Haihua Zhu , Yu Cheng , Xiuli Song , Yunlong Zhou , Fan Liu , Zigang Chen
{"title":"增强复杂供应链中的透明度和可追溯性:细粒度访问控制、准确性评估和安全存储","authors":"Haihua Zhu , Yu Cheng , Xiuli Song , Yunlong Zhou , Fan Liu , Zigang Chen","doi":"10.1016/j.jisa.2025.104169","DOIUrl":null,"url":null,"abstract":"<div><div>With the growing public awareness of product safety, the demand for supply chain traceability and transparency has significantly increased. Ensuring product information traceability while enhancing transparency and fostering information sharing across all stages of the supply chain remains a critical challenge. To address this, we propose a transparency and traceability enhancement scheme for complex supply chains. To ensure data confidentiality, the scheme employs a hierarchical encryption mechanism for secure data sharing. A multi-party evaluation mechanism is introduced to assess the accuracy of uploaded information, preventing unreliable data from compromising overall trust. Additionally, to overcome issues such as decentralized data storage, difficult access, and low sharing efficiency, we integrate the InterPlanetary File System (IPFS) to improve data redundancy and mitigate single points of failure. A hybrid on-chain and off-chain storage approach is adopted for efficient data sharing. To further strengthen access control, we implement Ciphertext-Policy Attribute-Based Encryption (CP-ABE) to enable fine-grained access control, ensuring that only authorized users can access the data. We validate our scheme on the Hyperledger Fabric platform and conduct performance evaluations using Hyperledger Caliper. Experimental results demonstrate that our scheme excels in traceability, privacy protection, and fine-grained access control, while maintaining high generalizability and scalability.</div></div>","PeriodicalId":48638,"journal":{"name":"Journal of Information Security and Applications","volume":"93 ","pages":"Article 104169"},"PeriodicalIF":3.8000,"publicationDate":"2025-07-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Enhancing transparency and traceability in complex supply chains: Fine-grained access control, accuracy evaluation, and secure storage\",\"authors\":\"Haihua Zhu , Yu Cheng , Xiuli Song , Yunlong Zhou , Fan Liu , Zigang Chen\",\"doi\":\"10.1016/j.jisa.2025.104169\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>With the growing public awareness of product safety, the demand for supply chain traceability and transparency has significantly increased. Ensuring product information traceability while enhancing transparency and fostering information sharing across all stages of the supply chain remains a critical challenge. To address this, we propose a transparency and traceability enhancement scheme for complex supply chains. To ensure data confidentiality, the scheme employs a hierarchical encryption mechanism for secure data sharing. A multi-party evaluation mechanism is introduced to assess the accuracy of uploaded information, preventing unreliable data from compromising overall trust. Additionally, to overcome issues such as decentralized data storage, difficult access, and low sharing efficiency, we integrate the InterPlanetary File System (IPFS) to improve data redundancy and mitigate single points of failure. A hybrid on-chain and off-chain storage approach is adopted for efficient data sharing. To further strengthen access control, we implement Ciphertext-Policy Attribute-Based Encryption (CP-ABE) to enable fine-grained access control, ensuring that only authorized users can access the data. We validate our scheme on the Hyperledger Fabric platform and conduct performance evaluations using Hyperledger Caliper. Experimental results demonstrate that our scheme excels in traceability, privacy protection, and fine-grained access control, while maintaining high generalizability and scalability.</div></div>\",\"PeriodicalId\":48638,\"journal\":{\"name\":\"Journal of Information Security and Applications\",\"volume\":\"93 \",\"pages\":\"Article 104169\"},\"PeriodicalIF\":3.8000,\"publicationDate\":\"2025-07-27\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Information Security and Applications\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2214212625002066\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Security and Applications","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2214212625002066","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
Enhancing transparency and traceability in complex supply chains: Fine-grained access control, accuracy evaluation, and secure storage
With the growing public awareness of product safety, the demand for supply chain traceability and transparency has significantly increased. Ensuring product information traceability while enhancing transparency and fostering information sharing across all stages of the supply chain remains a critical challenge. To address this, we propose a transparency and traceability enhancement scheme for complex supply chains. To ensure data confidentiality, the scheme employs a hierarchical encryption mechanism for secure data sharing. A multi-party evaluation mechanism is introduced to assess the accuracy of uploaded information, preventing unreliable data from compromising overall trust. Additionally, to overcome issues such as decentralized data storage, difficult access, and low sharing efficiency, we integrate the InterPlanetary File System (IPFS) to improve data redundancy and mitigate single points of failure. A hybrid on-chain and off-chain storage approach is adopted for efficient data sharing. To further strengthen access control, we implement Ciphertext-Policy Attribute-Based Encryption (CP-ABE) to enable fine-grained access control, ensuring that only authorized users can access the data. We validate our scheme on the Hyperledger Fabric platform and conduct performance evaluations using Hyperledger Caliper. Experimental results demonstrate that our scheme excels in traceability, privacy protection, and fine-grained access control, while maintaining high generalizability and scalability.
期刊介绍:
Journal of Information Security and Applications (JISA) focuses on the original research and practice-driven applications with relevance to information security and applications. JISA provides a common linkage between a vibrant scientific and research community and industry professionals by offering a clear view on modern problems and challenges in information security, as well as identifying promising scientific and "best-practice" solutions. JISA issues offer a balance between original research work and innovative industrial approaches by internationally renowned information security experts and researchers.