Cloud native food supply chain safety monitoring method and system
By deploying distributed monitoring nodes and blockchain technology under a cloud-native architecture, the problems of cross-organizational data silos and trusted transmission in the food supply chain have been solved, enabling transparent data recording and secure sharing, and improving the safety monitoring capabilities and emergency response efficiency of the food supply chain.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-30
- Publication Date
- 2026-04-03
AI Technical Summary
In the food supply chain, the problems of cross-organizational data silos and untrusted data transmission under cloud-native architecture are serious, making it difficult for regulatory systems to obtain a complete view of the supply chain, resulting in low efficiency in incident tracing and affecting the timeliness and effectiveness of food safety management.
By deploying multiple distributed monitoring nodes on a cloud-native service platform, key business data is collected and homomorphically encrypted to generate zero-knowledge proofs. Blockchain technology is used to achieve transparent recording and trusted sharing of data. Combined with a distributed file system and zero-knowledge proof mechanism, seamless transmission and secure sharing of data between different organizations are ensured.
It enables unified and reliable sharing and verification of data across organizations, improves the ability to perceive the safety situation and emergency response efficiency throughout the food supply chain, ensures data privacy and compliance, and enhances data linkage and information exchange capabilities.
Smart Images

Figure CN121792033A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security monitoring technology, and in particular to a cloud-native food supply chain security monitoring method and system. Background Technology
[0002] In the context of an increasingly complex and globalized food supply chain, efficient and real-time security monitoring of each link in the supply chain has become a critical issue. Traditional centralized management models are no longer adequate for the diverse stakeholders, high-frequency collaboration, and dynamic changes in the supply chain ecosystem. Therefore, building distributed and resilient supply chain monitoring systems using cloud-native architectures is gradually becoming a trend. However, in actual deployment, cloud-native systems often face structural obstacles to cross-organizational data collaboration.
[0003] The food supply chain involves multiple independent entities, including suppliers, manufacturers, logistics providers, retailers, and regulatory agencies. Due to reasons such as business segregation, privacy protection, and compliance restrictions, these organizations often keep their data closed within their own systems. This cross-organizational data isolation leads to a severe data silo problem. Because data cannot be efficiently exchanged, regulatory systems struggle to obtain a complete supply chain view, severely limiting their ability to track and monitor the entire process of food from raw material procurement to final sales. Furthermore, reduced efficiency in traceability after incidents hinders the rapid recall and determination of responsibility for problematic food products, significantly weakening the timeliness and effectiveness of food safety management.
[0004] Furthermore, the issue of reliable data transmission poses a significant challenge to cloud-native food supply chain security monitoring. Due to the lack of a unified trust mechanism among participating entities and the absence of effective authentication and verification methods during cross-system data exchange, data is susceptible to tampering, forgery, or loss during transmission. This not only undermines the regulatory authorities' trust in the data but also undermines the support for cloud-native analytics and early warning services, leading to increased uncertainty in monitoring results.
[0005] Therefore, in the current technologies, cross-organizational data silos and the problem of reliable data transmission have become key bottlenecks restricting the deep application of cloud-native architecture in the field of food supply chain safety monitoring, seriously affecting the ability to perceive the safety situation of the entire food supply chain and the efficiency of emergency response. Summary of the Invention
[0006] This invention provides a cloud-native food supply chain safety monitoring method, the main purpose of which is to solve the problems of cross-organizational data silos and reliable data transmission in the field of food supply chain safety monitoring using cloud-native architecture.
[0007] Firstly, to achieve the above objectives, the present invention provides a cloud-native food supply chain safety monitoring method, comprising: Obtain multiple distributed monitoring nodes deployed on the cloud-native service platform, and collect key business data from multiple organizations in the food supply chain of the distributed monitoring nodes; Extract the business data summary from the key business data and write the business data summary into a preset blockchain to generate a trusted on-chain record; The critical business data is stored in a distributed file system that is decoupled from the cloud-native service platform, and the stored critical business data is homomorphically encrypted to obtain ciphertext business data. Homomorphic computation is performed on the encrypted business data, and zero-knowledge proof is generated based on the obtained homomorphic computation result; The on-chain trusted record and the zero-knowledge proof are associated and stored in the preset blockchain to obtain the on-chain associated record; By utilizing the on-chain associated records, dynamic monitoring of data anomalies and tampering in the key business data is performed to obtain the monitoring results of the food supply chain.
[0008] Secondly, the present invention also provides a cloud-native food supply chain safety monitoring system, the system comprising: The data acquisition module is used to acquire key business data of multiple organizations in the food supply chain from multiple distributed monitoring nodes deployed on the cloud-native service platform. The summary-on-chain module is used to extract a business data summary of the key business data and write the business data summary into a preset blockchain to generate a trusted on-chain record. The data encryption module is used to store the key business data into a distributed file system that is decoupled from the cloud-native service platform, and to perform homomorphic encryption on the stored key business data to obtain business ciphertext data. The proof generation module is used to perform homomorphic computation on the business encrypted data and generate zero-knowledge proofs based on the obtained homomorphic computation results. The record association module is used to associate and store the on-chain trusted record and the zero-knowledge proof in the preset blockchain to obtain the on-chain associated record; The security monitoring module is used to dynamically monitor data anomalies and tampering of the key business data using the on-chain associated records, and obtain the monitoring results of the food supply chain.
[0009] This invention acquires multiple distributed monitoring nodes deployed on a cloud-native service platform, collects key business data from multiple organizations in the food supply chain from these nodes, and dynamically configures multiple containerized distributed monitoring nodes according to organizational location. Each monitoring node operates independently and is directly connected to the corresponding organization's data source, ensuring seamless data transmission and sharing between different organizations. A business data summary is extracted from the key business data and written into a preset blockchain to generate a trusted on-chain record. In the food supply chain, data from each organization is transparently and traceably recorded through blockchain technology. The key business data is stored in a distributed file system decoupled from the cloud-native service platform, and homomorphically encrypted to obtain encrypted business data. The encryption and subsequent decryption of the encrypted data protect data privacy while supporting computation and analysis, ensuring data trustworthiness and integrity. The combination of the flexibility of the cloud-native architecture and encryption protection improves overall security and data transmission efficiency. Homomorphic computation is performed on the encrypted business data, and zero-knowledge proofs are generated based on the results. Without exposing plaintext business data, encrypted computation and trusted verification of sensitive business information are achieved. Under a cloud-native architecture, different organizations can securely share encrypted data and collaborate on computations without disclosing their original data. This ensures data privacy and compliance while enhancing data linkage and end-to-end information interoperability. Simultaneously, combined with a zero-knowledge proof mechanism, the validity of computation results can be provided externally, preventing tampering and forgery. The on-chain trusted record and the zero-knowledge proof are associated and stored in the preset blockchain, resulting in an on-chain associated record. This achieves unified and trusted sharing and verification of data across organizations. The immutability and distributed consensus mechanism of the blockchain ensure data transparency and consistency among multiple parties. The on-chain associated record is used to dynamically monitor data anomalies and tampering in key business data, obtaining monitoring results for the food supply chain. By using the on-chain associated record combined with data digests from a distributed file system for dynamic comparison and zero-knowledge proof verification, dual integrity and trustworthiness guarantees are achieved in both storage and processing stages. This effectively optimizes the problem of cross-organizational data silos and trusted data transmission, improving the ability to perceive the security situation of the entire food supply chain and the efficiency of emergency response. Attached Figure Description
[0010] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 A flowchart illustrating a cloud-native food supply chain safety monitoring method according to an embodiment of the present invention; Figure 2 A schematic diagram of a cloud-native food supply chain safety monitoring system provided in an embodiment of the present invention; The objectives, features, and advantages of this invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0012] To enable those skilled in the art to better understand the technical solutions of this disclosure, and to fully understand and implement the process of how this disclosure applies technical means to solve technical problems and achieve corresponding technical effects, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, not all embodiments. The embodiments of this disclosure and the various features within them can be combined with each other without conflict, and the resulting technical solutions are all within the protection scope of this disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without creative effort should fall within the protection scope of this disclosure.
[0013] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0014] This application provides a cloud-native food supply chain safety monitoring method, which can be executed by software or hardware installed on terminal devices or server-side devices. The server-side includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be a standalone server or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0015] Reference Figure 1 The diagram shown illustrates a cloud-native food supply chain safety monitoring method according to an embodiment of the present invention. In this embodiment, the cloud-native food supply chain safety monitoring method includes: S1. Obtain multiple distributed monitoring nodes deployed on the cloud-native service platform, and collect key business data from multiple organizations in the food supply chain of the distributed monitoring nodes.
[0016] In this embodiment of the invention, the information of currently deployed monitoring nodes can be queried through the platform's management interface or API. These monitoring nodes are dynamically scheduled according to business needs and organizational location. Each node is containerized and has independent computing and storage resources. Through the container orchestration and management functions of the cloud-native platform, the status, configuration, and data acquisition task execution of each monitoring node can be obtained in real time, thereby realizing global monitoring and coordination and scheduling of data acquisition tasks in a distributed environment.
[0017] On a cloud-native platform, the geographical location of each organization in the food supply chain is obtained. Based on the geographical location, containerized distributed monitoring nodes are dynamically deployed on the cloud platform. For each monitoring node, a corresponding collection strategy is generated based on the specific data collection frequency and data filtering rules. By establishing a connection with the data source of the corresponding organization, data is collected using the collection strategy, and key business data of each monitoring node is extracted for subsequent processing and analysis.
[0018] Specifically, the collection of key business data from multiple organizations in the food supply chain by the distributed monitoring nodes includes: Obtain the organizational location of each organization in the food supply chain, and dynamically deploy multiple containerized distributed monitoring nodes according to the organizational location using a cloud-native service platform; Obtain the data collection frequency and data filtering rules for each of the distributed monitoring nodes, and generate a collection strategy based on the data collection frequency and the data filtering rules; The distributed monitoring nodes are connected to the data sources of the corresponding organizations, and the data collection strategy is used to collect data from the data sources to obtain the initial business data of the corresponding organizations in each of the distributed monitoring nodes. Obtain the microservice dependency graph of the cloud-native service platform, analyze the data impact of the initial business data using the microservice dependency graph, and generate data impact weights based on the analysis results. The initial business data is filtered for key business data using the data influence weights.
[0019] In detail, the system acquires the geographic location information of each organization in the food supply chain. Using this location information as a foundation, a cloud-native service platform dynamically schedules and deploys multiple containerized distributed monitoring nodes based on each organization's actual location. Through the elastic scalability of the cloud-native platform, it ensures that each monitoring node can efficiently match the organization's location, ensuring even geographical distribution of monitoring nodes, thereby achieving full coverage and efficient data collection and monitoring.
[0020] The system obtains data collection frequency and filtering rules from each distributed monitoring node; this information is typically determined by the needs or business scenarios of each organization. Based on the collection frequency setting, the data collection time interval and batch size are determined. According to the filtering rules, irrelevant or low-quality data in the data source is removed to ensure that the collected data is high-quality and relevant. Based on the data collection frequency and filtering rules, a customized collection strategy is generated for each monitoring node to ensure that data collection is executed efficiently and accurately, meeting the organization's requirements for data quality and timeliness.
[0021] Each distributed monitoring node is connected to the corresponding organization's data source via network protocols, ensuring that the monitoring nodes can access and obtain relevant information from the data source. Based on the previously generated collection strategy, corresponding data collection parameters are configured for each node, including collection frequency and filtering rules, to ensure efficient and accurate data collection. The monitoring nodes begin collecting data from the data source according to the predetermined strategy, acquiring business data in real time, and storing the collected raw data locally on the node or in the cloud platform, generating the initial business data for each distributed monitoring node.
[0022] In cloud-native service platforms, based on service registry centers and service call logs, the runtime information of each microservice instance and the call relationships between services are obtained, constructing a microservice dependency graph containing nodes (microservices) and directed edges (call relationships). The flow path of initial business data in the microservice dependency graph is identified, and indicators such as the number of service nodes traversed, the depth of the transmission hierarchy, the number of downstream dependent nodes, and the distribution of key nodes are analyzed to quantify the breadth and control influence of initial business data in the business process. Based on the above analysis results, combined with the service weight, call frequency, and abnormal propagation risk on each path, the overall impact of the initial business data is calculated, and corresponding data impact weights are generated to guide the selection of subsequent key business data.
[0023] Based on the data impact weights generated from the aforementioned analysis, the initial business data is weighted, sorted, and screened hierarchically. Data with long propagation paths in the microservice dependency graph, high downstream dependencies, coverage of many key nodes, and high risk sensitivity are prioritized for retention, identifying data items with a core impact on food supply chain safety. According to the set weight thresholds, business data exceeding the impact threshold is selected and marked as critical business data for subsequent reliable recording, risk warning, and dynamic monitoring processes.
[0024] By deploying multiple containerized distributed monitoring nodes and dynamically configuring them according to organizational location, each monitoring node operates independently and connects directly to the corresponding organization's data source, ensuring seamless data transmission and sharing between different organizations and avoiding data silos. Leveraging a cloud-native service platform and employing efficient data collection strategies and filtering rules, the reliability of data during collection is ensured, breaking down information barriers between different organizations and laying the foundation for real-time, accurate supply chain security situational awareness.
[0025] S2. Extract the business data summary of the key business data and write the business data summary into a preset blockchain to generate a trusted on-chain record.
[0026] In this embodiment of the invention, the extracted key business data undergoes format parsing, field standardization, and anonymization. The anonymized data is then hash-encrypted to generate a digest code for each data entry. Meta-information of the anonymized data is obtained and combined with the digest code to generate a business data digest. To ensure data trustworthiness, the generated business data digest is encapsulated using a cloud-native service platform and a pre-defined blockchain notarization field template to construct an on-chain notarization structure and generate a notarization request. The notarization request is sent to the blockchain's transaction pool for consensus verification. Once the verification result confirms that the notarization transaction has reached a consensus, the notarization transaction is written to the blockchain, generating the final notarization result. Combining the notarization result with the digest code forms an immutable, trustworthy on-chain record.
[0027] Specifically, the business data summary for extracting the key business data includes: Extract the basic structural information of the key business data; The key business data is semantically mapped and classified to obtain key business semantics; Identify the upstream and downstream related fields of the key business data based on the microservice dependency graph; Generate parsed business data based on the basic structural information, the key business semantics, and the upstream and downstream related fields; Obtain a cross-organizational field mapping table and semantic alignment rules, and use the cross-organizational field mapping table and semantic alignment rules to standardize the parsed business data to obtain standard business data; The sensitive fields of the standard business data are subjected to multi-level desensitization to obtain desensitized business data; The de-identified business data is hashed and encrypted to generate a digest code for each piece of de-identified business data; Obtain the metadata of the de-identified business data, and generate a business data digest based on the digest code and the metadata.
[0028] In detail, by parsing key business data, identifying and extracting core fields, data types, and hierarchical relationships from the data, a structured description of the data is formed. This includes steps such as field segmentation, data format identification, and confirmation of relationships between fields, with the aim of building a clear business data structure framework.
[0029] The structured business data fields are matched with predefined business semantic models. Natural language processing, rule engines, or machine learning methods are used to identify the business meaning and category attributes of the fields. The data is then labeled and classified for management, ultimately forming key business semantics that reflect business logic and semantic relationships.
[0030] Based on the microservice dependency graph, the data flow and call relationships between microservices are analyzed, the upstream and downstream related fields of key business data in different services are identified, the data transmission path and dependency relationship are clarified, and the related fields are integrated and associated with the extracted basic structural information and key business semantics to form complete and semantically clear parsed business data, so as to achieve accurate parsing of business data and comprehensive expression of upstream and downstream logic.
[0031] Cross-organizational field mapping table: Records the correspondence between identical or equivalent business fields in different organizations or systems, helping to achieve unified conversion of field names and formats. Semantic alignment rules: Used to standardize and unify the way different organizations express the same business concept, ensuring consistency and accurate interpretation of field meanings. Using the cross-organizational field mapping table and semantic alignment rules, fields in parsed business data are matched and transformed, unifying and standardizing the original field names, formats, and semantic differences between organizations, eliminating ambiguity and inconsistencies, and ultimately generating standardized business data with a unified structure and clear semantics, providing a standardized foundation for cross-organizational data exchange and integration.
[0032] Identify and label sensitive fields in standard business data, such as personally identifiable information, financial data, or other content that may leak privacy. Based on the type and risk level of sensitive fields, design tiered de-identification strategies, such as encryption, masking, and de-labeling. Combine these with business scenarios and access controls, flexibly apply different de-identification methods to process sensitive information. Common de-identification methods include data replacement, character encryption, or generating anonymous values through algorithms to ensure that sensitive information cannot be recovered or identified. Ensure data availability while effectively preventing the leakage of sensitive information, ultimately generating de-identified business data that meets security and compliance requirements and supports business use.
[0033] The anonymized business data is input into a hash algorithm to generate a fixed-length digest code. The hash algorithm performs mathematical transformations on the data to ensure that each piece of data generates a unique and irreversible digest code. Even if the original data changes, the digest code will not change, thus effectively verifying the integrity of the data.
[0034] Obtain the metadata of the anonymized business data, including key information such as data source, timestamp, and data type. Combine the digest code of each piece of anonymized business data with this metadata to generate a complete business data digest. By binding the digest code with the metadata, ensure that each piece of data not only has a unique identifier but also provides sufficient contextual information for accurate matching and traceability in subsequent evidence preservation or verification processes.
[0035] Specifically, writing the business data summary into a preset blockchain to generate a trusted on-chain record includes: Obtain the preset blockchain evidence storage field template through the cloud-native service platform; The business data digest is encapsulated according to the evidence storage field template to obtain an on-chain evidence storage structure. Generate an evidence storage request based on the on-chain evidence storage structure; The evidence storage request is sent to the transaction pool of a preset blockchain to generate an evidence storage transaction; The notarized transaction is subjected to consensus verification to obtain the verification result; When the verification result indicates that the evidence storage transaction has reached a consensus, the evidence storage transaction is written into a preset blockchain to generate an evidence storage result. A trusted on-chain record is generated based on the evidence storage result and the digest code.
[0036] In detail, the system connects to a pre-defined blockchain network through a cloud-native service platform and queries the blockchain network for supported notarization field templates. Notarization field templates define the field structure and format required for storing data on the blockchain, typically including necessary information such as data digest, timestamp, data source, and transaction ID. The appropriate template is selected based on business needs to ensure that business data meets the blockchain's notarization requirements and to provide a standardized data structure for subsequent encapsulation and notarization operations.
[0037] Based on the evidence storage field template, the business data summary and related metadata (such as timestamps, data sources, digest codes, etc.) are encapsulated according to a predefined field structure to generate an on-chain evidence storage structure. This on-chain evidence storage structure contains all necessary fields, ensuring data integrity and verifiability during the on-chain process. The encapsulated evidence storage structure not only conforms to the blockchain's evidence storage format requirements but also ensures that data is permanently stored on the blockchain and is traceable.
[0038] The on-chain evidence storage structure is packaged into an evidence storage request. This request includes a packaged summary of business data and relevant metadata, serving as a valid request for a blockchain transaction. The request specifies the required evidence storage fields, storage format, and relevant parameters of the target blockchain network. The evidence storage request is then sent to the blockchain transaction pool via a cloud-native service platform, awaiting further consensus verification and processing. This evidence storage request provides the foundation for the permanent recording and subsequent verification of data, ensuring that data is accurately written to the blockchain in the predetermined manner.
[0039] When a notarization request is sent to the pre-defined blockchain's transaction pool, the encapsulated request is transmitted to the blockchain network's transaction pool, awaiting processing by verification nodes. The transaction pool is where transactions awaiting processing are stored within the blockchain network; all requests sent to this pool must undergo verification through the consensus mechanism. During this process, the notarization request is treated as a transaction, containing a data summary, metadata, and necessary blockchain notarization fields. After the request enters the transaction pool, it awaits confirmation by the blockchain network and is packaged into a new block, ultimately generating a notarization transaction.
[0040] After a notarized transaction enters the blockchain network, it is verified through a consensus mechanism to ensure its legality, integrity, and consistency. During the consensus verification process, nodes in the blockchain network review the notarized transaction to verify its compliance with the rules and reach a consensus. When the verification result shows that the notarized transaction has reached a consensus, the system packages the notarized transaction into a new block and formally writes it into the pre-defined blockchain. This notarized transaction is permanently recorded on the blockchain, generating a notarized result and ensuring the immutability and traceability of data on the blockchain.
[0041] Based on the evidence storage result and digest code, the final state of the evidence storage transaction is associated with the generated digest code to form a trusted on-chain record. This record contains detailed information about the evidence storage transaction, the verification result, and a unique digest code corresponding to the business data. By binding the evidence storage result with the digest code, the unique identifier of each piece of data on the blockchain is ensured, and the source and processing of the original data can be accurately traced. This trusted on-chain record possesses immutability and high security, providing strong protection for the legality and integrity of the data.
[0042] By extracting key business data and processing it through format parsing, standardization, anonymization, and hash encryption to generate business data summaries, and then storing these summaries on the blockchain to create trusted on-chain records, the problems of cross-organizational data silos and trusted data transmission can be effectively solved. In the food supply chain, data from various organizations is transparently and traceably recorded through blockchain technology, breaking down traditional isolated data storage and enabling parties to share data without trusted intermediaries. Simultaneously, the anonymized and encrypted data ensures privacy and security, enhances data credibility, and provides strong support for supply chain security monitoring.
[0043] S3. Store the key business data in a distributed file system that is decoupled from the cloud-native service platform, and perform homomorphic encryption on the stored key business data to obtain encrypted business data.
[0044] In this embodiment of the invention, business requirements are generated based on key business data, and the necessary encryption parameters and public-private key pairs are generated accordingly. An encryption context is created using these encryption parameters to perform structured processing, data transformation, and data encoding on the key business data, generating business numerical encoded data. The business numerical encoded data is encrypted item by item using the public key and the encryption context in the public-private key pair to obtain ciphertext units. These ciphertext units are combined with business identification information to generate complete business ciphertext data, ensuring data security during storage and transmission, while also supporting subsequent encryption operations and calculations.
[0045] Specifically, the process of homomorphically encrypting the stored key business data to obtain ciphertext business data includes: Based on the key business data, business requirements are generated, and based on the business requirements, encryption parameters and public / private key pairs are generated; Generate an encryption context based on the encryption parameters; The key business data is dynamically structured to obtain structured business data; Convert the structured business data into business numerical data; The business numerical data is encoded to obtain business numerical encoded data; Extract the public key of the public-private key pair, and use the public key and the encryption context to encrypt the business numerical encoded data item by item to obtain ciphertext units; Generate corresponding service identification information based on the encrypted unit; Business encrypted data is generated based on the encrypted unit and the business identification information.
[0046] In detail, key business data is analyzed to extract corresponding business requirements. These requirements typically include specific requirements for data privacy protection, the choice of encryption strength, and possible subsequent operations (such as data computation or querying). Based on these business requirements, corresponding encryption parameters are generated, such as encryption algorithm type and key length, along with a public-private key pair. The public-private key pair is used to ensure the security and reliability of the data encryption and decryption process, with the public key used for encryption and the private key used for decryption. Throughout this process, it is ensured that the key pair generation meets the security level and operational requirements of the business needs, thus providing a foundation for subsequent homomorphic encryption.
[0047] An encryption context is a data structure containing parameters such as encryption algorithms, key management information, and encryption modes, designed to ensure the consistency and security of encryption operations. This context is constructed using encryption parameters (such as encryption algorithm type, key length, and encryption mode) to ensure that each step in the encryption process meets predetermined security requirements. The encryption context not only provides the necessary environment configuration for encryption but also guarantees consistent data security across different operations and computations.
[0048] Identify and organize the fields and elements in key business data, transforming them into a structured form with clear hierarchy and relationships. This includes classifying and grouping the data, and establishing a unified format and data structure, such as tables, tree structures, or relational data models, based on business needs and data types. Structured data not only facilitates storage and retrieval but also makes subsequent analysis, calculations, and encryption operations more efficient and consistent.
[0049] By performing appropriate numerical processing on each field of structured business data, non-numerical data (such as text, date, category information, etc.) can be transformed into quantifiable numerical forms. This includes: encoding text fields (such as converting category information into numerical codes), numericalizing date and time fields (such as converting them into timestamps), and standardizing or normalizing other complex data structures.
[0050] The original business numerical data is transformed into an encoding format suitable for encryption or transmission, mapping the numerical data to a specific encoding space. Common encoding methods include fixed-length binary encoding, Huffman coding, or other encoding methods required by compression and encryption algorithms. The encoded business numerical data not only retains the numerical information but also provides the necessary structure for subsequent encryption operations, making data storage and transmission more efficient and secure.
[0051] Each business numerical encoded data unit is taken as input, and combined with the public key and encryption context, each data unit is encrypted using a specified encryption algorithm (such as RSA, AES, etc.) to generate a corresponding ciphertext unit. Each ciphertext unit contains the encrypted data content, ensuring that the data is protected during transmission or storage, and only authorized parties with the corresponding private key can decrypt it.
[0052] By extracting key information from the encrypted units, such as the source, encryption time, and data type of the encrypted data, and combining it with preset rules or standards, a unique identifier is generated. Business identification information can include relevant metadata about the data, such as the business domain to which the data belongs, the operation type, and the encryption status, for subsequent storage, retrieval, and management. This identification information not only helps track and manage encrypted data but also ensures that relevant data can be quickly and accurately identified and decrypted when needed.
[0053] Each encrypted unit is combined with its corresponding business identification information to form a complete encrypted data packet. This data packet not only contains the encrypted business value, but also includes relevant metadata that can uniquely identify the data, such as data source, encryption time, and data type.
[0054] Homomorphic encryption ensures that critical business data remains private and sensitive information is not leaked during transmission between organizations, resolving data isolation issues between different organizations. Encryption and subsequent decryption of encrypted data support computation and analysis while protecting data privacy, ensuring data trustworthiness and integrity. This encryption mechanism provides transparent and verifiable data exchange for every link in the food supply chain, enhancing awareness of the entire supply chain's security posture and accelerating emergency response. The combination of cloud-native architecture flexibility and encryption protection improves overall security and data transmission efficiency.
[0055] S4. Perform homomorphic computation on the encrypted business data, and generate zero-knowledge proof based on the obtained homomorphic computation result.
[0056] In this embodiment of the invention, the corresponding business logic is extracted from the ciphertext data, and the target computational requirements are identified. These logical targets are then converted into computable Boolean expressions. A corresponding homomorphic computation function is constructed based on the logical targets, and the Boolean expressions are computed in the ciphertext state to generate an encrypted computation result ciphertext. To ensure the security and compatibility of the result, the ciphertext result is further re-encrypted and modulus-switched to ultimately obtain a homomorphic computation result that can be used for verification and subsequent processing.
[0057] The homomorphic computation result is used as the proof target and as the private input, while business parameters extracted from the original encrypted business data are used as the public input. Together, they constitute the proof input. The logical structure of the homomorphic computation function is obtained, converted into circuit form, and a corresponding constraint circuit model is established. Based on the constraint circuit model and the proof input, a zero-knowledge proof to be verified is generated. The validity of the zero-knowledge proof is verified; if the verification is valid, the zero-knowledge proof to be verified is confirmed as a zero-knowledge proof.
[0058] Specifically, the homomorphic computation on the encrypted business data includes: Extract the business logic from the encrypted business data; Obtain the logical target of the business logic and convert the logical target into a Boolean expression; Generate a homomorphic computation function based on the business logic; The homomorphic computation function is used to perform ciphertext operations on the Boolean expression to obtain the encrypted computation result ciphertext; The encrypted computation result is re-encrypted and the modulus is switched to obtain a homomorphic computation result.
[0059] In detail, the encrypted business data is structured and parsed to identify the embedded encrypted business fields and associated logical tags, and to analyze the logical relationships between the encrypted fields, such as dependencies, comparisons, and operations. By combining the business context information and the metadata of the encrypted data, the corresponding business processing flow is reconstructed, and the business logic expression form that can be used for encrypted operations is extracted.
[0060] Key business judgment conditions and decision rules are identified from the extracted business logic, and corresponding logical objectives are determined, such as comparison of size, judgment of equality, and state matching. Combining the logical template of the business scenario, these logical objectives are mapped into standardized Boolean logic structures, and the logical variables involved are abstracted. Logical operators such as AND, OR, and NOT are used to transform the logical objectives into formal Boolean expressions, providing an operable expression basis for subsequent homomorphic computation in the ciphertext domain.
[0061] The analysis transforms the logical target into a Boolean expression, extracts the logical structure and operation types (such as addition, multiplication, comparison, etc.) involved, combines the basic operation types supported by homomorphic encryption, selects a homomorphic operation strategy that matches the logical structure of the Boolean expression, and encapsulates it into a computation function that can be executed in the ciphertext domain. The computation function is structurally adjusted and semantically adapted according to the encryption context and encryption parameters to ensure that the target logic is operated without decrypting the data, forming a homomorphic computation function suitable for ciphertext data processing, supporting the calculation of the logical target while keeping the data encrypted.
[0062] The business values involved in the Boolean expression are input into the homomorphic computation function in ciphertext form. Without decrypting the ciphertext, the function performs step-by-step calculations on the ciphertext variables according to Boolean logic relationships, relying on arithmetic operations such as addition and multiplication supported by the homomorphic encryption algorithm. This maintains the consistency between the ciphertext structure and the computation logic, ensuring that the calculation process is correctly executed within the encrypted domain, and outputs a complete ciphertext of the calculation result, which is the encrypted representation of the logical operation result of the corresponding Boolean expression in the encrypted state.
[0063] To prevent the accumulation of ciphertext noise during the calculation process from causing decryption failure, a re-encryption operation is performed on the ciphertext of the calculation result. That is, the ciphertext is re-encrypted using the initial encryption parameters to refresh the noise level and maintain the encryption strength. According to the requirements of the homomorphic encryption algorithm for the complexity of multi-round operations, a modulus switching operation is performed, that is, the ciphertext is mapped from the current modulus space to a smaller modulus space to reduce the complexity of subsequent calculations and improve the running efficiency. Finally, a homomorphic calculation result with a stable structure that can continue to participate in homomorphic operations is obtained.
[0064] In detail, the generation of zero-knowledge proofs based on the obtained homomorphic computation results includes: The homomorphic computation result is used as the proof target, and the proof target is used as the private input; Obtain the business parameters of the encrypted business data and use the business parameters as common input; Construct a proof input using the private input and the public input; Obtain the function logic of the homomorphic computation function, convert the function logic into a circuit form, and construct a constraint circuit model based on the circuit form; Generate a zero-knowledge proof to be verified based on the proof input and the constraint circuit model; The validity of the zero-knowledge proof to be verified is then verified, and the verification result is obtained. When the verification result indicates that the zero-knowledge proof to be verified is invalid, the proof input and the constraint circuit model are detected and corrected, and the zero-knowledge proof is generated using the corrected proof input and constraint circuit model. When the verification result indicates that the zero-knowledge proof to be verified is valid, the valid zero-knowledge proof to be verified is taken as the zero-knowledge proof.
[0065] In detail, the homomorphic computation result after the ciphertext computation has been completed is obtained from the homomorphic computation process, and the computation result is set as the core proof target in the zero-knowledge proof. The proof target is used as private input, that is, privacy data that is not disclosed to the verifier but used by the verifier in the generation process. The private input will participate in the proof construction of circuit constraints together with the public input in the later stage, so as to ensure that the correctness and credibility of the computation are verified without disclosing the specific homomorphic computation content, thereby achieving the goal of balancing data privacy protection and computation verifiability.
[0066] Business parameter information related to homomorphic computation is extracted from the encrypted business data, such as thresholds for logical judgments, data identifiers or tags involved in the computation, etc. These business parameters are then formatted to meet the requirements of subsequent proof construction. The processed business parameters are used as public inputs, which are then disclosed to the verifier. In zero-knowledge proofs, these data participate in the execution of constraint circuits together with private inputs. This ensures that the verifier can verify the correctness and consistency of the computation results based on the disclosed business parameters without accessing the original encrypted data, thereby improving the ability to transmit trusted data across organizations.
[0067] Homomorphic computation results are used as private inputs, and business parameters extracted from business encrypted data are used as public inputs. The two are uniformly encapsulated according to the input structure specification to generate proof inputs for zero-knowledge proof construction. During the encapsulation process, it is necessary to ensure that the input format is consistent with the interface of the constraint circuit model, and the private inputs are encoded or mapped as necessary to ensure that they can participate in circuit constraint calculations without revealing the original content, thereby laying the data foundation for the subsequent generation of zero-knowledge proofs that meet the verification conditions.
[0068] This paper analyzes the logical structure of homomorphic computation functions, extracts the operational steps, conditional judgments, and logical relationships, and then transforms the functional logic into an equivalent circuit form. Typically, the operation nodes and connections are represented in the form of Boolean circuits or arithmetic circuits. Based on the circuit form, a corresponding constraint circuit model is constructed, and the input-output constraints and logical rules of each circuit node are defined to ensure that the circuit model can accurately express the operational logic of the homomorphic computation function. This provides a rigorous mathematical foundation and verification framework for the generation of zero-knowledge proofs.
[0069] Based on the proof input and constraint circuit model, private and public inputs are substituted into the constraint circuit, and a series of calculations are performed to satisfy all logical and arithmetic constraints defined in the circuit. A zero-knowledge proof algorithm (such as zk-SNARK or zk-STARK) is used to generate a zero-knowledge proof to be verified. This proves to the verifier that the input does indeed satisfy all constraints of the circuit model without revealing the private input content, ensuring the correctness and credibility of the calculation process and providing strong security for subsequent verification.
[0070] When validating the zero-knowledge proof to be verified, a common input and constraint circuit model are used as the verification basis. A zero-knowledge proof verification algorithm is employed to rigorously verify the proof, checking whether it satisfies all circuit constraints and contains no contradictions or forged information. The verification process does not require access to private inputs, ensuring privacy and security. Simultaneously, mathematical verification confirms the authenticity and completeness of the calculation results. Based on the execution result of the verification algorithm, the validity status of the proof is output, determining whether the zero-knowledge proof to be verified is valid or invalid, providing a basis for subsequent decision-making and trust establishment.
[0071] When the verification result of the zero-knowledge proof to be verified is invalid, a detailed inspection is performed on the proof input and constraint circuit model to locate possible problems such as input format errors, logical mismatches, or constraint deviations. Based on the inspection results, the input data or circuit model is corrected and optimized accordingly. The zero-knowledge proof generation algorithm is then re-executed using the corrected proof input and the updated and improved constraint circuit model to ensure that the newly generated proof can meet all constraints, thereby improving the correctness and credibility of the proof.
[0072] When the verification result confirms that the zero-knowledge proof to be verified is valid, the system officially recognizes the legality and integrity of the zero-knowledge proof to be verified, marks it and stores it as the final zero-knowledge proof, which becomes a trusted security credential. It can prove the correctness and compliance of the homomorphic computation result to relevant parties without disclosing any private information, and provides a solid trust foundation for data interaction and business collaboration.
[0073] The processing of homomorphic computation and zero-knowledge proofs enables encrypted computation and trusted verification of sensitive business information without exposing plaintext business data, effectively alleviating the challenges of cross-organizational data silos and trusted data transmission. Under a cloud-native architecture, different organizations can securely share encrypted data and collaborate on computations without disclosing their original data, ensuring data privacy and compliance while enhancing data linkage and end-to-end information interoperability. Simultaneously, combined with zero-knowledge proof mechanisms, it can provide external proof of the validity of computation results, preventing tampering and forgery, improving data verifiability and response credibility throughout the food supply chain safety monitoring process, and significantly enhancing the ability to perceive supply chain security situations and improve emergency decision-making efficiency.
[0074] S5. The on-chain trusted record and the zero-knowledge proof are associated and stored in the preset blockchain to obtain the on-chain associated record.
[0075] In this embodiment of the invention, a trusted on-chain record is bound to a zero-knowledge proof to form an associated structure containing information from both. This associated structure serves as the payload of a transaction. According to a preset blockchain encapsulation format and rules, the transaction payload is standardized and encapsulated to generate an associated transaction that meets on-chain requirements. This transaction is then broadcast to the blockchain network. On-chain plugins perform multi-node consensus verification of the transaction to ensure its legality and integrity. After successful verification, the associated transaction is written to the blockchain, ultimately generating a permanent and immutable on-chain associated record.
[0076] Specifically, the step of associating and storing the on-chain trusted record and the zero-knowledge proof in the preset blockchain to obtain the on-chain associated record includes: The trusted on-chain record and the zero-knowledge proof are bound together to obtain an associated structure; The associated structure is used as the transaction payload; Obtain the preset blockchain encapsulation format and encapsulation rules, and encapsulate the transaction payload according to the encapsulation format and encapsulation rules to obtain on-chain related transactions; The on-chain related transactions are broadcast to a preset blockchain, and the validity of each consensus node of the on-chain related transactions is verified by the on-chain plugin of the preset blockchain. When all consensus nodes of the on-chain associated transactions are valid, the on-chain associated transactions are written into a preset blockchain to generate on-chain associated records.
[0077] In detail, when binding on-chain trusted records and zero-knowledge proofs, the key information of the two is linked and integrated to form a unified data structure—the association structure, which includes the unique identifier, data digest and evidence storage information of the on-chain trusted record, while embedding the corresponding zero-knowledge proof to ensure that the proof and the record are closely bound and inseparable.
[0078] When using a relational structure as a transaction payload, the relational structure is encapsulated as a core data component of the blockchain transaction, ensuring that the format conforms to the blockchain network's specifications for transaction payloads. The payload contains complete on-chain trusted records and zero-knowledge proof information, guaranteeing data integrity and consistency during transaction transmission and storage. The payload is submitted to the blockchain network along with the transaction, serving as the foundation for subsequent consensus verification and on-chain storage, supporting secure tracking and verification of the relational data.
[0079] The system obtains the pre-defined blockchain encapsulation format and rules, defines the transaction structure, field order, data encoding method, and security verification requirements, and performs standardized encapsulation of the transaction payload, including data packaging, format conversion, and necessary signature operations. This ensures that the transaction content conforms to the blockchain protocol standard, generates a complete on-chain related transaction, meets the format and verification requirements of the blockchain network, and is ready to be submitted to the blockchain for consensus and storage.
[0080] The generated on-chain related transactions are broadcast to various consensus nodes through the blockchain network to ensure that transaction information is widely disseminated in the network. The on-chain plugin of the pre-set blockchain automatically receives the on-chain related transactions and performs format verification, signature verification and business logic legality checks on the transaction content. Each consensus node independently performs validity verification based on consistent verification rules to ensure that the transaction has not been tampered with and complies with the protocol requirements.
[0081] Once the on-chain related transactions have been verified for consistent validity by all consensus nodes, the blockchain network will include the on-chain related transactions in the block to be packaged. After confirmation by the consensus mechanism, they will be officially written into the ledger of the pre-set blockchain. The related structures in the on-chain related transactions will be permanently recorded, forming an immutable on-chain related record, ensuring the secure binding and long-term preservation of the on-chain trusted record and zero-knowledge proof.
[0082] By securely binding and storing trusted on-chain records with zero-knowledge proofs on the blockchain, unified and trusted sharing and verification of data across organizations is achieved. The immutability and distributed consensus mechanism of the blockchain ensure the transparency and consistency of data among multiple parties, while zero-knowledge proofs guarantee data privacy and trusted verification of computation results without disclosing sensitive information. This improves the security situation awareness and emergency response speed of the entire food supply chain, promotes the deep application and collaborative innovation of cloud-native architecture, and strengthens the overall security level of the supply chain.
[0083] S6. Utilize the on-chain associated records to dynamically monitor data anomalies and tampering of the key business data, and obtain the monitoring results of the food supply chain.
[0084] In this embodiment of the invention, a target business event in the food supply chain is obtained, the corresponding target on-chain record is extracted from the on-chain associated record, and the initial target business data of the target business event is obtained from the distributed file system. The initial data is hashed and encrypted to generate an off-chain business summary, which is then compared with the on-chain record one by one to determine the data integrity. If they match, the zero-knowledge proof in the on-chain record is further used to verify whether the initial data has been tampered with by computational behavior, thus forming a dynamic security monitoring result for the key business data of the food supply chain.
[0085] In detail, the dynamic monitoring of data anomalies and tampering of the key business data using the on-chain associated records to obtain the monitoring results of the food supply chain includes: Obtain the target business event from the food supply chain, and extract the target on-chain record of the target business event from the on-chain associated records; Extract the initial target business data of the target business event from the key business data within the distributed file system; The initial target business data is hashed and encrypted to obtain an off-chain business digest; The off-chain business summary is compared one by one with the target on-chain record to obtain the comparison results; If the comparison result shows that the off-chain business summary is inconsistent with the target on-chain record, then the initial target business data is marked as having data integrity issues. The data integrity anomaly is used as the first alarm message, and monitoring results are generated based on the first alarm message; If the comparison result shows that the off-chain business summary is consistent with the target on-chain record, then the zero-knowledge proof in the target on-chain record is used to determine whether there is any behavioral tampering in the calculation process of the initial target business data; If the calculation process of the initial target business data is subject to behavioral tampering, the initial target business data will be marked as having abnormal calculation behavior. The abnormal computational behavior is used as a second alarm message, and monitoring results are generated based on the second alarm message; If there is no behavioral tampering in the calculation process of the initial target business data, then the absence of anomalies in the initial target business data will be taken as the monitoring result of the food supply chain.
[0086] In detail, based on business rules and monitoring requirements, target business events in the food supply chain are identified and determined. Using the unique identifier or related attributes of the target business event, the corresponding target on-chain record is accurately retrieved from the associated records stored on the chain, ensuring that trusted blockchain data associated with the business event can be quickly located.
[0087] Based on the identification information of the target business event, locate and extract the original records of key business data associated with the target business event from the distributed file system, including accessing storage nodes, retrieving corresponding data files or data blocks, and performing necessary data parsing and format conversion to ensure that complete and accurate initial target business data is obtained.
[0088] The extracted initial target business data is encrypted using a secure hash algorithm, converting the original data into a fixed-length hash value to form an off-chain business summary. This summary is unique and irreversible, effectively representing the integrity of the original data and facilitating subsequent comparison and verification with on-chain records to ensure that the data has not been tampered with and remains consistent.
[0089] The off-chain business summary obtained from the distributed file system is compared line by line with the business summary stored in the target on-chain record. Data integrity is determined by verifying whether the hash values are completely consistent. If a mismatch is found between the off-chain summary and the on-chain record, the corresponding initial target business data is immediately marked as having data integrity issues, and this abnormal state is reported as a security monitoring alarm, indicating a potential risk of data tampering or loss. If the hash values are consistent, the zero-knowledge proof attached to the target on-chain record is further retrieved. Using the zero-knowledge proof, the computation process of the initial target business data is verified trustibly without exposing the original data, determining whether there has been any tampering or abnormal operation in the computation. Through this mechanism, dual integrity and trustworthiness guarantees are achieved for data in both storage and processing stages, thereby ensuring the accuracy and reliability of monitoring results.
[0090] After using zero-knowledge proof to verify the calculation process of the initial target business data, if signs of tampering with the calculation behavior are found, the system will mark the initial target business data as having suspicious calculation behavior and record this abnormal state as a monitoring result. If the verification result shows that the data calculation process has not been tampered with, the initial target business data will be determined to be without anomalies, confirming its integrity and trustworthiness. Then, the normal state will be used as a monitoring result to support subsequent security management and decision analysis.
[0091] By leveraging on-chain linked records combined with data digests from a distributed file system for dynamic comparison and zero-knowledge proof verification, dual integrity and trustworthiness guarantees are achieved in both storage and processing stages. This breaks down data silos across organizations, enabling secure interconnection and trusted sharing of data from multiple parties, and ensuring the integrity and tamper-proof nature of critical business data during transmission and storage. This not only enhances data transparency and trust among all links in the food supply chain but also significantly improves the real-time perception of the food supply chain's security posture and the efficiency of rapid response to abnormal behavior.
[0092] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0093] like Figure 2 The diagram shown is a functional block diagram of a cloud-native food supply chain safety monitoring system provided in an embodiment of the present invention.
[0094] This disclosure provides a cloud-native food supply chain safety monitoring system, which corresponds one-to-one with the cloud-native food supply chain safety monitoring method described in the previous embodiment. For example... Figure 2 As shown, the cloud-native food supply chain safety monitoring system 100 includes a data acquisition module 101, a summary upload module 102, a data encryption module 103, a proof generation module 104, a record association module 105, and a safety monitoring module 106. Detailed descriptions of each functional module are as follows: The data acquisition module 101 is used to acquire multiple distributed monitoring nodes deployed on the cloud-native service platform and collect key business data of multiple organizations in the food supply chain of the distributed monitoring nodes. The summary on-chain module 102 is used to extract the business data summary of the key business data and write the business data summary into a preset blockchain to generate a trusted on-chain record. The data encryption module 103 is used to store the key business data into a distributed file system that is decoupled from the cloud-native service platform, and to perform homomorphic encryption on the stored key business data to obtain business ciphertext data. The proof generation module 104 is used to perform homomorphic computation on the business encrypted data and generate zero-knowledge proof based on the obtained homomorphic computation result; The record association module 105 is used to associate and store the on-chain trusted record and the zero-knowledge proof in the preset blockchain to obtain the on-chain associated record; The security monitoring module 106 is used to dynamically monitor data anomalies and tampering of the key business data using the on-chain associated records, and obtain the monitoring results of the food supply chain.
[0095] In one embodiment, the data acquisition module 101 collects key business data from multiple organizations in the food supply chain of the distributed monitoring node, for the following purposes: Obtain the organizational location of each organization in the food supply chain, and dynamically deploy multiple containerized distributed monitoring nodes according to the organizational location using a cloud-native service platform; Obtain the data collection frequency and data filtering rules for each of the distributed monitoring nodes, and generate a collection strategy based on the data collection frequency and the data filtering rules; The distributed monitoring nodes are connected to the data sources of the corresponding organizations, and the data collection strategy is used to collect data from the data sources to obtain the initial business data of the corresponding organizations in each of the distributed monitoring nodes. Obtain the microservice dependency graph of the cloud-native service platform, analyze the data impact of the initial business data using the microservice dependency graph, and generate data impact weights based on the analysis results. The initial business data is filtered for key business data using the data influence weights.
[0096] In one embodiment, the summary-on-chain module 102, when performing the extraction of a business data summary from the key business data, is used for: Extract the basic structural information of the key business data; The key business data is semantically mapped and classified to obtain key business semantics; Identify the upstream and downstream related fields of the key business data based on the microservice dependency graph; Generate parsed business data based on the basic structural information, the key business semantics, and the upstream and downstream related fields; Obtain a cross-organizational field mapping table and semantic alignment rules, and use the cross-organizational field mapping table and semantic alignment rules to standardize the parsed business data to obtain standard business data; The sensitive fields of the standard business data are subjected to multi-level desensitization to obtain desensitized business data; The de-identified business data is hashed and encrypted to generate a digest code for each piece of de-identified business data; Obtain the metadata of the de-identified business data, and generate a business data digest based on the digest code and the metadata.
[0097] In one embodiment, the summary-on-chain module 102, when performing the action of writing the business data summary into a preset blockchain to generate a trusted on-chain record, is used for: Obtain the preset blockchain evidence storage field template through the cloud-native service platform; The business data digest is encapsulated according to the evidence storage field template to obtain an on-chain evidence storage structure. Generate an evidence storage request based on the on-chain evidence storage structure; The evidence storage request is sent to the transaction pool of a preset blockchain to generate an evidence storage transaction; The notarized transaction is subjected to consensus verification to obtain the verification result; When the verification result indicates that the evidence storage transaction has reached a consensus, the evidence storage transaction is written into a preset blockchain to generate an evidence storage result. A trusted on-chain record is generated based on the evidence storage result and the digest code.
[0098] In one embodiment, the data encryption module 103 performs homomorphic encryption on the stored key business data to obtain business ciphertext data, which is used for: Based on the key business data, business requirements are generated, and based on the business requirements, encryption parameters and public / private key pairs are generated; Generate an encryption context based on the encryption parameters; The key business data is dynamically structured to obtain structured business data; Convert the structured business data into business numerical data; The business numerical data is encoded to obtain business numerical encoded data; Extract the public key of the public-private key pair, and use the public key and the encryption context to encrypt the business numerical encoded data item by item to obtain ciphertext units; Generate corresponding service identification information based on the encrypted unit; Business encrypted data is generated based on the encrypted unit and the business identification information.
[0099] In one embodiment, the proof generation module 104 performs homomorphic computation on the business ciphertext data for: Extract the business logic from the encrypted business data; Obtain the logical target of the business logic and convert the logical target into a Boolean expression; Generate a homomorphic computation function based on the business logic; The homomorphic computation function is used to perform ciphertext operations on the Boolean expression to obtain the encrypted computation result ciphertext; The encrypted computation result is re-encrypted and the modulus is switched to obtain a homomorphic computation result.
[0100] In one embodiment, the proof generation module 104 generates a zero-knowledge proof based on the obtained homomorphic computation result, for the purpose of: The homomorphic computation result is used as the proof target, and the proof target is used as the private input; Obtain the business parameters of the encrypted business data and use the business parameters as common input; Construct a proof input using the private input and the public input; Obtain the function logic of the homomorphic computation function, convert the function logic into a circuit form, and construct a constraint circuit model based on the circuit form; Generate a zero-knowledge proof to be verified based on the proof input and the constraint circuit model; The validity of the zero-knowledge proof to be verified is then verified, and the verification result is obtained. When the verification result indicates that the zero-knowledge proof to be verified is invalid, the proof input and the constraint circuit model are detected and corrected, and the zero-knowledge proof is generated using the corrected proof input and constraint circuit model. When the verification result indicates that the zero-knowledge proof to be verified is valid, the valid zero-knowledge proof to be verified is taken as the zero-knowledge proof.
[0101] In one embodiment, the record association module 105, when performing the process of associating and storing the on-chain trusted record and the zero-knowledge proof in the preset blockchain to obtain an on-chain associated record, is used for: The trusted on-chain record and the zero-knowledge proof are bound together to obtain an associated structure; The associated structure is used as the transaction payload; Obtain the preset blockchain encapsulation format and encapsulation rules, and encapsulate the transaction payload according to the encapsulation format and encapsulation rules to obtain on-chain related transactions; The on-chain related transactions are broadcast to a preset blockchain, and the validity of each consensus node of the on-chain related transactions is verified by the on-chain plugin of the preset blockchain. When all consensus nodes of the on-chain associated transactions are valid, the on-chain associated transactions are written into a preset blockchain to generate on-chain associated records.
[0102] In one embodiment, the security monitoring module 106 performs dynamic monitoring of data anomalies and tampering of the key business data using the on-chain associated records to obtain monitoring results of the food supply chain, for the following purposes: Obtain the target business event from the food supply chain, and extract the target on-chain record of the target business event from the on-chain associated records; Extract the initial target business data of the target business event from the key business data within the distributed file system; The initial target business data is hashed and encrypted to obtain an off-chain business digest; The off-chain business summary is compared one by one with the target on-chain record to obtain the comparison results; If the comparison result shows that the off-chain business summary is inconsistent with the target on-chain record, then the initial target business data is marked as having data integrity issues. The data integrity anomaly is used as the first alarm message, and monitoring results are generated based on the first alarm message; If the comparison result shows that the off-chain business summary is consistent with the target on-chain record, then the zero-knowledge proof in the target on-chain record is used to determine whether there is any behavioral tampering in the calculation process of the initial target business data; If the calculation process of the initial target business data is subject to behavioral tampering, the initial target business data will be marked as having abnormal calculation behavior. The abnormal computational behavior is used as a second alarm message, and monitoring results are generated based on the second alarm message; If there is no behavioral tampering in the calculation process of the initial target business data, then the absence of anomalies in the initial target business data will be taken as the monitoring result of the food supply chain.
[0103] This invention addresses a cloud-native food supply chain safety monitoring method. It involves acquiring multiple distributed monitoring nodes deployed on a cloud-native service platform, collecting key business data from multiple organizations within the food supply chain, and dynamically configuring these containerized distributed monitoring nodes according to organizational location. Each monitoring node operates independently and is directly connected to the corresponding organization's data source, ensuring seamless data transmission and sharing between different organizations. A business data summary of the key business data is extracted and written into a pre-defined blockchain to generate a trusted on-chain record. In the food supply chain, data from each organization is transparently and traceably recorded using blockchain technology. The key business data is stored in a distributed file system decoupled from the cloud-native service platform, and homomorphically encrypted to obtain encrypted business data. The encryption and subsequent decryption of the encrypted data protect data privacy while supporting computation and analysis, ensuring data trustworthiness and integrity. The combination of the flexibility of the cloud-native architecture and encryption protection improves overall security and data transmission efficiency. Homomorphic computation is performed on the encrypted business data, and the results are used to... The generated zero-knowledge proof enables encrypted computation and trusted verification of sensitive business information without exposing plaintext business data. Under a cloud-native architecture, different organizations can securely share encrypted data and collaborate on computations without disclosing their original data, thus ensuring data privacy and compliance while enhancing data linkage and end-to-end information interoperability. Furthermore, combined with the zero-knowledge proof mechanism, it can provide external proof of the validity of computation results, preventing tampering and forgery. The trusted on-chain record and the zero-knowledge proof are associated and stored in the preset blockchain, resulting in an associated on-chain record, achieving cross-organizational data management. Trusted sharing and verification: The immutability and distributed consensus mechanism of blockchain ensure the transparency and consistency of data among multiple parties. The on-chain associated records are used to dynamically monitor data anomalies and tampering of key business data, obtaining monitoring results for the food supply chain. By combining on-chain associated records with data digests from a distributed file system for dynamic comparison and zero-knowledge proof verification, dual integrity and trustworthiness guarantees are achieved in both storage and processing stages. This effectively optimizes the problems of cross-organizational data silos and trusted data transmission, improving the ability to perceive the security situation of the entire food supply chain and the efficiency of emergency response. Specific limitations of a cloud-native food supply chain security monitoring system can be found in the limitations of a cloud-native food supply chain security monitoring method described above, and will not be repeated here. The various modules in the above-mentioned cloud-native food supply chain security monitoring system can be implemented entirely or partially through software, hardware, or combinations thereof.The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or they can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of the above modules.
[0104] In the embodiments provided by this invention, it should be understood that the disclosed system can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.
[0105] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.
[0106] Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be embraced within the invention. No appended diagram markings in the claims should be construed as limiting the scope of the claims.
[0107] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0108] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0109] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above.
[0110] In the embodiments provided in this disclosure, it should be understood that the disclosed systems and methods can also be implemented in other ways. The system embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0111] It should be noted that, in this disclosure, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element limited by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0112] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A cloud-native method for monitoring food supply chain safety, characterized in that, The method includes: Obtain multiple distributed monitoring nodes deployed on the cloud-native service platform, and collect key business data from multiple organizations in the food supply chain of the distributed monitoring nodes; Extract the business data summary from the key business data and write the business data summary into a preset blockchain to generate a trusted on-chain record; The critical business data is stored in a distributed file system that is decoupled from the cloud-native service platform, and the stored critical business data is homomorphically encrypted to obtain ciphertext business data. Homomorphic computation is performed on the encrypted business data, and zero-knowledge proof is generated based on the obtained homomorphic computation result; The on-chain trusted record and the zero-knowledge proof are associated and stored in the preset blockchain to obtain the on-chain associated record; By utilizing the on-chain associated records, dynamic monitoring of data anomalies and tampering in the key business data is performed to obtain the monitoring results of the food supply chain.
2. The cloud-native food supply chain safety monitoring method as described in claim 1, characterized in that, The collection of key business data from multiple organizations in the food supply chain by the distributed monitoring nodes includes: Obtain the organizational location of each organization in the food supply chain, and dynamically deploy multiple containerized distributed monitoring nodes according to the organizational location using a cloud-native service platform; Obtain the data collection frequency and data filtering rules for each of the distributed monitoring nodes, and generate a collection strategy based on the data collection frequency and the data filtering rules; The distributed monitoring nodes are connected to the data sources of the corresponding organizations, and the data collection strategy is used to collect data from the data sources to obtain the initial business data of the corresponding organizations in each of the distributed monitoring nodes. Obtain the microservice dependency graph of the cloud-native service platform, analyze the data impact of the initial business data using the microservice dependency graph, and generate data impact weights based on the analysis results. The initial business data is filtered for key business data using the data influence weights.
3. The cloud-native food supply chain safety monitoring method as described in claim 2, characterized in that, The business data summary for extracting the key business data includes: Extract the basic structural information of the key business data; The key business data is semantically mapped and classified to obtain key business semantics; Identify the upstream and downstream related fields of the key business data based on the microservice dependency graph; Generate parsed business data based on the basic structural information, the key business semantics, and the upstream and downstream related fields; Obtain a cross-organizational field mapping table and semantic alignment rules, and use the cross-organizational field mapping table and semantic alignment rules to standardize the parsed business data to obtain standard business data; The sensitive fields of the standard business data are subjected to multi-level desensitization to obtain desensitized business data; The de-identified business data is hashed and encrypted to generate a digest code for each piece of de-identified business data; Obtain the metadata of the de-identified business data, and generate a business data digest based on the digest code and the metadata.
4. The cloud-native food supply chain safety monitoring method as described in claim 3, characterized in that, The step of writing the business data summary into a preset blockchain to generate a trusted on-chain record includes: Obtain the preset blockchain evidence storage field template through the cloud-native service platform; The business data digest is encapsulated according to the evidence storage field template to obtain an on-chain evidence storage structure. Generate an evidence storage request based on the on-chain evidence storage structure; The evidence storage request is sent to the transaction pool of a preset blockchain to generate an evidence storage transaction; The notarized transaction is subjected to consensus verification to obtain the verification result; When the verification result indicates that the evidence storage transaction has reached a consensus, the evidence storage transaction is written into a preset blockchain to generate an evidence storage result. A trusted on-chain record is generated based on the evidence storage result and the digest code.
5. The cloud-native food supply chain safety monitoring method as described in claim 1, characterized in that, The process of homomorphically encrypting the stored key business data to obtain ciphertext business data includes: Based on the key business data, business requirements are generated, and based on the business requirements, encryption parameters and public / private key pairs are generated; Generate an encryption context based on the encryption parameters; The key business data is dynamically structured to obtain structured business data; Convert the structured business data into business numerical data; The business numerical data is encoded to obtain business numerical encoded data; Extract the public key of the public-private key pair, and use the public key and the encryption context to encrypt the business numerical encoded data item by item to obtain ciphertext units; Generate corresponding service identification information based on the encrypted unit; Business encrypted data is generated based on the encrypted unit and the business identification information.
6. The cloud-native food supply chain safety monitoring method as described in claim 1, characterized in that, The homomorphic computation on the encrypted business data includes: Extract the business logic from the encrypted business data; Obtain the logical target of the business logic and convert the logical target into a Boolean expression; Generate a homomorphic computation function based on the business logic; The homomorphic computation function is used to perform ciphertext operations on the Boolean expression to obtain the encrypted computation result ciphertext; The encrypted computation result is re-encrypted and the modulus is switched to obtain a homomorphic computation result.
7. The cloud-native food supply chain safety monitoring method as described in claim 6, characterized in that, The generation of zero-knowledge proofs based on the obtained homomorphic computation results includes: The homomorphic computation result is used as the proof target, and the proof target is used as the private input; Obtain the business parameters of the encrypted business data and use the business parameters as common input; Construct a proof input using the private input and the public input; Obtain the function logic of the homomorphic computation function, convert the function logic into a circuit form, and construct a constraint circuit model based on the circuit form; Generate a zero-knowledge proof to be verified based on the proof input and the constraint circuit model; The validity of the zero-knowledge proof to be verified is then verified, and the verification result is obtained. When the verification result indicates that the zero-knowledge proof to be verified is invalid, the proof input and the constraint circuit model are detected and corrected, and the zero-knowledge proof is generated using the corrected proof input and constraint circuit model. When the verification result indicates that the zero-knowledge proof to be verified is valid, the valid zero-knowledge proof to be verified is taken as the zero-knowledge proof.
8. The cloud-native food supply chain safety monitoring method as described in claim 1, characterized in that, The step of associating and storing the on-chain trusted record and the zero-knowledge proof in the preset blockchain to obtain the on-chain associated record includes: The trusted on-chain record and the zero-knowledge proof are bound together to obtain an associated structure; The associated structure is used as the transaction payload; Obtain the preset blockchain encapsulation format and encapsulation rules, and encapsulate the transaction payload according to the encapsulation format and encapsulation rules to obtain on-chain related transactions; The on-chain related transactions are broadcast to a preset blockchain, and the validity of each consensus node of the on-chain related transactions is verified by the on-chain plugin of the preset blockchain. When all consensus nodes of the on-chain associated transactions are valid, the on-chain associated transactions are written into a preset blockchain to generate on-chain associated records.
9. The cloud-native food supply chain safety monitoring method as described in claim 1, characterized in that, The method of dynamically monitoring data anomalies and tampering of key business data using the on-chain associated records to obtain monitoring results of the food supply chain includes: Obtain the target business event from the food supply chain, and extract the target on-chain record of the target business event from the on-chain associated records; Extract the initial target business data of the target business event from the key business data within the distributed file system; The initial target business data is hashed and encrypted to obtain an off-chain business digest; The off-chain business summary is compared one by one with the target on-chain record to obtain the comparison results; If the comparison result shows that the off-chain business summary is inconsistent with the target on-chain record, then the initial target business data is marked as having data integrity issues. The data integrity anomaly is used as the first alarm message, and monitoring results are generated based on the first alarm message; If the comparison result shows that the off-chain business summary is consistent with the target on-chain record, then the zero-knowledge proof in the target on-chain record is used to determine whether there is any behavioral tampering in the calculation process of the initial target business data; If the calculation process of the initial target business data is subject to behavioral tampering, the initial target business data will be marked as having abnormal calculation behavior. The abnormal computational behavior is used as a second alarm message, and monitoring results are generated based on the second alarm message; If there is no behavioral tampering in the calculation process of the initial target business data, then the absence of anomalies in the initial target business data will be taken as the monitoring result of the food supply chain.
10. A cloud-native food supply chain safety monitoring system, characterized in that, The system includes: The data acquisition module is used to acquire key business data of multiple organizations in the food supply chain from multiple distributed monitoring nodes deployed on the cloud-native service platform. The summary-on-chain module is used to extract a business data summary of the key business data and write the business data summary into a preset blockchain to generate a trusted on-chain record. The data encryption module is used to store the key business data into a distributed file system that is decoupled from the cloud-native service platform, and to perform homomorphic encryption on the stored key business data to obtain business ciphertext data. The proof generation module is used to perform homomorphic computation on the business encrypted data and generate zero-knowledge proofs based on the obtained homomorphic computation results. The record association module is used to associate and store the on-chain trusted record and the zero-knowledge proof in the preset blockchain to obtain the on-chain associated record; The security monitoring module is used to dynamically monitor data anomalies and tampering of the key business data using the on-chain associated records, and obtain the monitoring results of the food supply chain.