Motion Data Security Management Method and System in the Metaverse Smart Sports

By adopting an identity authentication model combining zero-knowledge proof and Merkle tree in the metacosmic motion data management system, combined with sharded storage technology, the problems of low identity authentication security and data privacy leakage are solved, and efficient user authentication and data privacy protection are achieved.

CN120128436BActive Publication Date: 2025-07-29HANGZHOU MOXI TECH DEV CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510616041.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-07-29
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

The existing metacosmic motion data management system has low identity authentication security and data privacy leakage risks, and cannot effectively guarantee the authenticity of user identity and privacy protection.

Method used

The identity authentication model combined with the Merkle tree is adopted to store motion data in a distributed manner through sharded storage technology and data access control is carried out based on the permission level.

Benefits of technology

It realizes the security verification and privacy protection of user identity information, prevents identity fraud and information leakage, improves the scalability and access efficiency of data storage, and at the same time realizes refined data authorization access management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128436B_ABST
    Figure CN120128436B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for secure management of motion data in the metaverse intelligent sports, which relates to the field of metaverse technology. It includes obtaining user motion data and identity information, establishing an identity authentication model based on the zero-knowledge proof mechanism, generating a Merkle tree zero-knowledge proof to verify the authenticity of the user's identity; using the sharding storage technology to perform distributed storage of motion data; and providing corresponding data according to the access permission level of third-party applications. The present invention realizes the protection of user data privacy and efficient storage, and at the same time supports multi-level data access control, improving data security and utilization efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of the metaverse, and particularly to a method and system for secure management of motion data in metaverse intelligent sports. Background Art

[0002] With the rapid development of metaverse technology, metaverse intelligent sports, as a new type of healthy lifestyle, are gradually attracting people's attention and favor. Metaverse intelligent sports refer to activities in which users carry out physical exercises and health management in a virtual digital world, collect users' motion data through digital devices, and present and analyze it in the metaverse space. These motion data include information such as users' motion trajectories, heart rate changes, energy consumption, and sports performance, and have extremely high personal privacy attributes and commercial value. With the expansion of metaverse sports scenarios and the growth of the user base, how to securely and effectively manage this massive amount of motion data has become an urgent technical problem to be solved.

[0003] Traditional metaverse motion data management systems mainly adopt a centralized data storage and management method. User authentication is usually based on a simple username and password mechanism, and data storage often focuses on a single server or cloud platform. However, this management method has obvious technical defects. First, the traditional authentication mechanism has low security, is vulnerable to identity fraud and data forgery attacks, and cannot effectively guarantee the authenticity and uniqueness of user identities in the metaverse, resulting in the generation and spread of false motion data. Second, the centralized storage mode makes a large amount of sensitive personal motion data concentrated in the hands of a single entity. Once a data leak or system attack occurs, it will cause large-scale user privacy leakage and bring serious security risks to users. Summary of the Invention

[0004] Embodiments of the present invention provide a method and system for secure management of motion data in metaverse intelligent sports, which can solve the problems in the prior art.

[0005] In a first aspect of embodiments of the present invention, a method for secure management of motion data in metaverse intelligent sports is provided, including:

[0006] Obtain the motion data of the user in the metaverse sports scenario and the user's identity information, establish an identity authentication model for the user based on the zero-knowledge proof mechanism, generate a zero-knowledge proof protocol based on the Merkle tree, calculate the hash value according to the identity information to construct the Merkle tree leaf nodes, obtain the Merkle tree root node value through iterative calculation, generate a zero-knowledge proof including path proof, verify the authenticity of the identity information, and generate an authentication credential including a timestamp and a digital signature;

[0007] After the authenticity verification of the identity information passes, the motion data is distributedly stored using the sharding storage technology, including: splitting the motion data into metadata shards, feature data shards, and evaluation result shards according to the data structure of the motion data, establishing index identifiers for each data shard using a Bloom filter, distributing and storing the data shards to multiple storage nodes through a circular hash space, and determining the storage location of the data shards through a consistent hashing algorithm;

[0008] When responding to a data access request from a third-party application, verify the authentication credentials and access privilege level provided by the requester, and retrieve and assemble the access result data of the corresponding level from the distributed storage network. Among them, full access privileges can obtain all motion data, and restricted access privileges can only obtain basic motion type information.

[0009] Generate a zero-knowledge proof protocol based on the Merkle tree. Calculate the hash value according to the identity information to construct the leaf nodes of the Merkle tree, and obtain the Merkle root node value through iterative calculation. The generation of the zero-knowledge proof including path proof includes:

[0010] Split the identity information into a user identification field, a registration time field, and a privilege level field, and calculate the SHA-256 hash values of the user identification field, the registration time field, and the privilege level field to form leaf nodes;

[0011] Arrange the leaf nodes in a preset order to construct the bottom layer of the Merkle tree, and calculate the SHA-256 hash value after cascading the hash values of adjacent two leaf nodes to obtain the parent node value;

[0012] Repeat the operation of pairing and combining adjacent leaf nodes until a unique Merkle root node value is generated. During the pairing and combining process, record the index information of the left and right child nodes of each leaf node and the corresponding hash values to construct a node relationship mapping table;

[0013] Select the target leaf node that needs to be authenticated, determine the verification path from the target leaf node to the root node based on the node relationship mapping table, and extract the hash values of adjacent leaf nodes and the node index information of the left and right child nodes on the verification path;

[0014] Generate a random prime number as the homomorphic encryption key, encrypt the hash values of the leaf nodes on the verification path using the homomorphic encryption key to generate an encrypted node sequence, and combine the encrypted node sequence with the node index information to form a zero-knowledge proof.

[0015] Verify the authenticity of the identity information, and generate an authentication credential including a timestamp and a digital signature, including:

[0016] Send the zero - knowledge proof and the Merkle tree root node value to the verifier. The verifier decrypts the encrypted node sequence using the homomorphic encryption key, reconstructs the verification path according to the node index information, and verifies whether the reconstructed root node value is consistent with the received root node value;

[0017] Receive the verification result returned by the verifier. When the verification result indicates that the reconstructed root node value is consistent with the received root node value, confirm that the identity authentication is passed, and generate an authentication credential containing a timestamp and a digital signature.

[0018] Segment the motion data into metadata shards, feature data shards, and evaluation result shards according to the data structure of the motion data. Establish index identifiers for each data shard using Bloom filters, and distribute and store the data shards to multiple storage nodes through a circular hash space. Determining the storage location of the data shards through the consistent hashing algorithm includes:

[0019] Perform sharding processing on the motion data according to the data structure type, including: dividing the user identifier, timestamp, and device information into metadata shards, dividing the motion trajectory data and motion posture data into feature data shards, and dividing the physiological feature data into evaluation result shards;

[0020] Construct a Bloom filter index for each data shard, including: selecting multiple independent hash functions, calculating the feature values of the data shard using the multiple hash functions respectively, mapping the feature values to the corresponding positions in the multi - dimensional vector space, setting the binary values of the mapped positions to 1, and generating the Bloom filter fingerprint of the data shard;

[0021] Determine the storage location of the data shards based on the consistent hashing algorithm, including: constructing a circular hash space, mapping the storage nodes to the virtual nodes of the circular hash space, calculating the hash value of the data shard, and finding the first virtual node greater than or equal to the hash value in the clockwise direction on the circular hash space as the storage location;

[0022] Send the metadata shards, the feature data shards, and the evaluation result shards to their corresponding storage locations for storage, and record the corresponding relationship between the data shards and the Bloom filter fingerprints at the storage locations.

[0023] Construct a circular hash space, map the storage nodes to the virtual nodes of the circular hash space, calculate the hash value of the data shard, and find the first virtual node greater than or equal to the hash value in the clockwise direction on the circular hash space as the storage location includes:

[0024] Generate a node identifier for each storage node, where the node identifier is obtained by concatenating the node network address, the node weight value, and the timestamp;

[0025] Determine the number of virtual nodes for each storage node based on the node weight value, combine the virtual node sequence number with the node identifier to generate a virtual node identifier, calculate the hash value of the virtual node identifier, map the virtual node to the corresponding hash segment in the circular hash space according to the hash value, and generate a routing table containing the mapping relationship between the virtual node position and the actual node;

[0026] Extracting a shard identifier, shard size, and shard content from the data shard, and calculating a target hash value for the shard identifier using the same hash algorithm as that used for the virtual node;

[0027] In the circular hash space, starting from the target hash value, the routing table is searched in a clockwise direction, the first virtual node with a value greater than or equal to the target hash value is used as the primary storage location, and the two adjacent virtual nodes thereafter are selected as backup storage locations, wherein the primary storage location and the backup storage location correspond to different actual storage nodes respectively.

[0028] Verify the authentication credentials and access level provided by the requester, and retrieve and assemble the corresponding level of access result data from the distributed storage network based on the access level, including:

[0029] Receiving a data access request sent by a requester, wherein the data access request includes an authentication credential, an authority level identifier, and a target data index, wherein the authentication credential includes a digital signature and a timestamp of the requester;

[0030] Verifying the validity of the authentication credentials includes: checking whether the timestamp is within the allowed time window, verifying the legitimacy of the digital signature using the requester's public key, and confirming whether the requester's identity is in the authorized user list;

[0031] Obtaining data access rules corresponding to the permission level identifier from an access control policy library, wherein the data access rules define sets of data fields and access operation types accessible to different permission levels, and determining the actual access permission scope of the requester based on the data access rules;

[0032] Based on the target data index, a data location mapping table in the distributed storage network is queried to obtain storage location information of the target data, wherein the storage location information includes multiple storage node addresses and corresponding data shard identifiers; based on the actual access permission scope of the requesting party, a set of data shard identifiers that are allowed to be accessed are filtered from the storage location information, and a data retrieval request is sent to the corresponding storage node;

[0033] Receive the data shard content returned by the storage node, verify the integrity and consistency of the data shards, and reassemble the verified data shards into complete data according to the preset assembly rules;

[0034] Filter the reorganized data according to the access privilege level of the requester, and only retain the data fields allowed to be accessed at this privilege level to generate access result data.

[0035] In the second aspect of the embodiments of the present invention, a motion data security management system in the metaverse intelligent sports is provided, including:

[0036] The first unit is used to obtain the motion data of the user in the metaverse motion scenario and the identity information of the user, establish an identity authentication model of the user based on the zero-knowledge proof mechanism, generate a zero-knowledge proof protocol based on the Merkle tree, calculate the hash value according to the identity information to construct the Merkle tree leaf nodes, obtain the Merkle tree root node value through iterative calculation, generate a zero-knowledge proof including path proof, verify the authenticity of the identity information, and generate an authentication credential including a timestamp and a digital signature;

[0037] The second unit is used to, after the authenticity verification of the identity information passes, perform distributed storage on the motion data by using the sharding storage technology, including: dividing the motion data into metadata shards, feature data shards, and evaluation result shards according to the data structure of the motion data, establishing an index identifier for each data shard by using a Bloom filter, distributing and storing the data shards to multiple storage nodes through a circular hash space, and determining the storage location of the data shards through a consistent hashing algorithm;

[0038] The third unit is used to, when responding to a data access request from a third-party application, verify the authentication credential and access privilege level provided by the requester, retrieve and assemble the access result data of the corresponding level from the distributed storage network, where full access privilege can obtain all motion data, and restricted access privilege can only obtain basic motion type information.

[0039] In the third aspect of the embodiments of the present invention, an electronic device is provided, including:

[0040] A processor;

[0041] A memory for storing instructions executable by the processor;

[0042] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.

[0043] In the fourth aspect of the embodiments of the present invention, a computer-readable storage medium is provided, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.

[0044] The beneficial effects of this application are as follows:

[0045] The motion data security management method in the metaverse intelligent sports provided by the present invention realizes the secure verification and privacy protection of user identity information through an identity authentication model that combines the zero-knowledge proof mechanism and the Merkle tree structure, effectively preventing the risks of identity fraud and information leakage, while ensuring the efficiency and reliability of the identity verification process.

[0046] The present invention adopts the sharding storage technology and the distributed storage architecture, divides the motion data into different types of data shards in a structured manner, establishes an efficient index through the Bloom filter, and then flexibly distributes them in the multi-node storage network by using the consistent hashing algorithm, significantly improving the scalability and access efficiency of data storage, while enhancing the fault tolerance and security of the data.

[0047] The present invention designs a data access control mechanism based on permission levels. By verifying the authentication credentials and access permissions of third-party applications, it realizes the refined authorized access management of motion data, which not only guarantees the control right of the data owner over personal motion data, but also provides a flexible data sharing scheme for different application scenarios, effectively balancing the data utilization value and the privacy protection requirements. Brief Description of the Drawings

[0048] Figure 1 It is a schematic flowchart of the motion data security management method in the metaverse intelligent sports according to the embodiment of the present invention;

[0049] Figure 2 It is a verification flowchart of zero-knowledge proof based on the Merkle tree according to the embodiment of the present invention;

[0050] Figure 3 It is a complete flowchart of the data distribution and routing mechanism based on the ring hash space according to the embodiment of the present invention;

[0051] Figure 4 It is a distributed data access control flowchart according to the embodiment of the present invention. Detailed Embodiments

[0052] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0053] The technical solutions of the present invention will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0054] Figure 1 This is a schematic flowchart of the motion data security management method in the metaverse intelligent motion of the embodiments of the present invention. As Figure 1 shown, the method includes:

[0055] Obtain the motion data of the user in the metaverse motion scenario and the identity information of the user, establish an identity authentication model for the user based on the zero-knowledge proof mechanism, generate a zero-knowledge proof protocol based on the Merkle tree, calculate the hash value according to the identity information to construct the Merkle tree leaf nodes, obtain the Merkle tree root node value through iterative calculation, generate a zero-knowledge proof including path proof, verify the authenticity of the identity information, and generate an authentication credential including a timestamp and a digital signature;

[0056] When the authenticity verification of the identity information passes, use the sharding storage technology to perform distributed storage on the motion data, including: splitting the motion data into metadata shards, feature data shards and evaluation result shards according to the data structure of the motion data, establishing an index identifier for each data shard using a Bloom filter, distributing and storing the data shards to multiple storage nodes through a circular hash space, and determining the storage location of the data shards through a consistent hashing algorithm;

[0057] When responding to the data access request of a third-party application, verify the authentication credential and access permission level provided by the requester, and retrieve and assemble the access result data of the corresponding level from the distributed storage network. Among them, full access permission can obtain all motion data, and restricted access permission can only obtain basic motion type information.

[0058] In an alternative embodiment, generating a zero-knowledge proof protocol based on the Merkle tree, calculating the hash value according to the identity information to construct the Merkle tree leaf nodes, and obtaining the Merkle tree root node value through iterative calculation and generating a zero-knowledge proof including path proof includes:

[0059] Split the identity information into a user identification field, a registration time field and a permission level field, and calculate the SHA-256 hash values of the user identification field, the registration time field and the permission level field to form leaf nodes;

[0060] Arrange the leaf nodes in a preset order to construct the bottom layer of the Merkle tree, and calculate the SHA-256 hash value after cascading the hash values of two adjacent leaf nodes to obtain the parent node value;

[0061] Repeat the operation of pairing and combining adjacent leaf nodes until a unique Merkle tree root node value is generated. During the pairing and combining process, record the index information of the left and right child nodes of each leaf node and the corresponding hash values to construct a node relationship mapping table;

[0062] Select the target leaf node that needs to be authenticated, determine the verification path from the target leaf node to the root node based on the node relationship mapping table, and extract the hash values of adjacent leaf nodes and the node index information of the left and right child nodes on the verification path;

[0063] Generate a random prime number as the homomorphic encryption key, encrypt the hash values of the leaf nodes on the verification path using the homomorphic encryption key to generate an encrypted node sequence, and combine the encrypted node sequence with the node index information to form a zero-knowledge proof.

[0064] The identity information is split into a user identification field, a registration time field, and a permission level field. To construct a Merkle tree, it is necessary to calculate the hash values of these fields as leaf nodes. For the identity information of any user, calculate the SHA-256 hash values of its user identification, registration time, and permission level respectively to obtain the corresponding hash value results.

[0065] These hash values constitute the leaf nodes of the Merkle tree. Arrange these leaf nodes in a preset order to form the bottom layer of the Merkle tree. In practical applications, there may be the identity information of multiple users, constituting a large number of leaf nodes. If the number of leaf nodes is odd, an empty node (all-zero hash value) can be added to make it an even number of nodes, which is convenient for constructing a complete binary Merkle tree.

[0066] Concatenate the hash values of two adjacent leaf nodes, and then calculate the SHA-256 hash value of the concatenated result to obtain the parent node value. The specific operation is to connect the hash values of two adjacent leaf nodes into a string in the order from left to right, and then calculate the SHA-256 hash value of this string to obtain the hash value of their parent node.

[0067] This process is executed recursively. Each time, take two adjacent nodes for pairing and combination, calculate the hash value of their parent node, until finally generate the unique Merkle tree root node value. During the construction process, record the index information of the left and right child nodes and the corresponding hash values of each node to construct a node relationship mapping table. This mapping table contains the position index of each node in the tree, its hash value, and the information of the child nodes connected to it.

[0068] When authentication is required, select the target leaf node to be verified. Based on the node relationship mapping table, determine the verification path from this target leaf node to the root node. This path contains the hash values of the sibling nodes at each layer on the path from the target leaf node to the root node. Through the hash values of these sibling nodes, the verifier can recalculate the hash value of the root node without knowing the specific content of other leaf nodes.

[0069] Extract the hash values of adjacent leaf nodes and the node index information of the left and right child nodes from the verification path. To achieve zero-knowledge, a random prime number is generated as the homomorphic encryption key, which consists of a prime number and a random number. Use the homomorphic encryption function to encrypt the hash values on the verification path. The encryption method is to add the random number to the hash value and then take the modulus of the prime number.

[0070] For hash values in hexadecimal representation, they need to be converted to decimal values first and then encrypted. Since hash values are usually long, the hash values can be processed in segments and each segment is encrypted separately. The length of the encrypted result may be different from the original hash value, but it retains the characteristics of the original hash value and does not disclose the content of the original hash value.

[0071] Combine the encrypted node sequence with the node index information to form a zero-knowledge proof. This proof includes the index of the target leaf node, the position information of each node in the verification path and the encrypted hash values, as well as the publicly available Merkle root node hash value. This information is sufficient for the verifier to verify that the requester indeed has the corresponding identity information, but does not disclose the specific identity information content.

[0072] The verifier uses the same hash function and encryption function to recalculate the path based on the publicly available Merkle root node value and the verification path information provided in the zero-knowledge proof, and verifies whether the calculated result is consistent with the publicly available root node hash value. If they are consistent, it proves that the requester indeed has the corresponding identity information; if not, it indicates that the verification fails.

[0073] The advantage of this method is that the verifier only needs to know the Merkle tree root node hash value and the node information on the verification path, without knowing the complete identity information content, thus protecting user privacy. At the same time, due to the use of homomorphic encryption, even if the node information on the verification path is leaked, the attacker cannot deduce the original identity information.

[0074] Through the above method, the purpose of efficiently and reliably verifying the user's identity is achieved without disclosing the user's complete identity information. This protocol is applicable to scenarios that require protecting user privacy while also performing identity verification, such as financial transactions, access control systems, blockchain applications, etc. In practical applications, the type of hash function, encryption method, and the construction method of the Merkle tree can be adjusted according to specific requirements to meet different security and performance requirements.

[0075] In an alternative implementation, verifying the authenticity of the identity information and generating an authentication credential including a timestamp and a digital signature includes:

[0076] Send the zero - knowledge proof and the Merkle tree root node value to the verifier. The verifier decrypts the encrypted node sequence using the homomorphic encryption key, reconstructs the verification path according to the node index information, and verifies whether the reconstructed root node value is consistent with the received root node value;

[0077] Receive the verification result returned by the verifier. When the verification result indicates that the reconstructed root node value is consistent with the received root node value, confirm that the identity authentication has passed, and generate an authentication credential containing a timestamp and a digital signature.

[0078] When a user needs to prove the authenticity of their identity to the verifier, the user sends a zero - knowledge proof and the Merkle tree root node value to the verifier. The zero - knowledge proof contains an encrypted node sequence and node index information, while the Merkle tree root node value is the unique identifier of the entire identity information tree. These two parts of information are packed into a data packet in a specific format and sent to the verifier. To ensure secure transmission, the entire communication process can be encrypted using the Secure Sockets Layer (SSL) or Transport Layer Security (TLS) protocol.

[0079] After receiving the zero - knowledge proof and the Merkle tree root node value sent by the user, the verifier first verifies the integrity and format validity of the received data. After passing the verification, the verifier decrypts the encrypted node sequence using the homomorphic encryption key pre - shared or obtained through a secure channel. The decryption process applies a homomorphic decryption function to each encrypted hash value, that is, subtracts a random number from the encrypted hash value and then takes the modulus with a prime number to obtain the original hash value.

[0080] After decryption, the verifier reconstructs the verification path according to the node index information. The specific steps are as follows: starting from the target leaf node, combined with the decrypted sibling node hash values, calculate the parent node hash values layer by layer until the root node value is reconstructed. During the reconstruction process, the verifier follows the Merkle tree construction rule, concatenates the hash values of two adjacent nodes and then calculates the SHA - 256 hash value to obtain the parent node value, and so on until the root node.

[0081] The verifier then compares whether the reconstructed root node value is consistent with the received root node value. The verification method is to directly compare whether the two hash strings are exactly the same. If they are exactly the same, the identity verification is considered to have passed; if there are any differences, the verification is considered to have failed. The verification result is returned to the user side through a secure channel.

[0082] The user receives the verification result returned by the verifier. When the verification result indicates that the reconstructed root node value is consistent with the received root node value, confirm that the identity authentication has passed. At this time, the user side or a trusted third party generates an authentication credential containing a timestamp and a digital signature.

[0083] The authentication credential generation process includes several key steps. First, basic credential information is created, including the user's anonymous identifier, permission level indicator, and verification timestamp. The timestamp uses a standard time format, is accurate to the millisecond, and can include time zone information to ensure the credential's timeliness can be accurately verified.

[0084] The basic credential information is hashed to generate a credential hash value. A secure hash algorithm such as SHA-256 is used to ensure that the credential content cannot be tampered with. Asymmetric encryption is then used to sign the credential hash value to generate a digital signature. The signing process encrypts the hash value with a private key. The resulting signature can be verified with the corresponding public key but cannot be forged.

[0085] An authentication credential consists of basic credential information, a timestamp, and a digital signature, forming a complete authentication credential data structure. This credential can be serialized into a specific format, such as JSON or XML, for easy storage and transmission. The credential may also include expiration information, indicating the timeframe within which the credential is valid.

[0086] Authentication credentials can be used for subsequent authorized access control. Users holding valid authentication credentials can access specific resources without having to repeat the full identity verification process, improving system efficiency. Furthermore, because the credentials only contain anonymous identifiers rather than full identity information, user privacy is protected.

[0087] After receiving the authentication credential, the verifier first checks whether the timestamp is within the validity period. It then verifies the digital signature using the previously acquired public key. During verification, the credential's basic information is extracted, its hash value is calculated, and the digital signature is decrypted using the public key to obtain the original hash value. The two hash values are then compared to ensure they match. If they match and the timestamp is valid, the credential is considered valid.

[0088] Zero-knowledge proof technology is used to ensure identity authentication without leaking complete identity information, and digital signature technology is used to ensure the unforgeability of authentication credentials. At the same time, the timestamp mechanism ensures the timeliness of the credentials. The overall solution provides an identity authentication solution that takes into account privacy protection, security, reliability and ease of use, and is suitable for various application scenarios that require strict protection of user privacy.

[0089] In the identity authentication system, this solution effectively solves the privacy leakage risks existing in traditional solutions. Through cryptographic technology, it ensures that even if the system is invaded, the attacker cannot obtain the user's complete identity information. At the same time, it ensures the reliability and non-repudiation of the authentication process, providing technical support for building a trusted identity authentication infrastructure.

[0090] Figure 2 The following is a flowchart of zero-knowledge proof verification based on Merkle tree in an embodiment of the present invention:

[0091] The figure shows the key steps of the zero - knowledge proof verification process based on the Merkle tree. After receiving the zero - knowledge proof and the Merkle tree root node value, the verifier uses the same homomorphic encryption key to decrypt the encrypted node sequence. After decryption, the verifier reconstructs the verification path according to the provided node index information and obtains a new root node value through iterative calculation. The verifier compares the calculated root node value with the received original root node value. When the two root node values are exactly the same, it indicates that the identity verification is passed. After the verification is passed, the system generates an authentication credential containing the verification timestamp and digital signature as a valid credential for the successful authentication of the user's identity. This authentication process, through zero - knowledge proof technology, not only ensures the reliability of the verification but also guarantees the privacy protection of the user's identity information. The entire verification process can complete the identity authentication without exposing the original identity information. This verification mechanism not only meets the security requirements but also has good privacy protection characteristics, and is an efficient and secure identity verification solution.

[0092] In an alternative embodiment, the motion data is segmented into metadata shards, feature data shards, and evaluation result shards according to its data structure. A Bloom filter is used to establish index identifiers for each data shard, and the data shards are distributed and stored on multiple storage nodes through a circular hash space. Determining the storage location of the data shards through the consistent hashing algorithm includes:

[0093] Segmenting the motion data according to the data structure type, including: dividing user identification, timestamp, and device information into metadata shards, dividing motion trajectory data and motion posture data into feature data shards, and dividing physiological feature data into evaluation result shards;

[0094] Constructing a Bloom filter index for each data shard, including: selecting multiple independent hash functions, calculating the feature values of the data shard using the multiple hash functions respectively, mapping the feature values to the corresponding positions in the multi - dimensional vector space, setting the binary values of the mapped positions to 1, and generating the Bloom filter fingerprint of the data shard;

[0095] Determining the storage location of the data shards based on the consistent hashing algorithm, including: constructing a circular hash space, mapping the storage nodes to virtual nodes in the circular hash space, calculating the hash value of the data shard, and finding the first virtual node greater than or equal to the hash value in the clockwise direction on the circular hash space as the storage location;

[0096] Sending the metadata shards, the feature data shards, and the evaluation result shards to their corresponding storage locations for storage, and recording the corresponding relationship between the data shards and the Bloom filter fingerprints at the storage locations.

[0097] Slice the motion data according to the data structure type. Motion data usually includes various types of data such as user basic information, motion trajectory, and physiological characteristics. To improve storage and retrieval efficiency, this method divides the motion data into three types of slices:

[0098] For the metadata slice, extract basic information such as the user identifier (e.g., user ID: user_12345), timestamp (e.g., 2023-10-15 08:30:25), and device information (e.g., device model: SportWatch-2000, device ID: DV87634) from the motion data. For example, a complete metadata slice can be represented as: {"user_id": "user_12345", "timestamp": "2023-10-15 08:30:25", "device_id": "DV87634", "device_model": "SportWatch-2000"}.

[0099] For the feature data slice, extract motion trajectory data (e.g., GPS coordinate sequence: [(39.9042, 116.4074),(39.9043, 116.4075),...]) and motion posture data (e.g., acceleration and angular velocity data: [{acceleration:[0.1, 0.2, 9.8], gyroscope: [0.01, 0.02, 0.03]},...]). For example, a feature data slice can be represented as: {"track_points": [(39.9042, 116.4074), (39.9043, 116.4075)], "posture_data": [{acceleration: [0.1, 0.2, 9.8], gyroscope: [0.01, 0.02,0.03]}]}.

[0100] For the evaluation result slice, extract physiological characteristic data such as heart rate, blood oxygen, and energy consumption. For example, an evaluation result slice can be represented as: {"heart_rate": [75, 78, 82, 85], "blood_oxygen": [98, 97, 98],"calories": 325}.

[0101] Construct a Bloom filter index for each data slice. A Bloom filter is a space-efficient probabilistic data structure used to determine whether an element is in a set. This method selects three independent hash functions: MurmurHash, FNV, and SipHash.

[0102] Taking metadata sharding as an example, for user ID "user_12345", calculate three hash values respectively: MurmurHash("user_12345") = 2356782, FNV("user_12345") = 6723541, SipHash("user_12345") = 9834217. Set the Bloom filter as a bit array with a size of 8MB (about 67,108,864 bits), and calculate the results of the above hash values modulo the array length: 2356782 % 67108864 = 2356782, 6723541 % 67108864 = 6723541, 9834217 % 67108864 = 9834217. Then set the values at the corresponding positions in the bit array to 1. Repeat the above process for other fields (timestamp, device information, etc.) in the shard, and finally generate the Bloom filter fingerprint of this shard.

[0103] The construction process of the Bloom filters for feature data shards and evaluation result shards is similar, and the difference lies in the data fields processed. For example, feature data shards may focus on indexing the start and end points of the trajectory, activity types, etc., and evaluation result shards may focus on indexing key data such as maximum / minimum heart rate, total energy consumption, etc.

[0104] Determine the storage location of the data shard based on the consistent hashing algorithm. First, construct a circular hash space with a 32-bit integer range (from 0 to 2^32 - 1). Assume there are 5 physical storage nodes (Node-1 to Node-5) in the system, create 100 virtual nodes for each node, and map these virtual nodes to the circular space through a hash function. For example, the identifiers of the virtual nodes can be "Node-1#1", "Node-1#2", etc., and their hash values may be: Hash("Node-1#1") = 123456789, Hash("Node-1#2") = 987654321.

[0105] For the metadata shard that needs to be stored, calculate its hash value, such as Hash(metadata shard) = 500000000. Then, in the circular hash space, search clockwise for the first virtual node that is greater than or equal to this hash value. Assume the found one is "Node-3#45" (hash value is 510000000), then this metadata shard will be stored on the Node-3 physical node.

[0106] The process of determining the storage locations for feature data shards and evaluation result shards is the same as that for metadata shards. Due to the randomness of hashing, the three types of shards will be relatively evenly distributed across each storage node, achieving load balancing. When the number of storage nodes changes (either increasing or decreasing nodes), only some data shards need to be reallocated, without the need for global rehashing, which greatly reduces the system reorganization cost.

[0107] Send the metadata shards, feature data shards, and evaluation result shards to their corresponding storage locations for storage respectively. On the storage node, each data shard is saved together with its Bloom filter fingerprint, forming a mapping relationship, such as: {"shard_id": "meta_user_12345_20231015", "bloom_filter": [binary representation or compressed form of the bit array], "data": [content of the shard data]}.

[0108] A local index table is also maintained on each storage node, recording all the data shard IDs stored on that node and their corresponding Bloom filter fingerprints. When querying the motion data of a certain user, the system can quickly determine the possible nodes where the data exists through the Bloom filter, avoiding global scanning and improving the query efficiency.

[0109] In an optional implementation manner, a circular hash space is constructed, mapping the storage nodes to virtual nodes in the circular hash space, calculating the hash value of the data shard, and finding the first virtual node greater than or equal to this hash value in the clockwise direction on the circular hash space as the storage location, including:

[0110] Generate a node identifier for each storage node, which is obtained by concatenating the node network address, node weight value, and timestamp;

[0111] Based on the node weight value, determine the number of virtual nodes for each storage node, combine the virtual node serial number with the node identifier to generate a virtual node identifier, calculate the hash value of the virtual node identifier, map the virtual nodes to the corresponding hash segments in the circular hash space according to the hash value, and generate a routing table containing the mapping relationship between virtual node locations and actual nodes;

[0112] Extract the shard identifier, shard size, and shard content from the data shard, and calculate the target hash value of the shard identifier using the same hashing algorithm as the virtual node;

[0113] Starting from the target hash value in the circular hash space, search the routing table in the clockwise direction, take the first virtual node greater than or equal to the target hash value as the primary storage location, and select the two adjacent virtual nodes behind it as backup storage locations. The primary storage location and the backup storage locations correspond to different actual storage nodes respectively.

[0114] In a distributed storage system, the generation of storage node identifiers is a crucial step in ensuring node uniqueness. For each physical node accessing the storage cluster, its node identifier is generated. The node identifier is obtained by concatenating the node network address, the node weight value, and the timestamp. The node network address includes the IP address and port number, represented in a standard format, such as "192.168.1.100:8080". The node weight value reflects the performance and capacity characteristics of the storage node. A higher weight value indicates better node performance or larger capacity. The timestamp records the time when the node joins the cluster, using the standard time format. These three parts of information are connected using a specific delimiter to form a complete node identifier string. For example, a node identifier might be "192.168.1.100:8080_weight5_20240429152010", where the underscore is used as the delimiter to separate the three parts of information.

[0115] To avoid data skew problems caused by uneven distribution of nodes on the hash ring, the virtual node mechanism is introduced. The number of virtual nodes for each storage node is determined based on the node weight value. Storage nodes with higher weight values correspond to more virtual nodes, enabling them to store more data shards. The number of virtual nodes can be obtained by multiplying the reference number of virtual nodes by the node weight value. For each virtual node, the virtual node sequence number and the node identifier are combined to generate the virtual node identifier. The virtual node sequence number starts incrementing from zero and is combined with the node identifier according to a specific rule, such as "nodeID#0" representing the first virtual node of the node.

[0116] When calculating the hash value of the virtual node identifier, hash algorithms such as SHA-256 can be used. The hash algorithm maps the virtual node identifier to a hash value of a fixed length, which determines the position of the virtual node in the circular hash space. The circular hash space can be regarded as a closed loop ranging from zero to the maximum hash value. The larger the hash value, the more backward the position on the ring. All virtual nodes are mapped to the corresponding hash segments in the circular hash space according to their respective hash values. Subsequently, a routing table containing the mapping relationship between the virtual node positions and the actual nodes is generated. The routing table records the hash value positions of each virtual node and the corresponding actual physical node information, facilitating the subsequent rapid location of the storage positions of data shards.

[0117] When data shards need to be stored, extract the shard identifier, shard size, and shard content from the data shards. The shard identifier can be the unique ID of the shard or can contain information about the dataset to which the shard belongs, such as "datasetA_partition3". The shard size records the amount of data in the shard, which helps the storage system with capacity planning. The shard content is the actual data to be stored. After extracting this information, calculate the target hash value of the shard identifier using the same hash algorithm as for the virtual nodes. Using the same hash algorithm ensures that shards and virtual nodes are comparable in the same hash space.

[0118] In the circular hash space, start from the target hash value and search in the routing table in the clockwise direction. Select the first virtual node whose hash value is greater than or equal to the target hash value as the primary storage location. If the target hash value is greater than the hash values of all virtual nodes on the ring, the circular structure will wrap back to the starting point, and the virtual node with the smallest hash value on the ring will be selected as the primary storage location. After determining the primary storage location, continue to select the two adjacent virtual nodes in the clockwise direction as backup storage locations. Note here that the primary storage location and the backup storage locations must correspond to different actual storage nodes to ensure data reliability. If adjacent virtual nodes map to the same actual node, continue to search for the next virtual node that maps to a different actual node.

[0119] Assume there are multiple virtual nodes in the circular hash space, and their corresponding actual nodes are different. After calculating the target hash value of a data shard and finding that the value is between the hash values of two virtual nodes, select the virtual node with the larger hash value as the primary storage location. If the target hash value is greater than the hash values of all virtual nodes on the ring, select the virtual node with the smallest hash value on the ring as the primary storage location. After determining the primary storage location, continue to check the subsequent virtual nodes and select two virtual nodes corresponding to different actual nodes as backup storage locations.

[0120] Store the data shard in the actual storage node corresponding to the primary storage location, and according to the backup policy set by the system, copy the same data shard to the actual storage nodes corresponding to the backup storage locations. After each storage node receives the data shard, persist the data according to the local storage policy and update the local index to record the correspondence between the shard identifier and the storage location.

[0121] Through the above method, the balanced distribution and highly available backup of data shards in a distributed storage cluster are achieved. When nodes join or leave the storage cluster, only the storage locations of the affected data shards need to be recalculated and migrated to new locations without affecting other data shards, greatly reducing the system rebalancing cost caused by node changes. This node mapping and positioning method based on consistent hashing has good scalability and fault tolerance and is applicable to large-scale distributed storage systems.

[0122] Figure 3 The following is the complete flowchart of the data distribution and routing mechanism based on the circular hash space in the embodiment of the present invention:

[0123] This figure shows the complete process of a data distribution and routing mechanism based on a circular hash space. The left process starts from generating node identifiers, constructing unique node identifiers by combining network addresses, weight values, and timestamps. Based on these node identifiers, the system generates corresponding virtual nodes, and the number of virtual nodes is determined by the weight value of the node. Subsequently, the system maps these virtual nodes into the circular hash space and generates a routing table to record the mapping relationship between virtual nodes and actual nodes. The right process shows the data processing process, starting from extracting the shard identifier and data content, calculating the target hash value using the same hash algorithm as the virtual nodes. The system will find the first virtual node greater than or equal to the target hash value in the circular hash space in a clockwise direction as the primary storage location, and then, in order to achieve data redundancy and load balancing, will select multiple subsequent virtual nodes corresponding to different actual nodes as backup storage locations. This design effectively solves the problems of unbalanced data distribution and data migration caused by dynamic node changes through the introduction of virtual nodes and the uniform distribution characteristics of the circular hash space, providing a scalable and efficient distributed storage solution.

[0124] In an alternative embodiment, verifying the authentication credentials and access privilege levels provided by the requesting party and retrieving and assembling access result data at corresponding levels from the distributed storage network includes:

[0125] Receiving a data access request sent by the requesting party, where the data access request includes authentication credentials, a privilege level identifier, and a target data index, and the authentication credentials include the digital signature and timestamp of the requesting party;

[0126] Verifying the validity of the authentication credentials, including: checking whether the timestamp is within the allowed time window, verifying the legality of the digital signature using the public key of the requesting party, and confirming whether the identity identifier of the requesting party is in the authorized user list;

[0127] Obtain the data access rules corresponding to the permission level identifier from the access control policy library. The data access rules define the set of data fields and access operation types that can be accessed at different permission levels, and determine the actual access permission range of the requester according to the data access rules;

[0128] Query the data location mapping table in the distributed storage network based on the target data index, and obtain the storage location information of the target data. The storage location information includes multiple storage node addresses and corresponding data shard identifiers; according to the actual access permission range of the requester, filter out the set of data shard identifiers allowed to be accessed from the storage location information, and send a data retrieval request to the corresponding storage node;

[0129] Receive the data shard content returned by the storage node, verify the integrity and consistency of the data shard, and reassemble the data shards that pass the verification into complete data according to the preset assembly rules;

[0130] Filter the reassembled data according to the access permission level of the requester, and only retain the data fields allowed to be accessed at this permission level to generate the access result data.

[0131] When a requester needs to access data in the distributed storage network, it first sends a data access request to the data management service. This request contains three key components: an authentication credential, a permission level identifier, and a target data index. The authentication credential includes the digital signature and timestamp of the requester, which are used for identity verification; the permission level identifier indicates the access permission level applied by the requester, such as "read-only level", "basic analysis level", or "full access level", etc.; the target data index indicates the specific data object that the requester hopes to access, which can be a dataset identifier or the unique identifier of a specific data item.

[0132] After receiving the access request, the data management service first verifies the validity of the authentication credential. The verification process includes three aspects: timestamp verification, signature verification, and identity authorization verification. Timestamp verification checks whether the timestamp in the request is within the time window allowed by the system to prevent replay attacks. The system can set a reasonable time window range, such as a few minutes to a few hours, according to the security requirements of the application scenario. If the timestamp has expired or is too far in advance, the request is rejected. Signature verification uses the public key of the requester to verify the legality of the digital signature to ensure that the request has not been tampered with and indeed comes from the claimed requester. Identity authorization verification checks whether the identity identifier of the requester is in the system's authorized user list to confirm that the requester has the basic permission to access the system.

[0133] After verification, the data management service retrieves the data access rules corresponding to the requested permission level identifier from the access control policy library. Different sets of data fields accessible and allowed operation types are predefined in the policy library for different permission levels. For example, the "read-only level" permission may only allow access to basic metadata fields and only support read operations; the "basic analysis level" may allow access to metadata and some feature data, and support read and statistical analysis operations; while the "full access level" may allow access to all data fields and support all operation types. Based on the retrieved access rules, the system determines the actual permission scope of the requester in the current access request, and this fine-grained permission control ensures the principle of least privilege for data access.

[0134] After determining the permission scope, query the data location mapping table in the distributed storage network based on the target data index to obtain the storage location information of the target data. The storage location information contains multiple storage node addresses and corresponding data shard identifiers, reflecting the distribution of data in the distributed network. Data may be dispersed and stored on different nodes according to the aforementioned sharding mechanism. For example, metadata shards, feature data shards, and evaluation result shards may be located on different storage nodes.

[0135] According to the actual access permission scope of the requester, filter out the set of data shard identifiers allowed to be accessed from the storage location information. For example, if the requester only has the "read-only level" permission, it may only be able to access metadata shards; if it has the "basic analysis level" permission, it may be able to access metadata shards and some feature data shards. After filtering, the data management service sends a data retrieval request to the corresponding storage node, and the request contains the data shard identifiers that need to be retrieved.

[0136] After receiving the retrieval request, the storage node reads the corresponding data shard content from the local storage according to the shard identifier and returns it to the data management service. After receiving the data shard content returned by the storage node, the data management service needs to verify the integrity and consistency of the data shard. Integrity verification is achieved by checking whether the hash value or checksum of the data shard is consistent with the expected value to ensure that the data has not been tampered with during transmission. Consistency verification ensures that multiple associated data shards are logically consistent, such as checking whether the timestamps are reasonably coherent and whether the associated fields match.

[0137] The data shards that pass the verification are recombined into complete data according to the preset assembly rules. The assembly rules define how to merge different types of data shards into a meaningful complete data structure. For example, the metadata shard may contain user identification and time information, the feature data shard contains location and attitude data, and the evaluation result shard contains analysis results. The assembly process recombines these scattered information according to the definition of the original data structure.

[0138] After the recombination is completed, the system performs a final filtration on the recombined data according to the access privilege level of the requester, only retaining the data fields allowed to be accessed at this privilege level to generate the final access result data. This step ensures that even if the complete data may be accessed during the internal processing of the system, the data returned to the requester still strictly adheres to the privilege restrictions. For example, for "basic analysis level" users, certain sensitive physiological index data may be filtered out, and only the basic movement trajectories and statistical metrics are retained.

[0139] Finally, the data management service returns the filtered access result data to the requester and records the detailed log of this access operation, including information such as the requester's identity, access time, accessed content, and privilege level, for subsequent auditing and security analysis.

[0140] Through the above method, the secure access control and on-demand assembly of data in the distributed storage network are realized, which not only ensures the security and compliance of data access but also meets the differentiated access needs of users with different privileges. This method is particularly suitable for processing multiple types of data with different sensitivities, such as in the fields of sports health data, enterprise data, etc., providing an effective solution for building a secure and reliable distributed data management system.

[0141] Figure 4 The flowchart of the distributed data access control in the embodiment of the present invention is as follows:

[0142] This figure describes a complete distributed data access control process. When the system receives a data access request, it first verifies the authentication credentials, privilege level identifier, and target data index information included in the request, where the authentication credentials need to include the digital signature and timestamp of the requester. The system will perform various verifications on the authentication credentials, including checking the validity of the timestamp, verifying the legality of the digital signature, and confirming whether the identity identifier of the requester is in the authorized user list. After that, the system obtains the access rules corresponding to the privilege level from the access control policy library. These rules define the range of data fields that can be accessed at different privilege levels and the allowed operation types, and accordingly determine the actual access privilege range of the requester. The system then queries the data location mapping table in the distributed storage network to obtain the storage location information of the target data, which includes multiple storage node addresses and corresponding data shard identifiers. Based on the access privilege range of the requester, the system filters out the set of data shard identifiers allowed to be accessed from the storage location information and sends a data retrieval request to the corresponding storage nodes. After receiving the data shards returned by the storage nodes, the system will verify the integrity and consistency of the data and reassemble the verified data shards into complete data according to the preset assembly rules. Finally, the system filters the recombined data according to the access privilege level of the requester, only retaining the data fields allowed to be accessed at this privilege level, thereby generating the final access result data.

[0143] In the second aspect of the embodiments of the present invention, a motion data security management system in the metaverse intelligent motion is provided, including:

[0144] A first unit, configured to obtain the motion data of the user in the metaverse motion scene and the identity information of the user, establish an identity authentication model of the user based on the zero-knowledge proof mechanism, generate a zero-knowledge proof protocol based on the Merkle tree, calculate a hash value according to the identity information to construct the leaf nodes of the Merkle tree, obtain the Merkle root node value through iterative calculation, generate a zero-knowledge proof including path proof, verify the authenticity of the identity information, and generate an authentication credential including a timestamp and a digital signature;

[0145] A second unit, configured to, after the authenticity of the identity information is verified, perform distributed storage on the motion data by using the sharding storage technology, including: splitting the motion data into metadata shards, feature data shards, and evaluation result shards according to the data structure of the motion data, establishing an index identifier for each data shard by using a Bloom filter, distributing and storing the data shards to multiple storage nodes through a circular hash space, and determining the storage location of the data shards through a consistent hashing algorithm;

[0146] A third unit, configured to, when responding to a data access request from a third-party application, verify the authentication credential and the access permission level provided by the requester, and retrieve and assemble the access result data of the corresponding level from the distributed storage network according to the access permission level, wherein full access permission can obtain all motion data, and restricted access permission can only obtain basic motion type information.

[0147] In the third aspect of the embodiments of the present invention, an electronic device is provided, including:

[0148] A processor;

[0149] A memory for storing executable instructions of the processor;

[0150] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.

[0151] In the fourth aspect of the embodiments of the present invention, a computer-readable storage medium is provided, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.

[0152] The present invention may be a method, an apparatus, a system, and / or a computer program product. The computer program product may include a computer-readable storage medium, on which computer-readable program instructions for executing various aspects of the present invention are loaded.

[0153] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for managing the security of motion data in the metaverse intelligent sports, characterized in that, Including: Obtain the motion data of the user in the metaverse motion scenario and the identity information of the user, establish an identity authentication model for the user based on the zero-knowledge proof mechanism, and generate a zero-knowledge proof protocol based on the Merkle tree. Calculate the hash value according to the identity information to construct the leaf nodes of the Merkle tree, and obtain the Merkle tree root node value through iterative calculation. The generation of the zero-knowledge proof including the path proof includes: Split the identity information into a user identification field, a registration time field, and a permission level field, and calculate the SHA-256 hash values of the user identification field, the registration time field, and the permission level field to form leaf nodes. Arrange the leaf nodes in a preset order to construct the bottom layer of the Merkle tree, cascade the hash values of adjacent two leaf nodes and then calculate the SHA-256 hash value to obtain the parent node value. Repeat the operation of pairing and combining adjacent leaf nodes until a unique Merkle tree root node value is generated. During the pairing and combining process, record the index information of the left and right child nodes of each leaf node and the corresponding hash values, and construct a node relationship mapping table. Select the target leaf node that needs to be authenticated, determine the verification path from the target leaf node to the root node based on the node relationship mapping table, and extract the hash values of adjacent leaf nodes and the node index information of the left and right child nodes on the verification path. Generate a random prime number as the homomorphic encryption key, encrypt the hash values of the leaf nodes on the verification path using the homomorphic encryption key, generate an encrypted node sequence, and combine the encrypted node sequence with the node index information to form a zero-knowledge proof. Verify the authenticity of the identity information and generate an authentication credential including a timestamp and a digital signature. When the authenticity verification of the identity information passes, use the sharding storage technology to perform distributed storage on the motion data, including: splitting the motion data into metadata shards, feature data shards, and evaluation result shards according to the data structure of the motion data, establishing an index identifier for each data shard using a Bloom filter, distributing and storing the data shards to multiple storage nodes through a circular hash space, and determining the storage location of the data shards through a consistent hashing algorithm. When responding to the data access request of a third-party application, verify the authentication credential and access permission level provided by the requester, and retrieve and assemble the access result data of the corresponding level from the distributed storage network, including: Receive the data access request sent by the requester. The data access request includes an authentication credential, a permission level identifier, and a target data index, where the authentication credential includes the digital signature and timestamp of the requester. Verify the validity of the authentication credential, including: checking whether the timestamp is within the allowed time window, verifying the legality of the digital signature using the public key of the requester, and confirming whether the identity identifier of the requester is in the authorized user list. Obtain the data access rules corresponding to the permission level identifier from the access control policy library. The data access rules define the set of data fields that can be accessed and the access operation types for different permission levels, and determine the actual access permission range of the requester according to the data access rules. Query the data location mapping table in the distributed storage network based on the target data index to obtain the storage location information of the target data, where the storage location information includes multiple storage node addresses and corresponding data shard identifiers; filter out the set of data shard identifiers allowed to be accessed from the storage location information according to the actual access permission range of the requester, and send a data retrieval request to the corresponding storage node; Receive the data shard content returned by the storage node, verify the integrity and consistency of the data shard, and reassemble the data shards that pass the verification into complete data according to the preset assembly rules; Filter the reassembled data according to the access permission level of the requester, and only retain the data fields allowed to be accessed at this permission level to generate the access result data.

2. The method according to claim 1, wherein Verify the authenticity of the identity information, and generate an authentication credential including a timestamp and a digital signature, including: Send the zero-knowledge proof and the Merkle tree root node value to the verifier. The verifier decrypts the encrypted node sequence using the homomorphic encryption key, reconstructs the verification path according to the node index information, and verifies whether the reconstructed root node value is consistent with the received root node value; Receive the verification result returned by the verifier. When the verification result indicates that the reconstructed root node value is consistent with the received root node value, confirm that the identity authentication is passed, and generate an authentication credential including a timestamp and a digital signature.

3. The method according to claim 1, characterized in that, According to the data structure of the motion data, it is divided into metadata shards, feature data shards, and evaluation result shards. A Bloom filter is used to establish an index identifier for each data shard, and the data shards are distributed and stored on multiple storage nodes through a circular hash space. Determining the storage location of the data shard by the consistent hashing algorithm includes: Perform sharding processing on the motion data according to the data structure type, including: dividing the user identifier, timestamp, and device information into metadata shards, dividing the motion trajectory data and motion posture data into feature data shards, and dividing the physiological feature data into evaluation result shards; Construct a Bloom filter index for each data shard, including: selecting multiple independent hash functions, calculating the feature values of the data shard using the multiple hash functions respectively, mapping the feature values to the corresponding positions in the multi-dimensional vector space, and setting the binary values of the mapped positions to 1 to generate the Bloom filter fingerprint of the data shard; Determine the storage location of the data shard based on the consistent hashing algorithm, including: constructing a circular hash space, mapping the storage nodes to the virtual nodes of the circular hash space, calculating the hash value of the data shard, and finding the first virtual node greater than or equal to the hash value in the clockwise direction on the circular hash space as the storage location; Send the metadata shard, the feature data shard, and the evaluation result shard to the corresponding storage locations for storage, and record the correspondence between the data shard and the Bloom filter fingerprint at the storage location.

4. The method according to claim 3, wherein Construct a circular hash space, map the storage nodes to the virtual nodes of the circular hash space, calculate the hash value of the data shard, and find the first virtual node greater than or equal to the hash value in the clockwise direction on the circular hash space as the storage location, including: Generate a node identifier for each storage node, which is obtained by concatenating the node network address, the node weight value, and the timestamp; Determine the number of virtual nodes of each storage node based on the node weight value, combine the virtual node serial number with the node identifier to generate a virtual node identifier, calculate the hash value of the virtual node identifier, and map the virtual node to the corresponding hash segment in the circular hash space according to the hash value to generate a routing table containing the mapping relationship between the virtual node position and the actual node; Extract the shard identifier, shard size, and shard content from the data shard, and calculate the target hash value of the shard identifier using the same hash algorithm as the virtual node; In the circular hash space, starting from the target hash value, search the routing table in the clockwise direction, use the first virtual node greater than or equal to the target hash value as the primary storage location, and select the two adjacent virtual nodes behind it as the backup storage locations. The primary storage location and the backup storage locations respectively correspond to different actual storage nodes.

5. A motion data security management system in the metaverse intelligent motion, which is used to implement the method described in any one of claims 1-4, and is characterized in that, Comprising: A first unit for obtaining the motion data of the user in the metaverse motion scenario and the identity information of the user, establishing an identity authentication model of the user based on the zero-knowledge proof mechanism, generating a zero-knowledge proof protocol based on the Merkle tree, calculating the hash value according to the identity information to construct the Merkle tree leaf node, obtaining the Merkle tree root node value through iterative calculation, generating a zero-knowledge proof containing the path proof, verifying the authenticity of the identity information, and generating an authentication credential containing the timestamp and the digital signature; A second unit for, when the authenticity verification of the identity information passes, performing distributed storage on the motion data by using the shard storage technology, including: dividing the motion data into metadata shards, feature data shards, and evaluation result shards according to the data structure of the motion data, establishing an index identifier for each data shard by using a Bloom filter, distributing and storing the data shards to multiple storage nodes through the circular hash space, and determining the storage location of the data shards through the consistent hashing algorithm; A third unit for, when responding to the data access request of a third-party application, verifying the authentication credential and the access privilege level provided by the requester, and retrieving and assembling the access result data of the corresponding level from the distributed storage network according to the access privilege level. Among them, full access privilege can obtain all motion data, and restricted access privilege can only obtain basic motion type information.

6. An electronic device, characterized in that, Comprising: A processor; A memory for storing instructions executable by the processor; Wherein, the processor is configured to call the instructions stored in the memory to execute the method according to any one of claims 1 to 4.

7. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, the method according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Federated identity management with decentralized computing platforms

    US20200067907A1

  • KR1018371690000B1