Distributed new energy asset chaining method and system based on error control
By managing off-chain data errors through a decentralized oracle network and error tolerance parameters, the systemic risk problem of distributed new energy assets being put on-chain is solved, the robustness and availability of the system are improved, and effective management and risk pricing of data errors are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGHAI LIGHT RING ENERGY TECH CO LTD
- Filing Date
- 2026-01-23
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies rely excessively on the accuracy of off-chain data sources when putting distributed new energy assets on the blockchain, lacking effective mechanisms to manage routine data errors, which leads to reduced system availability or systemic risks.
A decentralized oracle network is adopted, which calculates off-chain running data through multiple independent oracle nodes, uses aggregation rules to form an on-chain consensus state, and introduces error tolerance parameters and risk states to restrict on-chain interaction behavior, thereby achieving the management and isolation of data errors.
It improves the system's robustness and availability in the face of data errors, avoids the single point of trust risk of centralized data sources, reduces systemic financial risk, and realizes refined state modeling and risk pricing of distributed new energy assets.
Smart Images

Figure CN121580450B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of blockchain technology and asset digitization, specifically to a method and system for on-chaining distributed new energy assets based on error control. More particularly, it relates to a method and system for on-chaining distributed new energy assets by using a decentralized oracle to perform a reliable mapping and form Real-World Assets (RWAs), acknowledging the uncertainty and error risk inherent in off-chain data. Background Technology
[0002] In recent years, distributed new energy sources, represented by photovoltaics and wind power, have developed rapidly. Their assets are characterized by dispersed physical forms, fragmented scale, dynamic changes in operating status and returns over time, and a high dependence on off-chain equipment and the external environment for core indicators such as power generation, electricity prices, and carbon emission reduction. Digitizing these assets and mapping them to real-world assets on the blockchain is an important way to enhance their liquidity and financial value.
[0003] In the process of introducing off-chain asset data into the blockchain, existing technologies mainly face challenges related to trustworthiness and usability:
[0004] One approach is to use a centralized institution for data collection and reporting, but this introduces a single point of trust risk, as the data may be tampered with or have a single point of failure, which contradicts the decentralized nature of blockchain.
[0005] Another more advanced approach is to employ a decentralized oracle network. Existing oracle solutions typically acquire data from multiple data sources, aggregate them on-chain using an aggregation algorithm to form a consensus value, and may set a safety threshold. When the discrepancy between data sources exceeds this safety threshold, the system suspends certain high-risk on-chain activities, such as suspending liquidation, to mitigate risk. However, the fundamental flaw of this type of solution lies in its inherent assumption that off-chain data is accurate in most cases, treating data errors or significant disagreements as anomalous events requiring system suspension. For assets like distributed renewable energy, the sheer number and geographically dispersed data collection points mean that equipment failures, metering discrepancies, and network latency are common occurrences rather than isolated incidents. Simply suspending the system would severely impact asset availability and scalable management, failing to meet the demands of continuous operation and financial interaction.
[0006] Therefore, the market needs a distributed new energy asset on-chain method and system based on error control that does not rely on the absolute correctness of off-chain data, and can treat data errors as a manageable state within the system rather than an anomaly that causes system interruption. Summary of the Invention
[0007] To address the shortcomings of existing technologies, the purpose of this invention is to provide a method and system for on-chaining distributed new energy assets based on error control. This aims to solve the technical problem that existing technologies, when on-chaining real-world assets such as distributed new energy assets, rely excessively on the accuracy of off-chain data sources and lack effective mechanisms to manage and isolate routine data errors, thereby reducing system availability or triggering systemic risks.
[0008] To address the aforementioned technical problems, this invention provides a method for on-chaining distributed new energy assets based on error control, comprising the following steps: acquiring off-chain operational data associated with off-chain assets; distributing the off-chain operational data to multiple independent decentralized oracle nodes, each oracle node independently calculating and submitting asset status results to the blockchain network; aggregating the asset status results from multiple oracle nodes on the blockchain network using preset aggregation rules to form an on-chain consensus state regarding the off-chain asset; verifying the on-chain consensus state according to preset error tolerance parameters; when the on-chain consensus state satisfies the error tolerance parameters, generating or updating the on-chain state of the real-world asset RWA corresponding to the off-chain asset based on the on-chain consensus state; when the on-chain consensus state does not satisfy the error tolerance parameters, placing the on-chain state of the real-world asset RWA in a preset risk state and restricting at least one preset on-chain interaction behavior.
[0009] Preferably, the off-chain asset is a distributed new energy asset, and the off-chain operation data includes at least one of power generation, grid-connected power, electricity price revenue, or energy storage status data;
[0010] The error tolerance parameter includes the maximum acceptable rate of change of the state value or the maximum acceptable absolute deviation value within a single period.
[0011] Preferably, the preset aggregation rule includes at least one of the following: a median rule, a rule of taking the average value after removing extreme values, or a weighted aggregation rule.
[0012] Preferably, the decentralized oracle includes at least:
[0013] The first oracle is used to provide high-frequency data on the operating status of new energy sources.
[0014] The second oracle is used to provide low-frequency audit-level or regulatory-level verification data;
[0015] When the long-term deviation between the output results of the first oracle and the second oracle exceeds a preset threshold, the freezing or manual review process of the new energy RWA is automatically triggered.
[0016] Preferably, the preset risk status includes at least one of a disputed status and a frozen status;
[0017] The at least one preset on-chain interaction behavior includes at least one of token transfer, profit settlement, and collateral for financial applications.
[0018] Preferably, when the on-chain consensus state does not meet the error tolerance parameter, and the degree of divergence between the asset state results from the multiple oracle nodes exceeds a preset divergence threshold, the on-chain state of the real-world asset RWA is placed in the disputed state, and the restriction on at least one preset on-chain interaction behavior includes reducing its available value weight or financial interaction permissions.
[0019] Preferably, when it is detected that more than a predetermined proportion of oracle nodes submit consistent asset state results, but the consistent results cause the aggregated on-chain consensus state to not meet the error tolerance parameter, the on-chain state of the real-world asset RWA is placed in the frozen state.
[0020] Preferably, it further includes:
[0021] A challenge time window is established after the on-chain state of the real-world asset RWA is updated;
[0022] Within the challenge time window, in response to receiving counter-evidence data that conflicts with the on-chain consensus state, when the counter-evidence data is verified to be true, the on-chain state of the real-world asset RWA is rolled back to the on-chain state before this update operation, and economic penalties are imposed on the oracle nodes that have been verified by the counter-evidence data to have submitted erroneous data.
[0023] Preferably, the on-chain consensus state is a composite data structure, which includes at least a state expectation value and an uncertainty index;
[0024] Furthermore, after generating or updating the on-chain state of the real-world asset RWA based on the on-chain consensus state, the method further includes: dynamically adjusting the risk parameters of the real-world asset RWA according to the uncertainty index;
[0025] The risk parameters include at least one of the following: collateral ratio, settlement ratio, and risk weight.
[0026] According to the present invention, a distributed new energy asset on-chain system based on error control includes:
[0027] The data acquisition module is used to acquire off-chain operational data associated with off-chain assets;
[0028] The decentralized oracle module includes multiple independent oracle nodes, which are used to receive the off-chain running data and independently calculate to submit asset status results to the blockchain network;
[0029] The on-chain aggregation and error control module is used to aggregate asset state results from multiple oracle nodes according to preset aggregation rules to form an on-chain consensus state about the off-chain assets; and to verify the on-chain consensus state according to preset error tolerance parameters.
[0030] The RWA management module is used to generate or update the on-chain state of the real-world asset RWA corresponding to the off-chain asset based on the on-chain consensus state when the on-chain consensus state meets the error tolerance parameter; and to place the on-chain state of the RWA in a preset risk state and restrict at least one preset on-chain interaction behavior when the on-chain consensus state does not meet the error tolerance parameter.
[0031] Compared with the prior art, the present invention has the following beneficial effects:
[0032] 1. This invention transforms the unavoidable data uncertainties and errors in the real world from anomalies that cause system interruptions into manageable asset states on the blockchain. By triggering risk states with limited functionality rather than completely suspending the system, it significantly improves the robustness and overall availability of the system in the face of data errors.
[0033] 2. This invention avoids the single-point trust risk of centralized data sources by decentralized multi-node reporting and on-chain aggregation. By introducing error tolerance parameters and risk states, it effectively prevents erroneous off-chain data from evolving into erroneous on-chain value settlement, thereby significantly reducing the systemic financial risks that may be caused by oracle data errors.
[0034] 3. The error management mechanism of this invention enables the system to tolerate a certain proportion of data errors and uncertainties, providing an engineering-feasible technical basis for managing a large number of physically dispersed distributed new energy assets.
[0035] 4. This invention enables downstream decentralized finance applications to clearly identify the risk level of assets by performing refined state modeling of real-world asset tokens and assigning different permissions to different states, thereby achieving more complex risk pricing and financial operations. Attached Figure Description
[0036] Other features, objects, and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:
[0037] Figure 1 A schematic diagram of the architecture of a distributed new energy asset on-chain system based on error control, provided for an embodiment of the present invention;
[0038] Figure 2A flowchart illustrating a method for on-chaining distributed new energy assets based on error control, provided in an embodiment of the present invention;
[0039] Figure 3 This is a schematic diagram of RWA asset state machine transitions provided in an embodiment of the present invention;
[0040] Figure 4 The signaling interaction timing diagram for the challenge and rollback mechanism provided in the embodiments of the present invention. Detailed Implementation
[0041] The present invention will now be described in detail with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the present invention, but do not limit the invention in any way. It should be noted that those skilled in the art can make several changes and improvements without departing from the concept of the present invention. These all fall within the scope of protection of the present invention.
[0042] Example 1
[0043] This embodiment provides a basic implementation scheme for a method and system for on-chaining distributed new energy assets based on error control. The scheme aims to illustrate how the operational data of an off-chain asset (e.g., a distributed new energy asset) can be reported to the blockchain in a decentralized manner, forming a trusted consensus state on the chain. It also incorporates a basic error management mechanism to cope with abnormal data fluctuations.
[0044] Please see Figure 1 This diagram illustrates the overall architecture of a distributed new energy asset on-chain system based on error control, provided by an embodiment of the present invention. As shown, the system can be logically divided into an off-chain component and an on-chain component. The off-chain component mainly includes distributed new energy assets and their associated data acquisition module. The on-chain component, deployed on the blockchain network, mainly includes an on-chain aggregation and error control module and a new energy RWA management module. Connecting the off-chain and on-chain components is a decentralized oracle module, which consists of multiple independent oracle nodes.
[0045] Specifically, distributed new energy assets can be one or more physically existing power generation or energy storage units; in this embodiment, it can be a rooftop photovoltaic power station. The data acquisition module is a hardware device such as a smart meter, inverter, or data acquisition gateway installed in the photovoltaic power station, configured to periodically acquire the off-chain operating data of the power station. It should be noted that, in this embodiment, the off-chain operating data specifically refers to the cumulative power generation reading of the photovoltaic power station.
[0046] The decentralized oracle module consists of a network of nodes operated by multiple different entities. In this embodiment, it is assumed that the network comprises 5 independent oracle nodes. It is understood that these nodes are physically and operationally isolated from each other, thereby ensuring the decentralized nature of the data reporting process and its resilience against single points of failure.
[0047] The blockchain network can be Ethereum, Binance Smart Chain, or any other blockchain platform that supports smart contracts. The on-chain aggregation and error control module and the new energy RWA management module are a set of smart contracts deployed on this blockchain network. The on-chain aggregation and error control module is responsible for receiving and processing reports from multiple oracle nodes, thereby forming consensus and performing error verification. Correspondingly, the new energy RWA management module is responsible for generating or updating the on-chain state of RWA tokens representing the asset rights of the photovoltaic power station based on the processing results of the on-chain aggregation and error control module. The RWA token is a digital token that conforms to specific standards such as ERC-20 or ERC-721, and its value or state is pegged to the operating status of the off-chain photovoltaic power station.
[0048] The following will combine Figure 2 The flowchart shown below provides a detailed explanation of the method provided in this embodiment:
[0049] Step S1: Acquire and Store Data. The data acquisition module is configured to collect the cumulative power generation reading of the photovoltaic power station every hour on the hour. After acquiring the reading, the data acquisition module appends a current timestamp to the data and digitally signs the data packet (containing the power generation reading and timestamp) using a pre-installed private key representing the power station's identity. This ensures the timeliness and non-repudiation of the data's source. For example, if the collected cumulative power generation is 1500 kWh at 2:00 PM, the data packet can be represented as {value: 1500, timestamp: '14:00:00'}, with a signature. Subsequently, the data acquisition module broadcasts this signed data packet over the internet to all five oracle nodes in the decentralized oracle module.
[0050] Step S2: Independent Calculation and Reporting by Multiple Nodes. Upon receiving the data packet, each of the five oracle nodes independently performs a series of operations. First, each node uses its pre-acquired power plant public key to verify the digital signature of the data packet, ensuring that the data indeed originates from the designated distributed renewable energy asset and has not been tampered with. After successful verification, each node queries its local storage or on-chain data for the power plant's consensus cumulative power generation for the previous hour (i.e., 1:00 PM), assuming it is 1400 kWh. Then, the node calculates the incremental power generation for the current hour, i.e., 1500 - 1400 = 100 kWh. This 100 kWh is the asset status result calculated by the node. Subsequently, each oracle node submits this result (100 kWh) along with its own node signature as a report to the on-chain aggregation and error control module deployed on the blockchain network. Due to the independence between nodes, there is no communication or coordination between them.
[0051] Step S3: On-chain aggregation to form consensus. The on-chain aggregation and error control module, as a smart contract, continuously monitors and collects reports from oracle nodes. In this embodiment, the contract sets a minimum report threshold, for example, 3. When the contract collects at least 3 reports within a specified time window (e.g., within 10 minutes after the hour), the aggregation logic is triggered. Assuming that the power generation results submitted by 5 nodes are {100, 101, 99, 100, 125} kWh, one node may have read earlier data due to network latency, leading to a calculation deviation. The preset aggregation rule used in this embodiment is to take the median. The contract sorts these 5 values to obtain {99, 100, 100, 101, 125}, and takes the median of 100 kWh as the consensus power generation for the current settlement period (1:00 PM to 2:00 PM). It is understood that this aggregation rule can effectively resist extreme abnormal quotes from a few nodes.
[0052] Step S4: Verify the error tolerance parameter. After forming an on-chain consensus state of 100 kWh, the on-chain aggregation and error control module does not immediately update the asset value, but first performs an error tolerance check. The preset error tolerance parameter is the maximum acceptable rate of change or the maximum acceptable absolute deviation of the state value within a single period, such as the upper limit of single-period power generation change, the upper limit of single-period revenue change, the upper limit of single-period carbon emission reduction change, and the maximum allowable delay of data update time. In this embodiment, the preset error tolerance parameter is the maximum acceptable rate of change of the state value within a single period, specifically set to an hourly power generation change of no more than 50%. The contract reads the consensus power generation stored on the chain for the previous hour (12:00 noon to 1:00 pm), assuming it is 110 kWh. Then, it calculates the rate of change of the current consensus state relative to the previous period: (100 - 110) / 110 ≈ -9.1%. The absolute value of this rate of change, 9.1%, is within the preset 50% threshold range.
[0053] Step S5: Update to normal state. Since the verification result meets the error tolerance parameter (i.e., the process enters the negative branch of judgment box S4), the on-chain aggregation and error control module determines that the current asset state is normal. A function in the New Energy RWA management module, such as updateValue(amount), will be called. Upon receiving the call, the New Energy RWA management module will convert the 100 kWh of consensus power generation into value according to a preset electricity price (e.g., 0.5 yuan / kWh) and add it to the total value attribute of the RWA token representing the photovoltaic power station. At this time, the on-chain state of the RWA token is marked as normal (corresponding to...). Figure 3 In the ST1 normal state, its owner can freely transfer, trade, or use it in other decentralized finance applications.
[0054] Step S6: Trigger a dispute state and restrict interaction. As an example of an abnormal scenario, suppose at 3:00 PM, due to sudden obstruction by large clouds, the actual power generation of a photovoltaic power station drops sharply. After the oracle network reports and aggregates the data, the consensus power generation is 20 kWh. During step S4, the on-chain aggregation and error control module compares this to the consensus power generation of 100 kWh at 2:00 PM, calculating a change rate of (20 - 100) / 100 = -80%. The absolute value of this change rate, 80%, exceeds the preset error tolerance parameter threshold of 50%.
[0055] At this point, the process enters the decision box S4, which is the branch. The on-chain aggregation and error control module determines that the current consensus state does not meet the error tolerance parameters, and there may be a risk of data anomalies or equipment failure. Accordingly, the value of the RWA token will not be updated, but another function in the New Energy RWA management module, such as triggerDispute(), will be called. The New Energy RWA management module executes this function, switching the on-chain state of the RWA token from the normal state to the disputed state (corresponding to...). Figure 3 (ST2 dispute state in the contract). In this state, at least one on-chain interaction behavior preset in the contract will be restricted. In this embodiment, the restricted interaction behavior is token transfer. Specifically, the transfer() and transferFrom() functions in the RWA token contract will add a pre-check; if the asset state is disputed, the transaction will fail and be rolled back.
[0056] Through the above mechanism, this embodiment achieves a non-destructive risk isolation. The system does not cease operation due to a single drastic data fluctuation; instead, it precisely marks and restricts the functionality of individual assets that may pose a risk, thereby preventing erroneous value transfers during periods of data anomalies and protecting the interests of counterparties. When data returns to normal in subsequent periods (e.g., clouds dissipate, power generation returns to normal levels, and the rate of change falls back below the 50% threshold), the system automatically restores the asset status from disputed to normal and removes the functional restrictions. This embodies the core idea of treating data errors as a manageable state within the system, significantly improving the system's robustness and availability.
[0057] Example 2
[0058] As an optional implementation, this embodiment proposes a more refined state modeling and hierarchical risk isolation scheme based on Embodiment 1. The core of this scheme is that the system no longer simply divides assets into two binary states, normal or disputed, but introduces a richer state machine based on data quality and the degree of anomaly, and imposes different levels of financial function restrictions on assets with different risk levels.
[0059] The system architecture of this embodiment can be referred to Figure 1 It is basically the same as Example 1, but the on-chain smart contract logic is more complex. Specifically, the RWA token contract in the new energy RWA management module defines an asset state machine, such as... Figure 3 As shown. This state machine contains at least four states: ST1 Normal state, ST2 Dispute state, ST3 Frozen state, and ST4 Rollback state (the rollback state will be detailed in Example 3). The behavior of the contract, such as transfer, settlement, and use as collateral, will depend on the current state of the asset.
[0060] The logic of the on-chain aggregation and error control modules has also been improved. On one hand, regarding aggregation rules, this embodiment adopts a mean-removal rule. For example, after receiving reports from 5 oracle nodes, the contract automatically removes the highest and lowest values, and then calculates the arithmetic mean of the remaining 3 reports as the on-chain consensus state. This rule makes better use of the data information from the majority of honest nodes compared to taking the median.
[0061] On the other hand, this embodiment also introduces a new verification dimension: node divergence. This parameter is used to measure the consistency between the results reported by multiple oracle nodes, and can be calculated using statistics such as standard deviation, coefficient of variation, or maximum deviation. For example, a divergence threshold can be preset, such as the standard deviation of node quotes not exceeding 5%.
[0062] Combination Figure 3 The state machine in this embodiment, along with its workflow and risk control logic, can be categorized into the following scenarios:
[0063] Scenario 1: High data quality, assets are in ST1 normal state. Assume that the hourly power generation reported by 5 oracle nodes is {102, 100, 101, 103, 99} kWh. The on-chain aggregation and error control module first calculates the standard deviation of these data, which is approximately 1.58, far less than the 5% divergence threshold. Then, it uses the extreme value removal and mean-averaging rule to remove 99 and 103, calculating (102+100+101) / 3 = 101 kWh as the consensus power generation. Next, this consensus value is compared with the value of the previous period, and its rate of change is also within the error tolerance parameter range. At this point, all verifications pass, and the RWA management module maintains the RWA token in ST1-normal state and updates its value normally. In this state, the token has full functionality, can be freely transferred, and can also be used as collateral for borrowing in compatible decentralized lending protocols with the highest collateral ratio (e.g., 70%).
[0064] Scenario 2: Data Disagreement Leads to Asset Entering ST2 Dispute State and Degradation of Financial Functions. Assume that out of five nodes, one node reports 0 due to a software defect, while another node, due to network issues, performs duplicate calculations resulting in an inflated quote, reporting {102, 100, 101, 0, 150} kWh. The on-chain aggregation and error control module calculates the standard deviation of this data set to approximately 55.8, significantly exceeding the 5% disagreement threshold, but likely still within a higher threshold (e.g., 20%), indicating significant disagreement within the oracle network. Simultaneously, the aggregation contract uses a mean-reduction rule, removing 0 and 150, calculating (102+100+101) / 3 = 101 kWh. This aggregation result itself may still be accurate, and its rate of change from the previous period may be within the error tolerance parameter range. In this scenario, although the final consensus value appears normal, its formation process is accompanied by high uncertainty. To reflect this potential risk, the system will not place the asset in a completely normal ST1 state. According to preset rules, when the node divergence exceeds 5% but is below 20%, the on-chain aggregation and error control module triggers the RWA token to enter the ST2 disputed state. In this state, some of the asset's functions are restricted, representing a more granular risk isolation. For example, the RWA token can still be transferred, but when used in a decentralized lending protocol, its collateral ratio is automatically reduced from 70% to 30%. This mechanism is implemented by the lending protocol's smart contract reading the RWA token's state when calculating collateral value and applying different risk parameters based on that state. In other words, this mechanism reduces its usable value weight or financial interaction permissions, effectively preventing financial risks caused by data uncertainty without affecting the asset's basic liquidity.
[0065] Scenario 3: Systemic error detected, assets enter ST3 frozen state. Consider a more extreme case. Suppose that due to a failure in the upstream power grid company's data interface, three consecutive hours of erroneous power generation data of 0 were provided to all 5 oracle nodes. In this case, the 5 nodes would report a highly consistent result {0, 0, 0, 0, 0} kWh. In this situation, the node divergence would be very low (0), but the rate of change of the aggregated consensus power generation of 0 compared to the value of the previous normal period (e.g., 100 kWh) would be -100%, far exceeding the error tolerance parameter (e.g., 50%). The on-chain aggregation and error control module in this embodiment includes logic for identifying systemic risks: when it detects that more than a predetermined proportion (e.g., more than half, i.e., 3 or more) of oracle nodes submit consistent asset state results, but these consistent results cause the aggregated on-chain consensus state to not meet the error tolerance parameter, the system determines that this may be a systemic error event (e.g., common data source contamination, large-scale equipment outage, etc.). At this point, the system will trigger the highest level of risk response, placing the RWA token's on-chain state into ST3 frozen state. In this state, all on-chain interactions of the token, including token transfers, yield settlements, and all financial applications (such as staking and trading), will be completely suspended. The assets are frozen, awaiting manual intervention, investigation, and remediation by the project team or community. This mechanism effectively prevents large-scale erroneous settlements and liquidations throughout the on-chain financial system due to systemic failures of upstream data sources.
[0066] In summary, through the aforementioned hierarchical state management, this mechanism enables the system to smoothly adjust the risk level of assets and on-chain permissions based on continuous changes in data quality. This avoids drastic switching between normal and shutdown states, thereby improving the system's resilience and adaptability to complex financial scenarios, making financial applications built upon this foundation more robust and reliable.
[0067] Example 3
[0068] Building upon the aforementioned embodiments, this embodiment further discloses a final error correction and accountability mechanism based on economic game theory, namely, a challenge window and economic penalty mechanism. This mechanism aims to address a fundamental problem: even after decentralized aggregation and error tolerance verification, the consensus state formed on-chain may still be erroneous. This embodiment provides a path for ex-post correction and utilizes economic incentives and penalties to deter dishonest behavior by participants, thus offering a strong defense for the final correctness of on-chain assets.
[0069] The implementation of this embodiment requires... Figure 1The system architecture shown adds two key on-chain components: a staking contract and an arbitration contract. Simultaneously, the logic of the on-chain aggregation and error control module and the new energy RWA management module also needs to be expanded accordingly.
[0070] The specific structure and process of this mechanism are as follows, and can be used as a reference. Figure 4 The signaling interaction timing diagram shown is as follows:
[0071] Staking Mechanism: As a prerequisite for participating in the system, each oracle node wishing to become a member of the decentralized oracle module must lock a substantial amount of funds as collateral in a staking contract. This collateral can be the blockchain's native token or a widely accepted stablecoin, with a value, for example, equivalent to $10,000. This collateral forms the basis of economic penalties.
[0072] Challenge Window: After each update to the RWA token's state (specifically its value) according to step S5, the on-chain aggregation and error control module does not immediately consider the state final. Instead, it opens a challenge window of fixed duration, such as 24 hours, for this update. During this period, the state update is considered provisional.
[0073] Challenge Process: Within the 24-hour challenge window, any entity that disagrees with the current consensus state (hereinafter referred to as a challenger) can initiate a challenge. Challengers can be asset owners, community members, or any interested party. Initiating a challenge requires the challenger to also stake a sum of money (usually much less than the oracle node's stake, e.g., $100) to prevent malicious challenge attacks. The challenger needs to submit counter-evidence to the arbitration contract. This counter-evidence must be highly credible evidence proving the on-chain consensus state is incorrect. For example, for new energy assets, counter-evidence could be the hash value of an official settlement statement with legal validity, confirmed by the State Grid Corporation or a notary public, while the original document is uploaded to a decentralized storage system for verification by the arbitrator.
[0074] Arbitration and Rollback: Upon receiving a challenge, the arbitration contract will initiate a decentralized arbitration process. The arbitration committee can consist of a set of trusted entities elected by token holders, or it can be determined entirely by token holder votes. The arbitration committee or voters will verify the counter-evidence submitted by the challenger. Figure 4 As shown, when the arbitration contract verifies the disproven data (verifyProof()), confirming that the on-chain consensus state is indeed incorrect, it will trigger an automated coefficient operation, as follows:
[0075] The arbitration contract calls a special function of the on-chain aggregation and error control module, such as `executeRollback()`. Upon receiving this instruction, the on-chain aggregation and error control module further calls the New Energy RWA management module to roll back the state of the RWA tokens it manages to the on-chain state before the erroneous update operation. For example, if 1000 kWh of electricity generation was mistakenly over-recorded, the rollback operation will deduct this value from the total value of the RWA tokens. At this point, the state of the RWA tokens can be set to... Figure 3 The ST4 rollback state shown indicates that it has undergone a correction. Simultaneously, the arbitration contract identifies which oracle nodes submitted data that led to the erroneous consensus. Identification can be achieved by recording each adopted quote and its source node during aggregation. Oracle nodes whose submission of erroneous data is verified by counter-evidence will be subject to economic penalties.
[0076] Economic Incentives and Penalties: The arbitration contract calls the staking contract's function (slashStake()) to partially or completely forfeit the staked funds of the erroneous oracle node. For example, each erroneous node is penalized 10% of its $10,000 staked funds, or $1,000. This forfeited fund will be distributed according to preset rules to form a positive economic incentive loop, as follows:
[0077] A portion of the funds (e.g., $500) will be awarded to challengers who successfully launch challenges to compensate for their efforts and staking costs, and to incentivize community members to actively monitor the system.
[0078] Another portion of the funds (e.g., $400) can be used to compensate for any losses that RWA token holders may suffer due to the error (even if temporary).
[0079] The remaining amount (e.g., $100) can be injected into a systemic risk reserve pool to address unforeseen future risk events.
[0080] Let's take a specific example: Suppose that during an afternoon update, due to a shared calculation error by three oracle nodes, the consensus power generation of a photovoltaic power plant was overstated by 1000 kWh, resulting in an erroneous increase in the value of the RWA tokens by 500 yuan. This update was accepted by the system because its rate of change might still be within the error tolerance parameter range. During the subsequent 24-hour challenge window, the owner of the photovoltaic power plant (as the challenger) discovered this error. He obtained a stamped electricity bill from the local power company for that period, uploaded a scanned copy to the decentralized storage system, and submitted the file hash and a challenge deposit to the arbitration contract. Members of the decentralized arbitration committee downloaded and verified the bill, confirming that the on-chain data had indeed overstated by 1000 kWh. The arbitration vote passed, and the challenge was successful. The system then automatically executed the following: the value of the RWA tokens was rolled back, and the extra 500 yuan was deducted; a portion of the staking of the three oracle nodes that submitted the erroneous data was forfeited; and most of the forfeited funds were awarded to the power station owners who were challengers.
[0081] Understandably, by introducing this mechanism, this embodiment constructs a self-correcting closed-loop system driven by an economic model. It not only deters malicious (collusion) or lazy (failure to carefully verify data) behavior by oracle nodes through penalties, but also provides a final corrective path for all unavoidable errors not caught by the real-time verification mechanism. This enables the entire system to achieve result correctability on top of process fault tolerance (as described in Embodiments 1 and 2), enhancing the ultimate credibility of on-chain asset data and laying a solid foundation for building large-scale, high-value RWA financial applications.
[0082] Example 4
[0083] This embodiment proposes a scheme to quantify data uncertainty and record it on the blockchain. The core idea is that a single asset state expectation (such as average power generation) cannot fully reflect the underlying data quality and risk level. By reporting a composite data structure containing more statistical information, and allowing downstream financial applications to directly read and utilize this information, more accurate and dynamic risk pricing can be achieved.
[0084] To achieve the above objectives, the system architecture of this embodiment (see reference) Figure 1 In the design of the decentralized oracle module, a dual-track oracle architecture can be adopted, and the data format output by the on-chain aggregation and error control module, as well as the interaction method between the new energy RWA management module and downstream applications, have also been designed accordingly.
[0085] Dual-track oracle architecture: In one embodiment of the invention, the decentralized oracle module may consist of two different types of oracle networks:
[0086] The first oracle (high-frequency operating oracle): This network is similar to the oracle network in the aforementioned embodiments, consisting of multiple (e.g., 5-10) independent oracle nodes responsible for collecting and reporting real-time operational data of assets at a high frequency (e.g., hourly). Its characteristics include high timeliness, enabling rapid reflection of changes in asset status, but the data may contain short-term fluctuations and noise.
[0087] The second oracle (low-frequency audit oracle): This network consists of a few (e.g., 1-3) highly reputable entities, such as the Big Four accounting firms, authoritative third-party certification bodies, or government regulatory bodies, responsible for acquiring and reporting audited, authoritative official settlement data at a low frequency (e.g., monthly or quarterly). Its characteristics include extremely high data accuracy, serving as a benchmark for on-chain data truth, but poor timeliness.
[0088] Uncertainty On-Chain: In this embodiment, the on-chain aggregation and error control module no longer simply outputs a single consensus value. Instead, it aggregates data from high-frequency oracles and combines it with the comparison results of the previous low-frequency audit data to generate and report a composite data structure. This structure includes at least the expected state value and an uncertainty index. For example, after a settlement cycle, the on-chain aggregation and error control module can write data in the following format to the New Energy RWA management module: { value: 105.5, confidence_interval: [98.0, 112.0], uncertainty_score: 0.85} Where:
[0089] `value` (expected state value) represents the best estimate of the current period's asset state, calculated from high-frequency oracle data using algorithms such as extreme value removal and mean averaging. `confidence_interval` represents the range within which the true state value might fall. The width of this interval can be calculated based on the dispersion (e.g., standard deviation) of the high-frequency oracle node quotes; the more dispersed the node quotes, the wider the interval. `uncertainty_score` is a comprehensive score between 0 and 1, used to intuitively represent the confidence level of the current state data; 1 represents complete confidence, and 0 represents complete unconfidence. This score can be calculated considering multiple factors, including but not limited to: the dispersion of high-frequency data quotes (lower dispersion, higher score), the fit between the current high-frequency data aggregate value and the trend of the previous low-frequency audit data (better fit, higher score), and the latency of data updates.
[0090] Dynamic Risk Parameter Adjustment: This composite data structure containing uncertainty information is recorded in the RWA management module and is visible to all other smart contracts. Downstream decentralized finance protocols can directly read this structure and dynamically adjust their risk parameters for the RWA token based on the uncertainty indicators within it. These risk parameters may include at least one of collateralization ratio, settlement ratio, and risk weight. For example, a decentralized lending protocol might set the following rule: Collateralization Ratio = Base Collateralization Ratio * uncertainty_score, where the "base collateralization ratio" is a benchmark value (e.g., 80%) set for this type of asset.
[0091] Consider a specific workflow example: Imagine an RWA token belonging to a wind farm in a certain region. On a week with stable winds and favorable weather conditions, the hourly power generation data reported by the high-frequency oracle network is very stable, with minimal disagreement between nodes, and the data trend closely matches the previous month's audit report. At this time, the uncertainty_score calculated by the on-chain aggregation and error control module might be as high as 0.95. When the owner of this RWA token deposits it as collateral into a lending protocol, they can obtain a collateralization ratio of 80% * 0.95 = 76%, thus borrowing a higher value of funds. However, on a certain day during typhoon season, the wind is intermittent, and the power generation fluctuates wildly between 0 and full capacity, causing the data reported by the high-frequency oracle nodes to become highly discrete. At this time, the uncertainty_score calculated by the on-chain aggregation and error control module will drop significantly, for example, to 0.60. Even though the RWA token has been staked in the protocol, the lending protocol's smart contract automatically lowers the collateral ratio to 80% * 0.60 = 48% each period when it recalculates the risk. If a user's debt ratio exceeds the new liquidation threshold as a result, partial liquidation may be triggered, thus protecting the protocol's funds in advance.
[0092] Through the solution in this embodiment, the system achieves explicit and priced risk. Instead of hiding risk behind a single numerical value, it exposes the credibility or uncertainty hidden behind asset data as a clear, machine-readable parameter to the entire blockchain ecosystem. This enables financial protocols to shift from passively responding to errors (such as the disputed state in Embodiment 1) to proactively and dynamically managing risk. This refined risk management capability expands the application potential of RWA in more complex decentralized finance scenarios such as interest rate swaps and volatility derivatives, providing technical support for the deep integration of real-world assets and the digital financial world.
[0093] Those skilled in the art will understand that, besides implementing the system and its various devices, modules, and units provided by this invention in the form of purely computer-readable program code, the same functions can be achieved entirely through logical programming of the method steps, making the system and its various devices, modules, and units of this invention function in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, the system and its various devices, modules, and units provided by this invention can be considered as a hardware component, and the devices, modules, and units included therein for implementing various functions can also be considered as structures within the hardware component; alternatively, the devices, modules, and units for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0094] Specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the specific embodiments described above, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.
Claims
1. A distributed new energy asset chaining method based on error control, characterized in that, The method comprises the following steps: obtaining off-chain operation data associated with off-chain assets; distributing the off-chain operation data to a plurality of mutually independent decentralized oracle nodes, each oracle node independently calculating and submitting asset state results to a blockchain network; on the blockchain network, aggregating asset state results from a plurality of the oracle nodes by a preset aggregation rule to form an on-chain consensus state about the off-chain assets; verifying the on-chain consensus state according to a preset error tolerance parameter; when the on-chain consensus state meets the error tolerance parameter, generating or updating the on-chain state of the real-world asset (RWA) corresponding to the off-chain assets based on the on-chain consensus state; when the on-chain consensus state does not meet the error tolerance parameter, placing the on-chain state of the real-world asset (RWA) in a preset risk state and limiting at least one preset on-chain interaction behavior thereof; further comprising: after updating the on-chain state of the real-world asset (RWA), setting a challenge time window; within the challenge time window, in response to receiving counter-evidence data conflicting with the on-chain consensus state, when the counter-evidence data is verified, rolling back the on-chain state of the real-world asset (RWA) to the on-chain state before the update operation, and performing economic punishment on the oracle node that submitted the wrong data according to the counter-evidence data; the preset risk state comprises at least one of a dispute state and a frozen state; the at least one preset on-chain interaction behavior comprises at least one of token transfer, yield settlement, and collateral for financial applications; when the on-chain consensus state does not meet the error tolerance parameter, and the degree of disagreement between asset state results from a plurality of the oracle nodes exceeds a preset disagreement threshold, placing the on-chain state of the real-world asset (RWA) in the dispute state, and the at least one preset on-chain interaction behavior comprises reducing the available value weight or financial interaction authority thereof; when it is detected that more than a predetermined proportion of oracle nodes submit consistent asset state results, but the consistent asset state results make the aggregated on-chain consensus state not meet the error tolerance parameter, placing the on-chain state of the real-world asset (RWA) in the frozen state.
2. The error control based distributed new energy asset chaining method according to claim 1, characterized in that, The off-chain assets are distributed new energy assets, and the off-chain operation data comprises at least one of power generation, grid-connected power, electricity price income, or energy storage state data; The error tolerance parameter comprises a maximum acceptable rate of change of state value or a maximum acceptable absolute deviation value within a single cycle. 3.The error control based distributed new energy asset chaining method according to claim 1, characterized in that, The preset aggregation rule comprises at least one of taking the median, taking the average after removing extreme values, or weighted aggregation.
4. The error control based distributed new energy asset chaining method according to claim 1, characterized in that, The decentralized oracle at least comprises: a first oracle for providing high-frequency new energy operation state data; a second oracle for providing low-frequency audit-level or regulatory-level verification data; when the long-term deviation between the output results of the first oracle and the second oracle exceeds a preset threshold, automatically triggering a new energy RWA freezing or manual review process.
5. The error control based distributed new energy asset chaining method according to claim 1, characterized in that, The on-chain consensus state is a complex data structure, which at least includes a state expectation value and an uncertainty index; And after generating or updating the on-chain state of the real-world asset RWA based on the on-chain consensus state, the method further comprises: dynamically adjusting the risk parameter of the real-world asset RWA according to the uncertainty index; The risk parameter includes at least one of a mortgage rate, a settlement ratio, and a risk weight.
6. A distributed new energy asset chaining system based on error control, characterized in that, Comprise: A data collection module for acquiring off-chain running data associated with an off-chain asset; A decentralized oracle module comprising a plurality of independent oracle nodes for receiving the off-chain running data and independently calculating to submit asset state results to a blockchain network; An on-chain aggregation and error control module for aggregating asset state results from a plurality of the oracle nodes by a preset aggregation rule to form an on-chain consensus state about the off-chain asset; And according to a preset error tolerance parameter, the on-chain consensus state is verified; A RWA management module for generating or updating the on-chain state of the real-world asset RWA corresponding to the off-chain asset based on the on-chain consensus state when the on-chain consensus state meets the error tolerance parameter; and when the on-chain consensus state does not meet the error tolerance parameter, the on-chain state of the RWA is placed in a preset risk state, and at least one preset on-chain interaction behavior is limited; Further comprising: After updating the on-chain state of the real-world asset RWA, a challenge time window is set; Within the challenge time window, in response to receiving counter-evidence data conflicting with the on-chain consensus state, when the counter-evidence data is verified, the on-chain state of the real-world asset RWA is rolled back to the on-chain state before the update operation, and the oracle node that submitted the error data is punished economically when the counter-evidence data is verified; The preset risk state includes at least one of a dispute state and a frozen state; The at least one preset on-chain interaction behavior includes at least one of token transfer, income settlement, and collateral for financial applications; When the on-chain consensus state does not meet the error tolerance parameter, and the degree of disagreement between asset state results from a plurality of the oracle nodes exceeds a preset disagreement threshold, the on-chain state of the real-world asset RWA is placed in the dispute state, and the at least one preset on-chain interaction behavior includes reducing its available value weight or financial interaction permission; When it is detected that more than a predetermined proportion of oracle nodes submit consistent asset state results, but the consistent asset state results make the aggregated on-chain consensus state not meet the error tolerance parameter, the on-chain state of the real-world asset RWA is placed in the frozen state.