Computer spare and accessory part manufacturing traceability management system

By setting up a secure storage area and a dynamic identity value iteration system inside the parts, the problem of easy copying of external identifiers is solved, thus achieving security and accuracy in the traceability management of computer parts and reducing the risk of counterfeiting and verification costs.

CN121961597APending Publication Date: 2026-05-01GUANGZHOU QILI COMPUTER EQUIP MFG CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGZHOU QILI COMPUTER EQUIP MFG CO LTD
Filing Date
2026-01-12
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In the current traceability management of computer parts, externally readable identifiers are easily copied, replaced, or relabeled, leading to counterfeit parts using genuine traceability records, making it difficult to prevent counterfeiting. Furthermore, the verification end struggles to quickly locate and process mismatches in all stages of the record process.

Method used

A secure storage area is set up inside the parts and components. The dynamic identity value is updated in multiple manufacturing stages through the identity iteration module. The chain record module is used to associate the data of each stage with the dynamic identity value to form an immutable ledger. The consistency is verified by the online verification module. Combined with the physical unclonable function and challenge-response authentication, the accuracy and security of the verification are ensured.

Benefits of technology

It effectively prevents external identifiers from being copied or replaced, ensures the integrity and consistency of manufacturing records, reduces verification discrepancies, lowers the risk of misjudgment, supports rapid location of abnormal locations, and reduces the cost of evidence storage and verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121961597A_ABST
    Figure CN121961597A_ABST
Patent Text Reader

Abstract

The invention discloses a computer part manufacturing traceability management system, and relates to the technical field of computer and information security. Identity anchor points are arranged in a security storage area in a part body, and dynamic identity values are iteratively updated in a plurality of manufacturing links; the verification action depends on the consistency of a read value in the device and an account book recalculation result, so that the attack of only transferring an external identifier is converted into a high-threshold attack which must simultaneously break through the consistency of internal storage of the device and an iterative chain; besides, the digital signature of the link record covers a field set such as a sequence association abstract, a current dynamic identity value, a link identifier, normalized link data, a timestamp and the like, so that the difference is directly exposed in the signature verification stage when any field is replaced or rearranged, and double constraints are formed by the digital signature and a front-back reference relationship of a sequence association abstract chain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer and information security technology, and in particular to a traceability management system for the manufacturing of computer parts. Background Technology

[0002] Current traceability management solutions for computer components (such as high-value integrated circuit chips) commonly involve assigning a unique, machine-readable identifier, such as a serial number, QR code, RFID / NFC, to the component or its packaging. Information on the source of materials, production batches, test parameters, circulation, and delivery is then recorded in the Manufacturing Execution System or in storage media with tamper-proof features. Some solutions also propose using immutable ledgers such as blockchain to record key events in order to improve data integrity and auditability.

[0003] However, in practical applications, the reliability of digital records is not necessarily equivalent to the authenticity of physical entities. When the system mainly relies on externally readable identifiers for traceability, if the identifier is copied, replaced, or used for other devices through relabeling, the inspector may still obtain a seemingly complete and consistent historical record, thus allowing devices of unknown origin or with inconsistent performance to pass verification at both the appearance and data levels. In addition, counterfeiters can make it difficult to identify the appearance identifiers through conventional visual inspection by removing the original identifiers and relabeling them.

[0004] To address the aforementioned issues, some existing technologies employ methods to enhance the anti-tampering / anti-transfer capabilities of the identification carrier, such as using tamper-proof labels and embedded electronic tags, as well as introducing multi-dimensional identification at key nodes in the supply chain, including appearance / packaging consistency and comparison of test data. In addition, some solutions propose using chip-level hardware fingerprints, such as PUF, to establish an unclonable association between physical devices and digital records. However, these solutions still face engineering challenges in terms of cost, deployment complexity, and cross-node collaboration. Summary of the Invention

[0005] In view of the aforementioned existing problems, the present invention is proposed.

[0006] This invention provides a computer parts manufacturing traceability management system that solves the problem that while existing serial number ledger traceability can prevent tampering, it is difficult to prevent the transfer and falsification of identifiers.

[0007] To solve the above-mentioned technical problems, the present invention provides the following technical solution: This invention provides a computer parts manufacturing traceability management system, including a traceability server set up at the manufacturing end, multiple manufacturing nodes connected to equipment in each manufacturing stage, and verification nodes set up downstream of the supply chain; The components have a secure storage area that allows for additional writing but not erasure; The system includes: The identity iteration module is used to read the previous dynamic identity value from the secure storage area in at least two sequential manufacturing stages, obtain the current stage data, calculate the current dynamic identity value according to a predetermined cryptographic one-way rule, and append it to the secure storage area. The chained record module is used to write the data of each link and the corresponding dynamic identity value and their sequential association summary into an immutable ledger; The online verification module is used to recalculate the verification identity value according to the rules based on the data of each link in the ledger when a verification request is received, and compare it with the current dynamic identity value read from the target part to output a consistency result.

[0008] As a preferred embodiment of the computer parts manufacturing traceability management system described in this invention, the cryptographic one-way rule is as follows: after deterministically concatenating and normalizing the previous dynamic identity value with the current data, a hash operation or message authentication code operation is performed to obtain the current dynamic identity value, and the normalization code includes at least the field order and length convention. The digital signature of each stage record is used to sign the set of fields associated with the sequential association digest as a whole. The set of fields includes at least the sequential association digest of the previous stage record, the current dynamic identity value, the stage identifier, the normalized stage data, and the timestamp. During consistency verification, the verification node performs signature verification and comparison on the complete set of fields corresponding to the signature, so that when any field is replaced, deleted, or split and reassembled, the difference is exposed during the signature verification or digest chain verification stage.

[0009] As a preferred embodiment of the computer parts manufacturing traceability management system described in this invention, the secure storage area includes multiple sequentially numbered append write slots, allowing only the next empty slot to be written at a time while simultaneously writing a completion flag, and prohibiting overwriting or erasing already written slots.

[0010] As a preferred embodiment of the computer parts manufacturing traceability management system described in this invention, the read interface of the secure storage area is protected by access control, and the verification node is only allowed to read the current dynamic identity value after passing challenge-response authentication.

[0011] As a preferred embodiment of the computer component manufacturing traceability management system of the present invention, wherein: the at least two manufacturing stages include a wafer testing stage, and the stage data includes at least wafer coordinate information and the encoding of electrical performance parameters measured at that coordinate.

[0012] As a preferred embodiment of the computer component manufacturing traceability management system described in this invention, the at least two manufacturing stages further include a packaging stage and a final testing stage; the stage data of the packaging stage includes the packaging equipment identifier and the packaging batch number; the stage data of the final testing stage includes the test result code of key performance indicators.

[0013] As a preferred embodiment of the computer parts manufacturing traceability management system described in this invention, the immutable ledger is a blockchain network or a distributed database, and each record includes at least: the search key of the target part, the current dynamic identity value, the sequential association summary of the previous record, the timestamp, and the digital signature of the manufacturing node. When compressing and storing evidence by batch or time window, the order of records in the ledger is used as the leaf arrangement order. Records at each stage are serialized at the record level according to a fixed field order and field length prefix rule to obtain a record normalization result. The record normalization result is calculated as a leaf summary, and adjacent leaves are merged layer by layer to obtain a unique root value. When the number of leaves does not meet the requirements for pair merging, a pre-agreed completion method is used to participate in the merging. The root value and the corresponding batch or time window information can be written to the chain or anchor area, and the root value can be jointly signed by multiple nodes.

[0014] As a preferred embodiment of the computer parts manufacturing traceability management system of the present invention, the online verification module uses the current dynamic identity value or its summary as the search key to obtain the full series of process records of the target parts; when no results are found or the sequential association summary chain is broken, inconsistent results are output and the broken process number is indicated; wherein, the sequential association summary chain is a chain formed by sequential association summaries of adjacent process records according to the previous and next reference relationship.

[0015] As a preferred embodiment of the computer parts manufacturing traceability management system described in this invention, the parts integrate physically unclonable functions, and the identity iteration module also incorporates the response data or a summary of the physically unclonable functions when calculating the current dynamic identity value.

[0016] As a preferred embodiment of the computer parts manufacturing traceability management system described in this invention, the system further includes an audit voucher module, which generates a digital audit voucher containing a target parts retrieval key, a final verification identity value, a summary chain root value, and a corresponding signature set when the parts are consistent, and generates an anomaly report containing a broken link number and an evidence summary when the parts are inconsistent.

[0017] Through the above technical solution, the present invention can achieve at least the following beneficial effects: To address the issue that counterfeit parts can use genuine traceability records because external serialized identifiers are easily copied, replaced, or relabeled, the system places the identity anchor point in a secure storage area inside the component itself and iteratively updates the dynamic identity value at multiple manufacturing stages. This makes the verification action dependent on the consistency between the value read from the device and the ledger recalculation result, thus transforming an attack that only transfers the external identifier into a high-threshold attack that must simultaneously break through the consistency of the device's internal storage and the iteration chain.

[0018] To address the issue that manufacturing process records may pass surface consistency checks even if they are partially replaced, deleted, or split and reassembled, the digital signature of the process record covers a set of fields including the previous sequential association summary, the current dynamic identity value, the process identifier, the normalized process data, and the timestamp. This ensures that any field replacement or rearrangement directly exposes the differences during the signature verification stage and forms a dual constraint with the preceding and following reference relationships of the sequential association summary chain.

[0019] To address the issue of inconsistent data serialization methods used by different devices and software for the same process, which can lead to recalculation failures or difficulties in resolving disputes, the system adopts a structured set of fields for process data and performs normalized encoding. This clarifies the field order, field length expression, and character and numerical encoding standards, ensuring that the data written by the manufacturing end and the recalculation by the verification end are consistent at the byte level, thereby reducing verification discrepancies caused by encoding differences.

[0020] To address the issue of difficulty in distinguishing between repeated writes / uploads in the same stage due to replay or rollback of the dynamic identity chain, the system will add write slots and completion flags to the write process constraints, binding the dynamic identity value to the write order of the secure storage area. When there is a situation that does not conform to the slot advancement rules or the completion flag status is inconsistent, the in-device read and ledger recalculation cannot be completed simultaneously, thus exposing anomalies during the consistency verification stage.

[0021] To address the challenges of quickly locating all records of the target component at the verification end, and the potential for mismatches when multiple candidate record sequences exist, the system uses the current dynamic identity value or its summary as the retrieval key to create an index. It also performs summary chain continuity and signature validity filtering on candidate record sequences, thus forming a closed loop between the retrieval and verification phases and reducing the risk of misjudgment due to record mismatches.

[0022] To address the increased costs of evidence storage and verification resulting from the growing number of records in the supply chain, the system maintains the ability to locate breaks in the sequentially associated summary chain while introducing root value anchoring for batches or time windows and joint signatures from multiple nodes. This enables the verification side to quickly verify the evidence through the root value and proof path when needed, and retains a traceable chain of evidence for abnormal break locations. Attached Figure Description

[0023] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation on the scope of this application.

[0024] Figure 1 This is a framework diagram of a computer parts manufacturing traceability management system as described in this embodiment. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0026] All terms used in this application (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0027] Example 1: like Figure 1 As shown, this embodiment proposes a computer parts manufacturing traceability management system, including a traceability server set up at the manufacturing end, multiple manufacturing nodes connected to equipment in each manufacturing stage, and verification nodes set up downstream of the supply chain. In this embodiment, the traceability server maintains the registration information, certificate chain materials, and ledger access policies for manufacturing and verification nodes, and uniformly publishes the process identifiers and field list versions for each manufacturing process. A manufacturing node is a computing unit connected to the equipment in the manufacturing process; process data is generated by the equipment at the corresponding workstation and then collected and packaged by the manufacturing node before being written into the ledger. A verification node is a downstream verification terminal in the supply chain; verification requests are initiated by the verification node and carry the reading results and request time information of the target component. A secure communication channel with bidirectional authentication is used between the traceability server and the manufacturing nodes, and between the traceability server and the verification nodes. When communication is interrupted, the manufacturing node locally caches the process records to be written. The cache duration is a default of 24 hours, adjustable from 1 hour to 168 hours. Writing is rejected and abnormal status information is retained after the cache is full or expires.

[0028] The components have a secure storage area that allows for additional writing but not erasure; The secure storage area is located within the component itself on a non-volatile storage medium. This area is divided into a storage region for dynamic identity values ​​and a storage region for status flags. Writing to the secure storage area is done append-only, and the written content remains in an indelible state. The secure storage area provides both read and write interfaces. The write interface is only open when the authorized workstation in the manufacturing process is in a write-enabled state; write requests are rejected when write-enabled is disabled, and the stored content remains unchanged.

[0029] Specifically, the append-only write capability of the secure storage area allows writing only once to a predefined unwritten area, and the content remains indelible and cannot be written back after the write operation is completed. The write enable state is triggered by the authorized workstation and automatically deactivates upon leaving the authorized workstation. The enable duration is a default implementation parameter of 10 seconds, adjustable from 1 second to 120 seconds. Furthermore, when the secure storage area is in an unwritten state and the previous dynamic identity value needs to be read, the previous dynamic identity value is taken as a preset initialization constant byte string. The length of the constant byte string is consistent with the current dynamic identity value write bit width and consists of all zero bits.

[0030] The system includes: The identity iteration module is used to read the previous dynamic identity value from the secure storage area, obtain the current stage data, calculate the current dynamic identity value according to the predetermined cryptographic one-way rules, and append it to the secure storage area in at least two sequential manufacturing stages. The chained record module is used to write the data of each link and the corresponding dynamic identity value and their sequential association summary into an immutable ledger; For example, an immutable ledger is a set of records that are appended only; any written record remains unoverwriteable on the ledger side. A sequential association digest is a summary field used to bind the order relationship between records in adjacent stages. Its generation depends on the sequential association digest of the previous stage record and the record normalization result of the current stage record, allowing differences in record insertion, deletion, or rearrangement to be exposed during subsequent verification. Similarly, the writing order of stage records follows the manufacturing stage order. Before writing a record in its own stage, the manufacturing node completes an existence check and a digest chain connection check of the previous stage record. If the connection fails, the writing to this stage is stopped and the node remains in a pending state.

[0031] The online verification module is used to recalculate the verification identity value according to the rules based on the data of each link in the ledger when a verification request is received, and compare it with the current dynamic identity value read from the target part to output a consistency result. Furthermore, the verification request must include at least the reading result of the target component, the verification node identifier, and the request timestamp, which is recorded in milliseconds. The timestamp precision is 1 ms by default, and the adjustable range is 1 ms to 1000 ms. Optionally, the online verification module performs deduplication processing on duplicate verification requests for the same target component within a short period of time. The deduplication window is 5 s by default, and the adjustable range is 1 s to 300 s. Duplicate requests within the window return the previous consistent result and record the number of repetitions.

[0032] In this embodiment, the cryptographic one-way rule is: after deterministically concatenating and normalizing the previous dynamic identity value with the current data, a hash operation or message authentication code operation is performed to obtain the current dynamic identity value, and the normalization encoding includes at least the field order and length convention. In this embodiment, the output of the hash operation and message authentication code operation is a fixed-length bit string. The dynamic identity value is written with a default bit width of 128 bits, adjustable from 64 bits to 256 bits, consistent with the capacity constraint of the secure storage area. The truncation rule is fixed in the system parameters to take either the first L bits or the last L bits of the output bit string and maintain consistency throughout the process, avoiding inconsistencies between the manufacturing and verification ends due to different truncation standards. Furthermore, the process identifier field is a label indicating the category of the manufacturing process, and its value is published by the traceability server and remains consistent between the manufacturing and verification nodes. The slot number is the sequence number field for adding a slot to the secure storage area, and its value is determined by the current writing position in the secure storage area and, together with the completion flag, determines the next slot that can be written. Similarly, the key derivation base key for the message authentication code operation corresponds to the device key material in the secure storage area. The device key material is confidential material that can only be accessed within the secure storage area during authentication and operation. The verification material is the public verification material or certificate chain material corresponding to the device key material. The verification node uses the verification material to complete response verification and signature verification.

[0033] The process data is normalized and encoded using a structured set of fields, which includes at least a process identifier field, a data version field, a data source field, and a business data field. During normalization, each field is arranged in a predetermined order and converted into a byte sequence using a defined encoding method. Before concatenation, each field has its corresponding field identifier and length information written into it. Missing fields are encoded as empty fields while maintaining their original order. String fields use a unified character encoding and undergo normalization processing before encoding. Numerical fields use a unified endianness and fixed format encoding. Time information included in the process data is encoded in a unified format and incorporated into the concatenation sequence.

[0034] The digital signature of each stage record is signed as a whole with the set of fields associated with the sequential association digest. The set of fields includes at least the sequential association digest of the previous stage record, the current dynamic identity value, the stage identifier, the normalized stage data, and the timestamp. During consistency verification, the verification node performs signature verification and comparison on the complete set of fields corresponding to the signature. This ensures that if any field is replaced, deleted, or split and reassembled, the difference is exposed during the signature verification or digest chain verification stage, thereby reducing the replaceable space caused by signing only partial fields. In one implementation, the cryptographic one-way rule can be implemented at the manufacturing stage number... The manufacturing nodes are implemented according to the following process, enabling the verification nodes to recalculate and compare based on the ledger records in the same order according to the same rules. The specific process is as follows: Step a, construct domain-separated and normalizable input loads: The manufacturing node reads the previous dynamic identity value from the secure storage area and obtains the corresponding slot number for this write from the append write slot in the secure storage area. It then normalizes and encodes the process data for this stage according to the field order and length convention to form a payload for unidirectional computation. , in, Indicates the step number as The input payload byte string at that time Indicates the step number as Separate label for the link identifier field. Indicates the step number as The secure storage area is appended with the slot number. Indicates that the process is marked as Data on the process under constraints The byte string obtained by performing normalization encoding Indicates the step number is The process data, This indicates a deterministic concatenation operation; in, Normalized encoding can employ a combination of a field list and a fixed-length / variable-length prefix: the field order is determined by... The corresponding field list is fixed. Fixed-length fields use fixed byte width and fixed endianness, while variable-length fields are written with a length prefix before the field value. String fields use a unified character set and case rules, and numeric fields use a unified unit and rounding rules. This ensures that data from the same stage receives the same encoding result at different nodes, while also... Implement domain separation to prevent different stages from generating the same identity iterative input for the same byte string.

[0035] Step b, dynamic identity value calculation based on hash chain: In the hash chain implementation, the current dynamic identity value is calculated unidirectionally from the previous dynamic identity value and the payload, and the result is appended to a slot in the secure storage area. : , in, Indicates the step number is The current dynamic identity value, Indicates the step number is The previous dynamic identity value, Indicates the step number is The input payload byte string, This represents a hash operation. This indicates that the bit width of the operation output is [value missing]. truncated mapping, Indicates the bit width of the dynamic identity value written to the secure storage area; In this implementation, slot number Included Combined with the append write constraint that only allows writing to the next empty slot at a time, this makes the same stage identifier... The replay load will get different results when the slot numbers are inconsistent. This transforms replaying the same process into inconsistent identity values ​​caused by slot mismatch.

[0036] Step c, calculate the dynamic identity value based on the MAC key: In the keyed implementation, the manufacturing node performs message authentication code calculation on the payload, and the key is derived according to the link and slot, making it difficult to generate a subsequent legitimate dynamic identity value on another component even after reading the current dynamic identity value and ledger data. Its calculation is divided into two parts: key derivation and MAC operation. Key derivation: , in, Indicates the step number is MAC session key, This indicates the key derivation algorithm. This represents the key derived from the base key. Indicates the step number is Separate label for the link identifier field. Indicates the step number is The secure storage area is appended with the slot number. This indicates a deterministic concatenation operation; Dynamic identity value calculation based on derived keys: , in, Indicates the step number is The current dynamic identity value, Indicates the step number is MAC session key, Indicated by key Calculate the authentication code for the input message. Indicates the step number is The previous dynamic identity value, Indicates the step number is The input payload byte string, This indicates that the bit width of the operation output is [value missing]. truncated mapping, Indicates the bit width of the dynamic identity value written to the secure storage area; in, The system can be deployed from one of two sources without changing the aforementioned architecture: First, the root key from the secure storage area, which supports closed-loop derivation and natural rotation by slot at the manufacturing end. Second, when the component integrates a physically unclonable function, the response data of the physically unclonable function or its digest participates in the formation of the base key. This ensures that when the secure storage area content is copied to another component, the difference in the response of the physically unclonable function leads to inconsistent derived keys, thereby suppressing chain forgery of copying and writing after reading.

[0037] Step d, the relationship between truncation bit width and false positive rate: When the hash or message authentication code output bit width is greater than the available bit width in the secure storage area Map the output to a fixed value Bit-written value; if the attacker's attempts under unknown manufacturing key or unknown previous dynamic identity value are considered to be approximately uniformly distributed, then the upper bound of the probability of a single false acceptance is expressed by the following formula: , in, This represents the upper bound of the probability of a single false acceptance by the online verification module for a forged dynamic identity value. Indicates the bit width of the dynamic identity value written to the secure storage area; Under this constraint, the cutoff position is determined by... Fixed definition: take the output before After bitwise OR operation, the output will be... The bit width is kept consistent in the system parameters, ensuring that the manufacturing and verification ends obtain the same verification result for the same ledger data and the same read value. The value of is constrained by both the upper bound of the acceptable probability of false acceptance and the capacity of the safe storage area.

[0038] Furthermore, the upper bound of the probability of false acceptance is used to constrain the value of the dynamic identity value's bit width. The upper bound, as an implementation parameter, defaults to no more than 0.000001, with an adjustable range of 0.0000000001 to 0.0001. When the target upper bound is stricter, the dynamic identity value's bit width increases accordingly; when the secure storage area capacity is limited, the target upper bound is relaxed accordingly and fixed in the system parameters. Optionally, the normalization processing of string fields in normalized encoding includes case uniformity and whitespace character regularization. The unit uniformity and rounding rules for numeric fields, as implementation parameters, default to rounding to a predetermined number of decimal places, with an adjustable range of 0 to 6 decimal places, and the rounding caliber corresponding to the identifier in the same stage remains consistent.

[0039] Specifically, this one-way rule organizes the computation path around the one-way iteration of the previous dynamic identity value and the current stage data. It introduces domain separation through stage identifiers, enabling different manufacturing stages to produce distinguishable encoding results at the input level, reducing confusion caused by cross-stage data collisions. Normalized encoding, with fixed field order and length conventions as its core, converges the serialization differences of the same stage data across different devices and implementations into a consistent byte string, reducing verification failures caused by encoding inconsistencies. Appending the slot number to the payload binds identity iteration to the sequential write constraint of the secure storage area, suppressing replay within the same stage from the input side. The implementation can use a hash chain to reduce the key management burden on the manufacturing end, or a message authentication code with a key to enhance resistance to copying after reading. The key is derived by stage and slot to form a natural rotation, avoiding the risk accumulation caused by long-term use of the same key. When the output is limited by storage bit width, a fixed truncation rule and bit width constraint reduce the probability of false acceptance at the verification end as the bit width increases, while maintaining a consistent computation path between the manufacturing and verification ends.

[0040] In this embodiment, the secure storage area includes multiple sequentially numbered append write slots. Each time, only the next empty slot is allowed to be written, and a completion flag is written at the same time. Slots that have already been written are prohibited from being overwritten or erased. The appended write slots correspond one-to-one according to the manufacturing process. Each slot contains a dynamic identity value storage field and a completion flag field. The write process includes three steps: determining if the target slot is empty, writing the dynamic identity value, and writing the completion flag. When the completion flag is not written, the slot is considered to be in an incomplete write state and will not be used as the current dynamic identity value in subsequent reads. When the completion flag has been written, the slot is considered a valid slot, and subsequent write processes skip this slot and point to the next empty slot.

[0041] Specifically, empty slots are determined based on the completion flag field. If the completion flag is in an unwritten state, the slot is considered empty and writing is allowed. If the completion flag is in a written state, the slot is considered occupied and writing is prohibited. If the determination fails or the state is uncertain, the manufacturing node performs repeated read confirmations on the same slot. The number of repeated reads is a default parameter of 3 times, adjustable from 1 to 10 times. Furthermore, if a power outage or communication interruption occurs during the writing process, whether the completion flag is written is used as the final consistency criterion. Slots without a completion flag are considered incomplete in subsequent sessions and the writing process can be re-executed. Slots with a completion flag are considered valid in subsequent sessions and overwriting is prohibited.

[0042] In this embodiment, the read interface of the secure storage area is protected by access control. The verification node is only allowed to read the current dynamic identity value after passing the challenge-response authentication. The challenge-response authentication process involves the verification node sending challenge data to the target component. The target component generates response data based on the device key material in its secure storage area and returns it to the verification node. The verification node then verifies the response based on the verification material corresponding to the device key material. The challenge data contains a random component and is bound to the session state; repeated use of the same challenge data results in rejection of the response from the target component. In case of authentication failure, the component does not output its current dynamic identity value and does not change the contents of its secure storage area. In case of successful authentication, the component outputs its current dynamic identity value or its digest and maintains a valid session state until the session ends.

[0043] Similarly, the random component length of the challenge data is 128 bits by default, with an adjustable range of 64 bits to 256 bits, and is bound together with the verification node identifier in the verification request. The session state is an authentication context flag maintained on the component side during a challenge-response interaction, and the effective session duration is 30 seconds by default, with an adjustable range of 5 seconds to 300 seconds. Furthermore, the determination of repeated use of the same challenge data is based on the set of challenge identifiers already processed within the session. The set capacity is 256 entries by default, with an adjustable range of 32 to 4096 entries. If the capacity is exceeded, new challenges are rejected and the current dynamic identity value is not output.

[0044] In this embodiment, at least two manufacturing stages include a wafer testing stage, and the stage data includes at least wafer coordinate information and the encoding of electrical performance parameters measured at that coordinate. Wafer coordinate information is represented by a combination of wafer number and chip coordinates. Chip coordinates consist of row and column coordinates or equivalent two-dimensional positioning information and are consistent with the chip mapping table output by the wafer testing equipment. Electrical performance parameter codes are formed by the test results collected by the wafer testing equipment at the corresponding coordinates. Before generating codes, the test results undergo data cleaning and format standardization. The cleaning rules include removing obviously missing test records, removing invalid placeholder records returned by the equipment, and retaining the original order of valid test items.

[0045] Furthermore, wafer numbers are assigned by the wafer testing equipment within the test batch and correspond to the test batch number. The alignment of the die coordinates with the die mapping table is based on the coordinate reference output by the equipment and remains consistent within the same batch. The units and dimensions of the electrical performance parameter encoding are fixed according to the measurement configuration of the testing equipment, and the format before encoding is unified, including unit conversion and default value handling. For example, the threshold for judging obviously missing test records is set as an implementation parameter with a default missing test ratio of more than 5% for key test items, with an adjustable range of 1% to 20%. Records judged as obviously missing tests are included in the encoding as empty fields, and the field order is retained unchanged. The judgment of invalid placeholder records is based on the invalid flag field returned by the equipment, which is a predefined status field returned by the equipment.

[0046] In this embodiment, at least two manufacturing stages also include a packaging stage and a final testing stage; the packaging stage data includes the packaging equipment identifier and packaging batch number; the final testing stage data includes the test result codes of key performance indicators. The packaging equipment identifier is generated from the packaging equipment's device identity information and bound to the device's digital certificate. The packaging batch number is generated by the packaging execution system during material feeding and remains unique within that batch. The test result code in the final testing stage is generated from the set of test items output by the final testing equipment. The set of test items includes at least the pass / fail status and the classification results of key performance indicators. When the testing equipment outputs multiple retest results, the test result code selects the valid results of the same indicator according to a predetermined priority rule and maintains the consistency of the order of each indicator.

[0047] Specifically, the device identity information of the packaging equipment is a combination of the device serial number and the device certificate identifier. The device digital certificate is constrained by the certificate chain material recognized by the traceability server and is consistent with the signature identity of the manufacturing node. The packaging batch number remains unique within the same packaging equipment and the same feeding cycle. Furthermore, the predetermined priority rule for multiple retest results is fixed in the system parameters as either taking the latest valid result or the most unfavorable result, and the same caliber is used for all key performance indicators. The determination of a valid result is based on the pass or fail status output by the test equipment and the valid indicator mark field. When there is no valid result, it is coded as an empty field and its original order is maintained in the ledger record.

[0048] In this embodiment, the immutable ledger is a blockchain network or a distributed database, and each record at the stage includes at least: the search key of the target component, the current dynamic identity value, the sequential association summary of the previous record, the timestamp, and the digital signature of the manufacturing node. In this embodiment, the retrieval key is an identifier field used to locate the corresponding record sequence of the target component in the immutable ledger. The retrieval key is taken from the current dynamic identity value output by the target component in the verification session or its digest, and an index is built on the ledger side. When the digest is used as the retrieval key, the digest operation method is consistent with the hash method in the cryptographic one-way rule and is fixed in the system parameters. Furthermore, when the manufacturing node writes the record, it simultaneously writes the retrieval key and the current dynamic identity value, so that the verification node can complete the location and recalculation with only the read result.

[0049] When generating a process record, the manufacturing node forms the data to be signed from the set of fields of the process record and generates a digital signature. The set of fields includes a search key, the current dynamic identity value or its digest, the process identifier, the process data, the digest of the previous process record, and a timestamp. The digital signature of the manufacturing node is bound to its digital certificate, and the verification node performs signature verification and verifies the validity of the certificate based on the certificate chain. The immutable ledger stores process records in an append-only manner, and records already written to the ledger remain in an overwriteable state. The ledger provides interfaces for querying by search key, querying by time range, and tracing back by digest chain relationship.

[0050] Furthermore, the record sequence returned by the search key is based on the ledger storage order and includes a summary field for chain verification between adjacent records, indicating the previous sequential association. When a record is missing or the returned order is inconsistent during the query, the online verification module determines the sequence as unusable and outputs an inconsistent result. Optionally, the time window length for time range queries is set as an implementation parameter, defaulting to 24 hours, with an adjustable range of 1 hour to 720 hours. The time window boundaries are based on the timestamps of the process records and maintain consistency using a closed interval.

[0051] When compressing and storing evidence by batch or time window, the order of records in the ledger is used as the leaf arrangement order. Records at each stage are serialized at the record level according to a fixed field order and field length prefix rule to obtain the record normalization result. The record normalization result is calculated as a leaf digest, and adjacent leaves are merged layer by layer to obtain a unique root value. When the number of leaves does not meet the requirements for pair merging, a pre-agreed padding method is used to participate in the merging to maintain the consistency of the root value under different implementations. The root value and the corresponding batch or time window information can be written to the chain or anchor area, and the root value can be jointly signed by multiple nodes. This allows for fast verification and compression of evidence storage data based on the root value and proof path while retaining the ability to locate breaks in the digest chain. Specifically, the batch is a set identifier for process records defined by the manufacturing end, and the time window is a window description field that aggregates process records by timestamp. Both are written into the ledger or anchor area as metadata of the process records and participate in the signature coverage of the root value. The anchor area is an append-only storage area used to store the root value and the corresponding batch or time window information and their signature evidence. Further, the completion method is a deterministic rule used to generate paired inputs when the number of leaves cannot be merged in pairs. The completion method, as an implementation parameter, defaults to copying the last leaf digest, and the adjustable range is either copying the last leaf digest or using a leaf digest with all 0 bits. It is fixed in the system parameters to ensure that the root value is consistent under different implementations. The joint signature is when multiple participating nodes generate signatures for the same root value and batch or time window information respectively and form a signature set. The number of participating nodes, as an implementation parameter, defaults to 3 and the adjustable range is 2 to 15.

[0052] In one implementation, when each record is written to the immutable ledger, a sequential association digest is formed in a chain structure of record normalized byte string, sequential association digest, and signature overlay, so that any intermediate record that is replaced, deleted, or rearranged can be detected by the online verification module; the specific process is as follows: In the process sequence number is When a manufacturing node generates a ledger record, it first performs record-level serialization of the record's field set according to a fixed field order and length prefix rule, and then uses the aforementioned normalized encoding for the process data portion to obtain a normalized byte string for the record: , in, Indicates the step number is Record normalized byte strings, This indicates record-level serialization encoding. Indicates the step number is Search key, Indicates the step number is The current dynamic identity value, Indicates the step number is Separate label for the link identifier field. Indicates that the process is marked as Data on the process under constraints The byte string obtained by performing normalization encoding Indicates the step number is The process data, Indicates the step number is timestamp, Indicates the step number is Manufacturing node identifier, This indicates a deterministic concatenation operation; After record normalization, the sequential association summary of this record is calculated using the overlay method of the previous summary + the field set of this record, so that the summary chain binds the record order at the byte level: , in, Indicates the step number is Sequential association of summaries, This represents a hash operation. Indicates the step number is Sequential association of summaries, Indicates the step number is Record normalized byte strings, This indicates a deterministic concatenation operation; Under this structure, each entry in the ledger must be written at least once. , , , Simultaneously written with the manufacturing node's digital signature This serves as the sequential association summary for this record; after retrieving all records, the online verification module recalculates according to the ledger storage order. and If any record field is tampered with, or if a record is inserted or deleted, subsequent records will be affected. Inconsistencies with values ​​stored in the ledger will form evidence of a broken chain of summaries that can be located. The digital signature coverage of the manufacturing node and the digest chain should use the same standard to avoid the possibility of substitution due to signing only partial fields; the signed message can be defined as: , in, Indicates the step number is Digital signature, Indicates using private key Generate a digital signature for the input message. The manufacturing node identifier is The signature private key, Indicates the step number is Sequential association of summaries, Indicates the step number is The current dynamic identity value, Indicates the step number is Separate label for the link identifier field. Indicates data for each stage. The normalized encoding result, Indicates the step number is The process data, Indicates the step number is timestamp, This indicates a deterministic concatenation operation; When ledgers need to be compressed and stored by batch or time window, batch-level Merkle anchoring can be introduced without changing the structure of each record containing the previous summary: the same batch is identified as... The record set is processed in ledger order, leaf summaries are calculated, and a root value is constructed. The root value is written to the chain or to the anchor area of ​​the distributed database, and multiple nodes jointly sign the root value for rapid verification and to reduce the amount of verification data. , in, The batch identifier is The Leaf summary of each record The batch identifier is The The record normalized byte string of each record. This represents a hash operation. Indicates the first Batch identifier, Indicates the sequence number of the record within the batch; , in, The batch identifier is Merkle root value, This represents the operation of constructing the Merkle root value from the leaf summary sequence. The batch identifier is The Leaf summary of each record The batch identifier is The number of records, Indicates the first Batch identifier; The signature of the root value can overwrite both the root value and batch metadata, forming auditable anchored evidence: , in, Indicates that the participant is identified as Batch identifier is The root value signature, Indicates using private key Generate digital signatures, Indicates the participant identifier is The signature private key, The batch identifier is Merkle root value, Indicates the first Batch identifier, The batch identifier is Time window description, This indicates a deterministic concatenation operation.

[0053] Specifically, sequential association summaries organize the record structure around the binding of the previous summary and the current set of fields. Record-level serialization converges the search key, dynamic identity value, stage identifier, normalized stage data, timestamp, and node identifier into a consistent byte string, ensuring that the same record in different implementation environments receives the same summary input. Sequential association summaries fix the record order in the summary chain through continuous overlay. When any intermediate record undergoes field replacement, deletion, insertion, or rearrangement, subsequent summaries will deviate from the ledger stored value, thus forming a locatable evidence of breakage. Digital signatures cover key fields such as the previous summary, current dynamic identity value, stage data, and timestamp, allowing the summary chain and signature evidence to corroborate each other within the same scope, reducing the replacement space caused by signing only partial fields. When it is necessary to compress evidence storage or speed up verification, root values ​​can be constructed for the leaf summaries of records by batch or time window and multi-party signature anchoring can be performed. The verification side can complete the integrity verification of partial records through root value anchoring and leaf paths, reducing the dependence on the transmission and storage of the entire record, while maintaining consistency with the sequential detection logic of each summary chain.

[0054] In this embodiment, the online verification module uses the current dynamic identity value or its summary as the search key to obtain the full series of process records of the target part; when no results are found or there is a broken sequential association summary chain, an inconsistent result is output and the broken process number is indicated; wherein, the sequential association summary chain is a chain formed by the sequential association summaries of adjacent process records according to the previous and next reference relationship; The ledger establishes an index structure for the retrieval key, which records the association between the retrieval key and the corresponding process record sequence. After receiving a verification request, the online verification module first reads the current dynamic identity value or its digest from the target component through the verification node, and then uses this value as the retrieval key to query the target process record sequence in the index structure. When multiple candidate record sequences exist, the online verification module performs a digest chain consistency check on each candidate sequence and selects the record sequence with a continuous digest chain and a passed signature verification as the full process record.

[0055] The determination of a broken chain includes: a mismatch in the digest field of the previous record between two adjacent chain records, a non-contiguous sequence field between adjacent chain records, or a digital signature verification failure for any chain record. The broken chain number is determined by the online verification module based on the chain sequence field, and the anomaly report records the digest of the last valid chain record before the break, the chain identifier corresponding to the break location, and the verification failure type at the break point.

[0056] Furthermore, the candidate record sequence is a sequence of multiple records associated with the same search key in the index structure. The maximum number of candidates is set to 3 by default, with an adjustable range of 1 to 20. When the number of candidates exceeds the maximum, the online verification module truncates the candidate sequences to the maximum limit based on the latest timestamp and performs a digest chain consistency check. Similarly, updates to the index structure and appending records to stages maintain transactional consistency. When an index update fails, the corresponding stage record is marked as unindexable and can be retrieved after subsequent index repair.

[0057] Furthermore, the evidence summary is an evidence field obtained by summarizing and encoding the set of record fields related to the fracture site, the verification results, and the sequential association summary chain verification results. The encoding caliber of the evidence summary is consistent with the record-level serialization caliber and is fixed in the system parameters. The evidence summary is stored together with the fracture link number in the anomaly report, enabling subsequent review to complete consistency verification without relying on the original link equipment data. Optionally, the anomaly report performs merged storage of multiple failure results for the same search key. The merge window is set to 10 min by default, with an adjustable range of 1 min to 1440 min. Only the latest fracture location and the latest evidence summary are retained within the window.

[0058] In this embodiment, the spare parts integrate a physically unclonable function, and the identity iteration module also introduces the response data or its summary of the physically unclonable function when calculating the current dynamic identity value, so as to improve the resistance to copying and writing. The response data for physically unclonable functions is generated in real-time by the component after receiving challenge data. Before participating in identity iteration, the response data undergoes stabilization processing to form a repeatable response summary. Stabilization processing includes multiple sampling of responses under the same challenge, consistency alignment of the sampling results, and outputting a set of auxiliary data for subsequent reconstruction. The auxiliary data and response summary are written into the ledger as part of the stage data and bound to the corresponding stage record. When the component generates a response to the same challenge in a subsequent verification session, it uses the auxiliary data to complete the response reconstruction and outputs a response summary consistent with the ledger record.

[0059] Specifically, the default number of data collections is 5, adjustable from 3 to 15. Consistency alignment is based on the majority of consistent bits in the response bit string across multiple collections, and a stable response digest is output. When the majority of consistent bits are insufficient to form a stable result, the response digest participates as an empty field, maintaining its field order in the ledger record. Furthermore, auxiliary data is a public auxiliary information field bound to the response digest and used to reconstruct the consistent response digest in subsequent sessions. Auxiliary data and the response digest are written together into the ledger and bound to the corresponding stage record. Subsequent verification sessions read the auxiliary data, reconstruct the response digest using the same criteria, and participate in consistency verification.

[0060] Example 2: Based on Embodiment 1, the above system also includes an audit voucher module, which is used to generate a digital audit voucher containing a target spare part retrieval key, a final verification identity value, a summary chain root value and a corresponding signature set when consistent, and to generate an anomaly report containing a broken link number and an evidence summary when inconsistent. Digital audit credentials include a credential identifier, retrieval key, final verification identity value, digest chain root value, signature set reference information of the link record sequence, and generation time information. The audit credential is digitally signed by the audit credential module using its credential signature key and written to the ledger as an independent record. Anomaly reports include a retrieval key, the broken link number, the last valid digest before the break, the signature verification result digest of the candidate record at the break point, and the verification session identifier of the online verification module. Anomaly reports are bound to the corresponding verification request and stored in the ledger or audit storage in an append-only manner.

[0061] Furthermore, the signature key for the digital audit voucher is the voucher signature key material held by the audit voucher module, and the voucher signature verification material is the corresponding certificate chain material. Once the voucher is written to the ledger, it remains unwriteable and can be retrieved by search key and generation time. Similarly, the signature set reference information is a reference field used to locate the signature set of the record sequence in the process. The reference field and the root value of the digest chain jointly participate in the signature coverage of the audit voucher. When the complete signature set cannot be obtained, the audit voucher record remains in a failed generation state and only the search key and a summary of the failure reason are written to it.

[0062] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0063] Furthermore, those skilled in the art will understand that although some embodiments herein include certain features included in other embodiments but not others, combinations of features from different embodiments are meant to be within the scope of this application and form different embodiments. For example, all the embodiments above can be used in any combination. The information disclosed in this background section is intended only to enhance the understanding of the general background of this application and should not be construed as an admission or in any way implying that such information constitutes prior art known to those skilled in the art.

Claims

1. A computer component manufacturing traceability management system, comprising a traceability server located at the manufacturing end, multiple manufacturing nodes connected to equipment at each manufacturing stage, and verification nodes located downstream of the supply chain; characterized in that, The components have a secure storage area that allows for additional writing but not erasure; The system includes: The identity iteration module is used to read the previous dynamic identity value from the secure storage area in at least two sequential manufacturing stages, obtain the current stage data, calculate the current dynamic identity value according to a predetermined cryptographic one-way rule, and append it to the secure storage area. The chained record module is used to write the data of each link and the corresponding dynamic identity value and their sequential association summary into an immutable ledger; The online verification module is used to recalculate the verification identity value according to the rules based on the data of each link in the ledger when a verification request is received, and compare it with the current dynamic identity value read from the target part to output a consistency result.

2. The computer parts manufacturing traceability management system according to claim 1, characterized in that, The cryptographic one-way rule is as follows: after deterministically concatenating and normalizing the previous dynamic identity value with the current data, a hash operation or message authentication code operation is performed to obtain the current dynamic identity value, and the normalization code includes at least the field order and length convention. The digital signature of each stage record is used to sign the set of fields associated with the sequential association digest as a whole. The set of fields includes at least the sequential association digest of the previous stage record, the current dynamic identity value, the stage identifier, the normalized stage data, and the timestamp. When verifying consistency, the verification node performs signature verification and comparison on the complete set of fields corresponding to the signature.

3. The computer parts manufacturing traceability management system according to claim 1, characterized in that, The secure storage area includes multiple sequentially numbered append write slots. Each time, only the next empty slot is allowed to be written, and a completion flag is written at the same time. Slots that have already been written to are prohibited from being overwritten or erased.

4. The computer parts manufacturing traceability management system according to claim 1, characterized in that, The read interface of the secure storage area is protected by access control, and the verification node is only allowed to read the current dynamic identity value after passing challenge-response authentication.

5. The computer parts manufacturing traceability management system according to claim 1, characterized in that, The at least two manufacturing stages include a wafer testing stage, and the stage data includes at least wafer coordinate information and the encoding of electrical performance parameters measured at that coordinate.

6. The computer parts manufacturing traceability management system according to claim 1, characterized in that, The at least two manufacturing stages also include a packaging stage and a final testing stage; the packaging stage data includes packaging equipment identification and packaging batch number; the final testing stage data includes test result codes for key performance indicators.

7. The computer parts manufacturing traceability management system according to claim 1, characterized in that, The immutable ledger is a blockchain network or a distributed database, and each record contains at least: the search key of the target component, the current dynamic identity value, the sequential association summary of the previous record, the timestamp, and the digital signature of the manufacturing node. When compressing and storing evidence by batch or time window, the order of records in the ledger is used as the leaf arrangement order. Records at each stage are serialized at the record level according to a fixed field order and field length prefix rule to obtain a record normalization result. The record normalization result is calculated as a leaf summary, and adjacent leaves are merged layer by layer to obtain a unique root value. When the number of leaves does not meet the requirements for pair merging, a pre-agreed completion method is used to participate in the merging. The root value and the corresponding batch or time window information can be written to the chain or anchor area, and the root value can be jointly signed by multiple nodes.

8. The computer parts manufacturing traceability management system according to claim 1, characterized in that, The online verification module uses the current dynamic identity value or its summary as the search key to obtain the full range of process records for the target component; when no results are found or the sequential association summary chain is broken, an inconsistent result is output and the broken process number is indicated; wherein, the sequential association summary chain is a chain formed by sequential association summaries of adjacent process records according to their previous and subsequent reference relationships.

9. A computer parts manufacturing traceability management system according to claim 1, characterized in that, The component integrates a physically unclonable function, and the identity iteration module also incorporates the response data or a summary of the physically unclonable function when calculating the current dynamic identity value.

10. A computer parts manufacturing traceability management system according to claim 1, characterized in that, The system also includes an audit credential module, which generates a digital audit credential containing a target spare part retrieval key, a final verification identity value, a summary chain root value, and a corresponding signature set when there is consistency, and generates an anomaly report containing a broken link number and an evidence summary when there is inconsistency.