A method for supervising and managing digital assets in large enterprises

By employing a multi-level key system and hierarchical asset encryption mechanism, combined with private key sharding and zero-knowledge proofs, the system addresses the issues of complex key management and low security in large enterprise digital asset management systems. This enables flexible access control and efficient data access, enhancing the system's security and availability.

CN120639300BActive Publication Date: 2025-10-31SICHUAN CHUANGLI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511127720.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-13
Publication Date
2025-10-31
Estimated Expiration
2045-08-13

AI Technical Summary

Technical Problem

Large enterprise digital asset management systems suffer from complex key management, inflexible access control, low data security, and single point of failure risk, making it difficult to meet the requirements for high availability and fault tolerance.

Method used

It employs a multi-level key system and hierarchical asset encryption mechanism, stores private keys in fragments and combines zero-knowledge proofs and location credentials, dynamically adjusts permissions through smart contracts, and uses the Shamir secret sharing scheme to recover private keys, thereby achieving hierarchical data access.

Benefits of technology

It implements hierarchical access control and dynamic security adjustment to prevent private key leakage and unauthorized access, improve system availability and fault tolerance, and ensure data security and management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639300B_ABST
    Figure CN120639300B_ABST
Patent Text Reader

Abstract

This application discloses a method for supervising and managing digital assets in large enterprises. The method includes: constructing a multi-level key system for each digital asset, generating a key pair set corresponding to each security level, and generating ciphertext for each security level using a hierarchical asset encryption mechanism; dividing the private key of each security level into M fragments and distributing them to M storage nodes, generating location credentials and storing them to K verification nodes; upon receiving an access request from an asset access node, extracting the basic permission security level from a preset smart contract, generating a valid security level, and sending the ciphertext corresponding to the valid security level to the asset access node; sending location credential guidance information to the asset access node, guiding the asset access node to obtain K location credentials, deriving the fragment storage location based on the location credentials, reconstructing the private key, and decrypting the received ciphertext to achieve hierarchical data access. This improves the security and efficiency of enterprise digital asset management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of digital asset technology, and in particular to a method for supervising and managing digital assets of large enterprises. Background Technology

[0002] With the rapid growth of digital assets in large enterprises, the secure and efficient management and access of these assets has become a critical issue. Traditional digital asset management methods often suffer from complex key management, inflexible access control, and low data security. In traditional methods, keys are usually stored centrally in a single location, making them vulnerable to attacks. Once a key is leaked, all encrypted data is at risk. Large enterprise digital asset management systems need to be highly available and fault-tolerant to avoid system paralysis due to single points of failure. Traditional system architectures are difficult to meet the requirements of high availability and fault tolerance, and thus pose a risk of single points of failure.

[0003] Therefore, there is a need for a method for supervising and managing digital assets in large enterprises to improve data security, access control flexibility, and management efficiency. Summary of the Invention

[0004] This application provides a method for supervising and managing digital assets in large enterprises, thereby improving the security and efficiency of enterprise digital asset management.

[0005] This application provides a method for supervising and managing digital assets in large enterprises, including:

[0006] S101: Construct a multi-level key system for each digital asset, generate a key pair set corresponding to each security level, and use a preset hierarchical asset encryption mechanism to generate asset ciphertext corresponding to each security level and associate it with the same digital asset identifier.

[0007] S102, divide the private key of each security level into M fragments and distribute them to M storage nodes to generate location credentials { And store it to K verification nodes;

[0008] S103, when an access request is received from an asset access node, verify the identity of the access node and extract the basic permission security level from the preset smart contract, calculate the trust factor based on the access frequency deviation rate of the asset access node, generate a valid security level, and send the asset ciphertext corresponding to the valid security level to the asset access node.

[0009] S104, send location credential guidance information to the asset access node, guide the asset access node to obtain K location credentials, deduce the fragment storage location based on the location credentials, reconstruct the private key, decrypt the received asset ciphertext, and realize hierarchical data access.

[0010] Preferably, the multi-level key system is based on the root key pair. A hierarchical key pair set is generated from top to bottom using a one-way key derivation function. , For security classification, L represents the highest security level preset for the corresponding digital asset. Classified as confidential The public key to the encrypted assets, This is the corresponding private key.

[0011] Preferably, the preset hierarchical asset encryption mechanism is used to generate asset ciphertexts of different encryption levels for digital assets, including:

[0012] A1. Assign a security level L to each digital asset;

[0013] A2. Formulate desensitization rules for digital assets. Based on the sensitivity of information in digital assets, hide sensitive information in order of decreasing security level until the lowest security level is reached, at which point all sensitive information in the digital assets is hidden.

[0014] A3. Regarding digital asset D, according to the security classification... Generate the desensitized version corresponding to this security level. ;

[0015] A4. Utilize the public keys of each security level. The corresponding de-identified version of the encryption Obtain the asset ciphertext corresponding to each security level. ;

[0016] A5. Store all encrypted assets of the same digital asset in a linked manner.

[0017] Preferably, A4 includes:

[0018] B1. Based on each security level of the digital asset, generate a random symmetric key AES-Key, and use the AES-Key to encrypt the corresponding de-identified version to obtain the first asset ciphertext. ;

[0019] B2. Utilizing security classification public key Encrypt the symmetric key AES-Key to obtain the second key ciphertext. The first asset ciphertext and the second key ciphertext are combined to form the asset ciphertext of this security level. =( , ).

[0020] Preferably, in step S102, dividing the private key of each security level into M fragments specifically includes:

[0021] Use a preset threshold secret sharing scheme to share the private key. Divide the data into M partitions, setting a threshold value K and a total number of partitions M (M≥K); then process each partition... Stored on different storage nodes, with node index as follows: .

[0022] Preferably, the generation of location credentials { And store it to K verification nodes, specifically including:

[0023] D1. Generate a pseudonym for each storage node, denoted as... , This is the identity key for the storage node with index j. It is a random number;

[0024] D2. For each fragment Generate location credentials This includes pseudonym identification and zero-knowledge proofs, proving that a storage node exists to store the shard;

[0025] D3. Select K verification nodes from M storage nodes and store the K location credentials. Stored to K verification nodes.

[0026] Preferably, the smart contract includes the identity ID of the asset access node, the digital asset, and the basic access permission level for accessing the digital asset. The smart contract is constructed by the enterprise asset management platform and is pre-constructed based on the identity information registered on the platform by each asset access node.

[0027] Preferably, S103 specifically includes:

[0028] E1. Respond to the access request submitted by the asset access node, which includes its identity identifier;

[0029] E2. Verify identity and confirm its legitimacy;

[0030] E3. Query the smart contract to obtain the basic access level L0 of the asset access node preset on the platform;

[0031] E4. Calculate the trust factor τ based on the historical behavior characteristics of the asset access node;

[0032] E5. Dynamically generate effective security levels, adjust the basic access security levels according to the trust factor τ, and obtain the effective security level l_effective = floor(L0). τ), floor represents floor rounding down;

[0033] E6. Send the asset ciphertext corresponding to its valid security level to the asset access node.

[0034] Preferably, the location credential guidance information includes: a list of verification nodes { }、Location credential index{ S104 specifically includes:

[0035] G1. Send location credential guidance information to the asset access node;

[0036] G2. Based on the location credential guidance information, the asset access node sends requests to K verification nodes respectively, requesting location credentials. After verifying the asset access node's permissions, each verification node returns the location credential and the access token pre-defined with the storage node.

[0037] G3: The asset access node deduces the private key fragment storage location based on the received location credential and access token;

[0038] G4. The asset access node submits the corresponding access token to the corresponding K storage nodes based on the obtained storage location, requesting them to shard the data. After the storage node verifies the token's validity, it returns the shard. ;

[0039] G5: After the asset access node collects K shards, it uses the Shamir secret-shared reconstruction algorithm to recover the private key.

[0040] G6. The asset access node uses the reconstructed private key to decrypt the asset ciphertext and obtain the accessible digital asset.

[0041] Preferably, the G6 specifically includes:

[0042] H1. Use the private key to decrypt the second key ciphertext in the received asset ciphertext to obtain the symmetric key AES-Key;

[0043] H2. Use the symmetric key AES-Key to decrypt the second asset ciphertext to obtain the de-identified version of the digital asset corresponding to the effective security level.

[0044] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0045] Through a multi-level key system and hierarchical asset encryption, the following are achieved: hierarchical access control, with private keys of different security levels decrypting asset content of different granularities; dynamic adjustment, dynamically reducing the effective security level based on access behavior to enhance security; and secure storage, with private key sharding and zero-knowledge location credentials ensuring the security of the keys.

[0046] The security of digital assets is ensured through a multi-level key system and a two-layer encryption mechanism. Asymmetric encryption protects the symmetric key, while symmetric encryption protects the asset data, balancing efficiency and security. The private key sharding storage and location credential generation mechanism prevents private key leakage and unauthorized access. Zero-knowledge proofs are used to verify the legality of sharded storage while protecting privacy.

[0047] The trust factor is calculated based on the access frequency deviation rate, and the effective security level is dynamically generated to achieve flexible access control. When the access behavior is abnormal, the effective security level is reduced to prevent potential security risks. The Shamir secret sharing scheme is used to fragment the private key. Only K fragments need to be collected to recover the private key, which balances security and fault tolerance. Fragments and credentials are stored in a distributed manner to avoid single points of failure and improve system availability. Attached Figure Description

[0048] Figure 1 This is a flowchart illustrating the method for supervising and managing digital assets of large enterprises, as described in an embodiment of the present invention. Detailed Implementation

[0049] To facilitate understanding of the present invention, a more complete description of this application will be given below with reference to the accompanying drawings, which illustrate preferred embodiments of the invention. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to enable a more thorough and complete understanding of the disclosure of the present invention.

[0050] It should be noted that the terms "vertical," "horizontal," "up," "down," "left," "right," and similar expressions used in this article are for illustrative purposes only and do not represent the only possible implementation.

[0051] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to limit the invention; the term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0052] Example 1: Figure 1 This is a flowchart illustrating the method for supervising and managing digital assets of large enterprises, as described in an embodiment of the present invention.

[0053] like Figure 1 As shown, a method for supervising and managing digital assets in large enterprises, applied to an enterprise asset management platform, includes the following steps:

[0054] S101, constructs a multi-level key system for each digital asset, generating a set of key pairs corresponding to each key level. Using a pre-defined hierarchical asset encryption mechanism, ciphertext for each encryption level is generated. Associated with the same digital asset identifier, For security classification, L represents the highest security level preset for the corresponding digital asset. Classified as confidential The public key to the encrypted assets, This is the corresponding private key.

[0055] The multi-level key system is based on the root key pair. (The root key pair can be generated based on the elliptic curve cryptography algorithm), and a hierarchical key pair set can be generated from top to bottom using a one-way key derivation function (e.g., HKDF). .

[0056] It should be noted that high-security keys have backward compatibility, for example, Decryptable A high-level private key can be used to derive a low-level private key, but a low-level private key cannot be used to derive a high-level private key, ensuring one-way access control.

[0057] In some embodiments, a preset hierarchical asset encryption mechanism is used to generate asset ciphertexts of different encryption levels for digital assets, including:

[0058] A1. For each digital asset, set a security level L, for example, security level 1 (public), security level 2 (internal), security level 3 (confidential).

[0059] A2. Develop desensitization rules for digital assets. Based on the sensitivity of information in digital assets, hide sensitive information step by step in descending order of security level, until the lowest security level hides all sensitive information in the digital assets. For example, when the highest security level is 3, security level 1: hide all sensitive information, security level 2: hide some sensitive information, and security level 3: complete content. It should be noted that the specific desensitization rules can be formulated by the digital asset administrator, that is, determine the desensitized asset version with different security levels based on the sensitivity of information in the digital assets.

[0060] A3. Regarding digital asset D, according to the security classification... Generate the desensitized version corresponding to this security level. .

[0061] A4. Utilize the public keys of each security level. The corresponding de-identified version of the encryption Obtain the asset ciphertext corresponding to each security level. .

[0062] Specifically, step A4 includes:

[0063] B1. Based on each security level of the digital asset, generate a random symmetric key AES-Key, and use the AES-Key to encrypt the corresponding de-identified version to obtain the first asset ciphertext. ;

[0064] B2. Utilizing security classification public key Encrypt the symmetric key AES-Key to obtain the second key ciphertext. The first asset ciphertext and the second key ciphertext are combined to form the asset ciphertext of this security level. =( , ).

[0065] A5. Link and store the encrypted data of all assets with the same security level for easy dynamic access control: Stored in a distributed storage system and associated with a unique asset identifier corresponding to the digital asset.

[0066] Therefore, the hierarchical asset encryption mechanism is implemented through two layers of encryption (asymmetric encryption + symmetric encryption), resulting in encrypted asset data. The main body It is encrypted using AES-Key, but with an asymmetric encryption private key. Unable to directly decrypt AES ciphertext Asymmetric encryption (such as RSA and ECC) has high computational complexity and is inefficient for directly encrypting large amounts of data (such as files and JSON). Therefore, it is used to encrypt symmetric keys (rather than the data itself). Thus, a two-layer encryption approach for digital assets improves efficiency, security, and flexibility. Symmetric encryption is fast and suitable for encrypting large amounts of data; asymmetric encryption is used to encrypt the symmetric key, ensuring the secure distribution of the key. The same de-identified asset... It can be decrypted by multiple users using different private keys (as long as they possess the private key corresponding to the security level).

[0067] Alternatively, if you decrypt directly using the private key... Otherwise, the private key would be exposed during the decryption of large amounts of data, increasing the risk of leakage. With two layers of encryption, the private key is only used to decrypt short AES keys, resulting in higher security; only the user holding the corresponding security level private key can decrypt the data. to decrypt Users with low-level encryption cannot decrypt high-level encrypted text because their private key is incapable of decrypting high-level encrypted text. .

[0068] In summary, asymmetric encryption protects the symmetric key, while symmetric encryption protects asset data, balancing security and efficiency; the private key is only used to decrypt the symmetric key, not directly to decrypt asset data; and the key pairs with security levels ensure that accessing nodes can only decrypt ciphertext of assets within their authorized scope.

[0069] S102, divide the private key of each security level into M fragments. And allocated to M storage nodes, with node index as Generate a location credential containing zero-knowledge proofs. The results are then stored on K verification nodes, hiding the physical topology.

[0070] Specifically, to ensure the security and availability of the private key, it is stored in fragments through Shamir secret sharing, and the legitimate storage location of the fragments is verified using zero-knowledge proofs. The fragments are distributed across different storage nodes, and a threshold strategy is used to set a reconstruction threshold K (K≤M). At the same time, K location credentials containing verifiable storage relationships without exposing the physical topology are generated and stored on different verification nodes.

[0071] In some embodiments, the private key for each security level is divided into M fragments, specifically including:

[0072] C1. Use a threshold secret sharing scheme (such as Shamir secret sharing) to share the private key. Divide into M fragments, set a threshold value K (minimum number of fragments to be recovered) and a total number of fragments M (M≥K).

[0073] C2. Select K-1 random numbers { Construct a polynomial to generate M partitions.

[0074] For example, Shamir's secret sharing is based on polynomial interpolation, as follows:

[0075] a. Choose a random polynomial f(x) = + *x + ... + * ,in = (i.e., the private key to be fragmented);

[0076] b. Calculate the M partitions: For i=1 to M, calculate = f(i), then It refers to the i-th slice;

[0077] c. The polynomial can be reconstructed using any K pieces (through Lagrange interpolation) to obtain... However, if there are fewer than K fragments, it is impossible to obtain... .

[0078] C3. All fragments Storing on different storage nodes (storage node index j), each storage node stores only one shard. Furthermore, the content of other segments is unknown.

[0079] In some embodiments, location credentials containing zero-knowledge proofs are generated. And store it to K verification nodes, specifically including:

[0080] D1. Generate a pseudonym for each storage node (using the identity key hash of that storage node as the identifier), denoted as... ,in, This is the identity key for the storage node with index j. Use random numbers to ensure that the pseudonyms cannot be linked.

[0081] D2. For each fragment Generate location credentials The certificate contains the following:

[0082] Pseudo-identifiers, zero-knowledge proofs (ZKP), and / or commitments are used to prove the existence of storage nodes (using pseudonyms). The identifier stores the fragment;

[0083] A specific commitment scheme can be adopted: select a random number. Calculate the commitment of the fragment storage location = Commit( , (A hash function can be used, such as...) =H( || At the same time, a zero-knowledge proof is generated. This proves that the shard is stored on a valid storage node (i.e., the node is registered in the system), but does not expose the node's specific identifier; this is known as zero-knowledge verification. For verification:

[0084] Validity, fragmentation Stored on a legitimate node, i.e. ;

[0085] Consistency, Commitment Correctly bind shards and random numbers .

[0086] Proof process:

[0087] Define constraints (such as "the pseudonym of storage node j") In the list of legal nodes middle");

[0088] Generating proofs using zero-knowledge proofs Not exposed , .

[0089] D3. Select K verification nodes from M storage nodes and store the K location credentials. Stored to K verification nodes. Each verification node stores a set However, it does not need to know the contents of other credentials. The verification node only stores credentials and does not record the mapping relationship between shards and physical nodes, ensuring that attackers cannot infer the location of shards through topology.

[0090] It should be noted that the verification node check ,confirm Corresponding fragments Stored on legitimate nodes. Additionally, for private key recovery, collect any K shards. Given |I|=K, the private key is recovered by reconstructing the polynomial f(x) using Lagrange interpolation. =f(0).

[0091] Therefore, threshold storage of private keys is achieved through polynomial sharding, balancing security and availability; pseudonyms and promises in location credentials hide the shard storage location, preventing attackers from associating physical nodes through shards; zero-knowledge proofs are used to verify the legitimacy of shard storage while protecting privacy; in addition, shards and credentials are stored in a distributed manner to avoid single points of failure.

[0092] In summary, as an example, the specific implementation process of step S102 is as follows:

[0093] For each private key Use a threshold secret sharing scheme (such as Shamir secret share) to share the private key. Divide into M partitions;

[0094] Each fragment It is stored on different storage nodes (storage node index is j), and the location information of each shard is recorded (e.g., the identifier ID_j of the storage node).

[0095] Generate location credentials (for each fragment of the private key, generate location credentials to point to its storage location, but do not expose the location);

[0096] These K location credentials are stored on K different verification nodes. The location credentials do not contain the network address or physical location of the actual storage node, but are only a verifiable proof (proving that the fragment exists and is stored on a legitimate storage node), and can also be used to guide the accessing node on how to obtain the fragment.

[0097] S103: When an access request is received from an asset access node, the identity of the access node is verified and the basic permission security level in the preset smart contract is extracted. Based on the access frequency deviation rate of the asset access node, a trust factor is calculated, a valid security level is generated, and the asset ciphertext corresponding to the valid security level is sent to the asset access node.

[0098] The smart contract includes the identity ID of the asset access node, the digital asset, and the basic access permission level for accessing the digital asset. The smart contract is constructed by the enterprise asset management platform and is pre-constructed based on the identity information registered on the platform by each asset access node.

[0099] Specific implementation process:

[0100] E1. Respond to access requests submitted by asset access nodes, including their identity identifiers (such as digital certificates).

[0101] E2. Verify identity (such as verifying digital signatures) and confirm the legitimacy of the identity (generally, legitimate access identities have been registered or logged in to the platform in advance).

[0102] E3. Query the smart contract to obtain the basic permission level of the asset access node in the platform (such as the permissions corresponding to the role, department, etc. to which the identity belongs). Set the basic permission level to L0 (that is, the level of access it could originally access).

[0103] E4. Calculate the trust factor τ (0≤τ≤1) based on the historical behavior characteristics of the asset access node:

[0104] a. Record the access frequency of the node for different time attributes within the preset historical time period [0, T] (such as the number of daily accesses for a certain time attribute) to form the historical baseline frequency of different time attributes (such as the average number of daily accesses μ and the standard deviation σ); among which, the time attribute can be set according to the work rules of large enterprises. For example, the time attribute can be set to weekdays, holidays, or working hours and non-working hours.

[0105] b. Monitor the access frequency within the current time window (e.g., within the most recent day), denoted as f.

[0106] c. Calculate the deviation rate β = |f - μ| / μ (i.e., the absolute deviation rate relative to the historical average), where f is the current access frequency and μ is the historical baseline frequency with the same time attributes as the current time window.

[0107] d. Convert the deviation rate into a confidence factor using an exponential decay function: ,in, τ is a set sensitivity coefficient (λ>0) used to adjust the sensitivity to frequency deviations. The value of τ is between 0 and 1. The larger the deviation, the smaller τ is.

[0108] E5. Dynamically generate effective security levels, adjust the basic access security levels according to the trust factor τ, and obtain the effective security level l_effective = floor(L0). τ), floor is the floor function.

[0109] If τ=1, then l_effective = L0; if τ<1, the effective security level decreases (i.e., rounded down). Therefore, when access behavior is abnormal (abnormally high frequency), τ will be very small, leading to a decrease in the effective security level. It should be noted that if L0=1 and τ<1, l_effective=0, step E6 should not be executed. Instead, a warning message should be sent to the enterprise management platform, and it needs to be verified whether the asset access node poses a risk (it needs to be verified whether the user of the asset access node is authorized to access the asset within this time attribute). If the verification is successful, its effective security level is determined to be L0.

[0110] E6. Send the asset ciphertext corresponding to its valid security level to the asset access node.

[0111] S104, send location credential guidance information to the asset access node, guide the asset access node to obtain K location credentials, deduce the fragment storage location based on the location credentials, reconstruct the private key after collecting at least K fragments, and use the reconstructed private key to decrypt the received asset ciphertext to achieve hierarchical data access.

[0112] The location credential guidance information includes: a list of verification nodes { }、Location credential index{ }

[0113] Specific implementation process:

[0114] G1. Send location credential guidance information to the asset access node. This information includes: the identifier of the verification node to be accessed (K verification nodes are randomly selected), and the index (or identifier) ​​information of the corresponding location credential (but the index information has been obfuscated and cannot directly locate the fragment storage location).

[0115] G2. Based on the location credential guidance information, the asset access node sends requests to K verification nodes, requesting location credentials. Each verification node returns a location credential after verifying the asset access node's permissions. (Including the commitment and proof of sharding) and access tokens pre-defined between the storage nodes (equivalent to an authentication code, which requires pre-defined access rules between the storage nodes and the authentication nodes).

[0116] The specific method by which the verification node verifies the asset access node's permissions is as follows: In step G1, when sending location credential guidance information to the asset access node, a verification code (randomly generated or generated according to predefined rules) is generated and attached to the location credential guidance information and sent to the asset access node. Simultaneously, the verification code is synchronized to K verification nodes and assigned an expiration value. Upon expiration, the verification code automatically becomes invalid on the verification node, meaning the asset access node loses its permission to request location credentials from the verification node. When a verification node receives a request from the asset access node, it verifies the asset access node's verification code within the expiration value. If they match, the verification passes; otherwise, it fails.

[0117] G3, the asset access node derives the private key fragment storage location based on the received location credential and access token (used for temporary authorized access to fragments):

[0118] Asset access nodes query pseudonyms through a pre-defined decentralized directory service (such as Kademlia DHT). Corresponding actual node address Example: Query → ...

[0119] Location voucher It includes the ability to obtain fragments The pseudonym identifier of the storage node (i.e. The location credential also includes the necessary information for accessing the storage node (such as an access token). However, to conceal the location, this pseudonym needs to be mapped to the actual network address. Therefore, a secure directory service (which can be decentralized, such as DHT) is pre-defined. The asset access node queries the directory service using this pseudonym to obtain the actual network address of the storage node (this step can also be implicitly indicated in the location credential, for example, through an encrypted address, which the asset access node decrypts with a certain key; this invention will not elaborate on or limit this). Thus, the designed location credential should enable the access node to obtain the storage node's access token and address information without revealing which shards it needs. One way to do this is to include the storage node pseudonym in the location credential. With an access token token_j, the asset access node uses a secure lookup service (such as a smart contract on the blockchain or a mapping table) to map the pseudonym to the actual network address.

[0120] After receiving the location credential, the asset access node extracts the following information: the pseudonym of the storage node, the access token, the commitment, and the proof (to verify the legality of the sharded storage, but not directly used during the query phase).

[0121] Asset access nodes query the actual network address corresponding to the pseudonym identifier through a pre-defined decentralized directory service (such as DHT); for example, by entering the pseudonym identifier, the IP address or domain name of the storage node can be obtained. The directory service can be decentralized (such as a smart contract or distributed hash table on the blockchain) to ensure that the query process does not expose the shard storage location.

[0122] G4: The asset access node submits the corresponding access token to the K storage nodes based on the obtained storage location, requesting them to shard the data. (At this point, you need to submit token_j to prove that you have permission to obtain the shard.) After the storage node verifies the validity of the token, it returns the shard. .

[0123] Therefore, location credentials do not directly expose the storage location. The pseudonym and access token in the credentials are implicit guides rather than directly providing the physical address. This design prevents attackers from directly locating the shard storage location by intercepting credentials. The decentralized directory service itself does not store shards, but only provides a mapping from pseudonym to actual address to avoid single point of failure. The query process does not expose the identity of the asset access node or the requested shard information. The token ensures that only asset access nodes holding valid credentials can obtain shards, preventing unauthorized access.

[0124] G5, Asset Access Node collects K shards Then, the private key is recovered using the reconstruction algorithm (Lagrange difference) secretly shared by Shamir.

[0125] It should be noted that the reconstruction algorithm for Shamir's secret sharing can be applied with reference to relevant existing technologies, and this invention will not elaborate on this.

[0126] G6. The asset access node uses the reconstructed private key to decrypt the asset ciphertext and obtain the accessible digital asset.

[0127] Specifically, step G6 includes:

[0128] H1. Use the private key to decrypt the second key ciphertext in the received asset ciphertext to obtain the symmetric key AES-Key;

[0129] H2. Use the symmetric key AES-Key to decrypt the second asset ciphertext to obtain the de-identified version of the digital asset corresponding to the effective security level.

[0130] Therefore, by locating shards through verification nodes and directory services, the risks of centralization are avoided; token verification ensures the legitimacy of shard requests and prevents unauthorized access; private keys can be recovered with only K shards, balancing security and fault tolerance; two layers of decryption, asymmetric encryption protects symmetric keys, and symmetric encryption protects data, taking into account both efficiency and security.

[0131] It should be noted that the enterprise asset management platform is used to create digital assets and generate multi-level keys; the asset access node is used to submit access requests to the enterprise asset management platform; the storage node is used to store private key fragments; and the verification node is used to manage location credentials.

[0132] In summary, private key leakage is prevented through private key fragmentation and location credential generation mechanisms. A trust factor is calculated based on the access frequency deviation rate to achieve dynamic access control, addressing the issue of inflexible access control. Fragmentation and distributed credential storage improve the system's fault tolerance and availability, avoiding single points of failure and poor fault tolerance.

[0133] The pseudonym and access token in the location credentials are implicit guidelines that protect privacy and prevent attacks.

[0134] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages:

[0135] Through a multi-level key system and hierarchical asset encryption, the following are achieved: hierarchical access control, with private keys of different security levels decrypting asset content of different granularities; dynamic adjustment, dynamically reducing the effective security level based on access behavior to enhance security; and secure storage, with private key sharding and zero-knowledge location credentials ensuring the security of the keys.

[0136] The security of digital assets is ensured through a multi-level key system and a two-layer encryption mechanism. Asymmetric encryption protects the symmetric key, while symmetric encryption protects the asset data, balancing efficiency and security. The private key sharding storage and location credential generation mechanism prevents private key leakage and unauthorized access. Zero-knowledge proofs are used to verify the legality of sharded storage while protecting privacy.

[0137] The trust factor is calculated based on the access frequency deviation rate, and the effective security level is dynamically generated to achieve flexible access control. When the access behavior is abnormal, the effective security level is reduced to prevent potential security risks. The Shamir secret sharing scheme is used to fragment the private key. Only K fragments need to be collected to recover the private key, which balances security and fault tolerance. The fragments and credentials are stored in a distributed manner to avoid single points of failure and improve the availability of the system.

[0138] The pseudonym identifier and access token in the location credential are implicit guides that do not directly expose the storage location, preventing attackers from directly locating the shard storage location by intercepting credentials; the decentralized directory service itself does not store shards, but only provides a mapping from pseudonym to actual address, ensuring that the query process does not expose the shard storage location.

[0139] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. For those skilled in the art, the present invention can have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for supervising and managing digital assets in large enterprises, characterized in that, include: S101: Construct a multi-level key system for each digital asset, generate a key pair set corresponding to each security level, and use a preset hierarchical asset encryption mechanism to generate asset ciphertext corresponding to each security level and associate it with the same digital asset identifier. A hierarchical asset encryption mechanism is used to generate ciphertext with different security levels for digital assets, including: A1. Setting a maximum security level L for each digital asset; A2. Formulating desensitization rules for digital assets, and progressively hiding sensitive information in descending order of security level based on the sensitivity of information in the digital asset, until the lowest security level is reached, at which point all sensitive information in the digital asset is hidden; A3. For digital asset D, according to the security level... Generate the desensitized version corresponding to this security level. A4. Utilize the public keys of each security level. The corresponding de-identified version of the encryption Obtain the asset ciphertext corresponding to each security level. For each security level of the digital asset, a random symmetric key AES-Key is generated. The corresponding de-identified version is then encrypted using the AES-Key to obtain the first asset ciphertext. Using classified information public key Encrypt the symmetric key AES-Key to obtain the second key ciphertext. The first asset ciphertext and the second key ciphertext are combined to form the asset ciphertext of this security level. A5. Link and store the encrypted data of all assets with the same security level for the same digital asset. S102, divide the private key of each security level into M fragments and distribute them to M storage nodes to generate location credentials. And store it to K verification nodes; S103, when an access request is received from an asset access node, verify the identity of the asset access node and extract the basic permission security level from the preset smart contract. Calculate the trust factor based on the access frequency deviation rate of the asset access node, generate a valid security level, and send the asset ciphertext corresponding to the valid security level to the asset access node. Record the access frequency of the asset access node under different time attributes within a preset historical time period [0, T] to form a historical baseline frequency for different time attributes; monitor the access frequency of the current time window, denoted as f; calculate the deviation rate. f is the current access frequency, and μ is the historical baseline frequency with the same time attributes as the current time window; the deviation rate is converted into a confidence factor through an exponential decay function. , It is a set sensitivity coefficient used to adjust the sensitivity to frequency deviations; Based on credibility factor Adjust the basic access level to obtain the effective access level. , To round down, L0 is the basic access level; S104, send location credential guidance information to the asset access node, instructing the asset access node to obtain K location credentials, deduce the fragment storage location based on the location credentials, reconstruct the private key, decrypt the received asset ciphertext, and realize hierarchical data access.

2. The method for supervising and managing digital assets of large enterprises as described in claim 1, characterized in that, The multi-level key system is based on the root key pair. A hierarchical key pair set is generated from top to bottom using a one-way key derivation function. , For security classification, , The highest security level preset for the corresponding digital assets. Classified as confidential The public key to the encrypted assets, This is the corresponding private key.

3. The method for supervising and managing digital assets of large enterprises as described in claim 2, characterized in that, In step S102, the private key for each security level is divided into M fragments, specifically including: Use a preset threshold secret sharing scheme to share the private key. Divide the data into M partitions, setting a threshold value K and a total number of partitions M (M≥K); then process each partition... Stored on different storage nodes, with node index as follows: .

4. The method for supervising and managing digital assets of large enterprises as described in claim 3, characterized in that, The generation of location credentials And store it to K verification nodes, specifically including: D1. Generate a pseudonym for each storage node, denoted as... , For index The identity key of the storage node, It is a random number; D2. For each fragment Generate location credentials This includes pseudonym identification and zero-knowledge proofs, proving that a storage node exists to store the shard; D3. Select K verification nodes from M storage nodes and store the K location credentials. Stored to K verification nodes.

5. The method for supervising and managing digital assets of large enterprises as described in claim 1, characterized in that, The smart contract includes the identity ID of the asset access node, the digital asset, and the basic access permission level for accessing the digital asset. The smart contract is constructed by the enterprise asset management platform and is pre-constructed based on the identity information registered on the platform by each asset access node.

6. The method for supervising and managing digital assets of large enterprises as described in claim 4, characterized in that, S103 specifically includes: E1. Respond to the access request submitted by the asset access node, which includes its identity identifier; E2. Verify identity and confirm its legitimacy; E3. Query the smart contract to obtain the basic access level L0 of the asset access node preset on the platform; E4. Calculate the trust factor based on the historical behavior characteristics of the asset access node. ; E5. Dynamically generate valid security levels based on the credibility factor. Adjust the basic access level to obtain the effective access level. , To round down; E6. Send the asset ciphertext corresponding to its valid security level to the asset access node.

7. The method for supervising and managing digital assets of large enterprises as described in claim 4, characterized in that, The location credential guidance information includes: a list of verification nodes. Location voucher index S104 specifically includes: G1. Send location credential guidance information to the asset access node; G2. Based on the location credential guidance information, the asset access node sends requests to K verification nodes respectively, requesting location credentials. After verifying the asset access node's permissions, each verification node returns the location credential and the access token pre-defined with the storage node. G3: The asset access node deduces the private key fragment storage location based on the received location credential and access token; G4. The asset access node submits the corresponding access token to the corresponding K storage nodes based on the obtained storage location, requesting them to shard the data. After the storage node verifies the token's validity, it returns the shard. ; G5: After the asset access node collects K shards, it uses the Shamir secret-shared reconstruction algorithm to recover the private key. G6. The asset access node uses the reconstructed private key to decrypt the asset ciphertext and obtain the accessible digital asset.

8. The method for supervising and managing digital assets of large enterprises as described in claim 7, characterized in that, The G6 specifically includes: H1. Use the private key to decrypt the second key ciphertext in the received asset ciphertext to obtain the symmetric key AES-Key; H2. Use the symmetric key AES-Key to decrypt the first asset ciphertext to obtain the desensitized version of the digital asset corresponding to the effective security level.

Citation Information

Patent Citations

  • Digital asset management method and device based on block chain, storage medium and equipment

    CN114666064A

  • Hierarchical encryption privacy protection method based on block chain

    CN116842573A