A method and apparatus for an automotive enterprise supplier sustainable due diligence investigation information exchange

By constructing an exchange system based on trusted data space and asymmetric encryption algorithms, the problems of data access control and cross-enterprise information sharing in the due diligence information sharing between automotive companies and suppliers have been solved, realizing secure, controllable and efficient data exchange and improving compliance and transparency.

CN122046389BActive Publication Date: 2026-07-24中汽碳(北京)数字技术中心有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
中汽碳(北京)数字技术中心有限公司
Filing Date
2026-01-29
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

In existing technologies, the sharing of due diligence information between automotive companies and suppliers suffers from problems such as the inability to finely control data access permissions, inconsistent information sharing across enterprises, and the lack of a full-process traceability and auditing mechanism for data exchange, resulting in low information sharing efficiency, high costs, and poor compliance.

Method used

An exchange system based on trusted data space, asymmetric encryption algorithms, and digital signature mechanisms is adopted. Through the due diligence data exchange center platform, permission verification, dynamic authorization, and encrypted data storage are realized. A cross-enterprise information sharing and process-oriented access mechanism is built, and trusted logs and timestamps are generated to ensure the security and traceability of data transmission.

Benefits of technology

It enables secure, controllable, transparent and efficient exchange of due diligence data across enterprises and suppliers, reduces the cost of duplicate investigations, improves data security and compliance, and ensures data integrity and immutability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122046389B_ABST
    Figure CN122046389B_ABST
Patent Text Reader

Abstract

The application discloses a kind of car enterprise supplier sustainable due diligence investigation information exchange method and equipment, comprising: when there is member node to obtain the sustainable due diligence investigation information of specific supplier, initiate data access request;When due diligence data exchange center platform receives the encryption request sent by member node, to request permission verification, to determine whether the node has the authorized qualification of accessing target supplier due diligence data;When due diligence data exchange center platform confirms that member node has obtained the authorization of accessing target supplier due diligence data, execute this process to return the requested data to member node.This application realizes the confidentiality, integrity and non-tamperability of supplier due diligence data in the process of cross-enterprise exchange by introducing trusted data space, asymmetric encryption algorithm and digital signature mechanism, even if data is transmitted in public network, information leakage and tampering risk can be effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data management technology in the automotive industry, specifically to a method and device for exchanging information on sustainable due diligence between automotive companies and their suppliers. Background Technology

[0002] To mitigate potential supply chain risks, automakers need to conduct comprehensive sustainability due diligence on their suppliers, including aspects such as environmental performance and social responsibility fulfillment.

[0003] However, suppliers often serve multiple automotive companies, so there is a need among these companies to share supplier due diligence information in order to improve the efficiency of due diligence and reduce costs.

[0004] In existing technologies, conventional automotive suppliers use asymmetric encryption algorithms for data exchange and sharing. Specifically, by pairing public and private keys, the confidentiality and integrity of data transmission are achieved, greatly enhancing security. Therefore, it is also widely used for important data exchange.

[0005] However, in practical use, this type of operation relies solely on the confidentiality and integrity guarantees provided by asymmetric encryption, lacking the ability to finely and dynamically control data access permissions. Specifically: (1) Since supplier due diligence information involves corporate business privacy and supplier sensitive data, different car companies have different access permissions to the same supplier's information, and the permissions need to be dynamically adjusted according to the cooperation status. However, existing asymmetric encryption can only ensure data security in the transmission process and cannot accurately limit the access subject, access scope, and access time of the data. This is prone to the risk of unauthorized access and obtaining data beyond the scope. At the same time, it is difficult to achieve the compliance requirement that "only companies authorized by the supplier can access the corresponding data". (2) The lack of a trusted data sharing carrier and unified interaction standard across enterprises has resulted in low information sharing efficiency and high cost of repeated investigations. The due diligence systems and data formats of suppliers of various automobile companies are different. Point-to-point data transmission is carried out only through asymmetric encryption, which cannot achieve standardized information sharing among multiple enterprises. Therefore, different enterprises need to conduct repeated due diligence on the same supplier, which not only causes a lot of waste of manpower and time costs, but also results in inconsistent data credibility due to the lack of unified investigation standards, making it difficult to form a cross-enterprise collaborative management effect. (3) The lack of a traceability and audit mechanism for the entire data exchange process makes it impossible to meet the requirements of supply chain compliance management. Existing asymmetric encryption can only verify the integrity of data before and after transmission. It cannot record key information such as the data access subject, access time, and operation behavior, nor can it generate tamper-proof operation logs and timestamps. When data leakage or abuse occurs, it is impossible to trace the responsible party. It is difficult to meet the compliance audit requirements of sustainable management of the automotive industry supply chain, and it is also impossible to guarantee the transparency of the due diligence process.

[0006] Therefore, this application proposes a method and device for exchanging supplier due diligence information between automotive companies, which realizes the exchange of supplier due diligence data between automotive companies in a unified, secure and reliable manner, thereby solving the above-mentioned technical problems. Summary of the Invention

[0007] The main objective of this invention is to provide a method and device for exchanging information on sustainable due diligence between automotive companies and their suppliers, in order to solve the technical problems mentioned in the background art.

[0008] The present invention solves the above-mentioned technical problems by adopting the following technical solutions: A method for exchanging sustainable due diligence information among automotive companies and their suppliers is based on an exchange system consisting of multiple automotive company member nodes, multiple supplier nodes, and a due diligence data exchange center platform, comprising: S1. When a member node obtains sustainable due diligence information from a specific supplier, it sends an encrypted request to the designated node; S2. After receiving an encrypted request from a member node, the due diligence data exchange center platform performs permission verification on the request to determine whether the node is authorized to access the target supplier's due diligence data. S3. When the due diligence data exchange center platform determines that a member node does not have the authorization to access the target supplier's due diligence data, it will issue a specified authorization result through the supplier to enable authorized access. S4. Once the due diligence data exchange center platform has determined and confirmed in the previous process that the member node has been authorized to access the target supplier's due diligence data, it will send the requested data back to the member node.

[0009] Preferably, each member node of the exchange system accesses the system as a member of the trusted data space and obtains a unique identification code and key of no more than 255 binary bits assigned by the system during registration; The member nodes access the due diligence data exchange center platform through a designated network. The due diligence data exchange center platform stores the sustainable due diligence data of each supplier and is used to realize the registration, encrypted storage, permission allocation, access control and interaction log management of due diligence data. During the operation of the exchange system, each member node independently maintains its own supplier list, which is not disclosed to other nodes by default to ensure data sovereignty and privacy security. The information from each node in the exchange system is encrypted and digitally signed before being uploaded to the platform, and is accompanied by a trusted timestamp. Preferably, in the switching system, each node is defined. The unique identifier code and key are: ; in, The hash function used by the system. This is the registered name of the node. For registration timestamp; The identification code is recognized by all member nodes in the system, used for node identification and access control, and cannot be changed. It also generates a key for that node. ; in, Derived functions for the key used by the system. This is the system threshold; the key is not disclosed to other nodes after it is generated. Each supplier node possesses a key pair in the trusted data space; supplier nodes When adding data to a trusted data space, generate a key pair for it: ; in This refers to the public key. The private key is used for encryption communication; the supplier's public key is managed centrally by the platform and made public to all member nodes. The supplier's private key is held solely by the supplier and is used to decrypt content encrypted with the public key.

[0010] Preferably, the specific operation process of step S1 includes: S11. Member nodes determine the supplier objects to be queried in the local system based on business requirements. And obtain the supplier's unique identification code from the trusted data space registration information. ; S12. Member nodes use their own keys shared with the platform. This data segment Perform symmetric encryption: ; in, The symmetric encryption function used by the system. To generate the timestamp for this request, The generated encrypted string; To ensure the integrity and immutability of the request source, member nodes generate authentication tags based on their symmetric keys. : ; in, A function for generating message authentication codes; The node will have its own unique identifier code. With encrypted target supplier identification code Message authentication code Combined, they form the core data segment of the encrypted request message. : ; S13. Member nodes transmit the encrypted request message obtained in step S12 through the trusted data space interface. Send to the due diligence data exchange center platform.

[0011] Preferably, the specific operation process of step S2 includes: S21. After receiving the encryption request, the platform first uses the unique identifier code of the member node carried in the request. Retrieve the corresponding key from the registration information The platform uses keys hosted by member nodes to decrypt encrypted requests. ; in, This is the symmetric decryption function used by the system; the system extracts the member node identification code through this process. With the target supplier identification code ; S22. Platform authentication code attached to the message Verification required: ; in For message authentication verification operations; S23. The platform maintains a supplier access index table in the trusted data space to record the vehicle enterprise nodes that have obtained authorized access permissions from the supplier; The platform uses the decrypted supplier identification code Query whether a matching member node exists in the index table. Corresponding supplier identification code Access history: ; in, To access the index table; S24. If for If the query result matches, meaning the member node has authorization to access the target supplier's due diligence data, the platform confirms the access permission is valid and proceeds to step S4 to perform the data return operation; if for If the query result is not found, it means that the member node has not yet obtained access authorization for the supplier's data; the platform then records the request and proceeds to step S3 to initiate the authorization application mechanism.

[0012] Preferably, the message authentication verification operation The verification process is as follows: The platform first uses its locally stored session key. For the received message content ( Recalculate a new set of message authentication tags, denoted as... ; The newly calculated With received Perform a comparison; like and If they are completely identical, it indicates a verification identifier. for If so, it can be approved, ensuring that the request source is authentic, the content is complete, and it has not been tampered with; Otherwise, the verification failed, the request was invalidated, and recorded in the security log.

[0013] Preferably, the specific operation process of step S3 includes: S31. When the platform detects that the requesting node does not have access rights, it will send a signal requesting authorization to the target supplier node. At the same time, the platform will return a status signal to the member node that initiated the request, indicating that the current access requires authorization confirmation. S32. Upon receiving the platform signal, the member node uses the target supplier node's public key to its own private key. Encryption is performed to generate an encryption key message: ; in, It is a function that uses public-key encryption. For the public key of the supplier node, For shared timestamps; S33. The supplier node receives the encryption key message. Then, decrypt using your own private key: ; in, This is a function that uses a private key for decryption; the supplier node verifies the timestamp. The message is verified; if the verification passes, the next step is continued; otherwise, the message is retransmitted. Supplier nodes obtain member nodes' keys Then, the key is used to decrypt the original query message in order to read the request content and verify the request: ; S34. Suppliers may decide whether to grant access based on their own data sharing policies, partnerships, or compliance requirements; S35. If the supplier If authorized access is granted, the supplier node sends an "Authorization Agreement" message to the due diligence data exchange center platform: ; This information includes the authorized object identifier, supplier node identifier, and timestamp. ; Supplier nodes use their own private keys to perform digital signatures: ; in, It is a function that generates message digests. It is a function that uses a private key to encrypt and generate a digital signature; Supplier nodes will provide information and signature Send them together to the due diligence data exchange center platform; S36. The platform uses the supplier's public key to decrypt the signature. And verify whether the summary matches the information ontology:

[0014] in, It is a function that uses a public key for decryption. (If verification...) and If the messages are identical, it means the message has not been tampered with, and the process continues; otherwise, the platform requests the supplier to retransmit.

[0015] Preferably, the specific operation process of step S4 includes: S41. If the current access request has gone through the authorization process in correction S3, the platform first updates the vendor access index table in the trusted data space. Then, the member node identifier code, target supplier identifier code, authorization timestamp, and digital signature information for this authorization are written into the index table, resulting in: ; S42. The platform extracts the due diligence data file corresponding to the target supplier from the encrypted storage area. The platform uses the requesting member node's key to encrypt the data, ensuring that only the target member node can use its key to decrypt and view it. ; in, Represents a symmetric encryption function. The symmetric key for the member node. This is the timestamp when the file was extracted. Meanwhile, the platform also handles encrypted data. Computing data signatures This is so that member nodes can verify data integrity. ; S43. Member nodes receive returned data. and Then, use its own key. Regarding the received Recalculate a data signature and received If the two match, the verification passes, proving that the data has not been tampered with. After successful verification, the node uses its own key K. i Decryption: ; in yes Once the corresponding decryption function is verified, the node can view the supplier's sustainable due diligence information in the local trusted environment and perform analysis or decision-making as needed.

[0016] In another aspect, the present invention also discloses a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the method described above.

[0017] In another aspect, the present invention also discloses a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of the method described above.

[0018] As can be seen from the above technical solution, the present invention provides a method and device for exchanging information on sustainable due diligence between automotive companies and their suppliers. Compared with the prior art, the present invention has the following advantages: 1. By introducing a trusted data space, asymmetric encryption algorithms, and digital signature mechanisms, this invention achieves the confidentiality, integrity, and immutability of supplier due diligence data during cross-enterprise exchange, ensuring that even when data is transmitted over public networks, it can effectively prevent the risk of information leakage and tampering, thus greatly improving data security.

[0019] 2. This invention constructs a dynamic permission mechanism based on unique node identifiers, authorization management, and an index table, which requires member nodes to go through a strict authorization process when accessing supplier due diligence information. Therefore, it can ensure that only nodes with the supplier's consent can access the data, thus realizing the controllability and legality of data sharing in access control.

[0020] 3. By constructing a cross-enterprise information sharing and process-oriented access mechanism, this invention can reduce the number of times vehicle manufacturers conduct repeated due diligence on the same supplier, while also reducing the complexity of information sharing. This greatly improves the efficiency of supplier information exchange, thereby reducing the human and time costs of due diligence for enterprises and improving the overall operational efficiency of data exchange.

[0021] 4. By generating trusted logs and timestamps during data access, authorization, and feedback, this invention enables full traceability of data exchange. Member nodes can audit access history at any time, thereby ensuring the transparency and compliance of supply chain management and due diligence processes.

[0022] It should be understood that the descriptions in this section are not intended to identify key or essential features of embodiments of the invention, nor are they intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Of course, implementing any product of the invention does not necessarily require achieving all of the advantages described above simultaneously. Attached Figure Description

[0023] The accompanying drawings, which form part of this application, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings: Figure 1 This is a schematic diagram of the overall operation process of the present invention; Figure 2 This is a schematic diagram of the supplier node decryption query message process of the present invention. Detailed Implementation

[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Unless otherwise specified, the embodiments and features in the embodiments of this application can be combined with each other. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0025] For details in the embodiments, please refer to Figure 1 and Figure 2 .

[0026] like Figure 1 As shown in the embodiment of the present invention, the method for exchanging information on sustainable due diligence between automotive companies and their suppliers includes: The exchange system comprises multiple automotive enterprise member nodes, multiple supplier nodes, and a due diligence data exchange center platform. Each member node accesses the system as a member of a trusted data space and receives a unique identifier code and key (no more than 256 bits in length) assigned by the system during registration. Each node is defined... The unique identifier code and key are:

[0027] in: The hash function used by the system. This is the registered name of the node. This is the registration timestamp. This identifier is recognized by all member nodes in the system and is used for node identification and access control; it cannot be changed. A key is also generated for this node:

[0028] in, Derived functions for the key used by the system. This is a system threshold. This key is held solely by the member node and hosted on the due diligence data exchange center platform via a key management service to ensure the confidentiality and integrity of communication between the member node and the platform. This key is not disclosed to other member nodes or supplier nodes.

[0029] Each supplier node possesses a key pair in the trusted data space. When adding data to a trusted data space, generate a key pair for it:

[0030] Among them, This refers to the public key. The public key is managed centrally by the platform and made public to all member nodes, used for encrypted communication; the private key is held only by the supplier and used to decrypt content encrypted by the public key, ensuring the uniqueness and security of authorized operations.

[0031] Member nodes can access the due diligence data exchange center platform via public infrastructure networks (such as the Internet). As a core component of the trusted data space, this platform is responsible for the registration, encrypted storage, permission allocation, access control, and interaction log management of due diligence data, ensuring the security and trustworthiness of data during cross-enterprise sharing.

[0032] During system operation, each member node independently maintains its own supplier list, which is not disclosed to other nodes by default to ensure data sovereignty and privacy. The due diligence data exchange center platform stores the ongoing due diligence data of each supplier. This information is encrypted and digitally signed when uploaded to the platform, and includes a trusted timestamp to ensure the authenticity, integrity, immutability, and traceability of the data.

[0033] The system of this invention consists of four main workflows: Process 1: Node sends request When a member node needs to obtain sustainable due diligence information from a specific supplier, it must first execute this process to initiate a data access request.

[0034] The steps and description are as follows: Step 1: Member nodes determine the supplier objects to be queried in their local systems based on business requirements. And obtain the supplier's unique identification code from the trusted data space registration information. ; Step 2: Member nodes use their own keys This data segment Perform symmetric encryption: ; in, The symmetric encryption function used by the system. To generate the timestamp for this request, This is the generated encrypted string. To ensure the integrity and immutability of the request source, member nodes generate authentication tags based on their symmetric keys: ; in, This function generates the message authentication code. Subsequently, the node assigns its own unique identifier code. With encrypted target supplier identification code Message authentication code Combine them to form the core data segment of the request message: ; Step 3: Member nodes transmit the encrypted request message obtained in Step 2 through the trusted data space interface. Send to the due diligence data exchange center platform.

[0035] Step 2: Platform checks permissions When the due diligence data exchange center platform receives an encrypted request from a member node, it needs to verify the request's permissions to determine whether the node is authorized to access the target supplier's due diligence data.

[0036] The steps and description are as follows: Step 1: After receiving the encryption request, the platform first uses the unique identifier code of the member node carried in the request. Retrieve the corresponding key from the registration information The platform uses this key to decrypt encrypted requests: ; in, This is the symmetric decryption function used by the system. The system extracts the member node identifier code through this process. With the target supplier identification code ; Step 2: The platform verifies the message authentication code attached to the message. Verification required: ; If verification identifier for If the verification is successful, it ensures that the request source is authentic, the content is complete, and it has not been tampered with. If the verification fails, the request is invalidated and recorded in the security log. Step 3: The platform maintains a supplier access index table in the trusted data space. This table records which OEM nodes have obtained authorized access permissions to the supplier. The platform then uses the decrypted supplier identification code... Query whether a matching member node exists in the index table. Corresponding supplier identification code Access history: ; in, To access the index table.

[0037] Step 4: If for If the query result matches, meaning the member node has authorization to access the target supplier's due diligence data, the platform confirms the access permission is valid and proceeds to process 4 to return the data; if for If the query fails to find a match, it means that the member node has not yet obtained authorization to access the supplier's data. The platform then records the request and proceeds to process 3 to initiate the authorization request mechanism.

[0038] Step 3: Request access permissions This process will be executed when the due diligence data exchange center platform determines in process 2 that a member node does not yet have the authorization to access the target supplier's due diligence data.

[0039] The steps and description are as follows: Step 1: When the platform detects that the requesting node does not have access rights, it will send a signal requesting authorization to the target supplier node. At the same time, the platform will return a status signal to the member node that initiated the request, indicating that the current access requires authorization confirmation. Step 2: After receiving the status signal returned by the platform, the member node generates a temporary session symmetric key. The member node uses the target supplier node's public key to encrypt the generated temporary key, its own unique identifier, and the authorization request timestamp, generating an encrypted key message: ; in, It is a function that uses public-key encryption. For the public key of the supplier node, For sharing timestamps.

[0040] Step 3: The supplier node receives the encryption key message. Then, decrypt using your own private key: ; in, This is a function that uses a private key for decryption. The supplier node verifies the timestamp. The message is verified. If the verification passes, the process continues to the next step; otherwise, a retransmission of the message is requested.

[0041] Step 4: The platform has informed the supplier nodes of the requesting member node's identity information and request intent. Suppliers decide whether to grant access based on their own data sharing policies, partnerships, or compliance requirements. Step 5: If the supplier If authorized access is granted, the supplier node sends an "Authorization Agreement" message to the due diligence data exchange center platform: ; This information includes: authorized object identifier, supplier node identifier, and timestamp. Temporary keys for member nodes Next, the supplier node uses its own private key to perform a digital signature: ; in, It is a function that generates message digests. This is a function that uses a private key to encrypt and generate a digital signature. The supplier node will then send the information... and signature Send them together to the due diligence data exchange center platform.

[0042] Step 6: The platform uses the supplier's public key to decrypt the signature. And verify whether the summary matches the information ontology: ; in, It is a function that uses a public key for decryption. (If verification...) and If they are the same, it means the message has not been tampered with, and the platform simultaneously obtains the temporary session key. This establishes the shared encryption context required for subsequent data transmission; otherwise, the platform requests the provider to retransmit.

[0043] Step 4: Platform sends back data Once the due diligence data exchange center platform confirms in the previous process that the member node has been authorized to access the target supplier's due diligence data, it will execute this process to securely send the requested data back to the member node.

[0044] The steps and description are as follows: Step 1: If the current access request has gone through the authorization process in Step 3, the platform first updates the vendor access index table in the trusted data space. The platform will write the member node identifier code, target supplier identifier code, authorization timestamp, and digital signature information for this authorization into an index table, which includes: ; Step 2: The platform extracts the due diligence data file corresponding to the target supplier from the encrypted storage area. The platform uses temporary session keys. Encrypt the data to ensure that only the target member node can use its key to decrypt and view it: ; in, This is the timestamp when the file was extracted. Additionally, the platform provides data signing so that member nodes can verify data integrity. ; Step 3: After receiving the returned data, the member node decrypts it using the temporary session key. ; It also verifies the digital signature and timestamp. Once verified, the node can view the supplier's sustainable due diligence information in a local trusted environment and perform analysis or decisions as needed for business purposes.

[0045] On one hand, this invention further discloses a specific operational procedure for a method of exchanging information on sustainable due diligence between automotive companies and their suppliers. This method uses an internal computer server of the automotive company as a member node, an internal server of the supplier as a supplier node, TCP / IP as the network communication protocol, HTTP as the data exchange application protocol, JSON as the data message format, SHA-3 as the hash function, HMAC as the MAC algorithm, RSA-4096 as the asymmetric encryption algorithm, AES-256 as the symmetric encryption algorithm, and SHA-256 as the digital signature algorithm. PostgreSQL and MongoDB are used as the data storage implementation schemes. All communication over public infrastructure networks is end-to-end encrypted using Transport Layer Security (TLS / SSL) protocols to ensure the confidentiality, integrity, and authentication of data during transmission. In this embodiment, each member node holds only one symmetric key, which is private to the member node and not publicly disclosed. The platform can securely store or manage the verification materials of this key through a key management service according to business policies. The supplier node, on the other hand, holds a pair of asymmetric keys, such as... Figure 2 As shown, the specific process steps include: Process 1: Node sends request To obtain sustainable due diligence information from a specific supplier, a member node initiates a data access request. The steps and description, depending on the specific solution, are as follows: Member nodes determine the suppliers for whom they need to query information based on business requirements in their local systems, and obtain their unique identification codes through the due diligence data exchange center platform.

[0046] The node uses its own symmetric key to encrypt the supplier identification code and timestamp using the AES-256 symmetric encryption algorithm to generate an encrypted string.

[0047] The node combines its own unique identifier code with the encrypted supplier identifier code as the core field of the message, and generates a message authentication tag based on the symmetric key and timestamp for the core field. The authentication tag, along with its own unique identifier, the encrypted supplier identifier, and the timestamp, are then combined to form a JSON-formatted request message.

[0048] The node sends encrypted messages to the due diligence data exchange center platform via an HTTP POST request.

[0049] Step 2: Platform checks permissions After receiving a request message from a member node, the platform first verifies the message authentication tag to check the message's integrity and origin.

[0050] After successful verification, the platform uses the member node's AES-256 key to decrypt the message and extract the member node identifier and supplier identifier.

[0051] The platform queries the existing authorization history of the supplier in the index table built in PostgreSQL based on the supplier identifier, and determines whether there is a record corresponding to the member node.

[0052] If a response record exists, the access permission is confirmed to be valid and the process proceeds to step 4 to send the data back.

[0053] If no response record exists, record the request information and proceed to process 3 to request authorization from the supplier node.

[0054] Step 3: Request access permissions The platform sends a "request authorization" signal to the supplier node and returns a "waiting for authorization" signal to the member node.

[0055] After receiving the signal, the member node generates a random AES-256 session key and uses the supplier's public key to encrypt the key along with its own identification code and authorization request timestamp to form an encrypted message, which is then sent to the supplier.

[0056] The supplier node uses its private key to decrypt and obtain the temporary session key generated by the member node, as well as the member node's identity code, and then reads the request content. See [link to decryption process] for details. Figure 2 .

[0057] Suppliers decide whether to authorize access based on their internal policies and compliance requirements. If authorization is granted, an authorization message is generated, which includes the supplier's own identifier, the identifier of the member node to be authorized, and the authorization timestamp. The supplier then signs the authorization message with its private key and sends it to the platform.

[0058] After the platform verifies the supplier's signature, it writes the authorization information into the index table, generates an access record hash value, and stores it in the log.

[0059] Step 4: Platform sends back data The platform updates the index table in PostgreSQL to record member node identifiers, supplier identifiers, authorization time, and digital signatures.

[0060] The platform extracts the target supplier due diligence data requested by member nodes from MongoDB, encrypts the data using the member nodes' AES-256 session keys, and attaches a signature and timestamp generated by the SHA-256 algorithm to ensure data integrity.

[0061] Next, the platform sends the data back to the member nodes via an HTTP POST request. The member nodes use their private keys to decrypt the data, verify the signature and timestamp, and then view and analyze it in their local trusted environment.

[0062] On the other hand, embodiments of this application also provide an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus. Memory, used to store computer programs; When the processor executes a program stored in memory, it implements the aforementioned method for exchanging information on sustainable due diligence between automotive companies and their suppliers.

[0063] The communication bus mentioned in the above-mentioned electronic devices can be a standard bus for interconnecting peripheral components or an extended industrial standard structure bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc.

[0064] The communication interface is used for communication between the aforementioned electronic devices and other devices.

[0065] The memory may include random access memory or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0066] The processors mentioned above can be general-purpose processors, including central processing units, network processors, etc.; they can also be digital signal processors, application-specific integrated circuits, field-programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0067] In another embodiment provided in this application, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute any of the automotive enterprise supplier sustainable due diligence information exchange methods described above.

[0068] It is understood that the system provided in the embodiments of the present invention corresponds to the method provided in the embodiments of the present invention, and the explanation, examples and beneficial effects of the relevant content can be referred to the corresponding parts of the above methods.

[0069] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, an optical medium, or a semiconductor medium, etc.

[0070] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

[0071] Furthermore, it should be noted that if any directional indication (such as up, down, left, right, front, back, etc.) is involved in the embodiments of the present invention, the directional indication is only used to explain the relative positional relationship and movement of each component in a specific posture. If the specific posture changes, the directional indication will also change accordingly.

[0072] Furthermore, if the embodiments of this invention involve descriptions such as "first" or "second," these descriptions are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined with "first" or "second" may explicitly or implicitly include at least one of those features. Additionally, the meaning of "and / or" throughout the text includes three parallel solutions; for example, "A and / or B" includes solution A, solution B, or a solution where both A and B are satisfied simultaneously. Furthermore, in the embodiments of this invention, "multiple" refers to two or more. Moreover, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed by this invention.

Claims

1. A method for exchanging sustainable due diligence information among automotive companies and their suppliers, based on an exchange system consisting of multiple automotive company member nodes, multiple supplier nodes, and a due diligence data exchange center platform, characterized in that... include: S1. When a member node obtains sustainable due diligence information from a specific supplier, it sends an encrypted request to the due diligence data exchange center platform. S2. After receiving an encrypted request, the due diligence data exchange center platform performs an authorization check to determine whether the node has the specified authorization qualification; S3. When the platform determines that a node is not authorized, it issues a specified authorization result through the supplier to enable authorized access; S4. After the platform determines and confirms that the member node has obtained authorization, it sends the requested data back to the node; The specific operation process of step S2 includes: S21. After receiving the encryption request, the platform first uses the unique identifier code of the member node carried in the request. Retrieve the corresponding key from the registration information The platform uses keys hosted by member nodes to decrypt encrypted requests. ; in, This is the symmetric decryption function used by the system. The encrypted string generated for encrypting the key; the system extracts the member node identification code through this process. With the target supplier identification code ; S22. Platform authentication code attached to the message Verification required: ; in For message authentication verification operations, The timestamp of the request generated for key encryption. Generate authentication tags for the symmetric key; S23. The platform maintains a supplier access index table in the trusted data space to record the vehicle enterprise nodes that have obtained authorized access permissions from the supplier; The platform uses the decrypted supplier identification code Query the index table to see if there exists a matching member node. Corresponding supplier identification code Access history: ; in, To access the index table; S24. If for If the query result matches, meaning the member node has authorization to access the target supplier's due diligence data, the platform confirms the access permission is valid and proceeds to step S4 to perform the data return operation; if for If the query result is not found, it means that the member node has not yet obtained access authorization for the supplier's data; the platform then records the request and proceeds to step S3 to initiate the authorization application mechanism.

2. The method for exchanging information on sustainable due diligence between automotive companies and their suppliers as described in claim 1, characterized in that, Each member node of the exchange system accesses the system as a member of the trusted data space and obtains a unique identification code and key of no more than 255 binary bits assigned by the system during registration; The member nodes access the due diligence data exchange center platform through a designated network. The platform stores the sustainable due diligence data of each supplier and is used to register, encrypt, store, assign permissions, control access, and manage interaction logs of the due diligence data. During the operation of the exchange system, each member node independently maintains its own supplier list, and this supplier list data is not disclosed to other nodes to ensure data sovereignty and privacy security. The information from each node in the exchange system is encrypted and digitally signed before being uploaded to the platform, and is accompanied by a trusted timestamp.

3. The method for exchanging information on sustainable due diligence of automotive enterprise suppliers as described in claim 2, characterized in that, In the switching system, each node is defined. The unique identifier code and key are: ; in, The hash function used by the system. This is the registered name of the node. For registration timestamp; The identification code is recognized by all member nodes in the system, used for node identification and access control, and cannot be changed. It also generates a key for that node. ; in, Derived functions for the key used by the system. This is the system threshold; the key is not disclosed to other nodes after it is generated. Each supplier node possesses a key pair in the trusted data space; supplier nodes When adding data to a trusted data space, generate a key pair for it: ; in This refers to the public key. The private key is used for encryption communication; the supplier's public key is managed centrally by the platform and made public to all member nodes. The supplier holds the private key only and uses it to decrypt content encrypted with the public key.

4. The method for exchanging information on sustainable due diligence between automotive companies and their suppliers as described in claim 3, characterized in that, The specific operation process of step S1 includes: S11. Member nodes determine the supplier objects to be queried in the local system based on business requirements. And obtain the supplier's unique identification code from the trusted data space registration information. ; S12. Member nodes use their own keys shared with the platform. This data segment Perform symmetric encryption: ; in, The symmetric encryption function used by the system. To generate the timestamp for this request, The generated encrypted string; Authentication tags are generated by member nodes based on their symmetric keys. : ; in, A function for generating message authentication codes; The node will have its own unique identifier code. With encrypted target supplier identification code Message authentication code Combined, they form the core data segment of the encrypted request message. : ; S13. Member nodes transmit the encrypted request message obtained in step S12 through the trusted data space interface. Send to the due diligence data exchange center platform.

5. The method for exchanging information on sustainable due diligence between automotive companies and their suppliers as described in claim 4, characterized in that, The message authentication verification operation The verification process is as follows: The platform first uses its locally stored session key. For the received message content ( Recalculate a new set of message authentication tags, denoted as... ; The newly calculated With received Perform a comparison; like and If they are completely identical, it indicates a verification identifier. for If so, it can be approved, ensuring that the request source is authentic, the content is complete, and it has not been tampered with; Otherwise, the verification failed, the request was invalidated, and recorded in the security log.

6. The method for exchanging information on sustainable due diligence of automotive enterprise suppliers as described in claim 5, characterized in that, The specific operation process of step S3 includes: S31. When the platform detects that the requesting node does not have access rights, it will send a signal requesting authorization to the target supplier node. At the same time, the platform will return a status signal to the member node that initiated the request, indicating that the current access requires authorization confirmation. S32. Upon receiving the platform signal, the member node uses the target supplier node's public key to its own private key. Encryption is performed to generate an encryption key message: ; in, It is a function that uses public-key encryption. For the public key of the supplier node, For shared timestamps; S33. The supplier node receives the encryption key message. Then, decrypt using your own private key: ; in, This is a function that uses a private key for decryption; the supplier node verifies the timestamp. The message is verified; if the verification passes, the next step is continued; otherwise, the message is retransmitted. Supplier nodes obtain member nodes' keys Then, the key is used to decrypt the original query message in order to read the request content and verify the request: ; S34. Suppliers may decide whether to grant access based on their own data sharing policies, partnerships, or compliance requirements; S35. If the supplier If authorized access is granted, the supplier node sends an "Authorization Agreement" message to the due diligence data exchange center platform: ; This information includes the authorized object identifier, supplier node identifier, and timestamp. ; Supplier nodes use their own private keys to perform digital signatures: ; in, It is a function that generates message digests. It is a function that uses a private key to encrypt and generate a digital signature; Supplier nodes will provide information and signature Send them together to the due diligence data exchange center platform; S36. The platform uses the supplier's public key to decrypt the signature. And verify whether the summary matches the information ontology: in, It is a function that uses a public key for decryption. (If verification...) and If the messages are identical, it means the message has not been tampered with, and the process continues; otherwise, the platform requests the supplier to retransmit.

7. The method for exchanging information on sustainable due diligence between automotive companies and their suppliers as described in claim 6, characterized in that, The specific operation process of step S4 includes: S41. The platform first updates the vendor access index table in the trusted data space. Then, the member node identifier code, target supplier identifier code, authorization timestamp, and digital signature information for this authorization are written into the index table, resulting in: ; S42. The platform extracts the due diligence data file corresponding to the target supplier from the encrypted storage area. The platform uses the requesting member node's key to encrypt the data, ensuring that only the target member node can use its key to decrypt and view it. ; in, Represents a symmetric encryption function. The symmetric key for the member node. It is the timestamp when the file was extracted; at the same time, the platform also records the encrypted data. Computing data signatures This is so that member nodes can verify data integrity. ; S43. Member nodes receive returned data. and Then, use its own key. Regarding the received Recalculate a data signature and received If the two match, the verification passes, proving that the data has not been tampered with. After successful verification, the node decrypts the data using its own key. ; in yes After successful verification using the corresponding decryption function, the node can view the supplier's sustainable due diligence information in its local trusted environment.

8. An information exchange device for sustainable due diligence of automotive enterprise suppliers, characterized in that, It includes a memory and a processor, the memory storing a computer program that, when executed by the processor, causes the processor to perform the steps of the automotive supplier sustainable due diligence information exchange method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Block chain-based data sharing platform system, equipment and data sharing method

    CN112583802A

  • Method, device and system for processing customer full-duty survey data

    CN114048246A