores, this method accurately identifies potentially risky access without affecting normal operations, thereby enabling dynamic early warning and automatic response.

[0016] 4. The present invention uses a chain structure to store access behavior logs, and combines incremental hash accumulation with zero-knowledge proof technology to build a verifiable behavior tracing mechanism. Existing log recording methods have problems such as tampering risks, lack of integrity verification or audit delays. Especially in scenarios with high data security requirements, it is difficult to meet the needs of post-audit and responsibility tracing. The present invention generates a unique hash summary for each access behavior log as an independent block, and constructs an unalterable chain structure through forward references. At the same time, it maintains the global hash accumulation summary and anchors it to a trusted external node to achieve non-repudiation verification of the overall state of the log chain; further, it combines resource identification to build a hash reverse index mechanism, and introduces local zero-knowledge proof to protect log privacy, while ensuring log integrity and achieving efficient access record tracking and compliance review. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 This is a flow chart of the enterprise trusted data authorization and backtracking method based on dynamic QR codes of the present invention; Figure 2 Schematic diagram of the access control rules of the present invention; Figure 3 This is a schematic diagram of the configuration rule content of the present invention. DETAILED DESCRIPTION

[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0019] Example 1: See also Figure 1 The present invention provides an enterprise trusted data authorization and backtracking method based on dynamic QR code. The technical solution is as follows: The enterprise trusted data authorization and traceability method based on dynamic QR codes includes: Set enterprise access rights rules, generate dynamic QR codes based on access rights rules, current timestamp, session key and dynamic time factor, and embed access rights scope, validity period and key identification parameters to limit the short-term validity of the QR codes; Receive enterprise access requests and authorize them based on access control rules; set QR code usage parameters, determine the QR code status based on configuration rules, and trigger the self-destruction mechanism; Collect enterprise access behavior data and construct behavior feature vectors, and calculate behavior scoring results based on the behavior complexity modeling method of topological entropy analysis combined with the preset security policy model; collect access behavior logs, store them in a chain structure in chronological order, form an access record chain, and form a full-link backtracking trace through hash cumulative values and hash reverse indexes.

[0020] Specifically, enterprise access rights rules are set, which include access subject identification, access object ID, permission level (such as "read-only"), allowed access time period, and access frequency threshold (such as only one access allowed per QR code). The above rules are encoded into standardized data blocks as the data source for subsequent QR code generation.

[0021] The current timestamp is combined with a set of pseudo-randomly generated window offsets to calculate a dynamic time factor; the dynamic time factor is used to perturb the data block field structure to ensure that the QR code image content generated at different times under the same technical rules is not completely consistent, thereby enhancing tamper resistance and unpredictability; the perturbed data block is encrypted through a key derivation function, the key derivation function input includes the enterprise private root key, the hardware summary information of the execution device (such as the MAC address hash) and the session tag to generate the encryption key required for this authorization, and is used to perform symmetric encryption on the data block.

[0022] To support rapid identification via subsequent code scanning, the access permission scope, valid time period, and key identification parameters are appended in plain text to the QR code's auxiliary information area. To prevent the QR code image from being screenshotted and copied or used for illegal replay, the QR code binding fingerprint mechanism is combined with the generated device's current operating environment summary and the dynamic time factor, embedded in the QR code as a verification field. The QR code is only allowed to pass verification when the environment is consistent.

[0023] The constructed dynamic QR code is displayed in the form of image frames. Through the inter-frame image perturbation technology, the constructed dynamic QR code is based on image frame sequence encoding, splits the complete data structure into multiple image frames, and displays them sequentially within a preset time window; the change of details between frames is controlled by the perturbation factor, so that each frame has slight visual differences and remains consistent in decoding. The perturbation factor is jointly generated by the current timestamp, the device operation status hash, and the device identification (such as the MAC address or TPM summary), and is used to drive operations such as redundant pixel noise injection, error diffusion mask coverage, micro-scale image rotation and transparency perturbation, so as to construct a perturbation graphic sequence without destroying the effective decoding of the QR code; the dynamic QR code is played in a loop within a limited frame sequence window (such as 3 to 7 frames), and the display time of each frame is controlled by the perturbation parameter, which enhances the QR code's anti-screenshot and anti-replay capabilities and adapts to access terminals that support multi-frame decoding.

[0024] The present invention introduces multiple enhancement technologies such as dynamic time factor perturbation, key-derived encryption, device binding verification, and inter-frame image perturbation coding to achieve multi-dimensional protection of QR codes in content structure, generation process, and presentation form. Compared with the existing static QR code authorization method, it significantly improves the tamper-proof, anti-copying, and device binding capabilities of the data authorization link, and can effectively prevent attacks such as screenshot replay and cross-device counterfeiting, ensuring the security, uniqueness, and verifiability of enterprise data during the authorized transmission process.

[0025] When a scanning terminal initiates an access request, the transmission content includes the QR code data obtained by camera decoding and the attribute parameters of the current device; the QR code data contains an encrypted permission data block and plaintext auxiliary fields, including key identification parameters, access time period and permission range information; the device attribute parameters include the operating environment identifier (such as operating system type), device identifier (such as MAC address, TPM module summary) and session IP information; The recipient retrieves the corresponding authorization key from the local key library or cache based on the key identifier in the plaintext. If the key does not exist or is invalid, access is denied. If the key is valid, the recipient uses it to decrypt the encrypted data block and extract the access subject identifier, access object ID, permission level, authorized time interval, and access frequency. Authorize access requests based on access control rules. Figure 2, the access control rules include: Access subject rule: Verify whether the subject identity initiating the request falls within the authorized scope; Resource target rule: Checks whether the requested access object ID is within the permitted resource set; Permission level rules: Compare access operation types (such as read, modify) to see if they meet permission requirements; Time interval rule: determines whether the current time is within the authorized time period; Access frequency rule: record whether the current QR code has reached the maximum allowed number of times; Environment consistency rules: Use a device attribute hash comparison algorithm to compare the device summary of the QR code generator with the current device summary of the code scanner to prevent the duplication of QR codes across environments. A dynamic contextual discrimination mechanism has been introduced as an innovative approach to dynamically adjust the credibility of access requests. This mechanism comprehensively evaluates contextual factors such as access time patterns, device stability, and geographic location, assigning dynamic confidence weights to each rule. If a request satisfies most rules but exhibits minor deviations under edge conditions, a fault-tolerant approach can still be provided, rather than a blanket rejection. This improves the flexibility and robustness of the authorization mechanism.

[0026] Through the above-mentioned access authorization process, refined authorization judgment of scan code access requests is realized. Compared with the existing methods based only on static rules or fixed permission verification, the present invention can not only perform static verification based on visitor identity, resource targets, time frequency bands and access frequencies, but also combine device attribute consistency with dynamic analysis of contextual environment fluctuations, thereby effectively preventing attacks such as cross-device replay of QR codes and forged device access. At the same time, on the basis of ensuring security, flexible judgments are allowed within a reasonable tolerance range, which improves the adaptability and fault tolerance of enterprise data authorization processes in actual business collaboration, and is particularly suitable for frequent and highly sensitive cross-subject data verification scenarios.

[0027] When a dynamic QR code is generated, a set of usage parameters for lifecycle management and security verification will be embedded, including the QR code generation timestamp (used to determine whether it is currently expired), the valid time window (such as 60 seconds), the maximum number of scans (such as 1 time), the key identification parameter (identifying the key required for QR code decryption) and the QR code unique number (used for tracking and identification). To prevent the QR code from being screenshotted, copied and replayed on unauthorized devices, the QR code generating device will also use its own operating environment summary (such as CPU identification, MAC address, etc.) and the disturbance time factor to construct a QR code anti-copying fingerprint field, which is embedded in the QR code content as the basis for subsequent verification and comparison.

[0028] When the code scanning access request is triggered, the QR code data and current device parameters uploaded by the access terminal are received in real time, and judgment is made based on the following configuration rules. Figure 3 : Time validity rule: compare the current time with the QR code generation time. If it exceeds the valid time window, the QR code is considered expired; Scanning limit rule: Check the usage record of the QR code unique number. If the maximum number of scans has been reached, it is considered illegal reuse; Key status judgment rule: Locate the authorization key based on the key identification parameters attached to the QR code. If the key is invalid or unregistered, it is considered undecryptable. Device environment consistency rule: Calculate whether the current device summary is consistent with the anti-copy fingerprint embedded in the QR code. If they do not match, it means that the QR code is used across devices; QR code replay protection rules: Detect the QR code generation batch and the current network environment. If there is a high degree of similarity with historical access records, a potential replay will be prompted; Risk scoring rules: A scoring mechanism based on access behavior models is introduced. This mechanism assigns a risk score to current access behavior based on dynamic factors such as access time, frequency, geographic location, and device stability. If the score exceeds the preset threshold, the operation is considered suspicious. If any of the above rules is judged to be abnormal, the QR code self-destruction processing mechanism will be triggered immediately, the QR code usage record will be cleared, the associated key identifier will be frozen, the risk behavior log will be recorded, and a failure response will be returned to the access terminal, denying subsequent access.

[0029] By embedding anti-copy fingerprints, introducing risk scoring rules, and implementing cross-device consistency verification, this invention effectively blocks the misuse of QR codes on unauthorized devices, during unauthorized periods, and in high-risk scenarios. This significantly improves the QR code's ability to prevent screenshots and replays, as well as the controllability of access behavior. This ensures real-time security during the authorization process and immediate handling of abnormal behavior. This mechanism ensures the uniqueness and security of each QR code instance within the three-dimensional constraints of space, time, and behavior, enhancing the trusted boundary control capabilities of the data authorization process.

[0030] After the code scanning request is initiated, access behavior data is collected. The access behavior data includes the timestamp of the access operation, action type, request frequency, path jump, and terminal change. The extracted behavior data is standardized according to the preset behavior evaluation dimensions to form a behavior feature vector with a unified numerical structure. The constructed behavioral feature vector is input into a pre-configured access rule matching model for evaluation. The rule model loads the access security rule library. Each rule corresponds to a set of conditional judgment logic, including subject legitimacy, resource access legitimacy, time constraints, frequency limits, and environmental consistency requirements. Each rule's judgment result is output as a standardized score (0 for failure, 1 for full compliance), which is multiplied by the rule's assigned weight. This weight reflects the relative importance of each access security rule in the overall security assessment and is typically assigned based on the rule's security risk level and business criticality. High-risk rules, such as subject legitimacy and environmental consistency, are typically assigned a higher weight (approximately 0.3 to 0.4) to ensure that their anomalies significantly impact the overall score. Medium-risk rules, such as resource access legitimacy and time constraints, are assigned a medium weight (approximately 0.2 to 0.3) to ensure the legitimacy and timeliness of access operations. Relatively permissive rules, such as access frequency limits, are assigned a lower weight (approximately 0.1 to 0.15) to prevent sporadic behavior from overly influencing the overall judgment. Furthermore, weights can be dynamically adjusted based on contextual risks and historical behavior to implement flexible security protection strategies. All weight values are normalized for easier weighted calculation, thus building a balanced and adaptive access security assessment system. The rule matching score is calculated by weighted accumulation of all rule scores. This score reflects the overall compliance level of the current access behavior under the security rule system. This invention introduces a weighted access rule matching model to achieve a fine-grained, multi-dimensional security assessment of access behavior. It comprehensively considers the importance of different security rules and dynamically adjusts weight distribution, improving the accuracy and flexibility of access risk identification and effectively preventing misleading overall judgments due to single rule failures or occasional anomalies. Furthermore, the use of a unified and standardized behavioral feature vector and scoring system makes the security assessment process more scientific and quantifiable, enhancing enterprises' real-time monitoring of access behavior and risk response capabilities, and significantly improving the security and reliability of the data authorization process.

[0031] Combined with the preset security policy model, key sequence information is extracted from the collected access behavior data, including the order of users' access path jumps within the system, the sequence of executed operation commands, and the time-varying sequence of request frequencies. For these behavior sequences, the model uses window segmentation technology to divide the entire time range into multiple overlapping or non-overlapping fixed-length time windows in order to capture the changing characteristics of behavior in different time periods. In each time window, the model maps user behavior into a state transition graph. The nodes in the graph represent different behavioral states, and the edges represent the transition probabilities between states, forming a behavioral topology structure. Based on this topological structure, the corresponding topological entropy value is calculated. This entropy value reflects the orderliness and complexity of the behavior, specifically the randomness of state transitions and the stability of the behavior pattern. By analyzing the changing trend of topological entropy, the model can identify potential abnormal behavior disturbances, such as sudden jump patterns or abnormal frequency fluctuations; The topological entropy value is used as a complexity factor and is integrated with the rule matching score calculated by the rule matching model to generate the behavior scoring result. The topological entropy feature weight is set to 0.4 and the rule matching score weight is set to 0.6. This means that in the comprehensive score, the behavior rule compliance accounts for 60% of the weight and the behavior complexity accounts for 40% of the weight. The specific ratio can be flexibly adjusted according to the actual scenario; The behavior scoring result is used as a security assessment basis for access requests. When the score is above the set threshold, the access behavior is considered normal and trustworthy, and access is allowed. When the score is below the threshold, the access behavior is considered abnormal or risky, and the access request is denied or restricted. It may also trigger security response measures such as alerts or additional verification. This invention achieves a multi-dimensional dynamic assessment of access behavior by integrating a behavioral complexity modeling method based on topological entropy analysis with a weighted rule-matching model. This approach not only relies on static rule-based judgments but also incorporates indicators of the complexity and orderliness of behavioral patterns to effectively identify hidden abnormal disturbances and potential risks, thereby significantly improving the accuracy and security of access behavior identification. Furthermore, by flexibly adjusting the weight ratio between rule matching and topological entropy features, the adaptability and robustness of security judgments are ensured, misjudgments and missed judgments are reduced, and the system's protection capabilities against complex and changing access environments are enhanced, meeting the trusted requirements of enterprise data authorization in high-security scenarios.

[0032] The collected access behavior log data is organized in timestamp order, with each access behavior being used as the smallest unit to generate an independent log block. For each log block, a unique summary value is calculated using a hash function. This summary value not only identifies the current log block but also contains the hash summary of the previous log block, creating a chain-like association between log blocks and ensuring the sequential and tamper-proof nature of access records. An incremental hash accumulation value is simultaneously constructed, accumulating the hash summaries of all log blocks in chronological order to generate a global summary representing the entire link. The global summary is regularly submitted to a trusted external anchor (such as a blockchain or a third-party timestamp service) to provide external assurance of the integrity and tamper-proof nature of the chained record. To enhance data privacy and security, a local zero-knowledge proof is generated for each access log, ensuring that the authenticity of the log can be verified during the backtracking process without leaking sensitive content. Based on the unique identifier of the accessed resource (such as the resource ID or digital fingerprint), a hash reverse index structure is constructed to quickly locate the corresponding log block, significantly improving the efficiency and accuracy of on-chain backtracking retrieval. A dynamic hierarchical hash index mechanism is introduced to optimize multi-dimensional indexes based on the temporal and spatial characteristics of access behavior, reducing the length of the backtracking path and computing overhead, thereby improving response speed in large-scale log environments. A log summary protection technology based on differential privacy is used to desensitize sensitive fields in the collected access behavior logs. The original data is blurred by adding noise to ensure that a single log is difficult to identify alone without significantly affecting the overall data statistical characteristics. The addition of noise follows the differential privacy mechanism, using random noise generated by Laplace or Gaussian distribution, and controls the balance between privacy protection strength and data availability according to the set privacy budget parameters. When constructing hash summaries and zero-knowledge proofs, desensitized data with added noise is used as input to ensure that the final generated summary and proof information do not expose real sensitive information.

[0033] By introducing chain-structured associative storage technology, the integrity and non-tamperability of access behavior log data are ensured, and the credibility and security of data backtracking are improved; by submitting the global summary to a trusted external anchor point, multi-level tamper-proof protection of access records is achieved, and the external verification capability of chain records is enhanced. The hash inverted index and dynamic hierarchical hash index mechanism built based on resource identification have greatly improved the retrieval efficiency and backtracking response speed in large-scale access log environments, ensuring the efficiency and accuracy of the backtracking process. The use of log summary protection technology based on differential privacy effectively protects the privacy and security of sensitive information in access behavior, avoids the risk of sensitive data leakage during verification and auditing, and takes into account the availability and security of data, thereby improving the privacy protection level of the overall system. The combination of the above innovative technologies has achieved significant improvements in the security, privacy, and practicality of enterprise trusted data authorization and backtracking.

[0034] The enterprise trusted data authorization and backtracking method based on dynamic QR codes proposed in this invention achieves closed-loop management of the entire process from authorization generation, code scanning access, behavior assessment to chain log backtracking by constructing a short-term, traceable, and tamper-proof dynamic QR code, combined with behavior perception and access control strategies. This solution introduces a disturbance factor to construct a dynamic image frame sequence during the QR code generation process, effectively improving the QR code's anti-copying and anti-replay capabilities; in the access control link, it combines the context dynamic judgment mechanism with the behavior rule matching model to achieve flexible and accurate access authorization judgment; in terms of behavior log management, through chain structure storage, zero-knowledge proof and differential privacy protection, it ensures the integrity of the log and user privacy, and supports efficient and reliable backtracking verification.

[0035] Example 2: Company A plans to share its latest operating data with partner company B for reconciliation analysis and partnership evaluation. The data must only be accessible from 9:00 AM to 10:00 AM daily between June 26 and 30, 2025. Each QR code must be used only once, and the access process must be traceable. Specifically, set the authorization rules: the access subject is enterprise B's legal person number "B-ID-2038", the access object ID is "OPS-DATA-2025Q2", the permission level is "read-only", the available time period is "2025.6.26–2025.6.30, 9:00–10:00 every day", and the access frequency threshold is set to 1 time / code; The above rules are formatted into a structured data block. A dynamic time factor is calculated by combining the current timestamp with a pseudo-randomly generated window offset to perturb the data field order. Subsequently, an encryption key is derived using Enterprise A's private root key, the current device's environment digest (e.g., MAC address digest), and a temporarily generated session tag. The perturbed data block is then symmetrically encrypted. Plain text fields (such as validity period, permission level, and key identifier) are appended to the extended information area of the QR code. To enhance the security of the QR code, a device operation summary and a dynamic time factor are combined to generate a QR code anti-copy fingerprint, which is embedded in the image content to ensure that the QR code can only be parsed under the preset environment. Dynamic QR codes are encoded using a sequence of image frames, with each frame displaying a perturbed image. The inter-frame differences include pixel perturbations, slight rotations, and transparency perturbations, creating a QR code sequence that loops within a short period of time to prevent static screenshots from being copied. Each QR code is displayed for 60 seconds, and only one scan is allowed within the display period. After the authorized personnel of Enterprise B scan the code, the scanning terminal will extract the key identifier and encrypted data block in the QR code, and initiate an access request along with the device attributes (such as operating system type, MAC address, IP, etc.). After Enterprise A receives the access request, it first locates the key identifier and verifies the key status; if the key is valid, it uses it to decrypt the encrypted data block and obtain the authorization parameters; the access control logic sequentially determines whether the access subject is qualified, whether the access object is allowed, whether the current time is within the authorized period, whether the QR code has been used, and whether the device summary is consistent with the generator. It also performs a dynamic credibility assessment based on the access context (geographic location, device stability, request frequency, etc.); If all rules are judged to be legal, the access is authorized. At the same time, the access behavior data (such as access time, resource ID, and device attributes) is recorded as an independent log block. The log block contains the hash summary of the previous access, forming a chain structure. The log block summary is used to incrementally build the full-link hash cumulative value and is regularly submitted to the trusted anchor platform to ensure the integrity and tamper-proof capability of the log; a differential privacy mechanism is introduced to perform noise perturbation processing on sensitive fields in the log (such as operation content and device IP) to protect a single access record from being inferred to a specific user identity. At the same time, a zero-knowledge proof is generated for each log, so that subsequent verifiers can confirm the authenticity of the log without exposing the plaintext; After the cooperation period ends, Company A can quickly locate Party B's access records through the resource identification index, and conduct a complete backtracking and audit of its authorization behavior, effectively preventing authority abuse and data leakage.

[0036] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. The enterprise trusted data authorization and backtracking method based on dynamic QR code is characterized by: include: Set enterprise access rights rules, generate dynamic QR codes based on access rights rules, current timestamp, session key and dynamic time factor, and embed access rights scope, validity period and key identification parameters to limit the short-term validity of the QR codes; Receive enterprise access requests and authorize them based on access control rules; set QR code usage parameters, determine the QR code status based on configuration rules, and trigger the self-destruction mechanism; Collect enterprise access behavior data and construct behavior feature vectors, and calculate behavior scoring results based on the behavior complexity modeling method of topological entropy analysis combined with the preset security policy model; collect access behavior logs, store them in a chain structure in chronological order, form an access record chain, and form a full-link backtracking trace through hash cumulative values and hash reverse indexes.

2. The enterprise trusted data authorization and backtracking method based on dynamic QR code according to claim 1 is characterized in that: The specific process of generating a dynamic QR code is as follows: The enterprise access rights rules include access subject identification, access object ID, permission level, available time period and access frequency threshold; Formatting and encoding the enterprise access permission rules to form a dynamic QR code information data block; Calculating a dynamic time factor using a current timestamp and a randomly generated window offset to perform perturbation processing on the data block; Encrypting the data block using an internal enterprise key derivation function and binding a key identification parameter; The encrypted data block is embedded in the QR code, and the access permission range, valid time period and key identification parameters are attached in plain text to the QR code auxiliary information area to generate a dynamic QR code image.

3. The enterprise trusted data authorization and backtracking method based on dynamic QR code according to claim 1 is characterized in that: The specific process of authorizing an access request includes: Receive a scan code access request, the scan code access request including decoded QR code data and device attribute information; the QR code data includes an encrypted permission data block and plaintext meta information; the device attribute information includes system type, IP address, and device identification; Locate the session key. If the key is invalid, the request is rejected. If it is valid, the access control rules are executed. The access control rules include access subject rules, access resource rules, operation authority rules, time constraint rules, frequency constraint rules and environment consistency rules. All of them are judged to be legal.

4. The enterprise trusted data authorization and backtracking method based on dynamic QR code according to claim 1 is characterized in that: The self-destruction processing mechanism is specifically as follows: The usage parameters include the QR code generation timestamp, valid time window, maximum number of scans, key identification parameters, and QR code unique number; The binding environment summary and the disturbance time factor are introduced to form the QR code anti-copying fingerprint; After receiving an access request, the QR code status is judged according to the configuration rules. The configuration rules include time validity rules, scan count limit rules, key status judgment rules, device environment consistency rules, QR code replay protection rules and risk scoring rules. When any rule is judged to be abnormal, the QR code self-destruction processing flow is triggered and subsequent access operations are prohibited.

5. The enterprise trusted data authorization and backtracking method based on dynamic QR code according to claim 1 is characterized in that: The construction of the behavior feature vector is specifically as follows: Collect access behavior data, standardize it according to preset dimensions and construct a behavior feature vector, and input the behavior feature vector into the security policy model for matching score calculation; According to the preset access security rule library, the behavioral characteristics are checked one by one to see if they meet the requirements of each rule. The judgment results of each rule will be assigned different weights and summarized and calculated to form the rule matching score.

6. The enterprise trusted data authorization and backtracking method based on dynamic QR code according to claim 1 or 5, characterized in that: The security policy model is specifically: The security policy model is based on a behavioral complexity modeling method based on topological entropy analysis, which is used to calculate the orderliness and complexity indicators of behavioral sequences, extract topological entropy features that reflect the degree of abnormal disturbance in behavioral patterns, and identify implicit unstable trends in behavioral changes; The behavior sequence includes a user access path jump sequence, an operation command sequence, and a request frequency change sequence. The model performs topological mapping based on a window segmentation method, constructs a corresponding behavior state transition graph, and calculates its topological entropy value. The topological entropy feature is used as a complexity factor and is weighted and fused with the rule matching score to generate the final behavior scoring result.

7. The enterprise trusted data authorization and backtracking method based on dynamic QR code according to claim 1 is characterized in that: The specific process of chain structure association storage is as follows: Behavior log data is collected in real time and arranged in timestamp order to generate log blocks. Each access behavior is used as the smallest unit, and a unique summary value is generated through a hash function as the identifier of the log block. Each log block contains the hash summary of the previous log block, forming a chain structure. Synchronously build an incremental hash cumulative value and submit the cumulative value as the global summary of the chain record to a trusted external anchor point. At the same time, generate a local zero-knowledge proof for each access log and build a hash reverse index based on the resource identifier to accelerate the on-chain backtracking process.

Citation Information

Patent Citations

  • Cellphone-based dynamic two-dimension code access control system

    CN103955975A

  • Operating authorization method and system based on dynamic two-dimensional code

    CN103973448A

  • Log tamper-proofing method and system and storage medium

    CN114462998A

  • Food traceability verification method and system

    CN117788019A

  • E-commerce operation data security protection system and method based on block chain

    CN120030515A

Cited By

  • Information encryption management method and system

    CN120785659A

  • Security enhancement method based on block chain and multi-element dynamic authentication conjoint analysis

    CN121664389A