A Blockchain-Based Method for Digital Asset Security Management

The blockchain-based digital asset management system is divided into verification, storage, and sending units. By combining multi-dimensional identity verification and asset segmentation encryption, it solves the problem of weak security verification in the digital asset management system and achieves efficient and secure management throughout the entire process.

CN122293322APending Publication Date: 2026-06-26CHINA THREE GORGES CORPORATION +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA THREE GORGES CORPORATION
Filing Date
2026-04-27
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Existing digital asset management systems have simple security verification steps when users upload digital assets, which can easily lead to the risk of asset leakage or tampering.

Method used

The digital asset management system, built on blockchain technology, is divided into a digital asset verification unit, a digital asset storage unit, and a data asset sending unit. It generates a secure verification key through a multi-dimensional identity verification mechanism, and encrypts the digital assets by segmenting and combining the user's location information and biometrics.

Benefits of technology

It enhances the security verification strength of digital assets and users, prevents abnormal user logins and asset theft, improves system operation stability and security, and realizes closed-loop security management throughout the entire process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122293322A_ABST
    Figure CN122293322A_ABST
Patent Text Reader

Abstract

This invention relates to a blockchain-based method for secure management of digital assets. The method includes initiating a digital asset management system comprising a digital asset verification unit, a digital asset storage unit, and a data asset sending unit based on a digital asset upload instruction. The digital asset verification unit performs security verification on the user. If the user passes the security verification by the digital asset management unit, a security verification key is generated, the digital asset is acquired, and the digital asset is segmented into a first digital asset, ..., an nth digital asset. The first digital asset, ..., the nth digital asset are then encrypted using the security verification key to obtain a first encrypted asset, ..., an nth encrypted asset. Connection information for the data asset sending unit is obtained, and based on this connection information, the first encrypted asset, ..., the nth encrypted asset are sent to the digital asset storage unit. This invention can improve the security verification strength of digital assets and users uploading digital assets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, and in particular to a method for secure management of digital assets based on blockchain. Background Technology

[0002] Digital assets refer to non-monetary assets owned or controlled by an enterprise or individual, existing in the form of electronic data, held in the ordinary course of business for sale or in the process of production. The emergence of digital assets benefits from the continuous development of network technology; furthermore, the secure management of digital assets is crucial to the development and security of individuals or enterprises.

[0003] Currently, the security management of digital assets mainly relies on digital asset management systems. A digital asset management system is a management system developed according to the needs of enterprises or individuals. Its purpose is to provide users with operations such as changing and trading digital assets while securely storing them.

[0004] Digital asset management systems greatly satisfy the needs of enterprises or individuals for intelligent management of digital assets. However, there is still a problem with digital asset management systems: the technical steps for security verification of users who upload digital assets are relatively simple, which makes it easy to cause the risk of digital assets being leaked or tampered with. Summary of the Invention

[0005] This invention provides a blockchain-based method for the secure management of digital assets. Its main purpose is to improve the security verification strength of digital assets and the users who upload them throughout the entire process from uploading to storage.

[0006] To achieve the above objectives, this invention provides a digital asset security management method based on blockchain, comprising: The system receives a digital asset upload instruction initiated by a user and starts a digital asset management system based on the instruction. The digital asset management system is built on blockchain technology and includes a digital asset verification unit, a digital asset storage unit, and a data asset sending unit. The digital asset verification unit performs security verification on users. If a user passes the security verification of the digital asset supervision unit, a security verification key is generated. Acquire the user's digital assets, and segment the digital assets to obtain the first digital asset, ..., the nth digital asset; The first digital asset, ..., the nth digital asset are encrypted using the security verification key to obtain the first encrypted asset, ..., the nth encrypted asset; Obtain the connection information of the data asset sending unit, and send the first encrypted asset, ..., the nth encrypted asset to the digital asset storage unit based on the connection information.

[0007] Optionally, the step of using the digital asset verification unit to perform security verification on the user, and generating a security verification key if the user passes the security verification of the digital asset supervision unit, includes: Identify the client that initiated the digital asset upload command from the user, and obtain the command initiating client, which includes the username and password of the user; Obtain the device code of the device that supports the client running the command; A secure verification signature is generated based on the username, password, and device code. The user authentication unit of the digital asset management system is activated, wherein the user authentication unit pre-stores the user's registration verification signature before using the digital asset management system; Determine whether a registration verification signature identical to the security verification signature exists in the user identity authentication unit. If no registration verification signature identical to the security verification signature exists in the user identity authentication unit, generate a user registration reminder instruction and send it to the instruction initiating client. The user registration reminder instruction indicates that the user has failed the security verification of the digital asset supervision unit. If the user authentication unit contains a registration verification signature identical to the security verification signature, it indicates that the user has passed the security verification of the digital asset supervision unit. The user's location information and biometrics are immediately obtained, whereby the user's location information consists of two-dimensional coordinates. The biometrics include the user's face or fingerprint; A secure verification key is generated based on the user's location information and biometric characteristics.

[0008] Optionally, generating a security verification signature based on the username, user password, and device code includes: The username, password, and device code are all converted to binary to obtain a binary name, a binary password, and a binary device code. Compare the lengths of the binary name and the binary cipher. For the shorter binary name and the binary cipher, perform a trailing zero operation and then perform a bitwise AND operation to obtain the interactive cipher. Compare the lengths of the device code and the interaction password, perform a trailing zero operation on the shorter device code or interaction password, and then perform an OR operation to obtain the user equipment mixed code; Based on a pre-built signature algorithm, a secure verification signature for the user equipment hybrid code is generated, wherein there is a one-to-one correspondence between the secure verification signature and the user equipment hybrid code.

[0009] Optionally, generating a security verification key based on the user's location information and biometrics includes: Obtain the location information of the digital asset regulatory unit, wherein the location information of the digital asset regulatory unit is composed of two-dimensional coordinates. express; Based on the location information of the digital asset supervision unit and the user's location information, construct the communication location parameters between the digital asset supervision unit and the user; A secure verification key is generated based on communication location parameters and biometric features.

[0010] Optionally, the construction of communication location parameters between the digital asset supervision unit and the user based on the location information of the digital asset supervision unit and the user includes: The communication location parameters are calculated using the following formula: ; ; in, This indicates the communication location parameters between the digital asset regulatory unit and the user. The weighting factor represents the formula for calculating communication location parameters. This represents the distance value calculated based on the location information of the digital asset regulatory unit and the user's location information. This indicates the bandwidth value of the client that initiated the command at the current time. This indicates the amount of digital asset data that the data asset sending unit can receive from the instruction initiating client within a unit of time.

[0011] Optionally, generating a security verification key based on communication location parameters and biometrics includes: The biometric features are encrypted using the FuzzyVault algorithm to obtain encrypted biometric features. The communication location parameters are used as the feature header of the encrypted biometric feature, and combined to obtain the biometric location feature. Determine the number of bytes in the biological location feature. If the number of bytes in the biological location feature is greater than the specified number of bytes, compress the biological location feature until the number of bytes in the biological location feature is less than or equal to the specified number of bytes. Perform a hash operation on the biological location features to obtain the biological location hash value; Two factors to be encrypted are generated, and based on a symmetric encryption algorithm, the biometric location hash value is used as the key to encrypt the two factors to obtain a security verification public key and a security verification private key. The combination of the security verification public key and the security verification private key is the security verification key.

[0012] Optionally, the step of segmenting the digital asset to obtain a first digital asset, ..., an nth digital asset includes: The total number of digital assets n obtained from the segmentation is calculated based on the communication location parameters; Before performing the split, the number of bytes of the first digital asset, ..., the number of bytes of the nth digital asset are calculated sequentially; Based on the corresponding number of bytes, the digital asset is segmented to obtain the first digital asset, ..., the nth digital asset.

[0013] Optionally, calculating the total number of digital assets n obtained from the segmentation based on the communication location parameters includes: The total number of digital assets, n, is calculated based on the following formula: ; in, The integer operator is ||, and the absolute value is ||. The first weighting factor in the formula for calculating the total number of digital assets is represented, and The value must be greater than or equal to 10. Indicates the communication location parameters, It is the second weighting factor in the formula for calculating the total number of digital assets, and The value must be greater than 0 and less than or equal to 1.

[0014] Optionally, the calculation of the number of bytes of the first digital asset, ..., the number of bytes of the nth digital asset includes: Obtain the total number of bytes of the digital asset, and calculate the highest number of bytes for the first segmentation based on the total number of bytes. The calculation method for the highest number of bytes is as follows: ; in, This indicates the highest number of bytes in the first segmentation. This represents the total number of bytes in the digital asset. Construct a random segmentation function for the first segmentation based on the highest number of bytes in the first segmentation; Based on the random segmentation function of the first segmentation, the digital asset is segmented for the first time to obtain the first digital asset and the first asset to be segmented, wherein the number of bytes of the first asset to be segmented is greater than or equal to that of the first digital asset. Based on the number of bytes of the first asset to be split, construct the maximum number of bytes to be split in the second split, and construct a random splitting function for the maximum number of bytes to be split in the second split; Based on the random segmentation function of the second segmentation, the first asset to be segmented is segmented, and so on to obtain the second digital asset, ..., the nth digital asset.

[0015] Optionally, the random segmentation function for the first segmentation is: ; ; ; Or ; ; in, This indicates the number of bytes to be determined after the first split. This indicates the number of bytes in the first digital asset obtained after the first split. This indicates the number of bytes in the first asset to be split after the first split is performed. This represents the segmentation independent variable randomly generated during the first segmentation, and the range of values ​​for the segmentation independent variable is [value missing]. ], This represents the adjustment factor of the random partitioning function for the first partition.

[0016] This invention first receives a digital asset upload command initiated by a user, and then starts a digital asset management system based on the command. The digital asset management system is built on blockchain technology and includes a digital asset verification unit, a digital asset storage unit, and a data asset sending unit. It can be seen that this invention aims to improve the security of data assets by building a digital asset management system based on a more secure blockchain. In order to prevent the functions of the digital asset management system from being too centralized, which would lead to bloat and lag, this invention differentiates the functions of the digital asset management system, dividing it into a digital asset verification unit, a digital asset storage unit, and a data asset sending unit.

[0017] Furthermore, the digital asset verification unit performs security verification on the user. If the user passes the security verification of the digital asset supervision unit, a security verification key is generated. It can be seen that in order to prevent abnormal users from logging into the digital asset management system, this embodiment of the invention first performs security verification on the user and generates a security verification key with a unique identifier.

[0018] Furthermore, to prevent the theft of the overall digital assets, after acquiring the user's digital assets, the digital assets are segmented to obtain a first digital asset, ..., an nth digital asset. Then, the first digital asset, ..., an nth digital asset are encrypted using the security verification key to obtain a first encrypted asset, ..., an nth encrypted asset. Since the security verification key is generated based on the user, each encrypted digital asset has a strict correspondence with the user, thereby improving security.

[0019] Compared with the prior art, the present invention has the following beneficial effects: 1. This application addresses the problem that existing digital asset management systems have simple security verification steps during the user upload to asset storage stage, which easily leads to asset leakage and tampering. It builds a digital asset management system based on blockchain technology, which splits the system into a digital asset verification unit, a digital asset storage unit, and a data asset sending unit. The immutable, decentralized, and traceable characteristics of blockchain strengthen the underlying security, while realizing functional decoupling, avoiding the lag and inefficiency caused by the concentration of system functions, and improving the overall stability and response efficiency of the system.

[0020] 2. This application strengthens user security verification through a multi-dimensional identity verification mechanism. First, a unique security verification signature is generated using the username, password, and device code to complete the binding verification between the user and the device. Then, a unique security verification key is generated by combining the user's location information and biometric features. This constructs a four-fold verification system of account, device, location, and biometric features, which eliminates security risks such as abnormal user access, identity forgery, and unauthorized device uploads from the source, and significantly improves the reliability and uniqueness of user identity authentication.

[0021] 3. This application adopts a combination of dynamic asset segmentation and dedicated encryption to enhance asset protection capabilities. The number of asset segments is adaptively determined based on the communication location parameters between the user and the regulatory unit. Digital assets are split into segments using traceable random segmentation rules to prevent the overall assets from being directly exposed and stolen. Each segment of the asset is then independently encrypted using a security verification key strongly associated with the user, making the encrypted assets deeply bound to the user, device, and location information. This significantly increases the difficulty of cracking, splicing, and tampering with the assets, effectively reducing the risk of asset leakage.

[0022] 4. This application achieves a secure closed loop throughout the entire process from the initiation of the upload command to the completion of asset storage. It sets up progressive security protection in each stage of user verification, asset processing, transmission and storage, which not only solves the defects of weak verification and insufficient asset protection in traditional solutions, but also adapts to different network environments and transmission conditions, and balances security performance and operational efficiency, providing stable, efficient and highly secure full lifecycle management support for various digital assets of individuals and enterprises. Attached Figure Description

[0023] The present invention will be further described below with reference to the accompanying drawings and embodiments: Figure 1 This is a flowchart illustrating the blockchain-based digital asset security management method provided by the present invention. Detailed Implementation

[0024] The specific embodiments of the present invention will be further described in detail with reference to the accompanying drawings.

[0025] Reference Figure 1 The diagram shown is a flowchart illustrating a blockchain-based digital asset security management method according to an embodiment of the present invention, which includes the following steps: S1. Receive a digital asset upload instruction initiated by a user, and start the digital asset management system according to the digital asset upload instruction. The digital asset management system is built on blockchain technology and includes a digital asset verification unit, a digital asset storage unit, and a data asset sending unit.

[0026] It should be explained that digital assets include cryptocurrencies, digital traditional financial assets, legal digital currencies, digital intangible assets, digital tangible assets, and digital conventional services and products. When users generate digital assets of the above types, or when they are generated by enterprises, research institutes, etc., in order to ensure the security of digital assets, they need to upload the digital assets to the digital asset management system. Therefore, a digital asset upload command is initiated.

[0027] For example, Xiao Zhang is a researcher at the Intelligent Vehicle Autonomous Driving Research Institute. Through multiple experiments, he has developed an autonomous driving algorithm that can effectively improve the safety of autonomous driving. Therefore, Xiao Zhang has compiled digital assets such as the technical details of the autonomous driving algorithm, the patent certificates obtained, and the experimental data of the autonomous driving algorithm, and plans to upload them to the digital asset management system.

[0028] It should be emphasized that, in order to improve the security of managing digital assets, the digital asset management system of this invention includes a digital asset verification unit, a digital asset storage unit, and a data asset sending unit, and each unit is a node of the blockchain. That is, as the entire blockchain system, each unit of the digital asset management system is given a special role, so as to ensure security while effectively coordinating and utilizing each unit.

[0029] S2. Perform security verification on the user using the digital asset verification unit. If the user passes the security verification of the digital asset supervision unit, generate a security verification key.

[0030] In detail, the process of using a digital asset verification unit to perform security verification on the user, and generating a security verification key if the user passes the security verification by the digital asset supervision unit, includes: Identify the client that initiated the digital asset upload command from the user, and obtain the command initiating client, which includes the username and password of the user; Obtain the device code of the device that supports the client running the command; A secure verification signature is generated based on the username, password, and device code. The user authentication unit of the digital asset management system is activated, wherein the user authentication unit pre-stores the user's registration verification signature before using the digital asset management system; Determine whether a registration verification signature identical to the security verification signature exists in the user identity authentication unit. If no registration verification signature identical to the security verification signature exists in the user identity authentication unit, generate a user registration reminder instruction and send it to the instruction initiating client. The user registration reminder instruction indicates that the user has failed the security verification of the digital asset supervision unit. If the user authentication unit contains a registration verification signature identical to the security verification signature, it indicates that the user has passed the security verification of the digital asset supervision unit. The user's location information and biometrics are immediately obtained, whereby the user's location information consists of two-dimensional coordinates. The biometrics include the user's face or fingerprint; A secure verification key is generated based on the user's location information and biometric characteristics.

[0031] For example, in order to save the relevant digital assets of the autonomous driving algorithm in a timely manner, Xiao Zhang uses the computer at the research institute to launch the client and enters his username and password. Understandably, the computer at the research institute has a corresponding device code. Generally, the device code of a computer host starts with NS, NA, ES, SS, FS, EA, or BA and is followed by 8 digits. The device codes of mobile devices such as mobile phones are different from those of computers, and will not be elaborated here.

[0032] Furthermore, the step of generating a secure verification signature based on the username, user password, and device code includes: The username, password, and device code are all converted to binary to obtain a binary name, a binary password, and a binary device code. Compare the lengths of the binary name and the binary cipher. For the shorter binary name and the binary cipher, perform a trailing zero operation and then perform a bitwise AND operation to obtain the interactive cipher. Compare the lengths of the device code and the interaction password, perform a trailing zero operation on the shorter device code or interaction password, and then perform an OR operation to obtain the user equipment mixed code; Based on a pre-built signature algorithm, a secure verification signature for the user equipment hybrid code is generated, wherein there is a one-to-one correspondence between the secure verification signature and the user equipment hybrid code.

[0033] For example, if Xiao Zhang enters the username "Researcher Xiao Zhang" and the password "qpmz8888", then "Researcher Xiao Zhang", "qpmz8888" and the device code of the computer used by Xiao Zhang will all be converted into binary and then AND or OR operations will be performed respectively. Then, signature algorithms including but not limited to Rabin, DSS, RSA, DSA, ECDSA, etc. will be used to generate the corresponding security verification signature.

[0034] When Xiao Zhang registers in advance using the research institute's computer in the user identity authentication unit, a registration verification signature identical to the security verification signature already exists in the user identity authentication unit. However, if a registration verification signature identical to the security verification signature does not exist in the user identity authentication unit, it indicates that Xiao Zhang has not registered in the digital asset management system, or that Xiao Zhang registered in the digital asset management system using another device. It should be emphasized that this embodiment of the invention binds users to the devices they use. That is, even if Xiao Zhang has already registered in the digital asset management system, if he uploads digital assets again using a device other than the one he used to register, he will need to re-register. The main purpose of this technical step is to prevent users from using unverified devices indiscriminately, thereby preventing the theft of digital assets.

[0035] Furthermore, the generation of the security verification key based on the user's location information and biometrics includes: Obtain the location information of the digital asset regulatory unit, wherein the location information of the digital asset regulatory unit is composed of two-dimensional coordinates. express; Based on the location information of the digital asset supervision unit and the user's location information, construct the communication location parameters between the digital asset supervision unit and the user; A secure verification key is generated based on communication location parameters and biometric features.

[0036] Logically, user location information is usually represented by three-dimensional spatial information. However, acquiring spatial information requires excessive computing resources. Therefore, in order to avoid excessive computing resource consumption, this embodiment of the invention uses two-dimensional location information to represent the user's location, that is, constructing a two-dimensional coordinate system with the ground as the coordinate system, thereby generating... , This represents the x-axis coordinate in a two-dimensional ground coordinate system. This represents the y-axis coordinate in a two-dimensional ground coordinate system. Similarly, the location information of the digital asset regulatory unit is represented by two-dimensional coordinates. express.

[0037] Specifically, the construction of communication location parameters between the digital asset supervision unit and the user based on the location information of the digital asset supervision unit and the user includes: The communication location parameters are calculated using the following formula: ; ; in, This indicates the communication location parameters between the digital asset regulatory unit and the user. The weighting factor represents the formula for calculating communication location parameters. This represents the distance value calculated based on the location information of the digital asset regulatory unit and the user's location information. This indicates the bandwidth value of the client that initiated the command at the current time. This indicates the amount of digital asset data that the data asset sending unit can receive from the instruction initiating client within a unit of time.

[0038] As described above, the communication location parameters integrate the distance between the user and the digital asset verification unit, the network conditions of the user's instruction initiating client, and the receiving capability of the data asset sending unit to receive digital assets from the instruction initiating client. Therefore, the communication location parameters have strong uniqueness, and the security verification key generated based on the communication location parameters is very difficult to crack.

[0039] Furthermore, the generation of the security verification key based on communication location parameters and biometrics includes: The biometric features are encrypted using the FuzzyVault algorithm to obtain encrypted biometric features. The communication location parameters are used as the feature header of the encrypted biometric feature, and combined to obtain the biometric location feature. Determine the number of bytes in the biological location feature. If the number of bytes in the biological location feature is greater than the specified number of bytes, compress the biological location feature until the number of bytes in the biological location feature is less than or equal to the specified number of bytes. Perform a hash operation on the biological location features to obtain the biological location hash value; Two factors to be encrypted are generated, and based on a symmetric encryption algorithm, the biometric location hash value is used as the key to encrypt the two factors to obtain a security verification public key and a security verification private key. The combination of the security verification public key and the security verification private key is the security verification key.

[0040] The FuzzyVault algorithm primarily employs a polynomial constructor method to bind detailed feature points such as facial and fingerprint data, thereby generating encrypted biometrics with unique identification capabilities. However, since the FuzzyVault algorithm relies heavily on facial and fingerprint information, it is not difficult to crack the encrypted biometrics once a user's facial and fingerprint biometrics are stolen. Therefore, to prevent unauthorized personnel from stealing user biometrics and thereby obtaining digital assets managed in the digital asset management system, this embodiment of the invention embeds communication location parameters after the FuzzyVault algorithm performs biometric encryption. Specifically, the communication location parameters are used as the header position of the encrypted biometrics to construct the biometric location feature.

[0041] It should be emphasized that embedding biometric location features into communication location parameters can effectively improve security, because when unauthorized personnel use their own communication location parameters as one of the synthesis factors in the security verification key, the unauthorized personnel can be effectively located in subsequent user location security assessments or digital asset backtracking.

[0042] Furthermore, the symmetric encryption algorithm may be one or more of the following algorithms: TDEA, AES, Blowfish, RC2, RC4, RC5, etc.

[0043] S3. Obtain the user's digital assets, and perform segmentation on the digital assets to obtain the first digital asset, ..., the nth digital asset.

[0044] For example, if Xiao Zhang successfully passes the verification of the digital asset verification unit, that is: Xiao Zhang's location information is obtained to generate communication location parameters, and a security verification key is generated based on the communication location parameters and Xiao Zhang's biometrics. Then, this embodiment of the invention obtains Xiao Zhang's research results, namely the patent certificate, experimental data, etc. of the aforementioned autonomous driving algorithm.

[0045] To ensure the security of digital assets and prevent the entire digital asset from being stolen directly, this embodiment of the invention first performs a segmentation of the digital asset.

[0046] Specifically, the process of segmenting the digital asset to obtain a first digital asset, ..., an nth digital asset includes: The total number of digital assets n obtained from the segmentation is calculated based on the communication location parameters; Before performing the split, the number of bytes of the first digital asset, ..., the number of bytes of the nth digital asset are calculated sequentially; Based on the corresponding number of bytes, the digital asset is segmented to obtain the first digital asset, ..., the nth digital asset.

[0047] Further, calculating the total number of digital assets n obtained from the segmentation based on the communication location parameters includes: The total number of digital assets, n, is calculated based on the following formula: ; in, The integer operator is ||, and the absolute value is ||. The first weighting factor in the formula for calculating the total number of digital assets is represented, and The value must be greater than or equal to 10. Indicates the communication location parameters, It is the second weighting factor in the formula for calculating the total number of digital assets, and The value must be greater than 0 and less than or equal to 1.

[0048] For example, Xiao Zhang uploaded digital assets such as patent certificates and experimental data of the autonomous driving algorithm to the research institute's computer. Since the research institute and the digital asset management system are located in the same city, the actual value of the calculated communication location parameter is relatively small. Therefore, the total number of digital assets to be divided, n, is assumed to be 5, which means that the digital assets of the autonomous driving algorithm are divided into 5 parts, namely the first digital asset, ..., the fifth digital asset.

[0049] In this embodiment of the invention, the communication location parameter is used as an influencing factor in calculating the total number of digital asset segments, n. The main reason for this is that existing research has shown that in a series of systems built by blockchain technology, the user's location from the system and network information parameters are positively correlated with the user's security. That is, the farther the user is from the digital asset management system and the worse their network signal is, the higher the possibility that the digital assets they upload will be stolen or tampered with. Therefore, under the premise of saving computing resources, this embodiment of the invention uses the communication location parameter as the independent variable in the formula for calculating the total number of digital asset segments, n.

[0050] Further, the calculation of the number of bytes of the first digital asset, ..., the number of bytes of the nth digital asset includes: Obtain the total number of bytes of the digital asset, and calculate the highest number of bytes for the first segmentation based on the total number of bytes. The calculation method for the highest number of bytes is as follows: ; in, This indicates the highest number of bytes in the first segmentation. This represents the total number of bytes in the digital asset. Construct a random segmentation function for the first segmentation based on the highest number of bytes in the first segmentation; Based on the random segmentation function of the first segmentation, the digital asset is segmented for the first time to obtain the first digital asset and the first asset to be segmented, wherein the number of bytes of the first asset to be segmented is greater than or equal to that of the first digital asset. Based on the number of bytes of the first asset to be split, construct the maximum number of bytes to be split in the second split, and construct a random splitting function for the maximum number of bytes to be split in the second split; Based on the random segmentation function of the second segmentation, the first asset to be segmented is segmented, and so on to obtain the second digital asset, ..., the nth digital asset.

[0051] For example, if the total number of bytes of Xiao Zhang's autonomous driving algorithm's digital assets is 100M, then after converting 100M to bit units, the result is calculated using the method of dividing the highest byte number. .

[0052] Furthermore, the random segmentation function for the first segmentation is: ; ; ; Or ; ; in, This indicates the number of bytes to be determined after the first split. This indicates the number of bytes in the first digital asset obtained after the first split. This indicates the number of bytes in the first asset to be split after the first split is performed. This represents the segmentation independent variable randomly generated during the first segmentation. This represents the adjustment factor of the random partitioning function for the first partition.

[0053] Furthermore, to achieve better segmentation results, the range of values ​​for the segmentation independent variable is: The value of the adjustment factor can be set by the user in advance.

[0054] For example, if the total number of bytes of the digital assets of Xiao Zhang's autonomous driving algorithm is 100M, then the corresponding... The value is 25M. Since the ratio of 25M to 100M is significantly less than 0.5, 25M is determined to be the number of bytes in the first digital asset, and 75M is the number of bytes in the first asset to be segmented. Therefore, the 75M first asset to be segmented will be used as the target for the second segmentation, i.e., the 75M first asset to be segmented will be segmented a second time to obtain the second digital asset and the second asset to be segmented. The maximum number of bytes to be segmented and the random segmentation function during the second segmentation are the same as described above, except that... Alternative This will not be elaborated upon here.

[0055] It should be explained that calculating the number of bytes of the digital asset in each segment is to provide direction for the segmentation. For example, for a 100M digital asset of an autonomous driving algorithm, traditional methods generally segment it in half according to the number of bytes or randomly. Segmenting in half according to the number of bytes has a predictable pattern, making it easy for malicious users to piece together and reproduce. Random segmentation, on the other hand, is highly unpredictable, which increases the difficulty of subsequent reorganization of digital assets. Therefore, this invention provides a traceable randomized segmentation method based on the above approach.

[0056] S4. Encrypt the first digital asset, ..., the nth digital asset using the security verification key to obtain the first encrypted asset, ..., the nth encrypted asset.

[0057] It should be explained that, in order to further improve the security of digital assets, the embodiments of the present invention encrypt the first digital asset, ..., the nth digital asset, etc., based on the security verification key, wherein the encryption method includes, but is not limited to, encryption algorithms such as DES and RSA.

[0058] S5. Obtain the connection information of the data asset sending unit, and send the first encrypted asset, ..., the nth encrypted asset to the digital asset storage unit based on the connection information.

[0059] The connection information of the data asset sending unit includes, but is not limited to, its IP address and dial-up information of the network. Once the connection information of the data asset sending unit is obtained, the unit can be connected to, and the first encrypted asset, ..., the nth encrypted asset can be sent to the digital asset storage unit, thereby completing the secure management of digital assets.

[0060] In summary, this invention constructs a digital asset management system based on the more secure blockchain to improve the security of data assets. In order to prevent the functions of the digital asset management system from being too centralized, thereby causing the digital asset management system to become bloated and sluggish, this invention differentiates the functions of the digital asset management system, that is, the digital asset management system is divided into a digital asset verification unit, a digital asset storage unit, and a data asset sending unit.

[0061] Furthermore, this invention utilizes a digital asset verification unit to perform security verification on users to prevent unauthorized users from logging into the digital asset management system. At the same time, to prevent the theft of the overall digital assets, after acquiring the user's digital assets, the digital assets are segmented and then encrypted, so that each encrypted digital asset has a strict correspondence with the user, thereby improving security and enhancing the security verification strength of digital assets and users who upload digital assets.

[0062] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for secure management of digital assets based on blockchain, characterized in that, The method includes: The system receives a digital asset upload instruction initiated by a user and starts a digital asset management system based on the instruction. The digital asset management system is built on blockchain technology and includes a digital asset verification unit, a digital asset storage unit, and a data asset sending unit. The digital asset verification unit performs security verification on users. If a user passes the security verification of the digital asset supervision unit, a security verification key is generated. Acquire the user's digital assets, and segment the digital assets to obtain the first digital asset, ..., the nth digital asset; The first digital asset, ..., the nth digital asset are encrypted using the security verification key to obtain the first encrypted asset, ..., the nth encrypted asset; Obtain the connection information of the data asset sending unit, and send the first encrypted asset, ..., the nth encrypted asset to the digital asset storage unit based on the connection information.

2. The digital asset security management method as described in claim 1, characterized in that, The process of using a digital asset verification unit to perform security verification on the user, and generating a security verification key if the user passes the security verification by the digital asset supervision unit, includes: Identify the client that initiated the digital asset upload command from the user, and obtain the command initiating client, which includes the username and password of the user; Obtain the device code of the device that supports the client running the command; A secure verification signature is generated based on the username, password, and device code. Activate the user authentication unit of the digital asset management system; Determine whether a registration verification signature identical to the security verification signature exists in the user identity authentication unit. If no registration verification signature identical to the security verification signature exists in the user identity authentication unit, generate a user registration reminder instruction and send it to the instruction initiating client. The user registration reminder instruction indicates that the user has failed the security verification of the digital asset supervision unit. If the user identity authentication unit contains a registration verification signature that is identical to the security verification signature, it means that the user has passed the security verification of the digital asset supervision unit, and the user's location information and biometric features are then obtained. A secure verification key is generated based on the user's location information and biometric characteristics.

3. The digital asset security management method as described in claim 2, characterized in that, The step of generating a security verification signature based on the username, password, and device code includes: The username, password, and device code are all converted to binary to obtain a binary name, a binary password, and a binary device code. Compare the lengths of the binary name and the binary cipher. For the shorter binary name and the binary cipher, perform a trailing zero operation and then perform a bitwise AND operation to obtain the interactive cipher. Compare the lengths of the device code and the interaction password, perform a trailing zero operation on the shorter device code or interaction password, and then perform an OR operation to obtain the user equipment mixed code; Based on a pre-built signature algorithm, a secure verification signature for the user equipment hybrid code is generated, wherein there is a one-to-one correspondence between the secure verification signature and the user equipment hybrid code.

4. The digital asset security management method as described in claim 2, characterized in that, The generation of a security verification key based on the user's location information and biometrics includes: Obtain the location information of the digital asset regulatory unit, wherein the location information of the digital asset regulatory unit is composed of two-dimensional coordinates. express; Based on the location information of the digital asset supervision unit and the user's location information, construct the communication location parameters between the digital asset supervision unit and the user; A secure verification key is generated based on communication location parameters and biometric features.

5. The digital asset security management method as described in claim 4, characterized in that, The communication location parameters between the digital asset supervision unit and the user are constructed based on the location information of the digital asset supervision unit and the user, including: The communication location parameters are calculated using the following formula: ; ; in, This indicates the communication location parameters between the digital asset regulatory unit and the user. The weighting factor represents the formula for calculating communication location parameters. This represents the distance value calculated based on the location information of the digital asset regulatory unit and the user's location information. This indicates the bandwidth value of the client that initiated the command at the current time. This indicates the amount of digital asset data that the data asset sending unit can receive from the instruction initiating client within a unit of time.

6. The digital asset security management method as described in claim 4, characterized in that, The generation of a security verification key based on communication location parameters and biometric features includes: Encryption operations are performed on biometric features to obtain encrypted biometric features; The communication location parameters are used as the feature header of the encrypted biometric feature, and combined to obtain the biometric location feature. Determine the number of bytes in the biological location feature. If the number of bytes in the biological location feature is greater than the specified number of bytes, compress the biological location feature until the number of bytes in the biological location feature is less than or equal to the specified number of bytes. Perform a hash operation on the biological location features to obtain the biological location hash value; Two factors to be encrypted are generated, and based on a symmetric encryption algorithm, the biometric location hash value is used as the key to encrypt the two factors to obtain a security verification public key and a security verification private key. The combination of the security verification public key and the security verification private key is the security verification key.

7. The digital asset security management method as described in claim 1, characterized in that, The process of segmenting the digital assets to obtain a first digital asset, ..., an nth digital asset includes: The total number of digital assets n obtained from the segmentation is calculated based on the communication location parameters; Before performing the split, the number of bytes of the first digital asset, ..., the number of bytes of the nth digital asset are calculated sequentially; Based on the corresponding number of bytes, the digital asset is segmented to obtain the first digital asset, ..., the nth digital asset.

8. The digital asset security management method as described in claim 7, characterized in that, The calculation of the total number of digital assets n obtained from the segmentation based on the communication location parameters includes: The total number of digital assets, n, is calculated based on the following formula: ; in, The integer operator is ||, and the absolute value is ||. The first weighting factor in the formula for calculating the total number of digital assets is... This indicates the communication location parameters between the digital asset regulatory unit and the user. It is the second weighting factor in the formula for calculating the total number of digital assets.

9. The digital asset security management method as described in claim 7, characterized in that, The calculation of the number of bytes of the first digital asset, ..., the number of bytes of the nth digital asset includes: Obtain the total number of bytes of the digital asset, and calculate the highest number of bytes for the first segmentation based on the total number of bytes. The calculation method for the highest number of bytes is as follows: in, This indicates the highest number of bytes in the first segmentation. This represents the total number of bytes in the digital asset. Construct a random segmentation function for the first segmentation based on the highest number of bytes in the first segmentation; Based on the random segmentation function of the first segmentation, the digital asset is segmented for the first time to obtain the first digital asset and the first asset to be segmented. Based on the number of bytes of the first asset to be split, construct the maximum number of bytes to be split in the second split, and construct a random splitting function for the maximum number of bytes to be split in the second split; Based on the random segmentation function of the second segmentation, the first asset to be segmented is segmented, and so on to obtain the second digital asset, ..., the nth digital asset.

10. The digital asset security management method as described in claim 9, characterized in that, The random segmentation function for the first segmentation is: ; ; ; Or ; ; in, This indicates the number of bytes to be determined after the first split. This indicates the number of bytes in the first digital asset obtained after the first split. This indicates the number of bytes in the first asset to be split after the first split is performed. This represents the segmentation independent variable randomly generated during the first segmentation, and the range of values ​​for the segmentation independent variable is [value missing]. ], This represents the adjustment factor of the random partitioning function for the first partition.