Methods, systems, and media for hierarchical authorization sharing and traceability of cross-enterprise recruitment data
By encrypting candidate identity domains with multi-dimensional tag sets and managing corporate reputation accounts in cross-enterprise recruitment, the problem of blurred data sharing boundaries in cross-enterprise recruitment is solved, candidate privacy protection and data security are achieved, and collaboration efficiency and trust are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HANGZHOU JINGJIA TECH CO LTD
- Filing Date
- 2026-02-26
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies lack fine-grained data sharing boundary definitions in cross-enterprise recruitment, leading to risks of enterprises unauthorized access to candidate privacy fields and malicious secondary dissemination of data, failing to meet the balance between security and collaboration in joint recruitment scenarios.
By obtaining the candidate's identity domain, encoding identity features, generating a multi-dimensional tag set, and performing multiple layers of security encryption, a data usage carrier is built to form an identity digest; by obtaining enterprise qualification materials, creating a reputation account, formulating a reputation score adjustment mechanism to divide trust levels and configuring access tokens, and combining secure multi-party computation to calculate matching degree and traceability.
It achieves the protection of candidate privacy and controllable data sharing, accurately manages enterprise data access permissions, reduces the risk of unauthorized access and malicious secondary dissemination, enhances the trust foundation for multi-enterprise collaboration, and promotes the large-scale development of joint recruitment.
Smart Images

Figure CN121723457B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of human resources information security storage technology, and more specifically, to a method, system, and medium for cross-enterprise recruitment data hierarchical authorization sharing and traceability. Background Technology
[0002] With the continued growth in demand for cross-enterprise collaborative recruitment and the increasing need to improve the efficiency of accurate candidate matching, companies need to share some candidate information to support joint screening. However, traditional data sharing relies on API interfaces or file transfers, which lack fine-grained and tamper-proof definitions of sharing boundaries. This can easily lead to problems such as companies accessing other companies' candidate privacy fields without authorization and data being maliciously disseminated after sharing. This not only undermines the trust foundation of multi-enterprise collaboration but also hinders the large-scale implementation of joint recruitment. How to clarify data sharing boundaries and avoid the risks of unauthorized access and malicious secondary dissemination while ensuring candidate privacy and the data security of the companies themselves remains a technical challenge in the field of human resources joint recruitment.
[0003] In the prior art, Chinese patent application CN119814409A discloses a blockchain-based cross-domain data sharing method. This method includes generating public parameters and sending them to the data domain; calculating a master public key and a master private key; the data owner encrypting the shared data ciphertext using a symmetric key; uploading the ciphertext encrypted with the symmetric key to the blockchain; the blockchain verifying the requester's reputation value and attributes, and forwarding the request after verification; the data owner generating a re-encryption key, and a smart contract generating the re-encryption key ciphertext for the requester to decrypt and obtain the target data, thus improving data sharing security and privacy. Chinese patent CN109726586A discloses a fine-grained data authorization sharing method. This method generates an information list containing sensitive fields by scanning, establishes a data sharing authorization table containing sensitive fields and operation permissions; after receiving a data operation request, it compares it with the authorization table, and blocks the request if they do not match, thus solving the problem of low security in shared data.
[0004] However, while the two existing technologies mentioned above have some value in terms of cross-domain sharing security and fine-grained authorization, they fail to address the core pain point of blurred data privacy sharing boundaries in multi-company joint recruitment. Specifically, CN119814409A focuses on encrypted cross-domain data transmission but lacks a dynamic sharing boundary for candidate privacy fields specifically designed for recruitment scenarios, and lacks precise hierarchical access permissions between companies. CN109726586A focuses on sensitive data access control but fails to leverage the immutability of blockchain to build a sharing traceability mechanism, thus failing to prevent malicious secondary dissemination of data. Neither of these technologies establishes a linkage mechanism between corporate reputation and access permissions; they either excessively restrict data sharing efficiency or fail to guarantee candidate privacy and corporate data security, thus failing to meet the balance between security and collaboration in joint recruitment scenarios. Summary of the Invention
[0005] This invention is applicable to multi-enterprise joint recruitment scenarios, meeting the dual needs of cross-enterprise collaborative candidate screening and ensuring candidate privacy and enterprise data security. It obtains a multi-dimensional candidate tag set by acquiring the candidate's identity domain and performing identity feature encoding processing. Combining this with key crystal computation to encrypt the key crystal set and intra-block verification string, a data usage carrier is built to generate the candidate's public key and inter-block anchor code, forming an identity digest. Simultaneously, it acquires and calculates the recruiting company's qualification materials to obtain the company identifier, company public key, and creates a reputation account. A reputation score adjustment mechanism is established to obtain real-time reputation score, trust level, and access token. After verifying the recruiting company's identity using the company identifier and access token, the calculation range of the trust level is defined to verify the credentials, shifting data access permissions from broad control to precise definition, effectively avoiding unauthorized access and malicious secondary data propagation. Secure multi-party computation is used to perform matching degree calculation, obtaining the encrypted final result, which is then associated with the identity digest and access record index for traceability. This protects data security, improves collaboration efficiency, strengthens the trust foundation for multi-enterprise collaboration, and promotes the large-scale implementation of joint recruitment.
[0006] To achieve the above objectives, the present invention provides the following technical solution:
[0007] Methods for tiered authorization, sharing, and traceability of cross-enterprise recruitment data include:
[0008] Obtain the candidate identity field, perform identity feature encoding on the candidate identity field to obtain a candidate multidimensional tag set, perform multiple security encryption on the candidate multidimensional tag set to obtain an encryption key crystal set and an intra-block verification string, and construct a data usage carrier based on the encryption key crystal set and the intra-block verification string to perform security verification, thereby obtaining an identity digest of the data identifier and storage record representing the candidate's digital identity.
[0009] Obtain enterprise qualification information, create reputation accounts with reputation scores for recruiting enterprises based on enterprise qualification information, and formulate a reputation score adjustment mechanism to adjust the reputation scores to obtain real-time reputation scores for permission allocation. Based on the real-time reputation scores, divide trust levels and configure access tokens with different permissions for trust levels.
[0010] The system verifies the identity of recruiting companies based on reputation accounts, obtains recruitment requirements and transforms them into digital signatures for privacy protection, performs decryption verification on the digital signatures to obtain verification credentials that are associated with data identifiers and access tokens, defines the calculation range of trust levels for the verification credentials and performs matching degree calculations to obtain the final encrypted result and associate it with the identity digest for traceability.
[0011] Furthermore, the method for obtaining the candidate multidimensional label set includes:
[0012] Candidate identity domains are obtained through a blockchain-based human resources information exchange platform. These domains include heterogeneous original information composed of structured data and unstructured text, as well as the candidate's authorization intent.
[0013] Key information is identified from unstructured text in the candidate identity domain, and a set of key information is constructed.
[0014] Data identification was performed on structured data, key information sets, and candidate authorization intent, respectively. Occupational dimension labels were identified from structured data, competency dimension labels were identified from key information sets, and authorization dimension labels were identified from candidate authorization intent.
[0015] The occupational dimension label, ability dimension label, and authorization dimension label are combined to obtain a candidate multidimensional label set.
[0016] Furthermore, the method for obtaining the cryptographic key set and the intra-block check string includes:
[0017] Multiple highly sensitive privacy data are selected from the candidate identity domain, and then highly sensitive privacy data that can be directly linked to the candidate is selected from the multiple highly sensitive privacy data. The highly sensitive privacy data of the candidate is called the privacy barrier.
[0018] The key is converted into N independent binary data crystals.
[0019] Perform multiple security encryption on the tag combination string, that is, calculate the tag combination string to obtain the encryption key crystal, and calculate the encryption key crystal to obtain the block check string.
[0020] Furthermore, the method for obtaining the identity digest includes:
[0021] The data carrier contains data integrity verification, ownership proof, available operational scope, shared lifetime, and secondary propagation dormancy rules;
[0022] Data integrity verification is associated with the verification string within the block, generating a candidate public key for the candidate and associating it with ownership proof, the available operation scope is associated with the candidate's authorization intent, the shared lifetime value is associated with the preset number of times, and the secondary propagation dormancy rule is associated with the preset dormancy period;
[0023] The data integrity verification, ownership proof, available operation scope, shared lifetime value and secondary propagation dormancy rule are associated with the data to calculate the inter-block anchor code used to detect whether the data has been tampered with;
[0024] The data identifier representing the candidate's digital identity is obtained by concatenating the intra-block verification string with the inter-block anchor code string and calculating the concatenated string.
[0025] The data identifier, inter-block anchor code, and candidate public key are combined to obtain an identity digest for storing the record.
[0026] Furthermore, the reputation account includes:
[0027] Obtain enterprise qualification materials, verify the enterprise qualification materials, and if the verification is successful, extract the binding data of the associated recruiting enterprise from the enterprise qualification materials;
[0028] The bound data is converted into a string format and calculated to obtain the unique identifier of the corresponding recruiting company, i.e., the company identifier.
[0029] Generate a private key for the recruiting company;
[0030] Once the company's qualification materials are verified, a reputation account is created for the recruiting company. Each reputation account contains a reputation score and is also linked to the recruiting company's corporate identity and public key.
[0031] Furthermore, the method for obtaining the real-time reputation score includes:
[0032] The reputation score adjustment mechanism includes a positive score addition mechanism, a violation score deduction mechanism, and an appeal handling mechanism;
[0033] The reputation account contains reputation points. In the positive point-adding mechanism, recruiting companies receive points when they successfully hire a candidate with the candidate's authorization or recommend other recruiting companies to the candidate and the candidate is successfully hired.
[0034] In the violation penalty mechanism, points will be deducted from recruiting companies when they violate the secondary dissemination dormancy rules or when their access requests are rejected.
[0035] In the appeal handling mechanism, when a recruiting company is found to have abused its rights, its reputation score will be deducted. If a candidate makes a malicious appeal, their appeal privileges will be restricted.
[0036] The reputation score adjustment mechanism links the addition and subtraction of reputation scores to company identifiers, meaning that the real-time reputation score of recruiting companies can be viewed through the company identifier.
[0037] Furthermore, the reputation score adjustment mechanism includes:
[0038] When the reputation score in a reputation account is greater than the high reputation threshold, the recruiting company will be marked as a high-quality company and the title will be visible to candidates. At the same time, the recruiting company will be granted the right to apply to directly view the candidate's private profile.
[0039] If the reputation score of the recruiting company's reputation account is less than the low reputation threshold but greater than or equal to 1, the frequency of access requests initiated by the recruiting company will be limited, thereby reducing the chance of obtaining the key crystal.
[0040] If the reputation score of a recruiting company's reputation account is less than 1 (i.e., 0), the recruiting company will be marked as a company to be removed from the blockchain human resources information exchange platform, and the company's identity will be cancelled and the recruiting company will be removed. At the same time, the recruiting company's submitted qualification materials will no longer be accepted.
[0041] Furthermore, the method for obtaining the verification credential includes:
[0042] After clarifying their recruitment needs, the recruiting company converts the recruitment needs into a string format and calculates the seventh hash value. The seventh hash value is then asymmetrically encrypted to obtain a digital signature. The recruiting company then uploads the recruitment needs and the digital signature to the blockchain human resources information exchange platform.
[0043] After receiving the digital signature, the blockchain-based human resources information exchange platform decrypts it using the company's public key. If the signature can be decrypted, it determines that the recruitment request was initiated by the recruiting company. The platform then recalculates the recruitment request and compares it with the seventh hash value. If the hash values are completely identical, it determines that the recruitment request has not been tampered with during transmission. Simultaneously, the blockchain-based human resources information exchange platform sends a verification credential to the recruiting company.
[0044] Furthermore, the method for obtaining the final encrypted result includes:
[0045] The trust level of the recruiting company is extracted from the verification credentials, and the calculation range for different trust levels is defined by combining multi-company datasets. At the same time, the defined range is also the viewing permission range of the corresponding trust level.
[0046] Perform a matching degree calculation on the calculation range without exposing the original data to obtain the original calculation result. Convert the original calculation result into a string format and calculate to obtain the eighth hash value.
[0047] The original calculation result is asymmetrically encrypted using the company's public key to obtain the final encrypted result, which is then sent back to the recruiting company.
[0048] A cross-enterprise recruitment data hierarchical authorization sharing and traceability system, used to implement the aforementioned cross-enterprise recruitment data hierarchical authorization sharing and traceability method, the system comprising:
[0049] Candidate data processing module: used to obtain candidate identity domain, perform identity feature encoding on candidate identity domain to obtain candidate multidimensional tag set, perform multiple security encryption on candidate multidimensional tag set to obtain encryption key crystal set and block verification string, and construct data usage carrier based on encryption key crystal set and block verification string to obtain data identifier representing candidate digital identity and identity digest of storage record;
[0050] Enterprise data processing module: used to obtain enterprise qualification information, create reputation accounts with reputation scores for recruiting enterprises based on enterprise qualification information, formulate a reputation score adjustment mechanism to adjust the reputation scores, obtain real-time reputation scores for permission allocation, divide trust levels according to real-time reputation scores, and configure access tokens with different permissions for trust levels.
[0051] Data traceability module: Used to verify the identity of recruiting companies based on reputation accounts, obtain recruitment requirements and convert them into digital signatures for privacy protection, perform decryption verification on the digital signatures to obtain verification credentials that are associated with data identifiers and access tokens; define the calculation range of trust level for the verification credentials and perform matching degree calculation to obtain the encrypted final result and associate it with the identity digest for traceability.
[0052] A computer-readable storage medium storing a computer program, which, when executed, implements the aforementioned method for a cross-enterprise recruitment data hierarchical authorization sharing and traceability system.
[0053] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0054] This invention obtains a multi-dimensional tag set of candidates by acquiring their identity domain and performing identity feature encoding. It then combines this with key crystal calculation to encrypt the key crystal set and the intra-block verification string, and uses a data carrier to form an identity digest. This addresses the pain points of traditional data sharing, such as ambiguous boundaries and susceptibility to malicious secondary propagation, achieving both candidate privacy protection and controllable data sharing. Furthermore, by acquiring enterprise qualifications to generate enterprise identifiers, public keys, and reputation accounts, and relying on a reputation score adjustment mechanism to obtain real-time reputation scores, trust levels, and matching access tokens, it solves the problems of unauthorized access by enterprises and high leakage risks from low-trust enterprises. It precisely controls data access permissions for different enterprises. Through differentiated verification, combined with secure multi-party calculation of matching degree and generation of encrypted final results, it links the identity digest with access record indexes for traceability, solving the problems of exposed original data and untraceable operations. This balances data security and collaboration efficiency while strengthening the trust foundation among multiple enterprises, promoting the large-scale implementation of joint recruitment. Attached Figure Description
[0055] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0056] Figure 1 A flowchart illustrating the method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data provided in this embodiment of the invention;
[0057] Figure 2 A logical judgment diagram for the trust level of recruiting companies provided in an embodiment of the present invention;
[0058] Figure 3 A logical judgment diagram of a recruitment company access request provided in an embodiment of the present invention;
[0059] Figure 4 This is a functional module diagram of the cross-enterprise recruitment data hierarchical authorization sharing and traceability system provided in an embodiment of the present invention. Detailed Implementation
[0060] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0061] Example 1
[0062] Please see Figure 1 As shown, this embodiment provides a method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data. It should be specifically noted that all candidate information and recruiting company data involved in this embodiment are legal information obtained with explicit authorization from the relevant parties (candidates and companies) or after full authorization from all parties. This technical solution strictly adheres to relevant laws and regulations regarding personal information protection and data security in the collection, storage, encryption, and sharing of data, and there is no situation of illegal acquisition or use of data beyond the scope, including:
[0063] Step S10: Obtain the candidate identity field, perform identity feature encoding on the candidate identity field to obtain a candidate multidimensional tag set, perform multiple security encryption on the candidate multidimensional tag set to obtain an encryption key crystal and an intra-block verification string, and construct a data usage carrier based on the encryption key crystal and the intra-block verification string to perform security verification, thereby obtaining an identity digest representing the candidate's digital identity and the storage record.
[0064] Further, step S10 includes:
[0065] Step S11: Obtain the candidate identity field, perform identity feature encoding on the candidate identity field, and obtain the candidate multidimensional label set.
[0066] Candidate identity domains are obtained through a blockchain-based human resources information exchange platform. Before acquiring data, the platform displays a "User Privacy Agreement" and a "Data Authorization Letter" to candidates, clearly informing them of the scope of data collection (limited to professional background, skills information, and necessary contact information required for recruitment), processing purpose, and storage period. Data acquisition can only be performed after the candidate confirms by checking the box and actively uploads the data. Data collection is limited to adult users with legal work qualifications; no information from unauthorized users or minors is collected. The blockchain-based human resources information exchange platform uses blockchain technology as its underlying support, serving as a carrier for information exchange and data flow between candidates and recruiting companies. It can accept human resources-related data uploaded by candidates and receive requests submitted by recruiting companies, achieving decentralized and traceable management of information exchange and ensuring the reliability of data processing. The aim is to solve the risks of information leakage caused by direct transmission, the traceability problem of easily tampered operation records, the problem of excessive sharing caused by unclear permission boundaries, and the incompatibility between centralized architecture and security requirements in real-world scenarios. The candidate identity domain is data voluntarily uploaded by candidates to the blockchain-based human resources information exchange platform, including heterogeneous original information and the candidate's authorization intent. Heterogeneous raw information refers to factual information describing a candidate's professional background and abilities. It is divided into structured data and unstructured text. Structured data refers to information with a fixed format, clearly defined fields, and direct computer recognition and extraction capabilities, such as educational background, university, degree, major, and work experience in a resume. Unstructured text refers to free text without a fixed format, requiring semantic interpretation to extract information, such as project descriptions and personal skill summaries. The aim is to process the information provided by candidates more efficiently and accurately. The candidate's authorization intent represents the data usage boundaries set by the candidate, clearly defining their initial intention to use their data within the sharing process, including restrictions such as prohibiting sharing with specific candidate companies and allowing data use only in fintech recruitment scenarios.
[0067] Identity feature encoding is performed on the candidate identity domain. Specifically, key information is identified from the unstructured text in the candidate identity domain, and a key information set is constructed. Key information refers to technical entities and industry scenario entities in the unstructured text, output in key-value pair format. For example, if the extracted key information includes Java and the bank's core system, it is output in the form of (technical entity, Java) and (industry scenario entity, bank's core system). The technical entities and industry scenario entities output in key-value pair format constitute the key information set.
[0068] Data identification is performed on structured data, key information sets, and candidate authorization intentions. From the structured data, occupational dimension tags are identified, including experience years tags and job type tags. For example, if the structured data shows 5 years of work experience and a backend developer position, the experience years tag is 5 years, and the job type tag is backend developer. From the key information set, capability dimension tags are identified, including industry scenario tags and technology tags. For example, if the key information set shows "(technology entity, Java)" and "(industry scenario entity, bank core system)," the industry scenario tag corresponds to bank core system, and the technology tag corresponds to Java. From the candidate authorization intentions, authorization dimension tags are identified, including unauthorized tags and scenario tags. For example, "prohibited from sharing with the candidate's designated company, only for use in fintech recruitment scenarios," the corresponding unauthorized tag is the candidate's designated company name, and the scenario tag is fintech recruitment scenario. Scenario tags are broader than industry scenario tags and can cover similar scenarios across industries. Combining the occupational dimension tags, capability dimension tags, and authorization dimension tags yields a multi-dimensional tag set for the candidate.
[0069] Step S12: Select the key from the candidate identity field, divide the key into N key crystals, and combine them with the candidate multidimensional tag set to obtain the tag combination string. Perform multiple encryption calculations on the tag combination string to obtain the encryption key crystal set and the block verification string.
[0070] This invention filters out multiple highly sensitive privacy data from the candidate identity domain. The embodiments of this invention follow the "minimum necessity principle" for data filtering, processing only information specifically authorized by the candidate and necessary for core aspects of the recruitment process (such as identity verification and interview contact). Highly sensitive privacy data refers to personal information that may cause substantial harm to the candidate's person, property, or other legitimate rights. Examples include ID card numbers (used only for unique identification and irreversibly masked during storage), personal mobile phone numbers, and home addresses.
[0071] The process involves filtering out highly sensitive privacy data from multiple sources to identify data that allows direct contact with the candidate. This highly sensitive privacy data is referred to as the key, D, such as the candidate's private email address and mobile phone number. The key, D, is then converted into N independent binary key crystals, P. Among them, the key crystal is a secret partitioning method that divides the secret wall into N independent binary fragments to reduce the risk of leakage. Let N represent the Nth binary data key crystal. When a recruiting company obtains any K key crystals, it can calculate D using a recovery function, such as Lagrange interpolation. When the recruiting company obtains any K-1 key crystals, it cannot deduce the valid information of D through any calculation, thus reducing the harm of a single key crystal leakage and eliminating the need for separate key management, balancing data security and sharing flexibility. Here, N represents the total number of key crystals, where N key crystals constitute complete highly sensitive privacy data, ranging from 1 to N. K represents the minimum number of key crystals required to recover the highly sensitive privacy data, where 1 < K < N. The values of N and K are determined comprehensively based on the balance between security and availability, the complexity of the access scenario, and industry technical standards. For example, taking a user's bank account payment password as an example, due to the extremely high data sensitivity requiring strong security, combined with the core payment data standards of the financial industry, and needing to be distributed to 5 entities including the bank's risk control system, the user's mobile terminal, and a backup node in the cloud, while balancing security and availability, avoiding the risk of leakage of a single key crystal, and allowing recovery even when 1 to 2 nodes fail, N=5 and K=3 are ultimately chosen.
[0072] For each key crystal, an authorization dimension label is selected from the candidate multi-dimensional label set and combined with each key crystal to form a label combination string, accurately matching the user's authorization intent and preventing excessive data exposure and abuse at the source. The label combination string is a string obtained by combining the authorization dimension label and the key crystal. Multiple layers of security encryption are performed on the label combination string: a cryptographic hash algorithm is used to calculate the label combination string to obtain a first hash value. This first hash value is used as the symmetric encryption key for the key crystal corresponding to the label combination string. The symmetric encryption key is then encrypted again using the hash algorithm to obtain a string-formatted encrypted key crystal. All the encrypted key crystals corresponding to all the key crystals are combined to obtain a string-formatted encrypted key crystal set. A second hash value is calculated using a cryptographic hash algorithm on the encrypted key crystal set, and this second hash value is used as the intra-block checksum.
[0073] Step S13: Based on the intra-block verification string and the encryption key set, build a data usage carrier and perform security verification to obtain the candidate public key and inter-block anchor code used to detect data security.
[0074] The data usage carrier is implemented in the form of smart contracts, including data integrity verification, ownership proof, and available operation scope. Data integrity verification refers to detecting whether the encrypted key set has been tampered with, determined by comparing the string of the verification string within the block, providing a basis for judging the authenticity of the data. Ownership proof means that the data usage carrier clearly defines the data ownership, i.e., the candidate is the sole owner of the data. A candidate key pair is generated for the candidate based on an asymmetric encryption algorithm. The candidate key pair includes the candidate's private key and candidate's public key. The candidate's public key can be publicly transmitted, while the candidate's private key is kept by the candidate and the blockchain human resources information exchange platform to prevent unauthorized modification of data usage rules and ensure that the candidate can control data permissions. The available operation scope transforms the candidate's authorization intent into a visual list of operation permissions. The recruiting company can only perform operations within the scope of permissions, limiting the usage scenario and preventing over-authorization and abuse.
[0075] Building upon ownership proof and available operational scope, a shared lifetime and a secondary propagation dormancy rule are added to the data usage carrier. The shared lifetime represents a preset number of times the encrypted key set can be used. This limits the cumulative number of times the encrypted key set can be shared by different recruiting companies, preventing unlimited data access and ensuring the data owner's control over resource consumption. The preset number is set within a reasonable range for candidates on the blockchain-based human resources information exchange platform, taking into account the typical frequency of company access in the human resources recruitment scenario, the sensitivity of candidate data, and the security control settings of the blockchain-based human resources information exchange platform. The secondary propagation dormancy rule prohibits the same requesting company from directly or indirectly accessing the encrypted key set again within a preset dormancy period after the first access by the requesting company. This prevents unauthorized secondary propagation, aims to block chain propagation, protect candidate rights, and reduce the risk of data leakage. The preset dormancy period is set within a reasonable period for candidates on the blockchain-based human resources information exchange platform, taking into account the typical cycle of the human resources recruitment process, the timeliness requirements of candidate data, and candidates' willingness to protect against secondary data propagation.
[0076] The data integrity verification string associated with the block, the candidate public key associated with the ownership proof, the candidate authorization intent corresponding to the available operation scope, the preset number of times the shared lifetime value corresponds to, and the preset dormancy period corresponding to the secondary propagation dormancy rule are integrated into a structured dataset in a fixed order. A third hash value is obtained by calculating the structured dataset using a cryptographic hash algorithm. This third hash value is used as an inter-block anchor code to detect whether related data in the data usage carrier has been tampered with, such as whether the preset number of times the shared lifetime value has been modified. After the data usage carrier, including the shared lifetime value and the secondary propagation dormancy rule, is constructed, a fourth hash value is obtained by calculating the structured data of the initial state of the complete data usage carrier using a cryptographic hash algorithm. This fourth hash value is used as the base hash of the data usage carrier. The difference between the base hash and the inter-block anchor code is that the base hash is calculated on the structured data of the initial state of the constructed data usage carrier, while the inter-block anchor code is calculated on the real-time structured data of the data usage carrier. When a recruiting company initiates an access request, the blockchain human resources information interaction platform compares the inter-block anchor code with the base hash for string matching. If the two are completely consistent, access is allowed; otherwise, access is denied.
[0077] Step S14: Associate the encryption key set with the data carrier to obtain a data identifier representing the candidate's digital identity. Combine the data identifier with the inter-block anchor code and the candidate's public key to obtain an identity digest for secure storage.
[0078] The data integrity verification string in the data carrier is associated with the block verification string. The block verification string is concatenated with the inter-block anchor code string, and then the fifth hash value is calculated by a cryptographic hash algorithm. The fifth hash value is used as the data identifier. The data identifier is the candidate's digital identity in the blockchain human resources information interaction platform. Subsequent access requests from recruiting companies and data usage record queries are all located through the data identifier to avoid data confusion or misassociation.
[0079] The data identifier, inter-block anchor code, and candidate public key are combined to obtain an identity digest. The identity digest is stored in the blockchain blockchain of the human resources information exchange platform to prevent ownership misuse and unauthorized rule tampering, realize decentralized and traceable management of data exchange, avoid the risk of leakage of highly sensitive privacy data, reduce blockchain storage costs, and improve data processing reliability.
[0080] Step S10 addresses the technical challenges of direct transmission and leakage of human resources information, easy tampering of records, excessive sharing due to ambiguous permissions, and incompatibility between centralized architecture and security by using candidate identity domain, candidate multidimensional tag set, highly sensitive privacy data, encrypted key set, intra-block verification string, data usage carrier, candidate public key, inter-block anchor code, data identifier, and identity digest. It also solves the problems of leakage and failure of highly sensitive data, data abuse, unlimited access, unauthorized secondary propagation and data tampering, ownership misuse, high blockchain storage cost, and low processing reliability. The candidate identity domain enables efficient and accurate processing of candidate information; the encrypted key crystal avoids the harm of leaking a single key crystal and eliminates the need for separate management; the encrypted key crystal set ensures the security of highly sensitive data; the block checksum provides a basis for verifying the integrity of the encrypted key crystal set; data integrity verification in the data usage carrier ensures data ownership control; the shared lifespan limit the cumulative number of times data can be accessed by different recruiting companies; the secondary propagation dormancy rule prohibits the same company from directly or indirectly accessing the data repeatedly; the data identifier enables accurate positioning of data in the blockchain human resources information interaction platform, avoiding data confusion or misassociation; the identity digest enables decentralization and traceability of data interaction, preventing ownership misuse and unauthorized rule tampering.
[0081] Step S20: Obtain enterprise qualification information, create a reputation account with reputation score for the recruiting enterprise based on the enterprise qualification information, and formulate a reputation score adjustment mechanism to adjust the reputation score to obtain a real-time reputation score for permission allocation. Divide trust levels according to the real-time reputation score and configure access tokens with different permissions for the trust levels.
[0082] Further, step S20 includes:
[0083] Step S21: Obtain enterprise qualification materials, use the enterprise qualification materials to set a unique and identifiable enterprise identifier for the recruiting enterprise, and create a reputation account associated with the enterprise identifier for the recruiting enterprise.
[0084] Before recruiting candidates through the blockchain-based human resources information exchange platform, companies need to submit their qualification materials to the platform. These materials verify the company's legal business entity status, specific business operation licenses, and the validity of its identity. For example, these materials include a copy of the company's business license, a human resources service license, and proof of identity of the company's legal representative. The business license verifies the recruiting company's independent legal entity status; the human resources service license verifies whether the company possesses the necessary qualifications for compliant operation; and the legal representative's identity establishes a binding relationship between the company and its legal representative, supporting subsequent operational flexibility and liability determination.
[0085] The blockchain-based human resources information exchange platform verifies the qualification materials submitted by recruiting companies. If the verification is successful, the platform extracts the associated binding data of the recruiting company from the qualification materials, such as the unified social credit code on the company's business license copy. This binding data is converted into a string format, and a cryptographic hash algorithm is used to calculate the sixth hash value. This sixth hash value serves as the recruiting company's unique identifier. Similarly, an asymmetric encryption algorithm is used to generate a company key pair for the recruiting company. The key pair includes a public key and a private key. The private key is kept independently by the recruiting company and cannot be transmitted externally to prevent unauthorized modification of data access requests or breach of access boundaries, thus clarifying the company's security responsibility for its own operations. The company public key must be submitted to the blockchain-based human resources information exchange platform for registration and storage, and can only be publicly transmitted within the platform for verification and encryption. It is also associated with the company identifier as the basis for identity verification when initiating subsequent access requests, preventing unauthorized impersonation of the company to tamper with operation requests or forge data access applications, ensuring the traceability and uniqueness of the recruiting company.
[0086] Upon successful verification of the company's qualification materials, a reputation account is created for the recruiting company. This reputation account is linked to the company's corporate identity and public key, ensuring one reputation account per company. The reputation account reflects the recruiting company's trusted identity and status. The reputation account includes a reputation score, access record index, frozen score, and registration timestamp. The reputation score represents a quantifiable trust metric set by the company, with an initial value of 100. The access record index is a hash array recording interaction records between the recruiting company and candidate data. This allows for the review of past behavior and traceability management. The frozen score records reputation points temporarily frozen during appeals, with an initial value of 0. These points are unfrozen or deducted based on the arbitration result after the appeal concludes. The registration timestamp indicates the exact time the recruiting company's reputation account was created.
[0087] Step S22: Establish a reputation score adjustment mechanism for reputation accounts to obtain real-time reputation scores for permission allocation.
[0088] The reputation score adjustment mechanism includes a positive score addition mechanism, a violation deduction mechanism, and an appeal handling mechanism. The positive score addition mechanism adds points to the existing reputation score of the recruiting company's reputation account. When the reputation score exceeds a high reputation threshold, the recruiting company is marked as a high-quality company, and this title is visible to candidates. Simultaneously, the recruiting company gains the right to directly view candidates' highly sensitive privacy data. The recruiting company sends an application to the candidate, and the candidate can directly view the data after consent. The high reputation threshold is set based on the average reputation score of recruiting companies within the blockchain-based human resources information exchange platform, combined with security redundancy. Recruiting companies earn points for successfully hiring candidates with their authorization, or for recommending other recruiting companies to candidates. If other recruiting companies successfully hire candidates, points are awarded to both the other recruiting companies and the recommended recruiting companies. The point award standard is set based on the recruitment success rate of recruiting companies within the blockchain-based human resources information exchange platform. For recruiting companies, the positive score system, which grants them the title of "premium company" and the right to access highly sensitive privacy data, helps them more accurately match candidates with suitable candidates. Recommending other companies can also enhance their industry credibility and attract more cross-company recruitment collaboration opportunities. For society, this referral behavior allows talent to flow efficiently to matching positions, reduces the waste of human resources mismatch, promotes a healthy collaborative ecosystem among companies, lowers overall recruitment costs, and helps the human resources industry serve the job market in a more orderly manner.
[0089] The violation penalty mechanism deducts points from recruiting companies when they violate secondary propagation dormancy rules or have their access requests rejected. This is for example, due to mismatched tags or exceeding the shared lifetime value. The penalty standard is based on the security threat posed to candidates. If a recruiting company's reputation score is less than the low reputation threshold but greater than or equal to 1, the frequency of access requests initiated by the recruiting company will be limited, thus reducing the chance of obtaining key crystals. The low reputation threshold is set based on the minimum score required for recruiting companies to maintain basic collaboration. For recruiting companies whose reputation scores are between the low and high reputation thresholds (i.e., their reputation scores are greater than or equal to the low reputation threshold but less than or equal to the high reputation threshold), no permission increases or decreases will be granted. If a recruiting company's reputation score is less than 1 (i.e., 0), the recruiting company will be marked as a terminated company, its company identifier will be removed from the blockchain human resources information exchange platform, and the platform will no longer accept its submitted qualification materials. The violation penalty mechanism not only preserves a stable collaborative space for compliant companies, but also precisely constrains the violations of companies with low reputations, reducing their opportunities to obtain key crystals and lowering the risk of candidate data misuse from the source. At the same time, the removal of companies with a reputation score of 0 achieves the effect of continuously purifying the platform ecosystem, preventing malicious companies from disrupting the order of human resource data sharing in the long term, and helping the industry form a positive collaborative environment where compliance is retained and violations are removed.
[0090] The appeal handling mechanism is a request from a candidate to file a complaint against a recruiting company on the blockchain-based human resources information exchange platform. Upon receiving a candidate's appeal request, evidence collection is immediately initiated simultaneously for both the candidate and the recruiting company being appealed. Both parties can submit evidence within a preset timeframe. This preset timeframe is determined based on the daily data collaboration and response efficiency of recruiting companies within the blockchain-based human resources information exchange platform, as well as the reasonable timeframe for candidates to submit evidence. For example, it is set to 48 hours, allowing sufficient time for both parties to gather evidence while preventing the evidence from becoming less effective due to exceeding the time limit.
[0091] The blockchain-based human resources information exchange platform pre-judges the evidence provided by candidates and recruiting companies. If the candidate's evidence is found to be forged or the recruiting company's authorization intent perfectly matches the candidate's, the appeal is rejected without triggering any freeze or point deduction. If the evidence provided by the recruiting company matches the valid evidence provided by the candidate, the recruiting company is suspected of abuse, and its access to lock key crystals will be temporarily frozen to ensure the data security of other candidates during the appeal period. A third-party institution will then arbitrate, and the recruiting company and candidate will be dealt with accordingly based on the arbitration result. If the recruiting company has not abused its rights, the freeze will be lifted immediately. If the candidate has no malicious intent in their appeal, no action will be taken. If the candidate has a malicious intent, their appeal privileges will be restricted. If the recruiting company has abused its rights, its reputation score will be deducted. Through a reputation score adjustment mechanism, the recruiting company's reputation score changes, i.e., its real-time reputation score, are obtained. This real-time reputation score is linked to the company's identifier, meaning it is obtained through the reputation score adjustment mechanism.
[0092] Step S23: Assign trust levels to the real-time reputation score and configure access tokens with different permissions for each trust level.
[0093] If a recruiting company wants to obtain a candidate's private data, it needs to submit an access request to the blockchain-based human resources information exchange platform. The request includes the company identifier, company public key, data identifier, and a set of requirement tags. The requirement tag set consists of a multi-dimensional set of candidate tags. A ninth hash value is calculated from the string-formatted requirement tag set using a cryptographic hash algorithm. This ninth hash value is used as the symmetric key, which is then matched with the encrypted key. The requirement tag set is associated with the company's public key. The recruiting company can query the matching results through the blockchain-based human resources information exchange platform to obtain the corresponding key. If the symmetric key matches the encrypted key, a key can be obtained through a recovery function. When the recruiting company obtains K key crystals for the same candidate, it can use these K key crystals to obtain the candidate's highly sensitive privacy data and contact the candidate, ensuring that the data is only accessed in scenarios that align with the candidate's authorized intent and guaranteeing that the company accurately identifies the candidates it needs.
[0094] The blockchain-based human resources information exchange platform verifies the company identifiers provided by recruiting companies, such as... Figure 2 As shown; if the enterprise identifier does not match the one in the blockchain-based human resources information exchange platform, the request will be rejected directly. The blockchain-based human resources information exchange platform extracts the real-time reputation score from the corresponding recruiting company's reputation account through the enterprise identifier. Trust levels are assigned based on the recruiting company's real-time reputation score, including high-quality trust companies, medium-quality trust companies, and low-quality trust companies. If the recruiting company's real-time reputation score is greater than or equal to the high reputation threshold, it is determined to be a high-quality trust company; if the recruiting company's real-time reputation score is greater than or equal to the low reputation threshold but less than the high reputation threshold, it is determined to be a medium-quality trust company; if the recruiting company's real-time reputation score is greater than or equal to 1 but less than the low reputation threshold, it is determined to be a low-quality trust company; if the recruiting company's real-time reputation score is less than 1, the access request will be rejected.
[0095] Different access tokens are issued to recruiting companies with different trust levels. These tokens are linked to the recruiting company and stored through a blockchain-based human resources information exchange platform. The validity period and permissions of the access token vary depending on the trust level. For example, for recruiting companies with high trust, the access token allows unlimited access to the candidate's multi-dimensional tag set within 72 hours, suitable for screening more than 15 candidates, and allows viewing a maximum of 5 key crystals, satisfying the need to connect with 3-5 key candidates and reducing the risk of a single recruiting company acquiring too many key crystals. For recruiting companies with medium trust, the access token allows access to the candidate's multi-dimensional tag set 8 times within 48 hours and allows viewing a maximum of 3 key crystals, suitable for initial screening of 5-10 candidates, and focusing on following up with 3 key candidates, meeting basic screening needs and avoiding meaningless high-frequency access. For recruiting companies with low trust, the access token allows access to the candidate's multi-dimensional tag set 5 times within 24 hours and allows viewing a maximum of 1 key crystal, preventing insufficient access from completing basic screening and reducing the risk of data leakage by limiting the number of accesses. In the example, 72 hours, 48 hours, and 24 hours are the validity periods of the access token.
[0096] Step S20 addresses the technical challenges of forged recruitment company identities, untraceable company behavior, lack of dynamic constraints on data misuse, and mismatch between access permissions and company credibility in human resources information interaction through company identifiers, company public keys, reputation accounts, real-time reputation scores, trust levels, and access tokens. It also solves practical problems such as difficulty in holding companies accountable for anonymous violations, low collaboration efficiency among high-quality companies, insufficient risk control of data leakage from low-trust companies, and the inability to dynamically update company trust status. Verification of company qualification materials ensures the compliance of participating entities; the generation of company identifiers and public keys prevents identity theft and anonymous violations; reputation accounts are bound to company identifiers and public keys, using reputation scores to quantify trust levels and access record indexes to retain interaction traces, providing an on-chain foundation for behavior traceability; access tokens provide an efficient collaboration channel for high-quality companies and reduce the risk of data leakage from low-trust companies by limiting the number of key crystals and access frequency, ultimately building a secure control system for the enterprise side.
[0097] Step S30: Verify the identity of the recruiting company based on the reputation account, obtain the recruitment requirements and convert them into a digital signature for privacy protection, perform decryption verification on the digital signature to obtain a verification credential that is associated with the data identifier and access token; define the calculation range of the trust level for the verification credential and perform matching degree calculation to obtain the final encrypted result and associate it with the identity digest for traceability.
[0098] Further, step S30 includes:
[0099] Step S31: Extract the enterprise identifier from the reputation account to verify the identity of the recruiting enterprise.
[0100] In multi-company joint recruitment scenarios, it is necessary to verify the identity of the recruiting companies, such as... Figure 3 As shown, the system verifies whether the recruiting company's corporate identity matches the corporate identity in the blockchain human resources information interaction platform. If they do not match, the identity is deemed illegitimate, and access to candidate data is prohibited, thus avoiding the risk of information leakage caused by external companies accessing candidate data. If the corporate identity matches, the system further verifies whether the recruiting company's access token has expired. If the access token has expired, access to candidate data is prohibited, and the information is recorded in the access record index. If the access token has not expired, the system obtains the prerequisite for accessing candidate data.
[0101] For recruiting companies with different trust levels, differentiated calibration is implemented. The higher the trust level, the more comprehensive the verification process, reducing redundant operations for high-trust companies and strengthening basic control over low-trust companies. For low-trust companies, a three-layer verification process is used: field validity verification, scenario tag matching verification, and secondary propagation dormancy period verification. For high-quality and medium-trust companies, a two-layer verification process is used: field validity verification and scenario tag matching verification. Field validity verification compares the access list in the recruiting company's access request with a multi-company dataset. If the access list does not contain anything outside the scope of the multi-company dataset, the verification passes; otherwise, it fails. Scenario tag matching verification compares the recruiting company's submitted recruitment scenario description with the specific scenario defined by the scenario tag in the candidate's authorization intent. If the scenarios match, the verification passes; otherwise, it fails. Secondary propagation dormancy period verification involves the blockchain human resources information interaction platform retrieving the recruiting company's access record index, calculating the time difference between the current real-time timestamp and the timestamp of the most recent visit to the candidate in the access record index, and comparing this time difference with the pre-set dormancy period of the secondary propagation dormancy rules. If the time difference is less than or equal to the dormancy period, the verification passes; otherwise, it fails. Differentiated calibration enables more comprehensive verification as permissions broaden, avoiding significant risks caused by a lack of control for high-permission enterprises. Even if low-permission enterprises intend to spread the virus, the range of data they can obtain is limited, resulting in a smaller risk impact. Therefore, secondary dissemination verification is not prioritized for the time being, thus balancing security with the collaborative efficiency of joint recruitment.
[0102] Step S32: Obtain the recruitment requirements and convert them into digital signatures for privacy protection. Perform decryption verification on the digital signatures to obtain verification credentials for associated data identifiers and access tokens.
[0103] The recruitment requirements are verified to obtain verification credentials that identify the verification results, and these verification credentials are then associated.
[0104] After clarifying their recruitment needs, companies convert these needs into a string format and calculate a seventh hash value using a cryptographic hash algorithm. The seventh hash value is then asymmetrically encrypted using the company's private key to obtain a digital signature. This digital signature is the core credential proving the legitimacy of the recruitment needs. The recruitment needs and digital signature are then packaged and uploaded to a blockchain-based human resources information exchange platform.
[0105] After receiving the digital signature, the blockchain-based human resources information exchange platform verifies it by decrypting it using the company's public key. If decryption is successful, it's determined that the recruitment request was initiated by the recruiting company. The platform then recalculates the hash value of the recruitment request and compares it to the seventh hash value. If the hash values match exactly, it's determined that the recruitment request has not been tampered with during transmission, ensuring the recruitment company's request is not leaked. Once the digital signature can be decrypted and the hash value of the recruitment request has not been tampered with, the blockchain-based human resources information exchange platform sends a verification credential to the recruiting company. This verification credential signifies the recruiting company's legitimate identity, valid permissions, and compliant requirements. The verification credential also links to the company identifier, data identifier, trust level, access token, and the seventh hash value.
[0106] Simultaneously, limitations are imposed on the shareable data, usage scenarios, and secondary dissemination time among multiple enterprises, resulting in a multi-enterprise dataset. The multi-enterprise dataset includes a shared dataset and a scenario rule set. The shared dataset represents candidate data that can be shared among multiple enterprises, including a multi-dimensional set of candidate tags, which can support the core screening needs of joint recruitment by multiple enterprises and does not involve privacy information. The scenario rule set includes scenario tags representing candidate authorization intent and secondary dissemination dormancy rules, used to limit usage scenarios and the time for repeated access to candidates.
[0107] Step S33: Define the calculation range of the trust level for the verification credentials, perform a matching degree calculation, obtain the final encrypted result, and associate it with the identity digest for traceability.
[0108] The trust level of the recruiting company is extracted from the verification credentials, and the calculation scope is defined for different trust levels based on a multi-company dataset. This defined scope also corresponds to the viewing permissions for that trust level. For high-trust companies, the calculation scope includes the multi-company shared dataset and 5 key crystals; for medium-trust companies, it includes the multi-company shared dataset and 3 key crystals; and for low-trust companies, it includes the multi-company shared dataset. The data calculation and matching in this step are solely for job-person matching analysis. The calculation process is conducted in a secure multi-party computation environment to ensure that the original data remains localized and does not leave the domain. This data processing purpose does not exceed the scope of the candidate's authorized "job search and recruitment" scenario and does not involve any discriminatory algorithmic analysis based on race, gender, religion, or other characteristics.
[0109] Secure multi-party computation is used to calculate the matching degree within the calculation scope without exposing the original data, yielding the original calculation result. This original result is a percentage value representing the match between the candidate and the recruitment requirements. The original calculation result is converted into a string format and calculated using a cryptographic hash algorithm to obtain an eighth hash value, which is used for audit traceability. The blockchain-based human resources information exchange platform performs asymmetric encryption on the original calculation result using the enterprise's public key, obtaining the encrypted final result, which is then fed back to the recruiting company. The recruiting company can decrypt it using its private key. The obtained encrypted final result, the eighth hash value, and the enterprise identifier, data identifier, trust level, and access token validity period associated with the verification credential are recorded in the access record index and linked to the candidate's identity digest. This information is then stored in the blockchain-based human resources information exchange platform to ensure the integrity and authenticity of the traceability data and prevent unauthorized alteration or deletion of records.
[0110] When subsequent data interaction tracing is required, the corresponding access record index is located using the enterprise identifier or data identifier as the search criteria. A cryptographic hash algorithm is then called to recalculate the hash value of the original calculation result, which is compared with the stored eighth hash value to verify whether the matching result has been tampered with or whether the identity digest is associated with the data identifier. The matching record of the scenario tag in the candidate's authorization intent with the current recruitment scenario is checked to confirm that the data use conforms to the candidate's authorization intent. If cross-entity tracing is involved in multi-enterprise joint recruitment, the shared records in the multi-enterprise dataset can be relied upon to associate the access record indexes of each participating enterprise, clarifying the operational nodes of each enterprise. The shared records represent the candidate data sharing records between enterprises, recorded in real time by the access record index. This ensures that human resource information is verifiable, traceable, and verifiable throughout the entire process from demand initiation to result application. This reduces the difficulty of data dispute investigation and provides on-chain ironclad evidence for locating violations, strengthening the trust support role of blockchain technology in the secure storage and interaction of human resource information.
[0111] Step S30 addresses the technical challenges of identity theft, recruitment requirement tampering and leakage, uncontrolled data sharing scope, exposure of raw data in matching calculations, and lack of traceability of operational behavior in multi-enterprise joint recruitment scenarios by using enterprise identifiers, access tokens, multi-enterprise datasets, digital signatures, verification credentials, encrypted final results, identity digests, and access record indexes. It also solves practical problems such as redundant verification by high-trust enterprises affecting collaboration efficiency, insufficient management of low-trust enterprises leading to risks, lack of evidence for data dispute investigation, and difficulty in locating violations. The combined verification of enterprise identifiers and access tokens, along with multi-enterprise datasets, limits the sharing boundaries and avoids excessive exposure of private data. Differentiated verification reduces redundant operations by high-trust enterprises and improves collaboration efficiency while constraining risks from low-trust enterprises through basic verification. The encrypted final result is associated with the candidate identity digest, access record index, and eighth hash value, and can be retrieved through enterprise identifiers or data identifiers to verify the integrity of matching results, check the consistency of scenario tags, and trace multi-enterprise operation nodes, achieving full-process traceability, verifiability, and traceability from requirement initiation to result application. This process balances the collaborative efficiency and data security of multi-enterprise joint recruitment, and provides on-chain irrefutable evidence for data dispute investigation and violation location, thus strengthening the trust support role of blockchain in human resources information exchange.
[0112] Example 2
[0113] This embodiment, based on Embodiment 1, provides a cross-enterprise recruitment data hierarchical authorization sharing and traceability system, such as... Figure 4 As shown, it includes:
[0114] Candidate data processing module: used to obtain candidate identity domain, perform identity feature encoding on candidate identity domain to obtain candidate multidimensional tag set, perform multiple security encryption on candidate multidimensional tag set to obtain encryption key crystal set and block verification string, and construct data usage carrier based on encryption key crystal set and block verification string to obtain data identifier representing candidate digital identity and identity digest of storage record;
[0115] Enterprise data processing module: used to obtain enterprise qualification information, create reputation accounts with reputation scores for recruiting enterprises based on enterprise qualification information, formulate a reputation score adjustment mechanism to adjust the reputation scores, obtain real-time reputation scores for permission allocation, divide trust levels according to real-time reputation scores, and configure access tokens with different permissions for trust levels.
[0116] Data traceability module: Used to verify the identity of recruiting companies based on reputation accounts, obtain recruitment requirements and convert them into digital signatures for privacy protection, perform decryption verification on the digital signatures to obtain verification credentials that are associated with data identifiers and access tokens; define the calculation range of trust level for the verification credentials and perform matching degree calculation to obtain the encrypted final result and associate it with the identity digest for traceability.
[0117] In the candidate data processing module, the steps include: obtaining the candidate identity field; performing identity feature encoding on the candidate identity field to obtain a candidate multidimensional tag set; performing multiple security encryption on the candidate multidimensional tag set to obtain an encryption key set and an intra-block verification string; and constructing a data usage carrier based on the encryption key set and the intra-block verification string for security verification to obtain a data identifier representing the candidate's digital identity and an identity digest of the storage record, including:
[0118] Step S11: Obtain the candidate identity field, perform identity feature encoding on the candidate identity field, and obtain the candidate multidimensional label set;
[0119] Step S12: Select the key from the candidate identity field, divide the key into N key crystals, and combine them with the candidate multidimensional tag set to obtain the tag combination string. Perform multiple encryption calculations on the tag combination string to obtain the encryption key crystal set and the block verification string.
[0120] Step S13: Based on the intra-block verification string and the encryption key set, build a data usage carrier and perform security verification to obtain the candidate public key and inter-block anchor code used to detect data security.
[0121] Step S14: Associate the encryption key set with the data carrier to obtain a data identifier representing the candidate's digital identity. Combine the data identifier with the inter-block anchor code and the candidate's public key to obtain an identity digest for secure storage.
[0122] In the enterprise data processing module, the steps include: acquiring enterprise qualification information; creating a reputation account with a reputation score for the recruiting enterprise based on the enterprise qualification information; establishing a reputation score adjustment mechanism to adjust the reputation score; obtaining a real-time reputation score for permission allocation; classifying trust levels based on the real-time reputation score; and configuring access tokens with different permissions for each trust level, including:
[0123] Step S21: Obtain enterprise qualification materials, use the enterprise qualification materials to set a unique and identifiable enterprise identifier for the recruiting enterprise, and create a reputation account associated with the enterprise identifier for the recruiting enterprise;
[0124] Step S22: Establish a reputation score adjustment mechanism for reputation accounts to obtain real-time reputation scores for permission allocation;
[0125] Step S23: Assign trust levels to the real-time reputation score and configure access tokens with different permissions for each trust level.
[0126] In the data traceability module, the process of verifying the identity of recruiting companies based on reputation accounts, obtaining recruitment requirements and converting them into digital signatures for privacy protection, performing decryption verification on the digital signatures to obtain verification credentials that associate data identifiers with access tokens, defining the calculation range of trust levels for the verification credentials and performing matching degree calculations to obtain the encrypted final result and associating it with the identity digest for traceability, includes:
[0127] Step S31: Extract the enterprise identifier from the reputation account to verify the identity of the recruiting enterprise;
[0128] Step S32: Obtain recruitment requirements and convert them into digital signatures for privacy protection. Perform decryption verification on the digital signatures to obtain verification credentials for associated data identifiers and access tokens.
[0129] Step S33: Define the calculation range of the trust level for the verification credentials, perform a matching degree calculation, obtain the final encrypted result, and associate it with the identity digest for traceability.
[0130] Example 3
[0131] This embodiment discloses a computer-readable storage medium storing computer-readable instructions. When the computer-readable instructions are executed by a processor, the cross-enterprise recruitment data hierarchical authorization sharing and traceability method described in Embodiment 1 above can be executed. This achieves secure storage of candidate and human resource information, compliant access by recruiting companies, and full-link traceability of data interaction, effectively solving technical problems such as direct transmission and leakage of human resource information, forgery of company identities, data abuse, and untraceable operations. The storage medium includes, but is not limited to, volatile memory or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.
[0132] Furthermore, according to the embodiments of this application, the cross-enterprise recruitment data hierarchical authorization sharing and traceability process described in the above-mentioned flowchart can be implemented as a computer software program. For example, this application provides a non-transitory machine-readable storage medium storing machine-readable instructions, which can be executed by a processor to perform instructions corresponding to the method steps provided in this application. For example: obtaining the candidate identity domain of a candidate through a blockchain human resources information interaction platform; tagging the candidate identity domain to obtain a candidate multi-dimensional tag set; filtering highly sensitive privacy data from the candidate identity domain and converting it into a key crystal; combining the key crystal with the candidate multi-dimensional tag set to obtain a tag combination string; calculating the tag combination string to obtain an encrypted key crystal set; calculating the encrypted key crystal set to obtain an intra-block verification string; building a data usage carrier based on the intra-block verification string and the encrypted key crystal set; and performing data usage according to the data... The candidate's public key and inter-block anchor code are obtained using a carrier; the encrypted key set and the data carrier are associated with an intra-block checksum to obtain a data identifier; the data identifier is combined with the candidate's public key to obtain an identity digest; the recruitment company's qualification materials are obtained, and the company identifier and public key are calculated; a reputation account is created for the recruitment company, and a reputation score adjustment mechanism is established to obtain a real-time reputation score; trust levels are assigned to the real-time reputation score and an access token is assigned; the recruitment company is authenticated using the company identifier and access token; the recruitment requirements are obtained through asymmetric encryption to obtain a digital signature; the digital signature is verified using the company's public key to obtain a verification credential; the calculation range of the trust level is defined through the verification credential, and a matching degree calculation is performed to obtain the final encrypted result, which is associated with the identity digest for traceability. When this computer program is executed by the central processing unit (CPU), it performs the above-described functions as defined in the method of this application, namely, to achieve secure storage of candidate human resource information, compliant access control of recruitment companies, and traceable management of the entire data interaction chain, effectively solving technical problems such as direct transmission and leakage of human resource information, forgery of company identity, data abuse, and untraceable operation records.
[0133] The methods, systems, and media of this application may be implemented in many ways. For example, the methods, systems, and devices of this application may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order of steps for the method is for illustrative purposes only, and the steps of the method of this application are not limited to the order specifically described above, unless otherwise specifically stated. Furthermore, in some embodiments, this application may also be implemented as a program recorded on a recording medium, the program including machine-readable instructions for implementing the method according to this application. Thus, this application also covers recording media storing programs for performing the method according to this application.
[0134] In addition, the parts of the technical solutions provided in the embodiments of this application that are consistent with the implementation principles of the corresponding technical solutions in the prior art have not been described in detail, so as to avoid excessive elaboration.
[0135] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the invention. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for hierarchical authorization, sharing, and traceability of cross-enterprise recruitment data, characterized in that: The method includes: Obtain the candidate identity field, perform identity feature encoding on the candidate identity field to obtain a candidate multidimensional tag set, perform multiple security encryption on the candidate multidimensional tag set to obtain an encryption key crystal set and an intra-block verification string, and construct a data usage carrier based on the encryption key crystal set and the intra-block verification string to perform security verification, thereby obtaining an identity digest of the data identifier and storage record representing the candidate's digital identity. Obtain enterprise qualification information, create reputation accounts with reputation scores for recruiting enterprises based on enterprise qualification information, and formulate a reputation score adjustment mechanism to adjust the reputation scores to obtain real-time reputation scores for permission allocation. Based on the real-time reputation scores, divide trust levels and configure access tokens with different permissions for trust levels. The system verifies the identity of recruiting companies based on reputation accounts, obtains recruitment requirements and transforms them into digital signatures for privacy protection, performs decryption verification on the digital signatures to obtain verification credentials that are associated with data identifiers and access tokens, defines the calculation range of trust levels for the verification credentials and performs matching degree calculations to obtain the final encrypted result and associate it with the identity digest for traceability.
2. The method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data according to claim 1, characterized in that, The method for obtaining the candidate multidimensional label set includes: Candidate identity domains are obtained through a blockchain-based human resources information exchange platform. These domains include heterogeneous original information composed of structured data and unstructured text, as well as the candidate's authorization intent. Key information is identified from unstructured text in the candidate identity domain, and a set of key information is constructed. Data identification was performed on structured data, key information sets, and candidate authorization intent, respectively. Occupational dimension labels were identified from structured data, competency dimension labels were identified from key information sets, and authorization dimension labels were identified from candidate authorization intent. The occupational dimension label, ability dimension label, and authorization dimension label are combined to obtain a candidate multidimensional label set.
3. The method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data according to claim 2, characterized in that, The method for obtaining the encryption key set and the intra-block check string includes: Multiple highly sensitive privacy data are selected from the candidate identity domain, and then highly sensitive privacy data that can be directly linked to the candidate is selected from the multiple highly sensitive privacy data. The highly sensitive privacy data of the candidate is called the privacy barrier. The key is converted into N independent binary data crystals. Perform multiple security encryption on the tag combination string, that is, calculate the tag combination string to obtain the encryption key crystal, and calculate the encryption key crystal to obtain the block check string.
4. The method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data according to claim 3, characterized in that, Methods for obtaining an identity digest include: The data carrier contains data integrity verification, ownership proof, available operational scope, shared lifetime, and secondary propagation dormancy rules; Data integrity verification is associated with the verification string within the block, generating a candidate public key for the candidate and associating it with ownership proof, the available operation scope is associated with the candidate's authorization intent, the shared lifetime value is associated with the preset number of times, and the secondary propagation dormancy rule is associated with the preset dormancy period; The data integrity verification, ownership proof, available operation scope, shared lifetime value and secondary propagation dormancy rule are associated with the data to calculate the inter-block anchor code used to detect whether the data has been tampered with; The data identifier representing the candidate's digital identity is obtained by concatenating the intra-block verification string with the inter-block anchor code string and calculating the concatenated string. The data identifier, inter-block anchor code, and candidate public key are combined to obtain an identity digest for storing the record.
5. The method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data according to claim 4, characterized in that, The reputation accounts include: Obtain enterprise qualification materials, verify the enterprise qualification materials, and if the verification is successful, extract the binding data of the associated recruiting enterprise from the enterprise qualification materials; The bound data is converted into a string format and calculated to obtain the unique identifier of the corresponding recruiting company, i.e., the company identifier. Generate a private key for the recruiting company; Once the company's qualification materials are verified, a reputation account is created for the recruiting company. Each reputation account contains a reputation score and is also linked to the recruiting company's corporate identity and public key.
6. The method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data according to claim 5, characterized in that, Methods for obtaining real-time reputation scores include: The reputation score adjustment mechanism includes a positive score addition mechanism, a violation score deduction mechanism, and an appeal handling mechanism; The reputation account contains reputation points. In the positive point-adding mechanism, recruiting companies receive points when they successfully hire a candidate with the candidate's authorization or recommend other recruiting companies to the candidate and the candidate is successfully hired. In the violation penalty mechanism, points will be deducted from recruiting companies when they violate the secondary dissemination dormancy rules or when their access requests are rejected. In the appeal handling mechanism, when a recruiting company is found to have abused its rights, its reputation score will be deducted. If a candidate makes a malicious appeal, their appeal privileges will be restricted. The reputation score adjustment mechanism links the addition and subtraction of reputation scores to company identifiers, meaning that the real-time reputation score of recruiting companies can be viewed through the company identifier.
7. The method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data according to claim 6, characterized in that, The reputation score adjustment mechanism includes: When the reputation score in a reputation account is greater than the high reputation threshold, the recruiting company will be marked as a high-quality company and the title will be visible to candidates. At the same time, the recruiting company will be granted the right to apply to directly view the candidate's private profile. If the reputation score of the recruiting company's reputation account is less than the low reputation threshold but greater than or equal to 1, the frequency of access requests initiated by the recruiting company will be limited, thereby reducing the chance of obtaining the key crystal. If the reputation score of a recruiting company's reputation account is less than 1 (i.e., 0), the recruiting company will be marked as a company to be removed from the blockchain human resources information exchange platform, and the company's identity will be cancelled and the recruiting company will be removed. At the same time, the recruiting company's submitted qualification materials will no longer be accepted.
8. The method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data according to claim 7, characterized in that, The method for obtaining the verification credential includes: After clarifying their recruitment needs, the recruiting company converts the recruitment needs into a string format and calculates the seventh hash value. The seventh hash value is then asymmetrically encrypted to obtain a digital signature. The recruiting company then uploads the recruitment needs and the digital signature to the blockchain human resources information exchange platform. After receiving the digital signature, the blockchain-based human resources information exchange platform decrypts it using the company's public key. If the signature can be decrypted, it determines that the recruitment request was initiated by the recruiting company. The platform then recalculates the recruitment request and compares it with the seventh hash value. If the hash values are completely identical, it determines that the recruitment request has not been tampered with during transmission. Simultaneously, the blockchain-based human resources information exchange platform sends a verification credential to the recruiting company.
9. The method for hierarchical authorization sharing and traceability of cross-enterprise recruitment data according to claim 8, characterized in that, The method for obtaining the final encrypted result includes: The trust level of the recruiting company is extracted from the verification credentials, and the calculation range for different trust levels is defined by combining multi-company datasets. At the same time, the defined range is also the viewing permission range of the corresponding trust level. Perform a matching degree calculation on the calculation range without exposing the original data to obtain the original calculation result. Convert the original calculation result into a string format and calculate to obtain the eighth hash value. The original calculation result is asymmetrically encrypted using the company's public key to obtain the final encrypted result, which is then sent back to the recruiting company.
10. A cross-enterprise recruitment data hierarchical authorization sharing and traceability system, used to implement the cross-enterprise recruitment data hierarchical authorization sharing and traceability method as described in any one of claims 1-9, characterized in that, The system includes: Candidate data processing module: used to obtain candidate identity domain, perform identity feature encoding on candidate identity domain to obtain candidate multidimensional tag set, perform multiple security encryption on candidate multidimensional tag set to obtain encryption key crystal set and block verification string, and construct data usage carrier based on encryption key crystal set and block verification string to obtain data identifier representing candidate digital identity and identity digest of storage record; Enterprise data processing module: used to obtain enterprise qualification information, create reputation accounts with reputation scores for recruiting enterprises based on enterprise qualification information, formulate a reputation score adjustment mechanism to adjust the reputation scores, obtain real-time reputation scores for permission allocation, divide trust levels according to real-time reputation scores, and configure access tokens with different permissions for trust levels. Data traceability module: Used to verify the identity of recruiting companies based on reputation accounts, obtain recruitment requirements and convert them into digital signatures for privacy protection, perform decryption verification on the digital signatures to obtain verification credentials that are associated with data identifiers and access tokens; define the calculation range of trust level for the verification credentials and perform matching degree calculation to obtain the encrypted final result and associate it with the identity digest for traceability.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed, implements the cross-enterprise recruitment data hierarchical authorization sharing and traceability method as described in any one of claims 1-9.
Citation Information
Patent Citations
Cross-domain data sharing method based on block chain
CN119814409A
Data fine-grained authorization sharing method and system and electronic equipment
CN109726586A
Enterprise credit data co-processing method and system based on intelligent contract
CN114529385A