A method and system for intelligent task decomposition and trusted transfer based on process rehearsal

CN122712596APending Publication Date: 2026-09-08田忍峰
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610855029.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-14
Publication Date
2026-09-08

AI Technical Summary

Technical Problem

这导致两个问题:一是流程无法适应现实,用户被迫绕过系统走线下;二是变动操作无存证,事后审计时无法追溯“谁在什么时间改变了流程、出于什么原因”

Benefits of technology

[0032] The process is flexible and adaptable, with full evidence preservation throughout. It supports seven types of process modification operations, including adding signatures, removing signatures, skipping signatures, returning, transferring, withdrawing, and terminating. Each modification generates a verification record and is pinned to the credential chain. This solves the problems of rigid processes or lack of traceability in traditional systems, ensuring that the evidence of the entire process flow is fully recorded along all modification paths.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122712596A_ABST
    Figure CN122712596A_ABST
Patent Text Reader

Abstract

The application discloses a kind of intelligent task disassembly and credible flow transfer method and system based on process rehearsal.The system starts process rehearsal engine after template publishing, analyzes flow transfer dependence, identifies serial and parallel nodes and pre-task, generates dynamic task list for participants;Time consumption is monitored in flow transfer, and automatic diagnosis is carried out when it is blocked and early warning;When tabulating, multiple departments are collaboratively edited, and fields are automatically associated with acquisition components;When template is published, trust root is anchored through authoritative identity authentication;Flow transfer uses hierarchical verification, local signature for ordinary nodes, and face brushing for key nodes;Each node records hash locking chain evidence;File upload instant hash is bound with data;Identity management is built in the system and supports point-to-point communication, and offline flow transfer can be realized in no network scene.The application constructs a decentralized data flow transfer system with identity credibility, task active guidance, block diagnosis, hierarchical verification and multi-mode communication coverage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of information security and data exchange technology, and in particular to a reliable data flow method and system that integrates dynamic identity management, multi-department collaborative tabulation, intelligent component association, process pre-simulation and task decomposition, dynamic process change, hierarchical verification, chain-based evidence storage, blockage diagnosis, multi-mode communication, and custom archive generation. Background Technology

[0002] In existing technologies, data flow and form approval systems generally suffer from the following problems:

[0003] Rigid processes fail to adapt flexibly to real-world changes. Traditional workflow systems fix the workflow path once the template is published, making dynamic adjustments impossible during the process. However, in real-world business, it's extremely common to add approvals mid-process, skip unnecessary steps, return requests for modification, or delegate tasks to others. Existing systems either don't support these changes or require mandatory administrator intervention without proper documentation. This leads to two problems: first, the process cannot adapt to reality, forcing users to bypass the system and go offline; second, changes are not documented, making it impossible to trace "who changed the process, when, and for what reason" during post-process audits.

[0004] Passive form filling and a lack of proactive guidance and congestion diagnosis are prevalent in traditional workflow systems. Users only learn they have tasks to complete when they receive a notification. The system doesn't inform users in advance what materials are needed, which tasks can be processed in parallel, or where the current bottleneck is. When a process is blocked, the initiator and subsequent participants cannot quickly locate the blocking node and its cause, and can only inquire one by one via phone or message, which is inefficient. Existing systems lack intelligent congestion diagnosis and proactive early warning capabilities based on historical data.

[0005] Static identity management leads to a weakening of trust over time. Once registered, user identities remain valid indefinitely, failing to reflect dynamic changes such as expired qualifications, employee departures, or abnormal organizational status. Existing solutions lack a unified, dynamic management mechanism for organizational identities, individual qualifications, and device identities, making it impossible to verify operator identity validity in real-time during workflow.

[0006] Form design lacks collaboration and intelligence. Traditional form design requires a single person to complete the task at once, and cannot support collaborative editing by multiple departments based on their permissions. Field definitions are separated from interactive components, requiring the form creator to design the meaning of each field and the data collection method separately, which is inefficient and prone to errors.

[0007] The existing systems suffer from weak trust anchors and simplistic verification strategies. They either rely on centralized account and password systems, which lack sufficient legal validity, or they employ paid CA certificates for strong verification, resulting in high costs and a poor user experience. Current technologies lack mechanisms for flexibly configuring verification levels within the same system, failing to balance the needs for daily convenience with compliant trust.

[0008] The chain of evidence is incomplete, making offline verification impossible. External evidence such as physical receipts and on-site photos are stored separately from digital forms. Processing and approval records are typically centralized database logs, which are at risk of being tampered with or deleted. Furthermore, verification relies on a central server and network connection. Some solutions upload data hashes to the blockchain, but the data is separated from the evidence storage, and verification still requires an internet connection to query blockchain nodes, making independent verification impossible in an offline environment.

[0009] The archive file format is fixed and lacks user customization capabilities. Existing systems typically generate archive files in a pre-set, fixed format, preventing users from selecting the export content range, file format, and intended use template based on their actual needs. Different scenarios have significantly different requirements for the content and format of archive files, making a fixed format insufficient to meet diverse needs. Furthermore, existing systems do not record the export process itself, leaving the authenticity and integrity of archive files unverifiable.

[0010] Relying on cellular networks fails to cover scenarios without internet access. Existing workflow systems generally rely on cellular networks or Wi-Fi internet connections. In remote farmlands, underground tunnels, and deep within construction sites—scenarios without cellular network coverage—the systems cannot function properly, leading to interruptions in digital processes.

[0011] Lack of data sovereignty hinders cross-role queries. Data subjects such as patients and farmers lack control over their data, and participants cannot easily access the progress and results of processes they have participated in. Authorized data access lacks a reliable and revocable mechanism. Some solutions use deep learning models for automatic form filling, but users cannot view or intervene in the filling rules, resulting in opaque data flow. Summary of the Invention

[0012] Purpose of the invention: The present invention aims to provide a method and system for intelligent task decomposition and reliable flow based on process pre-simulation, so as to solve the problems existing in the prior art.

[0013] Technical solution:

[0014] This invention provides a method and system for intelligent task decomposition and reliable workflow based on process pre-simulation, the core of which includes the following subsystems:

[0015] Dynamic Identity Generation and Management System. The system incorporates a built-in identity lifecycle management mechanism, covering the entire process of dynamic management of institutional identities, personal qualification identities, and device identities. Each type of identity is bound to an expiration date, and supports real-time freezing by authorized parties after passing national network identity authentication. Once frozen, the identity cannot be used for new operations, but its historical operation records can still be traced and verified. Unlike existing technologies with static accounts or self-generated decentralized identities, this system uses national network identity authentication as the root of trust, and the identity has legal validity. Unlike static solutions that solely rely on CA certificates, this system supports real-time dynamic updates and freezing of identity status, ensuring that the identity validity of operators at every stage of the process can be verified in real time.

[0016] This is a multi-departmental, permission-based collaborative table creation system. The lead creator establishes the form framework and divides the editing areas into departmental permission zones, while also configuring change permissions for each node. Authorized personnel in each department, after passing national network identity authentication, independently define the fields and supporting document requirements for their respective zones. The system strictly limits the editing scope, ensuring no interference between departments. Once all departments have completed their work, the lead creator locks the template through national network identity authentication. The system then embeds the editing records from each department into the template metadata, forming a trusted credential template co-created by all parties.

[0017] The system automatically associates intelligent interactive components. It has a built-in, extensible explicit field-action mapping rule base. After the user selects a field type, the system automatically matches and generates the corresponding intelligent interactive data acquisition component. For photo types, it automatically adds a shooting timestamp and GPS coordinates and supports disabling selection from the album; for signature types, it automatically binds to the operator's network number and supports setting signature verification levels; for file types, it automatically triggers instant hash calculations and supports setting file format restrictions. The rule base supports user-defined extensions, and users can view and manage all mapping rules at any time. Unlike the black-box models in existing deep learning technologies, this system uses an explicit rule mapping table, allowing users to fully view, edit, and delete any mapping rule, making data flow transparent and controllable.

[0018] The system implements mandatory authentication and process rehearsal. When a template is published, the system forcibly verifies the publisher's real-time identity validity. Verification includes the publisher's network ID status, affiliated organization's identity status, and the validity period of relevant personal qualifications. Failure to pass any verification item results in publication being prohibited. Upon successful verification, the publisher completes national network identity authentication. The system generates a template publication verification record, embedding template metadata, and encodes the template as a QR code or near-field communication tag.

[0019] After the template is successfully published, the system automatically starts the process rehearsal engine to perform dependency analysis on the workflow path: identifying serial dependencies between workflow nodes, generating sequential task chains, and clarifying the pre-blocking conditions of each node; identifying parallel nodes without dependencies, generating a list of parallel tasks, and simultaneously pushing to-do notifications to all participants in the parallel nodes; analyzing the supporting documentation requirements and qualification requirements defined by each node, generating a list of pre-preparation tasks for each participant and pushing it out in real time; when a pre-preparation task is needed by multiple nodes, the system marks the task as a shared pre-preparation task and pushes collaborative preparation prompts to all relevant participants; and assigning tasks to each participant... Participants generate personalized dynamic task interfaces, which clearly display current pending tasks, preparatory tasks, ongoing parallel tasks, blocked tasks that need to wait for others to complete, and their expected completion conditions using colors or icons. Based on each participant's historical operation data, the estimated completion time of each node is estimated, and the estimated waiting time is displayed to subsequent node participants on the dynamic task interface. The qualification requirements for each node are matched and verified with the dynamic identity of the participants. If the qualification of a specified participant for a certain node is about to expire before the process is expected to reach that node, the system will issue a qualification renewal warning to the participant and the administrator in advance.

[0020] A tiered verification and intelligent fill system. After users obtain templates through various methods such as optical recognition, near-field communication, star flash, Wi-Fi Direct, and Bluetooth Mesh, the intelligent fill module automatically fills in public-level information based on the local personal database and explicit field mapping rule table, while privacy fields require manual authorization. The system dynamically adjusts the fill priority based on field semantic mapping and historical usage frequency. Upon submission, the system presets the verification level according to the template: ordinary nodes call the user's local private key to digitally sign the filled content and generate an ordinary verification record; mandatory verification level invokes the user's local national network identity authentication application, guiding the user to complete biometric authentication and obtain a mandatory verification record issued by the national system. Unlike the single strategy of all-strong or all-weak verification in existing technologies, this system supports different preset verification levels for different nodes within the same form, balancing daily convenience with compliance and reliability. Modifications or additions to automatically filled content by the user are updated in reverse to the explicit field mapping rule table in the local personal database after confirmation. Users can view, edit, or delete these rules at any time.

[0021] The system uses real-time file hashing and association. When a user selects or uploads a file, the system instantly hashes the file content to generate a digital fingerprint. Upon submission, the generated verification record simultaneously binds the hash value of the form data and the hash value of the uploaded file, cryptographically binding the file and form data into an inseparable whole. Any subsequent attempt to replace the file will result in a hash mismatch, leading to a break in the signature chain of all subsequent verification records.

[0022] Dynamic workflow modification system. During the workflow process, authorized operators with modification permissions can confirm and execute workflow modification operations such as adding signatures, removing signatures, skipping signatures, returning, transferring, withdrawing, and terminating by facial recognition. Adding a signature involves the current operator selecting a signer and filling in the reason for adding the signature. After facial recognition confirmation, the signer is temporarily inserted into the current workflow node. Once the signer completes the operation, the process returns. Removing a signature involves the authorized operator selecting an unprocessed node, filling in the reason for removing the signature, and confirming with facial recognition before removing it. Subsequent nodes will automatically move forward. Skipping a signature involves the authorized operator selecting the next node. After the system verifies the skipping conditions and confirms with facial recognition, the node is skipped. Returning a signature involves the current operator selecting the target node and filling in the reason for returning a signature. After facial recognition confirmation, the process returns to the target node for modification and resubmission. Transferring a signature involves the current operator selecting a transferor and filling in the reason for transferring a signature. After facial recognition confirmation, the pending task is transferred. Withdrawing a signature involves the initiator or authorized operator confirming withdrawal with facial recognition if a subsequent node has not yet been processed. The process returns to the initiator for modification and resubmission. Withdrawal is prohibited if a subsequent node has already been processed by an operator. Termination involves the authorized operator filling in the reason for termination and confirming with facial recognition. The process status changes to terminated. Completed node records are retained, and uncompleted nodes are no longer processed.

[0023] Each change operation generates a corresponding change verification record, including the change type, reason for change, identity of the operator, and timestamp, which is then appended to the verification record chain of the original voucher. After the change, the process simulation engine automatically recalculates subsequent paths and task allocations. Compared with the shortcomings of rigid processes or lack of traceability in existing technologies, this invention achieves "flexible and adaptable processes, full evidence preservation of changes, and complete traceability afterward," ensuring that the flow evidence not only records the final result but also completely records all change paths during the process.

[0024] The system employs a chain-based verification record and a self-contained evidence package system. Upon receiving the data packet, subsequent node users locally utilize the national system public key and the public keys of preceding users to completely offline verify the authenticity and integrity of all preceding verification records within the data packet, as well as the validity of the real-time identity status of each preceding operator. The verification scope includes all flow operation verification records and all process change verification records. The verification process does not require online queries to any blockchain node or centralized server. After successful verification, the user executes their node's operation, generating a verification record for that node. This record contains not only the node's verification information but also the hash value of the immediately preceding verification record, creating a hash-locked chain structure within the data packet. Upon completion of the flow, the system performs a comprehensive hash operation on the final data packet, which contains all chain-based verification records, all process change verification records, and associated files, generating a unique global evidence fingerprint. The final data packet is a self-contained evidence package, recording not only the final result but also all changes during the flow. Any user holding this data packet can completely offline verify the authenticity and integrity of all records within it.

[0025] Unlike existing technologies that rely on external blockchain storage, this system's verification record chain structure resides within the data packet, and the verification process is completed entirely offline, requiring no internet connection to query any blockchain node or centralized server. Unlike centralized database log solutions, this system's chain structure possesses cryptographic tamper-proof properties; any single point of modification will cause the entire chain to break.

[0026] A real-time process blockage diagnosis and early warning system. The system statistically analyzes historical operation data for each workflow node, dynamically calculating reasonable time thresholds based on node type, historical average time consumption, and standard deviation, and continuously optimizing and adjusting as system data accumulates. When the same node experiences multiple blockages, the system automatically lowers the node's threshold to improve early warning sensitivity. When the actual time consumption of the current node exceeds a preset threshold, the system automatically marks the node as a blocked node and pushes a blockage warning notification to the process initiator and subsequent dependent participants. The warning notification includes the blocked node name, the blocking operator's identity, the duration of the blockage, and suggested handling methods, including expediting, transferring, or initiating a signature operation within the changed permissions. The location, cause, and duration of the blockage are visually identified on the dynamic task interface of the process initiator and all relevant participants. If the operator of the blocked node has associated equipment or qualification identities, the system automatically checks the operator's equipment calibration status and qualification validity. When expired equipment calibration or impending qualification expiration is detected, the equipment status or qualification status is displayed as part of the blockage cause in the warning notification.

[0027] A cross-role progress query and data authorization access system. The system maintains a participant list for each transaction credential, recording the identities of all operators who have participated in any node of that credential, including participants temporarily added through signature. Participants can query the current transaction progress and final result of all credentials they have participated in through their user terminals. The query returned information includes the current node of the credential, a list of completed nodes and their corresponding operators, the completion time of each node, and all process change records. After data subjects pass national network identity authentication, they can grant temporary access to their personal data to any third party. Authorization operations generate corresponding authorization verification records, including the identity of the authorized object, the scope of authorized data, the start and end times of authorization, and the data subject's digital signature. When an authorized third party accesses data within the authorized scope, the system records the access log. Data subjects can view the authorization access log at any time and can withdraw authorization at any time through national network identity authentication; the withdrawal operation generates a corresponding withdrawal verification record.

[0028] A customizable archive file generation system. After the process is completed, the system provides users with an archive file generation interface. Users can choose the scope of content to export (all workflow records, form data, associated files, authentication records, authorized access logs, process change records, global evidence fingerprints), the scope of nodes to export (all nodes, nodes only participated in by the user, custom selected nodes), file format (PDF, JSON, XML, CSV, ZIP package), and usage template (court evidence package, regulatory reporting, financial reimbursement, insurance claims, project archiving, custom). The court evidence package template includes all process change records by default. The system extracts the corresponding content from the voucher data package according to the user's selection, formats and assembles it according to the selected format and template, and generates an archive file. The system performs a hash operation on the archive file to generate an exported file fingerprint and generates an export operation verification record, which is appended to the verification record chain of the original voucher. Any third party holding the archive file can verify the authenticity and integrity of the archive file offline by comparing the hash value of the archive file with the exported file fingerprint recorded on the voucher chain.

[0029] Multi-mode communication and offline workflow system. The system supports multiple point-to-point wireless communication methods, including StarFlash, Wi-Fi Direct, near-field communication, and Bluetooth Mesh. In scenarios without cellular network coverage, user terminals automatically discover nearby devices and establish temporary networks using the above communication methods. StarFlash's Polar code encoding technology enables interference-resistant data transmission, ensuring communication reliability in complex industrial environments with complex electromagnetic conditions. When StarFlash is unavailable, the system automatically downgrades to Wi-Fi Direct or Bluetooth Mesh to ensure continuous availability of the communication link; when the network environment recovers, it automatically switches back to StarFlash for better performance. Data packets and verification records are transmitted directly between user terminals through the temporary network, without passing through a central server. When multiple user terminals participate in workflow simultaneously, the system uses the multi-device concurrent transmission capabilities of StarFlash or Wi-Fi Direct to send data packets to multiple next-node user terminals simultaneously, achieving parallel workflow.

[0030] Beneficial effects

[0031] Compared with the prior art, the present invention has the following beneficial effects:

[0032] The process is flexible and adaptable, with full evidence preservation throughout. It supports seven types of process modification operations, including adding signatures, removing signatures, skipping signatures, returning, transferring, withdrawing, and terminating. Each modification generates a verification record and is pinned to the credential chain. This solves the problems of rigid processes or lack of traceability in traditional systems, ensuring that the evidence of the entire process flow is fully recorded along all modification paths.

[0033] From reactive to proactive, efficiency has seen a qualitative leap. The process pre-draft engine proactively informs each participant of their current task, preparatory work, parallel opportunities, and bottleneck status, significantly reducing waiting time. The bottleneck diagnosis and early warning functions make process bottlenecks visible in real time and allow for immediate handling. Early warning notifications include suggested changes to operations, guiding users to proactively resolve issues.

[0034] The trust foundation is dynamic and reliable. Identity has an expiration date and can be frozen in real time. The qualification early warning function proactively prevents risks, resolving the trust decay problem caused by static identities. Based on national network identity authentication as the root of trust, the identity has legal validity, distinguishing it from the rootless trust of self-generated decentralized identities.

[0035] It is legally credible and offers a flexible user experience. The system mandates national network identity authentication anchored to a root of trust, with each node in the process performing tiered verification as needed. This achieves a balance between security and convenience within a single form, unlike the single verification strategies of existing technologies.

[0036] The form design is efficient and intelligent. Multiple departments can collaboratively create forms in parallel, with fields automatically associated with data collection components. It uses an explicit mapping rule base instead of a black-box model, giving users complete control over the data flow, lowering the design threshold while ensuring transparency and controllability.

[0037] The evidence chain is complete and self-contained. Physical files and digital data are cryptographically bound, and the entire process of chain-verification records, including change records, are locked within the data packet, forming a self-contained evidence package that can be fully verified offline, unlike existing solutions that rely on external blockchain storage or centralized database logs.

[0038] The archive is customizable and verifiable. Users can choose the export content range, node range, file format, and usage template to generate formatted archive files that meet the needs of different scenarios. The export action itself is stored in the credential chain, and the archive file hash can be verified offline, ensuring the authenticity and integrity of the archive file.

[0039] Data sovereignty returns to individuals. Data subjects can independently authorize or revoke third-party access permissions, and each operation creates an immutable verification record. Smart population uses explicit rule mapping, allowing users to manage the scope of authorization and usage of their personal data at any time.

[0040] Decentralized with zero operating costs. Verification is completed through the user's local national network identity authentication application. Hash and signature are calculated on the terminal, eliminating the need for centralized verification servers and paid CA certificates, thus achieving zero marginal cost of system operation.

[0041] Unrestricted network coverage, usable in all scenarios. Utilizing various point-to-point wireless communication technologies such as StarFlash, the system can still operate normally in remote areas, underground spaces, and complex industrial environments without cellular network coverage. It supports automatic multi-mode switching and degradation, ensuring continuous availability of the communication link and filling a gap in existing systems in this field. Attached Figure Description

[0043] Figure 1 System overall architecture diagram

[0044] Figure 2 Schematic diagram of dynamic identity lifecycle management

[0045] Figure 3 Flowchart of multi-department permission-based collaborative table creation

[0046] Figure 4 Automatic association mapping diagram of intelligent interactive components

[0047] Figure 5 Starting Point Mandatory Authentication and Process Pre-Dialogue Engine Workflow Diagram

[0048] Figure 6 : Illustration of the dynamic task interface on the user side

[0049] Figure 7 Hierarchical verification workflow diagram

[0050] Figure 8 File real-time hashing and association binding principle diagram

[0051] Figure 9 : Dynamic process change operation diagram

[0052] Figure 10 Chained verification records and self-contained evidence package structure diagram

[0053] Figure 11 Flowchart of Self-Learning Reverse Update Mechanism

[0054] Figure 12 Flowchart for Real-time Diagnosis and Early Warning of Process Blockage

[0055] Figure 13 Schematic diagram of multi-mode communication and offline workflow scenarios

[0056] Figure 14 Cross-role progress query and data authorization access flowchart

[0057] Figure 15 Flowchart for generating custom formatted archive files Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments.

[0060] Example 1: The entire process of farmers selling grain – including dynamic signature verification

[0061] As the certification body, the Provincial Grain and Oil Quality Inspection Center publishes the "Corn Circulation Standard Certificate" template within the system, setting up four circulation nodes: grain dealers fill in the form → farmers confirm the form → drying tower processes the form → feed mill receives and archives the form.

[0062] The moment the template was released, the process simulation engine started: it pushed the task to grain dealer Lao Zhang and the reminder to calibrate the weighbridge; it pushed the qualification renewal warning to Xiao Li at the drying tower, as the system detected that his inspector certificate would expire in 30 days and issued a renewal warning in advance; it pushed the preparatory tasks such as the warehousing inspection standards to feed mill Xiao Zhang; and it pushed the notification to farmer Lao Wang that he needed to confirm.

[0063] In the fields, Mr. Zhang obtains a template by scanning a QR code. The system automatically fills in his publicly available business card information based on the explicit field mapping rule table. Mr. Zhang weighs the corn on the weighbridge, and the weighbridge data is automatically filled into the gross weight field via a smart scale, which is also automatically linked to the weighbridge calibration certificate. Mr. Zhang enters the unit price, calculates the total price, and submits the application.

[0064] During processing at the drying tower, Xiao Li discovered abnormal moisture content in the corn, requiring quality control manager Lao Liu to assess it. Xiao Li clicked "Add Signature," selected Lao Liu as the signatory, and filled in the reason for adding the signature: "Corn moisture content abnormal, requires quality control assessment," and confirmed via facial recognition. Lao Liu was temporarily inserted into the current workflow node, received the pending task, completed the assessment, and submitted it via facial recognition. The process automatically returned to Xiao Li to continue the drying process.

[0065] In a remote farmland without cellular network coverage, Lao Zhang and Lao Wang set up a temporary network using XingShan (a network-enabled internet service), allowing Lao Wang to complete facial recognition verification even without a network connection. The entire process was completed offline, and once they entered an area with network coverage, the globally stored fingerprint was automatically synchronized to the blockchain.

[0066] During the subsequent audit, the credential chain clearly recorded: the original four-party nodes + the signing node + the reason for signing + the person who performed the signing + the signing time. Anyone can verify the integrity of the entire chain offline.

[0067] After the process was completed, Mr. Zhang needed to apply for a loan from the bank. He opened the voucher details page and selected to generate an archive file: the export content range was selected as "All Transfer Records + Related Files + Process Change Records + Global Evidence Fingerprint", the file format was selected as "PDF", and the purpose template was selected as "Court Evidence Package". The system generated a PDF file containing a complete chain of evidence, performed a hash operation on the file, and generated an export operation verification record pinned to the voucher chain. After receiving the PDF, the bank verified the authenticity of the archive file offline by comparing the file hash with the record on the chain, and approved Mr. Zhang's loan application accordingly.

[0068] Example 2: Tunnel Engineering Acceptance – Including Returns and Skip Signatures

[0069] The acceptance inspection of a tunnel project requires the participation of the construction company, the supervision company, and the construction company. There is no cellular network signal inside the tunnel. After entering the tunnel, the mobile phones of all three parties automatically establish a temporary network via a network scanner. The construction company fills out a self-inspection record and submits it by facial recognition. The data packets are simultaneously transmitted to the supervision company and the construction company via the network scanner.

[0070] During the review, the supervisor discovered an error in the contractor's self-inspection record. They clicked "Return," selected the contractor's self-inspection node as the return point, filled in the reason for return as "Incorrect data in the weld flaw detection report," and confirmed it via facial recognition. The process was returned to the contractor, who modified and resubmitted the changes. The supervisor then reviewed and approved the changes again, signing off via facial recognition.

[0071] During the final acceptance inspection by the construction company, because the acceptance amount was relatively small and met company regulations, the construction company clicked "skip the check." The system verified that this node was marked as skippable in the template and that the skip check condition (amount less than the threshold) was met, so the verification passed. After the construction company confirmed via facial recognition, a non-essential approval node was skipped, and the process directly proceeded to the archiving node.

[0072] If StarFlash becomes unavailable due to extreme electromagnetic interference, the system automatically downgrades to Wi-Fi Direct to ensure uninterrupted operation. The entire process is completed in a network-free environment, and the stored fingerprint is automatically uploaded to the blockchain after exiting the tunnel.

[0073] After acceptance, the construction unit needs to submit an acceptance report to the Housing and Urban-Rural Development Bureau. The project director selects "Supervision Report" as the export content and "XML" as the format. The system automatically generates the report file according to the fields and format required by the Housing and Urban-Rural Development Bureau, and generates an export evidence record.

[0074] Example 3: Patient's Entire Medical Process and Data Authorization

[0075] When registering, patients use facial recognition to verify their identity, and the system generates an "Outpatient Visit Certificate." After the doctor's consultation, they use facial recognition to submit the diagnosis and examination forms; the laboratory technician and the reviewing doctor then complete the examinations and reports; the pharmacist uses facial recognition to dispense the medication. Each verification step is recorded and linked to the certificate, forming an internal chain structure within the data packet.

[0076] After discharge, patients can view their complete medical record at any time via the app, and all records can be verified offline. If a claim needs to be filed with the insurance company, the patient can select to export the "Insurance Claim" template, and the system will automatically extract relevant accident details, photo files, and a timeline to generate a dedicated PDF for claims.

[0077] When a patient needs to be referred, a temporary authorization code is generated after facial recognition. The receiving hospital doctor can scan the code to view examination reports and diagnostic records within the authorized scope. The system records access logs. Patients can see at any time who viewed what data and when, and can withdraw authorization at any time using facial recognition.

[0078] Example 4: Routine Internal Approvals within Enterprises – Including Transfer and Withdrawal

[0079] An employee submits a business trip expense report, with all nodes in the template set to standard verification level. The employee completes the form, signs it locally, and submits. Department manager Lao Wang receives the task, but the expense report should be handled by Xiao Li from the same department. Lao Wang clicks "Transfer," selects Xiao Li as the transferee, fills in the reason for the transfer, and confirms via facial recognition. The task is then transferred to Xiao Li.

[0080] If the initiator discovers an error in the reimbursement amount and clicks "Withdraw" before subsequent steps are completed, the process returns to the initiator after facial recognition confirmation. The initiator then corrects the amount and resubmits.

[0081] If a reimbursement claim exceeds a certain threshold, the template defaults to a mandatory verification level for that node, requiring the approver to confirm via facial recognition. This tiered verification system within the same form balances efficiency and compliance.

Claims

1. A method for intelligent task decomposition and reliable workflow based on process pre-simulation, characterized in that, The method includes: Dynamic identity generation and management: The system receives applications from organizations to join, verifies that the legal representative or authorized representative has passed the national network identity authentication, and generates a digital identity for the organization. The digital identity of the organization is bound to business license information, qualification certificate information and corresponding validity period. The system receives registrations from individual users and binds them to their national network identity number; in response to the issuance operation of the certification authority, it attaches qualification certificates to individual users, the qualification certificates including qualification type, digital signature of the issuing authority and validity period; The system receives device registration and generates a digital identity for the device, which is bound to the device number, model, calibration record, and calibration validity period. When the validity period of the identity association expires or the status changes, the system receives an update or freeze operation from the authorized party. The update or freeze operation requires the operator to perform national network identity authentication. The identity status takes effect immediately after the operation is completed. The historical operation records of the frozen identity can still be traced and verified, but the identity cannot be used for new operations. Multi-department permission-based collaborative table creation: The main creator establishes a form framework, defines basic information fields, sets the order of workflow nodes, the sending method of each node, and the change permission configuration for each node, and allocates corresponding departmental permission editing areas for each workflow node; the sending method includes automatic sending and manual sending, and when sending manually, the behavior of specifying the recipient of the next node must be confirmed through national network identity authentication and a corresponding specified behavior verification record must be generated; the change permission configuration includes: whether to allow adding signatures, whether to allow removing signatures, whether to allow skipping signatures, whether to allow returning, whether to allow forwarding, whether to allow withdrawal, whether to allow termination, and the scope of authorized operators for each change operation; After authorized personnel in each department pass the national network identity authentication, they enter their respective authorized editing areas and independently define the fields to be filled in, the field types, and the required supporting documents for this step; the system restricts authorized personnel in each department to only edit the content within their authorized areas, and the editing operations between departments do not interfere with each other; After all departments have completed the editing, the chief designer conducts a final review. Once confirmed to be correct, the form template is locked through national network identity authentication. The system embeds the editing records of each permission area, the identity information of the editors in each department, and the editing timestamp into the template metadata, forming a trusted credential template co-created by multiple parties. Automatic association of intelligent interactive components: When the creator adds a field to the form, the system provides field type options, which include at least the following field types: text, number, date, signature, photo, document, ID card, location, and amount. After the user selects a field type, the system automatically matches and generates a corresponding intelligent interactive data collection component for that field based on a preset explicit field-action mapping rule library that supports user-defined expansion. The data collection component includes: a data collection entry button, data format constraints, and automatic metadata appending rules. Among them, the photo type automatically appends a shooting timestamp and GPS coordinates and supports setting a restriction on selection from the album; the signature type automatically binds to the operator's network number and supports setting a signature verification level; and the file type automatically triggers instant hash calculations and supports setting file format restrictions. Developers can personalize the parameters of automatically generated data collection components, including adjusting the verification level, modifying metadata appending rules, and changing the data collection entry style. Template release and process rehearsal for mandatory authentication at the starting point: After the creator completes the template design, they initiate the publishing process. The system will then perform a mandatory verification of the publisher's real-time identity validity. The verification includes: the publisher's network ID status, the status of their affiliated organization, and the validity period of their personal qualifications. If any verification item fails, the system will prohibit publishing. After successful verification, the publisher completes national network identity authentication, and the system generates a template publishing verification record. The template publishing verification record includes the publisher's network ID, organization identity information, qualification status, template content hash value, national timestamp, and national digital signature, and embeds template metadata. The system encodes the template as a QR code or near-field communication tag. After the template is successfully published, the system automatically starts the process rehearsal engine to perform dependency analysis on the workflow path and perform the following operations: identify serial dependencies between workflow nodes, generate sequential task chains, and clarify the pre-blocking conditions of each node; identify parallel nodes without dependencies, generate a list of parallel tasks, and simultaneously push to-do notifications to all participants in the parallel nodes; analyze the supporting documentation requirements and qualification requirements defined by each node, generate a list of pre-preparation tasks for each participant, and push it out in real time. When a pre-preparation task is needed by multiple nodes, the system marks the task as a shared pre-preparation task and pushes collaborative preparation prompts to all relevant participants. A personalized dynamic task interface is generated for each participant. The interface clearly displays the current tasks to be done, the prerequisite tasks that can be prepared in advance, the parallel tasks that are in progress, the blocking tasks that need to wait for others to complete, and their expected completion conditions using colors or icons. Based on the historical operation data of each participant, the estimated completion time of each node is estimated and the estimated waiting time is displayed to the participants of subsequent nodes on the dynamic task interface. The qualification requirements required for each node are matched and verified with the dynamic identity of the participants. If the qualification of a specified participant for a certain node is about to expire before the process is expected to reach that node, the system will issue a qualification renewal warning to the participant and the administrator in advance. Data entry and hierarchical verification: The user terminal obtains the template through optical recognition, near-field communication, star flash, Wi-Fi Direct, Bluetooth Mesh or other point-to-point wireless communication methods, and parses out the form field list, the intelligent interactive collection components associated with each field, the node verification level requirements and the list of required supporting documents; The intelligent fill module automatically fills in public level information based on the local personal database and the explicit field mapping rule table. The field mapping rule table records the semantic mapping of fields and the historical frequency of users using specific fields in different types of templates. The system dynamically adjusts the priority of automatic filling based on the usage frequency. Privacy level fields are filled in after the user manually confirms and authorizes them. Users complete data collection through the intelligent interactive collection components associated with each field, and the system automatically attaches the corresponding metadata; After the user confirms and submits all the information, the system performs the corresponding verification operation according to the node verification level preset in the template: if it is the normal level, the system calls the user's local private key to digitally sign the information and generate a normal verification record; if it is the mandatory verification level, the system invokes the local national network identity authentication application on the user's terminal, guides the user to complete biometric authentication, and obtains a mandatory verification record issued by the national system. The mandatory verification record includes the user's de-identified network ID, data packet hash value, operation behavior identifier, national timestamp, and national digital signature. The generated verification record is appended to the current data packet and sent to the next node user terminal via StarFlash, Wi-Fi Direct, Near Field Communication, Bluetooth Mesh or other point-to-point wireless communication methods; Self-learning reverse update and file association upload: When a user manually modifies the automatically filled content or enters a new field that does not exist in the local personal database, the system will send a prompt to the user with the option of "Update personal database?" or "Save to personal frequently used field library?" after successful submission. In response to the user's confirmation, the system will update the explicit field mapping rule table in the local personal database with the modified content or the newly added field and its semantic mapping relationship. The user can view, edit or delete any mapping rule in the mapping rule table at any time. When the template has a pre-defined file upload node or the user triggers the file upload component, the user selects or takes a picture of the file to be uploaded. The system immediately performs a hash operation on the file content to generate a digital fingerprint of the file when the user selects the file. When the user submits, the generated verification record is simultaneously bound to the hash value of the form data and the hash value of the uploaded file, cryptographically binding the file and the form data into an inseparable whole. Any attempt to replace the file afterward will result in a mismatch in the file hash, which will lead to a break in the signature chain of all subsequent verification records. Dynamic process changes: During the transfer process, authorized operators with modification permissions can confirm and execute one or more of the following modification operations via facial recognition; each modification operation generates a corresponding modification verification record, including the modification type, modification reason, operator identity, and modification timestamp, which is appended to the verification record chain of the original voucher: Signature: The current node operator selects a signer and fills in the reason for signing. After facial recognition confirmation, the signer is temporarily inserted into the current flow node. After the signer completes the operation and submits it via facial recognition, the process returns to the current node operator to continue the flow; the signing operation generates a signature verification record. Signature reduction: The authorized operator selects an unprocessed node in the process, fills in the reason for the signature reduction, and confirms it by facial recognition. The node is then removed from the process, and subsequent nodes are automatically moved forward. The signature reduction operation generates a signature reduction verification record. Skip Sign: The authorized operator selects the next node after the current node. The system verifies whether the node is marked as skippable in the template and whether the skip sign conditions are met. After the verification is passed, the authorized operator confirms by facial recognition, the node is skipped, and the process directly proceeds to the next node. Skip sign operation generates a skip sign verification record. Return: The operator at the current node selects the target node to which they want to return and fills in the reason for the return. After facial recognition confirmation, the process returns to the target node. The operator at the target node modifies the information and resubmits. The return operation generates a return verification record, which records the return path and reason. Transfer: The current operator selects a transferee and fills in the reason for the transfer. After facial recognition confirmation, the pending task is transferred from the current operator to the transferee; the transfer operation generates a transfer verification record. Withdrawal: If the process initiator or authorized operator has not yet processed the subsequent node, they can use facial recognition to confirm the withdrawal of the submitted content. The process will then return to the initiator for modification and resubmission. A withdrawal verification record is generated for each withdrawal operation. If an operator has already processed the subsequent node, withdrawal is prohibited. Termination: After the authorized operator fills in the reason for termination and confirms it by facial recognition, the process status changes to terminated. All records of completed nodes are retained, and uncompleted nodes are no longer processed; the termination operation generates a termination verification record. Chain-based circulation and archiving: After receiving the data packet, subsequent node users use the national system public key and the public keys of previous users to verify the authenticity and integrity of all previous verification records in the data packet, as well as the validity of the real-time identity status of each previous operator, completely offline. The verification process does not require online querying of any blockchain node or centralized server. The verification scope includes all data packet verification records and all process change verification records. When it is detected that the identity of any previous operator has been frozen, the qualification has expired, or the device identity has expired, the system issues a clear warning on the interface and decides whether to prohibit the continued flow according to the template preset rules. After successful verification, the user performs the operation of this node, generating a verification record for this node. In addition to the verification information of this node, the verification record generated by this node also contains the hash value of the immediately preceding verification record, so that the verification records of each node form a hash-locked chain structure within the data packet. After the transfer is completed, the system performs a total hash operation on the final data packet containing all chain verification records, all process change verification records, and related files to generate a unique global evidence fingerprint. According to the template's preset archiving rules, the global evidence fingerprint is uploaded to the blockchain or other trusted evidence storage platform for permanent storage, or stored locally with encryption. The final data packet is a self-contained evidence packet that not only records the final result but also completely records all changes during the transfer process. Any user holding the data packet can completely verify the authenticity and integrity of all records within it offline. During the workflow, whenever a node is completed or a process change occurs, the system automatically updates the dynamic task interface of all participants: the subsequent dependent nodes of completed nodes are unlocked, and their status is automatically changed from waiting to pending processing; nodes that have changed are marked with a special mark on the interface to show the change type; at the same time, the workflow simulation engine dynamically adjusts and refreshes the preparatory task suggestions for each participant based on the latest workflow progress and changes. Real-time process blockage diagnosis and early warning: The system performs statistical analysis on the historical operation data of each flow node, dynamically calculates a reasonable time threshold based on node type, historical average time consumption and standard deviation, and continuously optimizes and adjusts it as system operation data accumulates; when the same node is blocked multiple times, the system automatically lowers the threshold of that node to improve the sensitivity of the early warning. When the actual time taken by the current node exceeds the preset threshold, the system automatically marks the node as a blocked node and pushes a blocking warning notification to the process initiator and subsequent dependent participants of the blocked node. The warning notification includes: the name of the blocked node, the identity of the blocking operator, the duration of the blockage, and the suggested handling method. The suggested handling method includes expediting, forwarding, or initiating a signature operation within the changed permissions. On the dynamic task interface of the process initiator and all relevant participants, the location of the blocking node, the reason for the blocking, and the duration are visually identified. If the operator of the blocked node has an associated device identity or qualification identity, the system will automatically check the operator's device calibration status and qualification validity period. When it is detected that the device calibration has expired or the qualification is about to expire, the device status or qualification status will be displayed as part of the blocking reason in the warning notification. Cross-role progress query and data authorization access: The system maintains a participant list for each circulation voucher, recording the identities of all operators who have participated in any node of the voucher, including participants who are temporarily added through signing. Participants can use their user terminals to query the current circulation progress and final result of all vouchers they have participated in. The information returned by the progress query includes: the current node of the voucher, the list of completed nodes and their corresponding operators, the completion time of each node, and all process change records. After a data subject passes national network identity authentication, they can grant temporary access to their personal data to any third party. The authorization operation generates a corresponding authorization verification record, which includes the identity of the authorized object, the scope of authorized data, the start and end time of the authorization, and the digital signature of the data subject. When the authorized third party accesses the data within the scope of authorization, the system records the access log. The data subject can view the authorization access log at any time and can withdraw the authorization at any time through national network identity authentication. The withdrawal operation generates a corresponding withdrawal verification record. Generate a custom formatted archive file: After the process is completed, the system provides the user with an archive file generation interface. The user can choose from the following export options: the scope of the exported content, including one or more of the following: all workflow records, form data, associated files, authentication records, authorized access logs, process change records, and global evidence fingerprints; the scope of the exported nodes, including all nodes, nodes only participated in by the user, or custom selected nodes; the file format, including one or more of the following: PDF, JSON, XML, CSV, and ZIP package; and the purpose template, including one of the following: court evidence package, regulatory reporting, financial reimbursement, insurance claims, project archiving, and custom. The court evidence package template includes all process change records by default. The system extracts the corresponding content from the credential data package according to the export options selected by the user, formats and assembles it according to the selected file format and purpose template, and generates a formatted archive file; The system performs a hash operation on the generated archive file to generate an export file fingerprint; the system generates an export operation verification record, which includes: the exporter's identity information, export time, export content range, export file format, and export file hash value; this export operation verification record is appended to the verification record chain of the original voucher, becoming an inseparable part of the voucher; Users or any third party holding the archive file can verify the authenticity and integrity of the archive file offline by comparing the archive file hash value with the fingerprint of the exported file recorded on the credential chain; Multi-mode communication and offline transfer: The system supports multiple point-to-point wireless communication methods, including StarFlash, Wi-Fi Direct, Near Field Communication, and Bluetooth Mesh. In scenarios without cellular network coverage, user terminals automatically discover nearby devices and establish temporary networks through the aforementioned communication methods. StarSignal's Polar code encoding technology enables interference-resistant data transmission, ensuring communication reliability in complex industrial environments. When StarSignal is unavailable, the system automatically downgrades to Wi-Fi Direct or Bluetooth Mesh to ensure the continuous availability of the communication link. When the network environment recovers, it automatically switches back to StarSignal for better performance. Data packets and verification records are transmitted directly between user terminals through the temporary network, without going through a central server; When multiple user terminals participate in the flow simultaneously, the system uses the multi-device concurrent transmission capability of StarFlash or Wi-Fi Direct to send data packets to multiple next-node user terminals at the same time, thus achieving parallel flow.

2. A smart task decomposition and reliable workflow system based on process pre-simulation, characterized in that, include: The identity generation and update module is used to manage the entire lifecycle of organizational identity, personal qualification identity, and device identity, including generation, update, and freezing operations. All operations are required to pass the national network identity authentication. The multi-departmental permission collaborative table creation module is used by the main creator to create a form framework and divide the departmental permission editing area, set the change permission configuration for each node, and allow authorized personnel in each department to independently define fields, field types and supporting document requirements within their respective permission areas. Editing is subject to mandatory national network identity authentication; the system embeds the editing records of each department and the editor's identity information into the template metadata. The intelligent interaction component association module stores an extensible explicit field-action mapping rule library, which is used to automatically match and generate corresponding intelligent interaction collection components based on the field type selected by the creator, and supports the creator to adjust the personalized parameters of the components. The template publishing authentication module is used to enforce the verification of the publisher's real-time identity validity when publishing a template. After the verification is successful and the national network identity authentication is completed, a template publishing verification record is generated and the template metadata is embedded. The process simulation and task decomposition engine is used to automatically analyze the dependencies of the workflow path after the template is released, identify serial nodes, parallel nodes and preparatory tasks, generate personalized dynamic task lists for each participant, estimate the node completion time, match and verify qualification requirements and issue renewal warnings, and refresh the task status in real time according to progress and process changes during the workflow. The dynamic process change module is used to support authorized operators to confirm and execute one or more process change operations such as adding signature, removing signature, skipping signature, returning, transferring, withdrawing, and terminating by facial recognition during the process. Each change operation generates a corresponding change verification record and attaches it to the voucher verification record chain. After the change, the process pre-reaction engine is automatically triggered to recalculate the subsequent path and task allocation. The congestion diagnosis and early warning module is used to statistically analyze the historical time consumption of each node, dynamically calculate reasonable time consumption thresholds based on node type, historical average time consumption, and standard deviation, and continuously optimize them as data accumulates; when a node times out, it automatically marks the congested node and pushes an early warning notification to relevant participants, which includes suggested changes; the congestion information is visualized on the task interface, and the calibration status and qualification validity of the diagnostic equipment are automatically associated. The intelligent fill module parses form fields and automatically fills in data based on the local personal database and explicit field mapping rule table, combined with field semantic mapping and historical usage frequency dynamic priority; it supports reverse learning updates for fields manually modified and added by the user, and users can view, edit or delete mapping rules at any time; The hierarchical verification call module is used to selectively call the user terminal's local private key for signing, or to invoke the national network identity authentication application to obtain mandatory verification records, based on the node verification level preset in the template. The file association module is used to generate a file hash fingerprint in real time when the user selects or takes a picture of a file, and bind the file hash and the form data hash in the same verification record, making the file and form data cryptographically bound into an inseparable whole. The verification record linking module is used to form a hash-locked chain structure within the data packet by linking the hash values ​​of the current node's verification record with those of the preceding verification record, making the final data packet a self-contained evidence packet that can be fully verified offline. The chain structure includes all flow operation verification records and all process change verification records. The local verification module is used to verify the authenticity and completeness of all verification records in the received data stream, as well as the real-time identity status of the corresponding operator, organization, and device, in a completely offline state. The flow control and archiving module is used to manage the flow order of nodes, control the automatic or manual sending mode, generate a global evidence fingerprint after the flow is completed and perform archiving operations, and trigger a dynamic refresh of the task interface after each node is completed or a process change occurs. The progress query and authorized access module is used to maintain the participant list for each credential, and allows participants to query the progress, final results, and all process change records of the credentials they have participated in; it also allows data subjects to grant temporary data access permissions to third parties after passing national network identity authentication, record access logs, and revoke authorization at any time. The custom archive generation module provides users with an archive file generation interface after the process is completed. Users can choose the export content range, node range, file format, and purpose template. The system generates a formatted archive file based on the user's selection, calculates the hash value of the exported file, and generates an export operation verification record to be appended to the original voucher verification record chain. The multi-mode communication module supports various point-to-point wireless communication methods such as StarFlash, Wi-Fi Direct, near-field communication, and Bluetooth Mesh. In scenarios without cellular network coverage, it automatically discovers nearby devices and establishes a temporary network, utilizes StarFlash's Polar code encoding technology to achieve anti-interference transmission, and automatically degrades to other communication methods when StarFlash is unavailable. It also supports concurrent transmission from multiple devices to achieve parallel processing.

3. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method of claim 1.

4. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the method of claim 1.

5. The method according to claim 1, characterized in that, The sending methods include: automatic sending, in which the data packet is automatically pushed to the next node user terminal after the current node completes its task according to a preset node order; and manual sending, in which the current node user specifies the next node recipient, and the specified action needs to be confirmed through national network identity authentication, and a corresponding specified action verification record is generated and attached to the data packet.

6. The method according to claim 1, characterized in that, The customizer's adjustments to the collection components include: prohibiting photo selection from the album to ensure on-site shooting, setting the verification level of the signature component, and setting file upload format restrictions; the explicit field-action mapping rule library allows users to bind and save custom field types with custom interactive collection components for later reuse.

7. The method according to claim 1, characterized in that, The personalized dynamic task interface distinguishes between current pending tasks, preparatory tasks, parallel tasks, and blocked waiting tasks by color or icon, and displays the estimated completion time of each task. When a process change occurs, the changed node is marked with a special label to indicate the change type, and the status and estimated time of subsequent nodes affected by the change are automatically updated.

8. The method according to claim 1, characterized in that, The explicit field mapping rule table allows users to view, edit, or delete any mapping rule at any time. When there are multiple candidate mappings for the same field, the system sorts them according to historical usage frequency and prioritizes filling in the value with the highest frequency.

9. The method according to claim 1, characterized in that, The reasonable time consumption threshold is dynamically calculated based on node type, historical average time consumption, and standard deviation, and is continuously optimized and adjusted as system operation data accumulates. When the same node is blocked multiple times in a row, the system automatically lowers the threshold of that node to improve the sensitivity of the early warning.

10. The method according to claim 1, characterized in that, Once any process change operation is completed, the process simulation engine automatically recalculates the estimated completion time and task allocation for the affected subsequent nodes and pushes the updated task interface to the affected participants. The templates for various uses include: court evidence packages, which by default contain all process change records, all transfer records, verification records, associated files, and hash verification instructions; regulatory reporting; financial reimbursement; insurance claims; project archiving; and customization. The generated archived files can be attached with a system digital signature to ensure the verifiability of the file source.