A digital will security management method and system based on artificial intelligence, blockchain, distributed storage and post-quantum cryptography
Patent Information
- Application Number
- CN202610733354.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-26
- Publication Date
- 2026-08-18
AI Technical Summary
[0003]数字遗嘱并非普通电子文档,而是具备高敏感性、长周期保存、高争议风险、强法律后果的特殊数据对象,其系统需同时解决四大核心问题:一是遗嘱内容与附件包含财产、身份、家庭关系、医疗意愿等敏感信息,需高强度机密性保护;二是遗嘱需长期保存,传统RSA、ECC等加密方案面临未来量子计算攻击风险;三是遗嘱涉及创建、审核、公证、存证、生效、执行等多阶段流程,需可核验的状态流转记录;四是发生争议时需证明内容未篡改、流程合规、访问可追溯
现有遗嘱管理方案通常仅能解决“遗嘱创建”或“遗嘱电子化保存”中的局部问题,例如传统纸质遗嘱虽然便于形成原始载体,但存在易遗失、易损毁、难验证和易伪造等问题;普通电子遗嘱系统虽然提高了存储和传输便利性,但多依赖中心化数据库、传统公钥密码体制或单一电子证据机制,在长期安全保护、关键节点留痕和大文件可信存证方面仍存在不足;部分在线遗嘱平台虽支持在线创建、保管或基础存证,但通常缺少对审核、公证录像、用户确认、作废、生效和访问记录等全过程的统一控制与可信记录。相较之下,本发明将基于格的无证书公钥加密、联盟链存证、IPFS分布式存储以及人工智能辅助审查进行协同集成:一方面,采用基于格的无证书公钥加密对遗嘱正文及附件进行保护,相比传统基于证书的公钥加密可减轻证书管理负担,相比基于身份的加密可避免密钥托管问题,并且更适合应对长周期保存场景下面向量子计算攻击的潜在风险;另一方面,采用“IPFS链下存储+联盟链链上锚定”的方式,将遗嘱密文、公证录像等大文件存于IPFS,将遗嘱摘要、CID、状态流转和访问记录写入联盟链,从而既避免了大文件直接上链造成的账本膨胀和处理压力,又比普通数据库或普通云存储更有利于实现内容一致性校验、防篡改和多方可信留痕。
Smart Images

Figure CN122595344A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of digital will services, cryptography, blockchain evidence storage and distributed storage technology, and specifically to a digital will security management method and system based on artificial intelligence, blockchain, distributed storage and post-quantum cryptography. Background Technology
[0002] With the aging population, the continuous accumulation of family wealth, and the increasing legal awareness of the public, the social demand for will making, estate planning, and post-mortem management continues to grow. Traditional offline paper-based will services are gradually transforming towards digitalization, online platforms, and platform-based solutions. Currently, mainstream will service platforms offer basic functions such as will consultation, appointment scheduling, registration, safekeeping, and document generation, but they generally focus on the "creation" and "safekeeping" stages of wills, lacking sufficient support for the authenticity, completeness, long-term security, access control, reliable execution, and full-process traceability of the entire will formation and execution process. Domestic and international platforms such as the China Will Registry, Will Guardian, LegalZoom, and Trust&Will have developed distinctive services in areas such as process standardization, electronic evidence, and document templates, but none have built an integrated technical system for digital wills that includes post-quantum security, on-chain and off-chain collaborative evidence storage, full lifecycle status management, and AI-powered intelligent review.
[0003] Digital wills are not ordinary electronic documents, but special data objects with high sensitivity, long-term storage, high risk of disputes, and strong legal consequences. Their systems must simultaneously address four core issues: First, the will content and attachments contain sensitive information such as property, identity, family relationships, and medical wishes, requiring strong confidentiality protection; second, the will needs long-term storage, and traditional encryption schemes such as RSA and ECC face the risk of future quantum computing attacks; third, the will involves multiple stages of processes including creation, review, notarization, storage, effectiveness, and execution, requiring verifiable records of its status progression; and fourth, in case of disputes, it is necessary to prove that the content has not been tampered with, the process is compliant, and access is traceable.
[0004] While the key technologies supporting digital will systems have reached a certain level of foundation, they have not yet achieved scenario-based integration. 1. Post-quantum cryptography: Lattice cryptography, based on the LWE hard problem, possesses strong resistance to quantum computing attacks and represents the core approach of post-quantum cryptography. Certificate-free public-key cryptography can address the shortcomings of traditional PKI systems, such as complex certificate management, difficult certificate revocation, and the need for pure identity-based cryptographic key escrow. Lattice-based certificate-free public-key encryption schemes have been verified to possess IND-CPA security, balancing post-quantum security with low certificate management burden, but have not yet been applied to long-term security protection of digital wills.
[0005] 2. Trusted Evidence Preservation and Distributed Storage: Blockchain possesses the characteristics of decentralization, immutability, traceability, and verifiability. Hyperledger Fabric, as a permissioned blockchain, supports member management and consortium access control, making it suitable for multi-entity collaboration and audit record keeping. However, directly storing large files such as scanned copies of wills, notarized videos, and attachments on the blockchain can lead to ledger bloat and decreased efficiency. In engineering practice, a "off-chain storage, on-chain anchoring" solution is usually adopted. IPFS is a content-addressed peer-to-peer distributed file system that uniquely identifies files with content hashes, making it suitable for storing large objects such as encrypted text and videos. However, it has not yet been combined with consortium blockchains to form a dedicated on-chain and off-chain collaborative evidence preservation architecture for digital wills.
[0006] 3. Legal Intelligence Assistance: Legal texts are rigorously worded, structurally complex, and prone to ambiguity, making it difficult for ordinary users to meet formal requirements and avoid legal risks when drafting wills. While large-scale legal models can achieve legal question answering, information extraction, and risk identification through prompting engineering and small-sample learning, they have not yet developed dedicated intelligent pre-screening and assisted review capabilities specifically for will texts.
[0007] Analysis of existing technical solutions I. Existing Product Solutions The China Will Registry boasts standardized processes and a high degree of organization, providing consultation, appointment, registration, and storage services, but it does not rely on quantum cryptography, consortium blockchains, or large-scale models as its core technologies.
[0008] Will Guardian: It uses technologies such as electronic signatures, trusted timestamps, and hash verification to enhance the validity of electronic evidence, but it does not adopt post-quantum encryption, on-chain and off-chain collaborative evidence storage, or full lifecycle state machine management.
[0009] International heritage planning platforms (LegalZoom, Trust&Will) offer mature user experiences and document templates, focusing on online document generation and storage, but do not employ blockchain-based evidence storage, post-quantum security, or end-to-end trusted execution as their technological approach.
[0010] II. Most Similar Research Scheme In 2021, Chen et al. proposed a traceable online will system based on blockchain and smart contracts to achieve trusted and traceable will processing. However, it has obvious shortcomings: it does not use lattice-based certificateless public key encryption to address post-quantum security; it does not use IPFS and consortium blockchain to achieve large file off-chain storage and on-chain dual-layer anchoring; it does not integrate a dedicated AI intelligent pre-examination for wills; and it does not construct a complete will lifecycle state machine.
[0011] III. Adjacent Technical Solutions Based on technologies such as certificateless public key encryption, Hyperledger Fabric, IPFS, and legal big data models, these technologies have capabilities in data security, consortium notarization, distributed storage, and legal text processing, respectively. However, none of them have been integrated into a unified design and engineering implementation for the characteristics of digital wills, which are highly sensitive, have long cycles, are complex processes, are legally binding, and have multiple attachments.
[0012] Current digital will technology has at least the following shortcomings: 1. Lack of long-term security mechanisms: The common use of traditional electronic signatures, timestamps, hash verification and conventional public key cryptography does not combine with certificateless lattice cryptography to achieve quantum-resistant long-term security protection. Certificate management is complex or there are risks of key escrow, which cannot meet the security requirements of wills to be preserved for decades.
[0013] 2. Lack of on-chain and off-chain collaborative evidence storage architecture: It focuses on a single database, a single blockchain or a single electronic evidence, and fails to solve the balance between the storage efficiency of large files and the verifiability of on-chain states. Files are easily replaced, addresses are mismatched, and traces are incomplete.
[0014] 3. Insufficient closed-loop management throughout the entire lifecycle: It focuses on the "creation" and "storage" stages, with weak support for processes such as review, notarization, confirmation, cancellation, effectiveness, and access auditing. The status transition is not standardized, the access control is rough, and the verification of key operations is lacking.
[0015] 4. Insufficient intelligent auxiliary review capabilities for wills: Relying on templates and manual consultation, it lacks semantic understanding of unstructured will texts, formal requirement checks, risk identification, and intelligent pre-review, resulting in high user operation thresholds and significant potential risks.
[0016] 5. Low integration of the comprehensive service platform: The functions are isolated and lack integration of quantum security, on-chain and off-chain evidence storage, full life cycle management, AI assistance and humanistic extension services, which cannot meet the needs of integrated, one-stop digital will services.
[0017] In summary, while existing technologies have made some progress in online will services, electronic evidence, blockchain record keeping, and online estate planning, they still cannot simultaneously meet the multiple requirements of digital will scenarios for post-quantum secure storage, on-chain and off-chain trusted evidence storage, full-process state flow control, AI-assisted review, and comprehensive humanistic service expansion. Therefore, it is necessary to propose a new technical solution to address these issues. Summary of the Invention
[0018] To address the problems existing in the prior art, the present invention aims to provide a security management technology solution for digital will scenarios. Through post-quantum certificateless public key encryption, collaborative evidence storage of consortium blockchain and interplanetary file system, full lifecycle state machine control, artificial intelligence-assisted review, and comprehensive platform architecture, it achieves long-term security protection of will data, trusted traceability throughout the process, closed-loop business management, and intelligent service enhancement.
[0019] To achieve the above objectives, the present invention provides the following technical solution: This invention proposes a digital will security management method based on artificial intelligence, blockchain, distributed storage, and post-quantum cryptography. The method includes the following steps: User registration and key generation steps: In response to the user registration request, the server generates key materials for the user based on the certificateless public key encryption mechanism of the lattice cryptosystem and returns the private key file to the user. At the same time, the server only saves the hash digest of the private key file. Will creation and pre-review steps: Receive the will text uploaded by the user, use a large language model to perform semantic analysis and compliance pre-review of the will text, and generate pre-review results to be fed back to the user; Review and notarization steps: Receive the staff's review results of the will and the notarization materials uploaded by the notary, and write the review information and the hash value of the notarization materials into the consortium blockchain; Confirmation and encryption steps: In response to the user's confirmation operation, the private key file uploaded by the user is verified. If the verification is successful, the plaintext of the will is encrypted using the user's public key to generate the ciphertext of the will. Collaborative evidence storage steps: Upload the encrypted will to the distributed file system IPFS to obtain the content identifier CID, and write the CID, will summary and current status information as anchor data into the consortium blockchain; Viewing and tracing steps: In response to the user's viewing request, verify the user's private key file. If it passes, obtain the CID from the consortium blockchain, pull the will ciphertext from IPFS and decrypt it and return it. At the same time, write the access record to the consortium blockchain. External agency collaboration steps: In response to a preset triggering scenario, authorized external agency nodes retrieve and verify will documents based on anchored data on the consortium blockchain, and write the verification behavior into the consortium blockchain.
[0020] Furthermore, the user registration and key generation steps of this invention specifically include: S1: Platform Initialization: The platform determines the lattice cryptosystem parameters according to the preset security parameters; it calls the TrapGen algorithm to generate the system public parameters and the master secret key msk, which is securely stored by the platform and not disclosed to the public; S2: Identity Input: Receive user identity information and generate a corresponding user identifier IDi. The user identifier IDi serves as the identity input parameter in the subsequent key generation and encryption process. S3: User-side private key generation: The user terminal calls the TrapGen algorithm locally to generate a secret value Tbi, constructs a user public key matrix Bi based on the secret value Tbi, and calculates a tag value ti based on the public key matrix Bi and the user identifier IDi to form a user public key pki associated with the identity. S4: Controlled private key component generation on the platform side: After obtaining the user identity identifier IDi, the platform uses the master secret key msk and public parameters to call the SamplePre algorithm to generate a controlled private key component Di corresponding to the user identity identifier IDi; the controlled private key component Di satisfies the constraint relationship with the identity mapping matrix and is used to cancel the identity mapping items in the subsequent decryption process, but it cannot decrypt the will ciphertext on its own. S5: Complete private key combination: The platform securely distributes the controlled private key component Di to the user terminal. The user combines the controlled private key component Di with the secret value Tbi locally to form the complete private key ski. The platform only saves the hash digest of ski and does not save the plaintext of ski.
[0021] Furthermore, the verification and encryption steps of this invention specifically include: S6: Will Confirmation Trigger: After the user completes the filling in of the will text, uploads the will attachments and supplements the necessary information in the system, and goes through the pre-process of review and uploading of notarized video, the system enters the will confirmation stage. The system organizes the will information that needs to be protected into a message M to be encrypted. S7: Verification of the validity of the user's public key pki: Before performing encryption, the system recalculates the tag value based on the public key matrix Bi and the user identifier IDi in the user's public key pki, and compares it with the tag carried in the public key pki; if the comparison is inconsistent, the encryption process is terminated. S8: Post-quantum encryption processing: After the verification is passed, the will message M, the user identity IDi and the user public key pki are used as inputs. The matrix Si is randomly selected and the noise terms Ei,1 and Ei,2 are sampled from the error distribution. Based on the system public parameters, the identity mapping matrix and the user public key matrix Bi, the ciphertext components cti1 and cti2 are constructed to generate the will ciphertext cti=(cti1, cti2). S9: Off-chain storage and CID acquisition: Upload the encrypted will (CTI) to the InterPlanetary File System (IPFS) to obtain the corresponding Content Identifier (CID); and write the will summary, Content Identifier (CID), will status, and user confirmation time into the consortium blockchain. S10: Decryption and Recovery: When the user views the message, the complete private key ski is used to decrypt the ciphertext cti obtained from IPFS. The identity mapping related items are offset by the controlled private key component Di. The original will message M is restored by regularizing the user's locally generated private key component Tbi. The access time is then written to the consortium blockchain.
[0022] Furthermore, the collaborative evidence preservation steps of this invention specifically include: S1: Initialization: The business backend loads the connection parameters of the consortium blockchain and the IPFS interface parameters; S2: Ciphertext Upload and CID Acquisition: Upload the ciphertext cti of the will generated in claim 3 to the InterPlanetary File System (IPFS) and obtain the unique content identifier (CID); S3: Organization anchor data: The organization's evidence information to be uploaded to the blockchain, which includes at least: will number hash value, creation time, reviewer number, review approval time, notarization video hash value, user confirmation time, CID, access record, invalidation time, effective time and will status; S4: On-chain anchoring: The business backend calls the consortium blockchain chaincode to write the evidence storage information into the consortium blockchain, forming an immutable evidence storage record; S5: Status Update: The business backend updates the status of the will in the local database to "created successfully".
[0023] Furthermore, the specific steps for viewing and tracing the source of this invention include: S6: Request and Verification: In response to a user's request to view or trace the source, the business backend receives the private key file uploaded by the user, calculates its hash value and compares it with the private key hash digest pre-stored in the database. After the verification is successful, the subsequent steps are executed. S7: On-chain query: The business backend calls the consortium blockchain chaincode to query the corresponding CID and timeline status information based on the hash value of the will number; S8: Ciphertext Acquisition: The business backend retrieves the ciphertext cti of the will from IPFS based on the CID; S9: Decryption and Recovery: The business backend uses the user's complete private key ski to perform decryption calculations on the ciphertext cti to recover the plaintext of the will; S10: Result Return: If it is a viewing scenario, the plaintext of the will is returned; if it is a tracing scenario, the on-chain state record and off-chain file information are integrated to generate the tracing result. S11: Access Recording: Write the access time to the consortium blockchain to form an access record.
[0024] Furthermore, when the message M to be encrypted in this invention contains an appendix to a will, it also includes: For will attachments exceeding a preset threshold, perform block processing to generate multiple attachment blocks; Using multi-threaded concurrent execution, each attachment block is encrypted using lattice-based certificateless encryption to generate encrypted blocks; Store the encrypted blocks and block metadata in the will artifact record; When a user views the file, encrypted blocks are retrieved from IPFS, decrypted concurrently, and then reassembled based on the block metadata to restore the complete attachment.
[0025] Furthermore, the collaborative evidence storage and viewing / tracing steps of this invention also achieve on-chain and off-chain entity binding and write-back traceability, specifically including: On-chain and off-chain entity binding: The will number is hashed, and the hash value is used as a unique index for the will entity on the chain. The CID obtained after uploading the encrypted will to IPFS, together with the hash value of the will number, the will status, the confirmation time, the access time, the hash of the notarized video, the hash of the death certificate, and the processing role identifier, is written into the consortium blockchain to establish a one-to-one correspondence between the off-chain file entity and the on-chain business status. Two-stage source tracing retrieval: During the tracing phase, the system first obtains the corresponding CID based on the hash value of the will number or the encrypted hash value; Based on the CID query chain, the status information, timeline information, and access records of the will entity are retrieved. By integrating the on-chain query results with the off-chain file retrieval results corresponding to the CID, complete tracing information for the will is generated. Access event write-back: After a user successfully views the contents of the will, the time of this access and the corresponding access behavior are recorded as new on-chain events and written back to the consortium blockchain, thus realizing the on-chain solidification of the will access behavior entity.
[0026] Furthermore, the present invention also includes dual-state linkage closed-loop control for will status entities, specifically including: On the business side, maintain the lifecycle status of the main business entity of wills. The lifecycle status includes at least: draft, submission, rejection and modification, approval, video upload, pending user confirmation, construction completed and effective. Maintain an on-chain state entity corresponding to the main business entity of the will. The on-chain state entity includes at least: will number hash value, confirmation time, notarization video hash, CID, access time, invalidation time and effective time. The key business actions of approval, notarization and uploading, user confirmation, cancellation and effectiveness are mapped to field updates or state migrations of the on-chain state entity through preset conditions. In response to the user's confirmation operation, an asynchronous task of IPFS notarization and on-chain anchoring is triggered; subsequent invalidation operations are only allowed when all the asynchronous tasks are executed successfully and the lifecycle state of the business side reaches the construction completion state. In response to the staff's activation operation, the lifecycle status of the business side and the on-chain status entity will only be updated to the effective status after the death certificate document is received and the on-chain verification is completed.
[0027] Furthermore, the present invention also includes a multi-role separation evidence injection and liability attribution step for digital wills, specifically including: At each business stage—approval, uploading of notarized video recordings, and the effective date of the will—heterogeneous evidence generated by different roles is separated by source and injected into on-chain entities. At the approved node, the reviewer number, approval time, rejection time, and reason for rejection are written as independent fields into the will entity on the consortium blockchain; At the notarized video upload node, the notary's number, the notarized video upload time, and the notarized video hash value are written as independent fields into the will entity; At the will taking effect node, the number of the person in charge of taking effect, the hash value of the death certificate, and the effective time are written as independent fields into the will entity; By establishing liability attribution relationships through these independent fields, on-chain will entities can distinguish the source, operation time, and legal facts of different types of evidence.
[0028] Furthermore, the present invention utilizes a large language model to perform semantic analysis and compliance pre-review of will texts, specifically including: Build a legal rule database for wills, and extract rules from official legal documents regarding the formal requirements, completeness of content, and key risks of wills; The rules are transformed into prompt word templates, and pre-screening prompt words are constructed by combining them with few sample examples; The pre-examination prompts are input into a large language model, which performs semantic understanding on the will text and outputs prompts for formal defects, content integrity, and legal risks. The preliminary review results are fed back to the user for correction and synchronized to the staff's end as a reference for manual review, but do not replace the final decision of manual review.
[0029] Based on the same inventive concept, the present invention also provides a digital will security management system, comprising: The front-end presentation layer is used to receive user input and display business results. The user input includes at least will creation information, review instructions, notarized materials, and viewing requests. The backend business layer is used to receive requests from the frontend presentation layer and execute core business logic. The backend business layer includes at least a user management module, a will management module, an audit workflow module, a material processing module, an artificial intelligence invocation module, a blockchain interaction module, an IPFS interaction module, and an audit log module. The data storage layer uses a separation of structured and unstructured data to store user information, business status, log information, wills, notarized videos, and death certificates. The trusted evidence storage layer adopts a two-layer trusted evidence storage structure jointly constructed by a consortium blockchain and the InterPlanetary File System (IPFS). The consortium blockchain is used to store the hash value of the will number, the content identifier (CID), the will status, key time nodes, and access records, while the IPFS is used to store the encrypted will and related large files. The intelligent service layer is used to access large language models to perform semantic analysis, compliance assistance judgment, and intelligent question answering support on will texts; The security control layer, which runs through the front-end presentation layer, back-end business layer, data storage layer, and trusted evidence storage layer, is used to perform identity authentication, access authorization, private key verification, sensitive data encryption, and auditing of key operations. The front-end presentation layer, back-end business layer, data storage layer, trusted evidence storage layer, intelligent service layer, and security control layer work together to process will-related matters through interface calls, status transmission, and data collaboration.
[0030] Based on the same inventive concept, the present invention also provides a digital will security management device, comprising: The user interaction unit is used to receive will information, attachment information, appointment information and query instructions input by users, and to display the will status, review results, traceability results and effective results to users; The identity authentication and access control unit is used to identify, authorize, and control the operational boundaries of ordinary users, auditors, notaries, and administrators. The Will Creation and Business Flow Unit is used to create will business instances, maintain the migration of wills from the state of creation, creation success, invalidation to effectiveness, and drive the review, notarization, confirmation and storage processes; The AI-assisted review unit is used to perform semantic analysis, rule prompts, and compliance assistance in judging the will text uploaded by users. The post-quantum encryption unit is used to encrypt the will text and attachments during the user confirmation stage, and to decrypt and recover the will based on the complete private key in a legitimate viewing scenario; Distributed storage units are used to write documents such as encrypted wills, notarized videos, and death certificates to the InterPlanetary File System (IPFS) and return Content Identifiers (CIDs). The blockchain evidence storage unit is used to write the will summary, CID, status transition information and access traces into the consortium blockchain; The will tracing unit is used to query the on-chain record and off-chain file corresponding to the will based on the will number hash value, ciphertext hash value or CID, thereby forming a complete timeline and state line; The effective processing unit is used to update the status of the will and record the effective time based on the death certificate information uploaded by the staff when the effective conditions are met. The audit log unit is used to record key operations within the platform, such as login, review, confirmation, viewing, invalidation, activation, and tracing. The various units cooperate with each other through interface calls, database associations, and message tasks.
[0031] The beneficial effects of this invention are as follows: Existing will management solutions typically only address partial issues in "will creation" or "electronic will preservation." For example, while traditional paper wills are convenient for creating original documents, they are prone to loss, damage, verification, and forgery. Although ordinary electronic will systems improve storage and transmission convenience, they often rely on centralized databases, traditional public-key cryptography, or single electronic evidence mechanisms, and still fall short in terms of long-term security protection, key node traceability, and reliable large-file evidence preservation. While some online will platforms support online creation, storage, or basic evidence preservation, they usually lack unified control and reliable recording of the entire process, including review, notarization recording, user confirmation, invalidation, effectiveness, and access records. In contrast, this invention integrates lattice-based certificateless public key encryption, consortium blockchain notarization, IPFS distributed storage, and AI-assisted review in a synergistic manner. On the one hand, lattice-based certificateless public key encryption is used to protect the will text and attachments. Compared to traditional certificate-based public key encryption, this reduces the burden of certificate management; compared to identity-based encryption, it avoids key escrow issues and is more suitable for dealing with the potential risks of quantum computing attacks in long-term storage scenarios. On the other hand, by using the "IPFS off-chain storage + consortium blockchain on-chain anchoring" approach, large files such as the will ciphertext and notarized video are stored in IPFS, while the will summary, CID, state transition, and access records are written to the consortium blockchain. This avoids the ledger bloat and processing pressure caused by directly uploading large files to the blockchain and is more conducive to achieving content consistency verification, tamper prevention, and multi-party trusted traceability than ordinary databases or ordinary cloud storage.
[0032] Furthermore, most existing platforms remain at the level of "creation + storage" or "creation + simple query," while this invention establishes a closed-loop management mechanism covering the entire lifecycle of wills, including will creation, AI pre-review, manual review, uploading of notarized video recordings, user confirmation, on-chain evidence storage, viewing, invalidation, effectiveness, and traceability query. Through on-chain state machines, multi-role fine-grained access control, and private key verification mechanisms, it unifies the operational boundaries, responsible parties, and time nodes of different roles at different business stages into a traceable, verifiable, and auditable control framework. Therefore, compared to ordinary form-based processes or centralized management methods, it significantly improves the standardization, security, and credibility of the will business process. Simultaneously, this invention introduces a large language model to assist in the review and intelligent question answering of unstructured will texts. Compared to traditional template matching, manual consultation, or basic retrieval methods, it is more conducive to semantic understanding, formal requirement checks, and risk warnings of will texts, thereby lowering the user threshold and improving the efficiency of pre-review and the overall intelligence level of the service. In summary, compared with the prior art, the present invention has at least the advantages of stronger long-term security, higher credibility of evidence storage, more complete business processes, more controllable key operations, stronger traceability capabilities, and higher level of intelligent assistance, making it more suitable for application scenarios such as digital wills that are highly sensitive, highly credible, and require long-term preservation. Attached Figure Description
[0033] Figure 1 This is an architecture diagram of a digital will security management system according to the present invention; Figure 2 This is a flowchart of the digital will security management method described in this invention; Figure 3 The flowchart of the certificateless public-key encryption algorithm based on lattice as described in this invention is as follows. Figure 4 This is a sequence diagram of the multi-terminal interaction between blockchain and IPFS as described in this invention; Figure 5 This is the ER diagram of the database described in this invention. Detailed Implementation
[0034] Example 1: Through analysis of existing technologies, current technical solutions related to will management mainly include traditional paper will storage methods, ordinary electronic will management systems, and some will service platforms with online creation or basic evidence storage functions. Existing technologies have the following main shortcomings in practical applications: 1. There is a lack of highly secure will protection mechanisms for long-term preservation scenarios.
[0035] Existing products mostly employ traditional electronic signatures, timestamps, hash verification, or conventional public-key cryptography to enhance the current credibility of wills. However, they lack sufficient consideration for the continued confidentiality protection of wills in long-term preservation scenarios, particularly lacking security designs that incorporate certificateless public-key encryption mechanisms. This makes it difficult to balance the convenience of key management, the user's autonomy in key control, and long-term security. Specifically, traditional paper wills are prone to loss, damage, alteration, and forgery, and the cost of verifying authenticity and integrity is high. While existing electronic will systems achieve digital storage, most still use centralized storage methods or rely on traditional public-key cryptography for data protection. For important documents like wills that require long-term preservation and confidentiality, existing solutions typically rely on public-key infrastructures for certificate issuance, distribution, and verification, resulting in complex certificate management and high maintenance costs. Furthermore, while identity-based encryption schemes can reduce the burden of certificate management, they are prone to key escrow risks, compromising the user's autonomy in controlling the will's content. Meanwhile, most existing certificateless public-key encryption schemes are still based on traditional difficult problems such as large integer factorization or discrete logarithms, offering limited resilience against future quantum computing attacks. Therefore, existing technologies generally lack a protection mechanism suitable for digital will scenarios that can simultaneously reduce the burden of certificate management, avoid key escrow issues, and meet the long-term security requirements of post-quantum systems.
[0036] 2. Lack of a complete evidence storage architecture that combines on-chain and off-chain collaboration.
[0037] Existing solutions typically focus on a single database, a single blockchain, or a single electronic evidence mechanism, rarely addressing the balance between efficient storage of large files and verifiable on-chain states. Specifically, will-related transactions often involve multiple data objects, including the will text, supporting documents, and notarized videos, some of which are quite large. Storing all data directly on the blockchain would lead to a heavy storage burden, low processing efficiency, and poor system scalability. Conversely, using only ordinary off-chain storage can result in issues such as file address mismatches, difficulty in promptly detecting content replacement, and a lack of credible anchoring evidence. Furthermore, many existing platforms only handle the uploading, storage, or simple recording of will documents, lacking unified traceability and management of key stages such as will creation, review, confirmation, effectiveness, invalidation, and access. Therefore, the transparency, verifiability, and tamper-proof capabilities of the will transfer process remain insufficient. Consequently, current technology lacks a collaborative on-chain and off-chain evidence storage solution that can simultaneously achieve efficient storage of large files, content consistency verification, multi-party credible traceability, and collaborative management by restricted participating entities.
[0038] 3. Lack of closed-loop management of the entire life cycle of wills and verification mechanism for key operations.
[0039] Many online platforms focus on "creation" and "storage," while offering limited support for subsequent business processes such as review, notarized video recording, user confirmation, voiding, effectiveness, and access tracking. Specifically, most existing will service platforms concentrate on single functions such as online creation, basic storage, or partial evidence preservation, failing to form a closed-loop business process covering "will creation, content review, review workflow, notarized document processing, user confirmation, reliable evidence preservation, effectiveness management, and traceability query." This easily leads to inefficient business connections, non-standardized status management, and incomplete operational audits, making it difficult to meet the requirements of actual will services for process completeness and standardization. On the other hand, wills are highly sensitive information involving critical operations such as viewing, confirmation, voiding, and effectiveness. Relying solely on account passwords or ordinary access control can easily result in unclear authorization boundaries and insufficient verification of critical operations. Existing technologies still have room for improvement in fine-grained access management for different roles and business stages, as well as reliable verification mechanisms for key stages.
[0040] 4. Lack of intelligent auxiliary review capabilities for will texts.
[0041] Most existing solutions rely on templates, manual consultation, or basic retrieval, making it difficult to perform semantic understanding, requirement checks, and risk warnings on unstructured will texts. Specifically, existing will platforms generally lack user-facing intelligent consultation, text-assisted review, or risk warning functions. Users typically still need to rely on manual consultation or understand the relevant requirements themselves during the will creation and submission process, resulting in high operational barriers, low efficiency, and hindering the improvement of the intelligence level of will services. For unstructured will texts, existing solutions generally lack content analysis capabilities based on semantic understanding, making it difficult to effectively support formal requirement checks, content integrity warnings, and potential risk identification.
[0042] 5. Lack of comprehensive platform design for expanding will service scenarios.
[0043] Existing platforms typically revolve around wills themselves, rarely extending to auxiliary scenarios and extended services closely related to will services, resulting in low overall functional integration. Specifically, most existing platforms focus on single-point functions such as will creation, safekeeping, and basic evidence preservation, lacking overall capabilities in intelligent services, distributed storage, post-quantum encryption, will traceability, and related extended services, making it difficult to form a comprehensive service platform centered around will-related business. This fragmented design hinders the improvement of the platform's integrated service capabilities and fails to meet users' comprehensive needs for will management, secure evidence preservation, intelligent assistance, and related extended applications.
[0044] To address the problems existing in the prior art, this embodiment provides a digital will security management method based on artificial intelligence, blockchain, distributed storage, and post-quantum cryptography. Through post-quantum certificateless public key encryption, collaborative evidence storage with consortium blockchain and interplanetary file system, full lifecycle state machine control, artificial intelligence-assisted review, and a comprehensive platform architecture, it achieves long-term security protection of will data, trusted traceability throughout the process, closed-loop business management, and intelligent service enhancement.
[0045] 1. Objectives and solutions for addressing the lack of long-term security-oriented will protection mechanisms. To address the shortcomings of existing technologies in supporting long-term preservation and confidentiality of wills, this invention aims to provide a highly secure will protection mechanism for long-term preservation scenarios. This mechanism ensures continuous confidentiality protection for the will text and its attachments during creation, submission, review, confirmation, storage, and viewing, and enhances its resilience against future quantum computing threats. To achieve this objective, this embodiment employs lattice-based certificateless public-key encryption to encrypt the will content. The platform generates a partial private key based on the user's identity, and the user then generates a secret value locally to form the complete private key, thereby achieving controlled encryption and decryption of the will content.
[0046] The reason for choosing "lattice-based certificateless public-key encryption" instead of traditional certificate-based public-key encryption, simple symmetric encryption, or identity-based encryption is that: traditional public-key systems rely on certificate issuance, distribution, and verification mechanisms, resulting in significant certificate management overhead; while identity-based encryption reduces certificate management, it suffers from key escrow issues; and certificateless public-key encryption can simultaneously alleviate the burden of certificate management and avoid the key escrow problems inherent in identity-based encryption. Furthermore, many existing certificateless public-key encryption schemes based on the difficulty of large integer factorization or discrete logarithms are vulnerable to quantum computing attacks. Therefore, this invention further employs a lattice-based certificateless public-key encryption scheme built upon the error-based learning problem, which is more suitable for long-term preservation scenarios such as wills.
[0047] 2. Objectives and solutions for addressing the lack of a complete evidence storage architecture that combines on-chain and off-chain collaboration. To address the shortcomings of existing technologies in simultaneously achieving efficient large file storage and on-chain verifiability, this invention aims to provide a trusted evidence storage mechanism that combines on-chain and off-chain collaboration. This mechanism enables the efficient storage of large documents such as encrypted wills, notarized videos, and death certificates, while ensuring that will summaries, state transitions, and access records are verifiable, traceable, and tamper-proof. To achieve this, this invention employs a technical approach of "InterPlanetary File System (IPS) off-chain storage + Hyperledger Fabric consortium blockchain on-chain anchoring." The encrypted will and related large files are uploaded to the IPS to obtain Content Identifiers (CIDs), and then the will summary, CID, state transition information, and access records are written to the consortium blockchain.
[0048] The reason for choosing this technology, rather than "all data directly on-chain" or "only using ordinary databases / object storage," is that: directly writing all data to the blockchain would lead to ledger bloat, decreased processing efficiency, and poor scalability; while using ordinary databases or ordinary cloud storage to store files can meet general business management and file storage needs, it is difficult to naturally provide a multi-party verifiable, tamper-proof, and trustworthy chain of evidence, and it is also difficult to guarantee a strong consistency association between file content and business status. The off-chain storage and on-chain anchoring mode adopted in this invention aims to achieve a balance between the efficiency of large file storage and the trustworthy recording of critical states. Furthermore, IPFS is chosen instead of ordinary cloud storage because IPFS uses a content-based addressing method, and the generated CID can form a binding relationship with the file content, making it more suitable for consistency verification and anti-substitution management of documents such as wills and notarized videos; Hyperledger Fabric is chosen instead of ordinary databases or open public chains because Fabric is more suitable for scenarios with multiple roles such as users, auditors, notaries, and institutions participating under restricted conditions, and can provide better identity management, access control, audit trails, and multi-party collaboration capabilities. Therefore, the present invention adopts a technical approach that combines Fabric and IPFS, which is more suitable for the comprehensive requirements of privacy protection, evidence credibility, system performance and business supervision in the context of digital wills.
[0049] 3. Objectives and solutions for addressing the "lack of closed-loop management throughout the entire lifecycle of wills" To address the issue that existing platforms often focus on single-point processing of "creation + storage" and lack subsequent closed-loop flow control, this invention aims to provide a closed-loop management mechanism for the entire lifecycle of wills. This mechanism unifies will creation, AI pre-screening, institutional review, notarized document processing, user confirmation, credible evidence storage, viewing, invalidation, effectiveness, and traceability into a controlled process, achieving standardized management through state transitions. To achieve this, this invention constructs a will lifecycle state machine, establishing state transition relationships around nodes such as "registration and login—will creation—AI pre-screening—institutional review—notarized video upload—user confirmation—on-chain evidence storage—will effectiveness," and recording the corresponding time, roles, and processing results on the blockchain.
[0050] The reason for choosing the "state machine + multi-role process control" approach, rather than ordinary form workflows or manual recording, is that will-related matters have higher requirements for chronological order, responsibility attribution, status changes, and subsequent verification. If only the free-flowing method found in ordinary business systems is used, problems such as process skipping, mixed use of permissions, inconsistent states, and lack of auditing can easily occur. State machines, on the other hand, can clearly define the constraints between each business node, making every status change traceable, verifiable, and auditable, which is more suitable for the highly sensitive and strictly regulated scenario of wills.
[0051] Meanwhile, for key operations such as viewing, confirming, voiding, and taking effect, this invention further integrates multi-role fine-grained access control and a private key verification mechanism, ensuring that different roles can only perform corresponding operations at their respective business stages. This approach, rather than relying solely on account passwords or general access control, is adopted because wills are highly sensitive information, and account-level authentication alone is insufficient to support the credibility requirements of critical operations. Introducing private key verification further enhances users' autonomy over the content of wills and key business actions.
[0052] 4. Objectives and solutions for addressing the "lack of intelligent auxiliary review capabilities for will texts". To address the shortcomings of existing technologies that rely primarily on templates, manual consultation, or basic retrieval, making it difficult to perform semantic understanding and risk alerts on unstructured will texts, this invention aims to provide an intelligent auxiliary review and question-answering mechanism for will texts. This mechanism enhances the convenience, intelligence, and pre-emptive risk identification capabilities during will creation and submission. To achieve this goal, this invention integrates a large language model and combines prompt word engineering and few-sample prompting technology to perform semantic understanding, content review assistance, and intelligent question-answering support on will texts.
[0053] The reason for choosing the large language model approach, rather than traditional keyword matching, fixed template comparison, or simple rule retrieval, is that will texts typically have strong unstructured characteristics, exhibit individual differences in expression, and many issues cannot be accurately identified through simple keyword matching. Your document also explicitly states that you have abandoned traditional keyword matching algorithms and instead utilize the natural language processing and semantic understanding capabilities of the large language model to perform compliance checks on will texts. Compared to pure rule-based methods, the large language model is more suitable for handling complex, freely expressed will texts; however, in this invention, it is positioned as an "auxiliary reviewer," not a replacement for human review, thus balancing intelligence with business stability.
[0054] 5. Objectives and solutions for addressing the lack of a comprehensive platform design that balances legal functions and extended services. To address the shortcomings of existing platforms, which often focus solely on will creation and safekeeping with insufficient functional integration, this invention aims to provide a comprehensive platform architecture for digital will scenarios. While ensuring the security and reliability of core will-related services, it further integrates functional modules related to life affairs management, family relationship maintenance, and extended services, thereby enhancing the platform's integrated service capabilities. To achieve this objective, this invention adopts an overall architecture that separates front-end and back-end processes, modularizes services, integrates on-chain and off-chain collaborative storage, and integrates intelligent services. Beyond the main will-related process, it further integrates extended modules such as kinship association, spatiotemporal envelopes, advance medical instructions, accidental entrustment, and family happiness moments.
[0055] The reason for choosing a "comprehensive platform integration" approach, rather than splitting various services into multiple independent systems, is that the will-related business itself is closely linked to identity authentication, access control, trusted evidence storage, access tracking, and data sharing boundaries. Completely separating these functions often leads to issues such as duplicate identity systems, fragmented evidence chains, inconsistent access control standards, and data silos between different systems. This invention, through a unified account system, unified access control, a unified trusted evidence storage platform, and a unified auditing mechanism, enables core will-related services and related extended services to share basic security and trust capabilities, making it more suitable as a holistic technical solution built around the digital will scenario. It should be noted that in the subsequent claims, this part can be considered as dependent or extended protection content, while the aforementioned long-term security protection, trusted evidence storage, full lifecycle control, and intelligent assisted review remain the core technical objectives of this invention.
[0056] The digital will security management method based on artificial intelligence, blockchain, distributed storage, and post-quantum cryptography described in this invention includes the following steps: User registration and key generation steps: In response to the user registration request, the server generates key materials for the user based on the certificateless public key encryption mechanism of the lattice cryptosystem and returns the private key file to the user. At the same time, the server only saves the hash digest of the private key file. Will creation and pre-review steps: Receive the will text uploaded by the user, use a large language model to perform semantic analysis and compliance pre-review of the will text, and generate pre-review results to be fed back to the user; Review and notarization steps: Receive the staff's review results of the will and the notarization materials uploaded by the notary, and write the review information and the hash value of the notarization materials into the consortium blockchain; Confirmation and encryption steps: In response to the user's confirmation operation, the private key file uploaded by the user is verified. If the verification is successful, the plaintext of the will is encrypted using the user's public key to generate the ciphertext of the will. Collaborative evidence storage steps: Upload the encrypted will to the distributed file system IPFS to obtain the content identifier CID, and write the CID, will summary and current status information as anchor data into the consortium blockchain; Viewing and tracing steps: In response to the user's viewing request, verify the user's private key file. If it passes, obtain the CID from the consortium blockchain, pull the will ciphertext from IPFS and decrypt it and return it. At the same time, write the access record to the consortium blockchain. External agency collaboration steps: In response to a preset triggering scenario, authorized external agency nodes retrieve and verify will documents based on anchored data on the consortium blockchain, and write the verification behavior into the consortium blockchain.
[0057] Furthermore, the method described in this embodiment is geared towards business scenarios such as digital will creation, review, notarization, confirmation, storage, traceability, and effectiveness. By integrating lattice-based certificateless public key encryption technology, consortium blockchain trusted storage technology, InterPlanetary File System (IPFS) distributed storage technology, large language model-assisted review technology, and multi-role access control technology, it achieves secure storage, trusted execution, full-process traceability, and intelligent services for will data.
[0058] Furthermore, the method described in this embodiment is not simply a stacking of functions, but rather a closed-loop technical solution built around the actual business chain of digital wills. This solution encompasses user initiation, platform processing, institutional review, notary office supplementation, user confirmation, on-chain and off-chain collaborative evidence storage, and subsequent viewing, invalidation, traceability, and effectiveness. For ease of understanding, the following detailed description, in conjunction with the accompanying drawings, illustrates the system structure, device composition, method flow, module connections, coordination relationships, and operating mode of this embodiment.
[0059] To implement the method described in this embodiment, a digital will security management system is provided. This system generally includes a front-end presentation layer, a back-end business layer, a data storage layer, a trusted evidence storage layer, an intelligent service layer, and a security control layer. These layers are not isolated from each other, but rather work together through interface calls, status transmission, and data collaboration to complete will processing.
[0060] like Figure 1 As shown, the front-end presentation layer is used to receive user input and display business results. The front-end preferably adopts a browser / server architecture, i.e., a B / S (Browser / Server) architecture. Users access the system page through a browser to complete operations such as registration and login, will creation, will viewing, will confirmation, will tracing, AI consultation, kinship association, time-space envelopes, and unexpected entrustment; staff complete operations such as will review, uploading notarized videos, business approval, uploading death certificates, and processing their effectiveness through the staff terminal.
[0061] The backend business layer handles frontend requests and executes core business logic, preferably composed of Java backend services. Internally, the backend business layer includes modules for user management, will management, review and approval processes, material processing, AI invocation, blockchain interaction, IPFS interaction, and audit logs. On one hand, the backend business layer connects to a relational database to store user information, task information, business status, and log information; on the other hand, it communicates with the trusted evidence storage layer to write will summaries, status transitions, and access traces to the consortium blockchain, and to write encrypted wills and large files to IPFS.
[0062] The data storage layer separates structured and unstructured data. Structured data is preferably stored in MySQL (MyStructuredQueryLanguage, a relational database management system), including user tables, role tables, master will tables, will review tables, will confirmation tables, review task tables, file object tables, and on-chain anchor tables, etc. Unstructured data includes will text documents, notarized videos, supporting materials, death certificates, etc. This part of the data is preferably stored off-chain in IPFS to reduce the pressure on the consortium blockchain ledger.
[0063] The trusted evidence storage layer employs a two-layer trusted evidence storage structure built through collaboration between Hyperledger Fabric (a consortium blockchain) and IPFS. Fabric is responsible for storing key metadata such as the will's serial number hash, will status, creation time, review time, notarization video hash, user confirmation time, IPFS Content Identifier (CID), invalidation time, effective time, and access records. IPFS is responsible for storing the encrypted will and related large files. The two layers are linked through a backend business layer, forming a trusted management mechanism of "off-chain storage, on-chain anchoring."
[0064] The intelligent service layer is used to assist in the review of will texts and provide intelligent question-and-answer services. This layer connects to a large language model, preferably the DeepSeek model. The backend uses prompt word engineering and few-sample prompting to transform the legal rules related to wills into analytical tasks that the model can process, in order to help identify whether the will text has problems such as formal irregularities, incomplete elements, or ambiguous expressions.
[0065] A security control layer permeates the entire system. This layer includes identity authentication, access authorization, private key verification, sensitive data encryption, and auditing of critical operations. Identity authentication is preferably implemented using Spring Security (security framework) and JWT (JSON Web Token); data encryption is preferably implemented using lattice-based certificateless public key encryption technology; critical operations such as will viewing, will confirmation, and will invalidation require verification in conjunction with the private key file; all critical operations are simultaneously logged to ensure subsequent verification and traceability.
[0066] From a device perspective, this embodiment also provides a digital will security management device, which includes at least: The user interaction unit is used to receive will information, attachment information, appointment information and query instructions input by users, and to display the will status, review results, traceability results and effective results to users; The identity authentication and access control unit is used to identify, authorize, and control the operational boundaries of ordinary users, auditors, notaries, and administrators. The Will Creation and Business Flow Unit is used to create will business instances, maintain the migration of wills from the state of creation, creation success, invalidation to effectiveness, and drive the review, notarization, confirmation and storage processes; The AI-assisted review unit is used to perform semantic analysis, rule prompts, and compliance assistance in judging the will text uploaded by users. The post-quantum encryption unit is used to encrypt the will text and attachments during the user confirmation stage, and to decrypt and recover the will based on the complete private key in a legitimate viewing scenario; Distributed storage units are used to write files such as encrypted wills, notarized videos, and death certificates into IPFS and return CIDs; The blockchain evidence storage unit is used to write the will summary, CID, status transition information and access traces into the Fabric consortium blockchain; The will tracing unit is used to query the on-chain record and off-chain file corresponding to the will based on the will number hash value, ciphertext hash value or CID, thereby forming a complete timeline and state line; The effective processing unit is used to update the status of the will and record the effective time based on the death certificate information uploaded by the staff when the effective conditions are met. The audit log unit is used to record key operations such as login, review, confirmation, viewing, invalidation, activation, and tracing within the platform.
[0067] Furthermore, the aforementioned units do not necessarily need to be physically independent; they can be deployed on the same server via software or distributed across multiple service nodes as needed. The units coordinate with each other through interface calls, database connections, and message tasks. For example, after receiving a creation request, the user interaction unit first verifies the user's identity using the identity authentication and access control unit, then the will creation and business flow unit generates the will business record. When the user selects AI pre-review, the AI-assisted review unit returns the result. When the will enters the confirmation stage, the post-quantum encryption unit generates the ciphertext, which is then written to IPFS by the distributed storage unit, and the blockchain evidence storage unit uploads the summary information to the blockchain. When the user subsequently views the will, the will tracing unit, in conjunction with the post-quantum encryption unit, completes retrieval, verification, and decryption. This embodiment also provides a method for secure management of digital wills. The main process of this method can be found in [reference needed]. Figure 2 Even without seeing the attached diagram, it can be understood to include the following steps: Step S1: User registration and identity establishment.
[0068] Users submit registration information such as name, mobile phone number, ID card number, and password through the front end. After completing basic identity registration, the platform establishes account and role information for the user. Furthermore, under the certificateless public key system adopted in this invention, the platform can generate a partial private key related to the user's identity, and the user then generates a secret value and public key matrix locally, thus forming a complete private and public key. After successful registration, the system can provide the user with a private key file for subsequent critical operations such as password retrieval, will confirmation, will viewing, and will invalidation.
[0069] Step S2: Will creation.
[0070] After logging in, users enter the will creation interface, fill in the will name, select a notary office, and upload the will text or related attachments. They can also choose to schedule an offline service. Upon receiving the request, the backend generates a master record for the will in the database and assigns a service identifier to it. At this point, the will is in the "creating" state.
[0071] Step S3: Artificial intelligence pre-screening.
[0072] In an optional implementation, users can trigger the AI pre-review function before or after submission. The system sends the will text to the AI-assisted review unit, where a large language model performs semantic analysis based on preset prompt word templates, outputting results regarding the completeness of the will's content, its formal compliance, and risk warnings. This pre-review result can be used by the user to modify the will, or by reviewers for reference during subsequent reviews.
[0073] Step S4: Will submission and on-chain initialization.
[0074] After a user submits a will, the backend performs hash processing on the will number and uses this hash value as a unique index for the entity on the blockchain. Then, it calls the Fabric chaincode to create an on-chain record of the will, initializes the on-chain structure, and writes at least the will number hash value, creation time, and current status, thus forming a trusted starting point for the will process.
[0075] Step S5: Staff review.
[0076] After logging into the staff terminal, the reviewers will view and process the will. If the review fails, the rejection time and reason will be recorded on the blockchain, and the will's status will be reverted to the pending modification state. If the review passes, the reviewer's identifier and the approval time will be written on the blockchain, and the will will be moved to the stage of awaiting notarization video upload.
[0077] Step S6: Upload the notarized video recording.
[0078] The notary public supplements the will with notarization video recordings and other materials. The system hashes the video files, saves the original video files off-chain, and writes the video hash value, the notary public's identifier, and the upload time into the consortium blockchain to create an immutable record of the notarization process.
[0079] Step S7: User confirmation and encryption processing.
[0080] After the review and notarization are completed, the user proceeds to the confirmation stage. The user uploads their private key file, and the system first performs a hash verification on the private key content and compares it with the key digest pre-saved in the database. If the verification passes, the confirmation operation is allowed. During confirmation, the system calls the post-quantum encryption unit to encrypt the will text and attachments, generating the ciphertext of the will.
[0081] Step S8: IPFS notarization and on-chain anchoring.
[0082] The system uploads the encrypted will to IPFS to obtain a unique CID. Then, the system calls the Fabric chaincode to write the CID, creation success time, user confirmation time, and current will status into the consortium blockchain. At this point, the will has completed the trusted notarization process of "off-chain storage + on-chain anchoring," and its status is updated to "creation successful."
[0083] Step S9: Review the will.
[0084] When a user needs to view the will's contents later, they must upload the private key file again. The system first verifies the private key, then queries the CID from the consortium blockchain based on the will's number hash, and retrieves the encrypted will from IPFS based on the CID. Subsequently, it calls the decryption algorithm to recover the plaintext of the will, and writes the access time to the consortium blockchain after successful viewing, thus creating an access record.
[0085] Step S10: The will is void.
[0086] Once a will has been successfully created, the user can apply to void it. The system also requires private key verification for the voiding operation. After successful verification, the system writes the voiding time and voiding status to the consortium blockchain and updates the will status to "voided".
[0087] Step S11: The will takes effect.
[0088] Under conditions that meet legal or business agreement requirements, staff upload valid documents such as death certificates. The system hashes the death certificate documents, writes the effective time and new status into the consortium blockchain, and updates the will status to "effective".
[0089] Step S12: Tracing the origin of the will.
[0090] After a user clicks on the traceability button, the system reads the encrypted hash value stored in the database or on the blockchain, queries the corresponding CID, and further queries the status flow record, timeline record, and access record corresponding to the CID or will number hash in the consortium blockchain. Finally, it returns a complete traceability result containing nodes such as creation, review, notarization, confirmation, storage, viewing, invalidation, or effectiveness.
[0091] Aside from tracing the source, the above methods and steps have a strict sequential and coordinated relationship. Creation is a prerequisite for review; approval is a prerequisite for notarization and uploading; notarization is a prerequisite for user confirmation; user confirmation is a prerequisite for ciphertext uploading to IPFS and completing on-chain anchoring; only after successful creation can the document be viewed or voided; and only after meeting certain conditions can the effective process begin. Through this state constraint, this embodiment achieves closed-loop control of the entire lifecycle of will services.
[0092] Furthermore, in this embodiment, the user registration and key generation, as well as the confirmation and encryption steps, are described in detail; The post-quantum encryption process described in this embodiment can be found in [reference needed]. Figure 3 Combining Figure 3 The illustrated process unifies the user registration, key generation, will confirmation encryption, evidence storage, and subsequent viewing and decryption processes in a digital will scenario. This scheme employs a lattice-based certificateless public-key encryption scheme, its security foundation built upon the LWE (Learning With Errors) hard problem. The scheme's key features are: the platform is responsible for generating the system master key and the controlled private key component associated with the user's identity, while the user is responsible for generating their own private key component and public key locally. This avoids the complex certificate management of traditional certificate systems and the security risks associated with the platform possessing the complete private key, making it more suitable for long-term, highly sensitive business scenarios such as wills.
[0093] The specific steps are as follows: S1: The platform performs system initialization.
[0094] The platform first performs an initialization operation based on preset security parameters to determine the parameters required for the lattice cryptosystem, including security parameters, modulus, matrix dimension, and error distribution parameters. Then, the platform calls the TrapGen algorithm to generate the system's public parameters and master secret key (msk). The master secret key is securely stored by the platform and not disclosed to the public; the public parameters are used for unified calculations in subsequent user registration, identity mapping, encryption, and decryption processes.
[0095] S2: The user initiates a will service and enters their identity identifier.
[0096] When a user logs into the system and prepares to create a will, the system receives the user's identity information, forming a user identifier IDi. This user identifier can be a unique user number within the system or an identity identifier bound to real-name registration information. This identity identifier is used not only for user identification in will processing but also as an identity input parameter in subsequent key generation and encryption processes. This step corresponds to... Figure 3 The process of "user" and "input user IDi" in the text.
[0097] S3: The user generates the user-side private key component and public key locally.
[0098] In this implementation, the user-side private key component is generated locally by the user. Specifically, the user terminal calls the TrapGen algorithm locally to generate a secret value Tbi, and constructs a user public key matrix Bi based on this secret value, further generating the user public key pki. To enhance the binding relationship between the public key and the user's identity, the user can also calculate a tag value ti based on Bi and the user identifier IDi, forming a user public key associated with the identity. This step corresponds to... Figure 3 The process involves "inputting user IDi → TrapGen algorithm → generating secret value Tbi → generating public key pki". By generating this private key component locally, it is ensured that this part of the key is always under the user's control and does not rely on the platform for safekeeping, thereby improving the autonomy and controllability of accessing and confirming the will content.
[0099] S4: The platform generates a controlled private key component based on the user's identity.
[0100] After obtaining the user's identity identifier IDi, the platform uses the system's master secret key msk and public parameters to call the SamplePre algorithm to generate a controlled private key component Di corresponding to that identity. This private key component satisfies the constraint relationship with the identity mapping matrix, and can be used to cancel identity mapping items in subsequent decryption processes. However, this private key component alone is insufficient to decrypt the will's ciphertext. In other words, even if the platform possesses the master secret key and can generate Di, it still cannot directly recover the plaintext of the will based solely on this information. This step corresponds to... Figure 3 The process is as follows: "Master key msk → SamplePre algorithm → Generate partial private key".
[0101] S5: Users combine data to form a complete private key.
[0102] The platform securely sends the controlled private key component generated in step S4 to the user. The user then combines this component with the user-side private key component Tbi generated in step S3 locally to obtain the complete private key ski. In other words, the complete private key in this invention consists of two parts: one part is the private key component generated by the platform based on the user's identity, and the other part is the private key component generated locally by the user and held solely by the user. Only when both parts are present does the device possess complete decryption capability. This step corresponds to... Figure 3 The process involves "generating a partial private key → generating a complete private key." This design reduces the management burden of traditional certificate systems while avoiding the key escrow problem in identity-based encryption schemes where the platform has complete control over the user's private key.
[0103] S6: The user completes the will and enters the confirmation and encryption stage.
[0104] After users complete the filling out of the will text, upload will attachments, and supplement necessary information in the system, and go through preliminary processes such as review and uploading of notarized video recordings, they enter the will confirmation stage. At this time, the system organizes the will information that needs to be protected into a message M to be encrypted. The message M preferably includes the will text content, necessary attachment content, or their structured representation, and may also include necessary metadata related to the will. By binding the will business with the encryption step, it can be ensured that only the will content that enters the formal confirmation stage is encrypted and enters the subsequent evidence preservation process.
[0105] S7: The system verifies the validity of the user's public key.
[0106] Before encryption, the system first verifies the legitimacy of the user's public key pki. Specifically, it recalculates the tag value based on the Bi and IDi in the public key and compares it with the tag carried in the public key. If they do not match, the public key is invalid or has been tampered with, and the system terminates the encryption process. If they match, the system proceeds to the next encryption step. This step prevents forged or incorrect public keys from being used in will encryption, thus avoiding the will's ciphertext from being unable to be decrypted correctly or being abnormally replaced.
[0107] S8: The system performs post-quantum encryption on the will message.
[0108] After the public key verification is successful, the system takes the will message M, user identity IDi, and user public key pki as input, randomly selects matrix Si, and samples noise terms Ei,1 and Ei,2 from the error distribution. Then, based on the system's public parameters, the identity mapping matrix H(IDi), and the user public key matrix Bi, it constructs ciphertext components. Preferably, two ciphertext components cti1 and cti2 are formed. The first ciphertext component mainly reflects the interaction between the system's public parameters and the random matrix, while the second ciphertext component embeds the identity mapping term, the user public key term, the noise term, and the will message M. The final ciphertext is cti = (cti1, cti2). During this process, the original will is not stored or transmitted in plaintext, thus achieving confidentiality protection of the will content during its internal and external circulation within the system.
[0109] S9: Outputs encrypted wills and integrates them with the trusted evidence storage process.
[0110] After obtaining the encrypted will CTI, the system outputs it as the official encrypted will. Furthermore, in the will service scenario of this invention, the encrypted will is not directly and permanently stored in a regular database, but instead enters the subsequent trusted evidence storage process: the system can upload the encrypted will to the InterPlanetary File System (IPFS) and obtain the corresponding Content Identifier (CID); simultaneously, it writes key information such as the will summary, CID, will status, and user confirmation time into the consortium blockchain, thus forming a trusted evidence storage mechanism of "encrypted will content stored off-chain, key status anchored on-chain." This avoids the storage pressure caused by directly uploading large files to the blockchain while ensuring the verifiability and tamper-proof capability of the will's transfer process.
[0111] S10: When a user views a will, the private key is verified and decrypted for recovery.
[0112] When a user needs to view the will's contents later, the system requires the user to upload or access the private key file corresponding to their local complete private key. The system first verifies the private key, for example, by comparing the private key digest to determine if it matches the user's identity and historical registration information. After successful verification, the system retrieves the ciphertext cti of the will from IPFS based on the will's CID, and then uses the complete private key ski to perform decryption calculations on the ciphertext. During decryption, the controlled private key component cancels out identity mapping-related items, and then the user's locally generated private key component is used to normalize and restore the remaining items, thereby restoring the original will message M in a modular sense. The restored message M is then parsed by the system into a readable will text and related content, and returned to the authorized user for viewing. Simultaneously, the system can also write the viewing time to the consortium blockchain, creating an access record.
[0113] S11: Achieve the desired effect.
[0114] Through the above steps, this embodiment unifies the technical process of "user identity establishment—user local key generation—platform-controlled private key generation—complete private key combination—will confirmation encryption—on-chain and off-chain evidence storage—legal viewing and decryption" in will-related services. On the one hand, the user-side private key component is generated locally by the user, enhancing the user's autonomy over the will; on the other hand, the platform-side controlled private key component is associated with the identity mapping, supporting the normal operation of the certificateless public key encryption system. Combined with the lattice-based construction method, this technical solution is more suitable than traditional RSA or ECC cryptosystems for addressing potential quantum attack risks in long-term storage scenarios, and is therefore more suitable for the data protection needs of highly sensitive, long-term storage data such as digital wills.
[0115] Furthermore, in this embodiment, the implementation scheme of blockchain and IPFS collaborative evidence storage technology is described in detail; The blockchain and IPFS collaborative evidence storage process in this embodiment can be found in [reference needed]. Figure 4 Combining Figure 4 The interactive process illustrated in this implementation mainly involves four types of entities: users, business backends, IPFS (InterPlanetary File System) nodes, and consortium blockchain nodes. The business backend, acting as the core scheduling center, is responsible for receiving user requests, invoking encryption modules, calling IPFS interfaces, invoking consortium blockchain chaincode, and integrating the returned results. This enables collaborative processing of the will's encrypted text stored off-chain and the critical business information anchored on-chain.
[0116] For ease of explanation, the technical solution is described below in two parts: the evidence preservation stage and the viewing and tracing stage.
[0117] I. Evidence Preservation Stage S1: The business backend completes the initialization of the blockchain network connection.
[0118] The backend preloads the connection parameters required by the consortium blockchain network, including node address, channel name, chaincode name, organization identifier, TLS certificate, client certificate, and private key, for subsequent chaincode invocation, query, and write operations. Simultaneously, the backend also pre-establishes an interface connection with the IPFS node for uploading and retrieving the encrypted will file. This step is typically completed during system startup, providing the basic operating environment for subsequent will notarization.
[0119] S2: The user completes the will confirmation and triggers the evidence storage request.
[0120] After the will has gone through the preliminary processes of creation, review, and uploading of notarized video recordings, the user performs a confirmation operation on the front end, indicating that the will content has entered the formal notarization stage. The front end sends the user's confirmation request to the business back end, which uses the current will business instance as the object to prepare to execute the will encrypted text generation and trusted notarization process.
[0121] S3: The business backend generates the encrypted will.
[0122] The backend calls the aforementioned post-quantum certificateless public key encryption module to encrypt the will text, necessary attachments, and related structured business data, generating a ciphertext will (CTI). Preferably, this ciphertext consists of multiple ciphertext components to ensure the confidentiality of the will content. After encryption, the original will content will no longer be used in plaintext for subsequent off-chain storage and on-chain recording.
[0123] S4: The business backend uploads the encrypted will to IPFS.
[0124] The backend sends the encrypted will generated in step S3 as a file object to the IPFS node. The IPFS node generates a unique content identifier (CID) for the encrypted file according to the content addressing mechanism and saves the encrypted will in the distributed file system. Since files such as wills, notarized videos, or death certificates are relatively large, using IPFS for off-chain storage can avoid the ledger bloat problem caused by directly uploading them to the blockchain and improve storage efficiency.
[0125] S5: IPFS nodes return CID.
[0126] After receiving and addressing the file, the IPFS node returns the corresponding CID to the business backend. Upon receiving the CID, the business backend associates it with the current will business instance for subsequent on-chain anchoring, viewing, tracing, and activation.
[0127] S6: Evidence storage information to be uploaded to the blockchain by the business backend organization.
[0128] The backend business, using the current will-related business as an example, requires the organization to write key evidence fields into the consortium blockchain. Preferably, the on-chain will entity includes at least the following fields: will number hash value, creation time, reviewer ID, approval time, rejection time, reason for rejection, notary ID, notary video hash value, notary video upload time, user confirmation time, IPFS CID, access record time, invalidation time, effective time, death certificate hash value, and will status. These fields comprehensively reflect the business traces of the will from its creation to its final termination.
[0129] S7: The business backend calls the chaincode to execute on-chain anchoring.
[0130] The business backend calls the consortium blockchain chaincode to write the evidence storage information organized in step S6 into the consortium blockchain. The written information includes at least the will number hash value, CID, current status, user confirmation time, and creation success time. For write operations, the request needs to go through endorsement, sorting, verification, and accounting processes to ultimately complete the on-chain state update. This step corresponds to... Figure 4 The code includes "5. On-chain anchoring (calling chaincode to write evidence information)" and "6. Writing evidence information and updating status".
[0131] S8: The consortium blockchain forms an immutable record of evidence.
[0132] After the consortium blockchain completes the ledger recording, a trusted evidence record corresponding to the will is generated on the chain. This record is characterized by time traceability, immutability of content, and verifiable state changes. From this point on, the will forms a two-layer evidence storage structure: the encrypted will text is stored in IPFS, and the digest and state are stored on the consortium blockchain. This step corresponds to... Figure 4 The text states, "7. Evidence data is uploaded to the blockchain to form an immutable evidence record."
[0133] S9: The business backend updates the local business status.
[0134] After successful on-chain anchoring, the business backend synchronously updates the will status and task status in the database. For example, the will status can be updated to "successfully created," and the asynchronous task status can be updated to "completed." Preferably, the on-chain will status is defined as at least as follows: 0 indicates creation in progress; 1 indicates successful creation; 2 indicates invalidation; and 3 indicates effective.
[0135] By maintaining these state values, a reliable state machine can be formed that covers the entire lifecycle of a will.
[0136] II. Inspection and Tracing Phase S10: The user initiates a request to view or trace the source and uploads the private key file.
[0137] When a user needs to view the contents of a will or perform will tracing, the frontend submits a corresponding request to the business backend, and simultaneously uploads the user's private key file. The business backend receives the private key file and prepares to perform the private key verification, ciphertext retrieval, decryption and recovery, and on-chain record keeping processes.
[0138] S11: The business backend reads the private key and performs hash verification.
[0139] The backend reads the private key file and calculates its SHA-256 (SecureHashAlgorithm256) hash value. This hash value is then compared to the private key hash pre-stored in the database. If they match, the user is deemed to have legitimate access; otherwise, the viewing or tracing process is terminated. This step corresponds to... Figure 4 The text includes phrases such as "2. Read the private key, calculate the SHA-256 hash, and verify the private key hash" and "3. Private key verification passed".
[0140] S12: The business backend calls the chaincode to query CID or timeline status line information.
[0141] After the private key verification is successful, the business backend calls the consortium blockchain to query the chaincode based on the will number hash value or other retrieval identifier to obtain the CID, current status, access records or timeline and status line information corresponding to the will.
[0142] If you are looking at a scene, it is preferable to obtain at least the CID; In the case of tracing the source, it is preferable to obtain on-chain records such as creation time, review time, notarization time, confirmation time, invalidation time, and effective time at the same time.
[0143] S13: The business backend retrieves the encrypted will from IPFS based on the CID.
[0144] After obtaining the CID, the business backend sends a file retrieval request to the IPFS node. The IPFS node locates the corresponding encrypted will file based on the CID and returns it to the business backend.
[0145] S14: The business backend uses the user's complete private key to perform decryption and verify integrity.
[0146] The backend calls the decryption module, which uses the user's complete private key to decrypt and recover the ciphertext of the will, obtaining the plaintext content. Simultaneously, it performs integrity checks on the decryption result, such as comparing the ciphertext digest, file digest, or business identifier for consistency, to confirm that the recovered will content matches the on-chain and off-chain records. S15: The business backend returns the will content or the tracing results.
[0147] For viewing scenarios, the backend will decrypt and recover the will content and return it to the user's frontend for authorized users to view. For tracing scenarios, the backend will integrate on-chain state records, timeline information, and off-chain file association information to form a complete will tracing result and return it to the frontend for display. S16: The business backend records this access and writes it to the consortium blockchain.
[0148] After the will is successfully viewed, the backend system creates an access record for this activity, including the access time, the accessed party, and necessary business identifiers. It then calls the consortium blockchain's chaincode to write this access record onto the blockchain. Once the consortium blockchain completes the write, an immutable access trace is created.
[0149] Furthermore, in this embodiment, the data organization and database cooperation relationship of the technical solution are specifically explained; The data relationships can be found in [reference]. Figure 5 This can be understood as follows: the solution adopts a database organization method of "business master table + process table + file table + log table + permission table" to support the collaboration between will business, personnel roles, and on-chain and off-chain data.
[0150] The user and permission management module is used to store user accounts, role information, staff information, service organization information, and user key information; the will business management module is used to store the master will record, will attachments, will review, will confirmation, notarization video recording, will effectiveness, and appointment information; the review and task flow module is used to store review tasks, review records, asynchronous tasks, and audit logs; and the file and trusted evidence storage module is used to store uploaded file information and on-chain anchoring status information.
[0151] The wills master table in the database is linked to on-chain records via will number hash or business number; the file object table is linked to CIDs in IPFS via storage identifiers; the audit task table is linked to the audit record table via task number; and the user table is linked to the role table via the user role association table. Through these relationships, the system can quickly complete business queries and permission checks in the local database, while leveraging blockchain and IPFS to perform trusted verification and file retrieval.
[0152] Furthermore, in this embodiment, the following modules can be created to better implement the method described in this embodiment; 1. Will Creation Module This module receives information from the user, including the will name, notary office, will text, and attachments, and generates a master record for the will in the database. Connected to the review and approval workflow module, this module switches the will's status to "pending review" upon submission and simultaneously writes the will's hash number into the blockchain as the starting point for on-chain business operations.
[0153] 2. Artificial Intelligence-Assisted Review Module This module connects to the will creation module. After the user uploads the will text, it performs segmented parsing, encapsulates prompts, and calls the model. The review results returned by the model may include content integrity prompts, formal defect prompts, and risk statements. These results are provided to the user and can also be used as a reference for reviewers, but they do not directly replace manual review.
[0154] 3. Review Module This module is deployed on the staff's end, allowing reviewers to approve or reject wills. Upon approval, the review time and reviewer's identifier are updated; upon rejection, the rejection time and reason are updated. The review module is connected to a blockchain-based evidence storage unit to ensure that the review results are recorded in an immutable manner.
[0155] 4. Notary video recording module This module is used to upload notarized video recordings and generate video hash values. The original video file can be stored off-chain, while the video hash value and upload time are written on-chain. This module works in conjunction with the subsequent user confirmation module as supplementary evidence before the will enters the final confirmation stage.
[0156] 5. User Confirmation Module This module requires users to upload a private key file to prove their true control over the will. After the system verifies the consistency of the private key digest, it triggers a post-quantum encryption unit to encrypt the will content and writes the confirmation time onto the blockchain. This module is the key control node for the will to move from the pending confirmation state to the formal notarization state.
[0157] 6. Evidence Preservation Module This module first uploads the encrypted will to IPFS to obtain the CID, and then writes the CID and status information into the Fabric consortium blockchain. It works in conjunction with the post-quantum encryption module, the blockchain evidence storage module, and the distributed storage module, and is the core module for realizing "off-chain storage + on-chain anchoring".
[0158] 7. Will Viewing Module This module requires users to upload their private key file again when viewing the content. After successful private key verification, the system queries the CID from the blockchain, retrieves the ciphertext from IPFS, and decrypts it. A record of the access is created upon successful viewing. This module works in conjunction with the security control layer, the post-quantum encryption unit, and the blockchain evidence storage unit to ensure that "only legitimate users can view the content, and the viewing process is auditable."
[0159] 8. Deprecated Module This module is only enabled after a will has been successfully created. When a user initiates a will cancellation, verification via private key is required, and the system then writes the cancellation time and status onto the blockchain. This prevents unverified wills or unauthorized entities from illegally canceling wills.
[0160] 9. Effective Module This module is triggered by staff. Upon receiving materials such as the death certificate, the system updates the effective date and will status, and records the death certificate hash on the blockchain. This allows the crucial legal milestone of the will's effectiveness to be incorporated into a trusted timeline.
[0161] 10. Traceability Module This module queries on-chain and off-chain data based on the will number hash, ciphertext hash, or CID, returning complete information about the will's process from creation to effectiveness or invalidation, including a timeline, status line, chaincode records, and file storage association information. This module enables will-related services to display a complete chain of evidence.
[0162] Example 2: This example provides alternative solutions to the technical solutions described in Example 1. 1. Alternatives in encryption protection schemes.
[0163] This invention is not limited to lattice-based certificateless public-key encryption schemes. Any post-quantum cryptography scheme capable of providing long-term security protection for the will text, attachments, and related sensitive data can be used as an alternative, such as post-quantum public-key encryption schemes based on modular lattice or NTRU-type structures, or hybrid encryption schemes combining post-quantum key encapsulation mechanisms and symmetric encryption. Furthermore, the "certificateless" method in the original scheme can also be replaced by identity-based encryption, attribute-based encryption, or a public-key system with digital certificates, as long as the purpose of encrypted storage and authorized access to the will content is still achieved.
[0164] 2. Alternatives to off-chain storage methods.
[0165] This invention is not limited to using IPFS to store encrypted wills and related large files. Any technical solution that can achieve distributed storage, content addressing, redundant storage, or secure external storage for large files can be used as an alternative, such as other distributed file systems, object storage systems, or external file storage systems with hash verification capabilities. In other words, as long as the off-chain storage requirements for encrypted wills, video materials, and evidentiary documents can be met, and a correspondence can be established with on-chain indexes or digests, it can replace IPFS to achieve the purpose of this invention.
[0166] 3. Alternatives in trusted evidence storage and blockchain implementation.
[0167] This invention is not limited to using the Hyperledger Fabric consortium blockchain. Any consortium blockchain, private blockchain, or other trusted ledger system that can achieve access control, on-chain writing, state recording, tamper-proof traceability, and traceability can be used as an alternative. The on-chain recorded content is not limited to will summary, CID, access time, and state information; it can also be replaced with file hashes, storage address indexes, operation log summaries, digital signature results, approval identifiers, and other records that can prove the authenticity and completeness of the will process.
[0168] 4. Alternatives in intelligent auxiliary review and consultation modules.
[0169] This invention is not limited to using the DeepSeek large language model. Any artificial intelligence model capable of semantic understanding, compliance assistance analysis, risk alerts, or intelligent question answering of will texts can be used as an alternative, such as other general-purpose large language models, legal-specific models, or a combination of "rule engine + natural language processing model". The PromptEngineering and Few-ShotPrompting in the original solution can also be replaced by knowledge base retrieval enhancement, template constraint generation, expert rule matching, etc., as long as they still provide auxiliary review and consultation services for the will content.
[0170] 5. Alternatives in identity authentication and access control.
[0171] This invention is not limited to using Spring Security and JWT for authentication and access control. Any authentication and authorization mechanism capable of user authentication, role differentiation, phased authorization, and verification of critical operations can be used as an alternative, such as access control methods based on session tokens, OAuth, digital certificates, electronic signatures, hardware keys, or multi-factor authentication. For critical operations such as viewing, confirming, voiding, and enacting wills, the private key verification in the original solution can be replaced with digital signature verification, certificate verification, or other trusted authentication methods.
[0172] 6. Alternatives in business process and state machine control.
[0173] This invention is not limited to a fixed sequence of "creation—AI pre-review—human review—upload of notarized video—user confirmation—documentation—effectiveness". Any process control scheme that can achieve standardized flow, controllable status, and auditable process throughout the will-making process can be used as an alternative. For example, the order of AI-assisted review and human review can be adjusted according to actual application needs, or some steps can be changed to parallel processing, asynchronous processing, or review and processing after supplementary materials; the roles of review, notarization, and confirmation can also be split or merged according to the institutional setup. As long as the core objectives of will creation, review and confirmation, reliable documentation, and final effectiveness are achieved, they are all alternative implementations of this invention.
[0174] 7. Alternatives in system deployment and module organization.
[0175] This invention is not limited to a front-end / back-end separated web platform. Any system deployment method capable of supporting will creation, storage, review, confirmation, traceability, and intelligent services can be used as an alternative, such as mobile applications, WeChat mini-programs, desktop clients, or monolithic deployments, microservice deployments, and cloud-edge collaborative deployments. Modules can be deployed centrally or distributed, as long as the secure processing, reliable recording, and intelligent assistance of will information are still achieved.
[0176] In summary, the technical solution proposed in this invention has the following innovative points: 1. A Post-Quantum Controlled Key Establishment and Key Holder Verification Method for Digital Wills The first core concept of this invention lies in proposing a post-quantum controlled key establishment and key holder verification method for digital will scenarios. This method does not merely generate encryption keys, but integrates user registration, private key file distribution, private key digest storage, and subsequent sensitive operation verification into a unified mechanism: During the registration phase, the system generates the necessary key materials for post-quantum certificateless public key encryption for the user, returning the private key only as a file to the user for storage. The platform does not store the plaintext private key; it only performs normalization processing on the private key content, calculates the hash digest, and saves it. During sensitive operations such as viewing, confirming, or voiding a will, the system requires the user to upload the private key file, then performs normalization processing and hash calculation on the private key file, matching it with the pre-stored hash digest. Only when a match is successful is the subsequent operation allowed.
[0177] The innovation of this concept lies not in the "use of post-quantum encryption" itself, but in the entire method of holding the private key file offline, storing only the private key hash on the platform, and using the private key hash matching as the trigger condition for key operations on the will. It directly protects the control capabilities of the legitimate key holder corresponding to the rights to view, confirm, and void the will, which is different from the existing system's practice of usually relying only on account passwords, ordinary permissions, or directly storing the key.
[0178] 2. Methods for Encrypted Storage and Concurrent Block Recovery of Digital Will Attachments After Confirmation The second core concept of this invention lies in proposing a method for encrypted storage and concurrent block recovery of digital will content after confirmation. This method converts the will text and attachments, especially will image attachments, into encrypted objects before entering the formal notarization process, and allows these encrypted objects to participate in subsequent storage, circulation, and retrieval. In implementation, after the will confirmation node, the system calls a lattice-based certificateless public key encryption mechanism to encrypt the will content; for will image attachments exceeding the single encryption capacity limit, they are first divided into blocks according to a preset threshold, then each block is encrypted separately, and the encrypted block results and block metadata are stored in the will artifact record.
[0179] Furthermore, this invention, based on block processing, employs a block concurrent processing mechanism to encrypt, decrypt, and restore will attachments. That is, multiple will attachment blocks do not necessarily need to be processed serially; instead, encryption or decryption calculations can be performed in parallel by the backend, and then uniformly assembled according to pre-recorded block order, block index, or block metadata. This improves the processing efficiency of large-sized will attachments in scenarios involving confirmation of evidence and legal viewing, while ensuring the integrity and consistency of the restored results. When a user subsequently views the will, after the private key hash verification passes, the system reads each encrypted block, performs concurrent decryption, and reassembles it to restore the complete original will.
[0180] The innovation of this concept lies in its integration of will confirmation, encrypted text generation, block-based encrypted storage, concurrent block processing, and block-based decryption and recombination during legitimate viewing. This solves the problems in digital will scenarios, such as the difficulty in directly encrypting large attachments, the unsuitability of platforms for long-term plaintext storage, and the necessity of restoring the original content for viewing. Specifically, it protects the will text and will image attachments, ensuring their verifiability, recoverability, and controlled access under post-quantum encryption constraints.
[0181] 3. On-chain and off-chain entity binding and write-back traceability methods for digital wills The third core concept of this invention lies in proposing a method for binding on-chain and off-chain entities and enabling write-back traceability in digital will scenarios. This method applies to off-chain document entities such as encrypted wills, notarized videos, and death certificates, as well as on-chain business entities such as will number hash values, content identifiers (CIDs), will status, key time nodes, access records, and responsible entity identifiers. By associating and binding these off-chain document entities with on-chain business entities, a verifiable, traceable, and tamper-proof chain of evidence is formed throughout the entire process of a will—from creation, review, notarization, confirmation, viewing, invalidation to effectiveness.
[0182] Specifically, this invention first performs a hash calculation on the will number and uses this hash value as a unique index for the on-chain will entity. After the user confirms the will, the encrypted will is uploaded to IPFS to obtain a Content Identifier (CID) corresponding to the encrypted content. Then, the CID, along with the will number hash value, will status, confirmation time, access time, notarized video hash, death certificate hash, and corresponding processing role identifier, are written into the consortium blockchain, thereby establishing a one-to-one correspondence between the off-chain encrypted file and the on-chain business status. Thus, what is stored off-chain is not a file in the ordinary sense, and what is recorded on-chain is not isolated summary information, but a two-layer association structure built around the same will business entity.
[0183] Furthermore, this invention proposes a two-stage tracing and retrieval method for digital wills. In the tracing or viewing stage, the system first obtains the corresponding CID based on the will's number hash value or the encrypted hash value saved during the confirmation stage. Then, based on this CID, it queries the status information, timeline information, and access records of the on-chain will entity. Finally, it integrates the on-chain query results with the off-chain file retrieval results to generate complete tracing information for the will. This method enables unified verification of key nodes such as will creation, review, notarization, confirmation, viewing, invalidation, and effectiveness, rather than performing isolated queries on a single file or a single on-chain record.
[0184] This invention further proposes a method for writing back access events. After a user completes private key verification and successfully views the will's contents, the system does not treat the viewing operation as a simple read operation. Instead, it rewrites the access time and corresponding access behavior into the consortium blockchain, making the will access behavior itself a new on-chain event record. In this way, the will not only has a credible trace in the processes of creation, review, notarization, confirmation, and effectiveness, but also forms an auditable and traceable behavior record when it is accessed. This method effectively protects the on-chain solidification of the will access event entity.
[0185] Therefore, the innovation of this invention lies in its approach: instead of simply using IPFS or consortium blockchains, it employs the following specialized processing methods for digital will business entities: First, a method that uses the will number hash and CID as a bridge to bind off-chain file entities with on-chain state entities; second, a method that uses encrypted hashes, CIDs, timelines, and state lines as paths to achieve full-process traceability and verification of wills; third, a method that rewrites will access behavior into the consortium blockchain to create access traces; and fourth, a method that uses multiple role identity fields, key time fields, and state fields to jointly describe the business events throughout the will's lifecycle. These methods collectively constitute the core technical features that distinguish this invention from ordinary database storage, ordinary object storage, or simple blockchain on-chain solutions.
[0186] 4. A dual-state linkage closed-loop control method for digital will status entities The fourth core concept of this invention does not lie in the generalization of "state machines," but rather in proposing a dual-state linkage closed-loop control method for digital will scenarios. The object directly affected and protected by this method is the main business entity of the will and its on-chain state entity. On one hand, the system maintains the lifecycle state of the will on the business side, from draft, submission, rejection and modification, approval, video upload, pending user confirmation, completion of construction, to effectiveness. On the other hand, the system maintains status fields such as the will number hash value, confirmation time, notarization video hash, CID, access time, invalidation time, and effectiveness time on the blockchain, and maps business actions such as approval, notarization upload, user confirmation, invalidation, and effectiveness to on-chain field updates or on-chain state changes through preset conditions. In this way, the will business entity is no longer just a record in a regular database, but is designed as a controlled object with dual constraints of "business state + on-chain state."
[0187] The innovation of this invention lies in its approach of using the hash value of the will number as a unique index for the will entity on the blockchain, rather than a single state value, and converting key business actions into corresponding on-chain field writes and state transition conditions. Specifically, in our existing implementation, after user confirmation, the system does not immediately mark it as complete but continues to trigger IPFS notarization and on-chain anchoring tasks. Only when all asynchronous tasks are successful and the lifecycle state reaches `will_build_completed` is subsequent invalidation processing allowed. Similarly, the will can only enter the effective state after the staff uploads the death certificate and completes the corresponding processing. This method effectively protects the integrity of the will's state entity, the consistency of its chronological order, and the non-repudiation of its legal validity timeline, thereby avoiding common problems in ordinary workflow systems such as skipped steps, state confusion, and unclear responsibilities.
[0188] 5. Rule-injection-based semantic pre-examination method for will text entities The fifth core concept of this invention does not lie in the general proposal of "introducing a large language model," but rather in proposing a rule-injected semantic pre-examination method for digital will scenarios. The object directly affected and protected by this method is the unstructured text entity of the will itself. In our implementation, the system does not employ traditional keyword matching, fixed template comparison, or simple full-text retrieval. Instead, it transforms the formal requirements, risk points, and content integrity requirements of wills in the Civil Code into prompt word templates, and inputs these templates, combined with a small number of sample examples, into a large language model. This allows the model to perform semantic understanding, formal requirement checks, content integrity prompts, and risk warnings on the will text after the user creates it but before formal submission, and then provides the pre-examination results to the user or reviewer for reference.
[0189] The innovation of this invention lies in its specialized method of "injecting legal rules of wills into the pre-examination process of a large language model to handle the unstructured text entity of the will itself," rather than a typical AI question-and-answer function. This method does not protect a general "level of intelligence," but rather the formal integrity, content defect discoverability, and risk warning generation of the will text before it formally enters the review and notarization process. In other words, our method does not replace human review with AI, but proposes a pre-examination mechanism that precedes submission and review. This allows problems that would otherwise be discovered through human experience, template comparison, or post-rejection issues to be identified and highlighted before the will text enters the formal process, thereby improving the reviewability of the will text and the efficiency of business processing.
[0190] 6. A Multi-Role Separate Evidence Injection and Liability Attribution Method for Digital Wills The sixth core concept of this invention lies in proposing a multi-role separation-based evidence injection and liability attribution method for digital will scenarios. The method directly affects and protects the entities responsible for reviewing the results, notarized video recordings, death certificates, and their corresponding role identifiers, and further extends to the on-chain business entities within the same will. Unlike ordinary systems that simply store all processing results as background logs, this invention injects different types of evidence generated by different business roles at different stages, separated by role and layered by time, into the same on-chain will entity, ensuring that each type of evidence has a clear source, clear time, and clear liability attribution.
[0191] Specifically, in our current implementation, when an auditor approves or rejects a will, the system writes the auditor's number, approval time, rejection time, and reason for rejection into the on-chain will entity. When a notary uploads a notarization video, the system writes the notary's number, video upload time, and video hash into the same on-chain entity. When a staff member uploads a death certificate and completes the processing during the will's effective stage, the system writes the death certificate hash, effective time, and corresponding processing identifier into the same on-chain entity. Therefore, the on-chain will entity is not a single-state record, but rather a unified carrier that gradually aggregates heterogeneous evidence from different stages such as approval, notarization, and effective date.
[0192] The innovation of this invention lies not in the common fact that "multiple roles can operate the system," but in a specialized method that separately writes different types of evidence generated by different roles into the same entity in the will chain, and establishes the attribution of responsibility through role fields, time fields, and evidence summary fields. Specifically, this method protects the distinguishability of evidence sources, the attributability of responsible parties, and the verifiability of evidence order across multiple stages of the same will-handling entity, including review, notarization, and effectiveness. Through this method, it is possible not only to determine the state of the will, but also "which type of role, at what time, and based on what evidence, drove this state change," thus making the boundaries of responsibility and evidence in the will-handling chain clearer.
[0193] 7. Collaborative Verification and Execution Methods for External Institutions in Consortium Blockchains for Digital Documents Related to Life Affairs The seventh core concept of this invention lies in proposing a consortium blockchain method for collaborative verification and execution of digital documents related to life-related matters by external institutions. The methods directly affect and protect entities such as entities issuing pre-medical instructions, entities entrusting accidental death, entities issuing wills, and external institutional nodes such as hospitals, judicial organs, and notary offices. Unlike most existing systems that merely store relevant documents as static electronic materials, this invention further extends the consortium blockchain from an "internal evidence storage base" to an "external institutional collaboration base," enabling relevant life-related documents to be reliably retrieved, verified, and executed by external institutional nodes when permission and triggering conditions are met.
[0194] Specifically, based on our existing platform's "off-chain file storage + on-chain state anchoring" structure and independent business modules such as pre-medical instructions and accidental entrustment, this invention further enables restricted participants such as hospitals, judicial organs, and notary offices to access the system as consortium blockchain nodes. When a user uploads documents such as pre-medical instructions, accidental entrustment, or wills, the system creates an off-chain storage object for the file entity and writes its summary, status, triggering conditions, authorization boundaries, and corresponding identifiers into the consortium blockchain. When a preset trigger occurs, such as a user losing the ability to express themselves, a sudden accident, entering the will execution procedure, or meeting the statutory verification procedure, the authorized institutional node can retrieve the corresponding file based on the on-chain identifier, complete content verification, status confirmation, and execution basis confirmation, and write this verification or execution action back into the consortium blockchain. Thus, digital files related to life affairs are no longer merely "stored," but can be reliably accessed in cross-institutional scenarios.
[0195] The core of this invention lies not in the business concept of "hospitals being able to view documents" or "judicial authorities being able to access documents," but in a specialized method that designs digital documents related to life-related matters, such as pre-medical instructions, accidental authorizations, and wills, as objects capable of controlled verification and execution across multiple institutional nodes in a consortium blockchain. The innovation of this method lies in the execution eligibility, verification path, access boundaries, and execution logger methods of life-related document entities in cross-institutional scenarios. In other words, this invention does not protect general electronic file sharing, but rather the entire set of external institutional collaborative processing logic regarding "when a file can be triggered, by whom, based on what on-chain criteria, and how a new on-chain record is formed after triggering."
[0196] 8. The core of this invention is not a single algorithm, a single business page, or a single platform function, but rather a complete technical solution for digital will business scenarios, covering will creation, pre-examination, review, notarization, confirmation, encryption, storage, viewing, invalidation, traceability, and effectiveness.
[0197] 9. Differences between this invention and general website / management systems This invention is not an ordinary will information entry system, nor a simple blockchain evidence storage platform, nor merely a website providing AI question-and-answer functionality. The key features of this invention are: On the one hand, it takes wills, a special business object that is highly sensitive, highly credible, and requires long-term preservation, as the core of its processing; On the other hand, it ensures the long-term security of will ciphertext through post-quantum encryption, achieves trusted evidence storage throughout the entire process through the collaboration of consortium blockchain and IPFS, ensures the orderly flow of business processes through state machines, ensures the legal execution of key operations through private key verification and role-based access control, and improves the efficiency and intelligence level of will services through artificial intelligence modules.
[0198] The above description of the technical solution provided by the present invention through several specific embodiments is intended to highlight the advantages and benefits of the technical solution provided by the present invention. However, the above-described specific embodiments are not intended to limit the present invention. Any reasonable modifications and improvements to the present invention, reasonable combinations of implementation methods and equivalent substitutions based on the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A digital will security management method based on artificial intelligence, blockchain, distributed storage, and post-quantum cryptography, characterized in that, The method includes the following steps: User registration and key generation steps: In response to the user registration request, the server generates key materials for the user based on the certificateless public key encryption mechanism of the lattice cryptosystem and returns the private key file to the user. At the same time, the server only saves the hash digest of the private key file. Will creation and pre-review steps: Receive the will text uploaded by the user, use a large language model to perform semantic analysis and compliance pre-review of the will text, and generate pre-review results to be fed back to the user; Review and notarization steps: Receive the staff's review results of the will and the notarization materials uploaded by the notary, and write the review information and the hash value of the notarization materials into the consortium blockchain; Confirmation and encryption steps: In response to the user's confirmation operation, the private key file uploaded by the user is verified. If the verification is successful, the plaintext of the will is encrypted using the user's public key to generate the ciphertext of the will. Collaborative evidence storage steps: Upload the encrypted will to the distributed file system IPFS to obtain the content identifier CID, and write the CID, will summary and current status information as anchor data into the consortium blockchain; Viewing and tracing steps: In response to the user's viewing request, verify the user's private key file. If it passes, obtain the CID from the consortium blockchain, pull the will ciphertext from IPFS and decrypt it and return it. At the same time, write the access record to the consortium blockchain. External agency collaboration steps: In response to a preset triggering scenario, authorized external agency nodes retrieve and verify will documents based on anchored data on the consortium blockchain, and write the verification behavior into the consortium blockchain.
2. The method according to claim 1, characterized in that, The user registration and key generation steps specifically include: S1: Platform Initialization: The platform determines the lattice cryptosystem parameters according to the preset security parameters; it calls the TrapGen algorithm to generate the system public parameters and the master secret key msk, which is securely stored by the platform and not disclosed to the public; S2: Identity Input: Receive user identity information and generate a corresponding user identifier IDi. The user identifier IDi serves as the identity input parameter in the subsequent key generation and encryption process. S3: User-side private key generation: The user terminal calls the TrapGen algorithm locally to generate a secret value Tbi, constructs a user public key matrix Bi based on the secret value Tbi, and calculates a tag value ti based on the public key matrix Bi and the user identifier IDi to form a user public key pki associated with the identity. S4: Controlled private key component generation on the platform side: After obtaining the user identity identifier IDi, the platform uses the master secret key msk and public parameters to call the SamplePre algorithm to generate a controlled private key component Di corresponding to the user identity identifier IDi; the controlled private key component Di satisfies the constraint relationship with the identity mapping matrix and is used to cancel the identity mapping items in the subsequent decryption process, but it cannot decrypt the will ciphertext on its own. S5: Complete private key combination: The platform securely distributes the controlled private key component Di to the user terminal. The user combines the controlled private key component Di with the secret value Tbi locally to form the complete private key ski. The platform only saves the hash digest of ski and does not save the plaintext of ski. The confirmation and encryption steps specifically include: S6: Will Confirmation Trigger: After the user completes the filling in of the will text, uploads the will attachments and supplements the necessary information in the system, and goes through the pre-process of review and uploading of notarized video, the system enters the will confirmation stage. The system organizes the will information that needs to be protected into a message M to be encrypted. S7: Verification of the validity of the user's public key pki: Before performing encryption, the system recalculates the tag value based on the public key matrix Bi and the user identifier IDi in the user's public key pki, and compares it with the tag carried in the public key pki; if the comparison is inconsistent, the encryption process is terminated. S8: Post-quantum encryption processing: After the verification is passed, the will message M, the user identity IDi and the user public key pki are used as inputs. The matrix Si is randomly selected and the noise terms Ei,1 and Ei,2 are sampled from the error distribution. Based on the system public parameters, the identity mapping matrix and the user public key matrix Bi, the ciphertext components cti1 and cti2 are constructed to generate the will ciphertext cti=(cti1, cti2). S9: Off-chain storage and CID acquisition: Upload the encrypted will (CTI) to the InterPlanetary File System (IPFS) to obtain the corresponding Content Identifier (CID); and write the will summary, Content Identifier (CID), will status, and user confirmation time into the consortium blockchain. S10: Decryption and Recovery: When the user views the message, the complete private key ski is used to decrypt the ciphertext cti obtained from IPFS. The identity mapping related items are offset by the controlled private key component Di. The original will message M is restored by regularizing the user's locally generated private key component Tbi. The access time is then written to the consortium blockchain.
3. The method according to claim 1, characterized in that, The collaborative evidence storage steps specifically include: S1: Initialization: The business backend loads the connection parameters of the consortium blockchain and the IPFS interface parameters; S2: Ciphertext Upload and CID Acquisition: Upload the ciphertext cti of the will generated in claim 3 to the InterPlanetary File System (IPFS) and obtain the unique content identifier (CID); S3: Organization anchor data: The organization's evidence information to be uploaded to the blockchain, which includes at least: will number hash value, creation time, reviewer number, review approval time, notarization video hash value, user confirmation time, CID, access record, invalidation time, effective time and will status; S4: On-chain anchoring: The business backend calls the consortium blockchain chaincode to write the evidence storage information into the consortium blockchain, forming an immutable evidence storage record; S5: Status Update: The business backend updates the status of the will in the local database to "created successfully"; The viewing and tracing steps specifically include: S6: Request and Verification: In response to a user's request to view or trace the source, the business backend receives the private key file uploaded by the user, calculates its hash value and compares it with the private key hash digest pre-stored in the database. After the verification is successful, the subsequent steps are executed. S7: On-chain query: The business backend calls the consortium blockchain chaincode to query the corresponding CID and timeline status information based on the hash value of the will number; S8: Ciphertext Acquisition: The business backend retrieves the ciphertext cti of the will from IPFS based on the CID; S9: Decryption and Recovery: The business backend uses the user's complete private key ski to perform decryption calculations on the ciphertext cti to recover the plaintext of the will; S10: Result Return: If it is a viewing scenario, the plaintext of the will is returned; if it is a tracing scenario, the on-chain state record and off-chain file information are integrated to generate the tracing result. S11: Access Recording: Write the access time to the consortium blockchain to form an access record.
4. The method according to claim 3, characterized in that, When the message M to be encrypted contains attachments to a will, it also includes: For will attachments exceeding a preset threshold, perform block processing to generate multiple attachment blocks; Using multi-threaded concurrent execution, each attachment block is encrypted using lattice-based certificateless encryption to generate encrypted blocks; Store the encrypted blocks and block metadata in the will artifact record; When a user views the file, encrypted blocks are retrieved from IPFS, decrypted concurrently, and then reassembled based on the block metadata to restore the complete attachment.
5. The method according to claim 1, characterized in that, The collaborative evidence storage and viewing / tracing steps also enable on-chain and off-chain entity binding and write-back tracing, specifically including: On-chain and off-chain entity binding: The will number is hashed, and the hash value is used as a unique index for the will entity on the chain. The CID obtained after uploading the encrypted will to IPFS, together with the hash value of the will number, the will status, the confirmation time, the access time, the hash of the notarized video, the hash of the death certificate, and the processing role identifier, is written into the consortium blockchain to establish a one-to-one correspondence between the off-chain file entity and the on-chain business status. Two-stage source tracing retrieval: During the tracing phase, the system first obtains the corresponding CID based on the hash value of the will number or the encrypted hash value; Based on the CID query chain, the status information, timeline information, and access records of the will entity are retrieved. By integrating the on-chain query results with the off-chain file retrieval results corresponding to the CID, complete tracing information for the will is generated. Access event write-back: After a user successfully views the contents of the will, the time of this access and the corresponding access behavior are recorded as new on-chain events and written back to the consortium blockchain, thus realizing the on-chain solidification of the will access behavior entity.
6. The method according to claim 1, characterized in that, The method also includes dual-state linkage closed-loop control for will status entities, specifically including: On the business side, maintain the lifecycle status of the main business entity of wills. The lifecycle status includes at least: draft, submission, rejection and modification, approval, video upload, pending user confirmation, construction completed and effective. Maintain an on-chain state entity corresponding to the main business entity of the will. The on-chain state entity includes at least: will number hash value, confirmation time, notarization video hash, CID, access time, invalidation time and effective time. The key business actions of approval, notarization and uploading, user confirmation, cancellation and effectiveness are mapped to field updates or state migrations of the on-chain state entity through preset conditions. In response to the user's confirmation operation, an asynchronous task of IPFS notarization and on-chain anchoring is triggered; subsequent invalidation operations are only allowed when all the asynchronous tasks are executed successfully and the lifecycle state of the business side reaches the construction completion state. In response to the staff's activation operation, the lifecycle status of the business side and the on-chain status entity will only be updated to the effective status after the death certificate document is received and the on-chain verification is completed.
7. The method according to claim 1, characterized in that, It also includes a multi-role separation of evidence injection and liability attribution process for digital wills, specifically including: At each business stage—approval, uploading of notarized video recordings, and the effective date of the will—heterogeneous evidence generated by different roles is separated by source and injected into on-chain entities. At the approved node, the reviewer number, approval time, rejection time, and reason for rejection are written as independent fields into the will entity on the consortium blockchain; At the notarized video upload node, the notary's number, the notarized video upload time, and the notarized video hash value are written as independent fields into the will entity; At the will taking effect node, the number of the person in charge of taking effect, the hash value of the death certificate, and the effective time are written as independent fields into the will entity; By establishing liability attribution relationships through these independent fields, on-chain will entities can distinguish the source, operation time, and legal facts of different types of evidence.
8. The method according to claim 1, characterized in that, The steps of using a large language model to perform semantic analysis and compliance pre-review of will texts specifically include: Build a legal rule database for wills, and extract rules from official legal documents regarding the formal requirements, completeness of content, and key risks of wills; The rules are transformed into prompt word templates, and pre-screening prompt words are constructed by combining them with few sample examples; The pre-examination prompts are input into a large language model, which performs semantic understanding on the will text and outputs prompts for formal defects, content integrity, and legal risks. The preliminary review results are fed back to the user for correction and synchronized to the staff's end as a reference for manual review, but do not replace the final decision of manual review.
9. A digital will security management system, characterized in that, include: The front-end presentation layer is used to receive user input and display business results. The user input includes at least will creation information, review instructions, notarized materials, and viewing requests. The backend business layer is used to receive requests from the frontend presentation layer and execute core business logic. The backend business layer includes at least a user management module, a will management module, an audit workflow module, a material processing module, an artificial intelligence invocation module, a blockchain interaction module, an IPFS interaction module, and an audit log module. The data storage layer uses a separation of structured and unstructured data to store user information, business status, log information, wills, notarized videos, and death certificates. The trusted evidence storage layer adopts a two-layer trusted evidence storage structure jointly constructed by a consortium blockchain and the InterPlanetary File System (IPFS). The consortium blockchain is used to store the hash value of the will number, the content identifier (CID), the will status, key time nodes, and access records, while the IPFS is used to store the encrypted will and related large files. The intelligent service layer is used to access large language models to perform semantic analysis, compliance assistance judgment, and intelligent question answering support on will texts; The security control layer, which runs through the front-end presentation layer, back-end business layer, data storage layer, and trusted evidence storage layer, is used to perform identity authentication, access authorization, private key verification, sensitive data encryption, and auditing of key operations. The front-end presentation layer, back-end business layer, data storage layer, trusted evidence storage layer, intelligent service layer, and security control layer work together to process will-related matters through interface calls, status transmission, and data collaboration.
10. A digital will security management device, characterized in that, include: The user interaction unit is used to receive will information, attachment information, appointment information and query instructions input by users, and to display the will status, review results, traceability results and effective results to users; The identity authentication and access control unit is used to identify, authorize, and control the operational boundaries of ordinary users, auditors, notaries, and administrators. The Will Creation and Business Flow Unit is used to create will business instances, maintain the migration of wills from the state of creation, creation success, invalidation to effectiveness, and drive the review, notarization, confirmation and storage processes; The AI-assisted review unit is used to perform semantic analysis, rule prompts, and compliance assistance in judging the will text uploaded by users. The post-quantum encryption unit is used to encrypt the will text and attachments during the user confirmation stage, and to decrypt and recover the will based on the complete private key in a legitimate viewing scenario; Distributed storage units are used to write documents such as encrypted wills, notarized videos, and death certificates to the InterPlanetary File System (IPFS) and return Content Identifiers (CIDs). The blockchain evidence storage unit is used to write the will summary, CID, status transition information and access traces into the consortium blockchain; The will tracing unit is used to query the on-chain record and off-chain file corresponding to the will based on the will number hash value, ciphertext hash value or CID, thereby forming a complete timeline and state line; The effective processing unit is used to update the status of the will and record the effective time based on the death certificate information uploaded by the staff when the effective conditions are met. The audit log unit is used to record key operations within the platform, such as login, review, confirmation, viewing, invalidation, activation, and tracing. The various units cooperate with each other through interface calls, database associations, and message tasks.