A method, system, device and storage medium for generating an evidence package, anchoring evidence and replayable verification based on behavioral fact evidence

By standardizing the raw data of behavioral events and generating evidence packages, the problems of unified organization and consistency of verification standards for multi-source behavioral data are solved, and the continuity of evidence generation and verification processes and efficient retrieval of detailed data are achieved.

CN122196234APending Publication Date: 2026-06-12GREEN AXIS (WUXI) TECHNOLOGY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GREEN AXIS (WUXI) TECHNOLOGY CO LTD
Filing Date
2026-03-12
Publication Date
2026-06-12

AI Technical Summary

Technical Problem

Existing methods for storing and verifying behavioral factual evidence have several problems, including difficulty in forming a unified evidence object from multi-source behavioral data, low consistency between the evidence generation criteria and the subsequent verification criteria, and unclear referencing relationships between detailed data and evidence objects. In particular, when the original detailed data is stored in fragments and distributed in different system environments, it is difficult to quickly locate and reconstruct the verification input.

Method used

By standardizing the raw data of behavioral events, atomic behavioral fact units are generated, evidence anchors are constructed and anchored evidence storage is performed, evidence packages are generated, and detailed data is retrieved based on the evidence citation index for playback verification, ensuring the consistency and coherence of the evidence generation process and the verification process.

Benefits of technology

It achieves unified organization of multi-source behavioral fact data, synchronous binding of evidence generation and verification processes, and continuity of detailed data retrieval and playback processing, thereby improving the structured organization of behavioral fact evidence and the consistency of the verification process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122196234A_ABST
    Figure CN122196234A_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on behavior fact evidence's evidence package generation, anchoring and evidence storage and replayable verification method, system, equipment and storage medium, it is related to computer data processing, evidence solidification, audit verification and data governance technical field, including processing behavior event original data obtains atomized behavior fact unit, according to atomized behavior fact unit, through human behavior fact proof storage system generates evidence anchor point and executes anchoring and evidence storage and carries out replayable verification.The method disclosed in the application realizes the unified organization of multi-source behavior fact data by normalizing processing behavior event original data and constructing atomized behavior fact unit;By encapsulating atomized behavior fact unit to generate evidence package, and after version freezing the rule set according to which the evidence package is generated, write into evidence package, the synchronous binding of evidence generation process and processing caliber is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of computer data processing, evidence preservation, audit verification and data governance, specifically to a method, system, device and storage medium for generating, anchoring and storing, and replayable verification of evidence packages based on behavioral factual evidence. Background Technology

[0002] Existing technologies often focus on simple document verification, log comparison, or fixed summary comparison in the behavioral fact verification stage, lacking a playback-style verification mechanism oriented towards behavioral fact evidence objects.

[0003] Especially when the original detailed data corresponding to the behavioral facts is large in volume, stored in fragments, subject to access control, or distributed in different system environments, if no index reference relationship is established corresponding to the evidence object, it will be difficult to quickly locate the corresponding detailed data based on the existing evidence object, and it will be even more difficult to reconstruct the verification input according to the established rules in a controlled environment.

[0004] Furthermore, if the verification process relies solely on simple result comparison and cannot incorporate historical processing guidelines, detailed data retrieval relationships, and structured fields of evidence objects for replay processing, the verification process is prone to remaining at the static verification level and is difficult to adapt to the need for full-process review of behavioral facts in complex business scenarios. Summary of the Invention

[0005] In view of the above-mentioned problems, the present invention is proposed.

[0006] Therefore, the technical problem solved by this invention is that existing methods for storing and verifying behavioral fact evidence have problems such as difficulty in forming a unified evidence object from multi-source behavioral data, low consistency between the evidence generation criteria and the subsequent verification criteria, and unclear reference relationships between detailed data and evidence objects. The invention also addresses the problem of how to standardize the original data of behavioral events and construct atomic behavioral fact units, further generate evidence packages that are written into the version freeze results, and retrieve the corresponding detailed data for playback verification based on the evidence reference index in the evidence package.

[0007] To address the aforementioned technical problems, this invention provides the following technical solution: a method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral fact evidence, comprising processing raw data of behavioral events to obtain atomized behavioral fact units, generating evidence anchors through a human behavioral fact evidence storage system based on the atomized behavioral fact units, performing anchoring and storage, and conducting replay verification.

[0008] The process of obtaining the atomized behavioral fact unit includes: performing normalization processing on the original data of the behavioral event to obtain normalized event records, and constructing the atomized behavioral fact unit based on the normalized event records.

[0009] The process of generating evidence anchors and performing anchored evidence storage includes: encapsulating atomic behavioral fact units to generate evidence packages; freezing the rule set on which the evidence packages are generated and writing it into the evidence packages; and calculating evidence anchors based on the evidence packages containing the results of the version freezing and performing anchored evidence storage.

[0010] The replay verification includes retrieving detailed data based on the evidence citation index in the evidence package for replay verification.

[0011] As a preferred embodiment of the method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence as described in this invention, the standardization process includes reading the original data of the accessed behavioral events and extracting the original fields according to the source field mapping table.

[0012] The extracted raw fields are converted into a unified field set, and then the unified field set is aligned.

[0013] Map fields from different event sources that have the same business semantics but different forms of expression to fields with a unified definition.

[0014] Perform de-identification processing on the data that has completed the caliber alignment, converting the behavior subject identifier into a subject code and the behavior object identifier into an object code.

[0015] Anomaly detection is performed on the de-identified data. Data that meets the removal criteria is removed directly, while data that does not meet the removal criteria but has anomaly markers retains the anomaly markers and proceeds to subsequent processing.

[0016] Perform time and space alignment on the data that was not removed.

[0017] When the behavior subject identifier, behavior object identifier, and behavior type identifier of multiple records meet the consistency condition, and the time difference falls within the time tolerance window and the unified location code meets the same domain condition, the multiple records will be merged to generate a standardized event record.

[0018] When the consistency condition is not met, separate normalized event records will be generated for the corresponding records, and the event source identifier, anomaly marker, and quality marker will be written into each normalized event record.

[0019] As a preferred embodiment of the method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral fact evidence described in this invention, the construction of atomic behavioral fact units includes: reading standardized event records and constructing atomic behavioral fact units based on the subject code, object code, behavior type identifier, event time, unified location code, event source identifier, and result evidence citation identifier in the standardized event records.

[0020] Event time is divided according to time slice rules to obtain behavior time slices.

[0021] The behavior type identifier in the normalized event record is associated with the corresponding behavior time slice and written into the atomic behavior fact unit.

[0022] When a normalized event record corresponds to the same subject ID and performs the same type of behavior on multiple object IDs within the same behavior time slice, the normalized event record is split into atomic behavior fact units according to the object ID.

[0023] When more than one normalized event record corresponds to the same subject code, the same object code, the same behavior type identifier, and the same behavior time slice, they are merged into an atomic behavior fact unit.

[0024] Assign a unique unit identifier to each generated atomic behavior fact unit, and establish a mapping relationship between the unique unit identifier and the corresponding normalized event record.

[0025] Write three of the following into the atomic behavior fact unit: subject code, object code, behavior type identifier, behavior time slice, uniform location code, event source identifier, result evidence citation identifier, anomaly marker, and quality marker.

[0026] As a preferred embodiment of the method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral fact evidence described in this invention, the step of generating the evidence package through encapsulation includes reading atomic behavioral fact units.

[0027] Extract the core fact fields from the subject code, object code, behavior type identifier, behavior time slice, uniform location code, event source identifier, and result evidence citation identifier in the atomic behavior fact unit.

[0028] The core fact fields are serialized according to their field order.

[0029] Generate an event summary field based on the serialization result.

[0030] Read the detailed data storage information corresponding to the atomic behavior fact unit.

[0031] An evidence citation index is generated based on the detailed data storage information.

[0032] The event summary field, evidence citation index, integrity verification field, generation time, and generation node identifier are encapsulated into an evidence package.

[0033] Before generating the evidence package, determine whether the core fact fields and corresponding detailed data storage information in the atomized behavioral fact unit are complete.

[0034] Once the core fact fields and their corresponding detailed data storage information are complete, the evidence package is generated.

[0035] When the core fact fields and their corresponding detailed data storage information are incomplete, stop generating the evidence package corresponding to the current atomic behavior fact unit.

[0036] The generated evidence package is associated with the unique unit identifier of the corresponding atomized behavioral fact unit.

[0037] As a preferred embodiment of the method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence as described in this invention, the rule set includes: reading the evidence package and synchronously reading the processing rules called during the generation of the evidence package.

[0038] The processing rules are organized into a rule set.

[0039] Write the rule identifier, rule content, parameter items, effective time range, and applicable scope for each rule in the rule set.

[0040] The written rule set is encapsulated into a version configuration file, and a version number is assigned to the version configuration file.

[0041] Perform version freeze processing on the version configuration file and generate the version freeze result.

[0042] Write the version freeze result into the evidence package.

[0043] When any rule or parameter item in the rule set changes, the version configuration file and the corresponding version freeze result are regenerated and written into the subsequently generated evidence package.

[0044] The evidence package containing the version freeze results will be output as the input data for the next step of generating evidence anchors and performing anchored evidence storage.

[0045] As a preferred embodiment of the method for generating, anchoring, and replaying verifiable evidence packages based on behavioral factual evidence described in this invention, the step of calculating evidence anchor points and performing anchoring includes reading and writing evidence packages based on version freeze results.

[0046] Extract the event summary field, version freeze result, and integrity verification field from the evidence package.

[0047] Evidence anchors are generated based on the event summary field, version freeze result, and integrity verification field.

[0048] Write the evidence anchor point, evidence package identifier, anchoring time, and version number into the evidence storage medium.

[0049] If the evidence package lacks version freeze results or integrity verification fields, stop the generation and anchoring of the current evidence anchor point.

[0050] As a preferred embodiment of the method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence described in this invention, the step of retrieving detailed data for replay verification includes reading the evidence reference index, version freeze result, and evidence anchor point in the evidence package.

[0051] Retrieve the corresponding detailed data based on the evidence citation index.

[0052] Load the corresponding version configuration file based on the version freeze result.

[0053] The detailed data is replayed according to the field mapping rules, anomaly detection rules, time alignment rules, spatial alignment rules, and replay processing rules in the version configuration file to generate a verification summary.

[0054] Determine the correspondence between the verification summary and the evidence anchor, and write it into the verification record.

[0055] Another objective of this invention is to provide a system for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral fact evidence. This system can standardize the original data of behavioral events and construct atomic behavioral fact units, encapsulate these units to generate evidence packages, freeze the version of the rule set used to generate the evidence packages, and then write it into the evidence packages. Based on the evidence reference index in the evidence packages, the system retrieves corresponding detailed data for replay verification. This solves the problems in current behavioral fact evidence processing technologies, such as the difficulty in forming a unified evidence object from multiple sources, insufficient connection between the evidence generation process and subsequent verification process, unclear relationships in detailed data retrieval, and difficulty in maintaining consistency in historical processing standards during the verification stage.

[0056] As a preferred embodiment of the system for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral fact evidence as described in this invention, it includes: an atomized behavioral fact unit generation module, an evidence anchor point generation and anchoring storage module, and a replay verification module.

[0057] The atomic behavior fact unit generation module is used to standardize the original data of behavior events to obtain standardized event records, and to construct atomic behavior fact units based on the standardized event records.

[0058] The evidence anchor point generation and anchoring storage module is used to encapsulate atomic behavioral fact units to generate evidence packages, freeze the rule set on which the evidence package is based and write it into the evidence package, calculate evidence anchor points based on the evidence package with the written version freeze result and perform anchoring storage.

[0059] The playback verification module is used to retrieve detailed data for playback verification based on the evidence reference index in the evidence package.

[0060] Another object of the present invention is to provide an apparatus for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps of a method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence.

[0061] Another object of the present invention is to provide a storage medium for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence, wherein a computer program is stored thereon, and when the computer program is executed by a processor, it implements the steps of the method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence.

[0062] The beneficial effects of this invention are as follows: The method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence provided by this invention achieves unified organization of multi-source behavioral factual data by standardizing the original data of behavioral events and constructing atomic behavioral factual units; by encapsulating the atomic behavioral factual units to generate evidence packages and freezing the version of the rule set on which the evidence packages are generated before writing it into the evidence packages, the evidence generation process and processing standards are synchronously bound; and by retrieving detailed data based on the evidence reference index in the evidence package for replay verification, the continuity between the evidence object and the subsequent verification process is achieved. This invention achieves better results in the structured organization of behavioral factual evidence, the consistency of evidence generation and verification processes, and the coherence of detailed data retrieval and replay processing. Attached Figure Description

[0063] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0064] Figure 1 This is an overall flowchart of a method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence, as provided in Embodiment 1 of the present invention. Detailed Implementation

[0065] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0066] Example 1, referring to Figure 1 As an embodiment of the present invention, a method for generating, anchoring, storing, and replayably verifying evidence packages based on behavioral factual evidence is provided, comprising:

[0067] S1: Normalize the raw data of behavioral events to obtain normalized event records, and construct atomic behavioral fact units based on the normalized event records.

[0068] Read the raw data of the accessed behavior events and extract the raw fields according to the source field mapping table.

[0069] A preferred approach for the source field mapping table is:

[0070] Establish a mapping relationship between source field names and standard field names for scanning records, location records, log records, image records, and form records in advance.

[0071] The source field name must include at least one or more of the following: user ID field, object ID field, event action field, collection time field, collection location field, and evidence file field.

[0072] The standard field name should include at least one or more of the following: subject identifier, object identifier, type identifier, event time, event location, event source identifier, and result evidence citation identifier.

[0073] When extracting raw fields, the data source type of the raw data of the current behavior event is first identified based on the event source identifier. Then, the source field mapping table corresponding to the data source type is called to map the source fields in the raw records to the corresponding standard field names. Source fields that do not match the standard field names are retained as extended fields in the raw record association area for subsequent review and retrieval.

[0074] The extracted raw fields are converted into a unified set of fields.

[0075] The unified field set includes three types: behavior subject identifier, behavior object identifier, behavior type identifier, event time, event location, event source identifier, and result evidence citation identifier.

[0076] Perform caliber alignment on a uniform set of fields.

[0077] Map fields from different event sources that have the same business semantics but different forms of expression to fields with a unified definition.

[0078] Perform de-identification processing on the data that has completed the caliber alignment, converting the behavior subject identifier into a subject code and the behavior object identifier into an object code.

[0079] Perform anomaly detection on the de-identified data.

[0080] Anomaly detection includes field missing detection, timestamp validity detection, event location range detection, duplicate record detection, and event source integrity detection.

[0081] A preferred scheme for anomaly detection is:

[0082] Field missing detection is used to determine whether there are null values ​​for the behavior subject identifier, behavior object identifier, behavior type identifier, and event time.

[0083] Timestamp validity checks are used to determine whether an event time falls within a preset business time period and whether it is earlier than the minimum start time allowed by the system.

[0084] Event location range detection is used to determine whether the event location falls within the preset business area boundary; duplicate record detection is used to determine whether the current record and the historical record meet the duplicate judgment conditions in terms of behavior subject identifier, behavior object identifier, behavior type identifier, and event time.

[0085] The event source integrity check is used to determine whether the event source identifier and the result evidence citation identifier are complete.

[0086] Data that meets the exclusion criteria is directly excluded. Data that does not meet the exclusion criteria but has an anomaly marker is retained and then processed in subsequent steps.

[0087] Perform time and space alignment on the data that was not removed.

[0088] Time alignment is used to unify records from different event sources to the same time base and determine whether they belong to the same event based on a preset time tolerance window. Spatial alignment is used to map coordinate information, area number, access control point number or base station location number to a unified location code.

[0089] When the behavior subject identifier, behavior object identifier, and behavior type identifier of multiple records meet the consistency condition, and the time difference falls within the time tolerance window and the unified location code meets the same domain condition, the multiple records will be merged to generate a standardized event record.

[0090] A preferred approach for merging and generating normalized event records is:

[0091]

[0092] in, This indicates the merge decision result. This indicates that a merge operation is being performed. This indicates that the merge will not be performed. Indicates an indicator function, and These represent the identifiers of the actors corresponding to the two records to be judged. and These represent the identifiers of the behavior objects corresponding to the two records to be judged. and These represent the behavior type identifiers corresponding to the two records to be judged. and These represent the event times corresponding to the two records to be judged. Indicates the time tolerance threshold. and These represent the unified location codes corresponding to the two records to be judged.

[0093] The primary matching key is the behavior subject identifier, behavior object identifier, and behavior type identifier, while the secondary matching key is the event time difference and the unified location code.

[0094] When any two records to be merged have the same primary matching key, the event time difference is not greater than the preset time tolerance threshold, and the unified location code belongs to the same business area code set, the records to be merged are merged into a single standardized event record.

[0095] When merging, the earliest event time is retained as the start time, the latest event time is retained as the end time, and multiple event source identifiers are written into the normalized event record in the form of a set.

[0096] Specifically, one preferred scheme for merging is:

[0097] When the consistency condition is not met, separate normalized event records will be generated for the corresponding records, and the event source identifier, anomaly marker, and quality marker will be written into each normalized event record.

[0098] Furthermore, the normalized event records are read, and atomic behavioral fact units are constructed based on the subject code, object code, behavior type identifier, event time, unified location code, event source identifier, and result evidence citation identifier in the normalized event records.

[0099] Event time is divided according to time slice rules to obtain behavior time slices.

[0100] The behavior type identifier in the normalized event record is associated with the corresponding behavior time slice and written into the atomic behavior fact unit.

[0101] When a normalized event record corresponds to the same subject ID and performs the same type of behavior on multiple object IDs within the same behavior time slice, the normalized event record is split into atomic behavior fact units according to the object ID.

[0102] When more than one normalized event record corresponds to the same subject code, the same object code, the same behavior type identifier, and the same behavior time slice, they are merged into an atomic behavior fact unit.

[0103] Assign a unique unit identifier to each generated atomic behavior fact unit.

[0104] Establish a mapping relationship between unique unit identifiers and corresponding standardized event records.

[0105] Write three of the following into the atomic behavior fact unit: subject code, object code, behavior type identifier, behavior time slice, uniform location code, event source identifier, result evidence citation identifier, anomaly marker, and quality marker.

[0106] S2: Encapsulate the atomic behavior fact units to generate evidence packages, freeze the rule set on which the evidence packages are generated, and write them into the evidence packages. Calculate evidence anchors based on the evidence packages with the results of the freeze, and perform anchoring and evidence storage.

[0107] POHA: A system for storing evidence of human behavior facts. It is used to standardize the raw data of behavioral events, construct atomic behavioral fact units, generate evidence packages, freeze the set of rules on which the evidence packages are generated, write them into the evidence packages, generate evidence anchors based on the evidence packages with the results of the freeze, and perform anchor storage. It also retrieves detailed data for playback verification based on the evidence reference index in the evidence packages.

[0108] Read the atomic behavior fact unit.

[0109] Extract the core fact fields from the subject code, object code, behavior type identifier, behavior time slice, uniform location code, event source identifier, and result evidence citation identifier in the atomic behavior fact unit.

[0110] The core fact fields are serialized according to their field order.

[0111] Generate an event summary field based on the serialization result.

[0112] Read the detailed data storage information corresponding to the atomic behavior fact unit.

[0113] An evidence citation index is generated based on the detailed data storage information.

[0114] A preferred scheme for evidence citation indexing is:

[0115] The detailed data storage location, sharding order, access scope, and retrieval key corresponding to the atomic behavior fact unit are combined to form an index structure.

[0116] The index structure includes storage key, fragment number, range identifier, permission identifier, and retrieval key.

[0117] When generating the evidence reference index, first assign a corresponding index identifier to the current atomic behavior fact unit, then establish a mapping relationship between the index identifier and the detailed data storage information, and write the index identifier into the evidence package so that the detailed data can be located by index in the subsequent playback verification stage.

[0118] A preferred scheme for evidence citation indexing is:

[0119]

[0120] in, Indicates the evidence citation index, Indicates the storage key. Indicates the fragment number. Indicates the range identifier, Indicates permission identifier, Indicates the search key. .

[0121] The event summary field, evidence citation index, integrity verification field, generation time, and generation node identifier are encapsulated into an evidence package.

[0122] The integrity verification field is calculated based on the evidence package.

[0123] A preferred method for calculating the integrity check field is:

[0124]

[0125] in, This represents the integrity verification field, and Hash represents the digest calculation function. This indicates the event summary field. Indicates the evidence citation index, Indicates the generation time. Indicates the identifier of the generated node. This indicates that the connections are made in a fixed order.

[0126] Before generating the evidence package, determine whether the core fact fields and corresponding detailed data storage information in the atomized behavioral fact unit are complete.

[0127] Once the core fact fields and their corresponding detailed data storage information are complete, the evidence package is generated.

[0128] When the core fact fields and their corresponding detailed data storage information are incomplete, stop generating the evidence package corresponding to the current atomic behavior fact unit.

[0129] The generated evidence package is associated with the unique unit identifier of the corresponding atomized behavioral fact unit.

[0130] Furthermore, the evidence package is read, and the processing rules called during the generation of the evidence package are read synchronously.

[0131] The processing rules are organized into a rule set.

[0132] The rule set includes three of the following: field mapping rules, caliber alignment rules, de-identification rules, anomaly detection rules, time alignment rules, spatial alignment rules, behavior time slice partitioning rules, core fact field extraction rules, evidence citation index generation rules, evidence package generation rules, integrity verification rules, summary calculation rules, detailed data fragmentation rules, playback processing rules, and correspondence judgment rules.

[0133] Write the rule identifier, rule content, parameter items, effective time range, and applicable scope for each rule in the rule set.

[0134] The parameters include three of the following: time tolerance parameters, spatial tolerance parameters, anomaly detection parameters, mandatory field parameters, fragmentation order parameters, and summary calculation parameters.

[0135] The written rule set is encapsulated into a version configuration file.

[0136] Assign version numbers to the version configuration file.

[0137] Perform version freeze processing on the version configuration file and generate the version freeze result.

[0138] The version freeze result includes the version number and version configuration file reference information.

[0139] Write the version freeze result into the evidence package.

[0140] When any rule or parameter item in the rule set changes, the version configuration file and the corresponding version freeze result are regenerated and written into the subsequently generated evidence package.

[0141] The evidence package containing the version freeze results will be output as the input data for the next step of generating evidence anchors and performing anchored evidence storage.

[0142] S3: Retrieve detailed data for playback verification based on the evidence citation index in the evidence package.

[0143] Read the evidence package containing the results of the version freeze.

[0144] Extract the event summary field, version freeze result, and integrity verification field from the evidence package.

[0145] Evidence anchors are generated based on the event summary field, version freeze result, and integrity verification field.

[0146] Write the evidence anchor point, evidence package identifier, anchoring time, and version number into the evidence storage medium.

[0147] If the evidence package lacks version freeze results or integrity verification fields, stop the generation and anchoring of the current evidence anchor point.

[0148] Furthermore, the evidence reference index, version freeze result, and evidence anchor point in the evidence package are read.

[0149] Retrieve the corresponding detailed data based on the evidence citation index.

[0150] Load the corresponding version configuration file based on the version freeze result.

[0151] The detailed data is replayed according to the field mapping rules, anomaly detection rules, time alignment rules, spatial alignment rules, and replay processing rules in the version configuration file to generate a verification summary.

[0152] Determine the correspondence between the verification summary and the evidence anchor, and write it into the verification record.

[0153] Example 2, an embodiment of the present invention, provides a system for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral fact evidence, including an atomized behavioral fact unit generation module, an evidence anchor point generation and anchoring storage module, and a replay verification module.

[0154] The atomic behavior fact unit generation module is used to standardize the original data of behavior events to obtain standardized event records, and to construct atomic behavior fact units based on the standardized event records.

[0155] The evidence anchor generation and anchoring module is used to encapsulate atomic behavioral fact units to generate evidence packages, freeze the rule set on which the evidence package is based and write it into the evidence package, calculate evidence anchors based on the evidence package with the written version freeze result and perform anchoring and storage.

[0156] A preferred approach for calculating evidence anchors and performing anchored evidence preservation is as follows:

[0157]

[0158] in, This represents the evidence anchor, and Hash represents the digest calculation function. This indicates the event summary field. This indicates the result of the version freeze. This represents the integrity verification field. This indicates that the connections are made in a fixed order.

[0159] The playback verification module is used to retrieve detailed data for playback verification based on the evidence reference index in the evidence package.

[0160] This embodiment also provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence as proposed in the above embodiments.

[0161] This embodiment also provides a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the method for generating, anchoring, storing, and replaying verification of evidence packages based on behavioral factual evidence as proposed in the above embodiments.

[0162] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0163] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-including system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0164] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0165] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0166] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for generating, anchoring, storing, and replayably verifying evidence packages based on behavioral factual evidence, characterized in that, include: The raw data of behavioral events is processed to obtain atomized behavioral fact units. Based on these atomized behavioral fact units, evidence anchors are generated through the human behavioral fact evidence storage system, and anchored evidence storage is performed followed by playback verification. The process of obtaining the atomized behavioral fact unit includes: performing normalization processing on the original data of the behavioral event to obtain normalized event records, and constructing the atomized behavioral fact unit based on the normalized event records; The process of generating evidence anchors and performing anchor storage includes: encapsulating atomic behavioral fact units to generate evidence packages; freezing the rule set on which the evidence packages are based and writing it into the evidence packages; and calculating evidence anchors based on the evidence packages with the written version freezing results and performing anchor storage. The replay verification includes retrieving detailed data based on the evidence citation index in the evidence package for replay verification.

2. The method for generating, anchoring, storing, and replayably verifying evidence packages based on behavioral factual evidence as described in claim 1, characterized in that: The standardization process includes, Read the raw data of the accessed behavioral events and extract the raw fields according to the source field mapping table; Convert the extracted raw fields into a unified set of fields; Perform caliber alignment on the unified field set; Map fields from different event sources that have the same business semantics but different forms of expression to fields with a unified definition. Perform de-identification processing on the data that has completed the caliber alignment, converting the behavior subject identifier into a subject code and the behavior object identifier into an object code; Perform anomaly detection on the de-identified data; Data that meets the exclusion criteria is directly excluded; data that does not meet the exclusion criteria but has an anomaly marker is retained and then processed in subsequent steps. Perform time and space alignment on the data that was not removed; When the behavior subject identifier, behavior object identifier, and behavior type identifier of multiple records meet the consistency condition, and the time difference falls within the time tolerance window and the unified location code meets the same domain condition, the multiple records will be merged to generate a standardized event record. When the consistency condition is not met, separate normalized event records will be generated for the corresponding records, and the event source identifier, anomaly marker, and quality marker will be written into each normalized event record.

3. The method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence as described in claim 1 or 2, characterized in that: The construction of atomic behavioral fact units includes Read the normalized event records and construct atomic behavioral fact units based on the subject code, object code, behavior type identifier, event time, unified location code, event source identifier, and result evidence citation identifier in the normalized event records; Event time is divided according to time-slicing rules to obtain behavior time slices; Associate the behavior type identifier in the normalized event log with the corresponding behavior time slice and write it into the atomic behavior fact unit; When a normalized event record corresponds to the same subject ID and performs the same type of behavior on multiple object IDs within the same behavior time slice, the normalized event record is split into atomic behavior fact units according to the object ID; When one or more normalized event records correspond to the same subject ID, the same object ID, the same behavior type identifier, and the same behavior time slice, they are merged into an atomic behavior fact unit. Assign a unique unit identifier to each generated atomized behavioral fact unit; Establish a mapping relationship between unique unit identifiers and corresponding standardized event records; Write three of the following into the atomic behavior fact unit: subject code, object code, behavior type identifier, behavior time slice, uniform location code, event source identifier, result evidence citation identifier, anomaly marker, and quality marker.

4. The method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence as described in claim 3, characterized in that: The process of encapsulating and generating the evidence package includes... Read atomic behavior fact units; Extract the core fact fields from the subject code, object code, behavior type identifier, behavior time slice, uniform location code, event source identifier, and result evidence citation identifier in the atomic behavior fact unit; Serialize the core fact fields according to their field order; Generate an event summary field based on the serialization result; Read detailed data storage information corresponding to the atomic behavior fact unit; Generate an evidence citation index based on detailed data storage information; The event summary field, evidence citation index, integrity verification field, generation time, and generation node identifier are encapsulated into an evidence package; Before generating the evidence package, determine whether the core fact fields and corresponding detailed data storage information in the atomic behavior fact unit are complete; Once the core fact fields and their corresponding detailed data storage information are complete, the evidence package is generated. When the core fact fields and their corresponding detailed data storage information are incomplete, stop generating the evidence package corresponding to the current atomic behavior fact unit. The generated evidence package is associated with the unique unit identifier of the corresponding atomized behavioral fact unit.

5. The method for generating, anchoring, storing, and replayably verifying evidence packages based on behavioral factual evidence as described in claim 1, 2, or 4, characterized in that: The rule set includes, Read the evidence package and synchronously read the processing rules called during the generation of the evidence package; Organize the processing rules into a rule set; For each rule in the rule set, write the rule identifier, rule content, parameter items, effective time range, and applicable scope; The written rule set is then encapsulated into a version configuration file; Assign a version number to the version configuration file; Perform version freeze processing on the version configuration file and generate the version freeze result; Write the version freeze result into the evidence package; When any rule or parameter item in the rule set changes, the version configuration file and the corresponding version freeze result are regenerated and written into the subsequently generated evidence package. The evidence package containing the version freeze results will be output as the input data for the next step of generating evidence anchors and performing anchored evidence storage.

6. The method for generating, anchoring, storing, and replayably verifying evidence packages based on behavioral factual evidence as described in claim 5, characterized in that: The calculation of evidence anchor points and the execution of anchored evidence preservation include, Read the evidence package containing the results of the version freeze; Extract the event summary field, version freeze result, and integrity verification field from the evidence package; Generate evidence anchors based on the event summary field, version freeze result, and integrity verification field; Write the evidence anchor point, evidence package identifier, anchoring time and version number into the evidence storage medium; If the evidence package lacks version freeze results or integrity verification fields, stop the generation and anchoring of the current evidence anchor point.

7. The method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence as described in claim 1, 2, 4, or 6, characterized in that: The process of retrieving detailed data for playback verification includes... Read the evidence reference index, version freeze result, and evidence anchor point from the evidence package; Retrieve the corresponding detailed data based on the evidence citation index; Load the corresponding version configuration file based on the version freeze result; The detailed data is replayed according to the field mapping rules, anomaly detection rules, time alignment rules, spatial alignment rules and replay processing rules in the version configuration file to generate a verification summary; Determine the correspondence between the verification summary and the evidence anchor, and write it into the verification record.

8. A system for generating, anchoring, storing, and replayably verifying evidence packages based on behavioral factual evidence, employing the method for generating, anchoring, storing, and replayably verifying evidence packages based on behavioral factual evidence as described in any one of claims 1 to 7, characterized in that: This includes a module for generating atomized behavioral fact units, a module for generating and anchoring evidence anchors, and a module for replay verification; The atomic behavior fact unit generation module is used to standardize the raw data of behavior events to obtain standardized event records, and to construct atomic behavior fact units based on the standardized event records; The evidence anchor point generation and anchoring evidence storage module is used to encapsulate atomic behavioral fact units to generate evidence packages, freeze the rule set on which the evidence package is based and write it into the evidence package, calculate evidence anchor points based on the evidence package with the written version freeze result and perform anchoring evidence storage. The playback verification module is used to retrieve detailed data for playback verification based on the evidence reference index in the evidence package.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method for generating, anchoring, storing, and replaying verifiable evidence packages based on behavioral factual evidence as described in any one of claims 1 to 7.