Digital asset identity authentication and authorization management system based on DID and programmable object
By using three-layer DID digital identity technology and an improved VF2 object encapsulation algorithm and TabPFN network, a digital asset identity authentication and authorization management system is constructed. This solves the problems of inconsistent identity binding and non-compliant authorization policy judgment in the digital asset management system, and achieves highly reliable, secure and traceable digital asset management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Filing Date
- 2026-05-28
- Publication Date
- 2026-07-10
AI Technical Summary
Existing digital asset management systems lack decentralized identity binding mechanisms, making it difficult to maintain consistency in asset ownership, usage, and authorization request relationships across platforms. This leads to issues such as impersonation, identity mismatch, and unclear authorization sources. Furthermore, the authorization policy determination methods lack constraints on DID link consistency and programmable object rules, making it difficult to generate trustworthy, compliant, and auditable authorization policies.
Employing three-layer DID digital identity technology, an improved VF2 object encapsulation algorithm, and an improved dual-constraint TabPFN network, a digital asset identity authentication and authorization management system is constructed. This system includes modules for digital asset data access, DID identity generation and binding, programmable object construction, identity authentication, authorization policy management, and secure communication and authorization execution. This achieves high identity credibility, strong compliance in authorization judgment, high security in digital asset circulation, and traceability of the authorization process.
It improves the integrity of user data asset management, the credibility of three-layer DID digital identity binding, the security of user asset account management, and the traceability of the authorization management process, ensuring the accuracy and compliance of authorization policy judgment and enhancing the security and credibility of digital asset circulation.
Smart Images

Figure CN122372224A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent logistics and unmanned warehouse scheduling technology, and in particular to a digital asset identity authentication and authorization management system based on DID and programmable objects. Background Technology
[0002] With the increasing demand for digital asset trading, digital collectible circulation, data element ownership confirmation, and cross-platform authorization, security control technologies for digital asset identity authentication, trusted entity binding, and authorization policy management have received widespread attention. Existing digital asset management systems primarily rely on account permissions, centralized identity authentication, static access control lists, or single signature verification methods for asset access and authorization management. However, these methods commonly suffer from the following problems in practical applications: The lack of a unified decentralized identity binding mechanism among digital assets, asset holders, asset users, and authorization initiators makes it difficult to maintain consistency in asset ownership, usage, and authorization request relationships across platforms. This can easily lead to issues such as impersonation, identity mismatch, and unclear authorization sources. Digital asset authorization rules are typically stored using fixed fields or manual configuration, making it difficult to uniformly encapsulate access authorization rules, usage authorization rules, circulation authorization rules, revocation authorization rules, and secondary authentication trigger rules with object states. This results in non-compliant authorization results even in revoked, frozen, expired, or prohibited circulation states. Existing authorization policy determination methods are mostly based on static rules or ordinary classification models, lacking joint modeling of DID link consistency and programmable object rule constraints. This makes it difficult to generate reliable, compliant, and auditable authorization policy determination results under conditions of changing authorization request data, complex identity binding relationships, and diverse asset circulation scenarios.
[0003] Therefore, how to provide a digital asset identity authentication and authorization management system based on DID and programmable objects is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0004] One objective of this invention is to propose a digital asset identity authentication and authorization management system based on DID and programmable objects. This invention fully utilizes three-layer DID digital identity technology, an improved VF2 object encapsulation algorithm, and an improved dual-constraint TabPFN network. It details the process of data assetization access, DID identity binding, programmable object instance construction, identity authentication, authorization policy determination, secure authorization execution, and audit traceability for user personal information, user online behavior information, and user asset account information. It has the advantages of high identity credibility, strong compliance of authorization determination, high security of digital asset circulation, and traceability of the authorization process.
[0005] The digital asset identity authentication and authorization management system based on DID and programmable objects according to embodiments of the present invention includes the following modules: The digital asset data access module is used to perform on-chain data storage, data ownership confirmation, data evaluation, data operation record and data usage record processing on the data to be managed, and generate a digital asset registration dataset of the digital assets to be managed. The DID identity generation and binding module is used to establish a three-layer DID digital identity structure for users based on the digital asset registration dataset, including user basic identity DID, user behavior identity DID, and user asset identity DID, and to establish identity binding relationships to obtain DID identity binding results. The programmable object construction module is used to construct programmable object instances based on the digital asset registration dataset and DID identity binding results using an improved VF2 object encapsulation algorithm. The digital asset identity authentication module is used to authenticate the DID identity binding result based on the programmable object instance and authorization request data, and obtain the identity authentication result. The digital asset authorization policy management module is used to perform authorization policy determination through an improved double-constraint TabPFN network when the identity authentication result is successful. This generates a compliant authorization policy probability vector and determines the authorization policy determination result of the digital asset to be managed based on the compliant authorization policy probability vector. The secure communication and authorization execution module is used to generate authorization tokens, and to sign, AES-GCM encrypted transmission, decrypt and authenticate, and verify the validity of the authorization tokens. When the validity verification passes, the authorization control operation is executed according to the authorization policy judgment result. The authorization record audit and traceability module is used to record the authorization management process of digital assets to be managed and generate an authorization audit link.
[0006] Optionally, the digital asset data access module specifically includes: Collect digital asset management data of digital assets to be managed. The digital asset management data includes basic digital asset data, asset holder data, asset user data, user personal information data, user online behavior data, user asset account data, data on-chain evidence storage data, data ownership confirmation data, data evaluation data, data operation data, data usage data, authorization request data, and asset transfer scenario data. Configure data association identifiers for digital asset management data, and organize and associate digital asset management data based on data association identifiers to generate a digital asset registration dataset; The data association identifiers include digital asset number, subject identifier, user basic identity DID, user behavior identity DID, user asset identity DID, asset account address, authorization request number, request time, and asset transfer scenario identifier.
[0007] Optionally, the DID identity generation and binding module specifically includes: Based on the digital asset registration dataset, DID identity identifiers are generated, specifically as follows: user basic identity DID is generated based on user personal information data; user behavior identity DID is generated based on user online behavior data; user asset identity DID is generated based on user asset account data and digital asset basic data; digital asset DID is generated based on digital asset basic data; holder entity DID is generated based on asset holder entity data; user entity DID is generated based on asset user entity data; and authorization initiator entity DID is generated based on authorization request data. Construct DID documents corresponding to DID identity identifiers, each DID document including DID identifier, public key information, authentication method, server endpoint, identity status, data sovereignty declaration field, and document update time; Establish identity binding relationships based on DID identity identifiers and data association identifiers; The identity binding relationships include: the behavior attribution binding relationship between the user's basic identity DID and the user's behavior identity DID; the asset account binding relationship between the user's basic identity DID and the user's asset identity DID; the asset attribution binding relationship between the user's asset identity DID and the digital asset DID; the asset holding binding relationship between the digital asset DID and the holding entity DID; the asset use binding relationship between the digital asset DID and the user entity DID; the authorization request binding relationship between the digital asset DID and the authorization initiating entity DID; the authorization source binding relationship between the holding entity DID and the authorization initiating entity DID; and the requesting entity binding relationship between the user entity DID and the authorization initiating entity DID. Combine the DID identity identifier, DID document, and identity binding relationship to generate the DID identity binding result.
[0008] Optionally, the programmable object construction module specifically includes: Based on the digital asset registration dataset and DID identity binding results, authorization rules, object status, and signature verification fields are generated. Based on the DID identity binding results, authorization rules, object status, and signature verification fields, construct an asset identity rule graph; Based on authorization rules and asset transfer scenario data, a set of candidate programmable object template diagrams is constructed. During the VF2 matching process, the object state nodes in the asset identity rule graph are read, and state constraint pruning is performed on the candidate programmable object template graph set according to the object state corresponding to the object state node to obtain the pruned programmable object template graph set. During the VF2 candidate node matching process, the asset identity rule graph and the set of pruned programmable object template graphs are matched to obtain a set of candidate matching paths. Based on the DID identity identifier, DID document, identity binding relationship and signature verification field, the DID link consistency verification is performed on the candidate matching path set to obtain the DID link consistent matching path set. The DID link consistency verification specifically involves: deleting candidate matching paths that do not satisfy the identity binding relationship, and deleting candidate matching paths whose signature subject DID, public key index, or signature verification status in the signature verification field is inconsistent with the DID document. Based on node type consistency, edge relationship consistency, state constraint consistency, and DID link consistency, the target matching path and the target programmable object template are determined from the DID link consistency matching path set; Based on the target matching path, the digital asset DID, holder DID, user DID, authorization initiator DID, identity binding relationship, authorization rules, object status, DID document and signature verification field are encapsulated into the target programmable object template to generate a programmable object instance corresponding to the digital asset to be managed. The programmable object instance includes an asset identity field, a subject binding field, an authorization rule field, an object status field, a signature verification field, and an object instance field.
[0009] Optionally, the identity authentication includes DID identity identifier consistency authentication, DID document validity authentication, identity binding relationship integrity authentication, authorization request subject consistency authentication, and programmable object instance consistency authentication; When all identity authentications are successful, a successful identity authentication result is obtained; when one identity authentication fails, a failed identity authentication result is obtained.
[0010] Optionally, the improved dual-constraint TabPFN network includes an authorization decision sample input layer, a field token encoding layer, a DID link consistency constraint layer, a TabPFN context reasoning layer, a programmable object rule mask layer, and a compliance authorization policy output layer; The authorization determination sample input layer combines programmable object instances and authorization request data into an authorization determination sample; The field token encoding layer encodes each field value in the authorization judgment sample through linear transformation and layer normalization, and arranges them in order of field value to obtain a field token vector sequence. The DID link consistency constraint layer performs bidirectional conflict suppression attention constraint processing on the field token vector sequence to obtain the DID link constraint vector. In the TabPFN context reasoning layer, the field token vector sequence and the DID link constraint vector are concatenated, and multi-layer context reasoning is performed through multi-layer attention interaction and feedforward mapping. The context reasoning results are pooled to obtain the authorization policy latent feature vector. The programmable object rule mask layer constructs a rule mask vector based on the authorization rule field and object state field in the programmable object instance; The rule mask vector includes access permission mask value, usage permission mask value, transfer permission mask value, revocation permission mask value, and secondary authentication trigger result mask value; The rules for constructing the rule mask vector include state restriction rules and authorization restriction rules; In the compliance authorization policy output layer, the latent feature vector of the authorization policy is linearly transformed and activated by Sigmoid to obtain the original authorization policy probability vector; Based on the rule mask vector, the original authorization policy probability vector is subjected to element-wise mask constraint processing to obtain the compliant authorization policy probability vector; according to each compliance probability value in the compliant authorization policy probability vector, the authorization policy judgment result of the digital asset to be managed is determined, and the authorization policy judgment result includes access permission, usage permission, transfer permission, revocation permission and secondary authentication trigger result.
[0011] Optionally, the DID link consistency constraint layer performs bidirectional conflict suppression attention constraint processing on the field token vector sequence, specifically including: The DID token vector set is formed by filtering the digital asset DID token vector, the holder DID token vector, the user DID token vector, and the authorizing initiator DID token vector from the field token vector sequence. Based on the subject binding field in the programmable object instance, determine the type of identity binding relationship between the p-th DID token vector and the q-th DID token vector in the DID token vector set, and construct the identity binding relationship identifier; Select the query projection matrix, key projection matrix, and value projection matrix corresponding to the identity binding relationship type, and map the p-th DID token vector to a DID query vector through the query projection matrix. Map the q-th DID token vector to a DID key vector and a DID value vector through the key projection matrix and value projection matrix. The p-th DID token vector and the q-th DID token vector are concatenated and mapped in forward and reverse order respectively to obtain the forward link representation vector and the reverse link representation vector; Calculate the L1 norm of the difference between the forward link representation vector and the reverse link representation vector to obtain the bidirectional link consistency difference between the p-th DID token vector and the q-th DID token vector; The DID query vector and DID key vector are subjected to attention operation to obtain the initial DID attention score; the bidirectional link consistency difference is negatively suppressed to obtain the link difference suppression score; and the identity binding relationship identifier is missing to obtain the identity binding missing suppression score. The initial DID attention score, link difference suppression score, and identity binding missing suppression score are added together to obtain the conflict suppression link attention score; The conflict suppression link attention score is normalized using Softmax to obtain the conflict suppression link attention coefficient between the p-th DID token vector and the q-th DID token vector. Based on the conflict suppression link attention coefficient, the DID value matrix is weighted and aggregated to generate the DID link consistency representation vector of the p-th DID token vector; By concatenating and mapping the DID link consistency representation vectors corresponding to each DID token vector and activating them with Sigmoid, the DID link constraint vector is obtained.
[0012] Optionally, the state restriction rules specifically include: If the object is in a revoked state, set the access permission mask, usage permission mask, and transfer permission mask to 0; if the object is in a frozen state, read-only state, or transfer prohibited state, set the transfer permission mask to 0; if the object is in an expired state, set the usage permission mask to 0. If the object status is pending ownership confirmation, then set the access permission mask value, usage permission mask value, and transfer permission mask value to 0; If the object status is under risk observation, set the access permission mask value, usage permission mask value, and flow permission mask value to 0, and set the secondary authentication trigger result mask value to 1. The authorization rules and restrictions specifically include: If the authorization rule field does not include an access authorization rule, the access permission mask value is set to 0; if the authorization rule field does not include a use authorization rule, the use permission mask value is set to 0. If the authorization rule field does not include a transfer authorization rule, then the transfer permission mask value is set to 0; if the authorization rule field does not include a revocation authorization rule, then the revocation permission mask value is set to 0. If the authorization rule field includes a secondary authentication trigger rule, then the secondary authentication trigger result mask value will be set to 1.
[0013] Optionally, the secure communication and authorization execution module specifically includes: Based on the authorization policy determination result, the digital asset DID of the digital asset to be managed, and the authorization request data, generate token payload data; Calculate the hash digest of the token payload data to obtain the token digest. Based on the private key corresponding to the authorized initiator's DID, the token digest is digitally signed to generate a token signature; The token payload data, token digest, and token signature are combined to generate an authorization token; A session key is generated using a cryptographically secure random number generator. The authorization token is then symmetrically encrypted using AES-GCM and the session key to obtain the token ciphertext and the authentication tag. Based on the public key information in the DID identity binding result, the session key is asymmetrically encrypted to obtain the encrypted session key; Combine the token ciphertext, authentication tag, and encrypted session key to generate an encrypted authorization token; Upon receiving the encrypted authorization token, the encrypted session key is decrypted using the private key that matches the public key information in the DID identity binding result to obtain the session key; the token ciphertext is then decrypted and authenticated based on the session key, authentication tag, and AES-GCM to obtain the decryption authorization token. The validity of the decryption authorization token is verified. When the decryption authorization token passes the validity verification, the authorization control operation is executed according to the authorization policy judgment result. The validity verification includes token integrity verification, token signature verification, token time validity verification, authorization request number consistency verification, digital asset DID consistency verification, authorization initiator DID consistency verification, and authorization policy determination result consistency verification. The authorization control operations include allowing access, restricting access, denying access, allowing use, restricting use, allowing circulation, prohibiting circulation, revoking authorization, and triggering secondary authentication.
[0014] Optionally, the authorization management process includes a digital asset data access process, a DID identity generation and binding process, a programmable object instance construction process, a digital asset identity authentication process, an authorization policy determination process, and a secure communication and authorization execution process. The authorization audit link is generated based on the digital asset DID, the holder DID, the user DID, the authorization initiator DID, and the authorization request number.
[0015] The beneficial effects of this invention are: This invention collects user personal information, internet behavior information, user asset account information, and data assetization records through a digital asset data access module, generating a digital asset registration dataset to improve the integrity and traceability of the user data asset formation process. A three-layer DID digital identity structure, consisting of a user basic identity DID, a user behavior identity DID, and a user asset identity DID, is constructed through a DID identity generation and binding module. Identity binding relationships are established between user identity, behavior data, asset accounts, and digital assets, improving the credibility of user data sovereignty expression and the consistency of identity binding relationships. In the programmable object construction stage, an improved VF2 object encapsulation algorithm is used to construct an asset identity rule graph and a set of candidate programmable object template graphs. Combined with state constraint pruning and DID link consistency verification, the target programmable object template is determined, generating programmable object instances. This avoids generating mismatched programmable object instances in revoked, frozen, expired, read-only, prohibited-transfer, or ownership-pending states, improving the accuracy and state compliance of digital asset objectification encapsulation. The digital asset identity authentication module performs DID identity binding result consistency authentication, DID document validity authentication, identity binding relationship integrity authentication, authorization request subject consistency authentication, and programmable object instance consistency authentication to improve the reliability of identity authentication before user asset account and digital asset entry policy determination. Furthermore, through the DID link consistency constraint layer and programmable object rule mask layer in the improved dual-constraint TabPFN network, bidirectional conflict suppression attention constraint processing is applied to the field token vector sequence. A rule mask vector is generated based on the authorization rule field and object state field, and element-wise mask constraints are applied to the original authorization policy probability vector to obtain a compliant authorization policy probability vector, improving the accuracy and compliance of access rights, usage rights, transfer rights, revocation rights, and secondary authentication trigger results. Finally, the secure communication and authorization execution module performs signing, AES-GCM encrypted transmission, decryption authentication, and validity verification of the authorization token. The authorization record audit and traceability module generates an authorization audit link to improve the security of user data asset transfer, the credibility of authorization execution, and the traceability of the authorization process. Therefore, this invention can improve the integrity of user data asset management, the credibility of three-layer DID digital identity binding, the security of user asset account management, and the traceability of the authorization management process. Attached Figure Description
[0016] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a schematic diagram of the modules of the digital asset identity authentication and authorization management system based on DID and programmable objects proposed in this invention; Figure 2 This is a flowchart of the improved VF2 object encapsulation algorithm in the digital asset identity authentication and authorization management system based on DID and programmable objects proposed in this invention; Figure 3 This is a flowchart of the improved dual-constraint TabPFN network structure in the digital asset identity authentication and authorization management system based on DID and programmable objects proposed in this invention. Detailed Implementation
[0017] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0018] refer to Figures 1-3 A digital asset identity authentication and authorization management system based on DID and programmable objects includes the following modules: The digital asset data access module is used to perform on-chain data storage, data ownership confirmation, data evaluation, data operation record and data usage record processing on the data to be managed, and generate a digital asset registration dataset of the digital assets to be managed. The DID identity generation and binding module is used to establish a three-layer DID digital identity structure for users based on the digital asset registration dataset, including user basic identity DID, user behavior identity DID, and user asset identity DID, and to establish identity binding relationships to obtain DID identity binding results. The programmable object construction module is used to construct programmable object instances based on the digital asset registration dataset and DID identity binding results using an improved VF2 object encapsulation algorithm. The digital asset identity authentication module is used to authenticate the DID identity binding result based on the programmable object instance and authorization request data, and obtain the identity authentication result. The digital asset authorization policy management module is used to perform authorization policy determination through an improved double-constraint TabPFN network when the identity authentication result is successful. This generates a compliant authorization policy probability vector and determines the authorization policy determination result of the digital asset to be managed based on the compliant authorization policy probability vector. The secure communication and authorization execution module is used to generate authorization tokens, and to sign, AES-GCM encrypted transmission, decrypt and authenticate, and verify the validity of the authorization tokens. When the validity verification passes, the authorization control operation is executed according to the authorization policy judgment result. The authorization record audit and traceability module is used to record the authorization management process of digital assets to be managed and generate an authorization audit link.
[0019] In this embodiment, the digital asset data access module specifically includes: Collect digital asset management data of digital assets to be managed. The digital asset management data includes basic digital asset data, asset holder data, asset user data, user personal information data, user online behavior data, user asset account data, data on-chain evidence storage data, data ownership confirmation data, data evaluation data, data operation data, data usage data, authorization request data, and asset transfer scenario data. Configure data association identifiers for digital asset management data, and organize and associate digital asset management data based on data association identifiers to generate a digital asset registration dataset; The data association identifiers include digital asset number, subject identifier, user basic identity DID, user behavior identity DID, user asset identity DID, asset account address, authorization request number, request time, and asset transfer scenario identifier.
[0020] In this embodiment, the DID identity generation and binding module specifically includes: Based on the digital asset registration dataset, DID identity identifiers are generated, specifically as follows: user basic identity DID is generated based on user personal information data; user behavior identity DID is generated based on user online behavior data; user asset identity DID is generated based on user asset account data and digital asset basic data; digital asset DID is generated based on digital asset basic data; holder entity DID is generated based on asset holder entity data; user entity DID is generated based on asset user entity data; and authorization initiator entity DID is generated based on authorization request data. Construct DID documents corresponding to DID identity identifiers, each DID document including DID identifier, public key information, authentication method, server endpoint, identity status, data sovereignty declaration field, and document update time; Establish identity binding relationships based on DID identity identifiers and data association identifiers; The identity binding relationships include: the behavior attribution binding relationship between the user's basic identity DID and the user's behavior identity DID; the asset account binding relationship between the user's basic identity DID and the user's asset identity DID; the asset attribution binding relationship between the user's asset identity DID and the digital asset DID; the asset holding binding relationship between the digital asset DID and the holding entity DID; the asset use binding relationship between the digital asset DID and the user entity DID; the authorization request binding relationship between the digital asset DID and the authorization initiating entity DID; the authorization source binding relationship between the holding entity DID and the authorization initiating entity DID; and the requesting entity binding relationship between the user entity DID and the authorization initiating entity DID. Combine the DID identity identifier, DID document, and identity binding relationship to generate the DID identity binding result.
[0021] In this embodiment, the programmable object construction module specifically includes: Based on the digital asset registration dataset and DID identity binding results, authorization rules, object status, and signature verification fields are generated. The authorization rules include access authorization rules, usage authorization rules, circulation authorization rules, revocation authorization rules, and secondary authentication triggering rules. The object status includes normal status, revoked status, frozen status, authorized expiration status, read-only status, prohibited circulation status, ownership pending confirmation status, and risk observation status. The signature verification fields include the signature subject DID, public key index, signature digest, signature time, and signature verification status. Based on the DID identity binding result, authorization rules, object status, and signature verification field, an asset identity rule graph is constructed. The asset identity rule graph includes digital asset DID nodes, holder entity DID nodes, user entity DID nodes, authorization initiator entity DID nodes, DID document nodes, identity binding relationship nodes, authorization rule nodes, object status nodes, and signature verification nodes. Based on authorization rules and asset transfer scenario data, a set of candidate programmable object template diagrams is constructed; The candidate programmable object template diagram set includes access authorization template diagram, usage authorization template diagram, flow authorization template diagram, sub-authorization template diagram, continued use authorization template diagram, editing authorization template diagram, transfer authorization template diagram, and full authorization template diagram; each candidate programmable object template diagram includes asset identity field node, subject binding field node, authorization rule field node, object status field node, signature verification field node, and object instance field node; During VF2 matching, the object state nodes in the asset identity rule graph are read, and state constraint pruning is performed on the candidate programmable object template graph set based on the object state corresponding to the object state node, resulting in a pruned programmable object template graph set, specifically: If the object's status is revoked, delete the access authorization template diagram, the usage authorization template diagram, and the transfer authorization template diagram; if the object's status is frozen, delete the transfer authorization template diagram and the sub-authorization template diagram. If the object's status is "authorization expired", delete the "continue to use" authorization template image; if the object's status is "read-only", delete the "edit authorization template image" and "transfer authorization template image". If the object status is "transfer prohibited", delete the transfer authorization template diagram; if the object status is "ownership pending confirmation", delete the full authorization template diagram. During the VF2 candidate node matching process, the asset identity rule graph and the set of pruned programmable object template graphs are matched to obtain a set of candidate matching paths. Based on the DID identity identifier, DID document, identity binding relationship and signature verification field, the DID link consistency verification is performed on the candidate matching path set to obtain the DID link consistent matching path set. Specifically, DID link consistency verification involves deleting candidate matching paths that do not meet the identity binding relationship, and deleting candidate matching paths whose signature subject DID, public key index, or signature verification status in the signature verification field is inconsistent with the DID document. Based on node type consistency, edge relationship consistency, state constraint consistency, and DID link consistency, the target matching path and the target programmable object template are determined from the DID link consistency matching path set; In this invention, the target matching path is a node mapping path formed between the asset identity rule graph and the candidate programmable object template graph; therefore, the candidate programmable object template graph corresponding to the target matching path is the target template graph that matches the DID identity binding result, authorization rules and object status of the digital asset to be managed, and the programmable object template corresponding to the target template graph is determined as the target programmable object template. Based on the target matching path, the digital asset DID, holder DID, user DID, authorization initiator DID, identity binding relationship, authorization rules, object status, DID document and signature verification field are encapsulated into the target programmable object template to generate a programmable object instance corresponding to the digital asset to be managed. Programmable object instances include asset identity fields, subject binding fields, authorization rule fields, object status fields, signature verification fields, and object instance fields.
[0022] In this invention, the improved VF2 object encapsulation algorithm introduces state constraint pruning and DID link consistency verification based on the standard VF2 algorithm. State constraint pruning removes mismatched candidate programmable object template diagrams based on object state, avoiding the generation of erroneous objects in revoked, frozen, expired, or prohibited states. DID link consistency verification removes candidate matching paths with inconsistent identity links based on DID identity identifier, DID document, identity binding relationship, and signature verification fields. Through these improvements, the improved VF2 object encapsulation algorithm can not only complete the structural matching between the asset identity rule diagram and the candidate programmable object template diagram, but also simultaneously constrain object state, identity link, and signature verification relationship during the matching process. This improves the accuracy of target programmable object template selection, reduces the risk of generating non-compliant programmable object instances in revoked, frozen, expired, read-only, prohibited, or ownership-pending states, and enhances the security, compliance, and consistency of digital asset programmable object construction.
[0023] In this embodiment, identity authentication includes DID identity identifier consistency authentication, DID document validity authentication, identity binding relationship integrity authentication, authorization request subject consistency authentication, and programmable object instance consistency authentication; DID identity consistency authentication involves comparing the digital asset DID, holder DID, user DID, and authorizing initiator DID associated with the programmable object instance with the digital asset DID, holder DID, user DID, and authorizing initiator DID in the DID identity binding result for consistency. DID document validity authentication is performed by validating the DID identifier, public key information, authentication method, server endpoint, identity status, and document update time based on the DID document in the DID identity binding result. The integrity authentication of identity binding relationships is as follows: based on the identity binding relationships in the DID identity binding results, the integrity of asset holding binding relationships, asset usage binding relationships, authorization request binding relationships, authorization source binding relationships, and request subject binding relationships is verified. The authorization request subject consistency authentication is performed by comparing the authorization initiator DID in the authorization request data with the authorization initiator DID in the DID identity binding result. Programmable object instance consistency authentication is performed as follows: based on the DID identity binding result, the consistency of the asset identity field, subject binding field, authorization rule field, object status field and object instance field in the programmable object instance is verified. When all identity authentications are successful, a successful identity authentication result is obtained; when one identity authentication fails, a failed identity authentication result is obtained.
[0024] In this embodiment, the improved dual-constraint TabPFN network includes an authorization decision sample input layer, a field token encoding layer, a DID link consistency constraint layer, a TabPFN context reasoning layer, a programmable object rule mask layer, and a compliance authorization policy output layer. The authorization determination sample input layer combines programmable object instances and authorization request data into an authorization determination sample; The field token encoding layer encodes each field value in the authorization judgment sample through linear transformation and layer normalization, and arranges them in order of field value to obtain a field token vector sequence. The DID link consistency constraint layer performs bidirectional conflict suppression attention constraint processing on the field token vector sequence to obtain the DID link constraint vector. In the TabPFN context reasoning layer, the field token vector sequence and the DID link constraint vector are concatenated, and multi-layer context reasoning is performed through multi-layer attention interaction and feedforward mapping. The context reasoning results are pooled to obtain the authorization policy latent feature vector. The programmable object rule mask layer constructs a rule mask vector based on the authorization rule field and object state field in the programmable object instance; The rule mask vector includes access permission mask value, usage permission mask value, flow permission mask value, revocation permission mask value, and secondary authentication trigger result mask value; The rules for constructing the rule mask vector include state restriction rules and authorization restriction rules; In the compliance authorization policy output layer, the latent feature vector of the authorization policy is linearly transformed and activated by Sigmoid to obtain the original authorization policy probability vector; Based on the rule mask vector, the original authorization policy probability vector is subjected to element-wise mask constraint processing to obtain the compliant authorization policy probability vector. Based on the compliance probability values in the compliance authorization strategy probability vector, the authorization strategy determination result of the digital asset to be managed is determined. The authorization strategy determination result includes access permissions, usage permissions, transfer permissions, revocation permissions, and secondary authentication trigger results.
[0025] In this embodiment, the DID link consistency constraint layer performs bidirectional conflict suppression attention constraint processing on the field token vector sequence, specifically including: The DID token vector set is formed by filtering the digital asset DID token vector, the holder DID token vector, the user DID token vector, and the authorizing initiator DID token vector from the field token vector sequence. Based on the subject binding field in the programmable object instance, determine the type of identity binding relationship between the p-th DID token vector and the q-th DID token vector in the DID token vector set, and construct the identity binding relationship identifier; where p and q are the indices of the DID token vector set; The types of identity binding relationships include asset holding binding relationship, asset use binding relationship, authorization request binding relationship, authorization source binding relationship, and request subject binding relationship; Specifically, the identity binding relationship identifier is as follows: if there is an identity binding relationship between the p-th DID token vector and the q-th DID token vector, the identity binding relationship identifier is 1; otherwise, the identity binding relationship identifier is 0. Select the query projection matrix, key projection matrix, and value projection matrix corresponding to the identity binding relationship type, and map the p-th DID token vector to a DID query vector through the query projection matrix. Map the q-th DID token vector to a DID key vector and a DID value vector through the key projection matrix and value projection matrix. The p-th DID token vector and the q-th DID token vector are concatenated and mapped in forward and reverse order respectively to obtain the forward link representation vector and the reverse link representation vector; Calculate the L1 norm of the difference between the forward link representation vector and the reverse link representation vector to obtain the bidirectional link consistency difference between the p-th DID token vector and the q-th DID token vector; The DID query vector and DID key vector are subjected to attention operation to obtain the initial DID attention score; the bidirectional link consistency difference is negatively suppressed to obtain the link difference suppression score; and the identity binding relationship identifier is missing to obtain the identity binding missing suppression score. The initial DID attention score, link difference suppression score, and identity binding missing suppression score are added together to obtain the conflict suppression link attention score; The conflict suppression link attention score is normalized using Softmax to obtain the conflict suppression link attention coefficient between the p-th DID token vector and the q-th DID token vector. Based on the conflict suppression link attention coefficient, the DID value matrix is weighted and aggregated to generate the DID link consistency representation vector of the p-th DID token vector; By concatenating and mapping the DID link consistency representation vectors corresponding to each DID token vector and activating them with Sigmoid, the DID link constraint vector is obtained.
[0026] In this embodiment, the state restriction rules specifically include: If the object's state is revoked, then set the access permission mask value, usage permission mask value, and transfer permission mask value to 0; If the object is in a frozen, read-only, or prohibited transfer state, the transfer permission mask value is set to 0; if the object is in an expired authorization state, the usage permission mask value is set to 0. If the object status is pending ownership confirmation, then set the access permission mask value, usage permission mask value, and transfer permission mask value to 0; If the object status is under risk observation, set the access permission mask value, usage permission mask value, and flow permission mask value to 0, and set the secondary authentication trigger result mask value to 1. The authorization rules and restrictions specifically include: If the authorization rule field does not include an access authorization rule, the access permission mask value is set to 0; if the authorization rule field does not include a use authorization rule, the use permission mask value is set to 0. If the authorization rule field does not include a transfer authorization rule, then the transfer permission mask value is set to 0; if the authorization rule field does not include a revocation authorization rule, then the revocation permission mask value is set to 0. If the authorization rule field includes a secondary authentication trigger rule, then the secondary authentication trigger result mask value will be set to 1.
[0027] In this invention, the improved dual-constraint TabPFN network maintains the basic inference framework of the standard TabPFN network. The standard TabPFN network typically encodes the field values in the table samples into field feature vectors, and inputs the labeled samples and the samples to be predicted into the contextual inference structure. Through multi-layer attention interactions and feedforward mapping in the Transformer, it learns the implicit relationships between fields and samples, and then generates the predicted category or predicted probability based on the contextual inference results.
[0028] The improved dual-constraint TabPFN network adds a DID link consistency constraint layer and a programmable object rule mask layer to the standard TabPFN network. The DID link consistency constraint layer filters the field token vector sequence to construct a DID token vector set, and determines the identity binding relationship type between different DID token vectors based on the subject binding field. It then forms a conflict suppression link attention score by using bidirectional link consistency differences, link difference suppression scores, and identity binding missing suppression scores to obtain the DID link constraint vector. The programmable object rule mask layer constructs a rule mask vector based on the authorization rule field and object state field in the programmable object instance. It then applies element-wise mask constraints to the original authorization policy probability vector through state restriction rules and authorization rule restriction rules to obtain a compliant authorization policy probability vector.
[0029] By introducing a DID link consistency constraint layer, the improved dual-constraint TabPFN network can explicitly identify the link consistency between the digital asset DID, the holder DID, the user DID, and the authorization initiator DID during the authorization policy determination process. This reduces the risk of erroneous authorization caused by missing identity binding relationships, inconsistent authorization sources, and mismatched request subjects. By introducing a programmable object rule mask layer, the improved dual-constraint TabPFN network can directly transform object states and authorization rules into authorization output constraints, avoiding non-compliant access permissions, usage permissions, or transfer permission results in revoked, frozen, expired, ownership-pending, and risk-observation states. Therefore, compared to the standard TabPFN network, the improved dual-constraint TabPFN network can improve the identity credibility, rule compliance, and authorization security of digital asset authorization policy determination.
[0030] In this embodiment, the secure communication and authorization execution module specifically includes: Based on the authorization policy determination result, the digital asset DID of the digital asset to be managed, and the authorization request data, generate token payload data; Calculate the hash digest of the token payload data to obtain the token digest. Based on the private key corresponding to the authorized initiator's DID, the token digest is digitally signed to generate a token signature; The token payload data, token digest, and token signature are combined to generate an authorization token; A session key is generated using a cryptographically secure random number generator. The authorization token is then symmetrically encrypted using AES-GCM and the session key to obtain the token ciphertext and the authentication tag. Based on the public key information in the DID identity binding result, the session key is asymmetrically encrypted to obtain the encrypted session key; Combine the token ciphertext, authentication tag, and encrypted session key to generate an encrypted authorization token; Upon receiving the encrypted authorization token, the encrypted session key is decrypted using the private key that matches the public key information in the DID identity binding result to obtain the session key; the token ciphertext is then decrypted and authenticated based on the session key, authentication tag, and AES-GCM to obtain the decryption authorization token. The validity of the decryption authorization token is verified. When the decryption authorization token passes the validity verification, the authorization control operation is executed according to the authorization policy judgment result. Validity verification includes token integrity verification, token signature verification, token time validity verification, authorization request number consistency verification, digital asset DID consistency verification, authorization initiator DID consistency verification, and authorization policy determination result consistency verification. Authorization control operations include allowing access, restricting access, denying access, allowing use, restricting use, allowing circulation, prohibiting circulation, revoking authorization, and triggering two-factor authentication.
[0031] In this embodiment, the authorization management process includes the digital asset data access process, the DID identity identifier generation and binding process, the programmable object instance construction process, the digital asset identity authentication process, the authorization policy determination process, and the secure communication and authorization execution process. The authorization audit chain is generated based on the digital asset DID, the holder DID, the user DID, the authorization initiator DID, and the authorization request number.
[0032] Example 1: To verify the feasibility of this invention in practice, it was applied to the digital artwork licensing management scenario of a digital copyright trading platform. This platform manages digital art images, 3D model materials, and video clips, and requires identity authentication and authorization control for asset holders, material purchasers, secondary creators, and transfer applicants. Existing systems mainly rely on account login, centralized permission tables, and fixed authorization rules. In scenarios involving cross-entity authorization, temporary use, secondary sub-licensing, and freeze revocation, problems easily arise such as difficulty in tracing the source of authorization, inconsistencies between asset status and authorization results, frozen assets still being transferred, and authorization tokens being reused.
[0033] In the implementation of this invention, the platform collects digital asset management data through the digital asset data access module and generates a digital asset registration dataset based on the digital asset number, subject identifier, account address, authorization request number, request time, and asset transfer scenario identifier. Subsequently, the DID identity generation and binding module generates digital asset DIDs, holding entity DIDs, user entity DIDs, and authorization initiator DIDs, constructs DID documents, and establishes asset holding binding relationships, asset usage binding relationships, authorization request binding relationships, authorization source binding relationships, and requesting entity binding relationships, obtaining DID identity binding results. The programmable object construction module, based on the digital asset registration dataset and DID identity binding results, generates programmable object instances using an improved VF2 object encapsulation algorithm. During the construction process, it performs state constraint pruning and DID link consistency verification, eliminating candidate matching paths with object state conflicts or inconsistent identity links. The digital asset identity authentication module performs consistency authentication, validity authentication, and integrity authentication on the DID identity binding results. After successful identity authentication, the digital asset authorization policy management module inputs the programmable object instance and authorization request data into the improved dual-constraint TabPFN network to generate a compliant authorization policy probability vector and determine access permissions, usage permissions, transfer permissions, revocation permissions, and secondary authentication trigger results. Finally, the secure communication and authorization execution module generates an authorization token and performs signing, AES-GCM encrypted transmission, decryption authentication, and validity verification on the authorization token. The authorization record audit and traceability module generates an authorization audit link.
[0034] To compare and analyze the implementation effect of the system of the present invention, it is compared and analyzed with the traditional account permission table scheme and the DID authentication and fixed rule scheme. The traditional account permission table scheme uses account login, a centralized user identity table, a role permission table, and a static access control list to authorize digital asset access requests; the DID authentication and fixed rule scheme uses DID identity resolution, DID document verification, digital signature verification, and fixed authorization rule matching to authenticate and authorize digital asset access requests. The comparison results are shown in Table 1.
[0035] Table 1. Comparison of the Implementation Effects of Different Digital Asset Authorization Management Schemes
[0036] As shown in Table 1, the overall implementation effect of the system of the present invention is superior to the traditional account permission table scheme and the DID authentication and fixed rule scheme. Specifically, the identity binding accuracy rate of the system of the present invention is 98.3%, which is 8.9 percentage points and 3.7 percentage points higher than the traditional account permission table scheme and the DID authentication and fixed rule scheme, respectively; the programmable object construction success rate is 96.8%, which is 14.1 percentage points and 7.9 percentage points higher, respectively, indicating that the improved VF2 object encapsulation algorithm can improve the accuracy of object construction. Regarding authorization security, the illegal authorization interception rate of the system of the present invention is 97.6%, which is 13.5 percentage points and 7.1 percentage points higher, respectively; the false authorization rate due to state conflict is reduced to 1.2%, which is 6.6 percentage points and 3.4 percentage points lower, respectively, indicating that the present invention can effectively reduce erroneous authorizations caused by inconsistencies in identity links and object state conflicts.
[0037] Regarding authorization policy determination, the system of this invention achieves an accuracy rate of 96.9%, representing improvements of 10.6 percentage points and 6.1 percentage points respectively. This demonstrates that the improved dual-constraint TabPFN network can enhance the accuracy of determining access permissions, usage permissions, transfer permissions, revocation permissions, and secondary authentication trigger results. Furthermore, the system of this invention achieves a token transmission tampering detection rate of 99.4%, an authorization audit link integrity rate of 98.7%, and an average authorization processing time of 218ms, all superior to the two comparative schemes. Therefore, this invention demonstrates that the system of this invention can improve the credibility of digital asset identity authentication, the compliance of authorization policy determination, the security of authorization execution, and the traceability of the authorization process.
[0038] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A digital asset identity authentication and authorization management system based on DID and programmable objects, characterized in that, include: The digital asset data access module is used to perform on-chain data storage, data ownership confirmation, data evaluation, data operation record and data usage record processing on the data to be managed, and generate a digital asset registration dataset of the digital assets to be managed. The DID identity generation and binding module is used to establish a three-layer DID digital identity structure for users based on the digital asset registration dataset, including user basic identity DID, user behavior identity DID, and user asset identity DID, and to establish identity binding relationships to obtain DID identity binding results. The programmable object construction module is used to construct programmable object instances based on the digital asset registration dataset and DID identity binding results using an improved VF2 object encapsulation algorithm. The digital asset identity authentication module is used to authenticate the DID identity binding result based on the programmable object instance and authorization request data, and obtain the identity authentication result. The digital asset authorization policy management module is used to perform authorization policy determination through an improved double-constraint TabPFN network when the identity authentication result is successful. This generates a compliant authorization policy probability vector and determines the authorization policy determination result of the digital asset to be managed based on the compliant authorization policy probability vector. The secure communication and authorization execution module is used to generate authorization tokens, and to sign, AES-GCM encrypted transmission, decrypt and authenticate, and verify the validity of the authorization tokens. When the validity verification passes, the authorization control operation is executed according to the authorization policy judgment result. The authorization record audit and traceability module is used to record the authorization management process of digital assets to be managed and generate an authorization audit link.
2. The digital asset identity authentication and authorization management system based on DID and programmable objects according to claim 1, characterized in that, The digital asset data access module specifically includes: Collect digital asset management data of digital assets to be managed. The digital asset management data includes basic digital asset data, asset holder data, asset user data, user personal information data, user online behavior data, user asset account data, data on-chain evidence storage data, data ownership confirmation data, data evaluation data, data operation data, data usage data, authorization request data, and asset transfer scenario data. Configure data association identifiers for digital asset management data, and organize and associate digital asset management data based on data association identifiers to generate a digital asset registration dataset; The data association identifiers include digital asset number, subject identifier, user basic identity DID, user behavior identity DID, user asset identity DID, asset account address, authorization request number, request time, and asset transfer scenario identifier.
3. The digital asset identity authentication and authorization management system based on DID and programmable objects according to claim 1, characterized in that, The DID identity generation and binding module specifically includes: Based on the digital asset registration dataset, DID identity identifiers are generated, specifically as follows: user basic identity DID is generated based on user personal information data; user behavior identity DID is generated based on user online behavior data; user asset identity DID is generated based on user asset account data and digital asset basic data; digital asset DID is generated based on digital asset basic data; holder entity DID is generated based on asset holder entity data; user entity DID is generated based on asset user entity data; and authorization initiator entity DID is generated based on authorization request data. Construct DID documents corresponding to DID identity identifiers, each DID document including DID identifier, public key information, authentication method, server endpoint, identity status, data sovereignty declaration field, and document update time; Establish identity binding relationships based on DID identity identifiers and data association identifiers; The identity binding relationships include: the behavior attribution binding relationship between the user's basic identity DID and the user's behavior identity DID; the asset account binding relationship between the user's basic identity DID and the user's asset identity DID; the asset attribution binding relationship between the user's asset identity DID and the digital asset DID; the asset holding binding relationship between the digital asset DID and the holding entity DID; the asset use binding relationship between the digital asset DID and the user entity DID; the authorization request binding relationship between the digital asset DID and the authorization initiating entity DID; the authorization source binding relationship between the holding entity DID and the authorization initiating entity DID; and the requesting entity binding relationship between the user entity DID and the authorization initiating entity DID. Combine the DID identity identifier, DID document, and identity binding relationship to generate the DID identity binding result.
4. The digital asset identity authentication and authorization management system based on DID and programmable objects according to claim 1, characterized in that, The programmable object construction module specifically includes: Based on the digital asset registration dataset and DID identity binding results, authorization rules, object status, and signature verification fields are generated. Based on the DID identity binding results, authorization rules, object status, and signature verification fields, construct an asset identity rule graph; Based on authorization rules and asset transfer scenario data, a set of candidate programmable object template diagrams is constructed; During the VF2 matching process, the object state nodes in the asset identity rule graph are read, and state constraint pruning is performed on the candidate programmable object template graph set according to the object state corresponding to the object state node to obtain the pruned programmable object template graph set. During the VF2 candidate node matching process, the asset identity rule graph and the set of pruned programmable object template graphs are matched to obtain a set of candidate matching paths. Based on the DID identity identifier, DID document, identity binding relationship and signature verification field, the DID link consistency verification is performed on the candidate matching path set to obtain the DID link consistent matching path set. The DID link consistency verification specifically involves: deleting candidate matching paths that do not satisfy the identity binding relationship, and deleting candidate matching paths whose signature subject DID, public key index, or signature verification status in the signature verification field is inconsistent with the DID document. Based on node type consistency, edge relationship consistency, state constraint consistency, and DID link consistency, the target matching path and the target programmable object template are determined from the DID link consistency matching path set; Based on the target matching path, the digital asset DID, holder DID, user DID, authorization initiator DID, identity binding relationship, authorization rules, object status, DID document and signature verification field are encapsulated into the target programmable object template to generate a programmable object instance corresponding to the digital asset to be managed. The programmable object instance includes an asset identity field, a subject binding field, an authorization rule field, an object status field, a signature verification field, and an object instance field.
5. The digital asset identity authentication and authorization management system based on DID and programmable objects according to claim 1, characterized in that, The identity authentication includes DID identity identifier consistency authentication, DID document validity authentication, identity binding relationship integrity authentication, authorization request subject consistency authentication, and programmable object instance consistency authentication; When all identity authentications are successful, a successful identity authentication result is obtained; when one identity authentication fails, a failed identity authentication result is obtained.
6. The digital asset identity authentication and authorization management system based on DID and programmable objects according to claim 1, characterized in that, The improved dual-constraint TabPFN network includes an authorization decision sample input layer, a field token encoding layer, a DID link consistency constraint layer, a TabPFN context reasoning layer, a programmable object rule mask layer, and a compliance authorization policy output layer. The authorization determination sample input layer combines programmable object instances and authorization request data into an authorization determination sample; The field token encoding layer encodes each field value in the authorization judgment sample through linear transformation and layer normalization, and arranges them in order of field value to obtain a field token vector sequence. The DID link consistency constraint layer performs bidirectional conflict suppression attention constraint processing on the field token vector sequence to obtain the DID link constraint vector. In the TabPFN context reasoning layer, the field token vector sequence and the DID link constraint vector are concatenated, and multi-layer context reasoning is performed through multi-layer attention interaction and feedforward mapping. The context reasoning results are pooled to obtain the authorization policy latent feature vector. The programmable object rule mask layer constructs a rule mask vector based on the authorization rule field and object state field in the programmable object instance; The rule mask vector includes access permission mask value, usage permission mask value, transfer permission mask value, revocation permission mask value, and secondary authentication trigger result mask value; The rules for constructing the rule mask vector include state restriction rules and authorization restriction rules; In the compliance authorization policy output layer, the latent feature vector of the authorization policy is linearly transformed and activated by Sigmoid to obtain the original authorization policy probability vector; Based on the rule mask vector, the original authorization policy probability vector is subjected to element-wise mask constraint processing to obtain the compliant authorization policy probability vector. Based on the compliance probability values in the compliance authorization strategy probability vector, the authorization strategy determination result of the digital asset to be managed is determined. The authorization strategy determination result includes access permissions, usage permissions, transfer permissions, revocation permissions, and secondary authentication trigger results.
7. The digital asset identity authentication and authorization management system based on DID and programmable objects according to claim 6, characterized in that, The DID link consistency constraint layer performs bidirectional conflict suppression attention constraint processing on the field token vector sequence, specifically including: The DID token vector set is formed by filtering the digital asset DID token vector, the holder DID token vector, the user DID token vector, and the authorizing initiator DID token vector from the field token vector sequence. Based on the subject binding field in the programmable object instance, determine the type of identity binding relationship between the p-th DID token vector and the q-th DID token vector in the DID token vector set, and construct the identity binding relationship identifier; Select the query projection matrix, key projection matrix, and value projection matrix corresponding to the identity binding relationship type, and map the p-th DID token vector to a DID query vector through the query projection matrix. Map the q-th DID token vector to a DID key vector and a DID value vector through the key projection matrix and value projection matrix. The p-th DID token vector and the q-th DID token vector are concatenated and mapped in forward and reverse order respectively to obtain the forward link representation vector and the reverse link representation vector; Calculate the L1 norm of the difference between the forward link representation vector and the reverse link representation vector to obtain the bidirectional link consistency difference between the p-th DID token vector and the q-th DID token vector; The DID query vector and DID key vector are subjected to attention operation to obtain the initial DID attention score; the bidirectional link consistency difference is negatively suppressed to obtain the link difference suppression score; and the identity binding relationship identifier is missing to obtain the identity binding missing suppression score. The initial DID attention score, link difference suppression score, and identity binding missing suppression score are added together to obtain the conflict suppression link attention score; The conflict suppression link attention score is normalized using Softmax to obtain the conflict suppression link attention coefficient between the p-th DID token vector and the q-th DID token vector. Based on the conflict suppression link attention coefficient, the DID value matrix is weighted and aggregated to generate the DID link consistency representation vector of the p-th DID token vector; By concatenating and mapping the DID link consistency representation vectors corresponding to each DID token vector and activating them with Sigmoid, the DID link constraint vector is obtained.
8. The digital asset identity authentication and authorization management system based on DID and programmable objects according to claim 6, characterized in that, The state restriction rules specifically include: If the object's state is revoked, then set the access permission mask value, usage permission mask value, and transfer permission mask value to 0; If the object is in a frozen, read-only, or prohibited transfer state, the transfer permission mask value is set to 0; if the object is in an expired authorization state, the usage permission mask value is set to 0. If the object status is pending ownership confirmation, then set the access permission mask value, usage permission mask value, and transfer permission mask value to 0; If the object status is under risk observation, set the access permission mask value, usage permission mask value, and flow permission mask value to 0, and set the secondary authentication trigger result mask value to 1. The authorization rules and restrictions specifically include: If the authorization rule field does not include an access authorization rule, the access permission mask value is set to 0; if the authorization rule field does not include a use authorization rule, the use permission mask value is set to 0. If the authorization rule field does not include a transfer authorization rule, then the transfer permission mask value is set to 0; if the authorization rule field does not include a revocation authorization rule, then the revocation permission mask value is set to 0. If the authorization rule field includes a secondary authentication trigger rule, then the secondary authentication trigger result mask value will be set to 1.
9. The digital asset identity authentication and authorization management system based on DID and programmable objects according to claim 1, characterized in that, The secure communication and authorization execution module specifically includes: Based on the authorization policy determination result, the digital asset DID of the digital asset to be managed, and the authorization request data, generate token payload data; Calculate the hash digest of the token payload data to obtain the token digest. Based on the private key corresponding to the authorized initiator's DID, the token digest is digitally signed to generate a token signature; The token payload data, token digest, and token signature are combined to generate an authorization token; A session key is generated using a cryptographically secure random number generator. The authorization token is then symmetrically encrypted using AES-GCM and the session key to obtain the token ciphertext and the authentication tag. Based on the public key information in the DID identity binding result, the session key is asymmetrically encrypted to obtain the encrypted session key; Combine the token ciphertext, authentication tag, and encrypted session key to generate an encrypted authorization token; Upon receiving the encrypted authorization token, the encrypted session key is decrypted using the private key that matches the public key information in the DID identity binding result to obtain the session key; the token ciphertext is then decrypted and authenticated based on the session key, authentication tag, and AES-GCM to obtain the decryption authorization token. The validity of the decryption authorization token is verified. When the decryption authorization token passes the validity verification, the authorization control operation is executed according to the authorization policy judgment result. The validity verification includes token integrity verification, token signature verification, token time validity verification, authorization request number consistency verification, digital asset DID consistency verification, authorization initiator DID consistency verification, and authorization policy determination result consistency verification. The authorization control operations include allowing access, restricting access, denying access, allowing use, restricting use, allowing circulation, prohibiting circulation, revoking authorization, and triggering secondary authentication.
10. The digital asset identity authentication and authorization management system based on DID and programmable objects according to claim 1, characterized in that, The authorization management process includes the digital asset data access process, the DID identity identifier generation and binding process, the programmable object instance construction process, the digital asset identity authentication process, the authorization policy determination process, and the secure communication and authorization execution process. The authorization audit link is generated based on the digital asset DID, the holder DID, the user DID, the authorization initiator DID, and the authorization request number.