Digital asset key management method and system based on quantum computing resistance
By splitting key shares using quantum-resistant cryptographic algorithms and threshold signature technology, and combining secure multi-party computation and node reputation assessment, a quantum-resistant and secure digital asset key management system is constructed. This solves the single point of failure and quantum attack resistance problems of existing solutions, and achieves dynamic balance and high reliability in key management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-15
- Publication Date
- 2026-03-27
AI Technical Summary
Existing digital asset key management schemes suffer from single point of failure risks, insufficient resistance to quantum computing, and inability to dynamically adapt to node states, making it difficult to guarantee the security and availability of digital assets, especially when quantum computing is widely used and faces significant security threats.
A quantum-resistant cryptographic algorithm is used to generate the root key and the key shares are split using threshold signature technology. A secure multi-party computation protocol is used to realize key collaborative operation. A quantum-resistant encryption storage and transmission mechanism is added, and the threshold is dynamically adjusted through a node reputation evaluation model to build a key management system with quantum-resistant security.
It effectively resists quantum computing attacks, avoids single points of failure and abuse of privileges, achieves a dynamic balance between security and availability in key management, provides decentralized and highly reliable digital asset key management, and meets the security needs of highly sensitive scenarios such as financial transactions.
Smart Images

Figure CN121750199A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of digital asset key management technology, specifically to a method and system for digital asset key management based on quantum computing resistance. Background Technology
[0002] Digital assets are digital certificates with economic value or rights attributes, formed based on digital technologies such as blockchain, distributed ledger, and encryption. They encompass various forms including cryptocurrencies, digital bills, electronic certificates, and cross-border payment vouchers, and have become a core value carrier and medium of circulation in the digital economy era. Key management is a core aspect of digital asset security. It refers to a series of operations that control the entire lifecycle of digital assets, including the generation, storage, distribution, updating, revocation, and destruction of keys required for accessing, using, transferring, and canceling them. Its security directly determines the ownership, integrity, and availability of digital assets, and is a key support for establishing trust and ensuring compliant operation in sensitive scenarios such as financial transactions and cross-border trade.
[0003] With the rapid development of quantum computing technology, traditional encryption algorithms based on large integer factorization and discrete logarithm problems face the risk of being efficiently cracked by quantum algorithms. Once quantum computing is widely applied, the existing digital asset key system will face a comprehensive security crisis, leading to the theft, tampering, or illegal transfer of digital assets, seriously threatening the stable operation of the digital economy. Therefore, integrating quantum-resistant computing technology into digital asset key management and building a key management system capable of resisting quantum attacks has become an urgent need to ensure the long-term security of digital assets.
[0004] However, existing digital asset key management solutions still have certain shortcomings. Most solutions adopt a centralized management model by a single institution, which poses a significant risk of single point of failure. If the management institution's system is compromised or internal personnel abuse their privileges, it will directly lead to the leakage of complete keys, causing significant losses of digital assets. Some distributed key management solutions do not incorporate quantum-resistant computing technology and cannot resist quantum computing attacks, resulting in insufficient long-term key security. Existing solutions lack a dynamic adjustment mechanism to adapt to node states, making it difficult to balance the security and availability of key management under conditions such as changes in node reputation and network environment fluctuations. They cannot meet the stringent key management requirements of highly sensitive scenarios. Therefore, developing a digital asset key management method and system based on quantum-resistant computing is of great significance. Summary of the Invention
[0005] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a digital asset key management method and system based on quantum computing resistance. It can generate root keys using quantum-resistant cryptographic algorithms and split key shares using threshold signature technology, avoiding single point of failure and abuse of authority risks caused by centralized control by a single institution. It uses a secure multi-party computation protocol to achieve key collaborative operation, and with a quantum-resistant encryption storage and transmission mechanism, it resists quantum computing attacks and ensures quantum-resistant security throughout the key's lifecycle. By constructing a node reputation evaluation model to dynamically adjust the threshold, it achieves a dynamic balance between key management security and availability.
[0006] To address the aforementioned technical problems, this invention provides the following technical solution: a digital asset key management method based on quantum computing resistance, comprising the following steps:
[0007] S1. A quantum-resistant cryptographic algorithm is used to generate a digital asset root key. The root key is then split into multiple key shares based on threshold signature technology. Each key share is encrypted using a quantum-resistant cryptographic algorithm.
[0008] S2. Distribute the encrypted key shares to multiple authorized nodes. Each authorized node stores the received key shares in a local secure storage unit and enables access control mechanisms.
[0009] S3. When performing key generation, update or revocation operations, at least a preset threshold number of authorized nodes must initiate a collaboration request. Each participating node decrypts its own key share through a secure multi-party computation protocol and collaborates to complete the corresponding key operation. During the operation, the node identity and operation instructions are verified using quantum-resistant signatures.
[0010] S4. Collect historical operational compliance, network connection stability, and security protection status indicators of each authorized node, score the reputation of each node, and dynamically adjust the preset threshold number based on the overall reputation score of all authorized nodes.
[0011] S5. Record the operation behavior information throughout the entire life cycle of the key, generate a hash digest of the operation behavior information using a quantum-resistant hash algorithm and store it for subsequent security auditing and behavior tracing.
[0012] Furthermore, step S1, when generating the digital asset root key using a quantum-resistant cryptographic algorithm and performing fragmented encryption, includes the following steps:
[0013] Select the corresponding quantum-resistant cryptographic algorithm according to the security level of the digital asset, generate the root key of the digital asset based on the key generation rules of the algorithm, and introduce quantum random numbers as key seeds in the generation process;
[0014] The sharding rule based on threshold signature technology splits the root key into a preset number of key shares, and each key share is encrypted separately using a quantum-resistant encryption algorithm. During the encryption process, a unique encryption key is generated by combining the unique identity of each authorized node.
[0015] The root key is generated according to the formula: ,in For digital asset root keys, For quantum-resistant hash functions, This is the core parameter matrix of the selected quantum-resistant cryptography algorithm. For quantum random numbers, A quantitative value for the security level of digital assets. These are the weighting coefficients. Based on the security strength test results of quantum-resistant cryptographic algorithms, it was determined that... The entropy detection result is set based on quantum random numbers. All three parameters are fixed values certified by authoritative encryption technology evaluation institutions, and are calibrated in accordance with the security grading standards of the digital asset industry.
[0016] Furthermore, step S3, when each participating node collaboratively completes the corresponding key operation through a secure multi-party computation protocol, includes the following steps:
[0017] The authorized node that initiates the collaboration request sends operation instructions and its own identity information to other qualified authorized nodes, along with a quantum-resistant signature;
[0018] The authorized node receiving the request verifies the identity information and operation instructions of the initiating node through a quantum-resistant signature verification algorithm. After successful verification, it initiates the local key share decryption process.
[0019] Each verified participating node establishes an encrypted communication channel through a secure multi-party computation protocol to complete collaborative computation and generate key operation results without exposing the complete key and key share plaintext.
[0020] After the key operation result is confirmed with a quantum-resistant signature, the subsequent activation process is executed.
[0021] Furthermore, step S4, when dynamically adjusting the number of preset thresholds based on the overall credit score results, includes the following steps:
[0022] Set credit score ranges and corresponding threshold adjustment rules. The credit score ranges are divided into multiple levels according to the score, and different levels correspond to different threshold adjustment ranges.
[0023] The overall reputation score is obtained by aggregating the reputation scores of all authorized nodes, and the score range to which the overall reputation score belongs is determined.
[0024] Adjust the number of preset thresholds according to the threshold adjustment rules for the corresponding rating range. Increase the number of preset thresholds when the overall credit score is in a low-level range, and maintain or decrease the number of preset thresholds when it is in a high-level range. Inform all authorized nodes simultaneously after the adjustment.
[0025] The overall credit score calculation follows the formula: ,in For overall credit rating, Scoring for compliance of historical operations Rate the network connection stability. To score the safety protection status, , , As the indicator weight, , Determined through the Analytic Hierarchy Process (AHP) combined with industry security standards for digital asset key management, and fixed after multiple rounds of review and calibration by industry technical experts, the threshold number adjustment satisfies the following formula: ,in The adjusted preset threshold number, The initial baseline threshold number, As a preset reference credit score, To adjust the coefficient, The value is determined based on statistical analysis of historical node failure data and key operation success rate, and is a fixed calibration value.
[0026] Furthermore, the quantum-resistant cryptographic algorithm used in step S1 includes one or more of lattice-based cryptography, hash-based cryptography, and encoding-based cryptographic algorithms. The quantum-resistant encryption algorithm used to encrypt the key share in step S1 is of the same or compatible type as the quantum-resistant cryptographic algorithm used to generate the root key.
[0027] Furthermore, in step S2, the local secure storage unit of each authorized node adopts a hardware-encrypted storage medium. The access control mechanism enabled in step S2 includes identity authentication, hierarchical operation permissions, and local recording of operation logs. Only accounts that have passed identity authentication and have the corresponding operation permissions can access the key share.
[0028] Furthermore, the operation behavior information recorded in step S5 throughout the key's entire lifecycle includes the operation node identifier, operation type, operation initiation time, operation execution duration, operation result status, and a list of nodes participating in the collaborative operation. The hash digest generated by the quantum-resistant hash algorithm in step S5 corresponds one-to-one with the operation behavior information, and is stored in a distributed storage manner across each authorized node.
[0029] Furthermore, the authorized nodes include business nodes at various levels of financial institutions, third-party compliance audit nodes, and nodes of different business lines of enterprises. Each authorized node must complete identity registration and qualification review before obtaining the key share distributed in step S2. After the review is passed, a unique identity identifier and corresponding operation permissions are assigned.
[0030] The quantum-resistant digital asset key management system is applicable to the aforementioned quantum-resistant digital asset key management method. The system includes: a quantum-resistant key generation module, a key fragmentation encryption module, an authorized node management module, a secure multi-party computation module, a dynamic threshold adjustment module, a secure storage module, a quantum-resistant verification module, and a log auditing module.
[0031] The quantum-resistant key generation module is used to generate digital asset root keys using a quantum-resistant cryptographic algorithm, and quantum random numbers are introduced as key seeds during the generation process.
[0032] The key fragmentation encryption module is used to split the root key into multiple key shares based on threshold signature technology, and to encrypt each key share using a quantum-resistant encryption algorithm;
[0033] The authorized node management module is used for the registration, qualification review, identity authentication, permission configuration and identity identifier allocation of authorized nodes;
[0034] The secure multi-party computation module is used to build an encrypted communication channel, supporting authorized nodes to collaboratively complete key operations through the secure multi-party computation protocol.
[0035] The dynamic threshold adjustment module is used to collect relevant indicators of authorized nodes and perform credit scoring, and dynamically adjust the preset threshold number according to the overall credit score.
[0036] The secure storage module is used to encrypt and store key shares and is equipped with an access control mechanism.
[0037] The quantum-resistant verification module is used to verify the node's identity and operation instructions using a quantum-resistant signature algorithm.
[0038] The log auditing module is used to record operational behavior information and generate quantum-resistant hash digests, providing auditing and traceability support.
[0039] Furthermore, the secure storage module adopts a hardware-encrypted storage medium and has a built-in key share anti-leakage mechanism, including data encryption storage, access behavior monitoring, and abnormal access alarm functions. It also supports key share backup and recovery. The backup process uses a quantum-resistant encryption algorithm to encrypt the backup data, and recovery requires multi-node collaborative verification.
[0040] Compared with existing technologies, this quantum-resistant digital asset key management method and system has the following advantages:
[0041] This invention employs a quantum-resistant cryptographic algorithm to generate the root key and combines it with threshold signature technology to split the key into shares. This avoids the risks of single-point failure and abuse of permissions caused by centralized control by a single institution. Even if some nodes are compromised, the complete key cannot be obtained. It utilizes a secure multi-party computation protocol to achieve key collaborative operation, coupled with a quantum-resistant encryption storage and transmission mechanism, to effectively resist quantum computing attacks and ensure quantum-resistant security throughout the key's lifecycle. By constructing a node reputation evaluation model to dynamically adjust the threshold, it achieves a dynamic balance between key management security and availability, solving the problem that existing solutions cannot adapt to changes in node state. This provides decentralized, quantum-resistant, and highly reliable digital asset key management support for highly sensitive scenarios such as financial transactions, comprehensively improving the security protection level and compliance adaptation capability of digital asset keys.
[0042] Other advantages, objectives and features of the invention will be set forth in part in the description which follows, and in part will be apparent to those skilled in the art from the following examination or study, or may be learned from the practice of the invention. Attached Figure Description
[0043] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.
[0044] Figure 1 A flowchart of a quantum-resistant digital asset key management method;
[0045] Figure 2 A flowchart illustrating a quantum-resistant digital asset key management method.
[0046] Figure 3 This is a schematic diagram of a quantum-resistant digital asset key management system. Detailed Implementation
[0047] To further illustrate the technical means and effects of the present invention in achieving its intended purpose, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention, in conjunction with the accompanying drawings and preferred embodiments, is provided below.
[0048] The present invention provides a method and system for digital asset key management based on quantum computing resistance, which clarifies a complete technical solution, and the core covers two parts: method and system.
[0049] See Figure 1 and Figure 2 The methodology comprises five key steps: First, generating and encrypting keys. Based on the security level of digital assets, quantum-resistant cryptographic algorithms such as lattice-based cryptography are selected. Quantum random numbers are introduced as seeds to generate the root key. Threshold signature technology is used to split the root key into multiple shares, and each share is encrypted using a compatible quantum-resistant encryption algorithm combined with the unique identity of authorized nodes. Second, distributing and storing keys. The encrypted key shares are distributed to authorized nodes such as financial institution business nodes. Nodes store the keys using hardware-encrypted storage media, enabling access control mechanisms such as identity authentication and hierarchical permission levels. Third, collaboratively executing key operations. When key generation, ... When updating or revoking, a preset threshold number of authorized nodes must initiate a request. After verification by a quantum-resistant signature, the nodes collaboratively complete the operation and confirm its effectiveness through a secure multi-party computation protocol without exposing the plaintext of the key. Fourth, the threshold number is dynamically adjusted by collecting indicators such as the compliance of historical operations, network stability, and security protection status of nodes to conduct a reputation score. Based on the overall score range, the preset threshold number is increased, maintained, or decreased according to corresponding rules. Fifth, operations are recorded and traced. The entire lifecycle operation information of the key is recorded, and a corresponding hash digest is generated using a quantum-resistant hash algorithm and stored in a distributed manner for subsequent auditing and tracing.
[0050] See Figure 3 The system comprises eight functional modules: a quantum-resistant key generation module, a key sharding encryption module, an authorized node management module, a secure multi-party computation module, a dynamic threshold adjustment module, a secure storage module, a quantum-resistant verification module, and a log auditing module. Each module performs its specific function, responsible for root key generation, key share splitting and encryption, full-process management of authorized nodes, establishment of encrypted communication channels and collaborative computation, dynamic adjustment of threshold quantity, secure storage and backup / recovery of key shares, verification of node identity and operation commands, and recording of operation information and generation of hash digests. Together, they support the implementation of the aforementioned key management methods, ensuring the quantum-resistant security and dynamic adaptability of digital asset keys throughout their entire lifecycle.
[0051] Example 1
[0052] This embodiment applies to the key management scenario of cryptocurrency transactions in financial institutions. Cryptocurrency transactions involve multiple business nodes of financial institutions, third-party compliance audit nodes, and nodes from different business lines of the trading platform. As an important value carrier in the digital economy era, the security of cryptocurrency keys directly affects the asset ownership and transaction compliance of both parties. With the rapid iteration of quantum computing technology, traditional encryption algorithms that rely on large integer factorization and discrete logarithm problems face the risk of being efficiently cracked. Furthermore, in financial transaction scenarios, nodes are widely distributed, the network environment is complex and changeable, and there are differences in node operating status and reputation. Therefore, there is an urgent need for a key management solution with quantum attack resistance, a decentralized management model, and the ability to dynamically adapt to node status. This embodiment achieves secure and efficient management of cryptocurrency transaction keys throughout their entire lifecycle through a quantum-resistant digital asset key management method and system. See [link to relevant documentation]. Figure 1 , Figure 2 and Figure 3 The specific details are as follows:
[0053] First, the root key generation and key share encryption were carried out. Based on the security level of cryptocurrencies, a hash-based cryptography algorithm was selected as the core quantum-resistant cryptographic algorithm. This algorithm has undergone security strength testing by authoritative encryption technology evaluation institutions and can meet the key security requirements of highly sensitive financial assets. During the root key generation process, quantum random numbers were introduced as key seeds. These quantum random numbers underwent professional entropy value testing to ensure extremely high randomness and unpredictability, laying the foundation for the security of the root key. Following the sharding rules of threshold signature technology, the generated root key was divided into a predetermined number of key shares. Each key share was individually encrypted using a quantum-resistant encryption algorithm of the same type as the hash-based cryptography algorithm. The encryption process incorporated the unique identifier of each authorized node, generating a dedicated encryption key to ensure that each key share can only be decrypted and used by its corresponding authorized node.
[0054] The generation of the root key satisfies the formula In the specific implementation process of this embodiment, The root key for cryptocurrency transactions. For quantum-resistant hash functions, This is the core parameter matrix of the hash-based cryptography algorithm. For quantum random numbers, A quantitative value for the security level of cryptocurrencies. , , These are the weighting coefficients. Based on the security strength test results of the hash-based cryptographic algorithm, it was determined that... The entropy detection result is set based on quantum random numbers. All three parameters are fixed values certified by authoritative encryption technology evaluation institutions, and are calibrated in accordance with the security grading standards of the digital asset industry.
[0055] Next, the key shares are distributed and securely stored. In this embodiment, the authorized nodes cover business nodes at all levels of financial institutions participating in cryptocurrency transactions, third-party compliance audit nodes, and nodes from different business lines of the trading platform. Before obtaining a key share, each authorized node must complete identity registration and qualification verification through the authorized node management module. The verification includes the node's compliance operation qualifications, security protection system construction, business authorization documents, etc. After the verification is passed, a unique identity identifier and corresponding operation permissions are assigned to each node, clarifying the key operation scope and permission boundaries of different nodes.
[0056] The encrypted key shares are distributed to the aforementioned authorized nodes. Each authorized node stores the received key shares in a local hardware-encrypted storage medium, which possesses characteristics such as tamper-proof, leak-proof, and resistance to physical attacks. Simultaneously, a robust access control mechanism is implemented, including authentication, tiered access permissions, and local recording of operation logs. Only accounts that have been authenticated and possess the corresponding access permissions can access the key shares. The operation logs record detailed information such as the accessing account, access time, operation content, and operation result, providing complete evidence for subsequent security audits.
[0057] The key collaboration process then proceeds. When key generation, updating, or revocation is required, at least a preset threshold of authorized nodes must jointly initiate a collaboration request. The authorized node initiating the collaboration request sends detailed operation instructions and its own identity information to other qualified authorized nodes, along with a quantum-resistant signature generated based on a quantum-resistant cryptographic algorithm to ensure the legitimacy of the request source and the integrity of the instructions. The authorized nodes receiving the request rigorously verify the initiating node's identity information and operation instructions using a quantum-resistant signature verification algorithm. The verification includes the validity of the initiating node's identity identifier and the compliance and completeness of the operation instructions. Upon successful verification, the local key share decryption process is initiated.
[0058] Each verified participating node establishes an encrypted communication channel through a secure multi-party computation protocol. This channel employs quantum-resistant encryption technology to ensure data transmission security. Without exposing the complete key and key share in plaintext, each node collaboratively decrypts its own key share and completes the computation to generate an accurate key operation result. Finally, the key operation result is confirmed with a quantum-resistant signature to ensure that the result has not been tampered with. After confirmation, subsequent activation procedures are executed, ensuring the security and validity of the key operation.
[0059] Next, dynamic adjustments to the threshold numbers were implemented. First, scientifically sound and reasonable reputation scoring ranges and corresponding threshold adjustment rules were established. The reputation scoring ranges were divided into multiple levels based on scores, with different levels corresponding to different threshold adjustment ranges, ensuring the precision and operability of the adjustment rules. Historical operational compliance, network connection stability, and security protection status indicators were collected for each authorized node. Historical operational compliance indicators primarily examined whether the node's past key operations complied with industry standards and system rules. Network connection stability indicators focused on the frequency of connection interruptions and data transmission delays during transaction periods. Security protection status indicators included the node's security vulnerability remediation status, the level of its anti-attack system construction, and the timeliness of security patch updates.
[0060] Each node is independently scored based on the above indicators. The overall reputation score is obtained by summing the reputation scores of all authorized nodes. The overall reputation score is calculated according to the formula. In the specific implementation process of this embodiment, For overall credit rating, Scoring for compliance of historical operations Rate the network connection stability. To score the safety protection status, , , The weights are the indicator weights. , , The scoring model was determined by combining the Analytic Hierarchy Process (AHP) with industry security standards for digital asset key management. It was then finalized after multiple rounds of review and calibration by industry technical experts to ensure the scientific validity and authority of the scoring model.
[0061] Determine the overall reputation score's corresponding score range and adjust the preset threshold quantity according to the threshold adjustment rules for that range. When the overall reputation score is in a low-level range, it indicates that some nodes may have security risks or compliance issues. In this case, increase the preset threshold quantity to reduce the risk of keys being illegally manipulated. When the overall reputation score is in a high-level range, it indicates that each node is operating well and has a high reputation level. Maintain or decrease the preset threshold quantity to improve the efficiency of key operations.
[0062] Threshold quantity adjustment satisfies the formula In the specific implementation process of this embodiment, The adjusted preset threshold number, The initial baseline threshold number, As a preset reference credit score, This is for adjusting the coefficient. Based on statistical analysis of historical node failure data and key operation success rates, a fixed calibration value was determined to ensure the reasonableness of the adjustment range. After adjustment, the new threshold number will be synchronously communicated to all authorized nodes to ensure consistency in subsequent collaborative operations among all nodes.
[0063] Finally, operation recording and traceability are performed. All operational information throughout the key's entire lifecycle is comprehensively recorded, including operation node identifier, operation type, operation initiation time, operation execution duration, operation result status, and a list of participating nodes, ensuring the integrity and accuracy of the operation information. A quantum-resistant hash algorithm is used to generate a hash digest of the above operational information. The hash digest corresponds one-to-one with the operational information, effectively preventing tampering of the operational information.
[0064] By employing a distributed storage approach, hash digests are distributed across authorized nodes, avoiding the single point of failure risk associated with centralized storage and improving storage security and reliability. When security audits or activity tracing are required, the stored hash digests and operation information are retrieved through the log audit module to verify the integrity and authenticity of the information. This enables clear traceability of the entire key operation process, ensuring the compliance and traceability of cryptocurrency transaction key management.
[0065] In summary, this embodiment successfully addresses the problems of single point of failure, insufficient resistance to quantum attacks, and inability to dynamically adapt to node states inherent in traditional key management schemes by applying a quantum-resistant digital asset key management method and system in the context of cryptocurrency transaction key management in financial institutions. The organic combination of quantum-resistant cryptographic algorithms and threshold signature technology completely eliminates the centralized control model of a single institution; even if some nodes are compromised, the complete key cannot be obtained, greatly reducing the risk of key leakage. The synergistic application of secure multi-party computation protocols and quantum-resistant encrypted storage and transmission mechanisms constructs a comprehensive security protection system, ensuring quantum-resistant security throughout the key's entire lifecycle. The node reputation assessment and dynamic threshold adjustment mechanism achieve a dynamic balance between key management security and availability, improving key operation efficiency while ensuring security.
[0066] Example 2
[0067] This embodiment applies to the key management scenario of an enterprise digital asset trading platform. This platform aggregates a large number of enterprise users' digital assets, including digital copyrights and digital collectibles, involving multiple business line nodes, third-party technical service nodes, and compliance audit nodes within the enterprise. Digital asset transactions are frequent and fast-moving, and the nodes are diverse with varying levels of security protection. Traditional key management solutions struggle to meet the balance between security and efficiency under high-frequency trading, and also face risks from quantum computing attacks and malicious node operations. Therefore, a key management solution that balances quantum resistance, security, efficient collaborative operation, and dynamic risk control is urgently needed. This embodiment achieves secure key control throughout the entire enterprise digital asset trading process through an optimized quantum-resistant digital asset key management method and system. (See [link to relevant documentation]). Figure 1 , Figure 2 and Figure 3 The specific details are as follows:
[0068] This embodiment, based on the aforementioned embodiments, optimizes the process to address the high-frequency characteristics of enterprise digital asset transactions. It first performs root key generation and key share encryption. Depending on the security level of the digital assets, some high-value digital assets use encoding-based cryptographic algorithms, while ordinary-value digital assets use hash-based cryptographic algorithms. Both algorithms have been certified by authoritative encryption technology evaluation institutions.
[0069] When generating the root key, a quantum random number that has undergone entropy testing is introduced as a seed. The root key is split into a predetermined number of key shares according to the threshold signature technology's sharding rules. Each share is encrypted using a quantum-resistant encryption algorithm compatible with the root key generation algorithm. The encryption process incorporates the unique identifier of the authorized node to generate a dedicated key. The generation of the root key satisfies the formula... In the specific implementation of this embodiment, the formula strictly follows the parameter setting logic of the aforementioned embodiment to ensure the security and consistency of the root key generation.
[0070] In the key share distribution and storage process, authorized nodes cover enterprise business line nodes, third-party technical service nodes, and compliance audit nodes. Each node needs to complete identity registration and qualification review. The review focuses on technical service qualifications, data security assurance capabilities, and transaction compliance commitments. After the review is passed, a unique identity identifier and operation permissions are assigned.
[0071] Each node stores the encrypted key share on a local hardware-encrypted storage medium. In addition to its tamper-proof and leak-proof features, this medium includes a real-time key share backup mechanism. Backup data is encrypted using a quantum-resistant encryption algorithm and stored on a remote backup node. Simultaneously, an enhanced access control mechanism is enabled. Building upon the existing hierarchical operation log recording system with tiered authentication permissions, multi-factor authentication is added. Only accounts that pass multi-factor authentication and have matching permissions can access the key share, and operation logs are synchronized to the distributed storage nodes in real time.
[0072] The key collaboration operation process is optimized for high-frequency trading scenarios. When a key generation, update, or revocation operation is initiated, a preset threshold number of authorized nodes quickly initiate a collaboration request through a dedicated communication interface. The request information includes the operation instruction's identity information and a quantum-resistant signature. The receiving node quickly verifies the identity's legitimacy and the instruction's integrity using a quantum-resistant signature verification algorithm. After successful verification, it initiates a fast decryption process for its local key share. This process optimizes the decryption algorithm's computational logic, reducing decryption time.
[0073] Each verified node establishes a low-latency encrypted communication channel through a secure multi-party computation protocol. Employing a lightweight collaborative computation algorithm, it rapidly generates operation results without exposing the full key or key share in plaintext. After the operation results are confirmed by a quantum-resistant signature, the activation process is executed through a priority scheduling mechanism, ensuring efficient key operations in high-frequency trading scenarios.
[0074] The dynamic adjustment of thresholds further refines the scoring indicators and adjustment rules. In addition to the three main indicators of historical operational compliance, network connectivity stability, and security protection status, a new indicator, transaction response timeliness, has been added to the reputation scoring system. More precise reputation scoring ranges and corresponding threshold adjustment rules have been established, with each scoring level corresponding to a clearly defined adjustment range.
[0075] The overall reputation score is obtained by aggregating the scores of all authorized nodes across various metrics. The overall reputation score is calculated according to the formula... In the specific implementation of this embodiment, the weights of the newly added indicators are determined by combining the analytic hierarchy process with industry standards, and together with the weights of the original indicators, they constitute a complete weight system.
[0076] The preset threshold number is adjusted based on the overall credit score range, and the threshold adjustment satisfies the formula. In the specific implementation of this embodiment, the adjustment coefficient is calibrated by combining node failure data and operation success rate statistics in high-frequency trading scenarios. When the overall reputation score is in the low-level range, the number of thresholds is significantly increased and the node security verification mechanism is triggered; when it is in the medium-level range, the number of thresholds is moderately increased; when it is in the high-level range, the number of thresholds is reduced to improve operational efficiency, and the adjustment results are synchronized to all authorized nodes in real time.
[0077] The operation logging and traceability process enhances information integrity and traceability efficiency. Recorded operation information is updated to include transaction association identifiers and operation permission levels, ensuring accurate traceability of key operations for each transaction. A quantum-resistant hash algorithm generates hash digests for operation information, with each digest corresponding to a specific operation. A triple storage approach—local storage, distributed backup, and blockchain notarization—is employed. Local storage ensures fast retrieval, distributed backup prevents data loss, and blockchain notarization ensures information immutability. When security audits or behavior tracing are required, the log audit module, in conjunction with the triple storage nodes, quickly retrieves and verifies relevant information, achieving efficient traceability of the entire key operation process and meeting the compliance auditing needs of enterprise digital asset transactions.
[0078] In summary, this embodiment, through scenario optimization for enterprise digital asset trading platforms, further improves the efficiency and adaptability of key management based on the aforementioned embodiments, effectively solving the problem of balancing security and efficiency in high-frequency trading scenarios. By selecting differentiated quantum-resistant cryptographic algorithms and applying lightweight collaborative computing algorithms, key operation speed is significantly improved while ensuring quantum-resistant security, meeting the needs of high-frequency trading. The newly added backup mechanism, multi-factor authentication, and blockchain evidence storage further enhance the security of key storage and operation records. The refined reputation scoring system and dynamic threshold adjustment rules improve the accuracy of node risk control.
[0079] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. A method for digital asset key management based on anti-quantum computing, characterized in that, The method comprises the following steps: S1, generating a digital asset root key by using an anti-quantum cryptographic algorithm, and splitting the root key into multiple key shares based on a threshold signature technology, each key share being encrypted by an anti-quantum encryption algorithm; S2, distributing the encrypted key shares to multiple authorized nodes respectively, and storing the received key shares in a local secure storage unit and enabling an access control mechanism by each authorized node; S3, when performing a key generation, update or revocation operation, at least a preset threshold number of authorized nodes are required to initiate a collaborative request, each participating node decrypts the key share held by itself through a secure multi-party computation protocol, and collaboratively completes the corresponding key operation, and the node identity and operation instruction are verified by an anti-quantum signature during the operation process; S4, collecting historical operation compliance, network connection stability and security protection state related indicators of each authorized node, scoring the reputation of each node, and dynamically adjusting the preset threshold number according to the overall reputation score of all authorized nodes; S5, recording the operation behavior information in the whole life cycle of the key, generating a hash digest of the operation behavior information through an anti-quantum hash algorithm, and storing it for subsequent security audit and behavior traceability.
2. The anti-quantum computing based digital asset key management method of claim 1, wherein, The step S1 comprises the following steps when generating a digital asset root key by using an anti-quantum cryptographic algorithm and performing fragmentation encryption: According to the security level of the digital asset, a corresponding anti-quantum cryptographic algorithm is selected, a digital asset root key is generated based on the key generation rule of the algorithm, and a quantum random number is introduced as a key seed during the generation process; The root key is split into a preset number of key shares based on the fragmentation rule of the threshold signature technology, and an anti-quantum encryption algorithm is used for each key share to perform encryption processing, and a special encryption key is generated in combination with the unique identity of each authorized node during the encryption process.
3. The anti-quantum computing based digital asset key management method of claim 1, wherein, The step S3 comprises the following steps when each participating node collaboratively completes the corresponding key operation through a secure multi-party computation protocol: The authorized node initiating the collaborative request sends the operation instruction and its own identity information to other authorized nodes meeting the conditions, and attaches an anti-quantum signature; The authorized node receiving the request verifies the identity information and operation instruction of the initiating node through an anti-quantum signature verification algorithm, and starts the local key share decryption process after verification; Each participating node that has passed the verification establishes an encrypted communication channel through a secure multi-party computation protocol, completes collaborative computation without exposing the complete key and key share plaintext, and generates a key operation result; After the key operation result is confirmed by an anti-quantum signature, the subsequent validation process is performed.
4. The anti-quantum computing based digital asset key management method of claim 1, wherein, The step S4 comprises the following steps when dynamically adjusting the preset threshold number according to the overall reputation score: Set the reputation score interval and the corresponding threshold adjustment rule, the reputation score interval is divided into multiple levels according to the score, and different levels correspond to different threshold adjustment amplitudes; The overall reputation score is obtained by aggregating the reputation scores of all authorized nodes, and the reputation score interval to which the overall reputation score belongs is determined; Adjust the preset threshold number according to the threshold adjustment rule corresponding to the score interval, increase the preset threshold number when the overall reputation score is in the low level interval, maintain or reduce the preset threshold number when it is in the high level interval, and adjust the preset threshold number after adjustment. Synchronously inform all authorized nodes.
5. The anti-quantum computing based digital asset key management method of claim 1, wherein, The anti-quantum encryption algorithm used in the step S1 includes one or more of lattice-based encryption algorithms, hash-based encryption algorithms, and encoding-based encryption algorithms, and the anti-quantum encryption algorithm used in the step S1 for encrypting the key share is of the same type or compatible type as the anti-quantum encryption algorithm used for generating the root key.
6. The anti-quantum computing based digital asset key management method of claim 1, wherein, The local secure storage unit of each authorized node in the step S2 uses a hardware encryption storage medium, and the access control mechanism enabled in the step S2 includes identity authentication, operation permission grading, and local operation log recording function. Only accounts that pass identity authentication and have corresponding operation permissions can access the key share.
7. The anti-quantum computing based digital asset key management method of claim 1, wherein, The operation behavior information recorded in the step S5 within the entire life cycle of the key includes operation node identification, operation type, operation initiation time, operation execution duration, operation result status, and node list participating in collaborative operation. The hash digest generated by the anti-quantum hash algorithm in the step S5 corresponds to the operation behavior information one by one, and is stored in a distributed storage manner and stored in each authorized node.
8. The anti-quantum computing based digital asset key management method of claim 1, wherein, The authorized nodes include various business nodes of financial institutions, third-party compliance audit nodes, and different business line nodes of enterprises. Each authorized node needs to complete identity registration and qualification audit before obtaining the key share distributed in the step S2. After passing the audit, a unique identity is assigned and corresponding operation permissions are assigned.
9. A quantum-resistant digital asset key management system adapted to the quantum-resistant digital asset key management method of any one of claims 1-8, characterized in that, The system includes: an anti-quantum key generation module, a key fragment encryption module, an authorized node management module, a secure multi-party computation module, a dynamic threshold adjustment module, a secure storage module, an anti-quantum verification module, and a log audit module. The anti-quantum key generation module is used to generate a digital asset root key using an anti-quantum encryption algorithm, and a quantum random number is introduced as a key seed during the generation process. The key fragment encryption module is used to split the root key into multiple key shares based on threshold signature technology, and encrypt each key share using an anti-quantum encryption algorithm. The authorized node management module is used for registration, qualification audit, identity authentication, permission configuration, and identity assignment of authorized nodes. The secure multi-party computation module is used to build an encrypted communication channel and support authorized nodes to collaboratively complete key operations through a secure multi-party computation protocol. The dynamic threshold adjustment module is used to collect authorized node related indicators and perform reputation scoring, and dynamically adjust the preset threshold number according to the overall reputation score. The secure storage module is used to encrypt and store key shares, and is equipped with an access control mechanism. The anti-quantum verification module is used to verify node identity and operation instructions through an anti-quantum signature algorithm. The log audit module is used to record operation behavior information and generate an anti-quantum hash digest, and provides audit and traceability support.
10. The anti-quantum computing based digital asset key management system of claim 9, wherein, The secure storage module adopts a hardware encryption storage medium, is internally provided with a key share anti-leakage mechanism, includes data encryption storage, access behavior monitoring, and abnormal access alarm functions, and simultaneously supports backup and recovery of key shares, the backup process adopts an anti-quantum encryption algorithm to encrypt backup data, and verification through multiple nodes is required during recovery.