Food inspection and detection data encryption sharing method and system

By assigning static business identification codes to food inspection and testing data and combining them with real-time external parameters for dynamic encryption, dynamic location identification codes are formed for encapsulation and migration. This solves the security and reliability issues of food inspection and testing data during the sharing process, and realizes dynamic adaptive protection and efficient sharing of data.

CN121765741APending Publication Date: 2026-03-31HANGZHOU CTI TESTING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

The current food inspection and testing data sharing process suffers from static encryption strategies and fixed storage, resulting in low data security and reliability.

Method used

By assigning a unique static business identifier to food inspection and testing data, and dynamically adapting encryption strategies based on real-time external business parameters, encrypted data blocks are formed. Dynamic location identifiers are generated in a secure environment for fusion and encapsulation, enabling dynamic migration and real-time monitoring of data between distributed storage locations, thus building a defense-in-depth system.

Benefits of technology

It enables dynamic adaptive adjustment of data protection strategies, enhances the resistance to attacks and security of data, and ensures the trusted sharing of data during storage, migration and access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121765741A_ABST
    Figure CN121765741A_ABST
Patent Text Reader

Abstract

The invention provides a food inspection and detection data encryption sharing method and system, and relates to the technical field of food data security, and the method comprises the steps: obtaining food inspection and detection data, and endowing a static business identification code according to the key business attribute of the food inspection and detection data; encrypting data through a dynamic adaptation encryption strategy in combination with the currently associated real-time external service parameters to form an encrypted data block; generating a dynamic position identification code in a secure environment, and fusing and packaging the dynamic position identification code and the secure environment into a packaged secure data object; based on the security state monitored in real time, a strategy is triggered to dynamically migrate the data object between distributed storage positions, and the mapping relation between the identification code and the storage position in the encryption mapping table is synchronously updated; and when an access request is responded, firstly verifying the authentication code of the requester, positioning the data position based on the mapping relation after the authentication code passes, analyzing the data object and restoring the original detection data feedback.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of food data security technology, specifically a method and system for encrypting and sharing food inspection and testing data. Background Technology

[0002] Food safety is a matter of national importance and people's livelihood. Food inspection and testing data, as a core basis for regulation and decision-making, is of paramount importance in terms of its authenticity, completeness, and security. With the development of big data and cloud computing technologies, the need for cross-departmental and cross-regional data sharing is increasingly urgent to achieve risk warning, source tracing, and collaborative governance. However, the security management of food inspection and testing data during the sharing process currently faces severe challenges.

[0003] Existing sharing technologies have core shortcomings, making it difficult to meet the dual requirements of security and efficiency. The key issues are concentrated in: First, encryption strategies are static. Existing technologies often use uniform and fixed algorithms, which can easily lead to insufficient encryption causing data leakage or excessive encryption affecting sharing efficiency.

[0004] Second, storage and encapsulation protection are weak. Encrypted data is often simply packaged and stored without proactive protection measures. The storage location is fixed and there is no dynamic migration mechanism based on security status, making the data vulnerable to location-based attacks.

[0005] Therefore, a method and system for encrypting and sharing food inspection and testing data are provided, which can solve the problem of low data security and reliability caused by the encryption, static storage and fixed storage of food inspection data in the prior art. Summary of the Invention

[0006] To address the aforementioned technical problems, the present invention aims to provide a method and system for encrypting and sharing food inspection and testing data, which can solve the problems of low data security and reliability caused by the encryption, static storage, and fixed storage of food inspection data in the prior art.

[0007] To achieve the above objectives, the present invention provides the following technical solution: a method for encrypting and sharing food inspection and testing data, the method comprising: Acquire the food inspection and testing data to be processed, and assign a unique static business identifier code to the food inspection and testing data based on the key business attributes of the food inspection and testing data; Based on the static business identifier code and the real-time external business parameters associated with the food inspection and testing data at the current moment, the food inspection and testing data is encrypted using a dynamically adapted encryption strategy to form an encrypted data block. Based on the encrypted data block, a dynamic location identifier is dynamically generated in a secure environment, and the dynamic location identifier is fused and encapsulated with the encrypted data block to form an encapsulated secure data object. Based on the security status monitored in real time, a preset security policy is triggered to dynamically migrate the encapsulated security data object between distributed physical storage locations, and the mapping relationship between the dynamic location identifier and the current physical storage location is updated in real time in the encrypted mapping table. In response to the requester's access request, the access authentication code is verified; after successful verification, the current actual physical storage location of the encapsulated security data object is located based on the mapping relationship, the encapsulated security data object is obtained and parsed, and the food inspection and testing data is restored and fed back to the requester.

[0008] Preferably, assigning a unique static business identifier to the food inspection and testing data based on its key business attributes includes: Key business fields are extracted from the food inspection and testing data, and a structured string is generated based on predefined structured coding rules; the structured string includes the testing object, testing items, and testing institution information; Obtain the accurate timestamp of the generation of the food inspection and testing data and the version number of the current data record, encode the accurate timestamp and version number and append them to the structured string; Based on the complete structured string and the preset check code generation rules, the corresponding check code is calculated and appended to the end of the string to form a unique static business identifier code.

[0009] Preferably, the step of encrypting the food inspection and testing data based on the static business identifier code and the real-time external business parameters associated with the food inspection and testing data at the current moment, through a dynamically adapted encryption strategy, to form an encrypted data block includes: Based on the static business identification code, extract the standard testing item code and the official code of the testing institution from the static business identification code; Access the real-time external business parameters associated with the food inspection and testing data at the current moment. The real-time external business parameters include at least the national average exceedance rate of the test item within the statistical period and the regulatory risk level of the region associated with the food inspection and testing data. Based on the preset weighted quantization rules, calculate a unique dynamic encryption priority. Based on the dynamic encryption priority, a personalized encryption instruction is generated, which includes a list of fields to be encrypted, a numerical perturbation rule, and a text obfuscation algorithm identifier. Based on the personalized encryption instructions, encryption, perturbation, or obfuscation operations are performed on the selected fields respectively to form the encrypted data block. Based on the dynamic encryption priority and the corresponding key parameters, a unique policy fingerprint is calculated and generated, and stored in association with the encrypted data block.

[0010] Preferably, the step of dynamically generating a dynamic location identifier code in a secure environment based on the encrypted data block, and fusing and encapsulating the dynamic location identifier code with the encrypted data block to form an encapsulated secure data object includes: Within a trusted execution environment, a dynamic location identifier is generated. The structure of the dynamic location identifier includes a self-destruct countdown timer, an access behavior counter, a policy fingerprint, a decoy generation seed, and a migration history signature chain. Based on intelligent segmentation and interleaving insertion technology, the encrypted data block is fused with the dynamic location identifier code to form a basic encapsulation body, and an encapsulation header is added. The encapsulation header includes data type, encapsulation time and verification hash value. Within a trusted execution environment, based on the decoy seed, a preset food safety data generation model is invoked to create N decoy data clones with the same real data structure, and an independent decoy identifier is generated for each decoy data clone. The basic encapsulation body and all decoy data clones are packaged together into the final encapsulated secure data object.

[0011] Preferably, the step of fusing the encrypted data block with the dynamic location identifier code based on intelligent segmentation and interleaving technology to form a basic encapsulation body, and adding an encapsulation header, includes: Based on the aforementioned strategy fingerprint, the data sensitivity level is parsed, and the encrypted data block is adaptively divided into blocks according to the sensitivity level. The components of the dynamic location identifier are decomposed according to a preset decomposition rule to form several identifier fragments of the same length. Based on the policy fingerprint and the hash value corresponding to the current timestamp, a pseudo-random dynamic insertion sequence is generated. Based on the dynamic insertion sequence, the data blocks and identifier fragments are arranged in a multi-dimensional interleaved arrangement in a four-dimensional matrix. A wrapper header is added to the front of the interleaved data sequence to form a basic wrapper.

[0012] Preferably, the step of triggering a preset security policy based on real-time monitoring of the security status, dynamically migrating the encapsulated secure data object between distributed physical storage locations, and updating the mapping relationship between the dynamic location identifier and the current physical storage location in the encrypted mapping table in real time includes: Real-time monitoring is performed on the access behavior recorded by the dynamic location identifier code in the encapsulated security data object, the real-time changes of external business parameters associated with the encapsulated security data object, and the alarm information in the collected external threat intelligence. Based on the monitoring results, a preset risk assessment model is used to determine whether migration is triggered. If so, a corresponding migration mode is selected and executed from a predefined set of migration modes based on the trigger condition type and level. Otherwise, monitoring continues. Within the trusted execution environment, data migration is completed through an encrypted transmission channel, and the correspondence between the dynamic location identifier code and the new physical storage location in the encrypted mapping table is updated in real time. At the same time, the timestamp and location signature of this migration are added to the migration history signature chain.

[0013] Preferably, in response to the requester's access request, the access authentication code is verified; after successful verification, the current actual physical storage location of the encapsulated secure data object is located based on the mapping relationship, including: Within the trusted execution environment, the received access authentication code is decoded to extract the requester's identity token and the temporary credential for this session; the validity period and digital signature of the temporary credential are verified. If the verification fails, the process is terminated and a security event log is recorded. Conversely, from the set consisting of the real encapsulated security data object in the encapsulated security data object and the associated N decoy data clones, a dynamic access proxy object is selected as the access proxy object for this interaction based on the historical access behavior baseline. The access request is routed to the access proxy object. When the access proxy object receives the request, it generates a behavior deviation score based on the access behavior counter in the dynamic location identifier code of the access proxy object and the current operation characteristics of the requester, and randomly generates business logic questions related to the business. The system receives the requester's business answer to a business logic question and determines whether the requester has successfully completed deep authentication based on the behavior deviation score and the business answer. If so, it determines the identity of the access proxy object. If the access proxy object is a real encapsulated secure data object, it extracts the complete dynamic location identifier from the secure storage area of ​​the encapsulated secure data object and queries the encrypted mapping table. If the access proxy object is a decoy data clone, it returns the decoy data with an embedded tracking watermark and triggers a collaborative defense network alarm.

[0014] Preferably, the step of acquiring and parsing the encapsulated security data object to reconstruct the food inspection and testing data and feed it back to the requester includes: The encapsulated security data object is read based on the current actual physical location, and the corresponding dynamic location identifier code is extracted from the encapsulated security data object; Based on the policy fingerprint in the dynamic location identifier, the dynamic encryption priority and key parameters used during encryption are extracted from the associated storage area of ​​the encrypted data block in the encapsulated secure data object. Based on dynamic encryption priority and key parameters, corresponding reverse parsing instructions are generated. The reverse parsing instructions include field decryption order, numerical restoration rules and text deobfuscation rules. According to the reverse parsing instruction, the reverse operation is performed on the encrypted data block to gradually restore the original structure of the food inspection and testing data. The restored food inspection and testing data is then fed back to the requester through a secure channel, and this access behavior is recorded in the access behavior counter of the dynamic location identifier.

[0015] Preferably, the process includes the following steps before performing the inverse operation: Verify the integrity of the encapsulation header of the encapsulated secure data object, and check whether the self-destruct countdown timer in the dynamic location identifier is within its validity period; If the self-destruct countdown timer has expired, the data self-destruct protocol is triggered, the data at the actual physical location is cleared, and an error code is returned to the requester. If the self-destruct countdown timer is valid, then based on the migration history signature chain, the location signature and timestamp of each migration are checked one by one to verify whether the encapsulated secure data object has been tampered with during each dynamic migration. If so, the tampering response and repair operation are triggered; otherwise, the subsequent operation is executed.

[0016] A second aspect of the present invention also provides a food inspection and testing data encryption and sharing system, comprising: The acquisition module acquires the food inspection and testing data to be processed, and assigns a unique static business identifier code to the food inspection and testing data based on the key business attributes of the food inspection and testing data. The encryption module, based on the static business identifier code and the real-time external business parameters associated with the food inspection and testing data at the current moment, encrypts the food inspection and testing data through a dynamically adapted encryption strategy to form an encrypted data block. The encapsulation module dynamically generates a dynamic location identifier code in a secure environment based on the encrypted data block, and then merges and encapsulates the dynamic location identifier code with the encrypted data block to form an encapsulated secure data object. The migration module triggers a preset security policy based on the real-time monitored security status, dynamically migrates the encapsulated security data object between distributed physical storage locations, and updates the mapping relationship between the dynamic location identifier and the current physical storage location in the encrypted mapping table in real time. The location feedback module responds to the requester's access request by verifying the access authentication code. After successful verification, it locates the current actual physical storage location of the encapsulated security data object based on the mapping relationship, obtains and parses the encapsulated security data object, and restores the food inspection and testing data to be fed back to the requester.

[0017] Compared with the prior art, the beneficial effects of the present invention are: Traditional encryption methods often employ fixed strategies, which may fail to accurately match the actual sensitivity and risk of the data. This solution dynamically calculates encryption strength by introducing real-time external business parameters (such as the national exceedance rate and regional risk level) and triggers proactive data migration between different physical storage locations based on security status monitoring. This makes the data protection strategy no longer static and rigid, but dynamically adaptive and adjustable according to the external threat environment and the intrinsic value of the data. It transforms passive "wall-like" protection into proactive, risk-based, and precise protection, effectively responding to targeted attacks.

[0018] The solution innovatively employs intelligent segmentation and interleaving insertion techniques to deeply bind encrypted data blocks with dynamic location identifiers containing security elements such as self-destruction, counting, and migration history, making it difficult to separate and parse the data and metadata. More importantly, it introduces a decoy data cloning mechanism to generate fake data objects that are highly similar to the real data. This not only effectively confuses attackers, increasing the difficulty and cost for them to identify and steal the real data, but also provides timely alerts when attackers access the decoy, enabling early detection and tracing of attack behavior and greatly enhancing the system's overall anti-attack capability.

[0019] In the data access phase, the solution constructs a defense-in-depth system, from identity verification to behavioral analysis and business logic Q&A. It not only verifies the identity of the requester but also generates a behavioral deviation score by analyzing their operational characteristics and randomly verifies their business intent. This multi-layered, continuous verification mechanism effectively identifies and blocks unauthorized access and credential misuse. Simultaneously, by migrating historical signature chains to verify the integrity of data throughout its lifecycle, it ensures the trustworthiness of the entire process from storage and migration to access resolution, ultimately achieving authorized data sharing under strict security controls. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0021] Figure 1 This is a schematic diagram of a method for encrypting and sharing food inspection and testing data.

[0022] Figure 2 This is a schematic diagram of a food inspection and testing data encryption and sharing system. Detailed Implementation

[0023] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be described in detail below. Obviously, the described embodiments are merely some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other implementation methods obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0024] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0025] Example 1 like Figure 1 As shown in the figure, this embodiment discloses a method for encrypting and sharing food inspection and testing data, the method comprising: Acquire the food inspection and testing data to be processed, and assign a unique static business identifier code to the food inspection and testing data based on the key business attributes of the food inspection and testing data; It should be noted that assigning a unique static business identifier to the food inspection and testing data based on its key business attributes includes: Key business fields are extracted from the food inspection and testing data, and a structured string is generated based on predefined structured coding rules. This structured string includes the testing object, testing items, and testing institution information. In this embodiment, the coding of the testing object can adopt international or national standard food classification codes (such as UNSPSC, GB / T7635.1), with an additional product sub-code (such as the first four digits of the production batch number). The coding of the testing items uses the unique code for testing items in national food safety standards (such as the pesticide residue code in GB 2763), and is associated with the testing method standard number. The coding of the testing institution information uses a specific segment of the testing institution's CMA / CNAS qualification number or unified social credit code, with the additional administrative division code.

[0026] The accurate timestamp of the food inspection and testing data generation and the version number of the current data record are obtained. The accurate timestamp and version number are encoded and appended to the structured string. In this embodiment, semantic versioning (e.g., major version.minor version.revision number) is used, and the initial generation is specified as 1.0.0. Each substantial data update (e.g., change in retest results) increments the minor version number; format adjustments only increment the revision number. The encoded timestamp and version number are concatenated with the aforementioned structured string using a specific delimiter (e.g., |), and the hash value (e.g., SM3) of this concatenated string is calculated. The first 8 bits are used as the "time version fingerprint" and appended.

[0027] Based on the complete structured string and the preset check code generation rules, the corresponding check code is calculated and appended to the end of the string to form a unique static business identifier code.

[0028] Based on the static business identifier code and the real-time external business parameters associated with the food inspection and testing data at the current moment, the food inspection and testing data is encrypted using a dynamically adapted encryption strategy to form an encrypted data block. It should be noted that the encryption of the food inspection and testing data based on the static business identifier code and the real-time external business parameters associated with the food inspection and testing data at the current moment, through a dynamically adapted encryption strategy, to form an encrypted data block includes: Based on the static business identification code, extract the standard testing item code and the official code of the testing institution from the static business identification code; Access the real-time external business parameters associated with the food inspection and testing data at the current moment. The real-time external business parameters include at least the national average exceedance rate of the test item within the statistical period and the regulatory risk level of the region associated with the food inspection and testing data. Based on the preset weighted quantization rules, calculate a unique dynamic encryption priority. In detail, in this embodiment, the system actively acquires and quantifies real-time external business parameters through an "external parameter perception engine," specifically including the national average exceedance rate. Based on the "testing item code" parsed from the static business identification code, the system periodically queries the statistical database of the National Food Safety Sampling and Monitoring Information System via a secure application programming interface (API) to obtain the national average non-compliance rate for that item within the most recent statistical period (e.g., 30 days), and expresses it as a percentage. Regional regulatory risk level. Based on the administrative division code of the inspected enterprise's location linked to the data, the system queries the enterprise credit information disclosure system or local regulatory platform to obtain the comprehensive regulatory risk assessment results for that region. The system pre-sets a mapping rule to map the publicly available assessment results (such as credit ratings A, B, C, D or risk scores) to an integer coefficient from 1 to 5, where 1 represents the lowest risk and 5 represents the highest risk. (Inherent data sensitivity) When generating a static business identification code, a fixed sensitivity level is determined based on the predefined classification rules, according to the category of the "test object" (such as ordinary food, special dietary food, food additives) and the nature of the "test item" (such as routine physicochemical, microbial, heavy metals), which is usually represented by an integer from 1 to 5.

[0029] Specifically, the formula for calculating the dynamic encryption priority is as follows: ; In the formula, This represents the floor function, ensuring that the dynamic encryption priority P is an integer. The baseline exceedance rate is a preset constant used to calculate the national average exceedance rate. Normalization is performed. A perturbation value randomly generated within a small interval, produced by a cryptographically secure random number generator, is used to introduce unpredictability into the calculation process, preventing attackers from precisely inferring the encryption strategy through reverse engineering. It creatively integrates external dynamic risk indicators with intrinsic data attributes, generating a priority value that reflects the comprehensive security needs of the data in real time through quantitative weighted calculations and random perturbations. This makes encryption strength no longer a static configuration, but dynamically and adaptively adjusted according to regulatory trends and business risks, achieving intelligent coupling between security strategies and the business environment. In this embodiment, when the real-time national exceedance rate is unavailable, it automatically downgrades to using data from the previous statistical period, or uses predictive interpolation based on historical trends of similar projects. When the regional risk level is unavailable, it uses the province's average risk level or the default risk level. The acquired external parameters (such as exceedance rates) are marked with their data cutoff time, and their validity period is set. Parameters exceeding their validity period have their weights automatically decayed during calculation.

[0030] Based on the dynamic encryption priority, a personalized encryption instruction is generated, which includes a list of fields to be encrypted, a numerical perturbation rule, and a text obfuscation algorithm identifier. Specifically, when priority P is greater than or equal to threshold A, the generated instruction requires encryption of all fields in the data object. For numeric fields, a combination of encryption is used: first, an asymmetric encryption algorithm (such as the Chinese national standard SM2) is used to encrypt the key, and then a symmetric encryption algorithm (such as the Chinese national standard SM4, CBC mode, 256-bit key) is used to encrypt the data. For text fields, a format-preserving encryption algorithm is used to ensure that the data format remains unchanged after encryption, but the content is unreadable. At the same time, metadata fields are obfuscated.

[0031] When priority P is between threshold B and threshold A, the instruction specifies that only key fields (such as test results, judgment conclusions, and company names) are processed. For numerical key fields, a protection method of adding controllable perturbations is adopted, with the perturbation amplitude calculated based on a certain random proportion of the historical data standard deviation of the test item; for textual key fields, a synonym replacement obfuscation technique is used, which maps and replaces words based on a pre-set thesaurus of synonyms in the food safety field.

[0032] When priority P is lower than threshold B, the instruction only requires protection of core identification fields (such as sample number and institution code) using standard symmetric encryption algorithms (such as SM4, ECB mode, 128-bit key). This mapping logic transforms the abstract "dynamic adaptation" into clear, layered, and specific operational rules. By introducing numerical perturbations based on statistical standard deviation and semantic obfuscation based on domain knowledge base, sensitive information is effectively protected while maximizing the usability of data in specific scenarios; for example, the perturbed data can still be used for trend analysis. In this embodiment, thresholds A and B are not fixed values ​​but adaptive thresholds dynamically adjusted based on the institution's historical encryption records and recent threat intelligence. For example, when the system detects an increase in web crawler attacks targeting food testing data, it can automatically lower threshold B, allowing more data to enter a higher level of protection mode.

[0033] Based on the personalized encryption instructions, encryption, perturbation, or obfuscation operations are performed on the selected fields respectively to form the encrypted data block. Based on the dynamic encryption priority and the corresponding key parameters, a unique policy fingerprint is calculated and generated, and stored in association with the encrypted data block.

[0034] Based on the encrypted data block, a dynamic location identifier is dynamically generated in a secure environment, and the dynamic location identifier is fused and encapsulated with the encrypted data block to form an encapsulated secure data object. It should be noted that the step of dynamically generating a dynamic location identifier code in a secure environment based on the encrypted data block, and then fusing and encapsulating the dynamic location identifier code with the encrypted data block to form an encapsulated secure data object includes: Within a trusted execution environment, a dynamic location identifier is generated. The structure of the dynamic location identifier includes a self-destruct countdown timer, an access behavior counter, a policy fingerprint, a decoy generation seed, and a migration history signature chain. Based on intelligent segmentation and interleaving insertion technology, the encrypted data block is fused with the dynamic location identifier code to form a basic encapsulation body, and an encapsulation header is added. The encapsulation header includes data type, encapsulation time and verification hash value. Within a trusted execution environment, based on the decoy seed, a preset food safety data generation model is invoked to create N decoy data clones with the same real data structure, and an independent decoy identifier is generated for each decoy data clone. The basic encapsulation body and all decoy data clones are packaged together into the final encapsulated secure data object.

[0035] Specifically, the method of fusing the encrypted data block with the dynamic location identifier code based on intelligent segmentation and interleaving insertion technology to form a basic encapsulation body, and adding an encapsulation header, includes: Based on the aforementioned strategy fingerprint, the data sensitivity level is parsed, and the encrypted data block is adaptively divided into blocks according to the sensitivity level. The components of the dynamic location identifier are decomposed according to a preset decomposition rule to form several identifier fragments of the same length. Based on the policy fingerprint and the hash value corresponding to the current timestamp, a pseudo-random dynamic insertion sequence is generated. Based on the dynamic insertion sequence, the data blocks and identifier fragments are arranged in a multi-dimensional interleaved arrangement in a four-dimensional matrix. A wrapper header is added to the front of the interleaved data sequence to form a basic wrapper.

[0036] In detail, based on the specific byte values ​​of the encryption policy fingerprint, the granularity of the encrypted data block segmentation (e.g., 256 bytes or 512 bytes) is dynamically determined, dividing the encrypted data block into a series of continuous data sub-block sequences. Simultaneously, the fixed-length fields of the dynamic location identifier are divided into equal-length segments to form a sequence of identifier fragments. .

[0037] Using the concatenated value of the "policy fingerprint" and the current precise timestamp as input, a dynamic key is generated using a key-hash message authentication code algorithm (e.g., HMAC-SHA256). This dynamic key serves as the seed to drive a cryptographically secure pseudo-random number generator, producing a unique pseudo-random number of length equal to... and Randomized index sequence with sum of lengths .

[0038] Operations are performed within a logical four-dimensional space (the four dimensions representing: data sub-block content, identifier fragment content, time dimension, and sequence order dimension, respectively). This is based on the generated pseudo-random index sequence. The indicated order will be used to divide the data sub-blocks. and identifier fragments Elements are alternately filled into a linear memory buffer. For example, if the sequence indicates that the first data sub-block is placed first, followed by the second identifier fragment, then the beginning of the buffer will contain this alternating content. A wrapper header containing the data type, encapsulation time, and integrity check hash is added to the front of the interleaved buffer to form the "base wrapper". During interleaving, not only is the order random, but the offset address of each fragment in the storage buffer is also determined by the pseudo-random sequence and its content hash.

[0039] Subsequently, using the decoy seed generated from the dynamic location identifier code, a pre-trained food safety data generation model is invoked to construct N decoy data clones with real data structures but fictitious content. Finally, the basic encapsulation body and all decoy data clones are packaged together to form a complete encapsulated secure data object. This achieves deep physical layer binding and obfuscation between the data body and secure metadata. Since the segmentation granularity and interleaved sequence dynamically depend on the encryption strategy and real-time, even if an attacker obtains the stored fragments, they cannot correctly reassemble them without knowing the specific fingerprint and time. In this embodiment, the pre-set "food safety data generation model" can specifically be a model trained based on a generative adversarial network or variational autoencoder, which learns a large amount of real, anonymized detection report data distribution. The decoy data is not completely random, but is highly similar to real data in statistical characteristics (such as the numerical range and distribution pattern of detection results), but fictitious in core fields such as key judgment conclusions and company names. Each decoy clone has an independent, static business identifier code (fictitious content) that conforms to the encoding rules, making it completely consistent with the real data packet in form.

[0040] Based on the security status monitored in real time, a preset security policy is triggered to dynamically migrate the encapsulated security data object between distributed physical storage locations, and the mapping relationship between the dynamic location identifier and the current physical storage location is updated in real time in the encrypted mapping table. It should be noted that the step of triggering a preset security policy based on real-time monitoring of the security status, dynamically migrating the encapsulated secure data object between distributed physical storage locations, and updating the mapping relationship between the dynamic location identifier and the current physical storage location in the encrypted mapping table in real time includes: Real-time monitoring is performed on the access behavior recorded by the dynamic location identifier code in the encapsulated security data object, the real-time changes of external business parameters associated with the encapsulated security data object, and the alarm information in the collected external threat intelligence. Based on the monitoring results, a preset risk assessment model is used to determine whether migration is triggered. If so, a corresponding migration mode is selected and executed from a predefined set of migration modes based on the trigger condition type and level. Otherwise, monitoring continues. Within the trusted execution environment, data migration is completed through an encrypted transmission channel, and the correspondence between the dynamic location identifier code and the new physical storage location in the encrypted mapping table is updated in real time. At the same time, the timestamp and location signature of this migration are added to the migration history signature chain.

[0041] Specifically, the migration mode set includes periodic rotation migration, threat alert migration, abnormal access migration, and business risk migration. For example, periodic rotation migration, upon the expiration of a preset time period, migrates the encapsulated secure data object from its current physical storage node to the next node in the distributed storage network in a predetermined order. Threat alert migration, when a subscribed threat intelligence platform issues alerts about high-risk security vulnerabilities or attack activities related to the current data storage technology stack or region, immediately migrates the affected data objects to a secure storage area with a different technical architecture or a higher level of physical / logical isolation. Abnormal access migration, when an abnormal surge in the access frequency to a data object is detected within a short period of time, exceeding its historical baseline behavior pattern, triggers a deep authentication mechanism and simultaneously migrates the data object to a specially designated storage node, where subsequent responses are all decoy data.

[0042] In response to the requester's access request, the access authentication code is verified; after successful verification, the current actual physical storage location of the encapsulated security data object is located based on the mapping relationship, the encapsulated security data object is obtained and parsed, and the food inspection and testing data is restored and fed back to the requester.

[0043] It should be noted that, in response to the requester's access request, the access authentication code is verified; after successful verification, the current actual physical storage location of the encapsulated secure data object is located based on the mapping relationship, including: Within the trusted execution environment, the received access authentication code is decoded to extract the requester's identity token and the temporary credential for this session; the validity period and digital signature of the temporary credential are verified. If the verification fails, the process is terminated and a security event log is recorded. Conversely, from the set consisting of the real encapsulated security data object in the encapsulated security data object and the associated N decoy data clones, a dynamic access proxy object is selected as the access proxy object for this interaction based on the historical access behavior baseline. The access request is routed to the access proxy object. When the access proxy object receives the request, it generates a behavior deviation score based on the access behavior counter in the dynamic location identifier code of the access proxy object and the current operation characteristics of the requester, and randomly generates business logic questions related to the business. The system receives the requester's business answer to a business logic question and determines whether the requester has successfully completed deep authentication based on the behavior deviation score and the business answer. If so, it determines the identity of the access proxy object. If the access proxy object is a real encapsulated secure data object, it extracts the complete dynamic location identifier from the secure storage area of ​​the encapsulated secure data object and queries the encrypted mapping table. If the access proxy object is a decoy data clone, it returns the decoy data with an embedded tracking watermark and triggers a collaborative defense network alarm.

[0044] Specifically, a historical behavioral feature baseline vector B is established for each legitimate requester. Vector B includes features such as frequently accessed login geographic locations, average access frequency, and typical operation time periods. For a new access request, its real-time behavioral feature vector C is extracted. The Behavioral Deviation Score (BDS) is quantified by calculating the Mahalanobis distance between the current feature vector C and the historical baseline vector B. The generation of business logic issues should be based on the data content itself and current external risks. A secondary authentication mechanism is added: even if business issue authentication is passed, if the operation type of this access request is abnormal (such as downloading a large amount of data), the system can require the requester to undergo secondary confirmation through another independent channel (such as a mobile token).

[0045] In detail, the process of acquiring and parsing the encapsulated security data object to reconstruct the food inspection and testing data and feed it back to the requester includes: The encapsulated security data object is read based on the current actual physical location, and the corresponding dynamic location identifier code is extracted from the encapsulated security data object; Based on the policy fingerprint in the dynamic location identifier, the dynamic encryption priority and key parameters used during encryption are extracted from the associated storage area of ​​the encrypted data block in the encapsulated secure data object. Based on dynamic encryption priority and key parameters, corresponding reverse parsing instructions are generated. The reverse parsing instructions include field decryption order, numerical restoration rules and text deobfuscation rules. According to the reverse parsing instruction, the reverse operation is performed on the encrypted data block to gradually restore the original structure of the food inspection and testing data. The restored food inspection and testing data is then fed back to the requester through a secure channel, and this access behavior is recorded in the access behavior counter of the dynamic location identifier.

[0046] Specifically, the process before performing the reverse operation also includes: Verify the integrity of the encapsulation header of the encapsulated secure data object, and check whether the self-destruct countdown timer in the dynamic location identifier is within its validity period; If the self-destruct countdown timer has expired, the data self-destruct protocol is triggered, the data at the actual physical location is cleared, and an error code is returned to the requester. If the self-destruct countdown is valid, based on the migration history signature chain, the location signatures and timestamps of each migration are verified one by one to check whether the encapsulated secure data object has been tampered with during each dynamic migration. If so, a tamper response and repair operation is triggered; otherwise, subsequent operations are executed. In this embodiment, the continuity and correctness of the migration history signature chain must be strictly verified before restoring the data. If any link in the signature verification fails, it is considered that the data may have been tampered with or damaged during migration, triggering an alarm and terminating the restoration, initiating a data recovery or audit process. Each successful and legitimate access may reset or extend the self-destruct countdown of the data, depending on the nature and result of the access (e.g., the data is used for the publication of a qualified report). For high-risk abnormal access attempts, the countdown may be shortened. The data self-destruct protocol must comply with the data deletion requirements of the Data Security Law to ensure that data residues on the physical storage medium are completely removed.

[0047] This embodiment also discloses a food inspection and testing data encryption and sharing system, including: The acquisition module acquires the food inspection and testing data to be processed, and assigns a unique static business identifier code to the food inspection and testing data based on the key business attributes of the food inspection and testing data. The encryption module, based on the static business identifier code and the real-time external business parameters associated with the food inspection and testing data at the current moment, encrypts the food inspection and testing data through a dynamically adapted encryption strategy to form an encrypted data block. The encapsulation module dynamically generates a dynamic location identifier code in a secure environment based on the encrypted data block, and then merges and encapsulates the dynamic location identifier code with the encrypted data block to form an encapsulated secure data object. The migration module triggers a preset security policy based on the real-time monitored security status, dynamically migrates the encapsulated security data object between distributed physical storage locations, and updates the mapping relationship between the dynamic location identifier and the current physical storage location in the encrypted mapping table in real time. The location feedback module responds to the requester's access request by verifying the access authentication code. After successful verification, it locates the current actual physical storage location of the encapsulated security data object based on the mapping relationship, obtains and parses the encapsulated security data object, and restores the food inspection and testing data to be fed back to the requester.

[0048] Optionally, in this embodiment, those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0049] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0050] If the integrated units in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in the aforementioned computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause one or more electronic devices to execute all or part of the steps of the methods described in the various embodiments of this application.

[0051] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0052] In the several embodiments provided in this application, it should be understood that the disclosed application can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection of units or modules may be electrical or other forms.

[0053] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0054] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0055] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A method for encrypting and sharing food inspection and testing data, characterized in that, The method includes: Acquire the food inspection and testing data to be processed, and assign a unique static business identifier code to the food inspection and testing data based on the key business attributes of the food inspection and testing data; Based on the static business identifier code and the real-time external business parameters associated with the food inspection and testing data at the current moment, the food inspection and testing data is encrypted using a dynamically adapted encryption strategy to form an encrypted data block. Based on the encrypted data block, a dynamic location identifier is dynamically generated in a secure environment, and the dynamic location identifier is fused and encapsulated with the encrypted data block to form an encapsulated secure data object. Based on the security status monitored in real time, a preset security policy is triggered to dynamically migrate the encapsulated security data object between distributed physical storage locations, and the mapping relationship between the dynamic location identifier and the current physical storage location is updated in real time in the encrypted mapping table. In response to the requester's access request, the access authentication code is verified; after successful verification, the current actual physical storage location of the encapsulated security data object is located based on the mapping relationship, the encapsulated security data object is obtained and parsed, and the food inspection and testing data is restored and fed back to the requester.

2. The method for encrypting and sharing food inspection and testing data according to claim 1, characterized in that, The key business attributes of the food inspection and testing data, which are used to assign a unique static business identifier to the food inspection and testing data, include: Key business fields are extracted from the food inspection and testing data, and a structured string is generated based on predefined structured coding rules; the structured string includes the testing object, testing items, and testing institution information; Obtain the accurate timestamp of the generation of the food inspection and testing data and the version number of the current data record, encode the accurate timestamp and version number and append them to the structured string; Based on the complete structured string and the preset check code generation rules, the corresponding check code is calculated and appended to the end of the string to form a unique static business identifier code.

3. The method for encrypting and sharing food inspection and testing data according to claim 2, characterized in that, The process of encrypting the food inspection and testing data based on the static business identifier code and the real-time external business parameters associated with the food inspection and testing data at the current moment, through a dynamically adapted encryption strategy, to form an encrypted data block includes: Based on the static business identification code, extract the standard testing item code and the official code of the testing institution from the static business identification code; Access the real-time external business parameters associated with the food inspection and testing data at the current moment. The real-time external business parameters include at least the national average exceedance rate of the test item within the statistical period and the regulatory risk level of the region associated with the food inspection and testing data. Based on the preset weighted quantization rules, calculate a unique dynamic encryption priority. Based on the dynamic encryption priority, a personalized encryption instruction is generated, which includes a list of fields to be encrypted, a numerical perturbation rule, and a text obfuscation algorithm identifier. Based on the personalized encryption instructions, encryption, perturbation, or obfuscation operations are performed on the selected fields respectively to form the encrypted data block. Based on the dynamic encryption priority and the corresponding key parameters, a unique policy fingerprint is calculated and generated, and stored in association with the encrypted data block.

4. The method for encrypting and sharing food inspection and testing data according to claim 3, characterized in that, The step of dynamically generating a dynamic location identifier code in a secure environment based on the encrypted data block, and then fusing and encapsulating the dynamic location identifier code with the encrypted data block to form an encapsulated secure data object includes: Within a trusted execution environment, a dynamic location identifier is generated. The structure of the dynamic location identifier includes a self-destruct countdown timer, an access behavior counter, a policy fingerprint, a decoy generation seed, and a migration history signature chain. Based on intelligent segmentation and interleaving insertion technology, the encrypted data block is fused with the dynamic location identifier code to form a basic encapsulation body, and an encapsulation header is added. The encapsulation header includes data type, encapsulation time and verification hash value. Within a trusted execution environment, based on the decoy seed, a preset food safety data generation model is invoked to create N decoy data clones with the same real data structure, and an independent decoy identifier is generated for each decoy data clone. The basic encapsulation body and all decoy data clones are packaged together into the final encapsulated secure data object.

5. A method for encrypting and sharing food inspection and testing data according to claim 4, characterized in that, The method based on intelligent segmentation and interleaving insertion technology fuses the encrypted data block with the dynamic location identifier code to form a basic encapsulation, and adds an encapsulation header, including: Based on the aforementioned strategy fingerprint, the data sensitivity level is parsed, and the encrypted data block is adaptively divided into blocks according to the sensitivity level. The components of the dynamic location identifier are decomposed according to a preset decomposition rule to form several identifier fragments of the same length. Based on the policy fingerprint and the hash value corresponding to the current timestamp, a pseudo-random dynamic insertion sequence is generated. Based on the dynamic insertion sequence, the data blocks and identifier fragments are arranged in a multi-dimensional interleaved arrangement in a four-dimensional matrix. A wrapper header is added to the front of the interleaved data sequence to form a basic wrapper.

6. The method for encrypting and sharing food inspection and testing data according to claim 5, characterized in that, The method of triggering a preset security policy based on real-time monitoring of the security status, dynamically migrating the encapsulated secure data object between distributed physical storage locations, and updating the mapping relationship between the dynamic location identifier and the current physical storage location in the encrypted mapping table in real time includes: Real-time monitoring is performed on the access behavior recorded by the dynamic location identifier code in the encapsulated security data object, the real-time changes of external business parameters associated with the encapsulated security data object, and the alarm information in the collected external threat intelligence. Based on the monitoring results, a preset risk assessment model is used to determine whether migration is triggered. If so, a corresponding migration mode is selected and executed from a predefined set of migration modes based on the trigger condition type and level. Otherwise, monitoring continues. Within the trusted execution environment, data migration is completed through an encrypted transmission channel, and the correspondence between the dynamic location identifier code and the new physical storage location in the encrypted mapping table is updated in real time. At the same time, the timestamp and location signature of this migration are added to the migration history signature chain.

7. The method for encrypting and sharing food inspection and testing data according to claim 6, characterized in that, In response to the requester's access request, verify its access authentication code; After successful verification, locating the current actual physical storage location of the encapsulated secure data object based on the mapping relationship includes: Within the trusted execution environment, the received access authentication code is decoded to extract the requester's identity token and the temporary credential for this session; the validity period and digital signature of the temporary credential are verified. If the verification fails, the process is terminated and a security event log is recorded. Conversely, from the set consisting of the real encapsulated security data object in the encapsulated security data object and the associated N decoy data clones, a dynamic access proxy object is selected as the access proxy object for this interaction based on the historical access behavior baseline. The access request is routed to the access proxy object. When the access proxy object receives the request, it generates a behavior deviation score based on the access behavior counter in the dynamic location identifier code of the access proxy object and the current operation characteristics of the requester, and randomly generates business logic questions related to the business. The system receives the requester's business answer to a business logic question and determines whether the requester has successfully completed deep authentication based on the behavior deviation score and the business answer. If so, it determines the identity of the access proxy object. If the access proxy object is a real encapsulated secure data object, it extracts the complete dynamic location identifier from the secure storage area of ​​the encapsulated secure data object and queries the encrypted mapping table. If the access proxy object is a decoy data clone, it returns the decoy data with an embedded tracking watermark and triggers a collaborative defense network alarm.

8. The method for encrypting and sharing food inspection and testing data according to claim 7, characterized in that, The step of acquiring and parsing the encapsulated security data object to restore the food inspection and testing data and feed it back to the requester includes: The encapsulated security data object is read based on the current actual physical location, and the corresponding dynamic location identifier code is extracted from the encapsulated security data object; Based on the policy fingerprint in the dynamic location identifier, the dynamic encryption priority and key parameters used during encryption are extracted from the associated storage area of ​​the encrypted data block in the encapsulated secure data object. Based on dynamic encryption priority and key parameters, corresponding reverse parsing instructions are generated. The reverse parsing instructions include field decryption order, numerical restoration rules and text deobfuscation rules. According to the reverse parsing instruction, the reverse operation is performed on the encrypted data block to gradually restore the original structure of the food inspection and testing data. The restored food inspection and testing data is then fed back to the requester through a secure channel, and this access behavior is recorded in the access behavior counter of the dynamic location identifier.

9. A method for encrypting and sharing food inspection and testing data according to claim 8, characterized in that, Before performing the reverse operation, the following is also included: Verify the integrity of the encapsulation header of the encapsulated secure data object, and check whether the self-destruct countdown timer in the dynamic location identifier is within its validity period; If the self-destruct countdown timer has expired, the data self-destruct protocol is triggered, the data at the actual physical location is cleared, and an error code is returned to the requester. If the self-destruct countdown timer is valid, then based on the migration history signature chain, the location signature and timestamp of each migration are checked one by one to verify whether the encapsulated secure data object has been tampered with during each dynamic migration. If so, the tampering response and repair operation are triggered; otherwise, the subsequent operation is executed.

10. A food inspection and testing data encryption and sharing system, implementing the food inspection and testing data encryption and sharing method according to any one of claims 1 to 9, characterized in that, include: The acquisition module acquires the food inspection and testing data to be processed, and assigns a unique static business identifier code to the food inspection and testing data based on the key business attributes of the food inspection and testing data. The encryption module, based on the static business identifier code and the real-time external business parameters associated with the food inspection and testing data at the current moment, encrypts the food inspection and testing data through a dynamically adapted encryption strategy to form an encrypted data block. The encapsulation module dynamically generates a dynamic location identifier code in a secure environment based on the encrypted data block, and then merges and encapsulates the dynamic location identifier code with the encrypted data block to form an encapsulated secure data object. The migration module triggers a preset security policy based on the real-time monitored security status, dynamically migrates the encapsulated security data object between distributed physical storage locations, and updates the mapping relationship between the dynamic location identifier and the current physical storage location in the encrypted mapping table in real time. The location feedback module responds to the requester's access request and verifies its access authentication code; After successful verification, the current physical storage location of the encapsulated security data object is located based on the mapping relationship, the encapsulated security data object is obtained and parsed, and the food inspection and testing data is restored and fed back to the requester.