Method and system for material management based on trusted platform

By adopting a materials management method based on a trusted platform, and using encrypted communication terminals to verify data consistency and store network status with outbound and inbound equipment, the problem of communication confidentiality and stability of the materials management system in harsh environments is solved, and the secure storage and synchronization of data is achieved.

CN121304044BActive Publication Date: 2026-03-20SICHUAN HANYU MORNINGSTAR BIG DATA TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

The existing materials management system lacks sufficient communication security and stability in harsh environments, making it susceptible to external interference, which can lead to information leakage and synchronization failure.

Method used

A trusted platform-based materials management method is adopted, which establishes a connection with the outbound and inbound management equipment through an encrypted communication terminal to verify data consistency. The data storage method is determined by the network status, ensuring that the data is uploaded to the trusted platform when the network connection is established and is stored offline with signature when the connection is lost.

Benefits of technology

It achieves the concealment and stability of the materials management system in harsh environments, ensuring that data can still be securely stored and synchronized when the network is unstable, and avoiding information leakage and synchronization failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121304044B_ABST
    Figure CN121304044B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on trusted platform's material management method and system, including with warehouse-out management equipment and warehouse-in management equipment to establish connection, obtain the warehouse-out data sent by warehouse-out management equipment and the warehouse-in data sent by warehouse-in management equipment;Consistency verification is carried out to warehouse-out data and warehouse-in data, when consistency verification passes, according to warehouse-out data and / or warehouse-in data, obtain the evidence data;Obtain the network state between trusted platform;If the network state between trusted platform is connection, upload evidence data to trusted platform;If the network state between trusted platform is disconnected, request warehouse-out management equipment and warehouse-in management equipment to store signature data after signing evidence data are obtained.Signature data is stored.The application provides a kind of material management scheme that can carry out off-network data storage and utilize multiple devices to synchronize data, at least solves the problem of the deficiency of communication privacy and stability of existing material management scheme in harsh environment.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of Internet of Things, in particular to a material management method and system based on a trusted platform. BACKGROUND

[0002] For a material management system in a special environment, confidentiality and stability are two important requirements, especially in some places that require high security and have a relatively harsh working environment. These systems not only require the confidentiality of communication to prevent sensitive information from being stolen or tampered with, but also must ensure that information can be transmitted stably and accurately in various extreme environments to ensure the normal operation of the system. However, the current material management system of many large-capacity warehouses generally uses wireless communication. Although this communication method has its advantages in convenience, it also faces many challenges in security and stability.

[0003] Firstly, the traditional wireless communication method has a significant security risk, that is, it is easy to be intercepted and cracked by illegal persons. Since the material management system involves sensitive data such as warehouse entry and exit information, inventory quantity, and item type, once these information is intercepted by external personnel, it may lead to loss of materials, misoperation, and even serious consequences such as leakage of business secrets. In addition, although wireless communication is convenient, its reliability and stability are often affected by external environment, especially in some extreme or complex working environments, the communication network is blocked and cannot synchronize the warehouse entry and exit data in real time.

[0004] In view of the deficiencies of the current material management system in terms of communication confidentiality and stability in harsh environments, it is urgent to develop a more secure, reliable and efficient communication scheme. SUMMARY

[0005] The material management method and system based on a trusted platform provide a material management scheme that can store off-network data and synchronize data using multiple devices, at least solving the problem of the deficiency of the existing material management scheme in terms of communication confidentiality and stability in harsh environments.

[0006] In one aspect, a material management method based on a trusted platform is applied to an encrypted communication terminal, comprising:

[0007] establishing a connection with a warehouse-out management device and a warehouse-in management device, obtaining warehouse-out data sent by the warehouse-out management device and warehouse-in data sent by the warehouse-in management device;

[0008] performing consistency verification on the warehouse-out data and the warehouse-in data, and when the consistency verification passes, obtaining evidence data according to the warehouse-out data and / or the warehouse-in data;

[0009] obtaining the network state between the trusted platform;

[0010] if the network state between the trusted platform is connected, uploading the stored evidence data to the trusted platform;

[0011] if the network state between the trusted platform is disconnected, requesting the out-of-warehouse management device and the in-warehouse management device to store signature data obtained after signing the stored evidence data.

[0012] Optionally, when the connection with the out-of-warehouse management device and the in-warehouse management device is established, the method further comprises:

[0013] distributing the stored signature data to the out-of-warehouse management device and / or the in-warehouse management device;

[0014] obtaining other signature data stored by the out-of-warehouse management device and / or the in-warehouse management device, the other signature data being configured to be stored by signature data distributed to the out-of-warehouse management device and / or the in-warehouse management device by other encrypted communication terminals.

[0015] Optionally, when the connection with the out-of-warehouse management device and the in-warehouse management device is established, the method further comprises:

[0016] obtaining the permissions of the out-of-warehouse management device and / or the in-warehouse management device;

[0017] distributing the stored signature data corresponding to the permissions of the out-of-warehouse management device and / or the in-warehouse management device to the out-of-warehouse management device and / or the in-warehouse management device according to the permissions of the out-of-warehouse management device and / or the in-warehouse management device;

[0018] obtaining other signature data stored by the out-of-warehouse management device and / or the in-warehouse management device, the other signature data being configured to be stored by signature data distributed to the out-of-warehouse management device and / or the in-warehouse management device by other encrypted communication terminals.

[0019] Optionally, after the connection with the out-of-warehouse management device and the in-warehouse management device is disconnected, the method further comprises:

[0020] continuously monitoring the network state between the trusted platform;

[0021] when the network state between the trusted platform is connected, uploading all the stored signature data to the trusted platform.

[0022] Optionally, the uploading all the stored signature data to the trusted platform when the network state between the trusted platform is connected comprises:

[0023] When the network state between the trusted platform is connected, the trusted platform receives the signature data in a preset period as the first signature data, and the preset period is from the current time to the disconnection time of the last connection with the trusted platform;

[0024] After deleting the repeated signature data in the stored all signature data, the stored all signature data is uploaded to the trusted platform.

[0025] Optionally, when the connection with the warehouse-out management device and the warehouse-in management device is established, the method further comprises:

[0026] The first signature data is sent to the warehouse-out management device and / or the warehouse-in management device to make the warehouse-out management device and / or the warehouse-in management device delete the signature data corresponding to the first signature data stored in the database.

[0027] Optionally, the connection with the warehouse-out management device and the warehouse-in management device, and obtaining the warehouse-out data sent by the warehouse-out management device and the warehouse-in data sent by the warehouse-in management device, comprises:

[0028] The connection request is sent to the warehouse-out management device and the warehouse-in management device, and the warehouse-out management device information and the warehouse-in management device information are obtained;

[0029] According to the warehouse-out management device information and the warehouse-in management device information, the identity authentication information corresponding to the warehouse-out management device and the warehouse-in management device is sent respectively to establish the connection with the warehouse-out management device and the warehouse-in management device;

[0030] According to the connection of the warehouse-out management device and the warehouse-in management device, the warehouse-out data sent by the warehouse-out management device and the warehouse-in data sent by the warehouse-in management device are obtained.

[0031] Optionally, in the step of verifying the consistency of the warehouse-out data and the warehouse-in data, the consistency verification condition comprises at least one of the following conditions:

[0032] The warehouse-out data and the warehouse-in data are completely consistent;

[0033] The difference between the warehouse-out data and the warehouse-in data does not exceed a preset threshold;

[0034] The warehouse-out management device and the warehouse-in management device confirm that the warehouse-out data or the warehouse-in data is correct.

[0035] On the other hand, a material management system based on a trusted platform comprises a trusted platform, an encrypted communication terminal, a warehouse-out management device and a warehouse-in management device:

[0036] The warehouse-out management device is configured to:

[0037] The materials entering and leaving the warehouse are scanned to obtain the out-of-warehouse data, and the out-of-warehouse data is sent to the encrypted communication terminal;

[0038] The warehouse management device is configured to:

[0039] The materials entering the warehouse are scanned to obtain the in-warehouse data, and the in-warehouse data is sent to the encrypted communication terminal;

[0040] The encrypted communication terminal is configured to:

[0041] Connect with the out-of-warehouse management device and the in-warehouse management device, obtain the out-of-warehouse data sent by the out-of-warehouse management device and the in-warehouse data sent by the in-warehouse management device;

[0042] Consistency verification is performed on the out-of-warehouse data and the in-warehouse data, and when the consistency verification passes, the evidence data is obtained according to the out-of-warehouse data and / or the in-warehouse data;

[0043] Obtain the network state between the trusted platform;

[0044] If the network state between the trusted platform is connected, the evidence data is uploaded to the trusted platform;

[0045] If the network state between the trusted platform is disconnected, request the out-of-warehouse management device and the in-warehouse management device to sign the evidence data to obtain the signature data for storage;

[0046] The trusted platform is configured to:

[0047] Receive the evidence data sent by the encrypted communication terminal for storage.

[0048] Optionally, the encrypted communication terminal is further configured to:

[0049] When connecting with the out-of-warehouse management device and the in-warehouse management device:

[0050] Distribute the stored signature data to the out-of-warehouse management device and / or the in-warehouse management device;

[0051] Obtain other signature data stored by the out-of-warehouse management device and / or the in-warehouse management device, and the other signature data is configured to be stored by the signature data distributed to the out-of-warehouse management device and / or the in-warehouse management device by other encrypted communication terminals.

[0052] In another aspect, a computer device includes a memory and a processor, the memory stores a computer program, and the processor executes the computer program to implement the above method.

[0053] In another aspect, a computer storage medium having stored thereon a computer program, a processor executes the computer program to implement the method described above.

[0054] Compared with the prior art, the application has the following advantages and beneficial effects:

[0055] The application discloses a material management method and system based on a trusted platform, and the method comprises the following steps: connecting with an out-of-warehouse management device and an in-warehouse management device, obtaining out-of-warehouse data sent by the out-of-warehouse management device and in-warehouse data sent by the in-warehouse management device; performing consistency verification on the out-of-warehouse data and the in-warehouse data, and when the consistency verification is passed, obtaining storage data according to the out-of-warehouse data and / or the in-warehouse data; obtaining a network state between the trusted platform; if the network state between the trusted platform is connected, uploading the storage data to the trusted platform; and if the network state between the trusted platform is disconnected, requesting the out-of-warehouse management device and the in-warehouse management device to store signature data obtained after signing the storage data. The application provides a material management scheme capable of performing off-network data storage and data synchronization by using multiple devices, and at least solves the problems of communication confidentiality and stability of an existing material management scheme in a harsh environment. BRIEF DESCRIPTION OF DRAWINGS

[0056] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed in the description of the embodiments or the prior art will be briefly introduced. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, each element or part is not necessarily drawn according to the actual scale.

[0057] Figure 1 The flowchart of the material management method based on the trusted platform in the application;

[0058] Figure 2 The structural diagram of the computer device in the application.

[0059] In the drawings, 101 is a processor, 102 is a communication bus, 103 is a network interface, 104 is a user interface, and 105 is a memory.

[0060] The implementation, functional features and advantages of the application will be further described with reference to the embodiments and the drawings. DETAILED DESCRIPTION

[0061] In order to enable a person skilled in the art to better understand the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, not all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by a person skilled in the art without creative labor should be within the scope of protection of the present disclosure.

[0062] It should be noted that the terms "first", "second", and the like in the specification and claims of the present disclosure and the above-described drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0063] Embodiment 1

[0064] As shown in Figure 1 A material management method based on a trusted platform, applied to an encrypted communication terminal, comprising:

[0065] S1, connection is established with the warehouse-out management device and the warehouse-in management device, and warehouse-out data sent by the warehouse-out management device and warehouse-in data sent by the warehouse-in management device are obtained.

[0066] Optionally, the encrypted communication terminal can be a mobile phone, a tablet computer, or other dedicated terminal device with communication function.

[0067] Optionally, the warehouse-out management device and the warehouse-in management device can be devices for manually entering warehouse-out information and warehouse-in information, or devices for automatically scanning RFID, two-dimensional code or bar code to enter warehouse-out information and warehouse-in information.

[0068] S2, consistency verification is performed on the warehouse-out data and the warehouse-in data, and when the consistency verification passes, evidence data is obtained according to the warehouse-out data and / or the warehouse-in data.

[0069] Optionally, the consistency verification at least includes verification of the types and quantities of the goods in the warehouse-out data and the warehouse-in data, and when the quantity of the goods is large, accurate measurement is difficult, or there is transmission loss, the warehouse-out data and the warehouse-in data are allowed to have a certain range of differences.

[0070] Optionally, when the outbound data and the inbound data have a certain range of differences, it can be agreed that the outbound data or the inbound data is correct, or the outbound data and the inbound data can be recorded respectively.

[0071] Optionally, the storage data is configured to include at least the outbound data or the inbound data, and the outbound management device and the inbound management device agree on the outbound data and / or the inbound data as standard data. The storage data can be configured as the standard data itself or as the standard data signed or encrypted by the encryption communication terminal, or as the standard data signed or encrypted by the outbound management device and the inbound management device, or as the standard data signed or encrypted by the outbound management device, the inbound management device and the encryption communication terminal.

[0072] S3, obtain the network state between the trusted platform.

[0073] Optionally, the encryption communication terminal obtains the network state between the trusted platform, and the network state at least includes connection and disconnection, and can also include signal strength, bandwidth, communication quality and other parameters.

[0074] S4, if the network state between the trusted platform is connected, upload the storage data to the trusted platform.

[0075] Optionally, when the encryption communication terminal uploads the storage data to the trusted platform, the storage data is encrypted by the public key, and the trusted platform receives the encrypted storage data and decrypts it by the private key to obtain the storage data.

[0076] Optionally, the encryption communication terminal can adapt to multiple trusted platforms, and the encryption communication terminal encrypts the storage data according to the information of the connected trusted platform.

[0077] S5, if the network state between the trusted platform is disconnected, request the outbound management device and the inbound management device to sign the storage data and store the signature data.

[0078] An optional example, if the material needs to be transferred from unit A to unit B, when the material management system receives the task, the task is assigned to the transport unit C, the transport unit C carries the encrypted communication terminal to unit A first, the warehouse management equipment of unit A as the out-of-warehouse management equipment, and the warehouse management equipment of the transport unit C as the in-warehouse management equipment, and the warehouse management equipment of the transport unit C can be deployed on the transport carrier of the transport unit C, such as a cargo vehicle or a cargo aircraft. The connection between the out-of-warehouse management equipment, the in-warehouse management equipment and the encrypted communication terminal is established through WLAN networking or wired connection, and the out-of-warehouse data sent by the out-of-warehouse management equipment and the in-warehouse data sent by the in-warehouse management equipment are received through the encrypted communication terminal. Here, the out-of-warehouse data sent by the out-of-warehouse management equipment and the in-warehouse data sent by the in-warehouse management equipment can be received after the out-of-warehouse and in-warehouse are completed, or the out-of-warehouse data and the in-warehouse data can be received in real time, that is, one piece of out-of-warehouse data is received for one piece of out-of-warehouse, and one piece of in-warehouse data is received for one piece of in-warehouse. After receiving all the out-of-warehouse data and the in-warehouse data, the consistency verification is performed by the encrypted communication terminal, and when the consistency verification is passed, the out-of-warehouse data or the in-warehouse data that passes the consistency verification is encrypted by the encrypted communication terminal to obtain the evidence data. When the encrypted communication terminal obtains an evidence data, the encrypted communication terminal detects the network state between itself and the trusted platform, if the network state between itself and the trusted platform is connected, the evidence data is directly uploaded to the trusted platform, if the network state between itself and the trusted platform is disconnected, the evidence data is stored after being signed by the out-of-warehouse management equipment and the in-warehouse management equipment to obtain the signature data, unit A and transport unit C complete the out-of-warehouse, and transport unit C transports the material to unit B, then the warehouse management equipment of transport unit C as the out-of-warehouse management equipment, and the warehouse management equipment of unit B as the in-warehouse management equipment, repeat the above scheme until the material is delivered to unit B. By using the above scheme, the consistency verification of the out-of-warehouse data and the in-warehouse data is performed by the encrypted communication terminal under the trusted platform every time the material is out-of-warehouse or in-warehouse. When the network communication is normal, the encrypted communication terminal can directly send the out-of-warehouse data and the in-warehouse data that passes the consistency verification to the trusted platform for evidence storage. When the network communication is abnormal, the encrypted communication terminal can temporarily store the evidence data, and then send it to the trusted platform for evidence storage after the network communication is restored. At least the problem of poor communication secrecy and stability of the existing material management scheme in harsh environment is solved.

[0079] Embodiment 2

[0080] The embodiment is based on the material management method based on the trusted platform in embodiment 1, applied to the encrypted communication terminal, comprising:

[0081] S1, connect with the out-of-warehouse management equipment and the in-warehouse management equipment, obtain the out-of-warehouse data sent by the out-of-warehouse management equipment and the in-warehouse data sent by the in-warehouse management equipment.

[0082] Optionally, the encrypted communication terminal can be a mobile phone, a tablet computer, or other dedicated terminal device with communication function.

[0083] Optionally, the out-of-warehouse management device and the in-warehouse management device can be devices for manually entering the out-of-warehouse information and the in-warehouse information, or devices for automatically scanning RFID, two-dimensional code or bar code to enter the out-of-warehouse information and the in-warehouse information.

[0084] Optionally, the connection with the out-of-warehouse management device and the in-warehouse management device, and the obtaining of the out-of-warehouse data sent by the out-of-warehouse management device and the in-warehouse data sent by the in-warehouse management device, include:

[0085] sending a connection request to the out-of-warehouse management device and the in-warehouse management device, and obtaining the out-of-warehouse management device information and the in-warehouse management device information;

[0086] according to the out-of-warehouse management device information and the in-warehouse management device information, sending identity authentication information corresponding to the out-of-warehouse management device and the in-warehouse management device respectively to establish the connection with the out-of-warehouse management device and the in-warehouse management device;

[0087] according to the connection with the out-of-warehouse management device and the in-warehouse management device, obtaining the out-of-warehouse data sent by the out-of-warehouse management device and the in-warehouse data sent by the in-warehouse management device.

[0088] Specifically, the connection with the out-of-warehouse management device and the in-warehouse management device, and the obtaining of the out-of-warehouse data sent by the out-of-warehouse management device and the in-warehouse data sent by the in-warehouse management device, include:

[0089] the encrypted communication terminal sends a connection request to the out-of-warehouse management device and the in-warehouse management device, and obtains the out-of-warehouse management device ID and the in-warehouse management device ID; the out-of-warehouse management device ID and the in-warehouse management device ID are unique identifiers of the out-of-warehouse management device and the in-warehouse management device, and the out-of-warehouse management device ID and the in-warehouse management device ID belong to the out-of-warehouse management device information and the in-warehouse management device information.

[0090] according to the out-of-warehouse management device ID and the in-warehouse management device ID, sending identity authentication information corresponding to the out-of-warehouse management device and the in-warehouse management device respectively to establish the connection with the out-of-warehouse management device and the in-warehouse management device;

[0091] Specifically, the identity authentication information sent to the out-of-warehouse management device and the in-warehouse management device can be a ciphertext for representing the out-of-warehouse management device or a trusted platform;

[0092] Specifically, the method for obtaining the ciphertext of the out-of-warehouse management device ID and the in-warehouse management device ID includes:

[0093] If the network state between the out-of-warehouse management device and the trusted platform is connected, the private keys corresponding to the out-of-warehouse management device and the in-of-warehouse management device are obtained according to the out-of-warehouse management device ID and the in-of-warehouse management device ID, and the information of the trusted platform is encrypted by the private keys corresponding to the out-of-warehouse management device and the in-of-warehouse management device and then sent to the out-of-warehouse management device and the in-of-warehouse management device;

[0094] If the network state between the out-of-warehouse management device and the trusted platform is disconnected, the private keys corresponding to the out-of-warehouse management device and the in-of-warehouse management device are obtained through the encryption chip set in the out-of-warehouse management device, and the information of the out-of-warehouse management device is encrypted by the private keys corresponding to the out-of-warehouse management device and the in-of-warehouse management device and then sent to the out-of-warehouse management device and the in-of-warehouse management device;

[0095] The out-of-warehouse management device and the in-of-warehouse management device establish a connection with the out-of-warehouse management device after identity verification of the trusted platform or the out-of-warehouse management device to the out-of-warehouse management device;

[0096] According to the connection between the out-of-warehouse management device and the out-of-warehouse management device and the in-of-warehouse management device, the out-of-warehouse data sent by the out-of-warehouse management device and the in-of-warehouse data sent by the in-of-warehouse management device are obtained.

[0097] Optionally, if the network state between the out-of-warehouse management device and the trusted platform is disconnected, the encryption chip set in the out-of-warehouse management device is enabled by a preset password before the private keys corresponding to the out-of-warehouse management device and the in-of-warehouse management device are obtained through the encryption chip.

[0098] The above scheme can further improve the reliability of the system, avoid the establishment of a connection between a counterfeit encryption communication terminal and the out-of-warehouse management device and the in-of-warehouse management device, and cause the information of the materials in and out of the warehouse to be unable to be correctly recorded.

[0099] S2, consistency verification is performed on the out-of-warehouse data and the in-of-warehouse data, and when the consistency verification passes, the evidence data is obtained according to the out-of-warehouse data and / or the in-of-warehouse data.

[0100] Optionally, the consistency verification at least includes verification of the types and quantities of the goods in the out-of-warehouse data and the in-of-warehouse data, and when the quantity of the goods is large, accurate measurement is difficult, or there is transmission loss, the out-of-warehouse data and the in-of-warehouse data are allowed to have a certain range of differences.

[0101] Optionally, when the out-of-warehouse data and the in-of-warehouse data have a certain range of differences, it can be agreed to follow the out-of-warehouse data or the in-of-warehouse data, or the out-of-warehouse data and the in-of-warehouse data can be recorded respectively.

[0102] Optionally, the storage evidence data is configured to at least include the out-of-warehouse data or the in-warehouse data, the out-of-warehouse data and / or the in-warehouse data agreed by the out-of-warehouse management device and the in-warehouse management device is defined as the standard data, the storage evidence data can be configured as the standard data itself or the standard data signed or encrypted by the encrypted communication terminal, or can be configured as the standard data signed or encrypted by both the out-of-warehouse management device and the in-warehouse management device, or can be configured as the standard data signed or encrypted by the out-of-warehouse management device, the in-warehouse management device and the encrypted communication terminal.

[0103] Optionally, in the step of verifying the consistency of the out-of-warehouse data and the in-warehouse data, the condition for passing the consistency verification includes at least one of the following conditions:

[0104] The out-of-warehouse data and the in-warehouse data are completely consistent.

[0105] The difference between the out-of-warehouse data and the in-warehouse data does not exceed a preset threshold.

[0106] The out-of-warehouse management device and the in-warehouse management device confirm that the out-of-warehouse data or the in-warehouse data is correct.

[0107] In some cases, the material itself may have some errors during transportation, such as diesel and natural gas during out-of-warehouse, in-warehouse and transportation. In a certain range, it is impossible to avoid the difference and loss of transportation. When the difference between the out-of-warehouse data and the in-warehouse data of such materials does not exceed the preset threshold, the consistency verification can still pass.

[0108] Optionally, in the step of verifying the consistency of the out-of-warehouse data and the in-warehouse data, when the consistency verification passes, the out-of-warehouse data and the in-warehouse data can be data encrypted by the public key of the encrypted communication terminal.

[0109] S3, obtain the network state between the encrypted communication terminal and the trusted platform.

[0110] Optionally, the encrypted communication terminal obtains the network state between the encrypted communication terminal and the trusted platform, and the network state at least includes connection and disconnection, and can also include signal strength, bandwidth, communication quality and other parameters.

[0111] S4, if the network state between the encrypted communication terminal and the trusted platform is connected, upload the storage evidence data to the trusted platform.

[0112] Optionally, when the encrypted communication terminal uploads the storage evidence data to the trusted platform, the storage evidence data is encrypted by the public key of the trusted platform, and the trusted platform decrypts the encrypted storage evidence data by the private key of the trusted platform to obtain the storage evidence data.

[0113] Optionally, the encrypted communication terminal can be adapted to multiple trusted platforms, and the encrypted communication terminal encrypts the evidence storage data according to the information of the connected trusted platform.

[0114] S5. If the network status with the trusted platform is disconnected, request the outbound management device and the inbound management device to sign the evidence data and then store the signed data.

[0115] Optionally, when establishing a connection with outbound management equipment and inbound management equipment, it also includes:

[0116] Distribute the stored signature data to outbound management devices and / or inbound management devices;

[0117] Obtain other signature data stored in the outbound management device and / or inbound management device, which is configured to be stored as signature data distributed to the outbound management device and / or inbound management device by other encrypted communication terminals.

[0118] Using the above method, data that was previously generated by other encrypted communication terminals but not uploaded to the trusted platform can be obtained from the outbound management device and / or inbound management device. When the current encrypted terminal establishes a connection with the trusted platform, it can upload this data on behalf of the device.

[0119] Optionally, when establishing a connection with outbound management equipment and inbound management equipment, it also includes:

[0120] Obtain permissions for outbound management devices and / or inbound management devices;

[0121] Based on the permissions of the outbound management device and / or the inbound management device, the stored signature data corresponding to the permissions of the outbound management device and / or the inbound management device is distributed to the outbound management device and / or the inbound management device.

[0122] Obtain other signature data stored in the outbound management device and / or inbound management device, which is configured to be stored as signature data distributed to the outbound management device and / or inbound management device by other encrypted communication terminals.

[0123] Optionally, after disconnecting from the outbound management device and the inbound management device, it also includes:

[0124] Continuously monitor the network status with the trusted platform;

[0125] When the network connection with the trusted platform is established, all stored signature data will be uploaded to the trusted platform.

[0126] Optionally, when the network state with the trusted platform is connected, all stored signature data is uploaded to the trusted platform, including:

[0127] When the network state between the trusted platform is connected, obtaining the signature data received by the trusted platform in a preset period as the first signature data, the preset period is from the current time to the time when the connection with the trusted platform is disconnected last time;

[0128] After deleting the repeated signature data in the stored all signature data from the first signature data, uploading the stored all signature data to the trusted platform.

[0129] Optionally, the first signature data is structured data, when the trusted platform

[0130] Optionally, the first signature data can include the unique identifier of each encrypted communication terminal and the time when the latest signature data corresponding to the encrypted communication terminal is received, and deleting the repeated signature data in the stored all signature data from the first signature data means deleting all the signature data before the time of the latest signature data of the encrypted communication terminal according to the time of the latest signature data corresponding to the encrypted communication terminal.

[0131] Optionally, the first signature data can include the unique identifier of each outbound management device and / or inbound management device and the time when the latest signature data corresponding to the outbound management device and / or inbound management device is received, and deleting the repeated signature data in the stored all signature data from the first signature data means deleting all the signature data before the time of the latest signature data of the outbound management device and / or inbound management device according to the time of the latest signature data corresponding to the outbound management device and / or inbound management device.

[0132] Optionally, when the connection with the outbound management device and the inbound management device is established, further comprising:

[0133] Sending the obtained first signature data to the outbound management device and / or the inbound management device to make the outbound management device and / or the inbound management device delete the signature data corresponding to the first signature data stored in the database.

[0134] Optionally, when the encrypted communication terminal establishes a connection with other encrypted communication terminals, further comprising: synchronizing the signature data and the first signature data between the encrypted communication terminal and the other encrypted communication terminals.

[0135] Optionally, when the network state between the trusted platform is connected, uploading the stored all signature data to the trusted platform, further comprising:

[0136] According to the stored all signature data, obtaining the priority order of all the signature data;

[0137] According to the priority order of all the signature data, uploading the stored all signature data to the trusted platform.

[0138] Optionally, the method for obtaining the priority order of all signature data includes one or more of the following methods:

[0139] Set the signature data associated with this encrypted communication terminal to the first priority, and set the signature data associated with other encrypted communication terminals to the second priority;

[0140] The signature data is sorted according to the time it was generated, prioritizing the first priority signature data.

[0141] The signature data is sorted according to the time it was generated;

[0142] The signature data is sorted according to the number of times it has been propagated.

[0143] Furthermore, the sorting of the second-priority signature data based on the number of times the signature data has been propagated is configured such that the more times the signature data has been synchronized to other encrypted communication terminals before being synchronized to this encrypted communication terminal, the later the signature data is sorted.

[0144] By adopting the above scheme, the transmission efficiency of the entire data transmission network can be further optimized, so that the optimal data transmission scheme can be selected when the connection between the encrypted communication terminal and the trusted platform is unstable, and the signature data that is not easily transmitted to the trusted platform by other encrypted communication terminals can be transmitted to the trusted platform first.

[0145] By adopting the above scheme, signature data is stored in a distributed manner through distributed encrypted communication terminals. As long as one encrypted communication terminal can establish a connection with the trusted platform, the signature data can be uploaded, which further solves the problem of insufficient communication confidentiality and stability of existing material management schemes in harsh environments.

[0146] Example 3

[0147] Based on Embodiments 1 and 2, this embodiment provides a materials management system based on a trusted platform, including a trusted platform, an encrypted communication terminal, outbound management equipment, and inbound management equipment.

[0148] The outbound management equipment is configured as follows:

[0149] The system scans incoming and outgoing materials to obtain outgoing data and then sends the outgoing data to an encrypted communication terminal.

[0150] The inbound management equipment is configured as follows:

[0151] The incoming materials are scanned to obtain the entry data, and the entry data is sent to the encrypted communication terminal.

[0152] The encrypted communication terminal is configured as follows:

[0153] establishing connection with the warehouse-out management device and the warehouse-in management device, obtaining warehouse-out data sent by the warehouse-out management device and warehouse-in data sent by the warehouse-in management device;

[0154] performing consistency verification on the warehouse-out data and the warehouse-in data, and when the consistency verification passes, obtaining evidence data according to the warehouse-out data and / or the warehouse-in data;

[0155] obtaining a network state between the trusted platform;

[0156] if the network state between the trusted platform is connected, uploading the evidence data to the trusted platform;

[0157] if the network state between the trusted platform is disconnected, requesting the warehouse-out management device and the warehouse-in management device to sign the evidence data and storing signature data obtained after the signing;

[0158] The trusted platform is configured to:

[0159] receive and store the evidence data sent by the encrypted communication terminal.

[0160] Optionally, the encrypted communication terminal is further configured to:

[0161] when the connection with the warehouse-out management device and the warehouse-in management device is established:

[0162] distribute the stored signature data to the warehouse-out management device and / or the warehouse-in management device;

[0163] obtain other signature data stored by the warehouse-out management device and / or the warehouse-in management device, the other signature data being configured to be stored by signature data distributed to the warehouse-out management device and / or the warehouse-in management device by other encrypted communication terminals.

[0164] Optionally, the encrypted communication terminal is further configured to:

[0165] when the connection with the warehouse-out management device and the warehouse-in management device is established:

[0166] obtain the permissions of the warehouse-out management device and / or the warehouse-in management device;

[0167] distribute the stored signature data corresponding to the permissions of the warehouse-out management device and / or the warehouse-in management device to the warehouse-out management device and / or the warehouse-in management device according to the permissions of the warehouse-out management device and / or the warehouse-in management device;

[0168] obtain other signature data stored by the warehouse-out management device and / or the warehouse-in management device, the other signature data being configured to be stored by signature data distributed to the warehouse-out management device and / or the warehouse-in management device by other encrypted communication terminals.

[0169] Optionally, the encrypted communication terminal is further configured to:

[0170] When the connection with the warehouse-out management device and the warehouse-in management device is disconnected:

[0171] Continuously monitor the network status between the encrypted communication terminal and the trusted platform;

[0172] When the network status between the encrypted communication terminal and the trusted platform is connected, upload the stored all signature data to the trusted platform.

[0173] Optionally, when the network status between the encrypted communication terminal and the trusted platform is connected, upload the stored all signature data to the trusted platform, including:

[0174] When the network status between the encrypted communication terminal and the trusted platform is connected, obtain the signature data received by the trusted platform in a preset time period as the first signature data, the preset time period being from the current time to the time when the connection with the trusted platform was last disconnected;

[0175] After deleting the signature data duplicated with the first signature data from the stored all signature data, upload the stored all signature data to the trusted platform.

[0176] Optionally, the encrypted communication terminal is further configured to:

[0177] When the connection with the warehouse-out management device and the warehouse-in management device is established:

[0178] Send the obtained first signature data to the warehouse-out management device and / or the warehouse-in management device to make the warehouse-out management device and / or the warehouse-in management device delete the signature data corresponding to the first signature data stored in the database.

[0179] Optionally, the connection with the warehouse-out management device and the warehouse-in management device is established, and the warehouse-out data sent by the warehouse-out management device and the warehouse-in data sent by the warehouse-in management device are obtained, including:

[0180] Send a connection request to the warehouse-out management device and the warehouse-in management device to obtain the warehouse-out management device information and the warehouse-in management device information;

[0181] According to the warehouse-out management device information and the warehouse-in management device information, send the identity authentication information corresponding to the warehouse-out management device and the warehouse-in management device respectively to establish the connection with the warehouse-out management device and the warehouse-in management device;

[0182] According to the connection with the warehouse-out management device and the warehouse-in management device, obtain the warehouse-out data sent by the warehouse-out management device and the warehouse-in data sent by the warehouse-in management device.

[0183] Optionally, in the step of performing consistency verification on the warehouse-out data and the warehouse-in data, the condition for passing the consistency verification includes at least one of the following conditions:

[0184] Outbound data and inbound data are completely consistent;

[0185] The difference between outbound and inbound data does not exceed a preset threshold;

[0186] The confirmation of outbound management equipment and inbound management equipment shall be based on outbound data or inbound data.

[0187] Example 4

[0188] This embodiment provides a computer device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement any of the methods described above.

[0189] Specifically, such as Figure 2 As shown, Figure 2 This is a schematic diagram of the structure of a computer device according to this application. The computer device may include: a processor 101, such as a central processing unit (CPU), a communication bus 102, a user interface 104, a network interface 103, and a memory 105. The communication bus 102 is used to enable communication between these components. The user interface 104 may include a display screen and an input unit such as a keyboard. Optionally, the user interface 104 may also include a standard wired interface or a wireless interface. The network interface 103 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 105 may be a storage device independent of the aforementioned processor 101. The memory 105 may be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM), such as at least one disk storage device. The processor 101 may be a general-purpose processor, including a central processing unit, a network processor, etc., or it may be a digital signal processor, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component.

[0190] Those skilled in the art will understand that the appendix Figure 2 The structure shown does not constitute a limitation on the electronic device and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0191] like Figure 2 As shown, the memory 105, which serves as a storage medium, may include an operating system, a network communication module, a user interface module, and an application program for implementing a material management method based on a trusted platform.

[0192] In Figure 2 In the electronic device shown, the network interface 103 is mainly used for data communication with a network server; the user interface 104 is mainly used for data interaction with a user; the processor 101 and the memory 105 in the present application can be arranged in the electronic device, and the electronic device calls an application program stored in the memory 105 for implementing a kind of material management method based on trusted platform to realize the above-mentioned method by processor 101.

[0193] Embodiment 5

[0194] The embodiment provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program, and a processor executes the computer program to realize any of the above methods.

[0195] In some embodiments, the computer-readable storage medium can be FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disc or CD-ROM memory; it can also be various devices including one or any combination of the above storage. The computer can be various computing devices including smart terminals and servers.

[0196] In the above embodiments of the present disclosure, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.

[0197] In several embodiments provided in the present application, it should be understood that the disclosed technical content can be implemented by other ways. Among them, the above-described device embodiments are only schematic, for example, the division of units can be a logical function division, and actual implementation can have another division way, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, units or modules, which can be electrical or other forms.

[0198] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or they can be distributed on multiple units. According to actual needs, part or all of the units can be selected to achieve the purpose of the present embodiment scheme.

[0199] In addition, each function unit in various embodiments of the present disclosure can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.

[0200] When the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable nonvolatile storage medium. Based on this understanding, the technical solutions of the present disclosure, essentially or in other words, the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a nonvolatile storage medium, including a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the various embodiments of the present disclosure method. The aforementioned nonvolatile storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0201] The above is only the preferred embodiment of the present disclosure, and it should be pointed out that for those skilled in the art, without departing from the principles of the present disclosure, a number of improvements and refinements can be made, and these improvements and refinements should be considered as the protection scope of the present disclosure.

Claims

1. A material management method based on a trusted platform, characterized in that, Applied to encrypted communication terminals, including: Establish a connection with outbound management equipment and inbound management equipment to obtain outbound data sent by outbound management equipment and inbound data sent by inbound management equipment; The consistency of the outbound data and the inbound data is verified. When the consistency verification is successful, the evidence data is obtained based on the outbound data and / or the inbound data. Obtain the network status with the trusted platform; If the network connection with the trusted platform is established, the evidence data will be uploaded to the trusted platform. If the network status with the trusted platform is disconnected, request the outbound management device and the inbound management device to sign the evidence data and obtain the signature data for storage. When establishing a connection with outbound and inbound management devices, it also includes: Distribute the stored signature data to the outbound management device and / or the inbound management device; Obtain other signature data stored in the outbound management device and / or the inbound management device, wherein the other signature data is configured to be distributed by other encrypted communication terminals to the outbound management device and / or the inbound management device for storage; After disconnecting from the outbound and inbound management devices, it also includes: Continuously monitor the network status with the trusted platform; When the network status with the trusted platform is connected, all stored signature data will be uploaded to the trusted platform. When the network connection with the trusted platform is established, all stored signature data will be uploaded to the trusted platform, including: Based on all stored signature data, obtain the priority sort of all signature data; Based on the priority of all signature data, all stored signature data is uploaded to the trusted platform; Methods for obtaining the priority order of all signature data include: Set the signature data associated with this encrypted communication terminal to the first priority, and set the signature data associated with other encrypted communication terminals to the second priority.

2. The material management method based on a trusted platform according to claim 1, characterized in that, When establishing a connection with outbound and inbound management devices, it also includes: Obtain permissions for the outbound management device and / or the inbound management device; Based on the permissions of the outbound management device and / or the inbound management device, the stored signature data corresponding to the permissions of the outbound management device and / or the inbound management device is distributed to the outbound management device and / or the inbound management device. Obtain other signature data stored in the outbound management device and / or the inbound management device, wherein the other signature data is configured to be stored as signature data distributed to the outbound management device and / or the inbound management device by other encrypted communication terminals.

3. The material management method based on a trusted platform according to claim 1, characterized in that, When the network connection with the trusted platform is established, uploading all stored signature data to the trusted platform includes: When the network status with the trusted platform is connected, the signature data received by the trusted platform within a preset time period is the first signature data, where the preset time period is from the current time to the last time the connection with the trusted platform was disconnected. After deleting any signature data that is duplicated in the first signature data from all stored signature data, upload all stored signature data to the trusted platform.

4. The material management method based on a trusted platform according to claim 3, characterized in that, When establishing a connection with the outbound management device and the inbound management device, the following is also included: The acquired first signature data is sent to the outbound management device and / or the inbound management device so that the outbound management device and / or the inbound management device delete the signature data corresponding to the first signature data stored in the database.

5. The material management method based on a trusted platform according to claim 1, characterized in that, The process of establishing a connection with the outbound management device and the inbound management device to obtain outbound data sent by the outbound management device and inbound data sent by the inbound management device includes: Send connection requests to the outbound management device and the inbound management device to obtain outbound management device information and inbound management device information; Based on the outbound management device information and the inbound management device information, authentication information corresponding to the outbound management device and the inbound management device is sent respectively to establish a connection with the outbound management device and the inbound management device; Based on the connection between the outbound management device and the inbound management device, outbound data sent by the outbound management device and inbound data sent by the inbound management device are obtained.

6. The material management method based on a trusted platform according to claim 1, characterized in that, In the step of verifying the consistency of the outbound data and the inbound data, the conditions for passing the consistency verification include at least one of the following conditions: The outbound data and the inbound data are completely consistent; The difference between the outbound data and the inbound data does not exceed a preset threshold; The outbound management device and the inbound management device confirm that the outbound data or the inbound data shall prevail.

7. A materials management system based on a trusted platform, characterized in that, This includes a trusted platform, encrypted communication terminals, outbound management devices, and inbound management devices. The outbound management device is configured as follows: The system scans incoming and outgoing materials to obtain outgoing data and then sends the outgoing data to an encrypted communication terminal. The warehouse management device is configured as follows: The incoming materials are scanned to obtain the entry data, and the entry data is sent to the encrypted communication terminal. The encrypted communication terminal is configured as follows: Establish a connection with outbound management equipment and inbound management equipment to obtain outbound data sent by outbound management equipment and inbound data sent by inbound management equipment; The consistency of the outbound data and the inbound data is verified. When the consistency verification is successful, the evidence data is obtained based on the outbound data and / or the inbound data. Obtain the network status with the trusted platform; If the network connection with the trusted platform is established, the evidence data will be uploaded to the trusted platform. If the network status with the trusted platform is disconnected, request the outbound management device and the inbound management device to sign the evidence data and obtain the signature data for storage. After disconnecting from the outbound and inbound management devices, it also includes: Continuously monitor the network status with the trusted platform; When the network status with the trusted platform is connected, all stored signature data will be uploaded to the trusted platform. When the network connection with the trusted platform is established, all stored signature data will be uploaded to the trusted platform, including: Based on all stored signature data, obtain the priority sort of all signature data; Based on the priority of all signature data, all stored signature data is uploaded to the trusted platform; Methods for obtaining the priority order of all signature data include: Set the signature data associated with this encrypted communication terminal to the first priority, and set the signature data associated with other encrypted communication terminals to the second priority; The trusted platform is configured as follows: The evidence data sent by the encrypted communication terminal is received and stored.

Citation Information

Patent Citations

  • Dynamic decoding method and system

    CN114499955A

  • Plate management method and device based on block chain, equipment and medium

    CN115936732A