Shipping data flow processing method, device, equipment and medium

By performing identity authentication and access control on the blockchain, the efficiency and security issues in traditional shipping document processing methods are resolved, enabling accurate identity verification and compliant authorization, and improving the security and reliability of shipping data flow.

CN121841733APending Publication Date: 2026-04-10CHINA MERCHANTS FINANCE HLDG CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-30
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Traditional paper-based shipping document processing methods are inefficient and insecure. Existing blockchain-based shipping data processing methods have shortcomings in identity authentication and access control, which affect the efficiency and security of data flow.

Method used

By acquiring user access requests, extracting identity information, performing whitelist verification and on-chain authentication, generating identity verification credentials, and combining digital signatures and shipping document state machine rules, accurate identity verification and access control are achieved, ensuring compliant authorization and operational security.

Benefits of technology

It improves data retrieval efficiency and response speed, enhances the security and credibility of shipping data in the blockchain environment, prevents unauthorized operations, ensures the reliability and traceability of document status transfer, and improves the security and compliance level of business processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841733A_ABST
    Figure CN121841733A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of block chains, and discloses a shipping data flow processing method and device, equipment and a medium, and the method comprises the steps: obtaining an access request of a user for target shipping data in a block chain, and extracting access identity information corresponding to the user in the access request; if the access identity information is in the white list, generating an identity identification certificate corresponding to the access identity information, and storing the identity identification certificate and the access identity information as on-chain authentication data to the block chain; judging whether the user has a shipping data circulation authority or not based on the on-chain authentication data; if the user has the shipping data transfer authority, collecting a transfer operation request of the user for target shipping data, and receiving a digital signature generated by signing the transfer operation request by the user; and if the digital signature is within a preset signature validity period, executing document state circulation of the target shipping data on the block chain according to a shipping document state machine rule. According to the invention, the reliability of shipping data flow processing can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of blockchain, and in particular to a method, apparatus, equipment and medium for processing shipping data flow. Background Technology

[0002] With the rapid development of global trade and shipping, the traditional paper-based shipping document processing methods have gradually revealed significant shortcomings in terms of efficiency, security, and transparency. In particular, the flow of shipping data such as paper bills of lading, warehouse receipts, and letters of credit relies on manual transmission and verification, which is cumbersome, time-consuming, and prone to disputes due to forgery, loss, or alteration, severely restricting the efficiency of logistics and capital flow coordination.

[0003] Furthermore, existing blockchain-based shipping data processing methods still have some shortcomings. Some methods are not perfect in terms of identity authentication, which can easily lead to the leakage or tampering of identity information; in terms of access control, the access rules of some methods are not flexible enough to meet the complex and ever-changing access requirements of shipping operations, which affects the efficiency and security of shipping data flow.

[0004] Therefore, a blockchain-based shipping data transfer and processing method is needed to achieve efficient and reliable data transfer of shipping data. Summary of the Invention

[0005] This invention provides a shipping data flow processing method, apparatus, equipment, and medium, the main purpose of which is to solve the problem of low reliability in the flow of shipping data documents.

[0006] Firstly, to achieve the above objectives, the present invention provides a shipping data transfer and processing method, comprising: Obtain a user's access request for target shipping data within a preset blockchain, and extract the access identity information corresponding to the user from the access request; If the access identity information is in the pre-stored whitelist, an identity identifier credential corresponding to the access identity information is generated, and the identity identifier credential and the access identity information are stored in the blockchain as on-chain authentication data. Based on the on-chain authentication data, determine whether the user has the authority to transfer shipping data; If the user has shipping data transfer permissions, then the user's request for the transfer of the target shipping data is collected, and a digital signature generated by the user signing the transfer request is received. If the digital signature is within the preset signature validity period, the document status flow of the target shipping data is executed on the blockchain according to the preset shipping document state machine rules.

[0007] Secondly, the present invention also provides a shipping data transfer and processing apparatus, comprising: The identity information extraction module is used to obtain a user's access request for target shipping data within a preset blockchain, and extract the access identity information corresponding to the user within the access request; The identity information storage module is used to generate an identity identifier credential corresponding to the access identity information if the access identity information is in a pre-stored whitelist, and store the identity identifier credential and the access identity information as on-chain authentication data in the blockchain. The data transfer permission confirmation module is used to determine whether the user has the permission to transfer shipping data based on the on-chain authentication data. The digital signature generation module is used to collect the user's request for the transfer of the target shipping data if the user has the authority to transfer shipping data, and to receive the digital signature generated by the user signing the transfer request. The document status transition module is used to execute the document status transition of the target shipping data on the blockchain according to the preset shipping document status machine rules if the digital signature is within the preset signature validity period.

[0008] Thirdly, the present invention also provides an electronic device, the electronic device comprising: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the shipping data transfer processing method described above.

[0009] Fourthly, the present invention also provides a computer-readable storage medium storing at least one computer program, which is executed by a processor in an electronic device to implement the shipping data transfer processing method described above.

[0010] In this embodiment of the invention, by automatically identifying and extracting user identity information from access requests, accurate identity verification for accessing blockchain shipping data is achieved, significantly improving the efficiency and response speed of data retrieval. Simultaneously, the identity information is intelligently matched with on-chain permissions, ensuring compliant authorized access while effectively preventing unauthorized operations, thus enhancing the security and credibility of shipping data in the blockchain environment. A whitelist mechanism is used for pre-access permission screening, combined with on-chain credential storage, achieving dual security enhancement. Specifically, whitelist verification immediately intercepts unauthorized access, eliminating the risk of illegal operations at the source and ensuring the initial security of shipping document circulation. Furthermore, authorized identity information and digital credentials are jointly anchored to the blockchain, forming an immutable authentication record, providing a reliable audit and traceability basis for subsequent operations on the document status circulation of the target shipping data.

[0011] Among these features, fine-grained permission judgment is performed based on authoritative certified data already on the blockchain, and a digital signature mechanism is introduced to achieve precise and dynamic management from identity authentication to operation authorization. This effectively prevents unauthorized behavior by legitimate users. By collecting digital signatures signed by users' private keys, each transfer operation is strongly bound to a specific identity, ensuring the non-repudiation and legal validity of the operation. This significantly improves the security, compliance, and traceability of the shipping document status transfer process. By verifying the timeliness of digital signatures, the risk of invalid operations in the long term due to private key leakage or malicious reuse is effectively prevented, greatly enhancing the real-time security of the business process. At the same time, combined with preset smart contract rules to drive the status transfer, it ensures that each status change simultaneously meets the three conditions of identity trustworthiness, permission compliance, and timeliness. This not only technically eliminates the erroneous execution of expired instructions and ensures strict synchronization between the on-chain document status and the actual business progress, but also further improves the automation, compliance, and risk resistance capabilities of the entire shipping blockchain system. Attached Figure Description

[0012] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a schematic diagram of an application environment for a shipping data flow processing method according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating a shipping data transfer and processing method according to an embodiment of the present invention. Figure 3This is a schematic diagram illustrating the process of executing the document status transition of the target shipping data on the blockchain according to preset shipping document state machine rules, as provided in an embodiment of the present invention. Figure 4 This is a schematic diagram illustrating the process of implementing the finite state machine flow of shipping and trade documents in a shipping data flow processing method according to an embodiment of the present invention.

[0014] Figure 5 This is a functional block diagram of a shipping data transfer and processing device provided in an embodiment of the present invention; Figure 6 This is a schematic diagram of the structure of an electronic device for implementing a shipping data flow processing method according to an embodiment of the present invention; Figure 7 This is another schematic diagram of an electronic device for implementing a shipping data flow processing method according to an embodiment of the present invention.

[0015] The objectives, features, and advantages of this invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0016] To enable those skilled in the art to better understand the technical solutions of this disclosure, and to fully understand and implement the process of how this disclosure applies technical means to solve technical problems and achieve corresponding technical effects, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, not all embodiments. The embodiments of this disclosure and the various features within them can be combined with each other without conflict, and the resulting technical solutions are all within the protection scope of this disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without creative effort should fall within the protection scope of this disclosure.

[0017] It should be noted that the terms "first," "second," etc., used in this disclosure and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, apparatus, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0018] This application provides a shipping data flow processing method. The executing entity of this method includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the device provided in this application: a server, a terminal, etc. In other words, the shipping data flow processing method can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0019] This invention discloses a shipping data flow processing method, which can be applied to applications such as... Figure 1 In this application environment, the client communicates with the server via a network. The server can obtain user access requests for target shipping data within the pre-defined blockchain through the client. Through a four-tiered security system—whitelist pre-screening, on-chain credential solidification, fine-grained permission verification, and digital signature validity verification—end-to-end trusted verification of every operation request is achieved. This not only intercepts illegal and unauthorized access at the source but also ensures the immutability and traceability of the entire process by permanently recording key authentication and operation information on the blockchain. Finally, after all security conditions are met, the document flow is automatically driven by pre-defined state machine rules, thereby ensuring business efficiency while achieving clear responsibilities and compliant, reliable shipping data collaboration. This improves the reliability of the document status flow of the target shipping data.

[0020] The client can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster consisting of multiple servers. The invention will now be described in detail through specific embodiments.

[0021] Reference Figure 2 The diagram shown is a flowchart illustrating a shipping data transfer and processing method according to an embodiment of the present invention. In this embodiment, the shipping data transfer and processing method includes: S1. Obtain the user's access request for target shipping data within the preset blockchain, and extract the access identity information corresponding to the user from the access request.

[0022] In this embodiment of the invention, the user refers to an individual or entity that submits an access request, hoping to obtain target shipping data information within the blockchain; the blockchain is a pre-defined data storage and transmission system built using blockchain technology, possessing characteristics such as decentralization and immutability; the target shipping data refers to specific data information related to shipping business stored in the blockchain; and the access identity information refers to relevant information used in the access request to identify the user's identity and determine whether the user has permission to access the target shipping data.

[0023] In this embodiment of the invention, extracting the access identity information corresponding to the user within the access request includes: Parse the HTTP header fields of the access request, and determine the location of the field used to carry identity information from the HTTP header fields; Extract the corresponding user's identity token string from the field location; The identity token string is Base64Url decoded to obtain the token payload portion of the identity token string; Parse the JSON content of the token payload to obtain the user identifier, and use the user identifier as the user's access identity information.

[0024] In this embodiment of the invention, HTTP (Hypertext Transfer Protocol) is an application layer protocol for transmitting hypertext. An HTTP request consists of a request line, a request header, and a request body. The request header contains a lot of metadata about the request, such as client information and authentication information. When a user's access request arrives at the server, the HTTP protocol parsing module on the server side will automatically parse the request and divide the request data into different parts, including the request line, request header, and request body, according to the HTTP protocol specification.

[0025] For request headers, the parsing module identifies the name and corresponding value of each header field and stores this information for subsequent processing. In this way, the server can obtain the HTTP header fields of the access request, providing a basis for determining the location of fields carrying identity information.

[0026] In detail, after parsing the HTTP header fields, keyword matching technology is used to find fields that may carry identity information. Specifically, predefined keywords, such as "Authorization," are searched in the name of each header field. If a matching field is found, the position of that field is determined as the field used to carry identity information. This process is similar to searching for specific words in text. By comparing field names and keywords, the target field can be quickly located.

[0027] Specifically, in the HTTP header fields, the value of each field is a string. After obtaining the field that carries the identity information, the value of that field is read directly. This value is the user's identity token string. For example, if the field carrying the identity information is "Authorization: Bearer xyz123", then "Bearer xyz123" will be extracted as the identity token string.

[0028] Furthermore, after obtaining the identity token string, the markers used to separate different parts of the token (such as the period ".") will be identified. The identity token string generally consists of three parts: header, payload, and signature, separated by periods. The Base64Url decoding algorithm is used to decode it. The Base64Url decoding algorithm converts the Base64Url encoded string back into the original binary data, and then converts this binary data into a readable string form, which is the token payload part of the identity token string.

[0029] Furthermore, JSON (JavaScript Object Notation) is a lightweight data-interchange format that represents structured data in text form. The token payload is typically a JSON string containing user-related information, stored as key-value pairs in predefined declared fields. The JSON parser reads the JSON string and converts it into an in-memory data structure, such as an object or dictionary. During parsing, the parser identifies and stores the key-value pairs according to JSON syntax rules. It then searches for predefined declared fields, such as "sub" (short for subject, usually used to represent a user identifier), in the parsed data structure. Once the field is found, its corresponding value is retrieved. This value is the user's identifier, which serves as the user's access identity information for subsequent permission verification and access control.

[0030] In this embodiment of the invention, by automatically identifying and extracting user identity information from access requests, accurate identity verification for accessing blockchain shipping data is achieved, which greatly improves the efficiency and response speed of data retrieval. At the same time, the mechanism intelligently matches identity information with on-chain permissions, which not only ensures compliant authorized access but also effectively prevents unauthorized operations, thereby enhancing the security and credibility of shipping data in the blockchain environment.

[0031] S2. Determine whether the access identity information is in the pre-stored whitelist.

[0032] In this embodiment of the invention, after obtaining the access identity information, there are problems such as inconsistent format, inclusion of redundant characters or special symbols. First, irrelevant characters such as spaces, newlines, and tabs are removed from the access identity information. For example, the original "user123" (with a space at the end) is cleaned to become "user123". The access identity information may contain a mixture of uppercase and lowercase letters, such as "USER123", which is then converted to lowercase "user123" or converted according to specific rules. Alternatively, the date format may have multiple forms such as "2023-01-01" and "01 / 01 / 2023", which are unified into a standard format, such as "20230101". Through this processing, standardized access identity information is obtained for accurate matching in the future.

[0033] In detail, the pre-stored whitelist is usually stored in some kind of data structure (such as array, linked list, database table, etc.). Each entry in the whitelist is accessed one by one. For whitelists stored in arrays, each element is accessed in the order of the array index, and the identity field corresponding to each whitelist entry is extracted. For example, each element in the array may be an object containing multiple fields, from which the key fields used for identity matching, such as username, ID, etc., are extracted.

[0034] For whitelists stored in database tables, use database query statements (such as SQL statements) to traverse each row of records in the table, extract the identity field of each row, and then extract the whitelist identity field corresponding to all whitelist entries.

[0035] Specifically, for each field of standardized access identity information, it is compared with the corresponding field in the whitelist identity field in turn, that is, the two strings are compared character by character to see if they are completely identical. For example, if the username in the standardized access identity information is "user123", it is compared with the username in the whitelist identity field character by character to check if they are completely identical. If every character of the two strings is the same, the two fields are considered to be matched successfully. If any character is different, they are considered to be mismatched.

[0036] Specifically, during the field-by-field matching process, if the identity information field of the standardized access identity information is found to be completely consistent with any field in the whitelist identity field, a flag is set or a specific value is returned to indicate that the access identity information is in the whitelist; if the identity information field of the standardized access identity information does not match any field in the whitelist identity field, another flag is set or another specific value is returned to indicate that the access identity information is not in the whitelist.

[0037] If the access identity information is not in the pre-stored whitelist, then execute S3 to terminate the user's execution of the document status flow of the target shipping data on the blockchain.

[0038] If the access identity information is in the pre-stored whitelist, then execute S4 to generate the identity identifier credential corresponding to the access identity information, and store the identity identifier credential and the access identity information as on-chain authentication data in the blockchain.

[0039] In this embodiment of the invention, generating the identity credential corresponding to the access identity information includes: The corresponding credential type and encryption algorithm are determined based on the preset credential generation strategy, and the credential private key bound to the credential type is obtained. The identity hash value of the access identity information is encrypted using the asymmetric encryption algorithm in the encryption algorithm and the credential private key to obtain the credential digital signature; Generate a credential payload based on the user identifier in the access identity information and the preset access validity period; The voucher payload and the voucher digital signature are combined and encoded according to the preset voucher format to generate the original voucher string; The original credential string is encapsulated for security purposes to obtain an identity verification credential.

[0040] In this embodiment of the invention, the preset credential generation strategy is a series of predefined rules and conditions used to guide the credential generation process, including different credential types (such as long-term credentials, short-term credentials, etc.) and corresponding encryption algorithms (such as RSA, ECDSA, etc.). In encrypted communication and authentication, the key is a very important component. For different credential types, the credential private key bound to it will be pre-generated and stored.

[0041] In detail, the system reads the preset credential generation strategy, which contains various conditions such as the source of the access request and the user's permission level. Based on these conditions, the system uses strategy matching technology to search for matching rules in the strategy library, thereby determining the appropriate credential type and encryption algorithm. Once the credential type is determined, the system uses key management technology to retrieve the credential private key bound to that credential type from the key storage system.

[0042] Specifically, a hash algorithm is used to process the access identity information, converting it into an identity hash value. This hash value is the unique identifier of the access identity information. Any small change to the access identity information will result in a huge change in the hash value. The identity hash value is then encrypted using a deterministic asymmetric encryption algorithm and the obtained credential private key. The encrypted result is the credential digital signature. This digital signature can ensure the authenticity and integrity of the identity hash value. Only the person with the corresponding private key can generate a valid signature.

[0043] Furthermore, the user identifier is extracted from the access identity information. This identifier is a string that uniquely identifies the user. At the same time, the preset access validity period is obtained. This validity period may be a time range, such as a period of time starting from the current time. The user identifier and the access validity period are concatenated according to a predefined format and rules. For example, the user identifier and the access validity period can be connected with a specific delimiter to form a string as a credential payload. This credential payload will be used as part of the identity verification credential for subsequent verification and processing.

[0044] Furthermore, based on the preset voucher format, the position and order of the voucher payload and digital signature in the original voucher string are determined. For example, the voucher format may specify that the voucher payload comes first, followed by the digital signature, separated by a specific delimiter. The voucher payload and digital signature are combined according to the determined format, and the combined data is encoded using encoding technology. For example, Base64 encoding is used to convert binary data into an ASCII string. The encoded string is the original voucher string, which can serve as the preliminary form of the identity voucher for subsequent security encapsulation.

[0045] Among them, using encryption encapsulation technology, selecting a suitable symmetric encryption algorithm and key, the original credential string is encrypted, and the encrypted data will become more secure, preventing unauthorized access; for example, a message authentication code can be generated and attached to the encrypted data. This message authentication code can be used to verify whether the data has been tampered with during transmission and storage, thus forming a complete identity credential.

[0046] In this embodiment of the invention, storing the identity credential and the access identity information as on-chain authentication data in the blockchain includes: The identity credential and the access identity information are encrypted using the user's public key, and the encryption result is stored in a preset data ontology area; Calculate the credential hash value of the identity identification credential and the identity hash value of the access identity information, and store the credential hash value, the identity hash value, and a preset timestamp into a preset metadata area; Generate on-chain data packets based on the data ontology area and the metadata area; Invoke a smart contract pre-deployed on the blockchain and select one or more target consensus nodes from the list of nodes on the blockchain according to a preset node selection strategy; The on-chain data packet is sent to the target consensus node via the smart contract; After receiving successful transmission notifications from more than two-thirds of the target consensus nodes within a preset time, the on-chain data packet is confirmed as the user's on-chain authentication data stored in the blockchain.

[0047] In this embodiment of the invention, the user's public key is obtained. This public key may be pre-generated during user registration or identity authentication. Using an asymmetric encryption algorithm, the identity credential and access identity information are used as input data and encrypted using the user's public key. The encryption process converts the original data into a string of ciphertext according to specific algorithm rules. The encrypted result is stored in a preset data ontology area. The data ontology area is the area in the blockchain used to store actual business data. In this way, only users with the corresponding private key can decrypt and view their identity credential and access identity information, ensuring data security.

[0048] In detail, a hash algorithm is used to process the identity credential and access identity information separately. The identity credential is taken as input, and the hash algorithm calculates the credential hash value. Similarly, the access identity information is taken as input, and the identity hash value is calculated. The hash algorithm converts the input data into a fixed-length string, which is a unique identifier for the input data. Any small change to the input data will result in a large change in the hash value. At the same time, a preset timestamp is obtained. This timestamp can represent the current system time or a specific time preset according to business needs.

[0049] Specifically, the calculated credential hash value, identity hash value, and timestamp are stored in a preset metadata area. The metadata area is the area in the blockchain used to store the metadata of data (such as the hash value and timestamp of the data). In this way, the data can be easily indexed, queried, and verified.

[0050] The data ontology area and metadata area are combined according to predefined formats and rules. For example, the encrypted data of the data ontology area can be placed first, followed by the hash value and timestamp of the metadata area, separated by a specific delimiter. During the combination process, additional processing can be performed on the data, such as adding verification information and compressing the data, to improve the data transmission efficiency and reliability. The combined data is then encapsulated into a complete on-chain data packet. This on-chain data packet contains the user's identity credentials, access identity information, and related metadata, and can be transmitted and stored on the blockchain as a whole.

[0051] Furthermore, a smart contract pre-deployed on the blockchain is invoked. This smart contract may have been deployed during blockchain initialization. The smart contract is usually invoked by sending a specific transaction to the blockchain network, triggering its execution. According to a preset node selection strategy, one or more target consensus nodes are selected from the blockchain's node list. The node selection strategy includes various rules, such as random selection, selection based on node load, and selection based on node reputation. Based on these rules, the nodes in the node list are filtered and sorted, and finally, the target consensus nodes that meet the conditions are selected.

[0052] Specifically, by calling a smart contract, on-chain data packets are passed as input parameters to the execution logic of the smart contract. During the execution process, the smart contract sends the on-chain data packets to the previously selected target consensus node according to the communication rules of the blockchain network. During the data transmission process, the blockchain network uses specific encryption and authentication mechanisms to ensure the security and integrity of the data. For example, the data may be encrypted before transmission, and the receiving node will decrypt and verify the data to ensure that the data has not been tampered with.

[0053] When the target consensus node receives the on-chain data packet, it verifies and processes the data. If the data verification is successful, the node sends a successful transmission notification to the system and waits for the successful transmission notification from the target consensus node within a preset time. If more than two-thirds of the target consensus nodes receive successful transmission notifications within the preset time, it is considered that most nodes have recognized the storage of the data. At this point, according to the blockchain consensus mechanism, the on-chain data packet is confirmed as the user's on-chain authentication data stored on the blockchain.

[0054] If not enough successful transmission notifications are received within the preset time, a timeout handling mechanism is triggered; for example, the on-chain data packet is resent to the target consensus node, or the storage operation is marked as failed and relevant personnel are notified for further processing.

[0055] In this embodiment of the invention, a whitelist mechanism is used for pre-access permission screening, combined with on-chain credential storage, to achieve dual security enhancement. Specifically, whitelist verification can immediately block unauthorized access, eliminating the risk of illegal operations from the source and ensuring the initial security of shipping document circulation. Secondly, authorized identity information and digital credentials are jointly anchored to the blockchain, forming an immutable authentication record, which provides a reliable audit and traceability basis for subsequent operations on the document status circulation of target shipping data.

[0056] S5. Determine whether the user has shipping data transfer permissions based on the on-chain authentication data.

[0057] In this embodiment of the invention, determining whether the user has shipping data transfer permissions based on the on-chain authentication data includes: The on-chain authentication data is processed to standardize its format, resulting in standardized on-chain authentication data. Extract the on-chain authentication identifier from the standardized on-chain authentication data; Invoke the preset permission policy engine, and query the corresponding permission rules from the blockchain according to the permission policy engine and the on-chain authentication identifier; The system analyzes the permission rules to determine if there are any permission entries for the transfer of the target shipping data. If the permission rule contains the flow operation permission entry, then the permission status of the flow operation permission entry is further determined: If the permission status of the data transfer operation permission entry is "allowed", then it is determined that the user has shipping data transfer permission. If the permission status of the data transfer operation permission entry is not allowed, it is determined that the user does not have shipping data transfer permission.

[0058] In this embodiment of the invention, the format of on-chain authentication data is analyzed. On-chain authentication data may exist in multiple formats due to different sources or storage methods, such as different data encodings and different data structures. According to preset standardization rules, the format of on-chain authentication data is converted. For example, if the on-chain authentication data is stored in binary format, it can be converted into a readable text format. If the field names in the data are inconsistent, the fields can be mapped according to a unified naming rule. During the conversion process, some necessary processing is also performed on the data, such as removing invalid characters and filling missing fields, to ensure the integrity and accuracy of the data. The processed data is output as standardized on-chain authentication data, providing a unified data foundation for subsequent permission judgment.

[0059] In detail, based on the definition and characteristics of on-chain authentication identifiers, extraction rules are determined. An on-chain authentication identifier is a specific field, a specific data pattern, or a specific combination of data in the data. Standardized on-chain authentication data is scanned and analyzed. During the scanning process, data that meets the conditions is searched according to the extraction rules. When data that meets the conditions is found, it is extracted and used as an on-chain authentication identifier. The extraction process can be achieved through technologies such as string matching and pattern recognition to ensure the accuracy and completeness of the extraction.

[0060] Specifically, a permission policy engine is a software component used to manage and execute permission policies. It can authorize and restrict user operations based on user identity, role, permissions, and other information. A permission policy engine typically includes functions such as defining, storing, querying, and executing permission rules. When an on-chain authentication identifier is passed to the permission policy engine as an input parameter, the permission policy engine will determine the user's identity and permission information based on the on-chain authentication identifier. The permission policy engine will then query the corresponding permission rules from the blockchain according to preset query rules, which include the blockchain node to be queried, the range of data to be queried, and the fields to be queried.

[0061] During the query process, the blockchain network uses specific encryption and authentication mechanisms to ensure the security and reliability of the query. The query result is a dataset containing permission rules, and the permission policy engine parses and processes the query result.

[0062] Furthermore, the queried permission rule data is obtained. The permission rule data is a dataset containing multiple permission entries. Each permission entry may contain different permission information. The permission rule data is parsed to extract the permission entries. During the parsing process, it is checked whether each permission entry is related to the flow operation of the target shipping data. For example, the data identifier, operation type and other information in the permission entry are checked to determine whether they match the flow operation of the target shipping data.

[0063] Specifically, if there are permission entries related to the transfer operation of the target shipping data, they are marked as having transfer operation permission entries; otherwise, they are marked as not having transfer operation permission entries. If there are transfer operation permission entries, the permission status information of the permission entries is further obtained, and the permission status is judged according to the preset permission status judgment rules. The permission status includes allowed status and disallowed status, and the judgment rules can be based on specific fields or flag bits in the permission entries.

[0064] Specifically, if the permission status is allowed, the corresponding operation is performed, such as allowing the user to perform shipping data transfer operations; if the permission status is disallowed, other operations are performed, such as rejecting the user's request or prompting the user that they do not have permission.

[0065] If the user does not have the permission to transfer shipping data, then return to step S3 and terminate the user's execution of the document status transfer of the target shipping data on the blockchain.

[0066] If the user has shipping data transfer permissions, then execute S6, collect the user's request for the transfer of the target shipping data, and receive the digital signature generated by the user signing the transfer request.

[0067] In this embodiment of the invention, receiving the digital signature generated by the user signing the transfer operation request includes: The request content of the transfer operation request is hashed according to a preset hash algorithm to obtain the message digest corresponding to the transfer operation request; The message digest is encrypted using the user's private key to generate an initial digital signature data block.

[0068] The initial digital signature data block and its generation timestamp are structured and encapsulated to obtain a standard digital signature data block.

[0069] The standard digital signature data block is appended to the specified data segment of the transfer operation request to obtain a digital signature with a complete verification path.

[0070] In this embodiment of the invention, a preset hash algorithm is determined, such as the SHA-256 algorithm, and the request content of the transfer operation request is obtained. The request content includes the request type (such as read, write, modify, etc.), the target data identifier of the request, the request time, and other information. This information is stored in the system in a specific data format. The request content is used as input, and calculation is performed according to the operation rules of the selected hash algorithm. The operation rules of the hash algorithm usually include a series of bit operations, modulo operations, etc. For example, in the SHA-256 algorithm, the input data is padded and divided into blocks, and then multiple rounds of complex operations are performed on each data block to finally generate a fixed-length (256-bit) message digest.

[0071] In detail, the user's private key is obtained. The user's private key is generated and securely stored when the user registers or generates a key pair. Only the user can access it. The calculated message digest is used as input data, and encryption is performed using the user's private key. The encryption process is carried out according to the rules of the selected asymmetric encryption algorithm. Taking the RSA algorithm as an example, the encryption process involves complex mathematical operations such as modular exponentiation. Specifically, the message digest is treated as a numerical value, and then modular exponentiation is performed using the exponent and modulus in the user's private key to obtain the encrypted data, which is the initial digital signature data block.

[0072] Due to the nature of asymmetric encryption, only the public key corresponding to the user's private key can be used to decrypt the initial digital signature data block, thereby verifying the validity of the signature. In this way, the initial digital signature data block contains the user's approval information for the content of the transfer operation request.

[0073] Specifically, determine the format for the structured data encapsulation, such as choosing JSON format. JSON is a lightweight data interchange format that represents structured data in text form. At the same time, obtain the initial digital signature data block and the generation timestamp of the initial digital signature data block. The generation timestamp is an identifier that records the generation time of the initial digital signature data block, which can ensure the timeliness and uniqueness of the digital signature.

[0074] Following the rules of JSON format, the initial digital signature data block and the generation timestamp are organized into a structured data object. For example, in JSON, data can be represented using key-value pairs, such as {"signature": "initial digital signature data block", "timestamp": "generation timestamp"}. The organized structured data object is stored as a standard digital signature data block. The standard digital signature data block contains the core information of the digital signature (initial digital signature data block) and auxiliary information (generation timestamp), providing complete data support for subsequent signature verification.

[0075] Furthermore, the designated data segment of the transfer operation request is determined. The designated data segment is a specific location in the transfer operation request used to store the digital signature. It may be in the header, footer, or other specific data fields of the request. The standard digital signature data block is appended to the designated data segment of the transfer operation request according to a predetermined format and rules. For example, if the designated data segment is a specific data field, the standard digital signature data block can be written to the field in string or binary form. If the designated data segment is a specific data structure, the standard digital signature data block can be added as a child element of the data structure.

[0076] Specifically, a verification path can be constructed, which includes the storage location information of the standard digital signature data block, the user's public key information (used to verify the signature), hash algorithm information (used to recalculate the message digest), etc. The construction of the verification path is designed according to security requirements and verification process to ensure that the verification can be performed according to the correct steps and methods when verifying the signature. The transfer operation request with the standard digital signature data block and verification path is output as a digital signature with a complete verification path. In this way, in the subsequent signature verification process, the receiver can verify the digital signature according to the verification path to ensure the authenticity and integrity of the transfer operation request.

[0077] In this embodiment of the invention, fine-grained permission judgment is performed based on authoritative certified data already on the blockchain, and a digital signature mechanism is introduced to realize a secure closed loop in the shipping data flow process. At the same time, it realizes precise and dynamic management from identity authentication to operation authorization, effectively preventing unauthorized behavior by legitimate users. In addition, digital signatures signed by users' private keys are collected to strongly bind each flow operation to a specific identity, ensuring the non-repudiation and legal validity of the operation, and greatly improving the security compliance level and post-event traceability of the shipping document status flow process.

[0078] S7. Determine whether the digital signature is within the preset signature validity period.

[0079] If the digital signature is not within the preset signature validity period, then return to step S3 and terminate the user's execution of the document status flow of the target shipping data on the blockchain.

[0080] If the digital signature is within the preset signature validity period, then execute S8 to execute the document status flow of the target shipping data on the blockchain according to the preset shipping document state machine rules.

[0081] like Figure 3 As shown in this embodiment of the invention, the step of executing the document status transition of the target shipping data on the blockchain according to preset shipping document state machine rules includes: The shipping document lifecycle of the target shipping data is divided into multiple ordered document status stages; Determine the status operation permissions of different users at the corresponding document status stage on the blockchain; Based on the preset shipping document state machine rules and the state operation permissions, a stage transition certificate is generated for the target shipping data to undergo state transition. The target shipping data is status-transferred according to the stage transfer certificate, and the document transfer status of the target shipping data on the blockchain is updated according to the result of the status transfer.

[0082] In this embodiment of the invention, an on-chain smart contract is used to formulate a finite state machine flow protocol for shipping and trade documents. This protocol covers the on-chain flow of electronic bills of lading, electronic replacement orders, electronic warehouse receipts, and electronic letters of credit. For example, the maritime shipping process can be designed as a finite state machine, where different types of documents can only flow between specific roles. If verification fails after the flow, the state machine also allows for state rollback. The most important process in the smart contract is the exchange of bills of lading for delivery orders, where the carrier completes transportation, and a freight forwarder converts the bill of lading into a delivery order at the port, allowing for cargo pickup and transportation. Once the exchange process is confirmed on the smart contract, ownership is confirmed and cannot be reversed. The flowchart of the finite state machine flow protocol for shipping and trade documents is as follows: Figure 4 As shown.

[0083] In this embodiment of the invention, a comprehensive requirements analysis is conducted on the lifecycle of shipping documents for the target shipping data. This includes understanding the various activities, participating roles, and business rules involved in the entire process from the creation to the final completion of the shipping document. For example, shipping documents include stages such as creation, review, issuance, transportation, and delivery, each with different business requirements and operating procedures.

[0084] Based on the results of the requirements analysis, business process modeling tools or methods are used to divide the shipping document lifecycle into multiple ordered document status stages. Taking BPMN as an example, each stage can be represented by an activity, and the sequence flow can be used to represent the order between stages. For example, a "Create Document" activity can be created, and then connected to the "Review Document" activity through a sequence flow, and then connected to the "Issue Document" activity, and so on, forming an ordered sequence of stages.

[0085] Each predefined document status stage is defined in detail, including the stage name, input and output data, participating roles, business rules, etc. For example, in the "Review Documents" stage, the input is defined as the document data to be reviewed, the output is the review result (pass or fail), the participating role is the reviewer, and the business rule is that the reviewer must review according to specific review standards.

[0086] In detail, on the blockchain, different user roles are first defined. These roles can be determined based on the participants in the shipping document business process, such as shipper, consignee, shipping company, customs, etc. Each role has different business responsibilities and operational requirements. According to the division of document status stages and the business requirements of each stage, corresponding status operation permissions are assigned to each role. For example, in the "create document" stage, only the shipper may have the permission to create documents; in the "review document" stage, only the reviewer may have the permission to review documents. A role-based access control model can be used to implement permission allocation, associating roles with permissions.

[0087] The defined roles and permissions are stored on the blockchain. Due to the blockchain's immutable nature, the security and reliability of the permission information are ensured. Smart contracts can be used to manage this information, defining rules for querying and modifying permissions. When a user attempts to perform an operation at a specific document status stage, the blockchain system verifies the user's identity and permissions. By querying the permission information stored in the smart contract, it determines whether the user has the necessary permissions for the current stage. If the user has the permissions, the operation is allowed; otherwise, the request is rejected.

[0088] Specifically, information related to the status flow of target shipping data, including the current document status stage, operation content, operation time, and operator, can be obtained from data sources such as transaction records and user operation logs on the blockchain. The collected data is verified and processed according to pre-defined shipping document state machine rules. These rules define the conditions and processes for status flow; for example, the next stage can only proceed after a certain stage's approval. These rules determine whether the current operation meets the requirements for status flow. Simultaneously, based on previously determined status operation permissions, it is checked whether the operator has the authority to perform the corresponding operation at the current stage. If the operator lacks permission, a stage flow certificate cannot be generated.

[0089] If the operation conforms to the state machine rules and the operator has the necessary permissions, a stage transition certificate is generated using digital certificate generation technology. The certificate may contain information such as the current certificate status stage, operation content, operation time, and operator signature. The operator's signature can be generated using digital signature technology to ensure the authenticity and non-repudiation of the signature. The timestamp can be generated using a timestamp service to record the certificate's generation time. The generated stage transition certificate is stored on the blockchain. Due to the immutable nature of the blockchain, this ensures the security and reliability of the certificate and provides a basis for subsequent state transition verification.

[0090] Furthermore, in the flow of shipping documents, state machine execution technology is used to transition the document status of the target shipping data from one stage to another based on the information in the stage flow certificate; blockchain is a distributed ledger technology that stores data on multiple nodes and ensures data consistency and immutability through a consensus mechanism. Blockchain data update technology is the technology for modifying and updating data on the blockchain, and it needs to follow the consensus rules and transaction verification mechanism of the blockchain.

[0091] Specifically, the stage transition vouchers are verified. Verification includes checking whether the voucher format is correct, the signature is valid, and the timestamp is within a reasonable range. Only vouchers that pass verification can be used for state transition. Based on the information in the stage transition vouchers, state machine execution technology is used to transform the document status of the target shipping data. For example, if the voucher indicates that the current document status stage is "approved," the document status is changed from "under review" to "pending issuance." A blockchain transaction is constructed to record the document transition status update of the target shipping data. The transaction includes information such as the current document status, the basis for the status transition (stage transition voucher), and the operator. The constructed transaction is broadcast to various nodes in the blockchain network, and the nodes will verify the transaction, including verifying the transaction format, signature, and whether it conforms to consensus rules.

[0092] In this blockchain network, nodes reach a consensus through consensus mechanisms (such as proof-of-work, proof-of-stake, etc.) to determine whether to add the transaction to the blockchain. Once a consensus is reached, the transaction will be added to the blockchain, and the document flow status of the target shipping data will be updated. Due to the immutable nature of the blockchain, the updated status will be permanently recorded on the blockchain, and any node can query the latest document flow status.

[0093] In this embodiment of the invention, by verifying the timeliness of digital signatures, a crucial time security dimension is added to the shipping data flow operation, effectively preventing the risk of invalid operations in the long term due to private key leakage or malicious reuse, greatly enhancing the real-time security of business processes. At the same time, combined with preset smart contract rules to drive state transitions, it ensures that each state change simultaneously meets the three conditions of identity trustworthiness, permission compliance, and timeliness validity. This not only technically eliminates the erroneous execution of expired instructions and ensures strict synchronization between on-chain document status and real business progress, but also further enhances the automation, compliance, and risk resistance capabilities of the entire shipping blockchain system.

[0094] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0095] like Figure 5 The diagram shown is a functional block diagram of a shipping data transfer and processing device provided in an embodiment of the present invention.

[0096] This disclosure provides a shipping data transfer and processing apparatus, which corresponds one-to-one with the shipping data transfer and processing method described in the above embodiments. For example... Figure 5As shown, this shipping data transfer processing device 100 can be installed in an electronic device. According to its functions, the shipping data transfer processing device 100 includes an identity information extraction module 101, an identity information storage module 102, a transfer permission confirmation module 103, a digital signature generation module 104, and a document status transfer module 105. Detailed descriptions of each functional module are as follows: The identity information extraction module 101 is used to obtain a user's access request for target shipping data in a preset blockchain, and extract the access identity information corresponding to the user in the access request; The identity information storage module 102 is used to generate an identity identification certificate corresponding to the access identity information if the access identity information is in a pre-stored whitelist, and store the identity identification certificate and the access identity information as on-chain authentication data in the blockchain. The data transfer permission confirmation module 103 is used to determine whether the user has shipping data transfer permission based on the on-chain authentication data. The digital signature generation module 104 is used to collect the user's request for the transfer of the target shipping data if the user has the right to transfer shipping data, and to receive the digital signature generated by the user signing the transfer request. The document status transition module 105 is used to execute the document status transition of the target shipping data on the blockchain according to the preset shipping document status machine rules if the digital signature is within the preset signature validity period.

[0097] In one embodiment, when the identity information extraction module 101 extracts the access identity information corresponding to the user within the access request, it is used to: Parse the HTTP header fields of the access request, and determine the location of the field used to carry identity information from the HTTP header fields; Extract the corresponding user's identity token string from the field location; The identity token string is Base64Url decoded to obtain the token payload portion of the identity token string; Parse the JSON content of the token payload to obtain the user identifier, and use the user identifier as the user's access identity information.

[0098] In one embodiment, when the identity information storage module 102 generates the identity credential corresponding to the access identity information, it is used to: The corresponding credential type and encryption algorithm are determined based on the preset credential generation strategy, and the credential private key bound to the credential type is obtained. The identity hash value of the access identity information is encrypted using the asymmetric encryption algorithm in the encryption algorithm and the credential private key to obtain the credential digital signature; Generate a credential payload based on the user identifier in the access identity information and the preset access validity period; The voucher payload and the voucher digital signature are combined and encoded according to the preset voucher format to generate the original voucher string; The original credential string is encapsulated for security purposes to obtain an identity verification credential.

[0099] In one embodiment, when the identity information storage module 102 stores the identity certificate and the access identity information as on-chain authentication data in the blockchain, it is used to: The identity credential and the access identity information are encrypted using the user's public key, and the encryption result is stored in a preset data ontology area; Calculate the credential hash value of the identity identification credential and the identity hash value of the access identity information, and store the credential hash value, the identity hash value, and a preset timestamp into a preset metadata area; Generate on-chain data packets based on the data ontology area and the metadata area; Invoke a smart contract pre-deployed on the blockchain and select one or more target consensus nodes from the list of nodes on the blockchain according to a preset node selection strategy; The on-chain data packet is sent to the target consensus node via the smart contract; After receiving successful transmission notifications from more than two-thirds of the target consensus nodes within a preset time, the on-chain data packet is confirmed as the user's on-chain authentication data stored in the blockchain.

[0100] In one embodiment, when the data transfer permission confirmation module 103 performs the function of determining whether the user has shipping data transfer permission based on the on-chain authentication data, it is used to: The on-chain authentication data is processed to standardize its format, resulting in standardized on-chain authentication data. Extract the on-chain authentication identifier from the standardized on-chain authentication data; Invoke the preset permission policy engine, and query the corresponding permission rules from the blockchain according to the permission policy engine and the on-chain authentication identifier; The system analyzes the permission rules to determine if there are any permission entries for the transfer of the target shipping data. If the permission rule contains the flow operation permission entry, then the permission status of the flow operation permission entry is further determined: If the permission status of the data transfer operation permission entry is "allowed", then it is determined that the user has shipping data transfer permission. If the permission status of the data transfer operation permission entry is not allowed, it is determined that the user does not have shipping data transfer permission.

[0101] In one embodiment, when the digital signature generation module 104 generates a digital signature by receiving the user's signature on the transfer operation request, it is used to: The request content of the transfer operation request is hashed according to a preset hash algorithm to obtain the message digest corresponding to the transfer operation request; The message digest is encrypted using the user's private key to generate an initial digital signature data block.

[0102] The initial digital signature data block and its generation timestamp are structured and encapsulated to obtain a standard digital signature data block.

[0103] The standard digital signature data block is appended to the specified data segment of the transfer operation request to obtain a digital signature with a complete verification path.

[0104] In one embodiment, when the document status transition module 105 executes the document status transition of the target shipping data on the blockchain according to preset shipping document status machine rules, it is used to: The shipping document lifecycle of the target shipping data is divided into multiple ordered document status stages; Determine the status operation permissions of different users at the corresponding document status stage on the blockchain; Based on the preset shipping document state machine rules and the state operation permissions, a stage transition certificate is generated for the target shipping data to undergo state transition. The target shipping data is status-transferred according to the stage transfer certificate, and the document transfer status of the target shipping data on the blockchain is updated according to the result of the status transfer.

[0105] In this invention, the specific limitations of a shipping data transfer processing device can be found in the above-described limitations of a shipping data transfer processing method, and will not be repeated here. Each module in the aforementioned shipping data transfer processing device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0106] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 6 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When the computer program is executed by the processor, it implements the functions or steps of a shipping data flow processing method on the server side.

[0107] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 7 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it implements the functions or steps on the client side of a shipping data flow processing method.

[0108] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps: Obtain a user's access request for target shipping data within a preset blockchain, and extract the access identity information corresponding to the user from the access request; If the access identity information is in the pre-stored whitelist, an identity identifier credential corresponding to the access identity information is generated, and the identity identifier credential and the access identity information are stored in the blockchain as on-chain authentication data. Based on the on-chain authentication data, determine whether the user has the authority to transfer shipping data; If the user has shipping data transfer permissions, then the user's request for the transfer of the target shipping data is collected, and a digital signature generated by the user signing the transfer request is received. If the digital signature is within the preset signature validity period, the document status flow of the target shipping data is executed on the blockchain according to the preset shipping document state machine rules.

[0109] In the several embodiments provided by this invention, it should be understood that the disclosed devices and apparatuses can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.

[0110] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.

[0111] Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be embraced within the invention. No appended diagram markings in the claims should be construed as limiting the scope of the claims.

[0112] In some embodiments of this example, a computer-readable storage medium is provided, on which a computer program is stored, characterized in that the computer program, when executed by a processor, implements the steps of the method described in the above embodiments.

[0113] The readable storage medium of the present invention stores a computer program, which, when executed by a processor of an electronic device, can perform the following: Obtain a user's access request for target shipping data within a preset blockchain, and extract the access identity information corresponding to the user from the access request; If the access identity information is in the pre-stored whitelist, an identity identifier credential corresponding to the access identity information is generated, and the identity identifier credential and the access identity information are stored in the blockchain as on-chain authentication data. Based on the on-chain authentication data, determine whether the user has the authority to transfer shipping data; If the user has shipping data transfer permissions, then the user's request for the transfer of the target shipping data is collected, and a digital signature generated by the user signing the transfer request is received. If the digital signature is within the preset signature validity period, the document status flow of the target shipping data is executed on the blockchain according to the preset shipping document state machine rules.

[0114] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0115] Computer-readable storage media may also store at least one computer-executable program / instruction, such as computer-readable instructions. Computer-readable storage media include, but are not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Computer-readable storage media may include, for example, read-only memory (ROM), hard disk, flash memory, etc. For example, a non-transitory computer-readable storage medium may be connected to a computing device such as a computer, and then, when the computing device executes the computer-readable instructions stored on the computer-readable storage medium, the various methods described above can be performed.

[0116] In addition, the computer device may include (but is not limited to) a data bus, an input / output (I / O) bus, a display, and input / output devices (e.g., keyboard, mouse, speakers, etc.).

[0117] In one embodiment, the at least one computer-executable instruction may also be compiled into or comprise a software product / computer program product, wherein one or more computer-executable instructions are executed by a processor to perform the steps of the various functions and / or methods in the embodiments described herein.

[0118] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Furthermore, any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory.

[0119] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0120] In the embodiments provided in this disclosure, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0121] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

[0122] It should be noted that if any software tools or components not belonging to our company appear in the embodiments of this application, they are merely for illustrative purposes and do not represent actual use.

Claims

1. A shipping data flow processing method, characterized in that, The method includes: Obtain a user's access request for target shipping data within a preset blockchain, and extract the access identity information corresponding to the user from the access request; If the access identity information is in the pre-stored whitelist, an identity identifier credential corresponding to the access identity information is generated, and the identity identifier credential and the access identity information are stored in the blockchain as on-chain authentication data. Based on the on-chain authentication data, determine whether the user has the authority to transfer shipping data; If the user has shipping data transfer permissions, then the user's request for the transfer of the target shipping data is collected, and a digital signature generated by the user signing the transfer request is received. If the digital signature is within the preset signature validity period, the document status flow of the target shipping data is executed on the blockchain according to the preset shipping document state machine rules.

2. The shipping data flow processing method as described in claim 1, characterized in that, Extracting the access identity information corresponding to the user from the access request includes: Parse the HTTP header fields of the access request, and determine the location of the field used to carry identity information from the HTTP header fields; Extract the corresponding user's identity token string from the field location; The identity token string is Base64Url decoded to obtain the token payload portion of the identity token string; Parse the JSON content of the token payload to obtain the user identifier, and use the user identifier as the user's access identity information.

3. The shipping data flow processing method as described in claim 1, characterized in that, The generation of the identity credential corresponding to the access identity information includes: The corresponding credential type and encryption algorithm are determined based on the preset credential generation strategy, and the credential private key bound to the credential type is obtained. The identity hash value of the access identity information is encrypted using the asymmetric encryption algorithm in the encryption algorithm and the credential private key to obtain the credential digital signature; Generate a credential payload based on the user identifier in the access identity information and the preset access validity period; The voucher payload and the voucher digital signature are combined and encoded according to the preset voucher format to generate the original voucher string; The original credential string is encapsulated for security purposes to obtain an identity verification credential.

4. The shipping data flow processing method as described in claim 1, characterized in that, The step of storing the identity credential and the access identity information as on-chain authentication data in the blockchain includes: The identity credential and the access identity information are encrypted using the user's public key, and the encryption result is stored in a preset data ontology area; Calculate the credential hash value of the identity identification credential and the identity hash value of the access identity information, and store the credential hash value, the identity hash value, and a preset timestamp into a preset metadata area; Generate on-chain data packets based on the data ontology area and the metadata area; Invoke a smart contract pre-deployed on the blockchain and select one or more target consensus nodes from the list of nodes on the blockchain according to a preset node selection strategy; The on-chain data packet is sent to the target consensus node via the smart contract; After receiving successful transmission notifications from more than two-thirds of the target consensus nodes within a preset time, the on-chain data packet is confirmed as the user's on-chain authentication data stored in the blockchain.

5. The shipping data flow processing method as described in claim 1, characterized in that, The step of determining whether the user has shipping data transfer permissions based on the on-chain authentication data includes: The on-chain authentication data is processed to standardize its format, resulting in standardized on-chain authentication data. Extract the on-chain authentication identifier from the standardized on-chain authentication data; Invoke the preset permission policy engine, and query the corresponding permission rules from the blockchain according to the permission policy engine and the on-chain authentication identifier; The system analyzes the permission rules to determine if there are any permission entries for the transfer of the target shipping data. If the permission rule contains the flow operation permission entry, then the permission status of the flow operation permission entry is further determined: If the permission status of the data transfer operation permission entry is "allowed", then it is determined that the user has shipping data transfer permission. If the permission status of the data transfer operation permission entry is not allowed, it is determined that the user does not have shipping data transfer permission.

6. The shipping data flow processing method as described in claim 1, characterized in that, The step of receiving the digital signature generated by the user's signing of the transfer operation request includes: The request content of the transfer operation request is hashed according to a preset hash algorithm to obtain the message digest corresponding to the transfer operation request; The message digest is encrypted using the user's private key to generate an initial digital signature data block. The initial digital signature data block and its generation timestamp are structured and encapsulated to obtain a standard digital signature data block. The standard digital signature data block is appended to the specified data segment of the transfer operation request to obtain a digital signature with a complete verification path.

7. The shipping data flow processing method as described in claim 1, characterized in that, The step of executing the document status transition of the target shipping data on the blockchain according to preset shipping document state machine rules includes: The shipping document lifecycle of the target shipping data is divided into multiple ordered document status stages; Determine the status operation permissions of different users at the corresponding document status stage on the blockchain; Based on the preset shipping document state machine rules and the state operation permissions, a stage transition certificate is generated for the target shipping data to undergo state transition. The target shipping data is status-transferred according to the stage transfer certificate, and the document transfer status of the target shipping data on the blockchain is updated according to the result of the status transfer.

8. A shipping data transfer and processing device, characterized in that, The device includes: The identity information extraction module is used to obtain a user's access request for target shipping data within a preset blockchain, and extract the access identity information corresponding to the user within the access request; The identity information storage module is used to generate an identity identifier credential corresponding to the access identity information if the access identity information is in a pre-stored whitelist, and store the identity identifier credential and the access identity information as on-chain authentication data in the blockchain. The data transfer permission confirmation module is used to determine whether the user has the permission to transfer shipping data based on the on-chain authentication data. The digital signature generation module is used to collect the user's request for the transfer of the target shipping data if the user has the authority to transfer shipping data, and to receive the digital signature generated by the user signing the transfer request. The document status transition module is used to execute the document status transition of the target shipping data on the blockchain according to the preset shipping document status machine rules if the digital signature is within the preset signature validity period.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the shipping data transfer processing method as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the shipping data flow processing method as described in any one of claims 1 to 7.