System, method and data processing system for managing purchase orders

By identifying and encrypting sensitive data in purchase orders, a purchase order non-fungible token (PONFT) is generated. Utilizing distributed storage and blockchain technology, this solves the problems of inefficiency and security in the procurement process in the construction and real estate industry, achieving low-cost, efficient, and secure procurement management.

CN121599593APending Publication Date: 2026-03-03李宝生 +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411124562.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-15
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

In the construction and real estate industry, procurement processes rely on traditional paper documents and scattered digital records, which are inefficient and prone to leaks. Small and medium-sized enterprises lack resources, leading to lost orders and inaccurate records. Closed systems lack interoperability, increasing complexity.

Method used

A computer-implemented system and method are provided that generates a purchase order non-fungible token (PONFT) by encrypting sensitive data in purchase orders, and utilizes distributed storage and blockchain to ensure data security and integrity, thereby achieving low-cost and efficient management.

Benefits of technology

It enables SMEs to efficiently manage procurement processes at low cost, ensures data security and prevents tampering, and improves the efficiency and security of purchase order management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121599593A_ABST
    Figure CN121599593A_ABST
Patent Text Reader

Abstract

The present disclosure relates to a computer-implemented method for managing purchase orders for building and real estate industries, comprising: identifying sensitive data in the purchase order; the sensitive data is encrypted; receiving a uniform content identifier (CID) for identifying the encrypted sensitive data; constructing metadata based on the CID, wherein the metadata comprises the CID and other data in the purchase order; receiving a purchase order non-homogeneous token PONFT generated based on the metadata; and transmitting the PONFT to each party involved in the purchase order. Compared with a comprehensive digital solution which needs to consume huge cost investment, the method has the advantage of low cost. Meanwhile, sensitive data in the purchase order in the building and real estate industries can be protected, the security of purchase order management is enhanced, and tampering of relevant information of the purchase order is prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the technical field of supply chain process management, and more specifically, to a method, system, data processing system, and computer-readable storage medium for managing purchase orders in the construction and real estate industry. Background Technology

[0002] Currently, procurement processes in the construction and real estate industry rely heavily on traditional paper documents and fragmented digital records, often exchanged through personal channels. This approach is inefficient, prone to information leaks, and susceptible to tampering.

[0003] Large companies tend to use closed procurement systems that are expensive to maintain. These closed systems are often located on-site or in Software as a Service (SaaS), which creates barriers for small and medium-sized enterprises (SMEs). Closed systems also often lack interoperability, further complicating procurement processes between different organizations.

[0004] On the other hand, SMEs often lack the resources and expertise to invest in comprehensive digital solutions, thus relying on inefficient manual processes. For example, small contractors may use spreadsheets and email for purchasing, resulting in lost orders, inaccurate records, and difficulty in tracking goods. Summary of the Invention

[0005] The purpose of this disclosure is to provide a low-cost method and system for managing purchase orders in the construction and real estate industry, which can be used by small and medium-sized enterprises in the industry, and aims to solve the inefficiencies and security problems in the procurement process of the construction and real estate industry.

[0006] To achieve the above objectives, this disclosure provides a computer-implemented system and method for managing purchase orders in the construction and real estate industry.

[0007] According to one aspect of this disclosure, a computer-implemented system for managing purchase orders in the construction and real estate industry is provided, comprising: a purchase order processing unit configured to identify sensitive data in the purchase order; an encryption engine configured to encrypt the sensitive data; and a metadata construction unit configured to receive a Uniform Content Identifier (CID) for identifying the encrypted sensitive data and to construct metadata based on the CID, wherein the metadata includes the CID and other data in the purchase order; the system is further configured to receive a Purchase Order Non-Fungible Token (PONFT) generated based on the metadata and to transmit the PONFT to the parties involved in the purchase order.

[0008] Optionally, the encryption engine uses a symmetric algorithm to encrypt the sensitive data.

[0009] Optionally, the encryption engine uses an asymmetric algorithm to encrypt the symmetric key of the symmetric algorithm using the public keys of each party involved in the purchase order.

[0010] According to another aspect of this disclosure, a computer-implemented method for managing purchase orders in the construction and real estate industry is provided, comprising: identifying sensitive data in the purchase order; encrypting the sensitive data; receiving a Uniform Content Identifier (CID) for identifying the encrypted sensitive data; constructing metadata based on the CID, wherein the metadata includes the CID and other data in the purchase order; receiving a Purchase Order Non-Fungible Token (PONFT) generated based on the metadata; and transmitting the PONFT to the parties involved in the purchase order.

[0011] According to another aspect of this disclosure, a data processing system is provided, comprising: at least one processor; and at least one memory including computer-readable program code executed by the at least one processor to configure the at least one processor to implement a computer-implemented method for managing purchase orders in the construction and real estate industry according to another aspect of this disclosure.

[0012] Through the above technical solutions, small and medium-sized enterprises in the construction and real estate industry can use the methods and systems provided in this disclosure to achieve efficient management of procurement processes while ensuring data security at a lower cost.

[0013] Other features and advantages of this disclosure will be described in detail in the following detailed description section. Attached Figure Description

[0014] The accompanying drawings are provided to further illustrate the present disclosure and form part of the specification. They are used together with the following detailed description to explain the present disclosure, but do not constitute a limitation thereof. In the drawings:

[0015] Figure 1 An exemplary block diagram of a system 100 for managing purchase orders in the construction and real estate industry according to an embodiment of the present disclosure is shown;

[0016] Figure 2 An embodiment according to the present disclosure is shown. Figure 1 An exemplary block diagram of the encryption engine 104;

[0017] Figure 3 An exemplary flowchart of a method 300 for managing purchase orders in the construction and real estate industry according to an embodiment of the present disclosure is shown;

[0018] Figure 4A diagram illustrating an exemplary specific interaction process 400 between a system for managing purchase orders in the construction and real estate industry and a user of the system and a blockchain, according to an embodiment of this disclosure;

[0019] Figure 5 A block diagram of an electronic device 500 capable of implementing one or more embodiments of the present disclosure is shown. Detailed Implementation

[0020] The specific embodiments of this disclosure will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit this disclosure.

[0021] One or more embodiments will now be described with reference to the accompanying drawings, wherein similar reference numerals are used throughout to refer to similar elements. Numerous specific details are set forth in the following description for purposes of explanation in order to provide a more thorough understanding of one or more embodiments. However, it will be apparent that one or more embodiments may be practiced in various circumstances without these specific details.

[0022] For the sake of simplicity, the computer-implemented method is depicted and described as a series of actions. It should be understood and recognized that this disclosure is not limited to the actions shown and / or the order of actions; for example, actions may occur in various orders and / or simultaneously, and together with other actions not presented and described herein. Furthermore, not all actions shown require the implementation of the computer-implemented method according to the disclosed subject matter. Additionally, those skilled in the art will understand and recognize that the computer-implemented method may alternatively be represented by a state diagram or events as a series of interrelated states. Furthermore, it should be understood that the computer-implemented method disclosed below and throughout the specification can be stored on an article of art to facilitate the transfer and transmission of such computer-implemented method to a computer. The term "article of art" as used herein is intended to encompass any computer program accessible from any computer-readable device or storage medium.

[0023] As described in the background section, procurement processes in the construction and real estate industry primarily rely on traditional paper documents and fragmented digital records, which are inefficient, prone to information leaks, and susceptible to tampering. Small and medium-sized enterprises (SMEs), lacking the resources and expertise to invest in comprehensive digital solutions, may also suffer from lost orders, inaccurate records, and difficulty in tracking goods due to their reliance on inefficient manual processes. Therefore, this disclosure provides a low-cost method and system for managing purchase orders that can be used by SMEs in the construction and real estate industry, aiming to address the inefficiencies and security issues in the procurement processes of the construction and real estate sector.

[0024] The embodiments of this disclosure fully consider the needs of numerous small and medium-sized enterprises (SMEs) in the construction and real estate industry, providing a system and method for managing purchase orders. SMEs can easily register as users of the system and utilize it to manage purchase orders. Compared to the costly investment required to build a comprehensive digital solution, the embodiments of this disclosure offer the advantage of low cost. Furthermore, as will be shown in the embodiments described below in conjunction with the accompanying drawings, the embodiments of this disclosure can also protect sensitive data in purchase orders within the construction and real estate industry, enhance the security of purchase order management, and prevent tampering with purchase order-related information.

[0025] First refer to Figure 1 This document illustrates an exemplary block diagram of a system 100 for managing purchase orders in the construction and real estate industry according to an embodiment of the present disclosure. According to one embodiment of the present disclosure, the system 100 for managing purchase orders in the construction and real estate industry includes: a purchase order processing unit 102, an encryption engine 104, a metadata construction unit 108, and so on. Figure 1 The dashed box in the diagram illustrates this. According to one embodiment of this disclosure, purchaser 101a and supplier 101b, as users of system 100, can interact with system 100 through an interface provided by system 100 (e.g., a graphical user interface GUI, not shown). System 100 can be directly or indirectly connected to distributed storage 106, for example, via the Bitswap protocol. According to one embodiment of this disclosure, distributed storage 106 can be the InterPlanetary File System (IPFS). IPFS is a decentralized network protocol that uses a content-based addressing scheme to retrieve files. Each file and all its blocks are assigned a unique fingerprint, which is used to locate the node storing the content behind that fingerprint. According to one embodiment of this disclosure, system 100 can also be connected to blockchain 112 via smart contract 110. Blockchain 112 can be permissioned or permissionless. A smart contract is a computer protocol that runs on a blockchain and is designed to disseminate, verify, or execute contracts in an informational manner. According to one embodiment of this disclosure, smart contract 110 specifies the interaction rules (i.e., contracts) between system 100 and blockchain 120. It is noted here that purchase orders can be of any form. A common form is a purchase order generated by the purchaser 101a through the interface provided by system 100, detailing the purchase process. Alternatively, the purchase order can be relevant documents uploaded by the purchaser 101a through the interface provided by system 100, such as a scanned purchase contract.

[0026] According to one embodiment of this disclosure, the purchase order processing unit 102 can identify sensitive data in a purchase order from the purchaser 101a, referred to as D. senAccording to one embodiment of this disclosure, after authentication and logging into system 100, the purchasing party 101a can input relevant purchasing details through an interface provided by system 100, such as a form in a GUI. The purchasing details can be organized into structured data, enabling the purchase order processing unit 102 to generate a purchase order through corresponding fields in the structured data and identify sensitive data in the purchase order based on those fields. According to one embodiment of this disclosure, the purchasing party 101a can also upload documents related to the purchase order, such as scanned copies of purchase contracts. System 100 uses OCR or other text recognition technologies to identify sensitive data in the purchase order from the scanned documents. According to one embodiment of this disclosure, sensitive data D... sen This includes data crucial for maintaining privacy, security, or competitive advantage, such as personally identifiable information like the names, addresses, phone numbers, and email addresses of purchasers and suppliers; financial information like bank account details, credit card information, and payment terms; pricing and cost information like specific pricing details, discounts, and cost structures that may be sensitive due to competition; product or service details like descriptions and quantities of purchased goods or services that may include proprietary or confidential information; and contractual terms like any specific terms and conditions, delivery dates, and other contractual obligations in the purchase order. This sensitive data should be restricted to access only by authorized interested parties. According to one embodiment of this disclosure, the purchase order processing unit 102 can identify sensitive data in the purchase order based on corresponding fields in the structured data constituting the purchase order, according to predefined rules. For example, certain field names can be predefined as sensitive field names, such as "Proc_Name" for the name of the purchaser's contact person, "Proc_Email" for the email address of the purchaser's contact person, etc. By identifying the corresponding field names, the purchase order processing unit 102 can identify the corresponding sensitive data. Alternatively, sensitive data D in purchase orders can be identified using machine learning and pre-trained models. sen .

[0027] Referring now to Table 1, which provides examples of data processed by the purchase order processing unit 102, the data in Table 1 is categorized as follows: sensitive data, which requires encryption; and public data, which is considered non-sensitive and does not require encryption. Table 1 can be obtained by identifying the data in the purchase order using the identification methods mentioned in the preceding embodiments. It should be noted that Table 1 is merely an example of data for illustrative purposes and does not represent all the data in the purchase order. For instance, the data in Table 1 does not include data related to supplier 101b; for example, the contact person's name and email address of supplier 101b are also identified as sensitive data. Table 1 also includes scanned copies of uploaded purchase contracts.

[0028]

[0029]

[0030] Table 1

[0031] This point points out that the same data may be identified as different categories depending on the criteria used. For example, if buyer 101a or supplier 101b believes that the purchase price involves competition and therefore should be restricted to access only by authorized interested parties, then the price should be identified as sensitive data, for example, by pre-defining the data corresponding to this field as sensitive data, or by using a pre-trained model based on machine learning.

[0032] According to one embodiment of this disclosure, encryption engine 104 is used to process identified sensitive data D. sen Encryption is performed to obtain the encrypted sensitive data, which is called Cipher. Dsen According to one embodiment of this disclosure, the encryption engine 104 can utilize a key (symmetric key k) s The sensitive data is symmetrically encrypted, for example, using the Advanced Encryption Standard (AES). According to one embodiment of this disclosure, the symmetric key k... s It must meet cryptographic standards, such as those defined by NIST SP 800-90A. The key length can be 128 bits, 192 bits, 256 bits, etc. More complex encryption algorithms and longer key lengths can provide better security, but will increase computational complexity. The appropriate encryption algorithm and key length can be selected based on the system's computational performance. Alternatively, for sensitive data D... sen The encryption can also employ other encryption methods, such as the Triple Data Encryption Standard (3DES) or Twofish encryption. According to one embodiment of this disclosure, to increase additional security, the sensitive data D can be encrypted using the public keys held by each party involved in the purchase order. sen The key (symmetric key k) s Further asymmetric encryption can be performed. For example, the public key k held by the purchaser can be used. proc For this symmetric key k s Asymmetric encryption is used so that only the purchasing party can use their private key to access their public key k. proc The encrypted symmetric key is decrypted to obtain the symmetric key k. s Therefore, it is possible to utilize this symmetric key k s Cipher of encrypted sensitive data Dsen Decryption yields sensitive data D sen Similarly, the public key k held by the supplier can be used. supp For ks Asymmetric encryption is used so that only the purchasing party can use their private key to access their public key k. supp The encrypted symmetric key is decrypted to obtain the symmetric key k. s Therefore, it is possible to utilize this symmetric key k s Cipher of encrypted sensitive data Dsen Decryption yields sensitive data D sen According to one embodiment of this disclosure, an RSA key pair can be used, with a key length of 1024 bits, 2048 bits, etc. Alternatively, for sensitive data D... sen Encryption can also employ other encryption methods, such as Elliptic Curve Cryptography (ECC) and Digital Signature Algorithm (DSA). Similarly, more complex encryption algorithms and longer key lengths can provide better security, but they increase the corresponding computational complexity. The appropriate encryption algorithm and key length can be selected based on the system's computational performance. According to one embodiment of this disclosure, during the encryption process, the generated key can be temporarily stored in a secure storage location to maintain its security.

[0033] According to one embodiment of this disclosure, the encryption engine 104 may include, for example: Figure 2 The structure shown. (Refer to...) Figure 2 The encryption engine 104 includes a key generator 202, an encryption unit 204, and a secure storage 206. The key generator 202 is configured to generate a symmetric key k for encrypting sensitive data. s According to one embodiment of this disclosure, alternatively, the key generator 202 may receive a symmetric key k from another key provider. s The key generator 202 can further generate keys for the symmetric key k. s A key pair for asymmetric encryption, which may include, for example, the public key k used by the purchaser 101a. proc The key pair with the corresponding private key, and the public key k used for provider 101b. supp A key pair with the corresponding private key. Alternatively, key generator 202 can receive the public key k for purchaser 101a from another key provider. proc The key pair with the corresponding private key and the public key k used for provider 101b. supp And a key pair with the corresponding private key. It should be noted here that although the key generator 202... Figure 2As shown in the diagram, the key generator 202 is part of the encryption engine 104. In specific implementations, the key generator 202 can be any trusted third-party organization capable of providing the aforementioned keys, and is not part of the encryption engine 104. The encryption engine 104 only needs to receive the keys generated by the trusted third-party organization and perform the corresponding encryption operations. According to one embodiment of this disclosure, the encryption unit 204 is configured to perform corresponding encryption operations, including: 1) using the generated symmetric key k s Sensitive data D identified by the purchase order processing unit 102 sen Perform symmetric encryption to obtain the encrypted sensitive data Cipher. Dsen 2) Utilize the generated public keys (e.g., k) for each party in the purchase order. proc and k supp For symmetric key k s Encryption is performed. The encryption unit 204 can use the encryption algorithm described above to perform the encryption, for example, using AES to encrypt sensitive data D. sen Perform symmetric encryption and use RSA to encrypt the symmetric key k. s Encryption is performed. Secure storage 206 is configured to securely store each key. According to one embodiment of this disclosure, when using a symmetric key k... s For sensitive data D sen During encryption, the symmetric key k s It is stored in secure storage 206 to prevent access to the symmetric key k. s Unauthorized access. According to one embodiment of this disclosure, using the respective public keys (e.g., k) of the parties in a purchase order. proc and k supp For symmetric key k s During the encryption process, the symmetric key k s The private keys used by each party in the purchase order are stored in secure storage 206. According to one embodiment of this disclosure, secure storage 206 may be a hardware encryption module (HSM) or a secure key management system (SecureKMS). It is noted here that although... Figure 2 The secure storage 206 is shown as part of the encryption engine 104. In specific implementations, the secure storage 206 can be located anywhere accessible via a secure connection and is not necessarily part of the encryption engine 104. It should be noted that while further use of the various public keys (e.g., k) for the parties in the purchase order is described herein, proc and k supp ) for k s Additional security can be achieved by using asymmetric encryption, or by using other key pairs. s Perform asymmetric encryption, or use another key to pair k sSymmetric encryption can be used, and different encryption methods can provide different levels of security.

[0034] According to one embodiment of this disclosure, the encryption engine 104 is further configured to encrypt the sensitive data Cipher. Dsen The data is transmitted to distributed storage 106 for storage. According to one embodiment of this disclosure, distributed storage 106 may be the InterPlanetary File System (IPFS). As previously described, IPFS is a decentralized network protocol that uses a content-based addressing scheme to retrieve files. Each file and all its blocks are assigned a unique fingerprint, which is used to locate the node storing the content behind that fingerprint. IPFS is based on encrypted sensitive data Cipher... Dsen Generate a corresponding unique content identifier (CID) sen The CID sen Cipher pointing to encrypted sensitive data Dsen Location within IPFS. According to the IPFS specification, this CID... sen Based on encrypted sensitive data Cipher Dsen The content itself is unique, and any tampering with it will result in the generation of a different CID. Therefore, utilizing the characteristics of distributed storage ensures the security of encrypted sensitive data. Dsen The authenticity and integrity of the data. Then, system 100 receives the encrypted sensitive data Cipher returned from distributed storage 106. Dsen CID sen Furthermore, the metadata construction unit 108 constructs a Purchase Order Non-Fungible Token (PONFT) through smart contract 110 and blockchain 112 to uniquely identify the corresponding purchase order. It should be noted that although the above description uses IPFS as an example of distributed storage 106 to illustrate the corresponding embodiment, those skilled in the art can employ any other content-based distributed storage implementation.

[0035] Referring now to Table 2, which provides examples of sensitive data encrypted by encryption unit 104, it can be seen that sensitive data is now represented as encrypted data. Table 2 includes a field "IPFS Upload Result" to identify the corresponding data: no upload required (corresponding to non-sensitive data), and CID (the CID of the corresponding encrypted sensitive data returned by distributed storage). Table 2 shows the CIDs corresponding to the sensitive data field according to one embodiment of this disclosure, where different data correspond to different CIDs. According to one embodiment of this disclosure, all identified sensitive data as a whole has a corresponding CID (the "IPFS Upload Result" field for sensitive data in Table 2 corresponds to the same CID, i.e., CID1 and CID2 are the same).

[0036]

[0037] Table 2

[0038] It should also be noted here that the same data may be identified into different categories depending on the criteria used. For example, if either buyer 101a or supplier 101b believes that the purchase price involves competition and therefore access should be restricted to only authorized interested parties, then the price should be identified as sensitive data. It should also be noted that although in the example in Table 2, buyer 101a's contact name and email address are shown as being uploaded to distributed storage, depending on the implementation, it may not be necessary to upload this encrypted sensitive data.

[0039] According to one embodiment of this disclosure, the encrypted sensitive data Cipher returned from distributed storage 106... Dsen CID sen The data is transmitted to the metadata construction unit 108. In addition, other non-sensitive data in the purchase order is also transmitted to the metadata construction unit 108. According to one embodiment of this disclosure, before transmitting the non-sensitive data to the metadata construction unit 108, this non-sensitive data may also be transmitted to the distributed storage 106, whereby the distributed storage 106 generates a corresponding unique content identifier (CID) based on this non-sensitive data. non-sen Then the CID non-sen The data is returned to system 100 and transmitted to metadata construction unit 108. According to one embodiment of this disclosure, this non-sensitive data can be directly transmitted to metadata construction unit 108. Then, metadata construction unit 108, based on the encrypted sensitive data Cipher... Dsen CID sen and non-sensitive data (or CID of non-sensitive data) non-senMetadata is constructed for generating a Purchase Order Non-Fungible Token (PONFT) based on smart contract 110 and blockchain 112, which can uniquely identify the corresponding purchase order. According to one embodiment of this disclosure, the generated metadata includes at least encrypted sensitive data Cipher. Dsen CID sen According to one embodiment of this disclosure, the metadata is constructed according to the ERC-721 standard. According to one embodiment of this disclosure, the metadata is in JSON format. It is noted here that the metadata format can be any non-fungible token standard, and is not limited to the ERC-721 standard or JSON format. Subsequently, the metadata construction unit 108 transmits the generated metadata to the smart contract 110.

[0040] Now refer to Table 3, which provides an example of the metadata constructed by metadata construction unit 108.

[0041] The metadata in Table 3 includes non-sensitive data categorized as public data, represented in plaintext. Sensitive data is represented as encrypted data, IPFS upload results (same as in Table 2), and data access methods, indicating how the data should be accessed. Table 2 also includes E_K. proc and E_K supp These correspond to encrypting the symmetric key k using the public key of the purchaser 101a and the public key of the supplier 101b, respectively. s The value obtained afterwards.

[0042]

[0043] Table 3

[0044] It is also noted here that the same data may be identified into different categories depending on the criteria used. For example, if either purchaser 101a or supplier 101b believes that the purchase price involves competition and therefore should be restricted to access only by authorized interested parties, then the price "Price" should be identified as sensitive data. Table 3 shows the CIDs corresponding to sensitive data fields according to one embodiment of this disclosure, where different data corresponds to different CIDs. According to one embodiment of this disclosure, all identified sensitive data as a whole has a corresponding CID (the "IPFS Upload Result" field in Table 3 corresponds to the same CID, i.e., CID1 and CID2 are the same). Data accessed in its raw form can be viewed without decryption. It should also be noted here that although in the example in Table 3, the contact name and email of purchaser 101a are shown as being uploaded to distributed storage, depending on the implementation, it may not be necessary to upload this encrypted sensitive data.

[0045] According to one embodiment of this disclosure, the smart contract 110 specifies, but is not limited to, the following transactions: 1) verifying whether the format of the metadata transmitted by system 100 meets the corresponding specifications, such as the ERC-721 specification; 2) verifying the authenticity and integrity of the metadata transmitted by system 100; 3) minting non-fungible tokens (PONFTs) for purchase orders using blockchain 112 based on the verified metadata; 4) verifying various transactions including transmitting PONFTs to the parties involved in the purchase order; 5) transmitting PONFTs to the parties involved in the purchase order, etc. The smart contract 110 can be customized according to requirements. According to one embodiment of this disclosure, non-sensitive data and encrypted sensitive data in the purchase order are integrated into a single PONFT. Each PONFT uniquely identifies the corresponding purchase order. The sensitive data is doubly encrypted to increase security, ensuring that sensitive data can only be accessed by authorized parties while keeping non-sensitive data visible, thus balancing security and transparency regarding access to non-sensitive data.

[0046] According to one embodiment of this disclosure, after receiving a PONFT, the purchaser 101a and the supplier 101b can use their respective private keys to decrypt the symmetric key encrypted with their respective corresponding public keys to obtain the symmetric key used to encrypt sensitive data. Then, they can use the CID identified by the received PONFT to access the encrypted sensitive data stored in the distributed storage, and use the decrypted symmetric key to access the sensitive data.

[0047] According to this disclosure, since the sensitive data is first encrypted and then stored on the distributed storage 106, the key used to encrypt the sensitive data is further encrypted again using the public keys of all parties to the purchase order. This mechanism ensures that: 1) the encrypted sensitive data stored on the distributed storage 106 is protected against encryption. Dsen Protected by anti-tampering mechanisms, 2) even if the encrypted sensitive data is obtained by Cipher... Dsen CID sen Without the private keys of all parties involved in the purchase order, the symmetric key k cannot be decrypted. s Therefore, it is impossible to encrypt sensitive data using Cipher. Dsen Decryption is performed; 3) Each key is stored in secure storage 206, effectively preventing unauthorized access. Only those possessing the private key corresponding to the public key of each party involved in the purchase order can decrypt the encrypted sensitive data. Dsen Decrypt the data to ensure that sensitive data in purchase orders can only be accessed by authorized parties.

[0048] Now for reference Figure 3The document illustrates an exemplary flowchart of a method 300 for managing purchase orders in the construction and real estate industry according to an embodiment of the present disclosure. The method for managing purchase orders in the construction and real estate industry includes step 302, identifying sensitive data in the purchase orders, such as data that can be obtained from... Figure 1 The purchase order processing unit 102 executes the process. As previously mentioned, sensitive data includes data that is crucial for maintaining privacy, security, and competitive advantage, and should be restricted to access only by authorized parties. The categories of data that can be considered sensitive data have already been listed above and will not be repeated here. According to one embodiment of this disclosure, sensitive data in a purchase order can be identified based on corresponding fields in the structured data constituting the purchase order, according to predefined rules. Alternatively, sensitive data in a purchase order can be identified using a pre-trained model via machine learning.

[0049] Furthermore, in step 304, the identified sensitive data is encrypted to obtain encrypted sensitive data, which can be obtained, for example, by... Figure 1 The encryption engine 104 in the system executes the encryption. The sensitive data can be symmetrically encrypted using a key, such as the Advanced Encryption Standard (AES). According to one embodiment of this disclosure, the symmetric encryption key conforms to cryptographic standards, such as those defined by NIST SP800-90A. The key length can be 128 bits, 192 bits, 256 bits, etc. According to one embodiment of this disclosure, to increase additional security, the key used to encrypt the sensitive data can be further asymmetrically encrypted using the public keys held by each party involved in the purchase order, for example, using RSA encryption. According to one embodiment of this disclosure, the key length for RSA encryption can be 1024 bits, 2048 bits, etc. It is noted here that more complex encryption algorithms and longer key lengths can provide better security, but will increase the corresponding computational complexity. The appropriate encryption algorithm and key length can be selected based on the system's computational performance.

[0050] Further, in step 306, a unique Content Identifier (CID) for identifying the encrypted sensitive data is received. According to one embodiment of this disclosure, this is achieved, for example, by... Figure 1 The encryption engine 104 in the middle transmits encrypted sensitive data to distributed storage, for example... Figure 1 The data is stored in distributed storage 106, and the distributed storage generates a corresponding CID based on the content of the encrypted sensitive data. For example... Figure 1 System 100 in Figure 1 The distributed storage 106 receives a CID used to identify encrypted sensitive data. According to one embodiment of this disclosure, the distributed storage may be the InterPlanetary File System (IPFS).

[0051] Further, in step 308, metadata is constructed based on the received CID used to identify encrypted sensitive data, for example, by... Figure 1 The metadata construction unit 108 in the process is executed. According to one embodiment of this disclosure, the metadata includes the aforementioned CID used to identify encrypted sensitive data and other non-sensitive data in the purchase order. According to one embodiment of this disclosure, the metadata is constructed according to the ERC-721 standard. According to one embodiment of this disclosure, the metadata is in JSON format. It is noted herein that the metadata format can be any non-fungible token standard, and is not limited to the ERC-721 standard or JSON format.

[0052] Further, in step 310, a purchase order non-fungible token (PONFT) generated based on metadata is received. According to one embodiment of this disclosure, this can be, for example, from... Figure 1 The smart contract 110 in the middle is based on, for example Figure 1 The metadata received by System 100 is minted into PONFTs using blockchain 112. Non-sensitive data and encrypted sensitive data from purchase orders are integrated into a single PONFT. Each PONFT uniquely identifies the corresponding purchase order. Sensitive data is double-encrypted to enhance security, ensuring that sensitive data can only be accessed by authorized parties while keeping non-sensitive data visible, thus balancing security and transparency regarding access to non-sensitive data.

[0053] Furthermore, in step 312, PONFT is transmitted to all parties involved in the purchase order. Since the sensitive data is first encrypted, and then the key used to encrypt the sensitive data is further encrypted using the public keys of all parties involved in the purchase order, only those possessing the private keys corresponding to the public keys of the parties involved in the purchase order can decrypt the encrypted sensitive data, ensuring that the sensitive data in the purchase order can only be accessed by authorized parties.

[0054] Now for reference Figure 4 The diagram illustrates an exemplary specific interaction process 400 between a system for managing purchase orders and a user of the system and a blockchain, according to an embodiment of the present disclosure.

[0055] According to one embodiment of this disclosure, a purchase order processing unit 102 receives a purchase order from a purchaser 101a, as shown in 401. The purchase order processing unit 102 can generate a purchase order based on the purchase details provided by the purchaser 101a. After authentication and logging into system 100, the purchaser 101a can input the corresponding purchase details through an interface provided by system 100, such as a form in a GUI. The purchase details can be organized into structured data, enabling the purchase order processing unit 102 to generate a purchase order through the corresponding fields in the structured data. The generated purchase order can be notified to the suppliers involved in the purchase order, such as supplier 101b, to review the purchase order. After receiving the notification, supplier 101b can log into system 100 to query the relevant purchase order. Supplier 101b reviews the purchase order and replies with the supply status, as shown in 402. The purchaser 101a reviews the supply status reply from supplier 101b and confirms the purchase order, as shown in 403. After purchaser 101a confirms the purchase order, the status of the corresponding purchase order is updated to confirmed.

[0056] In response to the purchase order status changing to confirmed, the purchase order processing unit 102 identifies sensitive data in the purchase order. According to one embodiment of this disclosure, sensitive data includes data crucial for maintaining privacy, security, and competitive advantage, and this sensitive data should be restricted to access only by authorized interested parties. The types of data that can be considered sensitive data have already been described and will not be repeated here. According to one embodiment of this disclosure, the purchase order processing unit can identify sensitive data in the purchase order based on corresponding fields in the aforementioned structured data, according to predefined rules. Alternatively, sensitive data in the purchase order can be identified using a pre-trained model via machine learning.

[0057] Next, the purchase order processing unit 102 transmits the identified sensitive data to the encryption engine 104, which encrypts the sensitive data to obtain the encrypted sensitive data, as shown in 404. According to one embodiment of this disclosure, the encryption engine 104 can use a key to perform symmetric encryption on the sensitive data, such as the Advanced Encryption Standard (AES).

[0058] Subsequently, encryption engine 104 transmits the encrypted sensitive data to distributed storage 106, as shown in 405. Distributed system 106 generates a unique content identifier (CID) based on the encrypted sensitive data. This CID points to the location of the encrypted sensitive data in distributed storage 106. Distributed storage 106 returns the generated CID to system 100 (e.g., to encryption engine 104), as shown in 406.

[0059] Then, system 100 (e.g., by encryption engine 108) transmits the CID of the encrypted sensitive data returned by distributed storage 106 to metadata construction unit 108, as shown in 407. Metadata construction unit 108 constructs metadata based on the CID of the encrypted sensitive data and other data in the purchase order, for use in minting PONFTs for identifying the purchase order via smart contract 110 using blockchain 112. According to one embodiment of this disclosure, the metadata is constructed according to the ERC-721 standard. According to one embodiment of this disclosure, the metadata is in JSON format.

[0060] System 100 transmits the constructed metadata (e.g., by metadata construction unit 108) to smart contract 110, as shown in 408. Smart contract 110 deploys the metadata to blockchain 112, using the blockchain to mint PONFTs for identifying purchase orders, as shown in 409. Blockchain 112 returns the constructed PONFTs to smart contract 110 and further transmits the PONFTs to purchaser 101a and supplier 101b, as shown in 411. Purchaser 101a and supplier 101b can use their respective private keys to decrypt the symmetric keys encrypted with their respective public keys to obtain symmetric keys for encrypting sensitive data. They then use the CID identified by the received PONFT to access the encrypted sensitive data stored in distributed storage, and use the decrypted symmetric keys to access the sensitive data.

[0061] Now refer to Figure 5 The diagram illustrates a block diagram of an electronic device 500 according to one embodiment of the present disclosure. For example, the electronic device 500 may be provided as a server. (Refer to...) Figure 5 The electronic device 500 includes a processor 522, which may be one or more, and a memory 532 for storing computer programs executable by the processor 522. The computer programs stored in the memory 532 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processor 522 may be configured to execute the computer program to perform the aforementioned method for managing purchase orders in the construction and real estate industry.

[0062] Additionally, the electronic device 500 may also include a power supply component 526 and a communication component 550. The power supply component 526 can be configured to perform power management of the electronic device 500, and the communication component 550 can be configured to enable communication of the electronic device 500, such as wired or wireless communication. Furthermore, the electronic device 500 may also include an input / output (I / O) interface 558. The electronic device 500 can operate on an operating system, such as Windows Server, stored in memory 532. TM Mac OSX TM UnixTM Linux TM etc.

[0063] In another exemplary embodiment, a computer-readable storage medium including program instructions is also provided, which, when executed by a processor, implement the steps of the method for managing purchase orders in the construction and real estate industry described above. For example, the computer-readable storage medium may be the memory 532 including the program instructions described above, which may be executed by the processor 522 of the electronic device 500 to complete the method for managing purchase orders in the construction and real estate industry described above.

[0064] The preferred embodiments of this disclosure have been described in detail above with reference to the accompanying drawings. However, this disclosure is not limited to the specific details of the above embodiments. Within the scope of the technical concept of this disclosure, various simple modifications can be made to the technical solutions of this disclosure, and these simple modifications all fall within the protection scope of this disclosure.

[0065] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, this disclosure will not describe the various possible combinations separately.

[0066] Furthermore, various different embodiments of this disclosure can be combined in any way, as long as they do not violate the spirit of this disclosure, they should also be regarded as the content disclosed in this disclosure.

Claims

1. A computer-implemented system for managing purchase orders in the construction and real estate industry, comprising: The purchase order processing unit is configured to identify sensitive data in the purchase order; An encryption engine is configured to encrypt the sensitive data; Metadata construction unit is configured to receive a Uniform Content Identifier (CID) for identifying encrypted sensitive data, and to construct metadata based on the CID, wherein the metadata includes the CID and other data in the purchase order; The system is further configured to receive a non-fungible token (PONFT) for a purchase order generated based on the metadata, and to transmit the PONFT to the parties involved in the purchase order.

2. The system according to claim 1, wherein: The encryption engine uses a symmetric algorithm to encrypt the sensitive data.

3. The system according to claim 1, further comprising: Distributed storage is configured to store the encrypted sensitive data and generate the CID.

4. The system according to claim 1, wherein: The PONFT is generated by a smart contract on the blockchain based on the metadata.

5. The system according to claim 1, wherein: The metadata is verified by the smart contract to ensure its correctness and completeness.

6. The system according to claim 1, wherein: The transmission of the PONFT to the parties involved in the purchase order is managed by the smart contract to ensure its correctness and integrity.

7. The system according to claim 2, wherein: The encryption engine uses an asymmetric algorithm to encrypt the symmetric key of the symmetric algorithm using the public keys of each party involved in the purchase order.

8. The system according to claim 1, wherein: The metadata is constructed according to the ERC-721 standard.

9. A computer-implemented method for managing purchase orders in the construction and real estate industry, comprising: Identify sensitive data in the purchase order; Encrypt the sensitive data; Receive a Uniform Content Identifier (CID) used to identify encrypted sensitive data; Metadata is constructed based on the CID, wherein the metadata includes the CID and other data in the purchase order; Receive a non-fungible token (PONFT) for a purchase order generated based on the metadata; as well as The PONFT is transmitted to all parties involved in the purchase order.

10. A data processing system, comprising: At least one processor, At least one memory includes computer-readable program code, which is executed by the at least one processor to configure the at least one processor to implement the method according to any one of claims 1-8.