TW202008202A - CSR data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method - Google Patents

CSR data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method Download PDF

Info

Publication number
TW202008202A
TW202008202A TW107125261A TW107125261A TW202008202A TW 202008202 A TW202008202 A TW 202008202A TW 107125261 A TW107125261 A TW 107125261A TW 107125261 A TW107125261 A TW 107125261A TW 202008202 A TW202008202 A TW 202008202A
Authority
TW
Taiwan
Prior art keywords
data
csr
subsystem
authentication
report
Prior art date
Application number
TW107125261A
Other languages
Chinese (zh)
Other versions
TWI698768B (en
Inventor
林庠序
林哲民
Original Assignee
林庠序
林哲民
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 林庠序, 林哲民 filed Critical 林庠序
Priority to TW107125261A priority Critical patent/TWI698768B/en
Publication of TW202008202A publication Critical patent/TW202008202A/en
Application granted granted Critical
Publication of TWI698768B publication Critical patent/TWI698768B/en

Links

Images

Landscapes

  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

A CSR data verification system, related verification party subsystem, computer program product, and CSR data verification method are disclosed. The method includes: utilizing a verification party subsystem to select valid raw data for verification out of CSR raw data of a source enterprise; generating database index corresponding to the valid raw data; generating de-identification data based on the valid raw data; and transmitting the de-identification data and database index into a block chain subsystem and instructing the block chain subsystem to execute smart contracts previously deployed by the verification party subsystem to verify the de-identification data; if the de-identification data satisfies the inspection rules of the smart contracts, the block chain subsystem generates and stores a verified data containing the de-identification data, the database index, and an electronic signature of a verification party corresponding to the verification party subsystem.

Description

具備防竄改能力的企業社會責任資料認證系統、相關的認證子系統、電腦程式產品、與資料認證方法Corporate social responsibility data certification system with anti-tampering capabilities, related certification subsystems, computer program products, and data certification methods

本發明涉及資料認證技術,尤指一種具備防竄改能力的企業社會責任(Corporate Social Responsibility,CSR)資料認證系統、相關的認證子系統、電腦程式產品、與企業社會責任資料認證方法。The present invention relates to data authentication technology, in particular to a corporate social responsibility (CSR) data authentication system, related authentication subsystem, computer program product, and corporate social responsibility data authentication method with anti-tampering capability.

經過聯合國多年來的推動,企業社會責任已成為全球關注的重要議題,越來越多的投資機構依循聯合國的「責任投資原則」(Principles for Responsible Investment,PRI),將企業在多個企業社會責任面向(例如,維護人權、保證勞工權益、發展永續與經濟、推動公司治理、持續創新等等)的表現,納入選擇投資標的時的重要考慮因素。另外,也有越來越多的公司或組織會檢視企業在企業社會責任方面的投入情況,以評估是否將其納入供應鏈的合作夥伴中。例如,許多政府單位、投資機構、與各種組織,都會檢視相關企業在環境、社會、公司治理(Environmental, Social, and Corporate Governance,ESG)等三大面向的表現,來做為衡量企業是否善盡企業社會責任的評估標準之一。因此,企業若不注重在各種企業社會責任方面的投入,不僅可能面臨政府相關法規的罰則,甚至會降低許多投資機構的投資意願、或是無法進入某些目標客戶的供應鏈。After years of promotion by the United Nations, corporate social responsibility has become an important issue of global concern. More and more investment institutions follow the United Nations' "Principles for Responsible Investment (PRI)" For performance (for example, safeguarding human rights, guaranteeing labor rights, developing sustainability and the economy, promoting corporate governance, continuous innovation, etc.), include important considerations when selecting investment targets. In addition, more and more companies or organizations will review the company's investment in corporate social responsibility to assess whether it will be included in the supply chain partners. For example, many government units, investment institutions, and various organizations will examine the performance of related companies in the three major aspects of environment, society, and corporate governance (Environmental, Social, and Corporate Governance, ESG), as a measure of whether the company is good. One of the evaluation criteria of corporate social responsibility. Therefore, if enterprises do not pay attention to the investment in various corporate social responsibilities, they may not only face punishment from relevant government regulations, but also reduce the investment willingness of many investment institutions or fail to enter the supply chain of certain target customers.

傳統上,當企業想取得較高階的企業社會責任認證(Certificate in Corporate Social Responsibility)時,需要聘請具有公信力或取得國際認證資格的會計師事務所或是第三方認證機構,為企業提供的相關財務數據與行為紀錄資料(以下簡稱為企業社會責任資料,CSR data)進行查核及製作相關的企業社會責任報告(以下簡稱為CSR報告),以衡量或證明企業在各種企業社會責任面向上的投入程度。Traditionally, when a company wants to obtain a higher level of Corporate Social Responsibility certification, it needs to hire an accounting firm or a third-party certification agency with credibility or international certification to provide relevant financial data for the company Check and produce relevant corporate social responsibility reports (hereinafter referred to as CSR reports) with behavior record data (hereinafter referred to as CSR data) to measure or prove the company's investment in various aspects of corporate social responsibility.

然而,傳統的CSR資料認證模式需要企業與認證機構雙方都投入可觀的人力查核各筆資料的正確性及合理性,所以需要耗費許多時間與費用才能完成。由於傳統模式在作業時間與成本上的缺點,導致企業進行CSR資料認證的頻率很低,通常是一季或一年才進行一次,所以產出的CSR報告經常難以反映出企業近期在各種企業社會責任面向的最新投入狀況。另一方面,傳統的CSR資料認證方式也無法因應突發性需要而即時產生最新的CSR報告。However, the traditional CSR data certification model requires that both the enterprise and the certification body invest considerable manpower to check the accuracy and rationality of each data, so it takes a lot of time and expense to complete. Due to the shortcomings of the traditional model in terms of operating time and cost, the frequency of CSR data certification by companies is very low, usually only once a quarter or a year, so the output CSR report often fails to reflect the company’s recent CSR The latest investment status. On the other hand, the traditional CSR data authentication method cannot produce the latest CSR report immediately in response to sudden needs.

有鑑於此,如何克服傳統企業社會責任資料認證方式的前述缺點,實為有待解決的問題。In view of this, how to overcome the aforementioned shortcomings of the traditional corporate social responsibility data certification method is really a problem to be solved.

本說明書提供一種CSR資料認證系統的實施例,其包含:一區塊鏈子系統;一認證子系統,設置成可存取該區塊鏈子系統;以及一CSR數據報告服務子系統,設置成可透過網路與一企業端裝置以及該認證子系統進行資料通信,並可在接收到該企業端裝置所傳來一目標企業的CSR原始資料後,將該CSR原始資料傳送給該認證子系統;其中,該認證子系統還設置成執行一電腦程式產品以進行以下運作:從該CSR原始資料中篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及將該去識別化資料及相應的該資料庫索引傳送至該區塊鏈子系統,並指示該區塊鏈子系統執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統所對應的一認證機構的電子簽章。This specification provides an embodiment of a CSR data authentication system, which includes: a blockchain subsystem; an authentication subsystem configured to access the blockchain subsystem; and a CSR data reporting service subsystem configured to pass through The network communicates with an enterprise-side device and the authentication subsystem, and after receiving the CSR original data of a target enterprise from the enterprise-end device, transmits the CSR original data to the authentication subsystem; , The certification subsystem is also configured to execute a computer program product to perform the following operations: filter out eligible raw data for certification from the CSR raw data, and store the qualified raw data into a database; generate and generate A database index corresponding to the eligible raw data; removing identifiable data from the eligible raw data to generate de-identified data; and transmitting the de-identified data and the corresponding database index to the blockchain subsystem, and Instruct the blockchain subsystem to execute one or more smart contracts to authenticate the de-identified data; where, if the de-identified data meets the verification rules in the one or more smart contracts, the blockchain subsystem generates and A post-certification data is stored, and the post-certification data includes the de-identified data, the database index, and an electronic signature of a certification body corresponding to the certification subsystem.

本說明書另提供一種用於一CSR資料認證系統中的認證子系統的實施例。該CSR資料認證系統包含一CSR數據報告服務子系統以及一區塊鏈子系統,且該CSR數據報告服務子系統在接收到一目標企業的CSR原始資料後,會將該CSR原始資料傳送給該認證子系統。該認證子系統包含:一通信電路,設置成可透過網路與該CSR數據報告服務子系統以及該區塊鏈子系統進行資料通信;一儲存電路,用於儲存一電腦程式產品;以及一處理電路,耦接於該通信電路與該儲存電路;其中,該處理電路設置成執行該電腦程式產品以進行以下運作:從該CSR原始資料中篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及利用該通信電路將該去識別化資料及相應的該資料庫索引傳送至該區塊鏈子系統,並指示該區塊鏈子系統執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統所對應的一認證機構的電子簽章。This specification also provides an embodiment of an authentication subsystem used in a CSR data authentication system. The CSR data certification system includes a CSR data reporting service subsystem and a blockchain subsystem, and after receiving the CSR raw data of a target company, the CSR data reporting service subsystem will send the CSR raw data to the certification Subsystem. The authentication subsystem includes: a communication circuit configured to communicate with the CSR data reporting service subsystem and the blockchain subsystem through the network; a storage circuit for storing a computer program product; and a processing circuit , Coupled to the communication circuit and the storage circuit; wherein, the processing circuit is configured to execute the computer program product to perform the following operations: filter out qualified original data that can be authenticated from the CSR original data, and convert the qualified original data Storing the data in a database; generating a database index corresponding to the qualified raw data; removing identifiable data from the qualified raw data to generate de-identified data; and using the communication circuit to de-identify the data and The corresponding database index is sent to the blockchain subsystem and instructs the blockchain subsystem to execute one or more smart contracts to authenticate the de-identified data; where, if the de-identified data matches the one or more The verification rules in the smart contract, the blockchain subsystem generates and stores a post-authentication data, and the post-authentication data includes the de-identified data, the database index, and a certification authority corresponding to the authentication subsystem Electronic signature.

本說明書另提供一種電腦程式產品的實施例。該電腦程式產品儲存在一認證子系統的一儲存電路中,允許該認證子系統進行一CSR認證運作,該CSR認證運作包含:從該認證子系統所接收到的一目標企業的CSR原始資料中,篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及利用一通信電路將該去識別化資料及相應的該資料庫索引傳送至一區塊鏈子系統,並指示該區塊鏈子系統執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統所對應的一認證機構的電子簽章。This manual also provides an embodiment of a computer program product. The computer program product is stored in a storage circuit of a certification subsystem, allowing the certification subsystem to perform a CSR certification operation. The CSR certification operation includes: CSR raw data of a target company received from the certification subsystem , Select the eligible raw data that can be authenticated, and store the qualified raw data in a database; generate a database index corresponding to the qualified raw data; remove the identifiable data from the qualified raw data to generate Identify the data; and use a communication circuit to send the deidentified data and the corresponding database index to a blockchain subsystem, and instruct the blockchain subsystem to execute one or more smart contracts to authenticate the deidentification Data; where, if the de-identified data meets the verification rules in the one or more smart contracts, the blockchain subsystem generates and stores a post-authentication data, and the post-authentication data includes the de-identified data, the The database index and the electronic signature of a certification body corresponding to the certification subsystem.

本說明書另提供一種CSR資料認證方法的實施例,其包含:從接收到的一目標企業的CSR原始資料中,篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及利用一通信電路將該去識別化資料及相應的該資料庫索引傳送至一區塊鏈子系統,並指示該區塊鏈子系統執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統所對應的一認證機構的電子簽章。This specification also provides an embodiment of a CSR data authentication method, which includes: selecting the qualified raw data for certification from the received CSR raw data of a target company, and storing the qualified raw data to a database Medium; generate a database index corresponding to the qualified raw data; remove identifiable data from the qualified raw data to generate de-identified data; and use a communication circuit to de-identify the data and the corresponding database index Send to a blockchain subsystem and instruct the blockchain subsystem to execute one or more smart contracts to authenticate the de-identified data; where, if the de-identified data conforms to the verification rules in the one or more smart contracts Then, the blockchain subsystem generates and stores a post-authentication data, and the post-authentication data includes the de-identified data, the database index, and the electronic signature of a certification authority corresponding to the authentication subsystem.

上述實施例的優點之一,是可大幅降低對企業的CSR資料進行認證所需的人力、時間、與成本,所以能夠提升企業進行CSR資料認證的頻率,並吸引更多企業與認證機構共同投入及推動CSR揭露制度。One of the advantages of the above embodiment is that it can greatly reduce the labor, time, and cost required to certify the CSR data of the company, so it can increase the frequency of CSR data certification and attract more companies and certification bodies to invest together And promote the CSR disclosure system.

上述實施例的另一優點,是能夠因應突發性需要而即時利用區塊鏈子系統來產生最新的特定CSR項目數據報告,以反映出企業近期在各種企業社會責任面向的最新投入狀況。Another advantage of the above-mentioned embodiment is that it can instantly use the blockchain subsystem to generate the latest specific CSR project data report in response to unexpected needs, to reflect the latest investment status of the company in various corporate social responsibility.

上述實施例的另一優點,是企業的適格原始資料是在區塊鏈子系統中進行認證與儲存,所以能夠有效避免被有心人士竄改的風險。Another advantage of the above embodiment is that the qualified raw data of the enterprise is authenticated and stored in the blockchain subsystem, so it can effectively avoid the risk of tampering by intentional persons.

本發明的其他優點將搭配以下的說明和圖式進行更詳細的解說。Other advantages of the present invention will be explained in more detail with the following description and drawings.

以下將配合相關圖式來說明本發明的實施例。在圖式中,相同的標號表示相同或類似的元件或方法流程。The embodiments of the present invention will be described below in conjunction with related drawings. In the drawings, the same reference numerals indicate the same or similar elements or method flows.

圖1為本發明一實施例的企業社會責任資料認證系統(以下簡稱為CSR資料認證系統)100簡化後的功能方塊圖。CSR資料認證系統100用來對各企業所提供的CSR資料進行認證,並可依據需求者的請求產生相關的特定CSR項目數據報告。FIG. 1 is a simplified functional block diagram of a corporate social responsibility data authentication system (hereinafter referred to as CSR data authentication system) 100 according to an embodiment of the present invention. The CSR data certification system 100 is used to authenticate the CSR data provided by each enterprise, and can generate relevant specific CSR project data reports according to the request of the requestor.

CSR資料認證系統100包含一企業社會責任數據報告服務子系統(以下簡稱為CSR數據報告服務子系統)110、一個或多個認證子系統(例如,圖1中所繪示的示例性認證子系統120與130)、一區塊鏈節點叢集140、以及由區塊鏈節點叢集140搭配其他區塊鏈運算電路所共同形成的一區塊鏈子系統150。The CSR data certification system 100 includes a corporate social responsibility data reporting service subsystem (hereinafter referred to as CSR data reporting service subsystem) 110, and one or more certification subsystems (for example, the exemplary certification subsystem shown in FIG. 1 120 and 130), a blockchain node cluster 140, and a blockchain subsystem 150 formed by the blockchain node cluster 140 and other blockchain computing circuits.

CSR資料認證系統100中的多個認證子系統120~130,分別對應於不同的認證機構,例如,具有公信力的會計師事務所、和/或取得國際認證資格的第三方認證單位。例如,以下假設認證子系統120是對應於第一認證機構,而認證子系統130則是對應於第二認證機構。實作上,認證子系統120~130可以用分別設置在各自對應的認證機構內部的電腦或伺服器等可聯網設備來實現。或者,認證子系統120~130也可以用設置在同一雲端平台上的不同虛擬機器來實現,並由各自對應的認證機構的人員遠端操控。The multiple certification subsystems 120-130 in the CSR data certification system 100 correspond to different certification bodies, such as a credible accounting firm and/or a third-party certification unit that has obtained international certification qualifications. For example, the following assumes that the certification subsystem 120 corresponds to the first certification authority and the certification subsystem 130 corresponds to the second certification authority. In practice, the authentication subsystems 120-130 can be implemented with network-connectable devices such as computers or servers that are respectively installed in their respective certification bodies. Alternatively, the authentication subsystems 120 to 130 may also be implemented by different virtual machines installed on the same cloud platform, and be remotely controlled by the personnel of the corresponding certification authority.

圖1中的標號101~103代表多個不同的企業端裝置,標號105~107則代表多個不同的需求端裝置。實作上,企業端裝置101~103通常是用各自企業內部的電腦或伺服器等可聯網設備來實現,需求端裝置105~107通常是利用各自資料需求者(例如,投資機構、企業或組織的供應鏈管理部門、或官方的金融監理單位等等)內部的電腦或伺服器等可聯網設備來實現。The reference numerals 101 to 103 in FIG. 1 represent multiple different enterprise-side devices, and the reference numerals 105 to 107 represent multiple different demand-side devices. In practice, enterprise-side devices 101-103 are usually implemented with networkable devices such as computers or servers in their respective enterprises, and demand-side devices 105-107 are usually those who use their respective data needs (for example, investment institutions, enterprises or organizations The supply chain management department, or the official financial supervision unit, etc.) internal computers or servers and other networked devices to achieve.

在運作時,不同的企業可透過各自的企業端裝置將各自的CSR原始資料傳送給CSR數據報告服務子系統110。CSR數據報告服務子系統110會將特定企業傳來的CSR原始資料,傳送給該特定企業所委任或是事先同意的特定認證機構所對應的認證子系統。During operation, different enterprises can send their original CSR data to the CSR data reporting service subsystem 110 through their respective enterprise-end devices. The CSR data report service subsystem 110 will send the CSR original data transmitted by the specific enterprise to the certification subsystem corresponding to the specific certification body appointed by the specific enterprise or agreed in advance.

接著,該認證子系統會搭配區塊鏈子系統150共同對企業的CSR原始資料進行認證,並將所產生的認證後資料儲存在區塊鏈子系統150中,以避免資料被竄改。Then, the authentication subsystem and the blockchain subsystem 150 jointly authenticate the original CSR data of the enterprise, and store the generated authenticated data in the blockchain subsystem 150 to avoid tampering of the data.

之後,當有任何資料需求者需要查詢特定企業的CSR資料時,可透過相應的需求端裝置向CSR數據報告服務子系統110發送請求。此時,CSR數據報告服務子系統110可傳送一報告製作請求給相應的認證子系統,而該認證子系統可從區塊鏈子系統150中讀取相關的認證後資料後,產生該特定企業的特定CSR項目數據報告,並將產生的特定CSR項目數據報告透過CSR數據報告服務子系統110傳送給相應的需求端裝置。Afterwards, when any data demander needs to query the CSR data of a specific enterprise, he can send a request to the CSR data report service subsystem 110 through the corresponding demand-side device. At this time, the CSR data report service subsystem 110 may send a report creation request to the corresponding authentication subsystem, and the authentication subsystem may read the relevant post-authentication information from the blockchain subsystem 150 to generate the specific enterprise’s The specific CSR project data report, and transmits the generated specific CSR project data report to the corresponding demand-side device through the CSR data report service subsystem 110.

在圖1的實施例中,CSR數據報告服務子系統110包含一網站伺服器112、一用戶關係資料庫114、以及一區塊鏈運算電路116。認證子系統120包含一通信電路121、一儲存電路122、一資料庫123、一區塊鏈運算電路124、以及一處理電路125。認證子系統130包含一通信電路131、一儲存電路132、一資料庫133、一區塊鏈運算電路134、以及一處理電路135。區塊鏈節點叢集140包含有多個區塊鏈節點(例如,圖1中所繪示的示例性區塊鏈節點141~147)。In the embodiment of FIG. 1, the CSR data reporting service subsystem 110 includes a website server 112, a user relationship database 114, and a blockchain computing circuit 116. The authentication subsystem 120 includes a communication circuit 121, a storage circuit 122, a database 123, a blockchain arithmetic circuit 124, and a processing circuit 125. The authentication subsystem 130 includes a communication circuit 131, a storage circuit 132, a database 133, a blockchain arithmetic circuit 134, and a processing circuit 135. The blockchain node cluster 140 includes a plurality of blockchain nodes (for example, the exemplary blockchain nodes 141-147 shown in FIG. 1).

請注意,前述的CSR數據報告服務子系統110、認證子系統120、以及認證子系統130,在實際實施時皆可設置供用戶進行操控所需的人機介面裝置(例如,顯示器、鍵盤、滑鼠、觸控螢幕等),但為了簡化圖面內容起見,這些人機介面裝置並未繪示在圖1中。Please note that the aforementioned CSR Data Reporting Service Subsystem 110, Authentication Subsystem 120, and Authentication Subsystem 130 can all be equipped with human-machine interface devices (such as monitors, keyboards and Mouse, touch screen, etc.), but in order to simplify the content of the picture, these man-machine interface devices are not shown in FIG. 1.

本實施例中的區塊鏈子系統150,是由CSR數據報告服務子系統110中的區塊鏈運算電路116、認證子系統120中的區塊鏈運算電路124、認證子系統130中的區塊鏈運算電路134、以及區塊鏈節點叢集140中的多個區塊鏈節點141~147所共同組成。The blockchain subsystem 150 in this embodiment is composed of the blockchain operation circuit 116 in the CSR data report service subsystem 110, the blockchain operation circuit 124 in the authentication subsystem 120, and the blocks in the authentication subsystem 130 The chain operation circuit 134 and a plurality of blockchain nodes 141-147 in the blockchain node cluster 140 are composed together.

在CSR數據報告服務子系統110中,網站伺服器112設置成可透過網際網路或其他網路,與前述的企業端裝置101~103、需求端裝置105~107、認證子系統120~130、以及區塊鏈子系統150進行資料通信。用戶關係資料庫114耦接於網站伺服器112,用來儲存多個企業與相關認證機構之間的對應關係,以供網站伺服器112查詢。區塊鏈運算電路116耦接於網站伺服器112,用於扮演區塊鏈子系統150的節點(node)之一,並可做為CSR數據報告服務子系統110與區塊鏈子系統150之間的溝通橋樑。In the CSR data reporting service subsystem 110, the web server 112 is configured to communicate with the aforementioned enterprise-side devices 101-103, demand-side devices 105-107, and authentication subsystems 120-130 via the Internet or other networks. And the blockchain subsystem 150 performs data communication. The user relationship database 114 is coupled to the web server 112 and is used to store correspondence between multiple enterprises and related certification organizations for the web server 112 to query. The blockchain computing circuit 116 is coupled to the website server 112 and serves as one of the nodes of the blockchain subsystem 150, and can be used as a link between the CSR data reporting service subsystem 110 and the blockchain subsystem 150. Bridge of communication.

在認證子系統120中,通信電路121設置成可透過網際網路或其他網路與CSR數據報告服務子系統110以及區塊鏈子系統150進行資料通信。儲存電路122設置成儲存一企業社會責任資料認證程式(以下簡稱為CSR資料認證程式)126。區塊鏈運算電路124耦接於通信電路121,用於扮演區塊鏈子系統150的節點之一,並可做為認證子系統120與區塊鏈子系統150之間的溝通橋樑。處理電路125耦接於通信電路121、儲存電路122、資料庫123、區塊鏈運算電路124,設置成控制前述裝置的運作,並可執行儲存電路122中的CSR資料認證程式126,以進行後續實施例中所揭露的CSR資料認證運作。In the authentication subsystem 120, the communication circuit 121 is configured to communicate with the CSR data report service subsystem 110 and the blockchain subsystem 150 through the Internet or other networks. The storage circuit 122 is configured to store a corporate social responsibility data authentication program (hereinafter referred to as CSR data authentication program) 126. The blockchain computing circuit 124 is coupled to the communication circuit 121 and serves as one of the nodes of the blockchain subsystem 150 and can serve as a communication bridge between the authentication subsystem 120 and the blockchain subsystem 150. The processing circuit 125 is coupled to the communication circuit 121, the storage circuit 122, the database 123, and the blockchain operation circuit 124, and is configured to control the operation of the aforementioned device, and can execute the CSR data authentication program 126 in the storage circuit 122 for subsequent The CSR data authentication operation disclosed in the embodiment.

在認證子系統130中,通信電路131設置成可透過網際網路或其他網路與CSR數據報告服務子系統110以及區塊鏈子系統150進行資料通信。儲存電路132設置成儲存一CSR資料認證程式136。區塊鏈運算電路134耦接於通信電路131,用於扮演區塊鏈子系統150的節點之一,並可做為認證子系統130與區塊鏈子系統150之間的溝通橋樑。處理電路135耦接於通信電路131、儲存電路132、資料庫133、區塊鏈運算電路134,設置成控制前述裝置的運作,並可執行儲存電路132中的CSR資料認證程式136,以進行後續實施例中所揭露的CSR資料認證運作。In the authentication subsystem 130, the communication circuit 131 is configured to communicate with the CSR data report service subsystem 110 and the blockchain subsystem 150 through the Internet or other networks. The storage circuit 132 is configured to store a CSR data authentication program 136. The blockchain computing circuit 134 is coupled to the communication circuit 131 and serves as one of the nodes of the blockchain subsystem 150 and can serve as a communication bridge between the authentication subsystem 130 and the blockchain subsystem 150. The processing circuit 135 is coupled to the communication circuit 131, the storage circuit 132, the database 133, and the blockchain operation circuit 134, and is configured to control the operation of the aforementioned device, and can execute the CSR data authentication program 136 in the storage circuit 132 for subsequent The CSR data authentication operation disclosed in the embodiment.

實作上,網站伺服器112可以用單一伺服器來實現,也可以用位於相同地理區域、或是位於不同地理區域的多個伺服器組合來實現。區塊鏈運算電路116、124、134、以及區塊鏈節點141~147,皆可用適合進行區塊鏈的共識決演算法(consensus algorithm)運算的一個或多個處理器模組或電腦來實現。通信電路121與131皆可利用符合相關網路通信、無線通信、或是行動通信規範的各種適當電路來實現,例如網路卡(Network Interface Card,NIC)、無線傳輸(Wi-Fi)電路、或是行動通信電路等等。儲存電路122與132皆可利用各種非揮發性儲存裝置來實現。處理電路125與126皆可利用具有適當運算能力的一個或多個處理器模組來實現。In practice, the website server 112 may be implemented by a single server, or may be implemented by a combination of multiple servers located in the same geographic area or in different geographic areas. Blockchain computing circuits 116, 124, 134, and blockchain nodes 141-147 can all be implemented with one or more processor modules or computers suitable for blockchain consensus algorithm (consensus algorithm) operation . Both the communication circuits 121 and 131 can be implemented by using various appropriate circuits conforming to the relevant network communication, wireless communication, or mobile communication specifications, such as a network interface card (NIC), wireless transmission (Wi-Fi) circuit, Or mobile communication circuits, etc. Both the storage circuits 122 and 132 can be implemented using various non-volatile storage devices. Both the processing circuits 125 and 126 can be implemented by one or more processor modules with appropriate computing capabilities.

前述認證子系統120或130中的CSR資料認證程式126或136,皆可用一個或多個功能模組組成的電腦程式產品來實現。例如,圖2為圖1中的CSR資料認證程式126(或136)簡化後的功能模組示意圖。在圖2的實施例中,CSR資料認證程式126(或136)皆包含一合約編輯模組210、一資料處理模組220、一資料庫存取模組230、一去識別化模組240、一區塊鏈存取模組250、以及一報告產生模組260。The CSR data authentication programs 126 or 136 in the foregoing authentication subsystem 120 or 130 can be implemented by computer program products composed of one or more functional modules. For example, FIG. 2 is a simplified functional module diagram of the CSR data authentication program 126 (or 136) in FIG. 1. In the embodiment of FIG. 2, the CSR data authentication program 126 (or 136) all include a contract editing module 210, a data processing module 220, a data storage access module 230, a de-identification module 240, a Blockchain access module 250 and a report generation module 260.

以下將搭配圖3至圖4來進一步說明CSR資料認證系統100進行CSR資料認證的運作方式。圖3與圖4為本發明一實施例的CSR資料認證方法簡化後的流程圖。The following describes the operation mode of CSR data authentication performed by the CSR data authentication system 100 in conjunction with FIGS. 3 to 4. 3 and 4 are simplified flowcharts of a CSR data authentication method according to an embodiment of the invention.

在圖3至圖4的流程圖中,位於一特定裝置所屬欄位中的流程,即代表由該特定裝置所進行的流程。例如,標記在「CSR數據報告服務子系統」欄位中的部分,是由CSR數據報告服務子系統110所進行的流程;標記在「認證子系統」欄位中的部分,是由認證子系統120~130的其中之一所進行的流程;標記在「區塊鏈子系統」欄位中的部分,則是由區塊鏈子系統150所進行的流程;其餘依此類推。前述的邏輯也適用於後續的其他流程圖中。In the flowcharts of FIGS. 3 to 4, the process located in the field to which a specific device belongs belongs to the process performed by the specific device. For example, the part marked in the "CSR Data Reporting Service Subsystem" field is the process performed by the CSR Data Reporting Service Subsystem 110; the part marked in the "Certification Subsystem" field is the certification subsystem The process performed by one of 120~130; the part marked in the "Blockchain Subsystem" field is the process performed by the Blockchain Subsystem 150; the rest are deduced by analogy. The aforementioned logic is also applicable to other subsequent flowcharts.

當任一認證機構要參與CSR資料認證系統100的運作時,該認證機構內部的人員可利用相應的認證子系統搭配區塊鏈子系統150進行流程302~306,以在區塊鏈子系統150中佈署進行CSR資料認證所需的相關智能合約。When any certification body wants to participate in the operation of the CSR data certification system 100, the personnel within the certification body can use the corresponding certification subsystem with the blockchain subsystem 150 to perform the processes 302 to 306 to deploy in the blockchain subsystem 150 The relevant smart contract required for CSR data certification.

例如,前述第一認證機構的人員可利用相應的認證子系統120進行流程302~304。在運作時,認證子系統120的處理電路125會執行儲存電路122中所儲存的CSR資料認證程式126,以進行圖3與圖4中的CSR資料認證方法。For example, the personnel of the aforementioned first certification authority may use the corresponding certification subsystem 120 to perform the processes 302-304. During operation, the processing circuit 125 of the authentication subsystem 120 executes the CSR data authentication program 126 stored in the storage circuit 122 to perform the CSR data authentication method in FIGS. 3 and 4.

在流程302中,CSR資料認證程式126中的合約編輯模組210可控制處理電路125依據用戶的操控,編輯並建立包含第一認證機構設定的多項CSR資料查核規則的一個或多個智能合約,並且將第一認證機構的電子簽章附加在其中一個智能合約中,使得前述的智能合約的其中之一包含有第一認證機構的電子簽章。實作上,合約編輯模組210可允許第一認證機構的用戶根據所需要的CSR資料認證層級或標準,彈性調整前述智能合約中的CSR資料查核規則的數量及具體內容。In the process 302, the contract editing module 210 in the CSR data authentication program 126 can control the processing circuit 125 to edit and create one or more smart contracts containing a number of CSR data checking rules set by the first certification authority according to user control, And the electronic signature of the first certification authority is added to one of the smart contracts, so that one of the aforementioned smart contracts includes the electronic signature of the first certification authority. In practice, the contract editing module 210 can allow users of the first certification authority to flexibly adjust the number and specific content of the CSR data verification rules in the aforementioned smart contract according to the required CSR data certification level or standard.

例如,合約編輯模組210可依據用戶的指示,將同一個認證層級或標準下的多個特定CSR項目的資料查核規則,整合在單一智能合約中。在此情況下,該單一智能合約可以用來查核多個特定CSR項目的資料。For example, the contract editing module 210 can integrate the data checking rules of multiple specific CSR items under the same authentication level or standard into a single smart contract according to the user's instruction. In this case, the single smart contract can be used to check the information of multiple specific CSR projects.

又例如,合約編輯模組210可依據用戶的指示,將同一個認證層級或標準下的多個特定CSR項目的資料查核規則,分別配置在多個智能合約中。在此情況下,每一智能合約只能用來查核相應的單一特定CSR項目的資料。For another example, the contract editing module 210 can configure data checking rules for multiple specific CSR items under the same authentication level or standard in multiple smart contracts according to user instructions. In this case, each smart contract can only be used to check the data of the corresponding single specific CSR project.

又例如,合約編輯模組210可依據用戶的指示,將不同認證層級或標準下的單一特定CSR項目的資料查核規則,分別配置在多個智能合約中。在此情況下,前述的多個智能合約都能用來查核該單一特定CSR項目的資料,但不同的智能合約中的查核規則所要求的數值門檻或判斷標準會有所不同。For another example, the contract editing module 210 can configure the data checking rules of a single specific CSR item under different authentication levels or standards in multiple smart contracts according to user instructions. In this case, the aforementioned multiple smart contracts can be used to check the data of a single specific CSR project, but the value threshold or judgment standard required by the check rules in different smart contracts will be different.

在流程304中,CSR資料認證程式126中的區塊鏈存取模組250可控制處理電路125利用通信電路121,將已建立的一個或多個智能合約,以交易信息(transaction message)的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對第一認證機構建立的智能合約進行認證。在運作時,區塊鏈存取模組250可控制處理電路125將已建立的一個或多個智能合約的原始碼編碼成對應的位元碼(bytecode),然後利用通信電路121將前述的位元碼以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對交易信息中的智能合約進行認證。In the process 304, the blockchain access module 250 in the CSR data authentication program 126 can control the processing circuit 125 to use the communication circuit 121 to convert the established one or more smart contracts in the form of transaction messages Sent to the blockchain subsystem 150, and instructs the blockchain subsystem 150 to authenticate the smart contract established by the first certification authority. In operation, the blockchain access module 250 can control the processing circuit 125 to encode the original code of the established smart contract or smart contracts into corresponding bytecodes, and then use the communication circuit 121 to encode the aforementioned bits The meta code is transmitted to the blockchain subsystem 150 in the form of transaction information, and instructs the blockchain subsystem 150 to authenticate the smart contract in the transaction information.

接著,區塊鏈子系統150會進行流程306,利用多個節點執行合適的共識決演算法來對第一認證機構建立的一個或多個智能合約進行認證。倘若第一認證機構建立的一個或多個智能合約通過區塊鏈子系統150的認證,區塊鏈子系統150便會將第一認證機構建立的一個或多個智能合約,以資料區塊的形式儲存在區塊鏈子系統150的區塊鏈帳本中,以完成將第一認證機構的相關智能合約佈署到區塊鏈子系統150中的程序。Next, the blockchain subsystem 150 will perform a process 306, using multiple nodes to execute an appropriate consensus decision algorithm to authenticate one or more smart contracts established by the first certification authority. If one or more smart contracts established by the first certification authority pass the authentication of the blockchain subsystem 150, the blockchain subsystem 150 will store the one or more smart contracts established by the first certification authority in the form of data blocks In the blockchain ledger of the blockchain subsystem 150, the procedure of deploying the relevant smart contract of the first certification authority to the blockchain subsystem 150 is completed.

在實際應用上,第一認證機構有可能受到許多使用CSR資料認證系統100的企業委託進行相關的CSR資料認證程序,但不同的企業所需要進行的CSR資料認證層級可能會有所不同。例如,有些企業可能需要較高層級的CSR資料認證服務,但另外一些企業則可能只需要較低層級的CSR資料認證服務。因此,第一認證機構可按照前述方式,利用認證子系統120將分別對應於不同CSR資料認證層級的多組智能合約,佈署到區塊鏈子系統150中。In practical applications, the first certification body may be entrusted by many companies using the CSR data certification system 100 to perform relevant CSR data certification procedures, but the level of CSR data certification required by different companies may be different. For example, some companies may require higher-level CSR data certification services, while others may only require lower-level CSR data certification services. Therefore, the first certification authority may use the certification subsystem 120 to deploy multiple sets of smart contracts corresponding to different CSR data certification levels to the blockchain subsystem 150 in the foregoing manner.

同樣地,前述第二認證機構的人員也可利用相應的認證子系統130進行流程302~304。在運作時,認證子系統130的處理電路135會執行儲存電路132中所儲存的CSR資料認證程式136,以進行圖3與圖4中的CSR資料認證方法。Similarly, the personnel of the aforementioned second certification authority can also use the corresponding certification subsystem 130 to perform the processes 302-304. During operation, the processing circuit 135 of the authentication subsystem 130 executes the CSR data authentication program 136 stored in the storage circuit 132 to perform the CSR data authentication method in FIGS. 3 and 4.

在流程302中,CSR資料認證程式136中的合約編輯模組210可控制處理電路135可依據用戶的操控,編輯並建立包含第二認證機構設定的多項CSR資料查核規則的一個或多個智能合約,並且將第二認證機構的電子簽章附加在其中一個智能合約中,使得前述的智能合約的其中之一包含有第二認證機構的電子簽章。同樣地,合約編輯模組210可允許第二認證機構的用戶根據所需要的CSR資料認證層級或標準,彈性調整前述智能合約中的CSR資料查核規則的數量及具體內容。In the process 302, the contract editing module 210 in the CSR data authentication program 136 can control the processing circuit 135 to edit and create one or more smart contracts containing multiple CSR data checking rules set by the second certification body according to user control , And attach the electronic signature of the second certification authority to one of the smart contracts, so that one of the aforementioned smart contracts includes the electronic signature of the second certification authority. Similarly, the contract editing module 210 may allow the user of the second certification authority to flexibly adjust the number and specific content of the CSR data verification rules in the aforementioned smart contract according to the required CSR data certification level or standard.

在流程304中,CSR資料認證程式136中的區塊鏈存取模組250可控制處理電路135利用通信電路131將已建立的一個或多個智能合約以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對第二認證機構建立的智能合約進行認證。在運作時,區塊鏈存取模組250可控制處理電路135將已建立的一個或多個智能合約的原始碼編碼成對應的位元碼,然後利用通信電路131將前述的位元碼以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對交易信息中的智能合約進行認證。In the process 304, the blockchain access module 250 in the CSR data authentication program 136 can control the processing circuit 135 to use the communication circuit 131 to transmit the established one or more smart contracts to the blockchain subsystem in the form of transaction information 150, and instructs the blockchain subsystem 150 to authenticate the smart contract established by the second certification institution. During operation, the blockchain access module 250 can control the processing circuit 135 to encode the original code of the established smart contract or smart contracts into corresponding bit codes, and then use the communication circuit 131 to encode the aforementioned bit codes into The form of transaction information is transmitted to the blockchain subsystem 150 and instructs the blockchain subsystem 150 to authenticate the smart contract in the transaction information.

接著,區塊鏈子系統150會進行流程306,利用多個節點執行合適的共識決演算法來對第二認證機構建立的一個或多個智能合約進行認證。倘若第二認證機構建立的一個或多個智能合約通過區塊鏈子系統150的認證,區塊鏈子系統150便會將第二認證機構建立的一個或多個智能合約,以資料區塊的形式儲存在區塊鏈子系統150的區塊鏈帳本中,以完成將第二認證機構的相關智能合約佈署到區塊鏈子系統150中的程序。Next, the blockchain subsystem 150 will perform a process 306, using multiple nodes to execute an appropriate consensus decision algorithm to authenticate one or more smart contracts established by the second certification authority. If one or more smart contracts established by the second certification authority pass the authentication of the blockchain subsystem 150, the blockchain subsystem 150 will store the one or more smart contracts established by the second certification authority in the form of data blocks In the blockchain ledger of the blockchain subsystem 150, the procedure of deploying the relevant smart contract of the second certification authority to the blockchain subsystem 150 is completed.

在實際應用上,第二認證機構也有可能受到使用CSR資料認證系統100的多個企業委託進行相關的CSR資料認證程序,但這些的企業所需要進行的CSR資料認證層級可能會有所不同。因此,第二認證機構可按照前述方式,利用認證子系統130將分別對應於不同CSR資料認證層級的多組智能合約,佈署到區塊鏈子系統150中。In practical applications, the second certification body may also be entrusted by multiple companies using the CSR data certification system 100 to perform relevant CSR data certification procedures, but the level of CSR data certification required by these companies may be different. Therefore, the second certification authority may use the certification subsystem 130 to deploy multiple sets of smart contracts corresponding to different CSR data certification levels to the blockchain subsystem 150 in the foregoing manner.

另外,在開始處理企業的CSR資料前,CSR數據報告服務子系統110也要先進行流程308。在流程308中,網站伺服器112可依據CSR數據報告服務子系統110的管理者的設定、或是接收企業端裝置和/或認證子系統傳來的設定資料,建立多個企業與相關認證機構之間的對應關係,並將前述的對應關係儲存在用戶關係資料庫114中。In addition, before starting to process the CSR data of the enterprise, the CSR data reporting service subsystem 110 also needs to perform the process 308 first. In the process 308, the web server 112 may establish multiple enterprises and related certification bodies according to the settings of the manager of the CSR data report service subsystem 110 or receive the configuration data from the enterprise device and/or certification subsystem The corresponding relationship between them, and store the aforementioned corresponding relationship in the user relationship database 114.

為了方便說明起見,以下將企業端裝置101所屬的企業稱為第一企業,將企業端裝置103所屬的企業稱為第二企業,並假設第一企業已經委任或同意委由認證子系統120所屬的第一認證機構為第一企業進行CSR資料認證,且假設第二企業已經委任或同意委由認證子系統130所屬的第二認證機構為第二企業進行CSR資料認證。在此情況下,網站伺服器112可於流程308中將第一企業與第一認證機構之間的對應關係,以及第二企業與第二認證機構之間的對應關係,儲存在用戶關係資料庫114中。For convenience of explanation, the enterprise to which the enterprise device 101 belongs is referred to as the first enterprise, and the enterprise to which the enterprise device 103 belongs is referred to as the second enterprise, and it is assumed that the first enterprise has appointed or agreed to delegate the authentication subsystem 120 The first certification body to which it belongs performs the CSR data certification for the first enterprise, and it is assumed that the second enterprise has appointed or agreed to appoint the second certification body to which the certification subsystem 130 belongs to perform the CSR data certification for the second enterprise. In this case, the website server 112 may store the correspondence between the first enterprise and the first certification authority and the correspondence between the second enterprise and the second certification authority in the user relationship database in process 308 114.

當任一企業想要利用CSR資料認證系統100為企業的CSR資料進行認證時,該企業(以下稱之為來源企業)內部的人員可利用相應的企業端裝置進行流程310,以提供來源企業的CSR原始資料(CSR raw data)給CSR數據報告服務子系統110。When any enterprise wants to use the CSR data authentication system 100 to authenticate the CSR data of the enterprise, the personnel inside the enterprise (hereinafter referred to as the source enterprise) can use the corresponding enterprise-end device to perform the process 310 to provide the source enterprise’s CSR raw data (CSR raw data) to the CSR data report service subsystem 110.

例如,假設來源企業是前述的第一企業。在一實施例中,第一企業內部的用戶可定期或不定期操控企業端裝置101進行流程310以登入CSR數據報告服務子系統110的網站伺服器112,並在網站伺服器112所產生的相關網頁中輸入第一企業的CSR原始資料,使得企業端裝置101將第一企業的CSR原始資料透過網際網路傳送給網站伺服器112。在另一實施例中,企業端裝置101可執行預設的應用程式,定期或不定期從第一企業的資訊管理系統(management information system,MIS)、企業資源規劃系統(enterprise resource planning system,ERP system)、或由第一企業的人員所操作的前端應用系統中自動擷取第一企業的CSR原始資料,並自動透過網際網路傳送給網站伺服器112。For example, assume that the source company is the aforementioned first company. In an embodiment, a user within the first enterprise may periodically or irregularly control the enterprise-side device 101 to perform a process 310 to log in to the web server 112 of the CSR data reporting service subsystem 110, and generate relevant information on the web server 112. Entering the CSR raw data of the first company in the webpage causes the enterprise-side device 101 to send the CSR raw data of the first company to the web server 112 via the Internet. In another embodiment, the enterprise-side device 101 can execute a preset application program, periodically or irregularly from the first enterprise's management information system (MIS), enterprise resource planning system (ERP) system), or the front-end application system operated by the personnel of the first company, automatically retrieves the CSR raw data of the first company, and automatically transmits it to the web server 112 through the Internet.

同樣地,對應第二企業的企業端裝置103,也可以依據前述方式定期或不定期進行流程310,以將第二企業的CSR原始資料透過網際網路傳送給網站伺服器112。Similarly, the enterprise-side device 103 corresponding to the second company may also perform the process 310 periodically or irregularly according to the aforementioned method to send the CSR raw data of the second company to the web server 112 through the Internet.

在流程312中,CSR數據報告服務子系統110的網站伺服器112會接收相應的企業端裝置所傳來的來源企業的CSR原始資料。In the process 312, the website server 112 of the CSR data reporting service subsystem 110 receives the original CSR data of the source enterprise from the corresponding enterprise device.

在流程314中,網站伺服器112會從用戶關係資料庫114中查詢來源企業所對應的認證機構。In the process 314, the web server 112 queries the user relationship database 114 for the certification authority corresponding to the source company.

在流程316中,網站伺服器112會將來源企業的CSR原始資料,傳送給相應認證機構的認證子系統。由前述說明可知,在本實施例中,倘若來源企業是第一企業,則相應的認證子系統是第一認證機構的認證子系統120,倘若來源企業是第二企業,則相應的認證子系統是第二認證機構的認證子系統130。In the process 316, the website server 112 will send the original CSR data of the source company to the certification subsystem of the corresponding certification body. As can be seen from the foregoing description, in this embodiment, if the source enterprise is the first enterprise, the corresponding certification subsystem is the certification subsystem 120 of the first certification body, and if the source enterprise is the second enterprise, the corresponding certification subsystem It is the certification subsystem 130 of the second certification body.

為了方面說明起見,以下假設前述的來源企業是第一企業。在此情況下,網站伺服器112會在流程316中將第一企業的CSR原始資料,傳送給相應的第一認證機構的認證子系統120。For illustrative purposes, the following assumes that the aforementioned source enterprise is the first enterprise. In this case, the website server 112 will send the CSR original data of the first enterprise to the certification subsystem 120 of the corresponding first certification authority in the process 316.

實作上,網站伺服器112可在每次接收到一筆CSR原始資料後,就立刻進行前述的流程316。或者,網站伺服器112也可以定期進行前述的流程316。又或者,網站伺服器112也可以等接收到的同一來源企業的CSR原始資料累積到一預定數量時,才進行前述的流程316。In practice, the web server 112 can immediately perform the aforementioned process 316 each time it receives a piece of CSR raw data. Alternatively, the web server 112 may periodically perform the aforementioned process 316. Alternatively, the web server 112 may wait until the received CSR original data of the same source company accumulates to a predetermined amount before proceeding to the foregoing process 316.

在流程318中,認證子系統120的通信電路121會接收網站伺服器112傳來的來源企業(在本例中為第一企業)的CSR原始資料。In the process 318, the communication circuit 121 of the authentication subsystem 120 receives the CSR original data from the source company (the first company in this example) from the website server 112.

在流程320中,CSR資料認證程式126中的資料處理模組220可控制處理電路125,從來源企業的CSR原始資料中篩選出可供認證的適格原始資料(valid raw data)。實作上,可事先在資料處理模組220中根據合適的財務及會計稽核原則和/或CSR資料稽核原則,設置多項篩選規則(filter rules)。處理電路125在流程320中可根據資料處理模組220中的篩選規則,從來源企業的CSR原始資料中剔除掉不合理、不合邏輯、不完整、和/或數據前後不一致的資料項目,並將剩下來的資料項目做為來源企業的適格原始資料。In the process 320, the data processing module 220 in the CSR data authentication program 126 can control the processing circuit 125 to select valid raw data (valid raw data) that can be authenticated from the CSR raw data of the source company. In practice, a plurality of filter rules may be set in the data processing module 220 according to appropriate financial and accounting audit principles and/or CSR data audit principles in advance. In the process 320, the processing circuit 125 can remove unreasonable, illogical, incomplete, and/or inconsistent data items from the source company's CSR raw data according to the screening rules in the data processing module 220, and The remaining data items are qualified raw data of the source company.

換言之,在認證子系統120接收到的來源企業的CSR原始資料中,只有能夠通過資料處理模組220的篩選規則的資料項目,才會被處理電路125選為來源企業的適格原始資料。In other words, among the CSR raw data of the source company received by the authentication subsystem 120, only the data items that can pass the screening rules of the data processing module 220 are selected by the processing circuit 125 as the qualified raw data of the source company.

實作上,認證子系統120可在每次接收到一筆CSR原始資料後,就立刻進行前述的流程320。或者,認證子系統120也可以定期進行前述的流程320。又或者,認證子系統120也可以等接收到的CSR原始資料累積到一預定數量時,才進行前述的流程320。又或者,認證子系統120也可以在第一認證機構的相關人員下達指令時,進行前述的流程320。In practice, the authentication subsystem 120 can immediately perform the aforementioned process 320 after receiving a piece of CSR original data. Alternatively, the authentication subsystem 120 may periodically perform the aforementioned process 320. Alternatively, the authentication subsystem 120 may wait until the received CSR raw materials accumulate to a predetermined amount before performing the foregoing process 320. Alternatively, the certification subsystem 120 may also perform the aforementioned process 320 when the relevant personnel of the first certification institution issue an instruction.

之後,認證子系統120與區塊鏈子系統150會搭配進行CSR資料認證方法的後半部流程,亦即圖4中的流程402~414。After that, the authentication subsystem 120 and the blockchain subsystem 150 will cooperate with the second half of the CSR data authentication method, that is, the processes 402 to 414 in FIG. 4.

以下將搭配圖5來輔助說明認證子系統120與區塊鏈子系統150在流程402~414中的運作方式。圖5為在本發明一實施例的CSR資料認證過程中簡化後的資料流示意圖。The following will use FIG. 5 to assist in explaining how the authentication subsystem 120 and the blockchain subsystem 150 operate in the processes 402-414. FIG. 5 is a simplified data flow diagram in the CSR data authentication process according to an embodiment of the present invention.

在流程402中,CSR資料認證程式126中的資料庫存取模組230可控制處理電路125,將每一筆適格原始資料儲存到資料庫123中,並產生與各筆適格原始資料相應的資料庫索引。前述的資料庫索引是可供用來查詢相應的適格原始資料在資料庫123中的儲存位置的索引資料。在運作時,資料庫存取模組230可以採用各種現有的資料庫所引產生方式,來產生前述的資料庫索引。In the process 402, the data acquisition module 230 in the CSR data authentication program 126 can control the processing circuit 125 to store each eligible raw data in the database 123, and generate a database index corresponding to each eligible raw data . The aforementioned database index is an index data that can be used to query the storage location of the corresponding eligible original data in the database 123. During operation, the database fetching module 230 may use various existing database generation methods to generate the aforementioned database index.

為了便於理解,以下將以圖5中的適格原始資料510為例,來說明認證子系統120與區塊鏈子系統150在流程402~414中的運作方式。如圖5所示,適格原始資料510包含多個資料欄位511~517,其中,資料欄位511是公司名稱欄位(company name field)、資料欄位512是日期欄位(date field)、資料欄位513~515是多個通用資料欄位(common data field)、資料欄位516~517是多個姓名欄位(personnel name field)。在來源公司是前述第一企業的情況中,公司名稱欄位511中會記錄第一企業的名稱。For ease of understanding, the following will take the eligible raw data 510 in FIG. 5 as an example to illustrate the operation of the authentication subsystem 120 and the blockchain subsystem 150 in the processes 402-414. As shown in FIG. 5, the eligible raw data 510 includes a plurality of data fields 511 to 517, wherein the data field 511 is a company name field (company name field), and the data field 512 is a date field (date field), The data fields 513~515 are multiple common data fields, and the data fields 516~517 are multiple name fields. In the case where the source company is the aforementioned first company, the name of the first company is recorded in the company name field 511.

日期欄位512通常用來記錄來源企業進行或支持某項特定活動的日期,或是來源企業支付某項特定用途或特定會計科目的費用的日期。通用資料欄位513~515可用來記錄來源企業進行或支持某項特定活動的相關資料。姓名欄位516~517可用來記錄來源企業進行或支持某項特定活動的相關參與人員的姓名。The date field 512 is usually used to record the date when the source company carried out or supported a specific activity, or the date the source company paid for a specific purpose or a specific accounting item. The general data fields 513~515 can be used to record the relevant data of the source company carrying out or supporting a specific activity. The name fields 516~517 can be used to record the names of the relevant participants of the source company to carry out or support a specific activity.

例如,假設適格原始資料510是來源企業的員工執行某一次共乘行為的資料紀錄,則日期欄位512可用來記錄該次共乘行為的發生日期。通用資料欄位513~515可用來記錄該次共乘減碳活動的總里程數、起點位置、終點位置、車輛廠牌、車輛排氣量、車輛燃油種類、耗油量、共乘人數等等的相關紀錄。姓名欄位516~517可用來記錄參與該次共乘減碳活動的司機、乘客、發起人等有關人員的姓名。For example, assuming that the qualified raw data 510 is a data record of employees of the source company performing a certain carpooling behavior, the date field 512 can be used to record the date of the carpooling behavior. The general data fields 513~515 can be used to record the total mileage, starting position, ending position, vehicle brand, vehicle exhaust, vehicle fuel type, fuel consumption, number of passengers, etc. Related records. The name fields 516~517 can be used to record the names of drivers, passengers, promoters and other relevant persons participating in the carpooling carbon reduction activities.

又例如,假設適格原始資料510是來源企業發起海岸淨灘活動的資料紀錄,則日期欄位512可用來記錄該次海岸淨灘活動的發生日期。通用資料欄位513~515可用來記錄該次海岸淨灘活動的地點、清除的垃圾總重量、參與人數、交通費、餐飲費總支出費用等等的相關紀錄。姓名欄位516~517可用來記錄參與該次海岸淨灘活動的召集人、活動成員等有關人員的姓名。For another example, assuming that the qualified raw data 510 is a data record of a coastal beach activity initiated by a source company, the date field 512 may be used to record the date of occurrence of the coastal beach activity. The general data fields 513~515 can be used to record the location of the coastal beach activities, the total weight of rubbish removed, the number of participants, transportation costs, total food and beverage expenses and other related records. The name fields 516~517 can be used to record the names of the conveners, members of the event and other relevant personnel participating in this coastal beach activity.

又例如,假設適格原始資料510是來源企業舉辦社區義診活動的資料紀錄,則日期欄位512可用來記錄該次義診活動的發生日期。通用資料欄位513~515可用來記錄該次義診活動的地點、總受診人數、涵蓋鄉鎮數量、涵蓋地理面積、參與的醫療人員人數、交通費、餐飲費、醫療用品費用、總支出費用等等的相關紀錄。姓名欄位516~517可用來記錄參與該次義診活動的醫療人員、社區居民、受診居民、相關支援人員等有關人員的姓名。For another example, assuming that the eligible raw data 510 is a data record of a community free clinic organized by the source company, the date field 512 can be used to record the date of the free clinic. The general data fields 513~515 can be used to record the location of the free consultation, the total number of patients, the number of townships covered, the geographic area covered, the number of medical personnel involved, transportation, catering, medical supplies, total expenditures, etc. Related records. The name fields 516~517 can be used to record the names of medical personnel, community residents, residents in consultation, relevant support personnel and other relevant personnel participating in this free consultation.

又例如,假設適格原始資料510是來源企業辦理有關重視營業秘密的內部員工教育訓練的資料紀錄,則日期欄位512可用來記錄該次教育訓練的發生日期。通用資料欄位513~515可用來記錄該次教育訓練的地點、受訓人數、訓練課程時數、會議場地費、餐飲費、總支出費用等等的相關紀錄。姓名欄位516~517可用來記錄參與該次教育訓練活動的講師、人資部門人員、參與的學員、相關支援人員等有關人員的姓名。For another example, assuming that the qualified raw data 510 is a data record of the internal company's internal employee education and training that values business secrets, the date field 512 can be used to record the date of the education and training. The general data fields 513~515 can be used to record the relevant records of the location of the education and training, the number of trainees, the hours of training courses, conference venue fees, catering expenses, total expenditures, etc. The name fields 516~517 can be used to record the names of the lecturers, personnel personnel, participating students, related support personnel and other relevant personnel participating in the education and training activities.

在實際應用中,適格原始資料510的資料欄位數量、順序、以及各欄位的記錄內容,皆可依據實際需要而調整,而不侷限於前述的實施例。In practical applications, the number and sequence of data fields of the eligible original data 510 and the recorded content of each field can be adjusted according to actual needs, and are not limited to the foregoing embodiments.

在流程404中,CSR資料認證程式126中的去識別化模組240可控制處理電路125,去除適格原始資料中跟個人資料有關的可識別資料(identifiable data),以產生去識別化資料(de-identification data)。實作上,哪些資料屬於應該被移除的可識別資料,可以由去識別化模組240自行判斷。或者,CSR資料認證系統100也可以預先定義用來記錄可識別資料的欄位位置,並通知相關的企業與認證機構根據相關定義來填寫或判斷。In the process 404, the de-identification module 240 in the CSR data authentication program 126 can control the processing circuit 125 to remove the identifiable data related to the personal data from the qualified original data to generate de-identified data (de -identification data). In practice, it can be determined by the de-identification module 240 which data belongs to the identifiable data that should be removed. Alternatively, the CSR data certification system 100 may also predefine the field positions used to record the identifiable data, and notify relevant companies and certification bodies to fill in or judge according to the relevant definitions.

在流程406中,CSR資料認證程式126中的區塊鏈存取模組250可控制處理電路125將來源企業的每一筆去識別化資料及相應的資料庫索引合併成一筆組合資料(combined data)。之後,區塊鏈存取模組250可控制處理電路125利用通信電路121,將一筆或多筆組合資料以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150執行與來源企業所需的CSR資料認證層級相應的一個或多個目標智能合約,以認證來源企業的去識別化資料。在運作時,區塊鏈存取模組250可控制處理電路125將一筆或多筆組合資料編碼成對應的位元碼,然後利用通信電路121將前述的位元碼以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對交易信息中的去識別化資料進行認證。In the process 406, the blockchain access module 250 in the CSR data authentication program 126 can control the processing circuit 125 to merge each de-identified data of the source enterprise and the corresponding database index into a combined data (combined data) . After that, the blockchain access module 250 can control the processing circuit 125 to use the communication circuit 121 to send one or more combined data to the blockchain subsystem 150 in the form of transaction information, and instruct the blockchain subsystem 150 to execute and source One or more target smart contracts corresponding to the CSR data authentication level required by the enterprise to authenticate the de-identified data of the source enterprise. During operation, the blockchain access module 250 can control the processing circuit 125 to encode one or more pieces of combined data into corresponding bit codes, and then use the communication circuit 121 to transmit the aforementioned bit codes in the form of transaction information to The blockchain subsystem 150 instructs the blockchain subsystem 150 to authenticate the de-identified data in the transaction information.

以圖5中的適格原始資料510為例,在前述的流程402中,資料庫存取模組230可控制處理電路125將適格原始資料510儲存到資料庫123中,並產生與適格原始資料510相應的資料庫索引520。如前所述,資料庫索引520是可供用來查詢適格原始資料510在資料庫123中的儲存位置的索引資料。Taking the eligible raw data 510 in FIG. 5 as an example, in the aforementioned process 402, the data acquisition module 230 may control the processing circuit 125 to store the eligible raw data 510 in the database 123, and generate corresponding to the eligible raw data 510 Index of database 520. As mentioned above, the database index 520 is index data that can be used to query the storage location of the eligible original data 510 in the database 123.

在流程404中,去識別化模組240可控制處理電路125去除適格原始資料510中跟個人資料有關的可識別資料,以產生不包含個人資料及無需被公開的公司費用支出細節等商業資料的去識別化資料530。為了方便說明,以下假設在圖5的實施例中,只有資料欄位516~517的資料以及通用資料欄位513~515中的局部欄位的資料屬於可識別資料,因此,去識別化模組240可將適格原始資料510中跟人名有關的資料欄位516~517以及通用資料欄位513~515中的局部欄位移除,使得資料欄位516~517及部分通用資料欄位的資料不會出現在去識別化資料530中。In the process 404, the de-identification module 240 can control the processing circuit 125 to remove the identifiable data related to the personal data in the qualified raw data 510, so as to generate business data that does not contain personal data and does not need to be disclosed company expense details, etc. De-identification data 530. For convenience of explanation, it is assumed that in the embodiment of FIG. 5, only the data in the data fields 516 to 517 and the partial data in the general data fields 513 to 515 belong to the identifiable data. Therefore, the de-identification module 240 can remove the data fields 516-517 related to the name of the qualified original data 510 and the partial fields in the general data fields 513-515, so that the data of the data fields 516-517 and some general data fields are not Will appear in the de-identified data 530.

在流程406中,區塊鏈存取模組250可控制處理電路125將去識別化資料530及相應的資料庫索引520合併成一筆組合資料540。如圖5所示,組合資料540中包含去識別化資料530的內容、以及相應的資料庫索引520的內容。之後,區塊鏈存取模組250可控制處理電路125利用通信電路121,將組合資料540單獨(或是與其他組合資料一起)以交易信息的形式傳送至區塊鏈子系統150。In the process 406, the blockchain access module 250 can control the processing circuit 125 to merge the de-identified data 530 and the corresponding database index 520 into a combined data 540. As shown in FIG. 5, the combined data 540 includes the content of the de-identified data 530 and the content of the corresponding database index 520. After that, the blockchain access module 250 can control the processing circuit 125 to use the communication circuit 121 to transmit the combined data 540 alone (or together with other combined data) to the blockchain subsystem 150 in the form of transaction information.

從前述說明可知,認證子系統120傳送給區塊鏈子系統150的去識別化資料,是適格原始資料的簡化版本,所以可以做為後續CSR資料認證的基礎。相較於適格原始資料,去識別化資料中不包含跟私人資料有關的個人信息。因此,認證子系統120將去識別化資料傳送到區塊鏈子系統150進行查核,並不會外洩來源企業的內部員工或相關人員的個人資料,因此不會導致個資外洩的疑慮。As can be seen from the foregoing description, the de-identified data sent by the authentication subsystem 120 to the blockchain subsystem 150 is a simplified version of the qualified original data, so it can be used as the basis for subsequent CSR data authentication. Compared with qualified raw data, de-identified data does not contain personal information related to private data. Therefore, the authentication subsystem 120 transmits the de-identified data to the blockchain subsystem 150 for verification, and will not leak the personal data of the internal employees or related personnel of the source enterprise, so there will be no doubt about the leakage of personal information.

實作上,認證子系統120進行前述的流程402~406的時機,可以依據需要而有多種不同的選擇。In practice, the timing for the authentication subsystem 120 to perform the aforementioned processes 402-406 can have many different options according to needs.

例如,認證子系統120可在每次產生一筆適格原始資料後,就立刻進行前述的流程402~406。For example, the authentication subsystem 120 may immediately perform the aforementioned processes 402 to 406 after generating a piece of qualified original data.

或者,認證子系統120可定期進行前述的流程402~406。Alternatively, the authentication subsystem 120 may periodically perform the aforementioned processes 402-406.

又或者,認證子系統120可等到適格原始資料累積到一預定數量時,才進行前述的流程402~406。Alternatively, the authentication subsystem 120 may wait until the eligible raw materials accumulate to a predetermined amount before performing the foregoing processes 402-406.

又或者,認證子系統120可定期進行前述的流程402~404,但可等到同一來源企業的去識別化資料與相應的資料庫所引累積到一預定數量時,才進行前述的流程406。Alternatively, the authentication subsystem 120 may periodically perform the aforementioned processes 402-404, but may not perform the aforementioned process 406 until the deidentified data of the same source company and the corresponding database are accumulated to a predetermined amount.

又或者,認證子系統120可在每次產生一筆適格原始資料後,就立刻進行前述的流程402~404,但可等到預定的時間點才定期進行前述的流程406。Alternatively, the authentication subsystem 120 may immediately perform the foregoing processes 402 to 404 after generating a piece of qualified original data, but may periodically perform the foregoing process 406 at a predetermined time.

又或者,認證子系統120可在每次產生一筆適格原始資料後,就立刻進行前述的流程402~404,但可等到同一來源企業的去識別化資料與相應的資料庫所引累積到一預定數量時,才進行前述的流程406。Alternatively, the authentication subsystem 120 may immediately perform the aforementioned processes 402 to 404 each time a qualified source data is generated, but may wait until the deidentified data of the same source company and the corresponding database are accumulated to a predetermined When the number is reached, the aforementioned process 406 is performed.

在流程408中,區塊鏈子系統150中的多個節點會共同執行認證子系統120指定的一個或多個目標智能合約,以對認證子系統120傳來的組合資料中的每一筆去識別化資料的內容逐一進行查核。In the process 408, multiple nodes in the blockchain subsystem 150 will jointly execute one or more target smart contracts specified by the authentication subsystem 120 to de-identify each piece of the combined data transmitted from the authentication subsystem 120 Check the contents of the documents one by one.

如前所述,認證子系統120預先佈署在區塊鏈子系統150中的一個或多個目標智能合約,包含有第一認證機構所設定的多項CSR資料查核規則,且前述的目標智能合約的其中之一包含有第一認證機構的電子簽章。區塊鏈子系統150在流程408中會將每一筆去識別化資料與目標智能合約中的多項CSR資料查核規則進行比對,以查核該筆去識別化資料是否滿足相應的CSR資料查核規則。As mentioned above, the authentication subsystem 120 pre-deployed one or more target smart contracts in the blockchain subsystem 150, including multiple CSR data check rules set by the first certification authority, and the aforementioned target smart contract’s One of them includes the electronic signature of the first certification body. In the process 408, the blockchain subsystem 150 compares each de-identified data with multiple CSR data check rules in the target smart contract to check whether the de-identified data meets the corresponding CSR data check rules.

在流程410中,區塊鏈子系統150會捨棄無法通過目標智能合約查核的去識別化資料,並傳送一認證失敗通知給認證子系統120。當認證子系統120在流程410中接收到區塊鏈子系統150傳來的認證失敗通知時,資料處理模組220便可控制處理電路125產生相關的提示信息,以便認證子系統120的用戶可以得知相關的結果。In the process 410, the blockchain subsystem 150 discards the de-identified data that cannot be checked by the target smart contract, and sends an authentication failure notification to the authentication subsystem 120. When the authentication subsystem 120 receives the authentication failure notification from the blockchain subsystem 150 in the process 410, the data processing module 220 can control the processing circuit 125 to generate relevant prompt information so that users of the authentication subsystem 120 can obtain Know related results.

在流程412中,區塊鏈子系統150可從前述的一個或多個目標智能合約中擷取出第一認證機構的電子簽章,並將通過查核的去識別化資料,連同相應的資料庫索引以及第一認證機構的電子簽章一起打包,以產生包含來源企業的去識別化資料、相應的資料庫索引、以及第一認證機構的電子簽章的認證後資料(verified data)。In process 412, the blockchain subsystem 150 may extract the electronic signature of the first certification authority from the aforementioned one or more target smart contracts, and de-identify the data through verification, together with the corresponding database index and The electronic signatures of the first certification body are packaged together to generate de-identified data of the source company, the corresponding database index, and the verified data of the electronic signatures of the first certification body.

在流程414中,區塊鏈子系統150會將認證後資料以資料區塊的形式儲存在區塊鏈子系統150中進行保存。In the process 414, the blockchain subsystem 150 stores the authenticated data in the blockchain subsystem 150 in the form of data blocks for storage.

來源企業的每一筆適格原始資料經過前述流程320、402、404、404、406、408、412、與414的處理後,便可完成相應認證層級的CSR資料認證程序。After each qualified source data of the source company is processed by the aforementioned processes 320, 402, 404, 404, 406, 408, 412, and 414, the CSR data certification process at the corresponding certification level can be completed.

之後,區塊鏈子系統150中的每個節點都能夠在需要的時候,讀取保存在區塊鏈子系統150中的認證後資料進行查閱或進一步分析。After that, each node in the blockchain subsystem 150 can read the post-authentication data stored in the blockchain subsystem 150 for review or further analysis when needed.

以前述圖5中的組合資料540為例,區塊鏈子系統150在流程408中會將組合資料540中的去識別化資料530,與目標智能合約中的多項CSR資料查核規則進行比對,以查核去識別化資料530是否滿足相應的CSR資料查核規則。Taking the aforementioned combined data 540 in FIG. 5 as an example, the blockchain subsystem 150 compares the de-identified data 530 in the combined data 540 with multiple CSR data check rules in the target smart contract in the process 408 to Check whether the de-identified data 530 meets the corresponding CSR data checking rules.

倘若去識別化資料530不符合目標智能合約中的CSR資料查核規則,則區塊鏈子系統150會捨棄組合資料540並通知認證子系統120。If the de-identified data 530 does not comply with the CSR data check rules in the target smart contract, the blockchain subsystem 150 will discard the combined data 540 and notify the authentication subsystem 120.

反之,倘若去識別化資料530符合目標智能合約中的CSR資料查核規則,則區塊鏈子系統150可在流程412中將通過查核的去識別化資料530,連同相應的資料庫索引520以及第一認證機構的電子簽章一起打包,以產生一認證後資料550,使得認證後資料550中會包含去識別化資料530的內容、資料庫索引520的內容、以及認證子系統120所屬的第一認證機構的電子簽章,如圖5所示。On the contrary, if the de-identified data 530 conforms to the CSR data check rules in the target smart contract, the blockchain subsystem 150 may pass the checked de-identified data 530 in the process 412, together with the corresponding database index 520 and the first The electronic signature of the certification body is packaged together to generate a post-certification data 550, so that the post-certification data 550 will contain the contents of the de-identified data 530, the contents of the database index 520, and the first certification to which the certification subsystem 120 belongs The organization's electronic signature is shown in Figure 5.

接著,區塊鏈子系統150會進行流程414,將認證後資料550以資料區塊的形式寫入區塊鏈子系統150中進行保存。Next, the blockchain subsystem 150 will perform a process 414 to write the authenticated data 550 into the blockchain subsystem 150 in the form of data blocks for storage.

如圖5所示,來源企業的適格原始資料510經過前述流程320、402、404、404、406、408、412、與414的處理後,便可完成相應認證層級的CSR資料認證程序,並使得與適格原始資料510相應的認證後資料550被保存在區塊鏈子系統150中。如此一來,任何有權限從區塊鏈子系統150中讀取認證後資料550的人,都可依據認證後資料550中的電子簽章,清楚得知認證後資料550中所包含的去識別化資料530已順利通過第一認證機構所佈署的智能合約的查核程序。從另一角度而言,這代表認證後資料550中的去識別化資料530已順利通過第一認證機構的CSR資料認證程序。As shown in FIG. 5, the qualified raw data 510 of the source company can be processed through the aforementioned processes 320, 402, 404, 404, 406, 408, 412, and 414 to complete the CSR data certification process at the corresponding certification level and make The post-authentication data 550 corresponding to the eligible original data 510 is stored in the blockchain subsystem 150. In this way, anyone who has the authority to read the post-authentication data 550 from the blockchain subsystem 150 can clearly know the de-identification contained in the post-authentication data 550 based on the electronic signature in the post-authentication data 550. Data 530 has successfully passed the verification procedure of the smart contract deployed by the first certification body. From another perspective, this means that the de-identified data 530 in the post-certification data 550 has successfully passed the CSR data certification process of the first certification body.

相仿地,前述的第二企業亦可比照前述方式將CSR原始資料傳送給CSR數據報告服務子系統110,再由CSR數據報告服務子系統110轉送給由第二認證機構操作的認證子系統130進行處理。認證子系統130與區塊鏈子系統150可按照前述圖3與圖4的方法搭配運作,以對第二企業所提供的CSR原始資料進行相關的CSR資料認證程序。Similarly, the aforementioned second company can also transfer the CSR raw data to the CSR data reporting service subsystem 110 according to the aforementioned method, and then the CSR data reporting service subsystem 110 is transferred to the certification subsystem 130 operated by the second certification body. deal with. The authentication subsystem 130 and the blockchain subsystem 150 can operate in conjunction with the methods of FIG. 3 and FIG. 4 described above to perform related CSR data authentication procedures on the CSR original data provided by the second company.

由前述說明可知,圖3與圖4中的CSR資料認證方法是利用區塊鏈搭配智能合約的架構來自動完成來源企業的CSR資料認證程序,所以能夠大幅提升CSR資料認證的效率與正確性,並同時大幅減少所需的人力與時間,更能有效避免儲存在區塊鏈子系統150中的認證後資料被事後竄改的風險。As can be seen from the foregoing description, the CSR data authentication methods in Figures 3 and 4 use the blockchain and smart contract architecture to automatically complete the source company's CSR data authentication process, so it can greatly improve the efficiency and accuracy of CSR data authentication. At the same time, the required manpower and time are greatly reduced, and the risk of tampering with the post-authentication data stored in the blockchain subsystem 150 can be effectively avoided.

另一方面,儲存於區塊鏈子系統150的認證後資料中所包含的去識別化資料的內容,並不包含跟私人資料有關的個人信息,利用區塊鏈子系統150來儲存認證後資料並不會外洩來源企業的內部員工或相關人員的個人資料,因此不會導致個資外洩的疑慮。On the other hand, the content of the de-identified data contained in the post-authentication data stored in the blockchain subsystem 150 does not include personal information related to private data. Using the blockchain subsystem 150 to store post-authentication data does not The personal data of internal employees or related personnel of the source company will be leaked, so there will be no doubts about the leakage of personal information.

請注意,傳統上為來源企業進行CSR資料認證的主體(entity),是來源企業所委任的認證機構,但在CSR資料認證系統100中卻並非如此。Please note that the entity that traditionally authenticates CSR data for the source company is the certification body appointed by the source company, but this is not the case in the CSR data certification system 100.

由前述圖3與圖4流程圖的說明可知,在CSR資料認證系統100中實際上依據相關CSR資料認證規則對去識別化資料進行查核的主體,是角色中立的區塊鏈子系統150,而不是任何認證子系統、也不是任何認證子系統所屬的認證機構。It can be seen from the foregoing descriptions of the flowcharts in FIG. 3 and FIG. 4 that, in the CSR data authentication system 100, the subject of checking the de-identified data according to the relevant CSR data authentication rules is the role-neutral blockchain subsystem 150, not Any certification subsystem is not a certification body to which any certification subsystem belongs.

以前述圖5中的去識別化資料530為例,認證子系統120在產生去識別化資料530後,並不會對去識別化資料530進行CSR資料認證,而是將包含去識別化資料530的組合資料540傳送到區塊鏈子系統150中進行認證。區塊鏈子系統150會執行認證子系統120預先佈署的目標智能合約,來查核組合資料540中的去識別化資料530的內容是否符合目標智能合約中的CSR資料查核規則。當去識別化資料530的內容通過相關智能合約的查核後,區塊鏈子系統150便會將去識別化資料530轉換成認證後資料550的形式,並保存在區塊鏈子系統150中。Taking the aforementioned de-identified data 530 in FIG. 5 as an example, after generating the de-identified data 530, the authentication subsystem 120 does not perform CSR data authentication on the de-identified data 530, but will include the de-identified data 530. The combined data 540 is sent to the blockchain subsystem 150 for authentication. The blockchain subsystem 150 will execute the target smart contract pre-deployed by the authentication subsystem 120 to check whether the content of the de-identified data 530 in the combination data 540 complies with the CSR data check rules in the target smart contract. After the content of the de-identified data 530 passes the verification of the relevant smart contract, the blockchain subsystem 150 converts the de-identified data 530 into the form of the authenticated data 550 and saves it in the blockchain subsystem 150.

很明顯地,任何企業都無法將偽造的認證後資料自行寫入區塊鏈子系統150中欺騙其他人。Obviously, no enterprise can write fake authentication information into the blockchain subsystem 150 to deceive others.

另外,從前述CSR資料認證系統100進行CSR資料認證的過程來看,實際上是認證子系統120把對企業的CSR資料進行認證的權力,透過智能合約作為媒介交到區塊鏈子系統150手上,由中立的區塊鏈子系統150代替第一認證機構操控的認證子系統120來對第一企業的CSR資料進行認證,並將認證後的CSR資料保存在區塊鏈子系統150中。In addition, judging from the process of CSR data authentication by the aforementioned CSR data authentication system 100, it is actually the authentication subsystem 120 that passes the power to authenticate the enterprise's CSR data to the blockchain subsystem 150 through smart contracts as a medium , The neutral blockchain subsystem 150 replaces the authentication subsystem 120 operated by the first certification body to authenticate the CSR data of the first enterprise, and saves the certified CSR data in the blockchain subsystem 150.

任何認證機構的智能合約都要先經過區塊鏈子系統150中的多個節點的共同認證,才能佈署到區塊鏈子系統150中,而且任何有權限讀取區塊鏈子系統150中的資料的人,皆可從認證後資料中的電子簽章得知該筆認證後資料先前是根據哪一個認證機構的智能合約來進行查核。因此,前述的CSR資料認證方式可有效避免企業串通委任的認證機構共同造假CSR資料認證結果的可能,所以能夠大幅提升CSR資料認證系統100整體認證過程的透明度與公信力。The smart contract of any certification authority must first be jointly authenticated by multiple nodes in the blockchain subsystem 150 before it can be deployed to the blockchain subsystem 150, and anyone with the authority to read the data in the blockchain subsystem 150 Everyone can know from the electronic signature in the post-authentication information which post-authentication information was previously checked based on which certification agency’s smart contract. Therefore, the aforementioned CSR data certification method can effectively avoid the possibility that the certification bodies appointed by the enterprises collude to falsify the CSR data certification results, so the transparency and credibility of the overall certification process of the CSR data certification system 100 can be greatly improved.

以下將搭配圖6至圖7來進一步說明CSR資料認證系統100產生相關特定CSR項目數據報告(specific-CSR-category data report)的運作方式。圖6與圖7為本發明一實施例的特定CSR項目數據報告產生方法簡化後的流程圖。6 to 7 are used to further explain the operation of the CSR data certification system 100 to generate a specific-CSR-category data report. 6 and 7 are simplified flowcharts of a specific CSR project data report generation method according to an embodiment of the invention.

如前所述,當任何資料需求者(例如,投資機構、企業或組織的供應鏈管理部門、或官方的金融監理單位等等)需要查詢特定目標企業的CSR資料時,可透過相應的需求端裝置向CSR數據報告服務子系統110發送請求。As mentioned earlier, when any data demander (for example, the investment chain, the supply chain management department of an enterprise or organization, or the official financial supervision unit, etc.) needs to query the CSR data of a specific target enterprise, the corresponding demand end can be used The device sends a request to the CSR data report service subsystem 110.

為了方面說明起見,以下用需求端裝置105的用戶想要查詢特定目標企業的特定CSR項目數據報告的情境為例,來說明圖6與圖7中的特定CSR項目數據報告產生方法。For illustrative purposes, the following uses the scenario where the user of the demand-side device 105 wants to query a specific CSR project data report of a specific target company as an example to illustrate the specific CSR project data report generation method in FIGS. 6 and 7.

首先,需求端裝置105可依據其用戶的操作進行流程602,以透過網際網路從遠端登入CSR數據報告服務子系統110。需求端裝置105登入CSR數據報告服務子系統110的方式,可採用各種合適的帳號查核或身分驗證方式來進行。First, the demand-side device 105 can perform the process 602 according to the operation of its user to remotely log in to the CSR data report service subsystem 110 through the Internet. The way for the demand-side device 105 to log in to the CSR data report service subsystem 110 can be performed by using various appropriate account checking or identity verification methods.

在需求端裝置105成功登入CSR數據報告服務子系統110後,CSR數據報告服務子系統110的網站伺服器112可產生相關的查詢對象選擇網頁,供需求端裝置105的用戶瀏覽及設定。After the demand-side device 105 successfully logs into the CSR data reporting service subsystem 110, the website server 112 of the CSR data-reporting service subsystem 110 may generate a relevant query object selection webpage for the user of the demand-side device 105 to browse and set.

接著,需求端裝置105可進行流程604,依據用戶的操作選擇欲查詢的目標企業、資料時間範圍、及資料項目(data category),並產生及傳送一相應的特定項目數據報告請求(specific-category data report request)至網站伺服器112。實作上,前述的特定項目數據報告請求中可包含一個或多個選定資料項目。在一實施例中,前述的資料項目是用來指定要查詢的CSR資料是屬於哪一個或哪幾個特定的主資料項目。在其他實施例中,前述的資料項目可進一步用來指定要查詢的CSR資料是屬於哪一個特定的主要資料項目底下的哪一個或哪幾個特定的子資料項目。Then, the demand-side device 105 may perform the process 604, select the target company, data time range, and data category to be queried according to the user's operation, and generate and transmit a corresponding specific project data report request (specific-category data report request) to the web server 112. In practice, the aforementioned specific project data report request may include one or more selected data items. In one embodiment, the aforementioned data items are used to specify which one or several specific master data items the CSR data to be queried belongs to. In other embodiments, the aforementioned data items may be further used to specify which specific sub-data item or which specific main data items the CSR data to be queried belongs to.

在流程606中,網站伺服器112會接收需求端裝置105傳來的特定項目數據報告請求。In the process 606, the website server 112 receives the specific project data report request from the demand-side device 105.

在流程608中,網站伺服器112會產生並傳送一詢問信息給特定項目數據報告請求所對應的目標企業。在運作時,網站伺服器112可將該詢問信息透過網際網路傳送給目標企業對應的企業端裝置。In the process 608, the website server 112 generates and sends an inquiry message to the target enterprise corresponding to the specific project data report request. During operation, the web server 112 can send the query information to the enterprise-side device corresponding to the target enterprise through the Internet.

為了方面說明起見,以下假設前述的目標企業是第一企業。在此情況下,網站伺服器112會在流程608中產生並傳送一詢問信息給第一企業所對應的企業端裝置101。For the sake of explanation, the following assumes that the aforementioned target company is the first company. In this case, the website server 112 generates and sends a query message to the enterprise device 101 corresponding to the first enterprise in the process 608.

在流程610中,企業端裝置101會接送網站伺服器112傳來的詢問信息,並產生相關的提示訊息以詢問第一企業的內部人員是否同意CSR數據報告服務子系統110提供第一企業的相關特定CSR項目數據報告給需求端裝置105的用戶。In the process 610, the enterprise device 101 will pick up the inquiry message from the website server 112 and generate a relevant prompt message to ask whether the internal staff of the first enterprise agrees to the CSR data reporting service subsystem 110 to provide the first enterprise related information The specific CSR project data is reported to the user of the demand side device 105.

倘若第一企業的內部人員不願意將第一企業的相關特定CSR項目數據報告提供給需求端裝置105的用戶,則可利用企業端裝置101進行流程612。反之,倘若第一企業的內部人員願意將第一企業的相關特定CSR項目數據報告提供給需求端裝置105的用戶,則可利用企業端裝置101進行流程616。If the internal personnel of the first enterprise are unwilling to provide the specific CSR project data report of the first enterprise to the user of the demand-side device 105, the enterprise-side device 101 may be used to perform the process 612. On the contrary, if the internal personnel of the first enterprise are willing to provide the data report of the specific CSR project related to the first enterprise to the user of the demand-side device 105, the enterprise-side device 101 may be used to perform the process 616.

在流程612中,企業端裝置101會依據其用戶的指示,傳送一拒絕信息(disapproval message)給CSR數據報告服務子系統110。CSR數據報告服務子系統110的網站伺服器112在收到企業端裝置101傳來的拒絕信息後,可產生並傳送一相應的拒絕通知(rejection notice)給需求端裝置105。In the process 612, the enterprise device 101 sends a rejection message (disapproval message) to the CSR data report service subsystem 110 according to the instructions of its user. After receiving the rejection information from the enterprise-side device 101, the website server 112 of the CSR data reporting service subsystem 110 may generate and send a corresponding rejection notice to the demand-side device 105.

在流程614中,需求端裝置105會接收網站伺服器112傳來的拒絕通知,並以適當的形式通知需求端裝置105的用戶。In the process 614, the demand-side device 105 receives the rejection notification from the website server 112 and notifies the user of the demand-side device 105 in an appropriate form.

在流程616中,企業端裝置101會依據其用戶的指示,傳送一同意信息(approval message)給CSR數據報告服務子系統110。In the process 616, the enterprise device 101 transmits an approval message to the CSR data report service subsystem 110 according to the instructions of its user.

在一實施例中,當網站伺服器112接收到企業端裝置101傳來的同意信息時,網站伺服器112會查詢區塊鏈子系統150中是否已儲存有前述特定項目數據報告請求所需要的特定CSR項目數據報告。倘若前述特定項目數據報告請求所需要的特定CSR項目數據報告已經製作完成並存在區塊鏈子系統150中,則網站伺服器112可單純從區塊鏈子系統150中讀取出所需的特定CSR項目數據報告,並傳送給需求端裝置105。反之,倘若區塊鏈子系統150中並沒有所需的特定CSR項目數據報告,則網站伺服器112會進行流程618。In one embodiment, when the web server 112 receives the consent information from the enterprise device 101, the web server 112 will query whether the specific information required by the aforementioned specific item data report request is already stored in the blockchain subsystem 150 CSR project data report. If the specific CSR project data report required by the aforementioned specific project data report request has been completed and stored in the blockchain subsystem 150, the website server 112 can simply read out the specific CSR project required from the blockchain subsystem 150 The data report is transmitted to the demand-side device 105. On the contrary, if there is no specific CSR project data report required in the blockchain subsystem 150, the website server 112 will proceed to the process 618.

在另一實施例中,當網站伺服器112接收到企業端裝置101傳來的同意信息時,不論區塊鏈子系統150中是否已儲存有前述特定項目數據報告請求所需要的特定CSR項目數據報告,網站伺服器112都會進行流程618。In another embodiment, when the website server 112 receives the consent information from the enterprise-side device 101, whether or not the specific CSR project data report required by the aforementioned specific project data report request is already stored in the blockchain subsystem 150 , The web server 112 will perform the process 618.

在流程618中,網站伺服器112會產生與需求端裝置105選定的目標企業(在本例中假設為第一企業)、資料時間範圍、及資料項目相應的一報告製作請求(report generation request)。實作上,網站伺服器112可將需求端裝置105所選定的目標企業、資料時間範圍、及資料項目,以各種合適的資料格式記錄在報告製作請求中。In the process 618, the website server 112 generates a report generation request (report generation request) corresponding to the target enterprise selected by the demand-side device 105 (assumed to be the first enterprise in this example), the data time range, and the data item . In practice, the web server 112 can record the target enterprise, data time range, and data items selected by the demand-side device 105 in various appropriate data formats in the report production request.

在流程620中,網站伺服器112會從用戶關係資料庫114中查詢目標企業所對應的認證機構。In the process 620, the web server 112 queries the user relationship database 114 for the certification authority corresponding to the target enterprise.

接著,網站伺服器112會進行流程622,將報告製作請求傳送給相應認證機構的認證子系統。由於本實施例中是假設目標企業為第一企業,而第一企業所對應的認證機構是第一認證機構。因此,網站伺服器112在流程622中會將報告製作請求傳送給第一認證機構對應的認證子系統120。Next, the website server 112 will perform a process 622 to send the report creation request to the certification subsystem of the corresponding certification authority. In this embodiment, it is assumed that the target enterprise is the first enterprise, and the certification authority corresponding to the first enterprise is the first certification authority. Therefore, in the process 622, the website server 112 transmits the report creation request to the certification subsystem 120 corresponding to the first certification authority.

接下來,認證子系統120與區塊鏈子系統150會搭配進行特定CSR項目數據報告產生方法的後半部流程,亦即圖7中的流程702~710。Next, the authentication subsystem 120 and the blockchain subsystem 150 will cooperate to perform the second half of the process of generating a specific CSR project data report, that is, the processes 702 to 710 in FIG. 7.

在流程702中,認證子系統120的通信電路121會接收網站伺服器112傳來的報告製作請求,而CSR資料認證程式126中的資料處理模組220可控制處理電路125讀取報告製作請求中所記錄的選定目標企業、選定資料時間範圍、以及選定資料項目等查詢參數。In the process 702, the communication circuit 121 of the authentication subsystem 120 receives the report creation request from the website server 112, and the data processing module 220 in the CSR data authentication program 126 can control the processing circuit 125 to read the report creation request Recorded query parameters such as selected target enterprise, selected data time range, and selected data items.

在流程704中,CSR資料認證程式126中的區塊鏈存取模組250可控制處理電路125,從區塊鏈子系統150中讀取出目標企業(在本例中為第一企業)在選定資料時間範圍內、對應一個或多個選定資料項目的多筆相關認證後資料。In the process 704, the blockchain access module 250 in the CSR data authentication program 126 can control the processing circuit 125 to read out the target enterprise (in this example, the first enterprise) from the blockchain subsystem 150 in the selected Multiple relevant post-authentication data corresponding to one or more selected data items within the time range of the data.

在流程706中,CSR資料認證程式126中的區塊鏈存取模組250可控制處理電路125從前述的多筆認證後資料中擷取出多筆資料庫索引。In the process 706, the blockchain access module 250 in the CSR data authentication program 126 can control the processing circuit 125 to extract multiple database indexes from the aforementioned multiple post-authentication data.

在流程708中,CSR資料認證程式126中的資料庫存取模組230可控制處理電路125,根據前述的多筆資料庫索引查詢資料庫123,以從資料庫123中讀取出目標企業(在本例中為第一企業)的多筆適格原始資料。In the process 708, the data acquisition module 230 in the CSR data authentication program 126 can control the processing circuit 125 to query the database 123 according to the aforementioned multiple database indexes to read out the target enterprise from the database 123 (in In this example, it is the first qualified source).

在流程710中,CSR資料認證程式126中的報告產生模組260可控制處理電路125根據預定的報告製作規則,將前述的多筆適格原始資料自動轉換成一份特定CSR項目數據報告。實作上,可以將如何對多筆適格原始資料中的相關紀錄進行分類、統計、分析、繪製圖表等各種規則,預先設置在報告產生模組260中,以供處理電路125據以進行流程710。In the process 710, the report generation module 260 in the CSR data authentication program 126 can control the processing circuit 125 to automatically convert the aforementioned plurality of eligible original data into a specific CSR project data report according to predetermined report production rules. In practice, various rules on how to classify, count, analyze, and draw relevant records in multiple eligible raw materials can be pre-set in the report generation module 260 for the processing circuit 125 to carry out the process 710 .

為了便於理解,在此搭配圖8來輔助說明圖7中的流程702~710。圖8為在本發明一實施例的特定CSR項目數據報告產生過程中簡化後的資料流示意圖。For ease of understanding, FIG. 8 is used here to assist in explaining the processes 702 to 710 in FIG. 7. FIG. 8 is a simplified data flow diagram during the process of generating a specific CSR project data report according to an embodiment of the present invention.

在前述的流程704中,處理電路125可依據區塊鏈存取模組250的控制,從區塊鏈子系統150讀取出第一企業在選定資料時間範圍內、對應一個或多個選定資料項目的多筆認證後資料,其中,圖8所繪示的認證後資料810是前述多筆認證後資料的其中之一。In the aforementioned process 704, the processing circuit 125 may read from the blockchain subsystem 150 according to the control of the blockchain access module 250 that the first enterprise corresponds to one or more selected data items within the selected data time range Multiple post-authentication data, of which the post-authentication data 810 shown in FIG. 8 is one of the aforementioned multiple post-authentication data.

如圖8所示,認證後資料810中包含有去識別化資料812、資料庫索引814、以及相應認證機構的電子簽章816(在本例中為第一認證機構的電子簽章)。As shown in FIG. 8, the post-certification data 810 includes the de-identified data 812, the database index 814, and the electronic signature 816 of the corresponding certification authority (in this example, the electronic signature of the first certification authority).

在前述的流程706中,處理電路125可依據區塊鏈存取模組250的控制,從認證後資料810中擷取出資料庫索引814。In the aforementioned process 706, the processing circuit 125 may extract the database index 814 from the authenticated data 810 according to the control of the blockchain access module 250.

在前述的流程708中,處理電路125可依據資料庫存取模組230的控制,根據資料庫索引814查詢資料庫123,以從資料庫123中讀取出與第一企業相應的一筆適格原始資料831。適格原始資料831的資料欄位配置與前述圖5中的適格原始資料510實質上相同。因此,為簡化圖面起見,在圖8中並未繪示適格原始資料831的資料欄位配置。In the aforementioned process 708, the processing circuit 125 can query the database 123 according to the database index 814 according to the control of the data storage module 230 to read out a piece of qualified original data corresponding to the first company from the database 123 831. The data field configuration of the eligible raw data 831 is substantially the same as the eligible raw data 510 in FIG. 5 described above. Therefore, in order to simplify the drawing, the data field configuration of the eligible original data 831 is not shown in FIG. 8.

接下來,處理電路125可根據區塊鏈存取模組250與資料庫存取模組230的控制,對其他的認證後資料重複進行擷取資料庫索引以及查詢資料庫123的運作,以從資料庫123中陸續讀取出其他的適格原始資料833~835。Next, the processing circuit 125 may repeat the operations of retrieving the database index and querying the database 123 for other authenticated data according to the control of the blockchain access module 250 and the data storage fetching module 230 to retrieve data from the data The library 123 successively reads other qualified raw materials 833~835.

當獲得所有符合條件的適格原始資料後,處理電路125便可依據報告產生模組260的控制,進行前述的流程710,以將前述的多筆適格原始資料根據預定的報告製作規則自動轉換成一份特定CSR項目數據報告,並可將前述的多筆適格原始資料中的相關紀錄的統計結果或分析結果,以各種圖表的方式呈現在該特定CSR項目數據報告中。After obtaining all eligible qualified raw materials, the processing circuit 125 can perform the aforementioned process 710 according to the control of the report generation module 260 to automatically convert the aforementioned multiple qualified raw materials into a copy according to predetermined report production rules The data report of a specific CSR project, and the statistical results or analysis results of the relevant records in the multiple eligible raw materials mentioned above can be presented in the data report of the specific CSR project in various charts.

換言之,認證子系統120的處理電路125會依據從區塊鏈子系統150中讀取出來的多筆認證後資料,即時產生前述的特定CSR項目數據報告。In other words, the processing circuit 125 of the authentication subsystem 120 will immediately generate the aforementioned specific CSR project data report based on the multiple pieces of post-authentication data read from the blockchain subsystem 150.

在流程712中,報告產生模組260可控制處理電路125利用通信電路121,將產生的特定CSR項目數據報告傳送給CSR數據報告服務子系統110的網站伺服器112。In the process 712, the report generation module 260 can control the processing circuit 125 to use the communication circuit 121 to transmit the generated specific CSR item data report to the website server 112 of the CSR data report service subsystem 110.

此時,網站伺服器112會進行流程714,以接收認證子系統120傳來的特定CSR項目數據報告。At this time, the web server 112 will perform a process 714 to receive the specific CSR project data report from the authentication subsystem 120.

接著,網站伺服器112會進行流程716,將認證子系統120產生的特定CSR項目數據報告提供給需求端裝置105。實作上,網站伺服器112可以將認證子系統120產生的特定CSR項目數據報告直接轉發給需求端裝置105。或者,網站伺服器112也可以將認證子系統120產生的特定CSR項目數據報告先進行加密後,再傳送給需求端裝置105,以提升特定CSR項目數據報告傳遞時的資料安全性。Next, the web server 112 will perform a process 716 to provide the specific CSR project data report generated by the authentication subsystem 120 to the demand-side device 105. In practice, the website server 112 can directly forward the specific CSR project data report generated by the authentication subsystem 120 to the demand-side device 105. Alternatively, the website server 112 may also encrypt the specific CSR project data report generated by the authentication subsystem 120 and then send it to the demand-side device 105 to improve the data security when the specific CSR project data report is delivered.

在流程718中,需求端裝置105會接收網站伺服器112傳來的特定CSR項目數據報告。如此一來,需求端裝置105的用戶便可藉由該特定CSR項目數據報告了解目標企業在一個或多個特定的企業社會責任面向上的投入情況,以藉此評估是否將目標企業納入選擇投資標的、或是評估是否要將目標企業納為供應鏈合作夥伴。In the process 718, the demand-side device 105 receives the specific CSR project data report from the website server 112. In this way, the user of the demand-side device 105 can use the specific CSR project data report to understand the target company’s investment in one or more specific CSR aspects, so as to assess whether the target company is included in the selected investment Target or evaluate whether the target enterprise should be included as a supply chain partner.

相仿地,倘若需求端裝置107的用戶想要查詢第二企業的特定CSR項目數據報告,也可以比照前述方式透過需求端裝置107傳送相關請求給CSR數據報告服務子系統110。CSR數據報告服務子系統110會透過企業端裝置103詢問第二企業是否同意CSR數據報告服務子系統110提供第二企業的相關特定CSR項目數據報告給需求端裝置107的用戶。在取得第二企業的同意之後,CSR數據報告服務子系統110可請求與第二認證機構相應的認證子系統130製作相關的特定CSR項目數據報告。接著,認證子系統130與區塊鏈子系統150可按照前述圖7的方法搭配運作,以產生與第二企業相應的特定CSR項目數據報告,並透過CSR數據報告服務子系統110傳送給需求端裝置107。Similarly, if the user of the demand-side device 107 wants to query the specific CSR project data report of the second company, the relevant request can also be sent to the CSR data-reporting service subsystem 110 through the demand-side device 107 as described above. The CSR data reporting service subsystem 110 will inquire through the enterprise-side device 103 whether the second company agrees to the CSR data reporting service subsystem 110 to provide the relevant specific CSR project data report of the second company to the user of the demand-side device 107. After obtaining the consent of the second enterprise, the CSR data reporting service subsystem 110 may request the certification subsystem 130 corresponding to the second certification body to make relevant CSR project data reports. Then, the authentication subsystem 130 and the blockchain subsystem 150 can operate in accordance with the method of FIG. 7 described above to generate a specific CSR project data report corresponding to the second enterprise, and send it to the demand-side device through the CSR data report service subsystem 110 107.

由前述說明可知,在接收到CSR數據報告服務子系統110傳來的報告製作請求後,相關的認證子系統會搭配區塊鏈子系統150自動產生相應的特定CSR項目數據報告,所以能夠大幅提升特定CSR項目數據報告的產生效率與正確性,並同時大幅減少所需的人力與時間,更能有效確保CSR數據報告服務子系統110提供給需求端裝置的特定CSR項目數據報告是未經竄改的版本。As can be seen from the foregoing description, after receiving the report creation request from the CSR data reporting service subsystem 110, the relevant certification subsystem will automatically generate the corresponding specific CSR project data report with the blockchain subsystem 150, so it can greatly improve the specific The generation efficiency and accuracy of the CSR project data report, while greatly reducing the manpower and time required, can more effectively ensure that the specific CSR project data report provided by the CSR data report service subsystem 110 to the demand-side device is an unaltered version .

如此一來,便能夠提升相關企業進行CSR資料認證的頻率,並吸引更多企業與認證機構參與CSR資料認證系統100的運作,以共同投入及推動CSR資料認證制度,進而擴大CSR揭露制度(CSR disclosure)的普及。In this way, it is possible to increase the frequency of CSR data certification by related companies, and to attract more companies and certification bodies to participate in the operation of the CSR data certification system 100 to jointly invest in and promote the CSR data certification system, thereby expanding the CSR disclosure system (CSR disclosure).

由於CSR數據報告服務子系統110能夠確保提供給需求端裝置的特定CSR項目數據報告是未經竄改的版本,所以各國的投資機構、供應鏈管理部門、或官方的金融監理單位,便得以根據CSR數據報告服務子系統110歷次提供的特定CSR項目數據報告來判斷目標企業是否真的在特定的企業社會責任面向上有長期且持續性的投入。Since the CSR data reporting service subsystem 110 can ensure that the specific CSR project data report provided to the demand-side device is not tampered with, the investment institutions, supply chain management departments, or official financial supervision units of various countries can be based on CSR The data report service subsystem 110 has provided specific CSR project data reports to determine whether the target company really has long-term and continuous investment in the specific corporate social responsibility.

請注意,在前述的CSR資料認證系統100中,產生特定CSR項目數據報告的主體是相關的認證子系統,但該認證子系統卻必須根基於區塊鏈子系統150提供的資料才能產生正確的特定CSR項目數據報告。Please note that in the aforementioned CSR data certification system 100, the main body generating the specific CSR project data report is the relevant certification subsystem, but the certification subsystem must be based on the information provided by the blockchain subsystem 150 to generate the correct specific CSR project data report.

以前述圖8中的認證後資料810為例,認證子系統120從區塊鏈子系統150中讀取出認證後資料810後,必須先從認證後資料810中擷取出資料庫索引814,再根據資料庫索引814查詢資料庫123,才能從資料庫123中讀取出相應的適格原始資料831。在沒有取得區塊鏈子系統150中所儲存的認證後資料810的情況下,認證子系統120的處理電路125便無法從資料庫123中讀取出正確的適格原始資料831。Taking the aforementioned post-authentication data 810 in FIG. 8 as an example, after the authentication subsystem 120 reads the post-authentication data 810 from the blockchain subsystem 150, it must first extract the database index 814 from the post-authentication data 810, and then The database index 814 queries the database 123 in order to read the corresponding qualified original data 831 from the database 123. Without obtaining the post-authentication data 810 stored in the blockchain subsystem 150, the processing circuit 125 of the authentication subsystem 120 cannot read the correct qualified original data 831 from the database 123.

因此,前述的特定CSR項目數據報告產生方法可有效避免企業串通委任的認證機構共同造假特定CSR項目數據報告的可能,能夠大幅提升CSR數據報告服務子系統110所提供的特定CSR項目數據報告的資料深度、資料詳細度、可信賴度、與公信力。Therefore, the aforementioned specific CSR project data report generation method can effectively avoid the possibility of colluding with the certification body appointed by the enterprise to jointly falsify the specific CSR project data report, and can greatly improve the specific CSR project data report information provided by the CSR data report service subsystem 110 Depth, detailed information, reliability, and credibility.

此外,在前述的CSR資料認證系統100中,來源企業的適格原始資料只會儲存於相應認證機構的認證子系統的資料庫中,所以任何認證機構在無權存取其他認證子系統的資料庫的情況下,都無法代替其他認證機構產生相關的特定CSR項目數據報告。In addition, in the aforementioned CSR data certification system 100, the qualified raw data of the source company will only be stored in the database of the certification subsystem of the corresponding certification body, so any certification body has no right to access the database of other certification subsystem Under the circumstances, it cannot replace other certification bodies to generate relevant CSR project data reports.

例如,假設前述第一企業的適格原始資料只會儲存於相應的第一認證機構的認證子系統120的資料庫123中,且屬於第二認證機構的認證子系統130無法存取認證子系統120的資料庫123。在此情況下,即使認證子系統130能夠從區塊鏈子系統150中讀取跟第一企業有關的多筆認證後資料,並從中擷取出多筆資料庫索引,由於認證子系統130無法取得資料庫123中的正確適格原始資料,因此也就無法產生與第一企業相應的特定CSR項目數據報告的詳細版本。換言之,前述的特定CSR項目數據報告產生方法可有效確保CSR數據報告服務子系統110所提供的特定CSR項目數據報告的權威性與公正性,並可降低不同的認證機構為了爭搶產生特定CSR項目數據報告的權力而出現惡性競爭的情況。For example, it is assumed that the aforementioned qualified raw data of the first enterprise will only be stored in the database 123 of the certification subsystem 120 of the corresponding first certification authority, and the certification subsystem 130 belonging to the second certification authority cannot access the certification subsystem 120 Of the database 123. In this case, even if the authentication subsystem 130 can read multiple pieces of post-authentication data related to the first enterprise from the blockchain subsystem 150 and extract multiple database indexes from it, the authentication subsystem 130 cannot obtain the data The correct and qualified original data in the library 123, so it is impossible to generate a detailed version of the specific CSR project data report corresponding to the first company. In other words, the aforementioned specific CSR project data report generation method can effectively ensure the authority and fairness of the specific CSR project data report provided by the CSR data report service subsystem 110, and can reduce the generation of specific CSR projects by different certification bodies in order to compete for The power of data reporting has led to vicious competition.

另一方面,當CSR數據報告服務子系統110為了因應突發性需要而傳送報告製作請求給相應的認證子系統時,該認證子系統都可搭配區塊鏈子系統150進行運作以即時產生最新的特定CSR項目數據報告,以反映出目標企業近期在一個或多個特定的企業社會責任面向上的最新表現。On the other hand, when the CSR data reporting service subsystem 110 transmits a report creation request to the corresponding authentication subsystem in response to the sudden need, the authentication subsystem can operate with the blockchain subsystem 150 to generate the latest Specific CSR project data report to reflect the latest performance of the target company in one or more specific CSR aspects.

再者,由於前述的CSR資料認證系統100允許資料需求者彈性設定所需要的特定CSR項目數據報告的資料時間範圍,所以相應認證子系統所產生的特定CSR項目數據報告的時間幅度能夠配合資料需求者的需要,而不再像傳統的CSR報告一樣只能侷限在以季節或年度為單位。因此,前述的特定CSR項目數據報告產生方法可大幅增加資料需求者的使用彈性與便利性,並讓各國的投資機構、供應鏈管理部門、或官方的金融監理單位,得以利用CSR資料認證系統100產生的特定CSR項目數據報告,來分析及比較不同的企業在某一段非制式化時間範圍內,在一個或多個特定的企業社會責任面向上的表現差異。Furthermore, since the aforementioned CSR data certification system 100 allows the data requester to flexibly set the required data time range of the specific CSR project data report, the time range of the specific CSR project data report generated by the corresponding certification subsystem can meet the data needs The needs of the authors are no longer limited to seasonal or annual units like traditional CSR reports. Therefore, the aforementioned specific CSR project data report generation method can greatly increase the flexibility and convenience of data demanders, and allow investment institutions, supply chain management departments, or official financial supervision units in various countries to use the CSR data certification system 100 Generate specific CSR project data reports to analyze and compare different companies' performance in one or more specific corporate social responsibility aspects within a certain period of non-standardized time.

請注意,前述各流程圖中的流程執行順序只是一示範性的實施例,並非侷限本發明的實際實施方式。例如,圖4中的流程404可以調整到流程402之前進行,也可以和流程402同時進行。又例如,圖6中的流程620可以調整到流程618之前進行,也可以和流程618同時進行。Please note that the execution sequence of the flowcharts in the foregoing flowcharts is only an exemplary embodiment, and does not limit the actual implementation of the present invention. For example, the process 404 in FIG. 4 can be adjusted before the process 402 or can be performed simultaneously with the process 402. For another example, the process 620 in FIG. 6 may be adjusted to be performed before the process 618, or may be performed simultaneously with the process 618.

在網站伺服器112無需詢問企業是否願意提供特定CSR項目數據報告給資料需求者的某些應用中,網站伺服器112在進行流程606之後,可以直接跳到流程618,以省略詢問目標企業是否同意CSR數據報告服務子系統110提供目標企業的相關特定CSR項目數據報告給資料需求者的相關流程。In some applications where the web server 112 does not need to ask whether the company is willing to provide specific CSR project data reports to data requesters, the web server 112 can directly jump to the process 618 after performing the process 606 to omit asking the target company whether to agree The CSR data reporting service subsystem 110 provides the relevant process of reporting data of the specific CSR project of the target enterprise to the data requester.

在實際應用中,資料需求者也可以不設定特別的資料時間範圍、和/或資料項目。在此情況下,相應的認證子系統在前述流程702中便可放寬從區塊鏈子系統150中搜尋認證後資料時的搜尋條件。In practical applications, the data requestor may not set a special data time range and/or data item. In this case, the corresponding authentication subsystem can relax the search conditions when searching the post-authentication data from the blockchain subsystem 150 in the foregoing process 702.

實作上,前述CSR資料認證系統100中的認證子系統的數量、企業端裝置的數量、以及需求端裝置的數量,都可依實際應用環境的需要而調整,並不侷限於前述實施例所繪示的態樣。In practice, the number of authentication subsystems, the number of enterprise-side devices, and the number of demand-side devices in the aforementioned CSR data authentication system 100 can be adjusted according to the needs of the actual application environment, and are not limited to those in the foregoing embodiments. The appearance shown.

在某些實施例中,可將前述CSR數據報告服務子系統110中的區塊鏈運算電路116省略,或是將區塊鏈運算電路116獨立於CSR數據報告服務子系統110之外。In some embodiments, the blockchain computing circuit 116 in the aforementioned CSR data reporting service subsystem 110 may be omitted, or the blockchain computing circuit 116 may be independent of the CSR data reporting service subsystem 110.

另外,在某些實施例中,可將前述認證子系統120中的區塊鏈運算電路124省略,或是將區塊鏈運算電路124獨立於認證子系統120之外。同樣地,在某些實施例中,可將前述認證子系統130中的區塊鏈運算電路134省略,或是將區塊鏈運算電路134獨立於認證子系統130之外。In addition, in some embodiments, the blockchain computing circuit 124 in the foregoing authentication subsystem 120 may be omitted, or the blockchain computing circuit 124 may be independent of the authentication subsystem 120. Similarly, in some embodiments, the blockchain computing circuit 134 in the foregoing authentication subsystem 130 may be omitted, or the blockchain computing circuit 134 may be independent of the authentication subsystem 130.

實作上,亦可將前述認證子系統120中的資料庫123獨立於認證子系統120之外。同樣地,亦可將前述認證子系統130中的資料庫133獨立於認證子系統130之外。In practice, the database 123 in the aforementioned authentication subsystem 120 can also be independent of the authentication subsystem 120. Similarly, the database 133 in the authentication subsystem 130 can be independent of the authentication subsystem 130.

在說明書及申請專利範圍中使用了某些詞彙來指稱特定的元件,而本領域內的技術人員可能會用不同的名詞來稱呼同樣的元件。本說明書及申請專利範圍並不以名稱的差異來作爲區分元件的方式,而是以元件在功能上的差異來作爲區分的基準。在說明書及申請專利範圍中所提及的「包含」爲開放式的用語,應解釋成「包含但不限定於」。另外,「耦接」一詞在此包含任何直接及間接的連接手段。因此,若文中描述第一元件耦接於第二元件,則代表第一元件可通過電性連接或無線傳輸、光學傳輸等信號連接方式而直接地連接於第二元件,或通過其它元件或連接手段間接地電性或信號連接至第二元件。Certain words are used in the specification and patent application scope to refer to specific elements, and those skilled in the art may use different terms to refer to the same element. This specification and the scope of patent application do not use the difference in names as a means of distinguishing elements, but the difference in function of elements as a basis for distinguishing. "Inclusion" mentioned in the description and the scope of patent application is an open term and should be interpreted as "including but not limited to." In addition, the term "coupled" here includes any direct and indirect connection means. Therefore, if it is described that the first element is coupled to the second element, it means that the first element can be directly connected to the second element through electrical connection, wireless transmission, optical transmission, or other signal connection, or through other elements or connections The means is indirectly electrically or signally connected to the second element.

在說明書中所使用的「和/或」的描述方式,包含所列舉的其中一個項目或多個項目的任意組合。另外,除非說明書中特別指明,否則任何單數格的用語都同時包含複數格的含義。The description method of "and/or" used in the specification includes any one of the listed items or any combination of multiple items. In addition, unless otherwise specified in the specification, any singular expressions also include the plural meaning.

權利要求書中的某些裝置權利要求中的流程特徵,與附圖及說明書的流程圖中的運作流程內容對應一致。因此,這些裝置權利要求,應當理解爲主要透過說明書記載的計算機程序實現前述解决方案的功能模組架構,而不應當理解爲主要通過硬件方式實現該解决方案的實體裝置。The flow features in certain device claims in the claims correspond to the operation flow contents in the flowcharts in the drawings and the description. Therefore, these device claims should be understood as the functional module architecture that mainly implements the foregoing solution through the computer program described in the specification, and should not be understood as the physical device that mainly implements the solution through hardware.

以上僅為本發明的較佳實施例,凡依本發明請求項所做的等效變化與修改,皆應屬本發明的涵蓋範圍。The above are only preferred embodiments of the present invention, and any equivalent changes and modifications made according to the claims of the present invention shall fall within the scope of the present invention.

100‧‧‧CSR資料認證系統(CSR data verification system)100‧‧‧CSR data verification system (CSR data verification system)

101~103‧‧‧企業端裝置(enterprise device)101~103‧‧‧enterprise device

105~107‧‧‧需求端裝置(requester device)105~107‧‧‧requester device

110‧‧‧CSR數據報告服務子系統(CSR data report service subsystem)110‧‧‧CSR data report service subsystem (CSR data report service subsystem)

112‧‧‧網站伺服器(web server)112‧‧‧Web server

114‧‧‧用戶關係資料庫(user relationship database)114‧‧‧ user relationship database

116‧‧‧區塊鏈運算電路(block chain computing circuit)116‧‧‧block chain computing circuit

120、130‧‧‧認證子系統(verification party subsystem)120、130‧‧‧verification party subsystem

121、131‧‧‧通信電路(communication circuit)121, 131‧‧‧ communication circuit (communication circuit)

122、132‧‧‧儲存電路(storage circuit)122, 132‧‧‧ storage circuit (storage circuit)

123、133‧‧‧資料庫(database)123, 133‧‧‧ database

124、134‧‧‧區塊鏈運算電路(block chain computing circuit)124,134‧‧‧block chain computing circuit (block chain computing circuit)

125、135‧‧‧處理電路(processing circuit)125、135‧‧‧processing circuit

126、136‧‧‧CSR資料認證程式(CSR data verification program)126、136‧‧‧CSR data verification program (CSR data verification program)

140‧‧‧區塊鏈節點叢集(block chain node cluster)140‧‧‧block chain node cluster

141~147‧‧‧區塊鏈節點(block chain node)141~147‧‧‧block chain node

150‧‧‧區塊鏈子系統(block chain subsystem)150‧‧‧block chain subsystem

210‧‧‧合約編輯模組(contract editing module)210‧‧‧contract editing module

220‧‧‧資料處理模組(data processing module)220‧‧‧Data processing module

230‧‧‧資料庫存取模組(database accessing module)230‧‧‧Database accessing module (database accessing module)

240‧‧‧去識別化模組(de-identification module)240‧‧‧de-identification module

250‧‧‧區塊鏈存取模組(block chain accessing module)250‧‧‧block chain access module

260‧‧‧報告產生模組(report generating module)260‧‧‧report generating module

302~320、402~414、602~622、702~718‧‧‧運作流程(operation)302~320, 402~414, 602~622, 702~718

510、831、833、835‧‧‧適格原始資料(valid raw data)510, 831, 833, 835‧‧‧‧ qualified raw data (valid raw data)

511~517‧‧‧資料欄位(data field)511~517‧‧‧ data field (data field)

520、814‧‧‧資料庫索引(database index)520, 814‧‧‧ database index (database index)

530、812‧‧‧去識別化資料(de-identification data)530, 812‧‧‧ de-identification data

540‧‧‧組合資料(combined data)540‧‧‧combined data

550、810‧‧‧認證後資料(verified data)550, 810‧‧‧ verified data (verified data)

816‧‧‧電子簽章(electronic signature)816‧‧‧Electronic signature (electronic signature)

840‧‧‧特定CSR項目數據報告(specific-CSR-category data report)840‧‧‧specific-CSR-category data report

圖1為本發明一實施例的CSR資料認證系統簡化後的功能方塊圖。FIG. 1 is a simplified functional block diagram of a CSR data authentication system according to an embodiment of the present invention.

圖2為圖1中的認證子系統內的電腦程式產品的一實施例簡化後的功能模組示意圖。FIG. 2 is a simplified functional module schematic diagram of an embodiment of the computer program product in the authentication subsystem in FIG. 1.

圖3與圖4為本發明一實施例的CSR資料認證方法簡化後的流程圖。3 and 4 are simplified flowcharts of a CSR data authentication method according to an embodiment of the invention.

圖5為在本發明一實施例的CSR資料認證過程中簡化後的資料流示意圖。FIG. 5 is a simplified data flow diagram in the CSR data authentication process according to an embodiment of the present invention.

圖6與圖7為本發明一實施例的特定CSR項目數據報告產生方法簡化後的流程圖。6 and 7 are simplified flowcharts of a specific CSR project data report generation method according to an embodiment of the invention.

圖8為在本發明一實施例的特定CSR項目數據報告產生過程中簡化後的資料流示意圖。FIG. 8 is a simplified data flow diagram during the process of generating a specific CSR project data report according to an embodiment of the present invention.

100‧‧‧CSR資料認證系統 100‧‧‧CSR data certification system

101~103‧‧‧企業端裝置 101~103‧‧‧Enterprise device

105~107‧‧‧需求端裝置 105~107‧‧‧demand device

110‧‧‧CSR數據報告服務子系統 110‧‧‧CSR Data Reporting Service Subsystem

112‧‧‧網站伺服器 112‧‧‧Web Server

114‧‧‧用戶關係資料庫 114‧‧‧User Relations Database

116‧‧‧區塊鏈運算電路 116‧‧‧Blockchain operation circuit

120、130‧‧‧認證子系統 120, 130‧‧‧ certification subsystem

121、131‧‧‧通信電路 121、131‧‧‧Communication circuit

122、132‧‧‧儲存電路 122, 132‧‧‧ storage circuit

123、133‧‧‧資料庫 123, 133‧‧‧ database

124、134‧‧‧區塊鏈運算電路 124, 134‧‧‧ Blockchain arithmetic circuit

125、135‧‧‧處理電路 125, 135‧‧‧ processing circuit

126、136‧‧‧CSR資料認證程式 126、136‧‧‧CSR data certification program

140‧‧‧區塊鏈節點叢集 140‧‧‧Blockchain node cluster

141~147‧‧‧區塊鏈節點 141~147‧‧‧Blockchain node

150‧‧‧區塊鏈子系統 150‧‧‧Blockchain subsystem

Claims (22)

一種CSR資料認證系統(100),包含: 一區塊鏈子系統(150); 一認證子系統(120),設置成可存取該區塊鏈子系統(150);以及 一CSR數據報告服務子系統(110),設置成可透過網路與一企業端裝置(101)以及該認證子系統(120)進行資料通信,並可在接收到該企業端裝置(101)所傳來一目標企業的CSR原始資料後,將該CSR原始資料傳送給該認證子系統(120); 其中,該認證子系統(120)還設置成執行一電腦程式產品(126)以進行以下運作: 從該CSR原始資料中篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫(123)中; 產生與該適格原始資料相應的資料庫索引; 去除該適格原始資料中的可識別資料,以產生去識別化資料;以及 將該去識別化資料及相應的該資料庫索引傳送至該區塊鏈子系統(150),並指示該區塊鏈子系統(150)執行一個或多個智能合約以認證該去識別化資料; 其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統(150)產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統(120)所對應的一認證機構的電子簽章。A CSR data authentication system (100), including: a blockchain subsystem (150); an authentication subsystem (120) configured to access the blockchain subsystem (150); and a CSR data reporting service subsystem (110), configured to communicate with an enterprise-side device (101) and the authentication subsystem (120) through the network, and can receive the CSR of a target enterprise from the enterprise-side device (101) After the original data, the CSR original data is sent to the certification subsystem (120); wherein, the certification subsystem (120) is also configured to execute a computer program product (126) to perform the following operations: From the CSR original data Filter out the eligible raw data that can be authenticated and store the qualified raw data in a database (123); generate a database index corresponding to the qualified raw data; remove the identifiable data from the qualified raw data to Generate de-identified data; and send the de-identified data and the corresponding database index to the blockchain subsystem (150), and instruct the blockchain subsystem (150) to execute one or more smart contracts for authentication The de-identified data; wherein, if the de-identified data conforms to the verification rules in the one or more smart contracts, the blockchain subsystem (150) generates and stores a post-authentication data, and the post-authentication data includes The de-identified data, the database index, and the electronic signature of a certification body corresponding to the certification subsystem (120). 如請求項1所述的CSR資料認證系統(100),其中,該認證子系統(120)還設置成執行該電腦程式產品(126)以進行以下運作: 建立並將該一個或多個智能合約佈署至該區塊鏈子系統(150),且該一個或多個智能合約的其中之一包含該電子簽章。The CSR data authentication system (100) according to claim 1, wherein the authentication subsystem (120) is further configured to execute the computer program product (126) to perform the following operations: establish and implement the one or more smart contracts Deployed to the blockchain subsystem (150), and one of the one or more smart contracts includes the electronic signature. 如請求項2所述的CSR資料認證系統(100),其中,倘若一需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告,該CSR數據報告服務子系統(110)會產生並傳送與該目標企業相應的一報告製作請求給該認證子系統(120),而該認證子系統(120)還設置成執行該電腦程式產品(126)以進行以下運作: 從該報告製作請求中取得一選定資料時間範圍; 從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內的多筆相關認證後資料; 從該多筆認證後資料中擷取出多筆資料庫索引; 根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及 根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給該需求端裝置(105)。The CSR data authentication system (100) according to claim 2, wherein, if a demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target enterprise, The CSR data reporting service subsystem (110) will generate and send a report making request corresponding to the target enterprise to the certification subsystem (120), and the certification subsystem (120) is also configured to execute the computer program product ( 126) To perform the following operations: Obtain a selected data time range from the report production request; Read multiple relevant post-authentication data of the target enterprise within the selected data time range from the blockchain subsystem (150) ; Retrieve multiple database indexes from the multiple post-certification data; query the database (123) according to the multiple database indexes to read the multiple records of the target enterprise from the database (123) Eligible raw data; and according to a predetermined report making rule, automatically convert the plurality of eligible raw materials into a specific CSR project data report corresponding to the target company, and pass the specific CSR project data report through the CSR data reporting service The subsystem (110) is transmitted to the demand-side device (105). 如請求項3所述的CSR資料認證系統(100),其中,該CSR數據報告服務子系統(110)在接收到該需求端裝置(105)的請求後,會傳送一詢問信息給該企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。The CSR data authentication system (100) according to claim 3, wherein, after receiving the request from the demand-side device (105), the CSR data report service subsystem (110) transmits an inquiry message to the enterprise Device (101) to ask whether the target enterprise agrees that the CSR data reporting service subsystem (110) provides relevant specific CSR project data reports to users of the demand-side device (105), and only after receiving the enterprise-side device (101) 101) In the case of a consent message, the CSR data report service subsystem (110) will only send the report creation request to the authentication subsystem (120). 如請求項2所述的CSR資料認證系統(100),其中,倘若一需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告,該CSR數據報告服務子系統(110)會產生並傳送與該目標企業相應的一報告製作請求給該認證子系統(120),而該認證子系統(120)還設置成執行該電腦程式產品(126)以進行以下運作: 從該報告製作請求中取得一選定資料時間範圍以及一個或多個選定資料項目; 從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內對應選定資料項目的多筆相關認證後資料; 從該多筆認證後資料中擷取出多筆資料庫索引; 根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及 根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給該需求端裝置(105)。The CSR data authentication system (100) according to claim 2, wherein, if a demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target enterprise, The CSR data reporting service subsystem (110) will generate and send a report making request corresponding to the target enterprise to the certification subsystem (120), and the certification subsystem (120) is also configured to execute the computer program product ( 126) To perform the following operations: obtain a selected data time range and one or more selected data items from the report production request; read out the target enterprise in the selected data time range from the blockchain subsystem (150) Multiple related post-authentication data corresponding to the selected data items within; extract multiple database indexes from the multiple post-authentication data; query the database (123) according to the multiple database indexes to retrieve data from the database ( 123) read out a number of eligible raw materials of the target company; and automatically convert the multiple qualified raw materials into a specific CSR project data report corresponding to the target company according to a predetermined report making rule, and convert The specific CSR project data report is transmitted to the demand-side device (105) through the CSR data report service subsystem (110). 如請求項5所述的CSR資料認證系統(100),其中,該CSR數據報告服務子系統(110)在接收到該需求端裝置(105)的請求後,會傳送一詢問信息給該企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。The CSR data authentication system (100) as described in claim 5, wherein the CSR data report service subsystem (110) transmits an inquiry message to the enterprise after receiving the request from the demand-side device (105) Device (101) to ask whether the target enterprise agrees that the CSR data reporting service subsystem (110) provides relevant specific CSR project data reports to users of the demand-side device (105), and only after receiving the enterprise-side device (101) 101) In the case of a consent message, the CSR data report service subsystem (110) will only send the report creation request to the authentication subsystem (120). 一種用於一CSR資料認證系統(100)中的認證子系統(120),其中,該CSR資料認證系統(100)包含一CSR數據報告服務子系統(110)以及一區塊鏈子系統(150),且該CSR數據報告服務子系統(110)在接收到一目標企業的CSR原始資料後,會將該CSR原始資料傳送給該認證子系統(120),該認證子系統(120)包含: 一通信電路(121),設置成可透過網路與該CSR數據報告服務子系統(110)以及該區塊鏈子系統(150)進行資料通信; 一儲存電路(122),用於儲存一電腦程式產品(126);以及 一處理電路(125),耦接於該通信電路(121)與該儲存電路(122); 其中,該處理電路(125)設置成執行該電腦程式產品(126)以進行以下運作: 從該CSR原始資料中篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫(123)中; 產生與該適格原始資料相應的資料庫索引; 去除該適格原始資料中的可識別資料,以產生去識別化資料;以及 利用該通信電路(121)將該去識別化資料及相應的該資料庫索引傳送至該區塊鏈子系統(150),並指示該區塊鏈子系統(150)執行一個或多個智能合約以認證該去識別化資料; 其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統(150)產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統(120)所對應的一認證機構的電子簽章。An authentication subsystem (120) used in a CSR data authentication system (100), wherein the CSR data authentication system (100) includes a CSR data reporting service subsystem (110) and a blockchain subsystem (150) , And after receiving the CSR original data of a target company, the CSR data reporting service subsystem (110) will send the CSR original data to the certification subsystem (120), the certification subsystem (120) includes: a The communication circuit (121) is configured to communicate with the CSR data reporting service subsystem (110) and the blockchain subsystem (150) through the network; a storage circuit (122) for storing a computer program product (126); and a processing circuit (125), coupled to the communication circuit (121) and the storage circuit (122); wherein, the processing circuit (125) is configured to execute the computer program product (126) to perform the following Operation: Select the qualified raw data for certification from the CSR raw data, and store the qualified raw data in a database (123); generate a database index corresponding to the qualified raw data; remove the qualified raw data Identifiable data in the data to generate de-identified data; and use the communication circuit (121) to transfer the de-identified data and the corresponding database index to the blockchain subsystem (150) and instruct the area The blockchain subsystem (150) executes one or more smart contracts to authenticate the de-identified data; where, if the de-identified data meets the verification rules in the one or more smart contracts, the blockchain subsystem (150) ) Generate and store a post-certification data, and the post-certification data includes the de-identified data, the database index, and the electronic signature of a certification body corresponding to the certification subsystem (120). 如請求項7所述的認證子系統(120),其中,該處理電路(125)還設置成執行該電腦程式產品(126)以進行以下運作: 建立並將該一個或多個智能合約佈署至該區塊鏈子系統(150),且該一個或多個智能合約的其中之一包含該電子簽章。The authentication subsystem (120) according to claim 7, wherein the processing circuit (125) is further configured to execute the computer program product (126) to perform the following operations: establish and deploy the one or more smart contracts To the blockchain subsystem (150), and one of the one or more smart contracts includes the electronic signature. 如請求項8所述的認證子系統(120),其中,倘若一需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告,該CSR數據報告服務子系統(110)會產生並傳送與該目標企業相應的一報告製作請求給該認證子系統(120),而該處理電路(125)還設置成執行該電腦程式產品(126)以進行以下運作: 從該報告製作請求中取得一選定資料時間範圍; 從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內的多筆相關認證後資料; 從該多筆認證後資料中擷取出多筆資料庫索引; 根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及 根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給該需求端裝置(105)。The authentication subsystem (120) according to claim 8, wherein if a demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target enterprise, the The CSR data report service subsystem (110) will generate and send a report making request corresponding to the target enterprise to the certification subsystem (120), and the processing circuit (125) is also set to execute the computer program product (126) To perform the following operations: Obtain a selected data time range from the report production request; read out multiple relevant post-authentication data of the target enterprise within the selected data time range from the blockchain subsystem (150); Extract multiple database indexes from the multiple post-certification data; query the database (123) according to the multiple database indexes to read out multiple qualified originals of the target enterprise from the database (123) Data; and according to a predetermined report production rule, automatically convert the plurality of eligible raw materials into a specific CSR project data report corresponding to the target enterprise, and pass the specific CSR project data report through the CSR data reporting service subsystem (110) Send to the demand-side device (105). 如請求項9所述的認證子系統(120),其中,該CSR數據報告服務子系統(110)在接收到該需求端裝置(105)的請求後,會傳送一詢問信息給對應於該目標企業的一企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。The authentication subsystem (120) according to claim 9, wherein, after receiving the request from the demand-side device (105), the CSR data reporting service subsystem (110) transmits an inquiry message to the target corresponding to the target An enterprise-side device (101) of the enterprise to ask whether the target enterprise agrees that the CSR data reporting service subsystem (110) provides relevant specific CSR project data reports to users of the demand-side device (105), and only after receiving In the case of a consent message from the enterprise device (101), the CSR data report service subsystem (110) will only send the report creation request to the authentication subsystem (120). 如請求項8所述的認證子系統(120),其中,倘若一需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告,該CSR數據報告服務子系統(110)會產生並傳送與該目標企業相應的一報告製作請求給該認證子系統(120),而該認證子系統(120)還設置成執行該電腦程式產品(126)以進行以下運作: 從該報告製作請求中取得一選定資料時間範圍以及一個或多個選定資料項目; 從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內對應選定資料項目的多筆相關認證後資料; 從該多筆認證後資料中擷取出多筆資料庫索引; 根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及 根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給該需求端裝置(105)。The authentication subsystem (120) according to claim 8, wherein if a demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target enterprise, the The CSR data reporting service subsystem (110) will generate and send a report making request corresponding to the target enterprise to the certification subsystem (120), and the certification subsystem (120) is also configured to execute the computer program product (126) ) To perform the following operations: obtain a selected data time range and one or more selected data items from the report production request; read out the target enterprise within the selected data time range from the blockchain subsystem (150) Multiple related post-certification data corresponding to the selected data item; extract multiple database indexes from the multiple post-certification data; query the database (123) according to the multiple database indexes to retrieve data from the database (123 ) Read out a number of eligible raw materials of the target company; and automatically convert the multiple qualified raw materials into a specific CSR project data report corresponding to the target company according to a predetermined report making rule, and convert the The specific CSR project data report is transmitted to the demand-side device (105) through the CSR data report service subsystem (110). 如請求項11所述的認證子系統(120),其中,該CSR數據報告服務子系統(110)在接收到該需求端裝置(105)的請求後,會傳送一詢問信息給對應於該目標企業的一企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。The authentication subsystem (120) according to claim 11, wherein, after receiving the request from the demand-side device (105), the CSR data reporting service subsystem (110) transmits an inquiry message to the corresponding target An enterprise-side device (101) of the enterprise to ask whether the target enterprise agrees that the CSR data reporting service subsystem (110) provides relevant specific CSR project data reports to users of the demand-side device (105), and only after receiving In the case of a consent message from the enterprise device (101), the CSR data report service subsystem (110) will only send the report creation request to the authentication subsystem (120). 一種電腦程式產品(126),儲存在一認證子系統(120)的一儲存電路(122)中,允許該認證子系統(120)進行一CSR認證運作,該CSR認證運作包含: 從該認證子系統(120)所接收到的一目標企業的CSR原始資料中,篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫(123)中; 產生與該適格原始資料相應的資料庫索引; 去除該適格原始資料中的可識別資料,以產生去識別化資料;以及 利用一通信電路(121)將該去識別化資料及相應的該資料庫索引傳送至一區塊鏈子系統(150),並指示該區塊鏈子系統(150)執行一個或多個智能合約以認證該去識別化資料; 其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統(150)產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統(120)所對應的一認證機構的電子簽章。A computer program product (126) stored in a storage circuit (122) of a certification subsystem (120), allowing the certification subsystem (120) to perform a CSR certification operation, the CSR certification operation including: from the certification sub From the CSR raw data of a target company received by the system (120), the qualified raw data that can be authenticated is filtered out, and the qualified raw data is stored in a database (123); generated corresponding to the qualified raw data Database index; remove the identifiable data from the qualified raw data to generate de-identified data; and use a communication circuit (121) to send the de-identified data and the corresponding database index to a blockchain System (150), and instruct the blockchain subsystem (150) to execute one or more smart contracts to authenticate the de-identified data; where, if the de-identified data conforms to the verification rules in the one or more smart contracts , The blockchain subsystem (150) generates and stores a post-authentication data, and the post-authentication data includes the de-identified data, the database index, and a certification authority corresponding to the authentication subsystem (120) Electronic signature. 如請求項13所述的電腦程式產品(126),其中,該CSR認證運作還包含: 建立並將該一個或多個智能合約佈署至該區塊鏈子系統(150),且該一個或多個智能合約的其中之一包含該電子簽章。The computer program product (126) according to claim 13, wherein the CSR certification operation further includes: establishing and deploying the one or more smart contracts to the blockchain subsystem (150), and the one or more One of the smart contracts contains the electronic signature. 如請求項14所述的電腦程式產品(126),其中,該CSR認證運作還包含: 從一CSR數據報告服務子系統(110)傳來與該目標企業相應的一報告製作請求中取得一選定資料時間範圍; 利用該通信電路(121)從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內的多筆相關認證後資料; 從該多筆認證後資料中擷取出多筆資料庫索引; 根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及 根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給一需求端裝置(105)。The computer program product (126) according to claim 14, wherein the CSR certification operation further includes: obtaining a selection from a report creation request transmitted from a CSR data reporting service subsystem (110) corresponding to the target enterprise Data time range; using the communication circuit (121) to read out from the blockchain subsystem (150) multiple pieces of relevant post-authentication data of the target enterprise within the selected data time range; from the multiple pieces of post-authentication data Retrieve multiple database indexes; query the database (123) according to the multiple database indexes to read out multiple qualified original data of the target enterprise from the database (123); and according to a predetermined The report production rules automatically convert the qualified raw data into a specific CSR project data report corresponding to the target enterprise, and send the specific CSR project data report to a demand through the CSR data report service subsystem (110) End device (105). 如請求項15所述的電腦程式產品(126),其中,當該需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告時,該CSR數據報告服務子系統(110)會傳送一詢問信息給對應於該目標企業的一企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。The computer program product (126) according to claim 15, wherein, when the demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target enterprise, The CSR data reporting service subsystem (110) sends an inquiry message to an enterprise device (101) corresponding to the target enterprise to inquire whether the target enterprise agrees that the CSR data reporting service subsystem (110) provides relevant specific The CSR project data is reported to the user of the demand-side device (105), and the CSR data report service subsystem (110) will only transmit it if it receives a consent message from the enterprise-side device (101) The report making request is sent to the authentication subsystem (120). 如請求項14所述的電腦程式產品(126),其中,該CSR認證運作還包含: 從一CSR數據報告服務子系統(110)傳來與該目標企業相應的一報告製作請求中取得一選定資料時間範圍以及一個或多個選定資料項目; 利用該通信電路(121)從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內對應選定資料項目的多筆相關認證後資料; 從該多筆認證後資料中擷取出多筆資料庫索引; 根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及 根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給一需求端裝置(105)。The computer program product (126) according to claim 14, wherein the CSR certification operation further includes: obtaining a selection from a report creation request transmitted from a CSR data reporting service subsystem (110) corresponding to the target enterprise Data time range and one or more selected data items; using the communication circuit (121) to read from the blockchain subsystem (150) the target company's multiple related items of the selected data item within the selected data time range Post-authentication data; extract multiple database indexes from the multiple post-authentication data; query the database (123) according to the multiple database indexes to read the target enterprise from the database (123) Multiple eligible raw materials; and according to a predetermined report production rule, automatically convert the multiple qualified raw materials into a specific CSR project data report corresponding to the target enterprise, and pass the specific CSR project data report through the CSR The data reporting service subsystem (110) is transmitted to a demand-side device (105). 如請求項17所述的電腦程式產品(126),其中,當該需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告時,該CSR數據報告服務子系統(110)會傳送一詢問信息給對應於該目標企業的一企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。The computer program product (126) according to claim 17, wherein, when the demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target enterprise, The CSR data reporting service subsystem (110) sends an inquiry message to an enterprise device (101) corresponding to the target enterprise to inquire whether the target enterprise agrees that the CSR data reporting service subsystem (110) provides relevant specific The CSR project data is reported to the user of the demand-side device (105), and the CSR data report service subsystem (110) will only transmit it if it receives a consent message from the enterprise-side device (101) The report making request is sent to the authentication subsystem (120). 一種CSR資料認證方法,包含: 從接收到的一目標企業的CSR原始資料中,篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫(123)中; 產生與該適格原始資料相應的資料庫索引; 去除該適格原始資料中的可識別資料,以產生去識別化資料;以及 利用一通信電路(121)將該去識別化資料及相應的該資料庫索引傳送至一區塊鏈子系統(150),並指示該區塊鏈子系統(150)執行一個或多個智能合約以認證該去識別化資料; 其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統(150)產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統(120)所對應的一認證機構的電子簽章。A CSR data authentication method, including: filtering out qualified raw data that can be certified from the received CSR raw data of a target company, and storing the qualified raw data in a database (123); generating and A database index corresponding to the eligible raw data; removing identifiable data from the eligible raw data to generate de-identified data; and using a communication circuit (121) to transmit the de-identified data and the corresponding database index to A blockchain subsystem (150), and instruct the blockchain subsystem (150) to execute one or more smart contracts to authenticate the de-identified data; wherein, if the de-identified data conforms to the one or more smart contracts In the verification rules in, the blockchain subsystem (150) generates and stores a post-authentication data, and the post-authentication data includes the de-identified data, the database index, and the corresponding of the authentication subsystem (120) 1. Electronic signature of certification body. 如請求項19所述的CSR資料認證方法,該CSR資料認證方法還包含: 建立並將該一個或多個智能合約佈署至該區塊鏈子系統(150),且該一個或多個智能合約的其中之一包含該電子簽章。The CSR data authentication method according to claim 19, further comprising: establishing and deploying the one or more smart contracts to the blockchain subsystem (150), and the one or more smart contracts One of them contains the electronic signature. 如請求項20所述的CSR資料認證方法,該CSR資料認證方法還包含: 從一CSR數據報告服務子系統(110)傳來與該目標企業相應的一報告製作請求中取得一選定資料時間範圍; 利用該通信電路(121)從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內的多筆相關認證後資料; 從該多筆認證後資料中擷取出多筆資料庫索引; 根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及 根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給一需求端裝置(105)。The CSR data authentication method as described in claim 20, the CSR data authentication method further includes: obtaining a selected data time range from a report production request transmitted from a CSR data reporting service subsystem (110) corresponding to the target enterprise Using the communication circuit (121) to read from the blockchain subsystem (150) multiple pieces of relevant post-authentication data of the target enterprise within the selected data time range; extracting multiple pieces of data from the multiple pieces of post-authentication data Pen database index; query the database (123) according to the multiple database indexes to read multiple qualified original data of the target enterprise from the database (123); and according to a predetermined report production rule , Automatically convert the qualified raw data into a specific CSR project data report corresponding to the target enterprise, and send the specific CSR project data report to a demand-side device through the CSR data report service subsystem (110) ( 105). 如請求項20所述的CSR資料認證方法,該CSR資料認證方法還包含: 從一CSR數據報告服務子系統(110)傳來與該目標企業相應的一報告製作請求中取得一選定資料時間範圍以及一個或多個選定資料項目; 利用該通信電路(121)從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內對應選定資料項目的多筆相關認證後資料; 從該多筆認證後資料中擷取出多筆資料庫索引; 根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及 根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給一需求端裝置(105)。The CSR data authentication method as described in claim 20, the CSR data authentication method further includes: obtaining a selected data time range from a report production request transmitted from a CSR data reporting service subsystem (110) corresponding to the target enterprise And one or more selected data items; the communication circuit (121) is used to read from the blockchain subsystem (150) a plurality of relevant post-certification data of the target enterprise corresponding to the selected data items within the selected data time range ; Retrieve multiple database indexes from the multiple post-certification data; query the database (123) according to the multiple database indexes to read the multiple records of the target enterprise from the database (123) Eligible raw data; and according to a predetermined report making rule, automatically convert the plurality of eligible raw materials into a specific CSR project data report corresponding to the target company, and pass the specific CSR project data report through the CSR data reporting service The subsystem (110) is transmitted to a demand-side device (105).
TW107125261A 2018-07-20 2018-07-20 Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method TWI698768B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW107125261A TWI698768B (en) 2018-07-20 2018-07-20 Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW107125261A TWI698768B (en) 2018-07-20 2018-07-20 Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method

Publications (2)

Publication Number Publication Date
TW202008202A true TW202008202A (en) 2020-02-16
TWI698768B TWI698768B (en) 2020-07-11

Family

ID=70413071

Family Applications (1)

Application Number Title Priority Date Filing Date
TW107125261A TWI698768B (en) 2018-07-20 2018-07-20 Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method

Country Status (1)

Country Link
TW (1) TWI698768B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112926085A (en) * 2021-03-05 2021-06-08 合肥都市链情商务有限公司 Database data storage and tamper-proof system and method based on block chain contract

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
SG115453A1 (en) * 2002-02-27 2005-10-28 Oneempower Pte Ltd Activity management method
TWI528217B (en) * 2014-07-02 2016-04-01 柯呈翰 A method and system for adding dynamic labels to a file and encrypting the file
TWM543422U (en) * 2016-12-09 2017-06-11 富邦產物保險股份有限公司 Decentralized insurance reward system

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112926085A (en) * 2021-03-05 2021-06-08 合肥都市链情商务有限公司 Database data storage and tamper-proof system and method based on block chain contract
CN112926085B (en) * 2021-03-05 2023-06-20 合肥都市链情商务有限公司 Database data storage and tamper-proof system and method based on blockchain contracts

Also Published As

Publication number Publication date
TWI698768B (en) 2020-07-11

Similar Documents

Publication Publication Date Title
US10705801B2 (en) Data processing systems for identity validation of data subject access requests and related methods
US20220019693A1 (en) Data processing systems for generating and populating a data inventory
Duy et al. A survey on opportunities and challenges of Blockchain technology adoption for revolutionary innovation
WO2022179008A1 (en) Supply chain finance ai daas algorithm warehouse platform based on blockchain
CN111526200A (en) Data storage access method and system based on block chain and cloud platform
CN111062690A (en) User purchase management system based on block chain technology
CN104363255A (en) Distributive patent service system
KR20230064354A (en) Blockchain-based authentication audit data sharing and integrity verification system, device and method thereof
CN110659976A (en) Enterprise technology service credit investigation system based on block chain and management method thereof
CN111506928A (en) Just information sharing system based on block chain
Handoko et al. UTAUT 2 model for predicting auditor's blockchain technology adoption
CN108985545B (en) Evaluation management system based on block chain
San et al. Blockchain-based learning credential verification system with recipient privacy control
Rustiana et al. Adoption computerized certificate transparency and confidentiality
KR20240020168A (en) Appratus and method for ESG management that facilitates response to internal and external ESG needs
Sargent Replacing financial audits with blockchain: the verification issue
US11222309B2 (en) Data processing systems for generating and populating a data inventory
CN112702410B (en) Evaluation system, method and related equipment based on blockchain network
TWI698768B (en) Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method
Zhou research on internal audit model of banking construction based on XBRL financial report
CN111522882A (en) Internal model management system and method based on block chain
Jacobs The importance of the quality of electronic records management in enhancing accountability in the South African public service: a case study of a national department
CN113709098B (en) Data transmission method and device
Yang et al. [Retracted] Framework Design of Science and Technology Venture Capital Salary Management System Driven by Blockchain Technology
Pakenaite et al. Investigation of the Blockchain’s influence on traditional banking: challenges and opportunities