Blockchain-based cloud warehouse supply chain traceability and data sharing method

CN122840861APending Publication Date: 2026-09-29ANHUI QUANQUAN SUPPLY CHAIN MANAGEMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202611017732.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-09
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

由于复杂的密码学计算极度消耗底层处理器资源,在面临溯源查询请求密集到达时,极易因算力过载而陷入响应停滞

Benefits of technology

[0043]本发明通过提取待处理出库数据总量与轨迹定位数据集合,执行空间几何投影与耗时推演,划定表征集中查询的系统预处理时间窗。驱动可信执行环境在外部并发洪峰触达接入边界前,提前异步执行隐匿授权计算。此机制成功将消耗大量系统计算资源的密码学操作从主干通信链路中剥离,有效避免了高频查询引发的计算节点负荷过载,增强系统在极限并发请求工况下的服务连续性与稳定性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122840861A_ABST
    Figure CN122840861A_ABST
Patent Text Reader

Abstract

The application provides a blockchain-based cloud warehouse supply chain traceability and data sharing method, and relates to the fields of information processing and blockchain technology. The application responds to a cross-domain traceability request by a data processing device, extracts a warehouse-out total quantity and a logistics track to deduce an expected time consumption, delimits a system preprocessing time window and triggers a trusted execution environment to perform an implicit authorization calculation in advance in the window to generate a state code; synchronizes and aligns an online query and an offline entity code scanning time sequence, calculates a time sequence difference value representing a degree of deviation from a real job, and dynamically calculates a privacy noise proportion to inject the state code to generate an implicit shared credential when the difference value is not out of bounds, or forcibly fuses when it is out of limits. The application realizes abnormality detection and adaptive desensitization distribution of secret data combined with a physical job beat, and improves the security and stability of cross-domain interaction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of information processing and blockchain technology, specifically a cloud warehouse supply chain traceability and data sharing method based on blockchain. Background Technology

[0002] Currently, in the fields of information processing and industrial data integration services, especially in cross-domain collaborative management of cloud warehouse supply chains, a common underlying architecture is to put warehouse circulation node information on the blockchain and broadcast hash values ​​to each network node to achieve tamper-proof evidence storage of traceability data status. This data synchronization mechanism based on distributed ledgers provides a foundation for the reliable verification of macro-logistics status. However, this infrastructure has significant limitations in system-level security and access isolation when handling cross-domain data sharing in multi-physical-node cloud warehouses.

[0003] Hash broadcasting can only solve the problem of data integrity verification. Existing technologies (such as the Chinese patent solution with publication number CN118586039A) can prevent historical data from being tampered with, but when cross-domain traceability query requests need to obtain the specific transfer trajectory of the underlying warehouse, there is still a lack of effective data access isolation rules and secure communication mechanisms. This can easily lead to the transmission of sensitive warehouse data across domains in plaintext, posing risks of unauthorized detection and privacy exposure.

[0004] Some systems attempt to introduce isolated sandbox mechanisms, such as trusted execution environments, for covert computation, but face computational bottlenecks in high-frequency scenarios of real-world industrial cloud warehouses. Because complex cryptographic calculations are extremely resource-intensive on the underlying processor, they are prone to overload and stagnation when faced with a dense influx of tracing query requests. Furthermore, existing security authorization mechanisms rely excessively on application-layer digital identity credentials, completely detached from the real physical rhythm of offline operations. They cannot identify and intercept high-frequency abnormal queries from machines using legitimate credentials as cover, nor can they dynamically adjust the protection strength of privacy data based on physical operation characteristics. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a blockchain-based cloud warehouse supply chain traceability and data sharing method. By extracting a preprocessing time window for centralized querying of spatial logistics trajectories, it achieves spatiotemporal decoupling and pre-emptive transfer of computationally intensive processes. Simultaneously, using the microscopic fluctuation characteristics of physical barcode scanning as a reference system, it constructs a dynamic noise reduction and interception logic strongly bound to the physical operation rhythm through multi-dimensional comparison of online and offline time sequences. This addresses the problems mentioned in the background technology.

[0006] To achieve the above objectives, the present invention provides the following technical solution:

[0007] A blockchain-based cloud warehouse supply chain traceability and data sharing method includes the following steps:

[0008] Step S1: In response to the cross-database traceability query request captured by the cross-domain traceability request terminal, extract the total amount of outbound traceability data to be processed and the trajectory positioning data set collected by the order management system and logistics positioning terminal, and simultaneously obtain the online query arrival time series and offline physical scanning time series generated by the cloud access control node and the physical warehouse scanning device, and obtain the encrypted traceability block corresponding to the cross-database traceability query request of the cross-domain traceability request terminal by calling the preset blockchain ledger node query interface;

[0009] Step S2: Calculate the expected handover time based on the total amount of outbound traceability data to be processed and the trajectory positioning data set, so as to define the system preprocessing time window for characterizing centralized queries, and compare the online query arrival time series with the offline entity scanning time series within the preset observation time window to calculate the time interval difference value for characterizing the degree of disconnect between online access frequency and offline actual operation.

[0010] Step S3: Based on the difference between the system preprocessing time window and the time interval value of the centralized query, generate multi-module linkage control instructions for the trusted execution environment and data distribution component;

[0011] Step S4: The multi-module linkage control instructions for the trusted execution environment and data distribution component are configured as follows:

[0012] The trusted execution environment is triggered to perform covert authorization calculation on the encrypted tracing block in advance within the system preprocessing time window of the centralized query, so as to generate a joint verification authorization status code temporarily stored in the secure state transition cache.

[0013] Furthermore, when the time interval difference value does not exceed the preset normal manual scanning error limit, the data distribution component is driven to dynamically calculate the privacy noise ratio based on the time interval difference value and inject it into the joint verification authorization status code, and finally output the data sharing certificate for covert data distribution.

[0014] Preferably, the synchronous acquisition of the online query arrival time series and the offline physical barcode scanning time series generated by the cloud access control node and the physical warehouse barcode scanning device specifically includes:

[0015] Intercept the cross-domain query request data received by the cloud access control node, extract the system received clock record carried in the identifier prefix area of ​​the request data, and summarize and splice them into the online query arrival time series;

[0016] The system monitors the local area network communication queue, obtains the physical check-in logs reported by the physical warehouse barcode scanning device in the work area, removes duplicate check-in records caused by network retransmission in the physical check-in logs, extracts the one-way transmission delay feature parameter between the physical warehouse barcode scanning device and the local area network communication queue, and aligns the timestamps of the cleaned logs with the one-way transmission delay feature parameter as a compensation parameter to generate the offline physical barcode scanning time series.

[0017] Preferably, the extraction of the total amount of outbound traceability data and trajectory positioning data set collected by the order management system and logistics positioning terminal specifically includes:

[0018] Retrieve the shipment task details of the order management data processing device for the current working day, filter and count the total number of shipment orders in the pending fulfillment outbound batch status, and use it as the total amount of outbound traceability data to be processed.

[0019] By using the spatial coordinate synchronization interface of the transportation equipment, the global satellite positioning coordinate stream of the transportation vehicle bound to the batch to be fulfilled and dispatched is retrieved, and the vehicle's current average speed data reported in real time by the vehicle's on-board terminal system is extracted simultaneously, so as to serve as the trajectory positioning data set.

[0020] Preferably, the step of calculating the expected handover time based on the total amount of outbound traceability data to be processed and the trajectory positioning data set, in order to delineate a system preprocessing time window for characterizing centralized queries, specifically includes:

[0021] The latest vehicle coordinates in the trajectory positioning data set are mapped to the effective road segment nodes of the structured road network map around the cloud warehouse through a spatial projection algorithm, and the remaining driving distance is calculated based on the road network topology connectivity distance between the mapped nodes.

[0022] The remaining travel distance is estimated using the vehicle's current average speed, and the total amount of outbound traceability data to be processed is internally loaded based on the pre-acquired historical average throughput of the warehouse.

[0023] The time consumption projection results and the internal loading time conversion results are superimposed on the time axis to draw a time distribution expected curve representing the dense arrival state of the source tracing query request. The time interval above the curve that exceeds the preset system preprocessing trigger threshold is selected and marked as the system preprocessing time window of the centralized query.

[0024] Preferably, within the observation window, by comparing the average step size and variance of the online interface access time interval sequence and the offline scanning action time interval sequence, and by calculating the algebraic difference of the statistical features of the two time intervals, the time interval difference value characterizing whether the frequencies of occurrence of the two parties are synchronized is calculated. Specifically, this is configured to perform the following multi-dimensional feature comparison and state conversion steps:

[0025] Extract the system clock synchronization reference parameters configured in the data processing device;

[0026] Using the system clock synchronization reference parameters, the average step size and variance of the online interface access time interval sequence and the offline scanning action time interval sequence are respectively divided and converted to eliminate the difference in time physical dimensions collected by heterogeneous devices, and generate the average deviation value of request frequency and the fluctuation range of single request time within a unified numerical range.

[0027] Obtain a weighted model for abnormal request risk assessment that has been pre-calibrated offline based on the cloud warehouse's anti-counterfeiting fault tolerance sensitivity;

[0028] The average deviation of the request frequency and the fluctuation range of the single request time are input into the weighted model of abnormal request risk assessment as independent dimensions. By performing a weighted summation calculation based on preset multi-dimensional assessment weights, the concurrent request abnormal risk index, which is used to comprehensively characterize the degree to which the frequency of automated access requests deviates from the actual physical operation, is calculated.

[0029] Extract the value of the concurrent request anomaly risk index and output it as the time interval difference value characterizing the frequency synchronization feature.

[0030] Preferably, the data distribution component is driven to dynamically calculate the privacy noise ratio based on the time interval difference value and inject it into the joint verification authorization status code, ultimately outputting a data sharing credential for covert data distribution, specifically including:

[0031] Extract the preset initial privacy noise distribution configuration;

[0032] In response to the time interval difference value falling into the time sequence matching tolerance range of the physical operation that represents the actual offline human operation, a preset reference noise lower limit ratio is substituted into the initial privacy noise distribution configuration to inject the lowest intensity of protection disturbance data into the joint verification authorization status code and generate a clear data sharing certificate.

[0033] In response to the timing interval difference value exceeding the timing matching tolerance range of the entity operation but within the normal manual scanning error limit, based on the difference deviation amplification factor of the timing interval difference value, the intensity of the privacy noise ratio is synchronously and proportionally amplified. By applying the amplified normalized privacy noise ratio as the underlying byte control instruction, the output sequence of the joint verification authorization status code is hidden and desensitized, and the data sharing certificate with desensitized granularity downgrade is generated.

[0034] Preferably, after generating multi-module linkage control instructions for the trusted execution environment and data distribution component based on the difference between the system preprocessing time window and the time interval value of the centralized query, the method further includes:

[0035] In response to the monitoring of the absolute value of the time interval difference value directly exceeding the normal manual scanning error limit, it is determined that the cloud warehouse server node is experiencing non-manual abnormal high-frequency query requests that are out of sync with the actual operation and physical rhythm.

[0036] Generate concurrent overload forced blocking signaling that is mutually exclusive with the multi-module linkage control instructions, interrupt the current decryption authorization processing flow of the trusted execution environment, synchronously clear the joint verification authorization status code data temporarily stored in the security state transition buffer, and perform communication connection isolation operation on the source access address of the cross-database traceability query request issued by the cross-domain traceability request end.

[0037] Preferably, during the process of generating the data sharing certificate with desensitized granularity downgraded, the following sensitive information partial masking operation is also performed simultaneously:

[0038] The risk level and desensitization parameter comparison table, which is pre-configured in the internal temporary storage unit of the server, is invoked. The risk level and desensitization parameter comparison table maintains multiple risk tolerance judgment intervals that increase in a step-like manner, as well as a desensitization alternative data sequence that is uniquely bound to each of the risk tolerance judgment intervals.

[0039] The time deviation amplitude value of the time interval difference value exceeds the time sequence matching tolerance range of the entity operation is calculated, and the time deviation amplitude value is used as a matching index to be input into the risk level and desensitization parameter comparison table for interval boundary comparison, so as to extract the target desensitization replacement data sequence that matches the current defense level, and the target desensitization replacement data sequence is used as the data carrier for performing local feature coverage operation;

[0040] The data transmission encapsulation structure of the joint verification authorization status code is parsed, and the data distribution component is driven to perform local feature overlay and secure desensitization replacement operations on the target desensitized replacement data sequence and the core subject identity record area in the joint verification authorization status code;

[0041] While maintaining the overall communication data length and infrastructure boundary of the joint verification authorization status code, the data sharing credential with key identity information de-identified and hidden is generated.

[0042] Compared with the prior art, the beneficial effects of the present invention are:

[0043] This invention extracts the total amount of outbound data to be processed and the trajectory positioning data set, performs spatial geometric projection and time consumption extrapolation, and delineates a system preprocessing time window representing concentrated queries. It drives a trusted execution environment to asynchronously perform covert authorization computation before external concurrency peaks reach the access boundary. This mechanism successfully separates cryptographic operations that consume significant system computing resources from the backbone communication link, effectively avoiding computing node overload caused by high-frequency queries, and enhancing the service continuity and stability of the system under extreme concurrent request conditions.

[0044] This invention simultaneously collects online query arrival time series and offline physical warehouse barcode scanning time series. After eliminating the differences in physical dimensions between heterogeneous devices, it compares and calculates the time interval difference value, which characterizes whether the frequencies of occurrence of the two are synchronized. It can introduce the unavoidable physiological fatigue fluctuations and physical focusing delays of front-line workers into the network protection base, enabling the identification of mechanically automated detection flows disguised as legitimate digital credentials but deviating from the rhythm of real physical operations, thus filling the defense blind spots of traditional digital firewalls.

[0045] Based on the calculated time interval difference value, this invention dynamically maps the privacy noise ratio to the data distribution component. When a request is determined to be within the safety tolerance range, lightweight obfuscation is applied; when faced with suspected out-of-bounds detection, the privacy noise intensity is proportionally amplified and sensitive features are partially masked. By constructing this dynamic data structure replacement mechanism, not only is absolute security isolation of stored privacy data ensured, but the integrity of the communication protocol encapsulation boundary is also maintained, achieving an optimal balance between cross-domain joint verification strength and communication distribution efficiency. Attached Figure Description

[0046] Figure 1 This is a schematic diagram of the system architecture and core logic control process of a blockchain-based cloud warehouse supply chain traceability and data sharing method.

[0047] Figure 2 This is a schematic diagram illustrating the numerical verification results of the relationship between the concurrent request anomaly risk index calculated based on time-series feature dimensionality reduction and the strength of privacy protection.

[0048] Figure 3 This is a diagram illustrating the physical calculation principle of the present invention, which uses the road network spatial projection and time distribution expected curve broadening operation to define the preheating boundary.

[0049] Figure 4A flowchart for multi-dimensional feature dimensionality reduction evaluation and asymmetric defense distribution in cross-domain traceability scenarios of cloud warehouses. Detailed Implementation

[0050] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0051] Example 1:

[0052] Please see Figures 1 to 4 The present invention provides a technical solution:

[0053] A blockchain-based cloud warehouse supply chain traceability and data sharing method, executed by data processing equipment configured on the cloud warehouse server, includes the following steps:

[0054] Step S1 is set up and described as follows: At the zero point of the entire lifecycle, cross-domain acquisition of the source data and extraction of physical entity features are performed. In response to the cross-database traceability query request captured from the cross-domain traceability request end, the total amount of outbound traceability data to be processed and the trajectory positioning data set collected by the order management system and logistics positioning terminal are extracted. Specifically, the following extraction actions are performed:

[0055] The system retrieves the detailed shipment task data set accumulated within the current working day from the order management system (ERP order data scheduling bus) deployed on the cloud warehouse enterprise intranet. This data set is pre-standardized and constructed as a static mapping structure containing traceability batch numbers or globally unique order serial numbers, current real-time logistics fulfillment status tags, product volume / weight dimensions, and uniquely bound trunk line carrier dispatch identifiers. The data processing equipment extracts batch feature data carried in cross-warehouse traceability query requests as retrieval keys, inputs them into this mapping structure, filters and counts the total number of shipments in the pending fulfillment outbound batch status, and directly uses the quantified number of items in this warehouse shipment document as the total amount of outbound traceability data to be processed.

[0056] Through a pre-set spatial coordinate synchronization interface for transportation equipment (a location synchronization open data interface based on a standard encrypted transmission protocol), the global satellite positioning coordinate stream of the transportation vehicles bound to the batches to be fulfilled and dispatched is retrieved (this coordinate stream is generated in real time by the satellite positioning sensing terminals onboard each trunk logistics truck) to serve as a trajectory positioning data set. Simultaneously, the online query arrival time series and offline physical barcode scanning time series generated by the cloud access control node and the physical warehouse barcode scanning equipment are acquired. The following clock cleaning and alignment actions are performed to eliminate jitter and offset interference in the transmission of time-series data over the physical network: Cross-domain query request data received by the cloud access control node deployed on the server is intercepted; the data transmission encapsulation communication protocol stack structure of the request data is parsed; the system received clock record carried in the request data identifier prefix area is extracted; and these are summarized in chronological order to form the online query arrival time series.

[0057] The system monitors the local area network (LAN) communication queue to obtain physical check-in logs reported by physical warehouse scanning devices within the work area. These physical warehouse scanning devices can be mobile wireless scanning devices held by packaging workers on the cloud warehouse assembly line. In highly automated warehousing embodiments, the physical warehouse scanning devices can also be equivalently configured as fixed RFID radio frequency reading access control systems deployed at the outbound nodes of the assembly line conveyor belt, or industrial-grade visual scanning matrix sensors mounted on the end side of automated guided vehicles (AGVs). All of these sensing hardware devices have standardized interfaces and can output physical check-in logs containing the device's physical serial number without loss. The LAN communication queue is constructed from a first-in-first-out (FIFO) memory buffer deployed on the wireless aggregation switch side, which receives and caches communication messages from each underlying sensing terminal in real time according to their arrival timestamps.

[0058] Based on the physical serial number of the device in the physical attendance log, duplicate attendance records caused by retransmission due to fluctuations in the warehouse wireless communication network are removed. The data processing device parses the message header of the physical attendance log, extracts the initial physical scanning timestamp captured locally in real time by the physical warehouse scanning device, and simultaneously obtains the one-way transmission delay characteristic parameter calculated during synchronous interaction between communication nodes in the local area network communication queue. By performing an algebraic compensation subtraction operation on the initial physical scanning timestamp and the one-way transmission delay characteristic parameter, random delay errors in the local area network wireless transmission process are eliminated, thereby outputting the offline physical scanning time sequence reflecting the actual physical scanning time. This offset compensation mechanism intercepts network congestion delay noise mixed in by simple server overwriting. Furthermore, the data processing device, by calling the preset blockchain ledger node query interface, extracts the encrypted traceability block corresponding to the request from the remote cloud warehouse blockchain distributed ledger network based on the unique identifier in the cross-database traceability query request.

[0059] Step S2 specifically includes expected time consumption projection and dimensionality reduction time series feature evaluation: In this embodiment, the expected handover time consumption is calculated based on the total amount of outbound traceability data to be processed and the trajectory positioning data set, so as to delineate the system preprocessing time window used to characterize centralized queries. The specific projection is as follows: Obtain the latest frame of vehicle coordinates containing latitude and longitude parameters, and load the structured road network topology mapping table around the cloud warehouse; the structured road network topology mapping table is generated offline by the cloud warehouse geographic information data processing equipment during the system initialization phase, and its acquisition and construction logic is configured as follows: by calling the open data interface of the standard geographic information system (GIS), the vector road network feature data within the preset physical coverage radius around the cloud warehouse is pulled; the data processing equipment performs spatial map discretization analysis operation on the vector road network feature data, and features the extracted real road intersections and road curvature change points as The physical intersection nodes in the map data are used to establish a unique key-value mapping relationship between the physical intersection node identifier and the absolute latitude and longitude coordinates in the memory block of the mapping table. At the same time, the continuous road entities connecting adjacent nodes are transformed into a set of edges representing the traffic connectivity between nodes, and the actual physical length of the road is calculated using geospatial spherical distance conversion logic. This length value is then fixed as a physical distance value field and associated with the corresponding connected edges. The initial loading of the mapping table is completed through the above multi-dimensional data writing and feature alignment actions, thereby providing a reference physical constraint for subsequent spatial geometric projection.

[0060] In this embodiment, as an engineering example, the structured road network topology mapping table is specifically instantiated as a denormalized composite feature table of road segment benchmarks in the memory pool of the geographic information data processing device. The specific key values ​​and feature mapping structure are set as shown in Table 1 below:

[0061] Table 1: Example of the data structure for a structured road network topology mapping table

[0062] Based on the composite feature mapping network shown in Table 1 above, when the data processing device performs Euclidean distance projection calculation for candidate physical road segments, it directly reads the feature identifiers of connected road segments and extracts the complete coordinates of the start and end nodes without loss within one clock cycle. and This allows the free-floating vehicle location coordinates to be snapped into the actual physical road network topology constraint range.

[0063] To address the aforementioned spatial projection logic and eliminate coordinate calculation errors caused by GPS signal drift, the data processing device extracts the latest frame's latitude and longitude coordinates of the current vehicle. And the start and end node coordinates of each candidate physical road segment in the structured road network topology mapping table. and The data processing node performs the following vertical Euclidean distance derivation calculation based on the spatial geometric mapping relationship:

[0064]

[0065] Where d represents the calculated absolute vertical Euclidean distance from the target vehicle coordinates to the corresponding candidate physical road segment; in this embodiment, the preferred unit of quantification is meters. In actual warehousing and logistics applications, the tolerance range of this parameter is set to the range of [0, 50] meters. If the range is exceeded, the road segment is determined to be physically disconnected. In addition to the single geometric projection method based on absolute vertical Euclidean distance calculation mentioned above, as an extended embodiment with equivalent engineering technical effectiveness and dynamic switching according to specific application scenarios, the data processing node can also be concretely configured to execute a spatial projection algorithm as follows: extract the driving heading angle parameter synchronously reported by the vehicle's on-board terminal in the trajectory positioning data set, and compare it with the static vector direction of the candidate physical road segment to perform angle deviation, thereby filtering out road segments with parallel interference characteristics; or construct a temporal spatial projection algorithm based on a hidden Markov model (HMM), input the vehicle's latitude and longitude coordinates of multiple consecutive frames as the observation sequence into the model, and use the connected edges in the mapping table as hidden state transition constraints, and output the state path with the highest confidence of the system by calculating the transition probability matrix. The data processing equipment extracts the target road segment node mapped and calculated by any of the above spatial projection algorithms, and directly uses it as the vehicle's true mapped coordinates. Along the entity connectivity path in the structured road network topology mapping table, it accumulates and calculates the directed polyline distance between the target road segment node and the fixed geographic coordinates of the cloud warehouse loading / unloading platform, outputting the remaining travel distance. This multi-track projection correction process physically isolates straight-line ranging errors across buildings caused by GPS signal drift.

[0066] This embodiment further extracts the vehicle's current average speed data reported in real time by the vehicle-mounted terminal system (such as a logistics vehicle network status acquisition gateway) from the trajectory positioning data set. The data processing device uses the remaining driving distance generated by the previous mapping as the numerator and the acquired vehicle's current average speed data as the denominator, and performs a division value conversion operation; through this basic algebraic mapping mechanism, the spatial distance parameter is reduced in dimension and transformed into a time dimension representing the time span of logistics entity handover to complete the time consumption extrapolation of physical space;

[0067] The system retrieves the pipeline activation status dictionary within the current cloud warehouse scheduling center in real time. This dictionary is updated synchronously by the programmable logic controller (PLC) hardware network at the cloud warehouse's underlying layer based on real-time level signals. Specifically, it is configured as a key-value pair mapping relationship, containing the physical loading and unloading channel device number as a unique retrieval identifier, and the corresponding active identifier bit data that indicates whether the channel is currently powered on and operating. Based on this, the total number of physical loading and unloading channels in an active operating state is extracted. Before performing queuing mapping, this embodiment injects an anti-downtime verification mechanism into the total number of physical loading and unloading channels: if the total number of physical loading and unloading channels is detected to drop to zero (the cloud warehouse physical loading and unloading nodes encounter extreme offline conditions such as full-line shutdown or shift lock), a hardware anomaly retreat strategy is triggered and the current division conversion link is interrupted. The maximum hysteresis penalty constant (the absolute value is set to 8 hours of the longest single shift cycle) preset in the read-only storage area is retrieved and directly used as the internal loading time conversion result for output, and an alarm signal is simultaneously sent to the downstream edge sensing nodes. Conversely, if the total number of physical loading and unloading channels is greater than zero, the data processing device directly divides the total amount of outbound traceability data obtained in the previous step by the total number of physical loading and unloading channels to map the queuing load margin of a single channel. Based on the warehouse's historical average throughput (the benchmark for the actual number of physical barcode scans processed per hour per channel), the queuing load margin of the single channel calculated normally is divided by a ratio operation, and then the internal loading time conversion result representing the actual physical loading and unloading cycle is output.

[0068] The data processing equipment performs an algebraic summation operation on the estimated time and the internal loading time, generating the expected arrival center reference point (denoted as the distribution mean) for the vehicle's arrival and completion of preparation. The data processing equipment extracts the true arrival delay fluctuation variance characteristics of similar historical transportation routes within the same time period, and performs a square root operation on the true arrival delay fluctuation variance characteristics to extract the dimension-aligned delay fluctuation standard deviation, which is then directly used as the Gaussian expanded standard deviation in the Gaussian probability density distribution equation. The data processing equipment constructs a Gaussian probability density distribution equation: It uses data processing equipment to process the previously calculated expected arrival center reference point. Gaussian Extended Standard Deviation Substituting into the model, a smooth probability density flow is mapped onto the continuous time axis vector t.

[0069] After mapping a smooth probability density flow f(t) onto the continuous time axis vector t, the data processing device extracts the total number of pre-authorized cross-domain tracing requests from the global system within the current time period, and uses this as a baseline mapping coefficient. The data processing device maps the probability density flow f(t) to the reference order of magnitude coefficients. Perform an algebraic chain multiplication mapping operation to generate a flow dimension-expanding function with absolute physical concurrency dimensions. The expanded-dimensional function F(t), after being converted to physical dimensions, is visualized as a time distribution curve representing the expected arrival of future source tracing query requests densely at the server. The Gaussian expanded standard deviation is included. Used to characterize the discrete hysteresis characteristics caused by unknown congestion in the physical road network, in this embodiment its value range is limited to the extreme value range of the statistical maximum likelihood estimate of similar orders in the first quarter of the cloud warehouse's history, so as to ensure that the expansion and extrapolation have an engineering fault tolerance benchmark.

[0070] Define the system preprocessing trigger threshold as . It represents the critical condition of concurrent load for a computing node to securely transition from a low-power sleep state to an authorized decryption computing state. In this preferred embodiment, it is set as the expected concurrent load corresponding to the data processing node load reaching the security warning line. This range is set to prevent excessive consumption of system processing resources due to prematurely waking up the cryptographic decryption module, which could lead to out-of-bounds anomalies such as timeouts in the response of the regular warehouse inbound and outbound query interface.

[0071] The data processing equipment is equipped with an offline computing power sandbox testing mechanism. Specifically, it continuously injects extremely high-frequency request data streams simulating cross-domain tracing requests into the concurrent communication gateway within the offline computing power sandbox. During the step-by-step increase in data stream concurrency, the monitoring probes of the data processing equipment acquire and record in real time the current concurrent task resident volume of the data processing node and the queue length of authorized computing requests within the Trusted Execution Environment (TEE). The data processing equipment uses the absolute convergence rule of ensuring that the response latency of the core inbound and outbound API interface of regular warehousing does not exceed 500 milliseconds, and searches downwards for the extreme inflection point where concurrent query traffic causes system response failure. It directly extracts the extreme concurrency data just before this safety inflection point arrives and solidifies it as the system preprocessing trigger threshold. .

[0072] Furthermore, the data processing equipment extracts the number of authorized cross-domain tracing request endpoints across the entire network within the current time period as a baseline request total mapping coefficient. This previously constructed probability density flow is then algebraically multiplied with the baseline request total mapping coefficient, transforming the dimensionless probability space into a time-series traffic distribution expectation curve characterizing the absolute physical concurrency frequency. This time-series traffic distribution expectation curve is then compared with the previously determined and solidified system preprocessing trigger threshold. Perform continuous time-domain comparison and truncate the curve to show the absolute concurrency exceeding the system preprocessing trigger threshold. The continuous time interval is marked as the system preprocessing time window for centralized query, so as to lock the optimal physical time for the data processing equipment computing resources to warm up.

[0073] Furthermore, this entity verification directly relies on the trunk logistics vehicle network receiving bus deployed in the existing network of a large hub cloud warehouse. The warehouse geographic information system continuously receives real-time latitude and longitude coordinate streams reported by the on-board terminals of various carrier vehicles in the surrounding area that are actually in transit, through a standard encrypted transmission protocol. The data processing equipment uses the received physical vehicle trajectory set and the warehouse throughput logs of the first quarter as data to perform dynamic measurements on the concurrency peak shift and computing power preheating defense line.

[0074] Table 2: Response Calculation for Concurrent Evaluation of Logistics Spatiotemporal Trajectory Projection and TEE Preheating / Wake-up Regular, unobstructed direct routes 12 10 2 150 300 Maintain application-layer synchronization while waiting (dormant state) Rain and snow cause traffic congestion and flood peak shift. 18 35 15 450 300 Extract the key in advance to perform covert computation (pre-warm-up wake-up). Sudden road closures and detours 35 90 40 180 300 Maintain application-layer synchronization while waiting (dormant state) Building obstruction causes severe GPS drift. 85 Reject mapping computation Refuse to convert Cut off and discard 300 Intercept and discard the invalid coordinate stream Extreme promotion with overlapping traffic flow 22 45 18 850 300 Forced pull-up of safe state transition buffer write

[0075] Table 2 above illustrates how spatial displacement is transformed into the wake-up trigger condition for computing nodes. When the coordinates reported by the vehicle terminal and the vertical Euclidean distance d between them and the road network node exceed the system's hard-set tolerance of 50 meters (85 meters as shown in the fourth row), the spatial projection algorithm immediately determines signal distortion and truncates the subsequent processing flow of that branch, effectively avoiding false coordinate contamination. For vehicle data that effectively falls into the road network topology, its time estimation and loading time conversion jointly determine the expected arrival time at the central reference point. The backward offset. As the variance of the true arrival delay caused by severe weather or traffic overlap increases, it is extracted as the Gaussian expanded standard deviation through square root operation. Participate in model broadening. Once the absolute peak of the concurrency, mapped by multiplying the probability density stream by the baseline total number of requests, is reached, it directly penetrates the offline-fixed system preprocessing trigger threshold. (300 times / second), the timeline capture module immediately generates multi-module linkage control instructions. These instructions directly drive the trusted execution environment to extract the session key, stripping the time-consuming decryption process from the future congested main road and completing it in advance, thereby avoiding the API gateway from crashing due to instantaneous overload at the physical hardware level.

[0076] Furthermore, the online query arrival time series and the offline entity scanning time series are compared within a preset observation time window to calculate the time interval difference value, which characterizes the degree of disconnect between online access frequency and offline actual operation. Specifically, the following steps are performed: An observation window is established with the time of the first extracted request action as the absolute starting point. The online interface access time interval sequence between two adjacent requests in the online query arrival time series is calculated. Simultaneously, the offline scanning action time interval sequence between adjacent actions in the offline entity scanning time series is calculated. The average step size (characterizing the absolute network access rate) and variance (characterizing the physical beat fluctuation caused by human fatigue) of these two sets of sequences are obtained respectively. The system clock synchronization reference parameters are further set and denoted as... It represents the time slice scale used to uniformly offset the data reporting cycle of heterogeneous physical devices in the current cloud warehouse local area network. In this preferred embodiment, its quantization is set to an absolute time scale of 20 milliseconds. This range is set to prevent short-term communication delay jitter caused by normal local area network communication congestion from being mistakenly judged as false positive circuit breaker out-of-bounds anomalies caused by high-frequency machine attack traffic.

[0077] Before performing dimensionality reduction, the data processing equipment pre-extracts the theoretical maximum communication route congestion delay extreme values ​​specified in the hardware manuals of all physical aggregation layer switches in the current cloud warehouse LAN, and obtains relevant line status parameters in conjunction with the on-site network architecture. The following clock skew hysteresis quantization derivation formula is then executed: It obtains the aforementioned theoretical maximum communication route congestion delay extreme value through data processing equipment. It also links to the network topology configuration table, which is dynamically scanned and constructed by the automated network management protocol during the physical device discovery phase. This table defines the hierarchical topology links between external network access routes and core computing nodes, including network node hierarchical identifiers, standard route hop count segments between adjacent nodes, and the correspondence between nominal physical cable lengths. Based on the source address identifier of the current communication link, a search is performed in this configuration table to extract the maximum network hop count between the external network access point and the cloud warehouse core server. and the average physical cable length per hop within the network segment. The data processing equipment will determine the maximum number of network hops. Average physical cable length per hop With the preset photoelectric medium transmission hysteresis constant Perform a multiplication operation to map the total link transmission delay at the network routing layer; then multiply this total link transmission delay by the theoretical maximum communication route congestion delay extreme value. Perform an algebraic summation operation and output the system clock synchronization reference parameters corresponding to this time envelope. Among them, the theoretical maximum communication route congestion delay extreme value Based on the full-load queuing condition of local area network communication nodes, its value is calibrated to 15 milliseconds; photoelectric medium transmission hysteresis constant Used to characterize the transmission delay within a physical cable, its preferred quantization value is 0.005 milliseconds / meter.

[0078] Furthermore, in this embodiment, considering the complex local area network cabling and heterogeneous sensing hardware environment within the warehouse, the automated network management component performs real-time link topology detection at the aggregation switch of the cloud warehouse's underlying access layer. Monitoring probes capture physical attendance logs from fixed RFID radio frequency reading access control systems deployed at the outbound nodes of the conveyor belt, as well as from automated guided vehicles (AGVs) moving in the deep shelving area. Based on these logs, a physical envelope calculation verification flow for aligning the clock reference is instantiated.

[0079] Table 3: Hysteresis Deduction and Clock Synchronization Reference Parameter Alignment Calculation for Heterogeneous Topology of Cloud Warehouse LAN The platform connects directly to a fixed barcode scanner via the external network. 1 50 15 0.005 15.25 As a dimensionless measure of extremely low hysteresis Shallow assembly line RFID reading access control 2 80 15 0.005 15.8 Normal execution of algebraic ratio operation Deep shelving area mobile AGV barcode scanning matrix 5 200 15 0.005 20 As the global maximum tolerance benchmark High-density stacker crane concurrent operation area 4 150 15 0.005 18 Normal execution of algebraic ratio operation External unauthorized connection to counterfeit free-floating terminals 8 500 15 0.005 35 (Throws an out-of-bounds exception) Reject mapping and trigger node isolation

[0080] The routing resolution logic in Table 3 is to determine the maximum network hop count. Average physical cable length per hop and the transmission hysteresis constant of the solidified photoelectric medium A product of 0.005 ms / m is performed. This product maps the cable media delay necessary for electrical signal transmission by physical devices at different depths. The processor algebraically sums this media delay with the theoretical maximum communication route congestion delay extreme value (15 ms) nominally indicated on the switch backplane. As shown in the third row of the table, even for AGV mobile nodes located in deep shelving areas and converged via multiple wireless APs, the calculated overall network hysteresis envelope converges to the preferred reference value of 20 ms. This system clock synchronization reference parameter is used in subsequent steps. When used as the denominator in division calculations to process offline physical barcode scanning time series, it can absorb legitimate random spikes caused by Ethernet channel contention without loss. If abnormal access data with both hop count and cable length exceeding limits is captured, as shown in the last line, its calculation result directly breaks through the envelope extreme value of the legitimate physical factory area. The data processing flow immediately determines that the node belongs to external network forgery injection and immediately refuses to include it in the subsequent fluctuation variance and average step size dimensionality reduction calculation sequence.

[0081] This embodiment utilizes system clock synchronization reference parameters. A homogeneous, same-dimensional alignment mapping is performed on the online interface access time interval sequence and the offline QR code scanning action time interval sequence. Specifically, the average step size of the two sets of sequences is directly extracted; the square root operation is performed on the variance data of the two sets of sequences, and the standard deviation parameter representing the physical beat fluctuation is extracted. The data processing equipment is synchronized with the system clock reference parameter. To unify the physical time scale, the extracted average step size and standard deviation parameters are divided by a ratio. This mapping step based on the physical scale eliminates the differences in the physical dimensions of time collected by heterogeneous devices, converting them losslessly into dimensionless pure numerical ratios, thereby generating the average deviation of request frequency and the fluctuation range of single request time within a unified numerical range.

[0082] Furthermore, a structured security gateway model is introduced to comprehensively evaluate this multidimensional bias characteristic; specifically, a weighted model for abnormal request risk assessment is set as follows: Its characterization consists of a set of risk control assessment logic attributes comprised of two-dimensional time-series features: request frequency deviation and single-request duration fluctuation. It maps to the system's judgment state regarding whether current concurrent requests deviate from normal human physical operation patterns, and serves as the control center in the current system communication architecture, receiving two-dimensional feature inputs from the front end and outputting one-dimensional alarm interception status to the back end. The average request frequency deviation and single-request duration fluctuation amplitude obtained above are used as independent orthogonal dimensions and input into the weighted model for abnormal request risk assessment. In the process, the data processing equipment pre-extracts the average deviation extreme value and fluctuation amplitude extreme value under normal logistics scanning operation conditions within a historical natural month; using these historical extreme values ​​as a benchmark, the data processing equipment performs linear normalization calculations on the two-dimensional features of the current input, mapping the actual input to a standard request frequency average deviation feature constrained in the [0,1] interval. Fluctuation characteristics of standard single request time Within the model, the following convergence logic is used to perform dimensionality reduction deduction of the time-series feature data flow: It extracts the average deviation feature of the normalized standard request frequency. Compare this with the rate deviation penalty weight of the solidified configuration. Perform the multiplication mapping action; simultaneously extract the normalized standard single request time fluctuation characteristics. This is weighted in conjunction with the fatigue variance amplification of the solidified configuration. Perform a multiplication mapping operation; combine the two mapping results with the noise floor compensation reference constant. Perform algebraic summation and round down to the nearest integer, outputting a one-dimensional integer parameter. This includes the rate deviation penalty weight. Used to characterize the abnormal contribution of global machine-wide uniform packet transmission; fatigue variance amplification weight. This is used to characterize the degree of missing data regarding human operational jitter. Before deployment, the data processing equipment is configured with a feature regression calibration step based on offline historical data: Real cross-domain access logs labeled within the historical calendar month are pre-extracted (including samples with normal manual assembly line operation labels and abnormal samples with known crawler detection labels). The average step size deviation and time fluctuation variance of this batch of logs are used as the input feature set, with the corresponding data security status label as the target output variable. Based on the statistical distribution patterns of on-site working conditions, the following mean squared error (MSE) loss function is constructed for gradient descent iterative fitting: Where L represents the algebraic value of the global mean square error in the current iteration period; it is a continuous floating-point number used to monitor the convergence state, and the preferred convergence boundary extreme value is set to 0.001. N represents the total number of samples extracted from the historical system benchmark logs used for offline training. This represents the data security status label value of the i-th historical log under manual offline calibration; its value is a discrete binary state quantity of 0 (representing manual security) or 1 (representing machine abnormality). This represents the predicted state score derived by the current linear regression model based on the input feature set; its value range is mapped to the interval [0,1]. When the output volatility of the above loss function L is lower than the convergence extreme value for ten consecutive periods, the data processing device extracts the feature coefficients of each dimension at this time and performs a normalization mapping operation, thereby solidifying the rate deviation penalty weight. The quantization value is 0.25, and the fatigue variance amplification weight is... The quantization value is 0.75. Noise floor compensation reference constant. The quantization value is set to 5 to compensate for occasional system clock bias drift in hardware devices. This allows for the calculation of the output target parameter used to comprehensively characterize the degree to which the frequency of automated access requests deviates from real physical operations. Further, a concurrent request anomaly risk index is defined, denoted as... This indicates the severity of the deviation between the current automated external network access request cycle and the actual offline pipeline manual QR code scanning pattern. In this preferred embodiment, it is set to an integer alarm value normalized to 0 to 100. This range is set to prevent abnormal delays in physical interception or blocking actions caused by downstream firewall components or status code data anonymization and distribution components being unable to directly parse floating-point numbers. Further, an abnormal concurrent request risk index is extracted. The specific integer value is directly used as the time interval difference value representing the frequency synchronization characteristics, and this closed-loop value is used to seamlessly drive the generation of the next stage of security defense collaborative scheduling instructions.

[0083] Step S3 includes the generation of multi-module linkage control instructions: a system preprocessing time window based on the centralized query calculated in the previous stage, and a time interval difference value characterizing the frequency of occurrence synchronization characteristics (concurrent request anomaly risk index). This generates multi-module linkage control instructions for the trusted execution environment and data distribution component. In this embodiment, the trusted execution environment is specifically configured as an independent secure microprocessor module mounted on the physical motherboard of the cloud warehouse server. It is physically isolated from the main central processing unit (CPU) via a dedicated isolated encrypted data communication bus, thereby constructing a hardware-level secure execution sandbox with resistance to physical probe eavesdropping. The data distribution component is specifically configured as a physical API routing gateway device deployed at the edge of the system's public network access. The multi-module linkage control instructions are configured to execute an anti-blocking "asynchronous preheating" compensation mechanism at the physical computing power level: before decryption, the data processing device activates the isolated secure handshake protocol. The trusted execution environment extracts the verification root key bound to the underlying hardware to perform trust chain verification of the device's operating environment. In response to the isolated state after the security gateway's trust chain verification passes, the data processing device drives the cloud key management center to dynamically inject the target decryption session key, valid only once for the current request batch, into the secure isolated storage area of ​​the trusted execution environment through an internal encrypted memory tunnel. This triggers the trusted execution environment to extract the imported target decryption session key within the system preprocessing time window of the centralized query (the absolute time interval within which the system predicts the peak of concurrent tracing requests from the external network will reach the cloud access boundary), bypassing the passive synchronization wait of the external network communication port. It then performs a hidden authorization calculation based on this key on the encrypted tracing block pulled from the front end in advance (in this embodiment, the SM4 symmetric decryption algorithm is run, and a plaintext stream is output to the secure cache). This isolated handshake mechanism ensures that even if the regular application layer is penetrated by malicious high-frequency concurrent probing attacks, the core decryption key remains insulated and leak-proof in a secure, isolated storage area.

[0084] This scheduling action, which removes computationally intensive cryptographic operations from the "concurrent response backbone" and performs "time-pre-shifting," generates joint verification authorization status codes in advance and temporarily stores them in the secure state transition buffer (a secure cache unit isolated from the application layer data interaction link).

[0085] In this embodiment, to ensure that the asynchronous decryption results can be aligned with the subsequent synchronous query traffic, the secure state transition buffer is pre-instantiated in physical memory as a hash mapping pool with a lifecycle eviction mechanism. The lifecycle eviction mechanism is specifically constructed as a management component containing dual-track reclamation logic: when writing data to the buffer, the trusted execution environment extracts the unique identifier of the cross-database traceability query request corresponding to the ciphertext traceability block as the addressing index, and uses the decrypted joint verification authorization status code as the valid data payload, establishing an absolute one-to-one key-value mapping relationship between the two; at the same time, a dynamic liveness time stamp (TTL) feature field is added to the key-value pair, and the absolute timeout boundary of the timestamp is aligned to the end time of the system preprocessing time window of the aforementioned centralized query. An atomic mutex lock with read-and-burn functionality is mounted on the read interface side of the hash mapping pool. Once the data distribution component successfully performs cross-domain memory penetration addressing based on the request identifier and reads the status code payload, the controller immediately erases the physical level of the block containing the key-value pair. This ensures deterministic reclamation of cache space in both edge scenarios of normal data flow consumption and request timeout failure. By constructing this structured state storage system, when a surge of concurrent tracing requests from the external network actually reaches the public network access edge, the data distribution component can directly perform ultra-fast cross-domain memory penetration addressing based on the request identifier, thereby eliminating the risk of API interface queuing and response failure caused by a surge in instantaneous query concurrency.

[0086] Step S4 includes setting up extreme concurrency anti-exhaustion physical isolation and structured de-identification distribution based on feature mapping; in this embodiment, the core data defense and outward control branch of the multi-module linkage control command are activated. A security benchmark parameter is introduced to determine whether abnormal detection traffic has breached the physical defense baseline: specifically defining the normal manual scanning error limit and denoting it as... It represents the maximum tolerable deviation of the barcode scanning cycle time from its extreme value caused by physical factors such as muscle fatigue and laser focusing delay of the barcode scanner during long shift work by workers on the cloud warehouse assembly line. In this preferred embodiment, it is set as the concurrent request anomaly risk index. The critical value of 85 is set to prevent delays caused by normal workers repeatedly focusing and scanning codes due to dim lighting during night shifts. This delay could be mistakenly identified by the firewall as a machine crawler attack, leading to indiscriminate network connection isolation and abnormal rejection of regular physical loading and unloading requests due to control flow outages. In this embodiment, the offline historical operation log library is dynamically generated by the data gateways of various physical pipeline nodes in the cloud warehouse network through asynchronous data streams during daily business operations. This log library is standardized and constructed as a structured storage space containing multi-dimensional record fields. It precisely maintains the operation timestamp field for time-dimensional traceability, the shift attribute tag for distinguishing work shifts, the high and low pressure picking mode identifier for locking the operation type, and the cycle characteristic value for recording the physical time consumption of a single code scan. The data processing equipment combines the attributes of the high-pressure picking cycle of the past three consecutive natural months' night shifts from the aforementioned multi-dimensional fields, extracts the long-tail logs of real industrial control check-in anomalies with statistically significant time consumption characteristics, transforms them into a benchmark test feature data replay stream marked with "extreme human fatigue delay," and injects it into the security gateway interception link in the test environment. The data processing equipment continuously monitors the fluctuation of the false blocking rate of the real physical human logs while continuously increasing the interception parameter boundaries. Using the smooth passage of 99.9% of the physical test data, including extreme fatigue delay, as the state convergence condition, the abnormal risk score corresponding to this convergence extreme value is extracted and absolutely solidified as the normal human barcode scanning error limit. .

[0087] Further configure the concurrent overload forced blocking branch with the highest execution priority: in response to the monitored time interval difference value showing an exponential and continuous surge, directly exceeding the normal manual scanning error limit in absolute value. The red line for circuit breaking (e.g., the risk index of abnormal concurrent requests caused by malicious high-frequency concurrent probing attacks). Upon reaching the warning threshold of 99%, the monitoring probes of the data processing equipment directly determine that the cloud warehouse server node is currently experiencing a large-scale, non-human, abnormal, high-frequency query request that deviates from the actual physical operation patterns and the operational rhythm of the physical loading and unloading personnel. Once triggered, it directly bypasses the application-layer risk control routing and generates a concurrent overload forced blocking signaling that is absolutely mutually exclusive in execution state with the previously issued multi-module linkage control instructions. The concurrent overload forced blocking signaling bypasses the regular API forwarding and is configured to execute multi-dimensional cutoff actions:

[0088] The first path utilizes system-level scheduling to control signaling interrupts the trusted execution environment's current decryption and authorization processing flow;

[0089] The second approach involves simultaneously issuing a data erasure command to the secure state transition buffer to remove plaintext fragments of sensitive joint authentication authorization status codes temporarily stored in the secure state transition buffer (preventing the residual risk of malicious extraction of privacy features from the physical medium).

[0090] The third approach involves linking the edge hardware firewall to directly discard communication sessions and isolate communication network connections for the source access address (such as the network address and physical media access control identifier of the external access node) of the cross-database tracing query request from the end that issued the cross-domain tracing request.

[0091] When the system determines that it is within a flexible and controllable range, it executes the de-identification and distribution branch for normal traffic and slightly abnormal traffic:

[0092] The concurrent request anomaly risk index represented by the time interval difference value. It did not exceed the preset error limit for normal manual scanning. At that time, the data distribution component dynamically calculates the privacy noise ratio based on the time interval difference and injects it into the joint verification authorization status code, ultimately outputting a data sharing credential for anonymous data distribution. Specifically, before executing the data distribution decision, it extracts the initial security de-identification configuration parameters pre-set on the server side;

[0093] Response to the comparison and judgment of the time interval difference value (concurrent request anomaly risk index) The timing of the physical operation falls completely within the tolerance range of the physical operation sequence, which represents the physical operation pattern of the offline entity (the engineering team determined that the current request's occurrence time did not show any machine forgery anomalies and is in an absolutely safe state).

[0094] In this embodiment, the initial privacy noise distribution configuration and the baseline noise lower limit ratio are statically configured and loaded into the static dictionary library of the global configuration management center during the cloud warehouse service deployment initialization phase by the unified operation and maintenance configuration distribution protocol. The static dictionary library internally configures the absolute mapping relationship between system security status identifiers and control parameter values, maintaining the binding relationship between the trust state identifier representing absolute security and the specific initial privacy noise distribution rules and lower limit ratio. The baseline noise lower limit ratio, as an enumerated polymorphic control parameter, is used to characterize the amount of basic communication packet obfuscation redundancy added to defend against third-party packet sniffing, assuming the current external network query is completely legitimate. In this preferred embodiment, it is quantized and set to a specific percentage value of 5%, or set to an equivalent lightweight placeholder padding instruction logical character.

[0095] When the data processing device logic determines that the current request belongs to the security trust state, it uses the generated trust state identifier as the retrieval condition and directly retrieves the preset baseline noise lower limit ratio (5% extremely low interference intensity ratio) from the static dictionary.

[0096] A protective perturbation data sequence is introduced; this sequence represents a low-level redundant obfuscated message injected to resist third-party network packet sniffing, provided that the current external network query is legitimate and does not touch the core plaintext. The data processing device triggers a pseudo-random number generator, using the current system security clock stamp as a dynamic seed, to calculate a meaningless random string whose byte length maps to the baseline noise lower limit ratio, and uses this as the generated protective perturbation data sequence. During the actual distribution action, the data processing device parses the network packet communication protocol stack structure of the joint authentication authorization status code temporarily stored in the transition buffer. Avoiding the effective data payload area storing the core traceability plaintext, the data distribution component injects the generated protective perturbation data sequence into the non-effective payload area (the extended identifier bit or check padding bit reserved in the data communication prefix) of the joint authentication authorization status code message encapsulation sequence via a memory overwrite instruction, without performing any substantial information masking on the core subject identity record area. Through this physical layer structured injection mechanism, the external data bit width and integrity hash characteristics of the message are disordered under the strict premise of not touching the core traceability plaintext structure boundary, thereby directly generating a data sharing certificate that retains complete plaintext traceability information and meets the minimum anti-replay attack verification strength of the protocol stack.

[0097] The data processing device eliminates the dimensional difference between abnormal scoring and network packet injection only when the response time interval difference value exceeds the physical operation time sequence matching tolerance range but is within the normal manual scanning error limit. The data processing device extracts the concurrent request anomaly risk index represented by the current time interval difference value. And it calls the basic transformation feature parameters pre-set in the global configuration center based on the statistical distribution of on-site working conditions, and performs the following mapping calculation:

[0098]

[0099] in This represents the final calculated normalized privacy noise ratio, used to determine the absolute proportion of desensitized garbled bytes in the message redundancy area; in this embodiment, its preferred value is 15%, and it is limited to between [5%, 30%] to prevent communication protocol stack overflow. This represents the lower limit ratio of the reference noise of the data processing device under absolutely safe conditions; in this embodiment, its preferred value is 5%. This represents the difference deviation amplification factor set based on the physical field boundary deduction. It participates in the above mapping calculation as a product constraint factor and is used to synchronously and proportionally amplify the intensity of the privacy noise ratio. In this embodiment, its preferred value is 0.25, configured in the range of [0.1, 0.5]. This serves as the upper bound boundary reference constant; the data processing device applies this normalized privacy noise ratio. Inject the corresponding de-identified data into the joint verification authorization status code. Specifically, it is configured to perform the following sensitive information partial masking operation: introduce a risk level and de-identification parameter lookup table and record it as follows: Its representation is a static two-dimensional gateway matrix, pre-hard-coded and loaded into the server-side read-only cache. It consists of a multi-segmented, stepped risk assessment scale (input-side retrieval judgment interval) bound to a specific asymmetric data concealment and desensitization character sequence (output-side overwrite action carrier). In this preferred embodiment, its data structure is set as a KV key-value pair retrieval tree containing multiple discrete tolerance intervals. This structure is designed to prevent overload and concurrency issues caused by real-time calculation of the desensitization mask using continuous algebraic functions, which could lead to significant network distribution timeouts and abnormal response latency.

[0100] Data processing devices access a risk level and de-identification parameter comparison table pre-configured in the server's internal temporary storage unit. The risk level and desensitization parameter comparison table internally maintains multiple risk tolerance judgment intervals that increase in a step-by-step manner (including an absolutely safe physical operation timing matching tolerance interval, and a step-by-step risk interval for slight deviations), as well as a desensitization replacement data sequence with a unique length of bytes that is bound to each risk tolerance judgment interval.

[0101] Before applying the table online, the data processing equipment performs offline benchmark data statistics and dictionary generation steps: The data acquisition node extracts all interface access logs from the cloud warehouse API gateway over the past thirty consecutive natural days, removes samples carrying signatures with known attack characteristics, and obtains a clean set of benchmark normal request time intervals. Statistical variance analysis is performed on this set to extract its time-series fluctuation normal distribution curve. The data processing equipment then uses this normal distribution curve... The (three standard deviations) confidence interval boundary is extracted as the upper limit benchmark for the time-series matching tolerance interval of the entity operation. For areas exceeding this upper limit benchmark, a stepped grid is performed according to a fixed numerical step size (every 5 units of exponent value) to generate multiple mutually orthogonal and increasing risk tolerance judgment intervals. At the same time, for each segmented interval, the data processing device instantiates a de-identified replacement data sequence containing a mask wildcard in the isolated cache space;

[0102] An offline expansion constraint formula is established for mapping the length of wildcard bytes within the de-identified replacement data sequence: It extracts the hierarchical index identifier of the risk tolerance judgment interval corresponding to the current processing batch. Compare it with the preset penalty amplification factor. Perform a multiplication operation and round up the product; then, combine the rounded result with the mask constant of the base identity field. Perform an accumulation operation to generate the expected mask length for the current risk level; the data processing device then limits this expected mask length to the maximum value of the pre-acquired communication bearer bytes. Perform a minimum value operation, and finally output the absolute constraint byte length of the wildcard in the sequence bound to the risk interval, denoted as the target de-identification mask length. The above-mentioned linkage and binding offline solidification output risk level and desensitization parameter comparison table. The basic identity field mask constant. To ensure the minimum obfuscation strength under low-risk conditions, its preferred value is 4 (bytes); penalty amplification factor The preferred value is 2.5; communication capacity byte limit. The value is determined by the physical boundary of the payload field specified by the cloud warehouse application layer communication protocol, and its preferred value is 32 (bytes).

[0103] Introduce the time deviation magnitude value and denot it as It represents the specific absolute quantitative distance span by which the actual frequency of concurrent requests currently encountering a mild high-frequency probing attack deviates from the perfect ideal physical manual scanning rhythm. In this preferred embodiment, it is set as an absolute positive integer increment, such as an exponential difference of 15 points exceeding the matching interval;

[0104] Data processing equipment deviation quantification conversion formula: ; The upper boundary reference constant of the entity job timing matching tolerance interval is read from the current global state configuration area. Then, extract the concurrent request anomaly risk index injected at the current moment. The scalar values ​​are then used. A subtraction operation is performed on the two sets of scalars to isolate the time-series fluctuations within a reasonable range. The algebraic difference, representing the abnormal exceedance, is then assigned to the time deviation amplitude value. During the pre-configuration phase, the data processing equipment retrieves the clean warehouse operation status monitoring stream under conditions free from any external malicious access interference, and statistically analyzes the normal distribution data of the baseline risk score output by the system under this fully manual and normal state. The statistical value at the upper edge of the 95% confidence interval of this normal risk baseline distribution curve is extracted, rounded down, and then solidified as the upper limit boundary baseline constant. This score, used to characterize the maximum credible risk that allows direct passage without triggering any desensitization instructions, is preferably quantified to 60 in this embodiment (corresponding to the passing safety limit under a normalized score system). The calculated time deviation amplitude value under the condition of cascading diffusion of abnormal features... A negative value indicates a failure in the preceding range interception and authentication node. In this case, the data processing device will shut down subsequent dimensionality reduction mapping steps and throw an out-of-bounds access logic exception. This is determined by the non-negative integer value of the time deviation. As the addressing offset of the discrete mapping matrix, it directly performs location matching and avoids the system data processing node load bottleneck caused by high-frequency floating-point traversal calculation.

[0105] The time deviation value calculated by the data processing equipment exceeds the time deviation range of the physical operation time sequence matching tolerance. and the time deviation magnitude value As the primary key for matching, input it into the risk level and desensitization parameter lookup table. The process involves comparing and traversing interval boundaries; directly extracting the target desensitized replacement data sequence that matches the current defense level, and using this to build a local sensitive feature masking mechanism independent of the full-scale scaling operation through table lookup matching.

[0106] After obtaining the mask carrier, the protocol interceptor is invoked to parse the specific data transmission encapsulation structure of the joint authentication authorization status code temporarily stored in the transition buffer (e.g., identifying the hierarchical structure and feature delimiters of its data transmission packets). The data distribution component is then driven to perform isomorphic character overwriting and secure desensitization replacement operations on the target desensitized replacement data sequence just extracted and the core subject identity record area in the joint authentication authorization status code used to expose plaintext (e.g., only locking and covering high-risk privacy areas such as "precise latitude and longitude coordinates of the shipping factory" and "real name of the carrier driver"). Under the strict communication control premise of maintaining the overall communication data length and basic structure boundary of the joint authentication authorization status code (verification feature bit width, and the delimiters of the beginning and end packet structures must not be destroyed) (to ensure that the external target receiving end security gateway will not directly throw a network protocol format error due to packet structure damage and distortion when sending), the data processing device generates a data sharing credential with key identity details blurred and hidden, but which can be smoothly penetrated by the upper-layer network routing. This hidden form completes the distribution and flow of the data sharing interface in a fully closed loop.

[0107] Concurrent Request Anomaly Risk Index Approaching the minimum value of 0: This indicates that the query request received by the current network end is synchronously mapped in time with the actual biological characteristics (including unavoidable fatigue delays and random jitter) of the manual physical scanning of the cloud warehouse's production line. At this point, it is determined to be an absolutely safe entity business state, thereby triggering the data distribution component to perform only basic network anti-replay verification, ensuring the efficient passage of legitimate loading and unloading operations.

[0108] The concurrent request anomaly risk index is approaching its maximum value of 100: This indicates that the current concurrent traffic rate has exceeded the objective physical limits of human muscle movement and device laser focusing (e.g., exhibiting absolute uniformity or microsecond-level constant concurrency in machine packet sending). Based on this, it is determined that the cloud warehouse node is being subjected to unauthorized access detection, directly triggering the computing power circuit breaker and gateway physical isolation of the Trusted Execution Environment (TEE).

[0109] Standardized privacy noise ratio The trend toward the minimum value of 5% indicates that only redundant background noise is injected within the safety tolerance range to maintain the integrity of the communication protocol stack and obfuscate the basic message, thereby achieving the most efficient plaintext data distribution performance and meeting the routine traceability and verification needs of the supply chain.

[0110] Standardized privacy noise ratio The trend towards the maximum of 30% indicates that when encountering a suspected attack that has deviated from the norm but has not crossed the boundary, the proportion of anonymized garbled text will approach the protocol's tolerance limit under the stringent condition of not violating the boundaries of data transmission packets. This mechanism maximizes the dilution of the signal-to-noise ratio of real privacy data, achieving physical-level covert defense.

[0111] Furthermore, this embodiment is configured in a physical monitoring scenario for parcel sorting and inbound / outbound traceability in a cloud warehouse assembly line. The system runs on a data processing node deployed at the warehouse edge gateway, directly pulling real-time log streams from the programmable logic controller (PLC) and reverse proxy node. Based on the aforementioned offline physical barcode scanning time series historical aligned data, a noise floor compensation baseline constant is set. 5; Upper boundary reference constant The error limit for normal manual barcode scanning is 60. The value is 85. After intercepting concurrent streams, the gateway extracts timing features and performs heterogeneous clock dimensionality reduction. These features are then input into an anomaly risk weighting model to derive the concurrent request anomaly risk index. ; Risk index of abnormal concurrent requests When the value is in the range (60, 85), extract the time deviation amplitude value. of The length of the desensitization mask is generated by looking up a table using a static matrix, and the noise ratio is calculated.

[0112] Table 4: Example of anomaly risk and de-identification distribution response calculation in high-concurrency detection scenarios for cross-domain traceability in cloud warehouses. Manual scanning status 10 10 15 0 5% 4 12.50% Artificial delay during extreme fatigue period 20 30 32 0 5% 4 12.50% Low-frequency, high-coverage camouflage detection 60 80 80 20 25% 14 43.75% Intermediate frequency automated scanning script 80 60 70 10 15% 9 28.12% Extreme high-frequency brute-force attack 95 90 96 Circuit breaker over the limit Block execution Hardware isolation Block execution Existing technical benchmark (low-frequency detection state) 60 80 80 Not supported Fixed value 5% Fixed value 4 12.50%

[0113] This embodiment defines the privacy data exposure convergence rate. The final limiting parameters generated during the data distribution process are calculated, specifically by determining the length of the target de-identification mask. Divided by the communication protocol's maximum limit on the number of bytes that can carry the communication ( ) is obtained, logically expressed as This parameter represents the depth of structured overlay blocking of internal sensitive plaintext identity features while maintaining the overall length of the physical message; the larger the value, the more thoroughly the possibility of unauthorized probes obtaining real privacy data is reduced.

[0114] A theoretical comparative analysis was conducted by extracting the performance of the "low-frequency high-concealment camouflage detection" scenario from Table 4 and comparing it with the "existing technical benchmark": When encountering input features as and During slow, covert detection, existing technologies, relying on a single threshold circuit breaker mechanism (setting the absolute blocking line at 85), misjudge these as regular requests due to the low frequency of concurrent detection. They inject only a fixed 5% of basic anti-replay noise. This solution, however, uses multi-dimensional fusion to deduce an abnormal risk index of 80 concurrent requests, directly triggering a cross-dimensional proportional mapping, dynamically increasing the normalized privacy noise ratio from the baseline 5% to 25%.

[0115] For the same scenario described above, due to the magnitude of the time deviation... The target desensitization mask length jumped to 20; the length of the mask increased dramatically from the baseline 4 bytes to 14 bytes. This resulted in a privacy data exposure convergence rate of 43.75%. This indicates that, under the "pseudo-compromise" state of not physically severing the TCP / IP connection, a high proportion of overwritten and corrupted valueless data was effectively returned to the attacker. Furthermore, when facing an "extreme high-frequency brute-force attack" scenario, the absolute value detected had already been breached. Physical tolerance. Immediately triggers hardware isolation signaling.

[0116] Figure 1It shows the data interaction link between the physical warehouse sensing equipment and the cloud-based core control system, as well as the complete technical implementation architecture that performs multi-dimensional feature comparison, computing power scheduling transfer, hidden data distribution and physical mandatory isolation when facing high-concurrency data requests. The physical physical warehouse area at the bottom of the drawing corresponds to the pre-data collection stage in the method steps, and presents the specific data sources that simultaneously extract the global satellite positioning coordinate stream of trunk logistics vehicles, as well as the clock-in logs of warehouse workers and automated equipment. The digital cloud control area at the top of the drawing and the processing server in the center correspond to the core processing mechanism for delimiting preprocessing time windows and calculating timing interval difference values. The comparison architecture inside the server intuitively shows the multi-dimensional feature dimensionality reduction evaluation process after eliminating the differences in physical heterogeneous dimensions. The two independent output paths drawn from the top of the server correspond to the multi-module linkage control instructions issued based on the calculated risk assessment indicators: among them, the data credentials with complete output structure but carrying masks show the dynamic privacy noise injection operation performed within the boundary of normal manual scanning errors; while the broken data packets outside the isolation wall prove the specific state of hardware interrupting the communication link and performing physical defense when it is determined that a non-manual attack that deviates from the real physical operation law is encountered. Meanwhile, the technical roadmap drawn from the core execution node in the drawing sequentially shows the four major method steps in accordance with causal logic, which are "Multi-source service data perception and aligned collection", "Spatial-temporal deviation dimensionality reduction and warm-up window delimitation", "Computing power isolation pre-positioning and linkage instruction issuance" and "Hierarchical dynamic desensitization and out-of-bounds blocking execution".

[0117] Figure 2 It shows the deterministic drive response of the data distribution component under the tolerance boundary. Figure 2 The X-axis herein represents the deduced concurrent request abnormal risk index, and the Y-axes (primary / secondary coordinates) respectively represent the normalized privacy noise ratio corresponding to instruction execution and the derived privacy data exposure convergence rate. Wherein, the mark S1 actually represents the upper limit boundary reference constant 60 for the safe state; the mark P1 represents the output response verification point value 80 when low-frequency hidden detection is captured; the open-circuit state mark B1 represents the normal manual scanning error boundary value 85 that triggers the hard circuit break of the security defense line.

[0118] When the X-axis data is in the interval from 0 to S1, it is determined to conform to the normal manual state, and the privacy noise ratio converges to 5% of the basic protocol requirement and presents a horizontal straight line. After the input feature crosses the S1 boundary, the curve triggers cross-dimensional mapping based on the timing deviation amplitude, and the two privacy protection indicators show a monotonous steep rise. This quantifies the defense effectiveness of issuing up to dozens of bytes of masks to the target camouflage without cutting off the link when encountering hidden camouflage detection. When the feature continues to polarize and touches the B1 boundary, an absolute regional disconnection occurs in the graphical topology, and it enters the red highlighted shadow area, where the discarding and isolation operations of the physical microprocessor and firewall are directly enabled.

[0119] Figure 3 The upper half of the screen uses node mapping to map the latest vehicle coordinates from the "trajectory positioning data set" to valid road segment nodes in the "structured road network map" surrounding the cloud warehouse using a spatial projection algorithm. It then calculates the "remaining driving distance" based on the road network topology connectivity distance between the mapped nodes. The lower half of the screen shows the data flow process, which involves overlaying the vehicle's current average speed with the internal loading time on the time axis to create a "time distribution expectation curve" representing the dense arrival status of traceability query requests. The graph nodes clearly indicate the time intervals above this curve that exceed a preset "system preprocessing trigger threshold," defining them as the absolute logical boundary of the "system preprocessing time window for centralized queries."

[0120] The above are merely preferred embodiments of the present invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the inventive concept of the present invention, and these modifications and improvements all fall within the protection scope of the present invention.

Claims

1. A blockchain-based cloud warehouse supply chain traceability and data sharing method, executed by data processing equipment configured on the cloud warehouse server, characterized in that, The specific steps include: Step S1: In response to the cross-database traceability query request captured by the cross-domain traceability request terminal, extract the total amount of outbound traceability data to be processed and the trajectory positioning data set collected by the order management system and logistics positioning terminal, and simultaneously obtain the online query arrival time series and offline physical scanning time series generated by the cloud access control node and the physical warehouse scanning device, and obtain the encrypted traceability block corresponding to the cross-database traceability query request of the cross-domain traceability request terminal by calling the preset blockchain ledger node query interface; Step S2: Calculate the expected handover time based on the total amount of outbound traceability data to be processed and the trajectory positioning data set, so as to define the system preprocessing time window for characterizing centralized queries, and compare the online query arrival time series with the offline entity scanning time series within the preset observation time window to calculate the time interval difference value for characterizing the degree of disconnect between online access frequency and offline actual operation. Step S3: Based on the difference between the system preprocessing time window and the time interval value of the centralized query, generate multi-module linkage control instructions for the trusted execution environment and data distribution component; Step S4: The multi-module linkage control instructions for the trusted execution environment and data distribution component are configured as follows: The trusted execution environment is triggered to perform covert authorization calculation on the encrypted tracing block in advance within the system preprocessing time window of the centralized query, so as to generate a joint verification authorization status code temporarily stored in the secure state transition cache. Furthermore, when the time interval difference value does not exceed the preset normal manual scanning error limit, the data distribution component is driven to dynamically calculate the privacy noise ratio based on the time interval difference value and inject it into the joint verification authorization status code, and finally output the data sharing certificate for covert data distribution.

2. The blockchain-based cloud warehouse supply chain traceability and data sharing method according to claim 1, characterized in that: Synchronously acquire online query arrival time series and offline physical barcode scanning time series generated by cloud access control nodes and physical warehouse barcode scanning devices, specifically including: The cross-domain query request data received by the cloud access control node is intercepted, and the system received clock record carried in the request data identifier prefix area is extracted and then summarized and spliced ​​into the online query arrival time series. The system monitors the local area network communication queue, obtains the physical check-in logs reported by the physical warehouse barcode scanning device in the work area, removes duplicate check-in records caused by network retransmission in the physical check-in logs, extracts the one-way transmission delay feature parameter between the physical warehouse barcode scanning device and the local area network communication queue, and performs timestamp alignment on the cleaned physical check-in logs using the one-way transmission delay feature parameter as a compensation parameter to generate the offline physical barcode scanning time series.

3. The blockchain-based cloud warehouse supply chain traceability and data sharing method according to claim 2, characterized in that: Extract the total amount of outbound traceability data to be processed and the trajectory location data set collected by the order management system and logistics positioning terminals, specifically including: Retrieve the shipment task details of the order management data processing device for the current working day, filter and count the total number of shipment orders in the pending fulfillment outbound batch status, and use it as the total amount of outbound traceability data to be processed; Through the spatial coordinate synchronization interface of the transportation equipment, the global satellite positioning coordinate stream of the transportation vehicle bound to the batch to be fulfilled and dispatched is retrieved, and the vehicle's current average speed data reported in real time by the vehicle terminal system is extracted simultaneously, so as to serve as the trajectory positioning data set.

4. The blockchain-based cloud warehouse supply chain traceability and data sharing method according to claim 3, characterized in that: The expected handover time is calculated based on the total amount of outbound traceability data to be processed and the trajectory positioning data set, in order to define a system preprocessing time window for representing centralized queries, specifically including: The latest vehicle coordinates in the trajectory positioning data set are mapped to the effective road segment nodes of the structured road network map around the cloud warehouse through a spatial projection algorithm, and the remaining driving distance is calculated based on the road network topology connectivity distance between the mapped nodes. The remaining travel distance is estimated using the vehicle's current average speed, and the total amount of outbound traceability data to be processed is internally loaded based on the pre-acquired historical average throughput of the warehouse. The time consumption projection results and the internal loading time conversion results are superimposed on the time axis to draw a time distribution expected curve representing the dense arrival state of the source tracing query request. The time interval above the curve that exceeds the preset system preprocessing trigger threshold is selected and marked as the system preprocessing time window of the centralized query.

5. The blockchain-based cloud warehouse supply chain traceability and data sharing method according to claim 4, characterized in that: Within the observation window, calculate the online interface access time interval sequence of adjacent requests in the online query arrival time sequence, and calculate the offline scanning action time interval sequence of adjacent actions in the offline entity scanning time sequence. By comparing the average step size and variance of the online interface access time interval sequence and the offline QR code scanning action time interval sequence, and by calculating the algebraic difference of the statistical characteristics of the two time intervals, the time interval difference value, which characterizes whether the frequencies of the two events are synchronized, is calculated. Specifically, the following steps are configured to be performed: Extract the system clock synchronization reference parameters configured in the data processing equipment; Using the system clock synchronization reference parameters, the average step size and variance of the online interface access time interval sequence and the offline scanning action time interval sequence are respectively divided and converted to generate the average deviation value of the request frequency and the fluctuation range of the single request time within a unified numerical range. Obtain a weighted model for assessing the risk of abnormal requests, pre-calibrated offline based on the cloud warehouse's anti-counterfeiting and fault tolerance sensitivity. The average deviation of the request frequency and the fluctuation range of the single request time are input into the weighted model of abnormal request risk assessment as independent dimensions. By performing a weighted summation calculation based on preset multi-dimensional assessment weights, the concurrent request abnormal risk index, which is used to comprehensively characterize the degree to which the frequency of automated access requests deviates from the actual physical operation, is calculated. Extract the value of the concurrent request anomaly risk index and output it as the time interval difference value characterizing the frequency synchronization feature.

6. The blockchain-based cloud warehouse supply chain traceability and data sharing method according to claim 5, characterized in that: The driving data distribution component dynamically calculates the privacy noise ratio based on the time interval difference value and injects it into the joint verification authorization status code, ultimately outputting a data sharing credential for covert data distribution, specifically including: Extract the preset initial privacy noise distribution configuration; In response to the time interval difference value falling into the time sequence matching tolerance range of the physical operation representing the actual offline manual operation, a preset reference noise lower limit ratio is substituted into the initial privacy noise distribution configuration, a corresponding protection disturbance data sequence is generated according to the reference noise lower limit ratio, and the protection disturbance data sequence is injected into the non-effective payload area of ​​the joint verification authorization status code to generate the data sharing certificate. In response to the timing interval difference value exceeding the timing matching tolerance range of the entity operation but within the normal manual scanning error limit, based on the difference deviation amplification factor of the timing interval difference value, the intensity of the privacy noise ratio is synchronously and proportionally amplified. By applying the amplified normalized privacy noise ratio as the underlying byte control instruction, the output sequence of the joint verification authorization status code is hidden and desensitized, and the data sharing certificate with desensitized granularity downgrade is generated.

7. The blockchain-based cloud warehouse supply chain traceability and data sharing method according to claim 6, characterized in that: After generating multi-module linkage control instructions for the trusted execution environment and data distribution components based on the difference between the system preprocessing time window and time interval values ​​obtained from centralized query, the following are also included: In response to the absolute value of the time interval difference detected directly exceeding the normal manual scanning error limit, it is determined that the cloud warehouse server node is experiencing non-manual abnormal high-frequency query requests that are out of sync with the actual operation and physical rhythm. Generate concurrent overload forced blocking signaling that is mutually exclusive with the multi-module linkage control instructions, interrupt the current decryption authorization processing flow of the trusted execution environment, synchronously clear the joint verification authorization status code data temporarily stored in the security state transition buffer, and perform communication connection isolation operation on the source access address of the cross-database traceability query request issued by the cross-domain traceability request end.

8. A blockchain-based cloud warehouse supply chain traceability and data sharing method according to claim 6, characterized in that: During the process of generating data sharing credentials with desensitized granularity downgrade, the following sensitive information partial masking operations are also performed simultaneously: The risk level and desensitization parameter comparison table is pre-configured in the internal temporary storage unit of the server. The risk level and desensitization parameter comparison table maintains multiple risk tolerance judgment intervals that increase in a step-like manner, as well as a desensitization alternative data sequence that is uniquely bound to each risk tolerance judgment interval. The time deviation amplitude value of the time interval difference value exceeds the time sequence matching tolerance range of the entity operation is calculated, and the time deviation amplitude value is used as a matching index to be input into the risk level and desensitization parameter comparison table for interval boundary comparison, so as to extract the target desensitization replacement data sequence that matches the current defense level, and the target desensitization replacement data sequence is used as the data carrier for performing local feature coverage operation; The data transmission encapsulation structure of the joint verification authorization status code is parsed, and the data distribution component is driven to perform local feature overlay and secure desensitization replacement operations on the target desensitized replacement data sequence and the core subject identity record area in the joint verification authorization status code; While maintaining the overall communication data length and infrastructure boundary of the joint verification authorization status code, the data sharing credential with key identity information de-identified and hidden is generated.

Citation Information

Patent Citations

  • Supply chain part traceability method based on block chain

    CN118586039A