An Enterprise Asset Protection Method and System Based on Blockchain Technology

By introducing a dual private key signature mechanism in blockchain technology, the transaction data is judged and the secondary signature is verified, the problem of asset losses caused by private key loss is solved, and the security protection of enterprise assets is achieved.

CN112150148BActive Publication Date: 2025-07-18GUANGZHOU IND CONTROL ASSET MANAGEMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011014489.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-24
Publication Date
2025-07-18
Estimated Expiration
2040-09-24

AI Technical Summary

Technical Problem

In blockchain technology, the loss or theft of enterprise private keys leads to asset loss, especially in exchanges and DApp projects. The existing technology cannot effectively prevent asset losses caused by inadvertent storage of private keys.

Method used

The dual private key signature mechanism is used to determine whether the transaction data is enterprise transaction data by obtaining the source address of the transaction data. If it is enterprise transaction data, the secondary signature data will be obtained and the consistency is verified with the preset verification signature data. Only after legal approval is approved, otherwise it will be discarded or signed by the enterprise administrator's public key and then turned on.

Benefits of technology

Even if the private key of the enterprise sub-account is lost, assets can be prevented. The dual private key signature mechanism ensures the security of enterprise assets and avoids the risks caused by single private key signature.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112150148B_ABST
    Figure CN112150148B_ABST
Patent Text Reader

Abstract

The present invention discloses an enterprise asset protection method based on blockchain technology, comprising the following steps: obtaining transaction data, wherein the transaction data includes a source address, primary signature data and secondary signature data; judging whether the transaction data is enterprise transaction data according to the source address; when the transaction data is enterprise transaction data, obtaining the secondary signature data and judging whether the secondary signature data is an empty set; when the secondary signature data is not an empty set, judging whether the secondary signature data is consistent with preset verification signature data; when the secondary signature data is consistent with the verification signature data, determining that the transaction data is legal approval data and allowing the transaction data to be packaged and chained. The technical solution of the present invention can achieve that even if the private key of a sub-account of an enterprise is lost, the assets of the sub-account will not be lost, and the operation that could be completed by single private key signature originally is transformed into an operation that requires double private key signatures to be completed, thereby ensuring the security of enterprise assets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain, and in particular, to an enterprise asset protection method and system based on blockchain technology. Background Art

[0002] Blockchain technology is a brand-new distributed infrastructure and computing method that uses a block chain data structure to verify and store data, uses a distributed node consensus algorithm to generate and update data, uses cryptography to ensure the security of data transmission and access, and uses smart contracts composed of automated script codes to program and operate data.

[0003] As an enterprise service of blockchain, private keys are often used for signature processing during application. Therefore, many current enterprises will store the account private keys on the server, which can reduce manual operations and workload, and at the same time, some automated operations can be carried out.

[0004] However, directly storing the private key on the server is very likely to result in the loss or theft of the private key due to improper custody, which will inevitably lead to the loss of enterprise assets.

[0005] In addition, if an enterprise needs an approval process, generally it can only be approved through business logic and finally signed with a unified public key. For example, in the related business of an exchange. In order to distinguish user recharge, the exchange will generate a unique recharge account for each user on the background service, and the recharge account is generally stored on the server.

[0006] As is well known, there have been many incidents where the exchange server was hacked and assets were stolen. Each time a theft incident occurs, it will bring huge losses to the exchange.

[0007] In the entire blockchain system, the private key is the controller of the entire account. Having the private key means having the entire account assets.

[0008] For enterprises, there are generally the following requirements:

[0009] First, private key signatures and other situations are often involved in enterprise project services. If each operation is carried out manually, the workload will be very large, and the efficiency is relatively low, and automated processing cannot be achieved. Therefore, currently, enterprises will directly store some private keys on the server to allow the program to sign automatically.

[0010] Second, due to business requirements, approval processing may be required. However, there may be only one private key for final processing, so decentralized approval cannot be achieved. Generally, it is business logic approval, and after the approval is completed, the final private key signature processing is started.

[0011] Third, due to the improper custody of the private key, the private key is lost, resulting in the loss of assets.

[0012] Especially for exchanges and DApp projects, the secure management of assets is particularly important. Incidents of asset loss or theft in exchanges are not uncommon, and there have also been many cases where the servers of DApp project parties were hacked and private keys were lost, resulting in asset losses.

[0013] Therefore, it is necessary to provide a new enterprise asset protection method and system based on blockchain technology to solve the above technical problems. Summary of the Invention

[0014] The main purpose of the present invention is to provide a method and system for implementing a synchronization node that synchronizes data on demand, aiming to solve the technical problem in related technologies where the loss of private keys leads to the loss of enterprise assets.

[0015] To achieve the above object, the present invention provides an enterprise asset protection method based on blockchain technology, including the following steps:

[0016] Obtain transaction data, where the transaction data includes a source address, primary signature data, and secondary signature data;

[0017] According to the source address, determine whether the transaction data is enterprise transaction data;

[0018] When the transaction data is enterprise transaction data, obtain the secondary signature data and determine whether the secondary signature data is an empty set;

[0019] When the secondary signature data is not an empty set, determine whether the secondary signature data is consistent with the preset verification signature data;

[0020] When the secondary signature data is consistent with the verification signature data, determine that the transaction data is legal approval data and allow the transaction data to be packaged and uploaded to the blockchain.

[0021] Preferably, after the step of determining whether the transaction data is enterprise transaction data according to the source address, the following steps are further included:

[0022] When the transaction data is not enterprise transaction data, directly package the transaction data and upload it to the blockchain.

[0023] Preferably, after the step of obtaining the secondary signature data and determining whether the secondary signature data is an empty set when the transaction data is enterprise transaction data, the following steps are further included:

[0024] When the secondary signature data is an empty set, sign the transaction data with the public key of the enterprise administrator and package the signed transaction data and upload it to the blockchain.

[0025] Preferably, after the step of determining whether the secondary signature data is consistent with the preset verification signature data when the secondary signature data is not an empty set, the following steps are further included:

[0026] When the secondary signature data is inconsistent with the verification signature data, determine that the transaction data is illegal approval data, and perform the operation of discarding the transaction data.

[0027] To solve the above technical problems, the present invention also provides an enterprise asset protection system based on blockchain technology, including:

[0028] An acquisition module, which is used to acquire transaction data, where the transaction data includes a source address, primary signature data, and secondary signature data;

[0029] A source judgment module, which is used to judge whether the transaction data is enterprise transaction data according to the source address;

[0030] A first judgment module, which is used to, when the transaction data is enterprise transaction data, acquire the secondary signature data and judge whether the secondary signature data is an empty set;

[0031] A second judgment module, which is used to, when the secondary signature data is not an empty set, judge whether the secondary signature data is consistent with the preset verification signature data;

[0032] A blockchain module, which is used to, when the secondary signature data is consistent with the verification signature data, determine that the transaction data is legal approval data and allow the transaction data to be packaged and uploaded to the blockchain.

[0033] Preferably, the first judgment module is further used to directly package and upload the transaction data when the transaction data is not enterprise transaction data.

[0034] Preferably, the second judgment module is further used to sign the transaction data with the public key of the enterprise administrator and package and upload the signed transaction data when the secondary signature data is an empty set.

[0035] Preferably, the blockchain module is further used to determine that the transaction data is illegal approval data and perform the operation of discarding the transaction data when the secondary signature data is inconsistent with the verification signature data.

[0036] The enterprise asset protection method based on blockchain technology provided by the present invention obtains transaction data; determines whether the transaction data is enterprise transaction data according to the source address; when the transaction data is enterprise transaction data, obtains the secondary signature data and determines whether the secondary signature data is an empty set; when the secondary signature data is not an empty set, determines whether the secondary signature data is consistent with the preset verification signature data; when the secondary signature data is consistent with the verification signature data, determines that the transaction data is legal approval data and allows the transaction data to be packaged and uploaded to the blockchain. The present invention provides an enterprise asset protection method based on blockchain technology. Through the technical solution of the present invention, it can be achieved that even if the private key of the sub-account of an enterprise is lost, the assets of the sub-account will not be lost. The operation that could originally be completed with a single private key signature is transformed into an operation that requires a double private key signature, thereby ensuring the security of enterprise assets. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 It is a flowchart of the operation of a relatively optimal embodiment of the enterprise asset protection method based on blockchain technology provided by the present invention;

[0038] Figure 2 It is an architecture diagram of a relatively optimal embodiment of the enterprise asset protection system based on blockchain technology provided by the present invention.

[0039] The implementation, functional features and advantages of the object of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0041] For the convenience of understanding the technical solution of the present invention, the following related technologies are introduced.

[0042] I. ICAP Interchange Client Address Protocol.

[0043] ICAP Interchange Client Address Protocol. An IBAN-compatible system for referencing and processing customer accounts, aiming to simplify the fund transfer process and be carefree between exchanges. And finally using KYC and AML is called the past.

[0044] The ICAP Interchange Client Address Protocol generally consists of several parts: project code, check code, asset identifier, institution code, customer identifier.

[0045] Taking the Ethereum ICAP address format as an example: XE81ETHXREGGAVOFYORK

[0046] Among them:

[0047] XE: Represents the Ethereum chain;

[0048] 81: Checksum;

[0049] ETH: Asset identifier in the customer account;

[0050] XREG: Institutional code of the account;

[0051] GAVOFRYORK: Customer identifier within the institution.

[0052] II. Account Address.

[0053] The account address uses the ICAP protocol rules, but does not involve asset identification.

[0054] The account address consists of the following: chain prefix + checksum + enterprise institutional code + base36 encoding of the actual address of the account.

[0055] Generally, accounts on the chain are divided into two types: personal accounts and enterprise accounts.

[0056] Therefore, a default institutional code needs to be reserved to identify personal accounts. For example, assuming the enterprise institutional code is 4 digits in length, it can be assumed that the institutional code "0000" represents personal accounts, and other institutional codes represent different enterprise accounts.

[0057] During use, it is necessary to pre-set the public key of the enterprise administrator corresponding to the institutional code using the administrator account and write the corresponding data into the blockchain.

[0058] III. Transaction Data Structure

[0059] The transaction data structure on the chain needs to include several parts: from (source address), originSign (initial signature data), and secondSign (secondary signature data).

[0060] Among them, the from address conforms to the above address rules;

[0061] originSign is the signature content of the entire transaction by the from address;

[0062] secondSign is the signature of the entire transaction containing originSign by the enterprise administrator account corresponding to the institutional code.

[0063] The present invention provides a method for protecting enterprise assets based on blockchain technology.

[0064] Please refer to Figure 1 , to achieve the above object, in an embodiment of the present invention, a method 100 for protecting enterprise assets based on blockchain technology includes the following steps:

[0065] S10. Obtain transaction data, where the transaction data includes a source address, primary signature data, and secondary signature data;

[0066] S20. Determine whether the transaction data is enterprise transaction data according to the source address;

[0067] Specifically, extract the institution code from the source address, and determine whether the transaction data corresponding to the source address is enterprise transaction data by determining whether the institution code is an enterprise institution code.

[0068] S30. When the transaction data is enterprise transaction data, obtain the secondary signature data and determine whether the secondary signature data is an empty set;

[0069] Specifically, it may be defined that the institution code corresponding to an individual is "0000", and other institution codes represent different enterprise accounts.

[0070] When the institution code extracted from the source address is not "0000", it can be determined that the transaction data corresponding to the source address is enterprise transaction data. Correspondingly, the chain can obtain the public key of the enterprise administrator corresponding to the institution code from the institution library.

[0071] S40. When the secondary signature data is not an empty set, determine whether the secondary signature data is consistent with the preset verification signature data;

[0072] It can be understood that the preset verification signature data is obtained by signing the primary signature data with the public key of the enterprise administrator.

[0073] S50. When the secondary signature data is consistent with the verification signature data, determine that the transaction data is legal approval data and allow the transaction data to be packaged and chained.

[0074] After the step S20, the enterprise asset protection method 100 based on blockchain technology further includes the following steps:

[0075] S31. When the transaction data is not enterprise transaction data, directly package the transaction data and chain it;

[0076] After the step S30, the enterprise asset protection method 100 based on blockchain technology further includes the following steps:

[0077] S41. When the secondary signature data is an empty set, sign the transaction data with the public key of the enterprise administrator and package the signed transaction data and chain it;

[0078] After the step S40, the enterprise asset protection method 100 based on blockchain technology further includes the following steps:

[0079] S51, when the secondary signature data is inconsistent with the verification signature data, determine that the transaction data is illegal approval data, and perform the operation of discarding the transaction data.

[0080] The present invention provides an enterprise asset protection method based on blockchain technology. Through the technical solution of the present invention, it can be realized that even if the private key of the sub-account of the enterprise is lost, the assets of the sub-account will not be lost.

[0081] The operation that could originally be completed by single private key signature is transformed into an operation that requires double private key signatures to complete, thereby ensuring the security of enterprise assets.

[0082] The present invention provides an enterprise asset protection system based on blockchain technology.

[0083] Please refer to Figure 2 , to achieve the above object, in an embodiment of the present invention, an enterprise asset protection system based on blockchain technology includes:

[0084] An acquisition module, the acquisition module is used to acquire transaction data, wherein the transaction data includes a source address, primary signature data, and secondary signature data;

[0085] A source judgment module, the source judgment module is used to judge whether the transaction data is enterprise transaction data according to the source address;

[0086] Specifically, an institution code is extracted from the source address, and by judging whether the institution code is an enterprise institution code, it is realized to judge whether the transaction data corresponding to the source address is enterprise transaction data.

[0087] A first judgment module, the first judgment module is used to, when the transaction data is enterprise transaction data, acquire the secondary signature data, and judge whether the secondary signature data is an empty set;

[0088] Specifically, it may be defined that the institution code corresponding to an individual is "0000", and other institution codes represent different enterprise accounts.

[0089] When the institution code extracted from the source address is not "0000", it can be judged that the transaction data corresponding to the source address is enterprise transaction data. Correspondingly, the chain can obtain the public key of the enterprise administrator corresponding to the institution code from the institution library.

[0090] A second judgment module, the second judgment module is used to, when the secondary signature data is not an empty set, judge whether the secondary signature data is consistent with the preset verification signature data;

[0091] It can be understood that the preset verification signature data is obtained by signing the initial signature data with the public key of the enterprise administrator.

[0092] A blockchain module, which is used to determine that the transaction data is legal approval data and allow the transaction data to be packaged and uploaded to the blockchain when the secondary signature data is consistent with the verification signature data.

[0093] Preferably, the first judgment module is further used to directly package and upload the transaction data to the blockchain when the transaction data is not enterprise transaction data;

[0094] Preferably, the second judgment module is further used to sign the transaction data with the public key of the enterprise administrator and package and upload the signed transaction data to the blockchain when the secondary signature data is an empty set;

[0095] Preferably, the blockchain module is further used to determine that the transaction data is illegal approval data and perform the operation of discarding the transaction data when the secondary signature data is inconsistent with the verification signature data.

[0096] The present invention provides an enterprise asset protection system based on blockchain technology. Through the technical solution of the present invention, it can be realized that even if the private key of the sub-account of the enterprise is lost, the assets of the sub-account will not be lost.

[0097] The operation that could originally be completed by single private key signature is transformed into an operation that requires double private key signature to complete, thereby ensuring the security of enterprise assets.

[0098] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a computer-readable storage medium as described above (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to enable a terminal device to enter the methods described in the various embodiments of the present invention.

[0099] In the description of this specification, the descriptions with reference to the terms "one embodiment", "another embodiment", "other embodiments", or "the first embodiment to the Xth embodiment", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, method steps, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0100] It should be noted that in this article, the term "comprising", "including", or any other variant thereof is intended to cover a non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or system. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article, or system comprising such element.

[0101] The serial numbers of the above embodiments of the present invention are only for description and do not represent the superiority or inferiority of the embodiments.

[0102] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.

Claims

1. An enterprise asset protection method based on blockchain technology, characterized in that It includes the following steps: Obtain transaction data, where the transaction data includes a source address, primary signature data, and secondary signature data; the primary signature data is the signature content of the entire transaction by the source address; The secondary signature data is the signature of the entire transaction containing the primary signature data by the enterprise administrator account corresponding to the institution code; Judge whether the transaction data is enterprise transaction data according to the source address; When the transaction data is enterprise transaction data, obtain the secondary signature data and judge whether the secondary signature data is an empty set; When the secondary signature data is not an empty set, judge whether the secondary signature data is consistent with the preset verification signature data; When the secondary signature data is consistent with the verification signature data, determine that the transaction data is legal approval data and allow the transaction data to be packaged and chained; When the secondary signature data is an empty set, sign the transaction data with the enterprise administrator public key and package and chain the signed transaction data.

2. The enterprise asset protection method based on blockchain technology according to claim 1, wherein, After the step of judging whether the transaction data is enterprise transaction data according to the source address, the following steps are further included: When the transaction data is not enterprise transaction data, directly package and chain the transaction data.

3. The enterprise asset protection method based on blockchain technology according to claim 1, wherein After the step of judging whether the secondary signature data is consistent with the preset verification signature data when the secondary signature data is not an empty set, the following steps are further included: When the secondary signature data is not consistent with the verification signature data, determine that the transaction data is illegal approval data and perform the operation of discarding the transaction data.

4. An enterprise asset protection system based on blockchain technology, characterized in that, It includes: An acquisition module, which is used to acquire transaction data, where the transaction data includes a source address, primary signature data, and secondary signature data; the primary signature data is the signature content of the entire transaction by the source address; the secondary signature data is the signature of the entire transaction containing the primary signature data by the enterprise administrator account corresponding to the institution code; A source judgment module, which is used to judge whether the transaction data is enterprise transaction data according to the source address; A first judgment module, which is used to, when the transaction data is enterprise transaction data, obtain the secondary signature data and judge whether the secondary signature data is an empty set; A second judgment module, which is used to, when the secondary signature data is not an empty set, judge whether the secondary signature data is consistent with the preset verification signature data; A chaining module, which is used to, when the secondary signature data is consistent with the verification signature data, determine that the transaction data is legal approval data and allow the transaction data to be packaged and chained; The second judgment module is also used to, when the secondary signature data is an empty set, sign the transaction data with the enterprise administrator public key and package and chain the signed transaction data.

5. The enterprise asset protection system based on blockchain technology according to claim 4, characterized in that The first judgment module is also used to, when the transaction data is not enterprise transaction data, directly package and chain the transaction data.

6. The enterprise asset protection system based on blockchain technology according to claim 4, wherein The chain-up module is further configured to, when the secondary signature data is inconsistent with the verification signature data, determine that the transaction data is illegal approval data and perform an operation of discarding the transaction data.

Citation Information

Patent Citations

  • Method and device for generating blockchain signature data, and blockchain transaction initiation system

    CN111062716A

  • Blockchain-based account protection method and device and blockchain-based transaction verification method and device

    CN111461721A