Digital asset management method, terminal equipment, business platform and storage medium
By implementing the digital asset management method on the SIM card of the terminal device, and using the interaction between the SIM card and the business platform to generate and verify digital vouchers, the problem of high cost and low security in the existing technology is solved, and the effect of reducing costs and improving security is achieved.
Patent Information
- Application Number
- CN202311598886.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-05-27
AI Technical Summary
The existing technology has high cost and low security in metaverse and cloud disk scenarios, and cannot effectively solve the problems of user access, authentication and management.
By implementing the digital asset management method on the SIM card of the terminal device, digital vouchers are generated and verified by the interaction between the SIM card and the business platform to verify whether the access object has the permission to use the target digital asset.
Reduce the cost of digital asset permission management and improve security. By directly verifying permissions on terminal devices, additional authentication devices are avoided, and costs are saved. At the same time, the high security of SIM cards is used to ensure the security of permission verification.
Smart Images

Figure CN120046830A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of digital asset technology, and in particular to a digital asset management method, terminal equipment, service platform and storage medium. Background Art
[0002] In the metaverse scenario, digital people are often a digital mapping of real people in real life in the metaverse. Digital people represent real people to carry out various activities in the metaverse. In the process of carrying out various activities, digital people need to manage relevant usage, management and other permissions, such as the authorized use of digital people in various scenarios. Similar situations also exist for objects in the metaverse. Therefore, digital collections also need to be managed by rights confirmation, traceability, authorization and other rights management to ensure safe buying, selling and dissemination. At the same time, in the cloud disk scenario, the rights confirmation and authorization of each role during data flow need to be associated with the user identity to complete the permission management process. It can be seen that the above-mentioned scenarios need to be associated with personal identity to complete the overall permission management process, but in the relevant technologies, in terms of the technical implementation of solving user access, authentication and management, the overall solution cost is high and the security is low in the permission management process. Summary of the invention
[0003] In view of this, the embodiments of the present application hope to provide a digital asset management method, terminal device, business platform and storage medium, which can reduce the cost of digital asset rights management and improve the security of digital asset rights management.
[0004] The technical solution of the embodiment of the present application is implemented as follows:
[0005] In a first aspect, an embodiment of the present application provides a digital asset management method, which is applied to a first terminal device, wherein the first terminal device includes a first subscriber identity module (Subscriber Identity Module, SIM) card, and the method includes:
[0006] When the first SIM card receives the first application request sent by the access object, a credential acquisition request for accessing the target digital asset is sent to the service platform through the first SIM card; wherein the credential acquisition request carries at least relevant information for generating a digital credential;
[0007] Receiving, through the first SIM card, a digital certificate for accessing the target digital asset sent by the service platform; wherein the digital certificate is generated based on the relevant information for generating the digital certificate carried in the certificate acquisition request;
[0008] Based on the digital certificate, the first SIM card is used to verify whether the access object has the right to use the target digital asset.
[0009] In a second aspect, an embodiment of the present application provides a digital asset management method, which is applied to a business platform, and the method includes:
[0010] When the service platform receives a credential acquisition request for accessing a target digital asset sent by the first SIM card, based on the relevant information for generating a digital credential carried in the credential acquisition request, a digital credential for accessing the target digital asset is generated;
[0011] The digital certificate is sent to the first SIM card, and the digital certificate is used by the first SIM card to verify whether the access object has the right to access the target digital asset based on the digital certificate.
[0012] In a third aspect, an embodiment of the present application provides a first terminal device, wherein the first terminal device includes a first SIM card, and the first terminal device includes:
[0013] A first sending module, configured to send a credential acquisition request for accessing a target digital asset to a service platform through the first SIM card when the first SIM card receives a first application request sent by the access object; wherein the credential acquisition request carries at least relevant information for generating a digital credential;
[0014] A receiving module, configured to receive, through the first SIM card, a digital certificate for accessing the target digital asset sent by the service platform; wherein the digital certificate is generated based on the relevant information for generating the digital certificate carried in the certificate acquisition request;
[0015] The verification module is used to verify whether the access object has the right to use the target digital asset through the first SIM card based on the digital certificate.
[0016] In a fourth aspect, an embodiment of the present application provides a service platform, the service platform comprising:
[0017] a credential generation module, configured to generate a digital credential for accessing the target digital asset based on the relevant information for generating a digital credential carried in the credential acquisition request when the service platform receives a credential acquisition request for accessing the target digital asset sent by the first SIM card;
[0018] The second sending module is used to send the digital certificate to the first SIM card, and the digital certificate is used by the first SIM card to verify whether the access object has the right to access the target digital asset based on the digital certificate.
[0019] In a fifth aspect, an embodiment of the present application provides a first terminal device, which includes: a first processor and a first memory; when the first processor executes the running program stored in the first memory, the digital asset management method on the first terminal device side is implemented.
[0020] In a sixth aspect, an embodiment of the present application provides a business platform, comprising: a second processor and a second memory; when the second processor executes the running program stored in the second memory, the digital asset management method on the above-mentioned business platform side is implemented.
[0021] In the seventh aspect, an embodiment of the present application provides a storage medium on which a computer program is stored, and when the computer program is executed by a processor, the digital asset management method on the first terminal device side mentioned above is implemented; or, when the computer program is executed by a processor, the digital asset management method on the business platform side mentioned above is implemented.
[0022] The embodiment of the present application provides a digital asset management method, a terminal device, a service platform and a storage medium. The method comprises: when a first SIM card receives a first application request sent by an access object, sending a credential acquisition request for accessing a target digital asset to a service platform through the first SIM card; wherein the credential acquisition request carries at least relevant information for generating a digital credential; when the digital asset service platform receives the credential acquisition request for accessing the target digital asset sent by the first SIM card, based on the relevant information for generating a digital credential carried in the credential acquisition request, generating a digital credential for accessing the target digital asset; sending the digital credential to the first SIM card; receiving, through the first SIM card, the digital credential for accessing the target digital asset sent by the service platform; wherein the digital credential is generated based on the relevant information for generating a digital credential carried in the credential acquisition request; and based on the digital credential, verifying, through the first SIM card, whether the access object has the right to use the target digital asset. By adopting the above implementation scheme, in the process of managing digital assets, the service platform interacts with the first SIM card on the first terminal device. When the first SIM card receives the first application request sent by the access object, it first sends a credential acquisition request for accessing the target digital asset to the service platform. The service platform generates a digital credential corresponding to the target digital asset on the service platform side according to the credential acquisition request sent by the first SIM card, and sends the digital credential to the first SIM card of the first terminal device. Since the information of the first SIM card on the first terminal device corresponds one-to-one with the identity information of the access object, the service platform uses the relevant information for generating the digital credential carried in the credential acquisition request for accessing the target digital asset sent by the first SIM card. The generated digital credential corresponds to the identity information of the access object. When the access object wants to access the target digital asset, the first SIM card on the first terminal device uses the received digital credential to verify the information carried by the first SIM card of the access object to confirm whether the access object has the access right to access the target digital asset. Through the first SIM card closely associated with the identity set on the first terminal device side, the use authority of the access object can be directly verified without the need to add additional related equipment for identity authentication, thus saving costs; at the same time, the first SIM card itself has high security, making the access rights to the target digital asset more secure when being verified. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 A schematic diagram of an application scenario of digital humans and digital products in a metaverse scenario;
[0024] Figure 2 A schematic diagram of an application scenario of digital assets in a cloud disk scenario;
[0025] Figure 3 A schematic diagram of the process of using NFT;
[0026] Figure 4 This is a schematic diagram of the process of using DRM technology;
[0027] Figure 5 A digital asset management method process diagram provided in this application embodiment Figure 1 ;
[0028] Figure 6 A digital asset management method process diagram provided in this application embodiment Figure 2 ;
[0029] Figure 7 A schematic diagram of the overall system architecture provided in an embodiment of the present application;
[0030] Figure 8 A digital asset management method process diagram provided in this application embodiment Figure 3 ;
[0031] Fig. 9 A digital asset management method process diagram provided in this application embodiment Figure 4 ;
[0032] Fig.10 A schematic diagram of the structure of a first terminal device provided in an embodiment of the present application Figure 1 ;
[0033] Fig.11 A schematic diagram of the structure of a first terminal device provided in an embodiment of the present application Figure 2 ;
[0034] Fig.12 A schematic diagram of the structure of a service platform provided in the embodiment of the present application Figure 1 ;
[0035] Fig.13 A schematic diagram of the structure of a service platform provided in the embodiment of the present application Figure 2 . DETAILED DESCRIPTION
[0036] In order to enable a more detailed understanding of the features and technical contents of the embodiments of the present application, the technical solution of the present application is further elaborated in detail below in combination with the drawings and specific embodiments of the specification. The attached drawings are for reference only and are not used to limit the embodiments of the present application.
[0037] Unless otherwise defined, all technical and scientific terms used in the embodiments of the present application have the same meaning as those commonly understood by those skilled in the art to which the present application belongs. The terms used in the embodiments of the present application are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0038] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments, but it is understood that "some embodiments" may be the same subset or different subsets of all possible embodiments, and may be combined with each other without conflict. It should also be noted that the terms "first / second / third" involved in the embodiments of the present application are only used to distinguish similar objects and do not represent a specific ordering of the objects. It is understandable that "first / second / third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0039] In the metaverse scenario, digital humans are often a digital mapping of real people in real life in the metaverse. Digital humans represent real people in the metaverse to carry out various activities. Digital humans need to be managed for permissions in the process of carrying out various activities, such as the authorized use of digital humans in various scenarios. Similar situations exist for objects in the metaverse. Who creates which products, which items can be used, and which assets they own? User-generated content in the metaverse sometimes involves issues of property rights protection. For example, digital collections require permission management such as confirmation of ownership, traceability, and authorization to ensure the safe sale, purchase, and dissemination of digital collections. Figure 1 As shown, this is a schematic diagram of the application scenarios of digital humans and digital products in the metaverse scenario.
[0040] In addition to the above-mentioned metaverse scenarios, there are some other scenarios. For example, in the cloud disk scenario, the rights confirmation and authorization of each role during data flow need to be associated with the user identity to complete the permission management process. As users have value-added needs for assets, cloud disks can also be expanded to provide users with business models such as traffic sharing in the future. Figure 2 Schematic diagram of application scenarios of digital assets in the cloud disk scenario shown.
[0041] In the related technology, non-fungible tokens (NFT) are usually used to manage the use rights of digital assets. NFT is a decentralized method based on blockchain technology. It is essentially a string of code used to prove the ownership of digital assets. Figure 3 The figure shows a flow chart of using NFT. Or adopt Digital Rights Management (DRM) technology, which refers to the technology of protecting the rights, controlling the use and managing the production, dissemination, sales and use of digital content, such as audio and video program content. Figure 4 The figure shows a flow chart of using DRM technology.
[0042] For the above-mentioned usage scenarios, in the process of permission management, it is necessary to associate it with personal identity in order to complete the overall permission management process. Whether it is DRM or NFT, it is impossible to solve the user's access, authentication, management, etc. from the terminal device side. Although DRM technology can be implemented based on TEE or security chips, the overall solution is relatively heavy and costly.
[0043] To solve the above problems, the embodiments of the present application provide a method for managing the rights of digital assets of individual users, which can be applied to various cloud business scenarios such as network disks and metaverses. Because the SIM card on the terminal device is highly secure and the SIM card is closely associated with the identity, it can make up for the deficiencies in the above related technologies.
[0044] In an embodiment of the present application, a digital asset management method is provided, such as Figure 5 As shown, applied to a first terminal device, the first terminal device includes a first SIM card, and the method may include:
[0045] S101. When a first SIM card receives a first application request sent by an access target, a credential acquisition request for accessing a target digital asset is sent to a service platform through the first SIM card.
[0046] The credential acquisition request carries at least relevant information for generating a digital credential.
[0047] In an embodiment of the present application, the business platform may include a digital asset business platform. The digital asset business platform varies according to different usage scenarios, including but not limited to a cloud asset storage platform, a digital identity management platform, etc.
[0048] In an embodiment of the present application, the types of target digital assets of an individual user may include: documents, audio and video, pictures, digital people and digital products / items (metaverse) and other types of data created by individuals, such as logos, words, trademarks, etc.
[0049] It should be noted that, in addition to the types of target digital assets described above, other types of digital assets of individual users also fall within the scope of protection of this application.
[0050] In the embodiment of the present application, the first terminal device may be referred to as User Equipment (UE). The first terminal device may be a Personal Communication Service (PCS) phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA) and the like. The terminal device may also be a smart phone, a tablet computer, a PDA, a Mobile Station (MS), a Mobile Terminal and the like. The first terminal device may communicate with one or more network devices via a Radio Access Network (RAN). For example, the terminal device may be a mobile phone (or a "cellular" phone) or a computer with a terminal device, etc., which is not specifically limited in the embodiment of the present application.
[0051] In the embodiment of the present application, the first terminal device includes a first SIM card, and a first application is set on the first SIM card. The first application can be an asset security management card application, which is used to complete the functions of confirming ownership and verifying usage rights. Specifically, the first application supports functions such as signing, verifying signatures, encrypting and decrypting permission-related data, and can also verify and parse the ownership and usage rights of digital assets.
[0052] In an embodiment of the present application, the first application request may include: an ownership certificate application request and a digital asset use request.
[0053] In the embodiment of the present application, the access object includes a user who accesses the target digital asset.
[0054] In an embodiment of the present application, when the digital asset is not public, the access object can first register the digital asset, authenticate the digital asset, and apply for the digital asset ownership certificate. The access object sends a digital asset ownership certificate application request to the first application on the first SIM card. When the first application on the first SIM card receives the digital asset ownership certificate application request, it sends an ownership certificate acquisition request for accessing the target digital asset to the service platform. The ownership certificate acquisition request carries at least relevant information for generating the ownership certificate.
[0055] In an embodiment of the present application, the relevant information for generating the ownership certificate includes at least the identity information of the access object, the asset information of the access object, etc.
[0056] In an embodiment of the present application, when digital assets are made public, when an access object applies to use certain digital assets, the access object sends a digital asset use request to a first application on a first SIM card. When the first application on the first SIM card receives the digital asset use application request, it sends a use right acquisition request to access the target digital asset to the service platform. The use right certificate acquisition request carries at least relevant information for generating a use right certificate.
[0057] In the embodiment of the present application, the relevant information for generating the usage right certificate includes at least the identity information of the access object, the target asset information that the access object wants to access, etc.
[0058] S102: Receive, through the first SIM card, a digital certificate for accessing a target digital asset sent by the digital asset service platform.
[0059] The digital certificate is generated based on the relevant information for generating the digital certificate carried in the certificate acquisition request.
[0060] In the embodiment of the present application, when the digital asset is not public, the digital certificate is the digital asset ownership certificate. When the digital asset is public, the digital certificate is the digital asset usage right certificate.
[0061] In an embodiment of the present application, the digital asset ownership certificate is generated by the business platform based on the identity information of the access object carried in the credential acquisition request, the accessed digital asset information, the platform signature of the business platform, and the ciphertext encrypted using the public key of the owner of the relevant information.
[0062] In an embodiment of the present application, after the business platform generates a digital asset ownership certificate, it adds the digital asset ownership certificate to the response message corresponding to the certificate acquisition request through an APDU write instruction, and sends it to the first application on the first SIM card. After the first application receives the digital asset ownership certificate, it stores the digital asset ownership certificate.
[0063] In an embodiment of the present application, the digital certificate includes a digital asset usage right certificate, and receiving the digital certificate for accessing the target digital asset sent by the service platform through the first SIM card includes: when the target digital asset is published, receiving the usage right certificate sent by the service platform through the first SIM card.
[0064] The usage right certificate is generated by the service platform based on the usage authority for accessing the target digital asset sent by the second SIM card included in the second terminal device; the usage authority is the authority to access the target digital asset allocated by the second SIM card to the access object.
[0065] In the embodiment of the present application, a second application is set on the second SIM card, and the second application may be an asset security management card application.
[0066] In an embodiment of the present application, the process of the business platform generating a digital asset usage right certificate is as follows: when the business platform receives a request message for applying to use the target digital asset, the business platform searches for the identity information of the owner corresponding to the target digital asset (user 2) based on the identity information of the access object in the application request message, the target digital asset accessed by the access object, and other information, and sends a permission allocation request to the owner corresponding to the target digital asset, wherein the permission allocation request includes the platform signature of the business platform, the identity information of the access object, and the target digital asset to be accessed by the access object, and other information. When the owner of the target digital asset agrees that the access object can access the target digital asset, the owner allocates access rights to the access object.
[0067] In an embodiment of the present application, the owner corresponding to the target digital asset sends a permission allocation request to the second application set on the second SIM card on the second terminal device through an APDU instruction, and the permission allocation request contains the platform signature of the business platform and the assigned access rights. The allocation of consent access rights is set through the second application. Specifically, the platform signature of the business platform is first verified by the second application, and the assigned access rights are digitally signed, and the data related to the access rights are encrypted at the same time. The permission allocation response message is sent to the second terminal device through the second application through APDU, wherein the permission allocation response message contains the platform signature of the business platform, the data ciphertext of the access rights, etc. The second terminal device forwards the permission allocation response message containing the platform signature of the business platform, the data ciphertext of the access rights, etc. to the business platform, and the business platform verifies the platform signature of the business platform in the access rights, and decrypts the data ciphertext of the access rights. The business platform generates a digital asset use right certificate based on the identity information, usage rights, and other information of the access object carried in the access rights allocation response message.
[0068] In an embodiment of the present application, after the business platform generates a digital asset usage right certificate, it adds the digital asset usage right certificate to the response message corresponding to the certificate application request through an APDU write instruction, and sends it to the first application set on the first SIM card. Based on this, the first application set on the first SIM card can obtain the digital asset usage right certificate.
[0069] S103: Based on the digital certificate, verify through the first SIM card whether the access object has the right to use the target digital asset.
[0070] In the embodiment of the present application, when the digital certificate is a digital asset ownership certificate, before verifying whether the access object has the right to use the target digital asset through the first SIM card based on the digital certificate, if the target digital asset has not been released, the first SIM card receives an ownership certificate confirmation request for the access object to use the target digital asset, and the ownership certificate confirmation request carries the first user identity information and the first digital asset information.
[0071] In an embodiment of the present application, when the target digital asset is not released, a first application set on the first SIM card receives an ownership certificate acquisition request sent by the access object, wherein the first user identity information carried in the ownership certificate acquisition request is the identity information carried by the first SIM card of the access object, and the first digital asset information is the digital asset information to be accessed by the access object.
[0072] Correspondingly, based on the digital certificate, verifying through the first SIM card whether the access object has the right to use the target digital asset includes: based on the first user identity information, the first digital asset information and the ownership certificate, verifying through the first SIM card whether the access object has the right to use the target digital asset.
[0073] In an embodiment of the present application, when the target digital asset is not published, when the access object accesses the target digital asset, an ownership certificate confirmation request is sent to the first application set on the first SIM card. The certificate confirmation request can be sent via an APDU instruction. The certificate confirmation request includes the first digital asset information accessed by the access object and the first user identity information of the access object.
[0074] It should be noted that the first user identity information may be the identity information of a user accessing a target digital asset, and the first digital asset information may be the digital asset information that the first user wants to access.
[0075] In the embodiment of the present application, the first application set on the first SIM card confirms the ownership certificate after receiving the certificate confirmation request. The specific execution process is as follows: ① Verify the identity information of the first user of the access object, and use the private key to decrypt the data; ② Verify the platform signature of the service platform; ③ Verify whether the first digital asset information accessed is consistent with the target digital asset information; ④ Return the verification result according to the verification situation.
[0076] In an embodiment of the present application, after obtaining the verification results through the above steps ① to ④, the verification results are added to the credential confirmation response message, and the digital asset access object accesses the target digital asset based on the verification results returned by the first application set on the first SIM card.
[0077] It should be noted that when at least one of the above steps ① to ③ does not meet the requirements, the verification result is that the access object has no access rights to the target digital asset.
[0078] When requirements ① to ③ are met, the verification result is that the digital asset access object has access rights to the target digital asset.
[0079] In an embodiment of the present application, based on the first user identity information, the first digital asset information and the ownership certificate, whether the access object has the right to use the target digital asset is verified through the first SIM card, including: comparing through the first SIM card whether the first user identity information is consistent with the user identity information included in the ownership certificate and whether the first digital asset information is consistent with the target digital asset information included in the ownership certificate; when the first user identity information is consistent with the user identity information included in the ownership certificate, and the first digital asset information is consistent with the target digital asset information included in the ownership certificate, it is determined that the access object has the right to use the target digital asset; when the first user identity information is inconsistent with the user identity information included in the ownership certificate, and / or the first digital asset information is inconsistent with the target digital asset information included in the ownership certificate, it is determined that the access object does not have the right to use the target digital asset.
[0080] In the embodiment of the present application, since the ownership certificate confirmation request carries the first user identity information and the first digital asset information, the ownership certificate contains the user identity information that is allowed to access the target digital asset, and the digital asset information corresponding to the user identity information, therefore, the first application set on the first SIM card can determine through the ownership certificate confirmation request whether the first user identity information of the access object is consistent with the user identity information contained in the ownership certificate, and whether the first digital asset to be accessed by the access object is consistent with the target digital asset information contained in the ownership certificate. If any of the comparison results are inconsistent, the access object does not have access rights to the target digital asset.
[0081] Exemplarily, the ownership certificate includes user A and file A that user A can access. At this time, if user A initiates an ownership confirmation request for accessing file A to the first application, the first application confirms whether the ownership certificate includes user identity information of user A and file A information corresponding to user A's identity information based on the user A's identity information carried in the ownership confirmation request and the file A information that user A wants to access. This can be achieved through a one-to-one comparison or a matching method. If the user A's identity information is consistent with the user A included in the ownership certificate, and the accessed file A is consistent with the file A in the ownership certificate, then user A has permission to access file A; otherwise, he has no access permission.
[0082] If user A wants to access file B, because the file A that user A can access is inconsistent with file B, user A does not have the access permission to file B.
[0083] In an embodiment of the present application, based on the digital certificate, the first SIM card is used to verify whether the access object has the right to use the target digital asset, including: parsing the asset key and the usage right from the usage right certificate, and verifying the asset key and the usage right through the first SIM card to determine whether the access object has the right to use the target digital asset.
[0084] In the embodiment of the present application, when the digital certificate includes a digital asset usage right certificate, based on the digital asset usage right certificate, a first application set on the first SIM card verifies whether the access object has the right to use the target digital asset.
[0085] In the embodiment of the present application, when the first application set on the first SIM card receives the digital asset usage right certificate sent by the service platform, the first application set on the first SIM card verifies or checks the digital asset usage right certificate. Specifically, it includes the following processes: ① verifying the platform signature of the service platform; ② decrypting the digital asset key; ③ decrypting the usage rights. Using the decrypted digital asset key, the user can decrypt the target digital asset and use the decrypted usage rights to access the target digital asset.
[0086] In an embodiment of the present application, through the above processes ① to ③, it can be obtained whether the access object has the right to use the target digital asset, and the decrypted digital asset key and the right to use the target digital asset are added to the digital asset usage response message. The access object decrypts the target digital asset based on the digital asset key in the digital asset usage response message, and uses the target digital asset based on the usage rights.
[0087] Based on the above embodiment, when the first application set on the first SIM card verifies that the access object has the right to use the target digital asset, the access object accesses the target digital asset based on the usage permission; when the first application set on the first SIM card verifies that the access object does not have the right to use the target digital asset, the access object cannot access the target digital asset.
[0088] In the embodiment of the present application, the first application set on the first SIM card verifies the digital asset ownership certificate or the digital asset usage certificate, determines the usage rights of the access object when accessing the target digital asset, and the access object accesses the target digital asset based on the usage rights. The usage rights can be information such as the number of days, hours, minutes, months, etc. when the access object has access to the target digital asset, or prohibits the access object from accessing the target digital asset.
[0089] It can be understood that in a digital asset management method provided in an embodiment of the present application, in the process of managing digital assets, an interaction is performed between a service platform and a first SIM card on a first terminal device. When the first SIM card receives a first application request sent by an access object, it first sends a credential acquisition request for accessing the target digital asset to the service platform. The service platform generates a digital credential corresponding to the target digital asset on the service platform side according to the credential acquisition request received from the first SIM card, and sends the digital credential to the first SIM of the first terminal device. Because the information of the first SIM card on the first terminal device corresponds one-to-one with the identity information of the access object, the service platform uses the relevant information for generating the digital credential carried in the credential acquisition request for accessing the target digital asset sent by the first SIM card. The generated digital credential corresponds to the identity information of the access object. When the access object wants to access the target digital asset, the first SIM card on the first terminal device uses the received digital credential to verify the information carried by the first SIM card of the access object to confirm whether the access object has access rights to access the target digital asset. By setting a first SIM card closely associated with the identity on the first terminal device side, the use authority of the access object can be directly verified without the need to add additional related equipment for identity authentication, thus saving costs; at the same time, the first SIM card itself has high security, making the access rights to the target digital asset more secure when being verified.
[0090] Based on the above embodiments, the present application also proposes a digital asset management method, such as Figure 6 As shown, applied to a business platform, the method includes:
[0091] S201: When the service platform receives a credential acquisition request for accessing a target digital asset sent by a first SIM card, the service platform generates a digital credential for accessing the target digital asset based on relevant information for generating a digital credential carried in the credential acquisition request.
[0092] In the embodiment of the present application, the certificate acquisition request includes a request to acquire an ownership certificate of a target digital asset or a request to acquire a usage right certificate of a target digital asset.
[0093] In the embodiment of the present application, when the certificate acquisition request includes a request to acquire the ownership certificate of the target digital asset, the generated digital certificate is the ownership certificate of the target digital asset. When the certificate acquisition request includes a request to acquire the right to use certificate of the target digital asset, the generated digital certificate is the right to use certificate of the target digital asset.
[0094] In an embodiment of the present application, the digital certificate includes an ownership certificate, and a digital certificate for accessing a target digital asset is generated based on relevant information for generating the digital certificate carried in a certificate acquisition request, including: when the certificate acquisition request is an ownership certificate application request, obtaining user identity information and target digital asset information from the ownership certificate application request; and generating an ownership certificate for accessing the target digital asset based on the user identity information and the target digital asset information.
[0095] In an embodiment of the present application, after the ownership certificate is generated, the ownership certificate is sent to a first application on a first terminal device. The first application set on the first terminal device verifies whether the digital asset access object has the right to use the target digital asset based on the first user identity information, the first digital asset information and the ownership certificate carried in the ownership certificate confirmation request.
[0096] In the embodiment of the present application, the first user identity information in the ownership certificate request is the user identity information of the user applying to access the target digital asset, and the target digital asset is the digital asset to be accessed. The business platform generates the ownership certificate based on the identity information of the access object applying to access the target digital asset, the target digital asset and the platform signature of the business platform, and the ciphertext encrypted by the owner's public key of the relevant information.
[0097] In the embodiment of the present application, after the ownership certificate for accessing the target digital asset is generated, the ownership certificate is sent to the first SIM card, and the ownership certificate is used for the first SIM card to verify whether the access object has the right to use the target digital asset based on the first user identity information, the first digital asset information and the ownership certificate carried in the received ownership certificate confirmation request.
[0098] In an embodiment of the present application, the ownership certificate is sent to a first application set on a first terminal device. The first application set on the first terminal device verifies whether the digital asset access object has the right to use the target digital asset based on the first user identity information, the first digital asset information and the ownership certificate carried in the ownership certificate confirmation request.
[0099] It should be noted that the process of the first application set on the first terminal device verifying whether the access object has the right to use the target digital asset based on the first user identity information, the first digital asset information and the ownership certificate carried in the ownership certificate confirmation request can be referred to the implementation process in the above embodiment and will not be repeated here.
[0100] In an embodiment of the present application, when the digital certificate includes a usage right certificate, the service platform generates a usage right certificate based on the usage right to access the target digital asset sent by the second SIM card included in the second terminal device, and sends the usage right certificate to the first SIM card.
[0101] The usage authority is the authority allocated by the second SIM card to the access object for accessing the target digital asset.
[0102] In the embodiment of the present application, the second application is set on the second SIM card.
[0103] In an embodiment of the present application, before receiving the usage permission for accessing the target digital asset sent by the second SIM card included in the second terminal device, when the credential acquisition request sent by the first SIM card is the usage permission credential application request information, the user identity information and the target digital asset are determined from the usage permission credential application request information; the second terminal device corresponding to the target digital asset is searched based on the target digital asset; and a permission allocation request for accessing the target digital asset is sent to the second SIM card of the second terminal device; correspondingly, receiving the usage permission for accessing the target digital asset sent by the second SIM card included in the second terminal device includes: receiving the permission allocation information corresponding to the permission allocation request sent by the second SIM card, and acquiring the usage permission of the user identity information to access the target digital asset from the permission allocation information.
[0104] In an embodiment of the present application, when the business platform receives an application request for a usage right certificate for accessing a target digital asset sent by a first application set on a first terminal device, the business platform searches for the identity information of the access object carried in the application request message, the target digital asset accessed by the access object, and other information, and sends a permission allocation request to the owner corresponding to the target digital asset, wherein the permission allocation request includes the platform signature of the business platform, the identity information of the access object, and the target digital asset information to be accessed by the access object. When the owner of the second terminal device corresponding to the target digital asset information agrees that the access object can access the target digital asset, the owner allocates access rights to the access object.
[0105] In an embodiment of the present application, the owner corresponding to the target digital asset information sends a permission allocation request to the second application set on the second SIM card on the second terminal device through an APDU instruction, and the permission allocation request contains the platform signature of the business platform and the assigned access rights. The second application set on the second SIM card agrees to the allocation of access rights. Specifically, the second application set on the second SIM card first verifies the platform signature of the business platform, and digitally signs the assigned access rights, and encrypts the data related to the access rights. The second application set on the second SIM card sends the permission allocation response to the second terminal device through APDU, wherein the permission allocation response message contains the platform signature of the business platform, the data ciphertext of the access rights, etc. The second terminal device forwards the permission allocation response message containing the platform signature of the business platform, the data ciphertext of the access rights, etc. to the business platform, and the business platform verifies the platform signature of the business platform in the access rights, and decrypts the data ciphertext of the access rights, and determines the use rights of the target digital assets corresponding to the user identity information from the permission allocation information. The business platform generates a digital asset use right certificate based on the identity information, use rights, and other information of the access object carried in the access rights allocation response.
[0106] S202: Send the digital certificate to the first SIM card, where the digital certificate is used by the first SIM card to verify whether the access object has the right to access the target digital asset based on the digital certificate.
[0107] In an embodiment of the present application, after the business platform generates a digital asset usage right certificate, it adds the digital asset usage right certificate to a certificate application response message through an APDU write instruction, and sends it to a first application set on the first SIM card. The first application set on the first SIM card obtains the target digital asset usage right certificate, and the first application set on the first SIM card verifies whether the access object has the right to access the target digital asset based on the target digital asset usage right certificate.
[0108] In an embodiment of the present application, after the business platform generates the ownership certificate of the digital asset, it sends the ownership certificate of the digital asset to the first application set on the first SIM card. The first application set on the first SIM card stores the ownership certificate and verifies whether the access object has the right to access the target digital asset based on the ownership certificate.
[0109] It should be noted that the implementation process of whether the first application set on the first SIM card has the right to access the target digital asset can refer to the above embodiment, which will not be repeated here.
[0110] It can be understood that in a digital asset management method provided in an embodiment of the present application, in the process of managing digital assets, interaction is performed between a service platform and a first SIM card on a first terminal device. When the first SIM card receives a first application request sent by an access object, it first sends a credential acquisition request for accessing the target digital asset to the service platform. The service platform generates a digital credential corresponding to the target digital asset on the service platform side according to the credential acquisition request received from the first SIM card, and sends the digital credential to the first SIM card of the first terminal device. Because the information of the first SIM card on the first terminal device corresponds one-to-one with the identity information of the access object, the service platform uses the relevant information for generating the digital credential carried in the credential acquisition request for accessing the target digital asset sent by the first SIM card. The generated digital credential corresponds to the identity information of the access object. When the access object wants to access the target digital asset, the first SIM card on the first terminal device uses the received digital credential to verify the information carried by the first SIM card of the access object to confirm whether the access object has access rights to access the target digital asset. Through the first SIM card closely associated with the identity set on the first terminal device side, the use authority of the access object can be directly verified without the need to add additional related equipment for identity authentication, thus saving costs; at the same time, the high security of the first SIM card itself makes the verification of access rights to the target digital asset more secure.
[0111] Based on the above embodiments, the present application also provides an overall architecture diagram for implementing the digital asset management method, such as Figure 7 As shown, it includes a digital asset business platform, and the digital asset business platform includes a digital asset management module. In the above embodiment, the interaction with the digital asset business platform can be based on the interaction with the digital asset management module included in the digital asset business platform. The architecture diagram also includes a first application, which can be a digital asset security management card application, and the first application is set in the first SIM card.
[0112] It should be noted that Figure 7 The IF1 interface is the interface between the first SIM card and the asset security management module, which realizes the secure transmission of authority management related data.
[0113] Digital asset security management card application: located in the first SIM card, completes the functions of confirming ownership and verifying usage rights. It supports functions such as signing, verifying, encrypting and decrypting permission-related data, and can verify and analyze ownership and usage rights.
[0114] Digital asset security management module: integrated into the digital asset business platform, completes the functions of generating ownership and allocating usage rights. It supports the generation of ownership certificates based on asset owner identity information, asset information, etc.; it supports the generation of usage rights certificates based on user identity information, asset keys, etc.
[0115] Digital asset business platforms vary according to usage scenarios, including but not limited to cloud asset storage platforms, digital identity management platforms, etc.
[0116] Based on the above embodiment, the embodiment of the present application also provides a digital asset management method. In this method, when the digital asset is not released, the user verifies the ownership through the SIM card side before using the digital asset. The digital asset can be used only after the verification is passed. Figure 8 shown.
[0117] It should be noted that the ownership application process: the asset security management module on the business platform side generates an ownership certificate based on user identity information, asset information, signature, and ciphertext of some data, and the SIM card side stores the certificate;
[0118] Ownership confirmation process: The asset security management card application on the SIM card side uses the user's private key to decrypt the data, verify the user's identity, verify the digital signature on the business platform side, and verify whether the digital asset information is consistent. If the verification passes, a response result is returned, allowing the user to use the asset. Otherwise, relevant result information such as non-owner or refusal to use is returned.
[0119] Based on the above embodiments, the embodiment of the present application also proposes a digital asset management method. In this method, when a digital asset is released, other users apply for the target digital asset's owner's right to use the target digital asset. The asset security management module on the service platform side needs to allocate the asset use right. The second SIM card side agrees to the allocation of the use right and supports the allocation process. At the same time, the first SIM card side needs to further verify the allocated use right. Specifically, the flow diagram of the interaction between the first terminal device, the second terminal device and the service platform is as follows: Fig. 9 shown.
[0120] It should be noted that the authority allocation process is as follows: the asset security management module on the business platform side forwards the use application based on the identity of the digital asset owner, the digital asset owner allocates the use rights to the user, the asset security management card application agrees to the allocation of the use rights, and the business platform side generates the use right certificate based on the asset key, user identity information, use rights and other contents, and sends it to the first SIM card side;
[0121] Credential verification process: The asset security management card application of the first SIM card verifies and parses the usage right certificate, and returns the parsed key, usage rights and other content to the user. The user decrypts and uses the asset based on this information.
[0122] If multiple users apply for permission, the usage certificate will contain the identity information of multiple users (users) and the asset key ciphertext encrypted with different public keys. Different users use their own card private keys to decrypt the ciphertext and obtain the asset key.
[0123] It should be noted that the specific implementation process has been explained in the above embodiments and will not be repeated here.
[0124] Based on the above embodiments, the advantages of the embodiments of the present application compared to the related technologies are that they do not need to rely on blockchain technology, do not need to put assets on the chain, and are strongly bound to personal identity. They provide secure title confirmation and authorization management for personal assets through ownership certificates, usage rights certificates, etc., and are lightweight and low-cost based on SIM cards, making up for the shortcomings of existing terminal solutions.
[0125] Based on the above embodiments, the present application embodiment provides a first terminal device 1. The first terminal device 1 includes a first SIM card, such as Fig.10 As shown, the first terminal device 1 includes:
[0126] A first sending module 10 is used to send a credential acquisition request for accessing a target digital asset to a service platform through the first SIM card when the first SIM card receives a first application request sent by the access object; wherein the credential acquisition request carries at least relevant information for generating a digital credential;
[0127] The receiving module 11 is used to receive, through the first SIM card, a digital certificate for accessing the target digital asset sent by the service platform; wherein the digital certificate is generated based on the relevant information for generating the digital certificate carried in the certificate acquisition request;
[0128] The verification module 12 is used to verify whether the access object has the right to use the target digital asset based on the digital certificate through the first SIM card.
[0129] Optionally, the first terminal device 1 further includes: an access module;
[0130] The access module is used to generate first information when the first SIM card verifies that the access object has the right to use the target digital asset, and the first information is used to instruct the access object to access the target digital asset based on the right to use; and generate second information when the first SIM card verifies that the access object does not have the right to use the target digital asset, and the second information is used to instruct the access object to prohibit access to the target digital asset.
[0131] Optionally, the digital certificate includes a certificate of ownership;
[0132] The receiving module 11 is further configured to receive, through the first SIM card, a request for confirmation of ownership certificate when the target digital asset is used by the access object when the target digital asset is not released, wherein the request for confirmation of ownership certificate carries the first user identity information and the first digital asset information;
[0133] The verification module 12 is further used to verify whether the access object has the right to use the target digital asset through the first SIM card based on the first user identity information, the first digital asset information and the ownership certificate.
[0134] Optionally, the first terminal device 1 further includes: a comparison module and a determination module;
[0135] A comparison module, configured to compare, through the first SIM card, whether the first user identity information is consistent with the user identity information included in the ownership certificate and whether the first digital asset information is consistent with the target digital asset information included in the ownership certificate;
[0136] A determination module is used to determine that the access object has the right to use the target digital asset when the first user identity information is consistent with the user identity information included in the ownership certificate, and the first digital asset information is consistent with the target digital asset information included in the ownership certificate; and to determine that the access object does not have the right to use the target digital asset when the first user identity information is inconsistent with the user identity information included in the ownership certificate, and / or the first digital asset information is inconsistent with the target digital asset information included in the ownership certificate.
[0137] Optionally, the receiving module 11 is further used to receive, through the first SIM card, a usage right certificate sent by the service platform when the target digital asset is published; wherein the usage right certificate is generated by the service platform based on the usage permission for accessing the target digital asset sent by the second SIM card included in the second terminal device; the usage permission is the permission to access the target digital asset allocated by the second SIM card to the access object.
[0138] Optionally, the verification module 12 is further used to parse the asset key and the usage permission from the usage right certificate, and verify the asset key and the usage permission through the first SIM card to determine whether the access object has the usage permission of the target digital asset.
[0139] An embodiment of the present application provides a first terminal device, the first terminal device includes a first SIM card, when the first SIM card receives a first application request sent by an access object, a credential acquisition request for accessing a target digital asset is sent to a service platform through the first SIM card; wherein the credential acquisition request carries at least relevant information for generating a digital credential; through the first SIM card, a digital credential for accessing the target digital asset sent by the service platform is received; wherein the digital credential is generated based on the relevant information for generating the digital credential carried in the credential acquisition request; based on the digital credential, whether the access object has the right to use the target digital asset is verified through the first SIM card. It can be seen that a first terminal device proposed in an embodiment of the present application interacts with a first SIM card on the first terminal device through a service platform during the process of managing digital assets. When the first SIM card receives a first application request sent by an access object, it first sends a credential acquisition request for accessing the target digital asset to the service platform. The service platform generates a digital credential corresponding to the target digital asset on the service platform side according to the credential acquisition request sent by the received first SIM card, and sends the digital credential to the first SIM card of the first terminal device. Because the information of the first SIM card on the first terminal device corresponds one-to-one with the identity information of the access object, the service platform uses the relevant information for generating the digital credential carried in the credential acquisition request for accessing the target digital asset sent by the first SIM card. The generated digital credential corresponds to the identity information of the access object. When the access object wants to access the target digital asset, the first SIM card on the first terminal device uses the received digital credential to verify the information carried by the first SIM card of the access object to confirm whether the access object has access rights to access the target digital asset. Through the first SIM card closely associated with the identity set on the first terminal device side, the use authority of the access object can be directly verified without the need to add additional related equipment for identity authentication, thus saving costs; at the same time, the first SIM card itself has high security, making the access rights to the target digital asset more secure when being verified.
[0140] Fig.11 This is a schematic diagram of the composition structure of a first terminal device 1 provided in an embodiment of the present application. In practical applications, based on the same disclosed concept of the above embodiments, Fig.11 As shown, the first terminal device 1 of the embodiment of the present application includes: a first processor 13, a first memory 14 and a first communication bus 15.
[0141] In the process of a specific embodiment, the first processor 13 may be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing image processing device (DSPD), a programmable logic image processing device (PLD), a field programmable gate array (FPGA), a CPU, a controller, a microcontroller, and a microprocessor. It can be understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other, and this embodiment does not specifically limit it.
[0142] In the embodiment of the present application, the first communication bus 15 is used to realize the connection and communication between the first processor 13 and the first memory 14; when the first processor 13 executes the running program stored in the first memory 14, the following digital asset management method is implemented:
[0143] When the first SIM card receives the first application request sent by the access object, a credential acquisition request for accessing the target digital asset is sent to the service platform through the first SIM card; wherein the credential acquisition request carries at least relevant information for generating a digital credential; through the first SIM card, a digital credential for accessing the target digital asset sent by the service platform is received; wherein the digital credential is generated based on the relevant information for generating the digital credential carried in the credential acquisition request; based on the digital credential, whether the access object has the right to use the target digital asset is verified through the first SIM card.
[0144] Furthermore, the first processor 13 is also used to generate first information when the first SIM card verifies that the access object has the right to use the target digital asset, and the first information is used to instruct the access object to access the target digital asset based on the usage permission; and to generate second information when the first SIM card verifies that the access object does not have the right to use the target digital asset, and the second information is used to instruct the access object to prohibit access to the target digital asset.
[0145] Furthermore, the first processor 13 is also used to receive, through the first SIM card, an ownership certificate confirmation request when the access object uses the target digital asset when the target digital asset is not released, and the ownership certificate confirmation request carries the first user identity information and the first digital asset information.
[0146] Furthermore, the first processor 13 verifies whether the access object has the right to use the target digital asset through the first SIM card based on the first user identity information, the first digital asset information and the ownership certificate.
[0147] Furthermore, the first processor 13 is further configured to compare, through the first SIM card, whether the first user identity information is consistent with the user identity information included in the ownership certificate, and whether the first digital asset information is consistent with the target digital asset information included in the ownership certificate; when the first user identity information is consistent with the user identity information included in the ownership certificate, and the first digital asset information is consistent with the target digital asset information included in the ownership certificate, determine that the digital asset access object has the right to use the target digital asset; when the first user identity information is inconsistent with the user identity information included in the ownership certificate, and / or the first digital asset information is inconsistent with the target digital asset information included in the ownership certificate, determine that the digital asset access object does not have the right to use the target digital asset.
[0148] Furthermore, the first processor 13 is also used to receive, through the first SIM card, a usage right certificate sent by the service platform when the target digital asset is released; wherein the usage right certificate is generated by the service platform based on the usage permission for accessing the target digital asset sent by the second SIM card included in the second terminal device; and the usage permission is the permission to access the target digital asset allocated by the second SIM card to the digital asset access object.
[0149] Furthermore, the first processor 13 is also used to parse the asset key and the usage permission from the usage right certificate, and verify the asset key and the usage permission through the first SIM card to determine whether the digital asset access object has the usage permission of the target digital asset.
[0150] The present application embodiment also provides a service platform 2, such as Fig.12 As shown, the business platform 2 includes:
[0151] The credential generation module 20 is used to generate a digital credential for accessing the target digital asset based on the relevant information for generating a digital credential carried in the credential acquisition request when the service platform receives a credential acquisition request for accessing the target digital asset sent by the first SIM card;
[0152] The second sending module 21 is used to send the digital certificate to the first SIM card, and the digital certificate is used by the first SIM card to verify whether the access object has the right to access the target digital asset based on the digital certificate.
[0153] Optionally, the digital asset business platform 2 further includes: an acquisition module;
[0154] An acquisition module, configured to acquire user identity information and target digital asset information from the ownership certificate application request when the certificate acquisition request is an ownership certificate application request;
[0155] The credential generation module 20 is further used to generate an ownership credential for accessing the target digital asset based on the user identity information and the target digital asset information.
[0156] Optionally, the second sending module 21 is further used to send the ownership certificate to the first SIM card, and the ownership certificate is used for the first SIM card to verify whether the access object has the right to use the target digital asset based on the first user identity information, the first digital asset information and the ownership certificate carried in the received ownership certificate confirmation request.
[0157] Optionally, the digital asset business platform 2 further includes: a receiving module;
[0158] a receiving module, configured to receive, when the digital credential includes a usage right credential, a usage right for accessing the target digital asset sent by a second SIM card included in a second terminal device, wherein the usage right is a right for accessing the target digital asset allocated by the second SIM card to the access object;
[0159] The certificate generation module 20 is further configured to generate the usage right certificate based on the usage permission for accessing the target digital asset, and send the usage right certificate to the first SIM card.
[0160] Optionally, the determination module is further configured to determine the user identity information and the target digital asset from the usage right certificate application request information when the certificate acquisition request sent by the first SIM card is a usage right certificate application request information;
[0161] The second sending module 21 is further used to search for a second terminal device corresponding to the target digital asset based on the target digital asset; and send a permission allocation request for accessing the target digital asset to a second SIM card of the second terminal device;
[0162] The receiving module is further used to receive the permission allocation information corresponding to the permission allocation request sent by the second SIM card, and obtain the use permission of the user identity information to access the target digital asset from the permission allocation information.
[0163] A service platform provided in an embodiment of the present application generates a digital credential for accessing a target digital asset based on relevant information for generating a digital credential carried in the credential acquisition request when the service platform receives a credential acquisition request for accessing a target digital asset; and sends the digital credential to the first SIM card, where the digital credential is used by the first SIM card to verify whether the access object has the right to access the target digital asset based on the digital credential. It can be seen that a service platform proposed in an embodiment of the present application interacts with a first SIM card on a first terminal device during the process of managing digital assets. When the first SIM card receives a first application request sent by an access object, it first sends a credential acquisition request for accessing the target digital asset to the service platform. The service platform generates a digital credential corresponding to the target digital asset on the service platform side according to the credential acquisition request sent by the received first SIM card, and sends the digital credential to the first SIM card of the first terminal device. Because the information of the first SIM card on the first terminal device corresponds one-to-one with the identity information of the access object, the service platform uses the relevant information for generating the digital credential carried in the credential acquisition request for accessing the target digital asset sent by the first SIM card. The generated digital credential corresponds to the identity information of the access object. When the access object wants to access the target digital asset, the first SIM card on the first terminal device uses the received digital credential to verify the information carried by the first SIM card of the access object to confirm whether the access object has access rights to access the target digital asset. Through the first SIM card closely associated with the identity set on the first terminal device side, the use authority of the access object can be directly verified without the need to add additional related equipment for identity authentication, thus saving costs; at the same time, the first SIM card itself has high security, making the access rights to the target digital asset more secure when being verified.
[0164] Fig.13 A schematic diagram of the composition structure of a service platform 2 provided in an embodiment of the present application. In practical applications, based on the same public concept of the above embodiments, Fig.13As shown, the service platform 2 of the embodiment of the present application includes: a second processor 22 , a second memory 23 and a second communication bus 24 .
[0165] In the specific embodiment, the second processor 22 may be at least one of ASIC, DSP, DSPD, PLD, FPGA, CPU, controller, microcontroller, and microprocessor. It is understandable that for different devices, the electronic device used to implement the processor function may also be other, which is not specifically limited in this embodiment.
[0166] In the embodiment of the present application, the second communication bus 24 is used to realize the connection and communication between the second processor 22 and the second memory 23; when the second processor 22 executes the running program stored in the second memory 23, the following digital asset management method is implemented:
[0167] When the digital asset service platform receives a credential acquisition request for accessing a target digital asset sent by the first SIM card, the digital asset service platform generates a digital credential for accessing the target digital asset based on the relevant information for generating the digital credential carried in the credential acquisition request; and sends the digital credential to the first SIM card, where the digital credential is used by the first SIM card to verify whether the access object has the right to access the target digital asset based on the digital credential.
[0168] Furthermore, the second processor 22 is also used to obtain user identity information and target digital asset information from the ownership certificate application request when the certificate acquisition request is an ownership certificate application request; and generate an ownership certificate for accessing the target digital asset based on the user identity information and the target digital asset information.
[0169] Furthermore, the second processor 22 is also used to send the ownership certificate to the first SIM card, and the ownership certificate is used for the first SIM card to verify whether the access object has the right to use the target digital asset based on the first user identity information, the first digital asset information and the ownership certificate carried in the received ownership certificate confirmation request.
[0170] Furthermore, the second processor 22 is further configured to, when the digital credential includes a usage right certificate, receive a usage right for accessing the target digital asset sent by a second SIM card included in a second terminal device, wherein the usage right is a right allocated by the second SIM card to the access object for accessing the target digital asset; generate the usage right certificate based on the usage right for accessing the target digital asset, and send the usage right certificate to the first SIM card.
[0171] Further, the second processor 22 is further configured to, when the credential acquisition request sent by the first SIM card is a usage right credential application request information, determine the user identity information and the target digital asset from the usage right credential application request information; search for a second terminal device corresponding to the target digital asset based on the target digital asset; and send a permission allocation request to the second SIM card of the second terminal device to access the target digital asset;
[0172] Receive the permission allocation information corresponding to the permission allocation request sent by the second SIM card, and obtain the use permission of the user identity information to access the target digital asset from the permission allocation information.
[0173] An embodiment of the present application provides a storage medium having a computer program stored thereon. The computer-readable storage medium stores one or more programs. The one or more programs can be executed by one or more processors and applied to a first terminal device and / or a service platform. The computer program implements the digital asset management method as described above.
[0174] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.
[0175] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present disclosure, or the part that contributes to the relevant technology, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a disk, or an optical disk), and includes a number of instructions for enabling an image display device (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in each embodiment of the present disclosure.
[0176] The above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application.
Claims
1. A digital asset management method, characterized in that, it is applied to a first terminal device, the first terminal device includes a first subscriber identity module (SIM) card, and the method includes: when the first SIM card receives a first application request sent by an access object, sending a credential acquisition request for accessing a target digital asset to a service platform through the first SIM card; wherein, the credential acquisition request carries at least relevant information for generating a digital credential; receiving, through the first SIM card, a digital credential for accessing the target digital asset sent by the service platform; wherein, the digital credential is generated based on the relevant information for generating the digital credential carried in the credential acquisition request; based on the digital credential, verifying, through the first SIM card, whether the access object has the usage right to the target digital asset.
2. The method according to claim 1, characterized in that, the method further includes: when the first SIM card verifies that the access object has the usage right to the target digital asset, generating a first piece of information for instructing the access object to access the target digital asset based on the usage right; when the first SIM card verifies that the access object does not have the usage right to the target digital asset, generating a second piece of information for instructing the access object to be prohibited from accessing the target digital asset.
3. The method according to claim 1, characterized in that, the digital credential includes an ownership credential, and before verifying, through the first SIM card, whether the access object has the usage right to the target digital asset based on the digital credential, the method further includes: when the target digital asset is not published, receiving, through the first SIM card, an ownership credential confirmation request for using the target digital asset sent by the access object, where the ownership credential confirmation request carries first user identity information and first digital asset information; the verifying, through the first SIM card, whether the access object has the usage right to the target digital asset based on the digital credential includes: verifying, through the first SIM card, whether the access object has the usage right to the target digital asset based on the first user identity information, the first digital asset information, and the ownership credential.
4. The method according to claim 3, characterized in that, the verifying, through the first SIM card, whether the access object has the usage right to the target digital asset based on the first user identity information, the first digital asset information, and the ownership credential includes: comparing, through the first SIM card, whether the first user identity information is consistent with the user identity information included in the ownership credential and whether the first digital asset information is consistent with the target digital asset information included in the ownership credential; When the first user identity information is consistent with the user identity information included in the ownership certificate, and the first digital asset information is consistent with the target digital asset information included in the ownership certificate, it is determined that the access object has the right to use the target digital asset; When the first user identity information is inconsistent with the user identity information included in the ownership certificate, and / or the first digital asset information is inconsistent with the target digital asset information included in the ownership certificate, it is determined that the access object does not have the right to use the target digital asset.
5. The method according to claim 1, wherein, the digital certificate includes a right of use certificate, and the receiving, by the first SIM card, of the digital certificate sent by the service platform for accessing the target digital asset includes: when the target digital asset is released, receiving, by the first SIM card, the right of use certificate sent by the service platform; wherein, the right of use certificate is generated by the service platform based on the right of use for accessing the target digital asset sent by the second SIM card included in the second terminal device; and the right of use is the right assigned by the second SIM card to the access object to access the target digital asset.
6. The method according to claim 5, wherein, the verifying, by the first SIM card based on the digital certificate, whether the access object has the right to use the target digital asset includes: parsing out the asset key and the right of use from the right of use certificate, and verifying the asset key and the right of use by the first SIM card to determine whether the digital asset access object has the right to use the target digital asset.
7. A digital asset management method, wherein, applied to a service platform, the method includes: when the service platform receives a certificate acquisition request for accessing a target digital asset sent by a first SIM card, generating a digital certificate for accessing the target digital asset based on the relevant information for generating the digital certificate carried in the certificate acquisition request; sending the digital certificate to the first SIM card, where the digital certificate is used for the first SIM card to verify whether an access object has the right to use the target digital asset based on the digital certificate.
8. The method according to claim 7, wherein, the digital certificate includes an ownership certificate, and the generating of the digital certificate for accessing the target digital asset based on the relevant information for generating the digital certificate carried in the certificate acquisition request includes: when the certificate acquisition request is an ownership certificate application request, obtaining the user identity information and the target digital asset information from the ownership certificate application request; generating an ownership certificate for accessing the target digital asset based on the user identity information and the target digital asset information.
9. The method according to claim 8, wherein, after generating the ownership certificate for accessing the target digital asset, the method further includes: Send the ownership certificate to the first SIM card, where the ownership certificate is used for the first SIM card to verify whether the access object has the usage right of the target digital asset based on the first user identity information, the first digital asset information, and the ownership certificate carried in the received ownership certificate confirmation request.
10. The method according to claim 7, wherein, the method further includes: when the digital certificate includes a usage right certificate, receiving the usage right of accessing the target digital asset sent by the second SIM card included in the second terminal device, where the usage right is the right allocated by the second SIM card for the access object to access the target digital asset; generating the usage right certificate based on the usage right of accessing the target digital asset, and sending the usage right certificate to the first SIM card.
11. The method according to claim 10, wherein, before receiving the usage right of accessing the target digital asset sent by the second SIM card included in the second terminal device, the method further includes: when the certificate acquisition request sent by the first SIM card is a usage right certificate application request message, determining the user identity information and the target digital asset from the usage right certificate application request message; finding the second terminal device corresponding to the target digital asset based on the target digital asset; and sending a permission allocation request for accessing the target digital asset to the second SIM card of the second terminal device; the receiving the usage right of accessing the target digital asset sent by the second SIM card included in the second terminal device includes: receiving the permission allocation information corresponding to the permission allocation request sent by the second SIM card, and obtaining the usage right of the user identity information to access the target digital asset from the permission allocation information.
12. A first terminal device, wherein, the first terminal device includes a first SIM card, and the first terminal device includes: a first sending module, configured to send a certificate acquisition request for accessing a target digital asset to a service platform through the first SIM card when the first SIM card receives a first application request sent by an access object; wherein, the certificate acquisition request carries at least relevant information for generating a digital certificate; a receiving module, configured to receive, through the first SIM card, the digital certificate for accessing the target digital asset sent by the service platform; wherein, the digital certificate is generated based on the relevant information for generating the digital certificate carried in the certificate acquisition request; a verification module, configured to verify, through the first SIM card, whether the access object has the usage right of the target digital asset based on the digital certificate.
13. A service platform, wherein, the service platform includes: A voucher generation module, configured to generate a digital voucher for accessing the target digital asset based on the relevant information for generating the digital voucher carried in the voucher acquisition request when the service platform receives a voucher acquisition request for accessing the target digital asset sent by the first SIM card; A second sending module, configured to send the digital voucher to the first SIM card, where the digital voucher is used for the first SIM card to verify whether the access object has the usage right to access the target digital asset based on the digital voucher.
14. A first terminal device, characterized in that, the first terminal device includes: a first processor and a first memory; when the first processor executes the running program stored in the first memory, the method described in any one of claims 1 to 6 is implemented.
15. A service platform, characterized in that, the service platform includes: a second processor and a second memory; when the second processor executes the running program stored in the second memory, the method described in any one of claims 7 to 11 is implemented.
16. A storage medium, on which a computer program is stored, characterized in that, when the computer program is executed by a processor, the method described in any one of claims 1 to 6 is implemented, or when the computer program is executed by a processor, the method described in any one of claims 7 to 11 is implemented.