Full-generation-cycle carbon data credibility verification method and system and related equipment

By combining zero-knowledge proof and hash chain recording technologies with trusted institutional devices and hardware security modules, the privacy and security issues in the carbon data verification process are resolved, achieving efficient and secure carbon data verification and avoiding the high cost and low throughput problems of blockchain.

CN121980620APending Publication Date: 2026-05-05E SURFING IOT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
E SURFING IOT CO LTD
Filing Date
2025-12-26
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing technologies suffer from data tampering and privacy leaks during carbon data collection, transmission, storage, and verification. This is especially true in centralized carbon registration systems, where companies are required to submit detailed, commercially sensitive data, leading to a conflict between data transparency and privacy. Meanwhile, blockchain technology faces challenges such as high costs, low throughput, and high latency in large-scale, high-frequency data verification scenarios.

Method used

A proof document for generating carbon data digests is generated using zero-knowledge proof technology. It is digitally signed by a trusted institution and stored in an immutable log system recorded on a hash chain. Combined with hardware security modules and trusted timestamps, this ensures data immutability and privacy protection.

Benefits of technology

It improves the credibility and efficiency of carbon data interaction, prevents data tampering, protects corporate privacy, reduces operating costs, and solves the performance bottleneck of blockchain technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121980620A_ABST
    Figure CN121980620A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a full generation cycle carbon data credibility verification method and system and related equipment, and belongs to the technical field of information security. According to the method, the data abstract about the carbon data from the data acquisition terminal is acquired, and the zero-knowledge certification technology is adopted to perform carbon data credibility rule verification on the data abstract to generate the certification file, so that the privacy of the carbon data authenticity verification process is improved. The proof file and the data abstract are sent to the trusted mechanism equipment for digital signature operation, so that a signature file from the trusted mechanism equipment is received, the signature file carries a timestamp and comprises the signed proof file and the signed data abstract, the credibility of the carbon data is improved, and the reliability of the carbon data is improved. And the signature file is stored in an immutable log system adopting a hash chain recording mechanism, so that the carbon data can be prevented from being tampered, and the carbon data interaction efficiency can be improved through a centralized storage mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a method, system and related equipment for trusted verification of carbon data throughout the entire generation cycle. Background Technology

[0002] To protect the global environment, higher requirements are being placed on carbon data collection, measurement, monitoring, and verification across all industries. During the collection, transmission, storage, and verification of carbon data, data may be tampered with or leaked. Centralized carbon registration systems often require companies to submit detailed, commercially sensitive raw data when verifying data credibility, creating an inherent conflict between data transparency and corporate privacy.

[0003] Related technologies include using zero-knowledge proofs to protect the privacy of carbon trading data, allowing for verification without providing detailed data. However, current solutions typically combine zero-knowledge proof technology with blockchain technology to build decentralized carbon tracking and trading systems. Nevertheless, blockchain technology has inherent limitations, such as high transaction fees, low transaction throughput, processing latency (potentially several minutes), and significant energy consumption, all of which restrict its application in large-scale, high-frequency data verification scenarios. Summary of the Invention

[0004] The main objective of this application is to propose a method, system, and related equipment for trusted verification of carbon data throughout the entire generation cycle, aiming to improve the privacy and security of the carbon data verification process, as well as the efficiency of carbon data interaction.

[0005] To achieve the above objectives, one aspect of this application proposes a method for trusted verification of carbon data throughout its entire generation cycle, applied in a data server. The method includes the following steps: Collect data summaries of carbon data from data acquisition terminals; Zero-knowledge proof technology is used to verify the carbon data trust rules of the data digest, and a proof document is generated. The certificate and the data digest are sent to a trusted institution device for digital signature operation to receive a signature file from the trusted institution device; the signature file carries a timestamp and includes the signed certificate and the data digest; The signature file is stored in an immutable log system that uses a hash chain recording mechanism.

[0006] In some embodiments, the full generation cycle carbon data credibility verification method further includes the following steps: Set a first timed trigger task for each signature file in the immutable log system; In response to the first trigger event of the first timed trigger task, the signature file is added to the public list, which is configured with an external public interface.

[0007] In some embodiments, the full generation cycle carbon data credibility verification method further includes the following steps: Set a second timed trigger task for each signature file in the immutable log system; In response to the second triggering event of the second timed triggering task, the signature file is verified using a digital signature verification algorithm and a zero-knowledge verification algorithm to obtain a verification result; If the verification result indicates an anomaly, an alarm will be triggered on the signature file.

[0008] In some embodiments, the data acquisition terminal generates a data summary through the following steps: Collect carbon data, which includes carbon absorption data and carbon emission data; After the carbon data is formatted and standardized, a data digest is generated using a first encryption algorithm.

[0009] In some embodiments, the step of using zero-knowledge proof technology to verify the carbon data trust rules of the data digest and generate a proof document includes the following steps: The data digest is parsed into carbon data using a first decryption algorithm corresponding to the first encryption algorithm; Zero-knowledge proof technology is used to verify the carbon data trust rules and generate a proof document.

[0010] In some embodiments, the trusted institution device performs a digital signature operation through the following steps: The proof document and the data digest are loaded into the hardware security module, so that the hardware security module uses the private key to perform asymmetric encryption on the proof document and the data digest to obtain the signature file and the public key; The system returns the signature file output by the hardware security module to the data server and discloses the public key output by the hardware security module.

[0011] In some embodiments, the immutable log system stores the signature file through the following steps: Based on the timestamp of the signature file currently submitted to the immutable log system, determine the hash chain of the previous signature file; Perform a hash operation on the hash chain and the current signature file to obtain the hash chain of the current signature file, and store the hash chain.

[0012] To achieve the above objectives, another aspect of this application proposes a full-cycle carbon data reliability verification system, comprising: A data acquisition terminal, used to acquire carbon data and generate a data digest of the carbon data; The data server is used to perform carbon data trust rule verification on the data digest using zero-knowledge proof technology, generate a proof document, and send the proof document and the data digest to the trusted institution device. A trusted institution device is used to perform a digital signature operation on the proof document and the data digest to generate a signature file; the signature file carries a timestamp and includes the signed proof document and the data digest. The data server is also used to store the signature file in an immutable log system that uses a hash chain recording mechanism.

[0013] To achieve the above objectives, another aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described method.

[0014] To achieve the above objectives, another aspect of the embodiments of this application proposes a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0015] The embodiments of this application include at least the following beneficial effects: This application provides a method, system, electronic device, and program product for trusted verification of carbon data throughout its entire generation cycle. This solution collects data digests of carbon data from data acquisition terminals, uses zero-knowledge proof technology to verify the carbon data's trusted rules using the data digests, and generates a certificate document, thereby improving the privacy of the carbon data authenticity verification process. The certificate document and data digest are sent to a trusted institution's device for digital signing to receive a signed file from the trusted institution's device. This signed file carries a timestamp and includes the signed certificate document and data digest, improving the trustworthiness of the carbon data. Furthermore, storing the signed file in an immutable log system using a hash chain recording mechanism can prevent carbon data from being tampered with, and the centralized storage method can improve the efficiency of carbon data interaction. Attached Figure Description

[0016] Figure 1 This is a flowchart of the full generation cycle carbon data credibility verification method provided in the embodiments of this application; Figure 2 This is a flowchart of a method for verifying the credibility of carbon data throughout the entire generation cycle, provided in another embodiment of this application; Figure 3 This is a flowchart of a method for verifying the credibility of carbon data throughout the entire generation cycle, provided in another embodiment of this application; Figure 4 yes Figure 1 Flowchart of the data acquisition terminal execution steps in step S101; Figure 5 yes Figure 1 Flowchart of step S102; Figure 6 yes Figure 1 Flowchart of the trusted mechanism device execution steps in step S103; Figure 7 yes Figure 1 Flowchart of the immutable log system storage in step S104; Figure 8 This is a schematic diagram of a carbon data credibility verification system covering the entire generation cycle provided in an embodiment of this application; Figure 9 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application; Figure 10 This is a schematic diagram of the full generation cycle carbon data credibility verification process provided in the embodiments of this application; Figure 11 This is a schematic diagram of the digital signature and immutable log protection process provided in an embodiment of this application; Figure 12 This is a schematic diagram of the verification client data verification process provided in the embodiments of this application. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.

[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0019] Before providing a detailed description of the embodiments of this application, some of the nouns and terms involved in the embodiments of this application will be explained first. The nouns and terms involved in the embodiments of this application are subject to the following interpretations.

[0020] Zero-Knowledge Proof (ZKP): A cryptographic method that allows a "prover" to prove the truth of a statement to a "verifier" without revealing any original data information. In this application embodiment, zero-knowledge proof is used to prove that carbon data conforms to preset rules, while protecting the company's business privacy.

[0021] A trusted institution device is a device within a central credit institution used to perform digital signature operations. The central credit institution is a trusted third party recognized by multiple parties, responsible for digitally signing and timestamping zero-knowledge proof documents, and is the core of trust in the entire data trust verification process.

[0022] Digital signature: A signature mechanism based on asymmetric encryption technology. It uses a private key to encrypt data, generating a unique signature. The recipient can use the public key to verify the validity of the signature and the integrity of the data, thereby ensuring the authenticity of the data source and that it has not been tampered with.

[0023] Trusted timestamp: A service provided by a trusted third-party timestamp authority to attach a non-repudiable time stamp to digital files. It proves that data existed at a specific point in time, thus preventing retroactive tampering.

[0024] An immutable log is a data storage mechanism whose core characteristic is that once data is written, it cannot be modified or deleted. This application's embodiment uses a centralized log system to record all signed proof documents, ensuring the integrity and traceability of the records; its function is similar to the distributed ledger of a blockchain.

[0025] Hardware Security Module (HSM): A dedicated, certified physical hardware device used to securely generate, store, and manage encrypted private keys and perform critical cryptographic operations (such as digital signatures). Due to its high resistance to tampering and physical attacks, the HSM is considered the "gold standard" for protecting private keys.

[0026] Hash Chain: A data structure that forms a chain by binding the hash value of each new record to the hash value of the previous record. Any modification to the historical record will cause all subsequent hash values ​​to mismatch, thus immediately exposing the tampering.

[0027] An API (Application Programming Interface) is a set of predefined functions, protocols, and specifications. Its main purpose is to act as a "messenger" or "bridge" between different software components. It allows applications or services to communicate and exchange data, quickly providing users with the functional services they need.

[0028] During the collection, transmission, storage, and verification of carbon data, data may be tampered with or leaked. Centralized carbon registration systems often require companies to submit detailed, commercially sensitive raw data when verifying data credibility, which creates an inherent conflict between data transparency and corporate privacy.

[0029] Related technologies include using zero-knowledge proofs to protect the privacy of carbon trading data, allowing for verification without providing detailed data. However, current solutions typically combine zero-knowledge proof technology with blockchain technology to build decentralized carbon tracking and trading systems. Nevertheless, blockchain technology has inherent limitations, such as high transaction fees, low transaction throughput, processing latency (potentially several minutes), and significant energy consumption, all of which restrict its application in large-scale, high-frequency data verification scenarios.

[0030] In view of this, this application provides a method, system, and related equipment for trusted verification of carbon data throughout its entire generation cycle. This scheme collects data digests of carbon data from data acquisition terminals, employs zero-knowledge proof technology to verify the carbon data's trusted rules using the data digests, and generates a certificate document, thereby improving the privacy of the carbon data authenticity verification process. The certificate document and data digest are sent to a trusted institution's device for digital signing to receive a signed file from the trusted institution's device. This signed file carries a timestamp and includes the signed certificate document and data digest, enhancing the credibility of the carbon data. The signed file is then stored in an immutable log system using a hash chain recording mechanism, preventing carbon data tampering, and the centralized storage method improves the efficiency of carbon data interaction.

[0031] The full-cycle carbon data trusted verification method provided in this application relates to the field of information security technology. This method can be applied to a terminal, a server, or software running on either a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, or in-vehicle terminal, but is not limited to these. The server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network. The software can be an application implementing the full-cycle carbon data trusted verification method, but is not limited to the above forms.

[0032] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0033] In some embodiments, the full-cycle carbon data trusted verification method of this application is applied in a data server. The data server, together with the data acquisition terminal and trusted institutional equipment, constitutes the application architecture of the method of this application, as described in detail below: Each data collection point is equipped with a data acquisition terminal to collect carbon data and report the collected carbon data to the data server. The data acquisition terminal can use a first encryption algorithm to initially generate a data digest from the collected carbon data and transmit the carbon data to the data server in the form of a data digest.

[0034] The data server provides services such as carbon data storage, querying, and verification. It can be equipped with an immutable log system that uses a hash chain recording mechanism to store carbon data. Specifically, the data server formats and standardizes the received carbon data and generates a certificate document using zero-knowledge proof technology. It then uses a trusted third-party institution to endorse the certificate document and the carbon data, obtaining a signature file from the trusted institution. Finally, the signature file is stored in the centralized immutable log system.

[0035] Trusted organization devices (TEDs), as devices of independent organizations, digitally sign and timestamp carbon data in the form of generated proof documents and data digests. TIDs include a Hardware Security Module (HSM) that uses the HSM to perform digital signature operations, protecting the private key used in the digital signature process.

[0036] Furthermore, the application architecture of this application embodiment also includes a verification client, which can access the signature proof file and data digest publicly available on the data server to perform digital signature verification and zero-knowledge proof verification.

[0037] This application's embodiments do not rely on blockchain technology. Instead, they establish a central credit institution and utilize trusted institution equipment to digitally sign and timestamp the generated zero-knowledge proof documents. This, combined with immutable log recording, hardware security module (HSM) protection, and independent third-party auditing, enhances data trustworthiness and immutability, thereby achieving trusted verification of carbon data throughout its entire generation cycle. This solution retains the advantages of centralized management, such as efficiency, low cost, and regulatory friendliness, while addressing the core pain point of data privacy protection by integrating advanced cryptographic technologies like zero-knowledge proofs, providing a unique technical path for carbon data verification.

[0038] Regarding the protection of data privacy, this application's embodiments utilize zero-knowledge proof (ZKP) technology to prove to a central credit agency that the data conforms to preset trust rules without disclosing details of the enterprise's original carbon emissions or carbon absorption data.

[0039] To ensure the authenticity and immutability of data, this application embodiment uses a trusted third-party device (i.e., a trusted institution device) recognized by multiple parties to endorse the ZKP certification document with digital signature technology and a trusted timestamp. This ensures that once the data is signed, its authenticity and generation time are locked and cannot be tampered with subsequently.

[0040] Regarding the implementation of trusted verification throughout the entire lifecycle, the embodiments of this application store the signed proof document in an immutable log system, and the signing private key of the central authority is protected by a hardware security module (HSM), thereby forming an efficient and secure closed loop throughout the entire process of data collection, generation, signing, storage and final verification. For centralized secure storage, this application's embodiments employ digital signatures, trusted timestamps, hash chains, and immutable log recording mechanisms. Without requiring blockchain technology, it can still guarantee the immutability and traceability of data. Compared to blockchain solutions, this application's embodiments avoid their high transaction fees and low throughput, offering significant performance advantages. Regarding independent third-party audits, the embodiments of this application periodically have an independent auditing firm (i.e., a verification client) audit the central credit institution and storage system, and publicly disclose signature records to further enhance the credibility of the system.

[0041] The solution proposed in this application is applicable to a variety of carbon metering scenarios, and can be flexibly deployed in industrial production, transportation, and urban greening.

[0042] Figure 1 This is an optional flowchart of the full-cycle carbon data reliability verification method provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps S101 to S104.

[0043] S101, collects a data summary of carbon data from the data acquisition terminal; S102, Zero-knowledge proof technology is used to verify the carbon data trust rules of the data digest and generate a proof document; S103, send the proof document and data digest to the trusted authority device for digital signature operation, and receive the signature file from the trusted authority device; the signature file carries a timestamp and includes the signed proof document and data digest; S104, store the signature file in an immutable log system that uses a hash chain recording mechanism.

[0044] Steps S101 to S104, as illustrated in this embodiment, involve collecting a data digest of carbon data from a data acquisition terminal, using zero-knowledge proof technology to verify the carbon data trust rules and generate a certificate document, thereby improving the privacy of the carbon data authenticity verification process. The certificate document and data digest are then sent to a trusted institution's device for digital signing to receive a signed file from the trusted institution's device. This signed file carries a timestamp and includes the signed certificate document and data digest, enhancing the credibility of the carbon data. Finally, the signed file is stored in an immutable log system using a hash chain recording mechanism, preventing carbon data tampering, and the centralized storage method improves the efficiency of carbon data interaction.

[0045] In step S101 of some embodiments, the data acquisition terminal can refer to a carbon metering sensor at the data acquisition point, or it can be an internal enterprise management system or production control system. At various data acquisition points (industrial facilities, traffic nodes, construction sites, green carbon sink areas, etc.), sensors and data acquisition modules are installed, and the internal enterprise management system and production control system are integrated to collect carbon emissions, carbon absorption, and related environmental data in real time. The collected raw carbon data is formatted and standardized, and a data digest (such as a hash value) is generated using a first encryption algorithm to improve data security during subsequent transmission.

[0046] In step S102 of some embodiments, after receiving the data digest, the data server parses the data digest into carbon data. Based on pre-defined carbon data credibility rules (e.g., data range, continuity, statistical characteristics), the pre-processed data is used as private input, and a proof document is generated using a zero-knowledge proof protocol (such as zk-SNARK or zk-STARK). This proof document proves that the data conforms to the rules without revealing the original data content. This embodiment creatively applies zero-knowledge proof (ZKP) technology to carbon data verification, enabling data generators (such as enterprises) to prove the authenticity of their carbon data reports to a central credit agency without disclosing their sensitive business data (such as specific production volumes and energy consumption details), thus resolving the issue of data transparency versus corporate privacy.

[0047] In step S103 of some embodiments, the proof document and the data digest of the carbon data are sent to a trusted institution device for digital signing to receive a signed file from the trusted institution device. The signed file carries a timestamp and includes the signed proof document and the data digest. In this embodiment, the trusted institution device acts as a trusted third party to digitally sign the generated zero-knowledge proof document and data digest, and timestamps the signed file using a trusted timestamp service. During the digital signing process, the trusted institution device uses a Hardware Security Module (HSM) to protect the private key of the central credit institution. The signing operation is completed in secure hardware to prevent malicious modification from internal or external sources.

[0048] In step S104 of some embodiments, the signature file is stored in an immutable log system employing a hash chain recording mechanism, ensuring that all records cannot be tampered with or deleted once generated. This embodiment employs a non-blockchain centralized architecture for carbon data management, using trusted institutional devices as the core trust anchor, thus avoiding the inherent high transaction fees, low throughput, and energy consumption problems of blockchain technology.

[0049] According to some embodiments of this application, please refer to Figure 2 The full-cycle carbon data reliability verification method of this application embodiment may also include, but is not limited to, the following steps: S201 sets a first timed trigger task for each signature file in the immutable log system; S202, in response to the first trigger event of the first timed trigger task, adds the signature file to the public list, which is configured with an external public interface.

[0050] In this embodiment, the data server sets a first timed trigger task for each signature file in the immutable log system. This first timed trigger task starts counting from the signature file's storage time or the most recent public disclosure time, and generates a first trigger event after a first preset duration. In response to the first trigger event of the first timed trigger task, the data server adds the signature file to a public list. The public list is configured with an external public interface, which is an API interface. The client verification end can quickly obtain the publicly disclosed signature files from the data server through this API interface and verify the signature files, ensuring that the data has not been tampered with throughout the entire generation cycle.

[0051] For example, the data server periodically publishes signature files and timestamp information for users or third parties to query and verify. The client verification end (such as regulatory agencies, third-party certification authorities, or users) obtains the publicly available parameters, signature proof files, and data digests through the public interface, and uses digital signature verification algorithms and zero-knowledge verification algorithms to confirm that the proof files and data digests match the publicly available parameters, ensuring that the data has not been tampered with throughout the entire generation cycle.

[0052] In some embodiments, the public list includes signature files and the time they were added to the public list (i.e., the public time). The data server periodically queries the public time of each signature file in the public list. If the public time is greater than the current time, the signature file is deleted from the public list.

[0053] According to some embodiments of this application, please refer to Figure 3 The full-cycle carbon data reliability verification method of this application embodiment may also include, but is not limited to, the following steps: S301 sets a second timed trigger task for each signature file in the immutable log system; S302, in response to the second triggering event of the second timed triggering task, the signature file is verified using a digital signature verification algorithm and a zero-knowledge verification algorithm to obtain the verification result; S303: If the verification result indicates an anomaly, an alarm will be triggered on the signature file.

[0054] In this embodiment, the data server sets a second timed trigger task for each signature file in the immutable log system. This second timed trigger task starts counting from the signature file's storage time or the most recent public disclosure time, and generates a second trigger event after reaching a second preset duration. Responding to the second trigger event of the second timed trigger task, the data server verifies the signature file using a digital signature verification algorithm and a zero-knowledge verification algorithm to obtain a verification result. Specifically, the signature file includes a digital signature, a data digest, a proof document, and a public key. The digital signature verification algorithm calculates the hash values ​​of the data digest and the proof document using the public key and a predefined verification algorithm, and compares the calculated hash values ​​with the digital signature. If they match, the digital signature verification passes; otherwise, it fails. If the verification result indicates an anomaly (such as either the digital signature verification algorithm or the zero-knowledge verification algorithm failing), an alarm operation is performed on the signature file. The alarm operation can trigger an audit process or send information about the signature file anomaly to relevant terminals.

[0055] According to some embodiments of this application, please refer to Figure 4 The data acquisition terminal in step S101 can generate a data summary through, but is not limited to, the following steps: S401, collect carbon data, which includes carbon absorption data and carbon emission data; S402, after formatting and standardizing the carbon data, uses the first encryption algorithm to generate a data digest.

[0056] In this embodiment, the data acquisition terminal collects carbon emissions, carbon absorption, and other related data in real time. The collected raw carbon data undergoes preprocessing operations such as formatting and standardization to ensure a standardized data format during subsequent transmission and storage. After preprocessing, the carbon data is hashed using a first encryption algorithm to generate a data digest (such as a hash value). This data digest is transmitted between the data acquisition terminal and the data server, and between the data server and trusted institutional devices, enhancing data security during subsequent transmission.

[0057] According to some embodiments of this application, please refer to Figure 5 Step S102 may include, but is not limited to, the following steps: S501, using the first decryption algorithm corresponding to the first encryption algorithm, parses the data digest into carbon data; S502 uses zero-knowledge proof technology to verify the carbon data trust rules and generate proof documents.

[0058] In this embodiment, after receiving the data digest, the data server uses a first decryption algorithm corresponding to the first encryption algorithm to parse the data digest into carbon data. Then, zero-knowledge proof technology is used to verify the carbon data according to carbon data trust rules, generating a proof document. Carbon data trust rule verification includes, but is not limited to, verifying whether the received carbon data is within a specified data range, whether it has continuity, and whether it meets preset statistical characteristics. The authenticity of the data is proven by verifying that the carbon data meets the carbon data trust rules. This embodiment creatively applies zero-knowledge proof (ZKP) technology to carbon data verification, enabling data generators (such as enterprises) to prove the authenticity of their carbon data reports to a central credit agency without disclosing their sensitive business data (such as specific production volumes and energy consumption details), thus resolving the issue of data transparency versus corporate privacy.

[0059] According to some embodiments of this application, please refer to Figure 6 The trusted institution device in step S103 can perform the digital signature operation through, but is not limited to, the following steps: S601, load the proof document and data digest into the hardware security module, so that the hardware security module uses the private key to perform asymmetric encryption on the proof document and data digest to obtain the signature file and public key; S602 returns the signature file output by the hardware security module to the data server and exposes the public key output by the hardware security module.

[0060] In this embodiment, the trusted organization device includes a Hardware Security Module (HSM). After receiving the proof document and data digest from the data server, the trusted organization device loads them into the HSM. The HSM uses a private key to perform asymmetric encryption on the proof document and data digest to obtain a signature file and a public key, and simultaneously generates a timestamp for the signature file. The trusted organization device returns the signature file and publicly discloses it to the verification client so that the verification client can subsequently verify the signature file. This embodiment introduces a Hardware Security Module (HSM) to protect the signature private key of the trusted organization device. As a tamper-proof dedicated hardware device, the HSM can ensure that the private key used for signing cannot be stolen or tampered with, thereby fundamentally guaranteeing the credibility of the digital signature and improving the credibility of the entire system.

[0061] According to some embodiments of this application, please refer to Figure 7 The immutable log system in the data server in step S104 can store the signature file through, but is not limited to, the following steps: S701, based on the timestamp of the signature file currently committed to the immutable log system, determine the hash chain of the previous signature file; S702: Perform a hash operation on the hash chain and the current signature file to obtain the hash chain of the current signature file, and store the hash chain.

[0062] In this embodiment, after receiving the signature file and its timestamp, the data server submits it to an immutable log system for storage. The immutable log system uses a hash chain recording mechanism to record signature files. Specifically, based on the timestamp of the signature file currently submitted to the mutable log system, the hash chain formed by the previously submitted signature file is determined. Then, a hash operation is performed on this hash chain and the current signature file to obtain the hash chain of the current signature file, and the newly calculated hash chain is stored. Each hash operation result in this embodiment includes the hash chain formed by the previously submitted signature file. This chain ensures that any tampering with historical data will invalidate the hash values ​​of all subsequent signature files, thus being detected by the system. In this embodiment, all zero-knowledge proof files and data digests signed by HSM are recorded in a centralized immutable log system. This log uses technologies such as hash chains to ensure that each record cannot be modified or deleted, thereby providing a traceable and auditable integrity guarantee for the data.

[0063] In some embodiments, please refer to Figure 10 The full-cycle carbon data reliability verification process of this application embodiment is described in detail below: S11, After each data acquisition terminal collects carbon data, it performs preliminary preprocessing to generate a data summary; S12, the data digest is uploaded to the data server (such as a data processing server) to generate a proof file based on zero-knowledge proof technology; S13, Zero-knowledge proof documents and data digests are submitted to a trusted institution device located at a central credit authority, which uses an HSM to digitally sign and bind trusted timestamps; S14, The signed data record is stored in a centralized immutable log system; S15, the verification client obtains data and signature files through the public interface, and calls the verification algorithm to verify the data's credibility.

[0064] In some embodiments, please refer to Figure 11 The specific process for digital signature and immutable log protection is as follows: S21, Parameter Setting: During the system initialization phase, the central credit agency sets public parameters (such as public keys) and timestamp policies; S22, Proof Generation and Signing: After the data processing server generates a zero-knowledge proof file, it submits it to the trusted institution device of the central credit agency for signing; during signing, the trusted institution device calls the HSM to perform the signing operation and embeds a trusted timestamp. S23, Log recording: Record the signature file (including proof of digital signature and data digest) and its timestamp in an immutable log in a hash chain manner; S24, Data Verification: The verification client retrieves the stored record, verifies the digital signature using the public key published by the central credit authority, and confirms that the data has not been modified.

[0065] In some embodiments, carbon data verification may include the following methods: Data validation: Please refer to Figure 12 In carbon measurement applications (such as carbon trading platforms and environmental monitoring systems), the verifier obtains the latest signature records and data digests by calling public interfaces, and uses digital signature verification and zero-knowledge verification algorithms to check the legality of the data. Dynamic monitoring: The system supports periodic verification to ensure data consistency throughout the entire generation cycle. If an anomaly is detected, an alarm is triggered and detailed logs are recorded. Third-party audit: The central credit agency and immutable log system are regularly audited by an independent third-party organization, which reports on data issuance and storage in a transparent and open manner to ensure the trustworthiness of the system.

[0066] Please refer to Figure 8 This application also provides a system for verifying the credibility of carbon data throughout its entire generation cycle, comprising: A data acquisition terminal, used to collect carbon data and generate a data summary of the carbon data; The data server is used to verify the carbon data trust rules of the data digest using zero-knowledge proof technology, generate a proof document, and send the proof document and data digest to the trusted institution's equipment. Trusted institution equipment is used to digitally sign certificates and data digests to generate signature files; the signature files carry timestamps and include the signed certificates and data digests. The data server is also used to store signature files in an immutable log system that uses a hash chain recording mechanism.

[0067] It is understood that the methods described in the above method embodiments are applicable to this system embodiment. The specific functions implemented in this system embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.

[0068] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described method. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.

[0069] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0070] Please see Figure 9 , Figure 9 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes: The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 902 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901. The input / output interface 903 is used to implement information input and output; The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 905 transmits information between various components of the device (e.g., processor 901, memory 902, input / output interface 903, and communication interface 904); The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.

[0071] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method.

[0072] It is understood that the content of the above method embodiments is applicable to this storage medium embodiment. The specific functions implemented in this storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.

[0073] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0074] It is understood that the content of the above method embodiments is applicable to the embodiments of this program product. The specific functions implemented by the embodiments of this program product are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0075] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0076] The full-cycle carbon data reliability verification method, system, and related equipment provided in this application have at least one of the following beneficial effects: Performance and efficiency improvements: Compared to blockchain solutions that rely on multi-node consensus, the centralized architecture of this application embodiment can achieve lower verification latency and higher transaction throughput, meeting the needs of high-frequency, large-scale acquisition and verification of carbon data.

[0077] Data privacy protection: Through ZKP technology, enterprises can prove data compliance without disclosing their trade secrets to third parties, effectively protecting sensitive information and enhancing the applicability and promotion potential of the solution.

[0078] High security and credibility: The use of HSM technology provides "gold standard" level security protection for the signing private keys of the central credit authority, preventing the risk of private key leakage at both physical and logical levels. Combined with third-party auditing mechanisms, the credibility of the entire system is further enhanced, making it a trusted carbon data verification infrastructure.

[0079] Regulatory friendliness and low cost: The centralized storage feature of this embodiment makes carbon data easy to regulate. At the same time, this solution avoids the high costs of public blockchains, significantly reducing operating costs and making it more economical and practical.

[0080] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0081] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0082] The system embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0083] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0084] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or modules is not necessarily limited to those steps or modules explicitly listed, but may include other steps or modules not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0085] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0086] In the embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0087] The modules described above as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0088] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0089] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0090] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A method for reliable verification of carbon data throughout its entire generation cycle, characterized in that, When applied to a data server, the full generation cycle carbon data reliability verification method includes the following steps: Collect data summaries of carbon data from data acquisition terminals; Zero-knowledge proof technology is used to verify the carbon data trust rules of the data digest, and a proof document is generated. The certificate and the data digest are sent to a trusted institution device for digital signature operation to receive a signature file from the trusted institution device; the signature file carries a timestamp and includes the signed certificate and the data digest; The signature file is stored in an immutable log system that uses a hash chain recording mechanism.

2. The method according to claim 1, characterized in that, The method for verifying the credibility of carbon data throughout the entire generation cycle also includes the following steps: Set a first timed trigger task for each signature file in the immutable log system; In response to the first trigger event of the first timed trigger task, the signature file is added to the public list, which is configured with an external public interface.

3. The method according to claim 1, characterized in that, The method for verifying the credibility of carbon data throughout the entire generation cycle also includes the following steps: Set a second timed trigger task for each signature file in the immutable log system; In response to the second triggering event of the second timed triggering task, the signature file is verified using a digital signature verification algorithm and a zero-knowledge verification algorithm to obtain a verification result; If the verification result indicates an anomaly, an alarm will be triggered on the signature file.

4. The method according to claim 1, characterized in that, The data acquisition terminal generates a data summary through the following steps: Collect carbon data, which includes carbon absorption data and carbon emission data; After the carbon data is formatted and standardized, a data digest is generated using a first encryption algorithm.

5. The method according to claim 4, characterized in that, The step of using zero-knowledge proof technology to verify the carbon data trust rules of the data digest and generating a proof document includes the following steps: The data digest is parsed into carbon data using a first decryption algorithm corresponding to the first encryption algorithm; Zero-knowledge proof technology is used to verify the carbon data trust rules and generate a proof document.

6. The method according to claim 1, characterized in that, The trusted institution device performs a digital signature operation through the following steps: The proof document and the data digest are loaded into the hardware security module, so that the hardware security module uses the private key to perform asymmetric encryption on the proof document and the data digest to obtain the signature file and the public key; The system returns the signature file output by the hardware security module to the data server and discloses the public key output by the hardware security module.

7. The method according to claim 1, characterized in that, The immutable log system stores the signature file through the following steps: Based on the timestamp of the signature file currently submitted to the immutable log system, determine the hash chain of the previous signature file; Perform a hash operation on the hash chain and the current signature file to obtain the hash chain of the current signature file, and store the hash chain.

8. A reliable verification system for carbon data throughout its entire generation cycle, characterized in that, include: A data acquisition terminal, used to acquire carbon data and generate a data digest of the carbon data; The data server is used to verify the carbon data trust rules of the data digest using zero-knowledge proof technology and generate a proof document; Send the supporting documents and the data digest to the trusted institution's device; A trusted institution device is used to perform a digital signature operation on the proof document and the data digest to generate a signature file; the signature file carries a timestamp and includes the signed proof document and the data digest. The data server is also used to store the signature file in an immutable log system that uses a hash chain recording mechanism.

9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method according to any one of claims 1 to 7.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 7.