A dual-loop closed-loop control system and method for bulk commodity trading

CN122571684APending Publication Date: 2026-08-14TAIYUAN HUIBIAN TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-22
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0006]本发明旨在解决现有技术中交易执行与审计监督之间缺乏实时、双向、硬件级权限互控和强制闭锁机制的技术问题

Benefits of technology

[0023]本发明与现有技术相比具有以下有益效果。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122571684A_ABST
    Figure CN122571684A_ABST
Patent Text Reader

Abstract

This invention discloses a dual-loop closed-loop control system and method for bulk commodity transactions. The system includes an inner-loop transaction control module, an outer-loop regulatory audit module, and a closed-loop freeze execution module. The closed-loop freeze execution module uses a hardware XOR arithmetic unit to perform XOR mutual control on the dynamic permission signals of the two loops. Its output, together with the closed-loop instruction triggered by the risk threshold, controls the hardware signal interceptor connected in series on the transaction instruction bus and the audit storage write bus. When a risk is triggered, a hardware interrupt independent of the operating system drives the simultaneous physical disconnection of the two buses, realizing bidirectional forced closed-loop of transaction execution and audit modification. Unlocking requires the risk value to fall back and joint review and approval after independent authentication by authorized personnel of both loops. This invention constructs an equal-rights constraint and forced closed-loop mechanism between the inner and outer loops at the hardware level, effectively preventing unilateral tampering or unauthorized actions and ensuring transaction security and compliance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of transaction security control technology, and in particular to a dual-loop closed-loop control system and method for spot commodity trading. This invention pertains to technical solutions that utilize computer programs and specific hardware architectures to collaboratively achieve secure control of financial transactions, specifically involving transaction data processing, access control, risk monitoring, and anomaly blocking. Background Technology

[0002] Commodity trading, such as spot listings and auctions of energy chemicals, agricultural products, and metal ores, is characterized by large single transaction amounts, multiple participating parties, and long fulfillment cycles. During transaction execution, the trading department and the compliance / risk control department often belong to different organizational entities or security domains. Traditional transaction risk management methods, such as post-event audits or rule-based single-layer risk control engines, have a fundamental technical flaw: the logic and authority of transaction execution and supervision / auditing are unidirectional, lacking a real-time, technically-based two-way check and balance mechanism.

[0003] Specifically, in existing technologies, the inner-loop system responsible for transaction execution and the outer-loop system responsible for supervision and auditing are loosely coupled or have a one-way control relationship. For example, in a multi-chain collaborative supervision method disclosed in patent document CN115907762B, the supervisory chain can audit or intervene in the business chain, but the business chain cannot constrain the behavior of the supervisory chain. This one-way mechanism may lead to two technical risks: first, if the inner-loop transaction system is hijacked, the outer loop may not be able to detect it in real time or can only passively record it; second, if the outer-loop auditing system itself is illegally manipulated, the inner-loop system also lacks the technical means to counteract it, and one party can unilaterally tamper with audit logs or forge compliance records, making it technically impossible to rigidly guarantee two-way compliance constraints.

[0004] Furthermore, existing risk circuit breaker and recovery mechanisms, such as those described in patent documents US12045889B2 or CN120743612B, typically involve a single risk control engine triggering a transaction ban, and recovery is often achieved through unilateral approval by the risk control party or a specific role. Technically, these solutions do not link transaction execution permissions and audit traceability permissions as a unified, interconnected mechanism. Even after a risk is triggered, the auditing end can still manipulate the data, posing a risk of evidence destruction.

[0005] Therefore, how to build a closed-loop control system that integrates inner-loop transaction execution and outer-loop regulatory auditing, enables mutual locking of permissions via XOR, allows for dual-path physical disconnection in case of risk, and requires joint dual-loop technology for unlocking, has become an urgent technical problem to be solved in the field of commodity trading security. Summary of the Invention

[0006] The present invention aims to solve the technical problem of the lack of real-time, two-way, hardware-level permission mutual control and mandatory locking mechanism between transaction execution and audit supervision in the prior art.

[0007] On one hand, this invention provides a dual-loop closed-loop control system for bulk commodity transactions. The closed-loop freeze execution module introduces an XOR operator implemented by hardware logic gate circuits. The two inputs of this operator receive inner-loop control permission signals representing the inner-loop's intent through a physically isolated private network encrypted communication module. And signals of regulatory authority representing the will of the outer ring. . and This is a dynamically changing level signal based on the transaction execution status and audit verification results. The output of the XOR operator is the final control authority signal. It directly controls the enable pins of two hardware signal interceptors. The first hardware signal interceptor is connected in series on the trading instruction bus, and the second hardware signal interceptor is connected in series on the audit data write bus. Simultaneously, the risk monitoring module integrates abnormal behavior indicators from both the inner and outer loops to calculate the comprehensive risk value in real time. .when When the threshold λ is exceeded, a locking instruction Lock=1 is generated. When Lock=1 and... Under an invalid voltage level, the two hardware interceptors physically disconnect their respective serially connected buses, enabling simultaneous two-way locking during transaction execution and audit modifications. Unlocking requires both conditions to be met. Once the price falls below the threshold, and after independent confirmation by the operators on both the inner and outer rings, and Both are set to active level, forming a dual-ring joint review passed status.

[0008] On the other hand, the present invention provides a dual-loop closed-loop control method for bulk commodity transactions based on the above system.

[0009] The specific technical solution adopted in this invention is as follows: This invention discloses a dual-loop closed-loop control system for bulk commodity transactions, comprising an inner-loop real-time transaction control module, an outer-loop regulatory audit module, a risk monitoring module, a threshold configuration module, a closed-loop freeze execution module, and a closed-loop release unit; The lockout freeze execution module includes: An XOR operator implemented using hardware logic gates receives an inner-loop control permission signal from the inner-loop transaction real-time control module at its first input terminal via a first private network encrypted communication module. Its second input terminal receives the outer ring supervision authority signal from the outer ring supervision and audit module through the second private network encrypted communication module. Its output terminal outputs the final control authority signal. The logic function of the XOR operator can be implemented by combining discrete logic gates, programmable logic lookup tables, or equivalent digital logic circuits. The inner ring control authority signal The inner-loop transaction real-time control module dynamically outputs the following based on the transaction execution status: when the transaction process is normal and the node verification passes, A valid high level; when unauthorized operations, abnormal transaction data, or process violations are detected, Automatically switch to invalid low level; The outer ring regulatory authority signal The outer ring supervision and audit module dynamically outputs the following based on the audit verification results: when the audit comparison is consistent and no data tampering or permission violations are detected, A valid high level; when inconsistencies in audit comparisons, unauthorized operations, or data anomalies are detected, Automatically switch to invalid low level; A first hardware signal interceptor implemented by any one of FPGA, CPLD, ASIC or dedicated hardware security chip, whose enable terminal is connected to the output terminal of the XOR arithmetic unit, and whose signal path is connected in series with the instruction sending bus of the inner loop transaction execution link. A second hardware signal interceptor implemented by any one of FPGA, CPLD, ASIC or dedicated hardware security chip, whose enable terminal is connected to the output terminal of the XOR operator, and whose signal path is connected in series to the storage write bus of the outer loop audit data write link. The risk monitoring module is used to collect a set of indicators of abnormal transaction behavior within the inner ring in real time. and the set of indicators for abnormal behavior in the outer ring audit According to the formula

[0010] Calculate the overall transaction risk value ,in, For the inner ring risk assessment function, Let α be the outer ring risk assessment function, and β be the preset weighting coefficients, with α+β=1; The threshold configuration module stores a preset risk control threshold λ; when When this occurs, a locking instruction Lock=1 is generated; When the lockout instruction Lock=1 takes effect and the final control authority signal is active... When the signal is invalid low, the first hardware signal interceptor physically cuts off the instruction sending bus, and at the same time the second hardware signal interceptor physically cuts off the storage writing bus, so that transaction execution and audit modification are simultaneously forced to be locked in both directions. The lockout release unit is used to control the first hardware signal interceptor and the second hardware signal interceptor to return to the conducting state and release the bidirectional forced lockout when the following two conditions are met simultaneously: (a) The risk monitoring module detected ; (b) After the operator confirms that the anomaly has been handled, the inner-loop transaction real-time control module will... Set to a valid high level, and after the compliance risks of the outer ring regulatory audit module have been independently confirmed by its auditors to be eliminated, When set to a valid high level, the two constitute a joint approval status.

[0011] Furthermore, the truth table of the XOR operator is defined as: when and When all are active high levels, Output active high level; when and If either of them is an invalid low level or the two levels are different, Output invalid low level; the first hardware signal interceptor and the second hardware signal interceptor are configured to turn on the corresponding bus when the enable terminal receives a high level, and physically cut off the corresponding bus when it receives a low level.

[0012] Furthermore, the latch freeze execution module also includes an unavoidable hardware interrupt controller. The hardware interrupt controller has a dedicated interrupt signal line independent of the operating system kernel. This dedicated interrupt signal line is a non-maskable interrupt defined during CPU design and is a physical interrupt line that is prevented from being remapped or masked by the kernel through firmware configuration after the operating system starts. The latch instruction Lock=1 acts directly on the enable input terminals of the first hardware signal interceptor and the second hardware signal interceptor through this dedicated interrupt signal line. Its signal transmission path does not pass through the interrupt handling routine of the operating system kernel, ensuring that the cutoff operation cannot be intercepted or canceled by software processes running at the operating system layer.

[0013] Furthermore, both the first and second hardware signal interceptors include a tri-state bus driver with an output enable control terminal. The enable terminal of the tri-state bus driver is connected to the output terminal of the XOR operator. When the voltage level is low, the output of the tri-state bus driver is in a high-impedance state, thus achieving the physical disconnection.

[0014] Furthermore, during the simultaneous forced bidirectional blocking, the outer loop monitoring and auditing module performs read-only access to the audit logs generated before the blocking through the reserved read-only bus, but the second hardware signal interceptor prohibits any data writing, modification or deletion operations on the storage write bus to ensure the integrity of audit evidence; the read-only bus and the storage write bus are physically two separate bus paths.

[0015] Furthermore, the inner-ring transaction real-time control module and the outer-ring supervision and audit module are physically deployed in mutually independent first and second security domains. The first private network encrypted communication module and the second private network encrypted communication module are respectively implemented by independent hardware encryption chips to ensure physical isolation and tamper resistance of the interlocking signal transmission.

[0016] Furthermore, the inner-ring abnormal transaction behavior indicator set includes at least two of the following: abnormal deviation of transaction amount, abnormal volatility of transaction frequency, and abnormal concentration of counterparties; the outer-ring abnormal audit behavior indicator set includes at least two of the following: number of unauthorized operations, number of data tampering detection hits, and audit log missing rate; the inner-ring risk assessment function... and the outer ring risk assessment function These are either linear weighting functions or nonlinear scoring functions, which are normalized versions of each indicator.

[0017] Furthermore, the commodities mentioned are energy and chemical products, agricultural products, or metal and mineral products, and the trading mode is spot listing or auction trading; the inner ring real-time trading control module is also used to control the electronic signature of the transaction contract and the cargo ownership locking instructions of the warehouse receipt.

[0018] This invention discloses a dual-loop closed-loop control method for bulk commodity transactions, comprising the following steps: S1. System initialization: Configure risk control threshold λ, weighting coefficients α and β of the inner-loop transaction abnormal behavior indicator set and the outer-loop audit abnormal behavior indicator set, and set up a two-way interlocking interaction protocol. S2. During transaction execution, the inner-loop transaction real-time control module collects all transaction data in real time and dynamically outputs inner-loop control permission signals based on the transaction execution status. When the transaction process is normal and the node verification passes, a valid high level is output. When unauthorized operation, abnormal transaction data, or process violation is detected, it automatically switches to an invalid low level. The outer ring supervision and audit module simultaneously performs audit comparison and reverse verification on the inner ring data, and dynamically outputs the outer ring supervision authority signal based on the audit verification results. When the audit comparison is consistent and no data tampering or permission violation is detected, a valid high level is output. When an audit comparison inconsistency, unauthorized operation, or data abnormality is detected, it automatically switches to an invalid low level. S3. An XOR operator implemented by hardware logic gates. and Perform an XOR operation and output the final control permission signal. Among them, when and When all are active high levels, Output a valid high level; otherwise, output an invalid low level. S4. The risk monitoring module collects abnormal transaction behavior indicators from the inner ring and abnormal audit behavior indicators from the outer ring in real time, according to the formula...

[0019] Calculate the overall transaction risk value Compare with the risk control threshold λ; S5, when determining When, a locking instruction Lock=1 is generated; in response to Lock=1 and When the level is invalid low, the unavoidable hardware interrupt controller uses a non-maskable interrupt dedicated signal line defined during CPU design and configured by firmware to prevent remapping or masking by the operating system kernel. This line drives the first hardware signal interceptor, implemented by FPGA, CPLD, ASIC, or dedicated hardware security chip, to physically cut off the instruction sending bus of the inner loop transaction execution link. At the same time, it drives the second hardware signal interceptor to physically cut off the storage write bus of the outer loop audit data write link, thereby achieving forced bidirectional blocking during transaction execution and audit modification. S6. After the anomaly handling is completed and the risk monitoring module detects... Furthermore, the real-time control module for inner-ring transactions will be confirmed by its operators. Set to active high level; the outer ring regulatory audit module will be independently confirmed by its auditors. When the joint review is passed and set to a valid high level, the first and second hardware signal interceptors are restored to the conducting state, the bidirectional forced interlock is released, and the full log of the interlock and the handling is stored in the immutable WORM storage area or the evidence storage area with an additional timestamp hash chain.

[0020] Furthermore, during the forced bidirectional blocking in step S5, the outer loop monitoring and auditing module performs read-only operations on the audit logs generated before the blocking through the reserved read-only bus, and the second hardware signal interceptor prohibits any data writing, modification or deletion operations on the storage write bus; the read-only bus and the storage write bus are physically two separate bus paths.

[0021] Furthermore, the inner-loop risk assessment function described in step S4 and the outer ring risk assessment function These are either linear weighting functions or nonlinear scoring functions after normalizing each indicator; the inner-ring abnormal transaction behavior indicator set includes at least two of the following: abnormal deviation of transaction amount, abnormal volatility of transaction frequency, and abnormal concentration of counterparty; the outer-ring abnormal audit behavior indicator set includes at least two of the following: number of unauthorized operations, number of data tampering detection hits, and audit log missing rate.

[0022] Furthermore, the dedicated interrupt signal line of the hardware interrupt controller is statically fixed during the hardware design phase, and its signal transmission path is entirely located at the hardware level, without passing through the interrupt vector table or interrupt descriptor table of the operating system kernel. This ensures that even if the operating system kernel is maliciously tampered with or replaced, the latch instruction Lock=1 can still be transmitted to the first hardware signal interceptor and the second hardware signal interceptor without error.

[0023] Compared with the prior art, the present invention has the following beneficial effects.

[0024] 1. The present invention implements a permission mutual control model through a hardware XOR operator, which constructs the inner and outer rings as equal permission subjects. Technically, it ensures that no single party can independently make the final control permission effective, thus eliminating the risk of single-point permission loss of control from the source.

[0025] 2. Unlike software-level logic blocking, this invention uses hardware signal interceptors such as FPGA / CPLD or tri-state bus drivers to physically cut off the path of transaction instructions and audit writing in case of anomalies. It has a higher level of security and cannot be bypassed by operating system-level malware.

[0026] 3. During the bidirectional locking period, the present invention can still trace the audit logs before the locking through the physically separated read-only bus, but the write path is cut off by hardware, ensuring the originality and immutability of the evidence after the occurrence of a risk event.

[0027] 4. The unlocking process of this invention mandates objective risk indicators ( (return) and subjective dual-loop independent confirmation ( , The dual conditions (positioning) form a complete technical closed loop from risk triggering, forced locking to safe recovery. Attached Figure Description

[0028] Figure 1 This is a schematic diagram of the dual-loop closed-loop control system architecture for bulk commodity transactions according to the present invention.

[0029] Figure 2 This is a schematic diagram of the process of the dual-loop closed-loop control method for bulk commodity transactions according to the present invention. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of this invention clearer, specific embodiments are described in further detail below. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of the invention.

[0031] Example 1, as Figure 1 As shown in the figure, this embodiment provides a dual-loop closed-loop control system for bulk commodity transactions, which is deployed in a server or dedicated hardware device. It includes an inner-loop real-time transaction control module, an outer-loop supervision and audit module, a risk monitoring module, a threshold configuration module, a closed-loop freeze execution module, and a closed-loop release unit.

[0032] The inner-loop real-time transaction control module, deployed within the first security domain of the trading system, is responsible for real-time monitoring, process control, and transaction node verification of the entire process of spot listing or auction transactions for commodities such as energy chemicals and agricultural products, including contract signing, electronic signatures, cargo warehouse receipt title locking instructions, and fund settlement. This module maintains an internal permission signal state machine to continuously monitor events such as unauthorized operations, abnormal transaction data (e.g., prices deviating from a reasonable range), and process violations. Based on its control status, the module dynamically outputs an inner-loop control permission signal. Specifically, the state machine initially starts in the "normal" state. The output is a valid high level (e.g., "1" in digital logic, corresponding to 3.3V); when any of the following events is received, such as "unauthorized operation," "data anomaly," or "process violation," the state machine transitions to the "abnormal" state. The system immediately and automatically switches to an invalid low level ("0" in digital logic, 0V voltage). The state machine only returns to the "normal" state after all abnormal events have been resolved and an authorized operator has initiated a confirmation reset command via the UKey digital certificate. Return to high level.

[0033] The outer-ring regulatory audit module is deployed in a physically independent second security domain and communicates with the inner ring via a dedicated network using encrypted communication. This module performs synchronous auditing, reverse verification, and anomaly tracing of transaction data, permission operation records, and data change logs generated within the inner ring. It not only compares data consistency but also verifies whether operations conform to preset permission matrix rules. Internally, this module also maintains a state machine. Based on its audit and verification results, this module dynamically outputs an outer-ring regulatory permission signal. The state machine initially starts in a "consistent" state. Output a valid high level; when any of the events "audit comparison inconsistency", "unauthorized operation", or "data anomaly" is detected, the state machine transitions to the "abnormal" state. The system immediately and automatically switches to an invalid low level. The state machine only returns to a "consistent" state after all abnormal events have been resolved and confirmed by authorized auditors through an authentication system independent of the inner loop (such as another UKey or biometric authentication). Return to high level.

[0034] The lockout freeze execution module is the core of this invention for implementing hardware-level bidirectional lockout. This module includes an XOR operator U1 implemented using hardware logic gates. U1 can be implemented using a separate XOR gate chip (such as 74HC86) or configured using a lookup table (LUT) within an FPGA or CPLD. U1 has a first input terminal and a second input terminal, which receive signals from the inner loop via first and second dedicated network encrypted communication modules (e.g., a physically isolated network card with integrated hardware encryption chips). Signal and outer loop Signal.

[0035] The permission mutual control model of the present invention This is implemented at the physical level using the XOR operator U1. The truth table of U1 is specifically configured to achieve the technical effect of "allowing passage only upon mutual agreement of both rings": only when... and When both are active high, its output terminal Only then is it considered a valid high level; when and If either is an invalid low level or the two levels are different (i.e., one high and one low), Output an invalid low level. It should be specifically noted that this logic function can be implemented using combinations of discrete logic gates (such as AND gates and NOT gates), programmable logic lookup tables, or their equivalent digital logic circuits; all of these should be considered within the scope of this invention.

[0036] The latch-freeze execution module also includes a first hardware signal interceptor U2 and a second hardware signal interceptor U3, both of which can be implemented using an FPGA, CPLD, ASIC, or dedicated hardware security chip. In this embodiment, U2 and U3 are constructed using a tri-state bus driver (such as a 74HC244 chip) with an output enable control terminal (OE). The enable terminals (OE) of U2 and U3 receive control signals through an AND gate G1. One input of the AND gate G1 is connected to the output P of the XOR operator U1, and the other input receives the latched latch instruction Lock. The signal path of U2 (from A to B) is connected in series on the instruction transmission bus (such as SPI or parallel data bus) of the inner loop transaction execution link; the signal path of U3 is connected in series on the storage write bus (such as SATA or PCIe storage command channel) of the outer loop audit data write link. When G1 outputs a high level, U2 / U3 conducts normally; when G1 outputs a low level, its output terminal is in a high-impedance state, physically cutting off the bus path, and the signal cannot pass through.

[0037] The risk monitoring module can be implemented using a high-performance FPGA accelerator card or a standalone server. It collects real-time data from the inner loop, including indicators such as abnormal deviations in transaction amounts, abnormal volatility in transaction frequency, and abnormal concentration of counterparties, forming a comprehensive analysis. The data collection includes metrics such as the number of unauthorized operations, the number of data tampering detection hits, and the audit log missing rate, forming a set of data. In a specific instance, Using a linear weighted model: ,in , , These are the three categories of indicators after normalization. A similar linear weighted model is also used. The module operates according to a preset formula.

[0038] Calculate the overall transaction risk value The weighting coefficients α and β satisfy α+β=1 and can be configured according to the degree of emphasis on internal and external risks (e.g., α=0.4, β=0.6).

[0039] The threshold configuration module stores preset risk control thresholds λ (e.g., λ=0.7). When the risk monitoring module outputs... At that time, the module generates and latches a locking instruction Lock=1.

[0040] The propagation path of the latch instruction Lock=1 is crucial. To ensure "unavoidability," this system introduces a hardware interrupt controller. This controller is configured with a dedicated non-maskable interrupt (NMI) signal line defined during CPU design. During the system firmware (BIOS / UEFI) boot phase, this signal line is configured to prevent remapping or masking by the operating system kernel.

[0041] The Lock=1 signal is converted into an NMI interrupt, which is sent directly to one input of AND gate G1 through this dedicated hardware path, without going through the operating system kernel's interrupt vector table or any interrupt handling routines.

[0042] When Lock=1 is latched high, and at this time, due to a risk anomaly, at least one of the inner or outer loops has set the permission signal low, then the output of the XOR operator U1 is... With an invalid low level, AND gate G1 outputs a low level, and the enable terminals of U2 and U3 are simultaneously low, resulting in a momentary high-impedance output. The first hardware signal interceptor U2 physically cuts off the inner-loop transaction instruction transmission bus, immediately halting all transaction execution. Simultaneously, the second hardware signal interceptor U3 physically cuts off the outer-loop audit data storage and writing bus, prohibiting any attempt to modify, delete, or add audit logs. The system enters a "simultaneous forced bidirectional latching" state.

[0043] During this lockout period, to facilitate post-event evidence collection, the outer-loop monitoring and auditing module is designed to allow read-only access to the audit logs that were previously stored before the lockout via a reserved read-only bus physically separate from the storage write bus. This dual-bus architecture ensures that the physical disconnection of the write path by the U3 does not affect the reading of historical data.

[0044] The lockout release unit is the only path for system recovery, and its control logic strictly follows the principle of "risk removal + dual-loop agreement". The release unit continuously monitors two conditions: condition (a) the risk monitoring module calculates... This indicates that the objective risk has disappeared; under condition (b), the real-time control module for inner-loop transactions confirms that the anomaly has been handled after its authorized operator has authenticated the transaction via UKey. The signal is reset to a valid high level. Simultaneously, the outer-ring regulatory audit module, after being independently certified by its authorized auditors, confirms that the compliance risk has been eliminated. The two setting actions, once set to a valid high level, constitute a "joint approval status." Only when conditions (a) and (b) are simultaneously met will the lockout release unit output a reset signal. This signal clears the latched state of the Lock, restores the output of G1 to a high level, and resets the enable pins of U2 and U3 to a high level, re-energizing the bus, releasing the lockout, and resuming the normal transaction process. The entire lockout and handling process log is written in real-time to a WORM (Write-once, Read-many) storage device, with a timestamp and hash chain appended for permanent storage.

[0045] Example 2, based on the same inventive concept, such as Figure 2 As shown, this embodiment provides a dual-loop closed-loop control method for bulk commodity transactions, which is applied to the aforementioned system embodiment. The method specifically includes the following steps: S1. System Initialization: During system startup, the NMI dedicated signal line of the hardware interrupt controller is locked via firmware configuration, disabling operating system kernel remapping. The risk control threshold λ, the weighting coefficients α and β of the inner and outer loop risk evaluation functions are configured, and a bidirectional interlocking interaction protocol is set.

[0046] S2. Dual-loop parallel monitoring and dynamic permission signal output: During transaction execution, the inner-loop real-time transaction control module collects all transaction data in real time and dynamically outputs based on the internal state machine. The outer-ring regulatory audit module simultaneously audits and compares the inner-ring data and performs reverse verification, and dynamically outputs data based on the internal state machine. .

[0047] S3. Hardware XOR Operation: The XOR operator implemented by hardware logic gates... and Perform an XOR operation and output the final control permission signal. .

[0048] S4. Dual-Source Risk Fusion Calculation and Comparison: The risk monitoring module collects abnormal behavior indicators from the inner and outer rings in real time, and calculates them according to the formula.

[0049] Calculate the overall transaction risk value And continuously compare it with the threshold λ.

[0050] S5, Threshold-triggered unavoidable two-way hardware interlocking: When a decision is made... At that time, Lock=1 is generated and latched. This instruction communicates with the NMI dedicated hardware path. After the signal is judged by the AND gate logic, it drives the first and second hardware signal interceptors. When the signal is invalid low, the inner loop transaction instruction sending bus and the outer loop audit data storage writing bus are physically disconnected, thereby enabling simultaneous forced bidirectional locking during transaction execution and audit modification.

[0051] S6. Dual-ring joint audit unlocking and log storage: After anomaly handling is completed, Furthermore, after each authorized personnel in both loops independently authenticate and confirm their authorization, establishing a joint approval status, the control system resets the lock and restores the hardware signal interceptor's conduction, thus releasing the lockout. A full log containing the lockout trigger time, risk value, dual-loop status, and handling process is stored in an immutable WORM storage area or an evidence storage area with an attached timestamp hash chain.

[0052] It should be noted that the above embodiments are merely preferred implementations of the present invention and should not be construed as limiting the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A dual-loop closed-loop control system for bulk commodity trading, characterized in that, It includes an inner-ring transaction real-time control module, an outer-ring supervision and audit module, a risk monitoring module, a threshold configuration module, a lockout / freeze execution module, and a lockout release unit; The lockout freeze execution module includes: An XOR operator implemented using hardware logic gates receives an inner-loop control permission signal from the inner-loop transaction real-time control module at its first input terminal via a first private network encrypted communication module. Its second input terminal receives the outer ring supervision authority signal from the outer ring supervision and audit module through the second private network encrypted communication module. Its output terminal outputs the final control authority signal. The logic function of the XOR operator can be implemented by combining discrete logic gates, programmable logic lookup tables, or equivalent digital logic circuits. The inner ring control authority signal The inner-loop transaction real-time control module dynamically outputs the following based on the transaction execution status: when the transaction process is normal and the node verification passes, A valid high level; when unauthorized operations, abnormal transaction data, or process violations are detected, Automatically switch to invalid low level; The outer ring regulatory authority signal The outer ring supervision and audit module dynamically outputs the following based on the audit verification results: when the audit comparison is consistent and no data tampering or permission violations are detected, A valid high level; when inconsistencies in audit comparisons, unauthorized operations, or data anomalies are detected, Automatically switch to invalid low level; A first hardware signal interceptor implemented by any one of FPGA, CPLD, ASIC or dedicated hardware security chip, whose enable terminal is connected to the output terminal of the XOR arithmetic unit, and whose signal path is connected in series with the instruction sending bus of the inner loop transaction execution link. A second hardware signal interceptor implemented by any one of FPGA, CPLD, ASIC or dedicated hardware security chip, whose enable terminal is connected to the output terminal of the XOR operator, and whose signal path is connected in series to the storage write bus of the outer loop audit data write link. The risk monitoring module is used to collect a set of indicators of abnormal transaction behavior within the inner ring in real time. and the set of indicators for abnormal behavior in the outer ring audit According to the formula , Calculate the overall transaction risk value ,in, For the inner ring risk assessment function, Let α be the outer ring risk assessment function, and β be the preset weighting coefficients, with α+β=1; The threshold configuration module stores a preset risk control threshold λ; when When this occurs, a locking instruction Lock=1 is generated; When the lockout instruction Lock=1 takes effect and the final control authority signal is active... When the signal is invalid low, the first hardware signal interceptor physically cuts off the instruction sending bus, and at the same time the second hardware signal interceptor physically cuts off the storage writing bus, so that transaction execution and audit modification are simultaneously forced to be locked in both directions. The lockout release unit is used to control the first hardware signal interceptor and the second hardware signal interceptor to return to the conducting state and release the bidirectional forced lockout when the following two conditions are met simultaneously: (a) The risk monitoring module detected ; (b) After the operator confirms that the anomaly has been handled, the inner-loop transaction real-time control module will... Set to a valid high level, and after the compliance risks of the outer ring regulatory audit module have been independently confirmed by its auditors to be eliminated, When set to a valid high level, the two constitute a joint approval status.

2. The dual-loop closed-loop control system for bulk commodity trading according to claim 1, characterized in that, The truth table of the XOR operator is defined as follows: when and When all are active high levels, Output active high level; when and If either of them is an invalid low level or the two levels are different, Output invalid low level; the first hardware signal interceptor and the second hardware signal interceptor are configured to turn on the corresponding bus when the enable terminal receives a high level, and physically cut off the corresponding bus when it receives a low level.

3. The dual-loop closed-loop control system for bulk commodity trading according to claim 1, characterized in that, The latch freeze execution module also includes an unavoidable hardware interrupt controller. The hardware interrupt controller has a dedicated interrupt signal line independent of the operating system kernel. This dedicated interrupt signal line is a non-maskable interrupt defined during CPU design and is a physical interrupt line that is prevented from being remapped or masked by the kernel through firmware configuration after the operating system starts. The latch instruction Lock=1 acts directly on the enable input terminals of the first hardware signal interceptor and the second hardware signal interceptor through this dedicated interrupt signal line. Its signal transmission path does not pass through the interrupt handling routine of the operating system kernel, ensuring that the cutoff operation cannot be intercepted or canceled by software processes running at the operating system layer.

4. The dual-loop closed-loop control system for bulk commodity trading according to claim 1, characterized in that, The first hardware signal interceptor and the second hardware signal interceptor each include a tri-state bus driver with an output enable control terminal. The enable terminal of the tri-state bus driver is connected to the output terminal of the XOR operator. When the voltage level is low, the output of the tri-state bus driver is in a high-impedance state, thus achieving the physical disconnection.

5. The dual-loop closed-loop control system for bulk commodity trading according to claim 1, characterized in that, During the simultaneous forced bidirectional blocking, the outer loop monitoring and auditing module performs read-only access to the audit logs generated before the blocking through the reserved read-only bus, but the second hardware signal interceptor prohibits any data writing, modification or deletion operations on the storage write bus to ensure the integrity of audit evidence; The read-only bus and the storage write bus are physically two separate bus paths.

6. The dual-loop closed-loop control system for bulk commodity trading according to claim 1, characterized in that, The inner-ring transaction real-time control module and the outer-ring supervision and audit module are physically deployed in a first security domain and a second security domain that are independent of each other. The first private network encrypted communication module and the second private network encrypted communication module are implemented by independent hardware encryption chips to ensure physical isolation and tamper resistance of the interlocking signal transmission.

7. A dual-loop closed-loop control system for bulk commodity trading according to any one of claims 1 to 6, characterized in that, The inner-ring abnormal transaction behavior indicator set includes at least two of the following: abnormal deviation of transaction amount, abnormal volatility of transaction frequency, and abnormal concentration of counterparties; the outer-ring abnormal audit behavior indicator set includes at least two of the following: number of unauthorized operations, number of data tampering detection hits, and audit log missing rate; the inner-ring risk assessment function... and the outer ring risk assessment function These are either linear weighting functions or nonlinear scoring functions, which are normalized versions of each indicator.

8. A dual-loop closed-loop control system for bulk commodity trading according to any one of claims 1 to 6, characterized in that, The commodities mentioned are energy and chemical products, agricultural products, or metal and mineral products, and the trading mode is spot listing or auction trading; the inner ring real-time trading control module is also used to control the electronic signature of transaction contracts and the cargo ownership locking instructions of warehouse receipts.

9. A dual-loop closed-loop control method for bulk commodity trading, based on the system described in any one of claims 1 to 8, characterized in that, Includes the following steps: S1. System initialization: Configure risk control threshold λ, weighting coefficients α and β of the inner-loop transaction abnormal behavior indicator set and the outer-loop audit abnormal behavior indicator set, and set up a two-way interlocking interaction protocol. S2. During transaction execution, the inner-loop transaction real-time control module collects all transaction data in real time and dynamically outputs inner-loop control permission signals based on the transaction execution status. When the transaction process is normal and the node verification passes, a valid high level is output. When unauthorized operation, abnormal transaction data, or process violation is detected, it automatically switches to an invalid low level. The outer ring supervision and audit module simultaneously performs audit comparison and reverse verification on the inner ring data, and dynamically outputs the outer ring supervision authority signal based on the audit verification results. When the audit comparison is consistent and no data tampering or permission violation is detected, a valid high level is output. When an audit comparison inconsistency, unauthorized operation, or data abnormality is detected, it automatically switches to an invalid low level. S3. An XOR operator implemented by hardware logic gates. and Perform an XOR operation and output the final control permission signal. Among them, when and When all are active high levels, Output a valid high level; otherwise, output an invalid low level. S4. The risk monitoring module collects abnormal transaction behavior indicators from the inner ring and abnormal audit behavior indicators from the outer ring in real time, according to the formula... , Calculate the overall transaction risk value Compare with the risk control threshold λ; S5, when determining When, a locking instruction Lock=1 is generated; in response to Lock=1 and When the level is invalid low, the unavoidable hardware interrupt controller uses a non-maskable interrupt dedicated signal line defined during CPU design and configured by firmware to prevent remapping or masking by the operating system kernel. This line drives the first hardware signal interceptor, implemented by FPGA, CPLD, ASIC, or dedicated hardware security chip, to physically cut off the instruction sending bus of the inner loop transaction execution link. At the same time, it drives the second hardware signal interceptor to physically cut off the storage write bus of the outer loop audit data write link, thereby achieving forced bidirectional blocking during transaction execution and audit modification. S6. After the anomaly handling is completed and the risk monitoring module detects... Furthermore, the real-time control module for inner-ring transactions will be confirmed by its operators. Set to active high level; the outer ring regulatory audit module will be independently confirmed by its auditors. When the joint review is passed and set to a valid high level, the first and second hardware signal interceptors are restored to the conducting state, the bidirectional forced interlock is released, and the full log of the interlock and the handling is stored in the immutable WORM storage area or the evidence storage area with an additional timestamp hash chain.

10. The dual-loop closed-loop control method for bulk commodity transactions according to claim 9, characterized in that, During the forced bidirectional blocking in step S5, the outer loop monitoring and auditing module performs read-only operations on the audit logs generated before the blocking through the reserved read-only bus. The second hardware signal interceptor prohibits any data writing, modification, or deletion operations on the storage write bus. The read-only bus and the storage write bus are physically two separate bus paths.

Citation Information

Patent Citations

  • A multi-chain coordination-based cross-industry supply chain supervision method

    CN115907762B

  • Methods and systems for automated intelligent transaction monitoring, circuit breaker triggering, and rapid recovery.

    CN120743612B

  • Risk mitigation in an electronic trading system

    US12045889B2