An operation execution full-link traceable auditing method and system based on a semantic graph

CN122818320APending Publication Date: 2026-09-25CHENGDU BOWEI DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610980235.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-02
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0002]复杂系统事故调查面临数据孤岛+语义断层的问题,如视频在NVR(网络视频录像机)、设备状态在SCADA(监控与数据采集系统)、操作票在OA/工单、网络日志在IT系统;现有日志缺少将“人(身份/权限)—动作(步骤/对象)—约束判决(为何放行/拦截)—物理后果(状态演化)”串成可审计证据链的结构化机制,导致复盘耗时、定责困难、存在篡改风险;针对此问题,目前采用的方式包括区块链存证/日志不可篡改、IT链路追踪(APM)、SCADA历史曲线与报警记录等,但它们要么缺少操作语义,要么无法在三维孪生中复现场景上下文,也不包含引擎判决依据,综合来看,现阶段还存在以下技术缺点:

Benefits of technology

[0039]在本申请中,针对视频、SCADA、工单、网络日志分散,无法串联人—动作—判决—后果,本发明以事件指纹为节点,按trace_id/资源/状态依赖构建因果DAG,统一关联查询,审计时可直接定位失败叶子条件与物理后果差分,显著降低复盘时间成本;针对传统日志缺少完整性校验,难以对外举证的问题,通过事件链式固化与批次默克尔聚合,并对报告签名,实现第三方可验证,即可证明事件未被改写,满足高合规行业审计与取证要求。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122818320A_ABST
    Figure CN122818320A_ABST
Patent Text Reader

Abstract

The application discloses a kind of operation execution full-link traceable audit method and system based on semantic graph, relating to traceable audit technical field, which comprises: generating event fingerprint corresponding to event for each type of event in runtime, event fingerprint at least includes field identity, operation behavior, context environment, differential snapshot, decision and evidence field;Event fingerprint is solidified by hash chain and builds causal DAG graph;Based on causal DAG graph, verifiable evidence report of traceable audit is generated according to event chain playback state and action in three-dimensional engine;When auditing, failure leaf condition and physical consequence difference can be directly located, which significantly reduces the time cost of review, realizes third-party verifiable, i.e. it can be proved that event has not been rewritten, meets the requirements of high compliance industry audit and evidence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of traceable auditing technology, and more specifically, to a method and system for full-link traceable auditing of operation execution based on semantic graphs. Background Technology

[0002] Complex system accident investigations face the problems of data silos and semantic gaps. For example, video is stored in NVRs (Network Video Recorders), equipment status is stored in SCADA (Supervisory Control and Data Acquisition Systems), operation tickets are stored in OA / work orders, and network logs are stored in IT systems. Existing logs lack a structured mechanism to link "person (identity / authority) - action (step / object) - constraint decision (why allow / block) - physical consequences (state evolution)" into an auditable chain of evidence, resulting in time-consuming review, difficulty in determining responsibility, and the risk of tampering. To address this issue, current methods include blockchain evidence storage / log immutability, IT link tracing (APM), and SCADA historical curves and alarm records. However, these either lack operational semantics, cannot reproduce the scene context in a 3D twin, and do not include the engine's decision-making basis. In summary, the current stage still has the following technical shortcomings:

[0003] 1. Inability to link across layers: People / actions / states / consequences are disconnected;

[0004] 2. Lack of legal basis for judgment: It cannot be proven whether the system fulfilled its responsibility to intercept;

[0005] 3. Clocks are difficult to align, resulting in high retrospective costs; there is also a risk of tampering.

[0006] Therefore, this application is hereby submitted. Summary of the Invention

[0007] The purpose of this invention is to provide a method and system for full-link traceability and auditing of operation execution based on semantic graphs, so as to solve the problems existing in the above-mentioned background technology.

[0008] The above-mentioned technical objective of the present invention is achieved through the following technical solution:

[0009] Firstly, this application provides a method for end-to-end traceable auditing of operation execution based on semantic graphs, including the following specific steps:

[0010] Generate event fingerprints for each type of event during runtime. Event fingerprints include at least the fields of identity identifier, operation behavior, context environment, differential snapshot, and decision and evidence fields.

[0011] The event fingerprint is hashed and solidified, and a causal DAG graph is constructed.

[0012] Based on the causal DAG graph, the state and actions are replayed in the 3D engine according to the event chain to generate a traceable and verifiable evidence report.

[0013] Based on the above technical solution, the present invention can be further improved as follows.

[0014] Furthermore, the above event types include at least request events, allow events, deny events, freeze events, lock events, circuit breaker events, and completion events.

[0015] Furthermore, the aforementioned differential snapshots are generated based on periodic baseline snapshots with a baseline period of 1s–10s.

[0016] Furthermore, the above-mentioned hash chaining of event fingerprints is specifically as follows:

[0017] The sequence of fields used for evidence in the event fingerprint is standardized and solidified to obtain the target string;

[0018] The target string is processed using a cryptographic hash algorithm to obtain a standard JSON serialization, and an event hash chain is formed based on the standard JSON serialization;

[0019] Construct the Merkle root tree according to the time window and optionally write consortium chain and / or timestamp services for batch integrity verification into the event hash chain.

[0020] Furthermore, the construction of causal edges in the aforementioned causal DAG graph includes:

[0021] Temporal causality, linked by the time sequence of events with the same tracking identifier;

[0022] Resource causality: If resources share the same lock resource, a resource causal edge is established.

[0023] State causality: If the state of one event depends on the effect of another event, then a state causal edge is established between the two events.

[0024] Furthermore, the above-mentioned cryptographic hash algorithm is used to process the target string, specifically as follows:

[0025] hash = sha256(payload || prev_hash);

[0026] In the formula, hash represents the calculated hash value, sha256() is the cryptographic hash algorithm function, || represents the concatenation operation, payload represents the payload, and prev_hash represents the previous hash.

[0027] Secondly, this application provides a semantic graph-based operation execution end-to-end traceability auditing system, applied to any of the semantic graph-based operation execution end-to-end traceability auditing methods in the first aspect, including:

[0028] The event fingerprint generation module is used to generate event fingerprints for various types of events during runtime. Event fingerprints include at least the fields of identity identifier, operation behavior, context environment, differential snapshot, and decision and evidence fields.

[0029] The graph construction module is used to hash chain event fingerprints and construct causal DAG graphs.

[0030] The traceability audit module is used to generate verifiable evidence reports for traceability audit based on the causal DAG graph, by replaying the state and actions in the event chain in the 3D engine.

[0031] Furthermore, the above-mentioned hash chaining of event fingerprints is specifically as follows:

[0032] The sequence of fields used for evidence in the event fingerprint is standardized and solidified to obtain the target string;

[0033] The target string is processed using a cryptographic hash algorithm to obtain a standard JSON serialization, and an event hash chain is formed based on the standard JSON serialization;

[0034] Construct the Merkle root tree according to the time window and optionally write consortium chain and / or timestamp services for batch integrity verification into the event hash chain.

[0035] Thirdly, this application provides an electronic device, including: at least one processor, at least one memory, and a data bus;

[0036] In this system, the processor and memory communicate with each other via a data bus; the memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute a semantic graph-based operation execution full-link traceability auditing method as described in any of the first aspects.

[0037] Fourthly, this application provides a non-transitory computer-readable storage medium that stores computer instructions, which cause the computer to execute any of the first aspects of a semantic graph-based operation execution full-link traceability auditing method.

[0038] Compared with the prior art, the present invention has at least the following beneficial effects:

[0039] In this application, addressing the issue that scattered video, SCADA, work orders, and network logs make it impossible to connect the person-action-judgment-consequence process, this invention uses event fingerprints as nodes and constructs a causal DAG based on trace_id / resource / state dependencies for unified association queries. During auditing, it can directly locate the difference between the leaf conditions of failure and the physical consequences, significantly reducing the time cost of review. Addressing the problem of traditional logs lacking integrity verification and being difficult to prove externally, this invention achieves third-party verifiability through event chain solidification and batch Merkel aggregation, along with report signing. This proves that the event has not been rewritten, meeting the audit and evidence collection requirements of highly compliant industries. Attached Figure Description

[0040] The accompanying drawings, which are included to provide a further understanding of embodiments of the invention and form part of this application, do not constitute a limitation thereof. In the drawings:

[0041] Figure 1 This is a flowchart of the auditing method in an embodiment of the present invention;

[0042] Figure 2 This is a schematic diagram of the audit closed-loop process in an embodiment of the present invention;

[0043] Figure 3 This is a schematic diagram of the end-to-end process of audit evidence from generation to solidification and verifiable export in an embodiment of the present invention;

[0044] Figure 4 This is a schematic diagram of the dual-solidification mechanism of event immutability (hash chain) and cross-layer association (causal DAG) in an embodiment of the present invention. Detailed Implementation

[0045] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0046] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.

[0047] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0048] In the description of the embodiments of the present invention, "multiple" means at least two.

[0049] Example 1: This example provides a method for end-to-end traceability and auditing of operation execution based on semantic graphs, including the following specific steps:

[0050] S1 generates event fingerprints for each type of event during runtime. The event fingerprint includes at least the fields of identity, operation behavior, context, differential snapshot, and decision and evidence fields. The differential snapshot is generated based on a periodic baseline snapshot with a baseline period of 1s–10s.

[0051] Among them, the above-mentioned event types include at least request events, allow events, deny events, freeze events, lock events, circuit breaker events, and completion events.

[0052] S2, hash chain the event fingerprint and construct a causal DAG graph.

[0053] Optionally, the above-mentioned hash chaining of event fingerprints is performed as follows:

[0054] S21, standardize and solidify the sequence of fields used for evidence in the event fingerprint to obtain the target string.

[0055] S22 uses a cryptographic hash algorithm to process the target string, obtains a standard JSON serialization, and forms an event hash chain based on the standard JSON serialization.

[0056] Specifically, the above-mentioned cryptographic hash algorithm is used to process the target string, as follows:

[0057] hash = sha256(payload || prev_hash);

[0058] In the formula, hash represents the calculated hash value, sha256() is the cryptographic hash algorithm function, || represents the concatenation operation, payload represents the payload, and prev_hash represents the previous hash.

[0059] S23, construct the Merkle root tree according to the time window and optionally write consortium chain and / or timestamp service for batch integrity verification into the event hash chain.

[0060] Specifically, the construction of causal edges in the aforementioned causal DAG graph includes:

[0061] Temporal causality, linked by the time sequence of events with the same tracking identifier;

[0062] Resource causality: If resources share the same lock resource, a resource causal edge is established.

[0063] State causality: If the state of one event depends on the effect of another event, then a state causal edge is established between the two events.

[0064] S3, based on causal DAG graphs, generates traceable and auditable verifiable evidence reports by replaying states and actions according to event chains in a 3D engine.

[0065] Example 2: This application provides a method for end-to-end traceable auditing of operation execution based on semantic graphs, such as... Figure 2 and Figure 3 As shown, the specific steps include:

[0066] Step S1: Event Capture and Normalization (Runtime Phase):

[0067] 1. Place tracking points on the critical path in the runtime:

[0068] 2. Operation request entry: Generate event_type="REQUEST".

[0069] 3. Rule judgment complete: Generate event_type="ALLOW" or event_type="DENY", along with the failure leaf condition and evidence.

[0070] 4. Intervention trigger: Generate event_type="FREEZE" / "LOCKDOWN" / "CIRCUIT_BREAK".

[0071] 5. Step complete: Generate event_type="COMPLETE".

[0072] 6. Unified event format: Assemble identity, operation, context, snapshot difference, judgment evidence and timestamp into an event fingerprint object EventFingerprint.

[0073] 7. Time Consistency: Event timestamps are uniformly set to milliseconds after gateway synchronization; allowable deviation clock_skew_ms≤20; cross-system events are associated through trace_id.

[0074] The event fingerprint is defined as an octet: E = (id, t, Id, Op, Ctx, Snap, Dec, Hash), where:

[0075] `id` is the unique identifier of the event; `t` is the monotonic timestamp after synchronization; `Id` = (subject identifier, role, authentication method); `Op` = (target object, behavior, tool / medium); `Ctx` = (context fields such as perspective / interface state); `Snap` = (Δ, base_ref) represents the difference from the baseline snapshot; `Dec` = (judgment result, failure leaf condition, evidence value); `Hash` = (prev_hash, hash) is the chained fingerprint.

[0076] Field example: Decision result ∈ {ALLOW, DENY, FREEZE, LOCKDOWN, CIRCUIT_BREAK, COMPLETE}; Δ is a finite mapping of state variables; evidence values ​​are in SI units and the measurement time is recorded.

[0077] Step S2: Differential snapshot generation and attachment sampling (evidence collection stage):

[0078] 1. Global State Tree Snapshot: Maintain periodic baseline snapshots (recommended every 1s–10s), recording the difference delta and base_ref for each event.

[0079] 2. Differential range control: Only record key variables related to this operation (such as valve status, key pressure points, lock resource status) to avoid log bloat.

[0080] 3. Attachment sampling: Capture video clips (e.g., ±5s), screenshots, and terminal UI status before and after high-risk events (LOCKDOWN / CIRCUIT_BREAK) within the time window, store them in object storage, and record the URI and hash in the event fingerprint.

[0081] Step S3: Hash chain solidification and Merkle aggregation (solidification stage), as follows Figure 4 As shown:

[0082] 1. Hash Input: Serialize the fields used for evidence in the event fingerprint into canonical JSON (field order fixed, floating-point normalized, string UTF-8) to obtain the payload.

[0083] 2. Chain-based solidification: Calculate hash = sha256(payload || prev_hash) and write it to prev_hash; form an event hash chain to ensure immutability and traceability.

[0084] Here, the event fingerprint can be denoted as E, containing the field set F = {identity, operation, context, snapshot, decision, ts}; F is serialized into a normalized payload P, using fixed field order, floating-point normalization, and UTF-8 encoding. The hash chain solidification calculation is as follows:

[0085] P = CanonicalSerialize(F); H i = SHA256(P || H i-1 );

[0086] Where H i-1 H0 is the hash of the previous event and H0 is the initial seed value (such as all zeros or the system's initial hash). This chain structure ensures that any tampering with an intermediate event will invalidate all subsequent hash values, achieving immutability and traceability.

[0087] 3. Batch Merkle Tree: Construct the Merkle tree root (merkle_root) according to time windows (e.g., every 1 minute or every 1000 events) for quick batch integrity verification; optional writing to consortium blockchain or third-party timestamp service.

[0088] Specifically, a Merkle root R is constructed according to a time window T (e.g., 1 minute or 1000 events) for batch integrity verification. Let the event hashes within the batch be {H1, H2, ..., H...}. n Hash the nodes pairwise from bottom to top until the root node is reached:

[0089] R = MerkleRoot({H1, H2, ..., H n If R is written to the consortium blockchain or a third-party timestamp service, then credibility can be enhanced.

[0090] Step S4: Causal DAG Construction and Query (Association Phase):

[0091] 1. Causal edge construction:

[0092] 1) Time-based causality: Connect events by time order based on the same trace_id.

[0093] 2) Resource causality: If the same lock resource (such as LINE-5) is shared, an edge is established.

[0094] 3) State causality: If the delta of event B depends on the effect of event A (with the same state_key), establish an edge.

[0095] 2. Graph database storage: Nodes are EventFingerprints, and edges are CAUSES / DEPENDS_ON; supports retrieval by user, device, step, and time range.

[0096] Step S5: 3D Replay and Evidence Export (Debriefing Phase):

[0097] 1. Playback Initialization: Load the BaseSnapshot at the start time and apply it to the 3D scene; set the camera to the camera_pose_id of the event context.

[0098] 2. Event replay: Apply delta in chronological order, overlaying judgment evidence (failure conditions, thresholds, differences) and ghost actions.

[0099] 3. Evidence Export: Export PDF / HTML audit report (event chain, merkle_root, key hash, attachment URI) and sign the report (e.g., Ed25519) for third-party verification.

[0100] Specifically, the 3D spatiotemporal replay algorithm is implemented in the following way:

[0101] Given a time interval [t] start , t end Perform the following playback steps:

[0102] 1. Baseline loading: Loading start time t start The corresponding baseline snapshot (BaseSnapshot) is applied to the initial state of the 3D scene.

[0103] 2. Event Query: Query the sequence of events E = {e1, e2, ..., e} within a time interval in a causal DAG. m}, sorted in ascending order by timestamp;

[0104] 3. Application of state difference: For each event e i Extract its snapshot difference Δ i = e i .snapshot.delta, will Δ i Accumulated to the current scene state S i = S i-1 + Δ i ;

[0105] 4. Viewpoint synchronization: based on the event context e i .context.camera_pose_id sets the camera pose to reproduce the operator's viewpoint;

[0106] 5. Judgment Overlay: Render judgment evidence e in the scene. i .decision includes interpretable information such as failure conditions, thresholds, and differences;

[0107] 6. Ghost Action Replay: Based on e i The .operation tool generates semi-transparent or highlighted "ghost actions" to simulate actual operation trajectories.

[0108] 7. Frame Output: Generates the current scene frame F. i It supports real-time preview or batch export as a video sequence.

[0109] The algorithm ensures that the replay process is strictly consistent with the actual execution in terms of the state evolution sequence, enabling one-click reproduction of the accident scene.

[0110] Example 3: This application provides a semantic graph-based operation execution end-to-end traceability auditing system, applied to the semantic graph-based operation execution end-to-end traceability auditing method of Example 1, including:

[0111] The event fingerprint generation module is used to generate event fingerprints for various types of events during runtime. Event fingerprints include at least the fields of identity identifier, operation behavior, context environment, differential snapshot, and decision and evidence fields.

[0112] The graph construction module is used to hash chain event fingerprints and construct causal DAG graphs.

[0113] The traceability audit module is used to generate verifiable evidence reports for traceability audit based on the causal DAG graph, by replaying the state and actions in the event chain in the 3D engine.

[0114] Furthermore, the above-mentioned hash chaining of event fingerprints is specifically as follows:

[0115] The sequence of fields used for evidence in the event fingerprint is standardized and solidified to obtain the target string;

[0116] The target string is processed using a cryptographic hash algorithm to obtain a standard JSON serialization, and an event hash chain is formed based on the standard JSON serialization;

[0117] Construct the Merkle root tree according to the time window and optionally write consortium chain and / or timestamp services for batch integrity verification into the event hash chain.

[0118] Example 4: This application provides an electronic device, including: at least one processor, at least one memory, and a data bus;

[0119] In this system, the processor and memory communicate with each other via a data bus; the memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute a semantic graph-based operation execution full-link traceability auditing method as described in Embodiment 1.

[0120] Example 5: This application provides a non-transitory computer-readable storage medium that stores computer instructions, which cause the computer to execute a semantic graph-based operation execution full-link traceability auditing method according to Example 1.

[0121] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0122] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0123] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0124] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0125] Those skilled in the art will understand that all or part of the steps in the above facts and methods can be implemented by a program instructing related hardware. The program or the program described therein can be stored in a computer-readable storage medium. When the program is executed, it includes the following steps: at this time, the corresponding method steps are introduced. The storage medium can be ROM / RAM, magnetic disk, optical disk, etc.

[0126] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for end-to-end traceable auditing of operation execution based on semantic graphs, characterized in that, The specific steps include the following: For each type of event during runtime, an event fingerprint is generated. The event fingerprint includes at least the fields of identity identifier, operation behavior, context environment, differential snapshot, and decision and evidence fields. The event fingerprints are hashed and solidified, and a causal DAG graph is constructed. Based on the aforementioned causal DAG graph, a traceable and auditable verifiable evidence report is generated in the 3D engine by replaying the state and actions according to the event chain.

2. The method for end-to-end traceability and auditing of operation execution based on semantic graphs according to claim 1, characterized in that, Event types include at least request events, allow events, deny events, freeze events, lock events, circuit breaker events, and completion events.

3. The method for end-to-end traceability and auditing of operation execution based on semantic graphs according to claim 1, characterized in that, The differential snapshot is generated based on a periodic baseline snapshot with a baseline period of 1s–10s.

4. The method for end-to-end traceability and auditing of operation execution based on semantic graphs according to claim 1, characterized in that, The event fingerprint is hashed and solidified, specifically as follows: The sequence of fields used for evidence in the event fingerprint is standardized and solidified to obtain the target string; The target string is processed using a cryptographic hash algorithm to obtain a standard JSON serialization, and an event hash chain is formed based on the standard JSON serialization; Construct the Merkle root tree according to the time window and optionally write consortium chain and / or timestamp services for batch integrity verification into the event hash chain.

5. The method for end-to-end traceability and auditing of operation execution based on semantic graphs according to claim 1, characterized in that, The construction of causal edges in the causal DAG graph includes: Temporal causality, linked by the time sequence of events with the same tracking identifier; Resource causality: If resources share the same lock resource, a resource causal edge is established. State causality: If the state of one event depends on the effect of another event, then a state causal edge is established between the two events.

6. The method for end-to-end traceability and auditing of operation execution based on semantic graphs according to claim 4, characterized in that, The target string is processed using a cryptographic hash algorithm, specifically as follows: hash = sha256(payload || prev_hash); In the formula, hash represents the calculated hash value, sha256() is the cryptographic hash algorithm function, || represents the concatenation operation, payload represents the payload, and prev_hash represents the previous hash.

7. A semantic graph-based operation execution end-to-end traceability audit system, characterized in that, include: The event fingerprint generation module is used to generate event fingerprints corresponding to various types of events during runtime. The event fingerprint includes at least the fields of identity identifier, operation behavior, context environment, differential snapshot, and decision and evidence fields. The graph construction module is used to hash chain the event fingerprint and construct a causal DAG graph. The traceability audit module is used to generate a traceable and verifiable evidence report based on the causal DAG graph, by replaying the state and actions in the event chain in the 3D engine.

8. The semantic graph-based operation execution end-to-end traceability audit system according to claim 7, characterized in that, The event fingerprint is hashed and solidified, specifically as follows: The sequence of fields used for evidence in the event fingerprint is standardized and solidified to obtain the target string; The target string is processed using a cryptographic hash algorithm to obtain a standard JSON serialization, and an event hash chain is formed based on the standard JSON serialization; Construct the Merkle root tree according to the time window and optionally write consortium chain and / or timestamp services for batch integrity verification into the event hash chain.

9. An electronic device, characterized in that, include: At least one processor, at least one memory, and a data bus; The processor and the memory communicate with each other via the data bus. The memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute a semantic graph-based operation execution end-to-end traceability auditing method as described in any one of claims 1-6.

10. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions that cause the computer to execute the semantic graph-based operation execution full-link traceability auditing method according to any one of claims 1-6.