This invention relates to the fields of
information security and
computer software technology, and discloses a collaborative asset
management system based on end-to-end
encryption, employing a zero-knowledge architecture with
client-
server collaboration. The
client creates a collaborative space and generates a space key. For sensitive credentials, it generates a content key to form credential
ciphertext and content key encapsulated
ciphertext. During access, a controlled-use proxy decapsulates the content key encapsulated
ciphertext in a local controlled execution environment to obtain the content key, completing controlled credential use and thus preventing the
plaintext credential from being exposed to external programs. The
server stores the space key encapsulated ciphertext, credential ciphertext, content key encapsulated ciphertext, and
directory and policy information. Through a proxy re-
encryption (ciphertext domain conversion) module, the space key encapsulated ciphertext is converted into ciphertext that new members can decapsulate without decrypting the
plaintext key, enabling dynamic member addition without re-encrypting and retransmitting all credentials. The
system registers capability declarations through extended module interfaces to describe heterogeneous asset access capabilities. Based on this, the
client selects a connector and executes a blind injection / proxy call
authentication process. At the same time, audit events are encrypted and their integrity is protected by hash chains or digital signatures. The
server only stores audit ciphertext and non-sensitive index fields, thereby achieving
collaborative management, controllable use, and scalable access under zero-knowledge conditions.