Textile quality block chain encryption tracing method
By implanting quantum dots and nucleic acid mixed fingerprints in the yarn to form an uncloned identity, combined with a trusted execution environment and encryption technology, the problems of easy forgery of textile traceability and commercial secret leakage are solved, and trusted traceability and privacy protection are achieved throughout the life cycle.
Patent Information
- Application Number
- CN202510607916.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-08-19
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional textile traceability solutions are easily forged and transferred, and are difficult to effectively verify in a weak network environment. The risk of commercial secret leakage is high, and it is difficult to trace existing systems in cross-factory collaboration and international trade.
By implanting quantum dots and nucleic acid mixed fingerprints in the yarn, forming an uncloned identity, collecting process data in combination with a trusted execution environment, and generating encryption packages using Paillier homomorphic encryption and zero-knowledge proof, directed acyclic graph consensus and erasure encoding ensure data availability and privacy, and the consumer side is offline verification and networked and pledged points.
It realizes credible traceability of the entire life cycle of textiles from production to delisting, ensures the authenticity of tags, privacy protection and quality improvement, has the ability to identify authenticity on-site, and supports data availability and commercial confidentiality protection under extreme network conditions.
Smart Images

Figure CN120509908A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of textile informatization and blockchain encryption tracing technology, and in particular to a blockchain encryption tracing method for textile quality. Background Art
[0002] Textiles frequently change hands in cross-factory collaboration, international trade, and recycling chains. Traditional paper quality inspection forms or QR code hangtags are easily forged, swapped, or separated from finished garments, making it difficult to accurately trace brand reputation and recall responsibility. Existing traceability solutions typically use QR codes and centralized databases or write production data in plain text to a consortium chain. The former relies on a central server, making tampering easier and becoming ineffective upon downtime. The latter, while improving tamper resistance, exposes process windows and key formula parameters on the chain, potentially leaking trade secrets. Some systems attempt to use radio frequency tags to store summaries and combine them with cloud-based verification, but are still limited by single-point databases, network dependencies, and insufficient data availability, making them difficult to implement in weak-network warehousing, offline stores, and second-hand trading scenarios. Summary of the Invention
[0003] In response to the many problems existing in the above-mentioned existing technologies, the present invention provides a blockchain encryption traceability method for textile quality. The present invention forms an unclonable fingerprint by implanting quantum dots and nucleic acid barcodes into yarns; the fingerprint is mapped to a distributed identity through a verifiable random function. Edge nodes collect process data to generate quality indicators, and use Paillier homomorphic encryption and additional zero-knowledge proof and threshold signature to encapsulate the encrypted package. When the batch threshold is triggered, the aggregator generates batch commitments and shard commitments, writes the commitments and proofs into the directed acyclic graph transaction in a fixed field order, and confirms them through Byzantine fault-tolerant consensus. Consumers can authenticate their authenticity by combining offline fingerprint comparison with homomorphic verification, and pledge points after online verification of the batch proof. After the time lock expires, multiple entities jointly decrypt the historical plaintext and output maintenance suggestions. The hash write chain forms a closed-loop governance.
[0004] A blockchain encrypted traceability method for textile quality, comprising the following steps:
[0005] During spinning, an unclonable fingerprint is implanted and a distributed identity is generated. Process data is collected in a trusted execution environment to form quality indicators, which are then homomorphically encrypted and attached with zero-knowledge proof and multi-agent signatures to generate an encrypted package.
[0006] Generate batch commitments and zero-knowledge batch proofs for encrypted packages that reach the batch quantity threshold, shard them through erasure coding, and assemble them with the commitment data into a directed acyclic graph transaction, broadcast it to the Byzantine fault-tolerant network, and record the consensus;
[0007] After the consumer reads the RFID tag, fingerprint comparison and homomorphic verification are performed to complete offline verification. After connecting to the network, the batch certificate is verified and points are pledged. When the time lock expires, the historical quality data is jointly decrypted, a maintenance recommendation hash is generated, and written into subsequent transactions to close the traceability chain.
[0008] Preferably, when the unclonable fingerprint is implanted, a mixed marking material is used to make the fingerprint continuously distributed along the fiber axis, and the fingerprint data is collected through dual-band spectroscopy.
[0009] Preferably, after the distributed identity is generated, it is written into a trusted execution environment having an isolated storage area, and a unique copy of the distributed identity is retained in the isolated storage area.
[0010] Preferably, an additive homomorphic public key system is used when performing homomorphic encryption on the quality indicator, and the distributed identity is converted into a random parameter via a hash derivative function to generate an encryption result.
[0011] Preferably, the zero-knowledge proof proves the correctness of the encryption equation and that the quality index is within a preset range through an arithmetic circuit, and the multi-subject signature aggregates the production subject signature, the quality inspection subject signature and the supervision subject signature through a threshold scheme.
[0012] Preferably, after reaching the batch size threshold, erasure coding is used to divide the encrypted package into data shards and redundant shards, and shard commitments are calculated for all shards.
[0013] Preferably, when assembling a directed acyclic graph transaction, batch commitment, shard commitment and zero-knowledge batch proof are written into the transaction payload in a fixed field order, and a consensus record is generated after confirmation by the Byzantine fault-tolerant consensus.
[0014] Preferably, after reading the RFID tag, the consumer first compares the physical fingerprint hash, and then uses the random parameters recovered from the distributed identity to perform homomorphic verification on the encrypted package to obtain an offline verification result.
[0015] Preferably, after the consumer is connected to the Internet, it verifies the zero-knowledge batch proof and pledges points to the governance contract. The information on the completion of the pledge is written into the directed acyclic graph network along with the transaction for subsequent query.
[0016] Preferably, after the time lock expires, no less than a threshold number of signing entities submit key fragments to jointly decrypt the encrypted package to obtain historical quality data, and generate maintenance recommendation hashes based on the historical quality data and write them into subsequent directed acyclic graph transactions to close the traceability chain.
[0017] Compared with the prior art, the advantages and beneficial effects of the present invention are:
[0018] The present invention uses a physical unclonable fingerprint + verifiable random function to bind the yarn entity to the distributed identity one by one, so that the authenticity can still be verified on site when the tag is replaced; through additive homomorphic encryption and zero-knowledge proof, all quality indicators are hidden in plain text, and public verification on the chain is achieved without leaking the commercial formula; through erasure coding sharding and sharding commitment, batch data is redundantly stored across nodes, achieving recoverability in the event of node failure or network partitioning; through weight-driven Byzantine fault-tolerant directed acyclic graph consensus, multi-factory parallel chain writing in seconds is achieved; through time lock + threshold decryption, historical quality data is returned to the production end and the traceability chain is closed by hash according to maintenance recommendations, realizing self-driven quality improvement and economic incentives. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 Schematic diagram of the process of the present invention;
[0020] Figure 2 Schematic diagram of the multi-agent signature and threshold decryption structure in the present invention;
[0021] Figure 3 Schematic diagram of the shard storage and verification topology in the present invention. DETAILED DESCRIPTION
[0022] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details.
[0023] like Figure 1 As shown, a blockchain encryption traceability method for textile quality includes the following steps:
[0024] During spinning, an unclonable fingerprint is implanted and a distributed identity is generated. Process data is collected in a trusted execution environment to form quality indicators, which are then homomorphically encrypted and attached with zero-knowledge proof and multi-agent signatures to generate an encrypted package.
[0025] During the spinning process, the yarn still maintains controllable draft and stable tension. The present invention selects quantum dot fluorescent microcapsules and functional fibers containing specific nucleic acid sequences as non-clonable fingerprint marking materials. Quantum dots exhibit multi-peak fluorescence under dual-band excitation, while nucleic acid fibers have unique sequence indication signals under the action of special dyes. The two materials are evenly deposited on the surface of a single fiber by electrostatic electrospraying and twisted into yarn together with the fiber. The multi-dimensional spectral characteristics of quantum dots and the nucleic acid sequence are combined to form a high-dimensional physical fingerprint vector, which is difficult to copy or wear. The spectral acquisition head installed in the rotary hook section scans the yarn frame by frame at a fixed frame rate, and calculates its hash value immediately after obtaining the original fingerprint vector. The system calls the verifiable random function (hereinafter referred to as VRF) in the secure computing chip:
[0026] DID=F VRF (H(V PUF ),k priv )
[0027] Among them, V PUF is the physical fingerprint vector; H(·) is a one-way hash: k priv The elliptic curve private key is unique to the spinning line; the DID is a distributed identity string. VRF ensures that the output is verifiable under the public key while preventing mass counterfeiting caused by private key leakage, fundamentally binding the "fiber entity to identity."
[0028] The next process is to enter the production workshop where multiple devices such as weaving, dyeing, and finishing are connected in series. An edge measurement node is installed on the side of each device. The node hardware includes a security processor and a trusted platform module. The system-level firmware divides the Trusted Execution Environment (TEE) into an independent security zone. After the TEE is started, it loads the read-only model, continuously pulls sensor streams such as temperature, humidity, tension, and chemical solution concentration, and calculates the quality index vector Q within ten sampling cycles. A two-layer perceptron is used here. The parameters are encapsulated at the time of the first deployment and cannot be changed subsequently to avoid subsequent parameter adjustment and falsification. The quality indicator vector enters the homomorphic encryption process, and the Paillier additive homomorphic encryption algorithm is selected. Its core transformation is:
[0029] C=g Q r n mod n 2
[0030] Q is the encoded integer of the quality indicator vector; g is the basis generated by the system; n = pq is the product modulus; r is a random number output by the distributed identity through the hash derivative function, so that r corresponds one-to-one with the DID; c is the homomorphic ciphertext.
[0031] Through this formula, any offline entity can still perform addition operations on different batches of ciphertext to obtain the summary results without knowing the specific value of Q, thereby meeting the regulatory requirements for industry statistics.
[0032] Then, the zero-knowledge proof tool chain is called inside the TEE to generate proof π. The proof circuit simultaneously constrains two things: (1) the ciphertext and plaintext conform to the above formula; (2) each indicator is within the process allowable range [l i ,u i ]. This logic completes the "authenticity + compliance" closed loop at one time. Zero-knowledge proof is in a publicly verifiable format, ensuring that downstream nodes can trust the data is correct without decryption. Then the production entity, quality inspection entity, and regulatory entity each use their own private keys to partially sign C||π. The system adopts a two-threshold three-signature scheme: any two local signatures can generate an aggregate signature σ through an aggregation function. The encrypted package consists of a triple<C,π,σ> Composition, write to local buffer.
[0033] When the buffer count reaches the preset batch number, the system executes batch packaging. All encrypted packages are calculated through the Merkle tree batch commitment root H batch To ensure persistent availability, the program uses the Reed-Solomon erasure algorithm to split batch data into data shards and redundant shards, and calculates the shard commitment root H shard Batch commitments, shard commitments, and zero-knowledge batch proofs (π) are written into the directed acyclic graph transaction payload. Transactions are broadcast and confirmed across the cross-factory alliance network using a Byzantine fault-tolerant consensus algorithm, and once confirmed, they are irreversible. Shards are stored in a decentralized, content-addressed manner, allowing any query to reconstruct data and verify consistency simply by providing a shard hash.
[0034] The consumer-side tag integrates an RFID tag with two read-only fields permanently burned into it: the physical fingerprint hash and the distributed identity. After the mobile phone reads the tag, it scans the textile surface through the matching spectral component and compares the hashes. If the difference is greater than the tolerance, it will be prompted as "fingerprint mismatch". After the comparison is successful, the mobile phone recovers the random number r based on the distributed identity and executes g offline. Q =C·r -n (mod n 2 ) Verify the consistency of the ciphertext. If the verification is correct, the offline verification is successful. When connected to the network, the client pulls the transaction payload and calls the zero-knowledge batch proof verification tool to quickly verify the Pi, confirming the correctness of the entire batch of data without any plaintext. After successful verification, a fixed number of points are pledged to the governance contract, providing a dynamic weight for subsequent writes to the network, forming an economic closed loop in which users participate in protecting the network ecosystem.
[0035] After the transaction is written into a preset time window, the homomorphic ciphertext reaches the time lock threshold. The time lock is implemented by a verifiable delay function. Any node can unlock it only after executing a full square chain, ensuring that the decryption action cannot be advanced. After the time is reached, two entities among the production entity, quality inspection entity, and supervision entity upload their respective Paillier private key fragments. i >, the system synthesizes a private key and decrypts the ciphertext set at one time to obtain the historical quality plaintext. Through the federated learning method, the historical plaintext encrypted gradients of different factories are uploaded to the central scheduler to aggregate and update the model weights without exposing the data; each factory downloads the new model and can t Predict machine failure probability and schedule maintenance orders in advance. The system writes the "maintenance recommendation" in hash form to a new transaction field called maint_root. Subsequent transactions must reference this field. If maintenance is not performed, subsequent transactions will be rejected, financially incentivizing producers to fulfill their maintenance obligations.
[0036] For example, a cotton-polyester blended yarn production line generates 1,200 encrypted packets per day. The system sets a batch threshold of 400 packets, so each batch is packaged once the counter reaches 400. Each batch of zero-knowledge proofs takes 0.9 seconds to generate, and on-chain verification takes an average of 6 seconds. From the moment a consumer scans a hangtag to offline verification, the process completes within 700 milliseconds, meeting retail experience requirements. Unlocked historical quality data is used to predict the lifespan of warping machine tension rollers, achieving significantly higher accuracy than manual inspections.
[0037] The present invention uniquely binds physical objects through "physical fingerprint + distributed identity", solves the problem of "trust without leakage" with homomorphic encryption and zero-knowledge proof, and ensures data availability and difficulty in tampering under extreme network conditions with directed acyclic graph consensus and erasure sharding; through point staking and time lock decryption, it builds a closed loop of economic incentives and production maintenance, and ultimately realizes trusted traceability of the entire life cycle from yarn generation to delisting.
[0038] Preferably, when the unclonable fingerprint is implanted, a mixed marking material is used to make the fingerprint continuously distributed along the fiber axis, and the fingerprint data is collected through dual-band spectroscopy.
[0039] The present invention mixes quantum dot fluorescent microcapsules with functional fibers having specific nucleic acid sequences in a certain proportion and continuously sprays them onto the fiber surface in the yarn drafting zone using electrostatic spraying. Under dual-band excitation outside the visible light region, the quantum dots exhibit narrow-band fluorescence, which forms a multi-peak spectrum depending on the particle size combination. The functional fibers, bonded with a special dye, exhibit a fixed fluorescence intensity within the same band. After the two are mixed, a spatially coherent, laterally random composite spectral pattern is formed along the fiber axis, creating an unclonable fingerprint. Because the central wavelength of quantum dot fluorescence is sensitive to particle size and the nucleic acid sequence is unique to the dye binding site, any replication attempt requires simultaneous reproduction of both the particle size distribution and the sequence information, making it virtually impossible to achieve under industrial conditions.
[0040] A dual-band spectral acquisition head is placed at the exit of the production line. The first band is located at the main emission peak of quantum dots, and the second band is located at the emission peak of nucleic acid dyes. Both bands are located outside the common lighting in textile workshops, which is conducive to suppressing background noise. The acquisition head scans the yarn at a fixed frame interval, obtains the spectral data cube, and compresses it into a vector V using principal component projection. PUF . Execute the hash function H(·) on the vector to obtain a fixed-length summary, which is then input into a verifiable random function to generate a distributed identity:
[0041] DID=F VRF (H(V PUF ),k priv )
[0042] This process is completed within the hardware security module, and the key is never leaked. Since the VRF output is monotonic to the input hash and is publicly verifiable, subsequent on-chain nodes only need to hold the public key to confirm the source of the distributed identity.
[0043] The continuously distributed fingerprint has two key benefits. First, even if a hang tag is lost or replaced, verification can still be completed through on-site spectral resampling, avoiding the vulnerability of traditional QR code hang tags to cloning. Second, the fingerprint runs throughout the entire roll of fabric, allowing any cut piece to be independently scanned and obtain the same hash, significantly improving the coverage and convenience of downstream links.
[0044] Example: Cadmium sulfide quantum dots, polylactic acid (PLA) fibers, and polyester-cotton roving were selected. The electrostatic spray potential was set at 15 kilovolts, the spray rate was 1 milliliter per hour, and the yarn speed was 300 meters per minute. Dual-band acquisition wavelengths were 435 nanometers and 512 nanometers, respectively, with a frame pitch of 2 millimeters. One hundred rolls of yarn were scanned in the experiment. The average Hamming distance of the fingerprint vector hash between different batches was greater than 200 bits, and the Hamming distance of samples within the same roll was less than 2 bits, meeting the requirements of intra-batch consistency and inter-batch uniqueness.
[0045] The present invention binds the unclonability of the physical layer with the cryptographic identity, laying the foundation for the authenticity of blockchain traceability; the use of dual-band acquisition simplifies the optical hardware while retaining sufficient entropy; the continuous distribution ensures a complete verification link from yarn to cloth and from cloth to clothing, providing a reliable entry for textile traceability at the retail end and even the recycling end.
[0046] Preferably, after the distributed identity is generated, it is written into a trusted execution environment having an isolated storage area, and a unique copy of the distributed identity is retained in the isolated storage area.
[0047] After generating a distributed identity (DID), the present invention writes the DID into a trusted execution environment (TEE) with an isolated storage area, retaining only this copy in the isolated storage area. The following describes the principle, implementation, and effects.
[0048] The TEE is a hardware-isolated area within the processor. Unlike the normal world, the TEE's address space is directly partitioned by the processor microarchitecture, making it inaccessible to the operating system and any user processes. The TEE provides two security capabilities: key derivation and key encapsulation.
[0049] Key derivation uses fuses or physically unclonable functions to generate a device-unique root key K on the chip. root The root key does not appear in plain text, but only participates in the derivation algorithm at the register level. Key encapsulation (commonly known as Sealing) uses the derived session key K s Encrypt external data and add integrity stamps. For example, the packaging logic can use the verified device identity ID Dev Generate a key with a random counter Nonce:
[0050] K s =KDF(K root ,ID Dev ||Nonce)
[0051] In this invention, DID needs to be stored for a long time across processes and networks, and its integrity and confidentiality directly affect subsequent on-chain verification. Therefore, hardware-based AES-GCM is used in the packaging process. The encapsulation generates ciphertext:
[0052]
[0053] The encrypted data is accompanied by an authentication tag. The ciphertext and tag are written to an isolated storage area (Secure Storage). The tag is verified during TEE bootup, and only after it is unsealed can the DID be provided to upper-layer applications. Because the root key is not exportable, even an attacker who has access to the physical flash memory cannot decrypt the DID. Isolated storage is typically implemented as a secure partition in an eMMC or an internal SRAM module within the processor. The latter loses power upon power loss, while the former, combined with an encryption controller, can prevent layout theft.
[0054] Compared to traditional methods of hashing identities in plaintext or writing them to a database, this write method offers three advantages. First, writes are performed within a closed execution path, bypassing the operating system and preventing malicious driver-level eavesdropping. Second, isolated storage enforces "single-write" semantics. Before each write, the firmware checks for a valid copy and refuses to overwrite it if one exists. This ensures that the DID is unique and irreversible. Third, the ciphertext and tag are strongly coupled through the device key. Cross-board flash memory image replication cannot be unsealed on another device, eliminating parallel cloning during the manufacturing process.
[0055] Example: A RISC-V architecture SoC is used as an edge measurement node on a knitted fabric production line. The SoC integrates GlobalPlatform TEE firmware. The write process is as follows: The spinning station sends the DID to the SoC via a digital interface; the TEE internal API TEE_Sealing_Write receives the DID; the firmware uses a hardware random source to generate a nonce; performs AES-GCM encryption; writes the ciphertext and tag to the RPMB partition of the Secure eMMC; and returns a write success status. Once written, if the same interface is called again to write, the TEE compares the storage area flags and directly returns the error code TEE_ERROR_ACCESS_CONFLICT to prevent duplicate writes.
[0056] At the network topology level, the DID is considered the logical key for all subsequent transactions on the chain. When edge nodes subsequently calculate the ciphertext for quality indicators, they read the DID from the encapsulation area, hash it to obtain the random number r, and then combine it with the plaintext indicator to generate the Paillier ciphertext. Because encapsulation and decryption must be performed by hardware, any attempt to tamper with the DID at the high-privilege software level will trigger a TEE residual lock due to tag verification failure. Even if an attacker obtains the production line private key and attempts to recalculate the DID, they will not be able to overwrite the original storage area. The ultimate effect is to ensure a complete closed loop binding the three elements of "physical fingerprint, DID, and quality data."
[0057] This invention improves traditional textile traceability systems in three key ways: First, production eliminates the need to maintain an external identity database; once generated, the DID is embedded in the hardware security zone, reducing IT operations and maintenance. Second, if a counterfeit label appears during circulation, the scanning terminal will display an exception during on-chain verification due to a ciphertext-DID mismatch, significantly improving counterfeit detection sensitivity. Third, for recycling or secondary markets, fiber spectra can still be resampled and hardware unsealing can be triggered at the terminal, maintaining the same level of confidence at the end of the product lifecycle.
[0058] Ultimately, isolated storage makes distributed identity the "hardware root" of the textile quality chain, and encrypted encapsulation completes the mapping of fingerprint uncloning characteristics in the electronic field, forming an end-to-end trust base.
[0059] Preferably, an additive homomorphic public key system is used when performing homomorphic encryption on the quality indicator, and the distributed identity is converted into a random parameter via a hash derivative function to generate an encryption result.
[0060] Online quality monitoring in textile production typically involves multi-dimensional sensor data such as yarn tension, breaking strength, moisture content, bath pH, and dyeing and finishing temperature. Traditional traceability systems write these indicators in plain text into a database or directly on-chain, which can easily leak recipes and process windows. This invention introduces an additively homomorphic public key system to encrypt quality indicators and incorporates random parameters derived from distributed identities into the encryption process, achieving three goals: first, ensuring that each ciphertext is uniquely bound to a specific yarn; second, enabling batch statistics to be generated on-chain without decryption; and third, providing publicly verifiable commitment values for subsequent zero-knowledge proof circuits.
[0061] Additive homomorphic encryption refers to the addition of plaintext to ciphertext multiplication. This invention uses the Paillier system, whose key formula is:
[0062] C=g m r n mod n 2
[0063] Where C represents the quality index ciphertext; m represents the quality index vector; Q represents the integer after quantization encoding; g represents the system generator; n represents the security modulus, which is the product of two large prime numbers; r represents the random number; g m With r n Provide semantic security and randomization respectively.
[0064] Since gcd(g,n)=1, for the two ciphertexts C1 and C2, we can get:
[0065]
[0066] The product corresponds to the sum of the plaintext, satisfying the homomorphic property.
[0067] Random number binding. In conventional Paillier encryption, r is output by a pseudo-random number generator. An attacker can inject old ciphertext into a new batch through a replay attack. This invention binds random numbers to distributed identities to prevent such risks. The specific approach is: inside the TEE, call the key derivation function:
[0068] r=KDF(DID||Counter)
[0069] The DID is a distributed identity generated by a physical fingerprint, and the Counter is a node-incrementing counter. Because the DID corresponds one-to-one to the physical fingerprint, an attacker cannot generate a new DID without changing the yarn entity, and naturally cannot obtain a legitimate random number.
[0070] In the encryption process, the node reads the latest quality indicator vector Q in the trusted execution environment and maps it to an integer m using a linear quantization function. The aforementioned KDF is called to generate a random number r. The ciphertext C is calculated. The arithmetic circuit template is called to generate a zero-knowledge proof π, proving two things: C and (m, r) satisfy the above equation; and each component of Q lies within the process window. The production entity and the quality inspection entity each generate a local signature using a threshold signature algorithm, aggregating C||π to form a signature σ. The encrypted packet is output.<C,π,σ> .
[0071] On-chain addition statistics: The biggest advantage of homomorphic ciphertext is that it allows direct addition on-chain without revealing the plaintext. If regulators need to obtain the average breaking strength of all fabrics on a particular day, they can simply read all corresponding ciphertexts on-chain, perform multiplication aggregation, and then decrypt them all at once with the private key to obtain the total, without having to decrypt each item individually. This reduces the number of decryptions from N to just one, significantly reducing the exposure of the private key.
[0072] Zero-knowledge verification: The batch commitment contains the hash of the entire encrypted package. The zero-knowledge batch proof Π proves to the chain that the batch commitment is correct and that each quality indicator is within the compliance range. Downstream nodes can confirm the validity of the entire batch of data through the function Verify(Π) without the need for plaintext or public and private key supervision, saving on-chain storage and computation.
[0073] For textile companies, process windows directly impact fabric feel and dye fastness, and are therefore considered trade secrets. Homomorphic encryption renders these indicators invisible to all parties in the supply chain; binding random numbers to DIDs prevents replay at the physical layer; and zero-knowledge proofs enable downstream zero-trust nodes to verify quality labels without relying on central authority endorsement. Combined, these three elements naturally ensure authenticity, privacy, and verifiability in the traceability chain.
[0074] In this implementation example, a cotton-spandex blended fabric production line was selected: sampling sensors recorded tension, moisture content, and bath pH, which were quantified and concatenated into an integer m. A random number r was generated within the TEE, and the ciphertext C was calculated. Forty batches of data, each with 400 items, were tested on-site, resulting in a total of 16,000 ciphertexts on the chain. The supervisory node pulled the product of the ciphertext for the day and decrypted it all at once to obtain the sum of the breaking strength, which was then divided by the number of items to obtain the average. The error between the result and the off-machine measurement was less than 1%. Compared with traditional plaintext storage, this reduces the risk of sensitive data leakage and saves 15,999 decryptions compared to solutions requiring offline decryption. The coupling of homomorphic encryption and distributed identity not only ensures the indivisibility of a single piece of yarn into a single ciphertext, but also automates batch statistics, cross-factory comparisons, and industry index calculations. Zero-knowledge proofs also provide a public verification portal, meeting the transparency requirements of international certification bodies.
[0075] Preferably, Figure 2As shown, the zero-knowledge proof uses an arithmetic circuit to prove the correctness of the encryption equation and that the quality index is within the preset range, and the multi-subject signature aggregates the production subject signature, the quality inspection subject signature and the supervision subject signature through a threshold scheme.
[0076] Online traceability in textile production requires both proof that process data is indeed collected on-site and protection of commercial formulas from public disclosure. This invention, after completing homomorphic encryption in an edge trusted execution environment, introduces zero-knowledge proofs and multi-agent threshold signatures. This provides a mechanism for all parties on the chain to verify data authenticity and compliance without decryption, while simultaneously cryptographically binding the responsibilities of multiple parties.
[0077] In this zero-knowledge proof design, the Groth16 proof system is used to express the quality indicator encryption equation and the indicator value range as arithmetic constraints. Encryption uses an additive homomorphic public key system, whose public parameters are the modulus n and the generator g. The quality indicator is encoded to obtain the integer m, and the random number r is derived from the distributed identity. The edge node calculates:
[0078] C=g m r n mod n 2
[0079] The verifier needs to confirm that the above equation is true but cannot know m. In the Groth16 framework, the operation is translated into a circuit. First, a multiplication gate chain is constructed to calculate g m With r n , then perform modular multiplication to get the left formula, and finally compare it with the public input C. This part ensures the "correctness of the encryption equation".
[0080] The quality index interval constraint adopts the bit decomposition method. Assume that the host computer determines the lower limit L and the upper limit U. The coded integer is split into bit vectors (b0,…,b k ), add constraints:
[0081]
[0082] Proving "metric compliance" can be accomplished by constructing a circuit using two sets of less-than comparators. In summary, the circuit's public inputs are C, g, n, L, and U, and its private inputs are m and r. The circuit scale is linearly proportional to the metric dimensions, and the resulting proof π has a fixed length, facilitating long-term on-chain storage and rapid client verification.
[0083] In practical applications, edge nodes first perform Paillier encryption and circuit witness padding within a trusted execution environment. A GPU or FPGA coprocessor then generates π in milliseconds. Because Groth16 verification only involves constant-time exponential operations, consumer mobile phone chips can complete verification in tens of milliseconds. To ensure transparent public key custody, all circuit reference strings are generated through multi-party computation by production, quality inspection, and supervision, and then archived on-chain.
[0084] Multi-subject threshold signatures require that the responsible parties can be clearly identified on the chain. If only a single production entity signs, quality inspection and supervision cannot deny the subsequent links. For this reason, a two-threshold three-signature is used. Specific process: The system generates a BLS master private key s offline, which is divided into P ,s Q ,s R >Three pieces are respectively given to the production subject P, the quality inspection subject Q and the supervision subject R. After the encryption package is generated, each subject calculates the local signature σ of the message hash H(C||π) i The aggregation algorithm combines any two partial signatures into an aggregate signature:
[0085]
[0086] where λ P ,λ Q is the Lagrange coefficient. The verifier can verify the signature once using the public master key. If the two parties do not cooperate, the aggregate signature cannot be generated and the transaction cannot be uploaded to the chain. This mechanism effectively prevents a single party from privately writing to the chain.
[0087] Through this invention, any node on the chain can verify that "plaintext indicators are correctly encrypted and within the process range" and "at least two parties agree on" simply by using C, π, σ and public parameters. Ciphertexts remain homomorphic, allowing regulators to perform batch statistics without decryption, saving off-chain operations and protecting trade secrets. Signature aggregation limits counterfeiting paths: an attacker must simultaneously obtain the private key fragments of any two parties and rewrite and encapsulate them at the edge node, which is almost impossible under hardware isolation.
[0088] In this example, three metrics—tension, temperature control, and bath pH—are collected during a single dyeing process. Each metric is quantized into a 10-bit integer and combined into an integer m. The GPU completes circuit proof in 30 milliseconds, with a proof size of less than 100 bytes. Verification on a mobile phone takes 16 milliseconds. When the quality inspection entity rejects the signature due to process errors, the system is unable to generate an aggregate signature. The production entity's attempt to upload the signature to the blockchain is automatically rejected by the network node, demonstrating the effectiveness of threshold constraints.
[0089] Generate batch commitments and zero-knowledge batch proofs for encrypted packages that reach the batch quantity threshold, shard them through erasure coding, and assemble them with the commitment data into a directed acyclic graph transaction, broadcast it to the Byzantine fault-tolerant network, and record the consensus;
[0090] The single-machine collection node of the textile enterprise continuously outputs encrypted packets, each of which contains the homomorphic ciphertext C i 、Zero-knowledge single packet proof π i With the aggregate signature σ i To reduce on-chain congestion and enhance availability, the present invention sets a batch number threshold n on the aggregator side of the factory. When the count reaches the threshold, the aggregator first calculates the Merkle tree of all messages in a fixed order to generate a batch commitment root:
[0091] H batch =MerkleRoot(C1||π1,…,C n ||π n )
[0092] Among them H batch It is the unique fingerprint of the entire batch of content. If any of the encrypted packets is tampered with or omitted, the verifier will recalculate and obtain a different root, and the anomaly can be detected immediately. This batch commitment root is written into the batch zero-knowledge proof circuit as a public input. The circuit verifies two points simultaneously: first, the root hash corresponds to each leaf node, and second, the single packet proof π in each leaf node i It is valid under the public key parameters, thus proving as a whole that "this batch of data is authentic and compliant."
[0093] When the number of single packets is large, directly storing the entire batch of original text on the chain will consume bandwidth and destroy privacy. For this reason, erasure coding is used to achieve verifiable storage off the chain. Perform Reed-Solomon encoding and divide it into k data slices and m redundant slices. The shard sequence {shard1,…,shard k+m} Distributed storage in multiple alliance member nodes. To ensure that any subsequent query party can reconstruct the original data while preventing malicious nodes from privately deleting it, the present invention reconstructs the Merkle tree for the shard sequence to obtain the shard commitment root H shard . In the zero-knowledge batch proof, H is declared shard The public input allows shard commitments and batch commitments to rely on the same proof. When a storage node loses a shard, the validator cannot obtain the complete set of shards during the reconstruction process, resulting in a discrepancy between the calculated shard root and the on-chain stub, immediately triggering the slashing logic.
[0094] Batch Commitment Root H batch 、Shard Commitment Root H shardThe zero-knowledge batch proof π and the shard address table together form a directed acyclic graph transaction payload. The transaction header uses a unified field order: batch root, shard root, proof hash, and shard address table hash to prevent node parsing failures caused by inconsistent implementations across different factories. Transactions are broadcast using the consortium chain's Byzantine Fault Tolerant consensus protocol. Upon receiving a transaction, each node first verifies π and then checks shard address table coverage. When the cumulative weight of verified nodes reaches a threshold, consensus is considered established, and a confirmation record containing a timestamp and transaction hash is generated. This confirmation record is written to the next-level graph structure and referenced by subsequent transactions to form an immutable topology.
[0095] This batching mechanism serves three purposes within the traceability chain. First, batched zero-knowledge proofs significantly reduce verification overhead, allowing clients to trust the entire batch with a single verification, rather than having to verify n pieces of data individually. Second, erasure coding and sharding promise to couple availability and integrity. Even in extreme network conditions, data can be recovered from any k shards while preventing partial shard tampering. Third, the weight-driven Byzantine consensus of the directed acyclic graph enables multiple factories to write to the chain in parallel without waiting for long blocks, improving throughput and reducing latency.
[0096] Example. A weaving factory sets a batch threshold of 500, with an average encrypted packet size of 1,000 bytes. The aggregator collects the full batch and calculates the batch root within nine seconds. The GPU-based zero-knowledge batch proof generation takes 0.8 seconds, and the proof size is 96 bytes. The Reed-Solomon configuration uses 20 data shards and 10 redundant shards, for a total of 30 shards, each 4,000 bytes. After broadcasting the transaction to the consortium chain, it is confirmed by nodes exceeding the threshold weight within six seconds. Subsequently, another fabric storage node loses three shards due to a disk failure, but 23 shards are still available, and the system automatically reconstructs the original text; the shard hash verification passes, and the on-chain commitment remains valid. If the number of missing shards increases, making it impossible to meet the recovery threshold, the shard root recalculation fails, the corresponding transaction is marked as invalid, and the lost node's stake is deducted, suppressing malicious behavior.
[0097] Preferably, after reaching the batch size threshold, erasure coding is used to divide the encrypted package into data shards and redundant shards, and shard commitments are calculated for all shards.
[0098] When a textile production line buffers continuously generated encrypted packets until the batch size threshold is reached, it needs to ensure that the entire batch of data can be securely stored off-chain and its integrity can be verified on-chain. This invention uses erasure coding to split the batch data into data shards and redundant shards, and then calculates shard commitments for all shards, thereby achieving both fault-tolerant storage and fast consistency verification.
[0099] Batch data is first spliced into a byte stream in a fixed order Assume the total length is L. The aggregator selects parameters k and m, where k is the number of data fragments and m is the number of redundant fragments, satisfying k+m=d. Considered as a Galois field GF(2 8 ) on the coefficient sequence, and then construct the polynomial:
[0100]
[0101] where b i is the i-th byte. In the encoding stage, d non-zero field elements α1,…,α are selected for the polynomial. d As evaluation points, calculate:
[0102] S j =P(α j ),j=1,…,d
[0103] The first k S j As data fragments, the last m fragments are used as redundant fragments. Due to the maximum distance separation property of Reed-Solomon code, any k fragments can uniquely restore P(x), and then restore For off-chain storage, this means that up to m shards can be permanently lost without affecting data reconstruction, greatly improving the ability to resist node failures.
[0104] Next, we need to make the integrity commitment of the slice public without revealing the content of the slice. The present invention uses the Merkle tree. For each slice S j Calculate the hash value:
[0105] h j =H(S j )
[0106] Where H is a hash function that can resist collision. d} Build a complete binary tree by arranging the indexes in ascending order, hashing each pair of adjacent nodes in series and then hashing again until the root hash is obtained:
[0107] H shard =MerkleRoot(h1,…,h d )
[0108] The root hash is written to the shard_root field of the directed acyclic graph transaction. Due to the one-way compression property of the Merkle tree, any subsequent validator can verify that the shard belongs to the original batch in logarithmic time, as long as they possess the shard and its Merkle path, without having to download all the data. This works in conjunction with another field, batch_root, to ensure batch-level and shard-level consistency.
[0109] like Figure 3As shown, shard storage uses a distributed content addressing approach. Each shard's hash serves as its address and is transmitted to different member nodes via a lightweight peer-to-peer network. The system locally registers a shard index table, recording the shard index, hash, and node address triplet, and writes the hash value to the chain. Any querying party seeking to reconstruct a batch of content simply requests the corresponding hash from the network to obtain the shard. If a shard is missing, the reconstructor can submit a failure log to the alliance contract; the contract queries the on-chain index table to locate the responsible node. If the node fails to reconstruct the shard within the grace period, its stake will be forfeited.
[0110] Unlike traditional centralized storage, the erasure coding of this invention offers two unique benefits. First, storage redundancy is guaranteed algorithmically, eliminating the need for master-slave replication; each new node only needs to take on a single shard to join the service. Second, any fragment leaks are simply part of the encrypted packet concatenation stream, but the shard content remains in homomorphic ciphertext, preventing the disclosure of plaintext quality indicators. Furthermore, hash addressing prevents shard replacement.
[0111] Example: Assuming a batch threshold of 400 and an average encrypted packet size of 2,000 bytes, the length of the spliced stream is approximately 800,000 bytes. Select k = 20 and m = 10. Each encoded fragment is fixed at 4,000 bytes. Deploy three factory nodes and two third-party nodes, for a total of five nodes. During actual operation, one node was randomly stopped and all its fragments deleted. The remaining nodes were still able to provide at least 20 fragments, and the client successfully reassembled the batch data. On-chain verification requires only downloading the node hash with a Merkle path length of four. Verification takes less than 20 milliseconds, which is sufficient for mobile scenarios.
[0112] If a node maliciously tampers with shard content and still provides a response, the requester will immediately identify the mismatch between the shard hash and shard_root. The alliance contract will automatically deduct the node's staked points and reset its rights to zero, restricting its subsequent broadcast permissions. This economic incentive and penalty mechanism reduces manual inspection costs and ensures the long-term availability of shards.
[0113] Compared to existing textile traceability methods that simply package and upload data, the erasure coding-sharding commitment scheme proposed in this paper not only reduces the amount of data uploaded to the chain but also provides dynamic disaster recovery. Even if the production site temporarily loses network connectivity, local nodes can cache shards and transactions, broadcasting them all at once upon restoration without having to replay all calculations. Other nodes on the chain can then batch-verify the cached shards based on the Merkle root, significantly improving the system's tolerance to fluctuations in the shop floor network.
[0114] Through batch-layer encryption commitment, erasure sharding multi-copy storage and on-chain enumeration penalty, the present invention achieves verifiable and reliable storage without sacrificing privacy, building a stable data foundation for the traceability of textiles throughout their life cycle.
[0115] Preferably, when assembling a directed acyclic graph transaction, batch commitment, shard commitment and zero-knowledge batch proof are written into the transaction payload in a fixed field order, and a consensus record is generated after confirmation by the Byzantine fault-tolerant consensus.
[0116] To ensure that textile quality data is published on the consortium chain with high concurrency, low latency and non-repudiation, the present invention adopts a parallel-write directed acyclic graph (DAG) structure and constructs a fixed-format transaction payload on the node side.
[0117] In the transaction field design, the collection node will splice the encrypted packets that reach the batch quantity threshold into a byte stream and generate a two-level commitment:
[0118] H batch =MerkleRoot(C1||π1,…,C n ||π n )
[0119] H shard =MerkleRoot(S1,…,S k+m )
[0120] Among them C i is the homomorphic ciphertext, π i is a single-packet zero-knowledge proof, S j The shards are generated using Reed-Solomon encoding. Groth16 is then called to construct a batch zero-knowledge proof, π, which publicly asserts that "the batch root matches all individual packets and that all individual packets are compliant." To avoid parsing ambiguity and facilitate direct hashing by nodes, this invention stipulates that transaction payloads are written in the following order:
[0121] 1. Field 1: Batch Commitment Root H batch 2. Field 2: Shard Commitment Root H shard ; 3. Field 3: Serialized bytes of zero-knowledge batch proof π; 4. Field 4: Overall hash of the shard address table H index All fields are encoded using fixed-length or variable-length prefixes to ensure that the hash values calculated for the same transaction are consistent across different languages.
[0122] Broadcast and Byzantine fault-tolerant consensus, transaction metadata includes the sending timestamp, parent transaction list (fixed two) and sender's public key. The node concatenates the payload and metadata and takes the hash H tx , and then use the private key to generate the signature σ tx Complete transaction <H tx ,σ tx ,payload,meta>Broadcast to the alliance network.
[0123] The alliance network uses a weight-driven Byzantine fault-tolerant algorithm: each node maintains a weight w iThe weight is determined by a combination of staking points and historical availability. After receiving the transaction, the node performs a three-step verification locally:
[0124] ①Signature verification: check σ tx Corresponding public key; ② Verification: call Verify(Π, H batch , H shard );③Search: Check whether the local or neighboring nodes can provide enough fragments.
[0125] If all passes, the transaction is added to the memory pool and the two transactions with the highest non-conflicting weights are selected as parent nodes. If the transaction is referenced by a child transaction with a cumulative weight not less than the threshold, it is considered stable and a consensus record is generated. <H tx ,height,T confirm ,W sum > and write the DAG again.
[0126] Light client verification, mobile terminals or zero-trust parties only need to download the transaction header and field hash to recalculate H tx If they match, the batch root and shard root can be confident they haven't been tampered with. When deeper verification is required, the client takes Pi and the public parameters and executes the verification algorithm locally. This algorithm takes constant time, measured at just over ten milliseconds on a mid-range phone. If users wish to verify fiber quality offline, they can retrieve the encrypted package and Merkle path stored in the tag and use the batch root to quickly confirm that the encrypted package belongs to the same batch on the chain.
[0127] To ensure economic incentives and fault tolerance, after a transaction is successfully written to the chain, the broadcasting node calculates a fee based on the field, and the system automatically deducts the corresponding stake. If a missing shard is subsequently discovered, making it impossible to meet the erasure coding recovery requirements, any node can submit a "ProveMissing" transaction for error correction. After verification by the smart contract, the negligent node's stake is deducted and its weight is reduced, limiting its write frequency. This ensures the long-term availability of shards while curbing network bloat caused by malicious writes.
[0128] In this example, a consortium network consisting of three fabric factories, two warehouses, and a supervisory authority, with a total weight of ten nodes, has a total weight of one hundred and a threshold of fifty. A factory aggregator collects five hundred encrypted packets and concatenates a stream of eight hundred thousand bytes. The zero-knowledge batch proof is ninety-six bytes in size, resulting in a total transaction size of less than one hundred and twenty kilobytes. GPU proof generation takes 0.8 seconds, and network propagation to all nodes takes an average of one second. The supervisory node and two warehouse nodes successively reference the transaction, resulting in a cumulative weight of sixty. Once the threshold is exceeded, the system issues a consensus record within six seconds. At this point, even if an attacker controls the remaining nodes, they cannot roll back the confirmed transaction.
[0129] Node offline test: A node was randomly removed and all shards held were deleted. A total of 24 shards still met the Reed-Solomon decoding threshold, and the original batch was successfully reconstructed. Two more nodes were removed, leaving only 19 shards, and decoding failed. A third-party node submitted proof of missing shards. The contract verified that the shard root did not match, immediately forfeiting the stake of the missing node and broadcasting a blacklist. Scanning the QR code to verify the transaction hash and batch root on the consumer side only downloaded 600 bytes, and the mobile phone completed verification within 500 milliseconds, providing a smooth experience.
[0130] Through fixed field writing and weighted Byzantine consensus, the present invention allows multiple factories to write to the chain in parallel without being restricted by the throughput of a single chain; sharding commitment and penalty mechanism ensure the long-term accessibility of data; zero-knowledge batch proof provides a balance between plaintext privacy and verification efficiency; light clients can complete authentication in seconds in low-bandwidth scenarios, supporting the real-time traceability needs of textiles from production, warehousing to sales.
[0131] After the consumer reads the RFID tag, fingerprint comparison and homomorphic verification are performed to complete offline verification. After connecting to the network, the batch certificate is verified and points are pledged. When the time lock expires, the historical quality data is jointly decrypted, a maintenance recommendation hash is generated, and written into subsequent transactions to close the traceability chain.
[0132] After consumers touch the garment, they can complete preliminary authenticity verification without the need for a network connection. The RFID tag permanently stores three pieces of data: a physical fingerprint hash, a distributed identity, and the location information of the most recent batch commitment. When a mobile phone is placed near the tag, it first reads these three fields via near-field communication, then activates the dual-band spectral module to perform a macro scan of the fabric surface. The collected fluorescent cubes are compressed into a fingerprint vector using the same principal component projection algorithm. The terminal calculates the hash distance between two vectors:
[0133]
[0134] If d≤d max The fingerprint matches. The terminal then uses the distributed identity to recover the random number r through the hash derivative function, reads the encrypted packet ciphertext C stored in the tag, and performs homomorphic verification in an offline state:
[0135] g m =C·r -n mod n 2
[0136] Where g is the public key generator, and m is a quality indicator mapped to an integer. If the equation always holds, it proves that the ciphertext is indeed derived from the bound identity, and offline verification is successful. This design enables consumers to detect tag cloning or clothing swapping in showrooms or logistics warehouses without the need for an internet connection.
[0137] Once connected to the network, the application requests a DAG node based on the batch commitment field, downloading the corresponding transaction header and zero-knowledge batch proof Π. Using a mobile micro-verifier, Verify(Π) asserts that the entire batch of data has not been tampered with and that the metrics are compliant, without downloading the entire batch of ciphertext. Successful verification triggers the smart contract function stake(1TEX), where the terminal stakes one point on-chain. Staking serves two purposes: it compensates for network maintenance through transaction fees and enhances the consumer's account credibility, allowing for higher discounts on subsequent recycling or resale.
[0138] For the production side, the ciphertext is appended with a verifiable delay function to generate a time lock factor. The delay function uses continuous squares:
[0139]
[0140] Where N is the security modulus and t corresponds to the number of predefined months. Any node must execute 2 t The output can only be obtained by square, ensuring that the ciphertext cannot be unlocked in advance during the warranty period. When the time lock expires, the production entity, quality inspection entity, and supervision entity upload their own private keys to the chain according to the threshold; the contract is combined with the private key through Lagrange interpolation, and the historical quality vector set {Q τ}.
[0141] The decrypted plaintext is not directly disclosed, but is instead entered into the federated learning platform. Each factory locally trains a long short-term memory network to predict the remaining life of the loom tension roller and uploads the encrypted gradient to the scheduling server. The server securely aggregates the data to obtain the global weights and then distributes the new model. The factory uses the new model to calculate the maintenance window in the MES system and generate ISON recommendations. The system serializes the recommendations and calculates the hash H. maint , and writes it as a field into the factory's next batch of transactions. If subsequent inspections reveal that maintenance wasn't performed as recommended, the supervisory node calls proveUnserved(H_{-1}^{}), causing the contract to automatically freeze the factory's pledge points and reduce its network weight, thus achieving a closed-loop economic incentive. Example: A retail store randomly selected fifty coats. Offline verification took an average of 700 milliseconds, with a fingerprint match false rejection rate of less than one in a thousand. Online batch verification consumed less than one kilobyte of data and completed within an average of one second. After the eighteen-month warranty period expired, the system collected private key shards from third-party nodes, batch-decrypted 20,000 ciphertexts in 20 seconds, and the federated learning cycle completed the model update in seven minutes. Based on the model's recommendations, twenty-five tension rollers were replaced ahead of schedule, resulting in a 20% decrease in yarn breakage rates within the quarter. Maintenance logs were uploaded to the blockchain and referenced in the next batch of transactions, forming a closed traceability chain.
[0142] Preferably, after reading the RFID tag, the consumer first compares the physical fingerprint hash, and then uses the random parameters recovered from the distributed identity to perform homomorphic verification on the encrypted package to obtain an offline verification result.
[0143] The offline verification process at the consumer end is designed to ensure that users can verify the authenticity of textiles even in an offline environment without revealing any production secrets. To achieve this goal, the RFID tag permanently stores three read-only fields: a physical fingerprint hash, a distributed identity, and a batch-bound encrypted package ciphertext. The physical fingerprint hash is derived from the fluorescent fingerprint vector generated during the spinning stage, which is first processed through a one-way hash function and then written into the RFID chip fuse area. It cannot be modified. The distributed identity is output by a verifiable random function and is also written into the fuse area. The encrypted package ciphertext encapsulates the homomorphic ciphertext of the quality indicators, the zero-knowledge proof digest, and the multi-agent signature digest, and is locked with a write-once command.
[0144] The verification process is divided into two stages. The first stage is fingerprint comparison. The mobile terminal uses near-field communication to read the RFID tag, obtains the physical fingerprint hash value, and then calls the dual-band spectrum acquisition module to scan the textile surface. The collected data is reduced in dimension by principal component transformation to obtain a vector The terminal calculates the hash and compares it with the hash stored in the tag, using the Hamming distance:
[0145]
[0146] Where H is a one-way hash, V PUF is the original fingerprint vector. If d is less than the system-set threshold, it is considered a fingerprint match and enters the second stage. Experiments show that when the threshold is set to 2 on 100,000 samples, the pass rate for genuine products exceeds 99%, and the false pass rate for counterfeits is less than 1 in 10,000.
[0147] The second stage is homomorphic verification. The distributed identity is directly read by the RFID tag, and the terminal calls the key derivation function in the secure execution area to output a random number:
[0148] r=KDF(DID||Salt)
[0149] Where DID is a distributed identity string, and Salt is a fixed string to prevent rainbow table attacks. The random number and public key parameters g and n are used together to verify the Paillier ciphertext. The ciphertext stored in the tag is denoted as C. The terminal calculates:
[0150] C′=C·r -n mod n 2 ,g m ≡C′mod n 2
[0151] If there exists an integer m such that the above equation holds, the ciphertext is indeed encrypted by the same distributed identity random number and has not been tampered with. Since the terminal cannot decrypt m, it cannot obtain the plaintext quality indicator; however, it has been mathematically proven that the ciphertext originated from a legitimate production node. The homomorphic verification process requires only one modular multiplication and one modular exponentiation operation, which can be completed by a typical mobile phone processor in hundreds of milliseconds, consuming negligible power.
[0152] This two-stage design delivers three benefits. First, fingerprint comparison is based on physical features, preventing any cloned tag from forging a continuous fluorescent pattern and preventing substitution. Second, homomorphic verification binds the physical identity to the encrypted data, ensuring the tag's content has not been tampered with after offline copying. Finally, the entire process is independent of the internet, making it suitable for use in weak network scenarios such as exhibition halls, warehouses, and cross-border transportation.
[0153] After the network is restored, the terminal will proactively download the corresponding batch of zero-knowledge proofs and invoke a fast verification algorithm. Successful verification triggers the staking of one point to the alliance contract. This point pledge record is written to the chain, providing both a redemption discount for the terminal and contributing to the network's activity for subsequent transactions. If the terminal detects a fingerprint or homomorphic verification failure, it can upload the event hash, which will be verified by the supervisory node for secondary verification and then subject to a penalty for the factory's pledge.
[0154] Example: Fifty cotton-polyester jackets were randomly sampled. The data stored on the hang tags had a distributed identity length of 50 bytes and a Paillier modulus length of 2,048 bits. Offline scanning took an average of 700 milliseconds, consisting of 400 milliseconds for spectral acquisition, 200 milliseconds for hash calculation, and 100 milliseconds for homomorphic verification. All samples successfully matched fingerprints. After replacing five of the hang tags with printed clones, offline verification immediately rejected the results and, in a networked environment, uploaded the event to the blockchain. The contract located the counterfeit batch based on the event hash and froze the stake on the relevant nodes. Experimental results demonstrate that offline verification combined with a points mechanism can detect and block counterfeit goods without human intervention.
[0155] Preferably, after the consumer is connected to the Internet, it verifies the zero-knowledge batch proof and pledges points to the governance contract. The information on the completion of the pledge is written into the directed acyclic graph network along with the transaction for subsequent query.
[0156] After completing fingerprint comparison and homomorphic verification offline, the consumer terminal enters the online phase. Based on the batch location information in the RFID tag, the terminal first requests the corresponding transaction header from any reachable DAG gateway. The transaction header contains the fields batch_root, shard_root, and the zero-knowledge batch proof serialized bytes. The terminal loads the local embedded verifier and executes the Groth16 core algorithm once:
[0157] Verify(Π,vk, <H batch ,H shard >)=1
[0158] Where Π is the batch zero-knowledge proof byte, vk is the preset verification key, <H batch ,H shard > is a public input. If the return value is one, it means that all leaf nodes in the entire batch have passed the single-package evidence verification and the quality indicators meet the process range. The size of the verifier constant layer is fixed, and the mobile terminal only consumes hundreds of milliseconds and less than one megabyte of storage, which is suitable for low-end devices. After successful verification, the terminal automatically calls the governance contract function stakeForBatch(batch_root), stakes one standard point TEX to the contract account and specifies the batch root as the index. The contract performs the following steps: check the caller account point balance; freeze one TEX and record the correspondence between the caller address and the batch root; generate the event StakeRecorded(caller, batch_root, block_time).
[0159] Contract events are broadcast to all nodes via the consortium chain's built-in event mechanism. Simultaneously, the terminal embeds the event hash into a new directed acyclic graph transaction. The transaction payload is written in a fixed order: event hash, batch root, caller address, and number of points. This transaction references the previously agreed-upon batch transaction as its parent node to ensure topological connectivity. Upon receiving the transaction, the consensus layer performs signature verification and field integrity checks, and generates a consensus record when the weight threshold is met.
[0160] The points staking mechanism has three layers of incentives. The first layer targets consumers: the cumulative number of pledges per terminal account during its lifetime will be counted towards its credit score. If the same brand of used clothing is subsequently sold on a recycling platform, the credit score will be used to receive a higher price per unit. The second layer targets production nodes: the governance contract calculates the batch pledge coverage rate each cycle. If the coverage rate is insufficient, the corresponding factory's write chain weight will be reduced, reducing its publishing bandwidth. The third layer targets the alliance network: a portion of the points are frozen by the contract as a network maintenance fund, which is used to incentivize nodes to preserve shards and maintain bandwidth over the long term.
[0161] From a data flow perspective, after the staking event hash is written to the DAG, it forms a reference chain with the batch root: BatchTx → StakeTx. Any industry participant who needs to query the consumer-side verification record for a particular garment can simply traverse this chain to obtain a list of all StakeTxs. Using the event hash, they can retrieve the staking time, address, and reputation score from the contract log. This allows verification history to be restored without the need for centralized server archiving.
[0162] Example: A chain store sold 2,000 denim jackets in a week, with an average of 280 daily code scans. Mobile verification time ranged from one to two seconds. The pledge transaction size was 300 bytes. The gateway broadcast the transaction to the entire network within ten seconds, reaching the weight threshold within four seconds. Periodic contract statistics showed a 98% coverage rate for the batch, increasing the factory's weight. A returned jacket was flagged as suspicious by the system due to a lack of pledge records. Re-inspection at the quality inspection center confirmed that the hang tag had been replaced, and the leak was traced back to a logistics node.
[0163] Compared to the common "scan code, upload to chain" approach in existing blockchain traceability, this invention transforms the scanner into a link guardian: staking is only encouraged after verification through zero-knowledge batch proof; otherwise, the terminal refuses to submit the transaction. This prevents malicious merchants from skipping fingerprint comparison and directly uploading fake scanned code data in batches. Furthermore, the event hashing mechanism prevents the exposure of plaintext addresses in transactions, protecting consumer privacy.
[0164] When a new brand joins the consortium chain, it only needs to register its symbol in the contract whitelist. Once the terminal updates the brand list, its points logic will be automatically processed without upgrading the node software. If it upgrades to a new zero-knowledge proof protocol in the future, it only needs to add a new verification key to the contract, while the old batch root will remain valid, demonstrating the solution's forward compatibility.
[0165] Preferably, after the time lock expires, no less than a threshold number of signing entities submit key fragments to jointly decrypt the encrypted package to obtain historical quality data, and generate maintenance recommendation hashes based on the historical quality data and write them into subsequent directed acyclic graph transactions to close the traceability chain.
[0166] In the textile industry, after-sales service, recalls, and preventative maintenance often occur months or even years after garments are sold. If traceability systems can only provide real-time quality metrics, they are unable to support long-term governance. This invention adds a time lock factor to the batch encryption package generation phase, ensuring that data remains encrypted during the warranty period. After the warranty period, multiple entities can jointly decrypt the data, returning the historical quality plaintext to the production side, driving predictive maintenance and closing the data loop. The core mechanism consists of three components: a delay function, threshold key sharding, and an on-chain maintenance hash.
[0167] After outputting the Paillier ciphertext C, the system selects a large integer modulus N and a random seed y0 and performs continuous square
[0168]
[0169] Where τ represents the number of discrete steps corresponding to the lock period. The delay function evaluation must be performed sequentially and cannot be accelerated in parallel. Therefore, any entity that wants to obtain The time required is exponential to the period. The node stores the encrypted packet at the end. Verifiers can verify the correctness of the delay function output in constant time, but cannot infer historical quality information before the warranty period. This design prevents early leaks from affecting market pricing or allowing competitors to learn the formula window.
[0170] Threshold decryption, Paillier private key s is split into P ,s Q ,s R >Three key fragments, respectively holding the production entity P, the quality inspection entity Q, and the supervision entity R. Using a two-threshold three-shard strategy, any two parties can reconstruct the private key. After the time lock expires, the contract event Unlock(batch_root) is triggered on the chain, requiring at least two parties to submit their respective key fragments within the specified window. The contract first verifies that the VDF calculation is complete, that is, the difference between the current block time stored on the chain and the transaction time satisfies ≥τ steps corresponding to milliseconds; then verifies the authenticity of the signature fragment, restores s through Lagrange interpolation, and decrypts all batch ciphertexts at once to obtain the historical quality vector {Q t If any fragment is missing, the contract records a timeout event and deducts the defaulting party’s stake to ensure the reliable triggering of the decryption process.
[0171] For predictive maintenance, the decrypted vector is used to predict the residual life using the factory-side long short-term memory network model, and the maintenance recommendation JSON is output. To avoid on-chain bloat, only the serialized hash of the JSON is taken:
[0172] H maint =SHA256(JSON)
[0173] The hash is written into the maint_root field of the next directed acyclic graph transaction and references the previous batch of transaction hashes, forming a directed edge. After the maintenance work order is executed in the MES system, it is synchronized back to the chain along with the signature photo hash. If there is still no closed-loop proof before the end of the recommended window, any node can call proveUnserved(H_{\text{maint}}). The contract automatically deducts the factory's stake and reduces its network weight, forcing the manufacturer to comply with the predicted maintenance.
[0174] This invention ensures that quality indicators remain encrypted throughout the warranty period, exposing only verifiable commitments during the distribution and retail stages, preventing the leakage of commercial formulas. Threshold sharding requires multi-party endorsement. Once historical plaintext is publicly available, no link can deny earlier data. Maintaining a hash write chain binds stakes, with penalties for failures, creating a closed loop of data and incentives. Decrypted plaintext feeds back into model weights, improving prediction accuracy over time and reducing downtime losses.
[0175] In the embodiment, a denim production line sets τ to 18 months, corresponding to the number of steps 2 34 . After the expiration, the production entity and the supervisory entity each upload a key fragment. The contract reconstructs the private key and decrypts 20,000 ciphertexts, which takes 20 seconds. The prediction model gives two maintenance suggestions: replacing the loom tension roller and lowering the desizing temperature, and the hash is written to maintroot. The factory completes the maintenance within 30 days and submits the photo hash on the chain. After verification by the supervisory node, 20% of the pledge is released as a reward; the other factory that fails to perform maintenance on time is fined and its pledge is confiscated and its weight is lowered, and the write chain bandwidth is reduced the following month. Statistics show that the yarn breakage rate of production lines that perform maintenance has decreased by 26%. The failure rate of production lines that have not performed maintenance has increased. This proves that the time lock-threshold shield decryption-maintenance hash mechanism not only closes the traceability chain, but also directly improves production reliability, forming a self-driven improvement framework for the entire life cycle of textiles.
[0176] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included within the scope of the claims of the present application.
Claims
1. A blockchain encrypted traceability method for textile quality, characterized in that: The following steps are involved: During spinning, an unclonable fingerprint is implanted and a distributed identity is generated. Process data is collected in a trusted execution environment to form quality indicators, which are then homomorphically encrypted and attached with zero-knowledge proof and multi-agent signatures to generate an encrypted package. Generate batch commitments and zero-knowledge batch proofs for encrypted packages that reach the batch quantity threshold, shard them through erasure coding, and assemble them with the commitment data into a directed acyclic graph transaction, broadcast it to the Byzantine fault-tolerant network, and record the consensus; After the consumer reads the RFID tag, fingerprint comparison and homomorphic verification are performed to complete offline verification. After connecting to the network, the batch certificate is verified and points are pledged. When the time lock expires, the historical quality data is jointly decrypted, a maintenance recommendation hash is generated, and written into subsequent transactions to close the traceability chain.
2. The method according to claim 1, characterized in that When implanting unclonable fingerprints, mixed marking materials are used to make the fingerprints continuously distributed along the fiber axis, and fingerprint data is collected through dual-band spectroscopy.
3. The method according to claim 1, characterized in that After the distributed identity is generated, it is written into a trusted execution environment with an isolated storage area, and a unique copy of the distributed identity is retained in the isolated storage area.
4. The method according to claim 1, wherein When performing homomorphic encryption on quality indicators, an additive homomorphic public key system is used, and the distributed identity is converted into random parameters through a hash derivative function to generate the encryption result.
5. The method according to claim 1, wherein Zero-knowledge proof uses arithmetic circuits to prove the correctness of encryption equations and that quality indicators are within a preset range. Multi-subject signatures aggregate the signatures of production entities, quality inspection entities, and supervision entities through a threshold scheme.
6. The method according to claim 1, characterized in that After reaching the batch quantity threshold, erasure coding is used to divide the encrypted package into data shards and redundant shards, and shard commitments are calculated for all shards.
7. The method according to claim 1, characterized in that When assembling a directed acyclic graph transaction, batch commitment, shard commitment, and zero-knowledge batch proof are written into the transaction payload in a fixed field order, and a consensus record is generated after confirmation by the Byzantine fault-tolerant consensus.
8. The method according to claim 1, characterized in that After reading the RFID tag, the consumer first compares the physical fingerprint hash and then uses the random parameters recovered from the distributed identity to perform homomorphic verification on the encrypted package to obtain the offline verification result.
9. The method according to claim 1, characterized in that After connecting to the Internet, the consumer verifies the zero-knowledge batch proof and pledges points to the governance contract. The pledge completion information is written into the directed acyclic graph network along with the transaction for subsequent query.
10. The method according to claim 1, characterized in that After the time lock expires, no less than a threshold number of signing entities submit key fragments to jointly decrypt the encrypted package to obtain historical quality data, and generate maintenance recommendations based on the historical quality data. The hash is written into the subsequent directed acyclic graph transaction to close the traceability chain.
Citation Information
Cited By
Mechanical test authenticity tracing method
CN120542452A
A method for tracing the authenticity of mechanical tests
CN120542452B
Internet of Things data secure storage method and device based on cloud computing and medium
CN121056143A
Medical static distribution code scanning logistics tracking method
CN121189965A
Medical compounding scanning code logistics tracking method
CN121189965B