A method, system, apparatus, and medium for provenance auditing of a semiconductor manufacturing knowledge base
By using a role-based multi-level permission model and digital watermarking and blockchain technology, the problems of crude permission control and insufficient traceability in semiconductor manufacturing knowledge base are solved, realizing refined permission allocation and full lifecycle traceability auditing, ensuring intellectual property security and manufacturing stability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CLP JIUTIAN INTELLIGENT TECH CO LTD
- Filing Date
- 2026-03-24
- Publication Date
- 2026-06-09
Smart Images

Figure CN122173495A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of semiconductor manufacturing technology, and more specifically, to a method, system, equipment, and medium for tracing and auditing a semiconductor manufacturing knowledge base. Background Technology
[0002] The semiconductor manufacturing industry contains a large amount of intellectual property-sensitive information, such as core process formulas, equipment operating parameters, and process control logic. This information directly determines the performance and competitiveness of semiconductor products and is an important component of a company's core intellectual property. Currently, the management of semiconductor manufacturing knowledge bases generally suffers from the following shortcomings: First, the access control model is crude, often employing a single level or simple role division, failing to achieve refined access allocation based on personnel positions and responsibilities. This results in unauthorized personnel potentially accessing core sensitive knowledge, or authorized personnel having redundant permissions leading to leakage risks. Second, the ability to trace the entire lifecycle of knowledge items is insufficient. Operations such as the creation, modification, application, and deletion of knowledge lack complete records, making it difficult to meet industry compliance audit requirements, and preventing accurate rollback in case of erroneous modifications or malicious tampering. Third, there is a lack of effective means to prevent leakage and tampering. Core process knowledge is easily copied, disseminated, or altered illegally, leading to damage to the company's intellectual property and affecting the stability and security of semiconductor manufacturing.
[0003] Therefore, designing a technical solution that enables refined access control, end-to-end traceability and auditing, and effectively prevents knowledge leakage and tampering to address the intellectual property protection needs of semiconductor manufacturing knowledge bases has become an urgent technical problem to be solved. Summary of the Invention
[0004] This invention addresses the problem of easy leakage and tampering of knowledge in semiconductor manufacturing processes by proposing a traceability and auditing method, system, equipment, and medium for semiconductor manufacturing knowledge bases. It employs a role-based multi-level permission model, combined with knowledge item sensitivity level classification, to achieve refined permission allocation, effectively preventing unauthorized personnel from accessing core sensitive knowledge and reducing the risk of intellectual property leakage. By combining digital watermarking and blockchain technologies, a comprehensive anti-leakage and anti-tampering protection system is formed, solving the pain point of easy leakage and tampering of sensitive knowledge in the semiconductor manufacturing field.
[0005] The specific implementation details of this invention are as follows: A traceability auditing method for a semiconductor manufacturing knowledge base specifically includes the following steps: Step S1: Construct a semiconductor manufacturing knowledge base based on the knowledge items extracted from multi-dimensional features; Step S2: Construct a role-based multi-level permission model based on the semiconductor manufacturing knowledge base; Step S3: Based on the multi-level permission model and operation information, call the hash algorithm to calculate the hash value and build the source tracing record engine; Step S4: Based on the hash value obtained from the traceability record engine, calculate the watermark capacity, embed the digital watermark into the redundant data bits of the knowledge item, and upload it to the blockchain node for evidence storage. Step S5: Compare the traceability log hash value obtained from the blockchain with the currently queried log hash value to generate traceability audit results.
[0006] To better realize the present invention, step S1 further includes the following steps: Step S11: Extract knowledge items from multi-dimensional features to obtain the confidentiality weight and access risk weight of the knowledge items; Step S12: Calculate the sensitivity coefficient based on the set confidentiality coefficient, access risk coefficient, confidentiality weight, and access risk weight; Step S13: Calculate the sensitivity level of knowledge items based on the sensitivity coefficient, and construct a semiconductor manufacturing knowledge base based on the sensitivity level of knowledge items.
[0007] To better realize the present invention, the sensitivity level of the knowledge item further includes core-level knowledge items, ordinary-level knowledge items, and public-level knowledge items.
[0008] To better realize the present invention, step S2 further includes the following steps: Step S21: Calculate the permission value based on the set role level correction coefficient, knowledge item sensitivity level correction coefficient, role level, and sensitivity coefficient; Step S22: Construct a role-based multi-level permission model based on permission values.
[0009] To better implement the present invention, step S3 further includes the following operations: Step S31: Based on the operation information, operation timestamp, and random interference number, call the hash algorithm to encrypt the operation information and obtain the hash value; Step S32: Use the hash value as the unique identifier of the traceability log, and store the traceability log in blocks according to the time dimension.
[0010] To better realize the present invention, step S4 further includes the following steps: Step S41: Calculate the watermark capacity based on the set embedding strength and the amount of data for core-level knowledge items; Step S42: Based on the watermark capacity, call the spatial domain digital watermark embedding technology to embed the digital watermark containing the knowledge ownership identifier and authorized viewing scope information into the redundant data bits of the core-level knowledge item, and call the grayscale adjustment algorithm to control the watermark embedding depth. Step S43: Based on the set number of blockchain nodes, invoke the practical Byzantine fault-tolerant consensus mechanism to synchronously upload the content hash value of core-level knowledge items, the traceability log hash value, and node verification information to the blockchain node for storage.
[0011] To better implement the present invention, the specific operation of step S5 is as follows: obtain the traceability log hash value from the blockchain, compare it with the currently queried log hash value, if the traceability log hash value is consistent with the log hash value, it is determined that the log has not been tampered with; if they are inconsistent, use the knowledge item version hash value matching technology to locate the knowledge item hash value of the specified historical version, and combine it with the historical operation records stored on the blockchain to roll back the knowledge item to the corresponding historical version.
[0012] Based on the aforementioned traceability auditing method for semiconductor manufacturing knowledge bases, and to better realize this invention, a traceability auditing system for semiconductor manufacturing knowledge bases is further proposed, for executing the aforementioned traceability auditing method for semiconductor manufacturing knowledge bases; including a knowledge base module, an access control module, a traceability record module, a leakage prevention and tampering prevention module, and an audit loop module; The knowledge base module is used to construct a semiconductor manufacturing knowledge base based on the knowledge items extracted from multi-dimensional features. The access control module is used to construct a role-based multi-level access control model based on the semiconductor manufacturing knowledge base. The source tracing recording module is used to calculate the hash value by calling a hash algorithm based on the multi-level permission model and operation information, and to build the source tracing recording engine. The anti-leakage and tampering module is used to calculate the watermark capacity based on the hash value obtained from the traceability record engine, embed the digital watermark into the redundant data bits of the knowledge item, and upload it to the blockchain node for evidence storage. The audit loop module is used to compare the hash value of the traceability log obtained from the blockchain with the hash value of the currently queried log to generate the traceability audit result.
[0013] Based on the aforementioned traceability auditing method for semiconductor manufacturing knowledge base, and to better realize this invention, an electronic device is further proposed, including a memory and a processor; the memory stores a computer program; when the computer program is executed on the processor, the aforementioned traceability auditing method for semiconductor manufacturing knowledge base is implemented.
[0014] Based on the aforementioned traceability auditing method for the semiconductor manufacturing knowledge base, and to better realize this invention, a computer-readable storage medium is further proposed, wherein computer instructions are stored on the computer-readable storage medium; when the computer instructions are executed on the aforementioned electronic device, the aforementioned traceability auditing method for the semiconductor manufacturing knowledge base is implemented.
[0015] The present invention has the following beneficial effects: (1) The present invention adopts a role-based multi-level permission model, combined with the knowledge item sensitivity level classification, to realize the fine allocation of permissions. It can accurately control the viewing, modification and application permissions of knowledge items according to the differences in personnel positions and responsibilities, effectively avoid unauthorized personnel from accessing core sensitive knowledge and reduce the risk of intellectual property leakage.
[0016] (2) This invention realizes full-chain traceability of knowledge items throughout their entire life cycle, and fully records various operation information. It not only meets the industry's compliance audit requirements, but also can quickly locate problems and trace responsibilities when anomalies occur. At the same time, through the operation rollback function, knowledge items that have been erroneously modified or tampered with can be restored in a timely manner, ensuring the accuracy and integrity of the knowledge base.
[0017] (3) This invention combines digital watermarking and blockchain technologies to form a comprehensive anti-leakage and anti-tampering protection system: digital watermarking can trace the source of leakage, and blockchain can realize the permanent and tamper-proof storage of core knowledge items and operation records, providing dual protection for the security of core intellectual property rights and solving the pain point of easy leakage and tampering of sensitive knowledge in the semiconductor manufacturing field.
[0018] (4) The system design of this invention is in line with the actual job requirements of semiconductor manufacturing enterprises. The permissions are clearly defined and the operation is convenient. The audit and rollback functions can quickly respond to compliance requirements and abnormal handling requirements, improve the efficiency of knowledge base management, ensure the stability and confidentiality of semiconductor manufacturing processes, and enhance the core competitiveness of enterprises. Attached Figure Description
[0019] Figure 1 A schematic flowchart of the traceability and auditing method for the semiconductor manufacturing knowledge base provided by this invention. Detailed Implementation
[0020] To more clearly illustrate the technical solutions of the embodiments of the present invention, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments, and therefore should not be regarded as a limitation on the scope of protection. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "set up," "connected," and "linked" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0022] Example 1: This embodiment proposes a traceability auditing method for a semiconductor manufacturing knowledge base, which specifically includes the following steps: Step S1: Construct a semiconductor manufacturing knowledge base based on the knowledge items extracted from multi-dimensional features; Step S1 specifically includes the following steps: Step S11: Extract knowledge items from multi-dimensional features to obtain the confidentiality weight and access risk weight of the knowledge items; Step S12: Calculate the sensitivity coefficient based on the set confidentiality coefficient, access risk coefficient, confidentiality weight, and access risk weight; Step S13: Calculate the sensitivity level of knowledge items based on the sensitivity coefficient, and construct a semiconductor manufacturing knowledge base based on the sensitivity level of knowledge items.
[0023] The sensitivity levels of the knowledge items include core-level knowledge items, general-level knowledge items, and public-level knowledge items.
[0024] Step S2: Construct a role-based multi-level permission model based on the semiconductor manufacturing knowledge base; Step S2 specifically includes the following steps: Step S21: Calculate the permission value based on the set role level correction coefficient, knowledge item sensitivity level correction coefficient, role level, and sensitivity coefficient; Step S22: Construct a role-based multi-level permission model based on permission values.
[0025] Step S3: Based on the multi-level permission model and operation information, call the hash algorithm to calculate the hash value and build the source tracing record engine; Step S3 specifically includes the following operations: Step S31: Based on the operation information, operation timestamp, and random interference number, call the hash algorithm to encrypt the operation information and obtain the hash value; Step S32: Use the hash value as the unique identifier of the traceability log, and store the traceability log in blocks according to the time dimension.
[0026] Step S4: Based on the hash value obtained from the traceability record engine, calculate the watermark capacity, embed the digital watermark into the redundant data bits of the knowledge item, and upload it to the blockchain node for evidence storage. Step S4 specifically includes the following steps: Step S41: Calculate the watermark capacity based on the set embedding strength and the amount of data for core-level knowledge items; Step S42: Based on the watermark capacity, call the spatial domain digital watermark embedding technology to embed the digital watermark containing the knowledge ownership identifier and authorized viewing scope information into the redundant data bits of the core-level knowledge item, and call the grayscale adjustment algorithm to control the watermark embedding depth. Step S43: Based on the set number of blockchain nodes, invoke the practical Byzantine fault-tolerant consensus mechanism to synchronously upload the content hash value of core-level knowledge items, the traceability log hash value, and node verification information to the blockchain node for storage.
[0027] Step S5: Compare the traceability log hash value obtained from the blockchain with the currently queried log hash value to generate traceability audit results.
[0028] The specific operation of step S5 is as follows: obtain the traceability log hash value from the blockchain and compare it with the currently queried log hash value. If the traceability log hash value is consistent with the log hash value, it is determined that the log has not been tampered with; if they are inconsistent, the knowledge item version hash value matching technology is used to locate the knowledge item hash value of the specified historical version, and combined with the historical operation records stored on the blockchain, the knowledge item is rolled back to the corresponding historical version.
[0029] Working principle: This embodiment realizes refined access control and full lifecycle traceability audit of sensitive knowledge in semiconductor manufacturing, while preventing the leakage and tampering of core knowledge, protecting the intellectual property security of enterprises, and meeting industry compliance requirements.
[0030] Example 2: This embodiment is based on the above embodiment 1, such as... Figure 1 As shown, a specific embodiment will be described in detail.
[0031] Step S1: Construct a semiconductor manufacturing knowledge base, classify the knowledge items in the knowledge base into core level, ordinary level and public level according to their sensitivity level and label them accordingly. The knowledge items include process formulas, equipment parameters, process specifications and testing standards. When constructing a semiconductor manufacturing knowledge base, multi-dimensional feature extraction is first performed on all knowledge items to determine their confidentiality weight and access risk weight. The sensitivity level of each knowledge item is then quantified using a sensitivity coefficient calculation formula to achieve accurate classification and labeling. The sensitivity coefficient calculation formula is as follows: ,in This is a weighting factor for classified information, with a range of values. , The access risk weighting coefficient has a range of values. And satisfy , For classified weight ( ), Access risk weight ( ); based on sensitivity coefficient Based on the differences in their values, knowledge items are divided into three levels: core level, general level, and public level. Among them, core level knowledge items satisfy... This corresponds to highly sensitive knowledge such as core process formulas and key equipment parameters, while general-level knowledge items meet the requirements. Corresponding to conventional process specifications and general equipment parameters, the open-source knowledge items meet the requirements. Based on industry-standard practices and basic operating guidelines, and after classification and labeling, a knowledge item index system is established to lay the foundation for subsequent access control and traceability.
[0032] Step S2: Construct a role-based multi-level permission model; the roles include administrators, authorized core personnel, process engineers, and general operators, and the permission model contains a mapping relationship between roles, permissions, and knowledge items to achieve fine-grained permission allocation.
[0033] Based on the above knowledge base classification results, an innovative role-based multi-level permission model is constructed. This model breaks through the traditional coarse-grained role division mode, adopts a quantitative approach to achieve precise mapping between role, permission, and knowledge item, and realizes fine-grained allocation of permissions through a permission value calculation formula. The permission value calculation formula is as follows: ,in This is a character level correction coefficient, with a value range of... , This is a sensitivity level correction coefficient for knowledge items, with a value range of... And satisfy , For the role level (administrator) Authorized core personnel Process Engineer General operators ), The sensitivity coefficient for the corresponding knowledge item; based on the access level. Threshold division, administrator privilege values It has full access to the knowledge base, including role creation, permission allocation, knowledge item review, and authorization of permission values for core personnel. It allows viewing and modifying all knowledge items at the core level and below. Modification of core-level knowledge items requires multiple layers of review. (Process Engineer's permission value) Users can view and apply general and public level knowledge items, and can submit modification requests for core level knowledge items but do not have direct modification permissions. (This refers to the permissions of ordinary operators.) Users can only view public knowledge items and cannot modify any knowledge items. After the permission model is built, a permission verification engine is embedded to realize real-time permission determination for all operation requests.
[0034] Step S3: Record the entire lifecycle operation information of knowledge items, including creation, modification, application, and deletion, to form an immutable traceability log; To achieve end-to-end traceability of knowledge items throughout their entire lifecycle, a traceability recording engine is built on top of the permission model. This engine collects and encrypts all operations related to the creation, modification, application, and deletion of knowledge items in real time. The SHA-256 hash algorithm is used to encrypt the operation information, generating an immutable traceability log. The hash calculation formula is as follows: ,in This includes operation information (including operator, operation content, and operation type). For operation timestamps (accurate to milliseconds). For random noise numbers, the range of values is... The hash value calculated using this formula As a unique identifier for the traceability log, ensuring the log content is immutable, the traceability log is also stored in blocks according to the time dimension, with the block size set to [value missing]. Each log entry corresponds to a unique block identifier, facilitating quick querying and auditing later.
[0035] Step S4: Embed digital watermarks into core-level knowledge items and upload the content hash value and traceability log information of core-level knowledge items to the blockchain to prevent leakage and tampering of core knowledge items; To address the core requirements of preventing leakage and tampering of core-level knowledge items, an innovative approach combines digital watermarking and blockchain technologies to construct a comprehensive protection system. Utilizing spatial digital watermarking embedding technology, an invisible digital watermark containing knowledge ownership identifiers and authorized viewing scope information is embedded into redundant data bits of the core-level knowledge item, with the embedding strength set accordingly. Watermark capacity ,in For the core-level knowledge items (in bytes), a grayscale adjustment algorithm is used to control the watermark embedding depth during the embedding process to avoid affecting the normal reading and use of the knowledge items; simultaneously, a blockchain evidence storage system with a consortium blockchain architecture is constructed, and the number of blockchain nodes is set. It adopts the Practical Byzantine Fault Tolerance (PBFT) consensus mechanism, which has a fault tolerance rate of [missing information]. Hash the content of core-level knowledge items Source log hash value In addition to node verification information, it is synchronously uploaded to all blockchain nodes for notarization. Leveraging the decentralized and immutable characteristics of blockchain, it achieves permanent notarization of core knowledge items and operation records. The data synchronization cycle between nodes is set to [missing information]. This ensures the timeliness and consistency of the evidence storage information.
[0036] Step S5: Conduct a compliance audit based on the source tracing logs and support rolling back knowledge items to a specified historical version.
[0037] The compliance audit and operation rollback functions are implemented based on the aforementioned traceability records and blockchain evidence storage technology. No additional hardware modules are required. The audit engine calls the traceability log hash value stored on the blockchain and compares it with the currently queried log hash value. If they match, the log is determined not to have been tampered with. Auditors can conduct compliance audits based on time, role, knowledge item type, and other dimensions to verify unauthorized operations, unauthorized modifications, and other behaviors. When erroneous modifications, malicious tampering, or knowledge item anomalies occur, the knowledge item version hash value matching technology is used to locate the hash value of a specified historical version of the knowledge item. By combining historical operation records stored on the blockchain, knowledge items are rolled back to their corresponding historical versions, and the hash value of the rollback operation is recorded during the rollback process. To ensure that rollback operations are traceable and tamper-proof, and that rollback response time is controlled within [timeframe missing]. Within this range, it meets the requirements for real-time anomaly handling.
[0038] The other parts of this embodiment are the same as those in Embodiment 1 above, so they will not be described again.
[0039] Example 3: This embodiment is based on any one of the above embodiments 1-2, and is described in detail with a specific embodiment.
[0040] This embodiment of the semiconductor manufacturing knowledge base includes three categories of knowledge items: core level (such as 7nm chip etching process formula, core operating parameters of lithography machine), general level (such as conventional chip packaging process specifications, parameters of general testing equipment), and public level (such as general standards of semiconductor manufacturing industry, basic operation manual).
[0041] The roles and corresponding permissions in the permission model are as follows: Administrator: Responsible for creating roles (authorizing core personnel, process engineers, and general operators), assigning permissions to each role, reviewing modification requests for core-level knowledge items, viewing all traceability logs, executing operation rollbacks, and having full access to the knowledge base; Authorized core personnel: These are core technical personnel of the enterprise. They can view all knowledge items at the core, ordinary, and public levels. They can directly modify ordinary and public knowledge items. When modifying core knowledge items, a modification application and modification plan must be submitted. The modification can only be completed after being reviewed and approved by two administrators. The entire modification process is recorded. Process Engineers: Can view general and public knowledge items, and can apply relevant knowledge items in the production process. If they find that there is room for optimization in core knowledge items, they can submit modification suggestions, but they do not have direct modification permissions. When applying knowledge items, they need to record the application scenario and application effect. Regular operators: can only view public knowledge items, which are used to guide basic operations. They cannot view sensitive knowledge, nor can they perform any operations other than modification or application of records.
[0042] Traceability Recording Process: When authorized core personnel modify the 7nm chip etching process formula, the traceability recording module automatically records the modifier (name, employee number), modification time, the original process formula content, the modified process formula content, and the reason for modification (such as optimizing etching efficiency). At the same time, it records the reviewers (2 administrators), review time, and review comments, forming a complete traceability log. When the process engineer applies the modified formula to production, it records the user, application time, production batch, and application effect (such as etching pass rate).
[0043] Leakage and tamper-proof protection: An invisible digital watermark is embedded in the 7nm chip etching process formula. The watermark information includes the company logo and authorized viewing role (authorized core personnel). If the formula is illegally copied and spread externally, the watermark information can be extracted using a watermark extraction tool to trace the source of the leak. At the same time, the content hash value of the formula and the aforementioned traceability log information are uploaded to the blockchain node. The blockchain achieves synchronized information storage through a consensus mechanism. If someone attempts to tamper with the formula content or traceability log, it will result in a hash value mismatch, failing the blockchain verification, thus achieving tamper-proof protection.
[0044] Compliance Audit and Operation Rollback: Auditors conduct a compliance audit of the knowledge base every quarter, checking the source logs for unauthorized operations (such as process engineers viewing core-level knowledge items) and unauthorized modifications (such as modifying core-level knowledge items without approval), and generating an audit report. If it is found that authorized core personnel have mistakenly modified process formula parameters, resulting in a decrease in production qualification rate, the administrator can use the operation rollback function to roll back the formula to the version before the modification based on the source logs, and restore normal production.
[0045] In this embodiment, the access control method for the semiconductor manufacturing knowledge base is implemented through a multi-step technical deployment. The specific technical implementation process is as follows: First, a semiconductor manufacturing knowledge base was constructed. A knowledge item feature extraction algorithm was used to extract multi-dimensional features of confidentiality and access risk from various knowledge items, including process formulas, equipment parameters, process specifications, and testing standards. Confidentiality features encompassed the technical confidentiality and market competitiveness weight of the knowledge item, while access risk features encompassed the access frequency and the scope of impact of leakage. After extraction, the confidentiality weight W1 and access risk weight W2 for each knowledge item were determined, with values controlled within the range of [0,1]. A confidentiality weight coefficient α = 0.7 and an access risk weight coefficient β = 0.3 (satisfying α + β = 1) were selected. The sensitivity coefficient was then calculated using the formula S = α × W1. The sensitivity coefficient S of each knowledge item is calculated using 1+β×W2. Based on the threshold value of S, knowledge items with S≥0.8 are labeled as core level (such as 7nm chip etching process formula, core operating parameters of lithography machine), those with S≤0.4<0.8 are labeled as ordinary level (such as conventional chip packaging process specifications, parameters of ordinary testing equipment), and those with S<0.4 are labeled as public level (such as general standards in semiconductor manufacturing industry, basic operation manuals). After classification, a knowledge item index system is established using the B+ tree index algorithm. The sensitivity level, feature parameters, storage address and other information of the knowledge items are entered into the index database to realize the rapid retrieval and location of knowledge items, providing technical support for subsequent access control and traceability.
[0046] Secondly, after the knowledge base is built, the deployment and implementation phase of the role-based multi-level permission model begins. First, role level parameters are configured through the permission control engine. Based on the job structure of semiconductor manufacturing enterprises, basic information for four roles—administrator, authorized core personnel, process engineer, and general operator—is entered sequentially. Level parameters R are set for each role: Administrator R=4, Authorized Core Personnel R=3, Process Engineer R=2, and General Operator R=1. A role level correction coefficient γ=0.6 and a knowledge item sensitivity level correction coefficient δ=0.4 (satisfying γ+δ=1) are selected. The permission value P for each role corresponding to different knowledge items is calculated using the permission value formula P=γ×R+δ×S. The permission threshold division standard is determined as follows: Administrator permission value P≥3.5, Authorized Core Personnel 3.0≤P<3.5, Process Engineer 2.0≤P<3.5. For ordinary operators with P < 2.0, the mapping relationship between role-permission value-knowledge item sensitivity level is entered into the permission database to complete the initial configuration of the permission model. Subsequently, the permission verification logic is embedded into the knowledge base access interface. When a user initiates a knowledge item access or operation request, the permission control engine automatically extracts the user's role level R and the sensitivity coefficient S of the target knowledge item, calculates the permission value P in real time, compares it with the preset threshold, and returns an allow or deny instruction to the interface after completing the permission verification. This achieves real-time permission determination for all operation requests. The review process for authorizing core personnel to modify core-level knowledge items involves configuring multi-level review nodes, synchronously pushing the modification application and modification plan to the designated administrator terminal. The modification operation can only be executed after all review nodes have completed the confirmation. The number of review nodes can be configured according to the enterprise's needs; in this embodiment, it is set to 2.
[0047] Third, after the permission model is deployed, a source tracing engine is built and its parameters are configured. First, the source tracing engine is integrated with the knowledge base's access interface and the permission control engine. The operation information collection frequency is configured to 10ms / time to ensure real-time collection of all operation information related to the creation, modification, application, and deletion of knowledge items. Then, the SHA-256 hash encryption algorithm is enabled, and hash calculation parameters are configured. This includes operation information O (containing the operator's identity, specific operation content, and operation type), an operation timestamp T accurate to milliseconds, and a random interference number r (in this embodiment, r is 568921, within the range
[10000] ). Within the range of 0, 999999, the hash value H is calculated using the hash calculation formula H = SHA256(O||T||r) to obtain a unique hash value H for each operation, which serves as the unique identifier for the traceability log. The generated traceability log is then stored in blocks according to the time dimension, with a block size of 16MB. Each log block is assigned a unique block identifier, which is associated with the hash value H of the corresponding operation and the sensitivity level information of the knowledge item. The logs are stored in an encrypted log database. At the same time, a log query interface is configured to support precise retrieval by time range, role identity, knowledge item type, operation type, and other dimensions, providing data support for subsequent compliance audits and operation rollbacks.
[0048] Fourth, the core-level knowledge item anti-leakage and anti-tampering protection system is implemented in the following steps: First, the digital watermark embedding unit is activated, using a spatial domain digital watermark embedding algorithm, with an embedding strength k=0.03 (within the range of [0.01, 0.05]), extracting the data volume D (unit: Byte) of the core-level knowledge item, calculating the watermark capacity using the formula C=k×D, embedding watermark information containing the enterprise's unique identifier and authorized viewing role scope into the redundant data bits of the core-level knowledge item, controlling the watermark embedding depth through a grayscale adjustment algorithm during the embedding process to ensure that the watermark is invisible and does not affect the normal reading and use of the knowledge item, and configuring a watermark extraction interface. When the core-level knowledge item is detected to be copied or disseminated, the watermark information can be extracted through this interface to trace the source of the leak; subsequently, a blockchain evidence storage system with a consortium blockchain architecture is deployed. In this embodiment, six blockchain nodes are deployed, including four core internal enterprise nodes and two compliance audit nodes, meeting the configuration requirement of N≥5. A Practical Byzantine Fault Tolerance (PBFT) consensus mechanism is adopted. Based on the number of nodes N=6, the fault tolerance rate f≈1.67 is calculated using the formula f=(N-1) / 3. Taking the integer f=1, this ensures that the abnormality of a single node does not affect the normal operation of the entire evidence storage system. The hash value Hc of the core-level knowledge item, the hash value H of the traceability log, and the verification information of each node are synchronously uploaded to all blockchain nodes. The data synchronization period between nodes is configured to 30 seconds, achieving permanent evidence storage of the core knowledge item content and operation records. When the core knowledge item content or traceability log is detected to have been tampered with, an anomaly will appear in the hash value comparison of the blockchain nodes, and the system will automatically trigger an early warning to prevent the tampering operation from taking effect.
[0049] Fifth, the technical implementation process of compliance audit and operation rollback functions is as follows: Auditors access the audit engine through the audit terminal, configure audit query conditions (such as audit time range, role type, and knowledge item sensitivity level), the audit engine calls the traceability log hash value in the blockchain evidence storage system, and compares it with the currently queried traceability log hash value in real time. If the two match, it is determined that the log has not been tampered with. The audit engine filters the target traceability log according to the query conditions, counts the number of abnormal operations (unauthorized operations, illegal modifications, etc.), the number of knowledge items involved, and related operator information, and automatically generates a standardized audit report; when erroneous modifications, malicious tampering, or abnormal knowledge items occur, the administrator... A rollback request is initiated through the rollback interface. The target knowledge item identifier and the time node of the historical version to be rolled back are input. The system uses knowledge item version hash value matching technology to locate the hash value Hh of the knowledge item in the historical version, calls the historical operation record and knowledge item content stored in the blockchain, and restores the knowledge item to the corresponding historical version. During the rollback process, the hash value Hr of the rollback operation is calculated by the formula Hr=SHA256(Hh||rollback person||rollback timestamp), and recorded in the traceability log and blockchain storage system to ensure that the rollback operation is traceable and tamper-proof. At the same time, the rollback response logic is optimized to control the rollback response time within 100ms to meet the requirements of real-time anomaly handling.
[0050] 8. The other parts of this embodiment are the same as any one of the above embodiments 1-2, so they will not be described again.
[0051] Example 4: Based on any one of Embodiments 1-3 above, this embodiment proposes a traceability auditing system for a semiconductor manufacturing knowledge base, used to execute the aforementioned traceability auditing method for a semiconductor manufacturing knowledge base; it includes a knowledge base module, an access control module, a traceability record module, a leakage prevention and tampering prevention module, and an audit loop module; The knowledge base module is used to construct a semiconductor manufacturing knowledge base based on the knowledge items extracted from multi-dimensional features. The access control module is used to construct a role-based multi-level access control model based on the semiconductor manufacturing knowledge base. The source tracing recording module is used to calculate the hash value by calling a hash algorithm based on the multi-level permission model and operation information, and to build the source tracing recording engine. The anti-leakage and tampering module is used to calculate the watermark capacity based on the hash value obtained from the traceability record engine, embed the digital watermark into the redundant data bits of the knowledge item, and upload it to the blockchain node for evidence storage. The audit loop module is used to compare the hash value of the traceability log obtained from the blockchain with the hash value of the currently queried log to generate the traceability audit result.
[0052] This embodiment also proposes an electronic device, including a memory and a processor; the memory stores a computer program; when the computer program is executed on the processor, it implements the above-described traceability audit method for the semiconductor manufacturing knowledge base.
[0053] This embodiment also proposes a computer-readable storage medium storing computer instructions; when the computer instructions are executed on the aforementioned electronic device, the aforementioned traceability auditing method for the semiconductor manufacturing knowledge base is implemented.
[0054] Working Principle: The semiconductor manufacturing knowledge base traceability and auditing system in this embodiment adopts a distributed deployment architecture. Based on the design of the technical solution described above, the technical implementation and integration are completed step by step in modules. The specific technical implementation steps are as follows: First, the overall system architecture is deployed. An industrial-grade server is selected as the core deployment hardware, configured with a CPU frequency of ≥3.0GHz, memory of ≥32GB, and hard disk capacity of ≥1TB. A distributed storage architecture is adopted, storing knowledge base data, permission data, and traceability log data on different storage nodes. A data encryption transmission protocol (SSL / TLS 1.3) is configured to ensure the security of data transmission between nodes. At the same time, a load balancer is deployed and a load balancing algorithm is configured to achieve even distribution of system requests and improve system stability.
[0055] The system in this embodiment includes a knowledge base module, an access control module, a source tracing and recording module, a leakage and tamper-proof module, an audit rollback module, and a user interaction module. These modules work together. (1) Knowledge base module: It adopts a distributed storage architecture to store various knowledge items, classifies and indexes knowledge items, supports fast query by knowledge item type and sensitivity level, and encrypts the knowledge items to ensure data security. The technical implementation steps of the knowledge base module are as follows: Deploy knowledge item storage services on distributed storage nodes, configure knowledge item classification and annotation interfaces, and connect to knowledge item feature extraction algorithms to achieve automatic classification and annotation of knowledge item sensitivity levels; build a knowledge item index service using the B+ tree index algorithm, input information such as the sensitivity level, feature parameters, and storage address of knowledge items, optimize the index retrieval logic, and ensure that the knowledge item query response time is ≤50ms; simultaneously configure knowledge item operation interfaces (query, add, modify, delete), and link them with the access control module to ensure that all knowledge item operations must undergo permission verification before execution; in addition, deploy a data backup service, configure a backup cycle of 24 hours, and adopt incremental backup to ensure the security and recoverability of the knowledge base data.
[0056] (2) Access Control Module: Built-in access control algorithm. When a user initiates an operation request, such as viewing core-level knowledge items or modifying ordinary-level knowledge items, the user's role and corresponding permissions are automatically verified. If it is an unauthorized operation, it is immediately rejected and the unauthorized behavior is recorded. Warning information is sent to the administrator. The technical implementation steps of the access control module are as follows: Deploy the access control engine on the core server, embedding the previously designed access value calculation logic and access verification algorithm. Configure role creation and access allocation interfaces, allowing administrators to input role information via the terminal, configure role level parameters R and correction coefficients γ and δ, calculate the access thresholds for different knowledge items corresponding to each role, and input the role-access-knowledge item mapping relationship into the access database. Deploy the access verification service, connecting with the knowledge base module and user interaction module. When a user initiates an operation request, the access verification service automatically extracts the user's role information and the sensitivity coefficient of the target knowledge item, calculates the access value in real time, and compares it with the threshold. If it is determined to be an unauthorized operation, the operation request is immediately rejected, and the unauthorized behavior (operator, operation time, operation content, and unauthorized type) is recorded. An alert is then sent to the administrator's terminal via the alert interface to ensure the real-time performance and effectiveness of access control.
[0057] (3) Traceability Record Module: It adopts an encrypted log format to record all operation information. The log content cannot be modified. It supports querying by time range, role, knowledge item type, operation type (create, modify, apply, delete) and other dimensions. It can export the log files required for auditing. The technical implementation steps of the traceability recording module are as follows: Deploy the traceability recording engine, configure the operation information collection interface, connect to the knowledge base module and the access control module, and collect operation information (operator, operation time, operation type, operation content, etc.) of the entire lifecycle of knowledge items in real time; enable the SHA-256 hash encryption algorithm, calculate the hash value H of the operation information according to the formula mentioned above, and use it as the unique identifier of the traceability log; configure the log block storage service, divide the traceability log into blocks according to the time dimension (block size 16MB), assign a unique block identifier to each log block, associate the hash value H with the knowledge item information, and store it in the encrypted log database; at the same time, deploy the log query and export service, which supports searching logs by time range, role, knowledge item type, operation type and other dimensions, and supports export formats such as PDF and Excel to meet compliance audit requirements.
[0058] (4) Anti-leakage and anti-tampering module: The digital watermarking unit adopts the spatial watermarking algorithm. The embedded watermark is invisible and tamper-proof, and does not affect the normal use of knowledge items; the blockchain evidence storage unit adopts the consortium blockchain architecture, which consists of internal enterprise nodes and compliance audit nodes to ensure the privacy and security of evidence storage information. The technical implementation steps of the anti-leakage and anti-tampering module are divided into two parts: First, the deployment of the digital watermarking unit. This involves deploying a digital watermark embedding and extraction service on the core server, configuring a spatial digital watermark embedding algorithm, setting the adjustable range of the embedding strength k to [0.01, 0.05], and connecting to the core-level knowledge item interface of the knowledge base module. When a core-level knowledge item is created or modified, the watermark embedding operation is automatically triggered, embedding watermark information containing knowledge ownership identifiers and authorized viewing scope into the redundant data bits of the knowledge item. Simultaneously, a watermark extraction interface is configured to support the extraction of watermark information to trace the source when a core-level knowledge item is suspected of leakage. Second, the deployment of the blockchain evidence storage unit. This involves building a consortium blockchain node (6 nodes in this embodiment), configuring the PBFT consensus mechanism, setting the node synchronization period to 30 seconds, deploying a hash value calculation service, and calculating the content hash value Hc of the core-level knowledge item and the traceability log hash value H in real time. The hash value and node verification information are then synchronously uploaded to all blockchain nodes for permanent evidence storage. Simultaneously, a hash value comparison service is deployed to detect the integrity of the core knowledge item content and the traceability log in real time, triggering an alert when tampering occurs.
[0059] (5) Audit rollback module: Provides a visual audit interface. Auditors can drag and drop filter conditions to query the source log, automatically count the number of abnormal operations and the number of knowledge items involved, and generate a standardized audit report; The operation rollback function supports accurate location of historical versions, one-click rollback, and records rollback operation information at the same time. The technical implementation steps of the audit rollback module are as follows: Deploy the audit engine, configure the audit query interface and audit report generation service, connect to the blockchain evidence storage system and traceability record module, allowing auditors to set audit conditions through a visual interface, retrieve traceability logs and perform hash comparisons, automatically collect abnormal operation information, and generate standardized audit reports; Deploy the operation rollback service, connect to the knowledge base module and blockchain evidence storage system, allowing administrators to input knowledge item identifiers and historical version time nodes, locate historical versions through knowledge item version hash value matching technology, call historical data stored on the blockchain, roll back the knowledge item to the specified version, and simultaneously record rollback operation information and upload it to the blockchain evidence storage system to ensure the traceability of rollback operations; Optimize the audit and rollback response logic to ensure that the audit query response time is ≤100ms and the rollback response time is ≤100ms.
[0060] (6) User interaction module: It adopts a combination of web and mobile terminals. After logging in, users with different roles will be shown the corresponding operation interface. The interface is simple and intuitive, easy to operate, and supports functions such as permission application, modification application, and log query.
[0061] The technical implementation steps of the user interaction module are as follows: A deployment method combining web and mobile terminals is adopted to develop interactive interfaces adapted to different terminals. Based on role-based permissions, corresponding operation function modules are displayed to users with different roles. The administrator interface includes functions such as role management, permission allocation, log viewing, and operation rollback; the authorized core personnel interface includes functions such as viewing and modifying knowledge items, and submitting modification requests; the process engineer interface includes functions such as viewing and applying knowledge items, and submitting modification suggestions; and the ordinary operator interface only includes the function of viewing public-level knowledge items. The module is integrated with the permission control module to achieve user authentication and permission adaptation, ensuring that users can only access function modules within their own permission scope. At the same time, the interface interaction logic is optimized to improve operational convenience, and offline caching of public-level knowledge items is supported for convenient offline viewing by ordinary operators.
[0062] After each module is deployed, system integration testing is conducted. The tests include the accuracy of permission verification, the integrity of traceability logs, the effectiveness of digital watermark embedding and extraction, the anti-tampering performance of blockchain evidence storage, the reliability of audit rollback function, and the coordination between modules. For issues such as response delays and data inconsistencies that occur during testing, module interfaces and operating parameters are optimized to ensure the overall stability of the system and that all technical indicators meet the design requirements. After the integration testing is passed, the system is deployed and put into practical application.
[0063] The other parts of this embodiment are the same as any one of the embodiments 1-3 above, so they will not be described again.
[0064] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Any simple modifications or equivalent changes made to the above embodiments based on the technical essence of the present invention shall fall within the protection scope of the present invention.
Claims
1. A method for tracing and auditing a semiconductor manufacturing knowledge base, characterized in that, Specifically, the following steps are included: Step S1: Construct a semiconductor manufacturing knowledge base based on the knowledge items extracted from multi-dimensional features; Step S2: Construct a role-based multi-level permission model based on the semiconductor manufacturing knowledge base; Step S3: Based on the multi-level permission model and operation information, call the hash algorithm to calculate the hash value and build the source tracing record engine; Step S4: Based on the hash value obtained from the traceability record engine, calculate the watermark capacity, embed the digital watermark into the redundant data bits of the knowledge item, and upload it to the blockchain node for evidence storage. Step S5: Compare the traceability log hash value obtained from the blockchain with the currently queried log hash value to generate traceability audit results.
2. The traceability auditing method for a semiconductor manufacturing knowledge base according to claim 1, characterized in that, Step S1 specifically includes the following steps: Step S11: Extract knowledge items from multi-dimensional features to obtain the confidentiality weight and access risk weight of the knowledge items; Step S12: Calculate the sensitivity coefficient based on the set confidentiality coefficient, access risk coefficient, confidentiality weight, and access risk weight; Step S13: Calculate the sensitivity level of knowledge items based on the sensitivity coefficient, and construct a semiconductor manufacturing knowledge base based on the sensitivity level of knowledge items.
3. The traceability auditing method for a semiconductor manufacturing knowledge base according to claim 2, characterized in that, The sensitivity levels of the knowledge items include core-level knowledge items, general-level knowledge items, and public-level knowledge items.
4. The traceability auditing method for a semiconductor manufacturing knowledge base according to claim 1, characterized in that, Step S2 specifically includes the following steps: Step S21: Calculate the permission value based on the set role level correction coefficient, knowledge item sensitivity level correction coefficient, role level, and sensitivity coefficient; Step S22: Construct a role-based multi-level permission model based on permission values.
5. The traceability auditing method for a semiconductor manufacturing knowledge base according to claim 1, characterized in that, Step S3 specifically includes the following operations: Step S31: Based on the operation information, operation timestamp, and random interference number, call the hash algorithm to encrypt the operation information and obtain the hash value; Step S32: Use the hash value as the unique identifier of the traceability log, and store the traceability log in blocks according to the time dimension.
6. The traceability auditing method for a semiconductor manufacturing knowledge base according to claim 3, characterized in that, Step S4 specifically includes the following steps: Step S41: Calculate the watermark capacity based on the set embedding strength and the amount of data for core-level knowledge items; Step S42: Based on the watermark capacity, call the spatial domain digital watermark embedding technology to embed the digital watermark containing the knowledge ownership identifier and authorized viewing scope information into the redundant data bits of the core-level knowledge item, and call the grayscale adjustment algorithm to control the watermark embedding depth. Step S43: Based on the set number of blockchain nodes, invoke the practical Byzantine fault-tolerant consensus mechanism to synchronously upload the content hash value of core-level knowledge items, the traceability log hash value, and node verification information to the blockchain node for storage.
7. The traceability auditing method for a semiconductor manufacturing knowledge base according to claim 6, characterized in that, The specific operation of step S5 is as follows: obtain the traceability log hash value from the blockchain and compare it with the currently queried log hash value. If the traceability log hash value is consistent with the log hash value, it is determined that the log has not been tampered with; if they are inconsistent, the knowledge item version hash value matching technology is used to locate the knowledge item hash value of the specified historical version, and combined with the historical operation records stored on the blockchain, the knowledge item is rolled back to the corresponding historical version.
8. A traceability auditing system for a semiconductor manufacturing knowledge base, used to execute the traceability auditing method for a semiconductor manufacturing knowledge base as described in claim 1; characterized in that, It includes a knowledge base module, an access control module, a traceability record module, a leak prevention and tampering prevention module, and an audit loop module; The knowledge base module is used to construct a semiconductor manufacturing knowledge base based on the knowledge items extracted from multi-dimensional features. The access control module is used to construct a role-based multi-level access control model based on the semiconductor manufacturing knowledge base. The source tracing recording module is used to calculate the hash value by calling a hash algorithm based on the multi-level permission model and operation information, and to build the source tracing recording engine. The anti-leakage and tampering module is used to calculate the watermark capacity based on the hash value obtained from the traceability record engine, embed the digital watermark into the redundant data bits of the knowledge item, and upload it to the blockchain node for evidence storage. The audit loop module is used to compare the hash value of the traceability log obtained from the blockchain with the hash value of the currently queried log to generate the traceability audit result.
9. An electronic device, characterized in that, It includes a memory and a processor; the memory stores a computer program; when the computer program is executed on the processor, it implements the traceability auditing method for the semiconductor manufacturing knowledge base as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions; when the computer instructions are executed on the electronic device as described in claim 9, the traceability auditing method for the semiconductor manufacturing knowledge base as described in any one of claims 1-7 is implemented.