Multi-dimensional dynamic trust chain mechanism construction method and system based on national secret algorithm

By constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms, using SM2 encryption to achieve decentralized identity authentication, SM3 hash algorithm to ensure the integrity of behavioral data, and SM4 encryption to achieve dynamic rewards and punishments, the systemic defects of traditional trust management models are solved, and the security and efficiency of the power trading platform are improved.

CN121418072APending Publication Date: 2026-01-27STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511536496.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-27
Publication Date
2026-01-27

AI Technical Summary

Technical Problem

Traditional trust management models suffer from systemic defects in multi-party collaboration, such as difficulty in verifying identity authenticity, difficulty in quantifying the credibility of behavior, and lack of incentive and constraint mechanisms. This leads to single-point failure of centralized CA institutions, high latency of RSA authentication, limited data integrity of international hash algorithms, low activity of blockchain nodes, and insufficient identification rate of malicious behavior, making it difficult to dynamically respond to collaborative scenarios.

Method used

A multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms is constructed. SM2 asymmetric encryption is used to achieve decentralized identity authentication, SM3 hash algorithm is used to ensure the integrity of behavioral data, SM4 symmetric encryption is used to achieve dynamic rewards and punishments, and blockchain smart contracts are used to realize the automated calculation of trust values ​​and access control, thus constructing a three-layer trust model of identity-behavior-incentive.

Benefits of technology

It enhances the security and efficiency of identity authentication, ensures the immutability and transparency of behavioral data, optimizes resource utilization, increases node activity and trust, forms a closed-loop incentive system, and improves the operational efficiency and security of the power trading platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121418072A_ABST
    Figure CN121418072A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-dimensional dynamic trust chain mechanism construction method and system based on a national secret algorithm. The method comprises construction of an identity layer, a behavior layer and an excitation layer. And the identity layer realizes decentralized identity anchoring and two-factor identity binding by using SM2 encryption. And the behavior layer audits on-chain behaviors through an SM3 hash algorithm, dynamically updates a reputation value based on user operation by using an intelligent contract and carries out on-chain. The incentive layer triggers awards according to the node reputation value and the active time and generates tokens and key fragments for uplink storage by adopting SM4 encryption, and the nodes decrypt and recover the key through reputation proof. According to the method and the system provided by the invention, closed-loop management of identity verification, behavior auditing and a dynamic incentive mechanism is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of blockchain and cryptography technology, specifically relating to a method and system for constructing a multi-dimensional dynamic trust chain mechanism based on Chinese national cryptographic algorithms. Background Technology

[0002] As my country's independently controllable cryptographic standard system, the national cryptographic algorithm includes SM2 (asymmetric encryption), SM3 (hash algorithm), and SM4 (symmetric encryption), which are used to replace international algorithms RSA, SHA-256, and AES, respectively, and have the advantages of high security strength, compliance, and hardware acceleration performance. Dynamic trust chain technology constructs full lifecycle security through "static root of trust expansion + dynamic behavior monitoring," using hook functions to monitor application behavior in real time and dynamically adjusting node trust values ​​through an active immune mechanism.

[0003] Patent application CN110868301A proposes a unified identity authentication system based on Chinese national cryptographic algorithms, integrating SM2 / SM3 for encryption / decryption and digital signatures, thus improving the security and efficiency of identity verification. Patent application CN114915396A proposes a jump-key digital communication encryption method, comprehensively utilizing SM2, SM3, and SM4 and introducing a pseudo-random jump-key mechanism to dynamically generate session keys and encrypt transmission, significantly reducing the risk of a single key being cracked.

[0004] However, traditional trust management models suffer from systemic flaws in multi-party collaborations, such as difficulty in verifying identity authenticity, difficulty in quantifying behavioral credibility, and a lack of incentive and constraint mechanisms. Specifically, PKI systems rely on centralized CA institutions, leading to single points of failure and forgery risks; RSA authentication suffers from high latency; international hash algorithms offer limited data integrity guarantees, making it difficult for smart contracts to adjust permissions in real time; while blockchain offers immutability, its identity layer does not fully adopt national cryptographic algorithms and lacks tokenization incentives, resulting in low node activity, insufficient malicious behavior detection rates, and difficulty in dynamically responding to collaborative scenarios. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this application proposes a multi-dimensional dynamic trust chain mechanism that integrates national cryptographic algorithms and blockchain. This mechanism constructs a three-layer trust model of "identity-behavior-incentive," combining SM2 asymmetric encryption for decentralized identity authentication, SM3 hash algorithm to ensure the integrity of behavioral data, SM4 symmetric encryption for dynamic rewards and punishments, and automated calculation of trust values ​​and access control through blockchain smart contracts.

[0006] The first aspect of this application discloses a method for constructing a multi-dimensional dynamic trust chain mechanism based on Chinese cryptographic algorithms, employing the following technical solution: An identity layer, a behavior layer, and an incentive layer are built on the power trading platform. The identity layer uses SM2 asymmetric encryption to perform decentralized identity anchoring, the behavior layer uses the SM3 hash algorithm to audit on-chain behavior, and the incentive layer uses SM4 symmetric encryption technology to encrypt dynamic reward and punishment information. Based on the aforementioned identity layer, a decentralized identity anchor is established on the blockchain, and a two-factor identity binding is performed using the SM2 key combined with biometrics; the verifier queries the user's public key and verifies the SM2 signature through the blockchain smart contract, and performs authorized operations based on the verification result; A behavior trust update mechanism is constructed at the behavior layer; regulatory rules are encoded in smart contracts to conduct real-time auditing of user operations and detection of risky behaviors; based on malicious behavior and valid verification behavior, the smart contract automatically executes a dynamic reputation update algorithm and records it on the blockchain; An incentive and reward mechanism is established for the incentive layer. Plaintext rewards are triggered based on the node's current reputation value and activity interval. Tokens are generated and uploaded to the blockchain using SM4 encryption. The SM4 key is associated with the node's current reputation value to generate an encrypted working key. The encrypted working key is then stored on the blockchain as ciphertext in shards. The node decrypts and restores the data using the latest reputation proof.

[0007] Furthermore, the two-factor identity binding process includes: Generate biometric hash values ​​based on user's biometric information. Use private key pair Perform SM2 signing to obtain the signature value ; Verification is achieved by querying the user's public key via a blockchain smart contract. And verify the signature value Whether the signature verification is valid; if the signature verification passes, the user's identity is granted permission; if it fails, the user's request is rejected and the on-chain malicious behavior counter is updated. The system will then lower the user's reputation score according to the outer deduction rules, triggering permission restrictions.

[0008] Furthermore, the behavior trust update mechanism includes: When users perform operations using decentralized identities, log entries containing metadata are generated; sensitive and non-sensitive data in the log entries are encrypted using different encryption algorithms, and the encrypted hash value corresponding to the sensitive data is uploaded to the blockchain; Define and write regulatory rules for smart contracts, including defining violations, risky operations, and unauthorized operations; smart contracts compare transaction content with regulatory rules, identify transactions that violate regulatory rules, and record them on the blockchain; It employs a built-in dynamic reputation update algorithm to update the user's current reputation value and adjust permissions based on the number of violations of regulatory rules.

[0009] Furthermore, the dynamic reputation update algorithm is an assignment statement; Calculate the updated reputation value, which is the sum of the current reputation value and the valid verification reward value, minus the malicious behavior penalty value; where the valid verification reward value is the product of the number of valid verification behaviors and the reward coefficient, and the malicious behavior penalty value is the product of the number of malicious behaviors and the penalty coefficient. The calculated updated reputation value is assigned to the new current reputation value.

[0010] Furthermore, based on the new current reputation value, dynamic access control is implemented, including: If the new current reputation value is less than the first threshold, the smart contract will mark the corresponding user as a restricted node and restrict their operation permissions; If the new current reputation value is greater than or equal to the first threshold and less than the second threshold, the smart contract will mark the corresponding user as a normal node and maintain the existing permissions; If the new current reputation value is greater than or equal to the second threshold, the smart contract will mark the corresponding user as a high-trust node and update the permission level.

[0011] Furthermore, the reward and penalty coefficients are adjusted based on behavioral patterns within the period, including: The total number of actions within a defined period is the sum of the number of malicious actions and the number of valid verification actions; Percentage of malicious behavior within the calculation period The calculation method is the ratio of the number of malicious actions within a period to the total number of actions within a period; if Then set ;like Then set ;like Then set ; in, and These are the first and second segment thresholds for the proportion of malicious behavior, respectively. Furthermore, the update method for the reward coefficient includes: Percentage of valid verification actions within the calculation period The calculation method is the ratio of the number of valid verification actions within the period to the total number of actions within the period; then the reward coefficient... Updated to ; In the formula, This is the proportionality coefficient. It is a constant.

[0012] Furthermore, plaintext rewards are triggered based on the node's current reputation value and activity time interval, including: When the node's current reputation value And active time interval When this occurs, an exponentially decaying excitation function is triggered, expressed as: ,in, For explicit rewards, This is the gain coefficient. This is the time decay factor.

[0013] Furthermore, the incentive and reward / punishment mechanism also includes: Combine the hash value of the current reputation value with the master key Perform a bitwise XOR operation to generate a one-time encryption factor, and perform an encryption operation on the one-time encryption factor and the SM4 key to generate an encryption working key; The encryption working key is split into ciphertext. Each shard is distributed and stored across multiple nodes on the chain and in the executable environment; Set a reconstruction threshold When any When a fragment is completed and the latest reputation proof passes verification, fragment merging and decryption can be performed to restore the SM4 key.

[0014] The second aspect of this application discloses a system for constructing a multi-dimensional dynamic trust chain mechanism based on Chinese cryptographic algorithms, which executes the multi-dimensional dynamic trust chain mechanism construction method described in the first aspect of this application. The system includes: Trust chain initialization module; used to build identity layer, behavior layer and incentive layer on power trading platform; the identity layer uses SM2 asymmetric encryption to perform decentralized identity anchoring, the behavior layer uses SM3 hash algorithm to audit on-chain behavior, and the incentive layer uses SM4 symmetric encryption technology to encrypt dynamic reward and punishment information; An identity verification mechanism construction module is used to establish a decentralized identity anchor on the blockchain based on the identity layer, and to use the SM2 key combined with biometrics for two-factor identity binding; the verifier queries the user's public key and verifies the SM2 signature through the blockchain smart contract, and performs authorized operations according to the verification result; A behavioral trust update mechanism construction module is used to build a behavioral trust update mechanism at the behavioral layer; to encode regulatory rules in smart contracts to perform real-time auditing of user operations and detection of risky behaviors; and to automatically execute a dynamic reputation update algorithm and record it on the blockchain based on malicious behavior and valid verified behavior. The incentive and reward mechanism construction module is used to establish the incentive and reward mechanism of the incentive layer. Plaintext rewards are triggered based on the node's current reputation value and active time interval. Tokens are generated through SM4 encryption and uploaded to the chain. The SM4 key is associated with the node's current reputation value to generate an encrypted working key. The encrypted working key is stored on the chain as ciphertext in shards. The node decrypts and restores the tokens using the latest reputation proof.

[0015] The beneficial effects of this invention are that, compared with the prior art, 1. Improved Decentralized Identity Anchoring and Authentication Efficiency: This application implements decentralized identity anchoring based on national cryptographic algorithms, using SM2 asymmetric encryption to generate decentralized identity identifiers (DIDs), and combining SM2 signatures with biometric two-factor authentication to replace traditional CA certificates. This method not only enhances the security of identity authentication but also improves authentication efficiency, providing a more efficient and secure identity verification mechanism for power trading platforms.

[0016] 2. Immutable Behavioral Audit Chain and Data Integrity Guarantee: This application utilizes the SM3 hash algorithm to ensure the integrity of on-chain behavioral data and dynamically adjusts user reputation values ​​through smart contracts. This solution can detect and record violations in real time, ensuring the immutability and transparency of the audit chain. Simultaneously, sensitive data is stored using SM4 encryption, which not only protects privacy but also improves audit throughput, providing regulatory agencies with efficient real-time auditing and risk management tools.

[0017] 3. Closed-loop incentive system and resource utilization optimization: This application implements a dynamic tokenized reward and punishment mechanism through SM4 symmetric encryption, combined with a reputation value tiering model, dynamically allocating permissions and rewards based on the node's reputation value and activity time interval. This closed-loop incentive system can effectively incentivize nodes to participate in behavioral verification, improve the system's resource utilization, and reduce the probability of malicious behavior, thereby improving the platform's overall operational efficiency and trustworthiness.

[0018] In summary, this application constructs a highly secure and efficient trust management framework for power trading platforms. SM2 encryption enables decentralized identity anchoring and two-factor authentication, ensuring the security and compliance of user identities. The SM3 hash algorithm guarantees the immutability of behavioral data, and smart contracts enable dynamic reputation updates and permission adjustments. Simultaneously, a tokenized reward and punishment mechanism based on SM4 encryption technology provides closed-loop incentives for nodes, optimizing resource allocation and preventing malicious behavior. This system not only improves the platform's operational transparency and auditing efficiency but also enhances trust among nodes, providing theoretical support and a basis for promoting the sustainable and secure operation of power trading platforms. Attached Figure Description

[0019] Figure 1 A diagram illustrating the architecture of a multi-dimensional dynamic trust chain system based on national cryptographic algorithms and blockchain, provided for this embodiment; Figure 2 An initialization diagram of a multi-dimensional dynamic trust chain system provided for an embodiment; Figure 3 The flowchart illustrates the execution steps of the multidimensional dynamic trust chain construction method provided in this embodiment. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this invention. The embodiments described in this application are merely some embodiments of this invention, and not all embodiments. Based on the spirit of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of this invention.

[0021] Example 1 This embodiment discloses a specific implementation method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms and blockchain. To more concretely illustrate this application, the specific implementation method of this embodiment will be described in conjunction with an electricity trading scenario.

[0022] Step 1: Construct a multi-dimensional dynamic trust chain system based on national cryptographic algorithms and blockchain. This system combines national cryptographic algorithms and blockchain technology to build a security framework integrating identity verification, behavior auditing, and dynamic reward and punishment mechanisms. In this application, unless otherwise specified, "node" refers to a user entity participating in the blockchain network and possessing a decentralized identity (DID), and is the object of the three-layer trust model of identity, behavior, and incentives.

[0023] Reference Figure 1 , Figure 1 This is a system architecture diagram for a multi-dimensional dynamic trust chain based on Chinese national cryptographic algorithms and blockchain. The system, deployed in a power trading platform, comprises three core layers: identity, behavior, and incentive. Each layer deploys specific Chinese national cryptographic algorithm components to ensure security and efficiency. (Refer to...) Figure 2 , Figure 2 This is the initialization diagram for a multi-dimensional dynamic trust chain system. The specific system architecture and deployment are as follows: The identity layer is responsible for decentralized identity management, using SM2 asymmetric encryption to generate key pairs for identity anchoring. This layer is primarily deployed on lightweight devices for key generation and authentication. By deploying the identity layer on lightweight terminals such as smart meters, power plants generate key pairs using the SM2 algorithm, such as power plant A's key pair. This enables decentralized identity anchoring.

[0024] The behavior layer uses the SM3 hash algorithm to audit actions on the blockchain, ensuring the immutability and integrity of the data. This layer is deployed on the blockchain nodes and is responsible for handling the storage and verification of audit logs. The behavior layer is deployed on the power grid company's blockchain nodes, using the SM3 hash algorithm to record electricity purchase transactions, such as generating LogHash from a user's electricity purchase record.

[0025] The incentive layer uses SM4 symmetric encryption technology to encrypt dynamic reward and punishment information, ensuring that the incentive and reward / punishment mechanisms in the system are encrypted and protected. This layer manages keys through a Hardware Security Module (HSM) to ensure key security and system load capacity. The incentive layer manages SM4 keys through the HSM module of the power dispatch center, encrypting electricity fee reward tokens, such as a reward of 0.1 yuan per kilowatt-hour.

[0026] The multi-dimensional dynamic trust chain system operates within a blockchain smart contract environment, supporting high-concurrency scenarios. The blockchain's smart contracts ensure that operations at each level are self-executable and immutable. Each level can be independently configured with resources to adapt to different load requirements. Resource allocation and adjustment are dynamically handled by the system to ensure efficient operation.

[0027] Specifically, the system adopts a dynamic resource allocation strategy, using a priority queue for load balancing, with the priority queue order being Identity Layer > Behavior Layer > Incentive Layer. When the peak transaction volume at the Behavior Layer exceeds a certain value (e.g., 1000 TPS), 50% of redundant node resources can be automatically allocated using Kubernetes containerization technology, achieving second-level scaling and ensuring efficient resource utilization. Table 1 shows a partial functional mapping of the national cryptographic algorithm in the three-layer architecture.

[0028] Table 1 Function Mapping Table

[0029] The following is combined with Figure 3 This paper describes the specific implementation of the method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms provided in this application. Figure 3 A flowchart illustrating the execution steps of a method for constructing a multidimensional dynamic trust chain.

[0030] Step 2: For the identity layer of the security framework built in Step 1, establish a decentralized identity anchor on the blockchain and use SM2 keys combined with biometric factors to achieve two-factor binding; the smart contract initializes and maintains the identity status and reputation, and links reputation penalties when authentication fails.

[0031] The initial state is defined by a smart contract, and participants generate key pairs locally and store them on the blockchain. The blockchain only stores non-sensitive data such as public keys and cryptographic digests, while the original identity data, original biometrics, and private keys are isolated throughout the secure execution environment of the user's terminal device, forming a complete privacy protection loop.

[0032] 2.1; Local key pair generation and initial registration; 2.1 (Decentralized Identifier) ​​generation Participants generate SM2-compliant asymmetric encryption key pairs locally. The public key The corresponding private key serves as the core credential for identity verification. Stored with strict confidentiality by the user.

[0033] To prevent replay attacks and identity conflicts, an unpredictable cryptographic random number, RandomNonce, is introduced, which is generated by a cryptographically secure random number generator.

[0034] public key Concatenate the random number RandomNonce with the hash calculated using SM3, and use it as a unique DID identifier; the calculation process is represented as follows: .

[0035] This process ensures that even if the same user registers multiple times, completely different DID identifiers will be generated due to the differences in random numbers, while protecting the original key information from being reverse-engineered.

[0036] Build a DID document containing the public key. Metadata such as server endpoints, claims, and signature policies. Calculate the SM3 digest DocHash for DIDDocument.

[0037] public key The abstract DocHash and ID are publicly stored on the blockchain through transactions, providing an immutable proof of existence. The smart contract initializes the initial reputation value and basic permissions of the identity.

[0038] The original DID document and private key are stored locally by the user or in a distributed storage system containing user notifications. The identity state of the DID is initialized on the blockchain via a smart contract: setting an initial reputation value. It also defines basic permission levels, establishing a traceable and programmable governance framework for subsequent dynamic adjustment of reputation and permission control.

[0039] Throughout the entire process, the blockchain only stores cryptographic digests; the original identity data is always managed by the user and is not stored in plaintext on the blockchain.

[0040] 2.2 Two-Factor Authentication Mechanism Users collect biometric features using biosensors (fingerprints, irises, etc.) to generate cryptographic hash values. This ensures that the original biological information cannot be restored.

[0041] Use user private key right Make an SM2 signature It achieves dual identity binding at the cryptographic level, proving that the user holds a legitimate private key and verifying the correlation between biometric features and the identity subject.

[0042] The verifier receives the signature and biohash Then, the DID public key previously established by the user is retrieved through a blockchain smart contract. Verify the signature validity by calling the SM2 signature verification algorithm: This process demonstrates the mechanism's three important characteristics: zero knowledge, decentralization, and real-time operation.

[0043] If the signature verification is successful, the user is considered to possess the key and the biometric data matches, thus determining the user to be a legitimate identity holder and granting the corresponding permissions.

[0044] If signature verification fails, the current access request is immediately rejected; the smart contract records each failure and updates the on-chain malicious behavior counter. And reduce reputation value / trigger restrictions according to the rules.

[0045] As one implementation method for this step, the following is a specific scenario implementation path: Power plant A generates its own SM2 key pair Generate a random number (RandomNonce) and calculate its hash: The data is stored in the power grid blockchain to complete identity verification.

[0046] Dispatcher C generates its own SM2 key pair And upload it to the blockchain.

[0047] Power plant A uses private key right Make a signature and will sign Stored in the DID document of dispatcher C as an authorization certificate for the organization.

[0048] When dispatcher C logs in, their fingerprint is collected, generating a biometric hash value. Power plant A uses a private key. right Make a signature: .

[0049] When dispatcher C initiates an operation, it obtains data from the blockchain. ,use Verify signature Verify if it is indeed C. Use the public key of power plant A. Verify signature Confirm whether C is authorized by power plant A.

[0050] If verification fails, the outer reputation penalty is triggered, and the reputation value is updated. ; ; This is the current reputation value. This is the penalty coefficient for malicious behavior (default value is 0.5). Failed identity authentication is also defined as a type of "malicious behavior." The reputation value update and access control here apply to dispatcher C. If dispatcher C fails to verify multiple times, the reputation value of power plant A may also be affected according to preset rules.

[0051] when At that time, the real-time electricity price bidding privileges of the account (corresponding to dispatcher C) will be automatically frozen, forming a closed-loop management system of identity verification, reputation rewards and penalties, and access control. This is a threshold value for reputation score, with a default value of 30.

[0052] This application automates identity verification, behavior monitoring, and access control to build a self-regulating mechanism. By deeply binding identity verification and operation authorization, it ensures the legality of operations; introduces a dynamic reputation system to quantify risks and respond in real time; and forms a closed loop of "verification-rewards and punishments-control" to enhance self-governance capabilities. It is applicable to critical infrastructures with high security and real-time requirements, such as smart grids.

[0053] Step 3: Establish a behavior trust update mechanism at the behavior layer.

[0054] The behavior layer is responsible for on-chain behavior auditing and dynamic trust assessment. It ensures log integrity through SM3 hashing and uses smart contracts to update reputation values ​​in real time. The mechanism includes on-chain behavior logs and trust value calculation algorithms.

[0055] 3.1 On-chain behavior log processing and local processing; When a user performs a specific operation using their DID, the system immediately generates a log entry containing the following core metadata: DID (user's decentralized identity identifier), ActionType (operation type), Timestamp (timestamp accurate to milliseconds), and Data (sensitive data, such as transaction amount).

[0056] Cryptographically bind non-sensitive core metadata (DID, ActionType, Timestamp) and calculate the hash value of the log entry. The calculation method is as follows: ; This hash value serves as a unique and tamper-proof "digital fingerprint" representing a specific operation, ensuring that the connection between the actor and the operation cannot be forged.

[0057] For the sensitive core metadata field "Data", authentication encryption is performed using the SM4-GCM algorithm: ; This represents the original encrypted data; Indicates the encryption algorithm; The core key is managed throughout its entire lifecycle by the Hardware Security Module (HSM). The HSM is dedicated hardware that ensures... It never leaves its security boundary, and even if the application server is compromised, the key will not be leaked.

[0058] hash value The transaction is written to the blockchain ledger, establishing a publicly verifiable proof of existence, and broadcast to the network. Once a transaction is confirmed and written to a block, the "proof of existence" and "timestamp proof" of that specific operation are permanently and immutably fixed, and can be publicly verified by any node.

[0059] Original encrypted data Data is transmitted to relevant authorized parties (such as regulatory agencies) via a peer-to-peer encrypted network. Sensitive data or raw encrypted data does not enter on-chain storage, in order to control the scale of on-chain data, protect privacy, and comply with data regulations.

[0060] 3.2: Smart Contract Auditing and Anomaly Detection Triggering; Smart contracts encode predefined regulatory rules, including setting frequency thresholds for specific operation types (the maximum number of operations a single user can perform within a unit of time), high-risk modes (such as frequent modification of identity information), clearly defining violations (such as forging timestamps, submitting duplicate transaction logs, etc.), and exceeding limits.

[0061] All user actions trigger transactions and are captured by smart contracts. The smart contracts compare transaction details with regulatory rules in real time, automatically identifying abnormal or high-risk behaviors.

[0062] When a violation of regulatory rules is detected, the smart contract immediately and automatically executes a reputation penalty.

[0063] Records of violations (including violation type, time, and punishment result) are written into the blockchain as an immutable transaction, forming a permanent and traceable audit trail.

[0064] When regulatory agencies need to decrypt audit data, they submit a decryption request, and the user authorizes the activation of the HSM decryption key via biometric signature. After verifying the authorization, HSM performs SM4-GCM decryption in a controlled environment and returns the plaintext fragment required for the audit. The entire process is recorded on-chain (authorization, time, scope).

[0065] The behavioral layer architecture allows regulators to access information through open channels. Verify log integrity and implement minimal auditing in conjunction with the encrypted data authorization and decryption process; ordinary users have full control over sensitive data - only requests authorized by the user's biometric signature can activate the HSM decryption key.

[0066] 3.3: Real-time Update of Inner Reputation Value (Smart Contract Execution) Defines the built-in dynamic reputation update algorithm: ; ; in, To update reputation score, Current reputation score (range 0-100); and These represent the number of malicious acts within the period and the penalty coefficient (default setting is 0.5). and These represent the number of valid verification actions within the period and the reward coefficient (default setting is 0.1).

[0067] In the dynamic reputation update formula, the penalty coefficient is set significantly higher than the reward coefficient. This design makes it possible for a single malicious act to cause the trust gains accumulated from the previous 5 positive verifications to be zero, thereby reducing the occurrence of malicious acts.

[0068] In this application, smart contracts, acting as the algorithm execution engine, implement three layers of automated governance. Specifically: Layer 1: Real-time reputation reassessment; Any node activity log submitted to the blockchain and uploaded to the chain will trigger a real-time reputation reassessment, which calls the dynamic reputation update algorithm to generate a new reputation value. And assign to This design leverages the characteristics of blockchain state machines to ensure the timeliness and immutability of the evaluation.

[0069] Second layer: Dynamic permission management; smart contracts are based on newly calculated permissions. Automatically execute preset permission adjustment policies: If The smart contract automatically marks it as a restricted node, restricting some or all of its operational permissions; if If so, mark it as a normal node and retain its existing permissions; if The smart contract upgrades it to a high-trust node, granting it higher privileges or rewards.

[0070] Third layer: Global state synchronization; will update the state... Write the data to the smart contract storage, broadcast it to all participating nodes via a P2P network, and use Merkle root hashing to achieve minute-level network-wide state synchronization. As one implementation of this application, a Byzantine fault tolerance mechanism is built in to cope with anomalies in distributed networks, such as network latency and node failures: When a node's reputation calculation times out due to network latency, verification is performed using the Blockchain Timestamp Service (BTS). Once the timeout is confirmed, the smart contract automatically triggers a state rollback, restoring the node's reputation value to the valid value of the previous block. .

[0071] This rollback operation and diagnostic logs (such as the reason for the timeout) will be recorded on a dedicated regulatory blockchain for analysis by the auditing contract. If the same node times out (or fails) twice consecutively, the smart contract will automatically freeze its reputation update permissions to prevent its continued abnormal state from affecting the system.

[0072] Frozen nodes can only apply for unfreezing after passing biometric multi-signature verification (such as joint authentication by multiple authorized administrators using biometric technology).

[0073] As an optional implementation of this step, "forged timestamps" are detected by a timestamp flushing algorithm, duplicate transactions are intercepted by a Bloom filter, and over-limit operations are counted by triggering threshold alarms.

[0074] As one embodiment of this application, a combination of real-time updates and periodic statistics is employed. Specifically: each transaction immediately triggers a reputation calculation, but the reward / penalty coefficient... This is based on dynamic adjustments to behavioral patterns within a cycle, avoiding conflicts between real-time and periodic requirements. Specifically: For the penalty coefficient : Percentage of malicious behavior within the calculation period : ; according to The adjustment mechanism is as follows: if (e.g., 10%), then set ;like (If greater than 10% and less than or equal to 30%), then set ;like (If it is greater than 30%), then set .

[0075] in, and These are the first and second segment thresholds for the proportion of malicious behavior, respectively.

[0076] For reward coefficient ; Percentage of valid verification actions within the calculation period : ; according to The adjustment mechanism is as follows: Reward coefficient Based on the percentage of valid verification behaviors Make positive adjustments:

[0077] in, This is the proportionality coefficient. These are constants, and both need to be set according to the specific scenario to suit the application of the current scenario.

[0078] Step 4: Establish an incentive and reward mechanism for the incentive layer; the incentive layer forms a closed-loop incentive through reputation value tiers and tokenized rewards and punishments, and uses SM4 encryption to achieve dynamic reward distribution.

[0079] The system categorizes nodes into three permission levels based on their reputation value, as shown in Table 2.

[0080] Table 2 Credit Rating Table

[0081] The tiering rules are defined by smart contracts and take effect in real time.

[0082] 4.1 Reward Distribution and Encryption Two key metrics for continuous node monitoring: current reputation value and active time interval (The time difference between the last two adjacent actions); 4.1.1: When a node is detected to simultaneously satisfy... and At that time, the exponentially decaying excitation function is triggered: ; in, For explicit rewards, This is the gain coefficient, used to control the total amount of rewards. The time decay factor is set to 0.01 in this embodiment to achieve dynamic adjustment. This means that the reward decays by about 1% for every hour a node maintains a trusted state, in order to prevent zombie accounts from exploiting the system.

[0083] The calculated plaintext reward is not directly recorded on the blockchain; instead, it needs to be converted into privacy assets. This application uses the GCM mode of the SM4 algorithm to encrypt the plaintext reward, represented as: ; For encryption algorithm The core key is generated and hosted by the Hardware Security Module (HSM); this generates an encrypted token. Its existence and validity can be verified across the entire network, but it cannot be decrypted, thus protecting the privacy of node assets.

[0084] The encrypted token The complete reward distribution is recorded in the blockchain ledger. This record is publicly verifiable and cannot be tampered with.

[0085] 4.1.2: Key management and penalty mechanism; key Binds to the node's real-time status, using the hash value of the node's current reputation. With master key Perform a bitwise XOR operation to generate a one-time encryption factor, and then use this one-time encryption factor to encrypt the working key. This is represented as: ; In the formula, The encrypted working key, This indicates a bitwise XOR operation. The calculation result is the one-time encryption factor.

[0086] This embodiment associates the encryption factor with the current reputation value, and the encryption factor increases with... Changes occur. After a node's reputation is downgraded, Changes will prevent the correct decryption. Therefore, they cannot access their reward assets. Even Leakage, due to hash Due to its irreversibility, attackers cannot deduce the master key. .

[0087] To prevent single points of failure and reduce the risk of key leakage, this application will encrypt the key. As encrypted, it is split into Shamir secret sharing scheme. Each segment ,like Each shard is distributed across multiple nodes on the chain and a Trusted Execution Environment (TEE); a refactoring threshold is set. ,For example If and only if any One fragment is enough to recover And thus decrypted And obtaining less than If there are only a few fragments, no information can be obtained.

[0088] When a node needs to redeem or use its rewards, it must submit the latest proof of reputation. Prove its current reputation status to the system to verify that it has the authority to perform the operation. Obtain at least [amount] from the blockchain. Each key is fragmented, and fragment merging and decryption are performed in a trusted execution environment to restore the dynamic key. .

[0089] Once successfully restored in a trusted execution environment After decrypting the token, the temporary fragment is immediately destroyed to ensure the transience of the key and prevent leakage.

[0090] As one implementation method of this embodiment, the smart contract continuously monitors node behavior. When malicious behavior is detected ( When the count increases, the contract automatically freezes the node's staked tokens and suspends its trading privileges.

[0091] For a penalized node to redeem its frozen assets, it must meet the following combined conditions: (1) Complete a certain number of valid verification actions to increase its current reputation value. (2) During the redemption process, the system will deduct 5% of the total amount of frozen collateral tokens as a system security reserve, thereby increasing the cost of wrongdoing.

[0092] As an embodiment of this application, performance analysis is performed, and the security mechanism is disclosed. Table 3 shows the average time consumption of the national cryptographic fusion algorithm scheme (SM2 / SM3 / SM4) in each step, and compares it with the traditional scheme (RSA / SHA-256 / AES) over the entire link. The national cryptographic algorithm has a total link consumption of only 288 milliseconds, which is 2.58 times more efficient than the traditional scheme's 742 milliseconds. The identity layer DID generation takes only 0.001 milliseconds; the behavior layer processes the electricity purchase log through the SM3 hash algorithm, with an audit latency of <0.1 milliseconds; the incentive layer SM4 encryption takes 0.005 milliseconds. It can be clearly seen that the national cryptographic fusion scheme is superior to the traditional scheme.

[0093] Table 3 Performance Analysis Table

[0094] In this application, when a single point of key leakage occurs, such as an HSM or a node attack, the protocol ensures that the leaked key only affects the current session and does not affect the global trust chain, including data or historical records of other nodes. Key generation embeds a reputation value hash. If the reputation value changes or an anomaly is detected (such as a forged timestamp), the protocol automatically triggers a key transition to generate a new key, preventing the reuse of historical keys. Combined with behavioral layer auditing, if frequent key requests are detected, the smart contract triggers a key transition update and simultaneously penalizes the reputation value.

[0095] In high-concurrency power trading scenarios, the security recovery mechanism deeply integrates anomaly detection and key switching: The system employs a shared rule engine for forged timestamp detection and key leakage recovery. For example, when a timestamp conflict with adjacent transactions less than 1ms is detected, the system simultaneously triggers a reputation deduction (δ=1.0) and a key transition (generating a new key). This prevents historical keys from being reused.

[0096] The high-frequency behavior threshold can be set based on the power trading scenario as follows: Key requests: If a single node requests decryption keys more than 5 times per hour (e.g., scheduler C1 initiates 7 requests per hour), a key change will be triggered and reputation value will be deducted; Transaction frequency: If the same DID has more than 10 electricity purchase transactions per minute (such as user B engaging in high-frequency order brushing), the user's access will be frozen and their reputation value will be deducted. Cross-node operations: If more than 3 DIDs associated with the same IP operate within 5 minutes (such as malicious crawlers), a Byzantine fault tolerance rollback will be triggered.

[0097] The key switching process ensures security through physical-virtual dual isolation: after HSM detects high-frequency requests, a new key is generated. The binding is updated via a key generation formula; old key fragments are destroyed and the new key ciphertext is broadcast, ensuring that the leaked key only affects the current session.

[0098] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.

Claims

1. A method for constructing a multi-dimensional dynamic trust chain mechanism based on Chinese cryptographic algorithms, characterized in that, include: An identity layer, a behavior layer, and an incentive layer are built on the power trading platform. The identity layer uses SM2 asymmetric encryption to perform decentralized identity anchoring, the behavior layer uses the SM3 hash algorithm to audit on-chain behavior, and the incentive layer uses SM4 symmetric encryption technology to encrypt dynamic reward and punishment information. Based on the aforementioned identity layer, a decentralized identity anchor is established on the blockchain, and a two-factor identity binding is performed using SM2 keys combined with biometrics. The verifier queries the user's public key and verifies the SM2 signature through a blockchain smart contract, and performs authorized operations based on the verification result. A behavior trust update mechanism is constructed at the behavior layer; regulatory rules are encoded in smart contracts to conduct real-time auditing of user operations and detection of risky behaviors; based on malicious behavior and valid verification behavior, the smart contract automatically executes a dynamic reputation update algorithm and records it on the blockchain; An incentive and reward mechanism is established for the incentive layer. Plaintext rewards are triggered based on the node's current reputation value and activity interval. Tokens are generated and uploaded to the blockchain using SM4 encryption. The SM4 key is associated with the node's current reputation value to generate an encrypted working key. The encrypted working key is then stored on the blockchain as ciphertext in shards. The node decrypts and restores the data using the latest reputation proof.

2. The method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms according to claim 1, characterized in that, The two-factor identity binding process includes: Generate biometric hash values ​​based on user's biometric information. Use private key pair Perform SM2 signing to obtain the signature value ; Verification is achieved by querying the user's public key via a blockchain smart contract. And verify the signature value Whether the signature verification is valid; if the signature verification passes, the user's identity is granted permission; if it fails, the user's request is rejected and the on-chain malicious behavior counter is updated. The system will then lower the user's reputation score according to the outer deduction rules, triggering permission restrictions.

3. The method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms according to claim 1, characterized in that, The behavior trust update mechanism includes: When users perform operations using decentralized identities, log entries containing metadata are generated; sensitive and non-sensitive data in the log entries are encrypted using different encryption algorithms, and the encrypted hash value corresponding to the sensitive data is uploaded to the blockchain; Define and write regulatory rules for smart contracts, including defining violations, risky operations, and unauthorized operations; smart contracts compare transaction content with regulatory rules, identify transactions that violate regulatory rules, and record them on the blockchain; It employs a built-in dynamic reputation update algorithm to update the user's current reputation value and adjust permissions based on the number of violations of regulatory rules.

4. The method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms according to claim 1, characterized in that, The dynamic reputation update algorithm is an assignment statement; Calculate the updated reputation value, which is the sum of the current reputation value and the valid verification reward value, minus the malicious behavior penalty value; where the valid verification reward value is the product of the number of valid verification behaviors and the reward coefficient, and the malicious behavior penalty value is the product of the number of malicious behaviors and the penalty coefficient. The calculated updated reputation value is assigned to the new current reputation value.

5. The method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms according to claim 4, characterized in that, Based on the new current reputation value, implement dynamic access control, including: If the new current reputation value is less than the first threshold, the smart contract will mark the corresponding user as a restricted node and restrict their operation permissions; If the new current reputation value is greater than or equal to the first threshold and less than the second threshold, the smart contract will mark the corresponding user as a normal node and maintain the existing permissions; If the new current reputation value is greater than or equal to the second threshold, the smart contract will mark the corresponding user as a high-trust node and update the permission level.

6. The method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms according to claim 4, characterized in that, The reward and penalty coefficients are adjusted based on behavioral patterns within the period, including: The total number of actions within a defined period is the sum of the number of malicious actions and the number of valid verification actions; Percentage of malicious behavior within the calculation period The calculation method is the ratio of the number of malicious actions within a period to the total number of actions within a period; if Then set ;like Then set ;like Then set ; , ; in, and These are the first and second segment thresholds for the proportion of malicious behavior, respectively.

7. The method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms according to claim 6, characterized in that, The update methods for the reward coefficient include: Percentage of valid verification actions within the calculation period The calculation method is the ratio of the number of valid verification actions within the period to the total number of actions within the period; then the reward coefficient... Updated to ; In the formula, This is the proportionality coefficient. It is a constant.

8. The method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms according to claim 1, characterized in that, Plaintext rewards are triggered based on the node's current reputation value and the time interval between active events, including: When the node's current reputation value And active time interval When this occurs, an exponentially decaying excitation function is triggered, expressed as: ,in, For explicit rewards, This is the gain coefficient. This is the time decay factor.

9. The method for constructing a multi-dimensional dynamic trust chain mechanism based on national cryptographic algorithms according to claim 1, characterized in that, The incentive and reward / punishment mechanism also includes: Combine the hash value of the current reputation value with the master key Perform a bitwise XOR operation to generate a one-time encryption factor, and perform an encryption operation on the one-time encryption factor and the SM4 key to generate an encryption working key; The encryption working key is split into ciphertext as follows: Each shard is distributed and stored across multiple nodes on the chain and in the executable environment; Set a reconstruction threshold When any When a fragment is completed and the latest reputation proof passes verification, fragment merging and decryption can be performed to restore the SM4 key.

10. A system for constructing a multi-dimensional dynamic trust chain mechanism based on Chinese cryptographic algorithms, comprising executing the multi-dimensional dynamic trust chain mechanism construction method as described in any one of claims 1-9, characterized in that, The system includes: Trust chain initialization module; used to build identity layer, behavior layer and incentive layer on power trading platform; the identity layer uses SM2 asymmetric encryption to perform decentralized identity anchoring, the behavior layer uses SM3 hash algorithm to audit on-chain behavior, and the incentive layer uses SM4 symmetric encryption technology to encrypt dynamic reward and punishment information; An identity verification mechanism construction module is used to establish a decentralized identity anchor on the blockchain based on the identity layer, and to use the SM2 key combined with biometrics for two-factor identity binding; the verifier queries the user's public key and verifies the SM2 signature through the blockchain smart contract, and performs authorized operations according to the verification result; A behavioral trust update mechanism construction module is used to build a behavioral trust update mechanism at the behavioral layer; to encode regulatory rules in smart contracts to perform real-time auditing of user operations and detection of risky behaviors; and to automatically execute a dynamic reputation update algorithm and record it on the blockchain based on malicious behavior and valid verified behavior. The incentive and reward mechanism construction module is used to establish the incentive and reward mechanism of the incentive layer. Plaintext rewards are triggered based on the node's current reputation value and active time interval. Tokens are generated through SM4 encryption and uploaded to the chain. The SM4 key is associated with the node's current reputation value to generate an encrypted working key. The encrypted working key is stored on the chain as ciphertext in shards. The node decrypts and restores the tokens using the latest reputation proof.

Citation Information

Patent Citations

  • Identity authentication system and method based on national cryptographic algorithm

    CN110868301A

  • Jumping key digital communication encryption system and method based on national secret algorithm

    CN114915396A