Carbon asset encryption method and platform based on block chain
Through the blockchain-based carbon asset encryption method, the problems of low data security and credibility and lack of traceability mechanism in the traditional management model are solved, and the full process traceability management and security of carbon assets are realized, and the transparency and synergy efficiency of the carbon trading market are improved.
Patent Information
- Application Number
- CN202510514556.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-04-23
AI Technical Summary
The traditional carbon asset management model has problems such as low data security and credibility, lack of effective traceability mechanisms, and low efficiency in information sharing and collaborative work, which is difficult to meet the requirements of carbon asset transactions for data security and information transparency.
The blockchain-based carbon asset encryption method is adopted to obtain and update the generation path of carbon assets, divide the original assets and inherited assets, and generate distributed keys based on role nodes and asset attributes to build a key structure tree to realize the authenticity and security of information.
It realizes traceable management of carbon assets throughout the process, ensures the security and privacy of carbon assets, and improves the transparency and synergy efficiency of the carbon trading market.
Smart Images

Figure CN120046174A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to data processing technologies, and in particular, to a carbon asset encryption method and platform based on blockchain. Background Art
[0002] Currently, most carbon asset management adopts the traditional centralized management mode, which has many drawbacks. On the one hand, the security and credibility of data are relatively low, and it is vulnerable to human tampering and data leakage threats, unable to meet the strict requirements for data security in carbon asset transactions. On the other hand, during the carbon asset trading process, there is a lack of an effective traceability mechanism, making it difficult to accurately track the source and transfer process of carbon assets, resulting in an increase in trading risks. In addition, under the traditional management mode, the information sharing and collaborative work efficiency among various participating entities are low, seriously restricting the development of the carbon trading market.
[0003] Therefore, how to improve the authenticity and security of carbon asset source and transfer information has become an urgent problem to be solved. Summary of the Invention
[0004] An embodiment of the present invention provides a carbon asset encryption method and platform based on blockchain, which can improve the authenticity and security of carbon asset source and transfer information.
[0005] In a first aspect of an embodiment of the present invention, a carbon asset encryption method based on blockchain is provided, including: Obtaining a first generation path of each first carbon asset of a first role node in the blockchain, and dividing the first carbon asset into an original asset or a successor asset based on the first generation path; After determining that a transaction request occurs between any second role node and the first role node, updating the first generation path corresponding to the original asset or successor asset of the transaction to obtain a second generation path; Determining a first distributed key of a newly added node of the second generation path based on the first role node, the second role node, and the attributes of the first carbon asset; Obtaining a key structure tree of the second generation path based on the first distributed key and a second distributed key, and distributing the updated key structure tree to the corresponding role nodes based on the role relationship.
[0006] Optionally, the obtaining a first generation path of each first carbon asset of a first role node in the blockchain, and dividing the first carbon asset into an original asset or a successor asset based on the first generation path includes: The first carbon asset includes at least one of carbon emission allowances, green power values, and green certificate values; If the first carbon asset is an original asset, generating an original node and a corresponding first generation path; If the first carbon asset is a successor asset, a successor node is generated, and the original historical generation path corresponding to the successor asset is obtained. The first generation path is assembled based on the viewing permission of the historical generation path and the successor node.
[0007] Optionally, the assembling the first generation path based on the viewing permission of the historical generation path and the successor node includes: Obtain multiple third role nodes corresponding to other identities of each path node in the historical generation path; If the third role nodes corresponding to the same path node are all added with viewable information, mark the corresponding path node as the first path node; If there is unviewable information added among the third role nodes corresponding to the same path node, mark the corresponding path node as the second path node; Assemble the first path node and / or the second path node with the successor node according to the assembling strategy to generate the first generation path.
[0008] Optionally, the assembling the first path node and / or the second path node with the successor node according to the assembling strategy to generate the first generation path includes: If it is determined that there are adjacent second path nodes, fold them into a third path node, and the third path node is in a non-selectable state; Connect and assemble the remaining first path nodes, third path nodes, and successor nodes in chronological order to obtain the first generation path.
[0009] Optionally, the marking the corresponding path node as the first path node if the third role nodes are all added with viewable information includes: Extract the target information that exists in all the viewable information added by all the third role nodes; Retrieve the preset viewing template, fill the target information into the target slot of the preset viewing template, and set the slots without target information in the preset viewing template to be empty; Statistically analyze the target slots and the empty slots to obtain the information data encoding of the first path node.
[0010] Optionally, the statistically analyzing the target slots and the empty slots to obtain the information data encoding of the first path node includes: Statistically analyze the preset order and preset encoding corresponding to each slot; Extract the character value of the target information, and combine the character value with the preset encoding to obtain the first sub-encoding of the corresponding target slot; Determine the second sub-encoding corresponding to the empty slot, and obtain the information data encoding of the first path node based on the first sub-encoding and the second sub-encoding.
[0011] Optionally, the determination of the second sub - encoding corresponding to the empty slot, and obtaining the information data encoding of the first path node based on the first sub - encoding and the second sub - encoding, includes: Delete the target slot to obtain the empty order of all empty slots, assign empty characters to each empty slot according to the empty order, and merge the empty characters with the preset encoding to obtain the second sub - encoding of the empty slot; Merge the first sub - encoding and the second sub - encoding in a preset order to obtain the information data encoding.
[0012] Optionally, after determining that any second role node makes a transaction request with the first role node, updating the first generation path corresponding to the original asset or the successor asset of the transaction to obtain the second generation path, includes: Establish a fourth path node corresponding to this transaction; Connect the fourth path node with the first generation path to update and obtain the second generation path, determine the order of the newly added nodes and add sequence encodings.
[0013] Optionally, the determination of the first distributed key of the newly added node in the second generation path based on the first role node, the second role node and the attributes of the first carbon asset, includes: Extract the role information of the first role node and the second role node to obtain the first role encoding and the second role encoding; Determine the corresponding attribute encoding according to the attributes of the first carbon asset; Sort the information data encoding, the sequence encoding, the first role encoding, the second role encoding, and the attribute encoding according to the generation time to obtain a fusion value, and perform a hash calculation on the fusion value to obtain the first distributed key.
[0014] Optionally, obtaining the key structure tree of the second generation path based on the first distributed key and the second distributed key, and updating and distributing the key structure tree to the corresponding role nodes based on the role relationship, includes: Use the keys of the other path nodes in the second generation path except the newly added nodes as the second distributed key; Generate a parent node corresponding to the second generation path, and generate child nodes corresponding to the first distributed key and the second distributed key, and obtain the key structure tree based on the parent node and the child nodes; Determine the third role node in the upper dimension corresponding to the first role node and the second role node, update the key structure tree based on the third role node and distribute it to the corresponding role nodes.
[0015] Optionally, the determination of the third role node in the upper dimension corresponding to the first role node and the second role node, updating the key structure tree based on the third role node and distributing it to the corresponding role nodes, includes: Retrieve the role structure trees corresponding to the first role node and the second role node respectively; Determine the third role node located in the upper dimension of the first role node and the second role node in the role structure tree, and count the third role nodes corresponding to each first role node and second role node to generate a role management form; Fill the initial first distributed key or second distributed key into the role management form, and after updating the key structure tree based on the role management form, distribute it to the corresponding role nodes.
[0016] Optionally, the step of updating the key structure tree based on the role management form and then distributing it to the corresponding role nodes includes: Determine the management right key of each third role node in the role management form. There is 1 management right key and it corresponds to all other managed role nodes; Fill the management right key into the role management form and correspond it to the first distributed key or the second distributed key, so as to call the first distributed key or the second distributed key based on the management right key; Distribute the first distributed key or the second distributed key and the management right key to the corresponding role nodes.
[0017] In the second aspect of the embodiments of the present invention, a blockchain-based carbon asset encryption platform is provided, including: A first module, configured to obtain the first generation path of each first carbon asset of the first role node in the blockchain, and divide the first carbon asset into original assets or successor assets based on the first generation path; A second module, configured to update the first generation path corresponding to the original asset or successor asset of the transaction to obtain a second generation path after determining that any second role node has a transaction request with the first role node; A key module, configured to determine the first distributed key of the newly added node of the second generation path based on the first role node, the second role node, and the attributes of the first carbon asset; A distribution module, configured to obtain the key structure tree of the second generation path based on the first distributed key and the second distributed key, and update and distribute the key structure tree to the corresponding role nodes based on the role relationship.
[0018] Beneficial effects
[0019] 1. Implement full-process traceable management of carbon assets. Through detailed recording and management of the first carbon asset generation path, whether it is the original asset or the successor asset, its source and transfer process can be clearly presented. During the construction of the generation path, strict screening and coding of path node information ensure the authenticity and integrity of the information. When a carbon asset is traded, the generation path is updated in a timely manner, making each transfer of the carbon asset traceable and improving the transparency of carbon trading.
[0020] 2. Ensure the security of carbon assets. The present invention constructs a complete key management system, generates distributed keys based on role information, carbon asset attributes, etc., and establishes a key structure tree to hierarchically manage the keys. During the key distribution process, the third role node in the upper dimension is determined in combination with the role structure tree, and a role management form is generated to accurately distribute and control the invocation of the keys. This method effectively ensures the security and privacy of carbon assets during the trading process, prevents key leakage and illegal use, and reduces security risks.
[0021] 3. Improve the collaborative efficiency of carbon asset management. Each module of the carbon asset encryption management platform of the present invention works collaboratively to achieve real-time sharing and processing of carbon asset information. During the carbon asset trading process, from the receipt of the trading request to the update of the generation path, and then to the generation and distribution of keys, the entire process has a high degree of automation, improving work efficiency. At the same time, through the generation and use of the role management form, the management authorities and responsibilities of each role node are clarified, promoting the collaborative efficiency among the participating entities. Description of the Drawings
[0022] Figure 1 is a schematic flow chart of a blockchain-based carbon asset encryption management method provided by an embodiment of the present invention; Figure 2 is a schematic diagram of a generation path provided by an embodiment of the present invention; Figure 3 is a schematic flow chart of a blockchain-based carbon asset encryption management platform provided by an embodiment of the present invention. Detailed Embodiment
[0023] The technical solutions of the present invention will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0024] See Figure 1 , which is a schematic flow chart of a blockchain-based carbon asset encryption method provided by an embodiment of the present invention. The method includes: S1. Obtain the first generation path of each first carbon asset of the first role node in the blockchain, and divide the first carbon assets into original assets or successor assets based on the first generation path.
[0025] Among them, the first role node is, for example, an enterprise, a thermal power station, a wind power station, etc., and the first carbon assets are held by each node. By analyzing the formation and transfer information of each first carbon asset, obtain its first generation path, and divide the first carbon assets into original assets or successor assets according to the path characteristics, providing a data basis for the subsequent full life cycle management of carbon assets.
[0026] It can be understood that, assuming an enterprise is the first role node and has a certain amount of carbon emission allowances. If the carbon emission allowances are original assets obtained by the enterprise itself through energy conservation and emission reduction, the system generates an original node and records its first generation path. If the enterprise purchases some carbon emission allowances from other thermal power stations, the system generates successor assets.
[0027] In some embodiments, the obtaining the first generation path of each first carbon asset of the first role node in the blockchain, and dividing the first carbon assets into original assets or successor assets based on the first generation path includes: The first carbon assets include at least one of carbon emission allowances, green power values, and green certificate values; S11. If the first carbon asset is an original asset, generate an original node and the corresponding first generation path.
[0028] When the system identifies that the first carbon asset is an untransferred original asset, the system immediately creates an original node, which is an untransferred node. At the same time, around the original node, the system constructs a record link reflecting the asset from its generation, forming the corresponding first generation path, thereby clarifying the origin and initial information of the original asset.
[0029] S12. If the first carbon asset is a successor asset, generate a successor node, obtain the original historical generation path corresponding to the successor asset, and assemble the first generation path based on the viewing permission of the historical generation path and the successor node.
[0030] When the system determines that the first carbon asset is a successor asset, it will generate a successor node to mark the act of asset transfer. Subsequently, the system traces the historical transfer information of the successor asset on the blockchain to obtain the corresponding original historical generation path. The system further evaluates the viewing permissions of each node in the historical generation path, and assembles the nodes that meet the permission requirements and the successor node according to specific rules to generate the first generation path including the whole process of asset transfer and permission information for subsequent tracing.
[0031] Among them, the viewing permission based on the historical generation path and the successor node are assembled to obtain the first generation path, including: S121. Obtain multiple third role nodes corresponding to other identities of each path node in the historical generation path.
[0032] After the original historical generation path corresponding to the successor asset has been obtained, the system will analyze each path node in the historical generation path. Each path node may be associated with multiple third role nodes with different identities. Through the distributed ledger feature of the blockchain, the system comprehensively collects all the information of the third role nodes associated with each path node. These third role nodes are other entities participating in the carbon asset transfer process, such as different enterprises, etc. By obtaining this information, the system can fully understand the relationships and relevant information of all parties involved in the historical transfer process of carbon assets, providing a comprehensive data basis for subsequent permission evaluation and path assembly.
[0033] S122. If the third role nodes corresponding to the same path node all add viewable information, mark the corresponding path node as the first path node.
[0034] The system will analyze the multiple third role nodes corresponding to each path node. If all the third role nodes corresponding to a certain path node have added viewable information, it means that the information contained in this path node is viewable in the eyes of these relevant third role nodes. Based on this, the system marks this path node as the first path node. Such marking and permission setting help to clearly distinguish different types of path nodes during the subsequent assembly of the first generation path and display and use information according to the permission rules.
[0035] Among them, the step of if the third role nodes corresponding to the same path node all add viewable information, then mark the corresponding path node as the first path node includes: S1221. Extract the target information that exists in all the viewable information added by all the third role nodes.
[0036] When the system determines that a certain path node is the first path node, it will deeply analyze the viewable information added by all the third role nodes corresponding to this path node. The system will carefully compare this viewable information and extract the information that all the third role nodes have in common. This information is defined as the target information. The target information can be various types of data, such as the amount and quantity of carbon asset transactions, the identity labels of participating entities, etc. By extracting the target information, the system can focus on the key data that is recognized and shareable by all relevant parties.
[0037] S1222. Retrieve the preset viewing template, fill the target information into the target slots of the preset viewing template, and set the slots in the preset viewing template without target information to be empty.
[0038] The system will call the preset viewing template that has been set in advance. This preset viewing template is designed according to the requirements and specifications of carbon asset information management and contains a series of slots for filling information. The system accurately fills the previously extracted target information into the corresponding target slots in the preset viewing template. For the slots in the preset viewing template that do not match the target information, the system will set them to be empty. Such an operation enables the information to be presented in a standardized and structured manner, facilitating subsequent information management, query, and sharing.
[0039] S1223. Statistically process the target slots and the empty slots to obtain the information data encoding of the first path node.
[0040] The target slots represent the information parts that can be viewed, and the empty slots represent the information parts that cannot be viewed. The system statistically processes these slots according to their status, position, and relevant rules, and finally obtains the information data encoding of the third node corresponding to the first path node. This information data encoding contains key information about the viewability and specific content of the node information, providing an effective means for subsequent information storage, transmission, and security management.
[0041] Among them, the statistically processing the target slots and the empty slots to obtain the information data encoding of the first path node includes: S12231. Statistically process the preset order and preset encoding corresponding to each slot.
[0042] For each slot in the preset viewing template, the system obtains its preset sequence number, such as 1, 2, 3, 4, etc., and the corresponding preset encoding, such as A, B, C, D, etc. These preset information provide the standards and basis for subsequent generation of information data encoding, enabling each slot to have a clear identifier during the encoding process and ensuring the standardization and consistency of the encoding.
[0043] S12232. Extract the character value of the target information, and merge the character value with the preset encoding to obtain the first sub-encoding of the corresponding target slot.
[0044] The system extracts the character values of the target information from the target slots of the preset viewing template. These character values represent the specific content of the target information. For example, information such as carbon emission allowances can be plain text information. The system combines the extracted character values with the preset encoding corresponding to the target slot to obtain the first sub-encoding corresponding to each target slot. In this way, the content of the target information is combined with the preset encoding system to realize the digital representation of the target slot information, which is convenient for subsequent information integration and management.
[0045] S12233. Determine the second sub-encoding corresponding to the empty slot, and obtain the information data encoding of the first path node based on the first sub-encoding and the second sub-encoding.
[0046] The system processes the empty slots in the preset viewing template. Determine the corresponding second sub-encoding for each empty slot. The second sub-encoding consists of preset characters or preset encodings, such as A, B, C, D, etc.
[0047] Among them, the determination of the second sub-encoding corresponding to the empty slot and obtaining the information data encoding of the first path node based on the first sub-encoding and the second sub-encoding includes: S122331. Delete the target slots to obtain the empty order of all empty slots. Assign empty characters to each empty slot according to the empty order, and combine the empty characters with the preset encoding to obtain the second sub-encoding of the empty slot.
[0048] The system first deletes the target slots from the preset viewing template to obtain the empty order of all empty slots. Taking a template with 5 slots as an example, if the 2nd and 4th slots contain target information, after deleting these two slots, the order of the originally empty 1st, 3rd, and 5th slots will be rearranged as 1, 2, 3. The system assigns preset empty characters, such as A, B, C, etc., to each empty slot according to this new empty order, and combines these empty characters with the corresponding preset encoding to obtain the second sub-encoding of each empty slot. This method not only encodes the empty slots but also increases the randomness of the encoding and improves the security of the information by rearranging and assigning characters.
[0049] S122332. Combine the first sub-encoding and the second sub-encoding in a preset order to obtain the information data encoding.
[0050] The system merges the previously generated first sub-code and second sub-code in a preset order. The preset order can be determined according to the original number of the slot, the coding rule, or other specific requirements. Through this merging operation, the coding information of the target slot and the empty slot is integrated together to form a complete information data code. This information data code comprehensively reflects the information content and visibility of the third node of the first path node, providing a unified digital format for subsequent information storage, transmission, and analysis.
[0051] S123, if there is added non-viewable information in the third role nodes corresponding to the same path node, then mark the corresponding path node as the second path node.
[0052] When the system checks the information of the third role nodes corresponding to each path node in the historical generation path, once it finds that there is added non-viewable information in the third role nodes corresponding to the same path node, it will mark that path node as the second path node. This operation helps to distinguish path nodes with different security levels and information visibility, providing a judgment basis for the subsequent refined assembly of the generation path of the successor assets, avoiding randomly incorporating non-viewable information into the publicly visible generation path, and ensuring the security of carbon asset transfer information during sharing.
[0053] S124, assemble the first path node and / or the second path node with the successor node according to the assembly strategy to generate the first generation path.
[0054] Based on the previously marked first path node and second path node, the system integrates with the successor node according to the established assembly strategy to generate the complete first generation path of the successor asset, fully presenting the transfer context of the asset.
[0055] Among them, the assembling the first path node and / or the second path node with the successor node according to the assembly strategy to generate the first generation path includes: S1241, if it is judged that there are adjacent second path nodes, then fold them into a third path node, and the third path node is in a non-selectable state.
[0056] The system will traverse all the second path nodes to judge whether there are adjacent second path nodes. If so, in order to optimize the path structure and improve the clarity of information display, the system will fold these adjacent second path nodes into a third path node. Since the second path node contains non-viewable information, the folded third path node is set to a non-selectable state to prevent users from accidentally obtaining non-viewable information and further ensuring information security.
[0057] S1242, connect and assemble the remaining first path nodes, third path nodes, and successor nodes in chronological order to obtain the first generation path.
[0058] The system connects and assembles the processed remaining first path nodes, newly generated third path nodes, and successor nodes in the chronological order of their occurrences in the carbon asset transfer process. The chronological order can accurately reflect the state changes of the assets at different stages, ensuring that the generated first generation path truly restores the transfer trajectory of the successor assets and providing reliable data for subsequent tracing of carbon assets.
[0059] S2. After determining that a transaction request occurs between any second role node and the first role node, update the first generation path corresponding to the original asset or successor asset of the transaction to obtain a second generation path.
[0060] See Figure 2 , when the system detects a transaction request between any second role node and the first role node, it means that the carbon assets have been transferred. To accurately record this transaction behavior and the latest state of the assets, the system needs to update the first generation path corresponding to the original asset or successor asset involved in the transaction, so as to obtain a second generation path reflecting the latest transfer situation of the assets and ensure the real-time and traceability of carbon asset information.
[0061] In some embodiments, the step of, after determining that a transaction request occurs between any second role node and the first role node, updating the first generation path corresponding to the original asset or successor asset of the transaction to obtain a second generation path includes: S21. Establish a fourth path node corresponding to this transaction.
[0062] After the system confirms the transaction request, it will create a new path node, that is, the fourth path node. This node is specially generated for this transaction and carries key information related to this transaction, such as the identities of the two parties to the transaction, the transaction time, the type and quantity of carbon assets traded, etc. The fourth path node serves as the recording point of this transaction in the carbon asset generation path and provides a clear identifier for subsequent information query and tracing.
[0063] S22. Connect the fourth path node with the first generation path for update to obtain a second generation path, determine the order of the newly added nodes, and add an order code.
[0064] The system connects the newly established fourth path node to the original first generation path. Through this connection operation, the transaction information of this time is incorporated into the historical transfer path of carbon assets to form a complete second generation path. At the same time, the system determines the order of the fourth path node in the new path according to the time when the transaction occurs and the order of each node in the first generation path, and adds the corresponding order code to it. The order code helps to clearly display the transfer order of carbon assets, facilitates the tracking and analysis of the asset transfer process, and ensures that the second generation path can accurately reflect the latest transfer status of carbon assets.
[0065] S3. Determine the first distributed key of the newly added node in the second generation path based on the first role node, the second role node, and the attributes of the first carbon asset.
[0066] To ensure the security of the newly added nodes in the second generation path and the integrity of the data, the system needs to generate the corresponding first distributed key based on the characteristics of the first role node, the second role node, and the attributes of the first carbon asset. This key will be used to encrypt and verify the data of the newly added nodes, ensuring that only authorized nodes can access and process relevant information, and enhancing the security and credibility of carbon asset transactions on the blockchain.
[0067] In some embodiments, the determining the first distributed key of the newly added node in the second generation path based on the first role node, the second role node, and the attributes of the first carbon asset includes: S31. Extract the role information of the first role node and the second role node to obtain the first role code and the second role code.
[0068] The system extracts the role information of the first role node and the second role node from the blockchain. These role information may include the types of nodes (such as enterprises, thermal power plants, wind power plants, etc.), relevant identifiers in the carbon trading market, etc. These codes are digital representations of the role information, facilitating subsequent calculations and combinations in the key generation process.
[0069] S32. Determine the corresponding attribute code according to the attributes of the first carbon asset.
[0070] The system determines the corresponding attribute code according to the attributes of the first carbon asset. The attributes of the first carbon asset include its type (such as carbon emission allowances, green electricity values, green certificate values, etc.), validity period, etc. For different attributes, the system has preset corresponding codes. For example, green certificates may correspond to specific preset codes. The system converts the attributes of the first carbon asset into attribute codes, providing key asset feature information for subsequent key generation.
[0071] S33. Sort the information data encoding, sequence encoding, first role encoding, second role encoding, and attribute encoding according to their generation times to obtain a fusion value, and perform a hash calculation on the fusion value to obtain the first distributed key.
[0072] The system sorts the previously obtained information data encoding (generated during the path node marking and assembly process), sequence encoding (determined when updating and generating the path), first role encoding, second role encoding, and attribute encoding according to their generation times.
[0073] The purpose of sorting is to ensure the sequential consistency of these encodings during the fusion process, making the generated key deterministic each time. The sorted encodings are combined into a fusion value. The system performs a hash calculation on this fusion value. Hash calculation is an encryption algorithm in the prior art that converts input data of any length into a fixed-length hash value. The obtained hash value is the first distributed key for the newly added node of the second generation path. Each path node has its corresponding first distributed key, which is used to encrypt and protect the data of that node, ensuring the secure storage and transmission of data on the blockchain.
[0074] S4. Based on the first distributed key and the second distributed key, obtain the key structure tree of the second generation path, and update and distribute the key structure tree to the corresponding role nodes based on the role relationship.
[0075] To achieve effective management and secure access control of the data of each node on the second generation path, the system needs to construct a key structure tree based on the generated first distributed key and second distributed key, update and distribute it according to the role relationship, so that each role node can operate on the relevant data according to its own permissions, ensuring the security and accessibility of carbon asset trading information.
[0076] In some embodiments, the obtaining the key structure tree of the second generation path based on the first distributed key and the second distributed key, and updating and distributing the key structure tree to the corresponding role nodes based on the role relationship includes: S41. Use the keys of the other path nodes in the second generation path except for the newly added node as the second distributed key.
[0077] The system traverses the second generation path and determines the keys of the other path nodes except for the newly added node as the second distributed key. These second distributed keys represent the security identifiers of the other nodes on the second generation path and are used to reflect the relationships and permission hierarchies among the nodes when constructing the key structure tree later, ensuring that the key of each node can be reasonably arranged in the key structure tree.
[0078] S42. Generate a parent node corresponding to the second generation path, and generate child nodes corresponding to the first distributed key and the second distributed key. Obtain a key structure tree based on the parent node and the child nodes.
[0079] The system first generates a parent node corresponding to the second generation path. This parent node serves as the root node of the entire key structure tree, playing a leading and integrating role. The system generates child nodes corresponding to the first distributed key and the second distributed key respectively. These child nodes are connected to the parent node, forming a hierarchical structure. The child node corresponding to the first distributed key represents the key information of the newly added node, and the child node corresponding to the second distributed key represents the key information of other path nodes. By combining the parent node and the child nodes, the system constructs a complete key structure tree. This key structure tree clearly shows the relationship between the keys of each node on the second generation path, providing an intuitive model for subsequent key management and access control.
[0080] S43. Determine the third role node corresponding to the upper dimension of the first role node and the second role node. Update the key structure tree based on the third role node and distribute it to the corresponding role nodes.
[0081] The system determines the third role node corresponding to the upper dimension of the first role node and the second role node in the role structure. These third role nodes usually have higher management permissions or a wider scope of responsibilities. The system updates the constructed key structure tree according to the permissions and role relationships of the third role nodes. The updated content may include adjusting the permission relationships between nodes, adding or deleting access permissions for certain nodes, etc. The system distributes the updated key structure tree to the corresponding role nodes. After each role node receives the key structure tree, it can perform corresponding operations on the data on the second generation path according to its own role and permissions, such as decryption, reading, or modification, so as to achieve the secure management and effective utilization of carbon asset trading information.
[0082] Among them, the determining the third role node corresponding to the upper dimension of the first role node and the second role node, updating the key structure tree based on the third role node and distributing it to the corresponding role nodes includes: S431. Retrieve the role structure trees corresponding to the first role node and the second role node respectively.
[0083] The system retrieves the role structure trees corresponding to the first role node and the second role node respectively from the storage system of the blockchain. The role structure tree is a hierarchical data structure that describes the positions and mutual relationships of each role node in the entire role system, including information such as the superior-subordinate and subordinate relationships between different roles, which is preset by the user.
[0084] S432. Determine the third role nodes in the upper dimension of the first role node and the second role node in the role structure tree, and count the third role nodes corresponding to each first role node and second role node to generate a role management form.
[0085] In the retrieved role structure tree, the system locates the positions of the first role node and the second role node. Then, according to the hierarchical relationship of the role structure tree, it searches upward to find the third role nodes in its upper dimension. These third role nodes usually have higher-level permissions. The system counts the third role nodes corresponding to each first role node and second role node, and organizes the relevant information into a role management form. The role management form can be a table or a document, which mainly records the corresponding relationship between each first role node and second role node and the third role node, clarifying the permissions of different role nodes in key management and data access.
[0086] S433. Fill the initial first distributed key or second distributed key into the role management form, and update the key structure tree based on the role management form and then distribute it to the corresponding role nodes.
[0087] The system fills the initial first distributed key or second distributed key into the role management form. The corresponding relationship between different role nodes and keys is recorded in the role management form. Through the filling operation, each role node can be associated with the corresponding key.
[0088] Based on the information in the role management form, the system updates the previously constructed key structure tree. The update operation may include adjusting the access permissions of key nodes, modifying the association relationships between nodes, etc., to ensure that the key structure tree can accurately reflect the permissions and responsibilities of different role nodes in carbon asset trading. The system distributes the updated key structure tree to the corresponding role nodes. After each role node receives the key structure tree, it can securely access and operate on the relevant data on the second generation path according to its permissions in the role management form, thereby realizing the effective management and protection of carbon asset trading information.
[0089] In some embodiments, the step of updating the key structure tree based on the role management form and then distributing it to the corresponding role nodes includes: Determine the management key of each third role node in the role management form. There is 1 management key, which corresponds to all other managed role nodes.
[0090] In the role management list of the system, a unique management right key is generated for each third role node. This management right key is specifically set for this third role node and is used to control the permissions of all other role nodes under its management. Its uniqueness lies in that a third role node has only one management right key, and this key has a corresponding relationship with all other role nodes managed by this third role node. In this way, the unified management of multiple managed role nodes is realized, and the process of permission management is simplified.
[0091] Fill the management right key into the role management list and correspond it to the first distributed key or the second distributed key, so as to call the first distributed key or the second distributed key based on the management right key.
[0092] The system fills the generated management right key into the role management list and establishes a corresponding relationship between it and the first distributed key or the second distributed key. This corresponding relationship enables the management right key to call the first distributed key or the second distributed key corresponding to the managed role node, realizing flexible control of key usage and permission grading.
[0093] Distribute the first distributed key or the second distributed key and the management right key to the corresponding role nodes.
[0094] The system distributes the first distributed key or the second distributed key and the corresponding management right key to the corresponding role nodes. The first distributed key or the second distributed key ensures that each role node can encrypt and decrypt the data of the path nodes it is responsible for, ensuring the security of the data. Through this key distribution method, each role node can securely access and operate on the data on the second generation path according to its own permissions, realizing the secure sharing and effective management of carbon asset transaction information among different role nodes.
[0095] See Figure 3 , which is a schematic structural diagram of a carbon asset encryption platform based on blockchain provided by an embodiment of the present invention. The platform includes: The first module is used to obtain the first generation path of each first carbon asset of the first role node in the blockchain, and divide the first carbon asset into original assets or successor assets based on the first generation path; The second module is used to update the first generation path corresponding to the original asset or successor asset of the transaction to obtain the second generation path after determining that any second role node has a transaction request with the first role node; The key module is used to determine the first distributed key of the newly added node of the second generation path based on the attributes of the first role node, the second role node, and the first carbon asset; A distribution module, configured to obtain a key structure tree of a second generation path based on a first distributed key and a second distributed key, and update the key structure tree based on a role relationship and then distribute it to corresponding role nodes.
[0096] The present invention also provides a storage medium, in which a computer program is stored. When the computer program is executed by a processor, it is used to implement the methods provided by the above various embodiments.
[0097] Among them, the storage medium can be a computer storage medium or a communication medium. The communication medium includes any medium that facilitates the transmission of a computer program from one place to another. The computer storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer. For example, the storage medium is coupled to the processor, so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC). In addition, the ASIC can be located in a user device. Of course, the processor and the storage medium can also exist as discrete components in a communication device. The storage medium can be a read-only memory (ROM), a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0098] The present invention also provides a program product, which includes execution instructions stored in a storage medium. At least one processor of the device can read the execution instructions from the storage medium, and the execution of the execution instructions by at least one processor causes the device to implement the methods provided by the above various embodiments.
[0099] In the above embodiments of the terminal or the server, it should be understood that the processor can be a central processing unit (CPU for short), and can also be other general-purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the present invention can be directly implemented by the execution of the hardware processor, or can be implemented by the combination of the hardware and software modules in the processor.
[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A carbon asset encryption method based on blockchain, characterized in that: include: Obtain a first generation path of each first carbon asset of a first role node in the blockchain, and divide the first carbon asset into original assets or successor assets based on the first generation path; After determining that a transaction request occurs between any second role node and the first role node, the first generation path corresponding to the original asset or the successor asset of the transaction is updated to obtain a second generation path; Determine a first distributed key of a newly added node of a second generation path based on the attributes of the first role node, the second role node, and the first carbon asset; A key structure tree of a second generation path is obtained based on the first distributed key and the second distributed key, and the key structure tree is updated based on the role relationship and distributed to corresponding role nodes.
2. The method according to claim 1, characterized in that The obtaining a first generation path of each first carbon asset of the first role node in the blockchain, and dividing the first carbon asset based on the first generation path to obtain an original asset or a successor asset, includes: The first carbon asset includes at least one of carbon emission quota, green electricity value and green certificate value; If the first carbon asset is an original asset, then an original node and a corresponding first generation path are generated; If the first carbon asset is a successor asset, a successor node is generated, and the original historical generation path corresponding to the successor asset is obtained, and the first generation path is assembled based on the viewing authority of the historical generation path and the successor node.
3. The method according to claim 2, characterized in that The first generation path is obtained by assembling the viewing permission based on the historical generation path and the successor node, including: Obtain multiple third role nodes of other identities corresponding to each path node in the historical generation path; If the third role nodes corresponding to the same path node all add searchable information, the corresponding path node is marked as the first path node; If there is added uncheckable information in the third role node corresponding to the same path node, the corresponding path node is marked as a second path node; The first path node and / or the second path node are assembled with the successor node according to the assembly strategy to generate a first generated path.
4. The method according to claim 3, characterized in that The step of assembling the first path node and / or the second path node with the successor node according to the assembly strategy to generate the first generated path includes: If it is determined that there is an adjacent second path node, it is folded into a third path node, and the third path node is in an unselectable state; The remaining first path nodes, third path nodes and successor nodes are connected and assembled in chronological order to obtain a first generated path.
5. The method according to claim 3, characterized in that: If the third role nodes all add searchable information, marking the corresponding path node as the first path node includes: Extract the target information that exists in all the searchable information added by the third role nodes; Retrieving a preset viewing template, filling the target information into the target slot of the preset viewing template, and setting the slot without target information in the preset viewing template to empty; The target slot and the empty slot are counted to obtain the information data encoding of the first path node.
6. The method according to claim 5, characterized in that The step of obtaining information data encoding of the first path node by counting the target slot and the empty slot includes: Count the preset sequence and preset code corresponding to each slot; Extract the character value of the target information, and combine the character value with the preset code to obtain the first subcode of the corresponding target slot; A second subcode corresponding to the empty slot is determined, and the information data code of the first path node is obtained based on the first subcode and the second subcode.
7. The method according to claim 6, characterized in that The determining of the second subcode corresponding to the empty slot, and obtaining the information data code of the first path node based on the first subcode and the second subcode, includes: Delete the target slot to obtain the vacancy order of all empty slots, assign a vacancy character to each empty slot according to the vacancy order, and combine the vacancy character with the preset code to obtain the second subcode of the empty slot; The first subcode and the second subcode are combined in a preset order to obtain an information data code.
8. The method according to claim 2, characterized in that: After determining that a transaction request occurs between any second role node and the first role node, updating the first generated path corresponding to the original asset or the successor asset of the transaction to obtain a second generated path includes: Establish a fourth path node corresponding to this transaction; The fourth path node is connected to the first generated path to update the second generated path, and the order of the newly added nodes is determined and the order code is added.
9. The method according to claim 8, characterized in that The method of determining the first distributed key of the newly added node of the second generation path based on the attributes of the first role node, the second role node and the first carbon asset includes: Extracting the role information of the first role node and the second role node to obtain the first role code and the second role code; Determining a corresponding attribute code according to the attribute of the first carbon asset; The fusion value is obtained by sorting the generation time of the information data code, the sequence code, the first role code, the second role code, and the attribute code, and the first distributed key is obtained by hashing the fusion value.
10. The method according to claim 8, characterized in that The key structure tree of the second generation path is obtained based on the first distributed key and the second distributed key, and the key structure tree is updated based on the role relationship and distributed to the corresponding role nodes, including: Using the keys of other path nodes in the second generated path except the newly added node as the second distributed key; Generate a parent node corresponding to the second generation path, and generate child nodes corresponding to the first distributed key and the second distributed key, and obtain a key structure tree based on the parent node and the child nodes; Determine the third role node of the dimension corresponding to the first role node and the second role node, and update the key structure tree based on the third role node and distribute it to the corresponding role nodes.
11. The method according to claim 10, characterized in that The determining of the third role node of the upper dimension corresponding to the first role node and the second role node, and updating the key structure tree based on the third role node and distributing it to the corresponding role node, includes: Retrieve the role structure tree corresponding to the first role node and the second role node respectively; Determine the third role node located in the upper dimension of the first role node and the second role node of the role structure tree, count the third role nodes corresponding to each first role node and the second role node to generate a role management list; The initial first distributed key or the second distributed key is filled into the role management list, and the key structure tree is updated based on the role management list and distributed to the corresponding role nodes.
12. The method according to claim 11, characterized in that The role-based management of the key structure tree is distributed to the corresponding role nodes after being updated, including: Determine the management right key of each third role node in the role management list, where the management right key is one and corresponds to all other managed role nodes; Filling the management right key into the role management list and making it correspond to the first distributed key or the second distributed key, so that the first distributed key or the second distributed key can be called based on the management right key; Distribute the first distributed key or the second distributed key and the management right key to the corresponding role nodes.
13. The blockchain-based carbon asset encryption platform is characterized by: include: A first module is used to obtain a first generation path of each first carbon asset of a first role node in a blockchain, and divide the first carbon asset into original assets or successor assets based on the first generation path; The second module is used to update the first generation path corresponding to the original asset or the successor asset of the transaction to obtain a second generation path after determining that a transaction request occurs between any second role node and the first role node; A key module, used to determine a first distributed key of a newly added node of a second generation path based on the attributes of the first role node, the second role node and the first carbon asset; The distribution module is used to obtain a key structure tree of a second generation path based on the first distributed key and the second distributed key, and to update the key structure tree based on the role relationship and distribute it to the corresponding role nodes.
Citation Information
Patent Citations
Carbon asset management method and device, equipment and readable storage medium
CN113888167A
Carbon asset management system based on block chain and big data
CN115187400A
Supply full data encryption protection carbon asset management method and system based on block chain
CN117436111A
Electronic file full life cycle management method and system based on block chain technology
CN117667842A
Carbon asset full life cycle management platform based on novel power system
CN118429135A