A smart contract-based salary payment method and system

CN122820155APending Publication Date: 2026-09-25BEIJING SHENGBANG ZHIXIANG TECH DEV CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610878952.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-17
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

在此类物联网与信息系统架构中,大门门禁仅能反映人员进入施工场地边界的状态,无法核实人员是否实际进入有效作业面;同时,由于高层建筑或地下工程存在严重的信号遮挡与多径效应,常规的无线定位技术(如GPS、UWB或蓝牙定位)在垂直方向(Z轴)上极易产生定位漂移,难以分辨层间重叠的真实位置,导致前端采集到的位置坐标难以与具体的作业楼层形成稳定映射

Benefits of technology

[0021]本发明的有益效果在于:本发明将施工现场门禁记录与升降机层站采集的驻留信号相结合,将现场真实到达作业楼层的操作作为计薪凭据的起始节点,利用边缘网关对作业时长进行本地计算和数据签名,随后映射至智能合约执行资金锁定与自动划转,降低了传统无线定位易漂移造成的错层误判率,同时减少了人工造表环节的干预空间,提高了劳动工时提取的客观性以及工资发放流程的准确度与透明度。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122820155A_ABST
    Figure CN122820155A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of smart contracts, and discloses a smart contract-based salary payment method and system, which comprises the following steps: establishing a salary calculation container bound with a wearable terminal in an edge gateway, and recording an access segment generated by the release of an access gate; reading the wearable terminal through a landing anchor point, obtaining a residence signal representing target floor residence and turning, and taking the residence signal as a starting node of a work segment; taking the starting node as a boundary, generating a work duration along a residence track of the wearable terminal in a work area corresponding to the target floor, and obtaining the work segment; then performing edge signature on the work segment to generate a data digest, and mapping the data digest to a smart contract; the smart contract determines a salary amount according to the data digest and the work duration, and locks funds in a salary special account; after a salary payment time arrives, the smart contract automatically transfers the funds to a personal wallet and outputs an account voucher. The application improves the evidence reliability of labor work duration and the objectivity of salary payment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of smart contract technology, and more specifically, to a method and system for payroll disbursement based on smart contracts. Background Technology

[0002] Existing real-name labor registration and wage payment systems generally use gate access control and wireless positioning devices to calculate working hours, and rely on manual compilation of payroll sheets before submission to the bank system for payment. In this type of IoT and information system architecture, gate access control can only reflect the status of personnel entering the construction site boundary, and cannot verify whether personnel have actually entered the effective work area. At the same time, due to the severe signal obstruction and multipath effect in high-rise buildings or underground projects, conventional wireless positioning technologies (such as GPS, UWB or Bluetooth positioning) are prone to positioning drift in the vertical direction (Z-axis), making it difficult to distinguish the true location of overlapping floors, resulting in the difficulty of establishing a stable mapping between the position coordinates collected by the front end and the specific working floor.

[0003] Furthermore, when introducing blockchain or smart contracts into payroll scenarios, existing systems often can only directly upload manually entered attendance results or post-processed datasets to the blockchain. This architecture has a problem: the on-chain logic cannot verify the objective authenticity of the off-chain input data. Because the original data may be intercepted and modified before being transmitted to the smart contract, the triggering basis for automated payroll instructions lacks rigor, leading to anomalies such as mis-level payroll calculation and invalid attendance being counted as time, making it difficult to ensure the data closure and consistency of the entire payroll process. Summary of the Invention

[0004] This invention provides a method and system for payroll based on smart contracts, which solves the technical problems mentioned in the background art.

[0005] Firstly, a smart contract-based salary payment method is applied to a payroll system, which includes an access control gate, a terminal bracket, a floor anchor point, a wearable terminal, an edge gateway, a smart contract, a salary account, a personal wallet, and a user terminal, comprising:

[0006] Based on the action of retrieving the wearable terminal from the terminal holder, a payroll container is established in the edge gateway, and the effective time of the payroll container is registered with the smart contract to form an independent payroll carrier object;

[0007] Obtain the access control gate's release data and activate the entry segment corresponding to the payroll container;

[0008] The wearable terminal is read through the anchor point of the floor station to obtain the dwell signal representing the stay and turn of the target floor. The dwell signal is used as the starting node of the work segment to define the boundary of physical labor.

[0009] The dwell trajectory of the wearable terminal is divided with the starting node as the boundary, and the work duration is generated along the dwell trajectory of the wearable terminal in the work area corresponding to the target floor to obtain the work segment;

[0010] Edge-signing is performed on the operation segment to generate a data digest, and the data digest is mapped to the smart contract;

[0011] The smart contract determines the wage amount based on the data summary and the work duration, and locks the corresponding wage funds in the wage account to isolate human intervention.

[0012] Once payday arrives, the locked salary funds are transferred to the individual wallet via the smart contract, an execution summary is generated, and a receipt containing the execution summary is output.

[0013] Secondly, a smart contract-based payroll system, in executing any one of the smart contract-based payroll methods, includes:

[0014] The container creation module is used to create a payroll container in the edge gateway based on the action of taking the wearable terminal from the terminal holder, and to register the effective time of the payroll container with the smart contract to form an independent payroll carrier object;

[0015] The entry control module is used to acquire the access control gate's release data and activate the entry segment corresponding to the payroll container;

[0016] The node determination module is used to read the wearable terminal through the floor anchor point, obtain the dwell signal representing the stay and turn of the target floor, and use the dwell signal as the starting node of the work segment to define the boundary of physical labor.

[0017] The segment generation module is used to cut the dwell trajectory of the wearable terminal with the starting node as the boundary, generate the work duration along the dwell trajectory of the wearable terminal in the work area corresponding to the target floor, and obtain the work segment;

[0018] The data mapping module is used to perform edge signatures on the job segment to generate a data digest, and then map the data digest to the smart contract.

[0019] The amount locking module is used to determine the wage amount based on the data digest and the work duration through the smart contract, and lock the wage funds corresponding to the wage amount in the wage account to isolate human intervention;

[0020] The automatic transfer module is used to transfer the locked salary funds to the personal wallet through the smart contract after the payday arrives, generate an execution summary, and output a receipt containing the execution summary.

[0021] The beneficial effects of this invention are as follows: This invention combines the access control records of the construction site with the dwell signals collected by the elevator floor stations, and takes the actual operation of reaching the working floor as the starting node of the payroll voucher. The edge gateway is used to perform local calculation and data signing of the operation time, and then mapped to the smart contract to execute fund locking and automatic transfer. This reduces the misjudgment rate of misalignment caused by the easy drift of traditional wireless positioning, and at the same time reduces the intervention space of manual table creation, improving the objectivity of labor time extraction and the accuracy and transparency of the wage payment process. Attached Figure Description

[0022] Figure 1 This is a flowchart of a smart contract-based salary payment method according to the present invention. Detailed Implementation

[0023] The subject matter described herein will now be discussed with reference to exemplary embodiments. It should be understood that these embodiments are discussed only to enable those skilled in the art to better understand and implement the subject matter described herein, and changes may be made to the function and arrangement of the elements discussed without departing from the scope of this specification. Various processes or components may be omitted, substituted, or added as needed in the examples. Furthermore, features described in some examples may be combined in other examples.

[0024] Example 1: A smart contract-based salary payment method applied to a payroll system, which includes an access control gate, terminal rack, layer anchor point, wearable terminal, edge gateway, smart contract, salary account, personal wallet, and user terminal, comprising:

[0025] Based on the action of retrieving the wearable terminal from the terminal holder, a payroll container is established in the edge gateway, and the effective time of the payroll container is registered with the smart contract to form an independent payroll carrier object;

[0026] Obtain the access control gate's release data and activate the entry segment corresponding to the payroll container;

[0027] The wearable terminal is read through the anchor point of the floor station to obtain the dwell signal representing the stay and turn of the target floor. The dwell signal is used as the starting node of the work segment to define the boundary of physical labor.

[0028] The dwell trajectory of the wearable terminal is divided with the starting node as the boundary, and the work duration is generated along the dwell trajectory of the wearable terminal in the work area corresponding to the target floor to obtain the work segment;

[0029] Edge-signing is performed on the operation segment to generate a data digest, and the data digest is mapped to the smart contract;

[0030] The smart contract determines the wage amount based on the data summary and the work duration, and locks the corresponding wage funds in the wage account to isolate human intervention.

[0031] Once payday arrives, the locked salary funds are transferred to the individual wallet via the smart contract, an execution summary is generated, and a receipt containing the execution summary is output.

[0032] The smart contract-based payroll method provided in this embodiment is applied to a payroll system that includes access control gates, terminal racks, floor anchors, wearable terminals, edge gateways, smart contracts, payroll accounts, personal wallets, and user terminals. The edge gateway is deployed in the local network server room at the construction site, using industrial-grade computer hardware, configured with a quad-core 2.0GHz processor, 8GB of RAM, and a 512GB solid-state drive, running a Linux operating system. It possesses data computing, storage, and communication capabilities, used to process work data collected from the front end and interact with the smart contract. The smart contract is deployed on a consortium blockchain network, on Ethereum-compatible consortium blockchain nodes, possessing automatic execution and data immutability characteristics, used to implement the logic of payroll calculation, fund locking, and automatic transfer. The payroll account is a dedicated payroll account opened by the construction company at a commercial bank in accordance with relevant regulations. Funds in the account can only be used for payroll payments. The account has a direct bank-enterprise connection interface, supporting automatic fund transfers and status inquiries. The personal wallet is a blockchain digital wallet held by the construction personnel, supporting the sending and receiving of digital assets on the consortium blockchain network. The wallet address is a 42-bit hexadecimal string. User terminals include smartphones used by construction workers and desktop computers used by project managers. Smartphones run Android or iOS operating systems and have dedicated applications installed to receive accounting vouchers and check payroll status. Desktop computers run Windows operating systems and have project management system clients installed to configure system parameters and view statistical data.

[0033] S201: Detect the action of taking the wearable terminal from the terminal rack, read the device identifier of the wearable terminal, and control the access control gate to complete the identity release.

[0034] The terminal rack is a dedicated device installed at the entrance of the construction site. Each rack position corresponds to one wearable terminal, with built-in contact metal contacts and a low-frequency RFID reading module. When the wearable terminal is placed on the rack, the metal contacts are activated, and the rack detects the terminal's presence. When a construction worker retrieves the wearable terminal, the metal contacts are deactivated, the rack detects the retrieval action, and the low-frequency RFID reading module reads the wearable terminal's device identifier. The device identifier is a globally unique hardware identifier pre-installed on the wearable terminal at the factory, represented by a 16-bit hexadecimal string, used to uniquely distinguish different wearable terminals. The pre-registration process for the wearable terminals is completed when construction workers register upon entry. Project managers use the project management system to bind the construction workers' names, ID numbers, job types, skill levels, and other identity information with the wearable terminal's device identifier. This binding information is stored in the edge gateway's local database and synchronized to the smart contract hourly. The access control gate is a personnel access control device installed at the main entrance of the construction site. It integrates an NFC reader module, mechanical drive components, and a Hall effect position sensor. It communicates with the edge gateway via the MQTT 3.1.1 protocol, using port 1883, and employs username and password authentication. When a construction worker approaches the NFC reader area of ​​the access control gate with a wearable device, the gate reads the device identifier and encapsulates it into a JSON-formatted verification request, which is then sent to the edge gateway. Upon receiving the verification request, the edge gateway queries its local database for pre-stored identity binding information. If the device identifier exists and the corresponding worker's status is "entered," it sends a release command to the access control gate. If the device identifier does not exist or the corresponding worker's status is "departed," it sends a denial command. If authentication fails, the access control gate issues an audible and visual alert, allowing three retries with a 5-second interval. After three consecutive failed authentications, the access control gate locks the device identifier for 10 minutes and sends an alarm message to the project management personnel. When communication between the edge gateway and the access control gate is interrupted, the access control gate switches to local verification mode and uses locally cached identity information for verification. The cached data is updated every 12 hours. After communication is restored, the access control gate synchronizes the locally recorded passage data to the edge gateway.

[0035] After the terminal bracket detects the return of the wearable terminal, it immediately and temporarily locks the work time calculation function of the corresponding pay container. When the wearable terminal is retrieved again, it needs to be re-authenticated through the access control gate to restore the calculation. In the local verification mode of the access control gate, the maximum storage time for cached data is 72 hours. Passage records that have not been synchronized after the time limit are automatically deleted and an alarm is generated. When the wearable terminal is pre-registered, the facial images of the construction personnel must be collected at the same time for secondary identity verification by the access control gate. The facial similarity threshold is set to 85%.

[0036] S202: Encapsulate the real-name token, device identifier, project number, personal wallet address, and assigned container number into a payroll container to bind the user-end association.

[0037] The real-name token is a unique identifier generated by the project management system when construction personnel register upon entry. It uses UUIDv4 format, is a 36-character string, and is uniquely linked to the construction personnel's identity information. The token's validity period coincides with the construction personnel's project work cycle. The project number is a unique identifier for the current construction project, represented by a 10-character string. The first four characters are the project's location code, the middle four characters are the project's year code, and the last two characters are the project sequence number, uniformly assigned by the project management system. The personal wallet address is a 42-character hexadecimal string generated by the construction personnel during registration on the consortium blockchain network, starting with 0x. The personal wallet identity binding verification process is as follows: after generating a wallet address through a dedicated application, the construction personnel upload the wallet address to the project management system. The project management system sends a test token of 0.0001 units to this wallet address. After the construction personnel confirm receipt of the test token in the application, the identity binding of the wallet address is completed. The container number is a unique identifier assigned by the edge gateway to each newly created payroll container. It is generated using an auto-incrementing integer sequence, starting with a value of 1 and a step size of 1. Each project maintains its own auto-incrementing sequence. After the edge gateway restarts, it reads the current maximum container number from the local database and continues the sequence to avoid duplicate numbers. The payroll container is an independent data structure in the edge gateway used to store the full-cycle payroll data for a single construction worker. It is encoded in JSON format with UTF-8 character encoding. The lifecycle management rules for payroll containers are as follows: when a construction worker completes their project work and completes the departure procedures, the edge gateway updates the status of the corresponding payroll container to "destroyed." After destruction, it will no longer receive new work segment data, but historical data will be permanently retained. When a construction worker changes their wearable terminal, the edge gateway creates a new payroll container and migrates the historical work segment data from the old container to the new container.

[0038] Payroll container The calculation formula is:

[0039] ;

[0040] in, It is a real-name token, the data type is string, and the length is 36 characters; This is the device identifier, with a string data type and a length of 16 characters. This is the project number, a string of data type, with a length of 10 characters; This is the address of your personal wallet, a string with a length of 42 characters. This is the container number, and its data type is an integer, with a value range from 1 to 2147483647.

[0041] When the same construction worker works on multiple projects simultaneously, each project generates an independent pay container. The container number is independently auto-incremented according to the project, and the data is completely isolated. After the personal wallet address is modified, the system automatically associates the new address with the historical pay containers. Historical pay records can be queried uniformly through real-name tokens. When verifying the uniqueness of pay containers, the system checks the uniqueness of the combination of device identifier and real-name token to prevent the same person from generating the same container on the same device.

[0042] S203: Send the payroll container to the smart contract to complete the registration of the effective time.

[0043] Each edge gateway possesses a unique node identity within the consortium blockchain network. This identity is obtained through a registration process, during which an ECDSAsecp256k1 key pair is generated. The private key is stored in the edge gateway's hardware security module, while the public key is uploaded to the consortium blockchain's identity management system. All transactions sent by the edge gateway to the smart contract are signed using this private key, with the signature algorithm being ECDSA-SHA256. The smart contract provides an interface named `registerContainer`, with the following function signature:

[0044] functionregisterContainer(stringmemory_tid,stringmemory_did,stringmemory_pid,stringmemory_waddr,uint256_cid)externalreturns(bool).

[0045] The interface parameters follow the same order as the fields in the payroll container, and the return value is a boolean indicating whether registration was successful. The smart contract's access control system uses role-based access control. Only edge gateway nodes have permission to call the `registerContainer` interface. Permissions are assigned by the consortium blockchain administrator during smart contract deployment, and revocation requires the administrator to initiate a multi-signature transaction. After the edge gateway generates the payroll container, it encapsulates the container's fields into transaction data according to the interface requirements, signs the transaction data using a private key, and then sends the transaction to the consortium blockchain node via the JSON-RPC 2.0 protocol, using port 8545. Upon receiving the transaction, the smart contract first verifies the validity of the transaction signature. If verification is successful, it checks whether all fields in the payroll container are non-empty and whether the container number is unique within the current project. If all verifications pass, it stores all parameters of the payroll container and the current blockchain block time as the effective time in the blockchain's state database. The effective time is millisecond-level precise and uses a Unix timestamp. When a transaction fails to send, the edge gateway adopts an exponential backoff retry strategy. The initial retry interval is 1 second, and the retry interval doubles each time. The maximum retry interval is 60 seconds, and the maximum number of retries is 10. After a retry fails, an alarm message is sent to the project management personnel.

[0046] When a smart contract fails to register a payroll container, the edge gateway immediately deletes the ineffective container data stored locally and generates an alarm message containing the reason for the failure. If network latency causes the registration to take effect more than 5 minutes later than the wearable terminal's access time, the system automatically uses the access time as the actual effective time of the payroll container and updates it to the smart contract synchronously. Changes to smart contract permissions must be confirmed by multiple signatures of at least two administrators to prevent abuse of permissions.

[0047] S301: After the mechanical components of the access control gate have completed the full opening and reset actions, record the gate number and passage time.

[0048] The mechanical components of the access control gate include the gate body, drive motor, and Hall position sensor. The Hall position sensor is installed at the gate hinge to detect the rotation angle of the gate body. The criteria for a complete opening and resetting action are: the gate body rotates from the closed state to an angle greater than or equal to 85 degrees, holds for a time greater than or equal to 0.5 seconds, and then rotates back to the closed state with an angle less than or equal to 5 degrees. When the Hall position sensor detects that the gate body has completed a complete opening and resetting action, the access control gate's control system records the current gate number and passage time. The gate number is a unique identifier for each access control gate, represented by a 5-digit string. The first two digits are the last two digits of the project number, and the last three digits are the gate serial number. The passage time is the timestamp of the gate body completing the resetting action, with millisecond precision, represented using a Unix timestamp. The access control gate's local clock is synchronized with the edge gateway's system clock via the NTP network time protocol. The NTP server address is the National Time Service Center server address 210.72.145.44, and the synchronization frequency is once every 10 minutes. When the time deviation exceeds 1 second, the access control gate automatically calibrates its local clock. The gate's anti-false alarm mechanism works as follows: the gate will only open after receiving a release command from the edge gateway. Gate actions in test and maintenance modes will not generate passage records. If the gate is blocked by external force and cannot be reset, the gate will initiate a timeout check with a 10-second timeout threshold. After the timeout, an audible and visual alarm will be issued, and the abnormal information will be sent to the edge gateway. The gate's anti-tailgating logic is as follows: after the gate opens, the infrared beam sensor detects the number of people passing through. When multiple people are detected, a tailgating event is recorded and sent to the edge gateway for manual handling by project managers.

[0049] Every 6 months after the access control gate is put into use, the gate opening angle threshold needs to be calibrated. The calibration method is to manually control the gate to fully open, and the system will automatically record the current angle and set the threshold to 95% of that angle. After the anti-tailgating detection fails, the system will automatically save the gate monitoring video clip for that period of time, which can be viewed and processed by the management personnel through the project management system. If the local clock calibration of the access control gate fails more than 3 times, the passage function will be automatically stopped and an alarm will be generated.

[0050] S302: Combine the gate number, passage time, and container number into an entry segment to separate entry behavior from labor behavior.

[0051] The entry segment is a data structure that records the time and location of construction personnel entering the construction site. It is encoded in JSON format with UTF-8 character encoding. The unique identifier of the entry segment is composed of the container number and the access time, in the format of container number_access time. The deduplication logic for entry segments is as follows: if the edge gateway receives multiple entry records with the same container number within 5 minutes, only the first record is retained, and subsequent records are considered duplicates and discarded. The departure records of construction personnel are generated into departure segments through the same process. The data structure of departure segments is consistent with that of entry segments. When the edge gateway receives a departure segment, it updates the status of the corresponding payable container to "departed". The invalid entry judgment logic is as follows: if no corresponding work segment is generated within 30 minutes after the entry segment is generated, it is judged as an invalid entry. The edge gateway deletes the invalid entry segment from the off-chain cache and updates the status of the payable container to "not entered".

[0052] Entrance footage The calculation formula is:

[0053] ;

[0054] in, This is the gate number, a string of data type, with a length of 5 characters; The data type is integer, and the unit is milliseconds; This is the container number, and its data type is an integer, with a value range from 1 to 2147483647.

[0055] When construction workers enter and exit the construction site multiple times on the same day, each entry segment corresponds to an independent work duration statistics period. After the exit segment is generated, the unfinished work segments within the corresponding period are automatically closed. The correspondence between entry and exit segments is matched by container number and timestamp, and the two most recent records with a time difference of less than 24 hours are automatically paired.

[0056] S303: Write the entry fragment to the off-chain cache and send the entry fragment to the smart contract to limit the entry status of the payroll container.

[0057] The off-chain cache is a Redis 6.2 high-speed cache database deployed locally on the edge gateway. The cache's key-value design uses a unique identifier for the entry fragment as the key and the JSON serialized string of the entry fragment as the value. The Redis cache employs a hybrid RDB+AOF persistence approach, with RDB snapshots generated hourly and AOF logs synchronized every second to ensure data reliability. When deployed across multiple edge gateways, a Redis cluster mode is used, with automatic data sharding and master-slave replication for data synchronization between nodes. After generating an entry fragment, the edge gateway first writes it to the off-chain cache, setting the cache expiration time to 72 hours. Simultaneously, the edge gateway encapsulates the entry fragment into transaction data, signs it with its private key, and sends it to the smart contract. The smart contract provides an interface named `updateEntryStatus` with the following function signature:

[0058] functionupdateEntryStatus(stringmemory_gid,uint256_tpass,uint256_cid)externalreturns(bool).

[0059] After receiving a transaction, the smart contract verifies the signature's validity and the data format's correctness. Then, it locates the corresponding payroll container based on the container number and updates the payroll container's status to "entered." The payroll container's status includes five states: inactive, active, entered, exited, and destroyed. State transitions are triggered as follows: active after successful registration, entered after receiving an entry fragment, exited after receiving an exit fragment, and destroyed after the construction worker leaves. When the smart contract receives a conflicting state transition request, such as an exited container receiving an entry request again, the smart contract rejects the request and returns an error message. The cached expired data cleanup mechanism involves Redis automatically cleaning up expired key-value pairs, and the edge gateway scanning the cache for expired data at 2 AM daily, backing up expired valid entry fragments to the local database, and then deleting them.

[0060] When the Redis cache master node fails, the system automatically switches to a slave node within 30 seconds. After the switch is complete, it automatically synchronizes the non-persistent data within 10 minutes before the master node failed. When there is a conflict in the payroll container status, the system automatically suspends all operations of the container, generates a conflict alarm and pushes it to the administrator. The administrator can resume operations after manually confirming the correct status in the system. When cleaning up expired cache data, the corresponding job fragment temporary cache is also cleaned up to free up system storage space.

[0061] S401: When the wearable terminal passes through a restricted passage consisting of a landing door, an unloading platform, and a floor passage, an anchor signal containing the floor number is sent to the wearable terminal through a fixed landing anchor point.

[0062] The landing door serves as the safety gate between the construction hoist and each floor. The unloading platform is used for loading and unloading building materials. The floor passageway is a closed passageway connecting the landing door to the floor's work area. Together, these three constitute the only restricted access for construction personnel to the work areas on each floor. The landing anchor point is a fixed Bluetooth 5.0 broadcasting device installed at the entrance of each floor's restricted passageway, positioned 1 meter inside the landing door and 1.5 meters above the ground. The broadcasting parameters for the landing anchor point are configured as follows: broadcast channels 37, 38, and 39; broadcast interval of 100 milliseconds; transmit power of -20dBm; and signal coverage radius not exceeding 3 meters. The anchor point signal is a periodically broadcast Bluetooth ADV_NONCONN_IND data packet. This packet contains the current floor number and the anchor point device identifier. The floor number is represented by a 16-bit unsigned integer, and the anchor point device identifier is a 6-byte MAC address. Landing anchor points on adjacent floors use different broadcast channels; for example, odd-numbered floors use channel 37, and even-numbered floors use channel 38, to avoid signal overlap and interference between adjacent floors. When metal obstructions in the construction environment cause signal attenuation, the transmission power can be appropriately increased, with a maximum transmission power not exceeding 0 dBm. The fault detection mechanism for floor anchor points is as follows: the anchor point sends a heartbeat packet to the edge gateway every 30 seconds. If the edge gateway fails to receive three consecutive heartbeat packets, it determines that the anchor point is faulty and sends an alarm message to the project management personnel. During an anchor point fault, the work duration calculation for that floor is replaced by the entry and exit records of the access control gate. Once the anchor point is restored, the calculation is corrected based on the anchor point data. The anchor point signal is encrypted using the AES-128 algorithm. The encryption key is centrally managed by the edge gateway and updated periodically every 7 days. The wearable terminal synchronizes the latest encryption key through the edge gateway to decrypt the anchor point signal.

[0063] The floor anchor point has a built-in power monitoring module. When the battery power is below 20%, it sends a low power alarm to the management personnel once a day, and when the power is below 5%, it sends an alarm once an hour. After replacing the floor anchor point battery, the anchor point's device QR code needs to be scanned through the project management system to complete the re-pairing. After successful pairing, the encryption key is automatically synchronized. When the demolition of floor walls during construction causes the signal coverage to expand, the anchor point's transmission power can be remotely reduced through the system, with each adjustment not exceeding 5dBm.

[0064] S402: Acquire dwell and turning data generated by the wearable terminal based on anchor point signals.

[0065] The wearable device has a built-in Bluetooth 5.0 scanning module and a nine-axis motion sensor. The Bluetooth scanning module is configured with a scanning window of 50 milliseconds, a scanning interval of 100 milliseconds, and a scanning timeout of 5 seconds. When the wearable device enters the signal coverage area of ​​a floor anchor point, it receives the anchor point signal containing the floor number. The wearable device records the start time, end time, and received signal strength indication value of each received anchor point signal. A valid stay is defined as continuously receiving five or more anchor point signals from the same floor, with an average received signal strength indication value greater than or equal to -60 dBm. The average received signal strength indication value is calculated using an arithmetic mean method, i.e., the sum of all received signal strength values ​​divided by the number of signals. Stay data includes the stay start time, stay end time, and average signal strength. The stay duration is the difference between the stay end time and the stay start time, in milliseconds. The nine-axis motion sensor includes a three-axis accelerometer, a three-axis gyroscope, and a three-axis magnetometer, with a sampling frequency of 100Hz, an accelerometer range of ±2g, a gyroscope range of ±250dps, and a magnetometer range of ±4800uT. Sensor data is preprocessed using a moving average filtering algorithm with a sliding window size of 10. Attitude calculation employs the Mahony complementary filtering algorithm with proportional gain Kp of 0.5 and integral gain Ki of 0.05. By fusing data from the accelerometer and magnetometer, gyroscope drift is corrected, and the pitch, roll, and yaw angles of the wearable terminal are calculated. The direction of motion is determined by the yaw angle. The axial direction of the floor passageway is pre-configured in the system. When the angle between the yaw angle and the axial direction of the floor passageway is less than or equal to 30 degrees, the direction of motion for the construction worker is determined to be towards the work area; when the angle is greater than or equal to 150 degrees, the direction of motion is determined to be towards the construction hoist. The wearable device must be worn on the non-dominant wrist of the construction worker. Upon first use, horizontal calibration is required. The calibration method involves placing the wearable device horizontally for 3 seconds, and the system automatically records the initial posture parameters. The filtering logic for invalid dwell times is as follows: dwell data with a duration of less than 3 seconds is considered invalid and discarded.

[0066] When the wearable terminal's battery level drops below 10%, it automatically enters low-power mode, recording location data every 5 seconds and saving all currently unuploaded work data to local flash memory. After charging is complete, the wearable terminal automatically synchronizes the locally saved data to the edge gateway, and resumes normal sampling frequency after synchronization. When construction workers wear the terminal and their wrists droop more than 30 degrees for more than 10 seconds, the system automatically starts the posture correction program to correct the motion direction calculation results.

[0067] S403: Encapsulate dwell data, turning data, and floor number into dwell signals and set them as the starting node of the work segment to define the boundaries of physical labor.

[0068] The dwell signal is a data structure recording when construction workers arrive at the target floor and prepare to enter the work area. It is encoded in JSON format with UTF-8 character encoding. The deduplication and merging logic for dwell signals is as follows: when multiple dwell signals for the same floor are generated within one minute for the same container number, they are merged into one dwell signal, with the earliest dwell signal generation time as the start time. When the wearable terminal receives anchor signals from multiple floors simultaneously, the floor with the strongest average signal strength is selected as the target floor, and the corresponding dwell signal is generated. The start node is the start time point for calculating the work duration, i.e., the timestamp of the dwell signal generation, with millisecond precision.

[0069] Dwelling signal The calculation formula is:

[0070] ;

[0071] in, The data is for stay information, and the data type is object, containing three fields: stay start time, stay end time, and average signal strength. For redirection data, the data type is floating point, the unit is degree, and the value range is 0 to 360; This is the floor number, with an integer data type and a value range of 1 to 200.

[0072] If no positioning signal is detected in the work area within 5 minutes after the dwell signal is generated, the system will automatically invalidate the dwell signal and not generate the corresponding work segment. When there are multiple restricted channels on the same floor, the dwell signals generated by different channels will be merged in chronological order, with the later generated signal covering the earlier generated signal. When there is a signal conflict on multiple floors, if the signal strength difference between two floors is less than 10dBm, the system will automatically mark that period as abnormal, and the target floor will be manually confirmed by the management personnel.

[0073] S501: Starting from the initial node, track the dwell trajectory of the wearable terminal in the work area corresponding to the target floor to generate the work duration.

[0074] The work area is a pre-defined work zone for construction workers within each floor. This zone is configured by project managers using polygon coordinates within the project management system, employing a local plane coordinate system. The origin is the southwest corner of the floor, with the X-axis pointing east and the Y-axis pointing north, and the unit is meters. Each work area consists of at least three vertex coordinates, rounded to two decimal places. A Bluetooth 5.0 positioning beacon is deployed every 20 square meters within the work area, installed at a height of 2.5 meters above the ground, with a broadcast interval of 100 milliseconds and a transmission power of -10dBm. The edge gateway receives Bluetooth signal strength data periodically transmitted by the wearable terminals and calculates the real-time location of the wearable terminals using trilateration, achieving a positioning accuracy of 1 meter. Positioning drift correction employs a Kalman filter algorithm, smoothing the positioning trajectory through prediction and update steps. Positioning drift is identified when three consecutive positioning points are outside the work area for a total duration of less than 5 seconds, without pausing the work duration calculation. Distinguishing between multiple users' positioning data is achieved through the device identifier of the wearable terminal. Each wearable terminal transmits a signal containing a unique device identifier, and the edge gateway assigns the positioning data to the corresponding payroll container based on this identifier. The logic for pausing and resuming work time is as follows: if the wearable device is outside the work area for 30 consecutive seconds, the work time calculation is paused; when the wearable device re-enters the work area, the work time continues to accumulate. The work time is accumulated in units of 1 second, and the accumulated result is converted to hours and retained to two decimal places.

[0075] After the work area boundary is adjusted midway through the project, the system supports backtracking the work data from the 30 days prior to the adjustment, recalculating the work duration and generating the corrected work segments; when a single positioning beacon fails, the system automatically uses the signals from three adjacent beacons to perform trilateration calculations, maintaining the positioning accuracy within 2 meters; the positioning beacons within the work area are calibrated quarterly, with a calibration error not exceeding 0.5 meters.

[0076] S502: When the wearable terminal leaves the target floor through the floor gate, turn off the operation time calculation to prevent cross-floor data merging.

[0077] The composite decision logic for leaving the target floor is based on the simultaneous fulfillment of the following three conditions: the wearable terminal receives the anchor signal of the current floor; the turning data shows that the worker's movement direction is towards the construction elevator; and no positioning signal from the wearable terminal is detected in the work area for 10 consecutive seconds. When all three conditions are met, the edge gateway immediately stops calculating the work duration for the current floor and records the end time of the work duration. The time segmentation logic for continuous cross-floor work is as follows: each time a worker enters a new floor, a new dwell signal is generated as the starting node of the new work segment. When leaving the current floor, the time calculation of the current work segment is stopped, ensuring that each work segment corresponds to the work duration of only one floor. The batch departure processing logic is as follows: in case of an emergency, the project manager sends an emergency evacuation signal through the project management system. Upon receiving the signal, the edge gateway immediately stops all currently calculated work durations, and the end time of the work duration is the time the emergency evacuation signal is received.

[0078] If a construction worker leaves the work area to enter a non-work area such as a restroom or tea room for no more than 15 minutes, the time will continue to be counted as work time; if the time exceeds 15 minutes, the work time calculation will be suspended and will resume upon returning; when working across floors, the time spent in the elevator will be counted as work time for leaving the floor, and if the time spent in the elevator exceeds 5 minutes, it will be counted as work time for entering the new floor; after an emergency evacuation signal is issued, the end time of all work time will be the same as the time the signal is issued, without waiting for the determination of leaving the floor.

[0079] S503: Obtain the preset salary standard, combine the work duration, floor number, salary standard and container number to generate a work segment.

[0080] The salary standard is a multi-dimensional wage standard pre-set in the project management system, linked to floor number, job type, skill level, and overtime hours. Job types include carpentry, steelwork, and concrete work; skill levels are divided into basic, intermediate, and advanced; and overtime hours are divided into weekday overtime, weekend overtime, and statutory holiday overtime. The unit of the salary standard is uniformly yuan per hour. The salary standard for normal working hours is set according to job type and skill level: the salary standard for weekday overtime is 1.5 times the normal standard, for weekend overtime it is 2 times, and for statutory holiday overtime it is 3 times. The overtime multiplier only affects the salary standard and does not directly affect the work hours. The dynamic update rule for the salary standard is as follows: after the salary standard is updated, work segments generated before the update time use the salary standard before the update, and work segments generated after the update time use the updated salary standard. The rounding rule for work hours is to retain two decimal places using the rounding method. The filtering logic for abnormal work duration is as follows: work segments with a cumulative daily work duration exceeding 16 hours are marked as abnormal. Abnormal work segments need to be manually reviewed and confirmed by project management personnel before they can be included in the salary calculation.

[0081] Homework snippets The calculation formula is:

[0082] ;

[0083] in, The duration of the task is a floating-point number, in hours, and rounded to two decimal places. This is the floor number, with an integer data type and a value range of 1 to 200; This is the salary standard, with a floating-point data type, a unit of yuan per hour, and two decimal places. This is the container number, and its data type is an integer, with a value range from 1 to 2147483647.

[0084] The system automatically matches the corresponding job type and skill level based on the construction worker's real-name token and obtains the corresponding salary standard without manual intervention. When abnormal work hours are manually reviewed, managers can view the corresponding location trajectory and access control records. After confirming that there are no errors, the system marks it as valid, and the marking result is automatically synchronized to the smart contract. When the salary standard is adjusted, it must be publicized in the system 7 days in advance, and it will officially take effect after the publicity period ends.

[0085] S601: Generate a data digest by edge signing the job segment within the edge gateway.

[0086] The binary serialization of job segments uses Protocol Buffers 3.0 format, with big-endian byte order. The field serialization order strictly follows the field order in the job segment formula: first, the job duration; then, the floor number; next, the salary standard; and finally, the container number. Edge signature uses the SM2 elliptic curve digital signature algorithm. The edge gateway generates an SM2 key pair; the private key is stored in the hardware security module, and the public key is uploaded to the smart contract. The data digest uses the SHA-256 hash algorithm to hash the binary serialized data of the job segment, generating a 256-bit hash value. Then, the edge gateway's SM2 private key is used to sign the data digest, generating a signature value.

[0087] Data Summary The calculation formula is:

[0088] ;

[0089] in, For homework segments ProtocolBuffers binary serialization data.

[0090] Edge signature The calculation formula is:

[0091] ;

[0092] in, The SM2 private key for the edge gateway; This is a data summary of a task segment.

[0093] The edge gateway is configured with two hardware security modules, one primary and one backup. When the primary module fails, it automatically switches to the backup module, with a switching time of no more than 1 second. The key is automatically updated every 90 days, and the update process does not affect normal signature operations. When job fragment serialization fails, it automatically retryes 3 times with a retry interval of 1 second. After a retry failure, an alarm is generated and the original data is saved.

[0094] S602: Obtain the set wage period, organize all data summaries within the wage period into a root value to compress the on-chain data volume.

[0095] The pay cycle is a calendar month, with a precise time range from 00:00:00.000 on the 1st of the month to 23:59:59.999 on the last day of the month, represented using Unix timestamps. The Merkle tree is constructed as follows: the data digests of all job segments corresponding to the same container number within the pay cycle are used as leaf nodes, arranged in ascending order of job segment generation time, and then SHA-256 hash calculations are performed layer by layer to generate a unique digest root value. If no job segment is generated within the pay cycle, the digest root value is a 256-bit hash value consisting entirely of zeros. After generating the digest root value, the edge gateway signs the digest root value using the SM2 private key to generate the root value signature.

[0096] Summary Root Value The calculation formula is:

[0097] ;

[0098] in, This is a data summary of the 1st to nth job segments corresponding to the same container number within the pay cycle, sorted in ascending order by generation time. This represents the total number of job segments generated within the pay cycle for this container number, ranging from 0 to a positive integer.

[0099] When there are no job segments within a pay period, the system generates a zero-based digest root value and uploads it to the blockchain, while marking the period as jobless in the remarks field; the Merkle tree intermediate node data is stored in the local database of the edge gateway, with a retention period consistent with the original job segment; when the digest root value signature verification fails, the smart contract refuses to accept the data and notifies the administrator to regenerate it.

[0100] S603: Store the original job fragment in off-chain storage on the local network.

[0101] The off-chain storage is an IPFS distributed file storage system, version 0.18.1, deployed on the project's local network. Original job fragments are encrypted using the AES-256-GCM algorithm. Encryption keys are generated and managed by the edge gateway, with each job fragment using a unique key stored in the edge gateway's hardware security module. Access control employs a role-based access control mechanism. System roles include project administrators, auditors, and construction personnel. Project administrators have read and write permissions for all data, auditors have read-only permissions, and construction personnel can only access their own job fragment data. The data integrity verification mechanism involves storing the SHA-256 data digest of each job fragment during storage. When reading data, the digest is recalculated and compared with the stored digest; if they do not match, the data is considered tampered with. The off-chain storage uses a multi-replica backup mechanism, storing three copies of each file distributed across different storage nodes to ensure data reliability and availability.

[0102] When expanding the off-chain storage system, an online expansion method is adopted to ensure that normal data read and write operations are not interrupted. After the data migration is completed, the integrity of all migrated data is verified. Once the verification pass rate reaches 100%, the original node data is deleted. After the construction personnel leave the company, their work data will continue to be retained for 5 years and will be automatically destroyed after 5 years. Before the destruction, a data destruction record will be generated and permanently stored.

[0103] S604: Write the digest root value, project number, pay cycle, and container number into the smart contract to complete the on-chain mapping.

[0104] The on-chain mapping is triggered at 09:00:00 on the first working day after the end of each payroll period. The edge gateway packages the digest root value, root value signature, project number, payroll period start time, payroll period end time, and container number corresponding to all payroll containers within the payroll period into transaction data, signs it with the ECDSA private key, and sends it to the smart contract. The smart contract provides an interface named uploadMerkleRoot, with the function signature as follows:

[0105] functionuploadMerkleRoot(bytes32_root,bytesmemory_sig,stringmemory_pid,uint256_start,uint256_end,uint256_cid)externalreturns(bool).

[0106] After receiving a transaction, the smart contract verifies the legality of the transaction signature, and then uses the SM2 public key of the edge gateway to verify the legality of the root value signature. Once the verification is successful, the above data is stored in the blockchain's state database and bound to the corresponding payroll container.

[0107] When on-chain mapping fails, an exponential backoff strategy is adopted for retrying, with a maximum of 5 retries. An emergency alarm is generated after a retry failure. For multiple mapping requests within the same pay period, the system automatically deduplicates them based on the container number and pay period, retaining only the first successful mapping result. After mapping is completed, the system automatically generates a mapping report, which includes the number of successful and failed containers and the reasons.

[0108] S701: After the pay cycle ends, the smart contract summarizes the corresponding job fragments according to the container number based on the mapped digest root value.

[0109] After the payroll period ends, the smart contract automatically triggers the payroll calculation process at 09:00:00 on the second working day following the payroll period. The smart contract iterates through all payroll containers in the "entered" state, finding the corresponding digest root value and payroll period information based on the container number. Then, the smart contract sends a data retrieval request to the off-chain storage system to obtain all original job fragments and Merkle tree intermediate node data for that container number within the corresponding payroll period. The smart contract first verifies the validity of the data digest and edge signature for each job fragment. Then, it sorts the job fragments in ascending order of generation time, reconstructs the Merkle tree, and calculates the root value. The calculated root value is compared with the digest root value stored on-chain. If they match, the verification passes, and the job fragment data is valid; if they do not match, the verification fails, the job fragment data corresponding to that container number is rejected, and an alert is sent to the project management personnel.

[0110] When a smart contract fails to retrieve data from off-chain storage, it will retry 3 times with a 5-second interval and a timeout of 30 seconds. After the data retrieval timeout, the smart contract will pause the wage calculation for that container and notify the administrator to manually upload the data. For failed job data verification, the administrator can view the original data and verification logs, and after confirming that it is correct, manually mark it as valid and resubmit it for verification.

[0111] S702: Determine the wage amount based on the salary standard and working hours, and generate a payment instruction.

[0112] After the smart contract verifies the validity of the job segment data, it multiplies the job duration of all job segments corresponding to that container number by the corresponding salary standard, and then sums them up to obtain the salary amount corresponding to that pay container. The job duration of all job segments is uniformly in hours, and the salary standard is uniformly in yuan per hour. The payment instruction includes the individual's wallet address, salary amount, and payment validity period. The payment validity period is 7 calendar days after the pay date. Payment instructions that are not executed after the payment validity period will automatically expire.

[0113] Salary amount The calculation formula is:

[0114]

[0115] in, Let be the duration of the i-th task segment, in hours; Here is the salary standard for the i-th task segment, in yuan per hour; The total number of valid job segments for this container within the pay cycle.

[0116] The salary calculation result is rounded to two decimal places using the rounding method. If the third decimal place is greater than or equal to 5, it is rounded up; if it is less than 5, it is rounded down. After the payment instruction is generated, the system automatically generates a preview report, which can be checked by managers 3 days before payday. If the check is correct, the instruction can be confirmed and executed. If an error is found, the payment instruction can be canceled and the calculation can be recalculated.

[0117] S703: Send the payment instruction to the pre-deposited salary account for labor costs, and lock the salary funds in the salary account that belong exclusively to the individual's wallet.

[0118] The smart contract connects to the payroll account bank system via a direct bank-enterprise interface, using HTTPS 1.3 for communication, the SM2 algorithm for interface signing, and TLS 1.3 for data encryption. Payment instructions follow standard bank specifications, including the paying account, receiving account, transfer amount, transaction serial number, and remarks. After generating the payment instruction, the smart contract signs it with its private key and sends it to the payroll account bank system via the bank interface. Upon receiving the payment instruction, the bank system verifies the signature's validity and format correctness. If verification is successful, it locks funds equal to the salary amount in the payroll account. These locked funds can only be transferred to the personal wallet address specified in the payment instruction; no entity or individual may misappropriate or retain them.

[0119] When the bank system returns a failure to lock funds, the system immediately generates an insufficient balance alarm, notifying the administrator to replenish the funds within 24 hours. After the funds are replenished, the system will automatically re-initiate the lock request. If the funds are not replenished within 24 hours, the process will be postponed to the next working day. After the funds are locked, if no transfer is executed within 7 days, the funds will be automatically unlocked and returned to the salary account.

[0120] S801: When the payday falls on the payday of the pay cycle, the payroll account is triggered to transfer funds via a smart contract.

[0121] Payday is the 15th of each month. If payday falls on a public holiday or rest day, it will be postponed to the next working day. The smart contract monitors the blockchain network's block time in real time. When the block time reaches 00:00:00.000 on the payday, the fund transfer process is automatically triggered. The smart contract sends a fund transfer instruction to the bank system of the payroll account, which contains payment instructions for all locked funds.

[0122] When the bank system is under maintenance on the payday, the system will automatically postpone the payday to the first working day after the bank system is restored and notify all construction personnel via SMS. If the smart contract fails to trigger a transfer, it will retry 3 times with a 10-minute interval. An alarm will be generated after a retry failure. The transfer trigger time can be adjusted according to the bank system's working hours, with an adjustment range of 0:00 to 18:00.

[0123] S802: Transfer the locked salary funds to the individual wallet in the receiving state to complete the salary settlement.

[0124] After receiving a fund transfer instruction from the smart contract, the bank system verifies the validity of each payment instruction and the fund lock status. Upon successful verification, the bank system transfers the funds locked in the salary account to the corresponding personal wallet address in installments. A personal wallet being in a receiving state means that the personal wallet address is a legitimate consortium blockchain address and has not been frozen or cancelled. After the fund transfer is completed, the bank system sends a successful transfer receipt to the smart contract, which includes the transaction serial number, transfer time, and transfer amount. If the transfer fails due to an invalid personal wallet address, a frozen wallet, or other reasons, the bank system will send a failed transfer receipt to the smart contract. The smart contract will then unlock the corresponding funds and send an alert to the project administrators, who will verify the information and re-initiate the transfer.

[0125] After a failed transfer, the funds will be automatically unlocked within 1 hour. The number of times a transfer can be re-initiated is limited to 3 times. After 3 times, the transfer must be initiated manually. After the funds are received in the personal wallet, in addition to SMS and application push notifications, a notification can also be received via the linked email address. After a successful transfer, the bank system will generate an electronic receipt within 24 hours, which can be downloaded from the project management system.

[0126] S803: After the transfer is completed, an execution summary is generated, and an invoice containing the project number, real-name token, salary cycle, salary amount, payment identifier and execution summary is generated. The corresponding invoice is then output to the user terminal to establish a fund ownership confirmation and traceability node.

[0127] The execution digest records detailed information about the fund transfer process, including the transfer time, sending account, receiving account, transfer amount, and bank transaction number. The recipient identifier is a unique 32-bit string generated by the bank system to identify the transfer. The receipt voucher is encoded in JSON format with UTF-8 character encoding. After receiving the successful transfer confirmation from the bank system, the smart contract generates an execution digest and combines the project number, real-name token, salary cycle start time, salary cycle end time, salary amount, recipient identifier, and execution digest to generate a receipt voucher. Then, the smart contract calculates the SHA-256 hash value of the receipt voucher and stores the hash value on the blockchain, forming an immutable fund ownership traceability node. Simultaneously, the edge gateway outputs the receipt voucher to the construction workers' user terminals via SMS and application push notifications. Construction workers can view and download the receipt voucher on their user terminals and verify it by querying the hash value through a blockchain explorer.

[0128] receipt voucher The calculation formula is:

[0129] ;

[0130] in, This is the project number, a string of data type, with a length of 10 characters; It is a real-name token, the data type is string, and the length is 36 characters; For the salary cycle, the data type is an object, containing two fields: start time and end time, with the unit being milliseconds; This represents the salary amount, with a floating-point data type, unit of yuan, and rounded to two decimal places. This is a payment receipt identifier; the data type is string, and the length is 32 characters. The execution summary is an object with five fields: transfer time, sending account, receiving account, transfer amount, and transaction number.

[0131] The receipt voucher supports the addition of electronic signatures, which have the same legal effect as paper seals. In the event of a labor dispute, the hash value of the receipt voucher can be queried through a blockchain explorer and compared with the hash value of the local voucher to verify the authenticity of the voucher. The receipt voucher is permanently stored on the blockchain and can be queried and downloaded at any time.

[0132] Example 2: A payroll system based on smart contracts, comprising executing a payroll method based on smart contracts as described in any one of the embodiments, including:

[0133] The container creation module is used to create a payroll container in the edge gateway based on the action of taking the wearable terminal from the terminal holder, and to register the effective time of the payroll container with the smart contract to form an independent payroll carrier object;

[0134] The entry control module is used to acquire the access control gate's release data and activate the entry segment corresponding to the payroll container;

[0135] The node determination module is used to read the wearable terminal through the floor anchor point, obtain the dwell signal representing the stay and turn of the target floor, and use the dwell signal as the starting node of the work segment to define the boundary of physical labor.

[0136] The segment generation module is used to cut the dwell trajectory of the wearable terminal with the starting node as the boundary, generate the work duration along the dwell trajectory of the wearable terminal in the work area corresponding to the target floor, and obtain the work segment;

[0137] The data mapping module is used to perform edge signatures on the job segment to generate a data digest, and then map the data digest to the smart contract.

[0138] The amount locking module is used to determine the wage amount based on the data digest and the work duration through the smart contract, and lock the wage funds corresponding to the wage amount in the wage account to isolate human intervention;

[0139] The automatic transfer module is used to transfer the locked salary funds to the personal wallet through the smart contract after the payday arrives, generate an execution summary, and output a receipt containing the execution summary.

[0140] The embodiments of this example have been described above. However, this example is not limited to the specific implementation methods described above. The specific implementation methods described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms based on the guidance of this example, and all of them are within the protection scope of this example.

Claims

1. A payroll disbursement method based on smart contracts, applied to a payroll system, the payroll system comprising an access control gate, a terminal bracket, a floor anchor point, a wearable terminal, an edge gateway, a smart contract, a payroll account, a personal wallet, and a user terminal, characterized in that, include: Based on the action of retrieving the wearable terminal from the terminal holder, a payroll container is established in the edge gateway, and the effective time of the payroll container is registered with the smart contract to form an independent payroll carrier object; Obtain the access control gate's release data and activate the entry segment corresponding to the payroll container; The wearable terminal is read through the anchor point of the floor station to obtain the dwell signal representing the stay and turn of the target floor. The dwell signal is used as the starting node of the work segment to define the boundary of physical labor. The dwell trajectory of the wearable terminal is divided with the starting node as the boundary, and the work duration is generated along the dwell trajectory of the wearable terminal in the work area corresponding to the target floor to obtain the work segment; Edge-signing is performed on the operation segment to generate a data digest, and the data digest is mapped to the smart contract; The smart contract determines the wage amount based on the data summary and the work duration, and locks the corresponding wage funds in the wage account to isolate human intervention. Once payday arrives, the locked salary funds are transferred to the individual wallet via the smart contract, an execution summary is generated, and a receipt containing the execution summary is output.

2. The method for payroll disbursement based on smart contracts according to claim 1, characterized in that, The establishment of the payroll container and registration of the effective time include: Read the device identifier of the wearable terminal and control the access control gate to complete identity clearance; The real-name token, the device identifier, the project number, the address of the personal wallet, and the assigned container number are encapsulated into the payroll container to bind the user-end association relationship; Send the payroll container to the smart contract to complete the registration of the effective time.

3. The method for payroll disbursement based on smart contracts according to claim 2, characterized in that, The opening of the entry segment corresponding to the payroll container includes: After the mechanical components of the access control gate have completed the full opening and resetting process, the gate number and passage time are recorded. The gate number, the passage time, and the container number are combined into the entry segment to separate the entry behavior from the labor behavior; The entry fragment is written to the off-chain cache and sent to the smart contract to limit the entry status of the payroll container.

4. The method for payroll disbursement based on smart contracts according to claim 3, characterized in that, The step of acquiring dwell signals characterizing the target floor's stay and turning, and using these dwell signals as the starting node of the work segment, includes: When the wearable terminal passes through a restricted passage consisting of a landing door, an unloading platform, and a floor passage, an anchor point signal containing the floor number is sent to the wearable terminal through the fixed landing anchor point. The wearable terminal acquires dwell data and turning data generated based on the anchor point signal; The dwell data, the turning data, and the floor number are encapsulated into the dwell signal and set as the starting node of the work segment.

5. A method for payroll disbursement based on smart contracts according to claim 4, characterized in that, The process of generating a work duration along the dwell trajectory of the wearable terminal within the work area corresponding to the target floor, to obtain the work segment, includes: Starting from the starting node, the work duration is generated by tracking the dwell trajectory of the wearable terminal within the work area corresponding to the target floor. When the wearable terminal leaves the target floor through the terminal door, the operation time calculation is turned off to prevent cross-floor data merging; Obtain the preset salary standard, and combine the work duration, the floor number, the salary standard and the container number to generate the work segment.

6. The method for payroll disbursement based on smart contracts according to claim 5, characterized in that, The step of edge-signing the job segment to generate a data digest and mapping the data digest to the smart contract includes: The data digest is generated for the job segment within the edge gateway; Obtain the set wage period, and organize all the data digests within the wage period into digest root values ​​to compress the on-chain data volume; The original job fragment is stored in off-chain storage on the local network; The on-chain mapping is completed by writing the digest root value, the project number, the wage cycle, and the container number into the smart contract.

7. A method for payroll disbursement based on smart contracts according to claim 6, characterized in that, The smart contract determines the wage amount based on the data digest and the work duration, and locks the corresponding wage funds in the wage account, including: After the pay cycle ends, the smart contract summarizes the corresponding job segments according to the container number based on the mapped digest root value. The wage amount is determined based on the stated salary standard and the stated work duration, and a payment instruction is generated. The payment instruction is sent to the pre-deposited salary account, and the salary funds belonging exclusively to the individual's wallet are locked in the salary account.

8. A method for payroll disbursement based on smart contracts according to claim 7, characterized in that, Upon the arrival of payday, the locked salary funds are transferred to the individual wallet via the smart contract, an execution summary is generated, and a receipt containing the execution summary is output, including: When the payday falls on the payday of the pay cycle, the smart contract triggers the payroll account to perform a fund transfer. The locked salary funds are transferred to the personal wallet that is in the receiving state to complete the salary settlement; After the transfer is completed, the execution summary is generated, and the receipt voucher containing the project number, the real-name token, the salary cycle, the salary amount, the payment identifier and the execution summary is generated. The corresponding receipt voucher is then output to the user terminal to establish a fund ownership verification and traceability node.

9. A payroll system based on smart contracts, executing the payroll method based on smart contracts as described in any one of claims 1-8, characterized in that, include: The container creation module is used to create a payroll container in the edge gateway based on the action of taking the wearable terminal from the terminal holder, and to register the effective time of the payroll container with the smart contract to form an independent payroll carrier object; The entry control module is used to acquire the access control gate's release data and activate the entry segment corresponding to the payroll container; The node determination module is used to read the wearable terminal through the floor anchor point, obtain the dwell signal representing the stay and turn of the target floor, and use the dwell signal as the starting node of the work segment to define the boundary of physical labor. The segment generation module is used to cut the dwell trajectory of the wearable terminal with the starting node as the boundary, generate the work duration along the dwell trajectory of the wearable terminal in the work area corresponding to the target floor, and obtain the work segment; The data mapping module is used to perform edge signatures on the job segment to generate a data digest, and then map the data digest to the smart contract. The amount locking module is used to determine the wage amount based on the data digest and the work duration through the smart contract, and lock the wage funds corresponding to the wage amount in the wage account to isolate human intervention; The automatic transfer module is used to transfer the locked salary funds to the personal wallet through the smart contract after the payday arrives, generate an execution summary, and output a receipt containing the execution summary.