A data asset trading control method, device, decentralized PUF network, and storage medium

Driven by physical characteristics in the decentralized PUF network, the unclonability and unpredictability of PUF devices are utilized to achieve secure storage and trusted transfer of data asset transactions, solving the problem of insufficient security of data assets in the virtual environment, and ensuring the immutability and credibility of transactions.

CN119762070BActive Publication Date: 2025-07-22GUANGDONG LVSUAN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510259830.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-07-22
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

When existing data assets are stored and traded in a virtual environment, they are insecurity and are vulnerable to hackers and data tampering. There is a single point of failure problem in centralized platforms, insufficient privacy protection and lack of protection against physical attacks.

Method used

Using a decentralized PUF network driven by physical characteristics, the physical unclonability and unpredictability of PUF devices is used to realize the secure storage and transaction control of data assets through digital signatures and verification mechanisms, including receiving transaction information, verifying signatures and point-to-point communication to confirm asset validity.

Benefits of technology

It provides low-cost and high-security data asset transaction control, ensuring the immutability and credibility of transactions, and enhancing the ownership protection and secure transfer of data assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119762070B_ABST
    Figure CN119762070B_ABST
Patent Text Reader

Abstract

The present application relates to a method, apparatus, decentralized PUF network, and readable storage medium for controlling data asset transactions driven by physical characteristics, including: receiving transaction information sent by a transferor of the ownership of a target data asset; sending the transaction information to a verification node, where the verification node is any PUF device in the decentralized PUF network, and the verification node uses the physical characteristics of its own PUF device to drive and verify the transaction signatures of the transferor of the ownership and the transferee of the ownership according to the approval encryption information and the transaction initiation identifier in the transaction information. After the verification is passed, the validity of the target data asset is verified by communicating with the transferor of the ownership, and a verification confirmation information is generated when it is confirmed that the target data asset is valid; when the verification confirmation information of the verification node is received, the ownership of the target data asset is transferred to the transferee of the ownership. The above method can achieve decentralized control of data asset transactions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a data asset transaction control method and device driven by physical properties, a decentralized PUF network, and a readable storage medium. Background Art

[0002] At present, with the rapid development of Internet technology and information society, data assets have gradually become one of the core resources of individuals, enterprises and even countries. Data assets include but are not limited to cryptocurrencies, digital files, electronic contracts, digital identity authentication, etc. These assets are stored and traded in a virtual environment, and their security is crucial to the stability of economic activities and information protection. Although the widespread application of data assets has brought convenience, its security still faces many challenges. The storage and trading of data assets mainly rely on the network environment and are vulnerable to threats such as hacker attacks and data tampering. Many data asset transactions rely on centralized platforms, which not only have single point failure problems, but may also cause user asset losses due to poor internal management or attacks. At the same time, insufficient privacy protection and the lack of protection against physical attacks by existing security mechanisms make it difficult for data assets to protect user privacy and respond to hardware-level attacks.

[0003] PUF technology, with its unique physical properties and security, provides a strong guarantee for the secure storage and transmission of data assets. The Physical Unclonable Function (PUF) feature relies on the chip characteristics and random differences in the manufacturing process, such as the working environment, production process, etc., which generate important information. These random differences make PUF unclonable and unpredictable, and cannot be simulated or copied, providing security for low-cost and high-security identity authentication mechanisms. Summary of the invention

[0004] Based on this, it is necessary to provide a data asset transaction control method, device, decentralized PUF network and readable storage medium driven by physical properties to address the above technical problems. This method can be driven by the physical properties of each PUF device in the decentralized PUF network to achieve decentralized data asset transaction control. The PUF is unclonable and unpredictable, and cannot be simulated or copied, providing security for low-cost and high-security ownership protection and secure transfer of ownership.

[0005] A data asset transaction control method driven by physical characteristics, which is applied to a decentralized PUF network, includes: receiving transaction information sent by a transferor of the ownership of a target data asset. The transaction information includes the target data asset, the transaction signature of the transferor, the transaction signature of the recipient of the ownership of the target data asset, approval encryption information, and a transaction initiation identifier. Both the transferor and the recipient are PUF devices, and the transaction signatures of both the recipient are generated by digitally signing the approval encryption information and the transaction initiation identifier by driving the physical characteristics of their own PUF devices. The approval encryption information is generated based on the transaction initiation identifier, and the transaction initiation identifier is a response generated by the recipient by taking the transaction identifier generated by the transferor as an incentive; sending the transaction information to a verification node. The verification node is any PUF device in the decentralized PUF network. The verification node drives the physical characteristics of its own PUF device and verifies the transaction signature of the transferor and the transaction signature of the recipient according to the approval encryption information and the transaction initiation identifier, and verifies the validity of the target data asset by means of point-to-point communication with the transferor after the verification passes and generates a verification confirmation information when it is confirmed to be valid; when receiving the verification confirmation information of the verification node, transferring the ownership of the target data asset to the recipient.

[0006] In one embodiment, the recipient generates a response by taking the transaction identifier generated by the transferor as an incentive, and sends the generated response to the transferor as the transaction initiation identifier; the transferor takes the response generated by taking the transaction initiation identifier as an incentive as the first key, and takes the response generated by taking the first key as an incentive as the second key, generates approval encryption information according to the first key and the transaction initiation identifier, digitally signs the approval encryption information and the transaction initiation identifier by using its own PUF device to generate the transaction signature of the transferor, and sends the second key and the approval encryption information to the transferor; the recipient verifies the approval encryption information based on the second key, and digitally signs the approval encryption information and the transaction initiation identifier by using its own PUF device to generate the transaction signature of the recipient when it is verified that the approval encryption information contains the transaction initiation identifier.

[0007] In one embodiment, the verification node conducts point-to-point communication with the transferor, requests the public key from the owner transferor, decrypts the target data asset through the public key, compares the decrypted target data asset with the plaintext corresponding to the target data asset pre-stored locally. If the comparison is consistent, it is confirmed that the target data asset is valid; wherein, the target data asset is encrypted by the transferor through the private key corresponding to the public key.

[0008] In one embodiment, the verification node generates a transaction signature field through the hash digest of the transaction information and by using its own PUF device, and the verification confirmation information includes the generated transaction signature field.

[0009] In one embodiment, there are multiple verification nodes. When receiving the verification confirmation information from the verification nodes, transferring the ownership of the target data asset to the recipient includes: when receiving the verification confirmation information from more than a preset number of verification nodes, transferring the ownership of the target data asset to the recipient.

[0010] In one embodiment, the multiple verification nodes are obtained by filtering based on preset conditions, and the preset conditions include any one or more of the geographical location of the PUF device, historical reliability, historical response time, and historical load capacity.

[0011] In one embodiment, the target data asset includes descriptive information of the target data, an ownership identifier of the target data asset, additional attribute information of the target data asset, and historical transaction information of the target data asset.

[0012] A data asset transaction control device driven by physical characteristics, which is applied to a decentralized PUF network, includes a receiving module, configured to receive transaction information sent by the transferor of the ownership of the target data asset. The transaction information includes the target data asset, the transaction signature of the transferor, the transaction signature of the recipient of the ownership of the target data asset, approval encryption information, and a transaction initiation identifier. Both the transferor and the recipient are PUF devices, and the transaction signatures of both are generated by digitally signing the approval encryption information and the transaction initiation identifier using the physical characteristics of their own PUF devices. The approval encryption information is generated based on the transaction initiation identifier, and the transaction initiation identifier is a response generated by the recipient by taking the transaction identifier generated by the transferor as an incentive; a verification module, configured to send the transaction information to a verification node, where the verification node is any PUF device in the decentralized PUF network. The verification node uses the physical characteristics of its own PUF device to drive and verify the transaction signature of the transferor and the transaction signature of the recipient according to the approval encryption information and the transaction initiation identifier, and after passing the verification, verify the validity of the target data asset through point-to-point communication with the transferor and generate a verification confirmation information when it is confirmed to be valid; a transaction transfer module, configured to transfer the ownership of the target data asset to the recipient when receiving the verification confirmation information from the verification node.

[0013] A decentralized PUF network, the decentralized PUF network includes multiple PUF devices, and the multiple PUF devices include a transferor of the ownership of the target data asset, an acceptor of the ownership of the target data asset, and one or more verification nodes and control nodes; the control node receives the transaction information sent by the transferor, and the transaction information includes the target data asset, the transaction signature of the transferor, the transaction signature of the acceptor, the approval encryption information, and the transaction initiation identifier. The transaction signatures of both the transferor and the acceptor are generated by using the physical characteristics of their own PUF devices to drive the digital signature of the approval encryption information and the transaction initiation identifier. The approval encryption information is generated based on the transaction initiation identifier, and the transaction initiation identifier is a response generated by the acceptor by taking the transaction identifier generated by the transferor as an incentive; the control node sends the transaction information to the verification node, and the verification node uses the physical characteristics of its own PUF device to drive and verify the transaction signature of the transferor and the transaction signature of the acceptor according to the approval encryption information and the transaction initiation identifier, and after the verification passes, verifies the validity of the target data asset through point-to-point communication with the transferor and generates a verification confirmation message when it is confirmed to be valid; when the control node receives the verification confirmation message from the verification node, it transfers the ownership of the target data asset to the acceptor.

[0014] A readable storage medium, on which an embedded program is stored, and when the embedded program is executed by a processor, it implements the steps of any one of the methods in the above embodiments.

[0015] The above-mentioned method, device, decentralized PUF network and readable storage medium for controlling data asset transactions driven by physical characteristics receive the transaction information sent by the transferor of the ownership of the target data asset. The transaction information includes the target data asset, the transaction signature of the transferor, the transaction signature of the acceptor of the ownership of the target data asset, the approval encryption information, and the transaction initiation identifier. Both the transferor and the acceptor are PUF devices, and the transaction signatures of both are generated by using the physical characteristics of their own PUF devices to drive the digital signature of the approval encryption information and the transaction initiation identifier. The approval encryption information is generated based on the transaction initiation identifier, and the transaction initiation identifier is a response generated by the acceptor by taking the transaction identifier generated by the transferor as an incentive; send the transaction information to the verification node, the verification node is any PUF device in the decentralized PUF network, the verification node uses the physical characteristics of its own PUF device to drive and verify the transaction signature of the transferor and the transaction signature of the acceptor according to the approval encryption information and the transaction initiation identifier, and after the verification passes, verifies the validity of the target data asset through point-to-point communication with the transferor and generates a verification confirmation message when it is confirmed to be valid; when receiving the verification confirmation message from the verification node, transfer the ownership of the target data asset to the acceptor. Description of the Drawings

[0016] Figure 1Schematic diagram of an application scenario of a data asset transaction control method driven by physical characteristics in an embodiment;

[0017] Figure 2 Schematic flowchart of a data asset transaction control method driven by physical characteristics in an embodiment;

[0018] Figure 3 Interaction schematic diagram of initiating a data asset transaction driven by physical characteristics in an embodiment;

[0019] Figure 4 Schematic flowchart of an ownership transfer mechanism of a data asset driven by physical characteristics in an embodiment;

[0020] Figure 5 Schematic flowchart of ownership verification of a data asset driven by physical characteristics in an embodiment;

[0021] Figure 6 Schematic diagram of a data asset driven by physical characteristics in an embodiment;

[0022] Figure 7 Block diagram of a data asset transaction control device driven by physical characteristics in an embodiment. Detailed implementation manners

[0023] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0024] A data asset transaction control method driven by physical characteristics provided by the present application. In an embodiment, a data asset transaction control method driven by physical characteristics is applied to Figure 1 the application environment shown. As Figure 1As shown, the receiving party of the ownership of the target data asset sends a transaction initiation identifier to the transferring party. The transaction initiation identifier is a response generated by the receiving party incentivized by the transaction identifier generated by the transferring party. The transferring party sends approved encryption information to the receiving party, and the approved encryption information is generated based on the transaction initiation identifier. Furthermore, both the transaction signature of the transferring party and the receiving party use the physical characteristics of their own PUF devices to drive the digital signature of the approved encryption information and the transaction initiation identifier to generate their respective transaction signatures. The transferring party broadcasts the transaction information to the decentralized PUF network. The transaction information includes the target data asset, the transaction signature of the transferring party, the transaction signature of the receiving party of the target data asset, the approved encryption information, and the transaction initiation identifier. The control node broadcasts the transaction information to the verification nodes. The verification nodes are any PUF devices in the decentralized PUF network. The verification nodes use the physical characteristics of their own PUF devices to drive and verify the transaction signature of the transferring party and the transaction signature of the receiving party according to the approved encryption information and the transaction initiation identifier, and verify the validity of the target data asset by means of peer-to-peer communication with the transferring party after the verification passes, and generate a verification confirmation information when the target data asset is confirmed to be valid; when the control node receives the verification confirmation information from the verification node, as Figure 1 shown, execute the ownership transfer mechanism to transfer the ownership of the target data asset to the receiving party. Specifically, as Figure 1 shown, when the target data asset is metadata 1, modify metadata 1, such as modifying the ownership of metadata 1, to obtain metadata 2, and transfer the ownership of metadata 2 to the receiving party.

[0025] In one embodiment, the present application provides a method for controlling data asset transactions driven by physical characteristics, which is applied to Figure 1 the decentralized PUF network shown. Specifically, as Figure 2 shown, a method for controlling data asset transactions driven by physical characteristics includes the following steps:

[0026] S202, receive the transaction information sent by the transferring party of the ownership of the target data asset. The transaction information includes the target data asset, the transaction signature of the transferring party, the transaction signature of the receiving party of the ownership of the target data asset, the approved encryption information, and the transaction initiation identifier. Both the transferring party and the receiving party are PUF devices. The transaction signature of the transferring party and the transaction signature of the receiving party are both generated by using the physical characteristics of their own PUF devices to drive the digital signature of the approved encryption information and the transaction initiation identifier. The approved encryption information is generated based on the transaction initiation identifier. The transaction initiation identifier is a response generated by the receiving party incentivized by the transaction identifier generated by the transferring party.

[0027] In one example, the recipient generates a response incentivized by the transaction identifier generated by the transferor, and sends the generated response to the transferor as the transaction initiation identifier; the transferor uses the response generated by the transaction initiation identifier as the incentive as the first key, and uses the response generated by the first key as the incentive as the second key, generates approval encryption information based on the first key and the transaction initiation identifier, digitally signs the approval encryption information and the transaction initiation identifier using its own PUF device to generate the transferor's transaction signature, and sends the second key and the approval encryption information to the transferor; the recipient verifies the approval encryption information based on the second key, and when it is verified that the approval encryption information contains the transaction initiation identifier, digitally signs the approval encryption information and the transaction initiation identifier using its own PUF device to generate the recipient's transaction signature.

[0028] Specifically, both the transferor and the recipient are PUF (Physical Unclonable Function) devices. PUF technology provides a strong guarantee for the secure storage and transmission of data assets with its unique physical characteristics and security. The physical unclonable function characteristics rely on chip characteristics and random differences during the manufacturing process, such as the working environment, manufacturing process, etc., to generate important information. These random differences make the PUF device have the characteristics of non-clonability and unpredictability, and cannot be simulated and replicated, providing security for the low-cost and high-security identity authentication mechanism. Among them, the generation processes of the transferor's transaction signature, the recipient's transaction signature, the approval encryption information, etc. are as follows:

[0029] As Figure 3 shown, the transferor submits a data asset sale application, stating the asset attributes and transaction conditions, and the trading platform generates a unique transaction identifier and associates it with the application. After the recipient confirms the purchase, it uses its PUF device to generate a unique verifiable identifier based on the transaction identifier, that is, the transaction initiation identifier, and sends it to the transferor.

[0030] After receiving the transaction initiation identifier, the transferor generates the first key, the second key, and the approval encryption information of the transaction through its PUF device. The approval encryption information is encrypted by the first key of the transaction, proving that the transferor has accepted the recipient's order.

[0031] The recipient receives the approval encryption information, verifies the transaction initiation identifier in the decryption result of the approval encryption information, and after confirmation, the two parties transfer the ownership of the data asset. To ensure the verifiability and immutability of the transaction, both parties use the PUF device to digitally sign the transaction initiation identifier and the approval encryption information as a voucher for the ownership change.

[0032] When the recipient and the transferor confirm the transaction, the transferor initiates and generates a transaction information, which contains the key information of this data asset transaction, such as the identities of the two parties to the transaction, the content of the asset being traded, and other attributes. This process ensures that the generation of the transaction information is trustworthy and consistent with the confirmation of both parties.

[0033] S204, send the transaction information to the verification node. The verification node is any PUF device in the decentralized PUF network. The verification node uses the physical characteristics of its own PUF device to drive the verification of the transferor's transaction signature and the recipient's transaction signature according to the approved encryption information and the transaction initiation identifier, and verifies the validity of the target data asset by means of peer-to-peer communication with the transferor after the verification passes, and generates a verification confirmation information when the target data asset is confirmed to be valid.

[0034] In an example, there are multiple verification nodes, which are selected based on preset conditions. The preset conditions include any one or more of the geographical location of the PUF device, historical reliability, historical response time, and historical load capacity. The verification node generates a transaction signature field through the hash digest of the transaction information and uses its own PUF device. The verification confirmation information includes the generated transaction signature field. Among them, when receiving the verification confirmation information of the verification node, transfer the ownership of the target data asset to the recipient, including: when receiving the verification confirmation information of more than the preset number of verification nodes, transfer the ownership of the target data asset to the recipient.

[0035] Specifically, as Figure 4 shown, the verification nodes are selected from the PUF node pool of the decentralized PUF network according to preset conditions. The preset conditions may include factors such as the geographical location of the verification node, historical reliability, response time, load capacity, etc., so as to ensure that the selected verification nodes have sufficient credibility and dispersion in the transaction verification process.

[0036] As Figure 4 shown, once the verification nodes are selected, the transaction information broadcasting module configured in the decentralized PUF network broadcasts the transaction information to these selected verification nodes. Among them, the nodes in the decentralized PUF network communicate in a peer-to-peer manner. The distribution of the broadcast transaction information is not completed by a single node alone, but through the cooperation of all nodes. After receiving the transaction information, these verification nodes generate a transaction signature field by taking the hash digest of the transaction information and using their internal physical characteristics as a challenge. The generation process of this transaction signature field depends on the uniqueness of the PUF device of the verification node, ensuring that the transaction signature fields generated by each verification node are unique and cannot be forged.

[0037] Next, the signature verification module in the decentralized PUF network verifies the generated transaction signature field through the threshold mechanism. The signature verification module is one or more PUF devices selected from the decentralized PUF network, which provide signature verification services for this transaction. The core of the threshold mechanism is that the transaction can only be considered legal if at least more than a preset number of verification nodes successfully verify the transaction signature. To achieve this function, the signature verification module is used to count the number of successfully verified verification nodes and compare this number with the preset threshold through the threshold comparison module. If the number of verified verification nodes reaches or exceeds the threshold, the transaction is considered legal.

[0038] In addition, the transaction information broadcast module in this implementation also supports the selective broadcast function, that is, the transaction information is only sent to specific pre-selected verification nodes, avoiding invalid or redundant broadcasts and improving system efficiency. Finally, each transaction signature field generated by the signature generation module contains a unique tag generated by the verification node, which makes each signature unique and further enhances the immutability of the transaction.

[0039] Therefore, it can effectively ensure that the ownership transfer process of data assets is completed in a trusted and decentralized environment, and each transaction step is independently verified by different PUF nodes, greatly enhancing the security, transparency and reliability of the entire transaction system.

[0040] In one example, the verification node conducts point-to-point communication with the transferor, requests a public key from the transferor of ownership, decrypts the target data asset using the public key, and compares the decrypted target data asset with the plaintext corresponding to the locally pre-stored target data asset. If the comparison is consistent, the target data asset is confirmed to be valid; wherein, the target data asset is encrypted by the transferor using the private key corresponding to the public key.

[0041] Specifically, see Figure 5 As shown, when verifying the digital assets of the target data asset owner, the verification node will receive a transaction signature jointly generated by the previous owner and the current owner of the target data asset. This signature is not only the identity of the two owners, but also a guarantee of the validity of the transaction. The verification node needs to verify the identity of the previous owner, which is achieved through communication with the previous owner. The verification node uses the transaction initiation identifier as a challenge and initiates a verification request to its PUF device, expecting to obtain a response identical to the transaction confirmer. Specifically, the items that need to be verified include the transaction signature and the address information of previous owners, which are all stored in plain text in the metadata of the digital asset.

[0042] Next, the verification node will verify the ownership identifier of the current owner. Here, the current owner in this instance refers to the transferor in this application. This identifier is an encrypted public ciphertext formed by encrypting the private key generated by the current owner's PUF device. To complete this verification, the verification node needs to request the public key from the current owner. After receiving the public key, the verification node will use this public key to decrypt the obtained ciphertext to get the decrypted information, and compare it with the plaintext corresponding to the target digital asset stored by the verification node. If the two are consistent, it indicates that the current owner has a valid ownership of the target digital asset. Specifically, the transferor uses the PUF response generated by its own PUF device as the encryption key. This PUF response is generated by taking the specific identifier obtained in the transaction as a challenge and inputting it into the PUF device, ensuring the uniqueness and security of the key.

[0043] Once all of the above verification processes are successful, the verification node will provide the current owner with the service corresponding to the target data asset. That is, the data asset transaction service in this application. This mechanism not only enhances the security of the target data asset transaction, but also provides the owner with a reliable way to manage their assets, ensuring the authenticity of the identities of all parties and the clarity of ownership throughout the process. Through this rigorous verification process, the effective confirmation of the ownership of the target data asset and the service delivery are ultimately achieved.

[0044] S206. When receiving the verification confirmation information from the verification node, transfer the ownership of the target data asset to the recipient.

[0045] In one example, the target data asset includes the descriptive information of the target data, the ownership identifier of the target data asset, the additional attribute information of the target data asset, and the historical transaction information of the target data asset.

[0046] Specifically, as Figure 6 shown, the target data asset includes the descriptive information of the target data, the ownership identifier of the target data asset, the additional attribute information of the target data asset, and the historical transaction information of the target data asset. Among them:

[0047] Generate the basic information of the target data asset. The descriptive data of each target data asset includes:

[0048] Token_ID: The unique identifier generated for the target data asset; Asset category: Indicates the type to which the target data asset belongs, such as pictures, text files, videos, etc.; Information such as image, author, etc.: According to the specific type of the target data asset, record the corresponding detailed information, such as the name of the image file and the name of the creator.

[0049] Use a PUF device to generate an ownership identifier for each target data asset. The PUF device utilizes the non-clonable characteristics of the physical structure to generate a unique and unpredictable encryption key, which is used to authenticate and confirm the ownership of the target data asset. Specifically, it includes:

[0050] Owner identification information: Assign relevant information of the owner to the target data asset, including the username and their homepage address; Ownership consensus signature: To ensure the uniqueness and legality of ownership, generate a consensus signature and record the ownership changes of each asset transaction; Owner PUF signature: Use the owner's PUF device to generate an encrypted signature to ensure that the ownership of the target data asset is verifiable and tamper-proof throughout its life cycle.

[0051] Set the current status information for each target data asset to indicate whether it is for sale, not for sale, or destroyed in the trading market. The status information is updated in real time by the system to ensure that the trading status of the asset can be queried at any time. Specifically, it includes:

[0052] For-sale status: The target data asset is in the process of being traded and is available for purchase by buyers; Not-for-sale status: The data asset is in a held state and has not yet entered the trading market; Destroyed status: The data asset has been destroyed and cannot be traded again.

[0053] When generating the target data asset, different additional attributes are added to different categories of target data assets. It includes:

[0054] API: Represents the interface address for interacting with the target data asset; URL: Stores the link address of the target data asset or its related resources.

[0055] The transaction history and ownership changes of each target data asset are recorded, and historical ownership information is generated for each transaction to ensure the transparency of ownership tracking. After each transfer of the target data asset, the signature of the new owner will be added to the historical record, including:

[0056] Historical owner information: After each transaction, the system will record the PUF signature of the owner to form an immutable transaction history chain to ensure the traceability of the history of each target data asset.

[0057] In summary, the target data asset includes, but is not limited to, fields such as descriptive data, ownership identifier, ownership history record, and current attribute signature. These fields can effectively indicate the characteristics and current status of the digital asset. Among them, the initialization process of fields such as descriptive data, ownership identifier, ownership history record, and current attribute signature is set by the producer of the target data asset when the target data asset is first generated and is encrypted or tagged by the producer of the target data asset or the PUF device of the receiving asset owner.

[0058] When the verification confirmation information of the verification node is received, transfer the ownership of the target data asset to the recipient. Specifically, as Figure 1 shown, after the verification is passed, trigger the ownership transfer mechanism, confirm the transaction of the target data asset and generate the corresponding signature. Modify the target data asset based on the corresponding signature and transfer its ownership to the recipient. As Figure 1 shown, Metadata 1 is the original target data asset. Modify Metadata 1 based on the signature and modify the ownership attribute of Metadata 1 to obtain Metadata 2. Transfer the ownership of Metadata 2 to the recipient.

[0059] The above method for controlling data asset transactions driven by physical characteristics receives the transaction information sent by the transferor of the ownership of the target data asset. The transaction information includes the target data asset, the transaction signature of the transferor, the transaction signature of the recipient of the ownership of the target data asset, the approval encryption information, and the transaction initiation identifier. Both the transferor and the recipient are PUF devices. The transaction signature of the transferor and the transaction signature of the recipient are both generated by digitally signing the approval encryption information and the transaction initiation identifier using the physical characteristics of their own PUF devices. The approval encryption information is generated based on the transaction initiation identifier. The transaction initiation identifier is a response generated by the recipient by taking the transaction identifier generated by the transferor as an incentive; send the transaction information to the verification node. The verification node is any PUF device in the decentralized PUF network. The verification node uses the physical characteristics of its own PUF device to drive the verification of the transaction signature of the transferor and the transaction signature of the recipient according to the approval encryption information and the transaction initiation identifier, and verifies the validity of the target data asset by means of peer-to-peer communication with the transferor after the verification is passed, and generates a verification confirmation information when the target data asset is confirmed to be valid; when the verification confirmation information of the verification node is received, transfer the ownership of the target data asset to the recipient.

[0060] Regarding the above method for controlling data asset transactions driven by physical characteristics, the following will respectively make relevant descriptions according to the data asset transaction initiation process, the ownership verification process of the data asset, and the ownership transfer mechanism of the data asset:

[0061] A data asset transaction initiation process using physical characteristics provided by an embodiment of the present application. This data asset transaction initiation process ensures the security, uniqueness, and verifiability of the transaction. The transferor and the recipient in the transaction process respectively use PUF devices to generate unique verifiable identifiers and keys to ensure the security and immutability during the transaction process. Specifically, it includes:

[0062] The transferor submits a data asset sale application, which details the attributes and transaction conditions of the data assets to be sold. The provider of the digital assets needs to define the access rules, price, and usage conditions of the data. After receiving the transferor's application, the decentralized PUF network generates a unique and non-repeating transaction identifier and associates it with the transferor's transaction application as the sole identifier for the subsequent transaction process.

[0063] After confirming the purchase intention, the recipient uses its PUF device to generate a unique verifiable identifier, namely the transaction initiation identifier. This identifier is generated by passing the transaction identifier as an input parameter to the recipient's PUF device and generating a response based on the unique physical characteristics inside the device. The unique verifiable transaction initiation identifier is sent to the transferor.

[0064] After receiving the transaction initiation identifier sent by the recipient, the transferor activates its PUF device to generate the first key for the transaction. This process involves passing the unique transaction initiation identifier as an input to the transferor's PUF device, and the PUF device outputs a unique private key value, namely the first key, based on its inherent physical characteristics. At the same time, the transferor also generates the second key for the corresponding transaction and the approval encryption information through the PUF device. The approval encryption information is generated by encrypting the unique transaction initiation identifier using the first key of the transaction. This approval encryption information is used to prove that the transferor has officially received and approved the recipient's purchase request.

[0065] After receiving the approval encryption information and the second key sent by the transferor, the recipient uses its PUF device to perform a decryption operation to verify whether the original unique transaction initiation identifier can be restored from the approval encryption information. If the decryption operation is successful and the decrypted identifier is exactly the same as the original unique transaction initiation identifier, it indicates that the recipient confirms that the transferor is aware of and has accepted the purchase request.

[0066] To ensure the subsequent verifiability and immutability of the transaction process, the transferor and the recipient respectively use their own PUF devices to digitally sign the transaction initiation identifier and the approval encryption information.

[0067] The embodiment of this application provides a data asset ownership transfer mechanism using physical characteristics, which uses physical unclonable function (PUF) technology to ensure the security of transactions and the transparency of ownership. This mechanism aims to ensure the integrity and authenticity of data asset transactions and can effectively verify the legality of transactions in a multi-node environment:

[0068] When the recipient and the transferor confirm the transaction, the control node starts and generates a transaction information, which contains the key information of this data asset transaction, such as the identities of the two parties to the transaction, the content of the assets traded, and other attributes. This process ensures that the generation of the transaction information is credible and consistent with the confirmation of both parties.

[0069] Subsequently, the control node selects several nodes from the PUF node pool according to preset conditions for identity generation. The preset conditions may include factors such as the geographical location of the nodes, historical reliability, response time, load capacity, etc., so as to ensure that the selected nodes have sufficient credibility and dispersion during the transaction verification process.

[0070] Once the nodes are selected, the transaction information broadcasting module broadcasts the transaction information and its hash digest to these selected PUF nodes. After receiving the hash digest of the transaction information, these PUF nodes generate a transaction signature field according to the transaction information and using their internal physical characteristics as a challenge. This signature process relies on the uniqueness of the PUF device to ensure that the transaction signature fields generated by each node are unique and cannot be forged.

[0071] Next, the signature verification module verifies the generated transaction signature fields through a threshold mechanism. The core of the threshold mechanism is that at least more than a preset number of PUF nodes successfully verify the transaction signature before the transaction can be considered legal. To achieve this function, the signature verification module is used to count the number of PUF nodes that successfully verify, and compare this number with the preset threshold through a threshold comparison module. If the number of nodes passing the verification reaches or exceeds the threshold, the transaction is considered legal.

[0072] In addition, the transaction information broadcasting module in this implementation scheme also supports the selective broadcasting function, that is, the transaction information is only sent to specific preselected PUF nodes, avoiding invalid or redundant broadcasts and improving the system efficiency. Finally, each transaction signature field generated by the signature generation module contains a unique tag generated by the PUF node, which makes each signature unique and further enhances the immutability of the transaction.

[0073] Through this implementation scheme, it can effectively ensure that the process of transferring the ownership of data assets is completed in a trusted and decentralized environment. Each transaction step is independently verified by different PUF nodes, greatly enhancing the security, transparency and reliability of the entire transaction system.

[0074] The method for transferring the ownership of data assets provided by the embodiments of this application, which is applied to an encryption device, the method includes:

[0075] When the verification node verifies the data assets of the asset owner, it will receive a transaction signature jointly generated by the previous owner and the current owner. This signature is not only an identity identifier for both owners but also a guarantee of the transaction's validity. The verification node needs to verify the identity of the previous owner, which is achieved through communication with the previous owner. The verification node uses the transaction initiation identifier as a challenge to initiate a verification request to its PUF device, expecting to obtain the same response as the transaction confirmation.

[0076] Next, the verification node will verify the ownership identifier of the current owner. This identifier is an encrypted public ciphertext generated by the private key of the current owner's PUF device. To complete this verification, the verification node needs to request the public key from the current owner. After receiving the public key, the verification node will use the public key to decrypt the obtained ciphertext, obtain the decrypted information, and compare it with the plaintext corresponding to the data asset stored by the verification node. If the two are consistent, it indicates that the current owner has valid ownership of the data asset.

[0077] Once all of the above verification processes are successful, the verification node will provide the corresponding services for the current owner for the data asset. This mechanism not only enhances the security of data asset transactions but also provides a reliable management method for the owner to ensure the authenticity of each party's identity and the clarity of ownership throughout the process. Through this rigorous verification process, the effective confirmation of data asset ownership and service delivery are ultimately achieved.

[0078] It should be understood that although the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the attached drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential either, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0079] The present application also provides a decentralized PUF network. The decentralized PUF network includes multiple PUF devices, and the multiple PUF devices include a transferor of the ownership of the target data asset, a recipient of the ownership of the target data asset, and one or more verification nodes and control nodes. The control node receives the transaction information sent by the transferor. The transaction information includes the target data asset, the transaction signature of the transferor, the transaction signature of the recipient, the approval encryption information, and the transaction initiation identifier. Among them, both the transaction signature of the transferor and the transaction signature of the recipient are generated by digitally signing the approval encryption information and the transaction initiation identifier by driving with the physical characteristics of their own PUF devices. The approval encryption information is generated based on the transaction initiation identifier, and the transaction initiation identifier is a response generated by the recipient by taking the transaction identifier generated by the transferor as an incentive. The control node sends the transaction information to the verification node. The verification node uses the physical characteristics of its own PUF device to drive to verify the transaction signature of the transferor and the transaction signature of the recipient according to the approval encryption information and the transaction initiation identifier, and verifies the validity of the target data asset by means of point-to-point communication with the transferor after the verification passes, and generates a verification confirmation information when it is confirmed that the target data asset is valid. When the control node receives the verification confirmation information from the verification node, it transfers the ownership of the target data asset to the recipient.

[0080] Specifically, the decentralized PUF network is as Figure 1 shown. Among them, for the specific operations of the transferor of the target data asset, the recipient of the target data asset, and one or more verification nodes, control nodes, etc., reference may be made to the relevant descriptions of a method for controlling data asset transactions driven by physical characteristics in the above respective embodiments, which will not be elaborated here.

[0081] The present application also provides a data asset transaction control device driven by physical characteristics, which is applied to a decentralized PUF network. As Figure 7As shown, a data asset trading control device driven by physical characteristics includes a receiving module 702, a verification module 704, and a trading transfer module 706. The receiving module 702 is used to receive trading information sent by the transferor of the target data asset ownership. The trading information includes the target data asset, the trading signature of the transferor, the trading signature of the transferee of the target data asset ownership, the approval encryption information, and the trading initiation identifier. Both the transferor and the transferee are PUF devices, and the trading signatures of both are generated by digitally signing the approval encryption information and the trading initiation identifier using the physical characteristics of their own PUF devices. The approval encryption information is generated based on the trading initiation identifier, and the trading initiation identifier is a response generated by the transferee by taking the trading identifier generated by the transferor as an incentive; The verification module 704 is used to send the trading information to a verification node, where the verification node is any PUF device in the decentralized PUF network. The verification node uses the physical characteristics of its own PUF device to drive and verifies the trading signature of the transferor and the trading signature of the transferee according to the approval encryption information and the trading initiation identifier, and after passing the verification, verifies the validity of the target data asset through point-to-point communication with the transferor and generates a verification confirmation information when it is confirmed to be valid; The trading transfer module 706 is used to transfer the ownership of the target data asset to the transferee when receiving the verification confirmation information from the verification node.

[0082] In one embodiment, the transferee takes the trading identifier generated by the transferor as an incentive to generate a response, and sends the generated response to the transferor as the trading initiation identifier; The transferor takes the response generated by taking the trading initiation identifier as an incentive as the first key, and takes the response generated by taking the first key as an incentive as the second key. The approval encryption information is generated according to the first key and the trading initiation identifier. The transferor's trading signature is generated by digitally signing the approval encryption information and the trading initiation identifier using its own PUF device, and the second key and the approval encryption information are sent to the transferor; The transferee verifies the approval encryption information based on the second key, and when it is verified that the approval encryption information contains the trading initiation identifier, the transferee's trading signature is generated by digitally signing the approval encryption information and the trading initiation identifier using its own PUF device.

[0083] In one embodiment, the verification node conducts point-to-point communication with the transferor, requests the public key from the ownership transferor, decrypts the target data asset with the public key, and compares the decrypted target data asset with the plaintext corresponding to the target data asset pre-stored locally. If the comparison is consistent, it is confirmed that the target data asset is valid; Among them, the target data asset is encrypted by the transferor using the private key corresponding to the public key.

[0084] In one embodiment, the verification node generates a trading signature field through the hash digest of the trading information and using its own PUF device, and the verification confirmation information includes the generated trading signature field.

[0085] In one embodiment, there are multiple verification nodes. When receiving the verification confirmation information from the verification nodes, transferring the ownership of the target data asset to the recipient includes: when receiving the verification confirmation information from more than a preset number of verification nodes, transferring the ownership of the target data asset to the recipient.

[0086] In one embodiment, the multiple verification nodes are obtained by screening based on preset conditions, and the preset conditions include any one or more of the geographical location of the PUF device, historical reliability, historical response time, and historical load capacity.

[0087] In one embodiment, the target data asset includes descriptive information of the target data, an ownership identifier of the target data asset, additional attribute information of the target data asset, and historical transaction information of the target data asset.

[0088] For the specific limitations of a data asset transaction control device driven by physical characteristics, reference can be made to the limitations of a data asset transaction control method driven by physical characteristics in the above text, which will not be elaborated here. Each module in the above data asset transaction control device driven by physical characteristics can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0089] In one embodiment, a readable storage medium is provided, on which an embedded program is stored. When the embedded program is executed by a processor, it implements the data asset transaction control method driven by physical characteristics described in any of the above embodiments.

[0090] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through an embedded program. The embedded program can be stored in a non-volatile computer-readable storage medium. When the embedded program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0091] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0092] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.

Claims

1. A data asset trading control method driven by physical characteristics, characterized in that, Applied to a decentralized PUF network, the method includes: Receiving transaction information sent by a transferor of the ownership of a target data asset. The transaction information includes the target data asset, the transaction signature of the transferor, the transaction signature of the transferee of the ownership of the target data asset, approval encryption information, and a transaction initiation identifier. Both the transferor and the transferee are PUF devices, and the transaction signatures of both are generated by driving the digital signature of the approval encryption information and the transaction initiation identifier using the physical characteristics of their own PUF devices. The approval encryption information is generated based on the transaction initiation identifier, and the transaction initiation identifier is a response generated by the transferee by taking the transaction identifier generated by the transferor as an incentive; Sending the transaction information to a verification node, where the verification node is any PUF device in the decentralized PUF network. The verification node drives using the physical characteristics of its own PUF device and verifies the transaction signature of the transferor and the transaction signature of the transferee according to the approval encryption information and the transaction initiation identifier, and after passing the verification, verifies the validity of the target data asset by means of point-to-point communication with the transferor and generates a verification confirmation information when it is confirmed to be valid; When receiving the verification confirmation information of the verification node, transferring the ownership of the target data asset to the transferee; where there are multiple verification nodes, and when receiving the verification confirmation information of the verification node, transferring the ownership of the target data asset to the transferee includes: when receiving the verification confirmation information of more than a preset number of verification nodes, transferring the ownership of the target data asset to the transferee; where the transferee generates a response by taking the transaction identifier generated by the transferor as an incentive and sends the generated response as the transaction initiation identifier to the transferor, and the transaction initiation identifier is used to indicate the transferee's willingness to purchase the target data asset; The transferor takes the response generated by taking the transaction initiation identifier as an incentive as the first key, takes the response generated by taking the first key as an incentive as the second key, generates the approval encryption information according to the first key and the transaction initiation identifier, uses its own PUF device to digitally sign the approval encryption information and the transaction initiation identifier to generate the transaction signature of the transferor, and sends the second key and the approval encryption information to the transferee, where the approval encryption information is used to indicate that the transferor accepts the order of the transferee to purchase the target data asset; The transferee verifies the approval encryption information based on the second key, and when it is verified that the approval encryption information contains the transaction initiation identifier, uses its own PUF device to digitally sign the approval encryption information and the transaction initiation identifier to generate the transaction signature of the transferee.

2. The method according to claim 1, wherein The verification node communicates point-to-point with the transferor, requests the public key from the transferor, decrypts the target data asset with the public key, and compares the decrypted target data asset with the plaintext corresponding to the target data asset pre-stored locally. If the comparison is consistent, it is confirmed that the target data asset is valid; Among them, the target data asset is encrypted by the transferor using the private key corresponding to the public key.

3. The method according to claim 1, characterized in that, The verification node generates a transaction signature field through the hash digest of the transaction information and by using its own PUF device. The verification confirmation information includes the generated transaction signature field.

4. The method according to claim 1, wherein Multiple verification nodes are obtained based on preset conditions, and the preset conditions include any one or more of the geographical location of the PUF device, historical reliability, historical response time, and historical load capacity.

5. The method according to claim 1, wherein The target data asset includes descriptive information of the target data, ownership identification of the target data asset, additional attribute information of the target data asset, and historical transaction information of the target data asset.

6. A data asset trading control device driven by physical characteristics, characterized in that, Applied to a decentralized PUF network, the device includes: A receiving module, configured to receive transaction information sent by a transferor of the ownership of the target data asset. The transaction information includes the target data asset, the transaction signature of the transferor, the transaction signature of the recipient of the ownership of the target data asset, approval encryption information, and a transaction initiation identifier. Both the transferor and the recipient are PUF device recipients, and the transaction signatures of both are generated by digitally signing the approval encryption information and the transaction initiation identifier using the physical characteristics of their own PUF devices. The approval encryption information is generated based on the transaction initiation identifier, and the transaction initiation identifier is a response generated by the recipient by using the transaction identifier generated by the transferor as an incentive; A verification module, configured to send the transaction information to a verification node, where the verification node is any PUF device in the decentralized PUF network. The verification node uses the physical characteristics of its own PUF device to drive and verify the transaction signature of the transferor and the transaction signature of the recipient according to the approval encryption information and the transaction initiation identifier, and after the verification passes, verifies the validity of the target data asset by communicating point-to-point with the transferor and generates verification confirmation information when it is confirmed to be valid; A transaction transfer module, configured to transfer the ownership of the target data asset to the recipient when receiving the verification confirmation information from the verification node; among them, there are multiple verification nodes, and when receiving the verification confirmation information from the verification node, transferring the ownership of the target data asset to the recipient includes: when receiving verification confirmation information from more than a preset number of verification nodes, transferring the ownership of the target data asset to the recipient; Among them, the recipient generates a response by using the transaction identifier generated by the transferor as an incentive, and sends the generated response to the transferor as the transaction initiation identifier. The transaction initiation identifier is used to indicate the recipient's willingness to purchase the target data asset; The transferor uses the response generated by the transaction initiation identifier as the incentive as the first key, and uses the response generated by the first key as the incentive as the second key. The approval encryption information is generated according to the first key and the transaction initiation identifier. The transferor uses its own PUF device to digitally sign the approval encryption information and the transaction initiation identifier to generate the transferor's transaction signature, and sends the second key and the approval encryption information to the recipient, where the approval encryption information is used to indicate that the transferor accepts the recipient's order to purchase the target data asset; The recipient verifies the approval encryption information based on the second key, and when it is verified that the approval encryption information contains the transaction initiation identifier, uses its own PUF device to digitally sign the approval encryption information and the transaction initiation identifier to generate the recipient's transaction signature.

7. A decentralized PUF network, characterized in that, The decentralized PUF network includes multiple PUF devices, and the multiple PUF devices include the transferor of the target data asset ownership, the recipient of the target data asset ownership, and one or more verification nodes and control nodes; The control node receives the transaction information sent by the transferor. The transaction information includes the target data asset, the transferor's transaction signature, the recipient's transaction signature, the approval encryption information, and the transaction initiation identifier. The transferor's transaction signature and the recipient's transaction signature are both generated by driving the physical characteristics of their own PUF devices to digitally sign the approval encryption information and the transaction initiation identifier. The approval encryption information is generated based on the transaction initiation identifier, and the transaction initiation identifier is the response generated by the recipient using the transaction identifier generated by the transferor as the incentive; The control node sends the transaction information to the verification node. The verification node uses the physical characteristics of its own PUF device to drive and verifies the transferor's transaction signature and the recipient's transaction signature according to the approval encryption information and the transaction initiation identifier, and after the verification passes, verifies the validity of the target data asset by means of point-to-point communication with the transferor and generates a verification confirmation information when it is confirmed to be valid; When the control node receives the verification confirmation information from the verification node, it transfers the ownership of the target data asset to the recipient; where, there are multiple verification nodes, and when receiving the verification confirmation information from the verification node, transferring the ownership of the target data asset to the recipient includes: when receiving the verification confirmation information from more than a preset number of verification nodes, transferring the ownership of the target data asset to the recipient; Wherein, the recipient uses the transaction identifier generated by the transferor as the incentive to generate a response, and sends the generated response as the transaction initiation identifier to the transferor, and the transaction initiation identifier is used to indicate the recipient's willingness to purchase the target data asset; The transferor uses the response generated by taking the transaction initiation identifier as an incentive as the first key, uses the response generated by taking the first key as an incentive as the second key, generates the approval encryption information according to the first key and the transaction initiation identifier, uses its own PUF device to digitally sign the approval encryption information and the transaction initiation identifier to generate the transferor's transaction signature, and sends the second key and the approval encryption information to the recipient, where the approval encryption information is used to indicate that the transferor accepts the recipient's order to purchase the target data asset; The recipient verifies the approval encryption information based on the second key, and when it is verified that the approval encryption information contains the transaction initiation identifier, uses its own PUF device to digitally sign the approval encryption information and the transaction initiation identifier to generate the recipient's transaction signature.

8. A readable storage medium, on which an embedded program is stored, characterized in that, When the embedded program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Authentication system and method

    US20230336366A1