Cascade anti-counterfeiting tracing method, system and device based on multi-layer hash nesting and medium
Patent Information
- Application Number
- CN202611032212.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-13
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2046-07-13
AI Technical Summary
[0008]其一,存储与溯源的矛盾难以调和:若采用将所有底层数据与衍生内容整体打包存证的方式,会导致数据包体积随引用层级呈几何级数增长,极大消耗系统存储与网络带宽资源;若采用普通超链接引用底层数据,则底层数据的篡改、删除或迁移会直接导致上层溯源链断裂,无法保证引用关系的高可靠性与持久性
1、本发明实现了基于哈希指针的轻量级嵌套溯源,大幅降低了存储与网络传输开销。针对现有技术在多级溯源时物理打包导致的资源浪费问题,本发明采用包含网络寻址定位符与其对应密码学哈希值的哈希指针作为元数据进行嵌套封装。在生成衍生数据节点时,无需冗余存储底层的实体数据,实现了源数据节点实体与拓扑验证结构在存储层面的彻底解耦。该方法在保障密码学溯源链条完整性的同时,使衍生数据节点的体积保持极轻量化,降低了验证时的存储与网络带宽消耗,并有效避免了传统单一超链接因失效(死链)而导致的溯源逻辑链条断裂风险,确保了数据节点引用关系的可靠性。
Smart Images

Figure CN122578322B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data anti-counterfeiting and traceability technology, and in particular to a cascaded anti-counterfeiting and traceability method, system, device and medium based on multi-layer hash nesting. Background Technology
[0002] With the profound development of the digital economy, digital content has become a core carrier for information transmission, value exchange, and decision support, widely permeating numerous fields such as judicial evidence preservation, financial auditing, news dissemination, academic research, intelligence analysis, medical data management, and corporate intellectual property protection. The authenticity and traceability of digital content are crucial foundations for the healthy operation of the digital society.
[0003] In recent years, the rapid iteration of generative artificial intelligence (GAI) and deep learning technologies has significantly lowered the barrier to generating and tampering with digital content. Traditional data forgery is often limited to local modifications within a single modality, such as adjusting pixel information of a single image or modifying parts of a single text segment. Such forgery often leaves obvious technical traces and can be effectively identified through conventional feature comparison or manual verification. However, current artificial intelligence technology has the capability for cross-modal, highly realistic, and large-scale systematic forgery. It can not only generate text, images, audio, and video content that is difficult to distinguish by the naked eye or conventional algorithms, but also simultaneously construct logically consistent contextual information and multi-source corroborating data to form a complete system of false information. This comprehensive and deep-seated forgery method poses a systemic challenge to traditional information acceptance mechanisms based on isolated evidence verification and cross-verification. The spread of various types of false digital content has substantially disrupted the normal operation of multiple industries and seriously threatens the foundation of trust in the digital space.
[0004] To address the trust crisis caused by digital content forgery, two mainstream technical approaches have been developed in the industry, but both have significant limitations when dealing with the multi-level data fusion and flow issues in complex business scenarios.
[0005] The first category is deepfake detection technology based on content features. This type of technology trains a dedicated discriminative model to extract and identify microscopic anomalies left over from fake data, thereby detecting fraudulent content. However, the generative model and the detection model are essentially in a state of adversarial evolution. Any effective features identified by the detection algorithm will be quickly incorporated into the optimization objective of the generative model, causing the detection capability to continuously decline with the iteration of generative technology. This AI-against-AI approach has inherent algorithmic limitations, and its detection results always have the possibility of false positives and false negatives. It cannot provide definitive and legally valid anti-counterfeiting proof, and it is difficult to meet the needs of scenarios with extremely high requirements for evidence reliability, such as judicial evidence preservation and financial auditing.
[0006] The second category is data tracing and evidence preservation technology based on cryptography. This type of technology uses digital signatures, hash verification, and blockchain evidence preservation to protect the integrity and prevent tampering of single data entities. Relevant international and industry standards have been gradually established and applied to the encapsulation and preservation of single evidence units. However, in actual business scenarios, most valuable digital content does not exist in isolation, but is a derivative product formed through multi-stage processing and multi-source integration. A final analysis report, audit document, or decision-making document often integrates a large amount of underlying data and intermediate results from different times and sources, forming a complex, multi-layered, mesh-like reference network.
[0007] Existing cryptographic evidence preservation technologies are ill-suited to this complex data ecosystem, primarily in three core aspects.
[0008] First, the contradiction between storage and traceability is difficult to reconcile: if all underlying data and derived content are packaged together for evidence storage, the data packet size will increase exponentially with the reference level, greatly consuming system storage and network bandwidth resources; if ordinary hyperlinks are used to reference the underlying data, the tampering, deletion or migration of the underlying data will directly lead to the break of the upper-level traceability chain, and the high reliability and persistence of the reference relationship cannot be guaranteed.
[0009] Secondly, there is a gap in trust across the entire chain: existing technologies mostly focus on signature verification at the initial data generation end and the final publishing end, neglecting the verification of behavior at intermediate processing nodes during data flow. Attackers can use real underlying data to create misleading content by maliciously splicing context, tampering with analysis logic, and fabricating deduction processes, and existing technologies cannot effectively identify and trace such behavior.
[0010] Third, the failure handling efficiency is low: when a certain underlying basic data is confirmed to be false, the existing technology lacks an automated failure propagation and linkage handling mechanism. It requires manual investigation of all derivative content that references the data, which is not only time-consuming, labor-intensive, and costly, but also prone to omissions. It is impossible to stop the propagation chain of false information in time, resulting in the continuous expansion of the false impact. Summary of the Invention
[0011] To address the aforementioned issues, this invention proposes a cascaded anti-counterfeiting and traceability method, system, device, and medium based on multi-layer hash nesting, which enables traceability and verification of the entire data flow and has the capability for automated cascaded processing after the underlying data fails.
[0012] The technical solution adopted in this invention is as follows: A cascaded anti-counterfeiting and traceability method based on multi-level hash nesting, see [reference]. Figure 1 ,include: The content payload to be encapsulated, the generation timestamp, and the set of reference data nodes are combined to form the payload to be encapsulated, and the node hash value of the payload to be encapsulated is calculated; the node hash value is signed using the publisher's private key, encapsulated to form a new data node, and the reference relationship between each data node is persistently recorded; the set of reference data nodes includes hash addressing pointers and complete data entities; The system performs cryptographic verification on the identity and content integrity of the data nodes to be verified. After the verification is successful, it recursively verifies all the underlying data nodes referenced and updates the trust status of each data node synchronously. When a failed data node is detected, all derived data nodes that directly and indirectly reference the failed data node are traversed according to the recorded reference dependencies, and the contaminated status of the derived data nodes is marked in batches.
[0013] Further, the step of combining the content payload to be encapsulated, the generation timestamp, and the set of reference data nodes to form the payload to be encapsulated, and calculating the node hash value of the payload to be encapsulated, includes: Iterate through all historical data nodes that need to be referenced, obtain the hash address pointer and / or complete data entity of the corresponding referenced data node, and combine the obtained hash address pointer and / or complete data entity to construct a set of referenced data nodes; Prepare a new content payload to be packaged. Logically concatenate the content payload, generation timestamp, and reference data node set to form the payload to be packaged. Perform cryptographic hash calculation on the payload to be packaged to obtain the node hash value.
[0014] It should be noted that this method supports the mixed use of hash-addressed pointers and complete data entities as reference methods, which can be flexibly selected according to the importance of the data and storage requirements, minimizing storage overhead while ensuring the reliability of traceability. By including the set of referenced data nodes in the calculation of node hash, any tampering with the reference relationship or referenced content will cause the node hash value to become invalid, fundamentally ensuring the reliability and immutability of the reference relationship between data nodes.
[0015] Furthermore, the step of signing the node hash value using the publisher's private key, encapsulating it to form a new data node, and persistently recording the reference relationships between the data nodes includes: The node hash value is signed using at least one publisher's private key to generate a corresponding signature packet. When multiple publishers exist, each signature contributes to the data node. The content payload, generation timestamp, set of referenced data nodes, and the signature packet are then encapsulated together to form a new data node, and the reference relationships between the new data node and each referenced data node are persistently recorded. After the new data node is encapsulated, the system selects whether to upload the data node entity to the public storage network based on the preset security policy or network conditions; it uses a directed acyclic graph structure to organize and persistently store the reference relationships between all data nodes, ensuring that traversing along the reference direction from any node cannot return to the node itself.
[0016] It should be noted that the data nodes themselves achieve self-verification storage by encapsulating hashes and digital signatures; the spatiotemporal decoupling design of node generation and network publication improves adaptability and flexibility in complex network environments; the directed acyclic graph reference relationship organization method avoids the infinite loop of tracing the source caused by circular references, while ensuring the uniqueness and clarity of the tracing path; data nodes can be persistently stored in centralized or decentralized networks, and each data node can generate a unique identifier composed of a network locator and a cryptographic hash value to achieve global addressing of content.
[0017] Furthermore, the cryptographic verification of the identity authenticity and content integrity of the data nodes to be verified includes: The system queries the trust status of each data node in local storage. If the data node to be verified has a confirmed trust status, the corresponding verification result is output directly. If the data node to be verified does not have a confirmed trust status, it performs structured parsing to separate the content payload, generation timestamp, referenced data node set, and signature packet. The system then uses the public key corresponding to the signature packet to decrypt and verify the identity of the publisher and the authenticity of the node. When multiple signatures exist, each signature must be verified. After successful decryption, the expected node hash value is extracted. The actual hash value is calculated in real time for the parsed content payload, generation timestamp, and reference data node set to complete the content integrity verification.
[0018] It should be noted that the pre-state query mechanism enables extremely fast response of verified nodes, avoids resource consumption caused by repeated calculations, and greatly improves system performance in high-frequency verification scenarios; the dual cryptographic verification of identity authenticity and content integrity ensures both the non-repudiation of the data publisher's identity and the preservation of data content from tampering during its flow; structured parsing breaks down data nodes into independent and verifiable logical units, providing a foundation for subsequent recursive verification and problem localization.
[0019] Furthermore, after the verification passes, all referenced underlying data nodes are recursively verified, and the trust status of each data node is updated synchronously, including: After the cryptographic verification is passed, check whether there is a reference data node in the current data node; if there is no reference data node, the current data node is deemed to have passed the verification and its trust status is updated; if there is a reference data node, the recursive verification process is executed for each reference data node in turn, until the end of all branches is traced. In the recursive verification process, the generation timestamps of the underlying reference data nodes and the upper-level data nodes are compared for temporal and causal order. If a time-series inversion occurs, the hash verification result of the underlying data node is checked. If the verification fails, the underlying data node is deemed to have failed verification; if it passes, the upper-level data node is deemed to have failed verification. The verification results of each data node are then synchronously updated in the locally stored trust status record.
[0020] It should be noted that the end-to-end recursive verification can penetrate multiple layers of data derivation relationships and reach the source data node directly, overcoming the limitation of traditional technologies that can only verify the authenticity of a single node; the temporal causality verification mechanism can identify malicious references and tampering that violate the data generation temporal logic, further enhancing the security of the traceability system and preventing attackers from creating false evidence chains by splicing data from different time sequences; and the real-time synchronized trust state record provides accurate state basis for subsequent verification and cascading pruning.
[0021] Furthermore, the synchronous update of the trust status of each data node includes: The trust status of data nodes is divided into three categories: trusted, invalid, and contaminated. The trust status of each data node is updated during the regression phase of recursive verification. Bind the corresponding update timestamp to the trust status of each data node, and configure a time-stamp-based state lifecycle management strategy to roll back deterministic states that exceed the effective threshold. Based on a preset cache eviction method, edge data nodes with no definite state and a reference frequency below the frequency threshold are periodically cleaned up.
[0022] It should be noted that updating the state during the regression phase of recursive verification avoids writing invalid intermediate states that have not been verified, ensuring the accuracy and consistency of the state data. Timestamp-based state lifecycle management forces the re-verification of long-unverified data, ensuring the timeliness of trusted states and preventing misjudgments of trust due to subsequent tampering of underlying data. The cache eviction mechanism effectively controls the size of the local state database, avoiding system performance degradation due to excessive data volume and ensuring long-term stable operation of the system.
[0023] Furthermore, when a failed data node is detected, the process of traversing all derived data nodes that directly and indirectly reference the failed data node based on the recorded reference dependencies, and batch-marking the contaminated status of the derived data nodes, includes: The cascading pruning process is initiated with the failed data node as the root node; based on the reference dependency relationship of the local persistent record, all derived data nodes that directly and indirectly reference the root node are traversed and retrieved, and the trust status of all retrieved derived data nodes is marked as contaminated in batches. After completing the batch status update, an early warning statement containing the characteristics of the failed data nodes and the reasons for the failure is generated. The early warning statement is then attached with a digital signature and broadcast and synchronized to an external network or a third-party verification system.
[0024] It should be noted that dependency traversal with the failed node as the root node can accurately locate all affected derived data nodes, realize automated batch blocking of false information, and completely solve the problems of low efficiency and high omission rate of traditional manual investigation; the warning statement with digital signature ensures the authenticity and non-repudiation of the warning information itself; the cross-domain broadcasting and synchronization mechanism can realize the sharing of failure status between different systems, build a full-domain collaborative false information prevention and control system, and minimize the spread and harm of false information.
[0025] A cascaded anti-counterfeiting and traceability system based on multi-level hash nesting includes: The encapsulation and signing module is configured to combine the content payload to be encapsulated, the generation timestamp, and the set of reference data nodes to form the payload to be encapsulated, and calculate the node hash value of the payload to be encapsulated; sign the node hash value using the publisher's private key, encapsulate it to form a new data node, and persistently record the reference relationship between each data node; the set of reference data nodes includes hash addressing pointers and complete data entities; The cryptographic verification module is configured to perform cryptographic verification on the identity authenticity and content integrity of the data nodes to be verified. After the verification is successful, it recursively verifies all the underlying data nodes referenced and synchronously updates the trust status of each data node. The cascading pruning module is configured to, when a failed data node is detected, traverse all derived data nodes that directly and indirectly reference the failed data node based on the recorded reference dependencies, and batch mark the contaminated state of the derived data nodes.
[0026] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the cascaded anti-counterfeiting and traceability method based on multi-level hash nesting.
[0027] A computer-readable storage medium storing a computer program that, when executed by a processor, implements the cascaded anti-counterfeiting and traceability method based on multi-level hash nesting.
[0028] The beneficial effects of this invention are as follows: 1. This invention implements lightweight nested tracing based on hash pointers, significantly reducing storage and network transmission overhead. Addressing the resource waste caused by physical packaging in multi-level tracing in existing technologies, this invention uses hash pointers containing network addressing locators and their corresponding cryptographic hash values as metadata for nested encapsulation. When generating derived data nodes, there is no need for redundant storage of underlying entity data, achieving complete decoupling of the source data node entity and the topology verification structure at the storage level. This method ensures the integrity of the cryptographic tracing chain while keeping the size of derived data nodes extremely lightweight, reducing storage and network bandwidth consumption during verification, and effectively avoiding the risk of tracing logic chain breakage due to failure (dead link) of traditional single hyperlinks, ensuring the reliability of data node reference relationships.
[0029] 2. This invention implements a multimodal nested encapsulation based on dynamic policy adaptation, balancing the needs of ultra-lightweight tracing and high-security offline self-verification. Addressing the resource waste or security risks caused by the lack of flexibility in existing technologies for multi-level tracing, this invention innovatively proposes a reference declaration layer architecture that supports policy adaptation. When executing a lightweight tracing strategy, this invention uses a hash addressing pointer containing a network addressing locator and its corresponding cryptographic hash value as metadata for nesting. When generating derived data nodes, there is no need for redundant storage of the underlying entity data, achieving complete decoupling of the source data node entity and the topology verification structure at the storage level. This method ensures the reliability of the cryptographic tracing chain while keeping the size of the derived data nodes extremely lightweight, significantly reducing storage and network bandwidth consumption during verification, and effectively avoiding the risk of the tracing logic chain breaking due to the failure (dead link) of traditional single hyperlinks. When executing a high-security offline strategy (or a hybrid strategy), this invention supports directly nesting the complete entity supporting the underlying data into a physical encapsulation. This dual mechanism endows the system with strong robustness in offline, weak network, and even extreme adversarial environments, enabling delayed synchronous encapsulation and real-time self-contained verification.
[0030] 3. This invention achieves full lifecycle anti-tampering tracking of multi-data-node flow links, bridging the trust gaps in intermediate links. Addressing the vulnerability of information processing to malicious context tampering or semantic hijacking, this invention employs a multi-layered recursive hash signature encapsulation structure. For the generation, modification, and referencing of data nodes, the hash addressing pointer of the referencing data node is configured to be deeply cryptographically bound to the private key signature of the current publisher during encapsulation. This mechanism establishes non-repudiable accountability, enabling the verification process not only to verify the authenticity of the data node source but also to transparently verify all intermediate data node processing behaviors (including publisher identity, timestamp records, and logical dependencies) throughout the information's lifecycle, effectively blocking security vulnerabilities caused by illegal tampering or malicious referencing of information in intermediate links.
[0031] 4. This invention establishes an automated cascading pruning mechanism based on source dependency relationships, significantly improving the efficiency of identifying and blocking derived fraudulent data. Addressing the technical bottleneck of low efficiency in manual verification under mesh-like referencing relationships, this invention utilizes global source dependency relationships recorded by nested hash pointers to construct a globally automated anti-counterfeiting and early warning network. When a bottom-level data node fails cryptographic verification (determined to be identity forged or content tampered with), it can automatically traverse the persistently stored referencing dependency path in the local state database, triggering a linked failure mechanism (i.e., cascading pruning), simultaneously marking all derived data nodes referencing this invalid data node as contaminated. This mechanism replaces the traditional, heavily manual, one-by-one verification process, greatly reducing the response time for identifying and blocking cross-domain fraudulent information. It not only improves defense effectiveness but also provides a highly robust and universal anti-counterfeiting and source tracing technology foundation for high-value commercial data exchange and the digital content ownership system in the AIGC era.
[0032] 5. This invention endows the system with delayed synchronization encapsulation capabilities in offline or weak network environments, greatly expanding the applicable scenarios and operational flexibility of the invention. Addressing the limitation of traditional traceability systems that heavily rely on real-time network connections for data anchoring, this invention utilizes a content-based addressing (CDO) positioning mechanism, allowing the operator (publisher) to pre-calculate a unique and deterministic network addressing locator for the data entity in a distributed network, even when completely offline. Based on this locally generated hash addressing pointer, the operator can complete the entire nested encapsulation and digital signature process for derived data nodes. When network conditions permit, the encapsulated data nodes are then uploaded in batches to a public storage network for synchronization. This non-real-time architecture of encapsulation followed by synchronization makes the anti-counterfeiting traceability method of this invention applicable to critical scenarios with extremely stringent network connectivity requirements, such as on-site emergency evidence collection and industrial data recording in network-disconnected environments. Attached Figure Description
[0033] Figure 1 This is a flowchart of the cascaded anti-counterfeiting and traceability method based on multi-level hash nesting of the present invention.
[0034] Figure 2 This is a flowchart of a data node generation and encapsulation process according to Embodiment 1 of the present invention.
[0035] Figure 3 This is a flowchart of a traceability chain cascading verification process according to Embodiment 1 of the present invention.
[0036] Figure 4 This is a functional module architecture diagram of an anti-counterfeiting and traceability system according to Embodiment 1 of the present invention.
[0037] Figure 5 This is a schematic diagram of the case evidence chain generation process in Embodiment 2 of the present invention.
[0038] Figure 6 This is a schematic diagram of the case evidence citation relationship in Embodiment 2 of the present invention.
[0039] Figure 7 This is a schematic diagram of the court hearing process in Embodiment 2 of the present invention.
[0040] Figure 8 This is a flowchart of the financial anti-counterfeiting traceability map construction and auditing process in Embodiment 3 of the present invention.
[0041] Figure 9 This is a schematic diagram of the public safety incident information generation process in Embodiment 4 of the present invention.
[0042] Figure 10 This is a schematic diagram of the data node verification process by a third-party organization in Embodiment 4 of the present invention. Detailed Implementation
[0043] To provide a clearer understanding of the technical features, objectives, and effects of the present invention, specific embodiments are now described. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention; that is, the described embodiments are only a part of the embodiments of the invention, not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0044] It should be noted that, after being generated and encapsulated, the data nodes at each level described in this invention can be persistently stored in a publicly accessible storage network (preferably, a decentralized distributed evidence storage network based on IPFS or blockchain) to achieve global addressing, high availability, and persistent storage of data. Furthermore, to accurately explain the logical flow of multi-level hash nesting and tracing topology in this invention, the following terminology definitions are provided for the core data objects and component states: Data node: In this invention, it refers to a cryptographically encapsulated, structured data entity unit. Its internal structure can be divided into two types: Type 1 is referenceless encapsulation, which only contains the content payload, generation timestamp, and corresponding digital signature packet; Type 2 is nested reference encapsulation, which, in addition to containing the content payload, generation timestamp, and signature packet, also contains a set of reference data nodes pointing to its referenced data.
[0045] Hash addressing pointer: In the framework of this invention, this specifically refers to an identification information that combines data retrieval and cryptographic verification functions. Depending on the storage network architecture, this identification information can be resolved into an address locator for the target data within the network and the expected cryptographic hash value. For example, in a centralized network, it can be represented as a data pair consisting of a URL link and an independent hash value; in a content-addressed decentralized network (such as IPFS), it can be represented as a single, composite identifier (such as a CID) that can simultaneously derive the address path and hash checksum through a specific algorithm. Relying on the hash addressing pointer, not only can the data node entity be obtained, but it can also serve as an immutable cryptographic anchor, ensuring the high reliability of data node reference relationships; any minor alteration to the underlying entity will cause hash verification to fail, thereby achieving cross-level anti-counterfeiting and traceability.
[0046] Local state database: Serves as the center for maintaining the state machine and relationships. It is configured to persistently record the hash pointer reference relationships between all data nodes and cache the real-time trust state of each data node. The reference relationships between data nodes form a directed graph, and traversing along the reference direction starting from any node cannot return to the original node.
[0047] Example 1 This embodiment provides a cascaded anti-counterfeiting and traceability method based on multi-level hash nesting, including a nested encapsulation sub-method for data nodes and a cascaded verification sub-method for the traceability chain, as detailed below.
[0048] A. Nested encapsulation of sub-methods for data nodes (generator end).
[0049] S1: Data node generation and encapsulation, see [link / reference] Figure 2 .
[0050] a) Content payload preparation: Prepare the new content payload to be packaged through methods such as collection and processing.
[0051] b) Preparing referenced data nodes (if any): Traverse all historical data nodes that need to be referenced. Based on the preset encapsulation strategy, obtain the core elements used to construct the referenced data node set using one of the following methods: Method 1: Obtain a hash addressing pointer. Obtain or generate a hash addressing pointer representing the referenced data node. The hash addressing pointer contains at least one entity pointer pointing to the referenced target data node; it may also contain an optional source pointer pointing to the source from which the target data node was obtained.
[0052] Method 2: Obtain the complete data entity. This retrieves the complete data entity of the referenced data node.
[0053] Those skilled in the art will understand that, during the encapsulation of a data node, the two methods described above can be used in combination for different reference data nodes.
[0054] c) Construct a set of reference data nodes (if there are reference data nodes): Combine all the hash-addressed pointers and complete data entities obtained in the previous step into a set of reference data nodes.
[0055] d) Combined Payload Construction and Node Hash Calculation: The content payload, generation timestamp, and the aforementioned set of referenced data nodes (if any) are logically concatenated to form a complete payload to be encapsulated. Subsequently, a cryptographic hash algorithm is executed on the payload to be encapsulated to calculate the node hash value.
[0056] e) Digital Signature and Encapsulation Completed: Using at least one publisher's private key, the node hash value is digitally signed to generate a signature packet; when multiple publishers exist, each signature contributes to the data node. Finally, the content payload, generation timestamp, referenced data node set, and the aforementioned signature packet are encapsulated together to form a new data node.
[0057] f) Selective Upload and Publication: After encapsulation, the publisher can decide whether to upload the data node entity to the public storage network based on security policies or network conditions. This action achieves spatiotemporal decoupling between node generation and network publication.
[0058] B. Cascaded verification sub-method of the traceability chain (verification end), see [link / reference] Figure 3 .
[0059] S2: Recursive verification of the reverse traceability chain When the verification client needs to verify any data node, the following recursive verification process is initiated: S2.1: Pre-state interception and judgment First, query the local status database. If the query result indicates that the node already has a definite verification status (such as "trusted" or "invalid"), then directly output the final verification result based on that status and terminate subsequent verifications; otherwise, proceed to the next step.
[0060] S2.2: Analysis and Separation The current data node to be verified is subjected to structured parsing. This step aims to separate four logical parts from the binary data block according to a preset data encapsulation protocol: content payload, generation timestamp, reference data node set (if it exists), and signature packet, for use in subsequent verification and recursive verification.
[0061] S2.3: Cryptographic School Verification It includes a cryptographic double-check mechanism. The first layer of identity verification: decryption verification is performed using the public key corresponding to the signature packet. When multiple signatures exist, each signature must pass verification. If decryption fails, the signature is deemed invalid, and the process proceeds to S2.4. The second layer of content integrity verification: if the signature decryption is successful, the expected node hash value is extracted; then, the actual hash value is calculated in real-time for the locally parsed combined payload (content payload, generation timestamp, and referenced data node set). If the two hash values do not match, the content is determined to have been tampered with, and the process proceeds to S2.4.
[0062] Only when the above cryptographic double verification passes can we be certain that the content payload parsed in S2.2, the timestamp generated by this node, and the set of referenced data nodes are authentic and reliable, and then proceed to the recursive operation in S2.5.
[0063] S2.4: Handling Verification Failures Record the currently verified data node (the initial node to be verified or the referenced data node being recursively explored) as a failed node, terminate the verification process, and start the S3 cascade pruning process from the failed node.
[0064] a) S2.5: Recursive probing of reference data nodes to check for the existence of reference data nodes: Check the internal structure of the data node to be verified to determine whether there are underlying reference data nodes.
[0065] b) If no data node is referenced: This indicates that the current branch has been traced to its end, the current data node has been verified, and the verification is returned.
[0066] c) If a reference data node exists: For each reference data node, first query the local state database to intercept the pre-state; if there is no definite verification state, then obtain the underlying reference data node entity. Subsequently, for each obtained reference data node, perform the following steps: Recursively execute basic verification: For this underlying reference data node, recursively repeat the verification process (i.e., execute loop calls from S2.1 to S2.5), embed a time-series causal comparison process between S2.2 and S2.3, until tracing back to the end of all branches; Timing Causality Verification (Optional): After S2.1 and S2.2 are completed, the generation timestamp of the parsed reference data node is compared with the generation timestamps of all its direct parent data nodes. If the generation time of the underlying data node is earlier than that of its direct parent data node (i.e., no causal reversal has occurred), then S2.3 to S2.5 are continued. If a causal reversal occurs, the reference link is considered to have been maliciously tampered with. At this time, the hash verification result of the underlying data node is checked. If it fails, the underlying data node is deemed to have failed verification; if it passes, the parent data node is deemed to have failed verification, and the process proceeds to S2.4 to handle verification failure.
[0067] S2.6: Closed-loop update of the local state database In the recursive verification process (preferably, updating occurs during the regression phase of recursive verification, i.e., when the verification result is returned from the bottom layer to the top layer, to avoid writing invalid intermediate states that would then be corrected by the S3 cascading pruning step), a closed-loop update is performed on the relevant records in the local state database based on the obtained verification results. The latest trust status (such as trusted, invalid, or contaminated) corresponding to each data node is appended to or overwritten to the database, while binding the current timestamp. This closed-loop update provides a reliable state basis for the pre-interception of subsequent verifications.
[0068] S2.7: Cache Eviction and State Degradation (Optional) The local state database can be configured to implement timestamp-based lifecycle management strategies. For example, when any data node in the database is in a deterministic state (such as trusted, invalid, or contaminated), and the time interval since its last verification timestamp exceeds a preset effective threshold, its trusted state can be automatically rolled back to its initial state, forcing recursive verification on the next access. Simultaneously, based on a cache eviction algorithm, edge data nodes in uncertain states and with extremely low reference frequency can be periodically cleaned up to prevent the local state database from becoming excessively bloated.
[0069] S3: Automated Cascade Pruning Based on Source Dependency Relationships S3.1: Automated Cascade Pruning Start: Start the cascade pruning process with the failed data node as the root node.
[0070] S3.2: Dependency traversal of associated nodes: The pruning engine starts from the root node and, based on the reference dependencies recorded in the local state database, initiates an association traversal search to all (direct or indirect) successor data nodes of nodes whose references have failed.
[0071] S3.3: Batch Blocking and Status Update: Automatically identify all (directly or indirectly) derived data nodes that reference the failed data node. Change the trust status of these derived data nodes in batches, marking them as contaminated, thereby achieving automated failure marking of the failure propagation chain.
[0072] S3.4: Global Early Warning Broadcast (Optional): After completing cascading pruning, generate one or more early warning statements containing the characteristics of the failed data nodes and the reasons for the failure, and attach a digital signature. Broadcast and synchronize this early warning statement to an external network or a third-party verification system to achieve cross-domain collaborative blocking of the failure state.
[0073] It should be noted that in the above method steps, each specific operation can be performed by different system hardware and software modules. Those skilled in the art should understand that the functional division of modules is not the only limitation on the core method steps of this invention. For example, in a preferred embodiment, the pre-state interception and task distribution are handled by an independent module, while all computationally intensive tasks such as parsing, local signature verification, pull interface calls, and recursive verification are uniformly handled by another cryptographic verification module to achieve high logical cohesion. In other optional embodiments, the preliminary parsing action and the purely cryptographic logic comparison calculation can also be decoupled to different modules for execution. The scope of protection of this invention covers all functional modules or system architectures capable of implementing the above core method steps.
[0074] Accordingly, this embodiment provides a cascaded anti-counterfeiting and traceability system 200 based on multi-layer hash nesting, including a generation terminal system and a verification terminal system. To clearly illustrate the processing flow and functional division of this invention, the system is described below and in the accompanying drawings as several logically independent modules.
[0075] It should be noted that the module structure and function allocation described below are merely a typical and preferred embodiment of the present invention, and not the sole limitation thereof. In actual software and hardware engineering deployments, those skilled in the art will understand that the core functions of these logically independent modules (such as 220, 230, and 240) can be implemented either through highly integrated methods (such as merging them into a unified verification engine) or through more fine-grained decomposition. The scope of protection of this invention covers all system architectures and functional module combinations capable of implementing the above-described method steps.
[0076] A. Generation terminal system See Figure 4 This subsystem is responsible for executing the nested encapsulation step S1 in the method, which mainly includes: Encapsulation and Signature Module 210: Receives raw data and referenced data (if any), generates a timestamp for the node, and constructs a set of referenced data nodes. It then performs node hash calculation and digital signature on the combined payload, including the content payload, the timestamp, and the set of referenced data nodes, to generate traceable, anti-counterfeiting data nodes that conform to a nested encapsulation structure.
[0077] B. Verification terminal system See Figure 4 This subsystem is responsible for executing the traceability chain verification step S2 and the cascading pruning step S3 in the method, and mainly includes: Source tracing and parsing module 220: Configured to receive data nodes to be verified and perform preliminary state evaluation. This module interacts with the local state database 260 to query the cached state of the data nodes to be verified in order to achieve preliminary interception. If the state of the data node needs further verification, this module triggers (or delegates to) the cryptographic verification module to perform deep parsing and verification.
[0078] Cryptographic verification module 230: Configured to execute the core asymmetric encryption signature verification and content hash comparison algorithm. When verifying derived data nodes, this module can recursively parse the internal reference list, append the derived data node and its reference data nodes to the local state database, and obtain the underlying reference data node entities through the addressing and retrieval interface module 250 for cyclic verification, while updating the status of the verified data nodes in the local state database. If verification fails, the failed data node is sent to the cascading pruning module 240, triggering the cascading pruning process.
[0079] Cascaded Pruning Module 240: Starting from the failed data node, this module traverses the derived data nodes in the local state database that directly or indirectly reference the failed data node, and updates the trust status of all derived data nodes to contaminated in batches.
[0080] Addressing and fetching interface module 250: Configured to initiate requests to external networks or public registry based on the incoming (or received) hash addressing pointer in order to achieve on-demand fetching of underlying reference data node entities.
[0081] Local State Database 260: Serving as the core hub and state cache center of the verification subsystem. This database is responsible for persistently storing two core pieces of information: first, the data node reference dependencies parsed from all historical verifications; and second, the verification status of each data node ("trusted," "invalid," "contaminated," etc.) and its verification timestamp. It provides pre-processing state query services for the source tracing and parsing module, and supports dependency-based traversal and batch state updates for the cascading pruning module.
[0082] Specifically, the following will describe in detail the specific operating mechanism of the cascaded anti-counterfeiting and traceability method and system based on multi-layer hash nesting of the present invention, combined with specific application scenarios in three different technical fields. It should be noted that the data node flow and verification process in the following embodiments all follow the aforementioned system architecture and method steps of the present invention by default.
[0083] In addition, the trust states maintained in the local state database in the following embodiments include the following five types, and each embodiment will select the required state for description: Unknown: Initial state, not yet verified, or verification status timed out; Pending: A task has already initiated a verification request for this data node and is currently performing computation or network fetching. This status is used to prevent duplicate computing power consumption under concurrent verification. Trustworthy: The data node has passed causal timing verification and cryptographic verification (signature verification and hash verification), and all its multi-level reference data nodes have passed verification; Failure: The digital signature of the data node is invalid (identity forgery), or the content hash comparison fails (content is tampered with), or there is a node time sequence reversal, which is a source of data node pollution; Contaminated: The referenced data nodes contained in the data node are "invalid", a trust degradation state triggered by the cascading pruning mechanism.
[0084] Example 2 This embodiment is based on embodiment 1: This embodiment provides a cascaded anti-counterfeiting and tracing method based on multi-level hash nesting, which is applied to the judicial electronic evidence chain of nested encapsulation and responsibility decoupling.
[0085] Background: In a certain case, judicial authorities need to extract, authenticate, and present various forms of electronic evidence (such as body camera videos, hard drive image files, expert reports, etc.) in court. All evidence entities are stored by default in a distributed evidence storage network overseen by a judicial consortium.
[0086] This embodiment aims to fully demonstrate the entire operational mechanism of the present invention, from the generation of underlying evidence to the examination in court, highlighting the following three core technical features: First, there is a progressive responsibility endorsement: demonstrating how to use the multi-layer hash nested encapsulation mechanism proposed in this invention to nest and encapsulate the personal signature of the operator of the evidence with the unit signature of the upper-level aggregation agency through serial (nested) signature, thereby constructing a clear and irrefutable electronic evidence chain.
[0087] Second, it demonstrates flexible, on-demand citation and decoupling of responsibility: showcasing how data processing nodes (such as third-party authentication centers) can safely and flexibly cite necessary evidence without assuming prior traceability and verification obligations. The final responsibility for determining authenticity rests with the verification end (the court).
[0088] Third, efficient caching accelerates verification: This demonstrates how the verification end (court) can utilize a local state database to achieve cache hits on verified nodes when processing evidence sets with complex network reference relationships, thereby avoiding redundant calculations and network overhead.
[0089] 1) Evidence generation stage (corresponding to step S1 in Implementation Example 1), see Figure 5 .
[0090] S301: Generation and Packaging of Law Enforcement Recorder Videos a) Law enforcement officers using body cameras to record on-site video. A1 The body camera calls a built-in hash function (such as the SHA-25 algorithm) based on Data. A1 The node hash value NodeHash is calculated from its generation timestamp. A1 Then, the private key from the body camera is used to access the NodeHash. A1 Perform digital signature generation A1 Finally, the Data A1 Generate timestamps and Signatures A1 Pack the data according to the predetermined format to form a hardware-encapsulated video data node A1; b) Law enforcement officers used body cameras to record multiple video clips of the scene, repeating step a) to create hardware-encapsulated video data nodes A2, A3…A10. Because the body cameras were not connected to the network, these data nodes were stored locally on the device and not uploaded to the evidence storage network. S302: Generation and Encapsulation of Law Enforcement Video Evidence a) Law enforcement officers record information such as the video recording location and the event as the content payload. A ; b) Law enforcement officers examine data nodes A1 to A10 and select A1, A3, and A10 as reference data nodes; c) Since the data is obtained from the device, the hardware-encapsulated data nodes are not uploaded to the evidence storage network. Therefore, the "complete data entity" is directly referenced to form a "video reference data node set" consisting of data entities A1, A3, and A10. d) Law enforcement officers will load the content data. AThe generated timestamp and the "video reference data node set" are logically concatenated to form a complete payload to be encapsulated. Then, the node hash value NodeHash is calculated based on the payload to be encapsulated. A ; e) Access the node hash value NodeHash using the private key of law enforcement personnel. A Perform digital signing and generate a signature package. A Finally, the content payload Data A Generate timestamps, video reference data node sets, and signature packets. A The data is jointly packaged to form law enforcement video evidence data node A; f) Calculate the hash address pointer CID of the data node. A And upload it to the Judicial Alliance Distributed Evidence Storage Network.
[0091] S303: Generation and Packaging of Disk Image Evidence Data extraction personnel extracted the hard drive image file Data from the suspect's computer B The node hash value NodeHash is obtained by hashing the timestamp generated by the node. B Based on NodeHash B This data is used to extract the user's private key and form a signature packet. B Overall, a hard disk image evidence data node B (Data) is formed. B Generate timestamps and Signatures B (The combination of these factors). Calculate the hash address pointer CID of the data node. B And upload it to the Judicial Alliance Distributed Evidence Storage Network.
[0092] S304: Generation and Packaging of Case Files The case-handling unit's personnel responsible for packaging the case files received the electronic file of video evidence data node A, as well as the hash address pointer CID of hard disk image evidence data node B. B Begin packaging the case files: a) Enter basic information from the case file. C ; b) Based on the content payload of the file of video evidence data node A, calculate the unique content-based hash address pointer (CID) of this data node in the network. A ; c) Using CID A and CID B This constitutes a "collection of referenced data nodes"; d) Based on combined load (Data) C(Generate timestamps, set of dossier reference data nodes) Calculate the node hash value NodeHash C ; e) Based on NodeHash C Signature using the private key of the dossier packer 卷宗 Because it needs to be delivered to an external unit, the private key of the case-handling unit is then used to access the Signature. 卷宗 Signature forms a nested signature structure C Encapsulate and form case file data node C; f) Calculate the hash address pointer CID of the data node. C And upload it to the Judicial Alliance Distributed Evidence Storage Network.
[0093] S305: Generation and Packaging of the Test Report The forensic center receives the hash-addressed pointer CID of case file data node C. C After retrieving the data from the judicial evidence preservation network, it was found that only the hard disk image evidence data node B referenced therein was needed to issue the appraisal report.
[0094] a) The forensic center extracts the hard disk image evidence, specifically the hash address pointer CID of data node B, from the reference set of data node C. B The data entity of data node B is retrieved from the evidence storage network for technical authentication, and an authentication report is written. D ; b) When constructing the set of referenced data nodes for data node D, to ensure that not only the target data entity (data node B) is anchored, but also the legitimate transfer source of that data (data node C), the following two encapsulation paths are provided: Path 1 (Implicit reference to the overall dataset): Directly references the parent node (case file data node C). This method simplifies the encapsulation process, but will trigger redundant calculations on unrelated data nodes (such as node A) during subsequent verification; Path Two (Explicit Anchoring of Two Types of Pointers): Employing a typed reference pointer design. The hash-addressed pointers are divided into two categories: one is the "entity pointer" (referring to data node B), and the other is the "source pointer" (the source data node C of data node B). This method achieves precise referencing while confirming the source of the data. c) Based on the preset strategy, use the CID of path one. C or a combination of path two (CID) B As an entity pointer, CID C (As a source pointer), forming a "set of identified reference data nodes"; d) Based on Data DThe node hash value NodeHash is calculated from the generated timestamp and the set of data nodes used for identification. D ; e) Use the authenticater's private key to access NodeHash D Complete the signing process to obtain the Signature 鉴定 Then use the private key of the authentication center to verify the Signature 鉴定 Signature forms a nested signature structure D The data node D of the identification report is encapsulated.
[0095] f) The chain of evidence dependencies formed by the above process, see [reference]. Figure 6 .
[0096] 2) During the court verification stage, see [reference needed]. Figure 7 .
[0097] S306: Determine the verification order During the court hearing, the court system received the aforementioned evidence set (case file data node C provided by the case-handling agency and expert report data node D provided by the expert appraisal center) and prepared to verify the evidence. Based on the generation timestamps in each data node, a strategy of "tracing back based on the generation timeline (tracing from the latest derived data node to the underlying source data node)" was adopted, first verifying data node D, and then verifying data node C.
[0098] S307: Verification and authentication report data node D (corresponding to step S2 in Example 1) The court system first initiates a verification request for data node D of the expert report submitted by the expert center, and initiates the following verification process: a) Pre-interception (S2.1): Query the status of data node D in the local status database, find that it is "unknown", and proceed to deep analysis and verification; b) Parsing and Separation (S2.2): Parse data node D, extract its content payload, generate a timestamp, reference data node set, and signature packet. The reference data node set may be encapsulation path one (containing only the CID of data node C). C ), or a combined pointer encapsulating path two (containing CID) B As an entity pointer, CID C (as a source pointer) c) Cryptographic Verification (S2.3): Verify the authenticity of the authentication agency's signature and the authentication personnel's signature, as well as the integrity of the data node D's content. Upon successful verification, initiate the recursive traversal of the corresponding path below; d) Recursive exploration of referenced data nodes and updates to the local state database (S2.5, S2.6): If it is encapsulation path one (implicit reference CID of the entire dataset) C ): If the status of data node C is "unknown", then the case file node C will be automatically located and retrieved via the network; identity verification and hash verification will be performed on node C. After the verification passed, the analysis revealed that it further referenced the underlying data nodes A and B; Query and retrieve data nodes A and B with a status of "unknown", and perform signature verification and hash verification on A and B respectively; If both cryptographic verifications of A and B pass, data node B has been traced to the end of the referencing link. Device-level signature verification and hash verification are then performed on data nodes A1, A3, and A10 referenced by data node A. If all verifications pass, data node A has also been traced to the end of the referencing link, and the link verification is complete. The states of data nodes A1, A3, A10, A, B, C, and D are uniformly updated in the local state database and marked as "trusted".
[0099] If it is encapsulation path two (explicit anchoring of two types of pointers: CID) B Entity + CID C source): Source legitimacy verification: Retrieve data node C and perform signature verification and hash integrity checks on it. After successful verification, parse the set of referenced data nodes of data node C to verify that it does indeed reference data node B, thus confirming that the legitimate source of data node B is the investigating agency C.
[0100] Entity data verification: If the status of data node B is "unknown", retrieve the entity of data node B via the network. Perform signature verification and hash verification on it. If both verifications pass, data node B has been traced to the end of the referencing link, and the status of data node B and data node D is updated to "trusted" in the local status database.
[0101] S308: Verify case file data node C (corresponding to step S2 in Implementation Example 1) After verifying data node D of the expert report, the court initiated a verification request for data node C of the case file submitted by the case-handling agency, and started the following verification process: a) Pre-interception (S2.1): Query the local state database. If data node D uses encapsulation path one (implicit reference to data node C as a whole), then in the verification of S307, data node C has passed the verification and been marked as "trusted". At this time, the system triggers state interception, and this verification ends immediately and returns success; if data node D uses encapsulation path two (explicit anchoring of two types of pointers), then the current state of data node C here is "unknown", and proceed to the subsequent parsing steps; b) Parsing and Separation (S2.2): Parse the content payload, generation timestamp, reference data node set and signature packet of data node C, and find that its reference data node set contains the hash address pointers of the underlying video evidence data node A and the hard disk image evidence data node B; c) Cryptographic Verification (S2.3): Verify the authenticity of the signatures of the investigating agency and personnel, and the integrity of data node C. After successful verification, initiate recursive traversal. d) Recursive probing and state update of referenced data nodes (S2.5-S2.6): During the underlying recursive verification process, the local state database can be relied upon to fully leverage caching acceleration performance. Regarding data node B (hit trusted cache) as evidence of the hard disk image: During the query of the local state database, it was found that data node B had been verified and marked as "trusted" in the previous step (S307). At this time, the system triggers the pre-interception mechanism, and the verification of data node B is completed; For video evidence data node A (deep verification performed): A query of the local state database reveals that data node A's trust status is "unknown". The hash address pointer of data node A is extracted, and based on this pointer, the entity data of node A is retrieved from the evidence storage network. Parsing this entity reveals internal physical nesting (the complete data entity references) of data node entities A1, A3, and A10 generated by the underlying devices. First, the law enforcement officer's public key is used to verify the identity of data node A and complete a hash integrity comparison. If the cryptographic verification passes, device-level signature verification and hash verification are performed on the referenced data nodes A1, A3, and A10 respectively. If all the above cryptographic verifications are correct, the link verification is complete, and data node A has been traced to the end of the reference link. The system updates the status of data nodes A1, A3, A10, A, and C to "trusted" in the local state database.
[0102] In summary, through the above-described end-to-end deduction from the generation of underlying evidence to the examination in court, this embodiment fully demonstrates the multiple technical advantages of the present invention in complex judicial scenarios. First, through progressive signature nesting, a clear and irrefutable chain of electronic evidence is constructed. Second, by supporting flexible on-demand citation and liability decoupling, the efficiency of cross-institutional collaboration (such as expert evaluation) is significantly improved while ensuring the legitimate source of evidence. Finally, through an efficient caching mechanism to accelerate verification, when faced with complex evidence sets with networked citation relationships, this system only requires computational power and network overhead that is approximately linearly related to the citation path length to complete deterministic automated verification based on cryptographic proofs. In conclusion, this embodiment provides a solution for the field of judicial electronic evidence storage that combines security, flexibility, and high efficiency.
[0103] Example 3 This embodiment is based on embodiment 1: This embodiment provides a cascaded anti-counterfeiting and traceability method based on multi-level hash nesting, which carries out financial anti-counterfeiting and traceability graph construction and cross-auditing based on a centralized network.
[0104] Background: In a commercial bank's centralized network, various business lines frequently receive and process massive amounts of external entity documents (such as scanned copies of paper invoices, customs declarations, etc.). In the traditional model, these documents are often scattered as independent attachments across different departments' business systems, making global comparison difficult. This embodiment uses the prevention of the same invoice being reused multiple times (for credit and remittance) as a case study to demonstrate how external entity documents can be incorporated into the underlying anti-counterfeiting and traceability database and automatically discovered by cross-departmental verification tasks.
[0105] This embodiment aims to demonstrate how to regulate the entry of external multi-source entity files into a centralized network environment, and how to achieve automatic discovery and source tracing blocking across business links based on file fingerprints. It highlights the following three core technical features: First, there is the hybrid nested encapsulation technology: within a single data node, pointer references and entity references can be used simultaneously to achieve on-demand lightweight combination of multi-source heterogeneous data; Second, the payload fingerprint mapping mechanism: core credentials are extracted from data nodes, and the pure physical flow calculation file fingerprint (FileHash) is extracted separately. A low-level mapping table of fingerprint-data node hash addressing pointers is established in the local state database so that the same credential file can be identified in different business tasks.
[0106] Third, cross-verification based on graph index: At the verification end, the local state database can not only perform reverse recursive verification and tracing, but also quickly retrieve all data nodes in the global network that reference the entity when the underlying file fingerprint collision is triggered.
[0107] 1) Company A applies for a loan from the bank's credit department. (See attached document) Figure 8 .
[0108] S401: Encapsulation of Loan Application for Company A Company A constructs a loan application data node A, whose payload includes the loan amount, purpose, and a "Large Purchase Invoice.pdf". After hash calculation, it is signed using Company A's private key. Company A submits the loan application data node A to the bank's credit department to apply for a loan.
[0109] S402: Credit Department Verification and Document Fingerprint Mapping a) The credit department verifies the signature of loan application data node A and extracts the hash. A Based on this index, it was found that the local state database does not yet have this data node, confirming that data node A is a new data node; b) Perform a hash check on data node A. If the check passes, it means that the data node has not been tampered with. c) Perform the upload action to synchronize data node A to the server and obtain the URL assigned by the system. A This is combined with the hash value of the file to form a hash addressing pointer; d) Data node A is parsed, and "important trade documents" are identified, triggering the document anti-reuse mechanism. The system performs hash calculation on the content of the file "Large Purchase Invoice.pdf" to obtain an independent file fingerprint, FileHash. A If the system determines that there is no matching fingerprint file in the "load fingerprint mapping table" of the local state database, it will store the entity file in the centralized server. e) Create a FileHash in the "Payload Fingerprint Mapping Table" of the local state database. A The mapping relationship between the hash addressing pointer of data node A and the storage path of the entity file.
[0110] S403: Credit Department completes loan approval a) The credit department completes due diligence, generates and signs the "Risk Assessment Report.pdf", and establishes risk report data node B. Since this assessment report is only relevant to this approval process and does not require independent node addressing across the entire network, it is not uploaded separately but will be reserved for further entity nesting in the next step. b) The credit department completes the loan approval and forms the loan approval data node C, which references the loan application data node A in the form of a pointer and the risk report data node B in the form of an entity. After completing the hash calculation, it is signed with the credit department's private key and the upload action is performed to synchronize to the server.
[0111] 2) One month later, Company B applied to the bank's compliance department for overseas remittance. (See attached document) Figure 8 .
[0112] S404: Company B's remittance application for packaging Company B (a hidden affiliate of Company A) uses the same "Large Purchase Invoice.pdf" to complete the hash calculation, signs it with Company B's private key, constructs remittance application data node D, and submits it to the bank's compliance department.
[0113] S405: Compliance Department Verification and Fingerprint Collision a) The compliance department verifies the signature and hash of the remittance application data node D. After indexing, it finds that it is a new data node and uploads data node D to the server. b) Identify that its payload contains "important trade documents", extract the pure physical file, and calculate the file fingerprint (FileHash). D ; c) By comparing the "payload fingerprint mapping table", the Compliance Department discovered FileHashD With FileHash A The files were completely identical, pointing to the same physical file, "Large Purchase Invoice.pdf", which triggered the audit.
[0114] S406: Audit Department's Source Tracing and Intervention a) The audit department retrieved the loan application data node A, which was added a month ago, through the mapping relationship. According to the graph index, it was found that data node A has been referenced by loan approval data node C.
[0115] (b) Although Company B compliantly generated a brand-new data node D, its core payload exhibited cross-business "physical overlap" in the underlying graph. The auditing department determined this to be a serious "multiple uses of a single invoice" risk and directly blocked the remittance process.
[0116] In summary, through the above deductions, this embodiment fully demonstrates the three major application values of the present invention in financial cross-audit scenarios: First, through hybrid nested encapsulation, it achieves lightweight structuring of business processes, avoiding unnecessary duplicate disk storage. Second, through the fingerprint mapping mechanism, it breaks down data silos between parallel business lines, accurately locating the same underlying physical voucher while fully ensuring the business execution of each department. Finally, relying on the indexing characteristics of the graph, this embodiment upgrades the traditional passive post-event audit to proactive, real-time blocking.
[0117] Example 4 This embodiment is based on embodiment 1: This embodiment provides a cascaded anti-counterfeiting and tracing method based on multi-level hash nesting, which is applied to the automated cascaded blocking of AIGC false information in the tracing graph.
[0118] Background: During a sudden public safety incident, a large amount of related information spread on internet social media platforms, including official announcements, media reports, and some data fabricated by generative artificial intelligence (GAI). To efficiently verify this information flow, the verification system of this invention is deployed as the background automated verification engine for third-party fact-checking organizations. All referenced underlying data node entities are stored by default in a publicly accessible decentralized storage network.
[0119] In the field of open-source information anti-counterfeiting and traceability, to achieve efficient storage and rapid traceability traversal of massive data node relationships (i.e., S3 cascading pruning), the local state database in this embodiment is preferably deployed using a graph database (such as Neo4j). In the graph database architecture, data node entities are mapped to "vertices" in the graph, and their trust states (such as "trustworthy" or "contaminated") are stored as "attributes" of the vertex; while the reference relationships between data nodes are mapped to "directed edges" between vertices. Through this mapping, the system can construct a directed acyclic graph (DAG) within the graph database, establishing dependencies between nodes to facilitate efficient dependency traversal and failure propagation analysis. This implementation maximizes the query efficiency of the cascading pruning algorithm during depth-first search (DFS). Those skilled in the art will understand that in other implementation scenarios with lower query performance requirements or a smaller number of data nodes, the above logical reference relationships and state caching can also be equivalently implemented by establishing a "data node state table" and a "reference relationship mapping table" using a traditional relational database (such as RDBMS).
[0120] This embodiment aims to demonstrate how the anomaly handling mechanism (cascading pruning) of this invention achieves rapid tracing and automated removal of misinformation from the same source in a decentralized storage and complex mesh reference environment, highlighting the following three core technical features: First, deep source tracing mapping based on graph databases: demonstrating how to transform the hash pointer reference relationship of data nodes from a linear data structure into "directed edges" in graph databases (such as Neo4j). Leveraging the efficient traversal characteristics of graph databases (such as Depth-First Search (DFS), it provides performance support for high-concurrency, deep-level source tracing in massive information networks.
[0121] Second, the automated cascading pruning of "poisonous tree fruit": In the complex derivative information chain, once the system locates the "poisonous source" node with illegal identity or tampered content at the bottom layer, how to use graph indexing to automatically and in batches mark all upper-level derivative nodes that directly or indirectly refer to the poisonous source as "contaminated", thereby avoiding the waste of computing power for verification one by one.
[0122] Thirdly, proactive state interception and broadcast immunity: This demonstrates how the system can instantly intercept verification processes with a confirmed verification status at the very beginning of the "state query" stage by updating the local state cache. By broadcasting a standardized blacklist with signatures across the entire network, subsequent verification requests for other misinformation from the same source are also immediately completed because they are marked as "contaminated," achieving proactive defense through network-wide collaboration.
[0123] 1) Information generation, see reference Figure 9 .
[0124] S501: Information generation (corresponding to step S1 in Embodiment 1) a) The forger used GAI to generate a fake viral gene sequence map and signed it with an unknown private key to encapsulate it as data node A; b) Official medical institutions release real case statistics, and the official private key signature of the medical institution is used to encapsulate data node B; c) An "expert" writes an analysis article based on data nodes A and B, signs it with the expert's personal private key, references nodes A and B in a pointer manner, and encapsulates it as data node C; d) Multiple media outlets cited expert article data node C for derivative reports, each using its own official private key to sign the data node C and referencing it via pointers, encapsulating it into derivative data nodes D, E, and F.
[0125] 2) Cascaded verification, see [link / reference] Figure 10 .
[0126] S502: Information verification and blocking trigger (corresponding to step S2 in Implementation Example 1) A third-party fact-checking organization receives a verification request for a media report (data node D) and initiates recursive verification: a) State interception (S2.1): Query the local state graph database built on Neo4j, find that the trust state of data node D is "unknown", and proceed to verification; b) Parsing and First-Level Verification (S2.2-S2.3): Parse data node D, use the public key of the medium to perform signature verification, confirming that the signature is valid and has not been tampered with. Extract the hash address pointer of its reference data node C; c) Recursive probing (S2.5): Retrieve data node C, perform signature verification using the expert's public key, and confirm that the signature is valid and has not been tampered with. Analysis reveals that it references data nodes A and B; d) Discovery of the underlying source of infection (abnormal trigger S2.4): Continue recursively fetching the underlying nodes A and B. Signature verification on official node B is successful. However, when verifying data node A, the system discovers that the public key corresponding to its signature is not on the whitelist of authoritative public health event publishers (i.e., unauthorized / illegal identity). The system immediately determines that data node A is a fake source of infection, interrupts the current verification process for D, and triggers the cascading pruning mechanism (S3).
[0127] S503: Trigger cascaded pruning (corresponding to step S3 in Example 1) a) Failed data node marking (S3.1): Mark data node A as "failed" in the local state database.
[0128] b) Traverse the source map (S3.2): Starting from data node A, traverse along the reference relationships in the source map, and automatically identify that data node C (directly references A) and data nodes D, E and F (indirectly reference A) all depend on data node A.
[0129] c) Batch status update (S3.3): Update the status of data nodes C, D, E and F in the database to "contaminated".
[0130] S504: Global Broadcast (S3.4) a) Generate a structured early warning statement: After completing local cascading pruning, the verification agency's system automatically generates a standardized "Data Node Failure Early Warning Statement." This statement specifically includes the following core fields: Characteristics of the source data node: The hash addressing pointer of data node A; Failure reason codes: For example, ERR_SIG_INVALID (digital signature forgery) or ERR_HASH_MISMATCH (content tampering). List of contaminated derived data nodes (optional): Hash address pointers for data node C and data node D, used to improve the interception efficiency of other systems; b) Digital signature of the warning statement: The warning statement is digitally signed using the official private key of the verification agency to ensure the non-repudiation of the warning information itself; c) Broadcast and Collaborative Interception: Broadcast the signed warning statement to a publicly available distributed blacklist registry (such as a blockchain-based threat intelligence sharing smart contract). Other independently operating OSINT analysis systems or social media platforms worldwide, after subscribing to this registry, can instantly implement cross-domain collaborative blocking in their local S2.1 step (pre-emptive state interception) upon receiving a verification request containing the aforementioned hash-addressed pointer.
[0131] Through the above deduction of false information flow in public safety emergencies, this embodiment demonstrates the technical superiority of the cascading pruning method of the present invention in dealing with massive and complex data in the AIGC era. First, by introducing a graph database architecture (such as Neo4j), the traditional cryptographic hash pointer chain is extended into an evidence graph with complete dependency expression capabilities, greatly improving the computational efficiency of deep relation traversal and source tracing, breaking through the performance bottleneck of relational databases when handling high-concurrency, network-nested data. Second, the innovative "cascading pruning" mechanism effectively solves the "poisonous tree fruit" problem in the source tracing system. The system only needs to accurately identify the "poisonous source" to discover and remove all derivative nodes through the graph. Finally, combined with a global state cache and blacklist broadcasting mechanism, the verification results of a single system can be transformed into network-wide defense rules, achieving rapid interception of homologous variant false information. In summary, this embodiment provides a fundamental technical paradigm for building a trusted internet and open-source intelligence (OSINT) governance that combines penetration, automated blocking, and network-wide collaborative effectiveness.
[0132] Example 5 This embodiment is based on embodiment 1: This embodiment provides a computer device, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the cascaded anti-counterfeiting and traceability method based on multi-level hash nesting of Embodiment 1. The computer program can be in the form of source code, object code, executable file, or some intermediate form.
[0133] Example 6 This embodiment is based on embodiment 1: This embodiment provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the cascaded anti-counterfeiting and traceability method based on multi-level hash nesting described in Embodiment 1. The computer program can be in the form of source code, object code, executable file, or some intermediate form. The storage medium includes any entity or device capable of carrying computer program code, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0134] The above description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the concept described herein through the above teachings or related technologies or knowledge. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.
[0135] It should be noted that, for the sake of simplicity, the foregoing method embodiments are described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
Claims
1. A cascaded anti-counterfeiting and traceability method based on multi-level hash nesting, characterized in that, include: The content payload to be encapsulated, the generation timestamp, and the set of reference data nodes are combined to form the payload to be encapsulated, and the node hash value of the payload to be encapsulated is calculated. The node hash value is signed using the publisher's private key, encapsulated to form a new data node, and the reference relationship between each data node is persistently recorded. The set of referenced data nodes includes hash addressing pointers and complete data entities. The hash addressing pointer is an identification information that combines data retrieval and cryptographic verification functions. Depending on the storage network architecture, the identification information can be parsed into the addressing locator of the target data in the network and the expected cryptographic hash value. The system performs cryptographic verification on the identity and content integrity of the data nodes to be verified. After the verification is successful, it recursively verifies all the underlying data nodes referenced and updates the trust status of each data node synchronously. When a failed data node is detected, all derived data nodes that directly and indirectly reference the failed data node are traversed according to the recorded reference dependencies, and the contaminated status of the derived data nodes is marked in batches. After the verification passes, all referenced underlying data nodes are recursively verified, and the trust status of each data node is updated synchronously. This includes: after the verification passes, if the current data node has referenced data nodes, the verification is recursively performed for each referenced data node until the end of each branch is traced, and the trust status of each data node is updated synchronously. The trust status includes trusted status, invalid status and contaminated status.
2. The cascaded anti-counterfeiting and traceability method based on multi-level hash nesting according to claim 1, characterized in that, The process of combining the content payload to be encapsulated, the generation timestamp, and the set of reference data nodes to form the payload to be encapsulated, and calculating the node hash value of the payload to be encapsulated, includes: Iterate through all historical data nodes that need to be referenced, obtain the hash address pointer and complete data entity of the corresponding referenced data node, and combine the obtained hash address pointer and complete data entity to construct a set of referenced data nodes; Prepare a new content payload to be packaged. Logically concatenate the content payload, generation timestamp, and reference data node set to form the payload to be packaged. Perform cryptographic hash calculation on the payload to be packaged to obtain the node hash value.
3. The cascaded anti-counterfeiting and traceability method based on multi-level hash nesting according to claim 2, characterized in that, The step of signing the node hash value using the publisher's private key, encapsulating it to form a new data node, and persistently recording the reference relationships between each data node includes: The node hash value is digitally signed using at least one publisher's private key to generate a corresponding signature package. When there are multiple publishers, each signature is used as a component of the data node. The content payload, generation timestamp, set of referenced data nodes, and signature package are encapsulated together to form a new data node, and the reference relationship between the new data node and each referenced data node is persistently recorded. After the new data node is encapsulated, the system selects whether to upload the data node entity to the public storage network based on the preset security policy or network conditions; it uses a directed acyclic graph structure to organize and persistently store the reference relationships between all data nodes, ensuring that traversing along the reference direction from any node cannot return to the node itself.
4. The cascaded anti-counterfeiting and traceability method based on multi-level hash nesting according to claim 1, characterized in that, The cryptographic verification of the identity authenticity and content integrity of the data nodes to be verified includes: The system queries the trust status of each data node in local storage. If the data node to be verified has a confirmed trust status, the corresponding verification result is output directly. If the data node to be verified does not have a confirmed trust status, it performs structured parsing to separate the content payload, generation timestamp, referenced data node set, and signature packet. The system then uses the public key corresponding to the signature packet to decrypt and verify the identity of the publisher and the authenticity of the node. When multiple signatures exist, each signature must be verified. After successful decryption, the expected node hash value is extracted. The actual hash value is calculated in real time for the parsed content payload, generation timestamp, and reference data node set to complete the content integrity verification.
5. The cascaded anti-counterfeiting and traceability method based on multi-level hash nesting according to claim 4, characterized in that, After the verification passes, all referenced underlying data nodes are recursively verified, and the trust status of each data node is updated synchronously, including: After the cryptographic verification is passed, check whether there is a reference data node in the current data node; if there is no reference data node, the current data node is deemed to have passed the verification and its trust status is updated; if there is a reference data node, the recursive verification process is executed for each reference data node in turn, until the end of all branches is traced. In the recursive verification process, the generation timestamp of the underlying reference data node is extracted and compared with the generation timestamp of the upper-level data node in a time-series causal comparison. If the time sequence is reversed, the hash verification result of the underlying data node is checked. If the verification fails, the underlying data node is determined to have failed verification. If it passes, the upper-level data node is determined to have failed verification. The verification results of each data node are synchronously updated to the trust status record in local storage.
6. The cascaded anti-counterfeiting and traceability method based on multi-level hash nesting according to claim 5, characterized in that, The synchronous update of the trust status of each data node includes: The trust status of data nodes is divided into multiple categories, including trusted status, invalid status and contaminated status. The trust status of each data node is updated during the regression phase of recursive verification. Bind the corresponding update timestamp to the trust status of each data node, and configure a time-stamp-based state lifecycle management strategy to roll back deterministic states that exceed the effective threshold. Based on a preset cache eviction method, edge data nodes with no definite state and a reference frequency below the frequency threshold are periodically cleaned up.
7. The cascaded anti-counterfeiting and traceability method based on multi-level hash nesting according to claim 1, characterized in that, When a failed data node is detected, all derived data nodes that directly and indirectly reference the failed data node are traversed according to the recorded reference dependencies, and the contaminated status of the derived data nodes is marked in batches, including: The cascading pruning process is initiated with the failed data node as the root node; based on the reference dependency relationship of the local persistent record, all derived data nodes that directly and indirectly reference the root node are traversed and retrieved, and the trust status of all retrieved derived data nodes is marked as contaminated in batches. After completing the batch status update, an early warning statement containing the characteristics of the failed data nodes and the reasons for the failure is generated. The early warning statement is then attached with a digital signature and broadcast and synchronized to an external network or a third-party verification system.
8. A cascaded anti-counterfeiting and traceability system based on multi-level hash nesting, characterized in that, include: The encapsulation and signing module is configured to combine the content payload to be encapsulated, the generation timestamp, and the set of reference data nodes to form the payload to be encapsulated, and to calculate the node hash value of the payload to be encapsulated; The node hash value is signed using at least one publisher's private key, encapsulated to form a new data node, and the reference relationship between each data node is persistently recorded; the set of referenced data nodes includes hash addressing pointers and complete data entities, and the hash addressing pointer is an identification information that has both data retrieval and cryptographic verification functions. Depending on the storage network architecture, the identification information can be parsed into the addressing locator of the target data in the network and the expected cryptographic hash value. The cryptographic verification module is configured to perform cryptographic verification on the identity authenticity and content integrity of the data nodes to be verified. After the verification is successful, it recursively verifies all the underlying data nodes referenced and synchronously updates the trust status of each data node. The cascading pruning module is configured to, when a failed data node is detected, traverse all derived data nodes that directly and indirectly reference the failed data node according to the recorded reference dependencies, and batch mark the contaminated state of the derived data nodes. After the verification passes, all referenced underlying data nodes are recursively verified, and the trust status of each data node is updated synchronously. This includes: after the verification passes, if the current data node has referenced data nodes, the verification is recursively performed for each referenced data node until the end of each branch is traced, and the trust status of each data node is updated synchronously. The trust status includes trusted status, invalid status and contaminated status.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the cascaded anti-counterfeiting and traceability method based on multi-level hash nesting as described in any one of claims 1-7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the cascaded anti-counterfeiting and traceability method based on multi-level hash nesting as described in any one of claims 1-7.
Citation Information
Patent Citations
Trusted application network data tracing method and auditing method for software complex network
CN111355570A
Logistics information tamper-proofing system based on block chain
CN120528583A