A Multi-Level Collaborative Management Method for Carbon Emission Reduction in a Green Cable Supply Chain

By calculating carbon emission margins in the cable supply chain and applying zero-knowledge proofs and Paillier homomorphic encryption, the data barriers and regulatory audit requirements for carbon management in multi-level supply chains are resolved. This achieves privacy protection and efficient carbon credit clearing, improving the efficiency and credibility of collaborative carbon reduction management.

CN122492200APending Publication Date: 2026-07-31RUITIAN CABLE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
RUITIAN CABLE CO LTD
Filing Date
2026-06-23
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

In multi-level supply chains, carbon management faces challenges such as data barriers, difficulty in balancing node privacy protection and regulatory audit requirements, and low efficiency of confidential clearing. Existing technologies cannot effectively solve the problem of end-to-end carbon footprint privacy tracking and continuous accumulation in long-chain, multi-level node scenarios in the cable supply chain.

Method used

By acquiring raw carbon data from each node in the supply chain, calculating carbon emission margins and performing zero-knowledge proofs, combining anonymous set-scale generation of ring signatures and interval proofs, and utilizing Paillier homomorphic encryption to perform weighted settlement of carbon credits in an off-chain trusted computing environment, the dual objectives of privacy protection and regulatory auditing are achieved.

Benefits of technology

Ensure that carbon data is standardized and highly condensed before on-chain computation, achieve seamless accumulation of carbon emissions and privacy protection, block data leakage paths, and improve the execution efficiency and credibility of collaborative carbon reduction management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122492200A_ABST
    Figure CN122492200A_ABST
Patent Text Reader

Abstract

This invention relates to the field of data processing technology, and in particular to a multi-level carbon emission reduction collaborative management method for a green cable supply chain. The method includes: acquiring raw carbon data of nodes and calculating carbon emissions and margins; using a verification circuit to add the previous carbon emission witness value to the current node's carbon emissions as a constraint, updating the full-link zero-knowledge proof; configuring anonymity sets according to margin levels to generate a first-layer ring signature and interval proof, constructing a commitment based on energy consumption and carbon emissions, and encrypting it with the regulator's public key to generate a second-layer ciphertext, which is then bound and encapsulated by the first-layer signature for privacy transactions on the blockchain; sending the homomorphically encrypted amount into a weighted summation in an off-chain trusted environment, combining it with adjustment coefficients to generate share ciphertext and knowledge proofs, and submitting it for contract archiving. This invention achieves trusted carbon footprint tracking while protecting privacy and anonymity, accommodating controlled audit requirements, and improving the efficiency of encrypted settlement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a multi-level carbon emission reduction collaborative management method for a green cable supply chain. Background Technology

[0002] The cable industry has a long supply chain with many participants, characterized by high energy consumption and widespread carbon emissions. Throughout the product lifecycle, carbon emissions are dispersed across multiple levels, making it difficult for a single company's emission reduction measures to achieve low-carbon synergy across the entire industry chain. Consortium blockchain technology, with its features of data immutability, process traceability, and trusted multi-party collaboration, offers a new technological approach to solving trust issues across supply chain nodes and has been explored for application in supply chain management and carbon footprint verification.

[0003] However, in multi-level supply chain carbon management practices, companies at each node typically treat operational data such as production capacity, energy consumption, and carbon footprint as commercially sensitive information, leading to significant data barriers between upstream and downstream entities. Traditional on-chain data disclosure mechanisms easily expose companies' true energy consumption and production capacity, while simply adopting strong privacy protection schemes may weaken the regulatory authorities' ability to conduct thorough audits, making it difficult for the system to balance node privacy protection with compliance traceability requirements. Furthermore, carbon emission reduction collaborative settlement involves the calculation and allocation of carbon credits for each node. Existing methods struggle to complete confidential calculations while protecting the privacy of each participant's actual emission reduction contributions, and are also ill-suited for efficient encrypted aggregation and validity verification in multi-level node scenarios.

[0004] Referring to Chinese patent document CN113065135B, a method for trusted privacy measurement of photovoltaic power based on blockchain is disclosed. This patent document constructs a trusted computing environment to verify the original power generation data, and converts the power generation data into carbon emission data accordingly. Then, the converted carbon emission data is sent to the blockchain system, thereby realizing trusted measurement and on-chain circulation of carbon emission data at the device end while protecting the enterprise's underlying original data from being disclosed.

[0005] Although the aforementioned patent documents utilize trusted computing environments and blockchain to achieve privacy protection and carbon emission record keeping for single-point devices, they are primarily designed for computing scenarios involving single or flat entities, and therefore cannot solve the challenges of end-to-end carbon footprint privacy tracking and continuous accumulation in long-chain, multi-level node scenarios within the cable supply chain. Furthermore, existing technologies lack a dual-layer encryption and decryption mechanism, making it difficult to simultaneously address both the strong anonymity protection of the supply chain business chain and the transparent and controllable auditing by regulatory agencies. Finally, when facing collaborative settlement of carbon credits from multiple parties, there is still a lack of efficient methods for processing encrypted weighted aggregation and conducting low-overhead non-interactive knowledge verification in a secure environment. Summary of the Invention

[0006] To address the technical challenges of balancing data barriers, node privacy protection, and regulatory auditing requirements in multi-level supply chain cross-node carbon management, as well as the low efficiency of confidential clearing, this invention provides a multi-level carbon emission reduction collaborative management method for green cable supply chains, comprising: S1, acquiring the original carbon data of enterprises at each node of the supply chain and extracting energy consumption data, converting various types of energy consumption to obtain the carbon emissions of this node, and calculating the difference between the read preset industry benchmark and the carbon emissions of this node as a carbon emission margin; S2. Perform addition constraint on the received preceding carbon emission witness value and the carbon emission amount of the current node in the verification circuit to output a zero-knowledge proof; generate a first-layer ring signature and interval proof according to the anonymity set size configured according to the carbon emission margin level; construct an attribute vector with the energy consumption data and the carbon emission amount of the current node; calculate the Pedersen commitment value by combining the configured generator matrix base point and the generated blinding factor; encrypt the Pedersen commitment value into a second-layer ciphertext using a public key; bind the second-layer ciphertext and the Pedersen commitment value by the first-layer ring signature. S3. Multiply the carbon emission margin by a preset coefficient to obtain the credit limit, and homomorphically encrypt it before sending it into the trusted environment. Perform homomorphic scalar multiplication on the encrypted credit limit ciphertext of each node according to the node level weight to obtain a weighted ciphertext. Multiply the weighted ciphertext together to decrypt and aggregate the total amount and calculate the allocation adjustment coefficient. Combine the allocation adjustment coefficient with the weighted ciphertext to generate the liquidation share ciphertext and knowledge proof, and submit it to the contract archive.

[0007] This invention establishes a quantitative basis for carbon credit allocation by calculating carbon emission margins; it uses recursive aggregation zero-knowledge proofs to achieve seamless carbon footprint accumulation within the circuit, enabling continuous and reliable data flow without exposing plaintext business transactions; the first-layer ring signature provides dynamic anonymity set protection based on margin performance; the second layer combines Pedersen commitments with dedicated regulatory public keys to encrypt data, achieving the dual goals of privacy hiding from the public perspective and controlled audit penetration from the regulatory perspective; it utilizes Paillier homomorphic encryption combined with an off-chain trusted computing environment to perform credit-weighted settlement, which not only completely blocks the data leakage path during multi-party joint settlement, but also ensures the accuracy of smart contract verification and archiving by generating non-interactive knowledge proofs, deeply promoting low-carbon collaboration in multi-level supply chains.

[0008] Preferably, the step of acquiring the original carbon data of enterprises at each node of the supply chain and extracting energy consumption data, and converting various types of energy consumption to obtain the carbon emissions of this node, includes: establishing a structured data dictionary, extracting electricity meter and gas meter readings as the energy consumption data; multiplying the energy consumption data by the extracted corresponding emission factors to convert it into carbon dioxide equivalent and summing them to obtain the carbon emissions of this node; using a hash algorithm to calculate a hash value for the energy consumption data and the carbon emissions of this node, and using the hash value as the primary key to construct a carbon data object.

[0009] This invention ensures the standardization and high data volume of raw multi-source carbon collection data before it enters the blockchain for computation, and enhances the anti-tampering and unique traceability capabilities of the underlying energy data objects by using hash values ​​as primary keys.

[0010] Preferably, the step of performing an additive constraint on the received prior carbon emission witness value and the current node's carbon emission amount within the verification circuit to output a zero-knowledge proof includes: within the verification circuit, generating a current node's cumulative commitment value by adding the extracted prior carbon emission witness value and the current node's carbon emission amount constraint; injecting the prior carbon emission witness value into a recursive verifier, and outputting the zero-knowledge proof by folding it through a polynomial commitment scheme.

[0011] This invention folds the complex upstream and downstream multi-node addition operation process into a verification file of constant volume, reducing the communication and verification burden of the consortium blockchain network, and maintaining the legitimacy of the carbon emission summation recursion relationship while hiding the preceding and current plaintext.

[0012] Preferably, the step of generating the first-layer ring signature and interval proof by configuring the size of the anonymous set according to the carbon emission margin level includes: dividing the carbon emission margin by the preset industry benchmark to obtain the carbon emission reduction rate; comparing the carbon emission reduction rate with the decision tree to determine the corresponding level and the corresponding anonymous set size; constructing a public key set according to the anonymous set size and using the node private key to execute a group signature algorithm to generate the first-layer ring signature; and using the carbon emission reduction rate and the boundary value of the corresponding level as input to execute an interval proof algorithm to generate the interval proof.

[0013] This invention constructs a differential privacy mechanism with positive incentive characteristics. Node enterprises with better emission reduction performance receive a larger obfuscated public key pool to protect their identity and traces. At the same time, it uses interval circuits to declare the objective authenticity of the self-verification layer to the entire network.

[0014] Preferably, when the carbon emission reduction rate is less than a minimum preset threshold, the interval proof algorithm is executed to generate the interval proof using the carbon emission reduction rate and the boundary value of the corresponding level as input, including: adding a preset offset constant to the value of the carbon emission reduction rate to obtain a non-negative integer value; and using the non-negative integer value to input the constraint circuit to generate the interval proof confirming that the boundary value has not been exceeded.

[0015] This invention avoids the system defect that the standard inner product interval proof algorithm cannot be directly substituted when the emission reduction ratio becomes negative due to severe over-emission at nodes, and improves the data compatibility and stability of the solution for various extreme carbon emission scenarios.

[0016] Preferably, the step of calculating the Pedersen commitment value by combining the configured generator matrix base points and the generated blinding factor, and encrypting it into two-layer ciphertext using a public key, includes: multiplying each value in the attribute vector by a scalar with the corresponding base point in the generator matrix and summing the results to obtain the dot product group element; performing a group-dot addition operation on the scalar product of the dot product group element and the blinding factor with another base point to obtain the Pedersen commitment value; and using an asymmetric encryption algorithm to encrypt the attribute vector, the blinding factor, and the Pedersen commitment value to generate the two-layer ciphertext.

[0017] This invention mathematically intertwines and blinds the company's actual water and electricity consumption and total carbon emissions with random factors, making it irreversible in public broadcasts. However, it reserves a secure channel for designated environmental agencies to use proprietary public keys to recover elements and verify the commitment equation.

[0018] Preferably, the step of multiplying the carbon emission margin by a preset coefficient to obtain a credit limit and homomorphically encrypting it before sending it into the trusted environment includes: when the carbon emission margin is greater than zero, multiplying the carbon emission margin by a preset conversion constant used as the preset coefficient and rounding it down, then combining it with a preset positive integer offset to perform non-negative integer encoding to generate the credit limit; using a global homomorphic public key and a secure random number to perform a modulo exponential operation on the credit limit to generate encrypted credit limit ciphertext, and sending the encrypted credit limit ciphertext into the trusted environment.

[0019] This invention blocks the vulnerability of obtaining abnormal rewards with negative margins and overcomes the plaintext operation domain limitation of the Paillier algorithm through an integer offset encoding mechanism, enabling seamless connection of the end-to-end quota encryption process and ensuring the stability of subsequent modulo division calculations of the ciphertext.

[0020] Preferably, the step of performing homomorphic scalar multiplication on the encrypted quota ciphertext of each node according to the node level weight to obtain the weighted ciphertext includes: loading a configuration table recording the corresponding node level weight in the isolated memory of the trusted environment; and performing homomorphic scalar multiplication instructions on each of the obtained encrypted quota ciphertexts of each node, using the node level weight corresponding to the current node as the scalar multiplier to obtain the weighted ciphertext.

[0021] This invention empowers the system with the ability to determine contribution proportions based on the differences in roles within the supply chain. Furthermore, since the weight loading process is strictly performed in a hardware black-box isolated memory, it can prevent malicious behavior by nodes in reverse-engineering the share of their peers by probing network parameters.

[0022] Preferably, the process of decrypting the aggregated total and calculating the allocation adjustment coefficient includes: submitting the ciphertext digest of the weighted ciphertext multiplication to the regulator; receiving the aggregated total after controlled decryption in isolated memory; and when the aggregated total is greater than zero, calculating the ratio of the preset allocation total to the aggregated total and generating the allocation adjustment coefficient in integer form through fixed-point scaling.

[0023] This invention constructs a one-time controlled decryption defense barrier, ensuring that the total amount of plaintext credit requests, which is crucial to the macro-lifeline of industry clearing, resides only within the fleeting memory lifecycle of the TEE, thereby precisely scaling the clearing allocation share.

[0024] Preferably, the submission of the contract archive includes: the smart contract extracting the built-in verification public key matrix set, performing point operations on the knowledge argument and the verification public key matrix set respectively using a pairing cryptography algorithm to obtain paired value pairs; after determining that the values ​​on both sides of the paired value pair are the same according to the bilinear pairing rule and obtaining a verification pass signal, writing the liquidation share ciphertext into the storage unit.

[0025] This invention empowers the underlying blockchain ledger with the ability to quickly identify massive offline settlement results. Ordinary nodes can use the deterministic mathematical law of bilinear pairing to prevent any tampered allocations from being blindly uploaded to the chain, thus ensuring the credibility of the final ledger.

[0026] The technical solution of the present invention has the following beneficial technical effects: This invention combines two-layer verifiable attribute-based encrypted signature encapsulation with recursive aggregation zero-knowledge proofs. The system dynamically allocates privacy protection strength based on each node's emission reduction contribution, and embeds a dedicated audit entry point for regulators within the invisible encrypted transactions from the perspective of ordinary nodes. This effectively resolves the contradiction between data disclosure and privacy leakage and excessive concealment that hinders regulatory penetration in traditional consortium blockchains.

[0027] Furthermore, leveraging the homomorphic properties of the Paillier algorithm and the isolation advantages of the off-chain trusted computing environment, sensitive calculation processes such as weighting, summarizing, and allocating the carbon emission reduction credit quota of nodes are executed entirely in a closed and black-box environment. This not only completely eliminates the risk of leakage of key production capacity energy consumption during the joint settlement process, but also compresses the entire off-chain core processing logic into concise non-interactive knowledge proofs for smart contract execution with strict bilinear pairing verification. While ensuring the compliance of business accounting, this significantly reduces on-chain storage overhead, reduces the risk of data leakage in multi-party joint settlement, and improves the execution efficiency, credibility, and public trust of the collaborative management of carbon emission reduction in the green cable supply chain. Attached Figure Description

[0028] Figure 1 This is a flowchart of a multi-level carbon emission reduction collaborative management method for a green cable supply chain; Figure 2 This is a diagram illustrating the cumulative carbon footprint of each node in the supply chain; Figure 3 This is a schematic diagram of anonymous set capacity allocation based on emission reduction rate. Detailed Implementation

[0029] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments.

[0030] Reference Figure 1 A multi-level carbon emission reduction collaborative management method for a green cable supply chain includes steps S1 to S3, which are described in detail below.

[0031] S1. Acquire carbon data and calculate carbon emission margin. Specifically, acquire raw carbon data from enterprises at each node of the supply chain and extract energy consumption data. Convert various types of energy consumption into carbon dioxide equivalents and sum them to obtain the carbon emissions of this node. Calculate the difference between the preset industry benchmark and the carbon emissions of this node as the carbon emission margin.

[0032] In one embodiment, the node enterprise collects real-time energy consumption sensor data from smart meters and flow meters through edge computing gateways deployed in the production workshop. The time-series energy consumption data is cleaned and deduplicated. The energy emission factors corresponding to the electricity and gas energy categories are extracted by combining the Life Cycle Assessment (LCA) standard database. When material input accounting is involved, the material emission factors corresponding to cable materials are extracted. The energy consumption reading is multiplied by the energy emission factor, and the material usage is multiplied by the material emission factor. The calculation results of each item are uniformly converted into carbon dioxide equivalent and then summed to obtain the total carbon emissions, avoiding the direct multiplication of energy consumption with material emission factors.

[0033] The Protobuf serialization framework is used to encapsulate timestamps, node hash identifiers, material codes, energy consumption types, power consumption values, gas consumption values, units for each field, total carbon emissions, and data hash fields into a structured data payload. The node enterprise server reads the preset green cable industry benchmark carbon emission threshold from the local configuration file. Floating-point arithmetic instructions are used to calculate the preset green cable industry benchmark carbon emission threshold minus the total carbon emissions, and the difference is temporarily stored in the carbon emission margin variable.

[0034] A unified data dictionary is established according to the JSON data standard, and data dictionary entries containing material codes are mapped to the material source field; electricity meter and gas meter readings are extracted and filled into the energy consumption value field, and energy category is filled into the energy consumption type field; emission factors corresponding to electricity and gas are set according to the international carbon footprint calculation standard ISO14067, and the readings of each type of energy are independently converted into grams of carbon dioxide equivalent and then summed. The total grams of carbon dioxide equivalent obtained by summing are filled into the carbon emission field; the hash value of the above-mentioned field set is calculated using the SHA-256 algorithm, and the calculated hash value is used as the primary key and concatenated with the data of the above-mentioned fields to form a complete structured carbon data object.

[0035] For example, taking a cable manufacturing node company as an example, during the data structure encapsulation process, a unified standard JSON data dictionary is generated. The material code CAB-CU-2023001 from the company's internal ERP system is extracted and mapped into the MaterialSource field of the JSON standard data dictionary. Periodic readings from the workshop's smart meters and gas meters are extracted via an Industrial Internet of Things (IIoT) interface. The electricity reading of 5000 and the gas reading of 2000 are filled into the EnergyValue array field, and the corresponding Electricity and NaturalGas identifiers are sequentially filled into the EnergyType field. In the carbon emission calculation stage, emission factors are set according to the international carbon footprint calculation standard ISO14067, using the built-in constant library.

[0036] The specific formula for calculating the carbon dioxide equivalent of electricity is as follows: .

[0037] in, Indicates the carbon dioxide equivalent of electricity. The power consumption value is obtained by extracting periodic readings from the smart meters in the workshop. In this embodiment, the preset value is 5000 kWh. The electricity emission factor is obtained by calling the built-in constant library of the international carbon footprint calculation standard ISO 14067. In this embodiment, the preset value is 581 gCO2e / kWh.

[0038] In this embodiment, 5000kWh is multiplied by 581 to obtain 2905000gCO2e, and its preset value is 2905000gCO2e.

[0039] The specific formula for calculating the carbon dioxide equivalent of fuel gas is as follows: .

[0040] in, Indicates the carbon dioxide equivalent of fuel gas. The gas consumption figure is obtained by extracting periodic readings from the workshop's gas meter. In this embodiment, the preset value is 2000 m³. The natural gas emission factor is obtained by calling the built-in constant library of the international carbon footprint calculation standard ISO 14067. In this embodiment, its value is preset to 2162.2 gCO2e / m³.

[0041] In this embodiment, 2000m³ is multiplied by 2162.2 to obtain 4324400gCO2e, and its preset value is 4324400gCO2e.

[0042] The specific relationship for calculating total carbon emissions is as follows: .

[0043] in, The total carbon emissions are calculated by adding the carbon dioxide equivalent of electricity and the carbon dioxide equivalent of gas, resulting in 7,229,400 gCO2e. In this embodiment, the preset total carbon emissions value is 7,229,400 gCO2e, and the total of 7,229,400 gCO2e is filled into the CarbonEmission field of the JSON standard data dictionary.

[0044] The complete JSON string containing material code, energy consumption type, electricity consumption value, gas consumption value, and total carbon emissions is converted into a byte stream, input into the SHA-256 hash algorithm, and a 256-bit hash value is generated. For example: "9f2c6d8e4b3a1c7f0e6d5c4b2a918273645f0a1b2c3d4e5f6789abcd0123ef45", The calculated 256-bit hash value contains 64 characters when represented in hexadecimal. The 256-bit hash value is assigned to the RecordID field as the primary key and concatenated with the original data segment to output a structured carbon data object with tamper-proof properties.

[0045] like Figure 2 As shown, the horizontal axis represents the raw material stage and the manufacturing stage, respectively; the left column represents the carbon emissions of the node itself, and the right column represents the cumulative carbon emissions of the entire chain, showing the segmented carbon emissions and the total cumulative values ​​of the entire chain under LCA accounting.

[0046] S2. Update the zero-knowledge proof and encapsulate the privacy transaction in a secret state. Specifically, perform an additive constraint on the cumulative carbon footprint proof of the preceding node and the carbon emissions of the current node within the witness verification circuit to generate an updated end-to-end cumulative carbon footprint zero-knowledge proof; configure the size of the anonymity set according to the preset level to which the carbon emission margin belongs to generate the first-layer ring signature and the corresponding margin interval proof; construct a multi-dimensional attribute vector with the energy consumption data and the carbon emissions of the current node; calculate the Pedersen commitment value by combining the corresponding base point and the blinding factor; and generate the second-layer ciphertext by encrypting it with the regulator's public key. The privacy transaction is then encapsulated by binding the second-layer ciphertext and the Pedersen commitment value with the first-layer ring signature.

[0047] In one embodiment, a node enterprise utilizes the Halo2 zero-knowledge proof algorithm library to construct an arithmetic circuit. The input pins of this circuit include the preceding cumulative carbon emission commitment value or regulatory encrypted ciphertext index transmitted by upstream supplier nodes via the consortium blockchain, the preceding proof document, and the total carbon emission private witness value encapsulated in the node's structured package. A state transition equation is set within the arithmetic circuit, and the addition operation logic of the preceding cumulative carbon emission private witness value plus the node's emission private witness value is executed. The validator verification interface in the Halo2 library is called to perform constraint verification on the preceding proof document. When the constraints pass and the addition equation holds, the Halo2 algorithm's prover entity executes a polynomial commitment scheme to fold the internal polynomial, outputting a bytecode sequence occupying constant storage space as proof of the validity of the current end-to-end cumulative carbon footprint, which is then packaged and written into a privacy transaction structure. Ordinary on-chain nodes verify the recursive relationship between commitments and the validity of the proof, without directly obtaining the preceding cumulative carbon emission plaintext or the current cumulative carbon emission plaintext. In the specific implementation, the verification logic of the preceding proof file is constructed as a Halo2 recursive verification sub-circuit and participates in the constraints as part of the current proof circuit. When the target chain environment does not directly support the recursive verification circuit, the off-chain proof aggregator completes the generation of recursive proof in the trusted execution environment or the preset proof service, and submits the aggregated fresh zero-knowledge proof to the on-chain or downstream node for verification.

[0048] The carbon emission margin is pre-divided into three levels—excellent, good, and acceptable—based on numerical ranges, and mapped to different ring-size configuration dictionaries. The node enterprise server matches its level based on the previously calculated carbon emission margin variable, queries the configuration dictionary to obtain the corresponding anonymous set size integer value, and calls the Go language's cryptographic standard library to randomly extract other node public keys equal to the anonymous set size integer value minus 1 from the blockchain's full node state tree. These public keys, along with the node's own real public key, form a signature set. A ring signature algorithm based on the Secp256k1 elliptic curve is used to generate a first-layer digital signature containing traces of the real signer. The Bulletproofs algorithm library is called to construct an interval constraint circuit, using the carbon emission margin variable as private input and the matched level's upper and lower limits as public input. An inner product proof protocol is executed to generate a zero-knowledge proof bitstream to prove that the margin satisfies the interval constraints without revealing the specific value. For levels less than 10%, the lower bound of the interval is a non-negative integer lower bound after a preset minimum proportion Rmin to ensure the interval proof is completed.

[0049] The node enterprise uses the random number generator in the cryptographic algorithm library to generate a 256-bit blinding factor. It extracts the power consumption, gas consumption, energy type, unit field, and carbon emissions from the structured encapsulated data as binding messages. Combining multiple independent generators on the elliptic curve group, it performs group scalar multiplication and group addition operations of the Pedersen commitment algorithm to calculate the commitment value. It extracts the public key of the environmental regulatory agency pre-installed on the node and calls the SM2 asymmetric encryption algorithm to perform asymmetric encryption operations on the plaintext of the actual energy consumption and carbon emissions, the generated blinding factor, and the commitment value, outputting a ciphertext data block. The commitment value, ciphertext data block digest, hierarchical ownership proof digest, and transaction entity digest are incorporated into the signed message of the first-layer ring signature, binding the second-layer attribute encryption payload with the first-layer anonymous signature to prevent attackers from replacing the second-layer ciphertext or commitment value. The first-layer generated ring signature, interval zero-knowledge proof, commitment value, and ciphertext data block are appended to the extended fields of the privacy transaction, completing the binding and encapsulation of the first-layer anonymous signature and the second-layer attribute encryption payload, and broadcasting it to the consortium blockchain network. The aforementioned verifiability refers to the ability of the regulatory authority to decrypt the second-layer ciphertext and recalculate the Pedersen commitment value during authorized audits, and to verify that the attribute data has not been replaced or tampered with by combining the ciphertext digest and commitment digest covered by the first-layer ring signature. It is not limited to a standard verifiable encryption structure that can be publicly verified without decryption.

[0050] In an optional embodiment, the process of generating a full-link cumulative carbon footprint validity proof using a recursive aggregation zero-knowledge proof algorithm, based on the cumulative carbon footprint validity proof of the preceding node and the carbon emissions of the current node, is as follows: The current processing node is the cable insulation layer manufacturing node, and the preceding node is the supplier of polyethylene granules, the raw material for cables; the client of this node reads the previous-layer proof document submitted by the preceding node from the blockchain. And the preceding proof of the public input parameters Preliminary proof reveals input parameters Including previous cumulative carbon emission commitments Dimensional identification and hash digest The cumulative carbon emissions value in the preceding sequence is used as a private witness input to the proof circuit and is not directly disclosed to ordinary on-chain observers; analytical dimension labeling. The node confirms that the previous cumulative carbon emissions are calculated internally in gCO2e. The node performs a 64-bit integer addition operation within the proof circuit with its own calculated carbon emissions of 7,229,400 grams and the previous cumulative carbon emissions' private witness value of 4,500,000 grams, resulting in a total cumulative carbon emissions of 11,729,400 gCO2e. This total cumulative carbon emissions is not output as plaintext on the regular blockchain but is instead used to generate a corresponding commitment value. Or the regulator's public key is used to encrypt the ciphertext. .

[0051] To prove the legitimacy of the cumulative carbon emissions at this node to subsequent stages without revealing the actual carbon emissions from upstream and downstream operations, the polynomial degree is invoked. The Halo2 zero-knowledge proof protocol is used to construct a Plonk-styled witness verification circuit. Inside the witness verification circuit, two calculations are input through custom gate constraints: a private input constraint equation is set to verify the correctness of the addition, and the upper-level proof file is then passed to the test case. The corresponding elliptic curve verification public key is injected into an internally nested recursive validator for validity verification. Using the inner product polynomial commitment on the Pasta elliptic curve, an updated zero-knowledge proof file with a size of 2KB is output. The updated zero-knowledge proof file The commitment value corresponding to the calculated cumulative carbon emissions at this node Or the regulator's public key is used to encrypt the ciphertext. Structured encapsulation generates proof of the validity of the cumulative carbon footprint across the entire value chain for verification by downstream nodes or regulatory nodes.

[0052] In an optional embodiment, the first layer employs ring signatures. The size of the ring's anonymity set is set according to the carbon emission margin level. The process of generating a zero-knowledge proof that the carbon emission margin is at the claimed level is as follows: The benchmark carbon emission index for the current cable manufacturing industry is obtained through an oracle service. Each ton of standard cable produced is allowed to emit 2,000,000 gCO2e. The current batch capacity is 5 tons, corresponding to a total industry benchmark of 10,000,000 gCO2e. The difference between the total industry benchmark of 10,000,000 gCO2e and the actual carbon emission of this node (7,229,400 gCO2e) is calculated, yielding a carbon emission margin of 2,770,600 gCO2e. Dividing the carbon emission margin of 2,770,600 gCO2e by the total industry benchmark of 10,000,000 gCO2e yields a carbon emission reduction rate of 27.7%. Based on the built-in margin hierarchy decision tree, the size of the anonymous set for ring signatures is set to 50 when the carbon emission reduction rate is not less than 20%; the size of the anonymous set is set to 20 when the carbon emission reduction rate is not less than 10% and less than 20%; and the size of the anonymous set is set to 10 when the carbon emission reduction rate is less than 10%. Since the condition of 27.7% not less than 20% is met, the size of the anonymous set for ring signatures is set to 50.

[0053] Based on the parameters set according to the size of the anonymous set, 49 active nodes in normal status are randomly extracted from the consortium blockchain identity registration center via a remote procedure call interface. These public keys, along with the node's own real public key, are mixed to construct a public key set of 50. A linkable, spontaneous anonymous group signature algorithm is invoked, using the node's 256-bit private key as input, to calculate and generate a ring signature on a curve containing the 50 public keys. The node uses the Bulletproofs inner product interval proof algorithm for proof, using the integerized carbon emission reduction rate of 277 as the algorithm's private input variable, and the lower bound constant of 200 and the upper bound constant of 1000 as public input parameters. By constructing a polynomial commitment, a range proof of 1KB in size is generated, proving to the network in a zero-knowledge manner that its emission reduction ratio is within the set range of no less than 20%.

[0054] For emission reduction rates less than 10%, if exceeding emission limits is permitted, the corresponding anonymity protection process will be implemented. The minimum percentage Rmin will be preset to -100%, and the integer percentage will be increased by an offset constant of 1000 before entering the Bulletproofs circuit. The formula for calculating the offset percentage is as follows:

[0055] in, This indicates the proportional value after offset. This represents the integerized value of the original negative percentage, obtained by integerizing the negative value of the carbon emission reduction rate. In this embodiment, its value is preset to -50. The offset constant is obtained by reading the CARBON_OFFSET_INT field from the global constant dictionary table of the privacy computing environment configured in the genesis block of the consortium blockchain. In this embodiment, its value is preset to 1000. The offset ratio of 950 is obtained by superimposing the integerization ratio -50 and the offset constant 1000. The proof range corresponding to the original ratio of -100% to less than 10% is set to 0 to 1099. Thus, a proof of a non-negative integer range is still constructed even when the ratio is negative. For example... Figure 3 The diagram shows the configuration relationship of the ring signature anonymous set capacity corresponding to the carbon emission margin classification. The horizontal axis represents the carbon emission reduction rate, which is divided into three levels: less than 10%, 10% to 20%, and greater than or equal to 20%. The vertical axis represents the size of the anonymous set, with corresponding values ​​of 10, 20, and 50.

[0056] In an optional embodiment, the second layer, after hiding energy consumption and carbon emissions through Pedersen commitments, embeds the privacy transaction using asymmetric encryption with the regulator's public key as follows: The node client cryptographic module initializes the secp256k1 elliptic curve group parameters and selects mutually independent generator matrices. and blinding basis Generate metamatrix Includes the first independent base point Second independent basis point and the third independent basis point A 256-bit blinding factor is generated using a pseudo-random number generator. .

[0057] The energy consumption value of 5000 (kWh), the natural gas consumption value of 2000 (m³), and the carbon dioxide equivalent of 7229400 (gCO2e) are combined to form a one-dimensional attribute vector V= .in, This represents the power consumption value, obtained through periodic readings of the workshop's smart meter. In this embodiment, the preset value is 5000 kWh. The value representing natural gas consumption is obtained through periodic readings of the workshop gas meter. In this embodiment, the preset value is 2000 m³. The value represents the carbon dioxide equivalent, which is obtained through energy consumption conversion and summation. In this embodiment, its value is preset to be 7229400gCO2e.

[0058] Perform Pedersen commitment computation: .

[0059] Among them, the first independent base point Second independent basis point Third independent basis point All parameters were obtained through the initialization of the secp256k1 elliptic curve group. Indicates blinding factor Homoblinding basis scalar product.

[0060] Through the above operations, output the Pedersen commitment value in the form of elliptic curve group elements. Pedersen's commitment value After being serialized according to a preset compression encoding format, the data is written into the transaction field to achieve the hiding of multi-attribute data.

[0061] To enable regulators to decrypt and verify, the node invokes the SM2 asymmetric encryption algorithm, reads the elliptic curve public key parameter PubKey_Reg registered with the regulatory agency from the on-chain parameter configuration, and converts the plaintext attribute into a one-dimensional vector. Blinding factor and Pedersen's commitment value Serialize the data into a byte stream according to the specified format, and perform asymmetric encryption on the byte stream using the elliptic curve public key parameter PubKey_Reg registered with the regulatory authority. This will generate a first ciphertext component starting with 0x04. Second ciphertext component Third ciphertext component The hexadecimal second-level ciphertext string is used to calculate its digest. This digest, along with the Pedersen commitment value, the transaction entity digest, and the hierarchical attribution proof digest, is then concatenated to form an attribute-bound message. The first-level ring signature uses this attribute-bound message as the signed message to generate a ring signature, thus binding the second-level attribute ciphertext to the anonymous signature. During auditing, the regulator decrypts the second-level ciphertext, recalculates the Pedersen commitment value, and verifies that the recalculated value matches the on-chain commitment value. Simultaneously, the regulator verifies that the second-level ciphertext digest matches the digest covered by the ring signature.

[0062] The generated ring signature is concatenated with the second-level ciphertext string to form the transaction payload. The transaction payload is then packaged and embedded into the additional field of the privacy transaction to complete the broadcast to the network nodes.

[0063] S3. Off-chain Homomorphic Weighted Summation and Clearing Share Ciphertext Archiving. Specifically, the credit limit calculated based on carbon emission margin is homomorphically encrypted and submitted to an off-chain trusted environment. Within the off-chain trusted environment, homomorphic scalar multiplication is performed on the encrypted credit limit ciphertext of each node according to the node hierarchy weight to obtain a weighted ciphertext. The weighted ciphertexts are then multiplied together to achieve a weighted sum, the aggregated total is decrypted, and the allocation adjustment coefficient is calculated. Combined with the allocation adjustment coefficient, homomorphic scalar multiplication is performed on the weighted ciphertext to generate the clearing share ciphertext and non-interactive knowledge proof, which is then submitted to the contract for archiving.

[0064] In an optional embodiment, the node enterprise first determines whether the carbon emission margin is greater than 0 based on the linear conversion coefficient set by the system smart contract; when the carbon emission margin is greater than 0, the calculated carbon emission margin variable is multiplied by the conversion coefficient to obtain the effective carbon emission reduction credit limit for the business; when the carbon emission margin is less than or equal to 0, the effective carbon emission reduction credit limit for the business is set to 0 to prevent nodes that exceed emission standards from obtaining positive emission reduction credit due to coding offset.

[0065] The effective carbon emission reduction credits are converted into fixed-point integers. The Paillier homomorphic encryption public key, generated during initialization, is loaded using the phe third-party library. The encrypt function in this library is then executed to nondeterministically encrypt the fixed-point integer carbon emission reduction credits, resulting in a homomorphic ciphertext object. Node enterprises establish an encrypted secure channel with the IntelSGX Trusted Execution Environment deployed on the server side using the Transport Layer Security (TLS) protocol. The homomorphic ciphertext object is serialized and sent to the IntelSGX memory enclave secure area via this secure channel. The positive integer value of the carbon emission reduction credit is an encoded value adapted to the Paillier encryption plaintext space. The positive integer offset is only used to ensure that the encrypted input is in the non-negative integer domain and is not used as the basis for enterprises to obtain positive carbon emission reduction credits as a business reward. During settlement or decoding, the encoded value is restored based on the positive integer offset. If the restored effective carbon emission reduction credit is less than or equal to 0, it is treated as 0.

[0066] Within the IntelSGX enclave, a homomorphic operation submodule of the Paillier algorithm is loaded. For the received homomorphic ciphertext objects from multiple nodes, homomorphic scalar multiplication is first performed on the credit limit ciphertext of each node according to the pre-registered supply chain hierarchy weights, resulting in the weighted credit ciphertext for each node. Then, a large integer modular multiplication instruction is called in the ciphertext space to simulate the addition logic in the plaintext space, performing a series multiplication operation on all weighted credit ciphertexts to complete the homomorphic summation calculation of the total weighted credit amount and obtain the global aggregated settlement result ciphertext. The global aggregated settlement result ciphertext or its digest, decryption authorization request, decryption result return, and total amount plaintext reception are all executed within a secure channel established after remote proof is completed in the off-chain trusted computing environment. The total amount plaintext returned by the regulator is only written to the isolated memory of the off-chain trusted computing environment and used to calculate the global adjustment coefficient, and is not disclosed to ordinary on-chain nodes, supply chain enterprise nodes, or external business processes.

[0067] After confirming the enclave code metric is consistent with the preset liquidation procedure via IntelSGX remote verification, the regulator provides the enclave with the threshold decryption share, temporary decryption authorization result, or controlled decryption service interface through a secure channel. This ensures that the global aggregated liquidation result is decrypted into plaintext only in the enclave's isolated memory. This plaintext total amount is not returned to ordinary on-chain nodes, other enterprise nodes, or external business processes. Internally, the enclave reads the preset allocated total amount, calculates the ratio of the preset allocated total amount to the global aggregated total amount plaintext, and converts this ratio into an integer adjustment coefficient using a fixed-point scaling factor. When the global aggregated total amount plaintext is zero, the enclave sets the individual liquidation share of each node enterprise to 0, or terminates the current round of liquidation according to the preset abnormal liquidation rules. When the global aggregated total amount plaintext is greater than 0, the ratio calculation of the preset allocated total amount to the global aggregated total amount plaintext is performed again. Subsequently, Paillier homomorphic scalar multiplication is performed on the weighted credit ciphertext of each node to generate individual liquidation share ciphertext with a scaling factor. During subsequent regulatory accounting or decryption display, the same scaling factor is used to restore the ciphertext, ensuring the correct dimension of the liquidation share.

[0068] To prevent homomorphic encryption operations from malfunctioning due to potentially negative carbon emission margins, a positive integer offset consistent with the carbon emission margin's dimensions is pre-set in the calculation module, preferably 500,000 gCO2e. This positive integer offset is only used for Paillier non-negative integer encoding and is not used to determine whether an enterprise has obtained positive emission reduction credits. The node enterprise calculation module compares the carbon emission margin with 0 and takes the maximum value. This maximum value is then multiplied by the national carbon quota conversion fixed constant coefficient to calculate the effective carbon emission reduction credit limit. For example, with a carbon emission margin of 2,770,600 gCO2e equivalent, since 2,770,600 gCO2e is greater than 0, the specified national carbon quota conversion fixed constant coefficient is called. Assuming the current national carbon quota conversion fixed constant coefficient is set to 0.05, the multiplication operation yields 138,530. The calculation module rounds the result of the multiplication operation and uses the unsigned integer value 138,530 as the plaintext of the effective carbon emission reduction credit limit for subsequent encryption processes. If another company's carbon emission margin is -100,000 gCO2e, then its effective carbon reduction credit will be set to 0; even if a positive integer offset of 500,000 gCO2e is used during the encoding process, no positive emission reduction credit will be generated. The node client loads the global Paillier encryption public key with a modulus length of 2048 bits, generated by the consortium blockchain regulator using the first and second largest prime numbers. And the generator g. The local encryption module uses a random number generator to select a secure random number of length 256 bits. Ensure safe random numbers With the global Paillier encryption public key The moduli are coprime.

[0069] Substitute the plaintext value m=138530 into the Paillier encryption equation. ,in, This represents the generated encrypted data packet containing the credit limit. Represents a homomorphic encryption generator. This indicates the explicit amount of effective carbon emission reduction credit available for the business. Represents a secure random number. The modulus of the globally homomorphic encryption public key is used in the modulo exponentiation unit to generate a 4096-bit (512-byte) encrypted data packet representing the credit limit. For cases where the carbon emission margin is positive and the effective carbon reduction credit limit can be represented as a non-negative integer within the Paillier plaintext space, the actual addition step for the positive integer offset can be omitted, and the fixed-point integer value of the effective carbon reduction credit limit can be directly used as the encrypted plaintext. To ensure secure isolation, the node initiates a TLS 1.3 handshake process to establish a secure, two-way authenticated communication channel with the off-chain trusted computing environment equipped with Intel SGX technology. This encrypted data packet, along with the node's private key digital signature generated using the ECDSA algorithm and an identification code such as "Node-MFG-01," is packaged and transmitted through the aforementioned encrypted channel to the memory of the off-chain trusted computing environment.

[0070] After completing remote proof in the off-chain trusted computing environment, the global aggregated liquidation result ciphertext or its digest is submitted to the regulator through a secure channel. The regulator provides a threshold decryption share, a temporary decryption authorization result, or a controlled decryption service response, ensuring that the off-chain trusted computing environment obtains the total plaintext only in isolated memory. When the total plaintext is greater than zero, the ratio of the preset allocated total amount to the total plaintext is calculated and generated as a global adjustment coefficient after fixed-point scaling. Paillier homomorphic scalar multiplication is performed on the weighted credit ciphertext of each node to generate the individual liquidation share ciphertext of each node enterprise. When the total plaintext is zero, the individual liquidation share of each node enterprise is set to zero or the current liquidation process is terminated. Based on the full sequence log of operations executing homomorphic instructions, the Groth16 algorithm is invoked to establish quadratic arithmetic program constraint equations, and concise non-interactive knowledge arguments are generated based on these constraint equations.

[0071] During startup, the off-chain trusted computing environment (TEE) reads a supply chain hierarchy weight configuration table into isolated memory. This table specifies the weight constant multipliers for each hierarchy. The node hierarchy weights are calculated by regulators using analytical hierarchy analysis based on the historical average carbon emission intensity of each node and the industry's marginal cost of emission reduction. Their values ​​range from the integer [1, 20]. In this embodiment, based on the above calculation rules, the raw material level constant multiplier is set to 12, the manufacturing level constant to 15, and the distribution level constant to 10. When processing the ciphertext c of the manufacturing node, the TEE calls the large number arithmetic library to execute Paillier homomorphic scalar multiplication instructions on the ciphertext. This yields the weighted credit ciphertext for the current node. After the ciphertext at each node in the entire link has been weighted and transformed, the TEE calls the Paillier homomorphic ciphertext multiplication instruction, iteratively multiplying the ciphertext of all nodes. Perform multiplication continuously and modulo The following cumulative calculations are performed to generate a global aggregated settlement result ciphertext. .

[0072] TEE first submits remote verification Quote and In summary, after the regulator confirms that the code metric in the Quote matches the preset liquidation procedure, it provides the TEE enclave with a threshold decryption share or a controlled decryption service response via a secure channel, ensuring that the TEE obtains the total credit request amount in plaintext only in isolated memory. For example, the TEE obtains the total credit request amount of 8,500,000 in isolated memory. This plaintext is not written to the blockchain, nor is it returned to other enterprise nodes.

[0073] TEE reads the total amount of the pre-allocated funds pool from memory, for example, a total amount of 10,000,000, and calculates a ratio of 1.176. A fixed-point scaling factor F is set to 1000, and this ratio is amplified and rounded to obtain an integer adjustment coefficient of 1176. TEE then performs a second scalar multiplication on the previously saved weighted credit ciphertext of each node. The system generates ciphertext of the individual liquidation share for each node enterprise with scaling. The plaintext corresponding to this ciphertext is "actual share × F". After being decrypted by the regulator or authorized party, it is divided by F to restore the actual liquidation share during off-chain display, auditing, or final settlement. The smart contract also records the scaling factor F or its hash digest to ensure consistency in subsequent restoration.

[0074] During this homomorphic computation cycle, the background audit process outputs the execution steps of large number multiplication, modulo operation, scalar multiplication, scaling factor generation, and share ciphertext generation as an operation sequence log file. The TEE core module, based on a predefined liquidation arithmetic circuit, uses the inputs, intermediate variables, and outputs from the operation sequence log as witness data to populate the first-order constraint system. For the core operations of the liquidation process, Paillier homomorphic scalar multiplication is used. The specific method for circuit-based constraints is as follows: First, the private input scalar multiplier... Perform binary decomposition and apply constraints in the circuit. Specifically, let... ,in .in, Scalar multipliers The maximum bit width or total number of iterations for each bit. Through a multiplication gate To constrain it to a Boolean value, a circuit implementation of the "square-multiplication" method is used to iteratively constrain the modular exponentiation process: setting intermediate variables. and will As publicly input encrypted text, for arrive Each step is constrained by the following two multiplication gates: Square gate: Constrains the self-multiplication of intermediate temporary variables, i.e. .

[0075] Conditional product gate: using the aforementioned constrained bits This constrains the temporary variables in the next stage. This gate is equivalent to the logic: If The result is the square of the original base multiplied by the square of the original base. ;like The result is simply the square value. This is achieved through a multiplication gate. Apply constraints. After completing all... After the next iteration, the ciphertext is finally output through a constraint gate. This completes the equivalence verification of the entire homomorphic scalar multiplication operation.

[0076] The above constraint logic will be automatically compiled by the background program to generate the corresponding first-order constraint system matrix. ,satisfy Among them, the witness vector It explicitly includes the input ciphertext and the decomposed bits. All intermediate variables The weight allocation and the final output share are encrypted.

[0077] The off-chain trusted computing environment integrates the data and sends transaction requests to the on-chain application layer of the Ethereum Virtual Machine architecture. The contract engine receives input parameters through the `submitAllocationProof` function interface. These input parameters include a combination of the enterprise hash address "0x1a2b..." and the paired allocation share ciphertext, the record field or hash field of the fixed-point scaling factor F, and the generated concise, non-interactive knowledge proofs of zk-SNARKs. Prove the parameter points. After triggering the smart contract, extract the Groth16 verification public key sequence matrix set embedded in the state variables. This parameter set contains data based on the BN254 elliptic curve system. , , , wait and Group parameters. The contract, using built-in pre-compiled library instructions, employs the Tate pairwise cryptography algorithm to substitute the input proof points and extracted matrix parameters into the pairwise equation. Mapping is performed on both sides of the computational branch to obtain two sets of data located in the twelfth extension field. The check constants within the paired numerical values, where, This represents a bilinear pairing mapping operation; This represents the public input variable to the smart contract. The contract compares the values ​​on both sides of the paired value pair according to the bilinear pairing rules. When the matching results are the same, the interpreter returns a boolean signal indicating successful verification to the application layer. Based on this boolean signal, the contract triggers the write operation code. A loop iterates through the unique hash addresses of all nodes within the bundle, writing the corresponding allocation share ciphertext into the persistent database of the corresponding block within the blockchain node, completing the permanent locking and archiving of the record.

[0078] The experiment used a server cluster with Intel Core i9 processors, 64GB of memory, and support for software protection extension technology to build the test environment. The underlying blockchain network was deployed as a consortium blockchain architecture consisting of 20 consensus nodes, with a network bandwidth of 1000Mbps between nodes. The experiment selected 100,000 real carbon emission data collection records from 1000 node enterprises across the upstream and downstream of the supply chain over 12 consecutive months as the test sample. Four groups were set up for the control experiment: a baseline group using traditional plaintext data on-chain; ablation group 1 using only zero-knowledge proofs and ring signatures but without a trusted computing environment; ablation group 2 deploying only a trusted computing environment and homomorphic encryption but without zero-knowledge privacy mechanisms; and a complete solution group using all features of this invention.

[0079] In the full-process execution of handling 100,000 test data points, the groups exhibited differences in performance and privacy metrics. In the baseline group, sensitive fields were recorded on-chain in plaintext form, with an experimentally observed plaintext exposure rate of 100%, an average data processing and computation latency of 12 milliseconds, an average on-chain storage overhead of 0.5 kilobytes per transaction, and an overall data verification pass rate of 95%. In Ablation Group 1, no plaintext exposure of sensitive fields was observed from the perspective of ordinary on-chain nodes and unauthorized participants, but the average computation latency per node surged to 145 milliseconds, and the average on-chain storage overhead reached 2.8 kilobytes. In Ablation Group 2, the plaintext exposure rate of sensitive fields from the perspective of ordinary on-chain nodes and unauthorized participants was 15%, the average computation latency per node was 45 milliseconds, and the on-chain storage overhead was 1.5 kilobytes. In the complete solution group, no plaintext exposure of sensitive fields was observed from the perspective of ordinary on-chain nodes and unauthorized participants, the average computation latency per node remained stable at 58 milliseconds, the average on-chain storage overhead was 1.8 kilobytes, and the cross-node verification pass rate of the entire data chain improved to 99.9%. Compared to the baseline group, the complete solution improves the end-to-end data verification pass rate by approximately 4.9 percentage points while reducing the risk of data leakage. Compared to ablation group 1, the complete solution reduces the average computation latency per node by 60% by introducing an off-chain trusted computing environment to share the burden of ciphertext operations such as homomorphic weighted summation, and reduces on-chain storage overhead by 35% due to the use of concise non-interactive knowledge proofs. Compared to ablation group 2, the complete solution addresses the identity trajectory exposure problem when relying solely on a trusted computing environment through ring signatures and recursive aggregation zero-knowledge proofs, demonstrating that the design combining multidimensional cryptography techniques with trusted hardware can improve the application performance of carbon footprint tracking systems.

[0080] It should be noted that those skilled in the art can make various modifications and improvements without departing from the inventive concept, and these all fall within the scope of protection of this invention. Therefore, the scope of protection of this patent should be determined by the appended claims.

Claims

1. A multi-level carbon emission reduction collaborative management method for a green cable supply chain, characterized in that, include: S1. Obtain the original carbon data of enterprises at each node of the supply chain and extract energy consumption data. Calculate the carbon emissions of this node by converting various types of energy consumption. Calculate the difference between the preset industry benchmark and the carbon emissions of this node as the carbon emission margin. S2. Perform addition constraint on the received preceding carbon emission witness value and the carbon emission amount of the current node in the verification circuit to output a zero-knowledge proof; generate a first-layer ring signature and interval proof according to the anonymity set size configured according to the carbon emission margin level; construct an attribute vector with the energy consumption data and the carbon emission amount of the current node; calculate the Pedersen commitment value by combining the configured generator matrix base point and the generated blinding factor; encrypt the Pedersen commitment value into a second-layer ciphertext using a public key; bind the second-layer ciphertext and the Pedersen commitment value by the first-layer ring signature. S3. Multiply the carbon emission margin by a preset coefficient to obtain the credit limit, and homomorphically encrypt it before sending it into the trusted environment. Perform homomorphic scalar multiplication on the encrypted credit limit ciphertext of each node according to the node level weight to obtain a weighted ciphertext. Multiply the weighted ciphertext together to decrypt and aggregate the total amount and calculate the allocation adjustment coefficient. Combine the allocation adjustment coefficient with the weighted ciphertext to generate the liquidation share ciphertext and knowledge proof, and submit it to the contract archive.

2. The multi-level carbon emission reduction collaborative management method for a green cable supply chain according to claim 1, characterized in that, The process of acquiring raw carbon data from enterprises at each node of the supply chain and extracting energy consumption data, then calculating various types of energy consumption to obtain the carbon emissions for that node, includes: Establish a structured data dictionary and extract the readings of electricity meters and gas meters as the energy consumption data; The energy consumption data is multiplied by the extracted corresponding emission factor to convert it into carbon dioxide equivalent and then summed to obtain the carbon emissions of this node. A hash algorithm is used to calculate a hash value between the energy consumption data and the carbon emissions of the local node, and the hash value is used as the primary key to construct a carbon data object.

3. The multi-level carbon emission reduction collaborative management method for a green cable supply chain according to claim 1, characterized in that, The step of performing an additive constraint output of a zero-knowledge proof within the verification circuit, combining the received prior carbon emission witness value with the current node's carbon emission amount, includes: Within the verification circuit, the cumulative commitment value of this node is generated by adding the extracted preceding carbon emission witness value to the current node's carbon emission constraint. The preceding carbon emission witness value is injected into the recursive validator, and the zero-knowledge proof is output through a polynomial commitment scheme.

4. The multi-level carbon emission reduction collaborative management method for a green cable supply chain according to claim 1, characterized in that, The process of generating the first-layer ring signature and interval proof by configuring the anonymity set size according to the carbon emission margin level includes: The carbon emission margin is divided by the preset industry benchmark to obtain the carbon emission reduction rate. The carbon emission reduction rate is compared with the decision tree to determine the corresponding level and the size of the corresponding anonymous set. Construct a public key set according to the size of the anonymous set, and generate the first-layer ring signature by executing a group signature algorithm using the node's private key; The interval proof is generated by executing an interval proof algorithm with the carbon emission reduction rate and the boundary value of the corresponding level as input.

5. The multi-level carbon emission reduction collaborative management method for a green cable supply chain according to claim 4, characterized in that, When the carbon emission reduction rate is less than a minimum preset threshold, the interval proof algorithm is executed using the carbon emission reduction rate and the boundary value of the corresponding level as input to generate the interval proof, including: Add a preset offset constant to the carbon emission reduction rate to obtain a non-negative integer value; The non-negative integer value is input to the constraint circuit to generate a proof that the interval has not been exceeded.

6. The multi-level carbon emission reduction collaborative management method for a green cable supply chain according to claim 1, characterized in that, The step of calculating the Pedersen commitment value by combining the configured generator matrix base points and the generated blinding factor, and then encrypting it into two-layer ciphertext using a public key, includes: The elements of the dot product group are obtained by multiplying each value in the attribute vector by the corresponding base point in the generator matrix and summing the results. The Pedersen commitment value is obtained by performing a group-dot addition operation on the scalar product of the dot product group elements and the blinding factor with the other base point; The attribute vector, the blinding factor, and the Pedersen commitment value are encrypted using an asymmetric encryption algorithm to generate the second-layer ciphertext.

7. The multi-level carbon emission reduction collaborative management method for a green cable supply chain according to claim 1, characterized in that, The step of multiplying the carbon emission margin by a preset coefficient to obtain a credit limit and then homomorphically encrypting it before sending it into a trusted environment includes: When the carbon emission margin is greater than zero, the carbon emission margin is multiplied by a preset conversion constant that is used as the preset coefficient and rounded down. Then, the credit limit is generated by performing non-negative integer encoding in combination with a preset positive integer offset. The credit limit is modulo-exponentially calculated using a globally homomorphic public key and a secure random number to generate encrypted credit limit ciphertext, which is then sent into the trusted environment.

8. The multi-level carbon emission reduction collaborative management method for a green cable supply chain according to claim 1, characterized in that, The process of performing homomorphic scalar multiplication on the encrypted ciphertext of each node according to its hierarchical weight to obtain the weighted ciphertext includes: Load the configuration table that records the node level weights in the isolated memory of the trusted environment; For each node's encrypted amount ciphertext, execute a homomorphic scalar multiplication instruction one by one, and use the node level weight corresponding to the current node as a scalar multiplier to obtain the weighted ciphertext.

9. The multi-level carbon emission reduction collaborative management method for a green cable supply chain according to claim 1, characterized in that, The process of decrypting the aggregated total and calculating the allocation adjustment coefficient includes: Submit the ciphertext digest of the weighted ciphertext multiplication to the regulator, and receive the aggregated total after controlled decryption in isolated memory; When the total aggregate amount is greater than zero, the ratio of the preset total allocation amount to the total aggregate amount is calculated and the allocation adjustment coefficient in integer form is generated by fixed-point scaling.

10. A multi-level carbon emission reduction collaborative management method for a green cable supply chain according to claim 1, characterized in that, The submitted contract archive includes: The smart contract extracts the built-in verification public key matrix set, and uses a pairwise cryptography algorithm to perform point operations on the knowledge argument and the verification public key matrix set respectively to obtain paired value pairs; After determining that the paired values ​​are the same on both sides according to the bilinear pairing rule and obtaining a verification pass signal, the clearing share ciphertext is written into the storage unit.