A blockchain-based organic tea traceability authentication method and system

By constructing a hybrid chain architecture and digital autonomous sovereign identity, the problems of cross-chain data interoperability and identity management in organic tea traceability have been solved, achieving efficient and reliable traceability authentication and ensuring the authenticity and reliability of tea traceability information.

CN121526647BActive Publication Date: 2026-05-01GUIZHOU YIPINXIAN ORGANIC TEA CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUIZHOU YIPINXIAN ORGANIC TEA CO LTD
Filing Date
2026-01-16
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing organic tea traceability solutions suffer from issues such as lack of cross-chain data interoperability, chaotic user identity management, and inconsistent authentication mechanisms, resulting in low traceability authentication efficiency and insufficient reliability of results, making it difficult to meet the needs of reliable traceability across the entire organic tea supply chain.

Method used

A hybrid chain architecture is constructed, including permissioned and permissionless chains. Data fingerprints are generated and anchored to the permissionless chain, which are then transformed into verifiable on-chain traceability digital credentials. This creates a unique digital self-sovereign identity for participating users, and authentication is performed by combining on-chain traceability digital credentials with cross-chain data protection mechanisms.

Benefits of technology

It enables multi-entity trusted collaborative authentication under cross-chain data interoperability, ensuring the authenticity and credibility of traceability information, solving the architecture adaptation problem of cross-chain collaborative authentication, unifying identity identification and data credential standards, and improving the efficiency and reliability of traceability authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121526647B_ABST
    Figure CN121526647B_ABST
Patent Text Reader

Abstract

The application provides a kind of organic tea traceability authentication method and system based on block chain, by constructing the hybrid chain architecture of organic tea traceability authentication, the data fingerprint of organic tea traceability data is generated on the permission chain of hybrid chain architecture, and the data fingerprint is anchored to the non-permission chain of the hybrid chain architecture, forming the cross-chain data protection mechanism from the permission chain to the non-permission chain;Based on the hybrid chain architecture, the organic tea traceability data is converted into a verifiable on-chain traceability digital certificate, and the digital autonomous sovereign identity of each participating user is created;When initiating the query request of organic tea traceability data, the query request is accessed into the hybrid chain architecture through the digital autonomous sovereign identity, and the organic tea traceability data corresponding to the query request is authenticated based on the on-chain traceability digital certificate and the cross-chain data protection mechanism. Using the scheme of the application, the organic tea traceability can be cooperatively authenticated based on cross-chain data intercommunication.
Need to check novelty before this filing date? Find Prior Art

Description

A blockchain-based method and system for traceability and authentication of organic tea. Technical Field

[0001] This application relates to the field of traceability and authentication technology, and more specifically, to a blockchain-based method and system for traceability and authentication of organic tea. Background Technology

[0002] Traceability certification is a professional verification activity that covers the entire lifecycle of a product, from its production source to its end consumer. It involves collecting key information at each stage, relying on technological means to ensure that the information is authentic, complete, and tamper-proof, and conducting multi-dimensional verification of the information according to preset standards to ultimately confirm the credibility of the product's traceability information.

[0003] As the organic tea market expands, consumers' demand for traceability of tea production sources, processing techniques, and logistics is becoming increasingly urgent. Organic tea traceability certification has become a crucial link in ensuring product quality and maintaining market order. Existing traceability solutions suffer from problems such as a lack of cross-chain data interoperability, chaotic user identity management, and inconsistent certification mechanisms. On the one hand, data between different chains is isolated, lacking secure cross-chain data transfer and protection mechanisms, and unable to achieve collaboration between storing privacy data on a permissioned chain and verification information on a permissionless chain. On the other hand, tea farmers, processing enterprises, regulatory agencies, and other participants lack unique online identities, making it difficult to accurately bind operational behaviors to entities and trace responsibility when quality problems occur. Furthermore, traceability data is mostly stored in its raw form and has not been converted into standardized verifiable credentials. When querying, only raw data can be retrieved for verification one by one, lacking a multi-dimensional trusted authentication mechanism based on credentials and cross-chain data. This results in low traceability certification efficiency and insufficient reliability of results, making it difficult to meet the actual needs of trusted traceability across the entire organic tea supply chain. Therefore, how to conduct collaborative certification of organic tea traceability based on cross-chain data interoperability has become a problem facing the industry. Summary of the Invention

[0004] This application provides a blockchain-based method and system for authenticating the traceability of organic tea, which can collaboratively authenticate the traceability of organic tea based on cross-chain data interoperability.

[0005] Firstly, this application provides a blockchain-based method for tracing and authenticating organic tea, comprising the following steps:

[0006] Construct a hybrid chain architecture for traceability and certification of organic tea, wherein the hybrid chain architecture includes a permissioned chain and a permissionless chain;

[0007] Collect organic tea traceability data, generate data fingerprints of the organic tea traceability data on the permissioned chain of the hybrid chain architecture, and anchor the data fingerprints to the permissionless chain of the hybrid chain architecture to form a cross-chain data protection mechanism from the permissioned chain to the permissionless chain;

[0008] Based on the hybrid chain architecture, the organic tea traceability data is transformed into verifiable on-chain traceability digital credentials, creating a unique digital self-sovereign identity for each participating user in the permissioned chain of the hybrid chain architecture.

[0009] When a query request for the organic tea traceability data is initiated, the query request is connected to the hybrid chain architecture through the digital self-sovereign identity, and the organic tea traceability data corresponding to the query request is verified for trusted traceability based on the on-chain traceability digital certificate and the cross-chain data protection mechanism.

[0010] In some embodiments, generating the data fingerprint of the organic tea traceability data on the permissioned chain of the hybrid chain architecture specifically includes:

[0011] The organic tea traceability data is standardized by the permissioned chain of the hybrid chain architecture to obtain standardized organic tea traceability data.

[0012] The standardized organic tea traceability data is subjected to a one-way hash operation based on the permissioned chain of the hybrid chain architecture to obtain the data fingerprint of the organic tea traceability data.

[0013] In some embodiments, anchoring the data fingerprint to the permissionless chain of the hybrid chain architecture to form a cross-chain data protection mechanism from the permissioned chain to the permissionless chain specifically includes:

[0014] The tea batch identifier is obtained from the organic tea traceability data;

[0015] The data fingerprint and the tea batch identifier are encrypted to obtain encrypted data of the data fingerprint and the tea batch identifier;

[0016] Send the encrypted data to the permissionless chain of the hybrid chain architecture;

[0017] Based on the permissionless chain's notarization smart contract in the hybrid chain architecture, the encrypted data is written into the permissionless chain's blockchain ledger, thereby forming a cross-chain data protection mechanism from the permissioned chain to the permissionless chain.

[0018] In some embodiments, converting the organic tea traceability data into verifiable on-chain traceability digital credentials based on the hybrid chain architecture specifically includes:

[0019] The organic tea traceability data is converted into a data body to be verified.

[0020] The hybrid chain architecture performs compliance verification on the data body to be verified, thereby generating a verifiable on-chain traceability digital certificate.

[0021] In some embodiments, creating a network-wide unique digital self-sovereign identity for each participating user in the permissioned chain of the hybrid chain architecture specifically includes:

[0022] Obtain the legal identity information of each participating user in the permissioned chain of the hybrid chain architecture;

[0023] The legal identity information of each participating user is converted into a unique identity identifier for that user, thereby obtaining a unique digital autonomous sovereignty identity for each participating user across the entire network.

[0024] In some embodiments, the trusted traceability authentication of the organic tea traceability data corresponding to the query request based on the on-chain traceability digital certificate and the cross-chain data protection mechanism specifically includes:

[0025] Retrieve the on-chain traceability digital credentials for the batch corresponding to the query request from the permissioned chain;

[0026] Retrieve the encrypted data corresponding to this batch from the permissionless chain through the cross-chain data protection mechanism;

[0027] Retrieve the organic tea traceability data corresponding to the query request from the permission chain;

[0028] Based on the on-chain traceability digital certificate and the encrypted data, the traceability data of the organic tea is verified in a reliable manner, and a reliable traceability certification report for this batch of organic tea is generated.

[0029] In some embodiments, the traceability data for organic tea includes soil testing data from the planting process, records of organic fertilizer use, pest and disease control methods, and harvesting time and batch.

[0030] Secondly, this application provides a blockchain-based organic tea traceability and authentication system, including:

[0031] A building module is used to construct a hybrid chain architecture for organic tea traceability certification, wherein the hybrid chain architecture includes a permissioned chain and a permissionless chain;

[0032] The processing module is used to collect organic tea traceability data, generate data fingerprints of the organic tea traceability data on the permissioned chain of the hybrid chain architecture, and anchor the data fingerprints to the permissionless chain of the hybrid chain architecture, forming a cross-chain data protection mechanism from the permissioned chain to the permissionless chain.

[0033] The processing module is also used to convert the organic tea traceability data into verifiable on-chain traceability digital credentials based on the hybrid chain architecture, and to create a unique digital autonomous sovereign identity for each participating user of the permissioned chain in the hybrid chain architecture.

[0034] The execution module is used to, when initiating a query request for the organic tea traceability data, connect the query request to the hybrid chain architecture through the digital self-sovereign identity, and perform trusted traceability authentication on the organic tea traceability data corresponding to the query request based on the on-chain traceability digital certificate and the cross-chain data protection mechanism.

[0035] Thirdly, this application provides a computer device including a memory and a processor, the memory storing code, and the processor being configured to acquire the code and execute the blockchain-based organic tea traceability and authentication method.

[0036] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the blockchain-based organic tea traceability and authentication method.

[0037] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects:

[0038] The blockchain-based organic tea traceability and authentication method and system provided in this application first constructs a hybrid chain architecture for organic tea traceability and authentication, wherein the hybrid chain architecture includes a permissioned chain and a permissionless chain; organic tea traceability data is collected, and a data fingerprint of the organic tea traceability data is generated on the permissioned chain of the hybrid chain architecture, and the data fingerprint is anchored to the permissionless chain of the hybrid chain architecture, forming a cross-chain data protection mechanism from the permissioned chain to the permissionless chain; based on the hybrid chain architecture, the organic tea traceability data is transformed into verifiable on-chain traceability digital credentials, creating a unique digital self-sovereign identity for each participating user in the permissioned chain of the hybrid chain architecture; when a query request for the organic tea traceability data is initiated, the query request is accessed into the hybrid chain architecture through the digital self-sovereign identity, and the organic tea traceability data corresponding to the query request is verified for trusted traceability based on the on-chain traceability digital credentials and the cross-chain data protection mechanism.

[0039] Therefore, in the organic tea traceability certification process, a hybrid chain architecture combining permissioned and permissionless chains is first constructed. This provides a private and controllable collaborative data interaction space for tea companies, regulatory agencies, and other participants, while leveraging the open and transparent nature of the permissionless chain to establish a foundation of cross-chain trust, thus resolving the architectural adaptation issue for cross-chain collaboration. Then, after collecting traceability data, data fingerprints are generated on the permissioned chain and anchored to the permissionless chain, resolving the contradiction between data privacy and trusted sharing in cross-chain data interoperability. Traceability data is transformed into verifiable on-chain digital credentials, and a unique digital self-sovereign identity is created for users participating in the permissioned chain. This unifies the identity identification and data credential standards for all participants in the cross-chain scenario, avoiding collaborative obstacles caused by incompatible identities or credentials. During queries, the user accesses the hybrid chain through their digital self-sovereign identity, and authentication is completed using on-chain credentials and cross-chain protection mechanisms. This ensures that the querying party can securely access data across chains, while cross-chain verification guarantees the authenticity of traceability information. Ultimately, this achieves multi-party trusted collaborative authentication of organic tea traceability under cross-chain data interoperability. Using the aforementioned scheme, collaborative authentication of organic tea traceability can be achieved based on cross-chain data interoperability. Attached Figure Description

[0040] Figure 1 is an exemplary flowchart of a blockchain-based organic tea traceability and authentication method according to some embodiments of this application;

[0041] Figure 2 is an exemplary flowchart illustrating the determination of a cross-chain data protection mechanism according to some embodiments of this application;

[0042] Figure 3 is an exemplary flowchart illustrating the determination of digital autonomous sovereign identity according to some embodiments of this application;

[0043] Figure 4 is a schematic diagram of the structure of a blockchain-based organic tea traceability and authentication system according to some embodiments of this application;

[0044] Figure 5 is a schematic diagram of the structure of a computer device for implementing a blockchain-based organic tea traceability and authentication method according to some embodiments of this application. Detailed Implementation

[0045] To better understand the technical solution of this application, the technical solution of this application will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0046] Referring to Figure 1, which is an exemplary flowchart of a blockchain-based organic tea traceability and authentication method according to some embodiments of this application, the blockchain-based organic tea traceability and authentication method mainly includes the following steps:

[0047] In step 101, a hybrid chain architecture for organic tea traceability certification is constructed, wherein the hybrid chain architecture includes a permissioned chain and a permissionless chain.

[0048] It should be noted that the hybrid blockchain architecture for organic tea traceability certification in this application represents a customized blockchain technology combination framework for the full lifecycle traceability certification of organic tea. Through the collaborative operation of permissioned and permissionless blockchains, it achieves hierarchical management and credible evidence storage of traceability data. This reflects the dual needs of multi-party participation in the organic tea traceability scenario, which requires both access control and publicly verifiable data credibility. It is necessary to protect the sensitive data privacy and operational permissions of tea farmers, processing enterprises, and other entities, while enhancing the trust of consumers and regulators in traceability information through decentralized public evidence storage. Specifically, the architecture includes a self-designed permissioned blockchain, a permissionless blockchain as the underlying support, and a cross-chain relay module connecting the two, while also including security mechanisms such as node communication encryption.

[0049] Additionally, it should be noted that the self-designed permissioned blockchain refers to a blockchain customized for the permission management needs of participants in the organic tea traceability scenario. Its core consists of an identity-verified node network, a distributed ledger supporting hierarchical control of data read and write permissions, and efficient consensus mechanisms such as PBFT. It is primarily used to store complete traceability data throughout the entire lifecycle of organic tea, ensuring data privacy and operational controllability through node access control and permission allocation, while relying on the consensus mechanism to ensure the immutability of data within the chain. The permissionless blockchain, as the underlying support, typically uses public chains such as Ethereum. It is a decentralized blockchain that can be accessed without permission. Its core consists of a public ledger jointly maintained by all network nodes, decentralized consensus mechanisms such as PoS, and a smart contract system. It is mainly used to store fingerprints of traceability data synchronized from the permissioned blockchain, such as hash values ​​calculated using the SHA-256 algorithm. Leveraging its decentralized characteristics and ledger... This public disclosure enables consumers, third-party institutions, and other users on permissionless blockchains to directly verify the authenticity of data fingerprints, thereby indirectly proving that the original traceability data in the permissioned blockchain has not been tampered with, thus enhancing the credibility of traceability information. The cross-chain relay module connecting the two is a technical component that enables data interaction between the permissioned and permissionless blockchains. It consists of a hash extraction unit, a transaction encapsulation unit, a cross-chain communication interface, and a security verification module. Its core function is to securely and accurately transmit the hash value of traceability data generated in the permissioned blockchain to the permissionless blockchain: first, the hash extraction unit calculates the hash value of newly generated data in the permissioned blockchain in real time; then, the transaction encapsulation unit encapsulates the hash value according to the transaction format of the permissionless blockchain; the cross-chain communication interface calls the evidence storage smart contract on the permissionless blockchain; and at the same time, TLS 1.3 encryption and signature verification are used to ensure the security of the transmission process, ultimately realizing the association between data in the permissioned blockchain and evidence storage in the permissionless blockchain, providing a technical bridge for cross-chain data verification.

[0050] In practice, the following steps are taken: First, the data requirements of participating entities in the organic tea traceability process, such as tea farmers, processors, and regulators, are obtained. Second, a permissioned chain is established: only verified participants are allowed to connect as nodes. Access to complete traceability data, including planting and processing, is controlled through permission configuration. A consensus mechanism ensures data consistency within the chain. Third, a permissionless chain is deployed to store hash fingerprints of the data in the permissioned chain for public verification. Finally, a cross-chain module synchronizes the data fingerprints from the permissioned chain to the permissionless chain. This results in a hybrid chain architecture where the permissioned chain manages permissions and stores complete data, the permissionless chain publicly stores fingerprints, and the cross-chain module enables data association.

[0051] In step 102, organic tea traceability data is collected, a data fingerprint of the organic tea traceability data is generated on the permissioned chain of the hybrid chain architecture, and the data fingerprint is anchored to the permissionless chain of the hybrid chain architecture to form a cross-chain data protection mechanism from the permissioned chain to the permissionless chain.

[0052] It should be noted that the organic tea traceability data in this application includes soil testing data, organic fertilizer usage records, pest and disease control methods, and harvesting time and batch in the planting stage; withering / roasting temperature, duration, processing equipment number, and processing batch number in the processing stage; GPS trajectory of transport vehicles, transportation temperature control data, and receiving and dispatching information in the logistics stage; and pesticide residue test reports, organic certification certificate numbers, and finished product sampling results in the quality inspection stage. The organic tea traceability data represents information on every key node from tea production to distribution. For example, the harvesting time represents the starting point of tea production, and the organic certification number represents the certificate of obtaining official organic qualification. It also reflects whether the tea meets organic standards, whether the operation of each stage is compliant, and whether the entire process is traceable.

[0053] In some embodiments, generating the data fingerprint of the organic tea traceability data on the permissioned chain of the hybrid chain architecture can be achieved by the following steps:

[0054] The organic tea traceability data is standardized by the permissioned chain of the hybrid chain architecture to obtain standardized organic tea traceability data.

[0055] The standardized organic tea traceability data is subjected to a one-way hash operation based on the permissioned chain of the hybrid chain architecture to obtain the data fingerprint of the organic tea traceability data.

[0056] In specific implementation, the organic tea traceability data is standardized by the permissioned chain of the hybrid chain architecture. The standardized organic tea traceability data can be obtained in the following way: the organic tea traceability data is standardized according to the preset rules in the permissioned chain of the hybrid chain architecture. For example, numerical data is kept to two decimal places, time data is converted to UTC timestamps, and text data is encoded in UTF-8. Then, the fields are sorted according to the order of planting, processing, logistics, and quality inspection, and integrated into a lightweight text format structured string. This ensures that the traceability data of the same batch of tea is unique after this processing, forming standardized organic tea traceability data. This avoids inconsistencies in subsequent hash results due to differences in field order or format. Other methods can also be used in other embodiments, which are not limited here.

[0057] Furthermore, in specific implementation, the data fingerprint of the standardized organic tea traceability data obtained by performing a one-way hash operation on the permissioned chain of the hybrid chain architecture can be achieved in the following way: the permissioned chain node of the hybrid chain architecture calls the built-in SHA-256 algorithm to process the standardized lightweight text string. For example, the string is first converted into a UTF-8 encoded byte stream, such as the character 7.2 corresponding to bytes 0x37, 0x2E, and 0x32; a padding operation is performed on the byte stream, adding a 0x80 byte at the end, and then adding several 0x00 bytes to make the total length a multiple of 512 minus... 64; then append a 64-bit binary representation of the original byte stream length, for example, an original length of 2048 bytes corresponds to a 64-bit binary number; initialize eight 32-bit hash value registers; group the padded byte stream into 512-bit groups, perform 64 rounds of compression operations on each group, using a preset 32-bit constant and round function in each round, and update the register values ​​based on the results of the previous round; after all grouping is completed, concatenate the values ​​of the eight registers in order to obtain a 256-bit binary number, which is then converted into a 64-bit hexadecimal string, i.e., the unique data fingerprint corresponding to the organic tea traceability data. In other embodiments, other methods can also be used for calculation, which are not limited here.

[0058] It should be noted that the data fingerprint in this application represents a unique digital identifier for the traceability data of organic tea gardens. This data fingerprint is irreversible and any slight change in the data will result in a completely different fingerprint. Ultimately, the permissioned chain node associates the fingerprint with the tea batch number and stores it in the local ledger, providing a basis for subsequent cross-chain evidence storage.

[0059] In some embodiments, referring to Figure 2, which is an exemplary flowchart for determining a cross-chain data protection mechanism in some embodiments of this application, the data fingerprint is anchored to the permissionless chain of the hybrid chain architecture to form a cross-chain data protection mechanism from the permissioned chain to the permissionless chain. This can be achieved by the following steps:

[0060] First, in step 1021, the tea batch identifier of the organic tea traceability data is obtained;

[0061] Secondly, in step 1022, the data fingerprint and the tea batch identifier are encrypted to obtain encrypted data of the data fingerprint and the tea batch identifier;

[0062] Then, in step 1023, the encrypted data is sent to the permissionless chain of the hybrid chain architecture;

[0063] Finally, in step 1024, the encrypted data is written into the blockchain ledger of the permissionless chain based on the notarization smart contract of the permissionless chain in the hybrid chain architecture, thereby forming a cross-chain data protection mechanism from the permissioned chain to the permissionless chain.

[0064] In practice, the tea batch identifier is generated using industry-standard coding rules. It consists of the last 8 digits of the national unified credit code of the organic tea producer, the production year, the production quarter, and the batch number. The tea batch identifier is already bound to the corresponding batch data when the traceability data is collected by the licensed chain. It is directly retrieved from the distributed ledger of the licensed chain node to ensure a unique association with the data fingerprint to be anchored. The tea batch identifier is a structured code that uniquely distinguishes organic tea production batches.

[0065] In addition, in specific implementation, the encryption of the data fingerprint and the tea batch identifier to obtain the encrypted data of the data fingerprint and the tea batch identifier can be achieved in the following way: using the RSA asymmetric encryption algorithm, for example, first obtaining the 2048-bit public key of the data fingerprint and the tea batch identifier from the permissionless chain node, which is generated by the permissionless chain node through an RSA key generator; concatenating the data fingerprint and the tea batch identifier into a string in fingerprint + identifier order, and performing a SHA-256 hash operation on the string to generate a digest; encrypting the digest and the concatenated original string using the permissionless chain public key, finally generating the encrypted data of the data fingerprint and the tea batch identifier, wherein the encrypted data represents the data after the data fingerprint and the tea batch identifier are encrypted; other methods can also be used in other embodiments, which are not limited here.

[0066] Furthermore, in specific implementation, the notarization smart contract on the permissionless chain in the hybrid chain architecture writes the encrypted data into the block ledger of the permissionless chain, thereby forming a cross-chain data protection mechanism from the permissioned chain to the permissionless chain. This can be achieved in the following way: the notarization smart contract pre-deployed on the permissionless chain contains a batch identifier, an encrypted data mapping structure, and a storeData write function; after the permissionless chain node verifies that the gas fee is sufficient, it calls the storeData function, writing the tea batch identifier as the key and the encrypted data as the value into the contract mapping; the permissionless chain uses the PoS consensus mechanism, where validator nodes verify the contract call logic and data format, and after passing, the transaction is packaged into a new block. After the new block is confirmed by the entire network, it is written into the permissionless chain ledger. The notarization smart contract returns the transaction hash to the relay node, and the relay node records the transaction hash and ledger address to the permissioned chain, forming a cross-chain data protection mechanism that enables publicly verifiable data fingerprints and traceable integrity of the original data.

[0067] It should be noted that the cross-chain data protection mechanism in this application refers to a security protection system established between the permissioned chain and the permissionless chain in the organic tea traceability hybrid chain architecture, covering the entire process of data fingerprint generation, transmission, storage, and verification. This ensures that the data fingerprints flowing from the permissioned chain to the permissionless chain are not stolen or tampered with, and that they can be publicly queried and verified after storage, thus laying the underlying security foundation for the credibility of organic tea traceability certification.

[0068] In step 103, the organic tea traceability data is transformed into verifiable on-chain traceability digital credentials based on the hybrid chain architecture, creating a unique digital self-sovereign identity for each participating user in the permissioned chain of the hybrid chain architecture.

[0069] In some embodiments, the conversion of the organic tea traceability data into verifiable on-chain traceability digital credentials based on the hybrid chain architecture can be achieved through the following steps:

[0070] The organic tea traceability data is converted into a data body to be verified.

[0071] The hybrid chain architecture performs compliance verification on the data body to be verified, thereby generating a verifiable on-chain traceability digital certificate.

[0072] In specific implementation, the organic tea traceability data can be converted into a data body to be verified in the following way: integrate the organic tea traceability data according to preset structured rules, and construct the data body to be verified using JSON-LD format. The top-level fields include tea batch identifier, process list, and data generation timestamp. Each process sub-object in the process list includes process name, core data (such as soil pH: 7.2 in the planting process), record node ID, and node signature. For example, the record node generates a signature for the process data using its ECDSA private key. The signing process is as follows: hash the process data with SHA-256, and then use the private key to perform elliptic curve encryption on the hash value to generate a 64-byte signature value to form the data body to be verified. This ensures that the data body to be verified contains complete traceability information and source identifier. The data body to be verified represents the complete set of traceability information to be verified for compliance. Other conversion methods can also be used in other embodiments, which are not limited here.

[0073] Furthermore, in specific implementation, the hybrid chain architecture can perform compliance verification on the data to be verified, thereby generating a verifiable on-chain traceability digital certificate. This can be achieved in the following way: the permissioned chain in the hybrid chain architecture calls a pre-deployed smart contract for certificate verification. The contract executes the verification in three steps: The first step verifies the legality of the data source by retrieving the corresponding node's ECDSA public key (stored in the permissioned chain identity ledger) through the recorded node ID. The public key is used to decrypt the node signature. For example, the decryption process is as follows: the public key is used to parse the 64-byte signature value to obtain the hash value, which is compared with the hash value recalculated by SHA-256 for the data in this step. If they match, the signature is valid, ensuring that the data is submitted by an authorized node. The second step verifies the compliance of the format by calling a preset JSON. The first step involves schema validation rules to check the completeness of data body fields and the matching of data types. The second step verifies content compliance by calling the organic tea industry standard rule library, which includes built-in parameters such as pesticide residue threshold ≤0.05mg / kg and withering temperature range of 220-280℃. Key indicators in the data body are compared item by item, such as whether the pesticide residue detection value is ≤ the threshold and whether the withering temperature is within the range. After successful verification, the smart contract automatically generates an on-chain traceability digital certificate. The certificate uses the X.509 standard format and includes a unique certificate ID, batch association information, verification result summary, certificate generation timestamp, and contract signature. The generated certificate is stored in a dedicated ledger on the permissioned chain. Simultaneously, the contract extracts the certificate hash value and anchors it to the permissionless chain for storage via a cross-chain relay module, ultimately forming a verifiable on-chain traceability digital certificate. The permissioned chain can view the complete certificate content, and the permissionless chain can verify that the certificate has not been tampered with through the anchored hash value.

[0074] It should be noted that the on-chain traceability digital certificate in this application represents a credible traceability proof of organic tea traceability data in a hybrid chain architecture, reflecting the compliance, immutability, and cross-chain verifiability of organic tea traceability data.

[0075] In some embodiments, referring to Figure 3, which is an exemplary flowchart for determining digital sovereign identity in some embodiments of this application, the following steps can be used to create a network-wide unique digital sovereign identity for each participating user in the permissioned chain of the hybrid chain architecture:

[0076] First, in step 1031, the legal identity information of each participating user in the permissioned chain in the hybrid chain architecture is obtained;

[0077] Finally, in step 1032, the legal identity information of each participating user is converted into a unique identity identifier for the corresponding participating user, thereby obtaining a unique digital autonomous sovereignty identity for each participating user across the entire network.

[0078] It should be noted that the legal identity information in this application refers to the legitimate identity information of the participating users, such as resident ID cards and household registration books. This information reflects the legitimate subject qualifications of the participating users, that is, tea farmers are natural persons with civil capacity, enterprises are legally existing market entities whose business scope includes tea production and processing, and regulatory agencies are administrative or industry agencies authorized to manage traceability, which can effectively exclude false or illegal identities from accessing the permission chain.

[0079] Furthermore, in specific implementation, converting the legal identity information of each participating user into a unique identifier for that user, thereby obtaining a unique digital self-sovereign identity for each participating user across the entire network, can be achieved in the following way: Using a decentralized identifier standard, a unique identifier is generated from the legal identity information of each participating user. First, an identifier prefix is ​​defined. Then, the anonymized user information is concatenated in the order of user type + anonymized subject information + generation timestamp. For example, tea farmer information is concatenated as tea farmer, 110101*********123, 1717238400123, where the timestamp is accurate to milliseconds. The concatenated string is processed using the SHA-256 algorithm. After converting the string to a UTF-8 byte stream, padding and grouping compression operations are performed to generate a 256-bit binary string. The hash value is converted into a 64-bit hexadecimal string as the identifier; the final identity identifier format is did:teaorg:64-bit hexadecimal string; simultaneously, an ECDSA key pair is generated for the user, based on the secp256k1 elliptic curve. The private key is encrypted by the user using the AES-256 algorithm and stored in the local hardware security module. The public key is bound to the identity identifier and written into the identity document (including the identifier, public key value, user role attributes, and verification agency digital signature (the verification agency signs the identity document hash value with its private key)). After the identity document is verified by the permissioned blockchain PBFT consensus node for format and signature legality, it is written into the blockchain ledger, forming a unique digital self-sovereign identity that is controlled by the user. In other embodiments, other methods can also be used, which are not limited here.

[0080] It should be noted that the digital self-sovereign identity in this application represents a unique digital identifier for participating users on the chain in the hybrid permissioned chain. The legitimacy of the other party can be verified based on the public key of this identity. At the same time, it supports users to authorize others to temporarily access specific data, ultimately achieving identity credibility, operation traceability, and responsibility location throughout the entire traceability process.

[0081] In step 104, when a query request for the organic tea traceability data is initiated, the query request is connected to the hybrid chain architecture through the digital self-sovereign identity, and the organic tea traceability data corresponding to the query request is verified for trusted traceability based on the on-chain traceability digital certificate and the cross-chain data protection mechanism.

[0082] In specific implementation, when initiating a query request for the organic tea traceability data, the query request can be integrated into the hybrid chain architecture through the digital self-sovereign identity in the following manner: When a user initiates a query request for organic tea traceability data, firstly, the local terminal calls its own digital self-sovereign identity-related components to read the stored decentralized identifier and corresponding ECDSA private key from the hardware security module; then, a query request data packet is constructed, containing core fields: target tea batch identifier, query range, request initiation timestamp, and user ID, and the data packet is converted into a UTF-8 encoded JSON string; subsequently, the string is hashed using SHA-256, and the hash value is signed using the user's ECDSA private key. The signature value is then concatenated with the original data packet to form a complete signed query request; this query request is transmitted via TLS. 1.3 The encrypted channel of the protocol is sent to the access gateway node of the permissioned chain. After receiving the request, the access node first parses the user ID in the request and queries the identity document corresponding to the ID through the identity index module of the permissioned chain's distributed ledger. During the verification phase, the access node extracts the JSON string in the request, re-hash it with SHA-256, and then decrypts the signature value using the public key in the identity document using ECDSA. If the two hash values ​​match, it confirms that the request has not been tampered with and that its source is legitimate. After successful verification, the access node calls the permission control module of the permissioned chain to match preset permission rules based on the user role attributes in the identity document. For example, tea farmers can only query the batch data they submitted, while regulatory agencies can query the full data. This verifies whether the user has permission to query the target batch. After the permission is granted, the access node converts the query request into the permissioned chain's internal data format and forwards it to the endorsement node that stores the traceability data of that batch. After querying the data, the endorsement node returns the result to the access node. The access node encrypts the result with its own public key and sends it back to the user. The user decrypts the result using the access node's public key to obtain the query result, completing the query request access process based on digital self-sovereign identity.

[0083] In some embodiments, the trusted traceability authentication of the organic tea traceability data corresponding to the query request based on the on-chain traceability digital certificate and the cross-chain data protection mechanism can be achieved by the following steps:

[0084] Retrieve the on-chain traceability digital credentials for the batch corresponding to the query request from the permissioned chain;

[0085] Retrieve the encrypted data corresponding to this batch from the permissionless chain through the cross-chain data protection mechanism;

[0086] Retrieve the organic tea traceability data corresponding to the query request from the permission chain;

[0087] Based on the on-chain traceability digital certificate and the encrypted data, the traceability data of the organic tea is verified in a reliable manner, and a reliable traceability certification report for this batch of organic tea is generated.

[0088] In specific implementation, firstly, the on-chain traceability digital certificate is retrieved from the permissioned blockchain. Using the tea batch identifier in the query request as an index, the corresponding on-chain traceability digital certificate is located in the permissioned blockchain's dedicated ledger. Next, encrypted data is retrieved from the permissionless blockchain. Based on the notarization smart contract address recorded in the cross-chain data protection mechanism, the dataStore mapping of the contract is called via the Ethereum JSON-RPC protocol to obtain the stored encrypted data. The encrypted data is decrypted using the 2048-bit RSA private key held by the permissionless blockchain node, obtaining the concatenated information of the data fingerprint and batch identifier. The data fingerprint is extracted for later use. Subsequently, the organic tea traceability data corresponding to the query request is retrieved from the permissioned blockchain. Again, using the batch identifier as an index, the organic tea traceability data corresponding to the query request is obtained from the distributed ledger. Finally, the organic tea traceability data is verified for trustworthiness based on the on-chain traceability digital certificate and the encrypted data. The process for generating a trusted traceability certification report for this batch of organic tea involves the following steps: First, verifying the legality of the on-chain traceability digital certificate. This involves decrypting the smart contract signature in the certificate using the ECDSA public key of the permissioned blockchain smart contract, for example, by restoring the hash value through elliptic curve point addition. The result is then compared with the overall SHA-256 hash of the certificate; if they match, the certificate has not been tampered with. Second, verifying cross-chain consistency. This involves comparing the hash value of the data body in the certificate with the data fingerprint obtained from decryption on a permissionless blockchain; if they match, the inter-chain data association is valid. Third, verifying data integrity. This involves performing SHA-256 operations on each stage of the original traceability data and comparing the results with the corresponding hash digests in the certificate; if all results match, the data has not been tampered with. Fourth, verifying the legitimacy of the source. This involves querying the permissioned blockchain identity ledger using the node ID recorded in the original data to obtain the corresponding user's ECDSA public key, decrypting the node signature at each stage, and comparing it with the SHA-256 hash of the data at that stage; if they match, the source is legitimate. Based on the combined results of these four verification steps, a trusted traceability certification report containing verification details and conclusions is generated and sent back to the querying party.

[0089] It should be noted that the credible traceability certification report in this application reflects the full-process verification details of the traceability data for the corresponding batch of organic tea, including the details and results of core verification items such as the legality of on-chain traceability digital certificates, cross-chain data consistency, integrity of original traceability data, legality of data sources, and compliance with organic standards. It indicates the credible status of the traceability information of this batch of organic tea after technical verification. If the report shows that all verification items have passed, it means that the data of this batch of tea from planting to logistics is authentic and untampered, the source entity is legal, and it meets organic production standards. If there are any failed items, the problematic links are clearly marked. This report is mainly used in three scenarios: first, consumers can verify the authenticity of tea traceability information when querying, as a reference for purchasing organic tea; second, regulatory agencies can use it as a technical certificate to determine whether enterprises are producing in compliance with regulations when conducting organic certification verification or quality sampling inspections; and third, tea production enterprises can use it to prove the credibility of product traceability to partners, or as qualification materials for market access, and it can also serve as a basis for determining traceability responsibility in the event of quality disputes.

[0090] In another aspect, in some embodiments, this application provides a blockchain-based organic tea traceability and authentication system. Referring to Figure 4, which is a schematic diagram of the structure of a blockchain-based organic tea traceability and authentication system according to some embodiments of this application, the blockchain-based organic tea traceability and authentication system 400 includes: a construction module 401, a processing module 402, and an execution module 403, which are described below:

[0091] Construction module 401, in this application, is mainly used to construct a hybrid chain architecture for traceability certification of organic tea, wherein the hybrid chain architecture includes a permissioned chain and a permissionless chain;

[0092] Processing module 402, in this application, is used to collect organic tea traceability data, generate data fingerprints of the organic tea traceability data on the permissioned chain of the hybrid chain architecture, and anchor the data fingerprints to the permissionless chain of the hybrid chain architecture, forming a cross-chain data protection mechanism from the permissioned chain to the permissionless chain.

[0093] It should be noted that the processing module 402 in this application is also used to convert the organic tea traceability data into verifiable on-chain traceability digital credentials based on the hybrid chain architecture, and to create a unique digital autonomous sovereign identity for each participating user of the permissioned chain in the hybrid chain architecture.

[0094] The execution module 403 in this application is mainly used to connect the query request to the hybrid chain architecture through the digital sovereign identity when a query request for the organic tea traceability data is initiated, and to perform trusted traceability authentication on the organic tea traceability data corresponding to the query request based on the on-chain traceability digital certificate and the cross-chain data protection mechanism.

[0095] In addition, this application also provides a computer device, the computer device including a memory and a processor, the memory storing code, and the processor being configured to acquire the code and execute the blockchain-based organic tea traceability and authentication method.

[0096] In some embodiments, referring to FIG5, which is a schematic diagram of the structure of a computer device for implementing a blockchain-based organic tea traceability and authentication method according to some embodiments of this application, the blockchain-based organic tea traceability and authentication method in the embodiments can be implemented by the computer device 500 shown in FIG5, which includes at least one processor 501, a communication bus 502, a memory 503, and at least one communication interface 504.

[0097] Processor 501 can be a general-purpose central processing unit (CPU) or an application-specific integrated circuit (ASIC).

[0098] The communication bus 502 can be used to transmit information between the components.

[0099] Memory 503 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital versatile optical discs, Blu-ray discs, etc.), magnetic disks or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Memory 503 may exist independently and be connected to processor 501 via communication bus 502. Memory 503 may also be integrated with processor 501.

[0100] The memory 503 stores program code for executing the scheme of this application, and its execution is controlled by the processor 501. The processor 501 executes the program code stored in the memory 503. The program code may include one or more software modules. The method used in the embodiments can be implemented by the processor 501 and one or more software modules in the program code in the memory 503.

[0101] Communication interface 504 uses any transceiver-like device to communicate with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc.

[0102] In a specific implementation, as one example, a computer device may include multiple processors, each of which may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. Here, a processor may refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).

[0103] The computer device described can be a general-purpose computer device or a special-purpose computer device. In specific implementations, the computer device can be a desktop computer, a portable computer, a network server, a handheld digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, a communication device, or an embedded device. This application does not limit the type of computer device.

[0104] In addition, this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the blockchain-based organic tea traceability and authentication method.

[0105] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0106] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A blockchain-based method for tracing and authenticating organic tea, characterized in that, The process includes the following steps: constructing a hybrid chain architecture for organic tea traceability certification, wherein the hybrid chain architecture includes a permissioned chain and a permissionless chain; collecting organic tea traceability data, generating data fingerprints of the organic tea traceability data on the permissioned chain of the hybrid chain architecture, and anchoring the data fingerprints to the permissionless chain of the hybrid chain architecture, forming a cross-chain data protection mechanism from the permissioned chain to the permissionless chain; based on the hybrid chain architecture, converting the organic tea traceability data into verifiable on-chain traceability digital credentials, creating a unique digital self-sovereign identity for each participating user in the permissioned chain of the hybrid chain architecture; when a query request for the organic tea traceability data is initiated, the query request is accessed into the hybrid chain architecture through the digital self-sovereign identity, and trusted traceability certification of the organic tea traceability data corresponding to the query request is performed based on the on-chain traceability digital credentials and the cross-chain data protection mechanism; wherein, the trusted traceability certification of the organic tea traceability data corresponding to the query request based on the on-chain traceability digital credentials and the cross-chain data protection mechanism specifically includes: retrieving the on-chain traceability data of the batch corresponding to the query request from the permissioned chain. The process involves: obtaining a digital certificate; retrieving encrypted data corresponding to the batch from the permissionless chain through the cross-chain data protection mechanism; retrieving organic tea traceability data corresponding to the query request from the permissioned chain; performing trusted verification of the organic tea traceability data based on the on-chain traceability digital certificate and the encrypted data, and generating a trusted traceability certification report for the batch of organic tea; specifically, performing trusted verification of the organic tea traceability data based on the on-chain traceability digital certificate and the encrypted data, and generating a trusted traceability certification report for the batch of organic tea includes: using the ECD of the permissioned chain smart contract. The SA public key is used to decrypt the smart contract signature in the on-chain traceability digital certificate; the hash value of the data body in the on-chain traceability digital certificate is compared with the data fingerprint obtained by decrypting the encrypted data; SHA-256 operation is performed on each link of the original traceability data, and the operation result is compared with the hash digest of the corresponding link in the on-chain traceability digital certificate one by one; the ECDSA public key of the corresponding user is obtained by querying the permissioned chain identity ledger through the node ID recorded in the original data, and the node signature of each link in the on-chain traceability digital certificate is decrypted and verified; finally, a trusted traceability authentication report containing verification item details and conclusions is generated.

2. The method as described in claim 1, characterized in that, Generating the data fingerprint of the organic tea traceability data on the permissioned chain of the hybrid chain architecture specifically includes: standardizing the organic tea traceability data by the permissioned chain of the hybrid chain architecture to obtain standardized organic tea traceability data; and performing a one-way hash operation on the standardized organic tea traceability data according to the permissioned chain of the hybrid chain architecture to obtain the data fingerprint of the organic tea traceability data.

3. The method as described in claim 1, characterized in that, Anchoring the data fingerprint to the permissionless chain of the hybrid chain architecture to form a cross-chain data protection mechanism from the permissioned chain to the permissionless chain specifically includes: obtaining the tea batch identifier of the organic tea traceability data; encrypting the data fingerprint and the tea batch identifier to obtain encrypted data of the data fingerprint and the tea batch identifier; sending the encrypted data to the permissionless chain of the hybrid chain architecture; and writing the encrypted data into the blockchain ledger of the permissionless chain based on the notarization smart contract of the permissionless chain in the hybrid chain architecture, thereby forming a cross-chain data protection mechanism from the permissioned chain to the permissionless chain.

4. The method as described in claim 1, characterized in that, The process of transforming the organic tea traceability data into verifiable on-chain traceability digital credentials based on the hybrid chain architecture specifically includes: converting the organic tea traceability data into a data body to be verified; and performing compliance verification on the data body to be verified by the hybrid chain architecture to generate verifiable on-chain traceability digital credentials.

5. The method as described in claim 1, characterized in that, Creating a network-wide unique digital self-sovereign identity for each participating user in the permissioned chain of the hybrid chain architecture specifically includes: obtaining the legal identity information of each participating user in the permissioned chain of the hybrid chain architecture; converting the legal identity information of each participating user into a unique identity identifier for the corresponding participating user, thereby obtaining a network-wide unique digital self-sovereign identity for each participating user.

6. The method as described in claim 1, characterized in that, The traceability data for organic tea includes soil testing data from the planting process, records of organic fertilizer use, pest and disease control methods, and harvesting time and batch.

7. A blockchain-based organic tea traceability and authentication system, characterized in that it is controlled by the method described in any one of claims 1 to 6, wherein... The system includes: a construction module for building a hybrid chain architecture for organic tea traceability certification, wherein the hybrid chain architecture includes a permissioned chain and a permissionless chain; a processing module for collecting organic tea traceability data, generating data fingerprints of the organic tea traceability data on the permissioned chain of the hybrid chain architecture, and anchoring the data fingerprints to the permissionless chain of the hybrid chain architecture, forming a cross-chain data protection mechanism from the permissioned chain to the permissionless chain; the processing module is also used to convert the organic tea traceability data into verifiable on-chain traceability digital credentials based on the hybrid chain architecture, creating a unique digital self-sovereign identity for each participating user in the permissioned chain of the hybrid chain architecture; and an execution module for, when a query request for the organic tea traceability data is initiated, accessing the query request into the hybrid chain architecture through the digital self-sovereign identity, and performing trusted traceability certification of the organic tea traceability data corresponding to the query request based on the on-chain traceability digital credentials and the cross-chain data protection mechanism.

8. A computer device, characterized in that, The computer device includes a memory and a processor, the memory storing code, and the processor being configured to retrieve the code and execute the blockchain-based organic tea traceability and authentication method as described in any one of claims 1 to 6.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the blockchain-based organic tea traceability and authentication method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Personal credit data authorization method based on hybrid chain and threshold proxy re-encryption

    CN113268764A

  • Supply chain product traceability system and method based on block chain, equipment and medium

    CN120689067A

  • Digital identity authentication and tracing method based on block chain

    CN120768702A