Asset management system based on Internet of Things

By installing asset identity chips on assets and generating verifiable handover records, the problem of identity chain breakage during cross-system asset transfers is solved, achieving identity continuity and data integrity in the asset management system, and ensuring the traceability and reliability of asset management.

CN121685133APending Publication Date: 2026-03-17HANGZHOU HUIXIJIN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511735255.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-25
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing systems struggle to maintain identity continuity during asset circulation, especially when transferring assets across systems. The integrity and traceability of asset data are difficult to verify, leading to identity gaps and disputes.

Method used

The asset identity chip is used for physical binding. Verifiable handover records are generated through edge gateways and handheld witness devices. During cross-domain transfers, dual signatures are performed and the records are uploaded to the cross-domain ledger. The chip's current response is combined with historical verification to ensure the integrity and immutability of the records.

Benefits of technology

It ensures the continuity of asset identity during cross-system transfers, guarantees the verifiability and immutability of records, meets the needs of cross-domain collaboration and evidence review, and achieves management with clear sources, traceable processes, and identifiable responsibilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121685133A_ABST
    Figure CN121685133A_ABST
Patent Text Reader

Abstract

The invention discloses an asset management system based on the Internet of Things, and belongs to the technical field of asset management, and the system specifically comprises the steps: installing an asset identity chip on an asset, and forming verifiable physical binding; the edge gateway initiates response verification on the chip, generates an initial handover record, a record position, a department and a keeper, and writes the record into a cross-domain account book; respectively signing chip responses by the original management domain and the new management domain during cross-domain transfer, generating a double-signature handover record, uploading the record, stopping using an old voucher and binding the new management domain; a witness abstract is generated and cached in a transportation off-network stage, an edge gateway additionally records an uplink after network access, and a time window is bridged; during management domain query, the edge gateway collects all handover records, generates a state packet in combination with the current response of the chip, and restores a complete history according to a time sequence; and triggering a chip termination instruction during scrap recovery, outputting a termination declaration, generating a handover termination record by the edge gateway, and uploading the handover termination record to complete asset identity state storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of asset management technology, and more specifically to an asset management system based on the Internet of Things. Background Technology

[0002] Throughout an asset's lifecycle, it may undergo various state transitions, including location relocation, change of ownership, leasing, transfer, or disposal. Existing systems typically use static tags as unique asset identifiers, but the binding of this identifier to the physical entity lacks verifiable continuity. Once an asset leaves its original network environment during circulation, its trusted identity chain is broken. Further complicating matters, when assets are reintegrated into different IoT systems, the integrity and traceability of the original data become difficult to verify. Maintaining identity continuity during cross-system transfers throughout the asset lifecycle, ensuring that the asset's entire historical state is verifiable and tamper-proof across any management domain, remains a deep-seated problem in the industry that has yet to be systematically solved. Summary of the Invention

[0003] The purpose of this invention is to provide an asset management system based on the Internet of Things (IoT) to solve the technical problems in the background art: The objective of this invention can be achieved through the following technical solutions: An Internet of Things (IoT) based asset management system includes: The identity binding module is used to install an asset identity chip on the asset, write a key and number, fix it with a tamper-proof connection, and trigger an invalidation flag when disassembled to form a verifiable physical binding. The initial access module is used by the edge gateway to initiate response verification to the chip, generate an initial handover record, record the location, department, and custodian, and write it into the cross-domain ledger; The cross-domain handover module is used to have the original management domain and the new management domain sign the chip response respectively during cross-domain transfer, generate a double-signed handover record and put it on the chain, deactivate the old certificate and bind it to the new management domain; The offline witnessing module is used to read the chip digest and tamper seal status by handheld witnessing devices during the offline transportation phase, generate a witnessing digest and cache it, and then be added to the chain by the edge gateway after the network is connected, thus bridging the time gap. The historical verification module is used to collect all handover records from the edge gateway when querying in any management domain, combine them with the chip's current response to generate a status packet, and provide verification playback to restore the complete history in chronological order; The termination and sealing module is used to trigger a chip termination command during scrapping and recycling, output a termination statement and a final response, and generate a termination handover record by the edge gateway and upload it to the blockchain to complete the sealing of the asset's identity status.

[0004] As a further aspect of the present invention: in the initial access module, the step of the edge gateway initiating a response verification to the chip, generating an initial handover record, recording the location, department, and custodian, and writing it into the cross-domain ledger specifically includes: The edge gateway establishes a temporary security session, sends a query password to the chip, reads the status of the tamper-proof connection and tamper-proof seal, generates a physical status verification value and binds it to the current session; The chip returns a response and a number; the edge gateway integrates the initial query password, response, number, and location, and adds a timestamp to form a draft initial handover record; The edge gateway guides the custodian to verify their identity and confirm their department on the handheld witnessing device, and the witnessing device generates a signature digest and sends it back. The edge gateway incorporates the signature digest into the draft, completes the initial handover record, writes the intra-domain signature into the cross-domain ledger, and writes the record identifier back to the chip.

[0005] As a further aspect of the present invention: the response is session verification data generated by the asset identity chip based on the master key and security algorithm after receiving a query password once; the number is a unique asset number written into the asset identity chip, which remains unchanged throughout the chip's lifecycle and corresponds one-to-one with the asset, used to index the asset's handover records and status in the cross-domain ledger.

[0006] As a further aspect of the present invention: in the cross-domain handover module, the step of having the original management domain and the new management domain sign the chip response during cross-domain transfer, generating a double-signature handover record and uploading it to the blockchain, deactivating the old credential and binding it to the new management domain specifically includes: The original management domain establishes a joint session with the new management domain; the original management domain issues a query password to the chip and receives the chip's response, generates a transfer commitment package containing the asset number, location snapshot information and the original credential fingerprint, and completes the original management domain's signature; The new management domain initiates a review and witnessing process based on the same chip response. It uses a one-time query password to derive a verification string and compares the contents of the transfer commitment package. If they match, the new management domain completes the signing and forms a double-signature handover draft. The edge gateway writes the dual-signature handover draft into the cross-domain ledger and obtains a record identifier; the original management domain issues an old credential deactivation instruction based on the record identifier and writes the deactivation result back to the chip; The new management domain generates a new credential and binds it to the chip number. The new management domain binding instruction is written back to the chip. The edge gateway fills the record identifier and the new credential fingerprint back into the handover record, completing the final on-chaining of the handover record.

[0007] As a further aspect of the present invention: in the offline witnessing module, the step of reading the chip digest and tamper-evident seal status by a handheld witnessing device during the offline transportation phase, generating a witnessing digest and caching it, and then having the edge gateway record and upload it to the chain after network access to bridge the time gap specifically includes: The handheld witnessing device wakes up the chip when offline, reads the chip digest value and the status of the tamper-evident seal, collects the location and time stamp, generates a witness draft and writes it to the local buffer. The witnessing device derives a temporary session based on a one-time query password, encapsulates the witness draft, device serial number and operator signature hash value, generates a witness digest, and performs encrypted caching; After reconnection to the network, the witnessing device submits a witness summary to the edge gateway; the edge gateway verifies the current response and tamper seal status of the chip, generates a supplementary record, and uploads it to the blockchain; The edge gateway links the supplementary records with the previous handover records, associates the location and timestamps with the transportation images, and writes the witness summary identifier back to the chip to close the time gap.

[0008] As a further aspect of the present invention: in the historical verification module, the step of collecting all handover records by the edge gateway during a query in any management domain, generating a status packet by combining it with the current response from the chip, and providing verification playback to restore the complete history in chronological order specifically includes: When the edge gateway receives a query request, it retrieves all handover records and witness summaries of the asset from the cross-domain ledger and establishes a sequential index based on the record identifier and time sequence. The edge gateway sends a query password to the chip to obtain the current response, compares the response with the credential fingerprint and physical status verification value of the latest handover record, and generates a draft status packet. The edge gateway sequentially indexes and drives the verification replay, recalculating each commitment chain and verifying the signature and hash value, while recording the replay log, forming a state packet, and restoring the complete history in chronological order.

[0009] As a further aspect of the present invention: the edge gateway sends a query password to the chip to obtain the current response, compares the response with the credential fingerprint and physical status verification value of the latest handover record, and generates a draft status packet with the following specific content: The edge gateway generates a query password, combines the record identifier and the password into a session factor, sends it to the chip, and locks the corresponding handover record for this comparison. The chip calculates the response based on the master key and sends it back; the edge gateway synchronously reads the tamper seal status, extracts the current physical status verification value, and appends it to the session factor; The edge gateway uses the session factor as the anchor item, compares the response with the credential fingerprint and physical status check value of the latest handover record, organizes the comparison results, and generates a draft state packet.

[0010] As a further aspect of the present invention: in the termination and sealing module, the step of triggering a chip termination command during scrapping and recycling, outputting a termination declaration and a final response, and having the edge gateway generate a termination handover record and upload it to the blockchain to complete the asset identity status sealing specifically includes: In the recycling scenario, the edge gateway verifies the status of the tamper-evident seal and the identity of the recycler, generates a recycling verification factor, establishes a secure session with the asset identity chip, and uses this as the basis for triggering a termination command. The edge gateway sends a termination command to the asset identity chip; the chip generates a final response based on the master key, and at the same time generates a termination statement and a sealed digest, which are returned to the edge gateway and cached. The edge gateway aggregates the termination statement, the last response, and the recovery verification factor, attaches the recovery person's signature, generates a termination handover record, and uploads it to the cross-domain ledger; then it writes the sealing identifier back to the chip, completing the sealing of the asset's identity status.

[0011] The beneficial effects of this invention are: This invention generates an initial handover record upon first access. Cross-domain transfers are solidified by dual signatures from both the original and new management domains. During the offline phase, a witness summary is generated using a handheld witnessing device and supplemented upon reconnection, uploaded to the cross-domain ledger, forming a verifiable record thread. Any query uses the asset number and record identifier as an index, combined with a comparison of the chip's current response. Evidence is anchored at both the blockchain and chip sides, avoiding identity breaches and disputes caused by tag duplication, off-ledger transfers, and verbal confirmations. It unifies people, objects, and records within the same session and cross-domain ledger context: the signatures of the custodian and reclaimer are juxtaposed with domain signatures; witness images and location / time markers are linked by pointers; historical verification allows for sequential playback of the commitment chain and verification of signatures and hash values; termination of sealing closes the lifecycle with the termination statement and the last response. Thus, assets in cross-system transfers achieve clear origins, traceable processes, and assignable responsibility. Off-site handovers, offline transportation, and disposal stages can all be restored and verified, meeting the needs of cross-domain collaboration and evidence verification. Attached Figure Description

[0012] The invention will now be further described with reference to the accompanying drawings.

[0013] Figure 1 This is a schematic diagram of a module of an Internet of Things-based asset management system according to the present invention. Detailed Implementation

[0014] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0015] Please see Figure 1 As shown, the present invention is an asset management system based on the Internet of Things, comprising: The identity binding module is used to install an asset identity chip on the asset, write a key and number, fix it with a tamper-proof connection, and trigger an invalidation flag when disassembled to form a verifiable physical binding. The initial access module is used by the edge gateway to initiate response verification to the chip, generate an initial handover record, record the location, department, and custodian, and write it into the cross-domain ledger; The cross-domain handover module is used to have the original management domain and the new management domain sign the chip response respectively during cross-domain transfer, generate a double-signed handover record and put it on the chain, deactivate the old certificate and bind it to the new management domain; The offline witnessing module is used to read the chip digest and tamper seal status by handheld witnessing devices during the offline transportation phase, generate a witnessing digest and cache it, and then be added to the chain by the edge gateway after the network is connected, thus bridging the time gap. The historical verification module is used to collect all handover records from the edge gateway when querying in any management domain, combine them with the chip's current response to generate a status packet, and provide verification playback to restore the complete history in chronological order; The termination and sealing module is used to trigger a chip termination command during scrapping and recycling, output a termination statement and a final response, and generate a termination handover record by the edge gateway and upload it to the blockchain to complete the sealing of the asset's identity status.

[0016] In the identity binding module, an asset identity chip is installed on the asset, a key and a number are written into it, and it is fixed with a tamper-proof connection. When the asset is disassembled, a failure flag is triggered, thus forming a verifiable physical binding.

[0017] First, a rigid and shielding area on the asset's casing is selected, the contact surface is cleaned and roughened, an insulating underlayer is laid, and the asset identification chip base is placed there. Next, a master key and asset number are written to the asset identification chip using a secure programming tool. The key is used for subsequent challenge-response verification, and the asset number is used for cross-domain ledger indexing. A programming record is generated immediately after programming for traceability. Then, an tamper-proof connection is laid between the chip solder points and the casing. The connection is structurally fixed to the casing using a cured adhesive layer and fasteners. The connection is electrically connected to the chip's fusible contacts, serving as the trigger path for a failure marker. Next, the two ends of the tamper-proof connection are closed to the chip's failure detection pins, controlling the chip to record the initial connectivity state and writing this state along with the asset number into a read-only area. Finally, a shielding cover is installed and sealed with a sealing material. The shielding cover has a disposable sealing strip; removing the seal destroys the integrity of the tamper-proof connection. When the chip detects an abnormal connectivity state, it generates a failure marker and reports it in the next session, allowing the edge gateway to determine whether the physical binding has been compromised. The asset identity chip and the asset shell are bound together in both structural and electrical ways. Any disassembly will trigger a failure flag, thus achieving a verifiable physical binding.

[0018] In the initial access module, the edge gateway initiates a response verification to the chip, generates an initial handover record, records the location, department, and custodian, and writes it into the cross-domain ledger.

[0019] When an asset enters the management domain, the edge gateway first initiates a temporary security session. To prevent external eavesdropping and replay attacks, the edge gateway generates a security query password and sends it to the asset identification chip via a short-range communication channel. Simultaneously, the edge gateway reads the tamper-evident connection status and tamper-evident seal status, obtaining two raw readings of the current physical status. After verifying the consistency of the two readings, the gateway provides a clear physical status verification value and records this verification value along with the current session, forming the session context. In this way, the logical identification on the network side and the physical status on the entity side are synchronously bound, and any subsequent comparison operations are performed within the same session, avoiding the mixing of readings from different times and different statuses.

[0020] After receiving an inquiry password, the asset identity chip calculates a response based on its master key and security algorithm, and sends the response back along with the serial number stored in the chip. Upon receiving the response and serial number, the edge gateway integrates the inquiry password, response, serial number, and asset location, adding a timestamp to the same transaction to form an initial handover record draft. The response in the draft record is session verification data bound to this session, used to prove that the asset identity chip is indeed online and in an undisturbed state; the serial number is a unique asset identifier written into the asset identity chip, remaining unchanged throughout the chip's lifecycle and clearly pointing to a single asset. The edge gateway uses the serial number as the primary key, the timestamp and location as on-site elements, and the response as session verification credentials, enabling the draft to indicate not only what asset it is, but also its current location and physical state.

[0021] The edge gateway guides the custodian to complete identity verification on the handheld witnessing device. The witnessing device determines the current operator's true identity by reading their ID card or verifying their account, and the operator confirms their department on the same interface. After confirmation, the witnessing device sequentially encapsulates the "custodian's identity, department, and operation time" along with the key fields of the aforementioned draft record to generate a signature digest. The signature digest uses a trusted execution environment within the device to retrieve the signature private key, ensuring the traceability of the signature material's origin and the verifiability of the process. Subsequently, the witnessing device sends the signature digest back to the edge gateway. Thus, the information of the person in the handover link is accurately collected and cryptographically solidified, corresponding to the chip response, number, location, and timestamp, avoiding problems such as unclear record subjects or broken responsibility chains. The handheld witnessing device is a portable terminal that can switch between offline and online scenarios, possessing five capabilities: near-field reading and writing, seal retrieval, personnel verification, spatiotemporal data acquisition, and signature caching. It issues interrogation commands via NFC / RFID and reads chip responses, detects the status of tamper-evident seals, records location and time, verifies the operator's identity, and generates and signs witness summaries for offline caching; after joining the network, it transmits the data back to the edge gateway for supplementary recording on the blockchain. Specific device types include ruggedized handheld devices, RFID readers, NFC card readers with mobile phones, ruggedized tablets, and evidence-collecting recorders, etc., which can be selected according to the scenario to meet the process requirements.

[0022] After obtaining the signature digest, the edge gateway incorporates it into the initial handover record draft, forming a complete initial handover record. To ensure the non-repudiation of the record within its management domain, the edge gateway uses the domain's signature key to sign the record, generating a domain signature block. Subsequently, the edge gateway writes the initial handover record with the domain signature block into the cross-domain ledger, using the asset number as the index key. The cross-domain ledger stores fields such as timestamp, location, response, number, custodian, department, and domain signature block, enabling other management domains to independently verify the integrity and origin of the record within their authorized scope. After the cross-domain ledger returns the record identifier, the edge gateway writes this record identifier back to a designated area of ​​the asset identity chip, using it as an anchor point for subsequent queries and concatenation. Through this process, the initial handover record is fixed on a publicly trusted record plane, while the chip side holds an identifier directly pointing to the record, achieving a consistent mapping between on-chain and off-chain data.

[0023] In the cross-domain handover module, during cross-domain transfer, the original management domain and the new management domain sign the chip response respectively, generate a double-signature handover record and upload it to the blockchain, deactivate the old credential and bind it to the new management domain.

[0024] When an asset is to be transferred from the original management domain to the new management domain, both parties establish a joint session through a controlled network. The edge gateway of the original management domain issues a query password to the asset identity chip, which calculates and returns a chip response. Based on this, the original management domain reads the asset's current location, captures a location snapshot, and extracts the original credential fingerprint corresponding to the asset from its own certificate library. Subsequently, the original management domain combines the asset number, location snapshot information, original credential fingerprint, and chip response into a transfer commitment package; the source and collection order of each field are marked within the commitment package for subsequent verification. The original management domain uses its own signing key to sign the transfer commitment package, forming a transfer commitment package signed by the original management domain, which is stored in the context of the joint session for the new management domain to review and verify.

[0025] After the new management domain joins the same federated session, it derives a verification string based on the chip response and one-time query password provided by the original management domain. This string is then used to compare the asset number, location snapshot information, and original credential fingerprint in the transfer commitment package item by item. The new management domain records the comparison order and conclusion locally and writes the session identifier and timestamp used during the comparison process into the verification record. If the comparison is successful, the new management domain uses its own signature key to add its own signature to the transfer commitment package, forming a dual-signature handover draft containing both the original and new management domain signatures. This draft retains the derivation relationship of the chip response and one-time query password, as well as the verification string, to indicate that the two domains have completed the verification and witnessing for the same session and the same chip object. After the draft is generated, the federated session remains active, awaiting subsequent writes and instruction issuance from the edge gateway.

[0026] After receiving the dual-signature handover draft, the edge gateway responsible for writing records writes the draft as a transaction into the cross-domain ledger. The ledger returns a record identifier, which the edge gateway sends back in the federated session and registers in the session caches of both domains. The original management domain identifies the target asset based on the record identifier and issues an old credential deactivation command to the asset identity chip. After completing the deactivation process, the chip generates a deactivation result locally and writes it back to the chip's status area, while simultaneously reporting it to the edge gateway via the session. The edge gateway associates the record identifier with the deactivation result and adds it to the extended fields of the previously written ledger record so that the ledger entry corresponding to the deactivation action can be directly located during subsequent retrievals. At this point, corresponding records for the old credential are formed on both the chip and ledger sides, and the transfer link enters the new credential binding stage.

[0027] After confirming the deactivation of the old credential, the new management domain generates a new credential for the asset and binds the new credential to the chip number. The new management domain writes the binding instruction back to the chip's binding area via a federated session, recording the binding time and session identifier. Subsequently, the edge gateway backfills the record identifier and the new credential fingerprint into the handover record, ensuring the handover record simultaneously contains both the old credential deactivation information and the new credential binding information. After backfilling, the edge gateway submits the final version of the handover record to the cross-domain ledger, marking it as final on-chain, and registers the mapping between the record identifier and the asset number at the query entry points of both domains. Thus, when the transfer process needs to be reviewed subsequently, either management domain can read the complete concatenation of the double-signature handover draft, the old credential deactivation result, and the new credential fingerprint based on the record identifier; the chip side retains the binding instruction and record identifier, facilitating continued response verification and record association within the new management domain, ensuring that management actions after the cross-domain transfer are referenced to the same record thread.

[0028] In the offline witnessing module, during the offline transportation phase, the handheld witnessing device reads the chip digest and tamper seal status, generates a witnessing digest and caches it. After reconnection, the edge gateway records and uploads the digest to the blockchain, bridging the time gap.

[0029] When the asset is offline during transport, the handheld witnessing device is activated in offline mode by the operator to perform on-site reading and writing of the target asset. The device uses a short-range communication channel to wake up the asset's identity chip, sequentially reading the chip digest value and tamper-evident seal status, and recording the location and timestamp on the same interface. To avoid information fragmentation, the device organizes the above readings and markers in a fixed field order to generate a witness draft. The draft includes the source of this data collection, the collection order, and the session start point marker for easy verification later. After the draft is generated, it is written to a local buffer, which is indexed by asset number for unified submission after network access.

[0030] To seamlessly integrate offline data collection with subsequent verification, the witnessing device derives a temporary session based on a single query password and binds this session to the newly generated witness draft. The device reads its own serial number and guides the operator to complete identity verification on its own machine, outputting the operator's signature hash value. Subsequently, the device encapsulates the witness digest in the order of "session identifier—draft—device serial number—operator signature hash value" to form a witness digest. The witness digest is encrypted and protected for integrity within the device's trusted area, and the digest generation time and location are recorded synchronously. After completion, the witness digest enters an encrypted cache state, awaiting submission to the edge gateway when the network recovers.

[0031] After the transportation link is restored, the witnessing device submits a witness summary to the edge gateway in the first available network window. The edge gateway retrieves the corresponding asset information based on the session identifier in the summary, sends a query password to the chip to obtain the chip's current response, and reads the tamper-evident seal status on-site to verify the authenticity and continuity of the offline data collection. After successful verification, the edge gateway generates a supplementary record based on the witness summary and the current reading, and writes the supplementary record into the cross-domain ledger as in-transit evidence for this transportation phase. The supplementary record retains the session identifier, summary fingerprint, and generation time to facilitate establishing a sequential relationship with subsequent records.

[0032] To present a complete timeline of the transportation process, the edge gateway links the newly generated supplementary records with previous handover records based on time and record identifiers. It also associates location, time stamps, and transportation images with each supplementary record, forming a clear record chain. For easy on-site verification, the edge gateway writes the witness summary identifier back to a designated area on the asset identity chip, ensuring the chip side and the ledger side share the same anchor point. Subsequent queries of the asset in any management domain can locate the supplementary record based on its record identifier, enabling a corresponding display of content collected during the offline phase and verified content during the online phase, thus eliminating time gaps in the transportation process at the record level.

[0033] In the historical verification module, when querying in any management domain, the edge gateway collects all handover records, combines them with the chip's current response to generate a status packet, and provides verification playback to restore the complete history in chronological order.

[0034] When a query request is issued from any management domain, the edge gateway first parses the asset number and the identity of the queryer in the request. After successful verification, it enters the data aggregation process. Using the asset number as the search key, the edge gateway reads all handover records and witness summaries related to that asset in batches from the cross-domain ledger. To avoid time misalignment caused by cross-domain synchronization, the edge gateway simultaneously retrieves the record identifier, record source, generation time, record type, and on-chain sequence marker for each record and temporarily stores these fields on disk. Subsequently, the edge gateway constructs a sequential index based on the correlation between record identifiers and the chronological relationship of generation times. The sequential index uses record identifiers as the main thread and chronological order as the sorting criterion, forming a record chain that starts from the initial handover record, runs through cross-domain handovers, offline witness supplementation, and termination sealing. To maintain index stability, the edge gateway performs deduplication for duplicate entries of the same record identifier, marks missing adjacent identifiers as placeholders, and associates witness summaries with handover records of the corresponding time period. Once completed, the sequential index serves as the base sequence for this query, and all subsequent calculations and verifications revolve around this sequence, ensuring that the generated results are consistent with existing records in the ledger.

[0035] After establishing the sequential index, the edge gateway enters the on-site verification process. The edge gateway generates a query password and combines the record identifier with this password to form a session factor. Using the session factor as the unique anchor for this session, it sends this information to the asset identity chip via a short-range communication channel, while simultaneously locking the latest handover record in the sequential index as the comparison target. Upon receiving the query password, the asset identity chip calculates a response based on its internal master key and security algorithm, and sends this response back along with the asset number stored on the chip. After receiving the response, the edge gateway reads the tamper-evident seal status within the same session, extracts the current physical status verification value according to a preset algorithm, and appends this verification value to the session factor, forming a complete on-site data set. Subsequently, using the session factor as the anchor, the edge gateway performs a correspondence comparison between the chip response and the credential fingerprint stored in the latest handover record, and simultaneously performs a consistency comparison between the current physical status verification value and the physical status verification value stored in that handover record. If both sets of comparisons match the anchored items, the edge gateway compiles a list of fields verified, comparison conclusions, and session timestamps, assembling them into a draft status packet. The draft status packet includes the asset number, session factor, chip response, credential fingerprint reference, current physical status checksum, target record identifier, physical status checksum reference of the target record, comparison conclusion, and generation time. To facilitate subsequent playback, the edge gateway establishes a subordinate relationship between the draft status packet and the sequential index, and records the location marker and operator identifier of the draft's generation, ensuring the draft has a clear source and destination in the query chain.

[0036] After the state packet draft is generated, the edge gateway initiates the verification replay process. Driven by the sequential index, the edge gateway reads each handover record and witness digest sequentially, starting from the head of the chain. It recalculates the commitment field of each record and verifies the signature and hash value within the record. The recalculation of the commitment field follows the original field organization and hash order of the record. During verification, the public key of the corresponding management domain is used to verify the signature, and the recalculated hash value is compared item by item with the hash value stored in the record. After each record verification is completed, the edge gateway writes the record identifier, the input field digest used for recalculation, the verification result, and the replay timestamp to the replay log, and establishes a link between this log entry and the corresponding node in the sequential index. When replaying the latest handover record, the edge gateway cross-references the session factor in the state packet draft with the commitment field of that node to confirm that the target record on which the draft depends is consistent with the corresponding node on the replay chain. Subsequently, the edge gateway merges the replay log, the sequential index, and the state packet draft to form the final state packet. The status packet uses a sequential index as its main thread, replay logs as evidence, and a draft as the carrier of the verification result at the current point in time. Structurally, it includes a continuous relationship between the link start point, key handover nodes, offline witness supplementation nodes, and the latest node, and lists a mapping table of asset numbers and record identifiers at the end. The edge gateway outputs this status packet in chronological order, allowing the querying party to browse from the starting record to the latest record and view the corresponding signature verification result and hash value recalculation result at any node. Through the above implementation method, the querying party can perform verification replay based on the same sequential index in any management domain and clarify the complete context of asset handover and witnessing according to the chronological order presented in the status packet. At the same time, the status packet retains the correspondence between the session factor and the current response, ensuring that the verification result at the current point in time is consistent with the historical link, facilitating the reuse of the logs and indexes from this replay in the query, thereby maintaining the continuity and clarity of the query process.

[0037] In the termination and sealing module, when the asset is scrapped and recycled, a chip termination command is triggered, a termination statement and a final response are output, and the edge gateway generates a termination handover record and uploads it to the blockchain to complete the sealing of the asset's identity status.

[0038] When an asset enters the disposal and recycling process, on-site personnel activate the recycling mode of the edge gateway at the recycling point. The edge gateway first reads the task information and asset number, verifying the physical item against the recycling list. Then, the edge gateway contacts the asset identification chip via a short-range communication channel, obtains the tamper seal status reading, and records the recycler's identification, recycling time, and recycling location. Based on this information, the edge gateway calculates and generates a "recycling verification factor," which consists of a recycler's identity summary, time and location markers, a tamper seal status summary, and the asset number, used to identify the prerequisites for this recycling action. To ensure clear attribution of subsequent instructions and data, the edge gateway establishes a secure session with the asset identification chip based on the recycling verification factor and asset number, generates a session identifier, and fixes the aforementioned readings and markers in the session context. After confirming that the recycling verification factor meets the recycling rules, the edge gateway uses it as the basis for triggering a termination command, entering the termination process's instruction phase.

[0039] After a secure session is established, the edge gateway sends a "termination command" to the asset identity chip. This command instructs the chip to end its active state in the management system and generate corresponding termination data. Upon receiving the termination command, the asset identity chip, following its built-in process, first calculates a "last response" for the current session based on the master key and security algorithm. This response is bound to the session identifier and reflects the chip's final presence verification result before termination. Subsequently, the chip generates a "termination declaration" based on a fixed field template, recording the asset number, session identifier, termination timestamp, and reference information related to the tamper-evident seal status. Simultaneously, the chip calculates an "archive digest," which is used to extract and archive the termination status at the chip and physical sides. After completing the calculation, the chip returns the "last response, termination declaration, and archive digest" to the edge gateway. The edge gateway receives and verifies the integrity of the returned data and its session matching relationship, writes the above three pieces of data into the gateway's buffer, archives them together with the retrieval verification factor and session identifier, and awaits the generation of a termination handover record and submission to the cross-domain ledger.

[0040] The edge gateway retrieves the "Termination Declaration, Last Response, Archive Summary," and "Recycling Verification Factor" from the cache and guides the recycler to complete the signature confirmation at the on-site terminal, generating a "Recycler Signature." The edge gateway assembles these elements into a "Termination Handover Record" according to a predetermined field order. The record body includes the asset number, session identifier, recycling verification factor, termination declaration, archive summary, last response, and recycler signature, along with the generation time and record source marker. After the record is generated, the edge gateway uploads the termination handover record to the cross-domain ledger using the asset number as the index key, obtains the record identifier, and binds and registers the record identifier with the session identifier for subsequent retrieval and verification. After the upload is completed, the edge gateway interacts with the asset identity chip using the same session, writing the "Archived Identifier" back to the designated area of ​​the chip, indicating that the identity status of the asset corresponding to the chip has entered the archive state. The write-back process records the write-back time and record identifier reference to ensure consistency between the chip side and the ledger side. At this point, a one-to-one correspondence is established between the termination data of the asset at the recycling node and the on-chain record. When the querying party accesses the asset in any management domain, it can locate the termination handover record based on the record identifier. On the chip side, the appearance and interaction restrictions of the termination state are maintained based on the sealing identifier, forming a state mapping with the cross-domain ledger.

[0041] The foregoing has provided a detailed description of one embodiment of the present invention, but this description is merely a preferred embodiment and should not be construed as limiting the scope of the invention. All equivalent variations and modifications made within the scope of the claims of this invention should still fall within the patent coverage of this invention.

Claims

1. An Internet of Things based asset management system characterized in that, The application comprises: An identity binding module for installing an asset identity chip on an asset, writing a key and a number, adopting a tamper-proof connection to fix and trigger a failure marker when disassembled, forming a verifiable physical binding; A first access module for initiating a response check by an edge gateway to the chip, generating an initial handover record, recording the location, the department to which it belongs, and the custodian, and writing into a cross-domain ledger; A cross-domain handover module for signing the chip response separately by the original management domain and the new management domain when transferring across domains, generating a double-signed handover record and chaining, disabling the old certificate and binding the new management domain; An offline witnessing module for reading the chip summary and the tamper-proof seal status by a handheld witnessing device during the transportation offline stage, generating a witnessing summary and caching, and supplementing and chaining by the edge gateway after entering the network, filling the time gap; A history verification module for collecting all handover records by the edge gateway when queried by any management domain, generating a state package in combination with the current response of the chip, and providing a verification playback, and restoring the complete history in chronological order; A termination storage module for triggering a chip termination instruction when recycling, outputting a termination statement and the last response, generating a termination handover record by the edge gateway and chaining, and completing the asset identity state storage.

2. The asset management system based on the Internet of Things according to claim 1, characterized in that, In the first access module, the edge gateway initiates a response check to the chip, generates an initial handover record, records the location, the department to which it belongs, and the custodian, and writes into a cross-domain ledger, which specifically comprises: The edge gateway establishes a temporary secure session, issues a one-time challenge password to the chip, reads the tamper-proof connection and tamper-proof seal status, generates a physical state check value and binds it to the current session; The chip returns the response and the number; the edge gateway integrates the one-time challenge password, the response, the number, and the location, and adds a timestamp to form an initial handover record draft; The edge gateway guides the custodian to verify the custodian's identity and confirm the department on the handheld witnessing device, and the witnessing device generates a signed summary and returns it; The edge gateway incorporates the signed summary into the draft, completes the initial handover record, writes it into the cross-domain ledger after completing the intra-domain signature, and writes the record identifier back to the chip.

3. The asset management system based on the Internet of Things according to claim 2, characterized in that, The response is the session check data generated based on the main key in the chip and the security algorithm after the asset identity chip receives the one-time challenge password; the number is the unique number of the asset written into the asset identity chip, which remains unchanged during the chip's life cycle and corresponds to the asset one by one, and is used to index the handover record and the state of the asset in the cross-domain ledger.

4. The asset management system based on the Internet of Things according to claim 1, characterized in that, In the cross-domain handover module, the original management domain and the new management domain establish a joint session; the original management domain issues a one-time challenge password to the chip and receives the chip response, generates a transfer commitment package containing the asset number, location snapshot information, and original certificate fingerprint, and completes the original management domain signature; The new management domain initiates a review witness based on the same chip response, uses the one-time challenge password to derive a check string, compares the contents of the transfer commitment package, and completes the new management domain signature after consistency, forming a double-signed handover draft; ​ The edge gateway writes the draft of the double signature handover into the cross-domain ledger and obtains a record identifier; the original management domain issues a old certificate disable instruction according to the record identifier, and writes the disable result back to the chip; The new management domain generates a new certificate and binds it with the chip number, and writes the new management domain binding instruction back to the chip; the edge gateway backfills the record identifier and the new certificate fingerprint into the handover record, and completes the final chaining of the handover record.

5. The asset management system based on the Internet of Things according to claim 1, characterized in that, In the off-network witnessing module, the chip summary and the tamper-evident strip state are read by the handheld witnessing device in the transportation off-network stage, a witnessing summary is generated and cached, and after being online, the edge gateway supplements and chains, and the time gap is filled, which specifically comprises: The handheld witnessing device wakes up the chip in the offline state, reads the chip summary value and the tamper-evident strip state, collects the location and time mark, generates a witnessing draft and writes it into the local buffer; The witnessing device generates a witnessing summary based on a one-time challenge password, encapsulates the witnessing draft, device serial number and operator signature hash value, generates a witnessing summary, and performs encrypted caching; After recovering online, the witnessing device submits the witnessing summary to the edge gateway; the edge gateway reviews the current response of the chip and the tamper-evident strip state, generates a supplement record and chains it, and writes the witnessing summary identifier back to the chip, filling the time gap. In the history verification module, the edge gateway collects all handover records when queried in any management domain, generates a state package combined with the current response of the chip, and provides a verification playback, and restores the complete history in chronological order, which specifically comprises:

6. The asset management system based on the Internet of Things according to claim 1, characterized in that, The edge gateway retrieves all handover records and witnessing summaries of the asset from the cross-domain ledger when receiving a query request, and establishes a sequence index according to the record identifier and time sequence; The edge gateway issues a one-time challenge password to the chip to obtain the current response, compares the response with the certificate fingerprint and physical state verification value of the latest handover record, and generates a state package draft; The edge gateway drives the verification playback according to the sequence index, recalculates the commitment chain piece by piece and verifies the signature and hash value, records the playback log at the same time, forms a state package, and restores the complete history in chronological order. The specific content of the edge gateway issuing a one-time challenge password to the chip to obtain the current response, comparing the response with the certificate fingerprint and physical state verification value of the latest handover record, and generating a state package draft is:

7. The asset management system based on the Internet of Things according to claim 6, characterized in that, The edge gateway generates a one-time challenge password, combines the record identifier and the password into a session factor, issues it to the chip, and locks the handover record corresponding to this comparison; The chip calculates the response based on the master key and returns it; The edge gateway synchronously reads the tamper-evident strip state, extracts the current physical state verification value, and appends it to the session factor; The edge gateway compares the response with the certificate fingerprint and physical state verification value of the latest handover record based on the session factor as the anchor, sorts the comparison results, and generates a state package draft. In the termination and sealing module, the chip termination instruction is triggered when the asset is scrapped and recycled, the termination statement and the last response are output, the edge gateway generates a termination handover record and chains it, and completes the sealing of the asset identity state, which specifically comprises:

8. The asset management system based on the Internet of Things according to claim 1, characterized in that, ​ In the recycling scenario, the edge gateway verifies the status of the anti-disassembly strip and the identity of the recycling person, generates a recycling verification factor, establishes a secure session with the asset identity chip, and uses it as the basis for triggering termination instructions; The edge gateway issues termination instructions to the asset identity chip. The chip generates a final response based on the master key, generates a termination statement and an archive digest, and returns them to the edge gateway for caching. The edge gateway collects the termination statement, the final response, and the recycling verification factor, and attaches the recycling person's signature to generate a termination handover record, which is then chained to the cross-domain ledger. Subsequently, the archive identifier is written back to the chip, completing the asset identity state archiving.