Power material traceability system and tamper-proofing method based on internet of things privacy protection
By assigning unique identifiers to power materials and comparing multi-sensor data in real time, combined with blockchain verification, the problem of synchronizing physical materials with digital records in the power material traceability system has been solved, achieving security and business continuity in end-to-end management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- STATE GRID JIANGSU ELECTRIC POWER CO LTD TAIZHOU POWER SUPPLY BRANCH
- Filing Date
- 2026-04-22
- Publication Date
- 2026-07-21
AI Technical Summary
The existing power material traceability system suffers from time and status misalignment when synchronizing physical materials with digital records, leading to data verification logic conflicts and making it impossible to smoothly repair distorted data.
A digital twin module is used to assign unique asset beacons, transfer beacons, and digital twin identifiers to power materials. Combined with a two-way verification module, the data from multi-sensor fusion and the status of the digital twin are compared in real time. The authenticity of the data is verified by blockchain records, and maintenance work orders are generated when anomalies occur.
It enables real-time synchronization of physical materials and digital records, improves the security and business continuity of the entire power material management chain, and ensures automated closed-loop processing of abnormal responses.
Smart Images

Figure CN122434548A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power Internet of Things (IoT) technology, and in particular to a power material traceability system and anti-tampering method based on IoT privacy protection. Background Technology
[0002] With the development of smart grids, the full lifecycle traceability and tamper prevention of high-value power materials, such as smart terminals and meter boxes, are crucial to grid security.
[0003] Current technologies for tracing power equipment typically employ IoT sensors to collect data and combine it with blockchain for evidence storage to prevent data tampering. However, this approach struggles to ensure that the actual state of physical equipment remains synchronized with the digital system's records in real time.
[0004] Specifically, when a system detects data tampering or loss, existing solutions typically extract trusted historical records from the blockchain to overwrite and restore the current digital state. However, because physical materials are constantly moving and undergoing environmental evolution in the real world, directly rolling back digital records to a historical point in time creates a gap between the restored historical state and the real-time physical state continuously collected by sensors. This misalignment between time and state can cause serious conflicts in subsequent data verification logic, preventing the traceability system from smoothly repairing distorted data. Summary of the Invention
[0005] This invention aims to at least partially address one of the technical problems in related technologies. Therefore, the objective of this invention is to propose a power material traceability system and anti-tampering method based on Internet of Things (IoT) privacy protection, to improve the security and business continuity of power material end-to-end management.
[0006] To achieve the above objectives, a first aspect of the present invention proposes a power material traceability system based on Internet of Things (IoT) privacy protection, comprising:
[0007] The digital twin module is used to assign unique asset beacons, transfer beacons, and digital twin identifiers to power materials, establish a binding relationship between physical materials and the digital twin identifiers, and incrementally update the status of the digital twin corresponding to the physical materials after receiving and verifying the encrypted transfer data at each stage.
[0008] The two-way verification module is used to compare the multi-sensor fusion data of the acquired physical materials with the status data of the digital twin in real time. If the deviation exceeds the first preset threshold, the consistency verification process is triggered, and the authenticity of the data is verified by recording it on the blockchain.
[0009] The dual anomaly detection module is used to monitor the physical state anomalies and data transmission anomalies of the physical materials during the consistency verification process or daily circulation process, and to locate the root cause of the anomaly by associating the full life cycle data through the digital twin when an anomaly occurs.
[0010] The operation and maintenance linkage module is used to generate an operation and maintenance work order containing the digital twin identifier, anomaly description and source tracing report and push it to the operation and maintenance terminal after the dual anomaly detection module locates the root cause of the anomaly.
[0011] The generation process of the digital twin identifier in the digital twin module includes: obtaining the asset beacon, the transfer beacon, and the manufacturer's unique code; performing a hash operation on the asset beacon, the transfer beacon, and the manufacturer's unique code to generate a unique digital twin identifier.
[0012] To achieve the above objectives, a second aspect of the present invention proposes a method for traceability and anti-tampering of power materials based on Internet of Things (IoT) privacy protection, applied to an IoT-based power material traceability system. The method includes:
[0013] A unique asset beacon, transfer beacon, and digital twin identifier are assigned to each power material. A binding relationship is established between the physical material and the digital twin identifier. After receiving and verifying the encrypted transfer data at each stage, the status of the digital twin corresponding to the physical material is incrementally updated.
[0014] The multi-sensor fusion data of the physical materials and the status data of the digital twin are compared in real time. If the deviation exceeds the first preset threshold, a consistency verification process is triggered, and the authenticity of the data is verified by blockchain records.
[0015] During the consistency verification process, if data anomalies are detected or during daily operations, the physical state of the physical materials and data transmission anomalies are monitored. When an anomaly occurs, the digital twin is used to correlate the entire lifecycle data to locate the root cause of the anomaly.
[0016] After locating the root cause of the anomaly, an operation and maintenance work order containing the digital twin identifier, anomaly description, and source tracing report is generated and pushed to the operation and maintenance terminal.
[0017] The process of generating a unique digital twin identifier includes: obtaining the asset beacon, the transfer beacon, and the manufacturer's unique code; performing a hash operation on the asset beacon, the transfer beacon, and the manufacturer's unique code to generate a unique digital twin identifier.
[0018] To achieve the above objectives, a third aspect of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory. When the computer program is executed by the processor, it implements the above-described method for traceability and anti-tampering of power materials based on Internet of Things privacy protection.
[0019] The IoT-based power material traceability system and anti-tampering method of this invention, in the material flow initialization stage, performs hash operations on asset beacons, flow beacons, and manufacturer unique codes to generate unique digital twin identifiers, establishing a cryptographic anti-counterfeiting binding between physical entities and digital archives. This prevents the risk of physical label replacement or counterfeit scanning during logistics handover and establishes an immutable initial trust benchmark. To address the conflict between physical entities and digital records during transportation, the system introduces a real-time two-way verification mechanism. When materials are subjected to unauthorized dismantling or exceeding limits, even if the database is tampered with, the system can still capture deviations exceeding a first preset threshold between multi-sensor fusion data and the digital twin state, triggering a blockchain-based consistency verification process to compensate for the security blind spots of a single database certificate.
[0020] Meanwhile, the dual anomaly detection module monitors physical and data anomalies simultaneously. By correlating full lifecycle data, it objectively determines whether the anomaly originates from manufacturing defects, transportation damage, or network attacks. After locating the anomaly, the system automatically generates an operation and maintenance work order containing a source tracing report and pushes it to the front-line operation and maintenance terminal. This achieves an automated closed loop from anomaly discovery and responsibility definition to work order dispatch and handling, effectively improving the safety management efficiency and response efficiency of power grid material flow. Attached Figure Description
[0021] Figure 1 This is a schematic diagram illustrating the implementation of the IoT-based privacy-protected power material traceability system provided by the present invention.
[0022] Figure 2 This invention provides a real-time monitoring and consistency triggering curve of state deviation based on multi-sensor fusion data in the power material traceability system based on Internet of Things privacy protection.
[0023] Figure 3 This is a comparison chart of the Kalman filter noise reduction and physical anomaly identification effects of the power material logistics vibration data in the power material traceability system based on Internet of Things privacy protection provided by this invention;
[0024] Figure 4 This is a comparison chart of the Kalman filter noise reduction and physical anomaly identification effects of the power material logistics vibration data in the power material traceability system based on Internet of Things privacy protection provided by this invention;
[0025] Figure 5This is a schematic diagram illustrating the effect of precise geographic coordinates to discrete spatial gridded projection and dimensionality reduction and desensitization in the IoT-based power material traceability system provided by this invention;
[0026] Figure 6 This invention provides a digital twin state sandbox incremental extrapolation and reconstruction trajectory diagram based on edge chain logs in the power material traceability system based on Internet of Things privacy protection.
[0027] Figure 7 This invention provides a graph showing the relative spatial distance change trend of terminals and the dynamic high-precision geographic token triggering critical curve in the IoT-based power material traceability system with privacy protection.
[0028] Figure 8 This is a flowchart illustrating the method for tracing and preventing tampering of power materials based on Internet of Things privacy protection provided by the present invention.
[0029] Figure 9 This is a schematic diagram of the electronic device provided by the present invention. Detailed Implementation
[0030] Embodiments of the present invention are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, and should not be construed as limiting the present invention.
[0031] The following description, with reference to the accompanying drawings, describes an embodiment of the Internet of Things-based power material traceability system, anti-tampering method, and electronic device for protecting privacy.
[0032] Example 1:
[0033] This embodiment provides a power material traceability system based on IoT privacy protection, which is applied to the complex scenario of full lifecycle management of power equipment. The system integrates perception layer hardware, network layer communication protocols, and application layer data processing engine to build a closed-loop traceability network from production, quality inspection, warehousing, transportation, installation, operation and maintenance to scrapping.
[0034] The core architecture of this system includes a digital twin module, a two-way verification module, a dual anomaly detection module, an operation and maintenance linkage module, a local encryption module, a local log management module, and an audit and traceability module. These modules work together to solve the problems of state synchronization between physical entities and digital records in complex flow networks, as well as data tamper-proofing.
[0035] For example, the digital twin module is used to assign a unique asset beacon, a transfer beacon, and a digital twin identifier to power materials, establish a binding relationship between physical materials and the digital twin identifier, and incrementally update the status of the digital twin corresponding to the physical materials after receiving and verifying the encrypted transfer data at each stage.
[0036] Here, asset beacons refer to RFID chips or secure encrypted microcontroller units embedded within the physical casing of power equipment, storing the device's hardware physical characteristics. Circulation beacons refer to dynamic RFID tags or low-power Bluetooth beacons attached to the outer packaging or smart logistics turnover boxes of power equipment, used to record environmental parameters and displacement information during circulation. A digital twin refers to a virtual data structure model built in the application layer database that maintains consistency with the physical equipment's state. Incremental updates mean that when the system receives new data, it does not overwrite historical data records, but instead adds the latest state to the time-series slice of the digital twin by appending data nodes.
[0037] The generation process of the digital twin identifier in the digital twin module includes: obtaining the asset beacon, the transfer beacon, and the manufacturer's unique code; performing a hash operation on the asset beacon, the transfer beacon, and the manufacturer's unique code to generate a unique digital twin identifier.
[0038] To ensure the uniqueness and irreversibility of the digital twin identifier, the above hashing process employs a cryptographically secure hashing algorithm. The formula for generating the digital twin identifier is given below:
[0039] ;
[0040] In the formula, A hexadecimal string representing the unique digital twin identifier generated; This represents the underlying hardware-coded data stream of the asset beacon read from physical materials; This represents the initial dynamic data stream of the streaming beacon read from the packaging carrier; This represents a manufacturer-specific data segment allocated by the system to the manufacturer; function This represents the secure hash algorithm operation function, which uses a one-way hash function with a 256-bit output length.
[0041] Specifically, the digital twin module incrementally updates the state of the digital twin corresponding to the physical material, including: extracting the data hash value and group signature attached to the encrypted data of each stage of the process, and comparing it with the registration information in the blockchain node. In response to the verification result of a consistent comparison, the corresponding flow state of the digital twin is updated and a stage state snapshot is generated, while simultaneously triggering the blockchain node to update the blockchain record. Here, the encrypted data of each stage of the process refers to the data packets collected by the perception layer device at each flow node and encapsulated using a public-key encryption algorithm; the data hash value is the digest value obtained by hashing the plaintext content of the data packet; the group signature is a special digital signature generated based on the elliptic curve discrete logarithm problem, which allows the signer to represent a group for signature verification while concealing the signer's specific identity and possessing the attribute of traceable identity in case of disputes; the stage state snapshot refers to a full state backup file of all field data within the digital twin, captured at a specific time point after verification; and the blockchain node refers to a server entity deployed in different geographical locations that runs a distributed ledger protocol.
[0042] It is also worth noting that this IoT-based privacy-preserving power material traceability system includes a two-way verification module. This module compares the multi-sensor fusion data of the acquired physical materials with the state data of the digital twin in real time. If the deviation exceeds a first preset threshold, a consistency verification process is triggered, verifying the authenticity of the data through blockchain records. Multi-sensor fusion data refers to the structured environment and attitude feature vector obtained by uniformly processing heterogeneous data streams from temperature sensors, humidity sensors, accelerometers, and GPS modules using a weighted average algorithm or a Bayesian estimation algorithm. The first preset threshold is a quantified value of the state deviation tolerance pre-set within the system. The mathematical expression of this deviation comparison process is as follows:
[0043] ;
[0044] In the formula, This represents the overall deviation between multi-sensor fusion data and digital twin state data; This indicates the total number of dimensions of the sensor data involved in the comparison; Indicates the first Weight coefficients for each data dimension; This indicates that the multi-sensor fusion data is in the first... Current measured values in each dimension; The state data of the digital twin is represented in the first... Expected values in each dimension. When When the value is greater than the first preset threshold, the system determines that a deviation has occurred.
[0045] like Figure 2 This diagram demonstrates the dynamic monitoring of power material logistics and transportation using this system. The horizontal axis represents the transportation time of power materials in minutes, and the vertical axis represents the comprehensive deviation value obtained after processing by the fusion algorithm.
[0046] The red dashed line in the figure represents the system's set state deviation tolerance boundary, i.e., the first preset threshold, which was set to 60 in this monitoring; the blue solid line in the figure represents the calculated multi-sensor fusion state deviation curve.
[0047] During the initial 0-74 minute period of transportation, the blue solid line fluctuates between 15 and 25 due to normal transportation fluctuations, which is lower than the red dashed line. This indicates that the physical condition of the goods is relatively consistent with the expected condition of the digital twin, and the system is in the normal flow recording stage.
[0048] At the 75-minute mark of the transportation process, an abnormal physical event occurred, causing the value of the blue solid line to surge significantly and exceed the red dashed line boundary of 60, reaching a peak value of 85. This surge reflects a deviation in the environmental and attitude characteristics of the data collected by the perception layer hardware. When the blue solid line rises above the red dashed line, the system determines that the deviation has exceeded the limit, thus triggering the subsequent blockchain consistency verification process, which calls historical record data to verify the authenticity of the current data.
[0049] The curve results demonstrate the system's ability to monitor abnormal fluctuations in the physical environment through its two-way verification mechanism, which helps to compensate for the lack of monitoring capabilities of a single database certificate when the physical and digital worlds are disconnected.
[0050] For example, the two-way verification module verifies the authenticity of data through blockchain records, including: extracting historical data hash values stored in the blockchain nodes, as well as hash values backed up by multiple nodes. The historical data hash values and the hash values backed up by multiple nodes are cross-compared with the current data hash value of the digital twin. In response to a discrepancy, the current data of the digital twin is determined to be distorted, and the data of the digital twin is restored based on the original data corresponding to the historical data hash value.
[0051] A multi-node backup hash value refers to the hash digest of the same data block recorded on at least three independent blockchain nodes in a distributed network. Cross-checking refers to the process of verifying the hash values of multiple data sources bit by bit using a Byzantine fault-tolerant consensus mechanism. Current data distortion refers to the erroneous data state of the digital twin's record in the application layer database, caused by network attacks, packet loss, or program anomalies, which deviates from the physical reality.
[0052] Specifically, the IoT-based privacy-preserving power material traceability system also includes a dual anomaly detection module. This module monitors physical state anomalies and data transmission anomalies in the physical materials during the consistency verification process or routine operations, and locates the root cause of the anomaly by associating the entire lifecycle data with the digital twin when an anomaly occurs. Physical state anomalies refer to environmental shocks experienced by power materials in physical space that exceed their design limits, such as severe impacts, immersion in water, or exceeding temperature limits. Data transmission anomalies refer to frequent retransmissions, abnormal data packet injection, or timestamp jumps during network layer communication. The entire lifecycle data refers to the structured data set stored in the digital twin, encompassing all environmental parameters, flow trajectories, and maintenance records from factory initialization to the current time point.
[0053] Optionally, the dual anomaly detection module includes a physical anomaly detection unit and a digital anomaly detection unit. The physical anomaly detection unit collects acceleration data and vibration data, and after fusion processing using a filtering algorithm, determines whether any physical state anomalies exist. The filtering algorithm employs a discrete Kalman filter for noise removal and optimal state estimation. The prediction and update formulas for the Kalman filter algorithm are as follows:
[0054] Prediction Phase Formula 1: ;
[0055] Formula 2 for the prediction phase: ;
[0056] Update phase formula three: ;
[0057] Update phase formula four: ;
[0058] Update phase formula five: ;
[0059] In the formula, A priori prediction vector representing the physical state; Represents the state transition matrix; Represents the posterior estimate vector of the physical state at the previous moment; Represents the control input matrix; Represents the system control vector; This represents the prior estimation error covariance matrix; This represents the posterior estimation error covariance matrix of the previous time step; The transpose of the state transition matrix; Represents the process excitation noise covariance matrix; Represents the Kalman gain matrix; Represents the measurement matrix; This represents the transpose of the measurement matrix. Represents the measurement noise covariance matrix; The superscript indicates the inverse of the matrix; This represents the posterior estimate vector of the physical state after fusion processing at the current moment; This represents the actual measurement vector formed by the collected acceleration and vibration data; This represents the posterior estimation error covariance matrix at the current time. This represents the identity matrix. When a specific component of the state estimation vector exceeds the set safety envelope range, it is determined that a physical state anomaly exists.
[0060] like Figure 3 This demonstrates the data processing procedure and results of the physical anomaly detection unit in the dual anomaly detection module. The horizontal axis in the figure represents the duration of the logistics transportation process, in units of... The vertical axis represents the vibration acceleration values collected by the accelerometer in the sensing layer, in units of... .
[0061] The light gray fluctuating curve in the figure represents the raw, noisy data without processing. Due to environmental interference such as the bumps caused by the movement of logistics vehicles, the raw data exhibits a lot of high-frequency noise, making the stress state of the materials unclear. The dark blue smooth curve in the figure represents the posterior estimated physical state data after processing by the discrete Kalman filter algorithm. The comparison shows that the dark blue curve filters out some of the high-frequency noise in the light gray curve, better reflecting the low-frequency movement trajectory of the power materials during transportation.
[0062] The red horizontal dashed line in the figure represents the system's set safety envelope threshold, which was set to 15 in this monitoring. At the 30-second mark of transportation, due to an abnormal collision event, both the light gray raw data and the dark blue filtered data showed waveform spikes.
[0063] The dark blue filtered curve climbs to a peak of 22 at 30 seconds, exceeding the safety envelope represented by the red dashed line. Based on this filtered characteristic value, the system identifies that the electrical equipment may have suffered a physical anomaly exceeding a set threshold. This signal processing mechanism helps reduce the false alarm rate caused by routine transportation bumps and provides data support for subsequently correlating full lifecycle data to pinpoint the root cause of the anomaly.
[0064] It is important to note that the digital anomaly detection unit is used to construct a time series of power material circulation data. This time series is then analyzed using a contrastive learning model to identify data tampering and falsely reported anomalies. A time series refers to a set of multidimensional state feature data points arranged chronologically according to the time of data collection and possessing equal time intervals. The contrastive learning model is a Siamese neural network architecture containing two feature extraction branches with shared network weights. It can learn the latent representation space distribution patterns of normal time series data, thereby isolating abnormal or tampered time series data from normal baseline data in a multidimensional feature space.
[0065] like Figure 4 This demonstrates the data classification performance of the digital anomaly detection unit in the dual anomaly detection module based on a contrastive learning model. The horizontal axis represents the first dimension of the feature dimensionality reduction space, and the vertical axis represents the second dimension, constructing a two-dimensional visualization of the feature distribution plane.
[0066] The scatter points in the figure represent the spatial mapping positions of the time series data on the circulation of electricity materials after feature extraction and dimensionality reduction by a Siamese neural network. The blue scatter clusters represent normal circulation data features. These feature points exhibit a relatively clustered state in space, with the distribution center located near the x-coordinate +15 and y-coordinate +20, indicating that normal time series data has a certain distribution pattern in the multidimensional feature space.
[0067] The red scatter plots represent abnormal data flow characteristics that have been tampered with or falsely reported, with their distribution center deviating to the area of x-axis -10 and y-axis -15.
[0068] Observing the distribution of the blue and red scatter clusters in the figure reveals a relatively clear spatial isolation boundary between them. This spatial isolation distribution indicates that the contrastive learning model can distinguish abnormal data sequences in the feature space without decrypting the underlying ciphertext, by learning the spatial distribution characteristics of normal baseline data. The discrimination mechanism based on spatial clustering distance helps the system identify data anomalies in the network layer, providing auxiliary support for the traceability of power materials.
[0069] The dual anomaly detection module uses the digital twin to correlate full lifecycle data to locate the root cause of anomalies. This includes: responding to anomalies during the flow process by extracting production quality inspection data, flow trajectory data, and multi-sensor fusion data from the digital twin for correlation determination to identify the anomaly's attribute as a production defect or flow damage. Production quality inspection data includes factory withstand voltage test reports, partial discharge test parameters, and visual inspection image feature values. Flow damage refers to the degradation of material performance caused by physical collisions or exposure to unsafe environments during logistics transportation, loading, and unloading. Correlation determination refers to the process of constructing a multi-dimensional data decision tree and mapping the extracted feature combination path to a preset fault code library. Responding to anomalies during operation, the module extracts installation records and historical operation and maintenance data from the digital twin for correlation determination to identify the anomaly's attribute as non-compliant installation or improper operation and maintenance. Installation records include terminal torque parameters, insulation resistance test values, and the digital signature of the construction personnel. Improper operation and maintenance refers to failure to perform operations according to the system-generated maintenance guidelines, such as incorrectly configuring operating parameters or failing to replace vulnerable parts in a timely manner.
[0070] In this embodiment, the IoT-based privacy-preserving power material traceability system also includes an operation and maintenance linkage module. This module generates an operation and maintenance work order containing the digital twin identifier, anomaly description, and traceability report after the dual anomaly detection module locates the root cause of the anomaly, and pushes it to the operation and maintenance terminal. The operation and maintenance work order is a structured extensible markup language document or a data payload based on script object simplified notation format automatically generated by the system, guiding on-site personnel in troubleshooting and repair. The traceability report is a visual data file automatically synthesized by the system based on full lifecycle data, presenting the trajectory of material status changes and anomaly triggering nodes along a timeline. The operation and maintenance terminal refers to a handheld explosion-proof smart terminal carried by operation and maintenance personnel or a graphical monitoring workstation deployed in the dispatch center.
[0071] Optionally, the system also includes a local encryption module, which is used to perform hierarchical fuzzification processing on the location information of the power materials based on the permissions of the participating parties. Hierarchical fuzzification processing refers to the operation of reducing the information entropy of the original geographic coordinate set using spatial transformation algorithms of different precision according to the authentication level and data access control policy of the access node. The hierarchical fuzzification process includes: performing spatial gridding and hashing operations on the precise geographic coordinates of the power materials to generate a core geographic index for core participating parties to access. Spatial gridding is a spatial quantization process that projects continuous geographic coordinates on the Earth's surface onto a two-dimensional hexagonal or square discrete grid cell system with fixed side lengths. The mathematical calculation model for the above process is as follows:
[0072] ;
[0073] ;
[0074] In the formula, A coded sequence representing a high-precision spatial grid; Indicates the precise geographical longitude value of power equipment; Represents the precise geographical latitude and longitude of electrical equipment; Indicates the preset high-resolution mesh level parameters; function Represents a spatial geometry meshing mapping function; Represents the generated core geographic index; function This refers to a secure hash function that includes a salt value, used to prevent reverse coordinate calculations via rainbow tables. The core participants refer to the institutional entities with the highest management authority in the system, such as the National Power Dispatch Center or a provincial-level materials management bureau.
[0075] like Figure 5 This diagram demonstrates the process by which the local encryption module in this system performs hierarchical fuzzification on the location information of power materials. The horizontal axis in the diagram represents geographical longitude in degrees, with a display range limited to 116.25 to 116.55; the vertical axis represents geographical latitude in degrees, with a display range limited to 39.75 to 40.05.
[0076] The curves formed by solid red lines and solid red dots in the diagram represent the precise geographic coordinate trajectories of electrical materials moving in the real physical world. To protect location information, the system uses a high-resolution spatial grid interwoven with light blue dashed lines in the diagram for spatial quantization mapping, capturing the continuous precise red coordinate trajectories and generating the blue star-shaped markers in the diagram. These blue star-shaped markers are the core geographic index mapping points, exhibiting a gridded discrete characteristic; this level of data is available to key stakeholders.
[0077] The system further performs dimensionality reduction and anonymization processing on the core geographic index. The squares on the map, divided by thick gray solid lines, represent the regional anonymized blocks generated after dimensionality reduction. For ordinary participants, the system blocks their access to the red precise trajectory and the blue star-shaped mapping points, allowing them to access gray grid blocks representing a wider range.
[0078] This transformation from continuous coordinates to discrete blue stars and then to broad gray squares demonstrates that the system can reduce the risk of power grid asset trajectories being tracked to some extent through a spatial scaling mechanism combined with hierarchical permission management.
[0079] It is important to note that the core geographic index undergoes dimensionality reduction and anonymization processing to generate regional geographic indexes for general participants. Dimensionality reduction and anonymization refers to an irreversible algorithmic operation that removes specific location details by truncating low-order feature bytes of the core geographic index or employing spatial clustering algorithms to expand the physical space represented by the geographic index. The regional geographic index is the output of this dimensionality reduction and anonymization process, typically representing a broad geographic area of several square kilometers. General participants refer to third-party logistics companies or outsourced construction teams that only undertake material transportation or on-site auxiliary handling tasks.
[0080] The system also includes a local log management module. This module is deployed within the edge computing gateway of the perception layer or within the smart hardware attached to the equipment. The local log management module generates a chained log containing the hash value of the previous log record and the digital signature of the current operation data. While storing this log locally, it also sends the current hash value of the chained log to a preset number of blockchain nodes for cross-backup.
[0081] A chained log is a data block structure based on cryptographic pointers linked end-to-end. Any minor alteration to a historical log record will cause the hash verification of all subsequent log blocks to fail. The digital signature of this operation is a signature string generated by encrypting the event record to be written using an asymmetric private key stored in the local security chip, ensuring the non-repudiation of the data source.
[0082] Cross-backup refers to a system that does not rely on a single uplink communication link, but instead uses a multi-routing protocol to concurrently transmit a simplified hash digest to at least three blockchain ledger nodes located in different network domains, in order to defend against single point of network failure and partial data overwrite attacks.
[0083] Specifically, the system also includes an audit and traceability module. This module, upon receiving a scrapping application for the electrical equipment, calculates the actual service life based on the installation records and current timestamp in the digital twin, and verifies whether the fault traceability records and environmental indicators in the full lifecycle data comply with preset rules. The scrapping application is a write-off request signaling message containing a material list and digital signature, initiated by the asset owner through the application layer front-end interface. The formula for calculating the actual service life is as follows:
[0084] ;
[0085] In the formula, This indicates the actual number of years that electrical equipment is in service within the power grid network; This indicates the current server standard timestamp value when the system receives the scrapping request; This represents the initial timestamp value for grid connection and operation of the equipment, extracted from the installation records of the digital twin. This represents a constant conversion factor that converts timestamp differences to standard calendar years. The preset rules are a set of logical judgment conditions generated by mapping power grid management regulations and mandatory national environmental protection standards.
[0086] Optionally, in response to a verification confirmation signal, the state of the digital twin is updated to a deprecated state, and the entire lifecycle data within the digital twin is packaged, encrypted, and archived on the blockchain. The verification confirmation signal refers to the internal state machine flow signaling generated after automated logical verification and digital signature authorization by the permission review node. The deprecated state refers to the termination node entered by the digital twin in the lifecycle state machine model; at this point, the system will freeze the digital twin and reject any routine business state update requests from the perception layer. Packaging and encryption refers to a hybrid encryption system combining advanced standard symmetric algorithms and commercial cryptographic asymmetric algorithms to perform high-intensity compression and sealing of massive time-series data and structured logs. Archiving on the blockchain refers to storing the packaged and encrypted data ciphertext in a distributed file system and publishing the ciphertext's address hash and decryption permission policy to a smart contract on the blockchain for future long-term secure access and legal auditing.
[0087] In the process of power equipment circulation, firstly, during the initial stage of power equipment leaving the factory and circulating, this invention obtains the asset beacon, circulation beacon, and manufacturer's unique code of the equipment, and performs hash operations to generate a unique digital twin identifier, establishing a strong binding relationship with cryptographic anti-counterfeiting properties between the physical equipment entity and the digital file. In the actual warehousing, delivery, and logistics handover process, this mechanism effectively prevents criminals from substituting high-value power grid assets by physically replacing labels or forging warehousing scanning records, providing an unforgeable initial trust benchmark for full lifecycle traceability.
[0088] Secondly, addressing the issue of traditional material traceability systems struggling to detect discrepancies between the actual physical state and the digitally recorded state during logistics and transportation, this invention introduces a real-time two-way verification mechanism. In actual transportation scenarios, if electrical materials are illegally dismantled, dropped, or exposed to excessive temperature and humidity, even if an attacker simultaneously intrudes into and tampers with the application-layer database to conceal the alarm status, the system can still detect deviations exceeding a first preset threshold between the multi-sensor fusion data transmitted from the site and the expected state of the digital twin. This deviation triggers a consistency verification process based on the immutable records of the blockchain, thereby accurately identifying the tampered and distorted records and compensating for the security blind spots of relying solely on database verification.
[0089] Finally, in the complex external circulation environment, when an anomaly occurs, the system simultaneously monitors abnormal fluctuations in physical status and abnormal data transmission in network communication through a dual anomaly detection module. In practical applications, the system automatically retrieves the entire lifecycle data of the material through a digital twin, comparing the current anomaly characteristics with historical production quality inspection and circulation trajectories to objectively determine whether the anomaly is caused by manufacturing defects, transportation damage, or human-caused network attacks. After confirming the root cause of the anomaly, the system automatically generates a standardized maintenance work order containing a digital twin identifier, anomaly description, and source tracing report, and pushes it to the mobile maintenance terminal of front-line maintenance personnel in real time. This linkage mechanism eliminates the time lag caused by traditional manual hierarchical reporting and cross-departmental investigation, realizing an automated business closed loop from supply chain anomaly detection and responsibility determination to on-site work order dispatch and handling, effectively improving the safety management efficiency and anomaly response efficiency of power grid material circulation.
[0090] Example 2:
[0091] Building upon Example 1, this example provides an incremental reconstruction mechanism. Specifically:
[0092] In actual power material transportation processes, such as the long-distance transport of main transformers and meter boxes, materials often pass through network signal blind spots in remote mountainous areas or may encounter malicious network layer isolation attacks, leading to a disconnect between the cloud state and the physical state. Current technologies, when detecting data distortion or tampering in the cloud, typically employ a simple data rollback strategy, directly extracting historical anchor data from the blockchain to overwrite the current system data. This existing mechanism causes the digital system's timeline to regress, resulting in a severe temporal misalignment with the continuously evolving physical state of the materials. For example, the cloud may show materials at their origin, while real-time sensor feedback indicates they are already en route, triggering a continuous logical mutual exclusion and alarm dead loop within the system.
[0093] Therefore, this embodiment provides a specific execution logic for restoring the data of a digital twin based on the original data corresponding to the historical data hash value.
[0094] For example, the process of restoring the data of the digital twin based on the original data corresponding to the historical data hash value includes: in response to the result of determining the current data distortion of the digital twin, marking the state of the digital twin as an isolated state, and caching the newly generated multi-sensor fusion data in the isolated state. The result of determining the current data distortion of the digital twin refers to the logical state where the application layer's data processing engine outputs a Boolean value of true after executing the Byzantine fault-tolerant comparison algorithm. Current data distortion not only refers to illegal tampering with the data content, but also includes the logical breakdown of the data state machine caused by out-of-order arrival, message replay, or concurrent writing by multiple nodes at the transmission protocol level.
[0095] Optionally, marking the state of the digital twin as isolated means that, in the system's underlying state machine management engine, a permission change instruction is triggered for the access control list based on the dedicated memory block and database primary key bound to a specific power asset. In isolated state, the system rejects standard business write requests initiated against the digital twin, severing its regular data synchronization link with external applications to prevent secondary contamination or cascading spread of distorted data within the system network. Simultaneously, the query interface provided by the digital twin will return a specific status code, indicating that the object is currently in a data consistency reconstruction cycle.
[0096] It is important to note that caching the newly generated multi-sensor fusion data in the isolated state means that the system does not discard the real-time physical state data continuously uploaded by the perception layer hardware during the isolation reconstruction period. Instead, it redirects these data streams to an independent, high-concurrency memory queue with first-in, first-out (FIFO) characteristics. The caching mechanism is introduced to ensure a smooth and seamless transition to the current physical world state after historical data repair is completed. The capacity model and data backlog status of the cache queue can be evaluated and monitored using the following integral function:
[0097] ;
[0098] In the formula, Indicates at any time The memory capacity in bytes occupied by the cache queue; This indicates the initial capacity of the cache queue at the moment the isolation state is triggered; This indicates the exact timestamp at which the system marks the digital twin's state as isolated; Indicates the integral over time At any given moment, the instantaneous data throughput rate of multi-sensor fusion data written to the cache queue.
[0099] Specifically, the system provided in this embodiment further performs the following operations: extracting the trusted timestamp corresponding to the historical data hash value, and retrieving the local chain log from the trusted timestamp to the current time interval. Extracting the trusted timestamp corresponding to the historical data hash value refers to the application layer server initiating a smart contract call request with authentication credentials to the blockchain consortium chain node, and based on the detected inconsistent data block index, tracing back and reading the header time parameter of the block that most recently achieved network-wide consensus and was successfully written to disk on the blockchain distributed ledger. The trusted timestamp has strict monotonically increasing temporal order and high anti-counterfeiting properties, serving as the logical zero point in the data reconstruction process.
[0100] For example, retrieving local chained logs from the trusted timestamp to the current time interval refers to the application layer server issuing instructions to the local log management module attached to the physical entity of the power equipment via an encrypted channel. The local chained log is a continuous data structure with cryptographic tamper-proof properties, stored in the non-volatile storage medium of edge computing hardware. The local chained log contains records of all environmental parameter changes and state transitions actually experienced by the physical equipment during communication interruptions or tampering. The determination logic for the retrieval interval is expressed in the form of a closed interval set:
[0101] ;
[0102] In the formula, the set Indicates the valid time window when initiating a retrieval command; This represents a trusted timestamp extracted from a blockchain consortium chain node; This indicates the current standard timestamp of the application layer server when the system initiates the retrieval command. The system only requests log data fragments whose generation time falls within this closed interval.
[0103] Optionally, after obtaining the above data, the system performs the following verification steps: verifying the nested hash values between adjacent log records in the local chained log and the continuity of the digital signature. Verifying the nested hash values between adjacent log records in the local chained log refers to performing a cryptographic integrity check on the log data stream uploaded from the edge side. The nested hash value mechanism requires that each new log record, when generating its own hash digest, must include the hash digest of the previous log record as part of its data payload. This structure ensures that even a tiny byte change in any historical record will cause a cascading effect on the hash values of all subsequent log records, thus failing verification. The calculation and verification of nested hash values follow the following algorithm structure:
[0104] ;
[0105] In the formula, Indicates the current number Each log record contains the generated hash digest results; function Indicates the specified secure hash operation function; Indicates the first The log record contains core business data payloads, such as temperature, humidity, or location coordinates; symbols Operators for concatenating data bits; Indicates the first Each log entry records the generated edge-side local timestamp; Indicates the first Each log record generates a hash digest of the hash value. The system needs to start from the first record in the local chained log and recalculate and compare each hash value sequentially.
[0106] It is important to note that verifying the continuity of digital signatures means not only ensuring data integrity but also verifying the authenticity and non-repudiation of the source of each log data entry. The digital signature is generated by the local encryption module using its built-in asymmetric encryption algorithm private key. The system uses a pre-obtained public key associated with the power equipment to mathematically verify the signature of each data block in the local chained log. The digital signature verification process employs the following algorithm model:
[0107] ;
[0108] In the formula, Indicates the first The signature verification output of the log record is a boolean data type; function This represents the signature verification execution function defined based on the elliptic curve cryptography standard. This indicates that the system has pre-registered the device's public key in a trusted environment and distributed it to the verification module; Indicates the first The nested hash digest results of each log record; Indicates appended to the Each log entry ends with a digital signature bit string. Continuity checks require all entries within this time interval to be valid. All verification results must be logically true; any result that returns logically false will block the verification process.
[0109] After completing a rigorous verification process, the system will branch based on the Boolean value of the verification result. In response to the successful verification of the local chained log, using the original data corresponding to the historical data hash value as the baseline state, the system sequentially executes the state update operations in the local chained log in chronological order to reconstruct the latest trusted state. The data of the digital twin is then restored using this latest trusted state. Subsequently, the isolation state is lifted, and the cached multi-sensor fusion data is processed. A successful local chained log verification result refers to a composite logical state where all nested hash value comparisons are consistent and all digital signature verifications return logically true.
[0110] For example, using the original data corresponding to the historical data hash value as the baseline state means that the system allocates an independent workspace in memory and loads the structured data records corresponding to trusted timestamps that have been registered and verified by consensus from the blockchain nodes into this workspace. This original data contains the last known secure state vector of the digital twin before it is tampered with or disconnected from the network. Executing the state update operations in the local chain log sequentially according to the time sequence means that the system initiates a state machine sandbox deduction process within this independent workspace. The system reads the verified local chain log, parses the data payload into state transition instructions in chronological order, and applies them to the baseline state vector. The mathematical deduction process of this state reconstruction is represented as follows:
[0111] ;
[0112] In the formula, Indicates that it has been executed The state feature vector of the digital twin derived from the local chained logs; This represents the initial baseline state vector transformed from the raw data read from the blockchain node; This represents a predefined business state transition matrix, used to transform the raw data in the log into an increment of the state vector; Indicates from the first Extract and format the valid business data column vector from the local chained logs.
[0113] Optionally, reconstructing the latest trusted state means that when the index in the above formula... The final state vector output after traversing the last local chained log within the retrieval interval. Restoring the digital twin data to the latest trusted state means that the system forcibly overwrites the distorted field values of the digital twin in the application layer database with the corresponding values in the latest trusted state vector derived above. This operation completes a smooth transition from the historical anchor point to the current true state on the edge side, corrects the cloud data, and preserves the true evolution trajectory of the physical device during the anomaly.
[0114] like Figure 6 This demonstrates the system's deductive repair mechanism when dealing with data distortion. The horizontal axis in the figure represents the local chained log sequence index, indicating the discrete log records retrieved by the system; the vertical axis represents the numerical values of the digital twin's state characteristics.
[0115] The red dashed line in the diagram represents the historical reliable baseline state extracted by the system. In this simulation, the initial baseline value is 20. When the system starts the state machine sandbox simulation process, the blue solid line in the diagram, in the form of a stepped curve, shows the simulation trajectory of the system executing log update operations sequentially according to the time sequence. The blue solid dots on the blue solid line represent discrete state update nodes, reflecting the incremental changes to the baseline state after each parsing of business data.
[0116] As the sequence index progresses, the blue stepped curve shows an upward trend and fluctuations, reflecting the evolution of the state of power resources during the anomaly. After the system has traversed the local chained log with index 10, the inference trajectory terminates at the green pentagram in the upper right corner of the figure. This marker represents the latest reliable state reconstructed by the system, and its value is fixed at 65.
[0117] This visualized trajectory, which starts from historical benchmarks and extrapolates through edge logs, demonstrates the method of bridging data gaps in this invention, which helps to update and repair the state of distorted data.
[0118] It is also important to note that the isolation state is subsequently lifted and the cached multi-sensor fusion data is processed. Lifting the isolation state means revoking the locking policy previously applied to the access control list of the digital twin, restoring its permission to receive normal business flow data. Processing the cached multi-sensor fusion data means that the system starts an independent asynchronous consumption thread to read the real-time sensor data accumulated during the isolation reconstruction from the previously established high-concurrency memory queue in a first-in-first-out time order. This cached data will be written to the now-healthy digital twin using normal incremental update logic. The rate control of cache processing adopts the following function model to prevent instantaneous system overload:
[0119] ;
[0120] In the formula, Indicates at time The system reads and processes the actual consumption rate of multi-sensor fusion data from the cache queue; function This represents a mathematical operation that takes the minimum value among multiple input parameters. This indicates the maximum safe write throughput limit allowed by the application layer server database input / output interface; This represents the baseline processing throughput allocated by the system to this asynchronous consumer thread; Indicates at time The current backlog capacity of the cache queue; This indicates the preset cache queue capacity alarm threshold.
[0121] Through the above processing, the system has completed the temporal bridging and smooth transition of states.
[0122] Specifically, for extreme anomalies such as data verification failure, the system provides another security circuit breaker branch logic. In response to the failure of the local chained log verification, the isolation state of the digital twin is maintained, and a field verification work order is generated. The failure of the local chained log verification indicates that not only is the data of the power equipment distorted at the network layer, but the attached local edge computing hardware itself is also highly likely to have suffered serious security events such as deep physical damage, hardware-level flashing attacks, or key leakage. In this situation, any data extrapolation based on software algorithms cannot guarantee the reliability of its results.
[0123] For example, maintaining the isolation of the digital twin aims to prevent high-risk physical devices from further participating in the automated flow system of the power grid logistics, and to prevent potentially malicious software and hardware from accessing the core power grid asset database. Generating a field verification work order refers to triggering the system's operation and maintenance linkage module to automatically assemble a high-priority standardized data structure file. The generation of the field verification work order is based on the verification interruption point information captured by the digital anomaly detection engine. The data assembly model of this work order is as follows:
[0124] ;
[0125] In the formula, This represents the final generated structured operation and maintenance work order object containing multi-dimensional attribute fields; function This represents the encapsulation operation of a data structure; A digital twin identifier that uniquely binds to the electrical equipment that experienced the anomaly; This indicates the last known precise geographic coordinates of the material extracted by the system from a trusted blockchain record or the last valid log. This represents the standardized troubleshooting code generated by the system based on the specific error type mapping of nested hash value breakage or digital signature verification failure; This represents the precise system timestamp when the verification process detected an anomaly in the local chained logs; This represents the hexadecimal index hash of the anomalous data block that caused verification to terminate in the local chained log sequence.
[0126] The on-site verification work order will be forcibly sent to the handheld terminal of the security personnel or senior maintenance engineer closest to the last known precise geographical coordinates of the material via an encrypted wireless communication network. It requires that the trust chain of the material be re-established and its subsequent disposal plan be determined through manual physical intervention, visual verification of anti-tampering tags, and direct connection of hardware interfaces.
[0127] In summary, this embodiment of the system, after isolating the distorted digital twin, does not blindly perform a full rollback. Instead, it retrieves the edge-side local chain logs from the perception layer during the network outage / attack period. After verifying that the local logs have not been corrupted using cryptographic mechanisms, the system uses historical trusted blockchain data as a benchmark to progressively deduce and reconstruct the state increments during the lost period according to the time sequence. In actual operation, this mechanism effectively bridges the time difference and state gap between historical trusted states and real-time sensor data, achieving smooth repair of distorted data. Furthermore, in extreme cases where log verification fails due to deep physical damage to local hardware, the system can securely trip and automatically dispatch the highest-level on-site verification work order, effectively improving the robustness of the traceability system in extremely harsh communication environments.
[0128] Example 3:
[0129] In real-world scenarios involving the cross-regional transfer and last-mile delivery of high-value, critical power grid assets, such as core smart meters and classified communication terminals, existing technologies often employ a single, static location anonymization strategy to prevent malicious tracking. This strategy only provides outsourced logistics drivers with rough regional coordinates. While this ensures data security, in practice, it can lead to drivers being unable to locate specific loading / unloading platforms or handover towers upon arrival at the target area due to a lack of precise navigation, causing the final physical connection operation to stall. Conversely, directly providing precise coordinates would compromise the system's privacy protection mechanisms.
[0130] To reconcile the aforementioned conflicting technical requirements, this embodiment performs dimensionality reduction and anonymization processing on the core geographic index, generating a regional-level geographic index for general participants to access. Specifically, this includes the following:
[0131] For example, the process of performing dimensionality reduction and anonymization processing on the core geographic index to generate a regional geographic index for general participants includes: extracting the job location coordinates uploaded by the general participants and calculating the spatial distance between the job location coordinates and the precise geographic coordinates of the power materials. Here, the core geographic index refers to the encrypted hash code representing the actual physical latitude and longitude of the power materials, recorded internally by the system; the dimensionality reduction and anonymization processing refers to the data generalization operation performed by the application layer server to reduce the effective resolution of latitude and longitude coordinates by truncating the low-bit strings of the high-precision spatial grid code; the regional geographic index refers to the fuzzy geographic code output after the above data generalization operation, which can only indicate the approximate administrative division or kilometer-level grid range of the power materials; and the general participants refer to restricted user entities assigned in the system's permission management module as outsourced logistics carriers, grassroots warehouse operators, or on-site auxiliary construction teams.
[0132] Furthermore, operational positioning coordinates refer to latitude and longitude data vectors that are collected in real time by the global satellite navigation system module built into the mobile smart terminals carried by ordinary participants, parsed by the baseband chip, and uploaded to the application layer server through the application layer application programming interface. Precise geographic coordinates refer to the real physical latitude and longitude data vectors that are actively reported by asset beacons or accompanying transfer beacons embedded in the power materials themselves, without undergoing any dimensionality reduction or generalization processing.
[0133] Optionally, extracting the job location coordinates uploaded by the ordinary participants refers to the application layer server's network access gateway opening a persistent transmission control protocol connection listening port, receiving location telemetry data streams from the ordinary participants' mobile smart terminals at a preset sampling frequency, and deserializing them into coordinate objects with explicit timestamp attributes. Calculating the spatial distance between the job location coordinates and the precise geographic coordinates of the power materials refers to the application layer server's knowledge graph engine calling a spatial geometry calculation function library to assess the relative linear proximity between the mobile smart terminal and the physical entity of the power materials based on an Earth ellipsoid model.
[0134] The spatial distance calculation process uses the semi-sine spherical distance calculation formula to eliminate the calculation error caused by the curvature of the Earth. The mathematical model for this spatial distance calculation is expressed as follows:
[0135] ;
[0136] In the formula, This represents the calculated numerical value of the actual spherical spatial straight-line distance between the mobile intelligent terminal of a general participant and the power material itself. This represents the Earth's average radius value, which is pre-written into the system constant configuration table. This represents the current geographic latitude and radian value of the mobile smart terminal of a general participant, extracted from the operation's positioning coordinates. This indicates the current geographic latitude and radian value of the power equipment extracted from precise geographic coordinates; This represents the current geographic longitude in radians of the mobile smart terminal of a general participant, extracted from the operation's positioning coordinates. This indicates the current geographical longitude in radians extracted from precise geographical coordinates for power materials.
[0137] It is also important to note that the system maintains the spatial distance calculation results in real time in the application layer memory and inputs them into an event-driven rule-based judgment engine for threshold comparison. In response to a determination that the calculated spatial distance is greater than a second preset threshold, the regional-level geographic index is continuously output to the ordinary participants. The calculated spatial distance refers to the distance output by the aforementioned semi-sine spherical distance calculation formula. The current updated value. The second preset threshold refers to the static scalar value written into the business rule base during the system initialization configuration phase, used to define the radius of the warning circle for safe handover operations. If the calculated spatial distance is greater than the second preset threshold, it indicates that the ordinary participants are still in the long-distance transportation scheduling phase and have not entered the physical line-of-sight range or the interior of the park that requires high-precision navigation guidance.
[0138] like Figure 7 This diagram illustrates the execution process of the permission adjustment mechanism based on spatial proximity in the system of this invention. The horizontal axis in the diagram represents logistics transportation time, in minutes. The diagram uses a dual vertical axis: the left vertical axis represents the relative spatial distance between ordinary participating terminals and power materials, in meters, corresponding to the blue solid line in the diagram; the right vertical axis represents the triggering status of the dynamic high-precision geographic token, corresponding to the black solid line in the diagram. A value of 0 indicates that it has not been triggered and a regional-level geographic index has been output to the terminal, while a value of 1 indicates that it has been triggered and a high-precision geographic token has been issued to the terminal.
[0139] The red dashed line in the figure represents the system's set safe connection threshold, which was set to 500 meters in this monitoring. Between 0 and the 46th minute, the blue solid line gradually decreases but remains above the 500-meter red dashed line, indicating that the vehicle is in a long-distance dispatch phase. The corresponding black solid line remains at a value of 0, and the system maintains a de-identified state for the location data.
[0140] At approximately the 46th minute, the blue solid line crossed the red dashed line, indicating that the terminal had entered the end-point connection range. At this time, the black solid line changed from a value of 0 to a value of 1, indicating that the system triggered a precision privilege escalation command, issuing a temporary geographic token to the terminal to provide physical handover coordinates.
[0141] At the 50-minute mark, the blue solid line drops to 0, indicating that the terminal has reached the target location and triggered a handover confirmation signal. Upon receiving this signal, the black solid line falls back to 0, indicating that the system has revoked the temporary geographic token and blocked ordinary participants from obtaining precise coordinates.
[0142] This curve transformation process reflects the mechanism of the present invention that dynamically adjusts navigation permissions based on spatial distance, which helps to balance the needs of location privacy protection and on-site handover operations.
[0143] Maintaining the output of the regional-level geographic index to the ordinary participants means that when the system receives a location query request from the mobile smart terminal of an ordinary participant, the data processing interface of the application layer server forcibly calls the dimension reduction and desensitization operator when encapsulating the location payload in the downlink data packet. Only the generalized hash value representing the kilometer-level range is serialized into the message body, thereby blocking the transmission of precise coordinate data on the communication link and ensuring reliable location concealment during long-distance logistics transportation.
[0144] Specifically, as logistics flow progresses, spatial distances will dynamically decrease. In response to the calculated spatial distance being less than or equal to the second preset threshold, a temporary geographic token with a preset valid duration is generated for the ordinary participant. This temporary geographic token dynamically restores the regional geographic index to precise geographic coordinates. The calculated spatial distance being less than or equal to the second preset threshold indicates that the transport vehicle driven by the ordinary participant or the terminal carried has exceeded the system's established security handover operation warning zone and entered the substantive end-point connection guidance stage. The preset valid duration refers to the lifecycle time window value of the temporary authentication certificate, dynamically calculated and assigned by the system based on historical average loading and unloading time statistics for similar materials. The temporary geographic token is an encrypted string with self-contained verification capabilities, issued in real-time by the system's key exchange module using a dynamic key generation algorithm based on the current timestamp, the material's digital twin identifier, and the terminal device's fingerprint.
[0145] For example, the specific process for generating a temporary geographic token with a preset validity period for the ordinary participant is as follows: a cryptographic construction method combining a hash-based message authentication code system and a symmetric encryption system is used. The mathematical model of the temporary geographic token generation algorithm is expressed as follows:
[0146] ;
[0147] ;
[0148] ;
[0149] ;
[0150] In the formula, This represents the absolute expiration timestamp value of the temporary geographic token calculated by the system. This represents the system's current standard timestamp value at the moment the application layer server generates the token; This represents the time offset value of the preset effective duration set by the system. This represents the plaintext data payload block assembled before encryption; This represents a digital twin identifier data segment that is uniquely linked to the target power equipment; The concatenation operator for data bits; A data stream representing the precise geographic coordinates of power equipment; This represents the temporary geographic token string that is ultimately generated and issued to the terminals of ordinary participants; function This represents the Advanced Encryption Standard (AES) symmetric encryption function; This represents the short-term session encryption key negotiated and generated between the application layer server and the ordinary participating terminal during the transport layer secure handshake phase; function This represents a hash-based message authentication code generation function; This represents the independent authentication key used to generate the message authentication code.
[0151] Optionally, dynamically restoring the regional-level geographic index to precise geographic coordinates using the temporary geographic token means that after receiving the issued temporary geographic token, the mobile smart terminal of the ordinary participant first uses its built-in local encryption module to verify the integrity and source legitimacy of the message authentication code using its held key. After successful verification, it extracts the current system clock timestamp of the terminal and compares it with the absolute expiration timestamp decrypted from the token. If the current clock has not expired, the terminal's local application software will parse the precise geographic coordinate data stream and overwrite the regional-level geographic index originally displayed on the user interface, thereby rendering navigation icons for loading / unloading platforms or specific pole connection points accurate to the meter on the electronic map layer. This restoration process is only executed in the volatile memory of the ordinary participant's terminal and does not involve any form of local persistent storage.
[0152] It is also important to note that this privilege escalation state based on spatial proximity is transient and strictly constrained by physical facts. In response to a physical handover confirmation signal triggered at the precise geographic coordinates, the temporary geographic token is cancelled, and the ordinary participant's access to the precise geographic coordinates is blocked. Simultaneously, the output of the regional-level geographic index is restored. The physical handover confirmation signal refers to a digital level pulse or cryptographic signature revocation signal generated within the physical space covered by the precise geographic coordinates, through a short-range near-field communication protocol, RFID handshake protocol, or physical tamper-evident seal sensor state flip, proving a substantial transfer of control of the materials. Cancellation of the temporary geographic token means that, upon receiving the physical handover confirmation signal, the application layer server immediately inserts the index digest of the temporary geographic token into its in-memory token revocation list, or actively sends a destruction control message to the ordinary participant terminal, forcing the terminal to clear the cached decryption key and coordinate plaintext in memory.
[0153] Specifically, blocking the ordinary participant's access to the precise geographic coordinates means that the multi-participant permission management module of the application layer server modifies the state of the access control list matrix element for that ordinary participant. The underlying control logic of this permission blocking mechanism can be described by the following state machine matrix equation:
[0154] ;
[0155] In the formula, This represents the access permission vector for a specific power material data object by a regular participating user entity in the current state; A unique identifier representing a regular participating user entity; A unique identifier representing the target power material data object; Represents a bitwise logical AND operation for matrix elements; This represents a predefined permission revocation mask vector. In this mask vector, the feature bits corresponding to high-precision location read permissions are set to logical zero, while the feature bits corresponding to region-level index read permissions are retained to logical one. After the above logical AND operation, application interface calls from ordinary participants attempting to read precise geographic coordinates will be directly intercepted by the system kernel and a permission denied exception will be thrown.
[0156] For example, synchronously restoring the output of the regional-level geographic index means that within the same transaction operation cycle in which the permission blocking matrix update takes effect, the system clears any precise location cache in the downlink data queue for the ordinary participant terminal and resets the routing rules of the data serialization interceptor.
[0157] When a participating party's terminal subsequently initiates another location polling request, the system's data processing engine will re-execute the dimensionality reduction and anonymization operator, outputting only the generalized regional-level geographic index data stream to that terminal. Through this closed-loop process, the high-precision positioning anchor point on the participating party's mobile smart terminal interface will immediately disappear, and the display accuracy will degrade back to macroscopic kilometer-level color block markers. This mechanism ensures that the associated precise location privacy exposure window is immediately closed the moment the physical transfer of power materials is completed and the handover task is accomplished. This effectively prevents participating parties from illegally and delayedly tracking the flow and destination of power materials after the operation is completed, achieving a balance between the rigid requirements of business functions and the principle of strict data privacy protection.
[0158] This embodiment upgrades static geographic privacy to a dynamic authorization mechanism based on spatial proximity. During long-haul transportation, the system calculates distances to determine when vehicles are too far away, strictly maintaining regional-level location ambiguity to ensure high security in long-haul transport. When the system determines that a logistics terminal has entered a set proximity threshold, it automatically issues a temporary geographic token with an expiration date to the operators, briefly decrypting the coordinates to meter-level accuracy to guide the vehicle to a precise stop. The moment the on-site sensors confirm the physical transfer of goods, the system immediately cancels the token and blocks access, and the terminal interface simultaneously reverts to its previous ambiguous display. In practical applications, this mechanism effectively resolves the rigid contradiction between global location privacy protection and precise end-point operational navigation, effectively meeting the actual business needs of efficient on-site logistics while strictly adhering to the security bottom line of preventing unauthorized delayed tracking of core assets.
[0159] Example 4:
[0160] like Figure 8 As shown, this embodiment provides a method for tracing and preventing tampering of power resources based on IoT privacy protection. This method is mainly executed collaboratively by an application layer server, a perception layer IoT device, and an edge computing gateway.
[0161] Specifically, the method in this embodiment is applied to an IoT-based privacy-preserving power material traceability system, and the method includes the following execution steps:
[0162] First, during the factory manufacturing and initialization phase of power equipment, such as smart meters and distribution transformers, a filing and binding process is performed. Specifically, this involves assigning unique asset beacons, transfer beacons, and digital twin identifiers to each power equipment, establishing a binding relationship between the physical equipment and the digital twin identifier. In practical applications, asset beacons are typically anti-metal radio frequency identification (RFID) tags fixed inside the metal casing of power equipment using industrial adhesives or rivets; transfer beacons are typically low-power Bluetooth (BLE) modules with independent power supplies attached to packaging crates or smart logistics pallets. Fixed readers in the production workshop read these hardware media and initiate a registration request to the application layer server. The process of generating the unique digital twin identifier includes: obtaining the asset beacon, transfer beacon, and manufacturer's unique code; performing a hash operation on the asset beacon, transfer beacon, and manufacturer's unique code to generate the unique digital twin identifier. The hash operation is typically performed by the manufacturer's local workstation or edge computing gateway, and the resulting digital twin identifier serves as the unique primary key for the electrical asset in relational databases and distributed blockchain ledgers.
[0163] Subsequently, as the electrical materials leave the manufacturing plant and enter the warehousing and logistics transportation stages, the system begins to continuously update its status records. Specifically, after receiving and verifying the encrypted data from each stage, the system incrementally updates the status of the digital twin corresponding to the physical materials. The encrypted data from each stage is collected and encrypted by vehicle-mounted industrial gateways deployed on transport vehicles or handheld IoT terminals at warehousing nodes. After verifying the validity of the digital signature and timestamp anti-replay mechanism of the data packets, the server-side receiving program appends the material's location migration information, temperature and humidity exposure information, etc., to the database in a time-series format, forming a continuously extending data timeline.
[0164] It is also important to note that, in order to prevent the physical state from becoming disconnected from the digital record, the system continuously executes a verification mechanism throughout the entire process: real-time comparison of the multi-sensor fusion data of the physical material with the state data of the digital twin. If the deviation exceeds a first preset threshold, a consistency verification process is triggered, and the authenticity of the data is verified through blockchain records.
[0165] In actual equipment operation, multi-sensor fusion data originates from an environmental sensing hardware cluster attached to logistics vehicles or turnover boxes, including a three-axis accelerometer, gyroscope, and temperature and humidity sensor. This data is uploaded to the cloud after being processed by Kalman filtering at the edge gateway. The application layer server performs a mathematical difference operation between this measured data and the expected state vector generated based on the transportation plan in the digital twin. When the difference exceeds a first preset threshold, such as a positional deviation exceeding a set distance or environmental parameters exceeding the safety envelope, the system suspends receiving regular data and initiates a query to the blockchain consortium chain node to compare hash values and confirm whether the application layer data has been tampered with at the network layer.
[0166] Furthermore, to achieve in-depth analysis of anomalies, the system executes the following monitoring and tracing steps: During the consistency verification process, if data anomalies are detected or during daily operations, the system monitors for physical state anomalies and data transmission anomalies in the physical materials. When an anomaly occurs, the system uses the digital twin to correlate the entire lifecycle data to pinpoint the root cause. Physical state anomalies are typically triggered by electrical signal pulses exceeding physical limits detected by underlying sensors, such as acceleration peaks caused by drops or collisions. Data transmission anomalies are triggered by frequent message retransmissions or checksum errors at the network layer. The process of locating the root cause involves a data mining task executed within the application layer server. By extracting the handover times of each node recorded in the digital twin, the logistics carrier's identification, and quality inspection reports, a decision tree algorithm is used to compare the spatiotemporal nodes where the anomaly occurred, thereby objectively outputting whether the anomaly was caused by substandard factory quality, rough handling during transportation, or interception and replacement of network data.
[0167] Finally, the system forms a physical closed loop for anomaly handling through an automated workflow mechanism: after locating the root cause of the anomaly, a maintenance work order containing the aforementioned digital twin identifier, anomaly description, and source tracing report is generated and pushed to the maintenance end. This maintenance work order uses a structured data format, such as JSON, where the anomaly description field contains specific error codes indicating sensor exceeding limits or hash mismatches; the source tracing report field contains log slices pointing to the responsibility handover node. The maintenance end typically manifests as a rugged smart tablet computer equipped by power company maintenance personnel or a large dispatch screen in the command center. Maintenance personnel arrive at the site based on the precise guidance information carried by the work order to perform physical verification, equipment repair, or execute isolation and decommissioning operations according to procedures.
[0168] In summary, the method disclosed in this embodiment closely integrates actual hardware devices such as RFID reader / writer, edge computing gateway, blockchain node server, and mobile maintenance terminal. By deeply integrating cryptographic identifier generation, multi-sensor deviation comparison, and blockchain consistency verification into the flow of power materials, it effectively bridges the time lag and gap between physical entity trajectories and digital status records. While ensuring data privacy and tamper-proof capabilities, it improves the efficiency of anomaly detection and location accuracy in complex supply chain networks.
[0169] Example 5:
[0170] Corresponding to the above embodiments, the present invention also proposes an electronic device.
[0171] like Figure 9 The diagram shows a structural schematic of an electronic device according to the present invention. The electronic device 100 includes a processor 101 and a memory 103. The processor 101 and the memory 103 are connected, for example, via a bus 102. Optionally, the electronic device 100 may further include a transceiver 104. It should be noted that in practical applications, the transceiver 104 is not limited to one unit, and the structure of this electronic device 100 does not constitute a limitation on the embodiments of the present invention.
[0172] Processor 101 may be a CPU, a general-purpose processor, a DSP, an ASIC, an FPGA, or other programmable logic device, transistor logic device, hardware component, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in connection with this disclosure. Processor 101 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0173] Bus 102 may include a pathway for transmitting information between the aforementioned components. Bus 102 may be a PCI bus or an EISA bus, etc. Bus 102 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 9 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0174] The memory 103 stores a computer program corresponding to the IoT-based privacy protection method for tracing and preventing tampering of power resources according to the above embodiments of the present invention. This computer program is controlled and executed by the processor 101. The processor 101 executes the computer program stored in the memory 103 to implement the content shown in the aforementioned method embodiments.
[0175] Among them, electronic devices 100 include, but are not limited to: mobile terminals such as laptops and PADs (tablet computers) and fixed terminals such as desktop computers. Figure 9The electronic device 100 shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of the present invention.
[0176] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. A power material traceability system based on Internet of Things (IoT) privacy protection, characterized in that, include: The digital twin module is used to assign unique asset beacons, transfer beacons, and digital twin identifiers to power materials, establish a binding relationship between physical materials and the digital twin identifiers, and incrementally update the status of the digital twin corresponding to the physical materials after receiving and verifying the encrypted transfer data at each stage. The two-way verification module is used to compare the multi-sensor fusion data of the acquired physical materials with the status data of the digital twin in real time. If the deviation exceeds the first preset threshold, the consistency verification process is triggered, and the authenticity of the data is verified by recording it on the blockchain. The dual anomaly detection module is used to monitor the physical state anomalies and data transmission anomalies of the physical materials during the consistency verification process or daily circulation process, and to locate the root cause of the anomaly by associating the full life cycle data through the digital twin when an anomaly occurs. The operation and maintenance linkage module is used to generate an operation and maintenance work order containing the digital twin identifier, anomaly description and source tracing report and push it to the operation and maintenance terminal after the dual anomaly detection module locates the root cause of the anomaly. The generation process of the digital twin identifier in the digital twin module includes: obtaining the asset beacon, the transfer beacon, and the manufacturer's unique code; performing a hash operation on the asset beacon, the transfer beacon, and the manufacturer's unique code to generate a unique digital twin identifier.
2. The system according to claim 1, characterized in that, The digital twin module incrementally updates the state of the digital twin corresponding to the physical material, including: Extract the data hash value and group signature attached to the encrypted data in each stage of the process, and compare them with the registration information in the blockchain node; In response to the verification result of the comparison, the corresponding circulation status of the digital twin is updated and a snapshot of the process status is generated, while the blockchain node is triggered to update the blockchain record.
3. The system according to claim 1, characterized in that, The two-way verification module verifies the authenticity of data through blockchain records, including: Extract the hash values of historical data stored in the blockchain nodes, as well as the hash values of multi-node backups; The historical data hash value and the hash value of the multi-node backup are cross-compared with the current data hash value of the digital twin; In response to the result of the inconsistency, it is determined that the current data of the digital twin is distorted, and the data of the digital twin is restored based on the original data corresponding to the historical data hash value.
4. The system according to claim 1, characterized in that, The dual anomaly detection module includes: The physical anomaly detection unit is used to collect acceleration data and vibration data, and after fusion processing by a filtering algorithm, to determine whether there is any physical anomaly. The digital anomaly detection unit is used to construct a time series of power material circulation data and to detect the time series through a comparative learning model in order to identify digital anomalies such as data tampering and false reporting.
5. The system according to claim 1, characterized in that, The dual anomaly detection module uses the digital twin to correlate full lifecycle data to locate the root cause of anomalies, including: In response to anomalies during the process, production quality inspection data, flow trajectory data, and multi-sensor fusion data from the digital twin are extracted and correlated to identify whether the anomaly is a production defect or flow damage. In response to anomalies during operation, the installation records and historical operation and maintenance data in the digital twin are extracted and correlated to identify whether the anomaly is due to non-compliant installation or improper operation and maintenance.
6. The system according to claim 1, characterized in that, The system also includes a local encryption module, which is used to perform hierarchical obfuscation processing on the location information of the power materials based on the permissions of the participants; The hierarchical fuzzification process includes: performing spatial gridding and hashing operations on the precise geographic coordinates of the power materials to generate a core geographic index for core participants to obtain; The core geographic index is subjected to dimensionality reduction and anonymization processing to generate a regional geographic index for general participants to access.
7. The system according to claim 1, characterized in that, The system also includes an audit traceability module; The audit traceability module is used to calculate the actual service life based on the installation record and current timestamp in the digital twin when it receives the application for scrapping the power materials, and to check whether the fault traceability record and environmental protection indicators in the full life cycle data meet the preset rules. In response to the confirmation signal that the verification has passed, the status of the digital twin is updated to the obsolete status, and the full lifecycle data of the digital twin is packaged, encrypted, and archived on the blockchain.
8. The system according to claim 3, characterized in that, The process of restoring the data of the digital twin based on the original data corresponding to the historical data hash value includes: In response to the result of determining the current data distortion of the digital twin, the state of the digital twin is marked as an isolated state, and the newly generated multi-sensor fusion data is cached in the isolated state; Extract the trusted timestamp corresponding to the historical data hash value, and retrieve the local chained log from the trusted timestamp to the current time interval; Verify the nested hash values between adjacent log records in the local chained log and the continuity of the digital signature; In response to the successful verification of the local chain log, the original data corresponding to the historical data hash value is used as the baseline state. The state update operation in the local chain log is executed sequentially according to the time sequence to reconstruct the latest trusted state. The data of the digital twin is then restored using the latest trusted state. Subsequently, the isolation state is lifted and the cached multi-sensor fusion data is processed. In response to the failure of the local chain log verification, the isolation state of the digital twin is maintained, and an on-site verification work order is generated.
9. The system according to claim 6, characterized in that, The process of performing dimensionality reduction and anonymization processing on the core geographic index to generate a regional geographic index for general participants includes: Extract the operation location coordinates uploaded by the ordinary participants, and calculate the spatial distance between the operation location coordinates and the precise geographical coordinates of the power materials; In response to the determination result that the calculated spatial distance is greater than the second preset threshold, the regional-level geographic index is continuously output to the ordinary participants; In response to the determination result that the calculated spatial distance is less than or equal to the second preset threshold, a temporary geographic token with a preset valid duration is generated for the ordinary participant, so as to dynamically restore the regional geographic index to accurate geographic coordinates through the temporary geographic token; In response to the physical handover confirmation signal triggered at the precise geographic coordinates, the temporary geographic token is cancelled, and the ordinary participant's access to the precise geographic coordinates is blocked. Simultaneously, the output of the regional geographic index is restored.
10. A method for tracing and preventing tampering of power materials based on Internet of Things (IoT) privacy protection, characterized in that, The method, applied to an IoT-based privacy-preserving power material traceability system, includes: A unique asset beacon, transfer beacon, and digital twin identifier are assigned to each power material. A binding relationship is established between the physical material and the digital twin identifier. After receiving and verifying the encrypted transfer data at each stage, the status of the digital twin corresponding to the physical material is incrementally updated. The multi-sensor fusion data of the physical materials and the status data of the digital twin are compared in real time. If the deviation exceeds the first preset threshold, a consistency verification process is triggered, and the authenticity of the data is verified by blockchain records. During the consistency verification process, if data anomalies are detected or during daily operations, the physical state of the physical materials and data transmission anomalies are monitored. When an anomaly occurs, the digital twin is used to correlate the entire lifecycle data to locate the root cause of the anomaly. After locating the root cause of the anomaly, an operation and maintenance work order containing the digital twin identifier, anomaly description, and source tracing report is generated and pushed to the operation and maintenance terminal. The process of generating a unique digital twin identifier includes: obtaining the asset beacon, the transfer beacon, and the manufacturer's unique code; performing a hash operation on the asset beacon, the transfer beacon, and the manufacturer's unique code to generate a unique digital twin identifier.