Personal data asset protection method, device, equipment, medium and product

By employing a dual-chain architecture based on blockchain technology, combined with encrypted sharded storage and smart contracts, the security and copyright protection issues of traditional cloud storage are resolved. This achieves secure data storage, reliability, and protection of creators' rights, while providing an automated copyright protection and revenue distribution mechanism.

CN121765762APending Publication Date: 2026-03-31CHINA MOBILE INTERNET CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-23
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Traditional cloud storage relies on centralized server storage, which poses risks of single points of failure and hacker attacks. Copyright protection lacks a transparent traceability mechanism, originality is difficult to verify, rights protection relies on manual evidence collection and the process is complicated, the use of works cannot be tracked, and there is a lack of automated revenue distribution mechanism, resulting in insufficient protection of creators' rights.

Method used

It adopts a dual-chain architecture based on blockchain technology. The security chain manages permissions and copyright information, while the storage chain is responsible for distributed storage. It protects data security and integrity through encryption technology, automatically executes copyright terms and handles infringement through smart contracts, and achieves reliable data storage and high availability. It also uses disk locking functions to encrypt and lock storage resources.

Benefits of technology

It ensures that the data stored on the blockchain for original works is secure and does not leak, that storage is reliable and does not lose data, that resources are controllable and do not waste resources, and that rights are protected and do not infringe on rights, thus ensuring the copyright income and data security of creators.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121765762A_ABST
    Figure CN121765762A_ABST
Patent Text Reader

Abstract

The invention relates to a personal data asset protection method and device, equipment, a medium and a product in the technical field of block chains. The method comprises the following steps: in response to an uplink request of a user requesting to store an original work, processing an original file of the original work to obtain encrypted fragments, and storing the encrypted fragments in a storage chain agent node in a distributed manner; and triggering a disk closing function in the security chain smart contract, and performing encryption locking on a disk space required for storing the original work in the storage chain agent node. According to the method, the encryption fragments are stored in the storage chain agent node in a distributed manner, so that the problems of secure storage and high availability of data are solved, and the problems of exclusive management and control and compliance release of storage resources are further solved by triggering the disk closing function in the security chain smart contract; the data security of the original work uplink storage and the controllability and no waste of storage resources are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of blockchain technology, and in particular to a method, apparatus, device, medium, and product for the protection of personal data assets. Background Technology

[0002] In the digital age, personal cloud storage has become a primary platform for users to store and share their personal digital assets. With the growth in cloud storage usage, security and copyright protection have become increasingly important. Currently, traditional cloud storage applications rely on centralized servers to store user files, which poses single points of failure and hacker attacks, making data vulnerable to attack and leakage. Furthermore, existing copyright protection methods (such as digital watermarking) lack transparent traceability mechanisms, making originality difficult to verify, and rights protection relies on manual evidence collection and is a complex process. Simultaneously, the use of works cannot be tracked, and there is a lack of automated revenue distribution mechanisms, resulting in insufficient protection of creators' rights. Summary of the Invention

[0003] To address the aforementioned technical problems, this disclosure provides a method, apparatus, device, medium, and product for protecting personal data assets, thereby achieving reliable storage and protection of personal data assets.

[0004] A first aspect of this disclosure provides a method for protecting personal data assets, the method comprising: In response to a user's request to store original works on the blockchain, the original files of the original works are processed to obtain encrypted fragments which are then distributed and stored on the storage chain proxy nodes. Trigger the disk locking function in the security chain smart contract to encrypt and lock the disk space required to store the original work within the storage chain proxy node.

[0005] A second aspect of this disclosure provides an apparatus for protecting personal data assets, the apparatus comprising: The storage module is configured to respond to user requests to store original works on the blockchain by processing the original files of the original works to obtain encrypted fragments and distributing them on the storage chain proxy nodes. The encryption module is configured to trigger the disk locking function in the security chain smart contract to encrypt and lock the disk space required to store the original work within the storage chain proxy node.

[0006] A third aspect of this disclosure provides an electronic device, comprising: At least one processor; Memory for storing the at least one processor-executable instruction; The at least one processor is used to execute the instructions to implement the above-described method.

[0007] A fourth aspect of this disclosure provides a computer-readable storage medium that, when instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform the methods described above.

[0008] A fifth aspect of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the above-described method for protecting personal data assets.

[0009] The above-mentioned at least one technical solution adopted in the embodiments of this disclosure can achieve the following beneficial effects: By distributing encrypted shards to storage chain proxy nodes, the embodiments of this disclosure solve the problems of secure data storage and high availability, and further solve the problems of dedicated management and compliant release of storage resources by triggering the disk closing function in the security chain smart contract, thus realizing the data security of original works stored on the chain without leakage, reliable storage without loss, controllable resources without waste, and protected rights without infringement. Attached Figure Description

[0010] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0011] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 A schematic flowchart of a method for protecting personal data assets provided in this disclosure embodiment; Figure 2 A schematic flowchart illustrating another method for protecting personal data assets provided in this disclosure embodiment; Figure 3 A schematic diagram illustrating another method for protecting personal data assets provided in this disclosure embodiment; Figure 4 This disclosure provides a schematic diagram of the structure of a device for protecting personal data assets; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure; Figure 6 This is a schematic diagram of the structure of an exemplary computer system provided in an embodiment of the present disclosure. Detailed Implementation

[0013] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0014] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.

[0015] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0016] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0017] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0018] Traditional cloud storage applications rely on centralized servers to store user files, which poses a single point of failure and the risk of hacker attacks, making data vulnerable to attacks and leaks. Furthermore, existing copyright protection methods (such as digital watermarking) lack transparent traceability mechanisms, making it difficult to verify originality, and rights protection relies on manual evidence collection and is a complex process. At the same time, the use of works cannot be tracked, and there is a lack of automated revenue distribution mechanisms, resulting in insufficient protection of creators' rights.

[0019] Currently, cloud storage and blockchain technology for storing original works mainly fall into two categories: peer-to-peer distributed file storage systems and file storage systems based on block weaving technology. Peer-to-peer distributed file storage systems provide a short-term, unreliable but highly efficient file storage capability through peer-to-peer distributed storage technology and caching techniques. However, they do not guarantee data persistence because file availability depends on the storage availability of nodes in the network. If no other nodes are storing the data, it may be lost if a storage node goes offline. File storage systems based on block weaving technology, on the other hand, provide permanent and reliable persistent storage. Through their unique block weaving technology, they ensure that once data is stored, it cannot be changed or deleted, achieving data permanence and immutability. However, because they require redundant backups of multiple files to ensure files are not lost, storage costs are higher, and their data retrieval efficiency is not as good as peer-to-peer distributed file systems.

[0020] This disclosure presents a personal digital asset protection scheme based on a dual-chain architecture using blockchain technology, aiming to address the technical problems of traditional cloud storage in areas such as data security and copyright protection. The dual-chain architecture mainly comprises two parts: a security chain and a storage chain.

[0021] Security Chain: Used to manage file permissions, copyright information, and transaction records. It uses smart contracts to automatically enforce copyright terms and handle infringement.

[0022] Storage chain: Responsible for distributed storage of file data. It ensures persistent storage of file data and protects data security and integrity through encryption technology.

[0023] The advantage of this dual-chain architecture lies in separating data storage and management, allowing each chain to focus on its core functions, improving the efficiency and security of the entire system, while ensuring creators' copyright revenue.

[0024] The following is combined Figures 1-6 This disclosure describes the methods, apparatus, devices, media, and products for protecting personal data assets provided in the embodiments of this disclosure.

[0025] Figure 1 This is a schematic flowchart illustrating a method for protecting personal data assets provided in an embodiment of this disclosure, as shown below. Figure 1 As shown, the method includes: S101. In response to the user's request to store the original work on the blockchain, the encrypted fragments obtained by processing the original file of the original work are distributed and stored in the storage chain proxy node. Users complete the local creation of original content and send a request to store the original work on the blockchain through the blockchain cloud storage client; Users access the security chain and complete the preprocessing of the original files of their original works, as well as the on-chain storage of copyright information; The storage chain proxy nodes process the original files of the original work to obtain encrypted fragments, which are then distributed for storage. These storage chain proxy nodes are selected based on a Delegated Proof of Stake (DPoS) mechanism.

[0026] S102. Trigger the disk locking function in the security chain smart contract to encrypt and lock the disk space required for storing the original work within the storage chain proxy node.

[0027] After the smart contract detects that a storage task has been assigned to a proxy node, it automatically calls the disk shut-down function. The function encrypts and locks the disk space required for a node storage shard, retaining only write / read permissions for that shard until the user requests deletion.

[0028] This disclosed embodiment solves the problems of secure data storage and high availability by distributing encrypted shards to storage chain proxy nodes. Furthermore, by triggering the disk closing function in the secure chain smart contract, it solves the problems of dedicated management and compliant release of storage resources, thus achieving data security without leakage, reliable storage without loss, controllable and waste-free resources, and protected rights without infringement when storing original works on the chain.

[0029] Figure 2 A schematic flowchart illustrating another method for protecting personal data assets provided in this disclosure embodiment is shown below. Figure 2 As shown, the method includes: S200, User-created original works; Users create original content locally (e.g., engineering drawings, written documents, videos, etc.).

[0030] For example, users create original content on their local devices (computers / mobile phones) using professional software; after creation, they save it as a standard format file (e.g., .dwg, .docx, .mp4, etc.) and temporarily store it on local storage (e.g., computer's D drive).

[0031] It should be noted that the files of original works created by users must be in complete, unencrypted original format. The client / storage chain will handle the fragmentation and encryption later, and no additional technical operations are required during the creation stage.

[0032] S201. Connect to the security chain and complete the preprocessing of the original files of the original work; Users access the secure chain through the blockchain cloud storage client (hereinafter referred to as the client) and gradually complete the preparation for uploading original work files, specifically including the following steps: S2011, Secure Link In; Users open the client, complete identity authentication, and successfully connect to the security chain.

[0033] S2012, Metadata Submission; The client collects the original file's metadata (format, size, title) and submits it to the secure chain smart contract; S2013, Preparation for uploading original files; The client temporarily stores the complete, unencrypted original file in the local cache, awaiting instructions from the storage chain storage task.

[0034] S202, Generate a unique hash value and digital fingerprint for the file; The secure chain smart contract generates a unique hash value and digital fingerprint of the file based on the work metadata of the original work and the content of the original file.

[0035] Based on the original work's metadata and the file hash preprocessing information submitted on the client, the system calls the EVM (Ethereum Virtual Machine)'s built-in hash function (the native Keccak256 function) to generate a 32-byte unique file hash value (fileHash).

[0036] Understandably, the digital fingerprint (hash file) consists of fileHash and work metadata hash, stored in a secure blockchain smart contract, serving as the file's "digital identity credential".

[0037] S203, On-chain deduplication verification to check file uniqueness; This step uses fileHash retrieval, where the secure chain smart contract determines whether the unique hash value of the received file already exists in the hash value list, in order to confirm whether the same content does not exist on the chain.

[0038] To avoid wasting storage chain resources through duplicate storage and to provide a unique basis for subsequent copyright registration, ensuring that the same file is not verified multiple times, the security chain smart contract uses hash value comparison to determine whether a file is unique.

[0039] After receiving the fileHash generated in step S202, the security chain smart contract determines whether the fileHash already exists in the hash value list (fileHashRecord). If it exists, it returns "The file has been certified and does not need to be certified again"; if it does not exist, it proceeds to the subsequent copyright certification process.

[0040] Understandably, due to the collision resistance of hash functions, the probability of different files generating the same fileHash is extremely low. Therefore, the search results can be directly used as the basis for determining the uniqueness of files.

[0041] S204. Copyright information is stored on the blockchain; The copyright information of original works is associated with and stored in a secure chain, that is, the copyright information is bound to the fileHash to generate an immutable "digital copyright certificate". The specific steps include: S2041, Copyright Information Collection; The client automatically collects copyright information.

[0042] Copyright information includes, but is not limited to, the following: author information (blockchain account address, real-name authentication information), creation timestamp (local creation completion time, security chain on-chain timestamp), and work metadata (file format, size, title).

[0043] S2042. Generate a digital signature; Users sign the above copyright information using their blockchain account private key to generate a digital signature (the core evidence proving copyright ownership). S2043, Copyright Registration Assembly; The secure chain smart contract associates fileHash, copyright information, and digital signature (Signature) to assemble a copyright certificate, writes it to the mapping fileHashRecord [fileHash], and completes the on-chain storage of copyright information.

[0044] Among them, fileHashRecord[fileHash] is a "key-value pair storage structure" that uses the file's unique hash value (fileHash) as the index key. It is a mapping data type defined in the smart contract. Its core function is to bind and store the fileHash (unique index) with all the associated data (copyright information, hash file, storage association information, etc.) corresponding to the file, thereby realizing the function of quickly retrieving the full information of the file through fileHash.

[0045] Among them, fileHash, as a unique identifier for content, becomes an "unalterable digital copyright certificate" after being strongly bound to copyright information, and can serve as key evidence for judicial rights protection.

[0046] It should be noted that, in order to ensure that only nodes with high service capacity undertake core storage tasks in the storage chain, it is necessary to screen proxy nodes. Therefore, the above methods also include: S205. Filtering proxy nodes based on the improved DPoS mechanism; Specifically, the following steps are included: S2051, Node Qualification Pre-screening; All nodes in the storage chain undergo pre-qualification to filter out invalid nodes.

[0047] Specifically, all nodes in the storage chain submit basic access materials (staking tokens, hardware thresholds, compliance qualifications) to filter out invalid nodes.

[0048] S2052, Multi-dimensional parameter scoring; The core parameters include: node available disk size score (S), node data encryption speed score (E), node cross-block access capability score (A), and node historical service quality score (H).

[0049] Quantitative scoring: S = (Average available disk space per node / Maximum available disk space per node in the network) × 100; E = (Actual encryption speed of the node / Average encryption speed of the industry) × 100; A = (Base access time / Node's actual access time to random blocks) × 100; H = (Node uptime - Failure time × Weight) / Total uptime × 100.

[0050] Weighted overall score: Storage_Capacity_Score =(S×ωS)+(E×ωE)+(A×ωA)+(H×ωH); Wherein, ωS is the weight of available disk size; ωE is the weight of data encryption speed; ωA is the weight of the ability to access other blocks; and ωH is the weight of historical records.

[0051] For example, the weights can be assigned as follows: ωS: 0.4 (A larger storage space is important for storage capacity); ωE: 0.2 (Encryption speed determines data security and write efficiency); ωA: 0.2 (The ability to access blocks affects data retrieval and network synchronization); ωH: 0.2 (A good historical record indicates the server's reliability).

[0052] S2053, Dynamic ranking and recommendation of agent nodes; Rank the nodes in descending order of their overall scores, and select the top N (e.g., the top 100) as agent nodes, which are then written into the agent node list (agentNodeList) of the security chain smart contract.

[0053] Based on the improved DPoS mechanism, proxy nodes are selected to provide node support for distributed storage.

[0054] S206, Minimum Redundancy Algorithm for Data Sharding and Task Allocation; The storage chain completes data sharding and node allocation based on the minimum redundancy guarantee algorithm. Therefore, step S206 includes: S2061, Input initialization; Data object D = the original file to be uploaded by the user; Node list N = the list of proxy nodes filtered out in step S205; Backup factor BF=3 (can be dynamically adjusted, such as set to 2-5 according to file importance).

[0055] S2062, Data Fragmentation; The storage chain divides the original file D into n sub-blocks S={S1, S2, ..., Sn} (8192 sub-blocks by default, which can be dynamically adjusted according to the file size), which facilitates parallel storage and processing. S2063, Hybrid encryption processing; The storage chain master node generates a symmetric key SK using the first encryption algorithm, encrypts each sub-block to generate encrypted fragments, and synchronously generates an initialization vector IV and an authentication tag; it then uploads the encrypted key E generated by encrypting the symmetric key SK using the second encryption algorithm to the security chain smart contract storage.

[0056] For example, the storage chain master node generates an AES-256-GCM symmetric key SK, encrypts each sub-block to generate encrypted fragments, and synchronously generates an initialization vector IV (12 bytes) and an authentication tag (16 bytes); at the same time, it encrypts SK using the RSA-2048 algorithm to generate an encryption key E (SK), and uploads it to the security chain smart contract storage. S2064, Fragmented hash calculation; The storage chain calls the first function to calculate the hash value of each encrypted shard, obtains the shard hash, packages it, and submits it to the security chain smart contract; for example, the first function is the Keccak256 function.

[0057] Understandably, the fragment hash is generated directly from the byte content of the encrypted fragment and is the unique digital fingerprint of the encrypted fragment. Any minor modification to the encrypted fragment (transmission tampering, storage corruption, malicious replacement) will result in a completely different fragment hash.

[0058] S2065, Node Selection; Randomly select BF nodes from N to determine the master node and backup node for each encrypted shard Si. S2066, Task instruction generation; The security chain smart contract integrates fileHash, number of shards, list of master / backup nodes, and E (SK) to generate storage task allocation instructions and send them to the storage chain.

[0059] In this embodiment, redundant storage is achieved by using the minimum redundancy guarantee algorithm based on DPoS-selected proxy nodes; the backup factor BF balances redundancy overhead and data availability, avoiding excessive backups that waste resources.

[0060] S207. Request to upload the original file of the original work to the storage chain; Specifically, the following steps are included: S2071, Upload triggered; The user initiates an upload request to the client, and the client uploads the complete original file to the designated master node according to the storage chain instructions.

[0061] S2072, File Receipt and Verification; After receiving the original file, the storage chain master node verifies the file's integrity (by comparing it with the hash of the work's metadata stored in the security chain) and sends the reception status back to the security chain.

[0062] S208, Distributed Storage and Security Management; The storage chain persistently stores the encrypted fragments obtained from data sharding on the proxy nodes. The storage chain completes the persistent storage and security hardening of the encrypted fragments, specifically including the following steps: S2081, Fragmented Distribution; The master node distributes the encrypted shards, IVs, and tags to BF-1 backup nodes.

[0063] S2082, Merkle tree construction; The master node constructs a Merkle tree based on all shard hashes; leaf nodes = shard hashes, non-leaf nodes = combinations of child node hashes; and generates the Merkle tree root hash.

[0064] The root hash is written to fileHashRecord[fileHash].hashFile.merkleRoot for quick verification of data integrity (any sub-block tampering will cause the root hash to change).

[0065] S2083, Block Weaving Storage; Each node packages the fragment Si into candidate blocks and links the parent block with a random historical memory block according to the Blockweave structure. That is, each candidate block is not only linked to the parent block, but also randomly linked to a historical memory block.

[0066] S2084, PoA verification and block confirmation; The security chain smart contract verifies the block shard hash and node qualifications, and completes block weaving and storage after passing the verification.

[0067] S2085, Disk shutdown function triggered; After the security chain smart contract detects that the storage task has been assigned to the agent node, it automatically calls the disk sealing function; The disk closure function encrypts and locks the disk space required for storing encrypted shards on a node, retaining only write / read permissions for the encrypted shard until the user requests deletion.

[0068] S2086, Storage status is uploaded to the blockchain; Write the node list, primary / backup allocation results, disk encryption status, IV / Tag, and E (SK) to fileHashRecord [fileHash].storageMeta.

[0069] Block weaving technology optimizes data security through dual-chain and PoA verification; disk closure functions are embedded in smart contracts to achieve encrypted control of storage resources and prevent unauthorized use.

[0070] S2087, Distributed storage confirmation; Encrypted shards are distributed to multiple filtered agent nodes (master node + backup node) according to the DPoS mechanism to achieve decentralized storage, reduce the risk of single point of failure, and ensure high data availability.

[0071] S2088, Hash digest association; Using `fileHash` as the unique hash digest of a file, it is deeply associated with copyright metadata (`fileHashRecord[fileHash].copyrightMeta`) and storage location information (the node list in `fileHashRecord[fileHash].storageMeta`), forming a hash-based index system for querying all information, enabling rapid access for subsequent file searches, permission verification, and revenue settlement. `fileHashRecord[fileHash].copyrightMeta` is the core copyright metadata structured storage field defined in the secure chain smart contract.

[0072] S209, Fixed terms and conditions for smart contract deployment and use; After receiving feedback that the storage chain has successfully stored the content, the secure link automatically deploys a copyright management contract via a smart contract, specifying the terms of content use. This includes the following steps: S2091, Contract Deployment; Automatically deploy a pre-set copyright management contract. The copyright management contract includes built-in terms of content use, which can be customized by the user before uploading or a default template can be used.

[0073] S2092, Terms of Use are Fixed; The copyright management contract includes built-in terms of content usage. Users can customize the terms before uploading or use the default template. The core terms of usage include: Licensed usage: Free for non-commercial use; commercial use requires payment of copyright fees. Copyright revenue distribution rules: For example, when others pay to use the content, the author receives 80% of the revenue; 80% for the author, 15% for the storage node, and 5% for the platform. Infringement accountability mechanism: Upon discovery of unauthorized use, the infringer's account privileges will be automatically frozen and pledged assets will be deducted; S2093, Terms and Conditions Binding; The copyright management contract is associated with fileHash. When any user accesses the file, they need to sign on the blockchain to confirm their agreement to the terms before they can obtain the decryption key E (SK) and access the file.

[0074] In some embodiments, in addition to storing original works on a blockchain cloud storage platform as described above, it is also necessary to consider subsequent operations such as sharing, licensing, and updating of original works. Figure 3 A schematic diagram illustrating another method for protecting personal data assets provided in this disclosure embodiment, as shown below. Figure 3 As shown, the method also includes: 301. File Access and Authorization; 3011. Permission Request; When a user requests access to a file, they first submit a permission request to the security chain, along with their identity information and usage scenario; that is, the security chain receives the permission request submitted by the user when requesting access to the file.

[0075] 3012. Permission verification; The security chain smart contract verifies the visitor's identity: The security chain smart contract verifies the requester's identity and, in conjunction with the authorization rules in fileHashRecord[fileHash].copyrightMeta (such as whether payment has been made, whether the authorization period is within the specified time), decides whether to grant authorization. 3013. File decryption; Once authorization is granted, the encryption key E (SK) is issued. In other words, the security chain smart contract issues the encryption key E (SK) to the authorized visitor.

[0076] The user decrypts to obtain the AES key SK, then uses SK+IV+Tag to decrypt the fragments and concatenates them into a complete plaintext file.

[0077] Unauthorized users cannot obtain the key and cannot read the file.

[0078] 302. Recording and preserving usage behavior; When original works are shared or used, the smart contract records the usage, specifically including: Sharing scenario: Creators initiate sharing through a client, and the smart contract generates a unique sharing link (associated with the fileHash and the authorized user's address). When the authorized user clicks the link, a record is triggered. Use case: When a user accesses / downloads a file, they must first pass permission verification (such as whether they have purchased a license or are within the license period). After successful verification, the smart contract automatically records the usage information. Core record fields: User address, usage timestamp, usage type (browse / download / commercial use), usage duration (if required); Record storage: Use records will be written to (array structure) fileHashRecord[fileHash].copyrightMeta.useRecords and simultaneously synchronized to the secure chain blocks to ensure immutability; The usage records provide data support for subsequent revenue settlement and infringement tracing, and are directly linked to the incentive mechanism.

[0079] 303. Copyright terms will be enforced automatically; When content is used, a smart contract is triggered to automatically execute the copyright terms, specifically including the following steps: 3031. Permission verification; The smart contract reads fileHashRecord[fileHash].copyrightMeta.licenseType to determine whether the usage complies with the authorization rules, such as: commercial use requires payment, non-commercial use is free).

[0080] 3032. Implementation of Clauses; Free authorization scenario: After successful verification, the smart contract automatically issues the decryption key E (SK), allowing the user to access the file normally; Paid licensing scenario: After the user pays the copyright fee to the contract address, the smart contract triggers the process of fee locking, key distribution, and usage record generation; Blocking prohibited behaviors: If a user attempts to... Figure 2 If prohibited actions such as modification or sub-licensing are attempted, the smart contract will automatically refuse to issue the key and record the violation. Copyright terms are enforced through smart contracts, avoiding the problem of terms being ineffective in traditional licensing agreements.

[0081] 304. Creators receive revenue based on usage records; Revenue Settlement: The smart contract automatically settles revenue according to a preset period (e.g., monthly). The settlement logic is based on the usage records in step S302. Revenue calculation formula: Total revenue = Number of uses × Per-license fee × Author's revenue share; Revenue sharing rules: 80% for authors, 15% for storage agent nodes (allocated according to node storage contribution), and 5% for the platform (operation and maintenance costs). Revenue Distribution: The smart contract automatically transfers revenue to the creator's blockchain account, and the distribution record is written to fileHashRecord[fileHash].copyrightMeta.profitRecords; where fileHashRecord[fileHash].copyrightMeta.profitRecords is a structured array of revenue records defined in the blockchain cloud storage security chain smart contract. It is specifically used to immutably store the settlement and distribution information of the entire lifecycle of copyright revenue for original works. It is the core data carrier connecting the use of works, revenue distribution rules and node incentive mechanisms.

[0082] Incentive linkage: The revenue of a proxy node is tied to its historical service quality score (H). The higher the revenue, the higher the H, and the easier it is to be elected in the next round of DPoS election. Earning revenue based on usage records enables a fully automated revenue incentive system from usage, recording, settlement to distribution, enhancing competitiveness in the next round of DPoS elections and creating a positive cycle.

[0083] 305. Document auditing and updating; Specifically, it includes: 3051. Data verification; Data integrity is verified by Merkle root hash. If the root hash is inconsistent, the data is determined to have been tampered with, triggering the repair process.

[0084] 3052, Data Update; When a creator initiates a file update request, the client uploads the new original file. The storage chain re-executes the sharding, encryption, and distribution process, synchronously updating the sharded data of all BF nodes. The security chain updates the work's metadata and hash file in fileHashRecord.

[0085] 3053. Audit Records; All operations (updates, accesses, revenue settlements) are recorded on the storage chain, making the entire lifecycle of operations transparent and traceable.

[0086] Throughout the entire lifecycle of original work management, Merkle tree verification and audit records ensure data security and operational traceability.

[0087] 306. Infringement detection and rights protection handling; The smart contract periodically compares the hash values ​​of files circulating on the network with the hash values ​​of files stored in the security chain. Upon discovering infringing files, the smart contract automatically executes preset penalty measures and packages the copyright information, creation timestamp, and infringing behavior records into a rights protection evidence package for the original user to export and use.

[0088] When a document with a mismatched signature is discovered, infringement penalties will be automatically enforced or evidence for rights protection will be provided, specifically including the following steps: 3061. Infringement detection; Active detection: The smart contract periodically scans on-chain files and compares their hash values ​​with the fileHash in fileHashRecord. If it finds that "the content is the same but the signature does not match" (i.e., unauthorized use), it is determined to be an infringement. Passive reporting: Users submit infringement reports (including hashes of suspected infringing files and screenshots of usage scenarios), and the smart contract triggers an infringement investigation after verifying the evidence.

[0089] 3062. Execution of penalties; Automatic penalty: If the infringer is an on-chain user (with a linked account), the smart contract will automatically deduct their staked assets (such as tokens), and the deducted amount will be transferred to the creator's account as compensation. At the same time, the infringer's access permissions will be frozen. Evidence for rights protection: The smart contract generates an immutable chain of evidence of infringement, including: the hash of the infringing file, the timestamp of the infringement, the address of the infringing user, the digital signature of the original file and copyright metadata, which can be directly used by the creator to protect their rights.

[0090] The infringement handling process is deeply integrated with copyright metadata and hash files, enabling automated penalties and providing judicially recognized evidence for rights protection, thereby strengthening copyright protection.

[0091] 307: File deleted; Specifically, it includes: 3071. Delete request; Only the original user can initiate a deletion request and submit a private key signature verification. 3072. Delete operation; Delete the relevant record in fileHashRecord[fileHash] and trigger the disk lock function to release the encrypted storage space; 3073, Node Notification; Send a delete command to all agent nodes that store the file fragment, and the nodes delete the local fragment data and update the file status on the storage chain to "deleted"; This step completes the final step in the full lifecycle management of original work files, ensuring that deletion operations are compliant and traceable, while also freeing up storage resources.

[0092] 308. Node Iteration and Redundancy Optimization.

[0093] This step re-executes the DPoS score update agent node list at regular intervals; it uses the minimum redundancy guarantee algorithm to handle node failures and dynamically adjusts the backup factor BF to ensure long-term data availability.

[0094] Specifically, it includes: 3081. Node fault handling; When the primary node fails, a new primary node is selected from the backup nodes, and data is copied from other backup nodes to the new primary node. For example, if a failure of primary node A is detected, a new primary node is selected from backup nodes B / C, and data is synchronized to the new primary node. 3082, Data Update; When a user updates a file, the smart contract triggers a synchronized update of the sub-blocks on all BF nodes; 3083. Periodic audits; Data integrity checks are performed according to a preset cycle, such as once a week, to verify the consistency between the shard hash and the shard hash stored in the security chain. 3084, Dynamic Optimization; H adjusts the node list based on nodes, removing nodes with frequent failures; BF is dynamically adjusted according to the storage load of the entire network (e.g., BF=2 when the load is high, BF=3 when the load is low).

[0095] 3085, DPoS node iteration; Perform DPoS scoring according to a preset cycle (monthly), update the list of agent nodes, and replace nodes with degraded capabilities.

[0096] In this embodiment, the minimum redundancy guarantee algorithm enables dynamic maintenance of fault handling, auditing, and optimization to ensure long-term data availability; the dynamic ranking of the DPoS mechanism enables iterative updates of proxy nodes to continuously guarantee the performance of the storage chain.

[0097] The above description is only a preferred embodiment of the present invention. It should be noted that, for those skilled in the art, several improvements, optimizations and modifications can be made without departing from the principle of the present invention, and these should also be considered within the scope of protection of the present invention.

[0098] Figure 4A schematic diagram of the structure of a device for protecting personal data assets provided in this disclosure embodiment is shown below. Figure 4 As shown, the device 400 includes: Storage module 401 is configured to respond to a user's request to store original works on the blockchain by processing the original files of the original works to obtain encrypted fragments and distributing them to the storage chain proxy nodes. The encryption module 402 is configured to trigger the disk locking function in the security chain smart contract to encrypt and lock the disk space required to store the original work within the storage chain proxy node.

[0099] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure, such as... Figure 5 As shown, this disclosure also provides an electronic device 500, which includes at least one processor 501 and a memory 502 coupled to the processor 501. The memory 502 is used to store at least one processor 501 executable instructions, wherein the at least one processor 501 is used to execute the instructions to implement the steps of the method described above in this disclosure.

[0100] The processor 501 described above can also be called a Central Processing Unit (CPU), which can be an integrated circuit chip with signal processing capabilities. Each step in the method described in this embodiment can be implemented by the integrated logic circuitry in the processor 501 or by software instructions. The processor 501 can be a general-purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method in this embodiment can be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor. The software modules can be located in the memory 502, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The processor 501 reads information from the memory 502 and, in conjunction with its hardware, completes the steps of the method described above.

[0101] Figure 6This is a schematic diagram of an exemplary computer system provided by an embodiment of the present disclosure. Various operations / processes according to embodiments of the present disclosure, implemented via software and / or firmware, can be transmitted from a storage medium or network to a computer system with a dedicated hardware architecture, for example... Figure 6 The computer system 600 shown is equipped with the programs that constitute the software. When various programs are installed, the computer system is able to perform various functions, including those described above.

[0102] Computer system 600 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic devices may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0103] like Figure 6 As shown, the computer system 600 includes a computing unit 601, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. The RAM 603 may also store various programs and data required for the operation of the computer system 600. The computing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0104] Multiple components in the computer system 600 are connected to the I / O interface 605, including: an input unit 606, an output unit 607, a storage unit 608, and a communication unit 609. The input unit 606 can be any type of device capable of inputting information into the computer system 600. The input unit 606 can receive input digital or character information and generate key signal inputs related to user settings and / or function control of the electronic device. The output unit 607 can be any type of device capable of presenting information and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. The storage unit 608 may include, but is not limited to, a hard disk and an optical disk. The communication unit 609 allows the computer system 600 to exchange information / data with other devices via a network such as the Internet, and may include, but is not limited to, modems, network interface cards, infrared communication devices, wireless communication transceivers, and / or chipsets, such as Bluetooth™ devices, Wi-Fi devices, WiMax devices, cellular communication devices, and / or the like.

[0105] The computing unit 601 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above. For example, in some embodiments, the methods described above in the embodiments of this disclosure can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed on an electronic device via ROM 602 and / or communication unit 609. In some embodiments, the computing unit 601 can be configured to perform the methods described above in the embodiments of this disclosure by any other suitable means (e.g., by means of firmware).

[0106] This disclosure provides a computer-readable storage medium storing one or more programs that can be executed by one or more processors to implement the methods described in this disclosure.

[0107] Computer-readable storage media can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or devices that include one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.

[0108] It should be noted that the computer-readable storage medium described in this disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), or any suitable combination thereof.

[0109] Embodiments of this disclosure provide a computer program product, including a computer program that, when executed by a processor, implements the steps of the above-described method for protecting personal data assets.

[0110] In embodiments of this disclosure, computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof. These programming languages ​​include, but are not limited to, object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on a computer, partially on a computer, as a standalone software package, partially on a computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0111] The modules, components, or units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the modules, components, or units do not necessarily constitute a limitation on the module, component, or unit itself.

[0112] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary hardware logic components that can be used include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), etc.

[0113] It should be noted that, in this document, terms such as "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0114] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A method of personal data asset protection, characterized by, The method comprises: In response to a user request to store an original work, the original file of the original work is processed to obtain encrypted fragments which are distributed stored in a storage chain agent node; Triggering a disk locking function in a security chain smart contract, the disk space required to store the original work in the storage chain agent node is encrypted and locked.

2. The method of claim 1, wherein, Before the original file of the original work is processed to obtain encrypted fragments which are distributed stored in a storage chain agent node in response to a user request to store an original work, the method further comprises: Storing the copyright information of the original work and the digital fingerprint in the security chain.

3. The method of claim 2, wherein, Before the copyright information of the original work and the digital fingerprint are stored in the security chain, the method further comprises: The security chain smart contract generates a file unique hash value and a digital fingerprint based on the work metadata and the content of the original file of the original work.

4. The method of claim 3, wherein, Before the copyright information of the original work and the digital fingerprint are stored in the security chain, the method further comprises: The security chain smart contract determines whether the received file unique hash value already exists in the hash value list to confirm whether the same content does not exist on the chain.

5. The method of claim 1, wherein, The method further comprises: Filtering agent nodes based on an improved proof-of-stake mechanism.

6. The method of claim 5, wherein, The filtering of agent nodes based on the improved proof-of-stake mechanism comprises: All nodes of the storage chain are prequalified to filter out invalid nodes; Obtaining a quantitative score of core parameters of the nodes; The core parameters include: node available disk size score S, node data encryption speed score E, node cross-zone block access capability score A, and node historical service quality score H; S = (node average available disk space / network maximum node available disk space) x 100; E = (node actual encryption speed / industry average encryption speed) x 100; A = (benchmark access time / node actual access random block time) x 100; H = (node normal operation time - failure time x weight) / total operation time x 100; Weighted calculation of comprehensive score: Storage_Capacity_Score = (S x ωS) + (E x ωE) + (A x ωA) + (H x ωH); Wherein, ωS is the weight of available disk size; ωE is the weight of data encryption speed; ωA is the weight of access to other block capability; ωH is the weight of historical record; Ranking in descending order of comprehensive score, selecting the top N as agent nodes, and writing into the agent node list of the security chain smart contract.

7. The method of claim 6, wherein, Wherein, ωS = 0.4; ωE = 0.2; ωA = 0.2; ωH = 0.

2.

8. The method of claim 1, wherein, The response to a user request to store an original work, the original file of the original work is processed to obtain encrypted fragments which are distributed stored in a storage chain agent node comprises: The storage chain distributes data fragments of the original file and nodes based on a minimum redundancy guarantee algorithm; The storage chain persistently stores the encrypted fragments obtained from the data fragments in the agent nodes.

9. The method of claim 8, wherein, The storage chain distributes data fragments of the original file and nodes based on a minimum redundancy guarantee algorithm comprises: The storage chain divides the original file D into n sub-blocks S={S1, S2,..., Sn}; The storage chain master node generates a symmetric key SK through a first encryption algorithm, encrypts each sub-block to generate an encrypted fragment, synchronously generates an initialization vector IV and an authentication tag Tag, and uploads an encrypted key E generated by encrypting the symmetric key SK with a second encryption algorithm to a security chain smart contract storage; The storage chain calls a first function to calculate the hash value of each encrypted fragment, obtains a fragment hash, and submits the packaged hash to the security chain smart contract after packaging; BF nodes are randomly selected from the proxy node list N to determine the master node and backup node of each encrypted fragment Si, wherein BF is a backup factor, and the value of BF is 2-5; The security chain smart contract integrates the file unique hash value, the number of fragments, the master / backup node list, the symmetric key SK, and the encrypted key E to generate a storage task allocation instruction and issue the instruction to the storage chain.

10. The method of claim 9, wherein, The storage chain persistently stores the encrypted fragments in the proxy nodes, including: The master node distributes the encrypted fragments, the initialization vector IV, and the authentication tag Tag to BF-1 backup nodes; The master node constructs a Merkle tree based on all fragment hashes; Each node packages the fragment Si as a candidate block, links the parent block and the random historical recall block according to the Blockweave structure, and stores the block in the storage chain. The security chain smart contract verifies the block fragment hash and the node qualification, and completes the block weaving storage after passing the verification.

11. The method of claim 1, wherein, The method further includes: The security chain automatically deploys a copyright right management contract through a smart contract, and stipulates content use terms. The copyright right management contract has built-in content use terms, which are customized by the user before uploading or use a default template.

12. The method of claim 1, wherein, The use terms include: authorized use scope; copyright income distribution rules; and infringement accountability mechanism. The copyright right management contract is associated and bound with the file unique hash value.

13. The method of claim 12, wherein, The method further includes:

14. The method of claim 13, wherein, The security chain receives a permission application submitted by a visitor when the visitor requests to access the file; 15. The method of claim 12, wherein, The security chain smart contract verifies the identity of the visitor.

16. The method of claim 1, wherein, The method further includes: The security chain smart contract issues an encrypted key E (SK) to the visitor who is authorized. The method further includes:

17. The method of claim 16, wherein, When the original work is shared or used, the security chain smart contract records the usage. When the original work is shared or used, the security chain smart contract records the usage, including:

18. The method of claim 1, wherein, The security chain smart contract verifies the identity of the requester and decides whether to authorize according to the authorization rules; The security chain smart contract issues an encrypted key E to the requester who is authorized.

19. The method of claim 18, wherein, The smart contract automatically records the usage information. The method further includes: The security chain smart contract is triggered when the content is used, and automatically executes the copyright terms. The method further includes:

20. The method of claim 1, wherein, The security chain smart contract is triggered when the content is used, and automatically executes the copyright terms. ​ 21. The method of claim 1, wherein, The method further comprises: When the original work is authorized to access or use, the security chain smart contract automatically transfers the copyright income to the user's blockchain account according to the preset allocation ratio.

22. The method of claim 1, wherein, The method further comprises: The data integrity is checked by the Merkel tree root hash, if the root hash is inconsistent, it is determined that the data is tampered, and the repair process is triggered.

23. The method of claim 1, wherein, The method further comprises: In response to a file update request initiated by a user, the storage chain uploads a new original file from the client, the storage chain re-executes the slicing, encryption and distribution process, synchronously updates the slice data of all BF nodes, and the security chain updates the work metadata and hash file in the hash value list.

24. The method of claim 1, wherein, The method further comprises: Periodically compare the hash values of the files spread in the network with the file hash values stored in the security chain, and when the infringing files are found, the smart contract automatically executes the preset punishment measures, and packs the copyright information, creation timestamp and infringement record to generate a right protection evidence package for export by the original user.

25. The method of claim 1, wherein, The method further comprises: Periodically execute the share proof score to update the agent node list; Handle node failure and dynamically adjust the backup factor BF through the minimum redundancy guarantee algorithm.

26. An apparatus for personal data asset protection, the apparatus comprising: The device comprises: A storage module configured to store the original file of the original work in response to a user request to store the original work on the chain, and to distribute the encrypted slices obtained by processing the original file in the storage chain agent node; An encryption module configured to trigger a disk sealing function in the security chain smart contract, and to encrypt and lock the disk space required to store the original work in the storage chain agent node.

27. An electronic device, comprising: Comprise: At least one processor; Memory for storing instructions executable by the at least one processor; The at least one processor is configured to execute the instructions to implement the method of any one of claims 1-25.

28. A computer-readable storage medium, characterized in that, The instructions in the computer readable storage medium are executed by the processor of the electronic device, so that the electronic device can execute the method of any one of claims 1-25.

29. A computer program product comprising a computer program, characterised in that, The computer program is executed by the processor to implement the steps of the personal data asset protection method of any one of claims 1-25.