Electronic component security authentication method and system

By acquiring and parsing the operational correlation information of electronic components in the gas station monitoring and tax evasion prevention system, a security attribute priority list is generated and multi-dimensional compliance verification is performed. This addresses the shortcomings of existing electronic component certification methods, enables comprehensive security assessment and compliance verification of electronic components, and improves the security and reliability of the system.

CN120974506BActive Publication Date: 2026-05-29YIHENG IOT TECHNOLOGY (GUANGZHOU) CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
YIHENG IOT TECHNOLOGY (GUANGZHOU) CO LTD
Filing Date
2025-08-08
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing electronic component certification methods lack systematic security attribute analysis and multi-dimensional compliance verification in gas station tax evasion monitoring systems. They cannot comprehensively assess the security attribute priority of electronic components, making it difficult to accurately determine whether there is a risk of tax evasion and thus failing to effectively ensure the safe operation of the system.

Method used

The system acquires the set of operational association information of the electronic components to be certified in the gas station monitoring and tax evasion prevention system, including device identification information, data collection rule information, and system interaction relationship information. It performs security attribute parsing and processing, generates a security attribute priority list, and conducts multi-dimensional compliance verification based on the preset tax evasion prevention security verification specifications. It generates a set of compliance verification results and finally generates a security certification conclusion.

Benefits of technology

By comprehensively covering the safety attributes of electronic components, ensuring their compliance with tax evasion monitoring requirements, the safety and reliability of the gas station tax evasion monitoring system are improved, enabling accurate determination of whether electronic components meet safe operation requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120974506B_ABST
    Figure CN120974506B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of electronic component security authentication method and system, first, the running associated information set of electronic component to be authenticated is acquired, including equipment identification information, data acquisition rule information and system interaction relationship information, then the security attribute analysis is carried out to the running associated information set, obtain security attribute priority list, then based on the preset tax leakage security verification specification, the multidimensional compliance verification is executed to security attribute priority list, and compliance verification result set is generated, then the tax leakage risk correlation analysis is carried out to compliance verification result set, obtain security authentication evaluation data, finally, according to security authentication evaluation data, security authentication conclusion is generated, indicate whether electronic component meets system security operation requirement, from which the security and reliability of gas station tax leakage monitoring system can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and more specifically, to a method and system for security authentication of electronic components. Background Technology

[0002] In gas station tax evasion monitoring systems, the security and compliance of electronic components are crucial, directly affecting the accurate and reliable operation of the entire system and thus ensuring the legitimate collection of taxes. However, existing electronic component certification methods have many shortcomings.

[0003] On the one hand, traditional authentication methods often only focus on whether the basic functions of electronic components are normal, lacking a comprehensive consideration of their operational information in the specific scenario of tax evasion prevention monitoring at gas stations. For example, they do not give sufficient attention to whether the device identification information of electronic components is unique and traceable, whether the data collection rules meet the accuracy requirements of tax evasion prevention monitoring, and whether the system interaction information is stable and secure.

[0004] On the other hand, existing certification processes lack systematic security attribute analysis and multi-dimensional compliance verification. They typically only perform simple functional tests, failing to deeply analyze the security attribute priorities of electronic components or conduct comprehensive assessments based on stringent anti-tax evasion security verification standards. This makes it difficult to accurately determine whether electronic components pose a tax evasion risk, and thus cannot effectively ensure the safe operation of gas station tax evasion monitoring systems. Summary of the Invention

[0005] In view of this, the purpose of this application is to provide a method and system for security authentication of electronic components.

[0006] According to a first aspect of this application, a method for security authentication of electronic components is provided, the method comprising:

[0007] Obtain the set of operational association information for the electronic components to be certified in the gas station monitoring and tax evasion prevention system. The set of operational association information includes the device identification information, data acquisition rule information, and system interaction relationship information of the electronic components.

[0008] The security attribute parsing process is performed on the set of operational association information to obtain a security attribute priority list of the electronic component;

[0009] Based on the preset anti-tax evasion security verification specifications, multi-dimensional compliance verification processing is performed on the priority list of security attributes to generate a set of compliance verification results;

[0010] The compliance verification result set is subjected to a tax evasion risk correlation analysis to obtain the security certification assessment data of the electronic component;

[0011] The safety certification conclusion of the electronic component is generated based on the safety certification assessment data. The safety certification conclusion is used to indicate whether the electronic component meets the safety operation requirements of the gas station tax evasion monitoring system.

[0012] According to a second aspect of this application, an electronic component security authentication system is provided, the electronic component security authentication system including a processor and a readable storage medium storing a program that, when executed by the processor, implements the aforementioned electronic component security authentication method.

[0013] Based on any of the above aspects, by acquiring the operational association information set of the electronic components to be certified in the gas station tax evasion monitoring system, which comprehensively covers equipment identification information, data collection rule information, and system interaction relationship information, the operational association information set is processed for security attribute parsing to generate a security attribute priority list. This clearly identifies the importance of each security attribute of the electronic component. Based on the preset tax evasion security verification specifications, multi-dimensional compliance verification processing is performed on the security attribute priority list to generate a compliance verification result set. This rigorously examines the security of the electronic component from multiple perspectives to ensure it meets the requirements of tax evasion monitoring. Tax evasion risk correlation analysis is then performed on the compliance verification result set to obtain security certification assessment data, which can deeply explore potential tax evasion risks of the electronic component. Finally, a security certification conclusion is generated based on the security certification assessment data, accurately indicating whether the electronic component meets the safe operation requirements of the gas station tax evasion monitoring system, effectively improving the security and reliability of the gas station tax evasion monitoring system. Attached Figure Description

[0014] Figure 1 A flowchart illustrating the electronic component security authentication method provided in an embodiment of this application is shown;

[0015] Figure 2 A schematic diagram of the component structure of the electronic component security authentication system provided in an embodiment of this application is shown. Detailed Implementation

[0016] Figure 1 The diagram illustrates a flowchart of an electronic component security authentication method provided in an embodiment of this application. It should be understood that in other embodiments, the order of some steps in the electronic component security authentication method may be interchanged according to actual needs, or some steps may be omitted or deleted. The detailed steps of the electronic component security authentication method are described below.

[0017] Step S110: Obtain the set of operational association information of the electronic components to be certified in the gas station monitoring and tax prevention system. The set of operational association information includes the device identification information, data collection rule information and system interaction relationship information of the electronic components.

[0018] In the practical scenario of a gas station tax evasion monitoring system, the electronic component to be certified can be considered a crucial part of the gas station for data collection, transmission, and processing, such as the data acquisition and transmission module inside the fuel dispenser. This module is responsible for collecting various key data during the refueling process, such as the amount of fuel dispensed, fuel type, and transaction time. It also needs to interact with the tax supervision platform and the gas station management system. To comprehensively understand the operation of this electronic component and ensure it meets the security requirements of the tax evasion monitoring system, it is necessary to obtain its operational association information set. This set covers multiple aspects, including device identification information to uniquely identify the electronic component, data acquisition rule information specifying the data acquisition method and frequency, and system interaction relationship information describing the connection and data transmission methods between the electronic component and other systems.

[0019] Step S111: Read the unique code consisting of the manufacturer code, component type code and batch serial number from the hardware identifier storage area of ​​the electronic component as the device identification information.

[0020] The hardware identifier storage area for electronic components is a specific storage location determined by the hardware design, typically located on the component's motherboard or within a specific chip. Taking the data acquisition and transmission module of a fuel dispenser as an example, its hardware identifier storage area might be a dedicated memory chip on the motherboard for storing device identifiers. When retrieving device identifier information, a read command needs to be sent to this storage area via a specific hardware interface and communication protocol. The manufacturer code is a unique code set by the manufacturer to distinguish different manufacturers, reflecting the origin of the electronic component's production. The component type code specifies the exact type of the electronic component, such as whether it's a sensor for fuel volume acquisition or a communication module for data transmission. The batch serial number distinguishes different production batches of the same type of electronic component from the same manufacturer, helping to trace the component's production time and batch information. By reading the unique code composed of these three codes, the electronic component can be accurately identified.

[0021] Step S112: Extract the trigger conditions, parameter types, and frequency settings for the logic of collecting fuel volume, fuel type, and transaction time from the software configuration file of the electronic component as data collection rule information.

[0022] Step S1121: Determine the storage path of the software configuration file of the electronic component, wherein the storage path is defined by the operating system directory structure of the electronic component.

[0023] The directory structure of an electronic component's operating system defines how its software system is organized. Different electronic components may use different operating systems, thus the storage path of their software configuration files will also differ. For the data acquisition and transmission module of a fuel dispenser, the storage path of its software configuration files may be based on the directory structure of a specific embedded operating system. For example, the operating system may use a hierarchical directory structure, and the software configuration files may be stored in a specific configuration directory. By analyzing the operating system documentation of the electronic component or using specific system commands, the specific storage path of the software configuration files can be determined.

[0024] Step S1122: Read the original data content of the software configuration file through the debugging interface of the electronic component. The original data content contains a list of configuration parameters in text format.

[0025] The debugging interface for electronic components is used for communication and debugging with external devices. It typically employs a pre-defined communication protocol, such as serial communication or USB communication. Through this debugging interface, commands to read software configuration files can be sent to the electronic component. In the data acquisition and transmission module of a fuel dispenser, the debugging interface may be a serial port located on the device's casing. After sending the read command, the electronic component will transmit the raw data content of the software configuration file in text format. This raw data content contains a series of configuration parameters, such as acquisition trigger conditions, acquisition parameter types, and acquisition frequency settings.

[0026] Step S1123: Perform syntax parsing on the original data content to identify the acquisition trigger condition field, acquisition parameter type field, and acquisition frequency setting field.

[0027] After obtaining the raw data content of the software configuration file, it needs to be parsed. This is because the raw data content is usually written according to set syntax rules and may contain comments, delimiters, and other information. Parsing allows the individual fields in the raw data content to be separated. For example, in the software configuration file of the data acquisition and transmission module of a fuel dispenser, the acquisition trigger condition field might be identified by a set keyword, such as "TriggerCondition," the acquisition parameter type field might be identified by "ParameterType," and the acquisition frequency setting field might be identified by "FrequencySetting." By parsing these fields, the trigger conditions, parameter types, and frequency settings for data acquisition can be clearly identified.

[0028] Step S1124: Extract the trigger event type information from the collection trigger condition field, including refueling nozzle operation events and timed trigger events.

[0029] The data collection trigger condition field contains information about the type of event that triggers the data collection. In a gas station scenario, common trigger event types include fuel nozzle operation events and timed trigger events. Fuel nozzle operation events refer to data collection triggered when the fuel nozzle is inserted, removed, turned on, or turned off. For example, when the fuel nozzle is removed from the pump, it triggers the collection of the refueling volume and fuel type. Timed trigger events collect data at preset time intervals, such as collecting transaction time information at set intervals. By analyzing the data collection trigger condition field, this trigger event type information can be extracted.

[0030] Step S1125: Extract the collection parameter name information from the collection parameter type field. The collection parameter name information includes the refueling volume parameter, the oil type parameter, and the transaction time parameter.

[0031] The parameter type field clearly defines the types of data parameters to be collected. In the gas station monitoring and tax evasion prevention system, the main parameter names include refueling quantity parameter, fuel type parameter, and transaction time parameter. The refueling quantity parameter reflects the specific quantity refueled each time, the fuel type parameter specifies the type of fuel added, such as gasoline or diesel, and the transaction time parameter records the specific time the refueling transaction occurred. By extracting the parameter type field, these parameter name information can be obtained.

[0032] Step S1126: Extract the time interval information of the timed trigger event from the acquisition frequency setting field. The time interval information is used to define the active acquisition cycle when the event is not triggered.

[0033] The data acquisition frequency setting field contains information about the time interval for timed trigger events. This time interval determines the frequency at which the electronic components actively acquire data when there are no events such as fuel nozzle operation. For example, in the data acquisition and transmission module of a fuel dispenser, the time interval for timed trigger events might be set to acquire transaction time information every set period to ensure accurate recording of transaction times. This time interval information can be obtained by extracting it from the data acquisition frequency setting field.

[0034] Step S1127: Perform logical consistency verification on the trigger event type information, collection parameter name information and time interval information, check whether the time interval of the timed trigger event is compatible with the collection frequency of the event trigger. If compatible, output the data collection rule information. If incompatible, mark the data collection rule information as abnormal information and record the specific incompatible parameters.

[0035] After obtaining the trigger event type information, collection parameter name information, and time interval information, they need to be logically consistent. This is to ensure the rationality and effectiveness of the data collection rules. For example, it is necessary to check whether the time interval of the timed trigger event is compatible with the collection frequency of events such as refueling nozzle operation. If the time interval of the timed trigger event is too short, but the event trigger collection frequency is high, it may lead to excessively frequent data collection, increasing the system load; conversely, if the time interval is too long, it may lead to untimely data collection. When the verification result shows compatibility, this information is integrated as the data collection rule information output; if incompatible, the data collection rule information is marked as abnormal information, and the specific incompatible parameters, such as the time interval of the timed trigger event and the event trigger collection frequency, are recorded for subsequent adjustments and optimizations.

[0036] Step S113: Obtain the connection interface type, communication protocol version, and data interaction format information with the tax supervision platform, gas station management system, and fuel dispenser control module from the communication protocol stack configuration module of the electronic component as system interaction relationship information.

[0037] The communication protocol stack configuration module of the electronic component is responsible for managing and configuring the communication between the electronic component and other systems. In a gas station monitoring and tax evasion prevention system, the electronic component needs to interact with the tax supervision platform, the gas station management system, and the fuel dispenser control module. Taking the fuel dispenser's data acquisition and transmission module as an example, its communication protocol stack configuration module may be located in the device's software system. Through this module, the connection interface type with other systems can be obtained, such as Ethernet interface, serial port interface, etc.; the communication protocol version, such as a specific version of the HTTP protocol, a specific version of the TCP / IP protocol, etc.; and the data interaction format information, such as whether the data is transmitted in JSON format, XML format, or other custom format. This information reflects the communication method and data interaction rules between the electronic component and other systems.

[0038] Step S114: Convert the device identification information, data acquisition rule information and system interaction relationship information into a set of operation association information with a unified field structure.

[0039] After obtaining device identification information, data acquisition rule information, and system interaction relationship information, these information may come from different data sources, and their formats and structures may be inconsistent. Therefore, it is necessary to convert them into a set of operational association information with a unified field structure. For example, a unified field structure can be defined, mapping the manufacturer code, component type code, and batch serial number in the device identification information to specific fields in the unified structure; the acquisition trigger conditions, acquisition parameter types, and acquisition frequency settings in the data acquisition rule information should also be organized according to a unified format; and the connection interface type, communication protocol version, and data interaction format information in the system interaction relationship information should also be mapped and organized. In this way, information from different sources can be integrated into a unified set of operational association information, facilitating subsequent processing and analysis.

[0040] Step S115: Perform integrity verification on the set of operation-related information to verify whether the device identification information contains complete components, whether the data acquisition rule information covers all preset acquisition parameters, and whether the system interaction relationship information clarifies the interaction specifications of all connected objects. If there are missing or unclear items, the information completion process is triggered. If the verification passes, the set of operation-related information is output.

[0041] The integrity verification of the runtime-related information set is to ensure that it contains all necessary information. For device identification information, it is necessary to verify whether it contains complete components such as the manufacturer code, component type code, and batch serial number. The absence of any of these elements may result in inaccurate identification of electronic components. For data collection rule information, it is necessary to check whether all preset collection parameters are covered, such as refueling volume, fuel type, and transaction time. Omissions may result in some data not being collected. For system interaction relationship information, it is necessary to verify whether the interaction specifications with all connected objects, such as the tax supervision platform, gas station management system, and fuel dispenser control module, are clearly defined, including connection interface type, communication protocol version, and data interaction format. When missing or unclear items are found during the verification process, an information completion process is triggered, for example, by querying the electronic component manufacturer or relevant management departments to obtain the missing information. If the verification passes, the runtime-related information set is output as the final result for subsequent security attribute parsing processing.

[0042] Step S120: Perform security attribute parsing processing on the set of operation-related information to obtain a security attribute priority list of the electronic component.

[0043] After obtaining the set of operational correlation information, it is necessary to perform security attribute parsing to determine the priority list of security attributes for electronic components. This is because in a gas station monitoring and tax evasion prevention system, different security attributes have varying degrees of importance in preventing tax evasion and ensuring the safe operation of the system. By parsing the set of operational correlation information, security attributes related to tax evasion risks can be identified and prioritized.

[0044] Step S121: Parse the data collection rule information in the operation association information set, and extract information reflecting the accuracy of refueling volume measurement, the reliability of oil type identification, and the consistency of transaction time synchronization as the collection accuracy attribute.

[0045] The data collection rule information includes information related to data collection accuracy. By parsing this information, data reflecting the accuracy of fuel volume measurement, the reliability of fuel type identification, and the consistency of transaction time synchronization can be extracted. For example, the collection rule information of the fuel dispenser's data collection and transmission module may include the error range of fuel volume measurement, the accuracy rate of fuel type identification, and the deviation in transaction time synchronization. Fuel volume measurement accuracy reflects the accuracy of the electronic components in measuring fuel volume; fuel type identification reliability reflects the electronic components' ability to correctly identify fuel types; and transaction time synchronization consistency indicates the degree of consistency between the transaction time recorded by the electronic components and the actual transaction time. Integrating this information serves as the data collection accuracy attribute, used to evaluate the accuracy of the electronic components in data collection.

[0046] Step S122: Analyze the system interaction relationship information in the set of running related information, and extract information reflecting the data transmission encryption method, verification mechanism and retransmission strategy as transmission integrity attributes.

[0047] System interaction information reflects the methods and rules by which electronic components interact with other systems. Analyzing this information reveals details about data transmission encryption methods, verification mechanisms, and retransmission strategies. For example, when the data acquisition and transmission module of a fuel dispenser transmits data to a tax supervision platform, the system interaction information may include the encryption algorithm used, the data verification method, and the data retransmission strategy. Data transmission encryption protects data security during transmission, preventing theft or tampering; verification mechanisms detect errors or alterations during transmission; and retransmission strategies ensure data integrity by retransmitting data in case of transmission failure. This information is used as transmission integrity attributes to assess the integrity of electronic components in data transmission.

[0048] Step S123: Associate the device identification information and data collection rule information in the operation association information set, and extract information describing the characteristics of the data storage medium, storage cycle settings and query permission control as storage traceability attributes.

[0049] Step S1231: Parse the component type code in the device identification information to determine the storage medium type of the electronic component. The correspondence between the component type code and the storage medium type is defined by a preset component type mapping table.

[0050] The component type code in the equipment identification information reflects the specific type of the electronic component. By parsing this code, the type of storage medium used by the electronic component can be determined. The preset component type mapping table is a predefined table that records the relationship between different component type codes and their corresponding storage medium types. For example, in the equipment identification information of the data acquisition and transmission module of a fuel dispenser, the component type code may correspond to a specific storage medium type, such as flash memory or hard disk. By querying the component type mapping table, the storage medium type of the electronic component can be accurately determined.

[0051] Step S1232: Extract data storage configuration sub-information from the data collection rule information. The data storage configuration sub-information includes a storage period setting field and a query permission control field.

[0052] In addition to information such as acquisition trigger conditions, parameter types, and frequency settings, data acquisition rule information may also include data storage configuration sub-information. This sub-information is used to manage the data storage period and query permissions. In the acquisition rule information of the fuel dispenser's data acquisition and transmission module, the storage period setting field may specify the length of time the data needs to be stored, while the query permission control field specifies which roles can query the stored data. These data storage configuration sub-information can be obtained by extracting the data acquisition rule information.

[0053] Step S1233: Extract the data storage start time information and storage end time information from the storage period setting field. The storage start time information is the data acquisition completion time, and the storage end time information is the data acquisition completion time plus the preset retention time.

[0054] The storage period setting field contains the start and end times of data storage. The data storage start time is typically the time when data acquisition is completed, because storage operations only begin after data acquisition is finished. The storage end time is the data acquisition completion time plus a preset retention period. For example, in the data acquisition and transmission module of a fuel dispenser, the preset retention period might be the specified number of days or months that the data needs to be retained. By extracting this information from the storage period setting field, the data storage period can be clearly defined, enabling effective data management and traceability.

[0055] Step S1234: Extract the allowed and prohibited role type information from the query permission control field. The role type information includes tax supervisor role, gas station manager role, and ordinary operator role.

[0056] The query permission control field controls which roles can and cannot query stored data. In a gas station monitoring and tax evasion prevention system, common role types include tax supervisors, gas station administrators, and general operators. Tax supervisors have high query privileges and are used to monitor the gas station's tax data; gas station administrators manage the daily operations of the gas station and can query some relevant data; general operators are primarily responsible for refueling operations and have relatively low query privileges. By extracting the allowed and prohibited role types from the query permission control field, the query permissions for different roles on stored data can be clearly defined, ensuring data security and traceability.

[0057] Step S1235: Verify whether the storage medium type matches the storage capacity requirements of the data storage configuration sub-information, including whether the maximum storage capacity of the storage medium can accommodate the total data volume of all collected data within the storage period.

[0058] After determining the storage medium type and data storage configuration sub-information, it is necessary to verify whether the maximum storage capacity of the storage medium can meet the total data volume of all collected data within the storage cycle. For example, in the data acquisition and transmission module of a fuel dispenser, the storage medium may be flash memory, which has a limited maximum storage capacity. The data storage configuration sub-information specifies information such as the data storage cycle and acquisition frequency. Based on this information, the total data volume of all collected data within the storage cycle can be estimated. If the maximum storage capacity of the storage medium is less than the total data volume, it may lead to data storage overflow, affecting data integrity and traceability. Therefore, a matching verification is required. When a mismatch occurs, it may be necessary to replace the storage medium or adjust the data storage configuration.

[0059] Step S1236: Verify whether the allowed query roles in the query permission control field only include the tax supervisor role and the gas station manager role, and whether the prohibited query roles include the ordinary operator role.

[0060] To ensure data security and traceability, it's necessary to verify the appropriateness of the role settings in the query permission control field. In gas station monitoring and tax evasion prevention systems, typically only tax inspectors and gas station administrators have the authority to query stored data; ordinary operators should be prohibited from doing so. By verifying the query permission control field, it's checked whether permitted roles only include tax inspectors and gas station administrators, and whether prohibited roles include ordinary operators. Inappropriate role settings may lead to data leaks or unauthorized queries, requiring timely adjustments.

[0061] Step S1237: Integrate and process the storage medium type, storage cycle setting information and query permission control information to generate the storage traceability attribute.

[0062] After extracting and verifying information such as storage media type, storage cycle settings, and query access control, this information is integrated. This integration creates a comprehensive storage traceability attribute to assess the traceability of electronic components in data storage. For example, information such as storage media type, storage start time, storage end time, allowed and prohibited query roles are combined to form a comprehensive storage traceability attribute, facilitating subsequent analysis and evaluation of the security attributes of electronic components.

[0063] Step S124: Input the acquisition accuracy attribute, transmission integrity attribute, and storage traceability attribute into the attribute correlation analysis module to identify the interaction between the impact of acquisition error on the reliability of transmitted data and the impact of storage access control on the effectiveness of historical data traceability.

[0064] The attribute correlation analysis module is specifically designed to analyze the relationships between different security attributes. In the gas station monitoring and tax evasion prevention system, the data acquisition accuracy attribute, transmission integrity attribute, and storage traceability attribute are not independent; they have complex interactions. When these attributes are input into the attribute correlation analysis module, the module identifies the interactions between them from multiple perspectives.

[0065] Regarding the impact of data collection errors on the reliability of transmitted data, in practice, if electronic components make errors when collecting data such as refueling volume, fuel type, and transaction time, this erroneous data will be transmitted to other systems, such as tax supervision platforms and gas station management systems. For example, if there is an error in collecting refueling volume, the data transmitted to the tax supervision platform will not match the actual refueling volume, which may lead to inaccurate tax calculations and thus affect the effectiveness of tax evasion prevention monitoring. The attribute correlation analysis module analyzes the specific impact of factors such as the magnitude and frequency of data collection errors on the reliability of transmitted data. It considers whether data collection errors will cause data to be misprocessed during transmission or whether the receiver will be unable to correctly understand and use the transmitted data. If the data collection error is too large, it may cause the transmitted data to become meaningless or even trigger communication failures between systems.

[0066] In analyzing the impact of storage access control on the effectiveness of historical data traceability, storage access control specifies which roles can query and access stored data. If storage access control settings are unreasonable, such as allowing ordinary operator roles to query sensitive historical data, data security and traceability will be compromised. When historical data needs to be traced, inappropriate permission settings may lead to data tampering or leakage, thus affecting the effectiveness of traceability. The attribute correlation analysis module assesses the impact of factors such as the strictness of storage access control and the rationality of permission allocation on the effectiveness of historical data traceability. It analyzes whether historical data can be accurately and completely traced under different permission settings, and whether the authenticity and reliability of the data can be guaranteed.

[0067] This module also considers the relationship between data collection accuracy and storage traceability attributes. Data collection accuracy directly impacts the quality of stored data. If the collected data is inaccurate, the stored data cannot accurately reflect the actual refueling transactions, significantly compromising storage traceability. For example, inaccurate refueling volume data can lead to deviations in subsequent tax statistics and analysis, affecting data traceability and reliability. The attribute correlation analysis module identifies the degree and manner of these interactions to comprehensively assess the safety performance of electronic components.

[0068] Furthermore, transmission integrity and storage traceability are also related. If data is not effectively protected during transmission, such as through insecure encryption or inadequate verification mechanisms, it may be tampered with or lost during transit. When this tampered or lost data is stored, its traceability will be affected. The attribute correlation analysis module analyzes the impact of various factors during transmission on the traceability of stored data, ensuring the integrity and traceability of data throughout its entire lifecycle.

[0069] By identifying these interactions, the attribute correlation analysis module can generate a detailed relationship graph, demonstrating the associations between the acquisition accuracy attribute, transmission integrity attribute, and storage traceability attribute. This relationship graph can help to further understand the safety performance of electronic components.

[0070] Step S125: Based on the interaction relationship, prioritize the acquisition accuracy attribute, transmission integrity attribute, and storage traceability attribute to generate a security attribute priority list that matches the correlation with tax evasion risk.

[0071] After determining the interactions between the attributes, it is necessary to prioritize the data collection accuracy, transmission integrity, and storage traceability attributes. This is because in a gas station monitoring and tax evasion prevention system, different security attributes have varying degrees of impact on tax evasion risk. The purpose of prioritization is to generate a priority list of security attributes that matches the relevance to tax evasion risk, allowing for focused checks during subsequent compliance verification.

[0072] The ranking process comprehensively considers the interactions between attributes and their direct impact on tax evasion risk. For example, if data collection errors significantly affect the reliability of transmitted data and the traceability of storage, and inaccurate data collection may directly lead to tax calculation errors, then the data collection accuracy attribute may be given a higher priority. Similarly, for the transmission integrity attribute, if the security and integrity of data transmission are crucial to preventing data tampering and tax evasion, and its interactions with other attributes are close, then it will also have a high priority. The storage traceability attribute plays a key role in ensuring the queryability and verifiability of historical data and is also important for tax evasion monitoring; its priority is determined based on its relationship with other attributes and the degree of its impact on tax evasion risk.

[0073] Several methods can be used for prioritization. One possible method is a weight-based ranking method. Each attribute is assigned a weight based on the interactions between them and their impact on tax evasion risk. For example, the weight of the data collection accuracy attribute might be determined based on its impact on transmission and storage, the weight of the transmission integrity attribute would consider its importance to data security and tax calculation, and the weight of the storage traceability attribute would be allocated based on its role in historical data tracing and tax evasion verification. Then, the attributes are ranked according to these weights, with attributes having higher weights having higher priority.

[0074] Another approach is rule-based prioritization. A set of rules is established to determine the priority of attributes based on their characteristics and interactions. For example, if the absence or non-compliance of an attribute directly leads to a serious risk of tax evasion, then that attribute will have a higher priority. By applying these rules, attributes such as data collection accuracy, transmission integrity, and storage traceability are prioritized.

[0075] In practice, multiple sorting methods may be combined to ensure the accuracy and rationality of the priority ranking. The final generated security attribute priority list will clearly indicate the priority order of each attribute.

[0076] Step S130: Based on the preset anti-tax evasion security verification specifications, perform multi-dimensional compliance verification processing on the priority list of security attributes to generate a set of compliance verification results.

[0077] The pre-defined tax evasion prevention security verification specifications are a set of pre-established rules and standards used to assess whether the security attributes of electronic components meet the requirements for tax evasion prevention monitoring. After obtaining the priority list of security attributes for electronic components, multi-dimensional compliance verification processing of the security attributes needs to be carried out according to these specifications.

[0078] Step S131: Extract the verification rules corresponding to the data collection accuracy attribute from the anti-tax evasion security verification specification, verify whether the fuel volume measurement accuracy meets the tax measurement standard, whether the oil type identification reliability meets the anti-tax evasion requirements, and whether the transaction time synchronization consistency is within the allowable range of tax data synchronization, and generate the data collection accuracy verification result.

[0079] The tax evasion prevention security verification specification includes verification rules related to the accuracy of data collection. Regarding the accuracy of fuel volume measurement, tax measurement standards stipulate an error range for fuel volume measurement; the fuel volume measurement accuracy of the electronic component must fall within this error range to meet the requirements. The verification process checks the accuracy of the fuel volume data collected by the electronic component by comparing it with known standard data to determine whether it complies with the tax measurement standards. For example, it can check the fuel volume measurement results of the electronic component under different refueling scenarios to see if they are all within the specified error range.

[0080] The reliability of fuel type identification is also a crucial aspect of verification. Tax evasion prevention requires electronic components to accurately identify fuel types, as different fuels may have different tax rates. Verification assesses the accuracy of the electronic components in identifying fuel types and checks for any misidentifications. For example, multiple refueling transactions involving different fuel types can be tested, and the percentage of times the electronic components correctly identify the fuel type can be statistically analyzed to determine if it meets the tax evasion prevention requirements.

[0081] Transaction time synchronization consistency also needs to be verified. The permissible range for tax data synchronization defines the deviation range between the transaction time recorded by electronic components and the actual transaction time. The verification process checks the difference between the transaction time recorded by electronic components and the actual transaction time to determine if it is within the permissible range. Inconsistent transaction time synchronization may lead to errors in tax data statistics and calculations, affecting the effectiveness of tax evasion prevention monitoring.

[0082] After verifying the accuracy of refueling volume measurement, the reliability of fuel type identification, and the consistency of transaction time synchronization, these verification results are integrated to generate a data collection accuracy verification result. This result clarifies whether the electronic components meet the requirements of the anti-tax evasion security verification specifications in terms of data collection accuracy.

[0083] Step S132: Extract the verification rules corresponding to the transmission integrity attribute, verify whether the data transmission encryption method adopts the standard recognized by the tax regulatory department, whether the verification mechanism can detect data tampering, and whether the retransmission strategy can guarantee the reliability of data retransmission, and generate the transmission integrity verification result.

[0084] Step S1321: Obtain a list of encryption algorithms recognized by the tax regulatory authorities from the anti-tax evasion security verification specification. The list of encryption algorithms includes the specific names and version numbers of symmetric encryption algorithms and asymmetric encryption algorithms.

[0085] The tax evasion prevention security verification specifications will clearly list the encryption algorithms approved by tax authorities. This list includes the specific names and version numbers of both symmetric and asymmetric encryption algorithms. Symmetric and asymmetric encryption algorithms have different characteristics and application scenarios in data encryption. The encryption algorithms approved by tax authorities have undergone rigorous screening and evaluation to ensure data security during transmission.

[0086] Step S1322: Check whether the encryption algorithm type in the transmission integrity attribute exists in the encryption algorithm list. If it exists, generate an encryption algorithm compliance sub-result of compliance; otherwise, generate an encryption algorithm compliance sub-result of non-compliance.

[0087] After obtaining the list of encryption algorithms approved by the tax authorities, the encryption algorithm type in the electronic component's transmission integrity attribute is compared with the list. If the encryption algorithm type used by the electronic component is in the list, it means that its encryption algorithm meets the requirements of the tax authorities, and the encryption algorithm compliance sub-result is generated as compliant; otherwise, if the encryption algorithm type is not in the list, the encryption algorithm compliance sub-result is generated as non-compliant. The purpose of this step is to ensure that the electronic component uses a secure and reliable encryption algorithm during data transmission, preventing data from being stolen or tampered with.

[0088] Step S1323: Verify the detection capability of the verification mechanism through a simulated data tampering experiment, record the types of tampering that can be detected and the types of tampering that fail to be detected, and generate a sub-result of the validity of the verification mechanism.

[0089] To verify the effectiveness of an electronic component's verification mechanism in detecting data tampering, a simulated data tampering experiment can be conducted. In this experiment, various types of tampering can be applied to the transmitted data, such as modifying the data's value or changing its order. The verification mechanism's ability to detect these modifications is then observed. The types of tampering detected and those that fail to be detected are recorded to evaluate the effectiveness of the verification mechanism. For example, if the verification mechanism can detect modifications to the data's value but cannot detect changes in the data's order, these cases will be recorded. Based on the experimental results, a sub-result of the verification mechanism's effectiveness is generated, clarifying the mechanism's capability in detecting data tampering.

[0090] Step S1324: Verify the retransmission capability of the retransmission strategy through a simulated network packet loss experiment, record the success of the first retransmission, the success of the second retransmission, and the success of the final retransmission, and evaluate the reliability of the retransmission.

[0091] In actual data transmission, packet loss is a common problem. To verify whether the retransmission strategy of electronic components can guarantee the reliability of data retransmission, a simulated network packet loss experiment can be conducted. In the experiment, network packet loss can be simulated, causing data to be lost during transmission. Then, the effectiveness of the electronic components' retransmission strategy in retransmitting the lost data is observed. The success rates of the first retransmission, the second retransmission, and the final retransmission are recorded. By analyzing these records, the reliability of the retransmission strategy can be evaluated. For example, if the initial retransmission success rate is low, but the final retransmission is successful after multiple retransmissions, the relationship between the number of retransmissions and the retransmission success rate can be further analyzed to determine the effectiveness of the retransmission strategy.

[0092] Step S1325: If the retransmission reliability meets the requirements, the retransmission strategy validity sub-result is generated as compliant; otherwise, the retransmission strategy validity sub-result is generated as non-compliant.

[0093] The retransmission reliability, as evaluated by simulated network packet loss experiments, is used to determine whether it meets the requirements. If the retransmission reliability meets the preset standard, such as the final retransmission success rate reaching a set percentage, then the generated retransmission strategy validity sub-result is considered compliant; conversely, if the retransmission reliability does not meet the requirements, the generated retransmission strategy validity sub-result is considered non-compliant. This retransmission strategy validity sub-result reflects the performance of the electronic component's retransmission strategy in ensuring data retransmission reliability.

[0094] Step S1326: Perform a comprehensive judgment on the compliance sub-result of the encryption algorithm, the validity sub-result of the verification mechanism, and the validity sub-result of the retransmission strategy. If all sub-results are compliant, mark the transmission integrity verification result as compliant. If at least one sub-result is non-compliant, mark the transmission integrity verification result as non-compliant, and record the specific non-compliant sub-result and verification process data.

[0095] After obtaining the compliance sub-results of the encryption algorithm, the validity sub-results of the verification mechanism, and the validity sub-results of the retransmission strategy, these sub-results are comprehensively judged. Only when all sub-results are compliant is the transmission integrity verification result marked as compliant; if at least one sub-result is non-compliant, the transmission integrity verification result is marked as non-compliant. Simultaneously, the specific non-compliant sub-results and relevant data from the verification process are recorded, such as detailed records of simulated data tampering experiments and simulated network packet loss experiments, for subsequent analysis and improvement.

[0096] Step S133: Extract the verification rules corresponding to the storage traceability attributes, verify whether the data storage medium has anti-tampering capabilities, whether the storage period setting meets the tax data retention requirements, and whether the query permission control only allows access by tax supervision roles, and generate storage traceability verification results.

[0097] The tax evasion prevention security verification specification includes verification rules related to storage traceability attributes. For data storage media, it is necessary to verify their tamper-proof capabilities. This can be determined by examining the physical characteristics of the storage media and the method of data storage. For example, some storage media may employ encryption technologies or write protection mechanisms to prevent data tampering. The verification process assesses whether these characteristics of the storage media are effective in preventing unauthorized data modification.

[0098] Storage period settings are also a crucial aspect of verification. Tax data retention requirements stipulate the length of time data must be stored, and the storage period settings of electronic components must meet these requirements. Verification will check whether the storage period settings comply with the regulations, specifically whether the storage start and end times are within the scope of tax data retention. If the storage period settings do not meet the requirements, historical data may not be fully preserved, affecting the traceability capabilities of tax evasion prevention monitoring.

[0099] Query access control also requires verification. As required, query permissions should only allow tax regulatory roles to access stored data to ensure data security and confidentiality. The verification process checks whether the query access control settings comply with this requirement and whether other roles have been incorrectly granted query permissions.

[0100] After verifying the tamper-proof capabilities of the data storage medium, the storage cycle settings, and the query access control, these verification results are integrated to generate a storage traceability verification result. This result clarifies whether the electronic components meet the requirements of the anti-tax evasion security verification specifications in terms of storage traceability.

[0101] Step S134: Convert the collection accuracy verification results, transmission integrity verification results, and storage traceability verification results into a set of compliance verification results with a unified representation.

[0102] After obtaining the verification results for data collection accuracy, transmission integrity, and storage traceability, these results may have different formats and representations. Therefore, they need to be converted into a unified set of compliance verification results. This facilitates subsequent processing and analysis. A unified format can be defined to organize and record the key information of each verification result, such as whether it meets the requirements and the specific reasons for non-compliance, in a consistent manner. For example, each verification result can be represented as an information unit containing multiple fields, each representing different verification content. In this way, the verification results for data collection accuracy, transmission integrity, and storage traceability are integrated into a single set of compliance verification results, giving them a consistent representation.

[0103] Step S135: Perform conflict detection processing on the compliance verification result set to check if there is a contradiction in which one attribute verification is compliant but other attribute verification is non-compliant. If such a contradiction exists, it is marked as an abnormal result that requires manual review. If no such contradiction exists, the compliance verification result set is output.

[0104] After obtaining a set of compliance verification results with a unified representation, conflict detection processing is required. This is because, in practice, there may be contradictory situations where one attribute verification meets the requirements, but causes other attribute verifications to fail. For example, to improve transmission integrity, an overly complex encryption algorithm may be used, which could affect the accuracy of data collection or the traceability of storage. Conflict detection processing carefully examines whether such contradictory relationships exist among the various verification results in the compliance verification result set.

[0105] If any inconsistencies are found, the result is marked as an anomaly requiring manual review. Manual review can be conducted by professional technicians or managers who will further analyze the causes of the inconsistencies and take appropriate measures for adjustment and improvement. If no inconsistencies are found after inspection, the compliance verification result set is output as the final result for subsequent tax evasion risk correlation analysis.

[0106] Step S140: Perform tax evasion risk correlation analysis on the compliance verification result set to obtain the security certification assessment data of the electronic component.

[0107] The compliance verification results set includes verification results for electronic components in terms of data collection accuracy, transmission integrity, and storage traceability. Performing a tax evasion risk correlation analysis on these results is to assess the impact of the electronic component's security performance on tax evasion prevention, thereby obtaining security certification assessment data for the electronic components.

[0108] Step S141: Perform risk impact assessment on the collection accuracy verification results, transmission integrity verification results, and storage traceability verification results in the compliance verification result set, and generate an assessment value that reflects the impact of each attribute verification result on the risk of tax evasion.

[0109] The accuracy verification results are used to assess their impact on tax evasion risk. If the accuracy verification results do not meet the requirements, such as the fuel volume measurement accuracy exceeding tax measurement standards or low reliability in fuel type identification, it may lead to tax calculation errors and increase the risk of tax evasion. The assessment process considers factors such as the magnitude of the collection error, the frequency of the error, and its specific impact on tax calculation, generating an assessment value that reflects the impact of the accuracy verification results on tax evasion risk.

[0110] The risk impact of transmission integrity verification results is also assessed. If the transmission integrity verification results do not meet the requirements, such as the encryption algorithm not conforming to standards or the verification mechanism failing to effectively detect data tampering, the transmitted data may be stolen or altered, leading to inaccurate tax data and increasing the risk of tax evasion. The assessment process analyzes various risk factors during transmission, such as the possibility of data leakage and the impact of data tampering on tax calculations, and generates an assessment value for the impact of transmission integrity verification results on the risk of tax evasion.

[0111] For the storage of traceability verification results, its impact on preventing tax evasion risks is assessed. If the storage of traceability verification results does not meet the requirements, such as the data storage medium lacking tamper-proof capabilities or unreasonable query access control, the traceability of historical data will be affected, potentially making it impossible to accurately trace tax transaction records and increasing the risk of tax evasion. The assessment process considers factors such as the security and searchability of stored data, as well as its impact on tax audits, to generate an assessment value for the impact of storing traceability verification results on preventing tax evasion risks.

[0112] Step S142: Determine the weighting coefficients of the acquisition accuracy assessment value, transmission integrity assessment value, and storage traceability assessment value according to the priority order of each attribute in the security attribute priority list.

[0113] The security attribute priority list clearly defines the priority order of data collection accuracy, transmission integrity, and storage traceability attributes. Based on this priority order, weighting coefficients are determined for the data collection accuracy assessment value, transmission integrity assessment value, and storage traceability assessment value. The higher the priority of the attribute, the larger the weighting coefficient assigned to its corresponding assessment value. This is because higher priority attributes have a more critical impact on preventing tax evasion risks.

[0114] When determining weighting coefficients, multiple factors can be considered. First, the importance of each attribute in the tax evasion prevention and monitoring system must be taken into account. For example, the accuracy of data collection directly relates to the basic data for tax calculations; inaccurate data collection will lead to deviations in subsequent tax processing, so it may have a higher priority, and correspondingly, its weighting coefficient will be larger. The transmission integrity attribute ensures the security and accuracy of data during transmission, preventing data tampering or loss, and is crucial for the timely and accurate delivery of tax data; its weighting coefficient will also be set according to its importance. The storage traceability attribute ensures the queryability and verifiability of historical tax data, which is of great significance for tax audits and tax evasion prevention and tracing; its weighting coefficient is also determined based on its importance.

[0115] Secondly, the interrelationships between the attributes can be considered. As mentioned earlier, the attributes do not exist independently; they interact with each other. For example, the accuracy of data collection affects the quality of transmitted data, which in turn affects the traceability of stored data. When determining the weighting coefficients, the comprehensive impact of these interrelationships on the risk of tax evasion can be analyzed. If a change in one attribute has a significant impact on other attributes, then the weighting coefficient of that attribute will be adjusted accordingly.

[0116] In addition, industry standards and experience will be considered. In the field of gas station monitoring and tax evasion prevention systems, there may already be some industry consensus and experience regarding the importance of various safety attributes. These standards and experiences can serve as a reference for determining the weighting coefficients, ensuring that the setting of the weighting coefficients is reasonable and scientific.

[0117] Step S143: Based on the weighting coefficients, the acquisition accuracy assessment value, transmission integrity assessment value, and storage traceability assessment value are standardized, converted, and weighted summed to generate a comprehensive risk impact assessment value.

[0118] After obtaining the assessment values ​​for data acquisition accuracy, transmission integrity, and storage traceability, along with their corresponding weighting coefficients, the first step is to standardize these assessment values. The purpose of standardization is to eliminate potential differences in dimensions and numerical ranges between different assessment values, ensuring their comparability when performing weighted summation.

[0119] The specific method of standardization transformation can be selected based on the characteristics of the evaluation values. For example, a normalization method can be used to map each evaluation value to a set numerical range, such as between 0 and 1. Through normalization, each evaluation value has the same numerical range, avoiding the problem of inaccurate weighted summation results caused by excessive differences in numerical values.

[0120] After standardization, the standardized assessment values ​​are weighted and summed according to the determined weighting coefficients. Specifically, the data collection accuracy assessment value, the transmission integrity assessment value, and the storage traceability assessment value are multiplied by their respective weighting coefficients. These three products are then added together to obtain the comprehensive risk impact assessment value. This comprehensive risk impact assessment value takes into account the impact of the three attributes of data collection accuracy, transmission integrity, and storage traceability on tax evasion risk, and can comprehensively reflect the overall impact of the security performance of electronic components on tax evasion prevention.

[0121] Step S144: Extract the specific verification details of each verification result in the compliance verification result set, including the specific rules and clauses verified as compliant, the specific rules and clauses verified as non-compliant, and a description of potential risk points discovered during the verification process.

[0122] The compliance verification results set not only includes overall conclusions regarding the accuracy of data collection, the integrity of transmission, and the traceability of storage, but also detailed verification information. This detailed information is crucial for gaining a deeper understanding of the safety performance of electronic components and any existing problems.

[0123] For specific rules and clauses that are verified to be compliant, the specific rules that comply with the tax evasion prevention and security verification specifications during the verification process of each attribute can be extracted from the compliance verification result set. For example, in the verification of data collection accuracy, if the fuel volume measurement accuracy meets the tax measurement standard, the specific clauses of that standard can be recorded; in the verification of transmission integrity, if the encryption algorithm adopts a standard recognized by the tax regulatory authorities, the specific rule clauses such as the recognized encryption algorithm name and version number can be clearly recorded.

[0124] For specific rules and clauses that are not verified, they will also be extracted in detail. For example, if the reliability of oil type identification in the accuracy verification does not meet the tax evasion prevention requirements, the specific clauses of the requirements and the gap between the actual identification accuracy and the requirements can be recorded; in the transmission integrity verification, if the verification mechanism cannot detect a certain type of data tampering, the specific rules of the verification mechanism and the type of tampering that could not be detected can be recorded.

[0125] In addition, descriptions of potential risk points discovered during the verification process will be extracted. These potential risk points may be situations discovered during the verification process that, while not currently causing non-compliance, could potentially lead to problems in the future. For example, in storage traceability verification, it may be found that the remaining storage space of the storage medium is close to its limit. Although data storage is currently normal, there may be a potential risk that data cannot be stored properly in the future. A detailed description of such potential risk points can be recorded.

[0126] Step S145: The comprehensive risk impact assessment value and the specific verification details are correlated and integrated to generate security certification assessment data containing the risk impact assessment value, verification details record and potential risk list.

[0127] Step S1451: Create an assessment data structure framework, which includes a risk impact assessment value field, a verification details record field, and a potential risk list field.

[0128] To effectively integrate the overall risk impact assessment with specific verification details, a data structure framework for the assessment must first be created. This framework is a structured organization that accommodates information such as the risk impact assessment, verification details, and a list of potential risks.

[0129] The Risk Impact Assessment Value field stores the comprehensive risk impact assessment value calculated earlier. This field stores the assessment value according to the set format and specifications for subsequent querying and analysis.

[0130] The verification details record field stores specific verification details extracted from the compliance verification result set, including the specific rules and clauses verified as compliant and non-compliant. This verification details record field categorizes and records this information according to attributes such as collection accuracy, transmission integrity, and storage traceability, allowing users to quickly understand the verification status of each attribute.

[0131] The Potential Risk List field stores descriptions of potential risks discovered during the verification process. These potential risks are arranged in a predefined order, such as by their likelihood of occurrence or degree of impact, to facilitate effective management and monitoring of potential risks.

[0132] Step S1452: In the risk impact assessment value field, write the numerical representation of the comprehensive risk impact assessment value and the corresponding risk level description.

[0133] In the Risk Impact Assessment Value field, the numerical representation of the comprehensive risk impact assessment value is entered first. This value is obtained through standardization and weighted summation, reflecting the overall impact of the electronic component's safety performance on tax evasion risk.

[0134] Simultaneously, based on the magnitude of the comprehensive risk impact assessment value, a corresponding risk level description is determined. Risk levels can be categorized into different grades, such as low risk, medium risk, and high risk. Each risk level corresponds to a defined numerical range, and the corresponding risk level description is determined based on the range in which the comprehensive risk impact assessment value falls. For example, if the comprehensive risk impact assessment value is low and falls within the low-risk range, a description of "low risk" can be recorded in the risk impact assessment value field; if it falls within the high-risk range, a description of "high risk" is recorded. This allows users to intuitively understand the risk status of electronic components.

[0135] Step S1453: In the verification details record field, according to the classification order of the verification results of collection accuracy, transmission integrity and storage traceability, write the specific rule clauses that meet the verification of each dimension and the specific rule clauses that do not meet the verification.

[0136] In the verification details record field, the verification results are categorized and recorded according to three dimensions: collection accuracy, transmission integrity, and storage traceability.

[0137] For the verification results of data collection accuracy, separate lists of specific rules and clauses that are verified to be compliant and those that are not can be entered into. For example, the list of compliant rules and clauses may include clauses that meet tax measurement standards for fuel volume measurement accuracy and clauses that meet the allowable scope of tax data synchronization for transaction time synchronization consistency; the list of non-compliant rules and clauses may include clauses that do not meet tax evasion prevention requirements for oil type identification reliability.

[0138] For the transmission integrity verification results, a list of specific rules and clauses for both verification compliance and non-compliance will be recorded separately. The list of rules and clauses for compliance may include clauses related to encryption algorithms that meet the standards recognized by tax regulatory authorities, and rules and clauses corresponding to tampering types that the verification mechanism can detect. The list of rules and clauses for non-compliance may include clauses related to retransmission strategies failing to meet reliability requirements.

[0139] Similar records will also be kept for the results of traceability verification. The list of rules and clauses that meet the verification criteria may include specific clauses regarding the tamper-proof capabilities of the data storage medium, and clauses regarding storage period settings that meet the requirements for tax data retention; the list of rules and clauses that do not meet the verification criteria may include clauses regarding unreasonable query access control, etc.

[0140] Step S1454: In the potential risk list field, for the specific rule clauses that the verification does not comply with, analyze the types of tax evasion risks and the scope of their impact, and generate risk description information.

[0141] In the potential risk list field, specific rule clauses that do not meet the verification criteria can be analyzed in depth to determine the types of tax evasion risks they may pose and the scope of their impact.

[0142] For example, if a rule clause fails to meet the reliability requirements for identifying oil type in the accuracy verification process, the potential tax evasion risk could be tax calculation errors. This is because different oil types have different tax rates, and inaccurate identification can lead to deviations in tax calculations. The impact of this risk could extend to all refueling transactions corresponding to the data collected by the electronic component, potentially affecting the tax authorities' tax accounting and supervision of the gas station.

[0143] For rule clauses in transmission integrity verification where the verification mechanism fails to detect certain types of data tampering, the potential tax evasion risk could be that data has been illegally altered without detection, thus affecting the authenticity and accuracy of tax data. The scope of this risk could include all relevant data transmitted between the electronic component and other systems, potentially leading tax authorities to make decisions based on erroneous data.

[0144] Regarding the potential risk of storage media approaching its maximum remaining storage space during traceability verification, the possible tax evasion risks include the inability to store data properly in the future, thus affecting the traceability of historical data. The scope of this risk may involve all tax-related data stored on the media, potentially making it impossible to provide complete historical data during a tax audit.

[0145] Based on these analyses, detailed risk descriptions are generated and recorded in the potential risk list field to enable effective management and prevention of potential risks.

[0146] Step S1455: Perform a logical coherence check on the contents of the Risk Impact Assessment Value field, Verification Details Record field, and Potential Risk List field. Standardize the data format of the assessment data structure framework that passes the check to generate security certification assessment data with a unified data representation.

[0147] After populating the fields for Risk Impact Assessment Value, Verification Details Record, and Potential Risk List, it is necessary to perform a logical consistency check on these fields. This is to ensure that the information in each field is interconnected, logically consistent, and free from contradictions or illogicalities.

[0148] For example, examine the logical relationship between the risk impact assessment value and the verification details record and potential risk list. If the risk impact assessment value shows high risk, but the verification details record only shows a few minor non-compliances with the rules, and the risk impact range in the potential risk list is small, then further examination of the accuracy of the data and the rationality of the logic is needed.

[0149] At the same time, check the logical consistency between the verification details and the potential risk list. For example, there should be a reasonable causal relationship between the specific rule clauses that are not verified and the descriptions of potential risks. If there are logical inconsistencies, they need to be corrected.

[0150] For assessment data structure frameworks that pass inspection, data format standardization can be performed. This is to ensure that security certification assessment data has a unified data representation, facilitating exchange and sharing between different systems. Data format standardization may include standardizing field naming conventions, data encoding formats, and data storage methods. Through standardization, security certification assessment data with a unified data representation is generated, which includes important information such as risk impact assessment values, verification detail records, and a list of potential risks.

[0151] Step S150: Generate a safety certification conclusion for the electronic component based on the safety certification assessment data. The safety certification conclusion is used to indicate whether the electronic component meets the safety operation requirements of the gas station tax evasion monitoring system.

[0152] For example, step S151: extract the comprehensive risk impact assessment value from the security certification assessment data, and obtain the risk impact threshold corresponding to the preset security certification standard.

[0153] The safety certification assessment data includes a comprehensive risk impact assessment value, which is a comprehensive quantitative indicator of the safety performance of electronic components. To determine whether the electronic components meet the safety operation requirements of the gas station tax evasion prevention monitoring system, this comprehensive risk impact assessment value needs to be compared with the risk impact threshold corresponding to the preset safety certification standard.

[0154] The preset safety certification standards are formulated based on the requirements of the tax evasion monitoring system and industry experience. The risk impact threshold is a critical value that classifies risk levels into different grades. When the comprehensive risk impact assessment value is lower than or equal to this threshold, it indicates that the safety performance of the electronic components is within an acceptable range; when the comprehensive risk impact assessment value is higher than this threshold, it indicates that the electronic components pose a high safety risk and may not meet the requirements for safe operation.

[0155] Step S152: Compare the comprehensive risk impact assessment value with the risk impact threshold. If the comprehensive risk impact assessment value is lower than or equal to the risk impact threshold, a certification pass conclusion is generated; if the comprehensive risk impact assessment value is higher than the risk impact threshold, a certification fail conclusion is generated.

[0156] The extracted comprehensive risk impact assessment value is compared with the preset risk impact threshold. This is a crucial judgment step that directly determines the safety certification result of the electronic component.

[0157] If the overall risk impact assessment value is lower than or equal to the risk impact threshold, it indicates that the electronic component's overall security performance in terms of data collection accuracy, transmission integrity, and storage traceability meets the requirements of the tax evasion prevention monitoring system, and a certification conclusion is generated. This means that the electronic component can operate safely in the gas station tax evasion prevention monitoring system, and the data it collects, transmits, and stores can serve as a valid basis for tax accounting and supervision.

[0158] If the overall risk impact assessment value exceeds the risk impact threshold, it indicates that the electronic component poses a high security risk and may not meet the requirements of the anti-tax evasion security verification specifications in some aspects. For example, there may be problems such as large data acquisition errors, easy tampering of transmitted data, or poor traceability of stored data. In this case, a certification failure conclusion is generated, indicating that the electronic component needs to be improved or adjusted to meet the safe operation requirements of the gas station anti-tax evasion monitoring system.

[0159] Step S153: In the certification pass conclusion, add the key rule clause information verified to be compliant from the security certification assessment data as supporting evidence; in the certification fail conclusion, add the key rule clause information verified to be non-compliant from the security certification assessment data and the corresponding potential risk description as improvement suggestions.

[0160] To provide more convincing evidence for certification approval, information on key rules and regulations verified in the security certification assessment data can be attached. These key rules and regulations are important components of the tax evasion prevention security verification specifications, and the electronic components' compliance with these clauses demonstrates that they meet security requirements in key aspects. For example, in terms of data collection accuracy, they meet tax measurement standards for fuel volume measurement accuracy; in terms of transmission integrity, they employ encryption algorithms approved by tax regulatory authorities. Adding this key rule and regulation information as supporting evidence to the certification approval conclusion makes the conclusion more credible.

[0161] For certification failures, to help users or managers of electronic components understand the problems and make improvements, information on key non-compliant rules and clauses in the security certification assessment data, along with descriptions of corresponding potential risks, can be attached. For example, if the reliability of oil type identification in the data collection accuracy verification does not meet the requirements, the specific clauses of this requirement and potential risks such as possible tax calculation errors can be detailed. In transmission integrity verification, if the verification mechanism cannot detect a certain type of data tampering, the specific rules of the verification mechanism and the potential risks of unauthorized data tampering can be clearly recorded. This information serves as improvement suggestions, providing specific directions and references for the improvement of electronic components.

[0162] Step S154: Associate the authentication pass or authentication fail conclusion with the corresponding supporting evidence or improvement suggestions to generate the final security authentication conclusion.

[0163] After receiving a certification approval or rejection conclusion, along with supporting evidence or improvement suggestions, these conclusions need to be linked together. This is to ensure a clear correspondence between the security certification conclusion and the supporting evidence or improvement suggestions, facilitating user understanding and use.

[0164] The association and binding process can employ a defined data structure or storage method to combine the authentication conclusion with supporting evidence or improvement suggestions. For example, the authentication conclusion can be stored as the primary information, and the supporting evidence or improvement suggestions as secondary information, both stored in a single data object. Through this association and binding process, a final security authentication conclusion is generated. This conclusion includes a judgment on whether the electronic components meet the safe operation requirements of the gas station tax prevention monitoring system, along with corresponding supporting evidence or improvement suggestions, providing comprehensive and clear guidance for the management and use of electronic components in the gas station tax prevention monitoring system.

[0165] Furthermore, Figure 2 A schematic diagram of the hardware structure of an electronic component security authentication system 100 for implementing the methods provided in the embodiments of this application is shown. Figure 2 As shown, the electronic component security authentication system 100 may include at least one processor 102 (the processor 102 may be, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, a transmission device 106 for communication functions, and a controller 108. Those skilled in the art will understand that... Figure 2 The structure shown is for illustrative purposes only and does not limit the structure of the electronic component security authentication system 100. For example, the electronic component security authentication system 100 may also include components that are more advanced than those described above. Figure 2 The more or fewer components shown, or having the same Figure 2 The different configurations shown.

[0166] The memory 104 can be used to store software programs and modules of application software, such as the program instructions corresponding to the method embodiments described above in this application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the above-described electronic component security authentication method. The transmission device 106 is used to acquire or send data via a network.

[0167] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

Claims

1. A method for security authentication of electronic components, characterized in that, The method includes: Obtain the set of operational association information for the electronic components to be certified in the gas station monitoring and tax evasion prevention system. The set of operational association information includes the device identification information, data acquisition rule information, and system interaction relationship information of the electronic components. The security attribute parsing process is performed on the set of operational association information to obtain a security attribute priority list of the electronic component; Based on the preset anti-tax evasion security verification specifications, multi-dimensional compliance verification processing is performed on the security attribute priority list to generate a set of compliance verification results; The compliance verification result set is subjected to a tax evasion risk correlation analysis to obtain the security certification assessment data of the electronic component; The safety certification conclusion of the electronic component is generated based on the safety certification assessment data. The safety certification conclusion is used to indicate whether the electronic component meets the safety operation requirements of the gas station monitoring and anti-tax evasion system. The security attribute parsing process performed on the set of operational association information yields a security attribute priority list for the electronic component, including: The data collection rule information in the aforementioned operational association information set is analyzed, and information reflecting the accuracy of refueling volume measurement, the reliability of oil type identification, and the consistency of transaction time synchronization is extracted as the data collection accuracy attribute. Analyze the system interaction relationship information in the aforementioned operational association information set, and extract information reflecting the data transmission encryption method, verification mechanism, and retransmission strategy as transmission integrity attributes; By associating the device identification information and data collection rule information in the aforementioned operational association information set, information describing the characteristics of the data storage medium, storage cycle settings, and query permission control is extracted as storage traceability attributes; The data collection accuracy attribute, transmission integrity attribute, and storage traceability attribute are input into the attribute correlation analysis module to identify the interaction between the impact of data collection error on the reliability of transmitted data and the impact of storage access control on the effectiveness of historical data traceability. Based on the aforementioned interaction relationships, the data collection accuracy attribute, transmission integrity attribute, and storage traceability attribute are prioritized to generate a security attribute priority list that matches the relevance to tax evasion risk. The aforementioned security verification standard for preventing tax evasion performs multi-dimensional compliance verification processing on the security attribute priority list, generating a set of compliance verification results, including: The verification rules corresponding to the data collection accuracy attribute are extracted from the aforementioned tax evasion prevention security verification specifications. The verification is performed to check whether the fuel volume measurement accuracy meets the tax measurement standards, whether the oil type identification reliability meets the tax evasion prevention requirements, and whether the transaction time synchronization consistency is within the allowable range of tax data synchronization. The data collection accuracy verification result is then generated. Extract the verification rules corresponding to the transmission integrity attribute, verify whether the data transmission encryption method adopts the standard recognized by the tax regulatory department, whether the verification mechanism can detect data tampering, and whether the retransmission strategy can guarantee the reliability of data retransmission, and generate the transmission integrity verification result. Extract and store the verification rules corresponding to the traceability attributes, verify whether the data storage medium has anti-tampering capabilities, whether the storage period setting meets the tax data retention requirements, and whether the query permission control only allows access by tax supervision roles, and generate the storage traceability verification results; The accuracy verification results of data collection, the integrity verification results of data transmission, and the traceability verification results of data storage are converted into a set of compliance verification results with a unified representation. The compliance verification result set is subjected to conflict detection processing to check whether there is a contradiction in which one attribute is verified but other attributes are not verified. If such a contradiction exists, it is marked as an abnormal result that requires manual review. If no such contradiction exists, the compliance verification result set is output. The process of performing tax evasion risk correlation analysis on the compliance verification result set yields the security certification assessment data for the electronic components, including: The risk impact degree of the collection accuracy verification results, transmission integrity verification results and storage traceability verification results in the compliance verification result set is assessed respectively to generate an assessment value reflecting the impact of each attribute verification result on the risk of tax evasion. Based on the priority order of each attribute in the security attribute priority list, the weighting coefficients of the data collection accuracy assessment value, transmission integrity assessment value, and storage traceability assessment value are determined. Based on the weighting coefficients, the assessment values ​​for accuracy of data collection, integrity of data transmission, and traceability of data storage are standardized, converted, and weighted summed to generate a comprehensive risk impact assessment value. Extract the specific verification details of each verification result in the compliance verification result set, including the specific rules and clauses verified as compliant, the specific rules and clauses verified as non-compliant, and a description of potential risk points discovered during the verification process; The comprehensive risk impact assessment value is linked and integrated with the specific verification details to generate security certification assessment data that includes the risk impact assessment value, verification details record and potential risk list. The device identification information and data collection rule information associated with the operational association information set are used to extract information describing the characteristics of the data storage medium, storage cycle settings, and query permission control as storage traceability attributes, including: The component type code in the device identification information is parsed to determine the storage medium type of the electronic component. The correspondence between the component type code and the storage medium type is defined by a preset component type mapping table. Data storage configuration sub-information is extracted from the data collection rule information, and the data storage configuration sub-information includes a storage period setting field and a query permission control field; Extract the data storage start time information and storage end time information from the storage period setting field. The storage start time information is the data collection completion time, and the storage end time information is the data collection completion time plus the preset retention time. Extract the allowed and prohibited role types from the query permission control field. The role types include tax supervisor, gas station manager, and ordinary operator roles. Verify whether the storage medium type matches the storage capacity requirements of the data storage configuration sub-information, including whether the maximum storage capacity of the storage medium can accommodate the total data volume of all collected data within the storage period; Verify whether the allowed query roles in the query permission control field only include the tax supervisor role and the gas station manager role, and whether the prohibited query roles include the ordinary operator role; The storage medium type, storage period setting information, and query permission control information are integrated and processed to generate the storage traceability attribute.

2. The electronic component security authentication method according to claim 1, characterized in that, The set of operational association information for the electronic components to be certified in the gas station monitoring and tax evasion prevention system includes: The unique code consisting of the manufacturer code, component type code, and batch serial number is read from the hardware identifier storage area of ​​the electronic component as the device identification information; Extract the trigger conditions, parameter types, and frequency settings for the logic of collecting fuel volume, fuel type, and transaction time from the software configuration file of the electronic component as data collection rule information; The connection interface type, communication protocol version, and data interaction format information with the tax supervision platform, gas station management system, and fuel dispenser control module are obtained from the communication protocol stack configuration module of the electronic component as system interaction relationship information. The device identification information, data acquisition rule information, and system interaction relationship information are converted into a set of operational association information with a unified field structure. The completeness verification process is performed on the set of operation-related information to verify whether the device identification information contains complete components, whether the data acquisition rule information covers all preset acquisition parameters, and whether the system interaction relationship information clarifies the interaction specifications of all connected objects. If there are missing or unclear items, the information completion process is triggered. If the verification passes, the set of operation-related information is output.

3. The electronic component security authentication method according to claim 2, characterized in that, The data collection rule information includes the extraction of trigger conditions, parameter types, and frequency settings for the logic defining refueling volume, fuel type, and transaction time from the software configuration file of the electronic component. The storage path of the software configuration file of the electronic component is determined, and the storage path is defined by the operating system directory structure of the electronic component; The original data content of the software configuration file is read through the debugging interface of the electronic component. The original data content contains a list of configuration parameters in text format. The original data content is parsed to identify the acquisition trigger condition field, acquisition parameter type field, and acquisition frequency setting field. Extract the trigger event type information from the collection trigger condition field, including fuel nozzle operation events and timed trigger events; Extract the collection parameter name information from the collection parameter type field. The collection parameter name information includes fuel volume parameter, fuel type parameter, and transaction time parameter. Extract the time interval information of the timed trigger event from the acquisition frequency setting field. The time interval information is used to define the active acquisition cycle when there is no event trigger. The event type information, collection parameter name information, and time interval information are subjected to logical consistency verification. The time interval of the timed event is checked to see if it is compatible with the collection frequency of the event. If they are compatible, the data collection rule information is output. If they are not compatible, the data collection rule information is marked as abnormal information and the specific incompatible parameters are recorded.

4. The electronic component security authentication method according to claim 1, characterized in that, The extraction and verification rules corresponding to the transmission integrity attributes verify whether the data transmission encryption method adopts the standard recognized by the tax regulatory authority, whether the verification mechanism can detect data tampering, and whether the retransmission strategy can guarantee the reliability of data retransmission, generating transmission integrity verification results, including: Obtain a list of encryption algorithms recognized by the tax regulatory authorities from the aforementioned tax evasion prevention security verification specifications. The list of encryption algorithms includes the specific names and version numbers of symmetric and asymmetric encryption algorithms. Check if the encryption algorithm type in the transmission integrity attribute exists in the encryption algorithm list. If it exists, generate an encryption algorithm compliance sub-result of compliance; otherwise, generate an encryption algorithm compliance sub-result of non-compliance. The detection capability of the verification mechanism is verified by simulating data tampering experiments. The types of tampering that can be detected and the types of tampering that fail to be detected are recorded, and the effectiveness sub-results of the verification mechanism are generated. The retransmission capability of the retransmission strategy was verified by simulating network packet loss experiments. The success rates of the first retransmission, the second retransmission, and the final retransmission were recorded to evaluate the reliability of the retransmission. If the retransmission reliability meets the requirements, the retransmission strategy validity sub-result is "compliant"; otherwise, the retransmission strategy validity sub-result is "incompatible". The compliance sub-result of the encryption algorithm, the validity sub-result of the verification mechanism, and the validity sub-result of the retransmission strategy are comprehensively judged. If all sub-results are compliant, the transmission integrity verification result is marked as compliant. If at least one sub-result is non-compliant, the transmission integrity verification result is marked as non-compliant, and the specific non-compliant sub-result and verification process data are recorded.

5. The electronic component security authentication method according to claim 1, characterized in that, The process of associating and integrating the comprehensive risk impact assessment value with the specific verification details to generate security certification assessment data that includes the risk impact assessment value, verification detail records, and a list of potential risks includes: Create an assessment data structure framework, which includes a risk impact assessment value field, a verification detail record field, and a potential risk list field. In the risk impact assessment value field, the numerical representation of the comprehensive risk impact assessment value and the corresponding risk level description are written; In the verification details record field, according to the classification order of the verification results of collection accuracy, transmission integrity and storage traceability, the specific rule clauses that meet the verification of each dimension and the specific rule clauses that do not meet the verification are written respectively. In the potential risk list field, for the specific rule clauses that the verification does not comply with, the possible types of tax evasion risks and the scope of risk impact are analyzed, and risk description information is generated; The contents of the risk impact assessment value field, verification detail record field, and potential risk list field are checked for logical coherence. The assessment data structure framework that passes the check is then processed for data format standardization to generate security certification assessment data with a unified data representation.

6. An electronic component security authentication system, characterized in that, It includes a processor and a readable storage medium storing a program that, when executed by the processor, implements the electronic component security authentication method according to any one of claims 1-5.