A Blockchain-Based Multi-Node Identity Authentication and Access Control Method for Drug Transportation
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-14
- Publication Date
- 2026-08-11
AI Technical Summary
但由于节点身份信息集中存储,一旦中心服务器被攻击或内部人员篡改,将导致身份伪造、权限滥用等安全风险,使得现有技术难以区分节点的操作请求是合法授权还是越权冒用,造成权限控制僵化;同时当节点发生违规操作时,中心化系统缺乏有效的责任追溯与即时惩戒机制,难以形成全链路的信任约束
本发明通过根据药品转运数据以及参与节点构建区块链,使得各参与节点的身份信息分布式存储于区块链中,无需依赖中心化服务器进行统一管理,从而有效杜绝了冒名接入的安全隐患;通过确定节点承诺值,实现了操作意图的提前锚定与不可抵赖性,为后续的身份核验与责任追溯提供了不可篡改的凭证基础;通过确定签名标签值,实现了操作主体身份与操作意图的强制关联,解决了现有技术难以区分合法操作与越权冒用的技术问题;通过根据节点承诺值和签名标签值与当前参与节点的身份凭证的核验情况,更新当前参与节点的信任存量,解决了现有技术中权限管理缺乏动态反馈、违规行为无法即时惩戒的技术问题;最后通过基于信任存量对当前参与节点进行操作权限的动态控制,实现了操作权限从静态预设到动态自适应的根本性转变,解决了现有技术中权限控制僵化、对违规操作缺乏即时惩戒的技术问题。
Smart Images

Figure CN122554237A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of logistics data processing technology, specifically to a blockchain-based method for multi-node identity authentication and access control in pharmaceutical transportation. Background Technology
[0002] The drug delivery chain involves multiple participants, including pharmacists, nurses, and delivery workers, who need to sequentially complete operations such as drug handover, transportation, warehousing, outbound delivery, and receipt signing. Each node must authenticate the identity of the operators and control their access permissions during the delivery process to prevent security issues such as impersonation, unauthorized operation, and information falsification.
[0003] Existing technologies typically rely on centralized servers combined with Role-Based Access Control (RBAC) for identity authentication and access control. Specifically, the central server centrally handles the registration of participating nodes, certificate issuance, and static permission configuration. Node access verification and operation authorization depend on centralized verification and control by the central system, with access permissions and preset operation scopes defined only according to fixed roles within the organization. However, because node identity information is centrally stored, attacks on the central server or tampering by internal personnel can lead to security risks such as identity forgery and permission abuse. Existing technologies struggle to distinguish between legitimate authorization and unauthorized misuse of node operation requests, resulting in rigid access control. Furthermore, when nodes engage in unauthorized operations, the centralized system lacks effective accountability and immediate punishment mechanisms, making it difficult to establish end-to-end trust constraints. Summary of the Invention
[0004] To address the technical problems of rigid access control and lack of immediate punishment for violations caused by existing technologies that rely on centralized servers and RBAC role-based authentication and access control, this invention aims to provide a blockchain-based multi-node identity authentication and access control method for drug transportation. The specific technical solution adopted is as follows: This invention proposes a blockchain-based multi-node identity authentication and access control method for drug transportation, the method comprising: Acquire drug transfer data for participating nodes in the drug transfer chain and the corresponding transfer process for each participating node; construct a blockchain based on the drug transfer data and participating nodes; the blockchain contains the trust inventory of each participating node; Each participating node is sequentially designated as the current participating node; based on the splicing characteristics of the drug transfer data, the node commitment value of the current participating node is determined; based on the binding of the node commitment value with the identity credentials of the current participating node, the signature tag value of the current participating node is determined; based on the verification of the node commitment value, the signature tag value, and the identity credentials of the current participating node, the trust inventory of the current participating node is updated. Dynamic control of the operation permissions of currently participating nodes is performed based on the aforementioned trust balance.
[0005] Furthermore, the method for obtaining the node commitment value includes: Obtain the type, timestamp, and batch number of the transportation process corresponding to the currently participating node in the drug transportation data; A random number is generated for the current participating node as the corresponding random disturbance factor; the type of the transfer process, timestamp, drug batch, and the random disturbance factor are compressed and mapped to determine the node commitment value of the current participating node.
[0006] Furthermore, the method for obtaining the signature tag value includes: The node commitment value is mixed with the block hash of the transfer process to determine the random challenge value of the current participating node; the random challenge value is bound to the identity credential of the current participating node to determine the signature tag value of the current participating node.
[0007] Furthermore, the process of updating the trust inventory includes: Based on the trust stock of the previous participating node, a trust transmission constraint is applied to the trust stock of the current participating node to determine the available trust stock of the current participating node. Determine the corresponding minimum inventory threshold based on the type of the transfer process; When the available trust stock is greater than or equal to the minimum stock threshold, the trust stock of the current participating node is determined based on the deviation between the available trust stock and the minimum stock threshold; when the available trust stock is less than the minimum stock threshold, the current transfer operation is rejected, and the available trust stock is penalized to determine the trust stock of the current participating node.
[0008] Furthermore, the method for obtaining the available trust stock includes: The remaining trust stock is determined based on the deviation between the trust stock of the previous participating node and the minimum stock threshold corresponding to the previous participating node. Based on the remaining trust balance and the preset trust balance limit, a corresponding trust transmission factor is determined; the trust transmission factor is positively correlated with the remaining trust balance and negatively correlated with the preset trust balance limit. The adjustment amount of the trust inventory of the current participating node is determined by multiplying the preset reference inventory of the current participating node with the trust transmission factor. The available trust stock of the current participating node is determined based on the trust stock stock of the current participating node and the trust stock stock adjustment amount.
[0009] Furthermore, the method for penalizing the available trust stock includes: The trust stock penalty value is determined based on the minimum stock threshold and the preset penalty factor; both the minimum stock threshold and the preset penalty factor are positively correlated with the trust stock penalty value. The trust stock of the currently participating node is determined based on the deviation between the available trust stock and the trust stock penalty value.
[0010] Furthermore, a hash algorithm is used for compressed mapping.
[0011] Furthermore, the available trust stock is the sum of the trust stock of the currently participating node and the trust stock adjustment amount.
[0012] Furthermore, the transfer process corresponding to each participating node is the drug transfer process between the previous participating node and each participating node.
[0013] Furthermore, the identity credentials are the private and public keys of each participating node.
[0014] The present invention has the following beneficial effects: This invention constructs a blockchain based on drug transport data and participating nodes, distributing the identity information of each participating node within the blockchain. This eliminates the need for centralized server management, effectively preventing the security risks of impersonation. By determining the node commitment value, it achieves pre-anchoring and non-repudiation of operational intent, providing an immutable credential basis for subsequent identity verification and accountability. By determining the signature tag value, it achieves a mandatory association between the operator's identity and operational intent, solving the technical problem of existing technologies struggling to distinguish between legitimate operations and unauthorized impersonation. By updating the trust inventory of the current participating node based on the node commitment value, signature tag value, and the verification of the current participating node's identity credentials, it solves the technical problems of existing technologies lacking dynamic feedback in permission management and failing to promptly punish violations. Finally, by dynamically controlling the operational permissions of the current participating node based on the trust inventory, it achieves a fundamental shift from static preset to dynamic adaptive operation permissions, solving the technical problems of rigid permission control and lack of immediate punishment for violations in existing technologies. Attached Figure Description
[0015] To make the objectives, technical solutions, and advantages of this application clearer, the application will now be described in further detail with reference to the accompanying drawings.
[0016] Figure 1 The flowchart illustrates a blockchain-based multi-node identity authentication and access control method for drug transportation, as provided in one embodiment of the present invention. Figure 2 A flowchart illustrating a method for updating a trust inventory according to an embodiment of the present invention; Figure 3This is a flowchart illustrating a method for obtaining available trust reserves according to an embodiment of the present invention. Detailed Implementation
[0017] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a blockchain-based multi-node identity authentication and access control method for drug transportation proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0018] It is understood that the term "embodiment" used throughout the specification means that a specific feature, structure, or characteristic related to an embodiment is included in at least one embodiment of this application. Therefore, various embodiments throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0019] The following description, in conjunction with the accompanying drawings, details a specific scheme for a blockchain-based multi-node identity authentication and access control method for drug transportation provided by this invention.
[0020] Please see Figure 1 The diagram illustrates a flowchart of a blockchain-based multi-node identity authentication and access control method for drug transportation, according to an embodiment of the present invention. The method includes: S101: Obtain drug transfer data of participating nodes in the drug transfer chain and the transfer process corresponding to each participating node; construct a blockchain based on the drug transfer data and participating nodes; the blockchain contains the trust inventory of each participating node.
[0021] In drug transportation scenarios, a batch of drugs needs to go through multiple stages from the hospital pharmacy, including pharmacist handover, logistics transportation, and nurse signature, involving various participating nodes such as hospital pharmacies, pharmacists, nurses, and delivery workers. These nodes belong to different institutions, do not have a complete trust relationship with each other, and the identity information and operating permissions of each node are stored separately in their respective business systems.
[0022] Existing technologies typically rely on a centralized server to manage the identity registration and permission configuration of all nodes. However, if this centralized server is compromised, the entire identity system of the drug transportation chain will collapse. Blockchain, on the other hand, possesses the technical characteristics of decentralization, immutability, distributed ledger, traceability, and automatic execution of smart contracts. It can build a decentralized and trusted identity system for multiple participating nodes in drug transportation, enabling distributed notarization of node identities, dynamic trusted authentication, and refined hierarchical permission control. Therefore, this invention obtains the participating nodes in the drug transportation chain and the drug transportation data corresponding to each participating node's transportation process; constructs a blockchain based on the drug transportation data and the participating nodes; and includes the trust inventory of each participating node in the blockchain.
[0023] It should be noted that the construction of blockchain is a technical means well known to those skilled in the art. The following is a brief description of the blockchain construction process of an embodiment of the present invention: (1) Blockchain Network Architecture: This embodiment of the invention selects a consortium blockchain architecture to adapt to the special requirements of node access control and data privacy protection in the drug transportation scenario. Following the transportation route of the drug transportation chain, hospital pharmacies, pharmacists, delivery workers, and nurses are sequentially added as participating nodes to the blockchain network. These nodes jointly maintain the blockchain ledger, are responsible for verifying node identities, consensus transaction data, and maintaining the integrity and security of the network. The consortium blockchain architecture ensures a decentralized trust foundation while preventing unauthorized nodes from accessing the network through an access control mechanism.
[0024] (2) Trust Stock and Identity Credential Management: Each participating node generates a unique public-private key pair upon registration. The public key is stored in the blockchain as the node's identity credential, while the private key is kept locally by each participating node. The registration smart contract allocates trust stock to each node, which is recorded in the blockchain ledger and bound to the node's identity credential. The smart contract is responsible for executing the initial allocation of trust stock, dynamic updates during the operation process, and the transmission constraints between nodes, ensuring that all stock change operations are verified through consensus and are tamper-proof.
[0025] (3) Node Commitment and Verification Mechanism: Before executing an operation, a node needs to concatenate the operation type, drug batch, timestamp, and random disturbance factor, then compress and map them using a hash algorithm to generate a node commitment value and submit it to the smart contract for temporary storage. The smart contract generates a random challenge value by mixing the block hash of the current transfer process with the node commitment value. The node uses its private key to sign the random challenge value and returns a signature tag value. The smart contract verifies the consistency between the signature tag value and the commitment value to achieve dual verification of the node's identity and operation intent.
[0026] (4) Security Design: Asymmetric encryption algorithms are used to protect node identity credentials and communication data, ensuring that node private keys are not leaked. A hash function is used to generate node commitment values, guaranteeing the irreversibility and tamper-proof nature of operational intentions. A random challenge mechanism combined with the current block hash ensures the unpredictability of each verification, effectively defending against replay attacks and session hijacking. The dynamic updating and permanent decay rules of the trust stock are automatically executed by the smart contract, eliminating manual intervention and unauthorized operations.
[0027] (5) User Interface and Operation Interface: Provides suitable operation terminals or API interfaces for various types of participating nodes. Hospital pharmacies can initiate drug outbound operations through the system, pharmacists can perform handover operations through warehouse PDA devices, delivery workers can complete handover confirmation by scanning drug batch codes through mobile terminals, nurses can complete receipt verification through the business system, and regulatory departments can query the trust inventory and operation records of each node in real time through the regulatory platform. The system dynamically displays executable operation options based on user roles and current trust inventory, and intercepts and prompts for insufficient inventory or unauthorized attempts in real time.
[0028] S102: Sequentially designate each participating node as the current participating node; determine the node commitment value of the current participating node based on the splicing characteristics of the drug transfer data; determine the signature tag value of the current participating node based on the binding of the node commitment value with the identity credential of the current participating node; update the trust inventory of the current participating node based on the verification of the node commitment value, the signature tag value, and the identity credential of the current participating node.
[0029] During drug transportation, each participating node needs to execute different types of transportation processes. For example, the hospital pharmacy is responsible for packaging and shipping drugs, delivery workers are responsible for transport handover, and nurses are responsible for signing and verifying receipts. Since these transportation processes involve different drug batches and occur at different times, and the importance and risk level of the operations also vary significantly, in order to define the operational intent and responsibility of each participating node in the corresponding transportation process, this embodiment of the invention determines the node commitment value of the current participating node based on the splicing characteristics of the drug transportation data.
[0030] Since a node commitment value can only prove the existence of an operation reservation, but cannot prove that the node submitting the reservation is the legitimate node itself, the following risks exist in drug transportation scenarios: attackers can intercept the commitment value submitted by a legitimate node and then impersonate that node to perform subsequent operations; or attackers can construct false commitment values and submit them to the smart contract, inducing the system to perform unauthorized operations. Furthermore, if a node obtains a temporary identity credential after completing an authentication, attackers can hijack the communication session during the validity period of that credential and impersonate the node to perform operations. Traditional username / password or token authentication cannot defend against such attacks because attackers do not need to obtain the node's identity credential; they only need to intervene within the window period after successful authentication. Therefore, this embodiment of the invention determines the signature tag value of the currently participating node based on the binding between the node commitment value and the identity credential of the currently participating node. The signature tag value can prove the authenticity of the currently participating node's identity and its acceptance of this specific operation.
[0031] In the multi-node relay process of drug transportation, the operational quality of different participating nodes varies. Some participating nodes can complete the operation on time and completely, while others may be late, make operational errors, or even forge records. In traditional permission models, as long as the identity of a participating node is verified, it is granted fixed operating permissions, regardless of its actual operational quality. A participating node that repeatedly makes operational errors still has the same permissions as a participating node that performs well, and the system cannot constrain its behavior through permission adjustments. Therefore, this embodiment of the invention updates the trust inventory of the current participating node based on the verification of the node commitment value, the signature tag value, and the identity credentials of the current participating node.
[0032] It should be noted that the essence of trust stock update is to quantify the operation results of each participating node into a numerical change, which directly determines the node's subsequent operation permissions.
[0033] S103: Dynamically control the operation permissions of the currently participating nodes based on the trust reserves.
[0034] In the drug transport chain, there are objective differences in the operational quality of different nodes. Traditional fixed-permission models cannot dynamically adjust the operational scope of nodes based on their actual performance quality. This results in nodes with good operating records not being granted higher permissions commensurate with their reputation, nodes with poor operating quality not being restricted in a timely manner, a lack of responsibility transmission mechanisms between nodes, and nodes that violate regulations not being isolated immediately. This invention dynamically controls the operational permissions of each participating node based on the aforementioned trust stock. The trust stock serves as a quantitative basis for permission judgment. Participating nodes with high trust stock are allowed to perform high-threshold operations, while those with low trust stock have their operational scope restricted. Nodes with zero trust stock are permanently prohibited from participating. Simultaneously, a trust transmission factor forcibly transmits the performance quality of preceding nodes to subsequent participating nodes, forming a full-chain responsibility constraint. This design links the operational permissions of nodes to their historical behavior in real time. Good operating records generate positive incentives for expanded permissions, while violations generate negative constraints for reduced permissions. Violations trigger immediate isolation, fundamentally solving the technical problems of rigid permission control and lack of immediate punishment for violations in existing technologies.
[0035] It should be noted that the dynamic control of operational permissions for currently participating nodes based on trust reserves in this invention is not a one-time determination performed only at the end of the process, but a continuous mechanism throughout the entire transfer operation. From the entry threshold judgment when the current participating node initiates an operation request, to the real-time update of trust reserves during operation execution, and then to the trust transmission constraints on subsequent participating nodes after the operation is completed, trust reserves always participate as a core decision variable in the judgment and calculation of each stage. Any change in the trust reserves of any participating node will immediately affect its own operational permissions and propagate downwards along the link through the transmission mechanism, forming a full-chain, real-time, adaptive dynamic control closed loop.
[0036] In summary, this invention constructs a blockchain based on drug transport data and participating nodes, enabling the distributed storage of each node's identity information within the blockchain. This eliminates the need for centralized server management, effectively preventing the security risks of impersonation. By determining node commitment values, it pre-anchors and ensures non-repudiation of operational intentions, providing an immutable credential basis for subsequent identity verification and accountability. By determining signature tag values, it enforces the association between the operator's identity and operational intentions, solving the technical problem of distinguishing between legitimate operations and unauthorized impersonation in existing technologies. By updating the trust inventory of current participating nodes based on the verification of node commitment values, signature tag values, and the identity credentials of the current participating nodes, it solves the technical problems of lack of dynamic feedback in permission management and inability to promptly punish violations in existing technologies. Finally, by dynamically controlling the operational permissions of current participating nodes based on the trust inventory, it achieves a fundamental shift from static preset to dynamic adaptive operation permissions, solving the technical problems of rigid permission control and lack of immediate punishment for violations in existing technologies.
[0037] Preferably, in some possible implementations of the embodiments of the present invention, the method for obtaining the node commitment value includes: In the drug transportation chain, drugs need to go through multiple nodes sequentially from the origin to the destination. For example, a drug transportation order is initiated through the system, a pharmacist performs the outbound operation, the drugs are then transported by delivery workers, and finally signed for by a nurse. Each handover between nodes corresponds to a specific transportation or operation process, which has a clear origin node, destination node, execution time, operation type, and drug batch information involved. In order to clearly define and identify each handover process, this embodiment of the invention obtains the type, timestamp, and drug batch of the transportation process corresponding to the currently participating node in the drug transportation data.
[0038] In one specific implementation of this invention, the type of the transfer process can be directly read from the drug transfer order of the current participating node. For example, if the current participating node is a hospital pharmacy node, the transfer process type is outbound shipment; if the current participating node is a delivery worker node, the transfer process type is transportation handover, etc. The timestamp can be obtained by the current participating node directly retrieving the timestamp of the current block by initiating an operation request when performing the transfer operation. Each batch of drugs is assigned a unique batch code when it leaves the factory. When the current participating node performs the transfer operation, it can directly scan the batch code through a PDA device to obtain the drug batch of the transfer process.
[0039] Considering that the same participating node may perform the same type of operation multiple times on the same batch of medicines within a short period of time. For example, a warehouse clerk might need to repeatedly perform the same inbound scanning operation on the same batch of medicines due to a malfunctioning barcode scanner; similarly, a logistics driver might need to resubmit transport handover confirmation due to a network signal interruption. Therefore, to differentiate between multiple identical operations performed by the same participating node, this embodiment of the invention generates a random number for the current participating node as a corresponding random perturbation factor. Since the value of the random perturbation factor is different each time, the input to the compressed mapping will inevitably be different, and the output commitment value will also inevitably be different, thus ensuring the uniqueness of the commitment value for each operation. This embodiment of the invention uses a cryptographically secure random number generator to generate a random number as the corresponding random perturbation factor.
[0040] Meanwhile, in order to facilitate storage and comparison in the blockchain, the operation information of each participating node needs to be in a unified format. Therefore, in this embodiment of the invention, the type of the transfer process, timestamp, drug batch, and random disturbance factor are compressed and mapped to determine the node commitment value of the current participating node.
[0041] In one specific implementation of this invention, the drug transfer process between the previous participating node and the current participating node is considered as the current participating node's transfer process. Due to the one-way nature of the hash algorithm, the original operation parameters cannot be deduced from the commitment value, protecting the privacy of operation details before verification. Simultaneously, the node commitment value output by this algorithm maintains a fixed length, facilitating storage and comparison in the blockchain. Therefore, this embodiment constructs a transfer string for each transfer process according to the type of transfer process, timestamp, drug batch, and the order of the random perturbation factor. The transfer string is then compressed and mapped using a hash algorithm, and the hash value output by the algorithm is used as the node commitment value of the current participating node. The node commitment value represents the operational intent and responsibility of the current participating node.
[0042] It should be noted that for the first participating node (the hospital pharmacy node in this embodiment of the invention), since it has no previous participating node, there is no transfer process; in this embodiment of the invention, the drug outbound operation of the participating node is taken as its corresponding transfer process, and the type of the outbound operation, the drug batch, the current timestamp, and the random disturbance factor are compressed and mapped to determine the node commitment value of the first participating node.
[0043] Preferably, in some possible implementations of the embodiments of the present invention, the method for obtaining the signature tag value includes: Since the block hash is the unique identifier of the current block when a participating node in the blockchain network performs an operation, and the current participating node cannot predict the block hash of future blocks when submitting its node commitment value, this embodiment of the invention mixes the node commitment value with the block hash of the transfer process to determine the random challenge value of the current participating node. Because the current participating node cannot pre-calculate the random challenge value and pre-set its response, it must respond in real time after receiving the random challenge value. Therefore, this process ensures that attackers cannot bypass verification through pre-calculation, guaranteeing the unpredictability of each challenge and thus improving system security. The block hash is a block identifier generated by the blockchain network for the transfer process through a consensus mechanism. It is a built-in field in blockchain technology, and its specific generation process is a well-known technique, so its implementation will not be elaborated here.
[0044] In one specific implementation of this invention, when the current participating node submits its node commitment value, the latest confirmed block hash of the blockchain network has already been generated and is unpredictable. A string is constructed according to the order of the node commitment value and the block hash and input into the hash algorithm. The hash value output by the algorithm is used as the random challenge value of the current participating node.
[0045] Furthermore, in order to effectively distinguish whether the target of the transfer process is a legitimate node or an attacker, this embodiment of the invention binds the random challenge value with the identity credentials of the currently participating node to determine the signature tag value of the currently participating node.
[0046] In one specific implementation of this invention, the current participating node uses the private key in its identity credentials to sign the random challenge value using the RSA algorithm, thereby obtaining the signature tag value of the current participating node.
[0047] It should be noted that the RSA algorithm is a well-known technique in the field, and its implementation process will not be described in detail here.
[0048] Preferably, in some possible implementations of the embodiments of the present invention, the process of updating the trust inventory includes: Please refer to Figure 2 The diagram illustrates a flowchart of a trust inventory update method according to an embodiment of the present invention, the method comprising: S201: Based on the trust stock of the previous participating node, apply trust propagation constraints to the trust stock of the current participating node to determine the available trust stock of the current participating node.
[0049] In distributed data transfer processes, there are chain dependencies among participating nodes. The operation of a current participating node depends on the quality of the data or resources provided by the previous participating node. If the trust balance of the previous participating node is insufficient, it indicates that its historical behavior is abnormal or its reliability is low, and any operation based on this carries uncontrollable risks. Therefore, this embodiment of the invention applies trust transmission constraints to the trust balance of the current participating node based on the trust balance of the previous participating node to determine the available trust balance of the current participating node.
[0050] It should be noted that for participating nodes participating in the transfer operation for the first time, the initial trust stock can be set according to the type of transfer process they are participating in. Specifically, the initial trust stock of a participating node is set to the minimum stock threshold for the type of transfer process it is participating in. For example, if a participating node is a hospital pharmacy node, since the transfer process type it is responsible for is "outbound", its initial trust stock is set to the minimum stock threshold corresponding to the "outbound" transfer process type. For the first participating node in the drug transfer chain (the hospital pharmacy node in this embodiment), since it does not have a previous participating node, it does not need to undergo a trust transmission constraint process, and directly uses its trust stock recorded in the blockchain as the available trust stock.
[0051] S202: Determine the corresponding minimum inventory threshold based on the type of the transfer process.
[0052] Different types of data transfer operations have fundamentally different requirements for trust reserves. High-value or high-risk transfer processes require higher trust guarantees, while low-risk operations can have a more relaxed threshold. For example, transfer operations involving large sums of money or critical resources require participating nodes to have a high trust reserve to reduce operational risk; while routine or low-value transfer operations can be performed with a lower trust reserve. Therefore, this embodiment of the invention determines the corresponding minimum trust reserve threshold based on the type of transfer process, thereby avoiding system stagnation due to an excessively high threshold and avoiding security risks caused by an excessively low threshold.
[0053] In one specific implementation of this invention, the minimum inventory threshold is set differently based on the type of transfer process. Specifically, this invention divides the transfer process of the entire drug transfer chain into four types: outbound, handover, transportation, and receipt, and sets the corresponding minimum inventory thresholds to 80, 70, 60, and 50 respectively.
[0054] It should be noted that the minimum stock threshold is positively correlated with the risk level of the transfer process, and its value range is the same as that of the trusted stock, which is [0, 100]. The higher the risk level, the larger the minimum stock threshold; the lower the risk level, the smaller the minimum stock threshold. It can be adjusted within the above value range according to the specific implementation scenario.
[0055] S203: When the available trust stock is greater than or equal to the minimum stock threshold, determine the trust stock of the current participating node based on the deviation between the available trust stock and the minimum stock threshold; when the available trust stock is less than the minimum stock threshold, refuse to execute this transfer operation, and penalize the available trust stock to determine the trust stock of the current participating node.
[0056] It should be noted that after the previous participating node is refused to execute the current transfer operation, in order to ensure the subsequent flow of medicines, the medicines still need to be transferred to the current participating node through emergency allocation, carrier change, manual emergency handling, or other means. In such scenarios, to ensure the integrity of responsibility transmission, the system calculates a trust transmission factor based on the current trust stock at the time the previous participating node was refused, and uses this transmission factor to constrain the upper limit of the available trust stock of the current participating node.
[0057] When the available trust stock is greater than or equal to the minimum stock threshold, it indicates that the current participating node possesses the basic qualifications to execute this transfer operation. At this point, the system does not simply use the available trust stock directly as the final trust stock, but dynamically adjusts it based on the deviation between the available stock and the threshold. The portion exceeding the minimum stock threshold represents the current participating node's credit surplus above the basic requirements. This surplus should be included in the trust stock assessment to incentivize nodes to continuously accumulate a good credit record. Furthermore, the larger the deviation, the more sufficient the current participating node's trust redundancy, and the higher the reliability of its subsequent operations.
[0058] In one specific implementation of this invention, the available trust stock is subtracted from the minimum stock threshold to obtain the trust stock redundancy value. The sum of the available trust stock and the trust stock redundancy value is used as the trust stock of the current participating node. Simultaneously, to prevent the trust stock from exceeding the theoretical upper limit, a truncation operation is required. Specifically, if the sum of the available trust stock and the trust stock redundancy value is greater than 100, the trust stock of the current participating node is forcibly set to 100.
[0059] When the available trust balance falls below the minimum threshold, it indicates that the current participating node does not possess the minimum trust required to execute the current transfer operation. Forcing the operation under these circumstances would trigger uncontrollable credit risks. Therefore, the system refuses to execute the transfer operation, preventing the risk event from occurring at its source. Furthermore, since the participating node initiates the operation request despite insufficient trust balance, it indicates a risk-prone nature or insufficient self-assessment ability. A penalty mechanism should be implemented to lower its trust level, creating a negative incentive that encourages it to accumulate sufficient trust balance before future operations.
[0060] Preferably, in some possible implementations of the embodiments of the present invention, the method for obtaining the available trust stock includes: Please refer to... Figure 3 The diagram illustrates a flowchart of a method for obtaining available trust reserves according to an embodiment of the present invention, the method comprising: S301: Determine the remaining trust balance based on the deviation between the trust balance of the previous participating node and the minimum trust balance threshold corresponding to the previous participating node.
[0061] In one specific implementation of this invention, the remaining trust balance is obtained by subtracting the minimum trust balance threshold corresponding to the previous participating node from the trust balance of the previous participating node.
[0062] S302: Determine the corresponding trust transmission factor based on the remaining trust stock and the preset trust stock limit; the trust transmission factor is positively correlated with the remaining trust stock and negatively correlated with the preset trust stock limit.
[0063] Considering the transitivity of trust reserves, the reputation level of the previous participating node directly determines the trust foundation that the current participating node can inherit. Therefore, to measure the impact of the reputation level of the previous participating node on the trust reserves of the current participating node, this embodiment of the invention introduces a trust transmission factor. The corresponding trust transmission factor is determined based on the remaining trust reserves and a preset upper limit of trust reserves. The trust transmission factor is positively correlated with the remaining trust reserves and negatively correlated with the preset upper limit of trust reserves.
[0064] In one specific implementation of this invention, the remaining trust balance is used as the numerator, the preset trust balance upper limit is used as the denominator, and the ratio of the two is used as the corresponding trust transmission factor. In this embodiment, the preset trust balance upper limit is set as the minimum trust balance threshold corresponding to the previous participating node.
[0065] S303: Determine the trust inventory adjustment amount of the current participating node based on the product of the preset reference inventory of the current participating node and the trust transmission factor.
[0066] The trust stock adjustment represents the adjustment of the trust capacity available to the current participating node by the trust level of the previous participating node. If the trust level of the previous participating node is high, that is, its available trust stock is greater than or equal to the corresponding minimum stock threshold, the trust stock adjustment of the current participating node is a non-negative value; conversely, if its available trust stock is less than the corresponding minimum stock threshold, the trust stock adjustment of the current participating node is a negative value, thereby limiting the operational capabilities of the current participating node.
[0067] In one specific implementation of this invention, the preset reference stock is set as the minimum stock threshold corresponding to the current participating node.
[0068] S304: Determine the available trust stock of the current participating node based on the trust stock stock and the trust stock stock adjustment amount.
[0069] In one specific implementation of this invention, the sum of the current participating node's trust balance and the trust balance adjustment amount is taken as the current participating node's available trust balance. To prevent the trust balance from exceeding the theoretical range, a truncation operation is required. Specifically, if the sum is greater than 100, the current participating node's available trust balance is forcibly set to 100; if the sum is less than 0, the current participating node's available trust balance is forcibly set to 0.
[0070] Preferably, in some possible implementations of the embodiments of the present invention, the method for penalizing the available trust stock includes: Since the minimum trust threshold reflects the safety baseline of the current operation type, a higher minimum trust threshold indicates a greater operational risk. If a participating node fails to meet the threshold, the more serious the problem exposed, the heavier the corresponding penalty should be. Therefore, to measure the severity of punishment for violations, this embodiment of the invention determines a trust stock penalty value based on the minimum trust threshold and a preset penalty factor. Both the minimum trust threshold and the preset penalty factor are positively correlated with the trust stock penalty value. A larger trust stock penalty value indicates a stronger penalty for the current participating node's violation. Finally, based on the deviation between the available trust stock and the trust stock penalty value, the trust stock of the current participating node is determined, thereby enabling penalties to be imposed based on the available trust stock.
[0071] In one specific implementation of this invention, the product of the minimum trust threshold and the preset penalty factor is used as the trust stock penalty value. The trust stock of the current participating node is obtained by subtracting the trust stock penalty value from the available trust stock. To prevent the trust stock from exceeding the theoretical range, a truncation operation is required. The specific truncation operation has been described in the process of obtaining the available trust stock and will not be repeated here. In this embodiment, the preferred range of the preset penalty factor is [0.2, 0.5], and the value in this embodiment is 0.3. It can be adjusted within the above preferred range according to the specific implementation scenario.
[0072] It should be noted that the larger the preset penalty factor, the greater the punishment for violations, the more trust reserves a participating node loses due to violations, the longer it takes for a participating node to recover to an operational state, and the stronger the deterrent effect on violations. Conversely, the smaller the preset penalty factor, the lighter the losses suffered by participating nodes and the lower the recovery cost, but it may weaken the punitive effect and increase the probability of violations.
[0073] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of this application.
Claims
1. A blockchain-based method for multi-node identity authentication and access control in drug transportation, characterized in that, The method includes: Acquire drug transfer data for participating nodes in the drug transfer chain and the corresponding transfer process for each participating node; construct a blockchain based on the drug transfer data and participating nodes; the blockchain contains the trust inventory of each participating node; Each participating node is sequentially designated as the current participating node; based on the splicing characteristics of the drug transfer data, the node commitment value of the current participating node is determined; based on the binding of the node commitment value with the identity credentials of the current participating node, the signature tag value of the current participating node is determined; based on the verification of the node commitment value, the signature tag value, and the identity credentials of the current participating node, the trust inventory of the current participating node is updated. Dynamic control of the operation permissions of currently participating nodes is performed based on the aforementioned trust balance.
2. The blockchain-based multi-node identity authentication and access control method for drug transportation according to claim 1, characterized in that, The method for obtaining the node commitment value includes: Obtain the type, timestamp, and batch number of the transportation process corresponding to the currently participating node in the drug transportation data; A random number is generated for the current participating node as the corresponding random disturbance factor; the type of the transfer process, timestamp, drug batch, and the random disturbance factor are compressed and mapped to determine the node commitment value of the current participating node.
3. The method for multi-node identity authentication and access control of drug transportation based on blockchain according to claim 1, characterized in that, The method for obtaining the signature tag value includes: The node commitment value is mixed with the block hash of the transfer process to determine the random challenge value of the current participating node; the random challenge value is bound to the identity credential of the current participating node to determine the signature tag value of the current participating node.
4. The blockchain-based multi-node identity authentication and access control method for drug transportation according to claim 2, characterized in that, The process of updating the trust inventory includes: Based on the trust stock of the previous participating node, a trust transmission constraint is applied to the trust stock of the current participating node to determine the available trust stock of the current participating node. Determine the corresponding minimum inventory threshold based on the type of the transfer process; When the available trust stock is greater than or equal to the minimum stock threshold, the trust stock of the current participating node is determined based on the deviation between the available trust stock and the minimum stock threshold; when the available trust stock is less than the minimum stock threshold, the current transfer operation is rejected, and the available trust stock is penalized to determine the trust stock of the current participating node.
5. A blockchain-based multi-node identity authentication and access control method for drug transportation according to claim 4, characterized in that, The method for obtaining the available trust stock includes: The remaining trust stock is determined based on the deviation between the trust stock of the previous participating node and the minimum stock threshold corresponding to the previous participating node. Based on the remaining trust balance and the preset trust balance limit, a corresponding trust transmission factor is determined; the trust transmission factor is positively correlated with the remaining trust balance and negatively correlated with the preset trust balance limit. The adjustment amount of the trust inventory of the current participating node is determined by multiplying the preset reference inventory of the current participating node with the trust transmission factor. The available trust stock of the current participating node is determined based on the trust stock stock of the current participating node and the trust stock stock adjustment amount.
6. The blockchain-based multi-node identity authentication and access control method for drug transportation according to claim 4, characterized in that, The method for penalizing the available trust stock includes: The trust stock penalty value is determined based on the minimum stock threshold and the preset penalty factor; both the minimum stock threshold and the preset penalty factor are positively correlated with the trust stock penalty value. The trust stock of the currently participating node is determined based on the deviation between the available trust stock and the trust stock penalty value.
7. A blockchain-based multi-node identity authentication and access control method for drug transportation according to claim 2, characterized in that, Compressed mapping is performed using a hash algorithm.
8. A blockchain-based multi-node identity authentication and access control method for drug transportation according to claim 5, characterized in that, The available trust stock is the sum of the trust stock of the currently participating node and the trust stock adjustment amount.
9. A blockchain-based multi-node identity authentication and access control method for drug transportation according to claim 1, characterized in that, The transfer process corresponding to each participating node is the drug transfer process between the previous participating node and each participating node.
10. A blockchain-based multi-node identity authentication and access control method for drug transportation according to claim 1, characterized in that, The identity credentials are the private and public keys of each participating node.