TWI698768B - Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method - Google Patents

Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method Download PDF

Info

Publication number
TWI698768B
TWI698768B TW107125261A TW107125261A TWI698768B TW I698768 B TWI698768 B TW I698768B TW 107125261 A TW107125261 A TW 107125261A TW 107125261 A TW107125261 A TW 107125261A TW I698768 B TWI698768 B TW I698768B
Authority
TW
Taiwan
Prior art keywords
data
csr
subsystem
authentication
report
Prior art date
Application number
TW107125261A
Other languages
Chinese (zh)
Other versions
TW202008202A (en
Inventor
林庠序
林哲民
Original Assignee
林庠序
林哲民
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 林庠序, 林哲民 filed Critical 林庠序
Priority to TW107125261A priority Critical patent/TWI698768B/en
Publication of TW202008202A publication Critical patent/TW202008202A/en
Application granted granted Critical
Publication of TWI698768B publication Critical patent/TWI698768B/en

Links

Images

Landscapes

  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

A CSR data verification system, related verification party subsystem, computer program product, and CSR data verification method are disclosed. The method includes: utilizing a verification party subsystem to select valid raw data for verification out of CSR raw data of a source enterprise; generating database index corresponding to the valid raw data; generating de-identification data based on the valid raw data; and transmitting the de-identification data and database index into a block chain subsystem and instructing the block chain subsystem to execute smart contracts previously deployed by the verification party subsystem to verify the de- identification data; if the de-identification data satisfies the inspection rules of the smart contracts, the block chain subsystem generates and stores a verified data containing the de-identification data, the database index, and an electronic signature of a verification party corresponding to the verification party subsystem.

Description

具備防竄改能力的企業社會責任資料認證系統、相關的認證子系統、電腦程式產品、與資料認證方法 A corporate social responsibility data certification system with anti-tampering capabilities, related certification subsystems, computer program products, and data certification methods

本發明涉及資料認證技術,尤指一種具備防竄改能力的企業社會責任(Corporate Social Responsibility,CSR)資料認證系統、相關的認證子系統、電腦程式產品、與企業社會責任資料認證方法。 The invention relates to data authentication technology, in particular to a corporate social responsibility (Corporate Social Responsibility, CSR) data authentication system with tamper-proof capability, related authentication subsystems, computer program products, and a method for authentication of corporate social responsibility data.

經過聯合國多年來的推動,企業社會責任已成為全球關注的重要議題,越來越多的投資機構依循聯合國的「責任投資原則」(Principles for Responsible Investment,PRI),將企業在多個企業社會責任面向(例如,維護人權、保證勞工權益、發展永續與經濟、推動公司治理、持續創新等等)的表現,納入選擇投資標的時的重要考慮因素。另外,也有越來越多的公司或組織會檢視企業在企業社會責任方面的投入情況,以評估是否將其納入供應鏈的合作夥伴中。例如,許多政府單位、投資機構、與各種組織,都會檢視相關企業在環境、社會、公司治理(Environmental,Social,and Corporate Governance,ESG)等三大面向的表現,來做為衡量企業是否善盡企業社會責任的評估標準之一。因此,企業若不注重在各種企業社會責任方面的投入,不僅可能面臨政府相關法規的罰則,甚至會降低許多投資機構的投資意願、或是無法進入某些目標客戶的供應鏈。 After years of promotion by the United Nations, corporate social responsibility has become an important issue of global concern. More and more investment institutions are following the United Nations’ Principles for Responsible Investment (PRI) and placing companies on multiple corporate social responsibilities. Performance in terms of (for example, safeguarding human rights, guaranteeing labor rights, developing sustainability and economy, promoting corporate governance, continuous innovation, etc.) is an important consideration when selecting investment targets. In addition, more and more companies or organizations will review the company's investment in corporate social responsibility in order to assess whether to include it in the supply chain partners. For example, many government units, investment institutions, and various organizations will examine the performance of related companies in the three major aspects of environmental, social, and corporate governance (Environmental, Social, and Corporate Governance, ESG), as a measure of whether the company is doing well. One of the evaluation criteria of corporate social responsibility. Therefore, if companies do not pay attention to investment in various corporate social responsibilities, they may not only face penalties from relevant government regulations, but also reduce the willingness of many investment institutions to invest or cannot enter the supply chain of certain target customers.

傳統上,當企業想取得較高階的企業社會責任認證(Certificate in Corporate Social Responsibility)時,需要聘請具有公信力或取得國際認證資格的會計師事務所或是第三方認證機構,為企業提供的相關財務數據與行為紀錄資料(以下簡稱為企業社會責任資料,CSR data)進行查核及製作相關的企業社會責任報告(以下簡稱為CSR報告),以衡量或證明企業在各種企業社會責任面向上的投入程度。 Traditionally, when a company wants to obtain a higher-level corporate social responsibility certification (Certificate in Corporate Social Responsibility), it is necessary to hire an accounting firm with credibility or obtain international certification qualifications or a third-party certification body to provide the company with relevant financial data and behavioral record data (hereinafter referred to as corporate social responsibility data, CSR data). Check and make relevant corporate social responsibility reports (hereinafter referred to as CSR reports) to measure or prove the level of investment in various aspects of corporate social responsibility.

然而,傳統的CSR資料認證模式需要企業與認證機構雙方都投入可觀的人力查核各筆資料的正確性及合理性,所以需要耗費許多時間與費用才能完成。由於傳統模式在作業時間與成本上的缺點,導致企業進行CSR資料認證的頻率很低,通常是一季或一年才進行一次,所以產出的CSR報告經常難以反映出企業近期在各種企業社會責任面向的最新投入狀況。另一方面,傳統的CSR資料認證方式也無法因應突發性需要而即時產生最新的CSR報告。 However, the traditional CSR data certification model requires both the enterprise and the certification body to invest considerable manpower to verify the correctness and rationality of each data, so it takes a lot of time and cost to complete. Due to the shortcomings of the traditional model in operating time and cost, the frequency of CSR data certification by companies is very low, usually once a quarter or once a year, so the output CSR reports often hardly reflect the company’s recent corporate social responsibilities The latest investment status of the company. On the other hand, the traditional CSR data authentication method cannot immediately generate the latest CSR report in response to sudden needs.

有鑑於此,如何克服傳統企業社會責任資料認證方式的前述缺點,實為有待解決的問題。 In view of this, how to overcome the aforementioned shortcomings of traditional corporate social responsibility data authentication methods is a problem to be solved.

本說明書提供一種CSR資料認證系統的實施例,其包含:一區塊鏈子系統;一認證子系統,設置成可存取該區塊鏈子系統;以及一CSR數據報告服務子系統,設置成可透過網路與一企業端裝置以及該認證子系統進行資料通信,並可在接收到該企業端裝置所傳來一目標企業的CSR原始資料後,將該CSR原始資料傳送給該認證子系統;其中,該認證子系統還設置成執行一電腦程式產品以進行以下運作:從該CSR原始資料中篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及將該去識別化資料及相應的該資料庫索引傳送至該區塊鏈子系統,並指示該區塊鏈子系統執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個 智能合約中的查核規則,則該區塊鏈子系統產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統所對應的一認證機構的電子簽章。 This specification provides an embodiment of a CSR data authentication system, which includes: a blockchain subsystem; an authentication subsystem configured to access the blockchain subsystem; and a CSR data reporting service subsystem configured to be transparent The network communicates data with an enterprise-end device and the authentication subsystem, and can transmit the CSR original data to the authentication subsystem after receiving the original CSR data of a target enterprise from the enterprise-end device; wherein , The authentication subsystem is also set to execute a computer program product to perform the following operations: filter out the eligible original data for authentication from the CSR original data, and store the eligible original data in a database; The database index corresponding to the eligible original data; remove the identifiable data from the eligible original data to generate de-identified data; and send the de-identified data and the corresponding database index to the blockchain subsystem, and Instruct the blockchain subsystem to execute one or more smart contracts to authenticate the de-identified data; wherein, if the de-identified data meets the one or more According to the verification rules in the smart contract, the blockchain subsystem generates and stores a post-authentication data, and the post-authentication data includes the de-identification data, the database index, and the certificate of a certification body corresponding to the authentication subsystem Electronic signature.

本說明書另提供一種用於一CSR資料認證系統中的認證子系統的實施例。該CSR資料認證系統包含一CSR數據報告服務子系統以及一區塊鏈子系統,且該CSR數據報告服務子系統在接收到一目標企業的CSR原始資料後,會將該CSR原始資料傳送給該認證子系統。該認證子系統包含:一通信電路,設置成可透過網路與該CSR數據報告服務子系統以及該區塊鏈子系統進行資料通信;一儲存電路,用於儲存一電腦程式產品;以及一處理電路,耦接於該通信電路與該儲存電路;其中,該處理電路設置成執行該電腦程式產品以進行以下運作:從該CSR原始資料中篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及利用該通信電路將該去識別化資料及相應的該資料庫索引傳送至該區塊鏈子系統,並指示該區塊鏈子系統執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統所對應的一認證機構的電子簽章。 This specification also provides an embodiment of the authentication subsystem used in a CSR data authentication system. The CSR data certification system includes a CSR data reporting service subsystem and a blockchain subsystem. After the CSR data reporting service subsystem receives the original CSR data of a target company, it will send the original CSR data to the certification Subsystem. The authentication subsystem includes: a communication circuit configured to communicate with the CSR data reporting service subsystem and the blockchain subsystem through the network; a storage circuit for storing a computer program product; and a processing circuit , Coupled to the communication circuit and the storage circuit; wherein, the processing circuit is configured to execute the computer program product to perform the following operations: filter out the qualified original data for authentication from the CSR original data, and compare the qualified original data The data is stored in a database; the database index corresponding to the eligible original data is generated; the identifiable data in the eligible original data is removed to generate de-identified data; and the de-identified data and The corresponding database index is sent to the blockchain subsystem, and instructs the blockchain subsystem to execute one or more smart contracts to authenticate the de-identified data; wherein, if the de-identified data matches the one or more According to the verification rules in the smart contract, the blockchain subsystem generates and stores a post-authentication data, and the post-authentication data includes the de-identification data, the database index, and the certificate of a certification body corresponding to the authentication subsystem Electronic signature.

本說明書另提供一種電腦程式產品的實施例。該電腦程式產品儲存在一認證子系統的一儲存電路中,允許該認證子系統進行一CSR認證運作,該CSR認證運作包含:從該認證子系統所接收到的一目標企業的CSR原始資料中,篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及利用一通信電路將該去識別化資料及相應的該資料庫索 引傳送至一區塊鏈子系統,並指示該區塊鏈子系統執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統所對應的一認證機構的電子簽章。 This specification also provides an embodiment of a computer program product. The computer program product is stored in a storage circuit of a certification subsystem, allowing the certification subsystem to perform a CSR certification operation. The CSR certification operation includes: the CSR raw data of a target company received from the certification subsystem , Screen out the eligible raw data for authentication, and store the eligible raw data in a database; generate a database index corresponding to the eligible raw data; remove the identifiable data in the eligible raw data to generate Identifying data; and using a communication circuit to retrieve the de-identified data and the corresponding database Lead to a blockchain subsystem, and instruct the blockchain subsystem to execute one or more smart contracts to authenticate the de-identified data; wherein, if the de-identified data meets the verification in the one or more smart contracts Rule, the blockchain subsystem generates and stores a post-authentication data, and the post-authentication data includes the de-identification data, the database index, and the electronic signature of a certification authority corresponding to the authentication subsystem.

本說明書另提供一種CSR資料認證方法的實施例,其包含:從接收到的一目標企業的CSR原始資料中,篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及利用一通信電路將該去識別化資料及相應的該資料庫索引傳送至一區塊鏈子系統,並指示該區塊鏈子系統執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統所對應的一認證機構的電子簽章。 This specification also provides an embodiment of a CSR data authentication method, which includes: selecting eligible raw data for authentication from received CSR raw data of a target company, and storing the eligible raw data in a database In; generate a database index corresponding to the eligible original data; remove the identifiable data in the eligible original data to generate de-identified data; and use a communication circuit to generate the de-identified data and the corresponding database index Send to a blockchain subsystem, and instruct the blockchain subsystem to execute one or more smart contracts to authenticate the de-identified data; wherein, if the de-identified data meets the verification rules in the one or more smart contracts , The blockchain subsystem generates and stores a post-authentication data, and the post-authentication data includes the de-identification data, the database index, and the electronic signature of a certification authority corresponding to the authentication subsystem.

上述實施例的優點之一,是可大幅降低對企業的CSR資料進行認證所需的人力、時間、與成本,所以能夠提升企業進行CSR資料認證的頻率,並吸引更多企業與認證機構共同投入及推動CSR揭露制度。 One of the advantages of the above embodiment is that it can greatly reduce the manpower, time, and cost required to certify the CSR data of the company, so it can increase the frequency of CSR data certification for the company, and attract more companies and certification agencies to invest together And promote the CSR disclosure system.

上述實施例的另一優點,是能夠因應突發性需要而即時利用區塊鏈子系統來產生最新的特定CSR項目數據報告,以反映出企業近期在各種企業社會責任面向的最新投入狀況。 Another advantage of the above-mentioned embodiment is that the blockchain subsystem can be used to generate the latest specific CSR project data report in response to unexpected needs, so as to reflect the latest investment status of the company in various corporate social responsibility aspects.

上述實施例的另一優點,是企業的適格原始資料是在區塊鏈子系統中進行認證與儲存,所以能夠有效避免被有心人士竄改的風險。本發明的其他優點將搭配以下的說明和圖式進行更詳細的解說。 Another advantage of the above-mentioned embodiment is that the qualified original data of the enterprise is authenticated and stored in the blockchain subsystem, so it can effectively avoid the risk of tampering by interested parties. Other advantages of the present invention will be explained in more detail with the following description and drawings.

100:CSR資料認證系統(CSR data verification system) 100: CSR data verification system (CSR data verification system)

101~103:企業端裝置(enterprise device) 101~103: enterprise device (enterprise device)

105~107:需求端裝置(requester device) 105~107: requester device

110:CSR數據報告服務子系統(CSR data report service subsystem) 110: CSR data report service subsystem (CSR data report service subsystem)

112:網站伺服器(web server) 112: web server

114:用戶關係資料庫(user relationship database) 114: user relationship database

116:區塊鏈運算電路(block chain computing circuit) 116: block chain computing circuit

120、130:認證子系統(verification party subsystem) 120, 130: verification party subsystem

121、131:通信電路(communication circuit) 121, 131: communication circuit (communication circuit)

122、132:儲存電路(storage circuit) 122, 132: storage circuit (storage circuit)

123、133:資料庫(database) 123, 133: database (database)

124、134:區塊鏈運算電路(block chain computing circuit) 124, 134: block chain computing circuit

125、135:處理電路(processing circuit) 125, 135: processing circuit

126、136:CSR資料認證程式(CSR data verification program) 126, 136: CSR data verification program

140:區塊鏈節點叢集(block chain node cluster) 140: block chain node cluster

141~147:區塊鏈節點(block chain node) 141~147: block chain node

150:區塊鏈子系統(block chain subsystem) 150: block chain subsystem

210:合約編輯模組(contract editing module) 210: contract editing module

220:資料處理模組(data processing module) 220: data processing module

230:資料庫存取模組(database accessing module) 230: database accessing module

240:去識別化模組(de-identification module) 240: de-identification module

250:區塊鏈存取模組(block chain accessing module) 250: block chain accessing module

260:報告產生模組(report generating module) 260: report generating module

302~320、402~414、602~622、702~718:運作流程(operation) 302~320, 402~414, 602~622, 702~718: operation

510、831、833、835:適格原始資料(valid raw data) 510, 831, 833, 835: valid raw data

511~517:資料欄位(data field) 511~517: data field

520、814:資料庫索引(database index) 520, 814: database index

530、812:去識別化資料(de-identification data) 530, 812: de-identification data

540:組合資料(combined data) 540: combined data

550、810:認證後資料(verified data) 550, 810: verified data

816:電子簽章(electronic signature) 816: electronic signature

840:特定CSR項目數據報告(specific-CSR-category data report) 840: specific-CSR-category data report

圖1為本發明一實施例的CSR資料認證系統簡化後的功能方塊圖。 FIG. 1 is a simplified functional block diagram of a CSR data authentication system according to an embodiment of the present invention.

圖2為圖1中的認證子系統內的電腦程式產品的一實施例簡化後的功 能模組示意圖。 Figure 2 is a simplified function of an embodiment of the computer program product in the authentication subsystem in Figure 1 Schematic diagram of energy module.

圖3與圖4為本發明一實施例的CSR資料認證方法簡化後的流程圖。 3 and 4 are simplified flowcharts of the CSR data authentication method according to an embodiment of the present invention.

圖5為在本發明一實施例的CSR資料認證過程中簡化後的資料流示意圖。 FIG. 5 is a simplified data flow diagram in the CSR data authentication process of an embodiment of the present invention.

圖6與圖7為本發明一實施例的特定CSR項目數據報告產生方法簡化後的流程圖。 6 and 7 are simplified flowcharts of a method for generating a specific CSR project data report according to an embodiment of the present invention.

圖8為在本發明一實施例的特定CSR項目數據報告產生過程中簡化後的資料流示意圖。 FIG. 8 is a simplified data flow diagram in the process of generating a specific CSR project data report according to an embodiment of the present invention.

以下將配合相關圖式來說明本發明的實施例。在圖式中,相同的標號表示相同或類似的元件或方法流程。 The embodiments of the present invention will be described below in conjunction with related drawings. In the drawings, the same reference numerals indicate the same or similar elements or method flows.

圖1為本發明一實施例的企業社會責任資料認證系統(以下簡稱為CSR資料認證系統)100簡化後的功能方塊圖。CSR資料認證系統100用來對各企業所提供的CSR資料進行認證,並可依據需求者的請求產生相關的特定CSR項目數據報告。 1 is a simplified functional block diagram of a corporate social responsibility data authentication system (hereinafter referred to as a CSR data authentication system) 100 according to an embodiment of the present invention. The CSR data certification system 100 is used to certify the CSR data provided by various enterprises, and can generate related specific CSR project data reports according to the request of the demander.

CSR資料認證系統100包含一企業社會責任數據報告服務子系統(以下簡稱為CSR數據報告服務子系統)110、一個或多個認證子系統(例如,圖1中所繪示的示例性認證子系統120與130)、一區塊鏈節點叢集140、以及由區塊鏈節點叢集140搭配其他區塊鏈運算電路所共同形成的一區塊鏈子系統150。 The CSR data certification system 100 includes a corporate social responsibility data reporting service subsystem (hereinafter referred to as CSR data reporting service subsystem) 110, one or more certification subsystems (for example, the exemplary certification subsystem shown in FIG. 1 120 and 130), a block chain node cluster 140, and a block chain subsystem 150 formed by the block chain node cluster 140 and other block chain operation circuits.

CSR資料認證系統100中的多個認證子系統120~130,分別對應於不同的認證機構,例如,具有公信力的會計師事務所、和/或取得國際認證資格的第三方認證單位。例如,以下假設認證子系統120是對應於第一認證機構,而認證子系統130則是對應於第二認證機構。 實作上,認證子系統120~130可以用分別設置在各自對應的認證機構內部的電腦或伺服器等可聯網設備來實現。或者,認證子系統120~130也可以用設置在同一雲端平台上的不同虛擬機器來實現, 並由各自對應的認證機構的人員遠端操控。 The multiple certification subsystems 120 to 130 in the CSR data certification system 100 respectively correspond to different certification agencies, for example, credible accounting firms and/or third-party certification units that have obtained international certification qualifications. For example, it is assumed below that the authentication subsystem 120 corresponds to the first authentication agency, and the authentication subsystem 130 corresponds to the second authentication agency. In practice, the authentication subsystems 120 to 130 can be implemented with networkable devices such as computers or servers that are respectively installed in the corresponding authentication agencies. Or, the authentication subsystem 120~130 can also be implemented by different virtual machines set on the same cloud platform, And remotely controlled by the personnel of their respective certification agencies.

圖1中的標號101~103代表多個不同的企業端裝置,標號105~107則代表多個不同的需求端裝置。實作上,企業端裝置101~103通常是用各自企業內部的電腦或伺服器等可聯網設備來實現,需求端裝置105~107通常是利用各自資料需求者(例如,投資機構、企業或組織的供應鏈管理部門、或官方的金融監理單位等等)內部的電腦或伺服器等可聯網設備來實現。 The numbers 101 to 103 in FIG. 1 represent multiple different enterprise end devices, and the reference numbers 105 to 107 represent multiple different demand end devices. In practice, the enterprise-side devices 101~103 are usually implemented by their own internal computers or servers and other networkable devices, and the demand-side devices 105-107 are usually used by their respective data demanders (for example, investment institutions, enterprises or organizations). The supply chain management department of the company, or the official financial supervision unit, etc.) internal computers or servers can be connected to the Internet.

在運作時,不同的企業可透過各自的企業端裝置將各自的CSR原始資料傳送給CSR數據報告服務子系統110。CSR數據報告服務子系統110會將特定企業傳來的CSR原始資料,傳送給該特定企業所委任或是事先同意的特定認證機構所對應的認證子系統。 During operation, different enterprises can send their respective CSR raw data to the CSR data reporting service subsystem 110 through their respective enterprise end devices. The CSR data reporting service subsystem 110 transmits the original CSR data from a specific company to the certification subsystem corresponding to the specific certification body appointed by the specific company or agreed in advance.

接著,該認證子系統會搭配區塊鏈子系統150共同對企業的CSR原始資料進行認證,並將所產生的認證後資料儲存在區塊鏈子系統150中,以避免資料被竄改。 Then, the authentication subsystem will work with the blockchain subsystem 150 to jointly authenticate the original CSR data of the enterprise, and store the generated authentication data in the blockchain subsystem 150 to avoid data tampering.

之後,當有任何資料需求者需要查詢特定企業的CSR資料時,可透過相應的需求端裝置向CSR數據報告服務子系統110發送請求。此時,CSR數據報告服務子系統110可傳送一報告製作請求給相應的認證子系統,而該認證子系統可從區塊鏈子系統150中讀取相關的認證後資料後,產生該特定企業的特定CSR項目數據報告,並將產生的特定CSR項目數據報告透過CSR數據報告服務子系統110傳送給相應的需求端裝置。 After that, when any data demander needs to query the CSR data of a specific enterprise, the request can be sent to the CSR data reporting service subsystem 110 through the corresponding demand-side device. At this time, the CSR data reporting service subsystem 110 can send a report production request to the corresponding authentication subsystem, and the authentication subsystem can read the relevant post-authentication data from the blockchain subsystem 150 to generate the specific enterprise’s The specific CSR project data report, and the generated specific CSR project data report is transmitted to the corresponding demand-side device through the CSR data report service subsystem 110.

在圖1的實施例中,CSR數據報告服務子系統110包含一網站伺服器112、一用戶關係資料庫114、以及一區塊鏈運算電路116。認證子系統120包含一通信電路121、一儲存電路122、一資料庫123、一區塊鏈運算電路124、以及一處理電路125。認證子系統130包含一通信電路131、一儲存電路132、一資料庫133、一區塊鏈運算電路134、以及一處理電路135。區塊鏈節點叢集140包含有多個區塊鏈節點 (例如,圖1中所繪示的示例性區塊鏈節點141~147)。 In the embodiment of FIG. 1, the CSR data reporting service subsystem 110 includes a website server 112, a user relationship database 114, and a blockchain computing circuit 116. The authentication subsystem 120 includes a communication circuit 121, a storage circuit 122, a database 123, a blockchain operation circuit 124, and a processing circuit 125. The authentication subsystem 130 includes a communication circuit 131, a storage circuit 132, a database 133, a blockchain operation circuit 134, and a processing circuit 135. Blockchain node cluster 140 contains multiple blockchain nodes (For example, the exemplary blockchain nodes 141-147 shown in FIG. 1).

請注意,前述的CSR數據報告服務子系統110、認證子系統120、以及認證子系統130,在實際實施時皆可設置供用戶進行操控所需的人機介面裝置(例如,顯示器、鍵盤、滑鼠、觸控螢幕等),但為了簡化圖面內容起見,這些人機介面裝置並未繪示在圖1中。 Please note that the aforementioned CSR data reporting service subsystem 110, authentication subsystem 120, and authentication subsystem 130 can all be provided with human-machine interface devices (for example, displays, keyboards, slides, etc.) required for user control during actual implementation. Mouse, touch screen, etc.), but in order to simplify the content of the drawing, these man-machine interface devices are not shown in Figure 1.

本實施例中的區塊鏈子系統150,是由CSR數據報告服務子系統110中的區塊鏈運算電路116、認證子系統120中的區塊鏈運算電路124、認證子系統130中的區塊鏈運算電路134、以及區塊鏈節點叢集140中的多個區塊鏈節點141~147所共同組成。 The blockchain subsystem 150 in this embodiment is composed of the blockchain operation circuit 116 in the CSR data reporting service subsystem 110, the blockchain operation circuit 124 in the authentication subsystem 120, and the block in the authentication subsystem 130 The chain operation circuit 134 and a plurality of blockchain nodes 141 to 147 in the blockchain node cluster 140 are jointly composed.

在CSR數據報告服務子系統110中,網站伺服器112設置成可透過網際網路或其他網路,與前述的企業端裝置101~103、需求端裝置105~107、認證子系統120~130、以及區塊鏈子系統150進行資料通信。用戶關係資料庫114耦接於網站伺服器112,用來儲存多個企業與相關認證機構之間的對應關係,以供網站伺服器112查詢。區塊鏈運算電路116耦接於網站伺服器112,用於扮演區塊鏈子系統150的節點(node)之一,並可做為CSR數據報告服務子系統110與區塊鏈子系統150之間的溝通橋樑。 In the CSR data reporting service subsystem 110, the website server 112 is set up to communicate with the aforementioned enterprise-end devices 101~103, demand-end devices 105~107, authentication subsystems 120~130, And the blockchain subsystem 150 for data communication. The user relationship database 114 is coupled to the website server 112 and is used to store the corresponding relationships between multiple enterprises and related certification agencies for the website server 112 to query. The blockchain computing circuit 116 is coupled to the website server 112 and is used to act as one of the nodes of the blockchain subsystem 150, and can be used as a link between the CSR data reporting service subsystem 110 and the blockchain subsystem 150 Communication bridge.

在認證子系統120中,通信電路121設置成可透過網際網路或其他網路與CSR數據報告服務子系統110以及區塊鏈子系統150進行資料通信。儲存電路122設置成儲存一企業社會責任資料認證程式(以下簡稱為CSR資料認證程式)126。區塊鏈運算電路124耦接於通信電路121,用於扮演區塊鏈子系統150的節點之一,並可做為認證子系統120與區塊鏈子系統150之間的溝通橋樑。處理電路125耦接於通信電路121、儲存電路122、資料庫123、區塊鏈運算電路124,設置成控制前述裝置的運作,並可執行儲存電路122中的CSR資料認證程式126,以進行後續實施例中所揭露的CSR資料認證運作。 In the authentication subsystem 120, the communication circuit 121 is configured to communicate with the CSR data reporting service subsystem 110 and the blockchain subsystem 150 via the Internet or other networks. The storage circuit 122 is configured to store a corporate social responsibility data certification program (hereinafter referred to as a CSR data certification program) 126. The blockchain computing circuit 124 is coupled to the communication circuit 121 to act as one of the nodes of the blockchain subsystem 150 and can serve as a communication bridge between the authentication subsystem 120 and the blockchain subsystem 150. The processing circuit 125 is coupled to the communication circuit 121, the storage circuit 122, the database 123, and the blockchain operation circuit 124, and is configured to control the operation of the aforementioned devices, and can execute the CSR data authentication program 126 in the storage circuit 122 for subsequent follow-up The CSR data authentication operation disclosed in the embodiment.

在認證子系統130中,通信電路131設置成可透過網際網路或其他網 路與CSR數據報告服務子系統110以及區塊鏈子系統150進行資料通信。儲存電路132設置成儲存一CSR資料認證程式136。區塊鏈運算電路134耦接於通信電路131,用於扮演區塊鏈子系統150的節點之一,並可做為認證子系統130與區塊鏈子系統150之間的溝通橋樑。 處理電路135耦接於通信電路131、儲存電路132、資料庫133、區塊鏈運算電路134,設置成控制前述裝置的運作,並可執行儲存電路132中的CSR資料認證程式136,以進行後續實施例中所揭露的CSR資料認證運作。 In the authentication subsystem 130, the communication circuit 131 is set to be able to pass the Internet or other networks It communicates data with the CSR data reporting service subsystem 110 and the blockchain subsystem 150. The storage circuit 132 is configured to store a CSR data authentication program 136. The blockchain arithmetic circuit 134 is coupled to the communication circuit 131 to act as one of the nodes of the blockchain subsystem 150 and can serve as a communication bridge between the authentication subsystem 130 and the blockchain subsystem 150. The processing circuit 135 is coupled to the communication circuit 131, the storage circuit 132, the database 133, and the blockchain arithmetic circuit 134, and is configured to control the operation of the aforementioned devices, and can execute the CSR data authentication program 136 in the storage circuit 132 for follow-up The CSR data authentication operation disclosed in the embodiment.

實作上,網站伺服器112可以用單一伺服器來實現,也可以用位於相同地理區域、或是位於不同地理區域的多個伺服器組合來實現。 區塊鏈運算電路116、124、134、以及區塊鏈節點141~147,皆可用適合進行區塊鏈的共識決演算法(consensus algorithm)運算的一個或多個處理器模組或電腦來實現。通信電路121與131皆可利用符合相關網路通信、無線通信、或是行動通信規範的各種適當電路來實現,例如網路卡(Network Interface Card,NIC)、無線傳輸(Wi-Fi)電路、或是行動通信電路等等。儲存電路122與132皆可利用各種非揮發性儲存裝置來實現。處理電路125與126皆可利用具有適當運算能力的一個或多個處理器模組來實現。 In practice, the website server 112 can be implemented with a single server, or can be implemented with a combination of multiple servers located in the same geographic area or located in different geographic areas. Blockchain computing circuits 116, 124, 134, and blockchain nodes 141~147 can all be implemented by one or more processor modules or computers suitable for blockchain consensus algorithm operations . The communication circuits 121 and 131 can be implemented by various appropriate circuits that comply with relevant network communication, wireless communication, or mobile communication specifications, such as network interface cards (NIC), wireless transmission (Wi-Fi) circuits, Or mobile communication circuits and so on. Both the storage circuits 122 and 132 can be implemented by various non-volatile storage devices. Both the processing circuits 125 and 126 can be implemented by one or more processor modules with appropriate computing capabilities.

前述認證子系統120或130中的CSR資料認證程式126或136,皆可用一個或多個功能模組組成的電腦程式產品來實現。例如,圖2為圖1中的CSR資料認證程式126(或136)簡化後的功能模組示意圖。在圖2的實施例中,CSR資料認證程式126(或136)皆包含一合約編輯模組210、一資料處理模組220、一資料庫存取模組230、一去識別化模組240、一區塊鏈存取模組250、以及一報告產生模組260。 The CSR data certification program 126 or 136 in the aforementioned certification subsystem 120 or 130 can be implemented by a computer program product composed of one or more functional modules. For example, FIG. 2 is a simplified functional module diagram of the CSR data authentication program 126 (or 136) in FIG. 1. In the embodiment of FIG. 2, the CSR data authentication program 126 (or 136) all includes a contract editing module 210, a data processing module 220, a data storage acquisition module 230, a de-identification module 240, and a Block chain access module 250 and a report generation module 260.

以下將搭配圖3至圖4來進一步說明CSR資料認證系統100進行CSR資料認證的運作方式。圖3與圖4為本發明一實施例的CSR資料認證方法簡化後的流程圖。 Hereinafter, the operation method of the CSR data authentication system 100 for CSR data authentication will be further explained in conjunction with FIGS. 3 to 4. 3 and 4 are simplified flowcharts of the CSR data authentication method according to an embodiment of the present invention.

在圖3至圖4的流程圖中,位於一特定裝置所屬欄位中的流程,即代表由該特定裝置所進行的流程。例如,標記在「CSR數據報告服務子系統」欄位中的部分,是由CSR數據報告服務子系統110所進行的流程;標記在「認證子系統」欄位中的部分,是由認證子系統120~130的其中之一所進行的流程;標記在「區塊鏈子系統」欄位中的部分,則是由區塊鏈子系統150所進行的流程;其餘依此類推。 前述的邏輯也適用於後續的其他流程圖中。 In the flowcharts of FIGS. 3 to 4, the process in the column of a specific device represents the process performed by the specific device. For example, the part marked in the "CSR Data Reporting Service Subsystem" field is the process performed by the CSR Data Reporting Service Subsystem 110; the part marked in the "Authentication Subsystem" field is the process performed by the authentication subsystem The process performed by one of 120~130; the part marked in the "Blockchain Subsystem" column is the process performed by the Blockchain Subsystem 150; the rest can be deduced by analogy. The aforementioned logic is also applicable to other subsequent flowcharts.

當任一認證機構要參與CSR資料認證系統100的運作時,該認證機構內部的人員可利用相應的認證子系統搭配區塊鏈子系統150進行流程302~306,以在區塊鏈子系統150中佈署進行CSR資料認證所需的相關智能合約。 When any certification body wants to participate in the operation of the CSR data certification system 100, the personnel inside the certification body can use the corresponding certification subsystem with the blockchain subsystem 150 to perform the processes 302 to 306 to deploy in the blockchain subsystem 150 Relevant smart contracts required for CSR data certification.

例如,前述第一認證機構的人員可利用相應的認證子系統120進行流程302~304。在運作時,認證子系統120的處理電路125會執行儲存電路122中所儲存的CSR資料認證程式126,以進行圖3與圖4中的CSR資料認證方法。 For example, the personnel of the aforementioned first certification agency can use the corresponding certification subsystem 120 to perform the processes 302 to 304. During operation, the processing circuit 125 of the authentication subsystem 120 executes the CSR data authentication program 126 stored in the storage circuit 122 to perform the CSR data authentication method in FIGS. 3 and 4.

在流程302中,CSR資料認證程式126中的合約編輯模組210可控制處理電路125依據用戶的操控,編輯並建立包含第一認證機構設定的多項CSR資料查核規則的一個或多個智能合約,並且將第一認證機構的電子簽章附加在其中一個智能合約中,使得前述的智能合約的其中之一包含有第一認證機構的電子簽章。實作上,合約編輯模組210可允許第一認證機構的用戶根據所需要的CSR資料認證層級或標準,彈性調整前述智能合約中的CSR資料查核規則的數量及具體內容。 In the process 302, the contract editing module 210 in the CSR data verification program 126 can control the processing circuit 125 to edit and create one or more smart contracts that include multiple CSR data verification rules set by the first certification authority according to user manipulation. In addition, the electronic signature of the first certification authority is attached to one of the smart contracts, so that one of the aforementioned smart contracts includes the electronic signature of the first certification authority. In practice, the contract editing module 210 may allow the user of the first certification authority to flexibly adjust the number and specific content of the CSR data verification rules in the smart contract according to the required CSR data certification level or standard.

例如,合約編輯模組210可依據用戶的指示,將同一個認證層級或標準下的多個特定CSR項目的資料查核規則,整合在單一智能合約中。在此情況下,該單一智能合約可以用來查核多個特定CSR項目的資料。 For example, the contract editing module 210 can integrate the data checking rules of multiple specific CSR items under the same authentication level or standard into a single smart contract according to the user's instruction. In this case, the single smart contract can be used to check the data of multiple specific CSR projects.

又例如,合約編輯模組210可依據用戶的指示,將同一個認證層級或標準下的多個特定CSR項目的資料查核規則,分別配置在多個智能合約中。在此情況下,每一智能合約只能用來查核相應的單一特定CSR項目的資料。 For another example, the contract editing module 210 can configure the data checking rules of multiple specific CSR items under the same authentication level or standard into multiple smart contracts according to the instructions of the user. In this case, each smart contract can only be used to check the data of the corresponding single specific CSR project.

又例如,合約編輯模組210可依據用戶的指示,將不同認證層級或標準下的單一特定CSR項目的資料查核規則,分別配置在多個智能合約中。在此情況下,前述的多個智能合約都能用來查核該單一特定CSR項目的資料,但不同的智能合約中的查核規則所要求的數值門檻或判斷標準會有所不同。 For another example, the contract editing module 210 can configure the data checking rules of a single specific CSR project under different authentication levels or standards into multiple smart contracts according to the instructions of the user. In this case, the aforementioned multiple smart contracts can be used to check the data of the single specific CSR project, but the numerical thresholds or judgment standards required by the check rules in different smart contracts will be different.

在流程304中,CSR資料認證程式126中的區塊鏈存取模組250可控制處理電路125利用通信電路121,將已建立的一個或多個智能合約,以交易信息(transaction message)的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對第一認證機構建立的智能合約進行認證。 在運作時,區塊鏈存取模組250可控制處理電路125將已建立的一個或多個智能合約的原始碼編碼成對應的位元碼(bytecode),然後利用通信電路121將前述的位元碼以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對交易信息中的智能合約進行認證。 In the process 304, the blockchain access module 250 in the CSR data authentication program 126 can control the processing circuit 125 to use the communication circuit 121 to convert one or more smart contracts that have been established in the form of transaction messages. It is sent to the blockchain subsystem 150 and instructs the blockchain subsystem 150 to authenticate the smart contract established by the first authentication agency. In operation, the blockchain access module 250 can control the processing circuit 125 to encode the source code of the established one or more smart contracts into corresponding bytecodes, and then use the communication circuit 121 to convert the aforementioned bits The metacode is transmitted to the blockchain subsystem 150 in the form of transaction information, and instructs the blockchain subsystem 150 to authenticate the smart contract in the transaction information.

接著,區塊鏈子系統150會進行流程306,利用多個節點執行合適的共識決演算法來對第一認證機構建立的一個或多個智能合約進行認證。倘若第一認證機構建立的一個或多個智能合約通過區塊鏈子系統150的認證,區塊鏈子系統150便會將第一認證機構建立的一個或多個智能合約,以資料區塊的形式儲存在區塊鏈子系統150的區塊鏈帳本中,以完成將第一認證機構的相關智能合約佈署到區塊鏈子系統150中的程序。 Next, the blockchain subsystem 150 will proceed to the process 306 to use multiple nodes to execute an appropriate consensus decision algorithm to authenticate one or more smart contracts established by the first certification authority. If one or more smart contracts established by the first certification authority pass the certification of the blockchain subsystem 150, the blockchain subsystem 150 will store one or more smart contracts established by the first certification authority in the form of data blocks In the blockchain ledger of the blockchain subsystem 150, the procedure of deploying the relevant smart contract of the first certification authority to the blockchain subsystem 150 is completed.

在實際應用上,第一認證機構有可能受到許多使用CSR資料認證系統100的企業委託進行相關的CSR資料認證程序,但不同的企業所 需要進行的CSR資料認證層級可能會有所不同。例如,有些企業可能需要較高層級的CSR資料認證服務,但另外一些企業則可能只需要較低層級的CSR資料認證服務。因此,第一認證機構可按照前述方式,利用認證子系統120將分別對應於不同CSR資料認證層級的多組智能合約,佈署到區塊鏈子系統150中。 In practical applications, the first certification body may be commissioned by many companies that use the CSR data certification system 100 to carry out related CSR data certification procedures, but different companies The level of CSR data certification required may vary. For example, some companies may need higher-level CSR data certification services, but other companies may only need lower-level CSR data certification services. Therefore, the first certification authority can deploy multiple sets of smart contracts corresponding to different CSR data certification levels into the blockchain subsystem 150 by using the certification subsystem 120 in the aforementioned manner.

同樣地,前述第二認證機構的人員也可利用相應的認證子系統130進行流程302~304。在運作時,認證子系統130的處理電路135會執行儲存電路132中所儲存的CSR資料認證程式136,以進行圖3與圖4中的CSR資料認證方法。 Similarly, the personnel of the aforementioned second certification body can also use the corresponding certification subsystem 130 to perform the processes 302 to 304. During operation, the processing circuit 135 of the authentication subsystem 130 executes the CSR data authentication program 136 stored in the storage circuit 132 to perform the CSR data authentication method in FIGS. 3 and 4.

在流程302中,CSR資料認證程式136中的合約編輯模組210可控制處理電路135可依據用戶的操控,編輯並建立包含第二認證機構設定的多項CSR資料查核規則的一個或多個智能合約,並且將第二認證機構的電子簽章附加在其中一個智能合約中,使得前述的智能合約的其中之一包含有第二認證機構的電子簽章。同樣地,合約編輯模組210可允許第二認證機構的用戶根據所需要的CSR資料認證層級或標準,彈性調整前述智能合約中的CSR資料查核規則的數量及具體內容。 In the process 302, the contract editing module 210 in the CSR data verification program 136 can control the processing circuit 135 to edit and create one or more smart contracts that include multiple CSR data verification rules set by the second certification authority based on user control. , And attach the electronic signature of the second certification authority to one of the smart contracts, so that one of the aforementioned smart contracts includes the electronic signature of the second certification authority. Similarly, the contract editing module 210 can allow users of the second certification body to flexibly adjust the number and specific content of the CSR data verification rules in the smart contract according to the required CSR data certification level or standard.

在流程304中,CSR資料認證程式136中的區塊鏈存取模組250可控制處理電路135利用通信電路131將已建立的一個或多個智能合約以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對第二認證機構建立的智能合約進行認證。在運作時,區塊鏈存取模組250可控制處理電路135將已建立的一個或多個智能合約的原始碼編碼成對應的位元碼,然後利用通信電路131將前述的位元碼以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對交易信息中的智能合約進行認證。 In the process 304, the blockchain access module 250 in the CSR data authentication program 136 can control the processing circuit 135 to use the communication circuit 131 to send one or more smart contracts that have been established to the blockchain subsystem in the form of transaction information. 150, and instruct the blockchain subsystem 150 to authenticate the smart contract established by the second authentication agency. In operation, the blockchain access module 250 can control the processing circuit 135 to encode the source code of the established one or more smart contracts into corresponding bit codes, and then use the communication circuit 131 to convert the aforementioned bit codes to The form of the transaction information is transmitted to the blockchain subsystem 150, and the blockchain subsystem 150 is instructed to authenticate the smart contract in the transaction information.

接著,區塊鏈子系統150會進行流程306,利用多個節點執行合適的共識決演算法來對第二認證機構建立的一個或多個智能合約進行認 證。倘若第二認證機構建立的一個或多個智能合約通過區塊鏈子系統150的認證,區塊鏈子系統150便會將第二認證機構建立的一個或多個智能合約,以資料區塊的形式儲存在區塊鏈子系統150的區塊鏈帳本中,以完成將第二認證機構的相關智能合約佈署到區塊鏈子系統150中的程序。 Next, the blockchain subsystem 150 will proceed to the process 306, using multiple nodes to execute an appropriate consensus decision algorithm to recognize one or more smart contracts established by the second certification authority. certificate. If one or more smart contracts established by the second certification body pass the certification of the blockchain subsystem 150, the blockchain subsystem 150 will store one or more smart contracts created by the second certification body in the form of data blocks In the blockchain ledger of the blockchain subsystem 150, the procedure of deploying the relevant smart contract of the second certification authority to the blockchain subsystem 150 is completed.

在實際應用上,第二認證機構也有可能受到使用CSR資料認證系統100的多個企業委託進行相關的CSR資料認證程序,但這些的企業所需要進行的CSR資料認證層級可能會有所不同。因此,第二認證機構可按照前述方式,利用認證子系統130將分別對應於不同CSR資料認證層級的多組智能合約,佈署到區塊鏈子系統150中。 In practical applications, the second certification body may also be entrusted by multiple companies using the CSR data certification system 100 to carry out related CSR data certification procedures, but the level of CSR data certification required by these companies may be different. Therefore, the second certification authority can deploy multiple sets of smart contracts corresponding to different CSR data certification levels into the blockchain subsystem 150 by using the certification subsystem 130 in the aforementioned manner.

另外,在開始處理企業的CSR資料前,CSR數據報告服務子系統110也要先進行流程308。在流程308中,網站伺服器112可依據CSR數據報告服務子系統110的管理者的設定、或是接收企業端裝置和/或認證子系統傳來的設定資料,建立多個企業與相關認證機構之間的對應關係,並將前述的對應關係儲存在用戶關係資料庫114中。 In addition, before starting to process the CSR data of the enterprise, the CSR data reporting service subsystem 110 also needs to perform the process 308 first. In the process 308, the website server 112 can establish multiple enterprises and related certification agencies according to the settings of the administrator of the CSR data reporting service subsystem 110, or receive the configuration data from the enterprise device and/or authentication subsystem And store the aforementioned corresponding relationship in the user relationship database 114.

為了方便說明起見,以下將企業端裝置101所屬的企業稱為第一企業,將企業端裝置103所屬的企業稱為第二企業,並假設第一企業已經委任或同意委由認證子系統120所屬的第一認證機構為第一企業進行CSR資料認證,且假設第二企業已經委任或同意委由認證子系統130所屬的第二認證機構為第二企業進行CSR資料認證。在此情況下,網站伺服器112可於流程308中將第一企業與第一認證機構之間的對應關係,以及第二企業與第二認證機構之間的對應關係,儲存在用戶關係資料庫114中。 For the convenience of description, the company to which the enterprise device 101 belongs is referred to as the first company, and the company to which the enterprise device 103 belongs is referred to as the second company. It is assumed that the first company has appointed or agreed to entrust the authentication subsystem 120. The first certification body to which it belongs performs CSR data certification for the first company, and it is assumed that the second company has appointed or agreed to appoint the second certification body to which the certification subsystem 130 belongs to perform CSR data certification for the second company. In this case, the website server 112 may store the corresponding relationship between the first company and the first certification authority and the corresponding relationship between the second company and the second certification authority in the user relationship database in the process 308 114 in.

當任一企業想要利用CSR資料認證系統100為企業的CSR資料進行認證時,該企業(以下稱之為來源企業)內部的人員可利用相應的企業端裝置進行流程310,以提供來源企業的CSR原始資料(CSR raw data)給CSR數據報告服務子系統110。 When any company wants to use the CSR data certification system 100 to certify the company’s CSR data, the internal personnel of the company (hereinafter referred to as the source company) can use the corresponding enterprise device to perform the process 310 to provide the source company’s information The CSR raw data (CSR raw data) is provided to the CSR data reporting service subsystem 110.

例如,假設來源企業是前述的第一企業。在一實施例中,第一企業內部的用戶可定期或不定期操控企業端裝置101進行流程310以登入CSR數據報告服務子系統110的網站伺服器112,並在網站伺服器112所產生的相關網頁中輸入第一企業的CSR原始資料,使得企業端裝置101將第一企業的CSR原始資料透過網際網路傳送給網站伺服器112。在另一實施例中,企業端裝置101可執行預設的應用程式,定期或不定期從第一企業的資訊管理系統(management information system,MIS)、企業資源規劃系統(enterprise resource planning system,ERP system)、或由第一企業的人員所操作的前端應用系統中自動擷取第一企業的CSR原始資料,並自動透過網際網路傳送給網站伺服器112。 For example, suppose the source company is the aforementioned first company. In one embodiment, users within the first enterprise can periodically or irregularly control the enterprise-end device 101 to perform the process 310 to log in to the website server 112 of the CSR data reporting service subsystem 110, and the related information generated by the website server 112 The CSR raw data of the first company is input into the webpage, so that the enterprise-end device 101 transmits the CSR raw data of the first company to the website server 112 via the Internet. In another embodiment, the enterprise device 101 can execute a preset application program, periodically or irregularly from the first enterprise's management information system (MIS), enterprise resource planning system (ERP) system), or the front-end application system operated by the personnel of the first company automatically retrieves the original CSR data of the first company, and automatically transmits it to the website server 112 via the Internet.

同樣地,對應第二企業的企業端裝置103,也可以依據前述方式定期或不定期進行流程310,以將第二企業的CSR原始資料透過網際網路傳送給網站伺服器112。 Similarly, the enterprise-end device 103 corresponding to the second enterprise can also perform the process 310 regularly or irregularly according to the aforementioned method to send the CSR raw data of the second enterprise to the website server 112 via the Internet.

在流程312中,CSR數據報告服務子系統110的網站伺服器112會接收相應的企業端裝置所傳來的來源企業的CSR原始資料。 In the process 312, the website server 112 of the CSR data reporting service subsystem 110 receives the original CSR data of the source company from the corresponding enterprise device.

在流程314中,網站伺服器112會從用戶關係資料庫114中查詢來源企業所對應的認證機構。 In the process 314, the website server 112 queries the user relationship database 114 for the certification authority corresponding to the source enterprise.

在流程316中,網站伺服器112會將來源企業的CSR原始資料,傳送給相應認證機構的認證子系統。由前述說明可知,在本實施例中,倘若來源企業是第一企業,則相應的認證子系統是第一認證機構的認證子系統120,倘若來源企業是第二企業,則相應的認證子系統是第二認證機構的認證子系統130。 In the process 316, the website server 112 sends the original CSR data of the source company to the certification subsystem of the corresponding certification body. From the foregoing description, in this embodiment, if the source company is the first company, the corresponding certification subsystem is the certification subsystem 120 of the first certification body, and if the source company is the second company, the corresponding certification subsystem is It is the authentication subsystem 130 of the second authentication agency.

為了方面說明起見,以下假設前述的來源企業是第一企業。在此情況下,網站伺服器112會在流程316中將第一企業的CSR原始資料,傳送給相應的第一認證機構的認證子系統120。 For the sake of explanation, the following assumes that the aforementioned source company is the first company. In this case, the website server 112 will send the original CSR data of the first company to the certification subsystem 120 of the corresponding first certification body in the process 316.

實作上,網站伺服器112可在每次接收到一筆CSR原始資料後,就 立刻進行前述的流程316。或者,網站伺服器112也可以定期進行前述的流程316。又或者,網站伺服器112也可以等接收到的同一來源企業的CSR原始資料累積到一預定數量時,才進行前述的流程316。 In practice, the web server 112 can receive a piece of CSR raw data every time, The aforementioned process 316 is performed immediately. Alternatively, the website server 112 may also periodically perform the aforementioned process 316. Alternatively, the website server 112 may also wait for the received CSR original data of the same source company to accumulate a predetermined amount before performing the aforementioned process 316.

在流程318中,認證子系統120的通信電路121會接收網站伺服器112傳來的來源企業(在本例中為第一企業)的CSR原始資料。 In the process 318, the communication circuit 121 of the authentication subsystem 120 receives the original CSR data of the source enterprise (the first enterprise in this example) from the website server 112.

在流程320中,CSR資料認證程式126中的資料處理模組220可控制處理電路125,從來源企業的CSR原始資料中篩選出可供認證的適格原始資料(valid raw data)。實作上,可事先在資料處理模組220中根據合適的財務及會計稽核原則和/或CSR資料稽核原則,設置多項篩選規則(filter rules)。處理電路125在流程320中可根據資料處理模組220中的篩選規則,從來源企業的CSR原始資料中剔除掉不合理、不合邏輯、不完整、和/或數據前後不一致的資料項目,並將剩下來的資料項目做為來源企業的適格原始資料。 In the process 320, the data processing module 220 in the CSR data verification program 126 can control the processing circuit 125 to filter out valid raw data for verification from the CSR raw data of the source enterprise. In practice, multiple filter rules can be set in the data processing module 220 in advance according to appropriate financial and accounting audit principles and/or CSR data audit principles. In the process 320, the processing circuit 125 can eliminate unreasonable, illogical, incomplete, and/or inconsistent data items from the original CSR data of the source enterprise according to the filtering rules in the data processing module 220, and The remaining data items serve as the qualified original data of the source enterprise.

換言之,在認證子系統120接收到的來源企業的CSR原始資料中,只有能夠通過資料處理模組220的篩選規則的資料項目,才會被處理電路125選為來源企業的適格原始資料。 In other words, among the original CSR data of the source enterprise received by the authentication subsystem 120, only data items that can pass the screening rules of the data processing module 220 will be selected by the processing circuit 125 as the qualified original data of the source enterprise.

實作上,認證子系統120可在每次接收到一筆CSR原始資料後,就立刻進行前述的流程320。或者,認證子系統120也可以定期進行前述的流程320。又或者,認證子系統120也可以等接收到的CSR原始資料累積到一預定數量時,才進行前述的流程320。又或者,認證子系統120也可以在第一認證機構的相關人員下達指令時,進行前述的流程320。 In practice, the authentication subsystem 120 may immediately perform the aforementioned process 320 after receiving a piece of CSR original data. Alternatively, the authentication subsystem 120 may also perform the aforementioned process 320 periodically. Alternatively, the authentication subsystem 120 may also wait for the received CSR original data to accumulate to a predetermined amount before performing the aforementioned process 320. Alternatively, the authentication subsystem 120 may also perform the aforementioned process 320 when the relevant personnel of the first authentication agency issue an instruction.

之後,認證子系統120與區塊鏈子系統150會搭配進行CSR資料認證方法的後半部流程,亦即圖4中的流程402~414。 After that, the authentication subsystem 120 and the blockchain subsystem 150 will cooperate to perform the second half of the process of the CSR data authentication method, that is, the processes 402 to 414 in FIG. 4.

以下將搭配圖5來輔助說明認證子系統120與區塊鏈子系統150在流程402~414中的運作方式。圖5為在本發明一實施例的CSR資料認證過程中簡化後的資料流示意圖。 Hereinafter, FIG. 5 will be used to assist in explaining the operation mode of the authentication subsystem 120 and the blockchain subsystem 150 in the processes 402 to 414. FIG. 5 is a simplified data flow diagram in the CSR data authentication process of an embodiment of the present invention.

在流程402中,CSR資料認證程式126中的資料庫存取模組230可控制處理電路125,將每一筆適格原始資料儲存到資料庫123中,並產生與各筆適格原始資料相應的資料庫索引。前述的資料庫索引是可供用來查詢相應的適格原始資料在資料庫123中的儲存位置的索引資料。在運作時,資料庫存取模組230可以採用各種現有的資料庫所引產生方式,來產生前述的資料庫索引。 In the process 402, the database access module 230 in the CSR data authentication program 126 can control the processing circuit 125 to store each eligible original data in the database 123, and generate a database index corresponding to each eligible original data . The aforementioned database index is an index data that can be used to query the storage location of the corresponding eligible original data in the database 123. In operation, the database acquisition module 230 can use various existing database reference generation methods to generate the aforementioned database index.

為了便於理解,以下將以圖5中的適格原始資料510為例,來說明認證子系統120與區塊鏈子系統150在流程402~414中的運作方式。如圖5所示,適格原始資料510包含多個資料欄位511~517,其中,資料欄位511是公司名稱欄位(company name field)、資料欄位512是日期欄位(date field)、資料欄位513~515是多個通用資料欄位(common data field)、資料欄位516~517是多個姓名欄位(personnel name field)。在來源公司是前述第一企業的情況中,公司名稱欄位511中會記錄第一企業的名稱。 For ease of understanding, the following will take the qualified original data 510 in FIG. 5 as an example to illustrate the operation modes of the authentication subsystem 120 and the blockchain subsystem 150 in the processes 402 to 414. As shown in Figure 5, the eligible raw data 510 includes multiple data fields 511 to 517, where the data field 511 is a company name field, the data field 512 is a date field, The data fields 513 to 515 are multiple common data fields, and the data fields 516 to 517 are multiple name fields (personnel name fields). In the case where the source company is the aforementioned first company, the company name field 511 will record the name of the first company.

日期欄位512通常用來記錄來源企業進行或支持某項特定活動的日期,或是來源企業支付某項特定用途或特定會計科目的費用的日期。 通用資料欄位513~515可用來記錄來源企業進行或支持某項特定活動的相關資料。姓名欄位516~517可用來記錄來源企業進行或支持某項特定活動的相關參與人員的姓名。 The date field 512 is usually used to record the date when the source company performed or supported a specific activity, or the date when the source company paid for a specific purpose or a specific account. The general data fields 513 to 515 can be used to record the relevant data of the source company to carry out or support a specific activity. The name fields 516 to 517 can be used to record the names of the relevant participants of the source company that perform or support a specific activity.

例如,假設適格原始資料510是來源企業的員工執行某一次共乘行為的資料紀錄,則日期欄位512可用來記錄該次共乘行為的發生日期。通用資料欄位513~515可用來記錄該次共乘減碳活動的總里程數、起點位置、終點位置、車輛廠牌、車輛排氣量、車輛燃油種類、耗油量、共乘人數等等的相關紀錄。姓名欄位516~517可用來記錄參與該次共乘減碳活動的司機、乘客、發起人等有關人員的姓名。 For example, assuming that the eligible original data 510 is a data record of a certain ride-sharing behavior performed by an employee of the source enterprise, the date field 512 can be used to record the date of the ride-sharing behavior. The general data fields 513~515 can be used to record the total mileage, starting position, ending position, vehicle brand, vehicle displacement, vehicle fuel type, fuel consumption, number of passengers, etc. Related records. The name fields 516~517 can be used to record the names of the drivers, passengers, promoters and other relevant personnel participating in the carbon-sharing activity.

又例如,假設適格原始資料510是來源企業發起海岸淨灘活動的資料紀錄,則日期欄位512可用來記錄該次海岸淨灘活動的發生日期。 通用資料欄位513~515可用來記錄該次海岸淨灘活動的地點、清除的垃圾總重量、參與人數、交通費、餐飲費總支出費用等等的相關紀錄。姓名欄位516~517可用來記錄參與該次海岸淨灘活動的召集人、活動成員等有關人員的姓名。 For another example, assuming that the eligible raw data 510 is a data record of a source company’s coastal beach cleaning activity, the date field 512 can be used to record the date of occurrence of the coastal beach cleaning activity. The general data fields 513~515 can be used to record the location of this coastal beach cleaning activity, the total weight of garbage removed, the number of participants, transportation expenses, total catering expenses, etc. related records. The name fields 516~517 can be used to record the names of the conveners, event members and other relevant personnel who participated in the coastal beach cleaning activity.

又例如,假設適格原始資料510是來源企業舉辦社區義診活動的資料紀錄,則日期欄位512可用來記錄該次義診活動的發生日期。通用資料欄位513~515可用來記錄該次義診活動的地點、總受診人數、涵蓋鄉鎮數量、涵蓋地理面積、參與的醫療人員人數、交通費、餐飲費、醫療用品費用、總支出費用等等的相關紀錄。姓名欄位516~517可用來記錄參與該次義診活動的醫療人員、社區居民、受診居民、相關支援人員等有關人員的姓名。 For another example, assuming that the eligible original data 510 is a data record of a community free clinic activity held by the source company, the date field 512 can be used to record the date of the free clinic activity. The general data fields 513~515 can be used to record the location of the free clinic, the total number of patients, the number of towns and towns covered, the geographic area covered, the number of medical personnel involved, transportation, catering, medical supplies, total expenditures, etc. Related records. The name fields 516 to 517 can be used to record the names of medical personnel, community residents, residents who have been diagnosed, and related support personnel who participated in the free clinic.

又例如,假設適格原始資料510是來源企業辦理有關重視營業秘密的內部員工教育訓練的資料紀錄,則日期欄位512可用來記錄該次教育訓練的發生日期。通用資料欄位513~515可用來記錄該次教育訓練的地點、受訓人數、訓練課程時數、會議場地費、餐飲費、總支出費用等等的相關紀錄。姓名欄位516~517可用來記錄參與該次教育訓練活動的講師、人資部門人員、參與的學員、相關支援人員等有關人員的姓名。 For another example, suppose that the eligible original data 510 is a data record of the source company's internal employee education and training that emphasizes business secrets, and the date field 512 can be used to record the date of the education and training. The general data fields 513~515 can be used to record the relevant records of the location, number of trainees, training course hours, conference venue fees, catering expenses, total expenditures and so on. The name fields 516~517 can be used to record the names of the lecturers, personnel from the human resources department, participating students, and related support personnel who participated in the education and training activities.

在實際應用中,適格原始資料510的資料欄位數量、順序、以及各欄位的記錄內容,皆可依據實際需要而調整,而不侷限於前述的實施例。 In practical applications, the number and sequence of the data fields of the eligible original data 510, and the recorded content of each field can be adjusted according to actual needs, and is not limited to the foregoing embodiment.

在流程404中,CSR資料認證程式126中的去識別化模組240可控制處理電路125,去除適格原始資料中跟個人資料有關的可識別資料(identifiable data),以產生去識別化資料(de-identification data)。 實作上,哪些資料屬於應該被移除的可識別資料,可以由去識別化模組240自行判斷。或者,CSR資料認證系統100也可以預先定義用來記錄可識別資料的欄位位置,並通知相關的企業與認證機構根據 相關定義來填寫或判斷。 In the process 404, the de-identification module 240 in the CSR data authentication program 126 can control the processing circuit 125 to remove the identifiable data related to personal data from the qualified original data to generate de-identifiable data (de -identification data). In practice, which data belongs to the identifiable data that should be removed can be determined by the de-identification module 240 by itself. Alternatively, the CSR data certification system 100 can also predefine the field positions used to record identifiable data, and notify the relevant companies and certification bodies according to Fill in or judge related definitions.

在流程406中,CSR資料認證程式126中的區塊鏈存取模組250可控制處理電路125將來源企業的每一筆去識別化資料及相應的資料庫索引合併成一筆組合資料(combined data)。之後,區塊鏈存取模組250可控制處理電路125利用通信電路121,將一筆或多筆組合資料以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150執行與來源企業所需的CSR資料認證層級相應的一個或多個目標智能合約,以認證來源企業的去識別化資料。在運作時,區塊鏈存取模組250可控制處理電路125將一筆或多筆組合資料編碼成對應的位元碼,然後利用通信電路121將前述的位元碼以交易信息的形式傳送至區塊鏈子系統150,並指示區塊鏈子系統150對交易信息中的去識別化資料進行認證。 In the process 406, the blockchain access module 250 in the CSR data authentication program 126 can control the processing circuit 125 to merge each de-identified data of the source enterprise and the corresponding database index into a combined data. . After that, the blockchain access module 250 can control the processing circuit 125 to use the communication circuit 121 to transmit one or more combined data to the blockchain subsystem 150 in the form of transaction information, and instruct the blockchain subsystem 150 to execute and source One or more target smart contracts corresponding to the CSR data authentication level required by the enterprise to authenticate the de-identified data of the source enterprise. In operation, the blockchain access module 250 can control the processing circuit 125 to encode one or more combined data into corresponding bit codes, and then use the communication circuit 121 to transmit the aforementioned bit codes in the form of transaction information to The blockchain subsystem 150, and instructs the blockchain subsystem 150 to authenticate the de-identified data in the transaction information.

以圖5中的適格原始資料510為例,在前述的流程402中,資料庫存取模組230可控制處理電路125將適格原始資料510儲存到資料庫123中,並產生與適格原始資料510相應的資料庫索引520。如前所述,資料庫索引520是可供用來查詢適格原始資料510在資料庫123中的儲存位置的索引資料。 Taking the eligible raw data 510 in FIG. 5 as an example, in the aforementioned process 402, the data storage module 230 can control the processing circuit 125 to store the eligible raw data 510 in the database 123, and generate the data corresponding to the eligible raw data 510 The database index 520. As mentioned above, the database index 520 is index data that can be used to query the storage location of the eligible original data 510 in the database 123.

在流程404中,去識別化模組240可控制處理電路125去除適格原始資料510中跟個人資料有關的可識別資料,以產生不包含個人資料及無需被公開的公司費用支出細節等商業資料的去識別化資料530。 為了方便說明,以下假設在圖5的實施例中,只有資料欄位516~517的資料以及通用資料欄位513~515中的局部欄位的資料屬於可識別資料,因此,去識別化模組240可將適格原始資料510中跟人名有關的資料欄位516~517以及通用資料欄位513~515中的局部欄位移除,使得資料欄位516~517及部分通用資料欄位的資料不會出現在去識別化資料530中。 In the process 404, the de-identification module 240 can control the processing circuit 125 to remove the identifiable data related to the personal data in the eligible original data 510, so as to generate business data that does not contain personal data and company expense details that do not need to be disclosed. De-identification data 530. For the convenience of description, the following assumes that in the embodiment of FIG. 5, only the data in the data fields 516 to 517 and the data in the partial fields in the general data fields 513 to 515 are identifiable data. Therefore, the de-identification module 240 can remove the data fields 516~517 related to the person’s name in the eligible original data 510 and the partial fields in the general data fields 513~515, so that the data in the data fields 516~517 and some general data fields are not Will appear in the de-identified data 530.

在流程406中,區塊鏈存取模組250可控制處理電路125將去識別化 資料530及相應的資料庫索引520合併成一筆組合資料540。如圖5所示,組合資料540中包含去識別化資料530的內容、以及相應的資料庫索引520的內容。之後,區塊鏈存取模組250可控制處理電路125利用通信電路121,將組合資料540單獨(或是與其他組合資料一起)以交易信息的形式傳送至區塊鏈子系統150。 In the process 406, the blockchain access module 250 can control the processing circuit 125 to de-identify The data 530 and the corresponding database index 520 are combined into a combined data 540. As shown in FIG. 5, the combined data 540 includes the content of the de-identified data 530 and the content of the corresponding database index 520. After that, the blockchain access module 250 can control the processing circuit 125 to use the communication circuit 121 to transmit the combined data 540 alone (or together with other combined data) to the blockchain subsystem 150 in the form of transaction information.

從前述說明可知,認證子系統120傳送給區塊鏈子系統150的去識別化資料,是適格原始資料的簡化版本,所以可以做為後續CSR資料認證的基礎。相較於適格原始資料,去識別化資料中不包含跟私人資料有關的個人信息。因此,認證子系統120將去識別化資料傳送到區塊鏈子系統150進行查核,並不會外洩來源企業的內部員工或相關人員的個人資料,因此不會導致個資外洩的疑慮。 From the foregoing description, it can be seen that the de-identified data sent by the authentication subsystem 120 to the blockchain subsystem 150 is a simplified version of the eligible original data, so it can be used as the basis for subsequent CSR data authentication. Compared with qualified original data, the de-identified data does not contain personal information related to private data. Therefore, the authentication subsystem 120 transmits the de-identified data to the blockchain subsystem 150 for verification, and the personal data of internal employees or related personnel of the source enterprise will not be leaked, and therefore, no personal information leakage will be caused.

實作上,認證子系統120進行前述的流程402~406的時機,可以依據需要而有多種不同的選擇。 In practice, the timing for the authentication subsystem 120 to perform the aforementioned processes 402 to 406 can have a variety of different options according to needs.

例如,認證子系統120可在每次產生一筆適格原始資料後,就立刻進行前述的流程402~406。 For example, the authentication subsystem 120 may immediately perform the aforementioned processes 402-406 after generating a piece of eligible original data.

或者,認證子系統120可定期進行前述的流程402~406。 Alternatively, the authentication subsystem 120 may periodically perform the aforementioned processes 402-406.

又或者,認證子系統120可等到適格原始資料累積到一預定數量時,才進行前述的流程402~406。 Alternatively, the authentication subsystem 120 may wait until the qualified original data has accumulated to a predetermined amount before performing the aforementioned processes 402-406.

又或者,認證子系統120可定期進行前述的流程402~404,但可等到同一來源企業的去識別化資料與相應的資料庫所引累積到一預定數量時,才進行前述的流程406。 Alternatively, the authentication subsystem 120 can periodically perform the aforementioned processes 402 to 404, but can wait until the de-identified data of the same source enterprise and the corresponding database references have accumulated to a predetermined amount before performing the aforementioned process 406.

又或者,認證子系統120可在每次產生一筆適格原始資料後,就立刻進行前述的流程402~404,但可等到預定的時間點才定期進行前述的流程406。 Alternatively, the authentication subsystem 120 may immediately perform the foregoing processes 402 to 404 after generating a piece of eligible original data, but may wait until a predetermined time point to periodically perform the foregoing process 406.

又或者,認證子系統120可在每次產生一筆適格原始資料後,就立刻進行前述的流程402~404,但可等到同一來源企業的去識別化資料與相應的資料庫所引累積到一預定數量時,才進行前述的流程 406。 Or, the authentication subsystem 120 may immediately perform the aforementioned processes 402 to 404 after generating a piece of eligible original data, but it may wait until the de-identified data of the same source company and the corresponding database reference are accumulated to a predetermined The aforementioned process is carried out only when the quantity is 406.

在流程408中,區塊鏈子系統150中的多個節點會共同執行認證子系統120指定的一個或多個目標智能合約,以對認證子系統120傳來的組合資料中的每一筆去識別化資料的內容逐一進行查核。 In the process 408, multiple nodes in the blockchain subsystem 150 will jointly execute one or more target smart contracts specified by the authentication subsystem 120 to de-identify each piece of the combined data from the authentication subsystem 120 Check the contents of the data one by one.

如前所述,認證子系統120預先佈署在區塊鏈子系統150中的一個或多個目標智能合約,包含有第一認證機構所設定的多項CSR資料查核規則,且前述的目標智能合約的其中之一包含有第一認證機構的電子簽章。區塊鏈子系統150在流程408中會將每一筆去識別化資料與目標智能合約中的多項CSR資料查核規則進行比對,以查核該筆去識別化資料是否滿足相應的CSR資料查核規則。 As mentioned above, the authentication subsystem 120 pre-deploys one or more target smart contracts in the blockchain subsystem 150, including multiple CSR data verification rules set by the first authentication agency, and the aforementioned target smart contracts One of them contains the electronic signature of the first certification body. In the process 408, the blockchain subsystem 150 compares each de-identified data with multiple CSR data check rules in the target smart contract to check whether the de-identified data meets the corresponding CSR data check rules.

在流程410中,區塊鏈子系統150會捨棄無法通過目標智能合約查核的去識別化資料,並傳送一認證失敗通知給認證子系統120。當認證子系統120在流程410中接收到區塊鏈子系統150傳來的認證失敗通知時,資料處理模組220便可控制處理電路125產生相關的提示信息,以便認證子系統120的用戶可以得知相關的結果。 In the process 410, the blockchain subsystem 150 discards the de-identified data that cannot be checked by the target smart contract, and sends an authentication failure notification to the authentication subsystem 120. When the authentication subsystem 120 receives the authentication failure notification from the blockchain subsystem 150 in the process 410, the data processing module 220 can control the processing circuit 125 to generate relevant prompt information so that the user of the authentication subsystem 120 can obtain Know the relevant results.

在流程412中,區塊鏈子系統150可從前述的一個或多個目標智能合約中擷取出第一認證機構的電子簽章,並將通過查核的去識別化資料,連同相應的資料庫索引以及第一認證機構的電子簽章一起打包,以產生包含來源企業的去識別化資料、相應的資料庫索引、以及第一認證機構的電子簽章的認證後資料(verified data)。 In the process 412, the blockchain subsystem 150 can extract the electronic signature of the first certification authority from the aforementioned one or more target smart contracts, and will pass the de-identified data through the verification together with the corresponding database index and The electronic signature of the first certification body is packaged together to generate verified data containing the de-identified data of the source enterprise, the corresponding database index, and the electronic signature of the first certification body.

在流程414中,區塊鏈子系統150會將認證後資料以資料區塊的形式儲存在區塊鏈子系統150中進行保存。 In the process 414, the blockchain subsystem 150 stores the authenticated data in the blockchain subsystem 150 for preservation in the form of data blocks.

來源企業的每一筆適格原始資料經過前述流程320、402、404、404、406、408、412、與414的處理後,便可完成相應認證層級的CSR資料認證程序。 After each qualified original data of the source company is processed by the aforementioned processes 320, 402, 404, 404, 406, 408, 412, and 414, the CSR data certification process of the corresponding certification level can be completed.

之後,區塊鏈子系統150中的每個節點都能夠在需要的時候,讀取保存在區塊鏈子系統150中的認證後資料進行查閱或進一步分析。 After that, each node in the blockchain subsystem 150 can read the post-authentication data stored in the blockchain subsystem 150 for reference or further analysis when needed.

以前述圖5中的組合資料540為例,區塊鏈子系統150在流程408中會將組合資料540中的去識別化資料530,與目標智能合約中的多項CSR資料查核規則進行比對,以查核去識別化資料530是否滿足相應的CSR資料查核規則。 Taking the combined data 540 in FIG. 5 as an example, the blockchain subsystem 150 compares the de-identified data 530 in the combined data 540 with the multiple CSR data check rules in the target smart contract in the process 408 to Check whether the de-identified data 530 meets the corresponding CSR data verification rules.

倘若去識別化資料530不符合目標智能合約中的CSR資料查核規則,則區塊鏈子系統150會捨棄組合資料540並通知認證子系統120。 If the de-identified data 530 does not comply with the CSR data checking rules in the target smart contract, the blockchain subsystem 150 will discard the combined data 540 and notify the authentication subsystem 120.

反之,倘若去識別化資料530符合目標智能合約中的CSR資料查核規則,則區塊鏈子系統150可在流程412中將通過查核的去識別化資料530,連同相應的資料庫索引520以及第一認證機構的電子簽章一起打包,以產生一認證後資料550,使得認證後資料550中會包含去識別化資料530的內容、資料庫索引520的內容、以及認證子系統120所屬的第一認證機構的電子簽章,如圖5所示。 Conversely, if the de-identified data 530 meets the CSR data check rules in the target smart contract, the blockchain subsystem 150 can combine the de-identified data 530 that has passed the check in the process 412, together with the corresponding database index 520 and the first The electronic signatures of the certification body are packaged together to generate a post-authentication data 550, so that the post-authentication data 550 will contain the content of the de-identified data 530, the content of the database index 520, and the first certification to which the authentication subsystem 120 belongs The electronic signature of the organization is shown in Figure 5.

接著,區塊鏈子系統150會進行流程414,將認證後資料550以資料區塊的形式寫入區塊鏈子系統150中進行保存。 Then, the blockchain subsystem 150 will perform the process 414 to write the authenticated data 550 in the form of data blocks into the blockchain subsystem 150 for storage.

如圖5所示,來源企業的適格原始資料510經過前述流程320、402、404、404、406、408、412、與414的處理後,便可完成相應認證層級的CSR資料認證程序,並使得與適格原始資料510相應的認證後資料550被保存在區塊鏈子系統150中。如此一來,任何有權限從區塊鏈子系統150中讀取認證後資料550的人,都可依據認證後資料550中的電子簽章,清楚得知認證後資料550中所包含的去識別化資料530已順利通過第一認證機構所佈署的智能合約的查核程序。從另一角度而言,這代表認證後資料550中的去識別化資料530已順利通過第一認證機構的CSR資料認證程序。 As shown in Figure 5, after the qualified original data 510 of the source company has been processed by the aforementioned processes 320, 402, 404, 404, 406, 408, 412, and 414, the CSR data certification process of the corresponding certification level can be completed, and The post-authentication data 550 corresponding to the eligible original data 510 is stored in the blockchain subsystem 150. In this way, anyone who has the authority to read the post-authentication data 550 from the blockchain subsystem 150 can clearly know the de-identification contained in the post-authentication data 550 based on the electronic signature in the post-authentication data 550 Data 530 has successfully passed the verification procedure of the smart contract deployed by the first certification body. From another perspective, this means that the de-identified data 530 in the post-authentication data 550 has successfully passed the CSR data certification procedure of the first certification body.

相仿地,前述的第二企業亦可比照前述方式將CSR原始資料傳送給CSR數據報告服務子系統110,再由CSR數據報告服務子系統110轉送給由第二認證機構操作的認證子系統130進行處理。認證子系統130與區塊鏈子系統150可按照前述圖3與圖4的方法搭配運作,以對 第二企業所提供的CSR原始資料進行相關的CSR資料認證程序。 Similarly, the aforementioned second enterprise can also send the CSR original data to the CSR data reporting service subsystem 110 in the aforementioned manner, and then the CSR data reporting service subsystem 110 will forward it to the certification subsystem 130 operated by the second certification body. deal with. The authentication subsystem 130 and the blockchain subsystem 150 can work together according to the method of FIG. 3 and FIG. The CSR original data provided by the second company undergoes relevant CSR data certification procedures.

由前述說明可知,圖3與圖4中的CSR資料認證方法是利用區塊鏈搭配智能合約的架構來自動完成來源企業的CSR資料認證程序,所以能夠大幅提升CSR資料認證的效率與正確性,並同時大幅減少所需的人力與時間,更能有效避免儲存在區塊鏈子系統150中的認證後資料被事後竄改的風險。 As can be seen from the foregoing description, the CSR data authentication method in Figures 3 and 4 uses the architecture of blockchain and smart contract to automatically complete the CSR data authentication process of the source enterprise, so it can greatly improve the efficiency and accuracy of CSR data authentication. At the same time, the required manpower and time are greatly reduced, and the risk of post-authentication data stored in the blockchain subsystem 150 can be avoided afterwards.

另一方面,儲存於區塊鏈子系統150的認證後資料中所包含的去識別化資料的內容,並不包含跟私人資料有關的個人信息,利用區塊鏈子系統150來儲存認證後資料並不會外洩來源企業的內部員工或相關人員的個人資料,因此不會導致個資外洩的疑慮。 On the other hand, the content of the de-identified data contained in the post-authentication data stored in the blockchain subsystem 150 does not include personal information related to private data. Using the blockchain subsystem 150 to store the post-authentication data does not The personal data of internal employees or related personnel of the source company will be leaked, so it will not lead to the doubt of personal information leakage.

請注意,傳統上為來源企業進行CSR資料認證的主體(entity),是來源企業所委任的認證機構,但在CSR資料認證系統100中卻並非如此。 Please note that the entity that traditionally performs CSR data certification for the source company is a certification body appointed by the source company, but this is not the case in the CSR data certification system 100.

由前述圖3與圖4流程圖的說明可知,在CSR資料認證系統100中實際上依據相關CSR資料認證規則對去識別化資料進行查核的主體,是角色中立的區塊鏈子系統150,而不是任何認證子系統、也不是任何認證子系統所屬的認證機構。 As can be seen from the description of the flowcharts in Figs. 3 and 4 above, in the CSR data authentication system 100, the main body that actually checks the de-identified data according to the relevant CSR data authentication rules is the role-neutral blockchain subsystem 150, not Any certification subsystem is not the certification body to which any certification subsystem belongs.

以前述圖5中的去識別化資料530為例,認證子系統120在產生去識別化資料530後,並不會對去識別化資料530進行CSR資料認證,而是將包含去識別化資料530的組合資料540傳送到區塊鏈子系統150中進行認證。區塊鏈子系統150會執行認證子系統120預先佈署的目標智能合約,來查核組合資料540中的去識別化資料530的內容是否符合目標智能合約中的CSR資料查核規則。當去識別化資料530的內容通過相關智能合約的查核後,區塊鏈子系統150便會將去識別化資料530轉換成認證後資料550的形式,並保存在區塊鏈子系統150中。 Taking the de-identified data 530 in FIG. 5 as an example, the authentication subsystem 120 will not perform CSR data authentication on the de-identified data 530 after generating the de-identified data 530, but will include the de-identified data 530. The combined data 540 of is sent to the blockchain subsystem 150 for authentication. The blockchain subsystem 150 will execute the target smart contract pre-deployed by the authentication subsystem 120 to check whether the content of the de-identified data 530 in the combined data 540 meets the CSR data check rules in the target smart contract. After the content of the de-identified data 530 passes the verification of the relevant smart contract, the blockchain subsystem 150 converts the de-identified data 530 into the form of the authenticated data 550 and saves it in the blockchain subsystem 150.

很明顯地,任何企業都無法將偽造的認證後資料自行寫入區塊鏈子 系統150中欺騙其他人。 Obviously, no company can write forged authentication data into the blockchain by itself The system 150 deceives other people.

另外,從前述CSR資料認證系統100進行CSR資料認證的過程來看,實際上是認證子系統120把對企業的CSR資料進行認證的權力,透過智能合約作為媒介交到區塊鏈子系統150手上,由中立的區塊鏈子系統150代替第一認證機構操控的認證子系統120來對第一企業的CSR資料進行認證,並將認證後的CSR資料保存在區塊鏈子系統150中。 In addition, judging from the process of CSR data authentication performed by the aforementioned CSR data authentication system 100, it is actually the authentication subsystem 120 that has the power to authenticate the company’s CSR data and transfers it to the blockchain subsystem 150 through smart contracts as a medium. , The neutral blockchain subsystem 150 replaces the authentication subsystem 120 controlled by the first certification body to authenticate the CSR data of the first enterprise, and save the authenticated CSR data in the blockchain subsystem 150.

任何認證機構的智能合約都要先經過區塊鏈子系統150中的多個節點的共同認證,才能佈署到區塊鏈子系統150中,而且任何有權限讀取區塊鏈子系統150中的資料的人,皆可從認證後資料中的電子簽章得知該筆認證後資料先前是根據哪一個認證機構的智能合約來進行查核。因此,前述的CSR資料認證方式可有效避免企業串通委任的認證機構共同造假CSR資料認證結果的可能,所以能夠大幅提升CSR資料認證系統100整體認證過程的透明度與公信力。 The smart contract of any certification body must be jointly certified by multiple nodes in the blockchain subsystem 150 before it can be deployed in the blockchain subsystem 150, and any person who has the authority to read the data in the blockchain subsystem 150 Everyone can know from the electronic signature in the post-authentication data that the post-authentication data was previously checked according to the smart contract of which certification authority. Therefore, the aforementioned CSR data authentication method can effectively avoid the possibility of enterprises colluding with the appointed certification body to jointly falsify the CSR data certification result, so it can greatly improve the transparency and credibility of the overall certification process of the CSR data certification system 100.

以下將搭配圖6至圖7來進一步說明CSR資料認證系統100產生相關特定CSR項目數據報告(specific-CSR-category data report)的運作方式。圖6與圖7為本發明一實施例的特定CSR項目數據報告產生方法簡化後的流程圖。 Hereinafter, the operation mode of the CSR data authentication system 100 to generate a specific-CSR-category data report (specific-CSR-category data report) will be further explained in conjunction with FIGS. 6-7. 6 and 7 are simplified flowcharts of a method for generating a specific CSR project data report according to an embodiment of the present invention.

如前所述,當任何資料需求者(例如,投資機構、企業或組織的供應鏈管理部門、或官方的金融監理單位等等)需要查詢特定目標企業的CSR資料時,可透過相應的需求端裝置向CSR數據報告服務子系統110發送請求。 As mentioned earlier, when any data demander (for example, investment institutions, supply chain management departments of enterprises or organizations, or official financial supervision units, etc.) needs to query the CSR data of a specific target company, they can use the corresponding demand side The device sends a request to the CSR data reporting service subsystem 110.

為了方面說明起見,以下用需求端裝置105的用戶想要查詢特定目標企業的特定CSR項目數據報告的情境為例,來說明圖6與圖7中的特定CSR項目數據報告產生方法。 For the sake of explanation, the following uses a situation where the user of the demand-side device 105 wants to query a specific CSR project data report of a specific target company as an example to illustrate the specific CSR project data report generation method in FIGS. 6 and 7.

首先,需求端裝置105可依據其用戶的操作進行流程602,以透過網際網路從遠端登入CSR數據報告服務子系統110。需求端裝置105登 入CSR數據報告服務子系統110的方式,可採用各種合適的帳號查核或身分驗證方式來進行。 First, the demand-side device 105 can perform the process 602 according to the operation of its user to remotely log in to the CSR data reporting service subsystem 110 via the Internet. 105 on demand side device The method of entering the CSR data reporting service subsystem 110 can be carried out by various suitable account checking or identity verification methods.

在需求端裝置105成功登入CSR數據報告服務子系統110後,CSR數據報告服務子系統110的網站伺服器112可產生相關的查詢對象選擇網頁,供需求端裝置105的用戶瀏覽及設定。 After the demand-side device 105 successfully logs in to the CSR data reporting service subsystem 110, the website server 112 of the CSR data reporting service subsystem 110 can generate a related query object selection webpage for users of the demand-side device 105 to browse and set.

接著,需求端裝置105可進行流程604,依據用戶的操作選擇欲查詢的目標企業、資料時間範圍、及資料項目(data category),並產生及傳送一相應的特定項目數據報告請求(specific-category data report request)至網站伺服器112。實作上,前述的特定項目數據報告請求中可包含一個或多個選定資料項目。在一實施例中,前述的資料項目是用來指定要查詢的CSR資料是屬於哪一個或哪幾個特定的主資料項目。在其他實施例中,前述的資料項目可進一步用來指定要查詢的CSR資料是屬於哪一個特定的主要資料項目底下的哪一個或哪幾個特定的子資料項目。 Then, the demand-side device 105 can proceed to the process 604 to select the target company to be queried, the data time range, and the data category according to the user's operation, and generate and transmit a corresponding specific-category data report request (specific-category). data report request) to the website server 112. In practice, the aforementioned specific project data report request may include one or more selected data items. In one embodiment, the aforementioned data item is used to specify which specific master data item or items the CSR data to be queried belongs to. In other embodiments, the aforementioned data items can be further used to specify which CSR data to be queried belongs to which specific main data item or several specific sub-data items.

在流程606中,網站伺服器112會接收需求端裝置105傳來的特定項目數據報告請求。 In the process 606, the website server 112 receives the specific project data report request from the demand-side device 105.

在流程608中,網站伺服器112會產生並傳送一詢問信息給特定項目數據報告請求所對應的目標企業。在運作時,網站伺服器112可將該詢問信息透過網際網路傳送給目標企業對應的企業端裝置。 In the process 608, the website server 112 will generate and send an inquiry message to the target company corresponding to the specific project data report request. During operation, the website server 112 can transmit the query information to the corresponding enterprise device of the target enterprise via the Internet.

為了方面說明起見,以下假設前述的目標企業是第一企業。在此情況下,網站伺服器112會在流程608中產生並傳送一詢問信息給第一企業所對應的企業端裝置101。 For the sake of explanation, the following assumes that the aforementioned target company is the first company. In this case, the website server 112 will generate and send an inquiry message to the enterprise device 101 corresponding to the first enterprise in the process 608.

在流程610中,企業端裝置101會接送網站伺服器112傳來的詢問信息,並產生相關的提示訊息以詢問第一企業的內部人員是否同意CSR數據報告服務子系統110提供第一企業的相關特定CSR項目數據報告給需求端裝置105的用戶。 In the process 610, the enterprise-end device 101 will pick up the inquiry message from the website server 112 and generate a related prompt message to ask the internal personnel of the first enterprise whether the CSR data reporting service subsystem 110 provides relevant information for the first enterprise The specific CSR project data is reported to the user of the demand-side device 105.

倘若第一企業的內部人員不願意將第一企業的相關特定CSR項目數 據報告提供給需求端裝置105的用戶,則可利用企業端裝置101進行流程612。反之,倘若第一企業的內部人員願意將第一企業的相關特定CSR項目數據報告提供給需求端裝置105的用戶,則可利用企業端裝置101進行流程616。 If the internal staff of the first company are not willing to share the number of related specific CSR projects of the first company According to the report, it is provided to users of the on-demand device 105, and the enterprise device 101 can be used to perform the process 612. Conversely, if the internal staff of the first company is willing to provide the relevant specific CSR project data report of the first company to the user of the demand-side device 105, the enterprise-side device 101 can be used to perform the process 616.

在流程612中,企業端裝置101會依據其用戶的指示,傳送一拒絕信息(disapproval message)給CSR數據報告服務子系統110。CSR數據報告服務子系統110的網站伺服器112在收到企業端裝置101傳來的拒絕信息後,可產生並傳送一相應的拒絕通知(rejection notice)給需求端裝置105。 In the process 612, the enterprise-end device 101 will transmit a rejection message to the CSR data reporting service subsystem 110 according to the instruction of its user. The website server 112 of the CSR data reporting service subsystem 110 can generate and send a corresponding rejection notice to the demand-side device 105 after receiving the rejection information from the enterprise-end device 101.

在流程614中,需求端裝置105會接收網站伺服器112傳來的拒絕通知,並以適當的形式通知需求端裝置105的用戶。 In the process 614, the on-demand device 105 will receive the rejection notification from the website server 112, and notify the user of the on-demand device 105 in an appropriate form.

在流程616中,企業端裝置101會依據其用戶的指示,傳送一同意信息(approval message)給CSR數據報告服務子系統110。 In the process 616, the enterprise device 101 will send an approval message to the CSR data reporting service subsystem 110 according to the instructions of its user.

在一實施例中,當網站伺服器112接收到企業端裝置101傳來的同意信息時,網站伺服器112會查詢區塊鏈子系統150中是否已儲存有前述特定項目數據報告請求所需要的特定CSR項目數據報告。倘若前述特定項目數據報告請求所需要的特定CSR項目數據報告已經製作完成並存在區塊鏈子系統150中,則網站伺服器112可單純從區塊鏈子系統150中讀取出所需的特定CSR項目數據報告,並傳送給需求端裝置105。反之,倘若區塊鏈子系統150中並沒有所需的特定CSR項目數據報告,則網站伺服器112會進行流程618。 In one embodiment, when the website server 112 receives the consent information from the enterprise device 101, the website server 112 will inquire whether the blockchain subsystem 150 has stored the specific item data required by the aforementioned specific project data report request. CSR project data report. If the specific CSR project data report required by the aforementioned specific project data report request has been completed and stored in the blockchain subsystem 150, the website server 112 can simply read the required specific CSR project from the blockchain subsystem 150 The data report is sent to the demand-side device 105. Conversely, if there is no required specific CSR project data report in the blockchain subsystem 150, the website server 112 will perform the process 618.

在另一實施例中,當網站伺服器112接收到企業端裝置101傳來的同意信息時,不論區塊鏈子系統150中是否已儲存有前述特定項目數據報告請求所需要的特定CSR項目數據報告,網站伺服器112都會進行流程618。 In another embodiment, when the website server 112 receives the consent information from the enterprise device 101, regardless of whether the blockchain subsystem 150 has already stored the specific CSR project data report required by the aforementioned specific project data report request , The website server 112 will perform the process 618.

在流程618中,網站伺服器112會產生與需求端裝置105選定的目標企業(在本例中假設為第一企業)、資料時間範圍、及資料項目相 應的一報告製作請求(report generation request)。實作上,網站伺服器112可將需求端裝置105所選定的目標企業、資料時間範圍、及資料項目,以各種合適的資料格式記錄在報告製作請求中。 In the process 618, the website server 112 will generate the target company (in this example, it is assumed to be the first company), the data time range, and the data item selected by the demand-side device 105. In response to a report generation request (report generation request). In practice, the website server 112 can record the target company, data time range, and data items selected by the demand-side device 105 in various suitable data formats in the report creation request.

在流程620中,網站伺服器112會從用戶關係資料庫114中查詢目標企業所對應的認證機構。 In the process 620, the website server 112 queries the user relationship database 114 for the certification authority corresponding to the target enterprise.

接著,網站伺服器112會進行流程622,將報告製作請求傳送給相應認證機構的認證子系統。由於本實施例中是假設目標企業為第一企業,而第一企業所對應的認證機構是第一認證機構。因此,網站伺服器112在流程622中會將報告製作請求傳送給第一認證機構對應的認證子系統120。 Next, the website server 112 will perform the process 622 to transmit the report creation request to the certification subsystem of the corresponding certification agency. In this embodiment, it is assumed that the target company is the first company, and the certification body corresponding to the first company is the first certification body. Therefore, the website server 112 sends the report creation request to the authentication subsystem 120 corresponding to the first authentication agency in the process 622.

接下來,認證子系統120與區塊鏈子系統150會搭配進行特定CSR項目數據報告產生方法的後半部流程,亦即圖7中的流程702~710。 Next, the authentication subsystem 120 and the blockchain subsystem 150 will cooperate to perform the second half of the process of the specific CSR project data report generation method, that is, the processes 702 to 710 in FIG. 7.

在流程702中,認證子系統120的通信電路121會接收網站伺服器112傳來的報告製作請求,而CSR資料認證程式126中的資料處理模組220可控制處理電路125讀取報告製作請求中所記錄的選定目標企業、選定資料時間範圍、以及選定資料項目等查詢參數。 In the process 702, the communication circuit 121 of the authentication subsystem 120 receives the report creation request from the website server 112, and the data processing module 220 in the CSR data authentication program 126 can control the processing circuit 125 to read the report creation request Recorded query parameters such as selected target companies, selected data time range, and selected data items.

在流程704中,CSR資料認證程式126中的區塊鏈存取模組250可控制處理電路125,從區塊鏈子系統150中讀取出目標企業(在本例中為第一企業)在選定資料時間範圍內、對應一個或多個選定資料項目的多筆相關認證後資料。 In the process 704, the block chain access module 250 in the CSR data authentication program 126 can control the processing circuit 125 to read the target company (the first company in this example) from the block chain subsystem 150. Multiple relevant post-authentication data corresponding to one or more selected data items within the data time range.

在流程706中,CSR資料認證程式126中的區塊鏈存取模組250可控制處理電路125從前述的多筆認證後資料中擷取出多筆資料庫索引。 In the process 706, the blockchain access module 250 in the CSR data authentication program 126 can control the processing circuit 125 to retrieve multiple database indexes from the multiple authentication data described above.

在流程708中,CSR資料認證程式126中的資料庫存取模組230可控制處理電路125,根據前述的多筆資料庫索引查詢資料庫123,以從資料庫123中讀取出目標企業(在本例中為第一企業)的多筆適格原始資料。 In the process 708, the database access module 230 in the CSR data authentication program 126 can control the processing circuit 125 to query the database 123 according to the aforementioned multiple database indexes, so as to read the target enterprise (in In this example, it is the multiple qualified original data of the first enterprise.

在流程710中,CSR資料認證程式126中的報告產生模組260可控制 處理電路125根據預定的報告製作規則,將前述的多筆適格原始資料自動轉換成一份特定CSR項目數據報告。實作上,可以將如何對多筆適格原始資料中的相關紀錄進行分類、統計、分析、繪製圖表等各種規則,預先設置在報告產生模組260中,以供處理電路125據以進行流程710。 In the process 710, the report generation module 260 in the CSR data authentication program 126 can control The processing circuit 125 automatically converts the aforementioned multiple eligible original data into a specific CSR project data report according to predetermined report making rules. In practice, various rules such as how to categorize, count, analyze, and draw charts in the relevant records of multiple eligible original data can be preset in the report generation module 260 for the processing circuit 125 to perform the process 710 accordingly. .

為了便於理解,在此搭配圖8來輔助說明圖7中的流程702~710。圖8為在本發明一實施例的特定CSR項目數據報告產生過程中簡化後的資料流示意圖。 For ease of understanding, FIG. 8 is used here to assist in describing the processes 702 to 710 in FIG. 7. FIG. 8 is a simplified data flow diagram in the process of generating a specific CSR project data report according to an embodiment of the present invention.

在前述的流程704中,處理電路125可依據區塊鏈存取模組250的控制,從區塊鏈子系統150讀取出第一企業在選定資料時間範圍內、對應一個或多個選定資料項目的多筆認證後資料,其中,圖8所繪示的認證後資料810是前述多筆認證後資料的其中之一。 In the aforementioned process 704, the processing circuit 125 can read from the blockchain subsystem 150 that the first enterprise corresponds to one or more selected data items within the selected data time range under the control of the blockchain access module 250 The post-authentication data 810 shown in FIG. 8 is one of the multiple post-authentication data described above.

如圖8所示,認證後資料810中包含有去識別化資料812、資料庫索引814、以及相應認證機構的電子簽章816(在本例中為第一認證機構的電子簽章)。 As shown in FIG. 8, the post-authentication data 810 includes the de-identified data 812, the database index 814, and the electronic signature 816 of the corresponding certification authority (in this example, the electronic signature of the first certification authority).

在前述的流程706中,處理電路125可依據區塊鏈存取模組250的控制,從認證後資料810中擷取出資料庫索引814。 In the aforementioned process 706, the processing circuit 125 can retrieve the database index 814 from the post-authentication data 810 under the control of the blockchain access module 250.

在前述的流程708中,處理電路125可依據資料庫存取模組230的控制,根據資料庫索引814查詢資料庫123,以從資料庫123中讀取出與第一企業相應的一筆適格原始資料831。適格原始資料831的資料欄位配置與前述圖5中的適格原始資料510實質上相同。因此,為簡化圖面起見,在圖8中並未繪示適格原始資料831的資料欄位配置。 In the aforementioned process 708, the processing circuit 125 can query the database 123 according to the database index 814 according to the control of the database access module 230 to read a piece of eligible original data corresponding to the first enterprise from the database 123 831. The data field configuration of the eligible raw data 831 is substantially the same as the eligible raw data 510 in FIG. 5. Therefore, in order to simplify the drawing, the data field configuration of the eligible original data 831 is not shown in FIG. 8.

接下來,處理電路125可根據區塊鏈存取模組250與資料庫存取模組230的控制,對其他的認證後資料重複進行擷取資料庫索引以及查詢資料庫123的運作,以從資料庫123中陸續讀取出其他的適格原始資料833~835。 Next, the processing circuit 125 can repeat the operations of retrieving the database index and querying the database 123 for other post-authenticated data under the control of the blockchain access module 250 and the database acquisition module 230 to retrieve the data from the database. Other eligible original data 833~835 are successively read from the library 123.

當獲得所有符合條件的適格原始資料後,處理電路125便可依據報 告產生模組260的控制,進行前述的流程710,以將前述的多筆適格原始資料根據預定的報告製作規則自動轉換成一份特定CSR項目數據報告,並可將前述的多筆適格原始資料中的相關紀錄的統計結果或分析結果,以各種圖表的方式呈現在該特定CSR項目數據報告中。 After obtaining all eligible raw data that meet the conditions, the processing circuit 125 can be The report generation module 260 performs the aforementioned process 710 to automatically convert the aforementioned multiple eligible original data into a specific CSR project data report according to predetermined report production rules, and can convert the aforementioned multiple eligible original data The statistical results or analysis results of related records are presented in the specific CSR project data report in the form of various charts.

換言之,認證子系統120的處理電路125會依據從區塊鏈子系統150中讀取出來的多筆認證後資料,即時產生前述的特定CSR項目數據報告。 In other words, the processing circuit 125 of the authentication subsystem 120 will instantly generate the aforementioned specific CSR project data report based on multiple pieces of post-authentication data read from the blockchain subsystem 150.

在流程712中,報告產生模組260可控制處理電路125利用通信電路121,將產生的特定CSR項目數據報告傳送給CSR數據報告服務子系統110的網站伺服器112。 In the process 712, the report generation module 260 can control the processing circuit 125 to use the communication circuit 121 to transmit the generated specific CSR project data report to the website server 112 of the CSR data reporting service subsystem 110.

此時,網站伺服器112會進行流程714,以接收認證子系統120傳來的特定CSR項目數據報告。 At this time, the website server 112 will perform the process 714 to receive the specific CSR project data report from the authentication subsystem 120.

接著,網站伺服器112會進行流程716,將認證子系統120產生的特定CSR項目數據報告提供給需求端裝置105。實作上,網站伺服器112可以將認證子系統120產生的特定CSR項目數據報告直接轉發給需求端裝置105。或者,網站伺服器112也可以將認證子系統120產生的特定CSR項目數據報告先進行加密後,再傳送給需求端裝置105,以提升特定CSR項目數據報告傳遞時的資料安全性。 Next, the website server 112 will perform the process 716 to provide the specific CSR project data report generated by the authentication subsystem 120 to the demand-side device 105. In practice, the website server 112 can directly forward the specific CSR project data report generated by the authentication subsystem 120 to the demand-side device 105. Alternatively, the website server 112 may also encrypt the specific CSR project data report generated by the authentication subsystem 120 before transmitting it to the demand-side device 105 to improve the data security of the specific CSR project data report.

在流程718中,需求端裝置105會接收網站伺服器112傳來的特定CSR項目數據報告。如此一來,需求端裝置105的用戶便可藉由該特定CSR項目數據報告了解目標企業在一個或多個特定的企業社會責任面向上的投入情況,以藉此評估是否將目標企業納入選擇投資標的、或是評估是否要將目標企業納為供應鏈合作夥伴。 In the process 718, the demand-side device 105 will receive the specific CSR project data report from the website server 112. In this way, users of the demand-side device 105 can use the specific CSR project data report to understand the target company’s investment in one or more specific corporate social responsibility aspects, so as to evaluate whether the target company is included in the selected investment Target or evaluate whether to include the target company as a supply chain partner.

相仿地,倘若需求端裝置107的用戶想要查詢第二企業的特定CSR項目數據報告,也可以比照前述方式透過需求端裝置107傳送相關請求給CSR數據報告服務子系統110。CSR數據報告服務子系統110會透過企業端裝置103詢問第二企業是否同意CSR數據報告服務子 系統110提供第二企業的相關特定CSR項目數據報告給需求端裝置107的用戶。在取得第二企業的同意之後,CSR數據報告服務子系統110可請求與第二認證機構相應的認證子系統130製作相關的特定CSR項目數據報告。接著,認證子系統130與區塊鏈子系統150可按照前述圖7的方法搭配運作,以產生與第二企業相應的特定CSR項目數據報告,並透過CSR數據報告服務子系統110傳送給需求端裝置107。 Similarly, if the user of the demand-side device 107 wants to query the specific CSR project data report of the second company, he can also send related requests to the CSR data report service subsystem 110 through the demand-side device 107 in the aforementioned manner. The CSR Data Reporting Service Subsystem 110 will ask the second company whether to agree to the CSR Data Reporting Service through the enterprise device 103. The system 110 provides relevant specific CSR project data reports of the second company to the users of the demand-side device 107. After obtaining the consent of the second enterprise, the CSR data reporting service subsystem 110 may request the certification subsystem 130 corresponding to the second certification body to produce a related specific CSR project data report. Then, the authentication subsystem 130 and the blockchain subsystem 150 can work together according to the method shown in FIG. 7 to generate a specific CSR project data report corresponding to the second enterprise, and transmit it to the demand-end device through the CSR data report service subsystem 110 107.

由前述說明可知,在接收到CSR數據報告服務子系統110傳來的報告製作請求後,相關的認證子系統會搭配區塊鏈子系統150自動產生相應的特定CSR項目數據報告,所以能夠大幅提升特定CSR項目數據報告的產生效率與正確性,並同時大幅減少所需的人力與時間,更能有效確保CSR數據報告服務子系統110提供給需求端裝置的特定CSR項目數據報告是未經竄改的版本。 From the foregoing description, after receiving the report production request from the CSR data reporting service subsystem 110, the relevant authentication subsystem will work with the blockchain subsystem 150 to automatically generate corresponding specific CSR project data reports, so it can greatly improve the specific The production efficiency and accuracy of CSR project data reports, while greatly reducing the manpower and time required, can more effectively ensure that the specific CSR project data reports provided by the CSR data reporting service subsystem 110 to the demand-side devices are the unmodified version .

如此一來,便能夠提升相關企業進行CSR資料認證的頻率,並吸引更多企業與認證機構參與CSR資料認證系統100的運作,以共同投入及推動CSR資料認證制度,進而擴大CSR揭露制度(CSR disclosure)的普及。 In this way, the frequency of CSR data certification by related companies can be increased, and more companies and certification bodies can be attracted to participate in the operation of the CSR data certification system 100 to jointly invest in and promote the CSR data certification system, thereby expanding the CSR disclosure system (CSR disclosure).

由於CSR數據報告服務子系統110能夠確保提供給需求端裝置的特定CSR項目數據報告是未經竄改的版本,所以各國的投資機構、供應鏈管理部門、或官方的金融監理單位,便得以根據CSR數據報告服務子系統110歷次提供的特定CSR項目數據報告來判斷目標企業是否真的在特定的企業社會責任面向上有長期且持續性的投入。 Since the CSR data reporting service subsystem 110 can ensure that the specific CSR project data report provided to the demand-side device is an un-tampered version, investment institutions, supply chain management departments, or official financial supervision units in various countries can follow CSR The data report service subsystem 110 has provided specific CSR project data reports to determine whether the target company really has long-term and continuous investment in the specific corporate social responsibility aspect.

請注意,在前述的CSR資料認證系統100中,產生特定CSR項目數據報告的主體是相關的認證子系統,但該認證子系統卻必須根基於區塊鏈子系統150提供的資料才能產生正確的特定CSR項目數據報告。 Please note that in the aforementioned CSR data authentication system 100, the main body that generates the specific CSR project data report is the relevant authentication subsystem, but the authentication subsystem must be based on the data provided by the blockchain subsystem 150 to generate the correct specific CSR project data report.

以前述圖8中的認證後資料810為例,認證子系統120從區塊鏈子系 統150中讀取出認證後資料810後,必須先從認證後資料810中擷取出資料庫索引814,再根據資料庫索引814查詢資料庫123,才能從資料庫123中讀取出相應的適格原始資料831。在沒有取得區塊鏈子系統150中所儲存的認證後資料810的情況下,認證子系統120的處理電路125便無法從資料庫123中讀取出正確的適格原始資料831。 Taking the post-authentication data 810 in FIG. 8 as an example, the authentication subsystem 120 starts from the blockchain subsystem After the post-authentication data 810 is read from the system 150, the database index 814 must be retrieved from the post-authentication data 810, and then the database 123 can be queried according to the database index 814, so that the corresponding qualified data can be read from the database 123 Original data 831. Without obtaining the post-authentication data 810 stored in the blockchain subsystem 150, the processing circuit 125 of the authentication subsystem 120 cannot read the correct qualified original data 831 from the database 123.

因此,前述的特定CSR項目數據報告產生方法可有效避免企業串通委任的認證機構共同造假特定CSR項目數據報告的可能,能夠大幅提升CSR數據報告服務子系統110所提供的特定CSR項目數據報告的資料深度、資料詳細度、可信賴度、與公信力。 Therefore, the aforementioned specific CSR project data report generation method can effectively avoid the possibility of enterprises colluding with the appointed certification body to jointly falsify the specific CSR project data report, and can greatly improve the information of the specific CSR project data report provided by the CSR data reporting service subsystem 110 Depth, data detail, reliability, and credibility.

此外,在前述的CSR資料認證系統100中,來源企業的適格原始資料只會儲存於相應認證機構的認證子系統的資料庫中,所以任何認證機構在無權存取其他認證子系統的資料庫的情況下,都無法代替其他認證機構產生相關的特定CSR項目數據報告。 In addition, in the aforementioned CSR data certification system 100, the qualified original data of the source company will only be stored in the database of the certification subsystem of the corresponding certification agency, so any certification agency has no right to access the database of other certification subsystems. Under the circumstance, it cannot replace other certification bodies to generate relevant specific CSR project data reports.

例如,假設前述第一企業的適格原始資料只會儲存於相應的第一認證機構的認證子系統120的資料庫123中,且屬於第二認證機構的認證子系統130無法存取認證子系統120的資料庫123。在此情況下,即使認證子系統130能夠從區塊鏈子系統150中讀取跟第一企業有關的多筆認證後資料,並從中擷取出多筆資料庫索引,由於認證子系統130無法取得資料庫123中的正確適格原始資料,因此也就無法產生與第一企業相應的特定CSR項目數據報告的詳細版本。換言之,前述的特定CSR項目數據報告產生方法可有效確保CSR數據報告服務子系統110所提供的特定CSR項目數據報告的權威性與公正性,並可降低不同的認證機構為了爭搶產生特定CSR項目數據報告的權力而出現惡性競爭的情況。 For example, suppose that the qualified original data of the aforementioned first enterprise will only be stored in the database 123 of the certification subsystem 120 of the corresponding first certification authority, and the certification subsystem 130 belonging to the second certification authority cannot access the certification subsystem 120的Database 123. In this case, even if the authentication subsystem 130 can read multiple pieces of post-authentication data related to the first enterprise from the blockchain subsystem 150, and retrieve multiple database indexes from it, the authentication subsystem 130 cannot obtain the data The correct and qualified original data in the database 123 cannot produce a detailed version of the specific CSR project data report corresponding to the first company. In other words, the aforementioned specific CSR project data report generation method can effectively ensure the authority and fairness of the specific CSR project data report provided by the CSR data reporting service subsystem 110, and can reduce the need for different certification agencies to compete for specific CSR projects. Vicious competition arises from the power of data reporting.

另一方面,當CSR數據報告服務子系統110為了因應突發性需要而傳送報告製作請求給相應的認證子系統時,該認證子系統都可搭配區塊鏈子系統150進行運作以即時產生最新的特定CSR項目數據報 告,以反映出目標企業近期在一個或多個特定的企業社會責任面向上的最新表現。 On the other hand, when the CSR data reporting service subsystem 110 sends a report production request to the corresponding authentication subsystem in response to unexpected needs, the authentication subsystem can work with the blockchain subsystem 150 to instantly generate the latest Specific CSR project data report Report to reflect the latest performance of the target company in one or more specific corporate social responsibility aspects.

再者,由於前述的CSR資料認證系統100允許資料需求者彈性設定所需要的特定CSR項目數據報告的資料時間範圍,所以相應認證子系統所產生的特定CSR項目數據報告的時間幅度能夠配合資料需求者的需要,而不再像傳統的CSR報告一樣只能侷限在以季節或年度為單位。因此,前述的特定CSR項目數據報告產生方法可大幅增加資料需求者的使用彈性與便利性,並讓各國的投資機構、供應鏈管理部門、或官方的金融監理單位,得以利用CSR資料認證系統100產生的特定CSR項目數據報告,來分析及比較不同的企業在某一段非制式化時間範圍內,在一個或多個特定的企業社會責任面向上的表現差異。 Furthermore, since the aforementioned CSR data authentication system 100 allows data users to flexibly set the required data time range of the specific CSR project data report, the time range of the specific CSR project data report generated by the corresponding authentication subsystem can match the data demand The needs of the participants are no longer limited to seasonal or annual units like traditional CSR reports. Therefore, the aforementioned specific CSR project data report generation method can greatly increase the flexibility and convenience of data demanders, and allow investment institutions, supply chain management departments, or official financial supervision units in various countries to use the CSR data certification system 100 Generate specific CSR project data reports to analyze and compare the performance differences of different companies in one or more specific corporate social responsibility aspects within a certain non-standardized time frame.

請注意,前述各流程圖中的流程執行順序只是一示範性的實施例,並非侷限本發明的實際實施方式。例如,圖4中的流程404可以調整到流程402之前進行,也可以和流程402同時進行。又例如,圖6中的流程620可以調整到流程618之前進行,也可以和流程618同時進行。 Please note that the execution sequence of the processes in the foregoing flowcharts is only an exemplary embodiment and does not limit the actual implementation of the present invention. For example, the process 404 in FIG. 4 may be adjusted to be performed before the process 402, or may be performed simultaneously with the process 402. For another example, the process 620 in FIG. 6 may be adjusted to be performed before the process 618, or may be performed simultaneously with the process 618.

在網站伺服器112無需詢問企業是否願意提供特定CSR項目數據報告給資料需求者的某些應用中,網站伺服器112在進行流程606之後,可以直接跳到流程618,以省略詢問目標企業是否同意CSR數據報告服務子系統110提供目標企業的相關特定CSR項目數據報告給資料需求者的相關流程。 In some applications where the website server 112 does not need to ask the company whether it is willing to provide specific CSR project data to the data requester, the website server 112 can jump directly to the process 618 after the process 606 is performed, so as to omit asking whether the target company agrees The CSR Data Reporting Service Subsystem 110 provides relevant procedures for reporting specific CSR project data of the target company to the data requester.

在實際應用中,資料需求者也可以不設定特別的資料時間範圍、和/或資料項目。在此情況下,相應的認證子系統在前述流程702中便可放寬從區塊鏈子系統150中搜尋認證後資料時的搜尋條件。 In practical applications, the data demander may not set a special data time range and/or data item. In this case, the corresponding authentication subsystem can relax the search conditions when searching for post-authentication data from the blockchain subsystem 150 in the aforementioned process 702.

實作上,前述CSR資料認證系統100中的認證子系統的數量、企業端裝置的數量、以及需求端裝置的數量,都可依實際應用環境的需 要而調整,並不侷限於前述實施例所繪示的態樣。 In practice, the number of authentication subsystems in the aforementioned CSR data authentication system 100, the number of enterprise-side devices, and the number of demand-side devices can all be based on the needs of the actual application environment. The adjustment is not limited to the aspect illustrated in the foregoing embodiment.

在某些實施例中,可將前述CSR數據報告服務子系統110中的區塊鏈運算電路116省略,或是將區塊鏈運算電路116獨立於CSR數據報告服務子系統110之外。 In some embodiments, the blockchain operation circuit 116 in the aforementioned CSR data reporting service subsystem 110 may be omitted, or the blockchain operation circuit 116 may be independent of the CSR data reporting service subsystem 110.

另外,在某些實施例中,可將前述認證子系統120中的區塊鏈運算電路124省略,或是將區塊鏈運算電路124獨立於認證子系統120之外。同樣地,在某些實施例中,可將前述認證子系統130中的區塊鏈運算電路134省略,或是將區塊鏈運算電路134獨立於認證子系統130之外。 In addition, in some embodiments, the blockchain operation circuit 124 in the authentication subsystem 120 may be omitted, or the blockchain operation circuit 124 may be independent of the authentication subsystem 120. Similarly, in some embodiments, the blockchain operation circuit 134 in the aforementioned authentication subsystem 130 may be omitted, or the blockchain operation circuit 134 may be independent of the authentication subsystem 130.

實作上,亦可將前述認證子系統120中的資料庫123獨立於認證子系統120之外。同樣地,亦可將前述認證子系統130中的資料庫133獨立於認證子系統130之外。 In practice, the database 123 in the aforementioned authentication subsystem 120 can also be independent of the authentication subsystem 120. Similarly, the database 133 in the aforementioned authentication subsystem 130 can also be independent of the authentication subsystem 130.

在說明書及申請專利範圍中使用了某些詞彙來指稱特定的元件,而 本領域內的技術人員可能會用不同的名詞來稱呼同樣的元件。本說明書及申請專利範圍並不以名稱的差異來作為區分元件的方式,而是以元件在功能上的差異來作為區分的基準。在說明書及申請專利範圍中所提及的「包含」為開放式的用語,應解釋成「包含但不限定於」。另外,「耦接」一詞在此包含任何直接及間接的連接手段。 因此,若文中描述第一元件耦接於第二元件,則代表第一元件可通過電性連接或無線傳輸、光學傳輸等信號連接方式而直接地連接於第二元件,或通過其它元件或連接手段間接地電性或信號連接至第二元件。 In the specification and the scope of patent applications, certain words are used to refer to specific components, and Those skilled in the art may use different terms to refer to the same element. This specification and the scope of the patent application do not use differences in names as a way to distinguish elements, but use differences in functions of elements as a basis for distinction. The "include" mentioned in the specification and the scope of the patent application is an open term and should be interpreted as "include but not limited to". In addition, the term "coupling" herein includes any direct and indirect connection means. Therefore, if it is described in the text that the first element is coupled to the second element, it means that the first element can be directly connected to the second element through electrical connection, wireless transmission, optical transmission, or other signal connection methods, or through other elements or connections. The means is indirectly connected to the second element electrically or signally.

在說明書中所使用的「和/或」的描述方式,包含所列舉的其中一個項目或多個項目的任意組合。另外,除非說明書中特別指明,否則任何單數格的用語都同時包含複數格的含義。 The description method of "and/or" used in the description includes one of the listed items or any combination of multiple items. In addition, unless otherwise specified in the specification, any term in the singular case also includes the meaning of the plural case.

權利要求書中的某些裝置權利要求中的流程特徵,與附圖及說明書的流程圖中的運作流程內容對應一致。因此,這些裝置權利要求, 應當理解為主要透過說明書記載的計算機程序實現前述解決方案的功能模組架構,而不應當理解為主要通過硬件方式實現該解決方案的實體裝置。 The process features in some device claims in the claims correspond to the operation process content in the drawings and flowcharts in the description. Therefore, these device claims, It should be understood that the functional module architecture of the aforementioned solution is realized mainly through the computer program recorded in the specification, and should not be understood as a physical device that mainly realizes the solution through hardware.

以上僅為本發明的較佳實施例,凡依本發明請求項所做的等效變化與修改,皆應屬本發明的涵蓋範圍。 The above are only preferred embodiments of the present invention, and all equivalent changes and modifications made in accordance with the claims of the present invention should fall within the scope of the present invention.

100:CSR資料認證系統 100: CSR data certification system

101~103:企業端裝置 101~103: Enterprise device

105~107:需求端裝置 105~107: Demand side device

110:CSR數據報告服務子系統 110: CSR data reporting service subsystem

112:網站伺服器 112: Web server

114:用戶關係資料庫 114: User Relationship Database

116:區塊鏈運算電路 116: Blockchain operation circuit

120、130:認證子系統 120, 130: authentication subsystem

121、131:通信電路 121, 131: communication circuit

122、132:儲存電路 122, 132: storage circuit

123、133:資料庫 123, 133: Database

124、134:區塊鏈運算電路 124, 134: Blockchain operation circuit

125、135:處理電路 125, 135: processing circuit

126、136:CSR資料認證程式 126, 136: CSR data authentication program

140:區塊鏈節點叢集 140: Blockchain node cluster

141~147:區塊鏈節點 141~147: Blockchain nodes

150:區塊鏈子系統 150: Blockchain subsystem

Claims (22)

一種CSR資料認證系統(100),包含:一區塊鏈子系統(150),包含有多個區塊鏈節點(141~147);一認證子系統(120),包含一通信電路(121)和耦接於該通信電路(121)的一處理電路(125),其中,該通信電路(121)設置成可透過網路存取該區塊鏈子系統(150);以及一CSR數據報告服務子系統(110),設置成可透過網路與一企業端裝置(101)以及該認證子系統(120)進行資料通信,並可在接收到該企業端裝置(101)所傳來一目標企業的CSR原始資料後,將該CSR原始資料傳送給該認證子系統(120)的該通信電路(121);其中,該認證子系統(120)的該處理電路(125)還設置成執行一電腦程式產品(126)以進行以下運作:從該CSR原始資料中篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫(123)中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及將該去識別化資料及相應的該資料庫索引傳送至該區塊鏈子系統(150),並指示該區塊鏈子系統(150)執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統(150)產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統(120)所對應的一認證機構的電子簽章。 A CSR data authentication system (100), including: a blockchain subsystem (150), including multiple blockchain nodes (141~147); an authentication subsystem (120), including a communication circuit (121) and A processing circuit (125) coupled to the communication circuit (121), wherein the communication circuit (121) is configured to be able to access the blockchain subsystem (150) through the network; and a CSR data reporting service subsystem (110), which is set to communicate with an enterprise device (101) and the authentication subsystem (120) through the network, and can receive the CSR of a target enterprise from the enterprise device (101) After the original data, the CSR original data is sent to the communication circuit (121) of the authentication subsystem (120); wherein, the processing circuit (125) of the authentication subsystem (120) is also set to execute a computer program product (126) to perform the following operations: filter out the eligible raw data for authentication from the CSR raw data, and store the eligible raw data in a database (123); generate a database corresponding to the eligible raw data Index; remove the identifiable data from the eligible original data to generate de-identified data; and send the de-identified data and the corresponding database index to the blockchain subsystem (150), and instruct the block The chain subsystem (150) executes one or more smart contracts to authenticate the de-identified data; wherein, if the de-identified data meets the check rules in the one or more smart contracts, the blockchain subsystem (150) A post-authentication data is generated and stored, and the post-authentication data includes the de-identification data, the database index, and the electronic signature of a certification body corresponding to the authentication subsystem (120). 如請求項1所述的CSR資料認證系統(100),其中,該認證子系統(120)還設置成執行該電腦程式產品(126)以進行以下運作: 建立並將該一個或多個智能合約佈署至該區塊鏈子系統(150),且該一個或多個智能合約的其中之一包含該電子簽章。 The CSR data authentication system (100) according to claim 1, wherein the authentication subsystem (120) is also configured to execute the computer program product (126) to perform the following operations: Create and deploy the one or more smart contracts to the blockchain subsystem (150), and one of the one or more smart contracts includes the electronic signature. 如請求項2所述的CSR資料認證系統(100),其中,倘若一需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告,該CSR數據報告服務子系統(110)會產生並傳送與該目標企業相應的一報告製作請求給該認證子系統(120),而該認證子系統(120)還設置成執行該電腦程式產品(126)以進行以下運作:從該報告製作請求中取得一選定資料時間範圍;從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內的多筆相關認證後資料;從該多筆認證後資料中擷取出多筆資料庫索引;根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給該需求端裝置(105)。 The CSR data certification system (100) according to claim 2, wherein if a demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target company, The CSR data reporting service subsystem (110) will generate and send a report production request corresponding to the target enterprise to the authentication subsystem (120), and the authentication subsystem (120) is also set to execute the computer program product ( 126) to perform the following operations: obtain a selected data time range from the report production request; read multiple relevant post-authentication data of the target company within the selected data time range from the blockchain subsystem (150) ; Retrieve multiple database indexes from the multiple post-authentication data; query the database (123) according to the multiple database indexes to read multiple records of the target company from the database (123) Qualified raw data; and automatically convert the multiple qualified raw data into a specific CSR project data report corresponding to the target company according to a predetermined report production rule, and use the CSR data report service for the specific CSR project data report The subsystem (110) is transmitted to the demand-side device (105). 如請求項3所述的CSR資料認證系統(100),其中,該CSR數據報告服務子系統(110)在接收到該需求端裝置(105)的請求後,會傳送一詢問信息給該企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。 The CSR data authentication system (100) according to claim 3, wherein the CSR data reporting service subsystem (110) will send an inquiry message to the enterprise end after receiving the request from the demand end device (105) Device (101) to inquire whether the target company agrees that the CSR data reporting service subsystem (110) provides relevant specific CSR project data reports to the user of the demand-side device (105), and only after receiving the enterprise-side device ( 101) In the case of a consent message, the CSR data reporting service subsystem (110) will transmit the report preparation request to the authentication subsystem (120). 如請求項2所述的CSR資料認證系統(100),其中,倘若一需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標 企業相應的一特定CSR項目數據報告,該CSR數據報告服務子系統(110)會產生並傳送與該目標企業相應的一報告製作請求給該認證子系統(120),而該認證子系統(120)還設置成執行該電腦程式產品(126)以進行以下運作:從該報告製作請求中取得一選定資料時間範圍以及一個或多個選定資料項目;從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內對應選定資料項目的多筆相關認證後資料;從該多筆認證後資料中擷取出多筆資料庫索引;根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給該需求端裝置(105)。 The CSR data authentication system (100) according to claim 2, wherein, if a demand-side device (105) requests the CSR data reporting service subsystem (110) to provide the target A specific CSR project data report corresponding to the enterprise, the CSR data reporting service subsystem (110) will generate and transmit a report production request corresponding to the target enterprise to the authentication subsystem (120), and the authentication subsystem (120) ) Is also configured to execute the computer program product (126) to perform the following operations: obtain a selected data time range and one or more selected data items from the report creation request; read from the blockchain subsystem (150) Extract multiple related post-authentication data corresponding to the selected data item within the selected data time range of the target company; extract multiple database indexes from the multiple post-authentication data; query the database based on the multiple database indexes (123) to read multiple eligible original data of the target company from the database (123); and automatically convert the multiple eligible original data into corresponding to the target company according to a predetermined report making rule A specific CSR project data report of the data report, and the specific CSR project data report is transmitted to the demand-side device (105) through the CSR data report service subsystem (110). 如請求項5所述的CSR資料認證系統(100),其中,該CSR數據報告服務子系統(110)在接收到該需求端裝置(105)的請求後,會傳送一詢問信息給該企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。 The CSR data authentication system (100) according to claim 5, wherein the CSR data reporting service subsystem (110) will send an inquiry message to the enterprise end after receiving the request from the demand end device (105) Device (101) to inquire whether the target company agrees that the CSR data reporting service subsystem (110) provides relevant specific CSR project data reports to the user of the demand-side device (105), and only after receiving the enterprise-side device ( 101) In the case of a consent message, the CSR data reporting service subsystem (110) will transmit the report preparation request to the authentication subsystem (120). 一種用於一CSR資料認證系統(100)中的認證子系統(120),其中,該CSR資料認證系統(100)包含一CSR數據報告服務子系統(110)以及一區塊鏈子系統(150),且該CSR數據報告服務子系統(110)在接收到一目標企業的CSR原始資料後,會將該CSR原始資料傳送給該認證子系統(120),該認證子系統(120)包含: 一通信電路(121),設置成可透過網路與該CSR數據報告服務子系統(110)以及該區塊鏈子系統(150)進行資料通信;一儲存電路(122),用於儲存一電腦程式產品(126);一資料庫(123);以及一處理電路(125),耦接於該通信電路(121)與該儲存電路(122);其中,該處理電路(125)設置成執行該電腦程式產品(126)以進行以下運作:從該CSR原始資料中篩選出可供認證的適格原始資料,並將該適格原始資料儲存到該資料庫(123)中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及利用該通信電路(121)將該去識別化資料及相應的該資料庫索引傳送至該區塊鏈子系統(150),並指示該區塊鏈子系統(150)執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統(150)產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統(120)所對應的一認證機構的電子簽章。 An authentication subsystem (120) used in a CSR data authentication system (100), wherein the CSR data authentication system (100) includes a CSR data reporting service subsystem (110) and a blockchain subsystem (150) And after the CSR data reporting service subsystem (110) receives the original CSR data of a target company, it will send the original CSR data to the authentication subsystem (120), the authentication subsystem (120) includes: A communication circuit (121) is configured to communicate with the CSR data reporting service subsystem (110) and the blockchain subsystem (150) through the network; a storage circuit (122) is used to store a computer program Product (126); a database (123); and a processing circuit (125) coupled to the communication circuit (121) and the storage circuit (122); wherein, the processing circuit (125) is configured to execute the computer The program product (126) is used to perform the following operations: filter out the qualified raw data for certification from the CSR raw data, and store the qualified raw data in the database (123); generate the corresponding qualified raw data Database index; remove the identifiable data from the eligible original data to generate de-identified data; and use the communication circuit (121) to send the de-identified data and the corresponding database index to the blockchain subsystem (150) and instruct the blockchain subsystem (150) to execute one or more smart contracts to authenticate the de-identified data; wherein, if the de-identified data meets the verification rules in the one or more smart contracts, Then the blockchain subsystem (150) generates and stores a post-authentication data, and the post-authentication data includes the de-identification data, the database index, and the electronic information of a certification body corresponding to the authentication subsystem (120). signature. 如請求項7所述的認證子系統(120),其中,該處理電路(125)還設置成執行該電腦程式產品(126)以進行以下運作:建立並將該一個或多個智能合約佈署至該區塊鏈子系統(150),且該一個或多個智能合約的其中之一包含該電子簽章。 The authentication subsystem (120) according to claim 7, wherein the processing circuit (125) is also configured to execute the computer program product (126) to perform the following operations: create and deploy the one or more smart contracts To the blockchain subsystem (150), and one of the one or more smart contracts includes the electronic signature. 如請求項8所述的認證子系統(120),其中,倘若一需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告,該CSR數據報告服務子系統(110)會產生並傳送與該目標企業相應的一報告製作請求給該認 證子系統(120),而該處理電路(125)還設置成執行該電腦程式產品(126)以進行以下運作:從該報告製作請求中取得一選定資料時間範圍;從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內的多筆相關認證後資料;從該多筆認證後資料中擷取出多筆資料庫索引;根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給該需求端裝置(105)。 The authentication subsystem (120) according to claim 8, wherein if a demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target company, the The CSR data reporting service subsystem (110) will generate and send a report production request corresponding to the target company to the certification The certificate subsystem (120), and the processing circuit (125) is also configured to execute the computer program product (126) to perform the following operations: obtain a selected data time range from the report creation request; from the blockchain subsystem ( 150) read out multiple related post-authentication data of the target company within the selected data time range; extract multiple database indexes from the multiple post-authentication data; query the data according to the multiple database indexes Database (123) to read multiple eligible original data of the target company from the database (123); and automatically convert the multiple eligible original data into corresponding to the target according to a predetermined report production rule A specific CSR project data report of the enterprise, and the specific CSR project data report is transmitted to the demand-side device (105) through the CSR data reporting service subsystem (110). 如請求項9所述的認證子系統(120),其中,該CSR數據報告服務子系統(110)在接收到該需求端裝置(105)的請求後,會傳送一詢問信息給對應於該目標企業的一企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。 The authentication subsystem (120) according to claim 9, wherein the CSR data reporting service subsystem (110), after receiving the request from the demand-side device (105), will send an inquiry message to the corresponding target An enterprise-end device (101) of an enterprise inquires whether the target enterprise agrees to the CSR data reporting service subsystem (110) to provide relevant specific CSR project data reports to the user of the demand-end device (105), and only after receiving In the case of a consent message from the enterprise device (101), the CSR data reporting service subsystem (110) will transmit the report preparation request to the authentication subsystem (120). 如請求項8所述的認證子系統(120),其中,倘若一需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告,該CSR數據報告服務子系統(110)會產生並傳送與該目標企業相應的一報告製作請求給該認證子系統(120),而該認證子系統(120)還設置成執行該電腦程式產品(126)以進行以下運作:從該報告製作請求中取得一選定資料時間範圍以及一個或多個選定 資料項目;從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內對應選定資料項目的多筆相關認證後資料;從該多筆認證後資料中擷取出多筆資料庫索引;根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給該需求端裝置(105)。 The authentication subsystem (120) according to claim 8, wherein if a demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target company, the The CSR data reporting service subsystem (110) will generate and send a report production request corresponding to the target company to the authentication subsystem (120), and the authentication subsystem (120) is also set to execute the computer program product (126) ) To perform the following operations: obtain a selected data time range and one or more selected data from the report production request Data items; read multiple related post-authentication data corresponding to the selected data item within the selected data time range of the target company from the blockchain subsystem (150); extract multiple pieces of post-authentication data from the multiple post-authentication data Database index; query the database (123) according to the multiple database indexes to read multiple eligible original data of the target company from the database (123); and according to a predetermined report production rule, Automatically convert the multiple eligible raw data into a specific CSR project data report corresponding to the target company, and send the specific CSR project data report to the demand-side device (105) through the CSR data reporting service subsystem (110) ). 如請求項11所述的認證子系統(120),其中,該CSR數據報告服務子系統(110)在接收到該需求端裝置(105)的請求後,會傳送一詢問信息給對應於該目標企業的一企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。 The authentication subsystem (120) according to claim 11, wherein the CSR data reporting service subsystem (110), after receiving the request from the demand-side device (105), will send an inquiry message to the corresponding target An enterprise-end device (101) of an enterprise inquires whether the target enterprise agrees to the CSR data reporting service subsystem (110) to provide relevant specific CSR project data reports to the user of the demand-end device (105), and only after receiving In the case of a consent message from the enterprise device (101), the CSR data reporting service subsystem (110) will transmit the report preparation request to the authentication subsystem (120). 一種電腦程式產品(126),儲存在一認證子系統(120)的一儲存電路(122)中,允許該認證子系統(120)進行一CSR認證運作,該CSR認證運作包含:從該認證子系統(120)所接收到的一目標企業的CSR原始資料中,篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫(123)中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及利用一通信電路(121)將該去識別化資料及相應的該資料庫索引 傳送至一區塊鏈子系統(150),並指示該區塊鏈子系統(150)執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統(150)產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統(120)所對應的一認證機構的電子簽章。 A computer program product (126) is stored in a storage circuit (122) of a certification subsystem (120), allowing the certification subsystem (120) to perform a CSR certification operation. The CSR certification operation includes: From the CSR original data of a target company received by the system (120), select the eligible original data that can be authenticated, and store the eligible original data in a database (123); generate corresponding original data Database index; remove the identifiable data in the eligible original data to generate de-identified data; and use a communication circuit (121) to use the de-identified data and the corresponding database index Send to a blockchain subsystem (150), and instruct the blockchain subsystem (150) to execute one or more smart contracts to authenticate the de-identified data; wherein, if the de-identified data matches the one or more According to the verification rules in the smart contract, the blockchain subsystem (150) generates and stores a post-authentication data, and the post-authentication data includes the de-identification data, the database index, and the authentication subsystem (120) The electronic signature of a corresponding certification body. 如請求項13所述的電腦程式產品(126),其中,該CSR認證運作還包含:建立並將該一個或多個智能合約佈署至該區塊鏈子系統(150),且該一個或多個智能合約的其中之一包含該電子簽章。 The computer program product (126) according to claim 13, wherein the CSR certification operation further includes: establishing and deploying the one or more smart contracts to the blockchain subsystem (150), and the one or more One of the smart contracts contains the electronic signature. 如請求項14所述的電腦程式產品(126),其中,該CSR認證運作還包含:從一CSR數據報告服務子系統(110)傳來與該目標企業相應的一報告製作請求中取得一選定資料時間範圍;利用該通信電路(121)從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內的多筆相關認證後資料;從該多筆認證後資料中擷取出多筆資料庫索引;根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給一需求端裝置(105)。 The computer program product (126) according to claim 14, wherein the CSR certification operation further includes: obtaining a selection from a report production request corresponding to the target enterprise from a CSR data reporting service subsystem (110) Data time range; use the communication circuit (121) to read multiple relevant post-authentication data of the target company within the selected data time range from the blockchain subsystem (150); from the multiple post-authentication data Retrieve multiple database indexes; query the database (123) according to the multiple database indexes to read multiple eligible original data of the target company from the database (123); and according to a predetermined Report production rules, automatically convert the multiple eligible raw data into a specific CSR project data report corresponding to the target company, and send the specific CSR project data report to a demand through the CSR data reporting service subsystem (110) End device (105). 如請求項15所述的電腦程式產品(126),其中,當該需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告時,該CSR數據報告服務子系統(110)會傳送一詢問信息給對應於該目標企業的一企業端裝置 (101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。 The computer program product (126) according to claim 15, wherein when the demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target company, The CSR data reporting service subsystem (110) will send an inquiry message to an enterprise device corresponding to the target enterprise (101) to inquire whether the target enterprise agrees to the CSR data reporting service subsystem (110) to provide relevant specific CSR project data reports to the user of the demand-side device (105), and only after receiving the enterprise-side device (101) In the case of a consent message from ), the CSR data reporting service subsystem (110) will transmit the report preparation request to the authentication subsystem (120). 如請求項14所述的電腦程式產品(126),其中,該CSR認證運作還包含:從一CSR數據報告服務子系統(110)傳來與該目標企業相應的一報告製作請求中取得一選定資料時間範圍以及一個或多個選定資料項目;利用該通信電路(121)從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內對應選定資料項目的多筆相關認證後資料;從該多筆認證後資料中擷取出多筆資料庫索引;根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給一需求端裝置(105)。 The computer program product (126) according to claim 14, wherein the CSR certification operation further includes: obtaining a selection from a report production request corresponding to the target enterprise from a CSR data reporting service subsystem (110) Data time range and one or more selected data items; using the communication circuit (121) to read from the blockchain subsystem (150) the multiple related data items corresponding to the selected data item within the selected data time range of the target company Post-authentication data; retrieve multiple database indexes from the multiple post-authentication data; query the database (123) according to the multiple database indexes to read the target company from the database (123) Multiple pieces of eligible raw data; and according to a predetermined report production rule, automatically convert the multiple pieces of eligible raw data into a specific CSR project data report corresponding to the target company, and report the specific CSR project data through the CSR The data report service subsystem (110) is transmitted to a demand-end device (105). 如請求項17所述的電腦程式產品(126),其中,當該需求端裝置(105)請求該CSR數據報告服務子系統(110)提供與該目標企業相應的一特定CSR項目數據報告時,該CSR數據報告服務子系統(110)會傳送一詢問信息給對應於該目標企業的一企業端裝置(101),以詢問該目標企業是否同意該CSR數據報告服務子系統(110)提供相關特定CSR項目數據報告給該需求端裝置(105)的用戶,且只有在接收到該企業端裝置(101)傳來的一同意信息的 情況下,該CSR數據報告服務子系統(110)才會傳送該報告製作請求給該認證子系統(120)。 The computer program product (126) according to claim 17, wherein when the demand-side device (105) requests the CSR data reporting service subsystem (110) to provide a specific CSR project data report corresponding to the target company, The CSR data reporting service subsystem (110) will send an inquiry message to an enterprise-end device (101) corresponding to the target company to inquire whether the target company agrees with the CSR data reporting service subsystem (110) to provide relevant specific CSR project data is reported to the user of the demand-side device (105), and only after receiving a consent message from the enterprise-side device (101) In this case, the CSR data reporting service subsystem (110) will transmit the report production request to the authentication subsystem (120). 一種CSR資料認證方法,包含:從接收到的一目標企業的CSR原始資料中,篩選出可供認證的適格原始資料,並將該適格原始資料儲存到一資料庫(123)中;產生與該適格原始資料相應的資料庫索引;去除該適格原始資料中的可識別資料,以產生去識別化資料;以及利用一通信電路(121)將該去識別化資料及相應的該資料庫索引傳送至一區塊鏈子系統(150),並指示該區塊鏈子系統(150)執行一個或多個智能合約以認證該去識別化資料;其中,倘若該去識別化資料符合該一個或多個智能合約中的查核規則,則該區塊鏈子系統(150)產生並儲存一認證後資料,且該認證後資料包含該去識別化資料、該資料庫索引、以及該認證子系統(120)所對應的一認證機構的電子簽章。 A CSR data authentication method includes: screening out eligible raw data for authentication from received CSR raw data of a target company, and storing the eligible raw data in a database (123); The corresponding database index of the qualified original data; remove the identifiable data from the qualified original data to generate de-identified data; and use a communication circuit (121) to transmit the de-identified data and the corresponding database index to A blockchain subsystem (150), and instructs the blockchain subsystem (150) to execute one or more smart contracts to authenticate the de-identified data; wherein, if the de-identified data conforms to the one or more smart contracts According to the verification rules in, the blockchain subsystem (150) generates and stores a post-authentication data, and the post-authentication data includes the de-identification data, the database index, and the corresponding authentication subsystem (120) An electronic signature of the certification body. 如請求項19所述的CSR資料認證方法,該CSR資料認證方法還包含:建立並將該一個或多個智能合約佈署至該區塊鏈子系統(150),且該一個或多個智能合約的其中之一包含該電子簽章。 For the CSR data authentication method described in claim 19, the CSR data authentication method further includes: establishing and deploying the one or more smart contracts to the blockchain subsystem (150), and the one or more smart contracts One of them contains the electronic signature. 如請求項20所述的CSR資料認證方法,該CSR資料認證方法還包含:從一CSR數據報告服務子系統(110)傳來與該目標企業相應的一報告製作請求中取得一選定資料時間範圍;利用該通信電路(121)從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內的多筆相關認證後資料;從該多筆認證後資料中擷取出多筆資料庫索引;根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR 項目數據報告透過該CSR數據報告服務子系統(110)傳送給一需求端裝置(105)。 For the CSR data authentication method described in claim 20, the CSR data authentication method further includes: obtaining a selected data time range from a report production request corresponding to the target enterprise from a CSR data reporting service subsystem (110) ; Use the communication circuit (121) to read from the blockchain subsystem (150) multiple pieces of relevant post-authentication data of the target company within the selected data time range; extract multiple pieces of post-authentication data from the multiple pieces of authentication data Database index; query the database (123) according to the multiple database indexes to read multiple eligible original data of the target company from the database (123); and according to a predetermined report production rule , Automatically convert the multiple qualified original data into a specific CSR project data report corresponding to the target company, and convert the specific CSR The project data report is transmitted to a demand-side device (105) through the CSR data report service subsystem (110). 如請求項20所述的CSR資料認證方法,該CSR資料認證方法還包含:從一CSR數據報告服務子系統(110)傳來與該目標企業相應的一報告製作請求中取得一選定資料時間範圍以及一個或多個選定資料項目;利用該通信電路(121)從該區塊鏈子系統(150)中讀取出該目標企業在該選定資料時間範圍內對應選定資料項目的多筆相關認證後資料;從該多筆認證後資料中擷取出多筆資料庫索引;根據該多筆資料庫索引查詢該資料庫(123),以從該資料庫(123)中讀取出該目標企業的多筆適格原始資料;以及根據一預定的報告製作規則,將該多筆適格原始資料自動轉換成對應於該目標企業的一特定CSR項目數據報告,並將該特定CSR項目數據報告透過該CSR數據報告服務子系統(110)傳送給一需求端裝置(105)。 For the CSR data authentication method described in claim 20, the CSR data authentication method further includes: obtaining a selected data time range from a report production request corresponding to the target enterprise from a CSR data reporting service subsystem (110) And one or more selected data items; using the communication circuit (121) to read multiple related post-authentication data corresponding to the selected data item from the blockchain subsystem (150) of the target company within the selected data time range ; Retrieve multiple database indexes from the multiple post-authentication data; query the database (123) according to the multiple database indexes to read multiple records of the target company from the database (123) Qualified raw data; and automatically convert the multiple qualified raw data into a specific CSR project data report corresponding to the target company according to a predetermined report production rule, and use the CSR data report service for the specific CSR project data report The subsystem (110) is transmitted to a demand-end device (105).
TW107125261A 2018-07-20 2018-07-20 Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method TWI698768B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW107125261A TWI698768B (en) 2018-07-20 2018-07-20 Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW107125261A TWI698768B (en) 2018-07-20 2018-07-20 Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method

Publications (2)

Publication Number Publication Date
TW202008202A TW202008202A (en) 2020-02-16
TWI698768B true TWI698768B (en) 2020-07-11

Family

ID=70413071

Family Applications (1)

Application Number Title Priority Date Filing Date
TW107125261A TWI698768B (en) 2018-07-20 2018-07-20 Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method

Country Status (1)

Country Link
TW (1) TWI698768B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112926085B (en) * 2021-03-05 2023-06-20 合肥都市链情商务有限公司 Database data storage and tamper-proof system and method based on blockchain contracts

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TW561381B (en) * 2002-02-27 2003-11-11 Oneempower Pte Ltd Activity management method
TWI528217B (en) * 2014-07-02 2016-04-01 柯呈翰 A method and system for adding dynamic labels to a file and encrypting the file
TWM543422U (en) * 2016-12-09 2017-06-11 富邦產物保險股份有限公司 Decentralized insurance reward system

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TW561381B (en) * 2002-02-27 2003-11-11 Oneempower Pte Ltd Activity management method
TWI528217B (en) * 2014-07-02 2016-04-01 柯呈翰 A method and system for adding dynamic labels to a file and encrypting the file
TWM543422U (en) * 2016-12-09 2017-06-11 富邦產物保險股份有限公司 Decentralized insurance reward system

Also Published As

Publication number Publication date
TW202008202A (en) 2020-02-16

Similar Documents

Publication Publication Date Title
US10705801B2 (en) Data processing systems for identity validation of data subject access requests and related methods
WO2022179008A1 (en) Supply chain finance ai daas algorithm warehouse platform based on blockchain
US11204970B2 (en) Real-time outage analytics and reliability benchmarking system
CN103473672A (en) System, method and platform for auditing metadata quality of enterprise-level data center
Lu et al. Blockchain technology for projects: A multicriteria decision matrix
CN111062690A (en) User purchase management system based on block chain technology
CN104363255A (en) Distributive patent service system
CN115168460A (en) Data processing method, data transaction system, device and storage medium
Klerman et al. Understanding The Current Population Survey's Insurance Estimates And The Medicaid ‘Undercount’ People can't accurately recall their insurance status when asked by the Census Bureau's survey takers—so these widely quoted estimates may be substantially off.
Sargent Replacing financial audits with blockchain: the verification issue
TWI698768B (en) Csr data verification system with tamper-proof capability, related verification party subsystem, computer program product, and data verification method
Jacobs The importance of the quality of electronic records management in enhancing accountability in the South African public service: a case study of a national department
Dong et al. Managing participants’ behaviors: A framework to improve the process efficiency of transport public-private partnerships
Damle et al. Problems with the e-Courts data
Pakenaite et al. Investigation of the Blockchain’s influence on traditional banking: challenges and opportunities
Chu et al. Bye audit! A novel blockchain-based automated data processing scheme for bank audit confirmation
Pham Surveying the state of data curation: a review of policy and practice in UK HEIs
Akmal et al. Transparency in healthcare reporting: the case of external contractors and consultants in New Zealand’s healthcare system
Wong et al. Assessing the adoption of Blockchain Technology in Smart Sustainable Cities: insights from construction practitioners in Malaysia
Tuffrey et al. Assessment of monitoring systems in the management of severe acute malnutrition in northern Nigeria
Prabawati et al. Analysis of Village Governments’ E-Readiness in Developing Villages E-monographs
US11985139B2 (en) Systems, methods, apparatuses and computer program products for executing data verification operations between independent computing resources
Zahid Towards a continuous process auditing framework (case study in healthcare auditing and decision support-infection regime control survey)
Katembwe Assessing the Technological Landscape: ICT Tools and Technologies for Citizen-Government Communication and Their Level of Maturity
Tartan A Blockchain-Based Welfare Distribution Model for Digital Inclusivity