A blockchain-based authentication consulting method and system

CN120821800BActive Publication Date: 2026-08-07FUZHOU JINDAO EDUCATION CONSULTING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
FUZHOU JINDAO EDUCATION CONSULTING CO LTD
Filing Date
2025-07-03
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0005]1、决策支持不足:依赖静态知识库和人工经验的被动问答模式,缺乏基于最新数据的主动分析决策机制,导致认证决策的准确性和时效性降低

Benefits of technology

[0030]1、通过服务器获取大量的历史认证咨询数据以及历史认证标准文件,对各历史认证咨询数据以及历史认证标准文件进行预处理,对预处理后的各历史认证咨询数据进行标注后构建咨询数据集,基于预处理后的各历史认证标准文件构建动态决策知识图谱;接着创建调用动态决策知识图谱进行认证咨询服务的认证咨询决策模型,设定认证咨询决策模型的损失函数,通过咨询数据集以及损失函数对认证咨询决策模型进行训练和部署;企业客户端与服务器进行双向鉴权并协商会话密钥,服务器记录鉴权日志,将鉴权日志加密为鉴权密文日志并存储,计算鉴权密文日志的第一日志指纹上传区块链,获取并存储区块链反馈的第一存证证书;企业客户端通过会话密钥将认证咨询内容加密为咨询密文,获取当前的时间戳T1作为请求时间,基于咨询密文以及请求时间生成认证咨询请求发送给服务器;服务器对认证咨询请求进行校验和解析得到认证咨询内容,对认证咨询内容进行脱敏得到脱敏咨询内容,将脱敏咨询内容输入部署的认证咨询决策模型进行推理得到实时咨询结果,删除明文的认证咨询内容;服务器实时记录咨询日志,将咨询日志加密为咨询密文日志并进行存储,计算咨询密文日志的第二日志指纹上传区块链,获取并存储区块链反馈的第二存证证书;服务器通过会话密钥将实时咨询结果以及第二存证证书加密为咨询反馈加密包反馈给企业客户端,基于咨询日志对认证咨询决策模型进行迭代优化,并动态更新动态决策知识图谱;即通过构建动态决策知识图谱并训练认证咨询决策模型,对脱敏后的认证咨询内容进行智能分析,生成包括合规建议报告以及认证执行路径图的实时咨询结果,显著提升了认证咨询的准确性与时效性;同时利用会话密钥加密传输关键数据、区块链存证鉴权密文日志的第一日志指纹和咨询密文日志的第二日志指纹,结合服务器即时删除明文的认证咨询内容,既保障了敏感数据的安全性,又构建了不可篡改的全流程溯源链条;而认证咨询决策模型的自动化处理与持续迭代优化,大幅降低人工依赖与服务延迟,从根本上提高了系统的运行效率和经济性,且通过内容脱敏、AI处理、明文删除、数据加密等手段解决了人工交互信任问题,最终极大的提升了认证咨询的准确性、时效性、安全性、溯源性以及经济性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120821800B_ABST
    Figure CN120821800B_ABST
Patent Text Reader

Abstract

The application provides a kind of authentication consultation method and system based on blockchain in the cross technical field of artificial intelligence and authentication consultation management, method includes: step S1, obtain a large number of historical authentication consultation data and historical authentication standard file, build consultation dataset, dynamic decision knowledge graph;Step S2, create an authentication consultation decision model that calls dynamic decision knowledge graph for authentication consultation service, train and deploy authentication consultation decision model through consultation dataset;Step S3, client and server are authenticated and negotiate session key;Step S4, authentication consultation content is encrypted into consultation ciphertext through session key and generates authentication consultation request and sends to server;Step S5, the authentication consultation content carried in authentication consultation request is input into authentication consultation decision model by server, and consultation result is obtained.The application has the advantages that: the accuracy, timeliness, security, traceability and economy of authentication consultation are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of interdisciplinary technology of artificial intelligence and certification consulting management, and in particular to a blockchain-based certification consulting method and system. Background Technology

[0002] Certification consulting refers to the systematic technical guidance and services provided to help companies (organizations) meet the requirements of specific certification standards and technical specifications. Its core objective is to assist companies in establishing, implementing, maintaining, and continuously improving their management systems to ensure compliance. Typical services include:

[0003] 1. Standard Interpretation: In-depth analysis of certification standards, transforming them into easily understandable guidelines for internal staff, clearly defining the specific requirements of the standards. 2. System Establishment Guidance: Assisting companies in reviewing existing management processes, identifying gaps with target certification standards, and customizing a management system framework (including policies, objectives, organizational structure, and responsibility planning) based on the company's actual situation. 3. Document Preparation: Guiding companies in preparing system documents that meet standard requirements and possess operability and effectiveness, such as quality manuals, procedure documents, and work instructions. 4. System Operation and Improvement Coaching: Providing continuous support during system operation, assisting in resolving operational issues, and guiding the identification of system deficiencies through internal audits and management reviews to promote continuous improvement. 5. Certification Preparation Assistance: Through simulated certification audit processes, helping companies familiarize themselves with audit requirements, identify and rectify problems in advance, increasing the probability of passing certification audits and boosting confidence in handling them.

[0004] However, current mainstream authentication and consultation systems, especially web-based portals or online customer service systems, rely heavily on human interaction, which results in the following inherent technical shortcomings:

[0005] 1. Insufficient decision support: The passive question-and-answer model, which relies on static knowledge bases and human experience, lacks an active analysis and decision-making mechanism based on the latest data, resulting in reduced accuracy and timeliness of certification decisions.

[0006] 2. Trust issues arising from human interaction: Human interaction presents significant trust barriers when sensitive information is involved. Companies are prone to concealing key details (such as actual difficulties and technical bottlenecks), which ultimately leads to suggested solutions deviating from actual needs and decision-making biases.

[0007] 3. High data security risks and difficulties in tracing: Sensitive information (such as corporate qualifications and internal data) is often transmitted through insecure channels such as email and online forms, facing high risks of cyberattacks (such as phishing and data breaches); at the same time, dynamic interactive data generated during the consultation process (such as communication records, informal plans, and temporary decision-making basis) is mostly stored temporarily, making it difficult to form an immutable and reliable record chain. When service disputes occur (such as losses caused by misjudgment of standards), companies lack legally valid and auditable electronic evidence to support the tracing of responsibility.

[0008] 4. Low efficiency and high service costs: Manually answering repetitive questions consumes a lot of human resources, which drives up service costs; moreover, the process is difficult to automate, and when the demand for certification consultation surges (such as during policy adjustment periods or standard update waves), it is easy to cause service backlog and delays, which cannot meet the requirements of lean service management.

[0009] In summary, existing certification and consulting systems have significant shortcomings in terms of accuracy, timeliness, data security, process traceability, and service economy. Therefore, how to provide a blockchain-based certification and consulting method and system to improve the accuracy, timeliness, security, traceability, and economy of certification and consulting services has become an urgent technical problem to be solved. Summary of the Invention

[0010] The technical problem to be solved by this invention is to provide a blockchain-based authentication consultation method and system, which improves the accuracy, timeliness, security, traceability and economy of authentication consultation.

[0011] In a first aspect, the present invention provides a blockchain-based authentication and consultation method, comprising the following steps:

[0012] Step S10: The server obtains a large amount of historical certification consultation data and historical certification standard files, preprocesses each of the historical certification consultation data and historical certification standard files, annotates each of the preprocessed historical certification consultation data and constructs a consultation dataset, and constructs a dynamic decision knowledge graph based on each of the preprocessed historical certification standard files.

[0013] Step S20: The server creates an authentication consultation decision model that calls the dynamic decision knowledge graph to provide authentication consultation services, sets the loss function of the authentication consultation decision model, trains the authentication consultation decision model using the consultation dataset and the loss function, and deploys the trained authentication consultation decision model.

[0014] Step S30: The enterprise client and the server perform two-way authentication and negotiate a session key. The server records the authentication log, encrypts the authentication log into an authentication ciphertext log and stores it, calculates the first log fingerprint of the authentication ciphertext log and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain for subsequent authentication and traceability.

[0015] Step S40: The enterprise client obtains the input authentication consultation content, encrypts the authentication consultation content into consultation ciphertext using the session key, obtains the current timestamp T1 as the request time, generates an authentication consultation request based on the consultation ciphertext and the request time, and sends the authentication consultation request to the server.

[0016] Step S50: The server verifies and parses the received authentication consultation request to obtain authentication consultation content, desensitizes the authentication consultation content to obtain desensitized consultation content, inputs the desensitized consultation content into the deployed authentication consultation decision model for reasoning, and obtains real-time consultation results including compliance suggestion reports and authentication execution path diagrams, and deletes the plaintext authentication consultation content.

[0017] Step S60: The server records consultation logs in real time, encrypts the consultation logs into ciphertext logs and stores them, calculates the second log fingerprint of the ciphertext logs and uploads it to the blockchain, obtains and stores the second evidence certificate fed back by the blockchain, and uses it for subsequent consultation tracing.

[0018] Step S70: The server uses the session key to encrypt the real-time consultation result and the second evidence certificate into a consultation feedback encrypted package, and sends the consultation feedback encrypted package to the enterprise client in real time.

[0019] Step S80: The server iteratively optimizes the deployed authentication consultation decision model based on the consultation logs and dynamically updates the dynamic decision knowledge graph.

[0020] Secondly, the present invention provides a blockchain-based authentication and consultation system, comprising the following modules:

[0021] The initialization module is used to obtain a large amount of historical certification consultation data and historical certification standard files from the server, preprocess the historical certification consultation data and historical certification standard files, annotate the preprocessed historical certification consultation data to construct a consultation dataset, and construct a dynamic decision knowledge graph based on the preprocessed historical certification standard files.

[0022] The certification consultation decision model training module is used by the server to create a certification consultation decision model that calls the dynamic decision knowledge graph to provide certification consultation services, set the loss function of the certification consultation decision model, train the certification consultation decision model through the consultation dataset and the loss function, and deploy the trained certification consultation decision model.

[0023] The two-way authentication module is used for enterprise clients and servers to perform two-way authentication and negotiate session keys. The server records authentication logs, encrypts the authentication logs into authentication ciphertext logs and stores them, calculates the first log fingerprint of the authentication ciphertext logs and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain, and uses it for subsequent authentication and traceability.

[0024] The authentication consultation request sending module is used by the enterprise client to obtain the input authentication consultation content, encrypt the authentication consultation content into consultation ciphertext using the session key, obtain the current timestamp T1 as the request time, generate an authentication consultation request based on the consultation ciphertext and the request time, and send the authentication consultation request to the server.

[0025] The real-time consultation result generation module is used by the server to verify and parse the received certification consultation request to obtain certification consultation content, de-identify the certification consultation content to obtain de-identified consultation content, input the de-identified consultation content into the deployed certification consultation decision model for reasoning, obtain real-time consultation results including compliance suggestion reports and certification execution path diagrams, and delete the plaintext certification consultation content.

[0026] The consultation log management module is used to record consultation logs in real time on the server, encrypt the consultation logs into ciphertext logs and store them, calculate the second log fingerprint of the ciphertext logs and upload it to the blockchain, obtain and store the second evidence certificate fed back by the blockchain for subsequent consultation tracing.

[0027] The result feedback module is used by the server to encrypt the real-time consultation result and the second evidence certificate into a consultation feedback encrypted package using the session key, and then feed the consultation feedback encrypted package back to the enterprise client in real time.

[0028] The iterative optimization module is used by the server to iteratively optimize the deployed authentication consultation decision model based on the consultation logs and dynamically update the dynamic decision knowledge graph.

[0029] The advantages of this invention are:

[0030] 1. Obtain a large amount of historical authentication consultation data and historical authentication standard documents from the server. Preprocess the historical authentication consultation data and historical authentication standard documents, and then annotate the preprocessed historical authentication consultation data to construct a consultation dataset. Based on the preprocessed historical authentication standard documents, construct a dynamic decision knowledge graph. Next, create an authentication consultation decision model that calls the dynamic decision knowledge graph to provide authentication consultation services, set the loss function of the authentication consultation decision model, and train and deploy the authentication consultation decision model using the consultation dataset and the loss function. The enterprise client and the server perform two-way authentication and negotiate session keys. The server records authentication logs and transmits the authentication... Logs are encrypted into authentication ciphertext logs and stored. The first log fingerprint of the authentication ciphertext log is calculated and uploaded to the blockchain. The first evidence certificate fed back from the blockchain is obtained and stored. The enterprise client encrypts the authentication consultation content into consultation ciphertext using the session key, obtains the current timestamp T1 as the request time, and generates an authentication consultation request based on the consultation ciphertext and the request time, sending it to the server. The server verifies and parses the authentication consultation request to obtain the authentication consultation content, de-identifies the authentication consultation content to obtain de-identified consultation content, inputs the de-identified consultation content into the deployed authentication consultation decision model for reasoning to obtain the real-time consultation result, and deletes the plaintext authentication consultation content. The server records consultation logs in real time. The system encrypts consultation logs into encrypted consultation logs and stores them. A second log fingerprint of the encrypted consultation logs is calculated and uploaded to the blockchain. A second evidence certificate is obtained and stored based on the blockchain feedback. The server uses a session key to encrypt the real-time consultation results and the second evidence certificate into an encrypted consultation feedback package and sends it back to the enterprise client. Based on the consultation logs, the certification consultation decision-making model is iteratively optimized, and the dynamic decision knowledge graph is dynamically updated. In other words, by constructing a dynamic decision knowledge graph and training the certification consultation decision-making model, the system intelligently analyzes the anonymized certification consultation content, generating real-time consultation results including compliance recommendation reports and certification execution path diagrams. This significantly improves the accuracy and timeliness of certification consultations. Simultaneously, by using session keys to encrypt the transmission of key data, the first log fingerprint of the blockchain-stored authentication and authorization ciphertext log, and the second log fingerprint of the consultation ciphertext log, combined with the server's immediate deletion of plaintext authentication and consultation content, the security of sensitive data is ensured, and an immutable end-to-end traceability chain is constructed. Furthermore, the automated processing and continuous iterative optimization of the authentication and consultation decision-making model significantly reduce reliance on manual labor and service delays, fundamentally improving the system's operational efficiency and economy. Moreover, by using methods such as content desensitization, AI processing, plaintext deletion, and data encryption, the trust issues of human interaction are resolved, ultimately greatly improving the accuracy, timeliness, security, traceability, and economy of authentication and consultation.

[0031] 2. By employing two-way authentication, session key negotiation, and encryption of authentication consultation content, the confidentiality of data during transmission and storage is ensured, reducing the risk of man-in-the-middle attacks and data leakage. By introducing data anonymization processing (anonymizing authentication consultation content) and deleting plaintext content (authentication consultation content), the exposure of sensitive information (such as corporate secrets) is avoided, enhancing privacy protection capabilities. Compared with conventional consultation methods, the multi-layer encryption (session key, encrypted log) of this invention reduces security vulnerabilities and makes the system more robust.

[0032] 3. By uploading log fingerprints (such as the first log fingerprint of the authentication encrypted log and the second log fingerprint of the consultation encrypted log) to the blockchain and obtaining a certificate of evidence, the distributed ledger characteristics of the blockchain are used to ensure the authenticity and immutability of the log records. Any subsequent tampering will be detected on the blockchain, which provides reliable evidence for auditing and dispute resolution. This innovation combines the anti-counterfeiting advantages of the blockchain (such as transparency and traceability) and enhances the credibility of the entire consultation service.

[0033] 4. Based on historical data, a dynamic decision-making knowledge graph and AI model (certification consultation decision model) are constructed. Through automated reasoning, compliance suggestions and certification execution path diagrams are generated, which significantly reduces the time for manual consultation (real-time response) and improves the accuracy and consistency of decision-making. Compared with traditional manual interaction, the data-driven model can handle complex standards and avoid subjective judgment errors, thereby improving the user experience and satisfaction of enterprises.

[0034] 5. The certification consulting decision-making model is iteratively optimized based on consulting logs and the dynamic decision knowledge graph is updated. This allows for learning new data from actual consulting, adapting to constantly changing certification standards (such as policy updates), and avoiding model obsolescence or error accumulation. This dynamic feature (combined with knowledge graph updates) enhances the system's intelligence and long-term effectiveness, which is superior to static models in terms of innovation. It reflects the evolvability and stability of the technical solution, and the optimization process reduces maintenance costs. Enterprises can obtain more accurate and up-to-date advice, thus improving service quality.

[0035] 6. By combining the immutability of blockchain, the intelligent reasoning of dynamic decision knowledge graphs, multi-layered data encryption and de-identification mechanisms, and continuous model optimization capabilities, a highly efficient, secure, and traceable authentication and consulting system has been constructed. This system achieves end-to-end privacy protection for enterprise consulting data (such as two-way authentication, session key encryption, and content de-identification), automation and precision in the decision-making process (generating real-time consulting results based on trained models), and utilizes blockchain notarization to ensure the authenticity and auditability of authentication and consulting logs (such as logging fingerprints on the blockchain). This significantly improves the response efficiency and accuracy of authentication and consulting, and allows for dynamic iteration of the knowledge base (dynamic decision knowledge graph) to adapt to policy changes. Ultimately, while ensuring data compliance, it provides enterprises with reliable, low-risk, and sustainably optimized authentication and consulting services.

[0036] 7. By simultaneously integrating historical certification consultation data (including certification consultation content, compliance advice reports, and certification execution roadmaps) and historical certification standard documents (including core standard documents, supporting documents, certification process documents, certification body documents, and certification standard interpretation documents), this systematic integration of "user practice data" and "official standard data" into a single processing flow avoids data silos and lays a solid foundation for building a more comprehensive and accurate decision-making model.

[0037] 8. By performing extremely detailed and targeted preprocessing on two types of data (historical certification consultation data and historical certification standard documents), namely, data cleaning, data formatting, data classification and tagging for historical certification consultation data, and document organization and classification, text content extraction and cleaning, key information annotation and association for historical certification standard documents, the efficiency and accuracy of subsequent processing have been significantly improved. Unified and clean input data is a key prerequisite for ensuring the effectiveness of the certification consultation decision model and dynamic decision knowledge graph construction. In particular, the key information annotation and association of unstructured standard documents is the core step in transforming complex rules into a machine-understandable form.

[0038] 9. By linking certification consultation content, compliance recommendation reports, and certification execution path diagrams in the preprocessed historical certification consultation data and labeling consultation results, a complete and causally related consultation case knowledge base is constructed: "demand / current situation -> recommendation -> execution path -> final result" forms a closed loop. Consultation result labels (success / failure / uncertified) provide direct feedback for verifying and optimizing recommendations and paths, greatly enhancing the traceability of data and the ability to analyze decision results, making subsequent intelligent decisions based on this more evidence-based and interpretable.

[0039] 10. By efficiently integrating historical certification consultation data and historical certification standard documents, and through systematic preprocessing, deep data association, and strict de-identification, a high-quality consultation dataset is constructed. Furthermore, by innovatively combining BiLSTM-CRF entity extraction and TransE relational reasoning technologies, complex certification rules are transformed into dynamic decision knowledge graphs, significantly improving the intelligence level of certification consultation. This not only ensures data compliance but also provides accurate knowledge support for the automated generation of compliance recommendation reports, certification execution path diagrams, and improved certification success rates, greatly reducing manual processing costs and enhancing decision reliability.

[0040] 11. By designing a clear and complete five-layer structure for the certification consulting decision-making model (input parsing, knowledge graph retrieval, feature fusion, decision generation, and output transformation), the model covers the entire process from raw input (text + numerical values) to final decision output (text report + visual path diagram). This end-to-end design avoids the fragmentation of multiple independent systems or manual steps in traditional consulting, and significantly improves the overall automation level and efficiency of certification consulting decision-making.

[0041] 12. By innovatively combining bidirectional LSTM (which excels at processing sequential text) and fully connected layers (which excel at processing structured numerical data) in the input parsing layer, the features of consultation requests and current enterprise data are effectively extracted. Initial fusion is achieved through vector concatenation. This design can fully understand complex and unstructured user requests while taking into account the specific quantitative situation of the enterprise, providing a more comprehensive and accurate information foundation for subsequent decision-making.

[0042] 13. By setting up a knowledge graph retrieval layer and using graph convolutional networks to encode the dynamic decision-making knowledge graph, the model can learn and utilize the dynamic relationships and semantic information of entities (such as regulations, standards, cases, and process nodes) in the dynamic decision-making knowledge graph, which is superior to static knowledge bases. By adopting a multi-head attention mechanism for retrieval, the model can actively and accurately focus on the most relevant parts (node ​​embeddings) of the dynamic decision-making knowledge graph based on the initial feature vector (representing the current consultation question and enterprise status), generating enhanced feature vectors, which greatly improves the professionalism and relevance of decision-making suggestions. In other words, the combination of "dynamic decision-making knowledge graph + GCN encoding + multi-head attention retrieval" is used for knowledge enhancement in consultation decisions, effectively improving the accuracy of certification consultation.

[0043] 14. By setting up a feature fusion layer, not only is simple feature concatenation (unifying the feature vector) performed, but a Transformer-based self-attention mechanism is further introduced. This mechanism can automatically learn the importance weights of different features in the unified feature vector and perform weighted fusion of key information, enabling the model to focus more on the most core elements of the current decision, suppress noise or irrelevant information, and generate better fused features. That is, applying the self-attention mechanism for feature fusion and key information filtering in the certification consultation decision model improves the model's reasoning ability and decision quality.

[0044] 15. The decision generation layer uses a seq2seq model in parallel to generate a detailed compliance recommendation report and a first-graph neural network to generate an authentication execution path diagram. This dual-channel output meets the user's dual needs for detailed textual explanations and clear process guidance, and the output results are more intuitive and practical.

[0045] 16. The output transformation layer uses a softmax+template engine to format the compliance recommendation report into a formal report, ensuring professionalism and standardization; it uses a tree decoder to convert the certification execution path diagram into a visual representation, improving the readability and usability of the results, and greatly enhancing the user experience and direct usability of the model output results.

[0046] 17. By setting a loss function that integrates sequence loss, graph structure loss, and regularization term, the sequence loss ensures the accuracy of the generated text report content (cross-entropy), the graph structure loss ensures the reasonable structure of the generated path graph (graph edit distance), and the regularization term prevents overfitting and improves generalization ability (L2+dropout). The optimization direction is flexibly adjusted through weight coefficients α, β, and γ. This joint optimization mechanism can simultaneously improve the quality of the text report and the accuracy of the path graph structure, and synergistically optimize the overall decision-making effect.

[0047] 18. Through an end-to-end five-layer architecture (input parsing, knowledge graph retrieval, feature fusion, decision generation, and output transformation), it innovatively integrates bidirectional LSTM text parsing, graph convolutional network dynamic knowledge encoding, multi-head attention precise retrieval, and Transformer self-attention feature weighting to achieve deep understanding and knowledge enhancement of heterogeneous data (consulting text + enterprise numerical data). Based on multi-task joint optimization of the loss function, it simultaneously generates formatted compliance recommendation reports (Seq2Seq + template engine) and visualized certification path diagrams (graph neural network + tree decoder). Finally, through rigorous dynamic hyperparameter optimization and a multi-dimensional evaluation process (covering indicators such as accuracy, efficiency, and robustness), it significantly improves the automation and intelligence level of enterprise certification consulting decisions and the practicality and professionalism of the output results.

[0048] 19. By using a two-tier CA root certificate to ensure the reliability of two-way identity authentication, combining the ECDHE algorithm to achieve forward confidentiality of key exchange, using national cryptographic algorithms (SM3 / SM9 / ChaCha20) to encrypt logs and dynamically generating temporary keys with quantum resistance, and further using blockchain to solidify the immutability of authentication logs, the system systematically solves the security risks of identity forgery, man-in-the-middle attacks, historical data leakage, and difficulty in log traceability in communication, and builds an end-to-end authentication and data protection system that takes into account high security, compliance, and auditability.

[0049] 20. A highly efficient and reliable secure transmission system is constructed by integrating multi-layered encryption mechanisms, hash calculations, and timestamp verification: The authentication consultation content is encrypted locally using the AES core to ensure confidentiality. The SM3 algorithm is used to generate an anti-tampering hash value H3 for the consultation ciphertext and request time. Then, all content is integrated through RC6 encryption to form an encrypted string. The introduction of request time effectively defends against replay attacks, while the entire process uses SSL protocol to achieve end-to-end channel encryption. This design simultaneously takes into account high-strength data protection (double encryption + integrity verification), timeliness control, and execution efficiency. At the same time, based on standardized algorithms (AES / RC6) and the national cryptographic standard SM3, the system compatibility and auditability are ensured, which significantly improves the security of sensitive enterprise information in authentication interactions and greatly reduces the risk of theft, tampering, or malicious replay.

[0050] 21. By receiving authentication consultation requests in real time and decrypting encrypted strings using the RC6 algorithm, the system prevents the plaintext theft of consultation ciphertext, request time, and hash value H3. Timeliness control is achieved through request time, and integrity verification is performed through hash value H3, effectively preventing data tampering and replay attacks. Furthermore, AES algorithm decryption and a streaming engine are used to anonymize and desensitize current enterprise data, strengthening privacy protection compliance. Subsequently, the system automatically generates compliance recommendation reports and authentication execution path diagrams from the authentication consultation decision model, providing efficient intelligent decision support. Finally, plaintext authentication consultation content is synchronously deleted, significantly reducing the risk of data leakage. The entire process integrates multiple security mechanisms, real-time processing, and automated reasoning, greatly improving data security, processing efficiency, business usability, and cost-effectiveness.

[0051] 22. By using dynamic key K3 / K4 derivation (based on real-time data hash value and segmented generation), block-based differential encryption (AES algorithm), and multiple encryption structures (session key + SSL), combined with timestamp anti-replay and SM3 hash integrity verification, a high-strength data security transmission and evidence storage system has been constructed. This system not only effectively protects the confidentiality, integrity, and tamper resistance of real-time consultation results and second evidence storage certificates, but also strengthens the effectiveness of evidence storage through enterprise client verification storage mechanisms.

[0052] 23. Through an intelligent incremental training mechanism and automated standard monitoring process, the dynamic collaborative optimization of the certification decision model and the dynamic decision knowledge graph is efficiently achieved: When the consultation logs accumulate to a preset threshold, iterative training is performed using incremental datasets during the model's idle period, significantly reducing computational resource consumption and improving decision accuracy; at the same time, the latest certification standard documents are captured in real time through parameterized monitoring agents, and the dynamic decision knowledge graph is automatically fused and updated with the help of graph neural networks, which not only ensures the timeliness and compliance of the decision basis, but also greatly reduces manual maintenance costs, ultimately forming a closed-loop optimization system with high response speed, strong adaptability, and low operating expenses.

[0053] 24. By innovatively integrating a dynamic decision-making knowledge graph with a multi-level AI decision-making architecture (certification consultation decision model), and utilizing BiLSTM-CRF entity extraction, graph attention mechanism, and Transformer feature fusion technology, it achieves high-precision analysis of enterprise certification consultation requests and dual-path decision output (compliance recommendation report + certification execution path diagram), significantly improving the accuracy and executability of certification consultation. At the security level, it constructs a full-process protection system: employing ECDHE dynamic key negotiation and layered encryption mechanisms (AES / national cryptographic SM combination) to ensure data transmission security; and achieving full traceability of operations through real-time enterprise data desensitization, instant plaintext destruction, and blockchain fingerprint evidence storage (SM3 hash + timestamp binding), effectively solving privacy leakage and auditing challenges. Furthermore, it possesses continuous evolution capabilities—utilizing incremental datasets to iteratively optimize the certification consultation decision model during idle periods, and automatically capturing the latest certification standard documents through a monitoring agent, dynamically updating the dynamic decision-making knowledge graph via a graph neural network, completely breaking through the knowledge lag bottleneck of traditional consultation systems. It forms a technological closed loop in three dimensions: decision intelligence, security reliability, and knowledge freshness, providing a new generation solution with industrial-grade robustness for the certification consultation field. Attached Figure Description

[0054] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0055] Figure 1 This is a flowchart of a blockchain-based authentication and consultation method according to the present invention.

[0056] Figure 2 This is a schematic diagram of the structure of a blockchain-based authentication and consultation system according to the present invention. Detailed Implementation

[0057] The overall approach of the technical solution in this application is as follows: By constructing a dynamic decision-making knowledge graph and training an authentication consultation decision-making model, intelligent analysis is performed on the de-identified authentication consultation content to generate real-time consultation results, including compliance suggestion reports and authentication execution path diagrams, significantly improving the accuracy and timeliness of authentication consultation. Simultaneously, key data is encrypted using session keys, and the first log fingerprint of the blockchain-stored authentication ciphertext log and the second log fingerprint of the consultation ciphertext log are used. Combined with the server's immediate deletion of plaintext authentication consultation content, the security of sensitive data is ensured, and an immutable end-to-end traceability chain is constructed. Furthermore, the automated processing and continuous iterative optimization of the authentication consultation decision-making model significantly reduce reliance on manual intervention and service delays, fundamentally improving the system's operational efficiency and economy. Moreover, by employing content de-identification, AI processing, plaintext deletion, and data encryption, the trust issue in human interaction is resolved, thereby enhancing the accuracy, timeliness, security, traceability, and economy of authentication consultation.

[0058] Please refer to Figures 1 to 2 As shown, a preferred embodiment of a blockchain-based authentication and consultation method of the present invention includes the following steps:

[0059] Step S10: The server obtains a large amount of historical certification consultation data and historical certification standard files, preprocesses each of the historical certification consultation data and historical certification standard files, annotates each of the preprocessed historical certification consultation data and constructs a consultation dataset, and constructs a dynamic decision knowledge graph based on each of the preprocessed historical certification standard files.

[0060] Step S20: The server creates an authentication consultation decision model that calls the dynamic decision knowledge graph to provide authentication consultation services, sets the loss function of the authentication consultation decision model, trains the authentication consultation decision model using the consultation dataset and the loss function, and deploys the trained authentication consultation decision model.

[0061] Step S30: The enterprise client and the server perform two-way authentication and negotiate a session key. The server records the authentication log, encrypts the authentication log into an authentication ciphertext log and stores it, calculates the first log fingerprint of the authentication ciphertext log and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain for subsequent authentication and traceability.

[0062] Step S40: The enterprise client obtains the input authentication consultation content, encrypts the authentication consultation content into consultation ciphertext using the session key, obtains the current timestamp T1 as the request time, generates an authentication consultation request based on the consultation ciphertext and the request time, and sends the authentication consultation request to the server.

[0063] Step S50: The server verifies and parses the received authentication consultation request to obtain authentication consultation content, desensitizes the authentication consultation content to obtain desensitized consultation content, inputs the desensitized consultation content into the deployed authentication consultation decision model for reasoning, and obtains real-time consultation results including compliance suggestion reports and authentication execution path diagrams, and deletes the plaintext authentication consultation content.

[0064] Step S60: The server records consultation logs in real time, encrypts the consultation logs into ciphertext logs and stores them, calculates the second log fingerprint of the ciphertext logs and uploads it to the blockchain, obtains and stores the second evidence certificate fed back by the blockchain, and uses it for subsequent consultation tracing.

[0065] Step S70: The server uses the session key to encrypt the real-time consultation result and the second evidence certificate into a consultation feedback encrypted package, and sends the consultation feedback encrypted package to the enterprise client in real time.

[0066] Step S80: The server iteratively optimizes the deployed authentication consultation decision model based on the consultation logs and dynamically updates the dynamic decision knowledge graph.

[0067] Step S10 specifically involves:

[0068] The server acquires a large amount of historical certification consultation data and historical certification standard documents; the historical certification consultation data includes at least certification consultation content, compliance recommendation reports, and certification execution path diagrams; the certification consultation content includes at least consultation requests and current enterprise data; the historical certification standard documents include at least core standard documents, supporting documents, certification process documents, certification body documents, and certification standard interpretation documents.

[0069] The enterprise's current status data should include at least the following: a) Basic enterprise information: the enterprise's size, industry sector, business scope, organizational structure, etc. This information helps to understand the overall situation of the enterprise and tailor a management system accordingly. b) Existing management system documents: the enterprise's existing management systems, process documents, operating procedures, etc., used to identify gaps with the target certification standards and provide a basis for system establishment and improvement. c) Current status of management processes: the enterprise's actual management processes, including business connections, information transmission, and decision-making mechanisms between departments, used to identify problems and weaknesses in the processes, and to propose optimization suggestions to make the management system smoother and more efficient. d) Personnel capabilities and responsibilities: the professional skills, work experience, and level of understanding and knowledge of the management system among the enterprise's internal personnel, while clearly defining the allocation of responsibilities for each department and position, so as to reasonably arrange personnel and ensure that all responsibilities are effectively implemented when establishing and operating the management system.

[0070] The core standard document includes at least the standard text and interpretations of the standard clauses. The standard text is the core part of the certification standard, which specifies in detail the specific requirements that enterprises or organizations need to meet, such as ISO 9001 quality management system standard, ISO 14001 environmental management system standard, and ISO 45001 occupational health and safety management system standard. The interpretations of the standard clauses are to help enterprises better understand and apply the standard clauses, and usually include the background, purpose, detailed explanation of the specific requirements, and how to implement these requirements in practice.

[0071] The supporting documents include at least application guidelines, industry-specific requirements, and technical specifications. The application guidelines provide guidance for the specific application of the standard, helping companies better implement the standard in different industries or specific situations. For example, the application guidelines for ISO 9001 may provide specific implementation suggestions for different industries such as manufacturing and services. The industry-specific requirements supplement or refine general standards for specific industries. For example, the automotive industry has the IATF 16949 standard, which is a more detailed quality management system standard for the automotive industry based on ISO 9001. The technical specifications provide technical details and specifications related to the standard, ensuring that companies can meet the technical requirements during implementation. For example, environmental management system standards may involve emission standards for specific pollutants, environmental monitoring technical specifications, etc.

[0072] The certification process documents include at least a certification application guide, audit process documents, and a certification certificate sample. The certification application guide details how companies can apply for certification, including application requirements, required documents and materials, and the application process, helping companies understand the entry requirements and initial steps. The audit process documents include an audit plan, audit checklist, and audit report template. These documents standardize the certification audit process, ensuring the fairness, objectivity, and consistency of the audit. The audit plan clarifies the audit timeline, scope, and focus. The audit checklist lists the specific clauses and contents to be checked during the audit. The audit report template specifies the format and content requirements for the audit report. The certification certificate sample demonstrates the style and content of the certification certificate, including the company name, certification scope, certificate number, issuing authority, and validity period, helping companies correctly use and display the certification certificate after obtaining it.

[0073] The certification body documents include at least the certification body rules and procedures, and certification body qualification certificates. The certification body rules and procedures are the certification body's own operating rules and procedures, including the certification body's qualification requirements, certification process, auditor qualification management, certification decision-making procedures, appeal and complaint handling mechanisms, etc., to ensure that the certification body's operation complies with regulations. The certification body qualification certificates are the certification body's qualification certificates, accreditation certificates, and other documents, proving that it has the legal qualifications and capabilities to carry out specific certification business.

[0074] The certification standard interpretation documents include at least a standard clarification document and a frequently asked questions (FAQs). The standard clarification document is used to further explain and clarify controversial or easily misunderstood clauses to ensure the correct understanding and application of the standard. The frequently asked questions are answers to questions that enterprises often encounter during the implementation of certification standards, providing a way to quickly resolve problems and improve the efficiency and accuracy of certification implementation.

[0075] The historical certified consultation data shall undergo preprocessing including at least data cleaning, data formatting, data classification, and tagging; the data cleaning shall at least include removing duplicate data, handling missing values, and correcting erroneous data; the data formatting shall at least include unifying text format and standardizing data structure; the data classification and tagging shall at least include consultation type classification and adding tags.

[0076] The process of removing duplicate data involves checking for duplicate records in certification consultation content, compliance recommendation reports, and certification execution path diagrams. For example, the same consultation case might be recorded repeatedly due to data entry errors or multiple backups. Duplicates can be identified and deleted by comparing key data fields. Handling missing values ​​involves taking corresponding measures when certain key information in the consultation request (such as the specific type of consultation issue) or enterprise status data (such as some financial indicators) is missing. If the missing data significantly impacts the analysis and cannot be completed, the data entry can be deleted. If the missing information is minor, interpolation or filling with default values ​​can be used. Correcting erroneous data involves checking for errors in the data, such as incorrect consultation date formats or numerical errors in enterprise status data (such as incorrect sales unit). Standardizing text format involves standardizing the font, font size, and other formats for text data such as certification consultation content and compliance recommendation reports. Simultaneously, the text is segmented to ensure a clear structure. The standardized data structure standardizes the data structure of the certification execution path diagram. If the certification execution path diagram is stored in image form, it can be converted into a graphical data structure, such as nodes and edges. Each node represents a certification stage, and the edges represent the transformation relationship between stages. Corresponding attributes are added to each node and edge. The consultation type classification divides historical certification consultation data into different consultation categories based on the content of the consultation request. For example, it can be divided into quality management system certification consultation, environmental management system certification consultation, etc. Adding tags involves adding tags to the data, such as consultation result tags (certification successful, certification failed, not certified, etc.) and compliance recommendation severity tags (high risk, medium risk, low risk), etc.

[0077] The historical authentication standard documents are preprocessed in at least the following ways: document organization and classification, text content extraction and cleaning, and key information annotation and association. The document organization and classification includes at least physical organization and index creation. The text content extraction and cleaning includes at least text extraction and text format cleaning. The key information annotation and association includes at least annotation of key information and establishment of document associations.

[0078] The physical organization involves classifying and storing core standard documents, supporting documents, certification process documents, certification body documents, and certification standard interpretation documents separately. In practice, this can be done by file type (e.g., Word document, PDF document) or subject (e.g., quality certification, environmental certification). Indexing involves creating an index for each file, including file name, file type, file category, and file version, facilitating quick file retrieval and management. Text extraction involves using PDF parsing tools to extract text content from PDF files and directly reading text from Word documents. During extraction, the integrity of the text must be ensured to avoid garbled characters. Text formatting removal involves removing redundant formatting elements such as headers, footers, and page numbers. Tables in the text can be converted to structured data formats such as CSV files. Marking key information involves marking key clauses and keywords in core standard documents, certification standard interpretation documents, etc. For example, in quality management system certification standard documents, key concepts such as "quality policy" and "quality objectives" are marked. Establishing file associations involves analyzing the relationships between files, such as the reference relationship between core standard documents and supporting documents, and the matching relationship between certification process documents and certification body documents.

[0079] In the preprocessed historical certification consultation data, the certification consultation content, compliance suggestion report, and certification execution path diagram are associated and labeled with consultation result tags. A consultation dataset is constructed based on the labeled historical certification consultation data. The enterprise information carried by the enterprise status data in the consultation dataset is anonymized and desensitized. The consultation result tags are certification successful, certification failed, or not certified.

[0080] Entities are extracted from the pre-processed historical certification standard documents using a pre-trained BiLSTM-CRF model. Relationships between these entities are inferred using the TransE algorithm. A dynamic decision knowledge graph is then constructed based on these entities and their relationships. The entities include at least standard-related entities, supporting document entities, certification process document entities, certification body document entities, and enterprise-related entities. The relationships include at least standard-related relationships, supporting document relationships, certification process document relationships, certification body document relationships, enterprise-standard relationships, and internal enterprise relationships.

[0081] The LSTM (Long Short-Term Memory) network in the BiLSTM-CRF model is a special type of recurrent neural network (RNN). By introducing input gates, forget gates, and output gates, it solves the gradient vanishing or exploding problems that traditional RNNs often encounter when processing long sequences of data, and can better capture long-term dependencies in the sequence. BILSTM (Bidirectional Long Short-Term Memory) is an improvement on LSTM, containing two LSTM layers: a forward LSTM layer that processes data sequentially from the beginning to the end of the sequence, and a backward LSTM layer that processes data sequentially from the end to the beginning of the sequence. This allows for the simultaneous acquisition of information from both directions in the sequence. This bidirectional information is crucial for many natural language processing tasks, such as named entity recognition. In sequence labeling tasks, whether a word is part of an entity depends not only on the words preceding it but also on the words following it. CRF (Conditional Random Field) is a discriminative model used to model a given observation sequence labeled with another entity. In sequence labeling tasks, there are often certain relationships between the labels of a labeled sequence. For example, in named entity recognition tasks, the start label of an entity (such as "B-PER" indicating the beginning of a person's name) is usually followed by an intermediate label (such as "I-PER") or an end label (such as "E-PER"), and it will not jump directly to other types of labels. CRF can model this transition relationship between labels very well. It calculates the probability of a certain labeled sequence under a given observation sequence by defining a conditional probability distribution, so as to maximize the probability that the labeled sequence conforms to the labeling rules.

[0082] TransE (Translating Embedding) is an algorithm for embedding knowledge graphs. The TransE algorithm maps entities and relations to a vector space, so that pairs of entities that satisfy the relations satisfy certain geometric relationships in the vector space. This allows the TransE algorithm to be used to predict missing triples in a knowledge graph, that is, to infer the relationships between entities.

[0083] Step S20 specifically involves:

[0084] The server creates an authentication consultation decision model based on an input parsing layer, a knowledge graph retrieval layer, a feature fusion layer, a decision generation layer, and an output transformation layer, and sets the loss function of the authentication consultation decision model.

[0085] The input parsing layer is constructed based on a bidirectional LSTM module, an enterprise status encoding module, and a vector concatenation module. The bidirectional LSTM module is used to extract text feature vectors from consultation requests; the enterprise status encoding module is used to extract numerical feature vectors from enterprise status data through a fully connected layer (with ReLU activation); and the vector concatenation module is used to concatenate the text feature vectors and numerical feature vectors into a preliminary feature vector.

[0086] The input parsing layer is used to parse and standardize the input authentication consultation content, encoding the consultation request into a text feature vector and the enterprise status data into a structured numerical feature vector for easier subsequent processing. In specific implementation, an adaptive length mechanism is adopted to handle variable-length consultation requests and missing enterprise data; dropout regularization is used to reduce the risk of overfitting and ensure robustness across various enterprise sizes.

[0087] The knowledge graph retrieval layer is constructed based on a graph embedding module and a graph attention retrieval module; the graph embedding module is used to encode the dynamic decision knowledge graph into node embeddings through a graph convolutional network (GCN); the graph attention retrieval module is used to retrieve enhanced feature vectors related to the initial feature vectors from each of the node embeddings through a multi-head attention mechanism;

[0088] The knowledge graph retrieval layer is used to dynamically access the dynamic decision-making knowledge graph, retrieve contextual features related to the input (preliminary feature vector), such as compliance standards and industry best practices, and output enhanced feature vectors (knowledge-driven features). These enhanced feature vectors include entity embeddings and relation weights. In practice, retrieval efficiency can be improved through a caching mechanism; and an error-tolerant module can be added to handle noisy or missing data in the dynamic decision-making knowledge graph, ensuring decision reliability.

[0089] The feature fusion layer is constructed based on a feature concatenation module and a self-attention fusion module. The feature concatenation module is used to concatenate the initial feature vector and the enhanced feature vector into a unified feature vector. The self-attention fusion module is used to perform weighted fusion of key features in the unified feature vector through a transformer-based self-attention mechanism to obtain fused features.

[0090] The feature fusion layer is used to unify features from different sources (preliminary feature vectors and enhanced feature vectors), capture the dependencies between features (such as the correlation between the current situation of the enterprise and the consulting needs), and output high-dimensional fused features to support subsequent decision-making. In specific implementation, a gating mechanism (such as GRU units) is introduced to prioritize the fusion of enhanced feature vectors from the dynamic decision knowledge graph to emphasize compliance knowledge; feature normalization is added to balance the scale differences between textual and numerical features and improve decision robustness.

[0091] The decision generation layer is constructed based on a suggestion generation module and a path graph generation module. The suggestion generation module is used to infer compliance suggestion reports by using a seq2seq model (encoder-decoder structure, mainly LSTM) to the fused features. The path graph generation module is used to decode the fused features by a first graph neural network (GNN) to obtain an authentication execution path graph.

[0092] The decision generation layer generates structured output based on fusion features; the suggestion generation module outputs a text sequence report (compliance suggestion report), and the path graph generation module outputs a directed graph (certification execution path graph). In specific implementation, the suggestion generation module integrates rule constraint decoding to ensure that the compliance suggestion report conforms to industry standards; the path graph generation module adds a dynamic path optimization sublayer (based on a reinforcement learning reward mechanism) to generate the shortest or lowest-risk execution path, adapting to the diversity of enterprises.

[0093] The output conversion layer is built upon a text formatting module and a graph rendering module; the text formatting module is used to convert compliance recommendation reports into formal report formats through a softmax layer and a template engine; the graph rendering module is used to convert the certification execution path graph into a visual graph representation through a tree decoder.

[0094] The output conversion layer is used for formatting compliance recommendation reports and certification execution path diagrams, generating the final consultation results.

[0095] The formula for the loss function is:

[0096] L total =α·L report +β·L path +γ·L reg ;

[0097] Among them, L total L represents the loss value of the loss function; report The sequence loss for compliance recommendation reports is represented by cross-entropy loss, which is suitable for text generation tasks; L path The graph structure loss representing the authentication execution path graph is represented by the graph edit distance loss, which measures the deviation between the generated path and the ideal path; L reg α represents the regularization term, including L2 regularization (weight decay) and dropout noise regularization; α, β, and γ all represent weight coefficients;

[0098] After performing sample augmentation on the consultation dataset based on the consultation category, the consultation dataset is divided into a training set, a validation set, and a test set in a ratio of 8:1:1. The certification consultation decision model is trained using the training set and a loss function. During the training process, the hyperparameters of the certification consultation decision model are continuously optimized, including at least the learning rate, learning warm-up rate, learning decay rate, random dropout rate, batch size, and number of hidden layers, until the loss value of the loss function is less than a preset loss threshold, or a preset early stopping condition is met (e.g., the training time or number of iterations reaches the upper limit, or the model parameters change too little).

[0099] The training set is used to calculate the accuracy of consultation results, inference latency, completeness of compliance recommendation report content, completeness of certification execution path rendering, and retrieval relevance of dynamic decision knowledge graph to validate the trained certification consultation decision model. If the validation fails, the training set is expanded and training continues; if the validation passes, then:

[0100] The test set is used to calculate task completion efficiency, actual path deviation rate, noise tolerance, resource consumption, and maximum processing request rate to test the verified certification consultation decision model. If the test fails, the training set is expanded and training continues; if the test passes, training ends and the certified consultation decision model that has passed the test is deployed.

[0101] Step S30 specifically includes:

[0102] Step S31: The enterprise client presets a certificate Cert_C carrying a long-term public key PublicKey_C, a long-term private key PrivateKey_C matching the long-term public key PublicKey_C, and a CA root certificate through the CA center.

[0103] The server pre-sets a certificate Cert_S carrying a long-term public key PublicKey_S, a long-term private key PrivateKey_S matching the long-term public key PublicKey_S, and a CA root certificate through the CA center.

[0104] The CA root certificate is used to verify the validity of certificates Cert_C and Cert_S;

[0105] Step S32: The enterprise client generates a random number Nonce_C, generates a first authentication request based on the list of cipher suites supported by the local machine and the random number Nonce_C, and sends it to the server;

[0106] Step S33: The server parses the received first authentication request to obtain a list of cipher suites and a random number Nonce_C. It selects a cipher suite from the list, generates a random number Nonce_S, and creates a pair of temporary public keys EphemeralPublicKey_S and temporary private keys EphemeralPrivateKey_S based on the ECDHE algorithm in the cipher suite. The server then signs the random number Nonce_C, the random number Nonce_S, and the temporary public key EphemeralPublicKey_S using the long-term private key PrivateKey_S to obtain the server signature Sig_S.

[0107] The server generates a second authentication request based on the cipher suite, the random number Nonce_S, the certificate Cert_S, the temporary public key EphemeralPublicKey_S, and the server signature Sig_S, and sends it to the enterprise client.

[0108] Step S34: The enterprise client parses the received second authentication request to obtain the cipher suite, random number Nonce_S, certificate Cert_S, temporary public key EphemeralPublicKey_S, and server signature Sig_S;

[0109] The enterprise client verifies the certificate Cert_S using the CA root certificate, and verifies the server signature Sig_S using the long-term public key PublicKey_S carried by the certificate Cert_S. Upon successful verification:

[0110] The enterprise client creates a pair of temporary public keys EphemeralPublicKey_C and temporary private keys EphemeralPrivateKey_C based on the ECDHE algorithm in the cryptographic suite. The client then uses the long-term private key PrivateKey_C to sign the random number Nonce_C, the random number Nonce_S, and the temporary public key EphemeralPublicKey_C to obtain the client signature Sig_C.

[0111] The enterprise client generates a third authentication request based on the certificate Cert_C, the temporary public key EphemeralPublicKey_C, and the client signature Sig_C, and sends it to the server.

[0112] Step S35: The server parses the received third authentication request to obtain the certificate Cert_C, the temporary public key EphemeralPublicKey_C, and the client signature Sig_C;

[0113] The server verifies the certificate Cert_C using the CA root certificate, verifies the client signature Sig_C using the public key PublicKey_C carried by the certificate Cert_C, and sends a verification result to the enterprise client indicating whether the verification was successful or failed.

[0114] Step S36: If the verification result is a verification failure, the process ends; if the verification result is a verification success, the enterprise client uses the ECDHE algorithm to call the temporary private key EphemeralPrivateKey_C and the temporary public key EphemeralPublicKey_S to calculate the shared key SharedSecret_C; the server uses the ECDHE algorithm to call the temporary private key EphemeralPrivateKey_S and the temporary public key EphemeralPublicKey_C to calculate the shared key SharedSecret_S, where the shared key SharedSecret_C and the shared key SharedSecret_S are the same key.

[0115] The ECDHE algorithm is a key negotiation algorithm based on elliptic curve cryptography. It allows two communicating parties to negotiate a shared key over an insecure channel without sharing any secret information beforehand. Its core idea is to leverage the one-way nature of dot product operations on elliptic curves, ensuring that even if an attacker intercepts the public keys of both parties, they cannot compute the shared key.

[0116] The enterprise client derives a session key using the shared key SharedSecret_C, random number Nonce_C, and random number Nonce_S via a KDF function; the server derives a session key using the shared key SharedSecret_S, random number Nonce_C, and random number Nonce_S via a KDF function; both the enterprise client and the server calculate and exchange the key fingerprint of the session key using the hash256 algorithm to verify the consistency of the session key.

[0117] Step S37: The server records the authentication log in real time. After authentication, it obtains the current timestamp T2, calculates the hash value H1 of the authentication log and timestamp T2 using the SM3 algorithm, calculates the hash value H2 of timestamp T2 using the SM3 algorithm, selects 8 bits starting from the 6th bit of the hash value H2 as the dynamic key K1, calls the dynamic key K1 using the ChaCha20 algorithm to encrypt the authentication log and hash value H1 into first-level encrypted data, encrypts the first-level encrypted data and timestamp T2 into authentication ciphertext log using the SM9 algorithm, stores the authentication ciphertext log in the specified path, calculates the first log fingerprint of the authentication ciphertext log using the hash256 algorithm and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain, which carries at least the evidence number, evidence time, evidence subject information, data information, blockchain information and signature information, for subsequent authentication and traceability.

[0118] Step S40 specifically involves:

[0119] The enterprise client obtains the input authentication consultation content, uses the AES algorithm to call the session key to encrypt the authentication consultation content into consultation ciphertext, obtains the current timestamp T1 as the request time, calculates the hash value H3 of the consultation ciphertext and the request time using the SM3 algorithm, and encrypts the consultation ciphertext, the request time, and the hash value H3 into an encrypted string using the RC6 algorithm. Based on the encrypted string, an authentication consultation request is generated and sent to the server via the SSL protocol.

[0120] Step S50 specifically involves:

[0121] The server receives the authentication consultation request in real time, parses the request to obtain an encrypted string, decrypts the encrypted string using the RC6 algorithm to obtain the consultation ciphertext, request time, and hash value H3, performs integrity verification on the consultation ciphertext and request time using the hash value H3, performs timeliness verification using the request time, and then uses the AES algorithm to call the session key to decrypt the consultation ciphertext to obtain the authentication consultation content. The server uses a streaming engine to perform anonymization and data desensitization on the enterprise information carried by the enterprise status data in the authentication consultation content to obtain desensitized consultation content. The desensitized consultation content is input into the deployed authentication consultation decision model for reasoning to obtain real-time consultation results including a compliance suggestion report and an authentication execution path diagram, and the plaintext authentication consultation content is deleted simultaneously.

[0122] Step S60 specifically involves:

[0123] The server records in real time a consultation log that includes at least authentication consultation requests, real-time consultation results, client information, and authentication feedback, wherein the authentication feedback is authentication success, authentication failure, or no authentication.

[0124] The server obtains the current timestamp T3, calculates the hash value H4 of the consultation log and timestamp T3 using the SM3 algorithm, calculates the hash value H5 of timestamp T3 using the SM3 algorithm, selects 8 bits starting from the 7th bit of the hash value H5 as the dynamic key K2, calls the dynamic key K2 using the ChaCha20 algorithm to encrypt the consultation log and hash value H4 into a layer of encrypted data, encrypts the layer of encrypted data and timestamp T3 into a consultation ciphertext log using the 3DES algorithm, stores the consultation ciphertext log in a specified path, calculates the second log fingerprint of the consultation ciphertext log using the hash256 algorithm and uploads it to the blockchain, obtains and stores the second evidence certificate fed back by the blockchain, which carries at least the evidence number, evidence time, evidence subject information, data information, blockchain information and signature information, for subsequent consultation tracing;

[0125] Step S70 specifically involves:

[0126] The server concatenates the real-time consultation result and the second certificate of authenticity into concatenated data, obtains the current timestamp T4, calculates the hash value H6 of the concatenated data and timestamp T4 using the SM3 algorithm, uses the first 1 / 3 of the hash value H6 as the dynamic key K3, the middle 1 / 3 as the dynamic key K4, and the last 1 / 3 as the dynamic key K5, and divides the concatenated data into a first data block, a second data block, and a third data block. The server uses the AES algorithm to encrypt the first data block using the dynamic key K3 to obtain the first encrypted data block, uses the AES algorithm to encrypt the second data block using the dynamic key K4 to obtain the second encrypted data block, and uses the AES algorithm to encrypt the third data block using the dynamic key K5 to obtain the third encrypted data block. The server then uses the session key to encrypt the first encrypted data block, the second encrypted data block, the third encrypted data block, the timestamp T4, and the hash value H6 into a consultation feedback encrypted packet, which is then sent back to the enterprise client in real time via the SSL protocol.

[0127] The enterprise client receives and stores the consultation feedback encrypted package in real time, decrypts and verifies the consultation feedback encrypted package to obtain the real-time consultation result and the second evidence certificate, and displays the real-time consultation result and the second evidence certificate through the consultation interface.

[0128] Step S80 specifically involves:

[0129] When the number of consultation logs reaches a preset threshold, the server constructs an incremental dataset based on each consultation log. During the idle period of the certification consultation decision model, the deployed certification consultation decision model is trained using the incremental dataset and then iteratively optimized.

[0130] The server creates a monitoring agent, sets the monitoring parameters of the monitoring agent, monitors the latest certification standard documents through the monitoring agent, preprocesses the latest certification standard documents, and then integrates the latest certification standard documents into the dynamic decision knowledge graph through a second graph neural network (updating or adding entities and relationships in the dynamic decision knowledge graph) to dynamically update the dynamic decision knowledge graph; the monitoring parameters include at least the monitoring period, monitoring source, and access permissions.

[0131] A preferred embodiment of the blockchain-based authentication and consultation system of the present invention includes the following modules:

[0132] The initialization module is used to obtain a large amount of historical certification consultation data and historical certification standard files from the server, preprocess the historical certification consultation data and historical certification standard files, annotate the preprocessed historical certification consultation data to construct a consultation dataset, and construct a dynamic decision knowledge graph based on the preprocessed historical certification standard files.

[0133] The certification consultation decision model training module is used by the server to create a certification consultation decision model that calls the dynamic decision knowledge graph to provide certification consultation services, set the loss function of the certification consultation decision model, train the certification consultation decision model through the consultation dataset and the loss function, and deploy the trained certification consultation decision model.

[0134] The two-way authentication module is used for enterprise clients and servers to perform two-way authentication and negotiate session keys. The server records authentication logs, encrypts the authentication logs into authentication ciphertext logs and stores them, calculates the first log fingerprint of the authentication ciphertext logs and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain, and uses it for subsequent authentication and traceability.

[0135] The authentication consultation request sending module is used by the enterprise client to obtain the input authentication consultation content, encrypt the authentication consultation content into consultation ciphertext using the session key, obtain the current timestamp T1 as the request time, generate an authentication consultation request based on the consultation ciphertext and the request time, and send the authentication consultation request to the server.

[0136] The real-time consultation result generation module is used by the server to verify and parse the received certification consultation request to obtain certification consultation content, de-identify the certification consultation content to obtain de-identified consultation content, input the de-identified consultation content into the deployed certification consultation decision model for reasoning, obtain real-time consultation results including compliance suggestion reports and certification execution path diagrams, and delete the plaintext certification consultation content.

[0137] The consultation log management module is used to record consultation logs in real time on the server, encrypt the consultation logs into ciphertext logs and store them, calculate the second log fingerprint of the ciphertext logs and upload it to the blockchain, obtain and store the second evidence certificate fed back by the blockchain for subsequent consultation tracing.

[0138] The result feedback module is used by the server to encrypt the real-time consultation result and the second evidence certificate into a consultation feedback encrypted package using the session key, and then feed the consultation feedback encrypted package back to the enterprise client in real time.

[0139] The iterative optimization module is used by the server to iteratively optimize the deployed authentication consultation decision model based on the consultation logs and dynamically update the dynamic decision knowledge graph.

[0140] The initialization module is specifically used for:

[0141] The server acquires a large amount of historical certification consultation data and historical certification standard documents; the historical certification consultation data includes at least certification consultation content, compliance recommendation reports, and certification execution path diagrams; the certification consultation content includes at least consultation requests and current enterprise data; the historical certification standard documents include at least core standard documents, supporting documents, certification process documents, certification body documents, and certification standard interpretation documents.

[0142] The enterprise's current status data should include at least the following: a) Basic enterprise information: the enterprise's size, industry sector, business scope, organizational structure, etc. This information helps to understand the overall situation of the enterprise and tailor a management system accordingly. b) Existing management system documents: the enterprise's existing management systems, process documents, operating procedures, etc., used to identify gaps with the target certification standards and provide a basis for system establishment and improvement. c) Current status of management processes: the enterprise's actual management processes, including business connections, information transmission, and decision-making mechanisms between departments, used to identify problems and weaknesses in the processes, and to propose optimization suggestions to make the management system smoother and more efficient. d) Personnel capabilities and responsibilities: the professional skills, work experience, and level of understanding and knowledge of the management system among the enterprise's internal personnel, while clearly defining the allocation of responsibilities for each department and position, so as to reasonably arrange personnel and ensure that all responsibilities are effectively implemented when establishing and operating the management system.

[0143] The core standard document includes at least the standard text and interpretations of the standard clauses. The standard text is the core part of the certification standard, which specifies in detail the specific requirements that enterprises or organizations need to meet, such as ISO 9001 quality management system standard, ISO 14001 environmental management system standard, and ISO 45001 occupational health and safety management system standard. The interpretations of the standard clauses are to help enterprises better understand and apply the standard clauses, and usually include the background, purpose, detailed explanation of the specific requirements, and how to implement these requirements in practice.

[0144] The supporting documents include at least application guidelines, industry-specific requirements, and technical specifications. The application guidelines provide guidance for the specific application of the standard, helping companies better implement the standard in different industries or specific situations. For example, the application guidelines for ISO 9001 may provide specific implementation suggestions for different industries such as manufacturing and services. The industry-specific requirements supplement or refine general standards for specific industries. For example, the automotive industry has the IATF 16949 standard, which is a more detailed quality management system standard for the automotive industry based on ISO 9001. The technical specifications provide technical details and specifications related to the standard, ensuring that companies can meet the technical requirements during implementation. For example, environmental management system standards may involve emission standards for specific pollutants, environmental monitoring technical specifications, etc.

[0145] The certification process documents include at least a certification application guide, audit process documents, and a certification certificate sample. The certification application guide details how companies can apply for certification, including application requirements, required documents and materials, and the application process, helping companies understand the entry requirements and initial steps. The audit process documents include an audit plan, audit checklist, and audit report template. These documents standardize the certification audit process, ensuring the fairness, objectivity, and consistency of the audit. The audit plan clarifies the audit timeline, scope, and focus. The audit checklist lists the specific clauses and contents to be checked during the audit. The audit report template specifies the format and content requirements for the audit report. The certification certificate sample demonstrates the style and content of the certification certificate, including the company name, certification scope, certificate number, issuing authority, and validity period, helping companies correctly use and display the certification certificate after obtaining it.

[0146] The certification body documents include at least the certification body rules and procedures, and certification body qualification certificates. The certification body rules and procedures are the certification body's own operating rules and procedures, including the certification body's qualification requirements, certification process, auditor qualification management, certification decision-making procedures, appeal and complaint handling mechanisms, etc., to ensure that the certification body's operation complies with regulations. The certification body qualification certificates are the certification body's qualification certificates, accreditation certificates, and other documents, proving that it has the legal qualifications and capabilities to carry out specific certification business.

[0147] The certification standard interpretation documents include at least a standard clarification document and a frequently asked questions (FAQs). The standard clarification document is used to further explain and clarify controversial or easily misunderstood clauses to ensure the correct understanding and application of the standard. The frequently asked questions are answers to questions that enterprises often encounter during the implementation of certification standards, providing a way to quickly resolve problems and improve the efficiency and accuracy of certification implementation.

[0148] The historical certified consultation data shall undergo preprocessing including at least data cleaning, data formatting, data classification, and tagging; the data cleaning shall at least include removing duplicate data, handling missing values, and correcting erroneous data; the data formatting shall at least include unifying text format and standardizing data structure; the data classification and tagging shall at least include consultation type classification and adding tags.

[0149] The process of removing duplicate data involves checking for duplicate records in certification consultation content, compliance recommendation reports, and certification execution path diagrams. For example, the same consultation case might be recorded repeatedly due to data entry errors or multiple backups. Duplicates can be identified and deleted by comparing key data fields. Handling missing values ​​involves taking corresponding measures when certain key information in the consultation request (such as the specific type of consultation issue) or enterprise status data (such as some financial indicators) is missing. If the missing data significantly impacts the analysis and cannot be completed, the data entry can be deleted. If the missing information is minor, interpolation or filling with default values ​​can be used. Correcting erroneous data involves checking for errors in the data, such as incorrect consultation date formats or numerical errors in enterprise status data (such as incorrect sales unit). Standardizing text format involves standardizing the font, font size, and other formats for text data such as certification consultation content and compliance recommendation reports. Simultaneously, the text is segmented to ensure a clear structure. The standardized data structure standardizes the data structure of the certification execution path diagram. If the certification execution path diagram is stored in image form, it can be converted into a graphical data structure, such as nodes and edges. Each node represents a certification stage, and the edges represent the transformation relationship between stages. Corresponding attributes are added to each node and edge. The consultation type classification divides historical certification consultation data into different consultation categories based on the content of the consultation request. For example, it can be divided into quality management system certification consultation, environmental management system certification consultation, etc. Adding tags involves adding tags to the data, such as consultation result tags (certification successful, certification failed, not certified, etc.) and compliance recommendation severity tags (high risk, medium risk, low risk), etc.

[0150] The historical authentication standard documents are preprocessed in at least the following ways: document organization and classification, text content extraction and cleaning, and key information annotation and association. The document organization and classification includes at least physical organization and index creation. The text content extraction and cleaning includes at least text extraction and text format cleaning. The key information annotation and association includes at least annotation of key information and establishment of document associations.

[0151] The physical organization involves classifying and storing core standard documents, supporting documents, certification process documents, certification body documents, and certification standard interpretation documents separately. In practice, this can be done by file type (e.g., Word document, PDF document) or subject (e.g., quality certification, environmental certification). Indexing involves creating an index for each file, including file name, file type, file category, and file version, facilitating quick file retrieval and management. Text extraction involves using PDF parsing tools to extract text content from PDF files and directly reading text from Word documents. During extraction, the integrity of the text must be ensured to avoid garbled characters. Text formatting removal involves removing redundant formatting elements such as headers, footers, and page numbers. Tables in the text can be converted to structured data formats such as CSV files. Marking key information involves marking key clauses and keywords in core standard documents, certification standard interpretation documents, etc. For example, in quality management system certification standard documents, key concepts such as "quality policy" and "quality objectives" are marked. Establishing file associations involves analyzing the relationships between files, such as the reference relationship between core standard documents and supporting documents, and the matching relationship between certification process documents and certification body documents.

[0152] In the preprocessed historical certification consultation data, the certification consultation content, compliance suggestion report, and certification execution path diagram are associated and labeled with consultation result tags. A consultation dataset is constructed based on the labeled historical certification consultation data. The enterprise information carried by the enterprise status data in the consultation dataset is anonymized and desensitized. The consultation result tags are certification successful, certification failed, or not certified.

[0153] Entities are extracted from the pre-processed historical certification standard documents using a pre-trained BiLSTM-CRF model. Relationships between these entities are inferred using the TransE algorithm. A dynamic decision knowledge graph is then constructed based on these entities and their relationships. The entities include at least standard-related entities, supporting document entities, certification process document entities, certification body document entities, and enterprise-related entities. The relationships include at least standard-related relationships, supporting document relationships, certification process document relationships, certification body document relationships, enterprise-standard relationships, and internal enterprise relationships.

[0154] The LSTM (Long Short-Term Memory) network in the BiLSTM-CRF model is a special type of recurrent neural network (RNN). By introducing input gates, forget gates, and output gates, it solves the gradient vanishing or exploding problems that traditional RNNs often encounter when processing long sequences of data, and can better capture long-term dependencies in the sequence. BILSTM (Bidirectional Long Short-Term Memory) is an improvement on LSTM, containing two LSTM layers: a forward LSTM layer that processes data sequentially from the beginning to the end of the sequence, and a backward LSTM layer that processes data sequentially from the end to the beginning of the sequence. This allows for the simultaneous acquisition of information from both directions in the sequence. This bidirectional information is crucial for many natural language processing tasks, such as named entity recognition. In sequence labeling tasks, whether a word is part of an entity depends not only on the words preceding it but also on the words following it. CRF (Conditional Random Field) is a discriminative model used to model a given observation sequence labeled with another entity. In sequence labeling tasks, there are often certain relationships between the labels of a labeled sequence. For example, in named entity recognition tasks, the start label of an entity (such as "B-PER" indicating the beginning of a person's name) is usually followed by an intermediate label (such as "I-PER") or an end label (such as "E-PER"), and it will not jump directly to other types of labels. CRF can model this transition relationship between labels very well. It calculates the probability of a certain labeled sequence under a given observation sequence by defining a conditional probability distribution, so as to maximize the probability that the labeled sequence conforms to the labeling rules.

[0155] TransE (Translating Embedding) is an algorithm for embedding knowledge graphs. The TransE algorithm maps entities and relations to a vector space, so that pairs of entities that satisfy the relations satisfy certain geometric relationships in the vector space. This allows the TransE algorithm to be used to predict missing triples in a knowledge graph, that is, to infer the relationships between entities.

[0156] The certification consulting decision model training module is specifically used for:

[0157] The server creates an authentication consultation decision model based on an input parsing layer, a knowledge graph retrieval layer, a feature fusion layer, a decision generation layer, and an output transformation layer, and sets the loss function of the authentication consultation decision model.

[0158] The input parsing layer is constructed based on a bidirectional LSTM module, an enterprise status encoding module, and a vector concatenation module. The bidirectional LSTM module is used to extract text feature vectors from consultation requests; the enterprise status encoding module is used to extract numerical feature vectors from enterprise status data through a fully connected layer (with ReLU activation); and the vector concatenation module is used to concatenate the text feature vectors and numerical feature vectors into a preliminary feature vector.

[0159] The input parsing layer is used to parse and standardize the input authentication consultation content, encoding the consultation request into a text feature vector and the enterprise status data into a structured numerical feature vector for easier subsequent processing. In specific implementation, an adaptive length mechanism is adopted to handle variable-length consultation requests and missing enterprise data; dropout regularization is used to reduce the risk of overfitting and ensure robustness across various enterprise sizes.

[0160] The knowledge graph retrieval layer is constructed based on a graph embedding module and a graph attention retrieval module; the graph embedding module is used to encode the dynamic decision knowledge graph into node embeddings through a graph convolutional network (GCN); the graph attention retrieval module is used to retrieve enhanced feature vectors related to the initial feature vectors from each of the node embeddings through a multi-head attention mechanism;

[0161] The knowledge graph retrieval layer is used to dynamically access the dynamic decision-making knowledge graph, retrieve contextual features related to the input (preliminary feature vector), such as compliance standards and industry best practices, and output enhanced feature vectors (knowledge-driven features). These enhanced feature vectors include entity embeddings and relation weights. In practice, retrieval efficiency can be improved through a caching mechanism; and an error-tolerant module can be added to handle noisy or missing data in the dynamic decision-making knowledge graph, ensuring decision reliability.

[0162] The feature fusion layer is constructed based on a feature concatenation module and a self-attention fusion module. The feature concatenation module is used to concatenate the initial feature vector and the enhanced feature vector into a unified feature vector. The self-attention fusion module is used to perform weighted fusion of key features in the unified feature vector through a transformer-based self-attention mechanism to obtain fused features.

[0163] The feature fusion layer is used to unify features from different sources (preliminary feature vectors and enhanced feature vectors), capture the dependencies between features (such as the correlation between the current situation of the enterprise and the consulting needs), and output high-dimensional fused features to support subsequent decision-making. In specific implementation, a gating mechanism (such as GRU units) is introduced to prioritize the fusion of enhanced feature vectors from the dynamic decision knowledge graph to emphasize compliance knowledge; feature normalization is added to balance the scale differences between textual and numerical features and improve decision robustness.

[0164] The decision generation layer is constructed based on a suggestion generation module and a path graph generation module. The suggestion generation module is used to infer compliance suggestion reports by using a seq2seq model (encoder-decoder structure, mainly LSTM) to the fused features. The path graph generation module is used to decode the fused features by a first graph neural network (GNN) to obtain an authentication execution path graph.

[0165] The decision generation layer generates structured output based on fusion features; the suggestion generation module outputs a text sequence report (compliance suggestion report), and the path graph generation module outputs a directed graph (certification execution path graph). In specific implementation, the suggestion generation module integrates rule constraint decoding to ensure that the compliance suggestion report conforms to industry standards; the path graph generation module adds a dynamic path optimization sublayer (based on a reinforcement learning reward mechanism) to generate the shortest or lowest-risk execution path, adapting to the diversity of enterprises.

[0166] The output conversion layer is built upon a text formatting module and a graph rendering module; the text formatting module is used to convert compliance recommendation reports into formal report formats through a softmax layer and a template engine; the graph rendering module is used to convert the certification execution path graph into a visual graph representation through a tree decoder.

[0167] The output conversion layer is used for formatting compliance recommendation reports and certification execution path diagrams, generating the final consultation results.

[0168] The formula for the loss function is:

[0169] L total =α·L report +β·L path +γ·L reg ;

[0170] Among them, L total L represents the loss value of the loss function; report The sequence loss for compliance recommendation reports is represented by cross-entropy loss, which is suitable for text generation tasks; L path The graph structure loss representing the authentication execution path graph is represented by the graph edit distance loss, which measures the deviation between the generated path and the ideal path; L reg α represents the regularization term, including L2 regularization (weight decay) and dropout noise regularization; α, β, and γ all represent weight coefficients;

[0171] After performing sample augmentation on the consultation dataset based on the consultation category, the consultation dataset is divided into a training set, a validation set, and a test set in a ratio of 8:1:1. The certification consultation decision model is trained using the training set and a loss function. During the training process, the hyperparameters of the certification consultation decision model are continuously optimized, including at least the learning rate, learning warm-up rate, learning decay rate, random dropout rate, batch size, and number of hidden layers, until the loss value of the loss function is less than a preset loss threshold, or a preset early stopping condition is met (e.g., the training time or number of iterations reaches the upper limit, or the model parameters change too little).

[0172] The training set is used to calculate the accuracy of consultation results, inference latency, completeness of compliance recommendation report content, completeness of certification execution path rendering, and retrieval relevance of dynamic decision knowledge graph to validate the trained certification consultation decision model. If the validation fails, the training set is expanded and training continues; if the validation passes, then:

[0173] The test set is used to calculate task completion efficiency, actual path deviation rate, noise tolerance, resource consumption, and maximum processing request rate to test the verified certification consultation decision model. If the test fails, the training set is expanded and training continues; if the test passes, training ends and the certified consultation decision model that has passed the test is deployed.

[0174] The two-way authentication module specifically includes:

[0175] The certificate initialization unit is used by the enterprise client to preset a certificate Cert_C carrying a long-term public key PublicKey_C, a long-term private key PrivateKey_C matching the long-term public key PublicKey_C, and a CA root certificate through the CA center.

[0176] The server pre-sets a certificate Cert_S carrying a long-term public key PublicKey_S, a long-term private key PrivateKey_S matching the long-term public key PublicKey_S, and a CA root certificate through the CA center.

[0177] The CA root certificate is used to verify the validity of certificates Cert_C and Cert_S;

[0178] The first authentication request sending unit is used to generate a random number Nonce_C by the enterprise client, generate a first authentication request based on the list of cipher suites supported by the local machine and the random number Nonce_C, and send it to the server.

[0179] The second authentication request sending unit is used by the server to parse the received first authentication request to obtain a list of cipher suites and a random number Nonce_C, select a cipher suite from the list of cipher suites, generate a random number Nonce_S, create a pair of temporary public keys EphemeralPublicKey_S and temporary private keys EphemeralPrivateKey_S based on the ECDHE algorithm in the cipher suite, and sign the random number Nonce_C, the random number Nonce_S, and the temporary public key EphemeralPublicKey_S with the long-term private key PrivateKey_S to obtain the server signature Sig_S.

[0180] The server generates a second authentication request based on the cipher suite, the random number Nonce_S, the certificate Cert_S, the temporary public key EphemeralPublicKey_S, and the server signature Sig_S, and sends it to the enterprise client.

[0181] The third authentication request sending unit is used by the enterprise client to parse the received second authentication request to obtain the cipher suite, random number Nonce_S, certificate Cert_S, temporary public key EphemeralPublicKey_S and server signature Sig_S;

[0182] The enterprise client verifies the certificate Cert_S using the CA root certificate, and verifies the server signature Sig_S using the long-term public key PublicKey_S carried by the certificate Cert_S. Upon successful verification:

[0183] The enterprise client creates a pair of temporary public keys EphemeralPublicKey_C and temporary private keys EphemeralPrivateKey_C based on the ECDHE algorithm in the cryptographic suite. The client then uses the long-term private key PrivateKey_C to sign the random number Nonce_C, the random number Nonce_S, and the temporary public key EphemeralPublicKey_C to obtain the client signature Sig_C.

[0184] The enterprise client generates a third authentication request based on the certificate Cert_C, the temporary public key EphemeralPublicKey_C, and the client signature Sig_C, and sends it to the server.

[0185] The verification result sending unit is used by the server to parse the received third authentication request to obtain the certificate Cert_C, the temporary public key EphemeralPublicKey_C, and the client signature Sig_C;

[0186] The server verifies the certificate Cert_C using the CA root certificate, verifies the client signature Sig_C using the public key PublicKey_C carried by the certificate Cert_C, and sends a verification result to the enterprise client indicating whether the verification was successful or failed.

[0187] The session key derivation unit is used to terminate the process when the verification result is a verification failure; when the verification result is a verification success, the enterprise client uses the ECDHE algorithm to call the temporary private key EphemeralPrivateKey_C and the temporary public key EphemeralPublicKey_S to calculate the shared key SharedSecret_C; the server uses the ECDHE algorithm to call the temporary private key EphemeralPrivateKey_S and the temporary public key EphemeralPublicKey_C to calculate the shared key SharedSecret_S, where the shared key SharedSecret_C and the shared key SharedSecret_S are the same key;

[0188] The ECDHE algorithm is a key negotiation algorithm based on elliptic curve cryptography. It allows two communicating parties to negotiate a shared key over an insecure channel without sharing any secret information beforehand. Its core idea is to leverage the one-way nature of dot product operations on elliptic curves, ensuring that even if an attacker intercepts the public keys of both parties, they cannot compute the shared key.

[0189] The enterprise client derives a session key using the shared key SharedSecret_C, random number Nonce_C, and random number Nonce_S via a KDF function; the server derives a session key using the shared key SharedSecret_S, random number Nonce_C, and random number Nonce_S via a KDF function; both the enterprise client and the server calculate and exchange the key fingerprint of the session key using the hash256 algorithm to verify the consistency of the session key.

[0190] The authentication log management unit is used by the server to record authentication logs in real time. After authentication, it obtains the current timestamp T2, calculates the hash value H1 of the authentication log and timestamp T2 using the SM3 algorithm, calculates the hash value H2 of timestamp T2 using the SM3 algorithm, selects 8 bits starting from the 6th bit of the hash value H2 as the dynamic key K1, calls the dynamic key K1 using the ChaCha20 algorithm to encrypt the authentication log and hash value H1 into first-level encrypted data, encrypts the first-level encrypted data and timestamp T2 into authentication ciphertext log using the SM9 algorithm, stores the authentication ciphertext log in a designated path, calculates the first log fingerprint of the authentication ciphertext log using the hash256 algorithm and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain, which carries at least the evidence number, evidence time, evidence subject information, data information, blockchain information and signature information, for subsequent authentication and traceability.

[0191] The authentication inquiry request sending module is specifically used for:

[0192] The enterprise client obtains the input authentication consultation content, uses the AES algorithm to call the session key to encrypt the authentication consultation content into consultation ciphertext, obtains the current timestamp T1 as the request time, calculates the hash value H3 of the consultation ciphertext and the request time using the SM3 algorithm, and encrypts the consultation ciphertext, the request time, and the hash value H3 into an encrypted string using the RC6 algorithm. Based on the encrypted string, an authentication consultation request is generated and sent to the server via the SSL protocol.

[0193] The real-time consultation result generation module is specifically used for:

[0194] The server receives the authentication consultation request in real time, parses the request to obtain an encrypted string, decrypts the encrypted string using the RC6 algorithm to obtain the consultation ciphertext, request time, and hash value H3, performs integrity verification on the consultation ciphertext and request time using the hash value H3, performs timeliness verification using the request time, and then uses the AES algorithm to call the session key to decrypt the consultation ciphertext to obtain the authentication consultation content. The server uses a streaming engine to perform anonymization and data desensitization on the enterprise information carried by the enterprise status data in the authentication consultation content to obtain desensitized consultation content. The desensitized consultation content is input into the deployed authentication consultation decision model for reasoning to obtain real-time consultation results including a compliance suggestion report and an authentication execution path diagram, and the plaintext authentication consultation content is deleted simultaneously.

[0195] The consultation log management module is specifically used for:

[0196] The server records in real time a consultation log that includes at least authentication consultation requests, real-time consultation results, client information, and authentication feedback, wherein the authentication feedback is authentication success, authentication failure, or no authentication.

[0197] The server obtains the current timestamp T3, calculates the hash value H4 of the consultation log and timestamp T3 using the SM3 algorithm, calculates the hash value H5 of timestamp T3 using the SM3 algorithm, selects 8 bits starting from the 7th bit of the hash value H5 as the dynamic key K2, calls the dynamic key K2 using the ChaCha20 algorithm to encrypt the consultation log and hash value H4 into a layer of encrypted data, encrypts the layer of encrypted data and timestamp T3 into a consultation ciphertext log using the 3DES algorithm, stores the consultation ciphertext log in a specified path, calculates the second log fingerprint of the consultation ciphertext log using the hash256 algorithm and uploads it to the blockchain, obtains and stores the second evidence certificate fed back by the blockchain, which carries at least the evidence number, evidence time, evidence subject information, data information, blockchain information and signature information, for subsequent consultation tracing;

[0198] The result feedback module is specifically used for:

[0199] The server concatenates the real-time consultation result and the second certificate of authenticity into concatenated data, obtains the current timestamp T4, calculates the hash value H6 of the concatenated data and timestamp T4 using the SM3 algorithm, uses the first 1 / 3 of the hash value H6 as the dynamic key K3, the middle 1 / 3 as the dynamic key K4, and the last 1 / 3 as the dynamic key K5, and divides the concatenated data into a first data block, a second data block, and a third data block. The server uses the AES algorithm to encrypt the first data block using the dynamic key K3 to obtain the first encrypted data block, uses the AES algorithm to encrypt the second data block using the dynamic key K4 to obtain the second encrypted data block, and uses the AES algorithm to encrypt the third data block using the dynamic key K5 to obtain the third encrypted data block. The server then uses the session key to encrypt the first encrypted data block, the second encrypted data block, the third encrypted data block, the timestamp T4, and the hash value H6 into a consultation feedback encrypted packet, which is then sent back to the enterprise client in real time via the SSL protocol.

[0200] The enterprise client receives and stores the consultation feedback encrypted package in real time, decrypts and verifies the consultation feedback encrypted package to obtain the real-time consultation result and the second evidence certificate, and displays the real-time consultation result and the second evidence certificate through the consultation interface.

[0201] The iterative optimization module is specifically used for:

[0202] When the number of consultation logs reaches a preset threshold, the server constructs an incremental dataset based on each consultation log. During the idle period of the certification consultation decision model, the deployed certification consultation decision model is trained using the incremental dataset and then iteratively optimized.

[0203] The server creates a monitoring agent, sets the monitoring parameters of the monitoring agent, monitors the latest certification standard documents through the monitoring agent, preprocesses the latest certification standard documents, and then integrates the latest certification standard documents into the dynamic decision knowledge graph through a second graph neural network (updating or adding entities and relationships in the dynamic decision knowledge graph) to dynamically update the dynamic decision knowledge graph; the monitoring parameters include at least the monitoring period, monitoring source, and access permissions.

[0204] While specific embodiments of the present invention have been described above, those skilled in the art should understand that the specific embodiments described are merely illustrative and not intended to limit the scope of the present invention. Equivalent modifications and variations made by those skilled in the art in accordance with the spirit of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A blockchain-based authentication and consultation method, characterized in that: Includes the following steps: Step S10: The server obtains a large amount of historical certification consultation data and historical certification standard files, preprocesses each of the historical certification consultation data and historical certification standard files, annotates each of the preprocessed historical certification consultation data and constructs a consultation dataset, and constructs a dynamic decision knowledge graph based on each of the preprocessed historical certification standard files. Step S20: The server creates an authentication consultation decision model that calls the dynamic decision knowledge graph to provide authentication consultation services, sets the loss function of the authentication consultation decision model, trains the authentication consultation decision model using the consultation dataset and the loss function, and deploys the trained authentication consultation decision model. Step S30: The enterprise client and the server perform two-way authentication and negotiate a session key. The server records the authentication log, encrypts the authentication log into an authentication ciphertext log and stores it, calculates the first log fingerprint of the authentication ciphertext log and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain for subsequent authentication and traceability. Step S40: The enterprise client obtains the input authentication consultation content, encrypts the authentication consultation content into consultation ciphertext using the session key, obtains the current timestamp T1 as the request time, generates an authentication consultation request based on the consultation ciphertext and the request time, and sends the authentication consultation request to the server. Step S50: The server verifies and parses the received authentication consultation request to obtain authentication consultation content, desensitizes the authentication consultation content to obtain desensitized consultation content, inputs the desensitized consultation content into the deployed authentication consultation decision model for reasoning, and obtains real-time consultation results including compliance suggestion reports and authentication execution path diagrams, and deletes the plaintext authentication consultation content. Step S60: The server records consultation logs in real time, encrypts the consultation logs into ciphertext logs and stores them, calculates the second log fingerprint of the ciphertext logs and uploads it to the blockchain, obtains and stores the second evidence certificate fed back by the blockchain, and uses it for subsequent consultation tracing. Step S70: The server uses the session key to encrypt the real-time consultation result and the second evidence certificate into a consultation feedback encrypted package, and sends the consultation feedback encrypted package to the enterprise client in real time. Step S80: The server iteratively optimizes the deployed authentication consultation decision model based on the consultation logs and dynamically updates the dynamic decision knowledge graph.

2. The blockchain-based authentication and consultation method as described in claim 1, characterized in that: Step S10 specifically involves: The server acquires a large amount of historical certification consultation data and historical certification standard documents; the historical certification consultation data includes at least certification consultation content, compliance recommendation reports, and certification execution path diagrams; the certification consultation content includes at least consultation requests and current enterprise data; the historical certification standard documents include at least core standard documents, supporting documents, certification process documents, certification body documents, and certification standard interpretation documents. The historical certified consultation data shall undergo preprocessing including at least data cleaning, data formatting, data classification, and tagging; the data cleaning shall at least include removing duplicate data, handling missing values, and correcting erroneous data; the data formatting shall at least include unifying text format and standardizing data structure; the data classification and tagging shall at least include consultation type classification and adding tags. The historical authentication standard documents are preprocessed in at least the following ways: document organization and classification, text content extraction and cleaning, and key information annotation and association. The document organization and classification includes at least physical organization and index creation. The text content extraction and cleaning includes at least text extraction and text format cleaning. The key information annotation and association includes at least annotation of key information and establishment of document associations. In the preprocessed historical certification consultation data, the certification consultation content, compliance suggestion report and certification execution path diagram are associated and labeled with consultation result tags. Based on the labeled historical certification consultation data, a consultation dataset is constructed. The enterprise information carried by the enterprise status data in the consultation dataset is anonymized and desensitized. The consultation result is tagged as successful authentication, failed authentication, or unauthenticated. Entities are extracted from the pre-processed historical authentication standard files using a pre-trained BiLSTM-CRF model. Relationships between the entities are inferred using the TransE algorithm. A dynamic decision knowledge graph is then constructed based on the entities and their relationships.

3. The blockchain-based authentication and consultation method as described in claim 1, characterized in that: Step S20 specifically involves: The server creates an authentication consultation decision model based on an input parsing layer, a knowledge graph retrieval layer, a feature fusion layer, a decision generation layer, and an output transformation layer, and sets the loss function of the authentication consultation decision model. The input parsing layer is constructed based on a bidirectional LSTM module, an enterprise status encoding module, and a vector concatenation module. The bidirectional LSTM module is used to extract text feature vectors from consultation requests; the enterprise status encoding module is used to extract numerical feature vectors from enterprise status data through a fully connected layer; and the vector concatenation module is used to concatenate the text feature vectors and numerical feature vectors into a preliminary feature vector. The knowledge graph retrieval layer is constructed based on a graph embedding module and a graph attention retrieval module; the graph embedding module is used to encode the dynamic decision knowledge graph into node embeddings through a graph convolutional network; the graph attention retrieval module is used to retrieve enhanced feature vectors related to the initial feature vectors from each of the node embeddings through a multi-head attention mechanism; The feature fusion layer is constructed based on a feature concatenation module and a self-attention fusion module. The feature concatenation module is used to concatenate the initial feature vector and the enhanced feature vector into a unified feature vector. The self-attention fusion module is used to perform weighted fusion of key features in the unified feature vector through a transformer-based self-attention mechanism to obtain fused features. The decision generation layer is constructed based on a suggestion generation module and a path graph generation module; the suggestion generation module is used to infer compliance suggestion reports by using a seq2seq model to analyze the fused features; the path graph generation module is used to decode the fused features by using a first graph neural network to obtain an authentication execution path graph. The output conversion layer is built based on a text formatting module and a graph rendering module; The text formatting module is used to convert compliance recommendation reports into formal report formats through a softmax layer and a template engine; the graph rendering module is used to convert the certification execution path graph into a visual graph representation through a tree decoder. The formula for the loss function is: L total =α·L report +β·L path +γ·L reg ; Among them, L total L represents the loss value of the loss function; report The sequence loss of the compliance recommendation report is represented by cross-entropy loss; L path The graph structure loss representing the authentication execution path graph is represented by the graph edit distance loss; L reg α represents the regularization term, including L2 regularization and dropout noise regularization; α, β, and γ all represent weight coefficients. After performing sample augmentation on the consultation dataset based on the consultation category, the consultation dataset is divided into a training set, a validation set, and a test set in a ratio of 8:1:

1. The certification consultation decision model is trained using the training set and the loss function. During the training process, the hyperparameters of the certification consultation decision model are continuously optimized, including at least the learning rate, learning warm-up rate, learning decay rate, random dropout rate, batch size, and number of hidden layers, until the loss value of the loss function is less than the preset loss threshold or the preset early stopping condition is met. The training set is used to calculate the accuracy of consultation results, inference latency, completeness of compliance recommendation report content, completeness of certification execution path rendering, and retrieval relevance of dynamic decision knowledge graph to validate the trained certification consultation decision model. If the validation fails, the training set is expanded and training continues; if the validation passes, then: The test set is used to calculate task completion efficiency, actual path deviation rate, noise tolerance, resource consumption, and maximum processing request rate to test the verified certification consultation decision model. If the test fails, the training set is expanded and training continues; if the test passes, training ends and the certified consultation decision model that has passed the test is deployed.

4. The blockchain-based authentication and consultation method as described in claim 1, characterized in that: Step S30 specifically includes: Step S31: The enterprise client presets a certificate Cert_C carrying a long-term public key PublicKey_C, a long-term private key PrivateKey_C matching the long-term public key PublicKey_C, and a CA root certificate through the CA center. The server pre-sets a certificate Cert_S carrying a long-term public key PublicKey_S, a long-term private key PrivateKey_S matching the long-term public key PublicKey_S, and a CA root certificate through the CA center. The CA root certificate is used to verify the validity of certificates Cert_C and Cert_S; Step S32: The enterprise client generates a random number Nonce_C, generates a first authentication request based on the list of cipher suites supported by the local machine and the random number Nonce_C, and sends it to the server; Step S33: The server parses the received first authentication request to obtain a list of cipher suites and a random number Nonce_C. It selects a cipher suite from the list, generates a random number Nonce_S, and creates a pair of temporary public keys EphemeralPublicKey_S and temporary private keys EphemeralPrivateKey_S based on the ECDHE algorithm in the cipher suite. The server then signs the random number Nonce_C, the random number Nonce_S, and the temporary public key EphemeralPublicKey_S using the long-term private key PrivateKey_S to obtain the server signature Sig_S. The server generates a second authentication request based on the cipher suite, the random number Nonce_S, the certificate Cert_S, the temporary public key EphemeralPublicKey_S, and the server signature Sig_S, and sends it to the enterprise client. Step S34: The enterprise client parses the received second authentication request to obtain the cipher suite, random number Nonce_S, certificate Cert_S, temporary public key EphemeralPublicKey_S, and server signature Sig_S; The enterprise client verifies the certificate Cert_S using the CA root certificate, and verifies the server signature Sig_S using the long-term public key PublicKey_S carried by the certificate Cert_S. Upon successful verification: The enterprise client creates a pair of temporary public keys EphemeralPublicKey_C and temporary private keys EphemeralPrivateKey_C based on the ECDHE algorithm in the cryptographic suite. The client then uses the long-term private key PrivateKey_C to sign the random number Nonce_C, the random number Nonce_S, and the temporary public key EphemeralPublicKey_C to obtain the client signature Sig_C. The enterprise client generates a third authentication request based on the certificate Cert_C, the temporary public key EphemeralPublicKey_C, and the client signature Sig_C, and sends it to the server. Step S35: The server parses the received third authentication request to obtain the certificate Cert_C, the temporary public key EphemeralPublicKey_C, and the client signature Sig_C; The server verifies the certificate Cert_C using the CA root certificate, verifies the client signature Sig_C using the public key PublicKey_C carried by the certificate Cert_C, and sends a verification result to the enterprise client indicating whether the verification was successful or failed. Step S36: If the verification result is a verification failure, the process ends; if the verification result is a verification success, the enterprise client uses the ECDHE algorithm to call the temporary private key EphemeralPrivateKey_C and the temporary public key EphemeralPublicKey_S to calculate the shared key SharedSecret_C; the server uses the ECDHE algorithm to call the temporary private key EphemeralPrivateKey_S and the temporary public key EphemeralPublicKey_C to calculate the shared key SharedSecret_S, where the shared key SharedSecret_C and the shared key SharedSecret_S are the same key. The enterprise client derives a session key from the shared key SharedSecret_C, the random number Nonce_C, and the random number Nonce_S using KDF functions; the server derives a session key from the shared key SharedSecret_S, the random number Nonce_C, and the random number Nonce_S using KDF functions. Step S37: The server records the authentication log in real time. After authentication, it obtains the current timestamp T2, calculates the hash value H1 of the authentication log and timestamp T2 using the SM3 algorithm, calculates the hash value H2 of timestamp T2 using the SM3 algorithm, selects 8 bits starting from the 6th bit of the hash value H2 as the dynamic key K1, calls the dynamic key K1 using the ChaCha20 algorithm to encrypt the authentication log and hash value H1 into first-level encrypted data, encrypts the first-level encrypted data and timestamp T2 into authentication ciphertext log using the SM9 algorithm, stores the authentication ciphertext log in the specified path, calculates the first log fingerprint of the authentication ciphertext log using the hash256 algorithm and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain, which carries at least the evidence number, evidence time, evidence subject information, data information, blockchain information and signature information, for subsequent authentication and traceability. Step S40 specifically involves: The enterprise client obtains the input authentication consultation content, uses the AES algorithm to call the session key to encrypt the authentication consultation content into consultation ciphertext, obtains the current timestamp T1 as the request time, calculates the hash value H3 of the consultation ciphertext and the request time using the SM3 algorithm, and encrypts the consultation ciphertext, the request time, and the hash value H3 into an encrypted string using the RC6 algorithm. Based on the encrypted string, an authentication consultation request is generated and sent to the server via the SSL protocol.

5. The blockchain-based authentication and consultation method as described in claim 1, characterized in that: Step S50 specifically involves: The server receives the authentication consultation request in real time, parses the request to obtain an encrypted string, decrypts the encrypted string using the RC6 algorithm to obtain the consultation ciphertext, request time, and hash value H3, performs integrity verification on the consultation ciphertext and request time using the hash value H3, performs timeliness verification using the request time, and then uses the AES algorithm to call the session key to decrypt the consultation ciphertext to obtain the authentication consultation content. The server uses a streaming engine to perform anonymization and data desensitization on the enterprise information carried by the enterprise status data in the authentication consultation content to obtain desensitized consultation content. The desensitized consultation content is input into the deployed authentication consultation decision model for reasoning to obtain real-time consultation results including a compliance suggestion report and an authentication execution path diagram, and the plaintext authentication consultation content is deleted simultaneously. Step S60 specifically involves: The server records in real time a consultation log that includes at least authentication consultation requests, real-time consultation results, client information, and authentication feedback, wherein the authentication feedback is authentication success, authentication failure, or no authentication. The server obtains the current timestamp T3, calculates the hash value H4 of the consultation log and timestamp T3 using the SM3 algorithm, calculates the hash value H5 of timestamp T3 using the SM3 algorithm, selects 8 bits starting from the 7th bit of the hash value H5 as the dynamic key K2, calls the dynamic key K2 using the ChaCha20 algorithm to encrypt the consultation log and hash value H4 into a layer of encrypted data, encrypts the layer of encrypted data and timestamp T3 into a consultation ciphertext log using the 3DES algorithm, stores the consultation ciphertext log in a specified path, calculates the second log fingerprint of the consultation ciphertext log using the hash256 algorithm and uploads it to the blockchain, obtains and stores the second evidence certificate fed back by the blockchain, which carries at least the evidence number, evidence time, evidence subject information, data information, blockchain information and signature information, for subsequent consultation tracing; Step S70 specifically involves: The server concatenates the real-time consultation result and the second certificate of authenticity into concatenated data, obtains the current timestamp T4, calculates the hash value H6 of the concatenated data and timestamp T4 using the SM3 algorithm, uses the first 1 / 3 of the hash value H6 as the dynamic key K3, the middle 1 / 3 as the dynamic key K4, and the last 1 / 3 as the dynamic key K5, and divides the concatenated data into a first data block, a second data block, and a third data block. The server uses the AES algorithm to encrypt the first data block using the dynamic key K3 to obtain the first encrypted data block, uses the AES algorithm to encrypt the second data block using the dynamic key K4 to obtain the second encrypted data block, and uses the AES algorithm to encrypt the third data block using the dynamic key K5 to obtain the third encrypted data block. The server then uses the session key to encrypt the first encrypted data block, the second encrypted data block, the third encrypted data block, the timestamp T4, and the hash value H6 into a consultation feedback encrypted packet, which is then sent back to the enterprise client in real time via the SSL protocol. The enterprise client receives and stores the consultation feedback encrypted package in real time, decrypts and verifies the consultation feedback encrypted package to obtain the real-time consultation result and the second evidence certificate, and displays the real-time consultation result and the second evidence certificate through the consultation interface. Step S80 specifically involves: When the number of consultation logs reaches a preset threshold, the server constructs an incremental dataset based on each consultation log. During the idle period of the certification consultation decision model, the deployed certification consultation decision model is trained using the incremental dataset and then iteratively optimized. The server creates a monitoring agent, sets the monitoring parameters of the monitoring agent, monitors the latest certification standard file through the monitoring agent, preprocesses the latest certification standard file, and then integrates the latest certification standard file into the dynamic decision knowledge graph through a second graph neural network to dynamically update the dynamic decision knowledge graph; the monitoring parameters include at least the monitoring period, monitoring source, and access permissions.

6. A blockchain-based authentication and consultation system, characterized in that: Includes the following modules: The initialization module is used to obtain a large amount of historical certification consultation data and historical certification standard files from the server, preprocess the historical certification consultation data and historical certification standard files, annotate the preprocessed historical certification consultation data to construct a consultation dataset, and construct a dynamic decision knowledge graph based on the preprocessed historical certification standard files. The certification consultation decision model training module is used by the server to create a certification consultation decision model that calls the dynamic decision knowledge graph to provide certification consultation services, set the loss function of the certification consultation decision model, train the certification consultation decision model through the consultation dataset and the loss function, and deploy the trained certification consultation decision model. The two-way authentication module is used for enterprise clients and servers to perform two-way authentication and negotiate session keys. The server records authentication logs, encrypts the authentication logs into authentication ciphertext logs and stores them, calculates the first log fingerprint of the authentication ciphertext logs and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain, and uses it for subsequent authentication and traceability. The authentication consultation request sending module is used by the enterprise client to obtain the input authentication consultation content, encrypt the authentication consultation content into consultation ciphertext using the session key, obtain the current timestamp T1 as the request time, generate an authentication consultation request based on the consultation ciphertext and the request time, and send the authentication consultation request to the server. The real-time consultation result generation module is used by the server to verify and parse the received certification consultation request to obtain certification consultation content, de-identify the certification consultation content to obtain de-identified consultation content, input the de-identified consultation content into the deployed certification consultation decision model for reasoning, obtain real-time consultation results including compliance suggestion reports and certification execution path diagrams, and delete the plaintext certification consultation content. The consultation log management module is used to record consultation logs in real time on the server, encrypt the consultation logs into ciphertext logs and store them, calculate the second log fingerprint of the ciphertext logs and upload it to the blockchain, obtain and store the second evidence certificate fed back by the blockchain for subsequent consultation tracing. The result feedback module is used by the server to encrypt the real-time consultation result and the second evidence certificate into a consultation feedback encrypted package using the session key, and then feed the consultation feedback encrypted package back to the enterprise client in real time. The iterative optimization module is used by the server to iteratively optimize the deployed authentication consultation decision model based on the consultation logs and dynamically update the dynamic decision knowledge graph.

7. The blockchain-based authentication and consultation system as described in claim 6, characterized in that: The initialization module is specifically used for: The server acquires a large amount of historical certification consultation data and historical certification standard documents; the historical certification consultation data includes at least certification consultation content, compliance recommendation reports, and certification execution path diagrams; the certification consultation content includes at least consultation requests and current enterprise data; the historical certification standard documents include at least core standard documents, supporting documents, certification process documents, certification body documents, and certification standard interpretation documents. The historical certified consultation data shall undergo preprocessing including at least data cleaning, data formatting, data classification, and tagging; the data cleaning shall at least include removing duplicate data, handling missing values, and correcting erroneous data; the data formatting shall at least include unifying text format and standardizing data structure; the data classification and tagging shall at least include consultation type classification and adding tags. The historical authentication standard documents are preprocessed in at least the following ways: document organization and classification, text content extraction and cleaning, and key information annotation and association. The document organization and classification includes at least physical organization and index creation. The text content extraction and cleaning includes at least text extraction and text format cleaning. The key information annotation and association includes at least annotation of key information and establishment of document associations. In the preprocessed historical certification consultation data, the certification consultation content, compliance suggestion report and certification execution path diagram are associated and labeled with consultation result tags. Based on the labeled historical certification consultation data, a consultation dataset is constructed. The enterprise information carried by the enterprise status data in the consultation dataset is anonymized and desensitized. The consultation result is tagged as successful authentication, failed authentication, or unauthenticated. Entities are extracted from the pre-processed historical authentication standard files using a pre-trained BiLSTM-CRF model. Relationships between the entities are inferred using the TransE algorithm. A dynamic decision knowledge graph is then constructed based on the entities and their relationships.

8. The blockchain-based authentication and consultation system as described in claim 6, characterized in that: The certification consulting decision model training module is specifically used for: The server creates an authentication consultation decision model based on an input parsing layer, a knowledge graph retrieval layer, a feature fusion layer, a decision generation layer, and an output transformation layer, and sets the loss function of the authentication consultation decision model. The input parsing layer is constructed based on a bidirectional LSTM module, an enterprise status encoding module, and a vector concatenation module. The bidirectional LSTM module is used to extract text feature vectors from consultation requests; the enterprise status encoding module is used to extract numerical feature vectors from enterprise status data through a fully connected layer; and the vector concatenation module is used to concatenate the text feature vectors and numerical feature vectors into a preliminary feature vector. The knowledge graph retrieval layer is constructed based on a graph embedding module and a graph attention retrieval module; the graph embedding module is used to encode the dynamic decision knowledge graph into node embeddings through a graph convolutional network; the graph attention retrieval module is used to retrieve enhanced feature vectors related to the initial feature vectors from each of the node embeddings through a multi-head attention mechanism; The feature fusion layer is constructed based on a feature concatenation module and a self-attention fusion module. The feature concatenation module is used to concatenate the initial feature vector and the enhanced feature vector into a unified feature vector. The self-attention fusion module is used to perform weighted fusion of key features in the unified feature vector through a transformer-based self-attention mechanism to obtain fused features. The decision generation layer is constructed based on a suggestion generation module and a path graph generation module; the suggestion generation module is used to infer compliance suggestion reports by using a seq2seq model to analyze the fused features; the path graph generation module is used to decode the fused features by using a first graph neural network to obtain an authentication execution path graph. The output conversion layer is built based on a text formatting module and a graph rendering module; The text formatting module is used to convert compliance recommendation reports into formal report formats through a softmax layer and a template engine; the graph rendering module is used to convert the certification execution path graph into a visual graph representation through a tree decoder. The formula for the loss function is: L total =α·L report +β·L path +γ·L reg ; Among them, L total L represents the loss value of the loss function; report The sequence loss of the compliance recommendation report is represented by cross-entropy loss; L path The graph structure loss representing the authentication execution path graph is represented by the graph edit distance loss; L reg α represents the regularization term, including L2 regularization and dropout noise regularization; α, β, and γ all represent weight coefficients. After performing sample augmentation on the consultation dataset based on the consultation category, the consultation dataset is divided into a training set, a validation set, and a test set in a ratio of 8:1:

1. The certification consultation decision model is trained using the training set and the loss function. During the training process, the hyperparameters of the certification consultation decision model are continuously optimized, including at least the learning rate, learning warm-up rate, learning decay rate, random dropout rate, batch size, and number of hidden layers, until the loss value of the loss function is less than the preset loss threshold or the preset early stopping condition is met. The training set is used to calculate the accuracy of consultation results, inference latency, completeness of compliance recommendation report content, completeness of certification execution path rendering, and retrieval relevance of dynamic decision knowledge graph to validate the trained certification consultation decision model. If the validation fails, the training set is expanded and training continues; if the validation passes, then: The test set is used to calculate task completion efficiency, actual path deviation rate, noise tolerance, resource consumption, and maximum processing request rate to test the verified certification consultation decision model. If the test fails, the training set is expanded and training continues; if the test passes, training ends and the certified consultation decision model that has passed the test is deployed.

9. A blockchain-based authentication and consultation system as described in claim 6, characterized in that: The two-way authentication module specifically includes: The certificate initialization unit is used by the enterprise client to preset a certificate Cert_C carrying a long-term public key PublicKey_C, a long-term private key PrivateKey_C matching the long-term public key PublicKey_C, and a CA root certificate through the CA center. The server pre-sets a certificate Cert_S carrying a long-term public key PublicKey_S, a long-term private key PrivateKey_S matching the long-term public key PublicKey_S, and a CA root certificate through the CA center. The CA root certificate is used to verify the validity of certificates Cert_C and Cert_S; The first authentication request sending unit is used to generate a random number Nonce_C by the enterprise client, generate a first authentication request based on the list of cipher suites supported by the local machine and the random number Nonce_C, and send it to the server. The second authentication request sending unit is used by the server to parse the received first authentication request to obtain a list of cipher suites and a random number Nonce_C, select a cipher suite from the list of cipher suites, generate a random number Nonce_S, create a pair of temporary public keys EphemeralPublicKey_S and temporary private keys EphemeralPrivateKey_S based on the ECDHE algorithm in the cipher suite, and sign the random number Nonce_C, the random number Nonce_S, and the temporary public key EphemeralPublicKey_S with the long-term private key PrivateKey_S to obtain the server signature Sig_S. The server generates a second authentication request based on the cipher suite, the random number Nonce_S, the certificate Cert_S, the temporary public key EphemeralPublicKey_S, and the server signature Sig_S, and sends it to the enterprise client. The third authentication request sending unit is used by the enterprise client to parse the received second authentication request to obtain the cipher suite, random number Nonce_S, certificate Cert_S, temporary public key EphemeralPublicKey_S and server signature Sig_S; The enterprise client verifies the certificate Cert_S using the CA root certificate, and verifies the server signature Sig_S using the long-term public key PublicKey_S carried by the certificate Cert_S. Upon successful verification: The enterprise client creates a pair of temporary public keys EphemeralPublicKey_C and temporary private keys EphemeralPrivateKey_C based on the ECDHE algorithm in the cryptographic suite. The client then uses the long-term private key PrivateKey_C to sign the random number Nonce_C, the random number Nonce_S, and the temporary public key EphemeralPublicKey_C to obtain the client signature Sig_C. The enterprise client generates a third authentication request based on the certificate Cert_C, the temporary public key EphemeralPublicKey_C, and the client signature Sig_C, and sends it to the server. The verification result sending unit is used by the server to parse the received third authentication request to obtain the certificate Cert_C, the temporary public key EphemeralPublicKey_C, and the client signature Sig_C; The server verifies the certificate Cert_C using the CA root certificate, verifies the client signature Sig_C using the public key PublicKey_C carried by the certificate Cert_C, and sends a verification result to the enterprise client indicating whether the verification was successful or failed. The session key derivation unit is used to terminate the process when the verification result is a verification failure; when the verification result is a verification success, the enterprise client uses the ECDHE algorithm to call the temporary private key EphemeralPrivateKey_C and the temporary public key EphemeralPublicKey_S to calculate the shared key SharedSecret_C; the server uses the ECDHE algorithm to call the temporary private key EphemeralPrivateKey_S and the temporary public key EphemeralPublicKey_C to calculate the shared key SharedSecret_S, where the shared key SharedSecret_C and the shared key SharedSecret_S are the same key; The enterprise client derives a session key from the shared key SharedSecret_C, the random number Nonce_C, and the random number Nonce_S using KDF functions; the server derives a session key from the shared key SharedSecret_S, the random number Nonce_C, and the random number Nonce_S using KDF functions. The authentication log management unit is used by the server to record authentication logs in real time. After authentication, it obtains the current timestamp T2, calculates the hash value H1 of the authentication log and timestamp T2 using the SM3 algorithm, calculates the hash value H2 of timestamp T2 using the SM3 algorithm, selects 8 bits starting from the 6th bit of the hash value H2 as the dynamic key K1, calls the dynamic key K1 using the ChaCha20 algorithm to encrypt the authentication log and hash value H1 into first-level encrypted data, encrypts the first-level encrypted data and timestamp T2 into authentication ciphertext log using the SM9 algorithm, stores the authentication ciphertext log in a designated path, calculates the first log fingerprint of the authentication ciphertext log using the hash256 algorithm and uploads it to the blockchain, obtains and stores the first evidence certificate fed back by the blockchain, which carries at least the evidence number, evidence time, evidence subject information, data information, blockchain information and signature information, for subsequent authentication and traceability. The authentication inquiry request sending module is specifically used for: The enterprise client obtains the input authentication consultation content, uses the AES algorithm to call the session key to encrypt the authentication consultation content into consultation ciphertext, obtains the current timestamp T1 as the request time, calculates the hash value H3 of the consultation ciphertext and the request time using the SM3 algorithm, and encrypts the consultation ciphertext, the request time, and the hash value H3 into an encrypted string using the RC6 algorithm. Based on the encrypted string, an authentication consultation request is generated and sent to the server via the SSL protocol.

10. A blockchain-based authentication and consultation system as described in claim 6, characterized in that: The real-time consultation result generation module is specifically used for: The server receives the authentication consultation request in real time, parses the request to obtain an encrypted string, decrypts the encrypted string using the RC6 algorithm to obtain the consultation ciphertext, request time, and hash value H3, performs integrity verification on the consultation ciphertext and request time using the hash value H3, performs timeliness verification using the request time, and then uses the AES algorithm to call the session key to decrypt the consultation ciphertext to obtain the authentication consultation content. The server uses a streaming engine to perform anonymization and data desensitization on the enterprise information carried by the enterprise status data in the authentication consultation content to obtain desensitized consultation content. The desensitized consultation content is input into the deployed authentication consultation decision model for reasoning to obtain real-time consultation results including a compliance suggestion report and an authentication execution path diagram, and the plaintext authentication consultation content is deleted simultaneously. The consultation log management module is specifically used for: The server records in real time a consultation log that includes at least authentication consultation requests, real-time consultation results, client information, and authentication feedback, wherein the authentication feedback is authentication success, authentication failure, or no authentication. The server obtains the current timestamp T3, calculates the hash value H4 of the consultation log and timestamp T3 using the SM3 algorithm, calculates the hash value H5 of timestamp T3 using the SM3 algorithm, selects 8 bits starting from the 7th bit of the hash value H5 as the dynamic key K2, calls the dynamic key K2 using the ChaCha20 algorithm to encrypt the consultation log and hash value H4 into a layer of encrypted data, encrypts the layer of encrypted data and timestamp T3 into a consultation ciphertext log using the 3DES algorithm, stores the consultation ciphertext log in a specified path, calculates the second log fingerprint of the consultation ciphertext log using the hash256 algorithm and uploads it to the blockchain, obtains and stores the second evidence certificate fed back by the blockchain, which carries at least the evidence number, evidence time, evidence subject information, data information, blockchain information and signature information, for subsequent consultation tracing; The result feedback module is specifically used for: The server concatenates the real-time consultation result and the second certificate of authenticity into concatenated data, obtains the current timestamp T4, calculates the hash value H6 of the concatenated data and timestamp T4 using the SM3 algorithm, uses the first 1 / 3 of the hash value H6 as the dynamic key K3, the middle 1 / 3 as the dynamic key K4, and the last 1 / 3 as the dynamic key K5, and divides the concatenated data into a first data block, a second data block, and a third data block. The server uses the AES algorithm to encrypt the first data block using the dynamic key K3 to obtain the first encrypted data block, uses the AES algorithm to encrypt the second data block using the dynamic key K4 to obtain the second encrypted data block, and uses the AES algorithm to encrypt the third data block using the dynamic key K5 to obtain the third encrypted data block. The server then uses the session key to encrypt the first encrypted data block, the second encrypted data block, the third encrypted data block, the timestamp T4, and the hash value H6 into a consultation feedback encrypted packet, which is then sent back to the enterprise client in real time via the SSL protocol. The enterprise client receives and stores the consultation feedback encrypted package in real time, decrypts and verifies the consultation feedback encrypted package to obtain the real-time consultation result and the second evidence certificate, and displays the real-time consultation result and the second evidence certificate through the consultation interface. The iterative optimization module is specifically used for: When the number of consultation logs reaches a preset threshold, the server constructs an incremental dataset based on each consultation log. During the idle period of the certification consultation decision model, the deployed certification consultation decision model is trained using the incremental dataset and then iteratively optimized. The server creates a monitoring agent, sets the monitoring parameters of the monitoring agent, monitors the latest certification standard file through the monitoring agent, preprocesses the latest certification standard file, and then integrates the latest certification standard file into the dynamic decision knowledge graph through a second graph neural network to dynamically update the dynamic decision knowledge graph; the monitoring parameters include at least the monitoring period, monitoring source, and access permissions.

Citation Information

Patent Citations

  • Commodity tracing method and system for cross-border logistics

    CN119359320A

  • Intelligent assistant system and method based on AI technology

    CN119443292A