A digital asset security storage management method and system

By splitting the private key into multiple fragments and storing them heterogeneously, and combining biometric verification and quantum key distribution technologies, the problem of low security in private key storage schemes is solved, and high-security and trusted transmission of private key management is achieved.

CN121077667BInactive Publication Date: 2026-01-23天创信用服务有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511604109.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-05
Publication Date
2026-01-23
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing private key storage solutions suffer from low security issues, including single points of failure due to centralized storage of private keys, ease of forgery of static biometric authentication, complex management of cold and hot wallets, and a lack of quantum computing defense capabilities.

Method used

The private key is split into multiple fragments and stored in different physical locations using the Shamir secret sharing algorithm. It employs HSM modules, blockchain smart contracts, and durable metal-based media, combined with quantum key distribution and lattice cryptography, to perform fragment verification, biometric verification, and environmental trustworthiness verification. Dynamic authentication tokens are generated and securely transmitted and reconstructed through a trusted execution environment and physical switch gateways. Digital signature files are generated and circuit breaker management is implemented.

Benefits of technology

It achieves secure storage of private keys in fragments, preventing single points of failure and tampering, ensuring the authenticity of the operator's identity, preventing side-channel attacks, providing trusted transmission and compliance auditing, and improving the defense capabilities of quantum computing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121077667B_ABST
    Figure CN121077667B_ABST
Patent Text Reader

Abstract

The application relates to a digital asset secure storage management method and system, which comprises the following steps: receiving a private key calling request of a user, searching for a target private key shard coordinate set and shard verification metadata according to the private key calling request, initiating biological information verification and environment credibility verification, performing chaotic refreshing when the verifications are passed, obtaining a dynamic authentication token, activating an HSM channel to access the target private key shard, and safely transferring the target private key shard from a storage location to a trusted execution environment for integrity and legality verification. When the verification is passed, a white box cryptographic engine is called to reconstruct the target private key shard into a target private key, a digital signature file is generated according to the reconstructed target private key, and the digital signature file is unidirectionally output through an electromagnetic shielding optical fiber. The target private key shard of this call is fused, a shard fuse list is recorded in the digital signature file, and the index of the private key shard is updated; an MPC engine is called to drive the digital asset to flow unidirectionally through a physical switch gateway.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of secure digital asset storage technology, and in particular to a secure digital asset storage management method and system. Background Technology

[0002] With the rapid development of modern society, enterprises have increasingly higher demands for information technology, leading to more complex business scenarios. In various production and operation processes, the supporting data has become a crucial digital asset. Digital assets refer to any posable value existing in digital form. Digital assets can include digital copyrighted materials (such as music, movies, and books), corporate financial data, tax data, employee data, operational data, and production and operation data.

[0003] The digital economy is profoundly changing human production and lifestyles, becoming a new driving force for economic growth. Digital assets (such as cryptocurrencies and NFTs) rely on cryptographic credentials for control, and their core risk lies in the security of private key storage. Traditional solutions have several shortcomings:

[0004] 1. Centralized storage of private keys leads to single points of failure, resulting in frequent hardware cracking and network attacks (such as the Mt. Gox incident).

[0005] 2. Static biometric authentication is vulnerable to deepfakes, and 2FA (two-factor authentication) OTP (One-Time Password) is susceptible to man-in-the-middle attacks.

[0006] 3. The separation of cold and hot wallet management leads to a contradiction between operational complexity and security. The asset transfer process is exposed to supply chain attacks. More seriously, there is a lack of quantum computing defense capabilities, and existing cryptographic algorithms face a disruptive threat from quantum computers.

[0007] The aforementioned defects collectively result in low security for existing private key storage schemes. Summary of the Invention

[0008] To at least partially overcome the low security issues of private key storage schemes in related technologies, this application provides a method and system for secure storage management of digital assets.

[0009] The proposed solution is as follows:

[0010] According to a first aspect of the embodiments of this application, a method for secure storage and management of digital assets is provided, comprising:

[0011] Receive a user's private key access request, and search for the fragment coordinate set and fragment verification metadata of the target private key based on the private key access request; the fragment coordinate set and fragment verification metadata of the target private key are obtained by splitting the target private key and storing it heterogeneously;

[0012] Biometric verification and environmental trustworthiness verification are initiated based on the fragmented verification metadata of the target private key;

[0013] When both biometric verification and environmental trustworthiness verification pass, a chaotic refresh is performed based on the fragmented coordinate set of the target private key to obtain a dynamic authentication token and activate the HSM (Hardware Security Module) channel.

[0014] Based on dynamic authentication tokens, the target private key fragment is accessed through the HSM channel and securely transmitted from the storage location to the trusted execution environment for integrity and legality verification.

[0015] When the integrity and legality verification passes, the white-box cryptography engine is invoked to prevent side-channel attacks by fragmenting and reconstructing the target private key into the target private key.

[0016] A digital signature file is generated based on the reconstructed target private key, and the digital signature file is output unidirectionally via an electromagnetically shielded optical fiber.

[0017] The target private key fragment of this call is circuit-broken, a fragment circuit-broken list is generated and recorded in the digital signature file, and the index of the private key fragment is updated.

[0018] The digital signature file is parsed and verified. After successful parsing and verification, the MPC (Multi-Party Computation) engine is invoked to drive the digital asset to flow unidirectionally through the physical switch gateway.

[0019] The physical switch gateway verifies the fragmented circuit breaker list in the digital signature file; after the fragmented circuit breaker list is verified, it outputs a real-time asset distribution map and transfer audit log.

[0020] Preferably, the method further includes:

[0021] Receive the user's private key storage request and the target private key to be stored;

[0022] The target stored private key is split into multiple private key fragments using the Shamir secret sharing algorithm;

[0023] The private key fragments are grouped, and the grouped private key fragments are stored in different physical locations using different storage methods.

[0024] The stored private key fragments are transmitted through the QKD (Quantum Key Distribution) channel and converted into fragment metadata;

[0025] A Merkle tree data structure is generated based on the fragmented metadata, and the fragmented coordinate set and fragmented verification metadata of the target stored private key are output based on the Merkle tree data structure.

[0026] The fragment coordinate set is used to characterize the physical location of the private key fragment;

[0027] The fragment verification metadata is used to verify whether the private key fragment belongs to the Merkle tree data structure.

[0028] Preferably, the grouped private key fragments are stored in different physical locations using different storage methods, including:

[0029] The first set of private keys is fragmented and stored in a geographically isolated HSM module; the HSM module is equipped with a physically tamper-proof shell and a self-destruct circuit.

[0030] The second set of private keys is fragmented, encrypted, and then stored in a blockchain smart contract; the blockchain smart contract is equipped with a multi-signature verification mechanism.

[0031] The third set of private key fragments were converted into QR code format and burned onto a durable metal-based physical storage medium, then stored in a vault.

[0032] Preferably, the second set of private key shards adopts a quantum-resistant cross-chain contract structure, and is deployed to a zero-knowledge proof public chain after being encrypted twice by a quantum digital signature algorithm;

[0033] The conditions for calling the second set of private key fragments are: at least 5 geographically dispersed HSM nodes collaboratively decrypt within a preset time.

[0034] The durable metal-based physical storage medium has a photochromic self-destruct coating, which is bound to the Merkle tree data structure; the photochromic self-destruct coating automatically blurs the QR code of the third private key fragment conversion under abnormal lighting.

[0035] Preferably, the method further includes:

[0036] The real-time asset distribution map and transfer audit logs are input into the LSTM (Long Short-Term Memory) model, and the LSTM model outputs the asset flow prediction value.

[0037] The deviation of asset current is obtained by comparing the forecast value of asset current with the actual value of asset current;

[0038] Determine whether the private key sharding node is abnormal based on the asset flow deviation.

[0039] If an anomaly is detected, the anomaly level is determined, and different stages of threat response are triggered based on the anomaly level.

[0040] Preferably, the threat response includes:

[0041] Phase 1 Threat Response: Isolate the abnormal private key sharding node and sever its physical connection; invoke redundant private key sharding nodes to reconstruct the key within a trusted execution environment; destroy the sharding data of the abnormal private key sharding node;

[0042] The second phase of threat response involves sending encrypted event log slices to multiple oracle networks for verification in a trusted execution environment; after successful verification, the DAO (Decentralized Autonomous Organization) threshold signature is used for arbitration, and the arbitration result is recorded on the blockchain in real time to trigger a blockchain smart contract.

[0043] Phase 3 Threat Response: Migrate the digital assets to a new storage medium based on the arbitration result; during the migration process, sign the digital assets using NTRU (N-th degree Truncated Polynomial Ring Units) lattice cryptography and write the NTRU lattice cryptographic signature to a 5D long-term archive storage medium; destroy the old storage medium of the digital assets after the migration.

[0044] Preferably, biometric verification is initiated based on the fragmented verification metadata of the target private key, including:

[0045] Initiate biometric verification for the user and bind the fragmented verification metadata of the target private key to the current biometric verification process;

[0046] User behavior data is collected in real time at a sampling rate of 1kHz; the behavior data includes: touch pressure matrix and device six-axis posture data;

[0047] Input the user's real-time behavioral feature data into the user's biological behavior model that has been trained locally beforehand, and output the user behavior judgment result;

[0048] If the judgment result is that the user's current behavior characteristics do not match the historical behavior characteristics, then the VR (Virtual Reality) challenge protocol is triggered;

[0049] If the judgment result is that the user's current behavior characteristics match the historical behavior characteristics, then the user's behavior entropy is calculated based on the user's real-time behavior characteristic data.

[0050] If a user's behavioral entropy is abnormal, the VR challenge protocol will be triggered;

[0051] If the user's behavioral entropy is normal, the biometric verification passes.

[0052] The VR challenge protocol includes:

[0053] Generate a corresponding 3D cryptographic puzzle based on the fragmented coordinate set of the target private key, and generate a time-limited spatial matching task based on the 3D cryptographic puzzle;

[0054] The time-limited spatial matching task is sent to the user terminal, and the multispectral camera of the user terminal is invoked to verify the user's physical operation.

[0055] If the user completes the time-limited spatial matching task and the entity operation verification passes, then the biometric information verification will be re-initiated for the user.

[0056] If the user fails to complete the time-limited spatial matching task, or if the entity operation verification fails, a private key sharding circuit breaker instruction is written to the blockchain smart contract.

[0057] Preferably, the method further includes:

[0058] In the trusted execution environment, a photonic computing core is integrated, and when the integrity and legitimacy verification is passed, the target private key is fragmented and encoded into polarized photons using a quantum dot laser;

[0059] The white-box cryptographic engine is invoked, and the target private key fragments are signed using NTRU cipher.

[0060] Some operations in the NTRU lattice cryptographic signature algorithm are mapped to Mach-Zehnder interferometry calculations, and the Mach-Zehnder interferometry calculations are performed on a lithium niobate photonic chip.

[0061] The target private key fragment in polarized photonic form after signing is converted into electronic form using a superconducting nanowire detector, and the target private key fragment in polarized photonic form is destroyed.

[0062] The superconducting nanowire detector has a shell covered with a μ metal layer and is filled with argon gas.

[0063] The photonic computing core and the QKD channel share a quantum random source to ensure that the signature parameters are random and unique each time.

[0064] Preferably, parsing and verifying the digital signature file includes:

[0065] The polarization angle information of the signature photons carried in the digital signature file is captured using a superconducting nanowire single-photon detector.

[0066] The expected quantum fingerprint is obtained from the updated index of the target private key fragment in this call, and the polarization angle information of the signature photons is compared with the expected quantum fingerprint.

[0067] Query the status record of the target private key shard in the blockchain smart contract to determine whether the target private key shard has been circuit-broken.

[0068] If the deviation between the polarization angle information of the signed photon and the expected quantum fingerprint does not exceed 0.1 arcseconds, and the target private key shard in this call is recorded as having a circuit breaker in the blockchain smart contract, then the verification is deemed successful, the MPC engine initialization instruction is activated, the encrypted digital asset transfer parameters are generated, and the MPC engine is called to drive the digital asset to flow unidirectionally through the physical switch gateway; otherwise, the verification is deemed unsuccessful.

[0069] The physical switch gateway includes a circuit switching module controlled by a mechanical relay;

[0070] The current flow direction of the circuit switching module is from the cold end to the hot end;

[0071] The physical switch gateway is equipped with entangled photon pairs at its input / output terminals. When the qubit error rate of the entangled photon pairs at the input / output terminals of the physical switch gateway exceeds a preset qubit error rate threshold, the circuit is automatically cut off.

[0072] The physical switch gateway transmits digital assets through anti-interference optical fiber. For each transfer of digital assets, environmental parameters are generated, sealed, and written into the transfer audit log.

[0073] According to a second aspect of the embodiments of this application, a digital asset secure storage management system is provided, comprising:

[0074] Processor and memory;

[0075] The processor and memory are connected via a communication bus:

[0076] The processor is used to call and execute the program stored in the memory;

[0077] The memory is used to store a program, which is at least used to execute a digital asset secure storage management method as described in any of the above.

[0078] The technical solution provided in this application may include the following beneficial effects:

[0079] This technical solution pre-split and heterogeneously stores the user-provided private key to avoid single-point-of-failure risks caused by centralized storage. The fragment coordinate set is used to precisely locate the fragment position; fragment verification metadata is used for subsequent integrity verification. Biometric verification is initiated based on the fragment verification metadata, forming a biometric protection layer to ensure the operator is the user. Simultaneously, environmental trust verification is performed to achieve physical non-intrusion. After both verifications pass, a chaotic refresh is performed based on the fragment coordinate set of the target private key to obtain a dynamic authentication token (generated by dynamic perturbation parameters), resulting in a one-time authentication token. This token temporarily activates the HSM channel, thus making each call parameter unpredictable and preventing replay attacks. The target private key fragment is accessed through the HSM channel and securely transmitted to the trusted execution environment. Integrity and legitimacy verification is performed in the trusted execution environment to prevent tampering or injection of forged fragments during transmission. After successful verification, a white-box cryptographic engine is invoked in the trusted execution environment to reconstruct the target private key fragment into the target private key. The private key reconstruction process does not leave the protected environment, making side-channel attacks difficult to succeed. A digital signature file is generated using the reconstructed private key and output via an electromagnetically shielded fiber optic unidirectional link, ensuring data only flows out and preventing external data or attack code injection through the channel. The private key fragments used in this operation are immediately circuit-broken, and a fragment circuit-broken list is generated and recorded in the signature file, reducing the risk of fragments being reused or stolen later. The fragment index is updated synchronously to ensure that the next call will not use the circuit-broken fragments. After the digital signature file is parsed and verified, the MPC engine drives the digital assets to flow unidirectionally through a physical switch gateway, which isolates the risk of external network intrusion. The gateway re-verifies the fragment circuit-broken list in the signature file to ensure a closed-loop and controllable execution chain. Finally, a real-time asset distribution map and transfer audit logs are output, providing evidence for compliance and post-event auditing.

[0080] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0081] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0082] Figure 1 This is a flowchart illustrating a digital asset secure storage management method according to an embodiment of this application;

[0083] Figure 2 This is a schematic diagram of the structure of a digital asset secure storage management system provided in one embodiment of this application.

[0084] Reference numerals: Processor-21; Memory-22. Detailed Implementation

[0085] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0086] Example 1

[0087] Figure 1 This is a flowchart illustrating a digital asset secure storage management method according to an embodiment of this application, with reference to... Figure 1 A method for secure storage and management of digital assets, comprising:

[0088] S11: Receive the user's private key call request, and find the fragment coordinate set and fragment verification metadata of the target private key according to the private key call request; the fragment coordinate set and fragment verification metadata of the target private key are obtained by splitting the target private key and storing it heterogeneously;

[0089] In this technical solution, the user-provided private key is pre-splitted and stored heterogeneously to avoid single points of failure caused by centralized storage of private keys. The fragment coordinate set is used to accurately locate the fragment position; the fragment verification metadata is used for subsequent integrity verification.

[0090] S12: Initiate biometric verification and environmental trustworthiness verification based on the fragmented verification metadata of the target private key;

[0091] Biometric verification is initiated based on fragmented verification metadata to form a biometric protection layer, ensuring that the operator is the user.

[0092] Simultaneously, environmental trustworthiness verification is performed to achieve physical non-intrusion.

[0093] S13: When both biometric verification and environmental trustworthiness verification pass, perform chaotic refresh based on the fragmented coordinate set of the target private key to obtain a dynamic authentication token and activate the HSM channel.

[0094] After both verifications pass, a chaotic refresh is performed based on the fragment coordinate set of the target private key to obtain a dynamic authentication token (generated by dynamic perturbation parameters). This results in a one-time authentication token, which is used to temporarily activate the HSM. This ensures that the parameters for each call are unpredictable, thus preventing replay attacks.

[0095] S14: Based on the dynamic authentication token, access the target private key fragment through the HSM channel, and securely transfer the target private key fragment from the storage location to the trusted execution environment for integrity and legality verification;

[0096] Access the target private key fragment via the HSM channel and securely transmit it to the Trusted Execution Environment (TEX). In the TEX, integrity and legitimacy verification is performed to prevent tampering or injection of forged fragments during transmission.

[0097] S15: When the integrity and legality verification passes, call the white-box cryptography engine to prevent side-channel attacks and reconstruct the target private key fragments into the target private key;

[0098] After verification, the white-box cryptographic engine is invoked in the trusted execution environment to reconstruct the target private key into a fragmented private key. The private key reconstruction process does not leave the protected environment, making side-channel attacks difficult to succeed.

[0099] S16: Generate a digital signature file based on the reconstructed target private key, and output the digital signature file unidirectionally via electromagnetically shielded optical fiber;

[0100] A digital signature file is generated using the reconstructed private key and output through a one-way electromagnetically shielded fiber optic link to ensure that data only goes out and never comes in, preventing external data or attack code from being injected into the channel.

[0101] S17: The target private key fragment of this call is circuit-broken, a fragment circuit-broken list is generated and recorded in the digital signature file, and the index of the private key fragment is updated;

[0102] The private key fragment used in this case was immediately circuit-broken, and a fragment circuit-broken list was generated and recorded in the signature file to reduce the risk of fragments being reused or stolen afterward.

[0103] Synchronously update the shard index to ensure that the circuit-broken shard will not be used again in the next call.

[0104] S18: Parse and verify the digital signature file. After successful parsing and verification, call the MPC engine to drive the digital assets to flow unidirectionally through the physical switch gateway.

[0105] After the digital signature file is parsed and verified, the MPC engine is invoked to drive the digital assets to flow unidirectionally through the physical switch gateway. The physical unidirectional gateway isolates the risk of external network intrusion.

[0106] S19: Verify the fragmented circuit breaker list in the digital signature file through the physical switch gateway; after the fragmented circuit breaker list is verified, output the real-time asset distribution map and transfer audit log.

[0107] The gateway re-verifies the fragmented circuit breaker list in the signature file to ensure the closed-loop controllability of the execution chain. Finally, it outputs a real-time asset distribution map and transfer audit logs, providing evidence for compliance and post-audit.

[0108] Example 2

[0109] It should be noted that the method also includes:

[0110] Receive the user's private key storage request and the target private key to be stored;

[0111] The target stored private key is split into multiple private key fragments using the Shamir secret sharing algorithm;

[0112] The private key is divided into fragments, and the fragments are stored in different physical locations using different storage methods.

[0113] The stored private key fragments are transmitted via the QKD channel and converted into fragment metadata.

[0114] Generate a Merkle tree data structure based on the fragmented metadata, and output the fragmented coordinate set and fragmented verification metadata of the target stored private key based on the Merkle tree data structure.

[0115] The fragment coordinate set is used to characterize the physical location of the private key fragment;

[0116] The fragment verification metadata is used to verify whether the private key fragment belongs to the Merkle tree data structure.

[0117] This embodiment describes the initialization and sharding storage process of the private key, providing a secure basic data structure and indexing system for subsequent operations such as calling, verification, and reconstruction.

[0118] The system receives a private key storage request from the user, along with the target private key that needs to be securely stored. It then uses the Shamir (Shamir Secret Sharing) algorithm to split the target private key into multiple fragments. The Shamir secret sharing algorithm works by encoding the private key as a constant term of a polynomial, using multiple sets of (x, y) points obtained with different x values ​​as fragments, and reaching a preset threshold number k is required to reconstruct the private key.

[0119] The private key is fragmented and grouped according to a strategy (e.g., security level, storage medium type, physical location), and the grouped private key fragments are stored in different physical locations using different storage methods. Specifically:

[0120] The first set of private keys is fragmented and stored in a geographically isolated HSM module; the HSM module is equipped with a physically tamper-proof shell and a self-destruct circuit;

[0121] Storing the first set of private keys in a geographically isolated HSM module can defend against physical intrusion, hardware probing, and reverse engineering. Even if an attacker obtains the device itself, they will not be able to recover the fragments.

[0122] The second set of private keys is fragmented, encrypted, and then stored in the blockchain smart contract; the blockchain smart contract is set up with a multi-signature verification mechanism.

[0123] Blockchain storage offers decentralized and tamper-proof features. Smart contracts incorporate multi-signature verification mechanisms to prevent abuse of permissions by a single node or individual. Encrypting and storing the second set of private keys in blockchain smart contracts ensures the integrity and access control of these shards within network storage, protecting against network attacks and single-point-of-failure attacks.

[0124] The third set of private key fragments were converted into QR code format and burned onto a durable metal-based physical storage medium, then stored in a vault.

[0125] The third set of private key fragments is converted into QR code format for easy cross-system reading and verification. After being burned onto a durable metal-based physical storage medium such as titanium alloy, it is stored in a vault for long-term offline storage, resisting damage from extreme environments such as fire, corrosion, and high temperature, and preventing online attacks from obtaining the fragment.

[0126] In summary, this embodiment improves the physical and logical security of private key shard storage through heterogeneous architecture and multi-location isolation. In this way, even if one storage type is compromised, it is impossible to obtain enough shards to reconstruct the private key.

[0127] Preferably, the second set of private key shards adopts a quantum-resistant cross-chain contract structure, and is deployed to a zero-knowledge proof public chain after being encrypted twice by a quantum digital signature algorithm;

[0128] The conditions for calling the second set of private key fragments are: at least 5 geographically dispersed HSM nodes must work together to decrypt within a preset time.

[0129] The durable metal-based physical storage medium has a photochromic self-destruct coating, which is bound to a Merkle tree data structure; the photochromic self-destruct coating automatically blurs the QR code of the third private key fragment conversion under abnormal lighting.

[0130] The stored private key is fragmented and transmitted via a QKD channel. During transmission, it is converted into fragment metadata (such as fragment hash, index identifier, and location tag). Transmission via a QKD channel ensures that the transmission process is detectable by eavesdropping and that the key cannot be copied. The transmission process is quantum-secured to prevent fragments from being stolen or tampered with during transmission.

[0131] Merkle tree data structures are generated using shard metadata. The root uniquely identifies the integrity of the entire shard set, the leaf nodes store the hash values ​​of each shard, and the intermediate nodes are combined hashes of the child node hashes.

[0132] Merkle tree data paths can be used to quickly verify whether a shard belongs to the current version of the shard set. Any shard tampering will cause the tree root to change.

[0133] Example 3

[0134] It should be noted that the method also includes:

[0135] Input the real-time asset distribution map and transfer audit logs into the LSTM model, and output the asset flow prediction value through the LSTM model;

[0136] The deviation of asset current is obtained by comparing the forecast value of asset current with the actual value of asset current;

[0137] Determine whether the private key sharding node is abnormal based on the asset flow deviation.

[0138] If an anomaly is detected, the anomaly level is determined, and different stages of threat response are triggered based on the anomaly level.

[0139] By inputting real-time asset distribution maps and transfer audit logs as time-series data into the LSTM model, the LSTM can capture short-term fluctuations and long-term trends in asset flows and generate asset flow forecasts.

[0140] The system determines whether the private key sharding node is abnormal (e.g., delayed response of sharding node, abnormal data transmission, unauthorized access, etc.) based on a preset deviation threshold.

[0141] Pre-classify the level of abnormality (e.g., low risk, medium risk, high risk, fatal).

[0142] This triggers different stages of threat response based on different levels of anomaly.

[0143] Specifically, threat response includes:

[0144] Phase 1 Threat Response: Isolate the abnormal private key sharding node and sever its physical connection; invoke redundant private key sharding nodes to reconstruct the key within a trusted execution environment; destroy the sharding data of the abnormal private key sharding node;

[0145] The second phase of threat response involves sending encrypted event log slices to multiple oracle networks for verification in a trusted execution environment; after successful verification, arbitration is conducted using DAO threshold signatures, and the arbitration result is recorded on the blockchain in real time to trigger a blockchain smart contract.

[0146] Phase 3 Threat Response: Migrate the digital assets to new storage media based on the arbitration result; sign the migration using an NTRU cipher during the migration process and write the NTRU cipher signature to a 5D long-term archive storage medium; destroy the old storage media of the digital assets after the migration.

[0147] In the digital asset secure storage management method of this embodiment, in response to detected abnormal events, the system can automatically trigger a multi-stage threat response based on the anomaly level to ensure the integrity and availability of digital assets, specifically including the following stages:

[0148] Phase One Threat Response

[0149] When a high-risk or fatal anomaly is detected in a private key sharding node, the system performs the following actions:

[0150] Isolate the abnormal private key shard node from the network and bus system, cutting off its communication connection with external systems.

[0151] Completely disconnect the electrical and data paths through hardware-level physical fuses to prevent further access to or leakage of data.

[0152] The corresponding shard is invoked from the pre-deployed redundant private key shard nodes, and the integrity of the private key is verified and reconstructed through the Trusted Execution Environment (TEE).

[0153] Perform physical destruction or data erasure on the storage media of abnormal private key shard nodes to ensure that they are unrecoverable.

[0154] Phase Two Threat Response

[0155] After the first phase is completed, the system will arbitrate and process the abnormal event information on the blockchain:

[0156] The encrypted logs containing anomalous events are sliced ​​and distributed to multiple oracle network nodes.

[0157] Verify the authenticity and completeness of event logs in the trusted execution environment of each oracle node.

[0158] The verification results are arbitrated using the threshold signature mechanism of a DAO (Decentralized Autonomous Organization), and the arbitration results are written to the blockchain in real time.

[0159] The smart contract executes corresponding on-chain asset protection or migration instructions based on the arbitration result.

[0160] Phase Three Threat Response

[0161] If the arbitration ruling requires asset migration, the system enters the final asset migration and old media destruction phase:

[0162] Migrate digital assets to new storage media (which could be a newly deployed HSM module, a durable metal-based medium, or a newly generated blockchain address).

[0163] During the migration process, the NTRU (Nth-degree Truncated Polynomial Ring Units) signature algorithm based on lattice cryptography is used to perform quantum-safe signatures on the migration data.

[0164] Write the NTRU signature content to 5D long-term archive storage media for future evidence preservation and auditing.

[0165] After the migration is complete, the old storage media should be physically destroyed or the data erased to prevent data residue from causing secondary leakage risks.

[0166] The three-stage response forms a closed-loop protection system covering the entire lifecycle, consisting of detection, isolation, arbitration, migration, and destruction, ensuring that abnormal threats are completely eliminated.

[0167] Example 4

[0168] It should be noted that initiating biometric verification based on the fragmented verification metadata of the target private key includes:

[0169] Initiate biometric verification for the user and bind the fragmented verification metadata of the target private key to the current biometric verification process;

[0170] User behavior data is collected in real time at a sampling rate of 1kHz; the behavior data includes: touch pressure matrix and device six-axis posture data;

[0171] Input the user's real-time behavioral feature data into the user's biological behavior model that has been trained locally beforehand, and output the user behavior judgment result;

[0172] If the judgment result is that the user's current behavior characteristics do not match the historical behavior characteristics, then the VR challenge protocol is triggered;

[0173] If the judgment result is that the user's current behavior characteristics match the historical behavior characteristics, then the user's behavior entropy is calculated based on the user's real-time behavior characteristic data.

[0174] If a user's behavioral entropy is abnormal, the VR challenge protocol will be triggered;

[0175] If the user's behavioral entropy is normal, the biometric verification passes.

[0176] The VR Challenge Agreement includes:

[0177] Generate a corresponding 3D cryptographic puzzle based on the fragment coordinate set of the target private key, and generate a time-limited spatial matching task based on the 3D cryptographic puzzle;

[0178] The time-limited spatial matching task is sent to the user terminal, and the multispectral camera of the user terminal is called to verify the user's physical operation.

[0179] If the user completes the timed spatial matching task and the physical operation verification is successful, then the biometric information verification will be re-initiated for the user.

[0180] If the user fails to complete the timed space matching task or the entity operation verification fails, a private key sharding circuit breaker instruction will be written to the blockchain smart contract.

[0181] In this embodiment, the system performs biometric verification based on the fragmented verification metadata of the target private key to ensure the authenticity and tamper-proof nature of the identity during the private key invocation process. Specifically, this includes the following steps:

[0182] The system initiates a biometric verification request to the user and binds the fragmented verification metadata of the target private key to the current biometric verification process, ensuring that the verification process corresponds one-to-one with the specific private key fragment call request, and preventing the verification result from being replayed and reused.

[0183] The system collects user behavior feature data in real time at a sampling rate of 1kHz. The behavior feature data includes: touch pressure matrix: recording the pressure distribution and change curve of the user during touch operation; device six-axis attitude data: including three-axis acceleration and three-axis angular velocity, used to reflect the dynamic characteristics of the user's operation of the device.

[0184] The collected real-time behavioral feature data is input into a locally pre-trained user biometric behavior model, which outputs user behavior judgment results:

[0185] If the judgment result is that the current behavioral characteristics do not match the historical behavioral characteristics, the VR challenge protocol will be triggered directly; if the judgment result is that they match, the behavioral entropy calculation stage will begin.

[0186] The system calculates the user's behavioral entropy based on real-time behavioral feature data to quantify the complexity and stability of behavior: if the behavioral entropy exceeds the preset threshold range (an anomaly occurs), the VR challenge protocol is triggered; if the behavioral entropy is normal, the biometric verification is passed and the system proceeds to the next stage.

[0187] When the VR Challenge Protocol is triggered, the system performs the following steps:

[0188] Generate the corresponding 3D cryptographic puzzle based on the fragment coordinate set of the target private key;

[0189] A timed spatial matching task is generated based on 3D cipher puzzles;

[0190] The timed task is sent to the user terminal, and the multispectral camera of the user terminal is used to perform physical operation liveness verification.

[0191] If the user completes spatial matching and entity operation verification within the specified time, the biometric verification will be re-initiated.

[0192] If the task is not completed or the verification fails, a private key sharding circuit breaker instruction is written to the blockchain smart contract to prevent subsequent calls.

[0193] This embodiment employs a two-layer authentication mechanism, combining biological behavior model matching with behavior entropy detection, which can detect forged or abnormal behavior in a short time and effectively defend against deepfake and remote control attacks.

[0194] The VR Challenge Protocol can dynamically generate time-limited spatial matching tasks related to the current private key fragment, preventing tasks from being predicted in advance and exploited by attack scripts.

[0195] The spatial matching task has a time limit of 5 seconds.

[0196] The fragmented verification metadata is bound to the verification process to ensure the uniqueness of the verification process; combined with multispectral liveness verification, it prevents man-in-the-middle substitution operations.

[0197] Introducing behavioral entropy as a quantitative indicator can not only detect obvious behavioral anomalies, but also capture subtle deviations in operational habits, providing a pre-trigger signal for threat response.

[0198] Example 5

[0199] It should be noted that the method also includes:

[0200] In a trusted execution environment, a photonic computing core is integrated, and when the integrity and legitimacy verification passes, the target private key is fragmented and encoded into polarized photons using a quantum dot laser.

[0201] The white-box cryptographic engine is invoked, and the target private key fragments are signed using NTRU cipher.

[0202] Map some operations in the NTRU lattice cryptographic signature algorithm to Mach-Zehnder interferometry calculations, and perform Mach-Zehnder interferometry calculations on a lithium niobate photonic chip;

[0203] The target private key fragment in polarized photonic form after signing is converted into electronic form using a superconducting nanowire detector, and the target private key fragment in polarized photonic form is destroyed.

[0204] The superconducting nanowire detector has a shell covered with a μ metal layer and is filled with argon gas.

[0205] The photonic computing kernel and the QKD channel share a quantum random source to ensure that the signature parameters are random and unique each time.

[0206] In this embodiment, to further enhance the security and quantum attack defense capabilities of the target private key fragmentation signing process, the system integrates a photonic computing core in a trusted execution environment and combines lattice cryptography with photonic operations to achieve high-security signature processing for private key fragmentation. Specifically, this includes the following steps:

[0207] After the target private key fragment passes integrity and legality verification, a quantum dot laser is invoked to encode the target private key fragment into polarized photons to realize the quantum state carrying of information and improve the anti-eavesdropping ability of data transmission.

[0208] The white-box cryptographic engine is invoked, and the target private key fragments are signed using NTRU lattice cryptography. The white-box cryptographic engine is designed to effectively resist side-channel attacks; NTRU lattice cryptography has high resistance to quantum computing and can defend against quantum attack methods such as Shor's algorithm.

[0209] Some operations in the NTRU lattice cryptographic signature algorithm are mapped to Mach-Zehnder interferometry calculations and executed on a lithium niobate photonic integrated chip to achieve high-speed parallel computing by utilizing the optical interference effect, thereby accelerating the signature process and reducing energy consumption.

[0210] The signed polarized photons are converted into electronic signals by a superconducting nanowire single-photon detector, while the private key fragments in the form of polarized photons are physically destroyed to ensure that the quantum state data cannot be measured and used again.

[0211] Preferably, the detector housing is covered with a μ metal layer to shield against external magnetic field interference; the interior is filled with argon gas to maintain the device's low-temperature stability and reduce oxidation reactions.

[0212] Preferably, the photonic computing core and the QKD channel share the same quantum random source to ensure the randomness and uniqueness of the parameters for each signature, thereby preventing signature replay and prediction attacks.

[0213] Example 6

[0214] It should be noted that parsing and verifying digital signature files includes:

[0215] The polarization angle information of the signature photons carried in the digital signature file is captured using a superconducting nanowire single-photon detector.

[0216] The expected quantum fingerprint is obtained from the updated index of the target private key fragment in this call, and the polarization angle information of the signature photons is compared with the expected quantum fingerprint.

[0217] Query the status record of the target private key shard in the blockchain smart contract to determine whether the target private key shard has been circuit-broken.

[0218] If the deviation between the polarization angle information of the signed photon and the expected quantum fingerprint does not exceed 0.1 arcseconds, and the target private key shard in this call is recorded as having a circuit breaker in the blockchain smart contract, then the verification is deemed successful, the MPC engine initialization instruction is activated, the encrypted digital asset transfer parameters are generated, and the MPC engine is called to drive the digital asset to flow unidirectionally through the physical switch gateway; otherwise, the verification is deemed unsuccessful.

[0219] The physical switch gateway includes a circuit switching module controlled by a mechanical relay.

[0220] The current flows from the cold end to the hot end in the circuit switching module;

[0221] The input / output terminals of the physical switch gateway are equipped with entangled photon pairs. When the qubit error rate of the entangled photon pairs at the input / output terminals of the physical switch gateway exceeds a preset qubit error rate threshold, the circuit is automatically cut off.

[0222] The physical switch gateway transmits digital assets through anti-interference optical fiber. For each transfer of digital assets, environmental parameters are generated, sealed, and written into the transfer audit log.

[0223] In this embodiment, to ensure the security and verifiability of the digital asset transfer process, the steps for parsing and verifying the digital signature file include:

[0224] The superconducting nanowire single-photon detector is invoked to read the polarization angle information of the signature photons carried in the digital signature file, ensuring that the data acquisition has high sensitivity and low noise characteristics.

[0225] The expected quantum fingerprint is extracted from the updated index of the target private key fragment in this call and compared with the polarization angle information of the captured signature photons; a successful match is considered when the deviation between the two does not exceed 0.1 arcseconds. This threshold ensures the uniqueness of the quantum state information and high-precision verification capability.

[0226] The status record of the target private key shard for this call is queried in the blockchain smart contract to determine whether the shard has been automatically circuit-broken after the signature is generated; only when the status is circuit-broken is it considered to meet the security conditions.

[0227] If the quantum fingerprint match is successful and the fragment has been melted, the verification is considered successful.

[0228] Activate MPC engine initialization command;

[0229] Generate encrypted digital asset transfer parameters;

[0230] The MPC engine is invoked to drive the unidirectional flow of digital assets through a physical switch gateway.

[0231] Otherwise, the verification will be deemed unsuccessful, and the asset transfer process will be blocked.

[0232] Preferably, the gateway includes a circuit switching module controlled by a mechanical relay, which only allows current to flow from the cold end to the hot end, preventing reverse current from causing data backflow.

[0233] Entangled photon pairs are configured at both the gateway input and output ends to monitor the qubit error rate in real time; when the qubit error rate exceeds a preset threshold (e.g., 10^6), the gateway will take action. -5 When this occurs, the circuit is automatically cut off to achieve physical isolation.

[0234] Asset flow data is transmitted via anti-interference fiber optic cables to protect against electromagnetic interference and fiber optic eavesdropping attacks.

[0235] During each asset transfer, the system generates environmental parameters (such as temperature, humidity, vibration, and light intensity), encrypts and encapsulates them, and writes them into the transfer audit log to ensure subsequent traceability and accountability.

[0236] Example 7

[0237] Figure 2 This is a schematic diagram of the structure of a digital asset secure storage management system provided in one embodiment of this application, with reference to... Figure 2 A digital asset secure storage management system, comprising:

[0238] Processor 21 and memory 22;

[0239] Processor 21 and memory 22 are connected via a communication bus:

[0240] The processor 21 is used to call and execute the program stored in the memory 22;

[0241] The memory 22 is used to store a program, which is at least used to execute a digital asset secure storage management method as described in the above embodiments.

[0242] It is understood that the same or similar parts in the above embodiments can be referred to each other, and the contents not described in detail in some embodiments can be referred to the same or similar contents in other embodiments.

[0243] It should be noted that in the description of this application, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this application, unless otherwise stated, "a plurality of" means at least two.

[0244] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this application pertain.

[0245] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0246] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0247] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0248] The storage media mentioned above can be read-only memory, disk, or optical disk, etc.

[0249] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0250] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.

Claims

1. A method for secure storage and management of digital assets, characterized in that, include: Receive a user's private key access request, and search for the fragment coordinate set and fragment verification metadata of the target private key based on the private key access request; The fragment coordinate set and fragment verification metadata of the target private key are obtained by splitting the target private key and storing it heterogeneously; Biometric verification and environmental trustworthiness verification are initiated based on the fragmented verification metadata of the target private key; When both bioinformatics verification and environmental trustworthiness verification pass, a chaotic refresh is performed based on the fragmented coordinate set of the target private key to obtain a dynamic authentication token and activate the HSM channel. Based on dynamic authentication tokens, the target private key fragment is accessed through the HSM channel and securely transmitted from the storage location to the trusted execution environment for integrity and legality verification. When the integrity and legality verification passes, the white-box cryptography engine is invoked to prevent side-channel attacks by fragmenting and reconstructing the target private key into the target private key. A digital signature file is generated based on the reconstructed target private key, and the digital signature file is output unidirectionally via an electromagnetically shielded optical fiber. The target private key fragment of this call is circuit-broken, a fragment circuit-broken list is generated and recorded in the digital signature file, and the index of the private key fragment is updated. The digital signature file is parsed and verified. After the parsing and verification are successful, the MPC engine is called to drive the digital assets to flow unidirectionally through the physical switch gateway. The physical switch gateway verifies the fragmented circuit breaker list in the digital signature file; after the fragmented circuit breaker list is verified, it outputs a real-time asset distribution map and transfer audit log.

2. The method according to claim 1, characterized in that, The method further includes: Receive the user's private key storage request and the target private key to be stored; The target stored private key is split into multiple private key fragments using the Shamir secret sharing algorithm; The private key fragments are grouped, and the grouped private key fragments are stored in different physical locations using different storage methods. The stored private key fragments are transmitted via the QKD channel and converted into fragment metadata. A Merkle tree data structure is generated based on the fragmented metadata, and the fragmented coordinate set and fragmented verification metadata of the target stored private key are output based on the Merkle tree data structure. The fragment coordinate set is used to characterize the physical location of the private key fragment; The fragment verification metadata is used to verify whether the private key fragment belongs to the Merkle tree data structure.

3. The method according to claim 2, characterized in that, The fragmented private keys are stored in different physical locations using different storage methods, including: The first set of private keys is fragmented and stored in a geographically isolated HSM module; the HSM module is equipped with a physically tamper-proof shell and a self-destruct circuit. The second set of private keys is fragmented, encrypted, and then stored in a blockchain smart contract; the blockchain smart contract is equipped with a multi-signature verification mechanism. The third set of private key fragments were converted into QR code format and burned onto a durable metal-based physical storage medium, then stored in a vault.

4. The method according to claim 3, characterized in that, The second set of private key shards adopts a quantum-resistant cross-chain contract structure, and is deployed to a zero-knowledge proof public chain after being encrypted twice by a quantum digital signature algorithm; The conditions for calling the second set of private key fragments are: at least 5 geographically dispersed HSM nodes collaboratively decrypt within a preset time. The durable metal-based physical storage medium has a photochromic self-destruct coating, which is bound to the Merkle tree data structure; the photochromic self-destruct coating automatically blurs the QR code of the third private key fragment conversion under abnormal lighting.

5. The method according to claim 1, characterized in that, The method further includes: The real-time asset distribution map and transfer audit log are input into the LSTM model, and the LSTM model outputs the asset flow prediction value. The deviation of asset current is obtained by comparing the forecast value of asset current with the actual value of asset current; Determine whether the private key sharding node is abnormal based on the asset flow deviation. If an anomaly is detected, the anomaly level is determined, and different stages of threat response are triggered based on the anomaly level.

6. The method according to claim 5, characterized in that, The threat response includes: Phase 1 Threat Response: Isolate the abnormal private key sharding node and sever its physical connection; invoke redundant private key sharding nodes to reconstruct the key within a trusted execution environment; destroy the sharding data of the abnormal private key sharding node; The second phase of threat response involves sending encrypted event log slices to multiple oracle networks for verification in a trusted execution environment; after successful verification, arbitration is conducted using DAO threshold signatures, and the arbitration result is recorded on the blockchain in real time to trigger a blockchain smart contract. Phase 3 Threat Response: Migrate the digital assets to new storage media based on the arbitration result; sign the migration using an NTRU cipher during the migration process and write the NTRU cipher signature to a 5D long-term archive storage medium; destroy the old storage media of the digital assets after the migration.

7. The method according to claim 1, characterized in that, Biometric verification is initiated based on the fragmented verification metadata of the target private key, including: Initiate biometric verification for the user and bind the fragmented verification metadata of the target private key to the current biometric verification process; User behavior data is collected in real time at a sampling rate of 1kHz; the behavior data includes: touch pressure matrix and device six-axis posture data; Input the user's real-time behavioral feature data into the user's biological behavior model that has been trained locally beforehand, and output the user behavior judgment result; If the judgment result is that the user's current behavior characteristics do not match the historical behavior characteristics, then the VR challenge protocol is triggered; If the judgment result is that the user's current behavior characteristics match the historical behavior characteristics, then the user's behavior entropy is calculated based on the user's real-time behavior characteristic data. If a user's behavioral entropy is abnormal, the VR challenge protocol will be triggered; If the user's behavioral entropy is normal, the biometric verification passes. The VR challenge protocol includes: Generate a corresponding 3D cryptographic puzzle based on the fragmented coordinate set of the target private key, and generate a time-limited spatial matching task based on the 3D cryptographic puzzle; The time-limited spatial matching task is sent to the user terminal, and the multispectral camera of the user terminal is invoked to verify the user's physical operation. If the user completes the time-limited spatial matching task and the entity operation verification passes, then the biometric information verification will be re-initiated for the user. If the user fails to complete the time-limited spatial matching task, or if the entity operation verification fails, a private key sharding circuit breaker instruction is written to the blockchain smart contract.

8. The method according to claim 2, characterized in that, The method further includes: In the trusted execution environment, a photonic computing core is integrated, and when the integrity and legitimacy verification is passed, the target private key is fragmented and encoded into polarized photons using a quantum dot laser; The white-box cryptographic engine is invoked, and the target private key fragments are signed using NTRU cipher. Some operations in the NTRU lattice cryptographic signature algorithm are mapped to Mach-Zehnder interferometry calculations, and the Mach-Zehnder interferometry calculations are performed on a lithium niobate photonic chip. The target private key fragment in polarized photonic form after signing is converted into electronic form using a superconducting nanowire detector, and the target private key fragment in polarized photonic form is destroyed. The superconducting nanowire detector has a shell covered with a μ metal layer and is filled with argon gas. The photonic computing core and the QKD channel share a quantum random source to ensure that the signature parameters are random and unique each time.

9. The method according to claim 1, characterized in that, The digital signature file is parsed and verified, including: The polarization angle information of the signature photons carried in the digital signature file is captured using a superconducting nanowire single-photon detector. The expected quantum fingerprint is obtained from the updated index of the target private key fragment in this call, and the polarization angle information of the signature photons is compared with the expected quantum fingerprint. Query the status record of the target private key shard in the blockchain smart contract to determine whether the target private key shard has been circuit-broken. If the deviation between the polarization angle information of the signed photon and the expected quantum fingerprint does not exceed 0.1 arcseconds, and the target private key shard in this call is recorded as having a circuit breaker in the blockchain smart contract, then the verification is deemed successful, the MPC engine initialization instruction is activated, the encrypted digital asset transfer parameters are generated, and the MPC engine is called to drive the digital asset to flow unidirectionally through the physical switch gateway; otherwise, the verification is deemed unsuccessful. The physical switch gateway includes a circuit switching module controlled by a mechanical relay; The current flow direction of the circuit switching module is from the cold end to the hot end; The physical switch gateway is equipped with entangled photon pairs at its input / output terminals. When the qubit error rate of the entangled photon pairs at the input / output terminals of the physical switch gateway exceeds a preset qubit error rate threshold, the circuit is automatically cut off. The physical switch gateway transmits digital assets through anti-interference optical fiber. For each transfer of digital assets, environmental parameters are generated, sealed, and written into the transfer audit log.

10. A secure storage management system for digital assets, characterized in that, include: Processor and memory; The processor and memory are connected via a communication bus: The processor is used to call and execute the program stored in the memory; The memory is used to store a program, which is at least used to execute the digital asset secure storage management method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Key management method, system and device, electronic device and storage medium

    CN114978514A

  • Electronic signature security management method and system based on block chain

    CN119808175A