Identity credibility collaborative authentication system and method in cross-department business process

By combining carrier management, two-way seal generation, and erasure embedding latch modules, the problem of unverifiable evidence in cross-departmental business processes is solved, enabling trusted collaborative authentication and efficient auditing in offline scenarios.

CN121690601APending Publication Date: 2026-03-17JIANGSU INST OF ECONOMIC & TRADE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-22
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

In cross-departmental business processes, existing technologies struggle to provide verifiable evidence of process links when data flows between multiple systems, leading to gaps in collaborative authentication and difficulties in auditing and attribution of responsibility. This is especially true in scenarios involving offline nodes and isolated network segments, where it is impossible to reliably determine whether a process has actually been completed.

Method used

The carrier management module is used to perform standardized summary calculation and generate a carrier bit set through dynamic mapping rules. The two-way seal generation module generates a seal and a handover receipt seal when each department's step is completed. The erasure embedding latch module performs fragment embedding and signature verification to ensure that the seal chain can still be restored after the exchange bus is rearranged.

Benefits of technology

It enables the Seal Chain to recover verification under fault tolerance thresholds without relying on online callbacks and shared logs, significantly improving the evidentiary value and audit efficiency of cross-departmental collaborative processes and reducing the risk of lost process proofs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121690601A_ABST
    Figure CN121690601A_ABST
Patent Text Reader

Abstract

The invention discloses an identity credibility collaborative authentication system and method in a cross-department business process, and relates to the technical field of network and information security, and the system comprises a carrier management module which is used for carrying out standardized abstract calculation on a business carrier and generating a bearing position set and a dynamic mapping rule which are used for scattered embedding, a follow-up department has the consistent bearing position positioning capability under the condition that only a service carrier is held; and the bidirectional seal generation module is used for respectively generating step seals and handover receipt seals when steps of each department are completed and handover occurs, after a seal chain formed by the step seals and the handover receipt seals is subjected to blinding and erasure coding fragmentation, a semantic invariant redundant bearing area of a business carrier is mapped and dispersedly embedded according to a dynamic bearing bit, and the step seals and the handover receipt seals are subjected to the step seals and the handover receipt seals. Any subsequent department can recover and check the fact that necessary steps are completed and handed over only by means of a service carrier in an off-line mode, and therefore credible collaborative authentication and responsibility-attributable auditing of the cross-department process are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network and information security, in particular to an identity trusted collaborative authentication system and method in cross-department business process. BACKGROUND

[0002] Cross-department business processes usually confirm the subject identity through federated authentication and single sign-on, but in the scenario where business flows between multiple systems, isolated network segments, offline nodes, and exchange bus field cleaning and rearrangement, it is difficult to provide verifiable process link evidence to subsequent departments relying solely on login assertions.

[0003] In cross-department workflows, downstream departments cannot reliably determine whether the previous necessary links are truly completed, handovers are truly occurring, carriers are being replayed or tampered with, and further collaborative authentication voids and audit accountability difficulties are produced without callback to upstream systems, without dependence on central orchestration online services, and without sharing authentication logs. At the same time, after the exchange bus desensitizes, rearranges, and deletes fields of the business carrier, the traditional scheme of placing process proof into explicit fields or token carriers is easily destroyed by cleaning, resulting in unrestorable and unverifiable process proof. SUMMARY

[0004] The purpose of the present application is to provide an identity trusted collaborative authentication system and method in cross-department business process to solve the problems raised in the background art.

[0005] To solve the above technical problems, the present application provides the following technical solution: an identity trusted collaborative authentication system and method in cross-department business process, comprising: a carrier management module for normalizing and abstracting business carriers and generating a set of bearing bits for dispersed embedding and dynamic mapping rules, so that subsequent departments have consistent bearing bit positioning capabilities under the condition of only holding business carriers; A two-way seal generation module is used to generate a step seal and a handover receipt seal when each department step is completed and a handover occurs, respectively, and to organize the step seal and the handover receipt seal into a seal chain to represent the completion of the process and the handover fact. An erasure embedding door latch module is used to perform erasure coding and fragmentation on the seal chain and disperse embedding into the business carrier according to the dynamic mapping rules, and to perform door latch verification in the downstream department to restore the seal chain and complete signature verification and link consistency check, and then output a release decision.

[0006] According to the technical scheme, the carrier management module comprises: a core abstract sub-module, configured to extract preset core fields from a service carrier, form a normalized representation, and calculate a core abstract; a bearing bit definition sub-module, configured to preset semantic invariant redundant bearing areas based on a service carrier format constraint, and form a bearing bit set; and a dynamic mapping sub-module, configured to generate a bearing bit index sequence based on a case identifier and a step identifier to determine a writing position of each fragment; The bidirectional seal generation module comprises: a step seal sub-module, configured to form a step seal that can be verified based on a step completion fact; a handover receipt sub-module, configured to form a handover receipt seal that can be verified based on a fact that a receiver actually receives and confirms; and a blinding processing sub-module, configured to perform deterministic blinding on the step seal and the handover receipt seal to make them appear as unstructured fragments in the bearing area. The error correction embedding latch module comprises: an error correction coding sub-module, configured to generate a fragment set satisfying a fault tolerance threshold based on the blinded seal; a dispersed embedding sub-module, configured to write the fragments into the bearing bit set according to the bearing bit index sequence; a recovery verification sub-module, configured to extract the fragments from the service carrier, recover the seal chain by error correction decoding, and perform verification and link consistency check; a strategy latch sub-module, configured to output a release or rejection decision according to a preset step set and a release rule; and an audit evidence output sub-module, configured to output an audit evidence package containing the seal chain and the verification result.

[0007] A method for identity trust collaborative authentication in a cross-department business process, comprising the following steps: S1, initialization step: an initiating department performs normalized processing on a service carrier, generates a core abstract and a mapping seed, forms bearing bit positioning basic information bound to a case, and writes the bearing bit positioning basic information into the service carrier; S2, step seal generation step: a current department generates a step seal bound to a case, a core abstract, and a step identifier after completing necessary business processing in the department, and integrates the step seal into a seal chain; S3, handover receipt generation and embedding step: a next department generates a handover receipt seal after actually receiving a service carrier and completing reception confirmation, and a current department dispersely embeds the step seal and the handover receipt seal into the service carrier after blinding and error correction coding of the step seal and the handover receipt seal; S4, downstream latch verification step: any subsequent department extracts fragments from a service carrier and recovers a seal chain before performing a key business operation, and outputs a release decision after completing verification, pair consistency check, and link consistency check; S5, audit accountability step: an audit party generates an audit evidence package based on a recovered seal chain and a verification result, and determines a responsibility boundary according to a step seal issuer and a handover receipt issuer.

[0008] According to the technical scheme, the S1 is specifically: S1-1, core field extraction and normalization: extract a preset core field set from the service carrier, denoted as , as a field set necessary for determining business processing results, permission release judgment, and audit accountability in cross-department processes, deterministic normalization serialization is performed to obtain , deterministic normalization serialization refers to the uniformization processing of field name, field order, character encoding, numerical format, time format, white space processing, and separator symbol, so that the byte sequence generated in the same in different systems, different network segments, and different parser environments remains consistent; S1-2, core summary calculation: calculate the core summary , satisfying , wherein represents a hash function, used to represent the consistency of the core content of the service carrier, as the binding object of the subsequent step sealing and handover receipt sealing, when the field rearrangement and field display form change of the service carrier in the exchange bus do not affect the core field semantics, due to the determinism of , it can still keep stable to allow consistent verification by downstream departments; S1-3, mapping seed generation and solidification: generate case identification and mapping seed , and write to the preset solidification area of the service carrier, the solidification area refers to the write area in the service carrier for storing process trusted evidence reference information, which satisfies that when the content is modified after writing, it can be detected in the subsequent door latch verification, thereby ensuring the consistency and non-repudiation of the mapping seed, wherein is generated by the initiating department based on its signing key, and the signing data is solidified, so that subsequent departments can derive the bearing bit index sequence and blind mask based on the same , ensuring the locatability and recoverability of the sealing fragments on each department side.

[0009] According to the above technical solution, the S2 is specifically: S2-1, step sealing data construction: construct the to-be-signed data of the current step, satisfying , wherein represents the step identifier, used to clearly indicate the process link corresponding to the current step, represents the previous step chain digest, used to bind the current step and the previous step in order, avoiding step insertion, deletion, and rearrangement while still passing the verification, represents the current department strategy snapshot digest, This is used to bind the authentication strategy status on which the release was based in this step, so that during auditing, it can be determined that the basis for the release at that time was consistent with the fact of the seal issuance. Indicates serial connection. Allow the policy text and rule set for this step. Its version number, It is a fixed-length hashed data, which facilitates signature and consistency verification; S2-2, Step Seal Issuance: Generate Step Seal ,satisfy ,in Indicates the use of the current department's private key. The digital signature generation algorithm, the steps of which are sealed. Used to prove that the current department has completed and The corresponding necessary business processing and the issuance of the signature can be used to verify that the seal was issued by the corresponding department and that the content of the seal has not been tampered with during the subsequent bolt verification. This provides verifiable evidence of the completion of steps for cross-departmental processes. S2-3, Blinding and Erasure Coding: Generating a Blinding Mask And the process of sealing the steps is blinded to obtain ,satisfy , ,in This represents a pseudo-random generation function. This is the current department identifier. This indicates bitwise XOR, and the blinding refers to a mask generated deterministically. Seal Transform into data with no readable structure This makes the sealed information appear as an unidentifiable fragment within the business carrier area, thereby reducing the probability of it being cleaned by switching bus rules or mistakenly deleted as sensitive information by field auditing strategies. Perform erasure coding to obtain a set of fragments. And satisfy any choice not less than One fragment is enough to recover. Erasure coding refers to expanding the original data into multiple redundant fragments, so that the original data can still be recovered even if some fragments are lost, some data bits are cleaned or rearranged. The total number of fragments, This indicates the recovery threshold.

[0010] According to the above technical solution, S3 specifically refers to: S3-1. Construction of Receipt Confirmation and Receipt Data: After the next department actually receives the business carrier and completes the core digest consistency check, it constructs the receipt data to be issued. ,satisfy The actual reception refers to the receiving system having obtained the service carrier and being able to reproduce it. And confirm that it is in the carrier curing area Consistent This is used to bind the receipt to the step seal one by one, ensuring that the receipt is not signed for any carrier, but for the carrier containing the step seal, thereby making the handover fact verifiable and objective. S3-2. Issuance of Handover Receipt: Generate a handover receipt seal. ,satisfy ,in This indicates the next department's private key, and the handover receipt is sealed. Used to prove the recipient's confirmation of the handover; since the receipt is issued by the recipient, it can prevent false handovers and subsequent denials, and clarify the boundaries of handover responsibility during auditing; S3-3, Receipt Blinding, Erasure Coding, and Distributed Embedding: Generating Blinding Results for Receipt Seals and will Erasure coding yields a set of fragments. ,in Total number of receipt fragments; based on the set of bearer bits. , and index sequence The step fragments and receipt fragments are written into the business carrier, whereby... To map the set of bearer bits to a permutation function of a deterministic index sequence, the steps are fragmented. With receipt segmentation according to The corresponding data is written to specified locations in a distributed manner, ensuring that the sealed information can still be restored under threshold conditions even after field rearrangement and deletion. This refers to the set of carrier units in the business carrier structure that allow the writing of fragmented data without changing the business semantics or affecting the business verification rules. The deterministic generation enables different departments to consistently locate the carrier position of the segment on the same carrier, avoiding irreversible damage caused by inconsistent positioning; S3-4. Determining the Bearer Bit Set: Determine the candidate bearer bit list based on the service carrier type identifier and the bearer bit rule version number. The candidate bearer list is a set of fields that do not participate in the core field set. The extracted carrier unit set includes extended field units, memo field units, order-insensitive duplicate unit units, and equivalent encoding expression bit units. Each carrier unit is at least one locatable element selected from key-value pair fields, array elements, paragraph blocks, and table units. For each candidate unit... The test vehicle is obtained by performing equivalent load injection. The test vehicle must simultaneously satisfy structural verification, business verification, and core digest retention. When the candidate unit is included in the set of bearing positions , wherein the structure verification is carrier format and field constraint verification, and the service verification is service rule and approval legality verification; the bearing position rule version number is written into the carrier solidification area, so that subsequent departments reproduce the same set of bearing positions based on the same version number , wherein the structure verification is field path existence, type consistency, length and coding legality, and the service verification is that the bearing position does not participate extraction and does not affect reproduction.

[0011] According to the above technical scheme, the S4 is specifically: S4-1, slice extraction and threshold recovery: extracting a slice subset belonging to step from the service carrier bearing position set , when is not less than , performing erasure decoding recovery , and restoring the step seal through ; at the same time, when the number of reply slice subsets meets the corresponding recovery threshold, recovering , and restoring the handover reply seal through , wherein the threshold recovery refers to: when the number of slices is less than the threshold, no recovery is performed and it is directly determined that the evidence of this step is incomplete, thereby avoiding false release under the condition of incomplete evidence; the erasure decoding recovery is used to resist slice loss caused by the exchange bus, so that the system can still recover complete seal data after part of the bearing positions are cleaned; S4-2, signature verification and pair consistency verification: using the step seal issuer public key to verify , and using the reply issuer public key to verify , wherein represents a digital signature verification algorithm, and the determination condition of the pair consistency verification is that the step seal and the handover reply pass the signature verification at the same time, and bound in is consistent with the hash of obtained by recovery, thereby proving that the reply is actually issued for the step seal, avoiding incorrect splicing of the reply of other cases or other step seals to the current carrier; S4-3, link consistency and latch decision: calculating the current link digest according to the seal chain digest update rule , and taking it as the The link digest refers to a continuity identifier obtained by performing cumulative hashing on the step seals in sequence, and is used to detect link breakage caused by step insertion, step deletion, step rearrangement, and seal replacement; a release decision is output when all steps in the preset mandatory step set meet the slice recoverability, signature verification, pairwise consistency, and consistent link digest, otherwise a rejection decision is output, thereby forming a gate blocking point before downstream critical business operations, and ensuring that the process can be trusted before proceeding.

[0012] According to the above technical solution, the S5 is specifically: S5-1, evidence package generation: structurally packaging the recoverable step seal set , the handover receipt seal set , the corresponding signature verification input digest , and the link digest sequence to form an audit evidence package ; the structural packaging refers to establishing a correspondence between the step identifier, the issuer identifier, the recipient identifier, the seal data, the signature verification element, and the link position for each process step, so that the auditor can directly verify and locate without accessing the upstream business system log; S5-2, responsibility boundary determination: when there is a link in the audit evidence package that meets and , the abnormal responsibility is attributed to the department to which the handover recipient belongs, because the recipient has not completed effective issuance of the receipt fact bound to the step seal; when there is a link that meets and the subsequent link cannot form a consistent continuous link digest, the abnormal responsibility is attributed to the department to which the step issuer belongs, because the step completion evidence from this department cannot pass the signature verification, thereby destroying the continuity of the seal chain; the above determination is given by the seal signature verification result and the link continuity, avoiding the ambiguity caused by relying only on single-point logs; S5-3, evidence output: outputting an audit conclusion containing the issuer identifier, the recipient identifier, the step identifier, the signature verification result, the link digest breakpoint position, and the evidence package index, so that there is verifiable and accountable evidence basis in cross-department dispute processing; wherein, the breakpoint position is used to identify from which link the seal chain starts to be discontinuous and inconsistent, thereby forming clear positioning information when reviewing, auditing, and tracing responsibility.

[0013] Compared with the prior art, the present application has the beneficial effects that the present application strongly binds identity trust and process trust: on the one hand, the pair of evidence of step seal and handover receipt is adopted to suppress step skipping, pseudo handover, denial and replay; on the other hand, the erasure coding fragmentation and dynamic bearing mapping are adopted, so that the seal chain can be recovered and verified after the exchange bus field is cleaned, rearranged and deleted, to realize offline door latch release which does not depend on online callback, shared log and central arrangement; at the same time, the seal chain signature verification result can directly locate the responsibility boundary of the signing party and the receiving party, significantly improving the evidence and audit efficiency of cross-department collaborative process, and reducing the business interruption and security risks caused by the loss of process proof. BRIEF DESCRIPTION OF DRAWINGS

[0014] The accompanying drawings are included to provide a further understanding of the present application, and constitute a part of the specification, illustrate the present application and explain the technical scheme of the present application, and do not constitute a limitation on the present application. In the drawings: Figure 1 It is a schematic diagram of the overall module structure of the present application. DETAILED DESCRIPTION

[0015] The technical scheme in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0016] Please refer to Figure 1 The present application provides a technical scheme: an identity trust collaborative authentication system in a cross-department business process, comprising a carrier management module for normalizing and abstracting a business carrier and generating a bearing position set for dispersed embedding and a dynamic mapping rule, so that subsequent departments have consistent bearing position positioning ability under the condition of only holding the business carrier; A bidirectional seal generation module is used to generate a step seal and a handover receipt seal respectively when each department step is completed and handover occurs, and to organize the step seal and the handover receipt seal into a seal chain to represent the completion and handover fact of the process link; An erasure embedding door latch module is used to perform erasure coding fragmentation on the seal chain and disperse embedding in the business carrier according to the dynamic mapping rule, and to output a release decision after performing door latch verification in the downstream department to recover the seal chain and complete signature verification and link consistency check; The carrier management module comprises: a core summary submodule for extracting preset core fields from a service carrier and calculating a core summary after forming a normalized representation; a bearing bit definition submodule for presetting semantic invariant redundant bearing areas based on service carrier format constraints and forming a bearing bit set; and a dynamic mapping submodule for generating a bearing bit index sequence based on a case identifier and a step identifier to determine a writing position of each fragment; The bidirectional seal generation module comprises: a step seal submodule for forming a step seal that can be verified based on a step completion fact; a handover receipt submodule for forming a handover receipt seal that can be verified based on a fact that a receiver actually receives and confirms; and a blinding processing submodule for performing deterministic blinding on the step seal and the handover receipt seal to make them appear as unstructured fragments in the bearing area; The erasure embedding latch module comprises: an erasure coding submodule for generating a fragment set that meets a fault tolerance threshold from the blinded seal; a dispersed embedding submodule for writing the fragments into the bearing bit set according to the bearing bit index sequence; a recovery verification submodule for extracting the fragments from the service carrier and performing verification and link consistency check after recovering the seal chain through erasure decoding; a policy latch submodule for outputting a release or rejection decision according to a preset step set and a release rule; and an audit evidence output submodule for outputting an audit evidence package containing the seal chain and the verification result; A method for identity trustable collaborative authentication in a cross-department business process, comprising the following steps: S1, initialization step: the initiating department performs normalized processing on the service carrier and generates a core summary and a mapping seed, forms bearing bit positioning basic information bound to the case and writes it into the service carrier; S2, step seal generation step: the current department generates a step seal bound to the case, the core summary and the step identifier after completing the necessary business processing of the department, and integrates the step seal into the seal chain; S3, handover receipt generation and embedding step: the next department generates a handover receipt seal after actually receiving the service carrier and completing the reception confirmation, and the current department dispersely embeds the step seal and the handover receipt seal into the service carrier after blinding and erasure coding fragmentation; S4, downstream latch verification step: any subsequent department extracts fragments from the service carrier and recovers the seal chain before performing key business operations, and outputs a release decision after completing verification, pair consistency check and link consistency check; S5, audit accountability step: the audit party generates an audit evidence package based on the recovered seal chain and the verification result, and determines the responsibility boundary according to the step seal issuer and the handover receipt issuer; S1 specifically is: S1-1, core field extraction and normalization: extracting a preset core field set from the service carrier, denoted as as a set of fields necessary for deciding the results of business processing, permission release judgment, and audit accountability in cross-departmental processes, to deterministic canonical serialization is performed to obtain Deterministic canonical serialization refers to the uniform processing of field names, field order, character encoding, numerical format, time format, white space processing, and separator symbols, so that the byte sequence generated in different systems, different network segments, and different parser environments remains consistent under the premise of consistent field semantics. In different systems, different network segments, and different parser environments, the byte sequence generated remains consistent. S1-2, Core Digest Calculation: Calculate the core digest , which satisfies , where represents a hash function used to represent the consistency of the core content of the business carrier, as the binding object of the seal and the handover receipt seal in the subsequent steps, when the field rearrangement and field display form change in the business carrier in the exchange bus but do not affect the core field semantics, due to the determinism of , it can still keep stable to allow consistent verification by downstream departments; S1-3, Mapping Seed Generation and Solidification: Generate the case identifier and the mapping seed , and write to the preset solidification area of the business carrier. The solidification area refers to the write area in the business carrier for storing process trusted evidence reference information. This area satisfies the condition that if the content is modified after writing, it can be detected in the subsequent gate latch verification, thereby ensuring the consistency and non-repudiation of the mapping seed, where The signing data is generated and solidified by the initiating department based on its signing key, allowing subsequent departments to derive the bearing bit index sequence and blind mask based on the same without calling the upstream system, ensuring the locatability and recoverability of the seal fragments on each department side; S2 is specifically: S2-1, Step Seal Data Construction: Construct the to-be-signed data for the current step , which satisfies , where represents the step identifier, which is used to clearly indicate the process link corresponding to the seal, represents the previous seal chain digest, which is used to bind the current step and the previous step in order to avoid step insertion, deletion, and rearrangement while still passing the verification, represents the current department policy snapshot digest, which is used to bind the authentication policy state on which the release of the current step is based, so that the audit can determine that the release at that time is consistent with the seal signing fact, represents concatenation, a release policy text and rule set for the step, a version number thereof, a hashed fixed-length data for signature and consistency check; S2-2, Step Seal Issuing: Generating Step Seal , satisfying wherein denotes a digital signature generation algorithm using the current department private key , the step seal is used to prove that the current department has completed the corresponding mandatory business process with and issued a seal for this fact. In subsequent gate verification, by verifying the signature, it can be confirmed that the seal is issued by the corresponding department and the seal content has not been tampered with, thereby providing verifiable step completion evidence for cross-departmental processes; S2-3, Blinding and Erasure Coding: Generating Blinding Mask and performing blinding on the step seal to obtain , satisfying , wherein denotes a pseudo-random generation function, is the current department identifier, denotes a bitwise XOR operation. Blinding refers to transforming the seal into data with no readable structure by a deterministically generated mask so that the seal appears as an indistinguishable segment in the business carrier bearing area, thereby reducing the probability of being washed by the exchange bus rule and being deleted as sensitive information by the field audit policy, and performing erasure coding on to obtain a set of shards , and satisfying that any shards can recover , wherein erasure coding refers to expanding the original data into multiple shards with redundancy, so that the original data can still be recovered after some shards are lost, some bearing bits are washed or rearranged, is the total number of shards, denotes the recovery threshold;The prior art is to directly store the step signature Si or its digest into a field, or put it into a workflow token, which is either washed out or too conspicuous to be located and deleted in multi-system flow, and cannot be verified once the field is lost, resulting in a break in the credibility of the process; The working principle of the present step is: a blind result Bi=SiXORKi is generated using a mask Ki derived from Seed0, IDdept,i, and IDstep,i, so that the data sealed in the carrier appears as unreadable structure, and then Bi is encoded to obtain a fragment set {bi,1...bi,ni}, which satisfies that any ki fragments can recover Bi, so that single-point evidence is changed into fault-tolerant recoverable fragment evidence; The present step plays two roles in the scheme: one is to reduce the probability of the seal being deleted as a sensitive signature by the bus strategy (blinding), and the other is to upgrade the evidence from single-point storage to loss-resistant storage (erasure code); The originality does not lie in the existence of blinding or erasure code alone, but in the abstraction of evidence loss caused by cross-department carrier washing as a bearing bit erasure channel, and the combination of blinding hiding and erasure recovery to systematically improve the evidence survival rate and recoverability, so that the downstream can reconstruct the step seal without callback, which is difficult to naturally think of in traditional workflow tokens or single-field signatures.

[0017] S3 is specifically: S3-1, receiving confirmation and return data construction: the next department constructs return data to be signed after actually receiving the business carrier and completing the core digest consistency check , satisfying , actual receiving means that the receiving system has obtained the business carrier and can reproduce and confirms that it is consistent with in the carrier solidification area, for binding the return with the step seal one by one, ensuring that the return is not signed for any carrier, but for the carrier containing the step seal, so that the handover fact has objective verifiability; S3-2, handover return issuance: generating a handover return seal , satisfying , wherein represents the private key of the next department, and the handover return seal is used to prove the confirmation of the receiving party to the handover fact; Since the return is issued by the receiving party, it can suppress false handover and ex post facto denial, and clearly define the handover responsibility boundary during auditing; Conventional handover proofs often involve the recipient signing a receipt or the platform recording a handover log. These receipts typically only bind a CaseID or document number and cannot prove which step of the seal they correspond to, thus leaving room for sham handovers, mismatched receipts, and subsequent repudiation. For example, an attacker could splice a receipt from another case or at another point in time onto the current carrier, creating a seemingly complete handover chain. The working principle of this step is: construct the receipt data Ni to be signed as H(IDcase||Dc||IDstep,i||H(Si)), that is, explicitly embed the hash H(Si) of the step seal into the receipt input. The recipient generates a receipt seal Ri=Signsk(i+1)(Ni), making the receipt a confirmation of the carrier containing the seal Si of this step. This step plays a role in strongly binding the handover facts with the evidence of specific steps in the scheme, and is the core anchor point for pairwise consistency verification in latch verification. Its originality lies in upgrading the handover from a general acceptance of documents / case numbers to a precise acceptance of the fingerprint of the step seal, structurally eliminating the vulnerability of receipts being ported across cases and steps, and clearly pointing the responsibility to the recipient's signing entity. This is a cryptographic level of evidence strength that conventional log records or general receipts cannot provide.

[0018] S3-3, Receipt Blinding, Erasure Coding, and Distributed Embedding: Generating Blinding Results for Receipt Seals and will Erasure coding yields a set of fragments. ,in Total number of receipt fragments; based on the set of bearer bits. , and index sequence The step fragments and receipt fragments are written into the business carrier, whereby... To map the set of bearer bits to a permutation function of a deterministic index sequence, the steps are fragmented. With receipt segmentation according to The corresponding data is written to specified locations in a distributed manner, ensuring that the sealed information can still be restored under threshold conditions even after field rearrangement and deletion. This refers to the set of carrier units in the business carrier structure that allow the writing of fragmented data without changing the business semantics or affecting the business verification rules. The deterministic generation enables different departments to consistently locate the carrier position of the segment on the same carrier, avoiding irreversible damage caused by inconsistent positioning; S3-4. Determining the Bearer Bit Set: Determine the candidate bearer bit list based on the service carrier type identifier and the bearer bit rule version number. The candidate bearer list is a set of fields that do not participate in the core field set. The extracted carrier unit set includes an extension field unit, a note field unit, a sequence-insensitive duplicate unit, and an equivalent encoding expression bit unit. The carrier unit is at least one of a key-value pair field, an array element, a paragraph block, and a table unit. For each candidate unit The test carrier is obtained by performing equivalent load injection. When the test carrier satisfies the structure verification, the business verification, and the core summary remains , the candidate unit is included in the bearing bit set . The structure verification is a carrier format and field constraint verification. The business verification is a business rule and approval legality verification. The bearing bit rule version number is written into the carrier solidification area, so that subsequent departments can reproduce the same bearing bit set based on the same version number . The structure verification is a field path existence, type consistency, length and coding legality. The business verification is that the bearing bit does not participate in extraction and does not affect the reproduction of the judgment formula. The conventional method is usually to write the process proof into a fixed field (metadata / attachment / extension field) or an independent token. As a result, the proof field is easily washed away under the desensitization, field pruning, field rearrangement, and Schema filtering of the cross-department exchange bus. Downstream departments cannot recover the evidence and can only call back the upstream system or rely on the central orchestrator online query, which directly fails in offline scenarios. The working principle of this step is: first, obtain the candidate bearing bit list Ucand according to the carrier type identifier and the rule version number, then perform equivalent load injection on each candidate unit, and simultaneously pass the structure verification and the business verification while keeping the core summary Dc unchanged as the access condition, so as to determine the writable bearing bit that does not change the semantics as U, and solidify the version number into the carrier to ensure cross-department reproducibility. This step plays a role in changing the abstract semantic invariant redundant bearing area into a set of carrier units that can be determined, reproduced, and implemented, directly supporting the subsequent fragmentation, dispersion, and embedding and offline recovery. Its originality lies in upgrading the bearing bit selection from an empirical and manually configured soft link to a verifiable judgment process (structure verification + business verification + core summary unchanged), and achieving consistent reproduction across domains through rule version solidification, which fundamentally solves the atypical pain point of where to put the evidence so that it will not be eaten by the bus.

[0019] S4 is specifically: S4-1, fragment extraction and threshold recovery: extracting a fragment subset belonging to step from the business carrier bearing bit set when is not less than , performing erasure decoding recovery , and passing The reduction step seals; at the same time, when the number of receipt fragments meets the corresponding recovery threshold, the recovery is performed , and by The reduction of the handover receipt seal, threshold recovery refers to: when the number of fragments is less than the threshold, the recovery is not performed and the evidence is directly determined to be incomplete, thereby avoiding false release under the condition of incomplete evidence; erasure decoding recovery is used to resist the loss of fragments caused by the exchange bus, so that the system can still recover complete sealed data after part of the bearing position is washed; S4-2, signature verification and pair consistency check: use the step seal issuer public key , verify , and use the receipt issuer public key verify , wherein represents a digital signature verification algorithm, and the judgment condition of pair consistency check is: the step seal and the handover receipt pass the signature verification at the same time, and The hash of bound in is consistent with the hash of obtained by recovery, thereby proving that the receipt is issued for the step seal, and avoiding the error of splicing the receipt of other cases or other step seals to the current carrier; S4-3, link consistency and gate decision: calculate the current link digest according to the seal chain digest update rule , and use it as the of the next step, the link digest is a continuity identifier obtained by accumulating the hash of the seal chain according to the step order, which is used to detect the link breakage caused by step insertion, step deletion, step rearrangement and seal replacement; when all steps in the preset necessary step set meet the fragment recoverable, the signature verification passes, the pair consistency passes and the link digest is consistent, output the release decision, otherwise output the rejection decision, thereby forming a gate type blocking point before the downstream key business operation, ensuring that the process is reliable before continuing to handle.The conventional process compliance inspection depends on a central workflow engine to maintain the state or relies on scattered logs for post-accounting; in a non-callable, cross-domain isolated scenario, the downstream department cannot query the previous state online, and can only default to believe the upstream or force manual verification, resulting in either security holes or efficiency disasters; the working principle of this step is: the downstream first recovers Si and Ri from the carrier fragment, then respectively verifies Verifypk(i)(Si, Mi) = 1 and Verifypk(i+1)(Ri, Ni) = 1 using the public key, and checks that the bound H(Si) in Ni is consistent with the recovered Si, forming step seal-receipt seal pair consistency; then recursively link the abstracts according to Dchain,i = H(Dprev||H(Si)||H(Ri)) and require continuous consistency, and convert missing steps, inserted steps, replaced seals, and rearranged steps into link breaks; this step plays a decisive role in the offline gate latch release in the scheme: it refuses critical operations if the evidence closed loop does not meet the mandatory steps; its originality lies in transferring cross-department process compliance from relying on central state to relying on the verifiable evidence chain carried by the carrier, and using pair consistency + link continuity to cover the authenticity of the handover and the integrity of the step order simultaneously, so that strict process authentication can still be completed under bus cleaning and isolated network, and this gate mechanism that moves the process control point to each downstream node is not a simple application of the conventional method in the field.

[0020] S5 is specifically: S5-1, evidence package generation: structurally package the recoverable step seal set , the handover receipt seal set , the corresponding signature verification input abstract , and the link abstract sequence to form an audit evidence package ; structurally packaging means establishing a correspondence between step identification, signature issuer identification, receiver identification, seal data, signature verification elements, and link position for each process step, so that the auditor can directly carry out verification and positioning without accessing the upstream business system logs; S5-2, responsibility boundary determination: when there is a link in the audit evidence package that satisfies and , the abnormal responsibility is attributed to the department to which the receiving party belongs, because the receiving party has not completed effective issuance of the receipt fact bound to the step seal; when there is a link that satisfies and the subsequent link cannot form a consistent continuous link abstract, the abnormal responsibility is attributed to the department to which the step issuer belongs, because the step completion evidence of this department cannot be verified through signature verification, thereby destroying the continuity of the seal chain; the above determination is given by the seal signature verification result and the link continuity, avoiding the ambiguity of attribution caused by relying only on single-point logs; S5-3, evidence output: output the audit conclusion containing the issuer identity, the receiver identity, the step identity, the signature verification result, the link summary breakpoint position and the evidence package index, so as to have verifiable and accountable evidence basis in cross-department dispute handling; wherein, the breakpoint position is used to identify the starting point of the seal chain discontinuity and inconsistency, thereby forming clear positioning information in the review, audit and responsibility tracing.

[0021] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one entity or action from another, without necessarily requiring or implying any such actual relationship or order between such entities or actions. Moreover, the terms including, including or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed or inherent to such process, method, article or apparatus.

[0022] Finally, it should be noted that the above only describes the preferred embodiments of the present application and is not intended to limit the present application. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent replacements to some technical features. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A system for identity trustable collaborative authentication in cross-department business processes, characterized in that: Comprise: A carrier management module for normalized summary calculation of business carriers and generation of a set of bearing positions for dispersed embedding and dynamic mapping rules, enabling subsequent departments to have consistent bearing position positioning capabilities under the condition of only holding business carriers; A two-way seal generation module for generating step seals and handover receipt seals respectively when each department step is completed and handover occurs, and organizing the step seals and the handover receipt seals into a seal chain to represent the completion and handover facts of the process; An erasure embedding door latch module for erasure coding and fragmenting the seal chain and dispersively embedding the business carrier according to the dynamic mapping rules, while performing door latch verification in downstream departments to recover the seal chain and output a release decision after signature verification and link consistency check.

2. The identity trustable collaborative authentication system in cross-department business processes according to claim 1, characterized in that: The carrier management module comprises: a core summary submodule for extracting preset core fields from the business carrier and forming a normalized representation to calculate a core summary; a bearing position definition submodule for predefining semantic invariant redundant bearing areas based on business carrier format constraints and forming a bearing position set; and a dynamic mapping submodule for generating a bearing position index sequence based on case identification and step identification to determine the writing position of each fragment; The two-way seal generation module comprises: a step seal submodule for forming a step seal that can be verified based on the step completion fact; a handover receipt submodule for forming a handover receipt seal that can be verified based on the actual receipt and confirmation fact of the receiver; and a blinding processing submodule for performing deterministic blinding on the step seal and the handover receipt seal to make them appear as unstructured fragments in the bearing area; The erasure embedding door latch module comprises: an erasure coding submodule for generating a set of fragments that satisfy the fault tolerance threshold after blinding the seal; a dispersed embedding submodule for writing the fragments into the bearing position set according to the bearing position index sequence; a recovery and signature verification submodule for extracting the fragments from the business carrier, recovering the seal chain after erasure decoding, and performing signature verification and link consistency check; a policy door latch submodule for outputting a release or rejection decision according to a preset set of required steps and release rules; and an audit evidence output submodule for outputting an audit evidence package containing the seal chain and the signature verification result.

3. The method of claim 1 or 2, wherein the method further comprises: Comprise the following steps: S1, initialization step: the initiating department performs normalized processing on the business carrier and generates a core summary and a mapping seed, forms bearing position positioning basic information bound to the case, and writes it into the business carrier; S2, step seal generation step: the current department generates a step seal bound to the case, the core summary, and the step identification after completing the required business processing in the department, and integrates the step seal into the seal chain; S3, handover receipt generation and embedding step: the next department generates a handover receipt seal after actually receiving the business carrier and completing the receipt confirmation, and the current department blinding and erasure coding fragments the step seal and the handover receipt seal before dispersively embedding them into the business carrier; S4, downstream door latch verification step: any subsequent department extracts fragments from the business carrier and recovers the seal chain before performing key business operations, and outputs a release decision after completing signature verification, pair consistency check, and link consistency check; S5, audit accountability step: the audit party generates an audit evidence package based on the recovered seal chain and the signature verification result, and determines the responsibility boundary according to the step seal issuing party and the handover receipt issuing party.

4. The method of claim 3, wherein: The S1 is specifically: S1-1, core field extraction and normalization: extract a preset core field set from the business carrier, denoted as , as a field set necessary for deciding business processing results, permission release determination, and audit accountability in cross-department processes, , to determine the normalized serialization of , the normalized serialization means to unify the field name, field order, character encoding, numerical format, time format, white space processing, and separator symbol, so that the byte sequence generated in the same in different systems, different network segments, and different parser environments remains consistent; S1-2, core summary calculation: calculate the core summary , meet , wherein , represents a hash function, used to characterize the consistency of the core content of the service carrier, as a binding object for sealing and handover receipt sealing in subsequent steps, when the service carrier has field rearrangement and field display form change in the switching bus, but does not affect the semantics of the core field, because of the determinacy of , can still keep stable; S1-3, mapping seed generation and solidification: generating a case identification with the mapping seed and writing into a preset solidification area of the service carrier, the solidification area refers to a writing area in the service carrier for storing the process trusted evidence reference information, the area meets the condition that when the content is modified after writing, it can be detected in the subsequent latch verification, wherein The issuing department generates issuing data based on its issuing key and solidifies, so that subsequent departments can derive the same bearing bit index sequence and blind mask.

5. The method of claim 4, wherein: The S2 is specifically: S2-1, Step-by-Step Seal Data Construction: Construct the data to be issued for the current step. ,satisfy ,in Indicates the first Each step is marked to clearly identify the process stage corresponding to this seal. This represents the digest of the previous seal chain, used to bind the current step to the previous step in sequence. This represents a summary of the current department's strategy snapshot. This is used to bind the authentication policy status upon which this step is based. Indicates serial connection. Allow the policy text and rule set for this step. Its version number, The hashed data is of fixed length. S2-2, Step Seal Issuing: Generating Step Seal , satisfying wherein denotes a digital signature generation algorithm using the current department private key , the step seal is used to prove that the current department has completed the corresponding mandatory business process with and issues a seal for this fact, and in the subsequent door latch verification, the seal can be confirmed by the corresponding department and the seal content has not been tampered with by signature verification. S2-3, blinding and erasure coding: generating a blinding mask and performing blinding on the step seal to obtain , satisfying , wherein denotes a pseudo-random generation function, is a current department identifier, denotes a bitwise XOR, and the blinding refers to masking the seal into data of an unreadable structure so that the seal appears as an unrecognizable piece in the business carrier carrying area, and performing erasure coding on the seal to obtain a set of shards and satisfying that any shards can be recovered wherein the erasure coding refers to expanding the original data into multiple shards with redundancy, is the total number of shards, denotes a recovery threshold.

6. The method of claim 5, wherein: The S3 is specifically: S3-1, Receiving Acknowledgement and Constructing Receipt Data: The next department constructs receipt data to be issued after actually receiving the service carrier and completing the core summary consistency check , satisfying , the actual receiving refers to that the receiving system has obtained the service carrier and can reproduce and confirms that it is consistent with the in the carrier solidification area, for binding the receipt with the step seal one by one; S3-2, handover receipt issuance: generating a handover receipt seal , satisfying wherein denotes a next department private key, the handover receipt seal for proving the receiver's confirmation of the handover fact; S3-3, Receipt blinding, erasure coding and dispersed embedding: generating blinding result for receipt seal and erasure coding to get a set of fragments wherein is the total number of receipt fragments; based on a set of bearing bits , and an index sequence write the step fragments and receipt fragments into a service carrier, wherein is a permutation function that maps the set of bearing bits to a deterministic index sequence, the step fragments and the receipt fragments are written in specified positions in a dispersed manner, so that the service carrier can still recover the seal information under the threshold condition after the field rearrangement and deletion, wherein refers to a set of carrier units in the service carrier structure that allow writing of fragment data without changing the service semantics and without affecting the service verification rules; S3-4, carrying position set determination: according to the service carrier type identifier and the carrying position rule version number to determine the candidate carrying position list , the candidate carrying position list is not involved in the core field set , the extracted carrier unit set, and includes the extension field unit, the note field unit, the order-insensitive repeat unit, and the equivalent encoding expression position unit. For each candidate unit , perform equivalent load injection to obtain a test carrier. When the test carrier simultaneously satisfies the structure verification, the service verification, and the core summary remains , the candidate unit is included in the carrying position set , wherein the structure verification is carrier format and field constraint verification, and the service verification is service rule and approval legality verification; write the carrying position rule version number into the carrier solidification area, so that subsequent departments can reproduce the same carrying position set based on the same version number , the structure verification is the existence of field path, type consistency, length and coding legality, and the service verification is that the carrying position is not involved in the extraction and does not affect , the reproduction of the judgment formula .

7. The method of claim 6, wherein: The S4 is specifically: S4-1, Fragment Extraction and Threshold Recovery: Extracting fragments from the business carrier bit set belonging to the step... Fragmentation ,when Not less than Perform erasure decoding and recovery at the time and through The restoration process is sealed; simultaneously, restoration is initiated when the number of receipt fragment subsets meets the corresponding restoration threshold. and through Restoring the handover receipt seal, the threshold restoration refers to: when the number of fragments is less than the threshold, the restoration is not performed and the evidence for this step is directly determined to be incomplete; S4-2, Signature Verification and Pairwise Consistency Check: Seal the issuer's public key using a step-by-step process. ,verify and using the public key of the signatory of the receipt. verify ,in This refers to a digital signature verification algorithm, where the pairwise consistency check is determined by the following conditions: both the step seal and the handover receipt pass the signature verification simultaneously, and... Binded in With the recovery The hashes are consistent; S4-3, link consistency and gate decision: calculate the current link digest according to the seal chain digest update rule , and as the next step , the link digest refers to the continuity identifier obtained by accumulating the hash of the seal chain in the order of steps, which is used to detect link breaks caused by step insertion, step deletion, step rearrangement and seal replacement; output the release decision when all steps in the preset mandatory step set meet the slice recoverable, signature verification passed, pairwise consistency passed and link digest continuous consistency, otherwise output the rejection decision.

8. The method of claim 7, wherein the method further comprises: The S5 is specifically: S5-1, Evidence package generation: Structured packaging of the recoverable set of step seals , handover receipt seal set , corresponding signature verification input digest and link digest sequence forms an audit evidence package , the structured packaging refers to establishing a correspondence of step identification - issuer identification - recipient identification - seal data - signature verification element - link location for each process step; S5-2, responsibility boundary determination: when there is a link in the audit evidence package that satisfies and , the abnormal responsibility is attributed to the department to which the handover receiver belongs, because the receiver has not completed effective issuance on the receipt fact bound to the seal of this step; when there is a link that satisfies and the subsequent link cannot form a consistent continuous link summary, the abnormal responsibility is attributed to the department to which the step issuer belongs; S5-3, evidence output: output an audit conclusion containing the identifier of the issuing party, the identifier of the receiving party, the identifier of the step, the signature verification result, the link summary breakpoint position, and the evidence package index, so as to have verifiable and accountable evidence basis in cross-department dispute handling; wherein, the breakpoint position is used to identify from which link the seal chain is discontinuous and inconsistent.