Digital asset processing method, computer system, and storage medium
By employing a user-held device with processing and integration software to generate zero-knowledge proofs for encrypted digital asset transactions, the solution addresses privacy and security concerns, enabling direct blockchain management without custodian platforms.
Patent Information
- Authority / Receiving Office
- HK · HK
- Patent Type
- Applications
- Current Assignee / Owner
- ADVANCED NOVA TECH (SINGAPORE) HLDG PTE LTD
- Filing Date
- 2026-05-12
- Publication Date
- 2026-07-17
AI Technical Summary
Users managing encrypted digital assets on blockchain platforms face challenges in performing encryption and decryption operations through their user devices, leading to privacy protection issues and increased risks of data leakage due to reliance on custodian platforms.
A user-held device with a general processing unit and target integration software processes asset change information, generating a change request with a zero-knowledge proof, enabling direct transactions on the blockchain for encrypted digital asset changes without custodian platforms, ensuring privacy and security.
This approach allows users to manage encrypted digital assets privately and securely, reducing the risk of privacy data leakage and enhancing the security of digital asset transactions on blockchain systems.
Smart Images

Figure 00000015_0000 
Figure 00000015_0001 
Figure 00000016_0000
Abstract
Description
Specification 1 Digital Asset Processing Method, Computer System, and Storage Medium Technical Field This specification relates to the blockchain field, specifically to a digital asset processing method, computer system, and storage medium. Background Technology Blockchain has advantages such as decentralization, traceability, and high security. In recent years, due to the rapid development of blockchain technology, various digital assets managed based on blockchain have gradually emerged. Some institutions or organizations can issue digital assets with certain value and functions to users through blockchain. In order to improve data security, protect personal privacy, and prevent the leakage of personal financial information and the leakage of the issuer's reserve funds, advanced cryptographic technology can be used to realize the circulation of privacy-protecting encrypted digital assets (such as privacy tokens) on the blockchain. Encrypted digital assets can hide the account balance of their holders, the identity of transaction participants, and the transaction amount. Currently, there is a need for a digital asset processing solution on the blockchain. Summary of the Invention This specification provides a digital asset processing method, computer system, and storage medium through one or more embodiments. According to a first aspect, a method for processing privacy-protecting encrypted digital assets is provided, wherein the encrypted digital assets are issued on a blockchain, and the method is executed by a target device; the target device includes a general processing unit and target integration software deployed for the encrypted digital assets, and the method includes: the general processing unit determining asset change information for the encrypted digital assets; including information on the target amount of the encrypted digital asset change and proof information for proving that the limit condition is met; the general processing unit transmitting the asset change information and a target key to the target integration software; the target integration software generating a change request based on the asset change information and the target key; the change request including a first asset change ciphertext for changing the encrypted digital assets and a zero-knowledge proof for legitimacy verification; the general processing unit sending a target transaction to the blockchain based on the change request, enabling nodes of the blockchain to execute the target transaction, perform legitimacy verification based on the zero-knowledge proof, and change the encrypted digital assets based on the first asset change ciphertext.According to a second aspect, a method for processing privacy-protecting encrypted digital assets is provided, wherein the encrypted digital assets are issued on a blockchain. The method is executed by target integrated software deployed on a target device and includes: receiving asset change information for the encrypted digital assets and a target key; the asset change information includes information on the target amount of the encrypted digital asset change and proof information for proving that the limit condition is met; generating a change request based on the asset change information and the target key; the change request includes a first asset change ciphertext for changing the encrypted digital assets and a zero-knowledge proof for legitimacy verification; and outputting the change request. According to a third aspect, a computer system is provided, the computer system including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program includes a general processing part and a target integration software program for deploying encrypted digital assets, wherein when the processor executes the program, it performs the following target operation at least once, and the target operation achieves the following steps: the general processing part determines asset change information for the encrypted digital asset; including information on the target amount of the encrypted digital asset change and proof information for proving that the limit condition is met; the general processing part transmits the asset change information and the target key to the target integration software; the target integration software generates a change request based on the asset change information and the target key; the change request includes a first asset change ciphertext for changing the encrypted digital asset and a zero-knowledge proof for performing legality verification; the general processing part sends a target transaction to the blockchain that issues the encrypted digital asset based on the change request, so that the nodes of the blockchain perform legality verification based on the zero-knowledge proof by executing the target transaction, and change the encrypted digital asset based on the first asset change ciphertext. According to a fourth aspect, a computer system is provided, the computer system including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, performs the following target operation at least once, thereby achieving the following steps: receiving asset change information for encrypted digital assets and a target key; the asset change information including information on the target amount of the encrypted digital asset change and proof information for proving that the limit condition is met; generating a change request based on the asset change information and the target key; the change request including a first asset change ciphertext for changing the encrypted digital asset and a zero-knowledge proof for performing legality verification; and outputting the change request.According to a fifth aspect, a computer-readable storage medium is provided, the storage medium storing a computer program that, when executed by a processor, implements the method described in any of the preceding claims. The technical solutions provided by the embodiments of this specification may include the following beneficial effects: The blockchain-based digital asset processing scheme provided by the embodiments of this specification includes a user-held target device comprising a general processing unit and target integration software deployed for encrypted digital assets. The general processing unit determines asset change information for the encrypted digital assets and transmits the asset change information and a target key to the target integration software. The target integration software generates a change request based on the asset change information and the target key. The change request includes a first asset change ciphertext for changing the encrypted digital assets and a zero-knowledge proof for legitimacy verification. The general processing unit sends a target transaction to the blockchain, enabling blockchain nodes to execute the target transaction, perform legitimacy verification based on the zero-knowledge proof, and change the encrypted digital assets based on the first asset change ciphertext. This allows users to directly instruct the blockchain system to perform asset changes for encrypted digital assets without going through a hosting platform, meeting the user's privacy protection needs, reducing the risk of privacy data leakage, and improving the security of encrypted digital assets. HK 30135243 A Specification 3 It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Brief Description of the Drawings To more clearly illustrate the technical solutions of the embodiments of this specification, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Figure 1 is a schematic diagram of a scenario for processing encrypted digital assets in the related technology according to an exemplary embodiment of this specification. Figure 2 is a schematic diagram of a digital asset management system on a blockchain according to an exemplary embodiment of this specification. Figure 3 is an interactive flowchart of a digital asset processing method on a blockchain according to an exemplary embodiment of this specification. Figure 4 is an interactive flowchart of another digital asset processing method on a blockchain according to an exemplary embodiment of this specification. Figure 5 is a schematic diagram of a computer system according to an exemplary embodiment of this specification. Detailed Description of Embodiments To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments in this specification, and not all of them. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.Blockchain boasts advantages such as decentralization, traceability, and high security. In recent years, due to the rapid development of blockchain technology, various digital assets managed based on blockchain have emerged. Some institutions or organizations can issue digital assets with certain value and functions to users through blockchain. To improve data security, protect personal privacy, and prevent the leakage of personal financial information and the issuer's reserve funds, advanced cryptographic technology can be used to enable the circulation of privacy-protecting encrypted digital assets (such as privacy tokens) on the blockchain. Encrypted digital assets can hide the account balance of their holders, the identities of transaction participants, and transaction amounts. Generally, when changing encrypted digital assets, encryption and decryption operations are required. However, users involved in the management and use of encrypted digital assets usually cannot perform encryption and decryption operations through their user devices. Therefore, as shown in Figure 1, when changing encrypted digital assets, the user device needs to perform encryption and decryption operations on the encrypted digital assets through a custodian platform. Then, the custodian platform changes the encrypted digital assets in the blockchain through a transaction. However, when encrypting and decrypting encrypted digital assets, a user-held privacy-protected key is required. This privacy-protected key can include a public key and a private key. The public key can be made public, while the private key is relatively private data. Since the encryption and decryption operations need to be performed by a hosting platform, the hosting platform needs to safeguard the privacy-protected key for the user. This makes it difficult to meet the privacy protection needs of some users and increases the risk of privacy data leakage. This specification provides a digital asset processing scheme on a blockchain. The target device held by the user includes a general processing unit and target integration software deployed for encrypted digital assets. The general processing unit determines the asset change information for the encrypted digital asset and transmits the asset change information and the target key to the target integration software. Based on the asset change information and the target key, the target integration software generates a change request. The change request includes a first asset change ciphertext for changing the encrypted digital asset and a zero-knowledge proof for legitimacy verification. The general processing unit sends a target transaction to the blockchain, enabling the blockchain nodes to execute the target transaction, perform legitimacy verification based on the zero-knowledge proof, and change the encrypted digital asset based on the first asset change ciphertext. This allows users to directly instruct the blockchain system to make asset changes to encrypted digital assets without going through a custodian platform, meeting users' privacy protection needs, reducing the risk of privacy data leakage, and improving the security of encrypted digital assets. Figure 2 is a schematic diagram of a blockchain-based digital asset management system according to an exemplary embodiment.As shown in Figure 2, a digital asset management system on a blockchain may include a blockchain 201, at least one issuer 202, at least one regulator 203, and at least one user 204. Issuer 202, regulator 203, and user 204 can all establish communication connections with blockchain 201 through their respective devices. Blockchain 201 may contain, for example, eight nodes (nodes 1 to 8). Each node can be implemented as any device, server, or device cluster with computing and processing capabilities. It is understood that although Figure 2 shows eight nodes in blockchain 201, this embodiment is not limited to this and may include other numbers of nodes. Each node in the blockchain can generate the same state in the blockchain by executing the same transactions, and each node stores the same state database. At least one smart contract for managing encrypted digital assets can be deployed in blockchain 201 (each smart contract corresponds to one encrypted digital asset, and one encrypted digital asset is issued by one issuer). The smart contract can record information such as the total issuance of encrypted digital assets and the balance of each account. Issuer 202 is an institution / organization capable of creating and issuing encrypted digital assets on the blockchain. Issuer 202 can issue encrypted digital assets to user 204 through blockchain 201, and can also liquidate and destroy some or all of the encrypted digital assets held by user 204 in blockchain 201. It can also query information such as the amount of related transactions and each user's balance recorded on the blockchain for this encrypted digital asset. Regulator 203 is a participant that supervises the issuance and balance of encrypted digital assets. Regulator 203 can query information such as the amount of transactions related to encrypted digital assets, each user's balance, and the issuance volume of encrypted digital assets from blockchain 201. Furthermore, when issuing or transferring encrypted digital assets, the issuer or transferor usually sends the issuance or transfer amount to Regulator 203 simultaneously in homomorphic ciphertext to supervise the issuance and transfer process. However, Regulator 203 does not have the authority to operate on encrypted digital assets (such as issuance, transfer, liquidation, etc.). User 204 is an individual or organization holding cryptocurrency assets. They can obtain a predetermined amount of cryptocurrency assets from issuer 202, or from other users' accounts, and can also transfer a predetermined amount of cryptocurrency assets to other users' accounts (e.g., user 204a transfers to user 104b, or user 204b transfers to user 204a). User 204 can query the balance information of their cryptocurrency assets on blockchain 201 and has the authority to decrypt their cryptocurrency assets.Specifically, taking the scenario of issuer 202 issuing encrypted digital asset Z to user 204a as an example, issuer 202 first obtains the issuance amount n of encrypted digital asset Z, and uses the public key portion KG2 of the privacy protection key held by issuer 202, the public key portion KG4a of the privacy protection key held by user 204a, and the public key portion KG3 of the privacy protection key held by regulator 203 to homomorphically encrypt the issuance amount n, obtaining the homomorphic ciphertext Enc(Zn). Next, based on the private key portion KS2 of the privacy protection key held by issuer 202, proof data Q is generated. This proof data Q can be used to prove that the issuance amount decrypted by user 204a and regulator 203 is consistent (both are n), and that the issuance amount issued by issuer 202 does not exceed the predetermined amount (i.e., there is no over-issuance). In addition, issuer 202 will also generate data D1, etc., to provide decryption information to user 204a and regulator 203. Then, issuer 202 can submit transaction TX1, which calls contract C, to blockchain 201. Transaction TX1 includes homomorphic ciphertext Enc(Zn), proof data Q, and data D1. Generally, issuer 202 will sign transaction TX1 using its blockchain private key to obtain signature data. After receiving transaction TX1, each node of blockchain 201 executes contract C. First, it uses the blockchain public key held by issuer 202 to verify the aforementioned signature data. After successful verification, it verifies the proof data Q. After successful verification, it can read the ciphertext Enc(Zm) of user 204a's account balance from the state data of contract C, add the ciphertext Enc(Zn) and ciphertext Enc(Zm) to obtain the new balance ciphertext Enc(Zn+Zm). The user 204a's account balance in the state data of contract C is then updated to the new balance ciphertext Enc(Zn+Zm). Furthermore, blockchain 201 can notify user 204a and regulator 203, enabling them to obtain the content of transaction TX1 from the blockchain's transaction data, and to acquire the homomorphic ciphertext Enc(Zn) and data D1. User 204a can decrypt the homomorphic ciphertext Enc(Zn) based on the private key portion KS4a of its privacy-protected key and data D1, obtaining the plaintext issuance amount n, and using the issuance amount n to update the balance of its locally recorded encrypted digital asset Z. Regulator 203 can also decrypt the homomorphic ciphertext Enc(Zn) based on the private key portion KS3 of its privacy-protected key and data D1, obtaining the plaintext issuance amount n, and performing regulatory audits based on the issuance amount n.Taking the scenario of user 204b transferring encrypted digital asset Z to user 204a as an example, user 204b first obtains the transfer amount w of encrypted digital asset Z, and uses the public key portion KG4b of the privacy protection key held by user 204b, the public key portion KG4a of the privacy protection key held by user 204a, and the public key portion KG3 of the privacy protection key held by regulator 203 to homomorphically encrypt the transfer amount w, obtaining the homomorphic ciphertext Enc(Zw). Next, based on the private key portion K4b of the privacy protection key held by user 204b, proof data Q is generated. This proof data Q can be used to prove that the transfer amount decrypted by user 204a and regulator 203 is consistent (both are n), and that the transfer amount by user 204b does not exceed its total balance. In addition, user 204b will also generate data D2, etc., to provide decryption information to user 204a and regulator 203. Then, user 204b can submit transaction TX2, which calls contract C, to blockchain 201. Transaction TX2 includes homomorphic ciphertext Enc(Zw), proof data Q, and data D2. Generally, user 204b will sign transaction TX2 using its blockchain private key to obtain signature data. After receiving transaction TX2, each node of blockchain 201 executes contract C, first verifying the signature data using the blockchain public key held by user 204b. After successful verification, the proof data Q is verified. After successful verification, the ciphertext Enc(Zm) of user 204a's account balance can be read from the state data of contract C. The ciphertext Enc(Zw) is added to the ciphertext Enc(Zm) to obtain a new balance ciphertext Enc(Zw+Zm). The user 204a's account balance in the state data of contract C is then updated to the new balance ciphertext Enc(Zw+Zm). Similarly, the ciphertext Enc(Zv) of user 204b's account balance is read, and the ciphertext Enc(Zv) is subtracted from the ciphertext Enc(Zw) to obtain the new balance ciphertext Enc(Zv-Zw). The account balance of user 204b in the state data of contract C is updated to the new balance ciphertext Enc(Zv-Zw). In addition, blockchain 201 can notify user 204b that the transaction was successfully executed, and user 204b can directly update the balance of its locally recorded encrypted digital asset Z using the transfer amount w. Blockchain 201 can also notify user 204a and regulator 203, allowing user 204a and regulator 203 to obtain the content of transaction TX2 from the blockchain's transaction data, and to obtain the homomorphic ciphertext Enc(Zw) and data D2.User 204a can decrypt the homomorphic ciphertext Enc(Zw) based on the private key portion KS4a and data D2 in its privacy-protected key to obtain the plaintext issuance amount w, and use the issuance amount w to update the balance of its locally recorded encrypted digital asset Z. Supervisor 203 can also decrypt the homomorphic ciphertext Enc(Zw) based on the private key portion KS3 and data D2 in its privacy-protected key to obtain the plaintext issuance amount w, and perform regulatory audits based on the issuance amount w. The following will describe the solution provided in this specification in detail with reference to specific embodiments. As shown in Figure 3, Figure 3 is an interactive flowchart illustrating a digital asset processing method on a blockchain according to an exemplary embodiment. This blockchain issues privacy-protected encrypted digital assets. The method involves a target device and blockchain nodes. The target device includes a general processing component and target integrated software deployed for encrypted digital assets. Both the target device and the blockchain nodes can be implemented as any device, server, or device cluster with computing and processing capabilities. The method includes the following steps: In step 301, the general processing part of the target device determines the asset change information for the encrypted digital asset, and in step 302, the general processing part transmits the asset change information and the target key to the target integration software. In this embodiment, the target device may be a device held by a participant managing or using the encrypted digital asset. The participant managing or using the encrypted digital asset may be a user of the encrypted digital asset or an issuer of the encrypted digital asset. The user can transfer the encrypted digital asset, and the issuer can issue or destroy the encrypted digital asset. The general processing part in the target device may be a part of a regular device, capable of information collection and interaction with the blockchain system. In addition to the general processing part, target integration software may be deployed on the target device for the encrypted digital asset. This target integration software may be an SDK or an application. This target integration software can use the key to encrypt plaintext digital assets, decrypt ciphertext digital assets, and generate zero-knowledge proofs for legitimacy verification. Specifically, when asset changes are required for encrypted digital assets, the general processing unit can first determine the asset change information for the encrypted digital assets. This asset change information may include information about the target amount of the encrypted digital asset change and proof information to demonstrate that the limit conditions are met. The asset change for the encrypted digital asset may include, but is not limited to, transferring out, issuing, or destroying the encrypted digital asset. The target amount may be the amount of the encrypted digital asset that needs to be transferred out, issued, or destroyed. The proof information may be a zero-knowledge proof to demonstrate that the limit conditions are met.In the case of transferring out encrypted digital assets, the limit condition is met if the account balance is greater than or equal to the target amount; in the case of issuing encrypted digital assets, the limit condition is met if the sum of the issuance amount and the target amount is less than the issuance limit; in the case of destroying encrypted digital assets, the limit condition is met if the total issuance amount is greater than or equal to the target amount. Then, the general processing unit can transmit the asset change information and the target key to the target integration software. The target key can include a public key and a private key. The public key can include the public key corresponding to the participant holding the target device, as well as the public keys corresponding to other participants. The private key can include the private key corresponding to the participant holding the target device. In step 303, the target integration software generates a change request based on the asset change information and the target key. In this embodiment, the target integration software can generate a change request based on the asset change information and the target key, and transmit the generated change request back to the general processing unit. The change request can at least include a first asset change ciphertext for changing the encrypted digital assets and a zero-knowledge proof for legitimacy verification. Specifically, the target integration software can use the public key portion corresponding to the target key to homomorphically encrypt the target amount information of the encrypted digital asset change, obtaining the first asset change ciphertext. Based on the proof information included in the asset change information and the private key portion corresponding to the target key, a zero-knowledge proof for legitimacy verification is generated. In one implementation, the target device can be a device used by the user, the change of encrypted digital assets can be a transfer of encrypted digital assets, and the proof information in the asset change information can include the balance of the user's corresponding account in the encrypted digital assets, which proves that the balance of the user's corresponding account is greater than or equal to the target amount. In another implementation, the target device can be a device used by the issuer, the change of encrypted digital assets can be the issuance of encrypted digital assets, and the proof information in the asset change information can include the issuance quantity and issuance limit of the encrypted digital assets, which can be used to prove that the sum of the issuance quantity and the target amount is less than the issuance limit. In another implementation, as described in HK 30135243 A Specification 8, the target device can be a device used by the issuer, and changing the encrypted digital asset can mean destroying the encrypted digital asset. The proof information in the asset change information can include the issuance quantity of the encrypted digital asset, which can be used to prove that the issuance quantity is greater than or equal to the target amount. In step 304, the general processing part sends the target transaction to the blockchain, and in step 305, the blockchain nodes perform legality verification based on zero-knowledge proof by executing the target transaction, and change the encrypted digital asset based on the first asset change ciphertext. In this embodiment, the general processing part can send the target transaction to the blockchain based on the change request returned by the target integrated software, and the target transaction can include the change request.After receiving a target transaction, a blockchain node can execute it. Execution begins with a legality verification using zero-knowledge proofs. Once the legality verification is successful, the encrypted digital asset is changed based on the first asset change ciphertext. It should be noted that the target transaction can also include information about the type of digital asset change and the accounts involved. Specifically, a blockchain node can obtain the ciphertext of the account balance requiring a reduction in digital assets, subtract the first asset change ciphertext from this ciphertext to obtain a new ciphertext, and then use this new ciphertext to update the old ciphertext in the state database; and / or obtain the ciphertext of the account balance requiring an increase in digital assets, add the first asset change ciphertext to this ciphertext to obtain a new ciphertext, and then use this new ciphertext to update the old ciphertext in the state database. The blockchain-based digital asset processing method provided in this specification includes a user-held target device comprising a general processing unit and target integration software deployed for encrypted digital assets. The general processing unit determines asset change information for the encrypted digital assets and transmits this information, along with a target key, to the target integration software. Based on the asset change information and the target key, the target integration software generates a change request. This request includes a first asset change ciphertext for changing the encrypted digital assets and a zero-knowledge proof for legitimacy verification. The general processing unit sends a target transaction to the blockchain, enabling blockchain nodes to execute the target transaction, perform legitimacy verification based on the zero-knowledge proof, and change the encrypted digital assets based on the first asset change ciphertext. This allows users to directly instruct the blockchain system to perform asset changes for encrypted digital assets without going through a hosting platform, meeting user privacy protection needs, reducing the risk of privacy data leakage, and improving the security of encrypted digital assets. Figure 4 illustrates another blockchain-based digital asset processing method according to an exemplary embodiment, describing the asset change query process. The method includes the following steps: In step 401, the general processing unit sends a transaction query request to the blockchain, and in step 402, the general processing unit receives the queried transaction information and transmits the transaction information and the target key to the target integrated software. In some application scenarios, for example, after a certain amount of digital assets are transferred to or destroyed in the account corresponding to the target device, the target device can query the changes in digital assets from the blockchain and perform corresponding business operations. Specifically, the general processing unit in the target device can send a transaction query request to the blockchain. The blockchain can return the query result to the general processing unit in the target device. The query result may include transaction information for encrypted digital assets, and the transaction information may include a second asset change ciphertext.After receiving the queried transaction information, the general processing unit transmits the transaction information and the target key to the target integration software. In step 403, the target integration software obtains the asset change information based on the second asset change ciphertext and transmits the asset change information back to the general processing unit. In step 404, the general processing unit performs business operations based on the asset change information. In this embodiment, the target integration software can obtain the asset change information based on the second asset change ciphertext and transmit the asset change information back to the general processing unit. Specifically, the target integration software can use the private key portion corresponding to the target key to decrypt the second asset change ciphertext to obtain the asset change information. The asset change information can be the amount of encrypted digital assets transferred to or destroyed in the account corresponding to the target device. The target integration software can transmit the asset change information back to the general processing unit. Finally, the general processing unit can perform corresponding business operations based on the asset change information. These business operations may include, for example, updating the locally recorded encrypted digital asset balance of the account corresponding to the target device. It is understood that this embodiment does not limit the specific method of this business operation. The blockchain-based digital asset processing method provided in this specification involves a user-held target device's general processing unit sending a transaction query request to the blockchain. The general processing unit receives the queried transaction information and transmits the transaction information and the target key to the target integration software. The target integration software obtains asset change information based on a second asset change ciphertext and transmits the asset change information back to the general processing unit. The general processing unit then performs business operations based on the asset change information. This further reduces the risk of privacy data leakage and helps improve the security of encrypted digital assets. It should be noted that although the operations of the methods in the embodiments of this specification are described in a specific order in the above embodiments, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Rather, the steps depicted in the flowcharts can be executed in a different order. Additionally or alternatively, certain steps can be omitted, multiple steps can be combined into one step, and / or one step can be broken down into multiple steps. This specification also provides a computer-readable non-transitory storage medium storing a computer program that, when executed by a processor, can be used to perform one or more steps of one or more methods described or illustrated herein, or to provide the functionality described or illustrated herein.Here, one or more computer-readable non-transitory storage media may include one or more semiconductor-based or other integrated circuits (ICs) (e.g., field-programmable gate arrays (FPGAs) or application-specific integrated circuits (ASICs)), hard disk drives (HDDs), hybrid hard disk drives (HHDs), optical disks, optical disk drives (ODDs), magneto-optical disks, magneto-optical disk drives, floppy disks, floppy disk drives (FDDs), magnetic tape, solid-state drives (SSDs), RAM drives, secure digital cards or drives, any other suitable computer-readable non-transitory storage media, or any suitable combination of two or more of these, where appropriate. The computer-readable non-transitory storage media may be volatile, non-volatile, or a combination of volatile and non-volatile, where appropriate. HK 30135243 A Specification 10 This specification also provides a computer system. Figure 5 illustrates an exemplary computer system 1000. In a particular embodiment, one or more computer systems 1000 perform one or more steps of one or more methods described or illustrated herein. In a particular embodiment, one or more computer systems 1000 provide the functionality described or illustrated herein. In a particular embodiment, software running on one or more computer systems 1000 performs one or more steps of one or more methods described or illustrated herein, or provides the functionality described or illustrated herein. The particular embodiment includes one or more portions of one or more computer systems 1000. Herein, references to computer systems may include computing devices, and vice versa, where appropriate. Furthermore, references to computer systems may include one or more computer systems, where appropriate. This disclosure contemplates any suitable number of computer systems 1000. This disclosure envisions computer systems 1000 taking any suitable physical form. By way of example and not limitation, computer system 1000 may be an embedded computer system, a system-on-a-chip (SOC), a single-board computer system (SBC) (e.g., a computer-on-module (COM) or system-on-module (SOM)), a desktop computer system, a laptop or notebook computer system, an interactive kiosk, a mainframe, a computer system network, a mobile phone, a personal digital assistant (PDA), a server, a tablet computer system, or a combination of two or more of these. Where appropriate, computer system 1000 may include one or more computer systems 1000; single or distributed; spanning multiple locations; spanning multiple machines; spanning multiple data centers; or residing in the cloud, which may include one or more cloud components in one or more networks. Where appropriate, one or more computer systems 1000 may perform one or more steps of one or more methods described or illustrated herein without substantial spatial or temporal limitations.By way of example and not limitation, one or more computer systems 1000 may execute one or more steps of one or more methods described or illustrated herein in real time or in batch mode. Where appropriate, one or more computer systems 1000 may execute one or more steps of one or more methods described or illustrated herein at different times or at different locations. In a particular embodiment, computer system 1000 includes processor 1002, memory 1004, storage 1006, input / output (I / O) interface 1008, communication interface 1010, and bus 1012. Although this disclosure describes and illustrates a particular computer system having a particular number of particular components in a particular arrangement, this disclosure contemplates any suitable computer system having any suitable number of any suitable components in any suitable arrangement. In a particular embodiment, processor 1002 includes hardware for executing instructions, such as instructions constituting a computer program. By way of example and not limitation, in order to execute instructions, processor 1002 may retrieve (or fetch) instructions from internal registers, internal caches, memory 1004, or memory 1006; decode and execute them; and then write one or more results to internal registers, internal caches, memory 1004, or memory 1006. In certain embodiments, processor 1002 may include one or more internal caches for data, instructions, or addresses. This disclosure contemplates that processor 1002 may include any appropriate number of appropriate internal caches where appropriate. By way of example and not limitation, processor 1002 may include one or more instruction caches, one or more data caches, and one or more translation back-of-care buffers (TLBs). Instructions in the instruction cache may be copies of instructions in memory 1004 or memory 1006, and the instruction cache may accelerate the retrieval of those instructions by processor 1002. The data in the data cache may be a copy of data in memory 1004 or memory 1006 for instruction operations executed at processor 1002; the result of a previous instruction executed at processor 1002 for subsequent instructions executed at processor 1002 to access or write to memory 1004 or memory 1006; or other suitable data. The data cache can accelerate read or write operations of processor 1002. The TLB can accelerate virtual address translation of processor 1002. In a particular embodiment, processor 1002 may include one or more internal registers for data, instructions, or addresses. This disclosure contemplates that processor 1002 may include any appropriate number of appropriate internal registers where appropriate.Where appropriate, processor 1002 may include one or more arithmetic logic units (ALUs), may be a multi-core processor, or may include one or more processors 1002. Although this disclosure describes and illustrates specific processors, this disclosure contemplates any suitable processor. In a particular embodiment, memory 1004 includes main memory for storing instructions to be executed by processor 1002 or data to be operated on by processor 1002. By way of example and not limitation, computer system 1000 may load instructions from memory 1006 or another source (e.g., another computer system 1000) into memory 1004. Processor 1002 may then load instructions from memory 1004 into internal registers or internal caches. To execute instructions, processor 1002 may retrieve instructions from internal registers or internal caches and decode them. During or after instruction execution, processor 1002 may write one or more results (which may be intermediate or final results) to internal registers or internal caches. Processor 1002 may then write one or more of these results to memory 1004. In a particular embodiment, processor 1002 executes only instructions in one or more internal registers or internal caches or memory 1004 (as opposed to memory 1006 or elsewhere), and operates only on data in one or more internal registers or internal caches or memory 1004 (as opposed to memory 1006 or elsewhere). One or more memory buses (each memory bus may include an address bus and a data bus) couple processor 1002 to memory 1004. As described below, bus 1012 may include one or more memory buses. In a particular embodiment, one or more memory management units (MMUs) reside between processor 1002 and memory 1004 and facilitate access to memory 1004 requested by processor 1002. In a particular embodiment, memory 1004 includes random access memory (RAM). Where appropriate, the RAM may be volatile memory. Where appropriate, the RAM may be dynamic RAM (DRAM) or static RAM (SRAM). Furthermore, where appropriate, the RAM may be single-port or multi-port RAM. This disclosure contemplates any suitable RAM. Where appropriate, memory 1004 may include one or more memories 1004. Although this disclosure describes and illustrates specific memories, it contemplates any suitable memories. In a particular embodiment, memory 1006 includes a large-capacity memory for data or instructions.By way of example and not limitation, storage 1006 may include a hard disk drive (HDD), a floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, storage 1006 may include removable or non-removable (or fixed) media. Where appropriate, storage 1006 may be internal to computer system 1000 or external to it. In a particular embodiment, storage 1006 is a non-volatile solid-state memory. In a particular embodiment, storage 1006 includes read-only memory (ROM). Where appropriate, the ROM may be a mask-programmable ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically changeable ROM (EAROM), or flash memory, or a combination of two or more of these. This disclosure contemplates large-capacity storage 1006 in any suitable physical form. Where appropriate, storage 1006 may include one or more storage control units that facilitate communication between processor 1002 and storage 1006. Where appropriate, storage 1006 may include one or more storage units 1006. Although specific storage is described and illustrated in this disclosure, any suitable storage is contemplated in this disclosure. In a particular embodiment, I / O interface 1008 includes hardware, software, or both, providing one or more interfaces for communication between computer system 1000 and one or more I / O devices. Where appropriate, computer system 1000 may include one or more of these I / O devices. One or more of these I / O devices can enable communication between a person and computer system 1000. By way of example and not limitation, I / O devices may include a keyboard, keypad, microphone, monitor, mouse, printer, scanner, speaker, still camera, stylus, graphics tablet, touchscreen, trackball, camera, other suitable I / O devices, or combinations of two or more of these devices. I / O devices may include one or more sensors. This disclosure contemplates any suitable I / O devices and any suitable I / O interface 1008 for them. Where appropriate, I / O interface 1008 may include one or more devices or software drivers that enable processor 1002 to drive one or more of these I / O devices. Where appropriate, I / O interface 1008 may include one or more I / O interfaces 1008. Although this disclosure describes and illustrates specific I / O interfaces, this disclosure contemplates any suitable I / O interface.In a particular embodiment, communication interface 1010 includes hardware, software, or both, providing one or more interfaces for communication (e.g., packet-based communication) between computer system 1000 and one or more other computer systems 1000 or one or more networks. By way of example, and not limitation, communication interface 1010 may include a network interface controller (NIC) or network adapter for communicating with Ethernet or other wired networks, or a wireless NIC (WNIC) or wireless adapter for communicating with wireless networks such as Wi-Fi networks. This disclosure contemplates any suitable network and any suitable communication interface 1010 for that network. By way of example, and not limitation, computer system 1000 may communicate with one or more portions of an ad hoc network, personal area network (PAN), local area network (LAN), wide area network (WAN), metropolitan area network (MAN), or the Internet, or a combination of two or more of these. One or more portions of one or more of these networks may be wired or wireless. As an example, computer system 1000 may communicate with a wireless PAN (WPAN) (e.g., Bluetooth WPAN), a Wi-Fi network, a Wi-Fi Max network, a cellular telephone network (e.g., a Global System for Mobile Communications (GSM) network), or other suitable wireless networks, or a combination of two or more of these networks. Where appropriate, computer system 1000 may include any suitable communication interface 1010 for any of these networks. Where appropriate, communication interface 1010 may include one or more communication interfaces 1010. Although specific communication interfaces are described and illustrated in this disclosure, any suitable communication interface is contemplated in this disclosure. HK 30135243 A Specification 13 In a particular embodiment, bus 1012 includes hardware, software, or both that couple components of computer system 1000 to each other. By way of example and not limitation, bus 1012 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), an HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an INFINIBAND interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCIe) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or another suitable bus, or a combination of two or more of these buses. Where appropriate, bus 1012 may include one or more buses 1012. Although this disclosure describes and illustrates specific buses, this disclosure contemplates any suitable bus or interconnect.It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. The various embodiments in this specification are described in a progressive manner, and similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and relevant parts can be referred to the description of the method embodiments. The above descriptions are merely embodiments of this specification and are not intended to limit this specification. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims of this application. HK 30135243 A Claims 1 1. A method for processing privacy-preserving encrypted digital assets, wherein the encrypted digital assets are issued on a blockchain, and the method is executed by a target device; the target device includes a general processing unit and target integrated software deployed for the encrypted digital assets, and the method includes: the general processing unit determining asset change information for the encrypted digital assets; the asset change information including information on the target amount of the encrypted digital asset change and proof information for proving that the limit condition is met; the general processing unit transmitting the asset change information and a target key to the target integrated software; the target integrated software generating a change request based on the asset change information and the target key; the change request including a first asset change ciphertext for changing the encrypted digital assets and a zero-knowledge proof for legitimacy verification; the general processing unit sending a target transaction to the blockchain based on the change request, enabling nodes in the blockchain to execute the target transaction, perform legitimacy verification based on the zero-knowledge proof, and change the encrypted digital assets based on the first asset change ciphertext. According to the method of claim 1, the step of generating a change request based on the asset change information and the target key includes: using the public key portion corresponding to the target key to perform homomorphic encryption on the target amount information of the encrypted digital asset change to obtain a first asset change ciphertext; and generating the zero-knowledge proof for legitimacy verification based on the proof information included in the asset change information and the private key portion corresponding to the target key.3. The method according to claim 1, wherein the method further comprises: the general processing part sending a transaction query request to the blockchain; the general processing part receiving the queried transaction information and transmitting the transaction information and the target key to the target integration software; the transaction information including a second asset change ciphertext; the target integration software obtaining asset change information based on the second asset change ciphertext and transmitting the asset change information back to the general processing part; the general processing part performing business operations based on the asset change information. 4. The method according to claim 3, wherein obtaining asset change information based on the second asset change ciphertext comprises: decrypting the second asset change ciphertext using the private key portion corresponding to the target key to obtain the asset change information. 5. The method according to claim 1, wherein the target integration software includes an SDK or an application. 6. The method according to claim 1, wherein changing the encrypted digital asset includes transferring out the encrypted digital asset, issuing the encrypted digital asset, or destroying the encrypted digital asset. 7. 8. The method according to claim 1, wherein the target device is a device used by a user, the change of the encrypted digital asset includes transferring out the encrypted digital asset, the proof information includes the balance of the user's corresponding account in the encrypted digital asset, and the proof information is used to prove that the balance of the user's corresponding account is greater than or equal to the target amount. 9. The method according to claim 1, wherein the target device is a device used by an issuer, the change of the encrypted digital asset includes issuing the encrypted digital asset, the proof information includes the issuance quantity and issuance limit of the encrypted digital asset, used to prove that the sum of the issuance quantity and the target amount is less than the issuance limit.10. A method for processing privacy-preserving encrypted digital assets, the encrypted digital assets being issued on a blockchain, the method being executed by target integrated software deployed on a target device, and comprising: receiving asset change information for the encrypted digital asset and a target key; the asset change information including information on the target amount of the encrypted digital asset change and proof information for proving that the limit condition is met; generating a change request based on the asset change information and the target key; the change request including a first asset change ciphertext for changing the encrypted digital asset and a zero-knowledge proof for legitimacy verification; and outputting the change request. HK 30135243 A Manual Appendix 1 User Equipment User Equipment Management Platform Blockchain System Figure 1 203 201 202 204 204a 204b Figure 2 HK 30135243 A Manual Appendix 2 General Processing Section Target Integration Software 301 Blockchain Node 302 Based on asset change information and target key, generate change request Determine asset change information for encrypted digital asset Target device Transmit asset change information and target key Send target transaction Execute target transaction, perform legality verification based on zero-knowledge proof, and change encrypted digital asset based on first asset change ciphertext 303 304 305 Return change request Figure 3 HK 30135243 A Manual Appendix 3 General Processing Section Target Integration Software 401 Blockchain Node 402 Based on second asset change ciphertext, obtain asset change information Target device Return transaction information Send transaction query request Perform business operation based on asset change information 405 Transmit asset change information Transmit transaction information and target key 403 Figure 4 Computer System 1000 Processor 1002 Input / Output (I / O) Interface 1008 Memory 1004 Storage 1006 Communication Interface 1010 Figure 5 HK 30135243 A.