如何提升Hyperledger Composer框架中资产类实体的审计追踪可用性?
Let’s walk through how to set up an audit trail that tracks all creation and update transactions for your assets, participants, and other modifiable entities—with easy, efficient querying built in.
Core Overview
The goal is to tie every transaction that creates or modifies an entity directly to that entity’s ID, so you can quickly pull up all related transactions for auditing. To make this work, we’ll extend Hyperledger Composer’s system transactions with a dedicated field to store associated entity identities.
Step-by-Step Implementation
Extend System Transaction Types: Add a
resourcesIdentitiesarray field (of typeString) to these key system transactions:org.hyperledger.composer.system.CreateAssetorg.hyperledger.composer.system.UpdateAssetorg.hyperledger.composer.system.CreateParticipantorg.hyperledger.composer.system.UpdateParticipant
This array will hold the unique ID(s) of the entity being created or updated in each transaction.
Auto-Populate the Field: Ensure that whenever an entity is created or updated, the corresponding transaction’s
resourcesIdentitiesfield gets automatically filled with the entity’s ID. For example:- When creating an asset with ID
supplyChainAsset_001, theCreateAssettransaction’sresourcesIdentitieswill includesupplyChainAsset_001. - Every subsequent update to that asset will add the same ID to the
UpdateAssettransaction’sresourcesIdentitiesarray.
- When creating an asset with ID
Querying for Audit Trails
Once the field is in place, you can use Composer Query Language (CQSL) to retrieve all transactions related to a specific entity. Here are practical examples:
- To get all update transactions for an asset with ID
supplyChainAsset_001:SELECT org.hyperledger.composer.system.UpdateAsset WHERE (resourcesIdentities CONTAINS 'supplyChainAsset_001') - To get all creation and update transactions for a participant with ID
vendor_AcmeCorp:SELECT org.hyperledger.composer.system.CreateParticipant, org.hyperledger.composer.system.UpdateParticipant WHERE (resourcesIdentities CONTAINS 'vendor_AcmeCorp')
Coverage for All Modifiable Entities
Make sure this setup applies to every entity type you need to audit:
- Assets: Track all creation and modification transactions for every asset in your network.
- Participants: Include participant entities (like vendors, users, or organizations) so you can audit changes to their details as well.
- If you have custom transaction types that modify entities, extend those too with the
resourcesIdentitiesfield to maintain full audit coverage.
内容的提问来源于stack exchange,提问作者Paul Grindean

