Iris acquisition and key authentication block chain transaction method and system based on cold wallet
By using cold wallet and iris collection modules in the blockchain transaction system for identity verification and reorganizing the private key signature, the security risks and insufficient authentication of traditional blockchain transaction systems are solved, and higher security and asset protection are achieved.
Patent Information
- Application Number
- CN202510289461.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-06-27
AI Technical Summary
Traditional blockchain transaction systems rely on hot wallets and traditional cryptography methods, which pose security risks and insufficient authentication problems, especially when facing advanced attacks.
The iris acquisition and key authentication method based on cold wallets is used to perform high-precision authentication through the iris acquisition module on the cold wallet, and multiple private key fragments at designated storage locations are called for reorganization, and transaction signatures are performed based on the reorganization of private keys.
It significantly improves the security of the blockchain transaction system, prevents unauthorized access, and ensures the security and privacy protection of user digital assets.
Smart Images

Figure CN120218932A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of iris authentication and blockchain asset transactions, and particularly to a blockchain transaction method and system based on cold wallet iris collection and key authentication. Background Art
[0002] In traditional digital asset management and blockchain transaction systems, security and user authentication mainly rely on hot wallets (online wallets) and traditional cryptographic methods. Although these methods provide a certain degree of security, they still have some significant security risks and technical limitations.
[0003] Since hot wallets are always online, the private key is exposed to the network environment and is extremely vulnerable to hacker attacks. Once the private key is stolen, the user's digital assets will face great risks. Traditional authentication methods mainly rely on username / password combinations and two-factor authentication, and these methods are ineffective in the face of advanced attacks. Summary of the Invention
[0004] Embodiments of the present invention provide a blockchain transaction method and system based on cold wallet iris collection and key authentication to solve the problems existing in the related technologies. The technical solutions are as follows:
[0005] In a first aspect, embodiments of the present invention provide a blockchain transaction method based on cold wallet iris collection and key authentication, including:
[0006] Obtain unsigned transaction data, trigger the iris collection module on the cold wallet to collect iris data, and perform identity authentication on the iris data through the cold wallet to obtain an identity authentication result;
[0007] In the case where the identity authentication result is authentication passed, based on the dynamic threshold algorithm, call private key shards stored in multiple specified storage locations for recombination to obtain a complete recombined private key; different private key shards are pre-stored in different storage locations;
[0008] Sign the transaction data according to the recombined private key to obtain a transaction signature, and send the transaction signature to the blockchain network for transaction.
[0009] In an implementation manner, performing identity authentication on the iris data through the cold wallet includes:
[0010] The cold wallet projects a specified pattern onto the surface of the human eye through the iris collection module, and uses the camera of the iris collection module to capture the reflected image, and reconstructs the three-dimensional shape of the iris based on the reflected image;
[0011] The cold wallet captures the microvascular vibration data of the iris area through microvascular movement detection;
[0012] The cold wallet captures the pupil microtremor pattern through pupil detection;
[0013] Judge whether the human eye is in a living state according to the three-dimensional shape of the human eye, the microvascular vibration data, and the pupil microtremor pattern;
[0014] When the human eye is in a living state, compare the iris features collected by the iris acquisition module with the iris templates of pre-stored legitimate users to confirm the identity of the user.
[0015] In one implementation, it further includes:
[0016] Pre-obtain the iris images of legitimate users, and extract the iris feature codes of both eyes from the iris images;
[0017] Obtain the device PUF of the cold wallet, and generate a composite master key by combining the iris feature codes and the device PUF;
[0018] Use the Shamir secret sharing algorithm to split the composite master key into multiple private key shards, and store each private key shard in different storage locations, where the storage locations are the internal storage space of the cold wallet or a multi-modal disaster recovery system.
[0019] In one implementation, the recombination of multiple specified storage location private key shards based on the dynamic threshold algorithm includes:
[0020] Based on the dynamic threshold algorithm, call the selected multiple private key shards, and transmit the multiple private key shards to the trusted execution environment of the cold wallet through a secure channel;
[0021] Use the Shamir secret sharing algorithm in the trusted execution environment to recombine the multiple private key shards to recover the complete recombined private key.
[0022] In one implementation, it further includes:
[0023] The multi-modal disaster recovery system responds to the emergency key recovery process to obtain the iris image and the physical mnemonic entered by the user, verifies the iris image and the physical mnemonic, and generates an emergency key when both are verified successfully. The emergency key is used to regenerate the master key or directly access the private key shards stored in the cold wallet; the emergency key recovery process is triggered when the master key is lost or unusable.
[0024] In one implementation, signing the transaction data according to the recombined private key includes:
[0025] Perform a hash process on the transaction data to obtain a transaction hash value;
[0026] Use the XMSS signature algorithm to sign the transaction hash value to obtain a quantum-resistant transaction signature; broadcast the transaction signature together with the transaction data to the blockchain network for transactions.
[0027] In one embodiment, it further includes:
[0028] During the identity authentication process, when the number of consecutive incorrect access attempts exceeds the set threshold, trigger an emergency response;
[0029] When the cold wallet detects brute force cracking, start the self-destruction trigger mechanism of the cold wallet to automatically destroy all data in the cold wallet, and the destroyed data cannot be recovered.
[0030] In a second aspect, an embodiment of the present invention provides a blockchain transaction system based on iris collection and key authentication of a cold wallet, which executes the blockchain transaction method based on iris collection and key authentication of a cold wallet as described above.
[0031] In a third aspect, an embodiment of the present invention provides an electronic device, which includes: a memory and a processor. Among them, the memory and the processor communicate with each other through an internal connection path. The memory is used to store instructions, and the processor is used to execute the instructions stored in the memory. When the processor executes the instructions stored in the memory, the processor executes the method in any one of the above aspects.
[0032] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program runs on a computer, the method in any one of the above aspects is executed.
[0033] The advantages or beneficial effects in the above technical solutions at least include:
[0034] The present invention performs iris recognition through the iris collection module on the cold wallet for high-precision identity verification to prevent unauthorized access; the present invention uses the cold wallet to store the sharded private keys offline to ensure that the private keys are not exposed in the network environment, and after the identity verification is passed, call the sharded private keys at multiple specified storage locations to recombine to obtain a complete recombined private key, and perform transaction signature based on the recombined private key, significantly improving the security of the transaction system and ensuring the security and privacy protection of users' digital assets.
[0035] The above summary is only for the purpose of the specification and is not intended to be limiting in any way. In addition to the above-described illustrative aspects, embodiments, and features, further aspects, embodiments, and features of the present invention will be readily apparent by reference to the drawings and the following detailed description. Description of the Drawings
[0036] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the several views denote the same or similar components or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings depict only some embodiments disclosed in accordance with the present invention and should not be regarded as limiting the scope of the present invention.
[0037] Figure 1 It is a schematic flowchart of the blockchain transaction method for iris collection and key authentication based on a cold wallet according to the present invention;
[0038] Figure 2 It is a structural block diagram of an electronic device according to an embodiment of the present invention. Detailed implementation manners
[0039] In the following, only some exemplary embodiments are simply described. As those skilled in the art can recognize, the described embodiments can be modified in various different ways without departing from the spirit or scope of the present invention. Therefore, the drawings and the description are considered to be exemplary in nature rather than restrictive.
[0040] Embodiment 1
[0041] An embodiment of the present invention provides a blockchain transaction method for iris collection and key authentication based on a cold wallet, as Figure 1 shown, including the following steps:
[0042] Step S1: Obtain unsigned transaction data, trigger the iris collection module on the cold wallet to collect iris data, and perform identity authentication on the iris data through the cold wallet to obtain an identity authentication result.
[0043] In this embodiment, the user needs to store cryptocurrency in a highly secure cold wallet and perform identity verification and transaction authorization through iris recognition technology.
[0044] In this embodiment, the cold wallet has an infrared iris collection module. This iris collection module integrates a dedicated 850nm wavelength infrared sensor on the cold wallet shell, supporting high-precision iris collection; at the same time, the internal data of the cold wallet is transmitted to the verification chipset through a one-way optical fiber to avoid electromagnetic radiation leakage and prevent malicious hardware attacks or data theft.
[0045] Before the cold wallet is used, it needs to be initially set up. In the initial setup stage, the user completes iris scanning through the dedicated iris collection module on the cold wallet, obtains the iris image of a legitimate user, and uses the Daugman algorithm to extract the iris feature code as the core biometric identifier.
[0046] Among them, the method of using the Daugman algorithm to extract the iris feature code is:
[0047] On the normalized iris image, a Gabor filter bank is used for feature extraction, and encoding is performed based on the output results of the Gabor filters. Specifically, the phase information of each filter response is calculated (because the phase is more robust to environmental factors such as illumination), and then it is quantized into a binary code. For example, if the phase at a certain position is greater than or equal to a certain threshold, it is assigned a value of 1; otherwise, it is assigned a value of 0. In this way, a binary string can be generated for the entire iris image as the iris code.
[0048] In this embodiment, the monocular iris feature is 1536 bytes. The method for extracting the iris feature code of a single eye can use multi-scale and multi-directional Gabor filters to extract iris texture features, and convert the response amplitude of the feature points into a binary feature code. For example, after extracting features through 40 groups of Gabor filters with different directions and frequencies, the frequency and direction information of each feature point is encoded into a 6-bit binary code, and finally a 1536-bit iris feature code is formed.
[0049] After obtaining the monocular iris feature code, the iris feature codes of both eyes are directly concatenated together. For example, if the monocular iris feature code is 1536 bytes (12288 bits), then the binocular feature code after concatenation is 3072 bytes (24576 bits).
[0050] Furthermore, in order to reduce the feature code length and improve the calculation efficiency, the binocular features can be fused and dimension-reduced. For example, principal component analysis (PCA) is used to reduce the dimension of the features and remove redundant information; also, through a feature fusion algorithm, the binocular features can be weighted averaged or key features can be selected as needed.
[0051] At the same time, the device PUF (Physical Unclonable Function) of the cold wallet is obtained, and combined with elliptic curve encryption (ECC), the device PUF and the iris feature code are used to generate a composite master key. In this embodiment, 80% of the entropy value of the composite master key comes from the hash value corresponding to the iris feature code, and 20% comes from the device PUF, realizing the dual binding of biometric features and hardware features, ensuring the uniqueness of the key and preventing it from being copied.
[0052] In this embodiment, the Shamir secret sharing algorithm is used to split the composite master key into multiple private key shards, and each private key shard is stored in different storage locations, which are the internal storage space of the cold wallet or a multi-modal disaster recovery system. Even if a certain private key shard is leaked, the attacker cannot directly recover the complete private key.
[0053] In this embodiment, the cold wallet always remains offline to avoid network attacks, and all private key operations are completed within a secure chip, without the risk of plaintext exposure.
[0054] It should be noted that a cold wallet refers to a way of storing cryptocurrency private keys in an offline environment, aiming to avoid exposing the private keys to the Internet, thereby preventing hacker attacks or network threats. The cold wallet in this embodiment can be a hardware cold wallet, which is built with a highly secure chip, such as the security chip of NXP Semiconductors.
[0055] After the preliminary setup of the cold wallet is completed, obtain the unsigned transaction data. Among them, the transaction data can be created on an Internet-connected device (such as a hot wallet on a computer or mobile phone), and the transaction data includes the sender address, recipient address, amount, etc.; export the unsigned transaction data as a QR code, file or other forms for transmission to the cold wallet device for signing.
[0056] When the cold wallet receives the transaction data, it can trigger the iris authentication module on the cold wallet to collect and authenticate the iris of the current user, thereby obtaining the identity authentication result.
[0057] The iris authentication in this embodiment, as a key step to verify the user's identity, is directly carried out on the cold wallet device. The user aligns the eyes with the iris collection module on the cold wallet to start the iris recognition process; the cold wallet device will prompt the user to correctly align the eyes and may provide feedback to ensure high-quality iris image collection.
[0058] The cold wallet determines whether the currently entered iris is in a living state through methods such as 3D structured light, microvascular motion detection, and pupil microtremor detection to achieve high-precision identity verification. Specifically:
[0059] The iris collection module projects a specified pattern onto the surface of the human eye. The specified image can be a grid or dot matrix, and uses the camera of the iris collection module to capture the reflected image. By analyzing the deformation of these reflected images, the three-dimensional shape of the iris can be reconstructed to ensure that the collected iris data is real and complete, preventing spoofing attacks using flat photos or forgeries.
[0060] Since the blood flow in the living iris will cause minute vibrations, this kind of vibration can be captured by a highly sensitive sensor. Therefore, the microvascular motion detection of the cold wallet in this embodiment uses infrared imaging technology to capture the minute blood vessel motion in the iris area, thereby obtaining the microvascular vibration data in the iris area. By detecting the microvascular motion in the iris area, it can be confirmed that the iris belongs to a real human eye rather than a forgery. This method can effectively prevent spoofing attacks using fake eyes or other non-living irises.
[0061] Since pupillary microtremor refers to the tiny vibrations that occur in the pupil in an unconscious state, usually several times per second, and this kind of vibration is part of the body's autonomic nervous system and is difficult to be artificially controlled or forged. Therefore, in this embodiment, the high-resolution camera of the iris acquisition module of the cold wallet can also capture and analyze the microtremor pattern of the pupil. If the pupil does not have a microtremor pattern, or the microtremor pattern does not match the corresponding microtremor pattern of the human body, it can be considered that the currently captured iris does not belong to a real human eye.
[0062] This embodiment determines whether the human eye is a real human eye according to one of the methods of 3D structured light detection, microvascular vibration detection, and pupillary microtremor detection, or a combination of multiple detection methods. When the human eye is in a living state, that is, when the human eye is a real human eye, the iris features collected by the iris acquisition module are compared with the iris templates of pre-stored legitimate users. If the iris features exist in the iris template, the current user can be considered a legitimate user to confirm the user's identity and ensure that they are a legitimate holder. If it is detected that the iris does not belong to a real human eye, or the comparison and verification of the iris features with the iris template fails, the system will prompt the user to try again or reject access.
[0063] Among them, the iris templates of pre-stored legitimate users are iris features / iris feature codes extracted in the initial setting stage of the cold wallet. In this embodiment, lattice-based encryption technology is used for iris template storage. By using lattice-based encryption, the iris templates can be encrypted and stored without exposing the original data, which greatly reduces the risk of user privacy being damaged due to database leakage.
[0064] Step S2: In the case where the identity authentication result is passed, based on the dynamic threshold algorithm, the private key shards stored in multiple specified storage locations are called for recombination to obtain a complete recombined private key; among them, different private key shards are pre-stored in different storage locations.
[0065] The master key of this embodiment is divided into N private key shards and stored in different secure locations. This embodiment starts to call the private key shards only after the iris authentication is passed (that is, it is determined that the iris is a real human eye and the current iris belongs to a legitimate holder), ensuring that only legitimate users can initiate transactions.
[0066] This embodiment selects k / N private key shard combinations according to the dynamic threshold algorithm. Among them, the dynamic threshold algorithm determines which shards to select for combination during each transaction. Its main purpose is to provide flexibility and fault tolerance while ensuring security. The following is the specific decision-making process of the dynamic threshold algorithm:
[0067] a. Set the threshold
[0068] Fixed Threshold: In some embodiments, the value of k is fixed. For example, k = 3 and N = 5, which means that at least 3 private key shards are required to recover the private key for each transaction.
[0069] Dynamic Threshold: In some embodiments, the value of k is adjusted according to specific circumstances. For example, in the case of a large transaction amount or high risk, more private key shards (a larger value of k) may be required to increase security.
[0070] b. Shard Selection Strategy
[0071] The selection of which private key shards are used for the private key recombination in this verification is usually based on the following several strategies:
[0072] i. Random Selection
[0073] Randomly select k shards from all available private key shards for each transaction, which increases the difficulty for attackers to predict and obtain specific private key shards.
[0074] ii. Location - Based Selection
[0075] Store the shards in different locations or devices (such as cold wallets, multi - modal disaster recovery systems, etc.). Set priorities according to the location and reliability of the private key shards. For example, preferentially select the private key shards stored in cold wallets, followed by other backup locations, which improves the reliability and fault tolerance of the system.
[0076] iii. Risk - Assessment - Based Selection
[0077] Dynamically adjust the value of k and the selection strategy according to the risk level of the transaction (such as transaction amount, type of assets involved, etc.). For large - value transactions or highly sensitive operations, select more private key shards (a larger value of k) for combination; for small - value transactions or daily operations, fewer private key shards (a smaller value of k) can be selected to improve efficiency and optimize the user experience while ensuring security.
[0078] In the actual execution process, the decision of the dynamic threshold algorithm is pre - set in advance. When a user initiates a transaction request, the corresponding private key shards can be selected for private key recombination according to the pre - set decision.
[0079] The multiple selected private key shards in this embodiment are transmitted to the trusted execution environment of the cold wallet (such as a security island based on ARM TrustZone) through a secure channel. In the trusted execution environment, the Shamir secret sharing algorithm is used to recombine the selected multiple private key shards to recover the complete recombined private key.
[0080] Step S3: Sign the transaction data according to the recombined private key to obtain a transaction signature, and send the transaction signature to the blockchain network for the transaction.
[0081] Before generating a signature, it is first necessary to perform a hash processing on the transaction data to obtain a transaction hash value. Among them, the hash algorithm includes SHA-256 or Keccak (the hash function used by Ethereum).
[0082] Subsequently, the elliptic curve digital signature algorithm (ECDSA) is used to sign the hash value of the transaction data with the recombined private key to obtain a transaction signature, so as to ensure the security and integrity of the private key.
[0083] Furthermore, the extended Merkle signature scheme (XMSS) can also be used to sign the hash value of the transaction data to obtain a quantum-resistant transaction signature, so as to provide stronger security protection.
[0084] This embodiment can select a suitable signature algorithm according to the requirements of specific application scenarios. For example, ECDSA is used in scenarios that require quick response, and XMSS is used in scenarios that require long-term storage and high security.
[0085] It should be noted that the elliptic curve digital signature algorithm (ECDSA) and the extended Merkle signature scheme (XMSS) have been disclosed in the prior art, and the specific working principles of the two algorithms will not be described repeatedly here.
[0086] This embodiment broadcasts the original transaction data and transaction objects such as the signed transaction signature to the nodes in the blockchain network, and the nodes verify and include them in a new block. After receiving the transaction, the blockchain node will perform signature verification. Specifically:
[0087] The blockchain node extracts the public key of the sender from the transaction object, extracts the signature from the transaction object, and recalculates the hash value according to the transaction data. The node uses the public key of the sender and the extracted signature to verify the recalculated hash value to ensure its legality and integrity.
[0088] The transaction signature and transaction data and other transaction objects in this embodiment can be transmitted to the blockchain node through the one-way optical fiber of the cold wallet to complete the broadcast, so as to improve security.
[0089] Furthermore, the multi-modal disaster recovery system in this embodiment can exist independently of the cold wallet and can be integrated into the cold wallet to further enhance the security and reliability of the cold wallet. The multi-modal disaster recovery system is a multi-level data protection and recovery mechanism that combines a variety of security technologies and means to ensure that the user's identity and data can still be restored in extreme cases (such as the loss of the master key, device damage, etc.).
[0090] When the master key is lost or unavailable, an emergency key recovery process is triggered. At this time, the user's iris image and the physical mnemonic entered by the user are collected. The iris features in the iris image are extracted to determine the user's identity. At the same time, it is verified whether the entered physical mnemonic matches the pre-stored mnemonic. When both iris verification and mnemonic verification are successful, an emergency key is generated. The user can regenerate the master key through the emergency key or directly access the private key shards stored in the cold wallet.
[0091] Furthermore, in the emergency key recovery process, the multi-modal disaster recovery system can also record the physical mnemonic in audio mode. While extracting the physical mnemonic from the audio, the voiceprint in the audio is also identified and compared with the pre-stored voiceprint template to determine the user's identity again. The physical mnemonic extracted from the audio is matched with the pre-stored mnemonic. Only when iris verification, voiceprint verification, and mnemonic verification are all successful, an emergency key is generated. The user can regenerate the master key through the emergency key or directly access the private key shards stored in the cold wallet.
[0092] The emergency key combines multiple different types of verification methods such as iris, voiceprint, and mnemonic, increasing the difficulty for attackers to obtain the complete key, improving security, and ensuring data availability for users in extreme situations. In addition, zero-knowledge proof technology can be incorporated, allowing users to complete identity verification and key recovery without exposing sensitive information, further enhancing the security and privacy protection capabilities of the emergency key.
[0093] Furthermore, the cold wallet can also be set with a hardware security module (HSM) and specific security measures to prevent the leakage of sensitive information. Among them, the hardware security module (HSM) can detect brute-force attacks by monitoring the number and pattern of access attempts. Once abnormal behavior is detected, an emergency response mechanism can be triggered. Specifically: a threshold is set in advance, and when the number of consecutive incorrect access attempts exceeds this threshold, an emergency response is triggered for an alarm; or once brute-force cracking is detected, that is, the cold wallet detects abnormal voltage / frequency fluctuations or external physical attacks, the self-destruction trigger mechanism is immediately activated to automatically destroy all data in the cold wallet, and the destroyed data cannot be recovered.
[0094] This embodiment aims to construct a highly secure biometric and hardware-bound two-factor authentication system resistant to quantum computing attacks, suitable for high-sensitivity scenarios (such as cold wallet private key management). By integrating and improving iris recognition algorithms, elliptic curve cryptography (ECC), optical isolation verification architectures, dynamic sharding signature protocols, and quantum security protection systems, the deep integration of biometric features and physical hardware characteristics is achieved to ensure data security and the non-forgeability of user identities.
[0095] Embodiment Two
[0096] This embodiment provides a blockchain transaction system based on iris collection and key authentication with a cold wallet, which executes the blockchain transaction method based on iris collection and key authentication with a cold wallet as described in Embodiment 1.
[0097] The blockchain transaction system at least includes a cold wallet and a blockchain network. Identity authentication and transaction signing are performed through the cold wallet, and the transaction signature is transmitted to the blockchain node through the unidirectional optical fiber of the cold wallet for transactions, comprehensively protecting the security of users' digital assets. The blockchain transaction system in this embodiment realizes the perfect integration of offline storage and strong identity authentication through the combination of iris recognition and cold wallet technology, providing a solution with high security, high convenience, and anti-attack ability for blockchain assets.
[0098] It should be noted that the functions implemented by the system in the embodiments of the present invention can be referred to the method description in Embodiment 1 above, and will not be elaborated here.
[0099] Embodiment 3
[0100] This embodiment provides an electronic device. Figure 2 The structural block diagram of the electronic device according to an embodiment of the present invention is shown. As Figure 2 shown, the electronic device includes: a memory 100 and a processor 200, and a computer program that can run on the processor 200 is stored in the memory 100. When the processor 200 executes the computer program, it implements the blockchain transaction method based on iris collection and key authentication with a cold wallet in the above embodiments. The number of the memory 100 and the processor 200 can be one or more.
[0101] The electronic device further includes:
[0102] A communication interface 300, which is used to communicate with external devices and perform data interaction and transmission.
[0103] If the memory 100, the processor 200, and the communication interface 300 are implemented independently, the memory 100, the processor 200, and the communication interface 300 can be interconnected through a bus and complete communication with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc.
[0104] Optionally, in a specific implementation, if the memory 100, the processor 200, and the communication interface 300 are integrated on a single chip, the memory 100, the processor 200, and the communication interface 300 can communicate with each other through an internal interface.
[0105] An embodiment of the present invention provides a computer-readable storage medium storing a computer program, which when executed by a processor implements the method provided in the embodiment of the present invention.
[0106] An embodiment of the present invention further provides a chip, which includes a processor for calling and running instructions stored in a memory, so that a communication device equipped with the chip executes the method provided in the embodiment of the present invention.
[0107] An embodiment of the present invention further provides a chip, including: an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is configured to execute code in the memory, and when the code is executed, the processor is configured to execute the method provided in the embodiment of the invention.
[0108] It should be understood that the above-mentioned processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor supporting the advanced RISC machines (ARM) architecture.
[0109] Further, optionally, the above-mentioned memory may include a read-only memory and a random access memory, and may further include a non-volatile random access memory. The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may include a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may include a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0110] In the above embodiments, it may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the present invention are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium.
[0111] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "examples", "specific examples", or "some examples" etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. Moreover, the specific features, structures, materials, or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0112] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of the present invention, "a plurality of" means two or more unless otherwise specifically defined.
[0113] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various changes or substitutions, and these should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A blockchain transaction method based on iris collection and key authentication of a cold wallet, characterized in that: include: Obtain unsigned transaction data, trigger the iris collection module on the cold wallet to collect iris data, perform identity authentication on the iris data through the cold wallet, and obtain an identity authentication result; When the identity authentication result is that the authentication is passed, the private key fragments of multiple designated storage locations are called based on a dynamic threshold algorithm to reorganize to obtain a complete reorganized private key; wherein different storage locations pre-store different private key fragments; The transaction data is signed according to the reorganized private key to obtain a transaction signature, and the transaction signature is sent to the blockchain network for transaction.
2. The blockchain transaction method based on iris collection and key authentication of cold wallet according to claim 1 is characterized in that: The identity authentication of the iris data by the cold wallet includes: The cold wallet projects a specified pattern onto the surface of the human eye through the iris acquisition module, and uses the camera of the iris acquisition module to capture the reflected image, and reconstructs the three-dimensional form of the iris based on the reflected image; The cold wallet captures microvascular vibration data of the iris area through microvascular motion detection; The cold wallet captures pupil microtremor patterns through pupil detection; Determine whether the human eye is alive based on the three-dimensional shape of the human eye, microvascular vibration data, and pupil microtremor pattern; When the human eye is alive, the iris features collected by the iris collection module are compared with the pre-stored iris templates of legitimate users to confirm the identity of the user.
3. The blockchain transaction method based on iris collection and key authentication of cold wallet according to claim 1 is characterized in that: Also includes: Acquire an iris image of a legitimate user in advance, and extract iris feature codes of both eyes from the iris image; Obtain the device PUF of the cold wallet, and generate a composite master key by combining the iris feature code and the device PUF; The composite master key is divided into a plurality of private key shards using the Shamir secret sharing algorithm, and each private key shard is stored in a different storage location, which is a storage space inside a cold wallet or a multimodal disaster recovery system.
4. The blockchain transaction method based on iris collection and key authentication of cold wallet according to claim 1 is characterized in that: The calling of a plurality of private key fragments at designated storage locations for reorganization based on a dynamic threshold algorithm includes: Calling the selected multiple private key shards based on a dynamic threshold algorithm, and transmitting the multiple private key shards to the trusted execution environment of the cold wallet through a secure channel; The Shamir secret sharing algorithm is used in a trusted execution environment to reorganize the multiple private key fragments to restore the complete reorganized private key.
5. The blockchain transaction method based on iris collection and key authentication of cold wallet according to claim 3 is characterized in that: Also includes: The multimodal disaster recovery system obtains an iris image and a physical mnemonic entered by a user in response to an emergency key recovery process, verifies the iris image and the physical mnemonic and generates an emergency key if both are successfully verified. The emergency key is used to regenerate a master key or directly access a private key shard stored in a cold wallet. The emergency key recovery process is triggered when the master key is lost or cannot be used.
6. The blockchain transaction method based on iris collection and key authentication of cold wallet according to claim 1 is characterized in that: The signing of the transaction data according to the reorganized private key comprises: Hash the transaction data to obtain a transaction hash value; The transaction hash value is signed using the XMSS signature algorithm to obtain the quantum-resistant transaction signature; the transaction signature is broadcast together with the transaction data to the blockchain network for transaction.
7. The blockchain transaction method based on iris collection and key authentication of cold wallet according to claim 1 is characterized in that: Also includes: During the identity authentication process, when the number of consecutive incorrect access attempts exceeds the set threshold, an emergency response is triggered; When the cold wallet detects a brute force attack, the self-destruction trigger mechanism of the cold wallet is activated to automatically destroy all data in the cold wallet, and the destroyed data cannot be recovered.
8. A blockchain transaction system based on iris collection and key authentication of cold wallet, characterized in that: Execute the blockchain transaction method based on iris collection and key authentication of a cold wallet as described in any one of claims 1 to 7.
9. An electronic device, characterized in that: include: A processor and a memory, wherein the memory stores instructions, and the instructions are loaded and executed by the processor to implement the blockchain transaction method based on iris collection and key authentication of a cold wallet as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the blockchain transaction method based on iris collection and key authentication of a cold wallet as described in any one of claims 1 to 7 is implemented.