WO2026007993A1 - 数字资产的操作权限的控制方法、模块及存储介质 - Google Patents

数字资产的操作权限的控制方法、模块及存储介质

Info

Publication number
WO2026007993A1
WO2026007993A1 PCT/CN2025/106662 CN2025106662W WO2026007993A1 WO 2026007993 A1 WO2026007993 A1 WO 2026007993A1 CN 2025106662 W CN2025106662 W CN 2025106662W WO 2026007993 A1 WO2026007993 A1 WO 2026007993A1
Authority
WO
WIPO (PCT)
Prior art keywords
digital asset
functional module
information
user
platform
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2025/106662
Other languages
English (en)
French (fr)
Inventor
刘婧雯
李一萌
张慧媛
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
Research Institute of China Mobile Communication Co Ltd
Original Assignee
China Mobile Communications Group Co Ltd
Research Institute of China Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Group Co Ltd, Research Institute of China Mobile Communication Co Ltd filed Critical China Mobile Communications Group Co Ltd
Publication of WO2026007993A1 publication Critical patent/WO2026007993A1/zh
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/37Managing security policies for mobile devices or for controlling mobile applications

Definitions

  • This application relates to the field of business access control technology, specifically to a method, module, and storage medium for controlling the operation permissions of digital assets.
  • At least one embodiment of this application provides a method, module, and storage medium for controlling the operation permissions of digital assets, which addresses the issue of cross-platform operation permission control for digital assets.
  • This application provides a method for controlling operation permissions of digital assets, including:
  • the first functional module receives a first request sent by the first platform, which is used to request the first user to perform a first operation on the first digital asset.
  • the first functional module sends a first response to the first platform to indicate the result of the first operation on the first digital asset.
  • the information of the first digital asset includes: the digital asset identifier of the first digital asset;
  • the information for the first operation includes the operation type and/or the operation time, wherein the operation type includes one or more of access, update, change, and download.
  • the first request and the second request further include: a token list of the first user, wherein each token in the token list of the first user corresponds to an operation authorization for a digital asset.
  • the second token may be included in the first response sent to the first platform so that the first terminal corresponding to the first user may add the second token to the first user's token list.
  • This application provides a method for controlling operation permissions of digital assets, including:
  • the second functional module receives a second request sent by the first functional module.
  • the second request is used to verify whether the first user has permission to perform a first operation on the first digital asset.
  • the second functional module verifies whether the first user has permission to perform the first operation on the first digital asset
  • the second functional module sends a second response to the first functional module to indicate whether the first user has permission to perform a first operation on the first digital asset.
  • the second request includes: the first user's first user information and/or the first digital asset information and/or the first operation information.
  • the first user information includes a user identifier and/or a list of tokens for the first user
  • the information of the first digital asset includes: the digital asset identifier of the first digital asset;
  • the information for the first operation includes the operation type and/or the operation time, wherein the operation type includes one or more of access, update, change, and download.
  • the second functional module verifies whether the first user has permission to perform a first operation on the first digital asset, including:
  • the second functional module verifies the control mode of the first digital asset
  • the second functional module When the first digital asset is in a relaxed control mode, the second functional module sends a second response to the first functional module, and the second response is used to indicate that the first user has permission to perform a first operation on the first digital asset.
  • the second functional module in verifying whether the first user has permission to perform a first operation on the first digital asset, further includes:
  • the first digital asset When the first digital asset is in strict control mode or general control mode, the first user's permission to perform the first operation on the first digital asset is verified. When the permission verification is successful, the second functional module sends a second response to the first functional module. The second response is used to indicate that the first user has permission to perform the first operation on the first digital asset.
  • verifying the first user's permission to perform the first operation on the first digital asset includes: verifying the first user's permission to perform the first operation on the first digital asset through the authorization record stored in the second functional module.
  • the second functional module in verifying whether the first user has permission to perform the first operation on the first digital asset, further includes:
  • the second functional module sends a third request to the second platform and/or the second terminal to request the first user's permission to perform a first operation on the first digital asset.
  • the second functional module receives a third response from the second platform and/or the second terminal, indicating whether the first user is allowed to perform a first operation on the first digital asset.
  • Optional also includes:
  • the second functional module proceeds to the step of sending a second response to the first functional module, and the second response is used to indicate that the first user has permission to perform a first operation on the first digital asset.
  • the second functional module proceeds to the step of sending a second response to the first functional module, and the second response is used to indicate that the first user does not have permission to perform the first operation on the first digital asset.
  • the third request may include: first user information and/or first digital asset information and/or first operation information;
  • the first user information includes a user identifier
  • the information of the first digital asset includes: the digital asset identifier of the first digital asset;
  • the information for the first operation includes the operation type and/or the operation time, wherein the operation type includes one or more of access, update, change, and download.
  • Optional also includes:
  • a new authorization record is stored according to the third response, the new authorization record including information about the first digital asset and information about the first operation.
  • the second request includes the first user's token list, wherein each token in the first user's token list corresponds to an operation authorization for a digital asset;
  • Verifying the first user's permission for the first operation on the first digital asset using the authorization records stored in the second functional module includes: matching the first user's token list with the first digital asset's token list, wherein each token in the first digital asset's token list corresponds to an operation authorization of the first digital asset and is associated with information of an operation.
  • first user's token list and the first digital asset's token list contain the same first token, obtain the information of the second operation associated with the first token. If the information of the first operation matches the information of the second operation, determine that the permission verification is successful; otherwise, determine that the permission verification has failed.
  • storing the new authorization record specifically includes: generating a second token, storing it in the token list of the first digital asset, and associating the second token with the information of the first operation.
  • Optional also includes:
  • the second response includes the second token, which is then added to the first user's token list by the first terminal corresponding to the first user.
  • This application provides a method for controlling operation permissions of digital assets, including:
  • the second functional module receives a fourth request sent by the first platform or the first terminal to apply for the first user's permission to perform a first operation on the first digital asset.
  • the second functional module determines whether the fourth request requires the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal;
  • the second functional module sends a fifth request to the second platform and/or the second terminal to request the first user's permission for a first operation on the first digital asset.
  • the fourth request may include first user information and/or information about the first digital asset and/or information about the first operation;
  • the first user information includes a user identifier; the information of the first digital asset includes: the digital asset identifier of the first digital asset; the information of the first operation includes the operation type and/or the operation time, wherein the operation type includes one or more of access, update, change, and download.
  • Optional also includes:
  • the second functional module receives a fifth response from the second platform and/or the second terminal, indicating whether the first user is allowed to perform a first operation on the first digital asset.
  • Optional also includes:
  • the authorization information of the owner and/or the second platform for the first digital asset is recorded and/or stored, including information about the first digital asset and/or user information and/or information about the first operation.
  • Optional also includes:
  • a fourth response is sent to the first platform or the first terminal, the fourth response being used to indicate the result of the first user's application for permission to perform a first operation on the first digital asset.
  • the second functional module determines whether the fourth request requires the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal, including:
  • the second functional module verifies the control mode of the first digital asset
  • the process proceeds to sending a fourth response to the first platform or the first terminal, and the fourth response is used to indicate that the first user's request for permission to perform the first operation on the first digital asset has been rejected.
  • the fourth request requires the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal;
  • the fourth request does not require the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal, then proceed to the step of sending a fourth response to the first platform or the first terminal, and the fourth response is used to indicate that the first user's application for permission to perform the first operation on the first digital asset has been approved and/or authorized.
  • the recording and/or storing of the authorization information of the owner and/or the second platform for the first digital asset specifically includes: generating a third token, storing it in the token list of the first digital asset, and associating the third token with the information of the first operation;
  • the fourth response includes the third token, which the first terminal adds to the first user's token list.
  • This application provides a method for controlling operation permissions of digital assets, including:
  • the second functional module receives a sixth request sent by the third platform and/or the third terminal and/or the first functional module, for setting or updating the control mode of the first digital asset;
  • the second functional module verifies whether the sixth request has obtained authorization from the owner of the first digital asset and/or the second platform and/or the second terminal. If the verification is successful, it sets and/or updates and/or stores the control mode of the first digital asset according to the sixth request, and sends a sixth response to the third platform and/or the third terminal to indicate whether the control mode of the first digital asset has been set or updated successfully.
  • Optional also includes:
  • the sixth request includes information and/or control mode of the first digital asset.
  • Optional also includes:
  • a sixth response is sent to the third platform and/or the first functional module of the third terminal, and the sixth response is used to indicate that the control mode setting or update of the first digital asset has failed.
  • This application provides a method for controlling operation permissions of digital assets, including:
  • the first functional module receives a seventh request sent by the third platform and/or the third terminal, which is used to set or update the control mode of the first digital asset.
  • the first functional module sends an eighth request to the second functional module to set or update the control mode of the first digital asset.
  • the first functional module receives an eighth response sent by the second functional module, which is used to indicate whether the control mode of the first digital asset has been set or updated successfully;
  • the first functional module sends a seventh response to the third platform and/or the third terminal to indicate whether the control mode of the first digital asset has been successfully set or updated.
  • Optional also includes:
  • the seventh request includes information about the first digital asset and its control mode.
  • This application provides a method for controlling operation permissions of digital assets, including:
  • the second functional module receives the first information sent by the first functional module, the first information including information about the first digital asset and/or information about the owner of the first digital asset and/or information about the second platform;
  • the second functional module sends a ninth request to the first functional module to request the owner of the first digital asset and/or the second platform and/or the second terminal to set the control mode of the first digital asset.
  • the second functional module receives the ninth response sent by the first functional module, which is used to indicate the control mode of the first digital asset;
  • the second functional module sets and/or stores the first digital asset control mode according to the ninth response.
  • the information of the first digital asset includes the digital asset identifier of the first digital asset; the owner information of the first digital asset includes the owner identifier; and the information of the second platform includes at least one of the platform IP address, platform identifier, and platform call interface.
  • the ninth response includes: information and/or control mode of the first digital asset.
  • Optional also includes:
  • the second functional module sends a fourth message to the first functional module, indicating the setting result of the control mode of the first digital asset.
  • Optional also includes:
  • the second functional module creates a token list for the first digital asset, generates a fourth token for the owner of the first digital asset, associates the fourth token with third operation information, and saves the fourth token in the token list of the first digital asset.
  • the fourth information also includes the fourth token.
  • This application provides a method for controlling operation permissions of digital assets, including:
  • the first functional module sends first information to the second functional module, the first information including information about the first digital asset and/or information about the owner of the first digital asset and/or information about the second platform;
  • the first functional module receives a ninth request sent by the second functional module, which is used to request the setting of the control mode of the first digital asset;
  • the first functional module sends a tenth request to the second platform and/or the second terminal to request the setting of the control mode of the first digital asset;
  • the first functional module receives a tenth response sent by the second platform and/or the second terminal, which is used to indicate the control mode of the first digital asset;
  • the first functional module sends a ninth response to the second functional module to indicate the control mode of the first digital asset.
  • the information of the first digital asset includes the digital asset identifier of the first digital asset; the owner information of the first digital asset includes the owner identifier; and the information of the second platform includes at least one of the platform IP address, platform identifier, and platform call interface.
  • the tenth response includes: information and/or control mode of the first digital asset.
  • Optional also includes:
  • the first functional module receives the fourth information sent by the second functional module, which is used to indicate the setting result of the control mode of the first digital asset;
  • the first functional module sends a fifth message to the second platform or the second terminal, the fifth message including the setting result of the control mode of the first digital asset.
  • the fourth information also includes a fourth token
  • the first functional module further includes the fourth token in the fifth information so that the second terminal can save the fourth token in the token list of the owner of the first digital asset.
  • This application provides a first functional module, including:
  • the first receiving module is configured to receive a first request sent by the first platform, which is used to request the first user to perform a first operation on the first digital asset.
  • the first sending module is configured to send a second request to the second functional module to verify whether the first user has permission to perform a first operation on the first digital asset.
  • the second receiving module is configured to receive a second response sent by the second functional module, which is used to indicate whether the first user has permission to perform a first operation on the first digital asset.
  • the second sending module is configured to send a first response to the first platform to indicate the result of the first operation on the first digital asset.
  • This application provides a second functional module, including:
  • the first receiving module is configured to receive a second request sent by the first functional module.
  • the second request is used to verify whether the first user has permission to perform a first operation on the first digital asset.
  • the verification module is configured to verify whether the first user has permission to perform the first operation on the first digital asset.
  • the first sending module is configured to send a second response to the first functional module, which is used to indicate whether the first user has permission to perform a first operation on the first digital asset.
  • This application provides a second functional module, including:
  • the first receiving module is configured to receive a fourth request sent by the first platform or the first terminal, which is used to request the first user's permission to perform a first operation on the first digital asset.
  • the determining module is configured to determine whether the fourth request requires the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal;
  • the first sending module is configured to send a fifth request to the second platform and/or the second terminal if the fourth request requires consent and/or authorization, for requesting the first user's permission to perform a first operation on the first digital asset.
  • This application provides a second functional module, including:
  • the first receiving module is configured to receive a sixth request sent by the third platform and/or the third terminal and/or the first functional module, for setting or updating the control mode of the first digital asset;
  • the first processing module is configured to verify whether the sixth request has obtained authorization from the owner of the first digital asset and/or the second platform and/or the second terminal. If the verification is successful, the module sets and/or updates and/or stores the control mode of the first digital asset according to the sixth request, and sends a sixth response to the third platform and/or the third terminal to indicate whether the control mode of the first digital asset has been successfully set or updated.
  • This application provides a first functional module, including:
  • the first receiving module is configured to receive a seventh request sent by a third platform and/or a third terminal, for setting or updating the control mode of the first digital asset;
  • the first sending module is configured to send an eighth request to the second functional module for setting or updating the control mode of the first digital asset.
  • the second receiving module is configured to receive the eighth response sent by the second functional module, which is used to indicate whether the control mode of the first digital asset has been set or updated successfully.
  • the second sending module is configured to send a seventh response to a third platform and/or a third terminal to indicate whether the control mode of the first digital asset has been successfully set or updated.
  • This application provides a second functional module, including:
  • the first receiving module is configured to receive first information sent by the first functional module, the first information including information of the first digital asset and/or owner information of the first digital asset and/or second platform information;
  • the first processing module is configured to set and/or store the first digital asset control mode according to the ninth response.
  • the first sending module is configured to send first information to the second functional module, the first information including information of the first digital asset and/or owner information of the first digital asset and/or second platform information;
  • the first receiving module is configured to receive the ninth request sent by the second functional module, which is used to request the setting of the control mode of the first digital asset;
  • the second sending module is configured to send a tenth request to the second platform and/or the second terminal to request the setting of the control mode of the first digital asset.
  • the second receiving module is configured to receive a tenth response sent by the second platform and/or the second terminal, which is used to indicate the control mode of the first digital asset;
  • This application provides a first functional module, including: a processor, a memory, and a program stored in the memory and executable on the processor.
  • the program When the program is executed by the processor, it implements the steps of the method performed by the first functional module as described above.
  • This application provides a second functional module, including: a processor, a memory, and a program stored in the memory and executable on the processor.
  • the program When the program is executed by the processor, it implements the steps of the method performed by the first functional module as described above.
  • This application provides a computer-readable storage medium storing a program that, when executed by a processor, implements the steps of the method described in any of the above embodiments.
  • the digital asset operation permission control method, module, and storage medium realize cross-platform management and control of digital asset operation permissions.
  • this application embodiment can provide a cross-platform digital asset collaboration and sharing solution for users of various metaverses, meeting the needs of people in the metaverse world to anonymously navigate various metaverse business platforms and achieve sharing and collaborative operation of the same digital asset.
  • FIG. 2 is a flowchart of a digital asset operation permission control method according to an embodiment of this application
  • FIG. 3 is another flowchart of the digital asset operation permission control method according to an embodiment of this application.
  • Figure 4 is an interactive example diagram of a digital asset operation permission control method according to an embodiment of this application.
  • FIG. 5 is another flowchart of the digital asset operation permission control method according to an embodiment of this application.
  • FIG. 7 is another flowchart of the digital asset operation permission control method according to an embodiment of this application.
  • FIG. 8 is another flowchart of the digital asset operation permission control method according to an embodiment of this application.
  • Figure 9 is another interactive example diagram of the digital asset operation permission control method according to an embodiment of this application.
  • FIG 11 is another flowchart of the digital asset operation permission control method according to an embodiment of this application.
  • Figure 12 is another flowchart of the digital asset operation permission control method according to an embodiment of this application.
  • Figure 14 is a schematic diagram of a structure of the first functional module provided in an embodiment of this application.
  • Figure 15 is a schematic diagram of a second functional module provided in an embodiment of this application.
  • Figure 17 is another structural schematic diagram of the second functional module provided in the embodiment of this application.
  • Figure 18 is a schematic diagram of another structure of the first functional module provided in the embodiment of this application.
  • Figure 19 is a schematic diagram of another structure of the second functional module provided in the embodiment of this application.
  • Figure 20 is another structural schematic diagram of the first functional module provided in the embodiment of this application.
  • Figure 21 is a schematic diagram of the structure of the first or second functional module of another embodiment of this application.
  • first and second are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first” and “second” are generally of the same class, without limiting the number of objects; for example, the first object can be one or more.
  • “or” in this application indicates at least one of the connected objects. For example, “A or B” covers three scenarios: Scenario 1: including A but not B; Scenario 2: including B but not A; Scenario 3: including both A and B. The character “/" generally indicates that the preceding and following objects are in an "or” relationship.
  • instruction in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction).
  • a direct instruction can be understood as one in which the sender explicitly informs the receiver of specific information, the operation to be performed, or the requested result, etc., in the instruction sent.
  • An indirect instruction can be understood as one in which the receiver determines the corresponding information based on the instruction sent by the sender, or makes a judgment and determines the operation to be performed or the requested result, etc., based on the judgment result.
  • LTE Long Term Evolution
  • LTE-A Long Term Evolution-Advanced
  • CDMA Code Division Multiple Access
  • TDMA Time Division Multiple Access
  • FDMA Frequency Division Multiple Access
  • OFDMA Orthogonal Frequency Division Multiple Access
  • SC-FDMA Single-carrier Frequency-Division Multiple Access
  • NR New Radio
  • 6G 6th Generation
  • This application provides a system that can manage cross-platform operation permissions for digital assets.
  • the system includes multiple platforms, a first functional module, a second functional module, and a terminal (the first terminal in Figure 1).
  • the multiple platforms may include a first platform, a second platform, a third platform, ..., an nth platform, and these platforms can be various business platforms, such as Metaverse business platforms 1 to n respectively.
  • one or more platforms may be the owner's virtual application layer server (Owner Virtual Application Layer Server, Consumer VAL Server, Owner VAL Server), the owner's platform, or the owner's business platform (such as the owner's Metaverse business platform); another or more platforms may be the user's virtual application layer server (Consumer VAL Server), the user's platform, or the user's business platform (such as the user's Metaverse business platform). Additionally, this document sometimes refers to the owner as the owner and the user as the user or consumer.
  • the first functional module can also be referred to as a digital asset storage management platform, a digital asset storage management functional module, an application-digital asset container management (A-DACM) function, an A-DACM functional module, an A-DACM platform, or an API provider area.
  • A-DACM application-digital asset container management
  • the second functional module can also be called a digital asset operation permission management platform, a digital asset operation permission control function module, a digital asset permission management (DAPM) function, a DAPM function module, or a common application interface framework (CAPIF) core function module.
  • a digital asset operation permission management platform e.g., a digital asset operation permission control function module
  • DAPM digital asset permission management
  • CAPIF common application interface framework
  • Terminals can include DAPM clients, personal computer (PC) terminals, mobile terminals, wearable devices, etc.
  • a terminal can include, but is not limited to, the following modules: a platform client (such as a metaverse business client), a permission management client, and a local storage module.
  • a platform client such as a metaverse business client
  • a permission management client such as a permission management client
  • a local storage module such as a local storage module.
  • the first terminal and the second terminal shown in Figure 1 are illustrated; the specific structure of the second terminal can be similar to that of the first terminal.
  • the second functional module This module is used for managing access permissions for digital assets. Specific functions include:
  • operation permission information includes digital asset identifier, authorized operations, and authorization time, etc.
  • Operations on digital assets include, but are not limited to, accessing, modifying, and downloading;
  • permission tokens are sometimes simply referred to as tokens.
  • This module is used to store digital assets and record basic information about the digital assets (such as the name of the digital asset).
  • Platform Initiating applications for uploading digital assets and information, setting permissions, requesting operation permissions, and performing operations on digital assets.
  • the permission management client enables the updating of operation permissions for digital assets and the application for new permissions.
  • Platform client (such as Metaverse business client): A client installed on the terminal for interaction with the user, enabling the setting of digital asset permissions, permission application, etc.
  • Local storage module A secure storage module within the terminal used to store the user's permission tokens for operating on their digital assets. It requires its own secure access control mechanism to ensure legitimate users can access the information.
  • Interface 1 The interface between the first functional module and the second functional module, used to transmit basic information of digital assets (such as digital asset number, digital asset name, owner, etc.), permission settings, permission query requests, and query result feedback.
  • Interface 2 The interface between the second functional module and the platform, used to transmit information such as the setting and updating of operation permissions for digital assets by all parties, and the application and acquisition of operation permissions for digital assets by users.
  • Interface 3 The interface between the first functional module and the platform, used to transmit digital asset registration information (such as digital asset number, digital asset name, owner, etc.), permission setting information, digital asset operation requests, etc.
  • digital asset registration information such as digital asset number, digital asset name, owner, etc.
  • permission setting information such as digital asset number, digital asset name, owner, etc.
  • digital asset operation requests etc.
  • Interface 4 The interface between the digital asset operation permission management platform/module and the permission management client, used to transmit information such as the setting and updating of operation permissions for digital assets by all parties, and the application and acquisition of operation permissions for digital assets by users.
  • permission tokens also referred to as tokens herein
  • control modes of digital assets involved in some embodiments of this application are described below:
  • Digital asset permission tokens are generated by the second functional module, based on information such as the digital asset identifier, the type of authorized operation, and the authorized operation time. Considering that the digital human identities across different platforms (such as various business platforms within the Metaverse world) may be inconsistent, making it difficult to distinguish the identity of the same user on different business platforms, tokens are issued for digital asset operation permissions, and operation control is achieved through token verification.
  • Each user has a list of permission tokens (also referred to as the token list in this article). Each permission token in the token list corresponds to a digital asset that the user can operate. In addition, related digital asset identifiers can also be stored.
  • Second functional module Store a list of permission tokens for each digital asset.
  • the list stores all permission tokens authorized for the digital asset and information about the associated operations (such as the type of authorized operation and/or the time of authorized operation). Therefore, the information stored in the second functional module may include digital asset identifier, permission token, type of authorized operation, time of authorized operation, etc.
  • the control model of digital assets refers to the way users restrict their operations when using digital assets. It can be divided into three models: strict control model (also known as the first control model), general control model (also known as the second control model), and lenient control model (also known as the third control model).
  • the general control model requires authorization from the owner for any operation on the digital asset; that is, some people are allowed to operate the digital asset, but others do not need authorization from the owner before operating it.
  • the lenient control model does not require authorization from the owner for any operation on the digital asset; that is, everyone has the right to operate the digital asset.
  • the strict control model prohibits any user other than the owner from operating the digital asset.
  • the first user is a user under a first platform (such as the First Metaverse Business Platform), and the first user accesses the first platform through a first terminal.
  • the second user is a user under a second platform (such as the Second Metaverse Business Platform), and the second user accesses the second platform through a second terminal.
  • the first digital asset is the digital asset of the second user, that is, the owner of the first digital asset is the second user, and the first digital asset is an asset of the second platform.
  • the first user is the user of the first digital asset.
  • the second user can send the request to the second platform or the second functional module through a second terminal.
  • the xth request and xth response are typically a pair, meaning the xth response is a response to the xth request.
  • x can be one, two, three, etc.
  • the method for controlling the operation permissions of digital assets can realize cross-platform operation permission control of digital assets.
  • the method described below will be explained from the perspective of different functional modules through different business processes.
  • Process 1 The first user initiates a request for the first operation on the first digital asset.
  • Figures 2 to 4 Some embodiments of this application provide a method for controlling the operation permissions of digital assets, implementing relevant permission management in the process of a first user initiating a request for a first operation on a first digital asset.
  • Figure 2 is a flowchart of the above-mentioned process 1 on the first functional module side
  • Figure 3 is a flowchart of the above-mentioned process 1 on the second functional module side
  • Figure 4 is an example diagram showing the interaction flow of the above-mentioned process 1 between various devices/modules, using the Metaverse business platform as an example.
  • a first user can initiate a request for a first operation on a first digital asset through a first platform.
  • the first platform sends a first request to a first functional module, and the first functional module receives the first request sent by the first platform.
  • the information or content included in the first request may include: the first user's first user information, the first digital asset's information, and the first operation's information.
  • the first user information may include the first user's user identifier and/or the first user's token list.
  • the first digital asset's information includes: the first digital asset's digital asset identifier.
  • the information regarding the operation on the digital asset (such as the first operation) may specifically include the operation type and/or the operation time.
  • the operation type includes one or more of access, update, change, and download.
  • the operation time may be the start and end time of the operation, the start time and duration of the operation, the operation cycle, and the operation time range within each cycle, etc. This embodiment does not specifically limit these aspects.
  • a user's token list includes tokens representing operation permissions for various digital assets obtained by the user, with each token corresponding to an operation permission for a digital asset.
  • the operation permission specifically includes the operation type and/or operation time.
  • Step 22 The first functional module sends a second request to the second functional module to verify whether the first user has permission to perform the first operation on the first digital asset.
  • Step 23 The first functional module receives a second response sent by the second functional module, which indicates whether the first user has permission to perform a first operation on the first digital asset.
  • the first functional module after receiving the first request, sends a second request to the second functional module to verify/determine/judge whether the first user has permission to perform the first operation on the first digital asset.
  • the second functional module verifies/determines/judges whether the first user has permission to perform the first operation on the first digital asset, and based on the verification/determination/judgment result, returns a second response to the first functional module, indicating whether the first user has permission to perform the first operation on the first digital asset.
  • Step 24 The first functional module sends a first response to the first platform to indicate the result of the first operation on the first digital asset.
  • the first functional module can allow or disallow the first user's first operation on the first digital asset based on the second response.
  • the digital assets of each platform can be pre-registered and stored in the first functional module.
  • the first functional module can perform the first operation on the first digital asset; if the second response indicates that the first user does not have permission to perform the first operation on the first digital asset, the first functional module can refuse the first operation. Then, the first functional module can also send the first response from step 24 to the first platform.
  • the first platform can send it to the first terminal (first user) to notify the first user (first terminal) of the result of the first operation on the first digital asset, which may specifically include whether the first operation is allowed to be executed and whether the first operation was successfully executed if allowed.
  • this embodiment of the application realizes the permission control of the first user's first operation on the first digital asset through the second functional module. Since the first platform to which the first user belongs and the second platform to which the first digital asset belongs can be different platforms, it is possible to realize the control of cross-platform operation permissions of digital assets.
  • the second functional module can verify whether the first user has permission to perform a first operation on the first digital asset in various ways. For example, by recording the operation authorizations obtained by the user for the digital asset, the recorded data can be used for verification.
  • a specific implementation method can be in the form of permission tokens.
  • the second functional module stores/saves a token list for each digital asset, wherein each token in the token list of a certain digital asset corresponds to an operation authorization for that digital asset and is associated with information about an operation, including the operation type and/or operation time.
  • Each user saves their own token list, and each token in a user's token list corresponds to an operation authorization for a digital asset.
  • the first user's token list as an example, in this embodiment, when the first user requests a first operation on the first digital asset, they can send a request to the first platform.
  • the request carries the first user's first user information, the information of the first digital asset, the information of the first operation, and the first user's token list.
  • the first request and the second request in steps 21-22 above may each include: a token list of the first user, wherein each token in the first user's token list corresponds to an operation authorization for a digital asset, thereby sending the first user's token list to the second functional module for comparison with the token list of the first digital asset stored in the second functional module.
  • the second functional module can compare the first user's token list with the first digital asset's token list to determine whether there are identical tokens. If identical tokens exist, it obtains information about the associated operations associated with those identical tokens and determines whether the first operation matches the associated operations to obtain a verification result. If the first operation belongs to a subset of the associated operations, it is determined that the first operation matches the associated operations; otherwise, it is determined that the first operation does not match the associated operations.
  • the information of the first operation includes the first operation type and the first operation time, and if the associated operation also includes the first operation type, and the corresponding second operation time covers the first operation time, then it is determined that the first operation belongs to a subset of the associated operations; otherwise, it is indeed determined that the first operation does not belong to a subset of the associated operations.
  • the information of the first operation only includes the first operation type, and the associated operation also includes the first operation type and does not limit the operation time corresponding to the first operation type, then it is determined that the first operation belongs to a subset of the associated operations; otherwise, it is indeed not a subset of the associated operations.
  • the information of the first operation only includes the first operation time, and the associated operation also only includes the second operation time, and the first operation time is a subset of the second operation time, then it is determined that the first operation belongs to the subset of the associated operation; otherwise, it is confirmed that the first operation does not belong to the subset of the associated operation.
  • the first user can request permission from the second functional module to perform a first operation on the first digital asset before step 21 described above. If authorization is granted, the second functional module will generate a token for the first digital asset (referred to as the first token for ease of description), store it in the token list of the first digital asset, and associate the first token with the first operation. The second functional module will also send the first token to the first user through the first platform. After receiving the first token, the first user stores it in their token list. Thus, in steps 21 and 22 described above, the first user's token list in both the first and second requests contains the first token. When the second functional module performs the above verification, it will detect that the first user's token list and the first digital asset's token list contain the same first token.
  • the second functional module performs the above verification, it will detect that the first user's token list and the first digital asset's token list contain the same first token.
  • the first user may not have applied for permission to perform the first operation on the first digital asset before step 21, or, although they applied, they were not authorized.
  • the second functional module upon receiving the second request in step 22, can also generate a new token for the first digital asset (referred to as the second token for ease of description) and store it in the token list of the first digital asset, associating it with the first operation, while allowing the first user to perform the first operation on the first digital asset.
  • the second functional module also carries the second token in the second response. If the second response includes the second token, the first functional module includes the second token in the first response described in step 24 sent to the first platform, so that the first terminal corresponding to the first user can add the second token to the first user's token list.
  • both the first token and the second token mentioned above are authorizations granted by the first user for the first operation on the first digital asset. Therefore, the first token and the second token are the same token.
  • Step 31 The second functional module receives a second request sent by the first functional module.
  • the second request is used to verify whether the first user has permission to perform the first operation on the first digital asset.
  • the second request may include: the first user's first user information and/or the first digital asset's information and/or the first operation's information.
  • the first user information includes a user identifier and/or the first user's token list;
  • the first digital asset information includes: the digital asset identifier of the first digital asset;
  • the first operation information includes the operation type and/or the operation time, wherein the operation type includes one or more of access, update, change, and download.
  • Step 32 The second functional module verifies whether the first user has permission to perform the first operation on the first digital asset.
  • Step 33 The second functional module sends a second response to the first functional module to indicate whether the first user has permission to perform a first operation on the first digital asset.
  • this embodiment of the application verifies the first user's permission to perform a first operation on the first digital asset using the second functional mode and provides a second response, thereby achieving cross-platform control over the operation permissions of digital assets.
  • the control modes of digital assets include a general control mode (also referred to as the first control mode), a lenient control mode (also referred to as the second control mode), and a strict control mode (the third control mode).
  • the general control mode requires authorization from the owner for any operation on the digital asset; the lenient control mode does not require authorization from the owner for any operation on the digital asset; and the strict control mode prohibits any user from performing any operation on the digital asset except for the owner.
  • step 32 the second functional module can verify the control mode of the first digital asset:
  • step 33 If the first digital asset is in a relaxed control mode, proceed to step 33, where the second response is specifically used to indicate that the first user has permission to perform a first operation on the first digital asset.
  • the second functional module further verifies the first user's permission to perform the first operation on the first digital asset:
  • step 33 the second response is used to indicate that the first user has permission to perform a first operation on the first digital asset.
  • the second functional module can also send a third request to the second platform and/or the second terminal to request permission from the first user to perform a first operation on the first digital asset. Then, the second functional module receives a third response from the second platform and/or the second terminal, indicating whether the first user is allowed to perform the first operation on the first digital asset.
  • the process proceeds to step 33, where the second response indicates that the first user has permission to perform the first operation on the first digital asset.
  • the process proceeds to step 33, and the second response indicates that the first user does not have permission to perform the first operation on the first digital asset.
  • the third request may include at least one of the following: first user information, first digital asset information, and first operation information.
  • the first user information includes a user identifier;
  • the first digital asset information includes a digital asset identifier of the first digital asset;
  • the first operation information includes operation type and/or operation time, wherein the operation type includes one or more of access, update, change, and download.
  • the second functional module verifies the first user's permission to perform a first operation on the first digital asset, which may include verifying the first user's permission to perform a first operation on the first digital asset through the authorization record stored in the second functional module.
  • the authorization record is a record of the user's operation authorizations for each digital asset.
  • the second functional module may also store a new authorization record based on the third response, the new authorization record including information about the first digital asset and information about the first operation.
  • the authorization record in this embodiment can be a token.
  • the second request includes the first user's token list, where each token in the first user's token list corresponds to an operation authorization for a digital asset.
  • the first user's token list can be matched with the first digital asset's token list, where each token in the first digital asset's token list corresponds to an operation authorization for the first digital asset and is associated with operation information. Therefore, if there is a matching first token between the first user's token list and the first digital asset's token list, the information of the second operation associated with the first token is obtained.
  • the permission verification is determined to be successful; otherwise, the permission verification is determined to be unsuccessful.
  • the method for determining whether a match is found can be referred to the description above, and will not be repeated here.
  • storing the new authorization record in the above process specifically includes: the second functional module generating a second token, storing it in the token list of the first digital asset, and associating the second token with the information of the first operation.
  • the second functional module can include the second token in the second response, so that the first terminal corresponding to the first user can add the second token to the first user's token list.
  • the first functional module is the digital asset storage management platform/functional module
  • the second functional module is the digital asset operation permission management platform.
  • the interaction process between the various devices/modules in the above process 1 includes:
  • Step 101 The user initiates a request to perform one or more operations on a specific digital asset through the Metaverse business platform, carrying digital asset information (such as digital asset identifier), user information (such as user identifier, permission token list), and specific operations (such as accessing, modifying/upgrading, downloading, etc. of the digital asset), and sends the request to the digital asset storage management platform/functional module.
  • digital asset information such as digital asset identifier
  • user information such as user identifier, permission token list
  • specific operations such as accessing, modifying/upgrading, downloading, etc. of the digital asset
  • Step 102 The digital asset storage management platform/functional module initiates a query request to the digital asset operation permission management platform/functional module to check whether the user has requested operation permissions for a specific digital asset.
  • This request carries the digital asset identifier and a list of user permission tokens.
  • Step 103 The digital asset operation permission management platform/functional module determines whether the digital asset has operation permission control. If it is controlled, it determines whether the operation request has been authorized. This determination includes the platform retrieving the list of permission tokens corresponding to the digital asset and verifying the permission token carried by the user. It also checks whether the operation permissions corresponding to the verified permission token include the permissions requested by the user and whether the permission token is within its validity period. Finally, it determines whether the operation can be executed. If it can, proceed to step 109; otherwise, proceed to the next step.
  • Step 104 The digital asset operation permission management platform/functional module finds the owner based on the digital asset identifier.
  • Step 105 The digital asset operation permission management platform/functional module sends a request to inquire about the intentions of all parties.
  • the request information includes digital asset information, user information, the requested operation, and the operation time.
  • Step 106 The business platform obtains user feedback from all parties and informs them whether the application for digital asset operation permissions is allowed.
  • Step 107 The business platform provides feedback on the user's intention to the digital asset operation permission management platform/functional module.
  • Step 108 After verifying the owner's permissions, the digital asset operation permission management platform/functional module records the owner's authorization information, including the digital asset identifier, authorized operation, and permission token.
  • the generated permission token is stored in the permission token list corresponding to the digital asset, along with the corresponding permission information and authorization time limit.
  • Step 109 The digital asset operation permission management platform/function module reports back to the digital asset storage management platform/function module whether the user has operation permission. If it is the first time to operate on the digital asset, a permission token is returned.
  • Step 110 The digital asset storage management platform/functional module performs an operation on the digital asset or rejects the operation based on the permission result. If it is the first time to operate on the digital asset, a permission token will be returned.
  • Step 111 The digital asset storage management platform/functional module sends the operation response to the user's Yuan Universe business management platform. If this is the first time operating on this digital asset, an access token is provided, which is the user's local storage access token.
  • Process 2 The process by which the first user applies for permission to perform the first operation on the first digital asset before initiating the first operation request.
  • Figures 5 and 6 Some embodiments of this application provide a method for controlling the operation permissions of digital assets, implementing relevant permission management in the request process of the first user applying for relevant authorization.
  • Figure 5 is a flowchart of the above-mentioned process 2 on the second functional module side
  • Figure 6 is an example diagram showing the interaction flow of the above-mentioned process 2 between various devices/modules, using the Metaverse business platform as an example.
  • Step 51 The second functional module receives a fourth request sent by the first platform or the first terminal to apply for the first user's permission to perform a first operation on the first digital asset.
  • the first user wants to obtain permission to perform a first operation on the first digital asset, he/she can directly send the fourth request to the second functional module, for example, through interface IF4; or he/she can send a relevant request to the first platform, which will then send the fourth request through interface IF4.
  • the fourth request may include the first user's first user information and/or the first digital asset's information and/or the first operation's information; the first user information includes a user identifier; the first digital asset's information includes the digital asset identifier of the first digital asset; the first operation's information includes the operation type and/or the operation time, and the operation type includes one or more of access, update, change, and download.
  • Step 52 the second functional module determines whether the fourth request requires the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal.
  • Step 53 If the fourth request requires consent and/or authorization, the second functional module sends a fifth request to the second platform and/or the second terminal to request the first user's permission to perform a first operation on the first digital asset.
  • this application embodiment realizes the process of users applying for relevant authorizations before operating digital assets, thereby realizing the control of cross-platform operation permissions for digital assets.
  • the second functional module may also receive a fifth response from the second platform and/or the second terminal, indicating whether the first user is permitted to perform a first operation on the first digital asset. For example, if the fifth response indicates permission for the first user to perform a first operation on the first digital asset, authorization information from the owner and/or the second platform for the first digital asset is recorded and/or stored.
  • This authorization information includes information about the first digital asset and/or user information and/or information about the first operation.
  • the user information may be user identity information, and the information about the first operation includes the operation type and/or operation time, etc.
  • the second functional module may also send a fourth response to the first platform or the first terminal, the fourth response being used to indicate the result of the first user's application for permission to perform a first operation on the first digital asset, such as whether authorization has been granted.
  • the second functional module determines the specific method by which it determines whether the fourth request requires the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal, which may include:
  • the step of sending a fourth response to the first platform or the first terminal is initiated, and the fourth response is used to indicate that the first user's request for permission to perform the first operation on the first digital asset is rejected.
  • the fourth request requires the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal;
  • the fourth request does not require the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal
  • a fourth response is sent to the first platform or the first terminal, and the fourth response is used to indicate that the first user's application for permission to perform the first operation on the first digital asset has been approved and/or authorized.
  • the authorization information can take the form of a token.
  • recording and/or storing the authorization information of the owner and/or the second platform for the first digital asset specifically includes: generating a third token, storing it in the token list of the first digital asset, and associating the third token with the information of the first operation.
  • the second functional module sends the fourth response, it includes the third token in the fourth response, so that the first terminal can add the third token to the first user's token list.
  • the third token is an authorization from the first user for the first operation on the first digital asset.
  • the first functional module is the digital asset storage management platform/functional module
  • the second functional module is the digital asset operation permission management platform.
  • the interaction process between the various devices/modules in the above process 2 includes:
  • Step 201 The user initiates a permission request to perform one or more operations on a specific digital asset through the Metaverse business platform/permission management client.
  • the request is sent to the digital asset operation permission control platform/functional module, and includes the digital asset identifier, operation method, and permission duration.
  • Step 202 The digital asset operation permission management platform/functional module determines whether operation of a specific asset requires authorization from the owner. If so, it locates the owner based on the digital asset identifier; if not, it skips to step 206.
  • Step 203 The digital asset operation permission management platform/functional module sends a request to inquire about the intentions of all parties.
  • Step 204 All parties respond to the inquiry through the business platform, informing whether the applicant is permitted to operate on the specific digital assets.
  • Step 205 The digital asset operation permission management platform/functional module records the authorization information of all parties involved, including the digital asset identifier, the operable type, the operation time, etc., generates a permission token for the user to operate the digital asset, and stores this permission token in the permission token list corresponding to the digital asset.
  • Step 206 The digital asset operation permission control platform/functional module sends a response to the operation permission application to the user's Yuan Universe business management platform, informing them of the application result and sending a permission token.
  • the user stores the received permission token locally.
  • Process 3 The process by which the owner of a digital asset sets or updates the control mode of the digital asset.
  • process 3 can be followed.
  • Figures 7 to 10 Some embodiments of this application provide a method for controlling the operation permissions of digital assets, enabling the owner of the digital asset to set or update the control mode of the digital asset.
  • Figure 7 is a flowchart of process 3 on the second functional module side
  • Figure 8 is a flowchart of process 3 on the first functional module side.
  • Figures 9 and 10 provide two interaction examples between various devices/modules of the process of setting or updating the control mode in process 3.
  • Step 71 The second functional module receives a sixth request sent by the third platform and/or the third terminal and/or the first functional module, for setting or updating the control mode of the first digital asset.
  • the sixth request includes information and/or control mode of the first digital asset.
  • the control mode may include three types, which can be found in the preceding text and will not be repeated here.
  • Step 72 The second functional module verifies whether the sixth request has obtained authorization from the owner of the first digital asset and/or the second platform and/or the second terminal. If the verification is successful, the module sets and/or updates and/or stores the control mode of the first digital asset according to the sixth request, and sends a sixth response to the third platform and/or the third terminal to indicate whether the control mode of the first digital asset has been set or updated successfully.
  • this application embodiment realizes the setting or updating of digital asset control mode.
  • the second functional module may send a sixth response to the third platform and/or the first functional module of the third terminal, and the sixth response is used to indicate that the control mode setting or update of the first digital asset has failed.
  • Step 81 The first functional module receives a seventh request sent by the third platform and/or the third terminal, for setting or updating the control mode of the first digital asset.
  • the seventh request includes information about the first digital asset and its control mode.
  • Step 82 The first functional module sends an eighth request to the second functional module to set or update the control mode of the first digital asset.
  • Step 83 The first functional module receives the eighth response sent by the second functional module, which indicates whether the control mode of the first digital asset has been successfully set or updated.
  • Step 84 The first functional module sends a seventh response to the third platform and/or the third terminal to indicate whether the control mode of the first digital asset has been successfully set or updated.
  • the second functional module is the digital asset operation permission management platform
  • the third platform is the owner's Metaverse business platform
  • the third terminal is the permission management client for the corresponding terminal of the owner.
  • Step 301 All parties initiate a digital asset control mode setting request or update request to the digital asset operation permission management platform/module through the Metaverse business platform.
  • the request includes the digital asset identifier, the control mode for digital asset operation, etc.
  • Step 302. The digital asset operation permission management platform/module verifies whether the owner has the permission to set or update permissions. If yes, skip to step 3; otherwise, skip to step 304.
  • Step 303 The digital asset operation permission management platform/module stores the latest settings or updates of the owner's digital asset control mode.
  • Step 304 The digital asset operation permission management platform/module returns the control mode setting or update result to the metaverse business platform.
  • the example shown in Figure 10 includes steps 401 to 406.
  • the permission management client in the platform Metal Business Platform
  • the terminal corresponding to all parties forwards the control mode setting or update request via the first functional module (digital asset storage management module/functional module).
  • Step 4 Control Mode Setup Procedure During Digital Asset Registration
  • Digital assets on each platform need to be registered to the first functional module.
  • the second functional module can set the control mode of the digital assets and generate relevant authorization records (such as permission tokens) for the owners of the digital assets.
  • Figures 11 to 14 Some embodiments of this application provide a method for controlling the operation permissions of digital assets, which implements the setting of a control mode during the digital asset registration process.
  • Figure 11 is a flowchart of process 4 on the second functional module side
  • Figure 12 is a flowchart of process 4 on the first functional module side.
  • Figure 13 provides two interaction examples of process 4 between various devices/modules.
  • Step 1101 The second functional module receives the first information sent by the first functional module.
  • the first information includes information about the first digital asset and/or information about the owner of the first digital asset and/or information about the second platform.
  • the information of the first digital asset includes the digital asset identifier of the first digital asset; the owner information of the first digital asset includes the owner identifier; and the information of the second platform includes at least one of the platform IP address, platform identifier, and platform call interface.
  • Step 1102 The second functional module sends a ninth request to the first functional module to request the owner of the first digital asset and/or the second platform and/or the second terminal to set the control mode of the first digital asset.
  • Step 1103 The second functional module receives the ninth response sent by the first functional module, which is used to indicate the control mode of the first digital asset.
  • the ninth response may include: information and/or control mode of the first digital asset.
  • Step 1104 The second functional module sets and/or stores the first digital asset control mode according to the ninth response.
  • this embodiment of the application realizes the setting of the control mode of the first digital asset by the second functional module during the process of registering the digital asset to the first functional module.
  • the second functional module may also send a fourth message to the first functional module to indicate the setting result of the control mode of the first digital asset.
  • the second functional module can create a token list for the first digital asset, generate a fourth token for the owner of the first digital asset, associate the fourth token with the third operation information, and store the fourth token in the token list of the first digital asset.
  • the fourth token can also be included in the fourth information when it is sent.
  • the first, second, and third tokens mentioned above are user tokens, while the fourth token in this process is an owner token, but these tokens can be the same or similar in format and function. Compared with the first, second, and third tokens mentioned above, the fourth token may have broader permissions.
  • Step 1203 The first functional module sends a tenth request to the second platform and/or the second terminal to request the setting of the control mode of the first digital asset.
  • Step 1204 The first functional module receives a tenth response sent by the second platform and/or the second terminal, which indicates the control mode of the first digital asset.
  • the tenth response is a response to the tenth request.
  • the tenth response may include: information and/or control mode of the first digital asset.
  • Step 1205 The first functional module sends a ninth response to the second functional module to indicate the control mode of the first digital asset.
  • the second functional module can set the control mode of digital assets during the digital asset registration process.
  • the first functional module may further receive fourth information sent by the second functional module, which indicates the setting result of the control mode of the first digital asset.
  • the first functional module may also send fifth information to the second platform or the second terminal, the fifth information including the setting result of the control mode of the first digital asset.
  • the fourth information may also include a fourth token
  • the first functional module also includes the fourth token in the fifth information, so that the second terminal can save the fourth token in the token list of the owner of the first digital asset.
  • the second functional module is the digital asset operation permission management platform
  • the first functional module is the digital asset storage management platform/functional module.
  • the above process 4 updates the control mode of digital assets and the interaction process between various devices/modules includes:
  • Step 501 All parties initiate a request for registration of digital asset information and uploading of digital asset files through the Metaverse business platform.
  • the request carries digital asset-related information (such as digital asset identifier, digital asset attributes, digital asset usage terms, etc.), owner-related information (such as owner identifier), and digital asset files.
  • Step 502. The digital asset storage management platform/module stores digital asset files, digital asset information, and owner information.
  • Step 503. The digital asset storage management platform/functional module forwards the digital asset registration information to the digital asset operation control platform/functional module, including digital asset information and owner information.
  • Step 504. The digital asset operation management platform/functional module stores the basic information of the digital assets and initiates a control mode setting request for digital asset operation to the digital asset storage management platform/module.
  • Step 510 The digital asset storage management platform/module returns a digital asset registration response to the metaverse business platform, carrying the asset registration result and the permission token set upon successful registration.
  • the embodiments of this application provide a system and method for cross-platform digital asset collaboration and sharing, realizing the control of operation permissions for digital assets across platforms.
  • the embodiments of this application can provide a solution for cross-platform digital asset collaboration and sharing for users of various metaverses, meeting the needs of people in the metaverse world to anonymously navigate various metaverse business platforms and achieve the sharing and collaborative operation of the same digital asset.
  • This embodiment of the application also provides a first functional module, including:
  • the second receiving module 143 is used to receive a second response sent by the second functional module, which is used to indicate whether the first user has permission to perform a first operation on the first digital asset.
  • the information of the first digital asset includes: the digital asset identifier of the first digital asset;
  • the first request and the second request further include: a token list of the first user, wherein each token in the token list of the first user corresponds to an operation authorization for a digital asset.
  • the second sending module is further configured to include the second token in the first response sent to the first platform if the second response includes the second token, so that the first terminal corresponding to the first user can add the second token to the first user's token list.
  • This embodiment of the application also provides a second functional module, including:
  • the first receiving module 151 is configured to receive a second request sent by the first functional module.
  • the second request is used to verify whether the first user has permission to perform a first operation on the first digital asset.
  • the verification module 152 is used to verify whether the first user has the permission to perform the first operation on the first digital asset.
  • the first user information includes a user identifier and/or a list of tokens for the first user
  • the information of the first digital asset includes: the digital asset identifier of the first digital asset;
  • the information for the first operation includes the operation type and/or the operation time, wherein the operation type includes one or more of access, update, change, and download.
  • the verification module is further configured as follows:
  • the second functional module When the first digital asset is in a relaxed control mode, the second functional module sends a second response to the first functional module, and the second response is used to indicate that the first user has permission to perform a first operation on the first digital asset.
  • the verification module is further configured as follows:
  • the first digital asset When the first digital asset is in strict control mode or general control mode, the first user's permission to perform the first operation on the first digital asset is verified. When the permission verification is successful, the second functional module sends a second response to the first functional module. The second response is used to indicate that the first user has permission to perform the first operation on the first digital asset.
  • the verification module is further configured as follows:
  • the authorization records stored in the second functional module are used to verify the first user's permission to perform the first operation on the first digital asset.
  • the verification module is further configured as follows:
  • the second functional module sends a third request to the second platform and/or the second terminal to request the first user's permission to perform a first operation on the first digital asset.
  • the second functional module receives a third response from the second platform and/or the second terminal, indicating whether the first user is allowed to perform a first operation on the first digital asset.
  • Optional also includes:
  • the first processing module is configured to, when the third response indicates that the first user is allowed to perform a first operation on the first digital asset, proceed to the step of the second functional module sending a second response to the first functional module, and the second response is used to indicate that the first user has permission to perform a first operation on the first digital asset.
  • the second processing module is configured to, when the third response indicates that the first user is not allowed to perform the first operation on the first digital asset, proceed to the step of the second functional module sending a second response to the first functional module, and the second response is used to indicate that the first user does not have permission to perform the first operation on the first digital asset.
  • the third request may include: first user information and/or first digital asset information and/or first operation information;
  • the first user information includes a user identifier
  • the information of the first digital asset includes: the digital asset identifier of the first digital asset;
  • the information for the first operation includes the operation type and/or the operation time, wherein the operation type includes one or more of access, update, change, and download.
  • the first processing module is further configured to, upon the third response indicating permission for the first user to perform a first operation on the first digital asset, store a new authorization record based on the third response, the new authorization record including information about the first digital asset and information about the first operation.
  • the second request includes the first user's token list, wherein each token in the first user's token list corresponds to an operation authorization for a digital asset;
  • the verification module is further configured to: match the token list of the first user with the token list of the first digital asset, wherein each token in the token list of the first digital asset corresponds to an operation authorization of the first digital asset and is associated with the information of an operation;
  • first user's token list and the first digital asset's token list contain the same first token, obtain the information of the second operation associated with the first token. If the information of the first operation matches the information of the second operation, determine that the permission verification is successful; otherwise, determine that the permission verification has failed.
  • the first processing module is further configured to: generate a second token, store it in the token list of the first digital asset, and associate the second token with the information of the first operation.
  • the second response includes the second token, which is then added to the first user's token list by the first terminal corresponding to the first user.
  • This embodiment of the application also provides a second functional module, including:
  • the first receiving module 161 is used to receive a fourth request sent by the first platform or the first terminal, for requesting the first user's permission to perform a first operation on the first digital asset.
  • the determining module 162 is used to determine whether the fourth request requires the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal;
  • the first sending module 163 is configured to send a fifth request to the second platform and/or the second terminal when the fourth request requires consent and/or authorization, for requesting the first user's permission to perform a first operation on the first digital asset.
  • the fourth request may include first user information and/or information about the first digital asset and/or information about the first operation;
  • the first user information includes a user identifier; the information of the first digital asset includes: the digital asset identifier of the first digital asset; the information of the first operation includes the operation type and/or the operation time, wherein the operation type includes one or more of access, update, change, and download.
  • Optional also includes:
  • the second receiving module is configured to receive a fifth response sent by the second platform and/or the second terminal, for indicating whether the first user is allowed to perform a first operation on the first digital asset.
  • Optional also includes:
  • the first processing module is configured to, upon the fifth response indicating that the first user is permitted to perform a first operation on the first digital asset, record and/or store authorization information of the owner and/or the second platform for the first digital asset, the authorization information including information of the first digital asset and/or user information and/or information of the first operation.
  • Optional also includes:
  • the second sending module is configured to send a fourth response to the first platform or the first terminal, the fourth response being used to indicate the result of the first user's application for permission to perform a first operation on the first digital asset.
  • the determining module is further configured to:
  • the process proceeds to the step of sending a fourth response to the first platform or the first terminal, and the fourth response is used to indicate that the first user's request for permission to perform the first operation on the first digital asset is rejected.
  • the fourth request requires the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal;
  • the fourth request does not require the consent and/or authorization of the owner of the first digital asset and/or the second platform and/or the second terminal, then proceed to the step of sending a fourth response to the first platform or the first terminal, and the fourth response is used to indicate that the first user's application for permission to perform the first operation on the first digital asset has been approved and/or authorized.
  • the first processing module is further configured to: generate a third token, store it in the token list of the first digital asset, and associate the third token with the information of the first operation;
  • the fourth response includes the third token, which the first terminal adds to the first user's token list.
  • This embodiment of the application also provides a second functional module, including:
  • the first receiving module 171 is used to receive a sixth request sent by the third platform and/or the third terminal and/or the first functional module, for setting or updating the control mode of the first digital asset.
  • the first processing module 172 is used to verify whether the sixth request has obtained authorization from the owner of the first digital asset and/or the second platform and/or the second terminal. If the verification is successful, it sets and/or updates and/or stores the control mode of the first digital asset according to the sixth request, and sends a sixth response to the third platform and/or the third terminal to indicate whether the control mode of the first digital asset has been set or updated successfully.
  • the sixth request may include information and/or control mode of the first digital asset.
  • Optional also includes:
  • the first sending module is configured to send a sixth response to the third platform and/or the first functional module of the third terminal in the event of verification failure, and the sixth response is used to indicate that the control mode setting or update of the first digital asset has failed.
  • This embodiment of the application also provides a first functional module, including:
  • the first receiving module 181 is used to receive a seventh request sent by a third platform and/or a third terminal, for setting or updating the control mode of the first digital asset.
  • the first sending module 182 is used to send an eighth request to the second functional module for setting or updating the control mode of the first digital asset.
  • the second receiving module 183 is used to receive the eighth response sent by the second functional module, which is used to indicate whether the control mode of the first digital asset has been set or updated successfully.
  • the second sending module 184 is used to send a seventh response to the third platform and/or the third terminal to indicate whether the control mode of the first digital asset has been successfully set or updated.
  • the seventh request may include information about the first digital asset and its control mode.
  • This embodiment of the application also provides a second functional module, including:
  • the first receiving module 191 is used to receive first information sent by the first functional module, the first information including information of the first digital asset and/or owner information of the first digital asset and/or second platform information;
  • the first sending module 192 is used to send a ninth request to the first functional module, and to request the owner of the first digital asset and/or the second platform and/or the second terminal to set the control mode of the first digital asset.
  • the second receiving module 193 is used to receive the ninth response sent by the first functional module, which is used to indicate the control mode of the first digital asset.
  • the first processing module 194 is configured to set and/or store the first digital asset control mode according to the ninth response.
  • the ninth response includes: information and/or control mode of the first digital asset.
  • Optional also includes:
  • the second sending module is configured to send fourth information to the first functional module to indicate the setting result of the control mode of the first digital asset.
  • the first processing module is configured to create a token list for the first digital asset, generate a fourth token for the owner of the first digital asset, associate the fourth token with third operation information, and store the fourth token in the token list of the first digital asset.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)

Abstract

本申请实施例公开了一种数字资产的操作权限的控制方法、模块及存储介质。本申请实施例实现了跨平台的数字资产的操作权限的管控。本申请实施例在应用于元宇宙场景下时,能够为各元宇宙用户提供了一个跨平台数字资产协作共享的方案,满足了元宇宙世界中人们匿名畅游各个元宇宙业务平台且能实现对同一个数字资产共享和协同操作的需求。

Description

数字资产的操作权限的控制方法、模块及存储介质
相关申请的交叉引用
本申请基于申请号为202410880745.5、申请日为2024年07月02日的中国专利申请提出,并要求该中国专利申请的优先权,该中国专利申请的全部内容在此引入本申请作为参考。
技术领域
本申请涉及业务权限控制技术领域,具体涉及一种数字资产的操作权限的控制方法、模块及存储介质。
背景技术
随着移动网络技术的发展和移动终端类型的丰富,人们将对移动网络中元宇宙的需求更加迫切,希望随时随地通过移动设备接入元宇宙世界。
未来在元宇宙世界的业务将十分丰富,对数字资产的使用也将出现多种需求。一方面需要提供网络现网服务支撑各种业务,满足对数字资产使用中的多种需求(云存储、共享等),另一方面需考虑对数字资产的访问控制,避免出现违规使用的情况。
移动通信网络支持元宇宙业务的规范正在建立过程中。目前相关技术提出设立一个数字资产存储管理的功能模块,用于存储用户在元宇宙世界的数字资产。但是所存储的数字资产如何在用户间和元宇宙间共享还没有提出合理的方法。
发明内容
本申请的至少一个实施例提供了一种数字资产的操作权限的控制方法、模块及存储介质,用于实现数字资产跨平台的操作权限控制的问题。
为了解决上述技术问题,本申请是这样实现的:
本申请实施例提供了一种数字资产的操作权限的控制方法,包括:
第一功能模块接收第一平台发送的第一请求,用于请求第一用户对第一数字资产的第一操作;
所述第一功能模块向第二功能模块发送第二请求,用于查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
所述第一功能模块接收第二功能模块发送的第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限;
所述第一功能模块向第一平台发送第一响应,用于指示所述第一数字资产的第一操作的结果。
可选的,所述第一请求包括:所述第一用户的第一用户信息、第一数字资产的信息、第一操作的信息。
可选的,所述第一用户信息包括用户标识和/或第一用户的令牌列表;
所述第一数字资产的信息包括:第一数字资产的数字资产标识;
所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
可选的,所述第一请求和所述第二请求还分别包括:所述第一用户的令牌列表,其中,所述第一用户的令牌列表中的每个令牌,对应于一个数字资产的操作授权。
可选的,在所述第二响应包括第二令牌的情况下,在向第一平台发送的所述第一响应中包括所述第二令牌,以供所述第一用户对应的第一终端将所述第二令牌增加到所述第一用户的令牌列表中。
本申请实施例提供了一种数字资产的操作权限的控制方法,包括:
第二功能模块接收第一功能模块发送的第二请求,所述第二请求用于查验第一用户是否具有第一数字资产的第一操作的权限;
所述第二功能模块查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
所述第二功能模块向所述第一功能模块发送第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限。
可选的,所述第二请求包括:所述第一用户的第一用户信息和/或第一数字资产的信息和/或第一操作的信息。
可选的,所述第一用户信息包括用户标识和/或第一用户的令牌列表;
所述第一数字资产的信息包括:第一数字资产的数字资产标识;
所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
可选的,所述第二功能模块查验所述第一用户是否具有所述第一数字资产的第一操作的权限,包括:
所述第二功能模块查验所述第一数字资产的控制模式;
在所述第一数字资产是宽松控制模式的情况下,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限。
可选的,所述第二功能模块查验所述第一用户是否具有所述第一数字资产的第一操作的权限,还包括:
在所述第一数字资产是严格控制模式或通用控制模式的情况下,验证所述第一用户对所述第一数字资产的第一操作的权限,并在权限验证成功时,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限。
可选的,验证所述第一用户对所述第一数字资产的第一操作的权限,包括:通过第二功能模块存储的授权记录,验证所述第一用户对所述第一数字资产的第一操作的权限。
可选的,所述第二功能模块查验所述第一用户是否具有所述第一数字资产的第一操作的权限,还包括:
在权限验证失败时,所述第二功能模块向第二平台和/或第二终端发送第三请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限;
所述第二功能模块接收所述第二平台和/或第二终端发送的第三响应,用于指示是否允许所述第一用户对所述第一数字资产的第一操作。
可选的,还包括:
在所述第三响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限;
在所述第三响应指示不允许所述第一用户对所述第一数字资产的第一操作的情况下,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户不具有所述第一数字资产的第一操作的权限。
可选的,所述第三请求包括:第一用户信息和/或第一数字资产的信息和/或第一操作的信息;
所述第一用户信息包括用户标识;
所述第一数字资产的信息包括:第一数字资产的数字资产标识;
所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
可选的,还包括:
在所述第三响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,根据所述第三响应,存储新的授权记录,所述新的授权记录包括所述第一数字资产的信息和所述第一操作的信息。
可选的,所述第二请求包括所述第一用户的令牌列表,其中,所述第一用户的令牌列表中的每个令牌,对应于一个数字资产的操作授权;
通过第二功能模块存储的授权记录,验证所述第一用户对所述第一数字资产的第一操作的权限,包括:将所述第一用户的令牌列表与所述第一数字资产的令牌列表进行匹配,其中,所述第一数字资产的令牌列表中的每个令牌,对应于所述第一数字资产的一个操作授权,且与一个操作的信息相关联;
在所述第一用户的令牌列表与所述第一数字资产的令牌列表之间存在相同的第一令牌的情况下,获取所述第一令牌所关联的第二操作的信息,并在所述第一操作的信息与第二操作的信息相匹配的情况下,确定权限验证成功,否则,确定权限验证失败。
可选的,所述存储新的授权记录,具体包括:生成第二令牌,存储在所述第一数字资产的令牌列表中,并将所述第二令牌与所述第一操作的信息相关联。
可选的,还包括:
所述第二响应包括所述第二令牌,以供所述第一用户对应的第一终端将所述第二令牌增加到所述第一用户的令牌列表中。
本申请实施例提供了一种数字资产的操作权限的控制方法,包括:
第二功能模块接收第一平台或第一终端发送的第四请求,用于申请第一用户对第一数字资产的第一操作的权限;
所述第二功能模块确定所述第四请求是否需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权;
所述第二功能模块在所述第四请求需要获得同意和/或授权的情况下,向第二平台和/或第二终端发送第五请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限。
可选的,所述第四请求包括第一用户信息和/或第一数字资产的信息和/或第一操作的信息;
所述第一用户信息包括用户标识;所述第一数字资产的信息包括:第一数字资产的数字资产标识;所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
可选的,还包括:
所述第二功能模块接收所述第二平台和/或第二终端发送的第五响应,用于指示是否允许所述第一用户对所述第一数字资产的第一操作。
可选的,还包括:
在所述第五响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,记录和/或存储所有方和/或第二平台对第一数字资产的授权信息,授权信息包括第一数字资产的信息和/或用户信息和/或第一操作的信息。
可选的,还包括:
向所述第一平台或第一终端发送第四响应,所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请结果。
可选的,所述第二功能模块确定所述第四请求是否需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权,包括:
所述第二功能模块查验所述第一数字资产的控制模式;
所述第一数字资产是严格控制模式的情况下,进入向所述第一平台或第一终端发送第四响应的步骤,且所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请被拒绝;
在所述第一数字资产是通用控制模式的情况下,确定所述第四请求需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权;
在所述第一数字资产是宽松控制模式的情况下,确定所述第四请求不需要所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权,进入向所述第一平台或第一终端发送第四响应的步骤,且所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请获得同意和/或授权。
可选的,所述记录和/或存储所有方和/或第二平台对第一数字资产的授权信息,具体包括:生成第三令牌,存储在所述第一数字资产的令牌列表中,并将所述第三令牌与所述第一操作的信息相关联;
所述第四响应包括所述第三令牌,以供所述第一终端将所述第三令牌增加到所述第一用户的令牌列表中。
本申请实施例提供了一种数字资产的操作权限的控制方法,包括:
第二功能模块接收第三平台和/或第三终端和/或第一功能模块发送的第六请求,用于设置或更新第一数字资产的控制模式;
所述第二功能模块验证所述第六请求是否获得第一数字资产的所有方和/或第二平台和/或第二终端的授权,在验证成功的情况下,根据所述第六请求设置和/或更新和/或存储所述第一数字资产的控制模式,并向所述第三平台和/或第三终端发送第六响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
可选的,还包括:
所述第六请求包括第一数字资产的信息和/或控制模式。
可选的,还包括:
在验证失败的情况下,向所述第三平台和/或第三终端第一功能模块发送第六响应,且所述第六响应用于指示所述第一数字资产的控制模式设置或更新失败。
本申请实施例提供了一种数字资产的操作权限的控制方法,包括:
第一功能模块接收第三平台和/或第三终端发送的第七请求,用于设置或更新第一数字资产的控制模式;
所述第一功能模块向第二功能模块发送第八请求,用于设置或更新所述第一数字资产的控制模式;
所述第一功能模块接收所述第二功能模块发送的第八响应,用于指示所述第一数字资产的控制模式是否设置或更新成功;
所述第一功能模块向第三平台和/或第三终端发送第七响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
可选的,还包括:
所述第七请求包括第一数字资产的信息、控制模式。
本申请实施例提供了一种数字资产的操作权限的控制方法,包括:
第二功能模块接收第一功能模块发送的第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
所述第二功能模块向所述第一功能模块发送第九请求,用于向所述第一数字资产的所有方和/或第二平台和/或第二终端请求设置所述第一数字资产的控制模式;
所述第二功能模块接收所述第一功能模块发送的第九响应,用于指示所述第一数字资产的控制模式;
所述第二功能模块根据所述第九响应,设置和/或存储所述第一数字资产控制模式。
可选的,所述第一数字资产的信息包括第一数字资产的数字资产标识;所述第一数字资产的所有方信息包括所有方标识;所述第二平台的信息包括平台IP地址、平台标识、平台调用接口中的至少一种。
可选的,所述第九响应包括:第一数字资产的信息和/或控制模式。
可选的,还包括:
所述第二功能模块向所述第一功能模块发送第四信息,用于指示所述第一数字资产的控制模式的设置结果。
可选的,还包括:
所述第二功能模块为所述第一数字资产创建令牌列表,生成所述第一数字资产的所有方的第四令牌,将所述第四令牌与第三操作信息相关联,并将所述第四令牌保存在所述第一数字资产的令牌列表;
其中,所述第四信息还包括所述第四令牌。
本申请实施例提供了一种数字资产的操作权限的控制方法,包括:
第一功能模块向第二功能模块发送第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
所述第一功能模块接收所述第二功能模块发送的第九请求,用于请求设置所述第一数字资产的控制模式;
所述第一功能模块向第二平台和/或第二终端发送第十请求,用于请求设置所述第一数字资产的控制模式;
所述第一功能模块接收所述第二平台和/或第二终端发送的第十响应,用于指示所述第一数字资产的控制模式;
所述第一功能模块向所述第二功能模块发送第九响应,用于指示所述第一数字资产的控制模式。
可选的,所述第一数字资产的信息包括第一数字资产的数字资产标识;所述第一数字资产的所有方信息包括所有方标识;所述第二平台的信息包括平台IP地址、平台标识、平台调用接口中的至少一种。
可选的,第十响应包括:第一数字资产的信息和/或控制模式。
可选的,还包括:
所述第一功能模块接收所述第二功能模块发送的第四信息,用于指示所述第一数字资产的控制模式的设置结果;
所述第一功能模块向所述第二平台或第二终端发送第五信息,所述五信息包括所述第一数字资产的控制模式的设置结果。
可选的,所述第四信息还包括第四令牌,所述第一功能模块还在第五信息中包括所述第四令牌,以供所述第二终端将所述第四令牌保存在所述第一数字资产的所有方的令牌列表中。
本申请实施例提供了一种第一功能模块,包括:
第一接收模块,配置为接收第一平台发送的第一请求,用于请求第一用户对第一数字资产的第一操作;
第一发送模块,配置为向第二功能模块发送第二请求,用于查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
第二接收模块,配置为接收第二功能模块发送的第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限;
第二发送模块,配置为向第一平台发送第一响应,用于指示所述第一数字资产的第一操作的结果。
本申请实施例提供了一种第二功能模块,包括:
第一接收模块,配置为接收第一功能模块发送的第二请求,所述第二请求用于查验第一用户是否具有第一数字资产的第一操作的权限;
查验模块,配置为查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
第一发送模块,配置为向所述第一功能模块发送第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限。
本申请实施例提供了一种第二功能模块,包括:
第一接收模块,配置为接收第一平台或第一终端发送的第四请求,用于申请第一用户对第一数字资产的第一操作的权限;
确定模块,配置为确定所述第四请求是否需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权;
第一发送模块,配置为在所述第四请求需要获得同意和/或授权的情况下,向第二平台和/或第二终端发送第五请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限。
本申请实施例提供了一种第二功能模块,包括:
第一接收模块,配置为接收第三平台和/或第三终端和/或第一功能模块发送的第六请求,用于设置或更新第一数字资产的控制模式;
第一处理模块,配置为验证所述第六请求是否获得第一数字资产的所有方和/或第二平台和/或第二终端的授权,在验证成功的情况下,根据所述第六请求设置和/或更新和/或存储所述第一数字资产的控制模式,并向所述第三平台和/或第三终端发送第六响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
本申请实施例提供了一种第一功能模块,包括:
第一接收模块,配置为接收第三平台和/或第三终端发送的第七请求,用于设置或更新第一数字资产的控制模式;
第一发送模块,配置为向第二功能模块发送第八请求,用于设置或更新所述第一数字资产的控制模式;
第二接收模块,配置为接收所述第二功能模块发送的第八响应,用于指示所述第一数字资产的控制模式是否设置或更新成功;
第二发送模块,配置为向第三平台和/或第三终端发送第七响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
本申请实施例提供了一种第二功能模块,包括:
第一接收模块,配置为接收第一功能模块发送的第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
第一发送模块,配置为向所述第一功能模块发送第九请求,用于向所述第一数字资产的所有方和/或第二平台和/或第二终端请求设置所述第一数字资产的控制模式;
第二接收模块,配置为接收所述第一功能模块发送的第九响应,用于指示所述第一数字资产的控制模式;
第一处理模块,配置为根据所述第九响应,设置和/或存储所述第一数字资产控制模式。
本申请实施例提供了一种第一功能模块,包括:
第一发送模块,配置为向第二功能模块发送第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
第一接收模块,配置为接收所述第二功能模块发送的第九请求,用于请求设置所述第一数字资产的控制模式;
第二发送模块,配置为向第二平台和/或第二终端发送第十请求,用于请求设置所述第一数字资产的控制模式;
第二接收模块,配置为接收所述第二平台和/或第二终端发送的第十响应,用于指示所述第一数字资产的控制模式;
第三发送模块,配置为向所述第二功能模块发送第九响应,用于指示所述第一数字资产的控制模式。
本申请实施例提供了一种第一功能模块,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,所述程序被所述处理器执行时实现如以上由第一功能模块执行的方法的步骤。
本申请实施例提供了一种第二功能模块,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,所述程序被所述处理器执行时实现如以上由第人功能模块执行的方法的步骤。
本申请实施例提供了一种计算机可读存储介质,所述计算机可读存储介质上存储有程序,所述程序被处理器执行时,实现如以上任一项所述的方法的步骤。
本申请实施例提供了一种计算机程序产品,包括计算机指令,所述计算机指令被处理器执行时实现如以上任一项所述的方法的步骤。
与相关技术相比,本申请实施例提供的数字资产的操作权限的控制方法、模块及存储介质,实现了跨平台的数字资产的操作权限的管控。本申请实施例在应用于元宇宙场景下时,能够为各元宇宙用户提供了一个跨平台数字资产协作共享的方案,满足了元宇宙世界中人们匿名畅游各个元宇宙业务平台且能实现对同一个数字资产共享和协同操作的需求。
附图说明
通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本申请的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1为本申请实施例的对数字资产跨平台操作权限进行管控的系统示意图;
图2为本申请实施例的数字资产操作权限的控制方法的一种流程图;
图3为本申请实施例的数字资产操作权限的控制方法的另一种流程图;
图4为本申请实施例的数字资产操作权限的控制方法的一种交互示例图;
图5为本申请实施例的数字资产操作权限的控制方法的另一种流程图;
图6为本申请实施例的数字资产操作权限的控制方法的另一交互示例图;
图7为本申请实施例的数字资产操作权限的控制方法的另一种流程图;
图8为本申请实施例的数字资产操作权限的控制方法的另一种流程图;
图9为本申请实施例的数字资产操作权限的控制方法的另一交互示例图;
图10为本申请实施例的数字资产操作权限的控制方法的另一交互示例图;
图11为本申请实施例的数字资产操作权限的控制方法的另一种流程图;
图12为本申请实施例的数字资产操作权限的控制方法的另一种流程图;
图13为本申请实施例的数字资产操作权限的控制方法的另一交互示例图;
图14为本申请实施例提供的第一功能模块的一种结构示意图;
图15为本申请实施例提供的第二功能模块的一种结构示意图;
图16为本申请实施例提供的第二功能模块的另一种结构示意图;
图17为本申请实施例提供的第二功能模块的另一种结构示意图;
图18为本申请实施例提供的第一功能模块的另一种结构示意图;
图19为本申请实施例提供的第二功能模块的另一种结构示意图;
图20为本申请实施例提供的第一功能模块的另一种结构示意图;
图21为本申请另一实施例的第一功能模块或第二功能模块的结构示意图。
具体实施方式
本申请的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,本申请中的“或”表示所连接对象的至少其中之一。例如“A或B”涵盖三种方案,即,方案一:包括A且不包括B;方案二:包括B且不包括A;方案三:既包括A又包括B。字符“/”一般表示前后关联对象是一种“或”的关系。
本申请的术语“指示”既可以是一个直接的指示(或者说显式的指示),也可以是一个间接的指示(或者说隐含的指示)。其中,直接的指示可以理解为,发送方在发送的指示中明确告知了接收方具体的信息、需要执行的操作或请求结果等内容;间接的指示可以理解为,接收方根据发送方发送的指示确定对应的信息,或者进行判断并根据判断结果确定需要执行的操作或请求结果等。
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency-Division Multiple Access,SC-FDMA)或其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统以外的系统,如第6代(6th Generation,6G)通信系统。
目前,基于移动通信网络架构,相关技术并未提供在元宇宙中对数字资产跨平台使用的控制方案。虽然非元宇宙世界中也存在数字资产在个人之间共享和协作操作,但是上述操作都是基于同一个平台提供的服务。未来元宇宙世界可能是一个平行于现实世界的数字世界,元宇宙业务平台之间将会有大量互联互通应用场景,因此,需要有一种高效可行的数字资产共享互通的控制方案。
请参照图1,本申请实施例提供了一种能够对数字资产跨平台操作权限进行管控的系统,该系统包括多个平台、第一功能模块、第二功能模块和终端(如图1中的第一终端)。
所述多个平台可以包括第一平台、第二平台、第三平台、…、第n平台,所述平台可以是各种业务平台,例如分别为元宇宙业务平台1~n。针对某一个数字资产而言,一个或一些平台可以是该数字资产的所有方的虚拟化应用程序服务器(Owner Virtual Application Layer Server,Consumer VAL Server,Owner VAL Server)、所有方的平台、所有方的业务平台(如所有方的元宇宙业务平台);另一个或另一些平台可以是使用方的虚拟化应用程序服务器(Consumer VAL Server)、使用方的平台、使用方的业务平台(如使用方的元宇宙业务平台)。另外,本文有时也将所有方称作所有者,将使用方称作使用者或消费者。
所述第一功能模块也可以称作数字资产存储管理平台、数字资产存储管理功能模块、数字资产容器管理应用(Application-Digital Asset Container Management,A-DACM)功能、A-DACM功能模块、A-DACM平台或API提供方区域。
所述第二功能模块也可以称作数字资产操作权限管理平台或数字资产操作权限管控功能模块、数字资产权限管理(Digital Asset Permission Management,DAPM)功能、DAPM功能模块或通用的应用程序接口框架(Common API Framework,CAPIF)核心功能模块。
终端包括可以是DAPM客户端(DAPM client)、个人电脑(Personal Computer,PC)终端、手机终端、可穿戴设备等。具体的,如图1所示,终端可以包括但不限于以下模块:平台客户端(如元宇宙业务客户端)、权限管理客户端和本地存储模块。图1中示出的第一终端和第二终端,第二终端的具体结构可以与第一终端相类似。
下面对相关模块/平台的功能以及相关接口进行说明。
第二功能模块:该模块用于对数字资产操作权限的管理。具体功能包括:
(1)数字资产所有方信息存储及授权询问;
(2)数字资产的操作权限信息的生成、更新、存储、删除、查询;其中操作权限信息包括数字资产标识、授权的操作及授权时间等。对数字资产的操作包括但不限于访问、更改、下载等;
(3)权限令牌生成,本申请实施例中,有时候也将权限令牌简称为令牌;
(4)权限验证。
第一功能模块:该模块用于存储数字资产,及记录数字资产的基础信息(例如数字资产的名称)。
平台:发起对数字资产及信息上传、权限设置申请、发起操作权限申请、对数字资产的操作等。
权限管理客户端:通过权限管理客户端,实现对数字资产的操作权限的更新和新权限的申请。
平台客户端(如元宇宙业务客户端):安装于终端的客户端,用于与用户的交互,实现对数字资产权限设置、权限申请等。
本地存储模块:终端内一个安全存储模块,用于存储用户对名下可操作的数字资产的权限令牌。其自身需要安全访问控制机制,保障合法用户对信息的调用。
接口1(IF1):第一功能模块与第二功能模块之间接口,用于传输数字资产基础信息(例如数字资产编号、数字资产名称、所有者等),权限设置,权限查询请求和查询结果反馈。
接口2(IF2):第二功能模块与平台之间的接口,用于传输所有方对数字资产的操作权限设置和更新等信息,使用方对数字资产操作权限申请和获取权限信息。
接口3(IF3):第一功能模块与平台之间接口,用于传输数字资产注册信息(例如数字资产编号、数字资产名称、所有者等),权限设定信息,数字资产操作请求等。
接口4(IF4):数字资产操作权限管理平台/模块与权限管理客户端之间接口,用于传输所有方对数字资产的操作权限设置和更新等信息,使用方对数字资产操作权限申请和获取权限信息。
另外,对本申请一些实施例中涉及的数字资产的权限令牌(本文也简称为令牌)以及控制模式说明如下:
数字资产权限令牌由第二功能模块生成,可以根据数字资产标识、授权的操作类型、授权的操作时间等信息生成。考虑到各个平台(如元宇宙世界各业务平台)的数字人身份可能不统一,难以辨别同一个用户在不同业务平台上的身份,因此针对数字资产的操作权限发放令牌,通过验证令牌进行操作管控。
令牌的存储方式:
(1)用户侧存储:每个用户有一个权限令牌列表(本文也简称为令牌列表),令牌列表内的每一个权限令牌对应用户可操作的一个数字资产,另外还可以存储相关的数字资产标识。
(2)第二功能模块:针对每一个数字资产存储一个权限令牌列表,列表内存储该数字资产授权的所有权限令牌以及关联的操作的信息(如授权的操作类型和/或授权的操作时间),因此第二功能模块存储的信息可以包括数字资产标识、权限令牌、授权的操作类型、授权的操作时间等。
数字资产的控制模式是数字资产被使用者使用时,限制使用者操作的方式。可分为三种模式,分别为严格控制模式(也可以称作第一控制模式)、通用控制模式(也可以称作第二控制模式)、宽松控制(也可以称作第三控制模式)。其中,所述通用控制模式是指对所述数字资产的任何操作都需要得到所有方的授权,即允许部分人操作数字资产,但他人对数字资产操作前是否需要获得所有方授权;宽松控制模式是指对所述数字资产的任何操作都不需要得到所有方的授权,即开放给所有人对数字资产的操作权项;严格控制模式是除所有方外,任何使用者对所述数字资产的任何操作都被拒绝。
在下文的各个实施例中,假设第一用户为第一平台(如第一元宇宙业务平台)下的用户,第一用户通过第一终端接入第一平台。第二用户为第二平台(如第二元宇宙业务平台)下的用户,第二用户通过第二终端接入第二平台。第一数字资产为第二用户的数字资产,即,第一数字资产的所有方为所述第二用户,第一数字资产为第二平台的资产。第一用户为所述第一数字资产的使用方。所述第一终端包括但不限于DAPM client、DAPM客户端、PC端、手机终端、可穿戴设备等功能模块或装置;类似的,第二终端包括但不限于DAPM client、DAPM客户端、PC端、手机终端、可穿戴设备等功能模块或装置。第一用户向第一平台或第二功能模块发送请求、响应或信息,可以通过其所登录/关联/对应的终端进行发送,例如,第一用户通过第一终端,向第一平台或第二功能模块进行发送。类似的,第二用户向第二平台或第二功能模块发送请求、响应或信息,可以通过其所登录/关联/对应的终端进行发送,例如,第二用户通过第二终端,向第二平台或第二功能模块进行发送。另外,本申请实施例中,第x请求与第x响应通常是一对请求和响应,即,第x响应是针对第x请求的响应。x可以是一、二、三……等。
本申请实施例提供的数字资产的操作权限的控制方法,能够实现数字资产跨平台的操作权限控制。下面通过不同的业务流程,分别从不同功能模块侧对本申请的以上方法进行说明。
流程1:第一用户发起对第一数字资产的第一操作的请求
请参照图2~图4,本申请一些实施例提供的数字资产的操作权限的控制方法,在第一用户发起对第一数字资产的第一操作的请求流程中实现相关权限管控。其中,图2是上述流程1在第一功能模块侧的流程图,图3是上述流程1在第二功能模块侧的流程图,图4是以元宇宙业务平台为例,提供上述流程1在各个设备/模块间的交互流程的示例图。
如图2所示,上述流程1在应用于第一功能模块侧时,包括以下步骤:
步骤21,第一功能模块接收第一平台发送的第一请求,用于请求第一用户对第一数字资产的第一操作。
这里,第一用户可以通过第一平台发起对第一数字资产的第一操作的请求,此时,第一平台向第一功能模块发送第一请求,所述第一功能模块接收第一平台发送的所述第一请求。所述第一请求包含的信息或内容可以包括:所述第一用户的第一用户信息、第一数字资产的信息、第一操作的信息。具体的,所述第一用户信息可以包括所述第一用户的用户标识和/或所述第一用户的令牌列表。所述第一数字资产的信息包括:第一数字资产的数字资产标识。其中,对数字资产的操作(如所述第一操作)的信息,具体可以包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。操作时间可以是操作的起始时间和截止时间,也可以是操作的起始时间和持续时长,还可以是操作周期以及每个周期内的操作时间范围等等,本申请实施例对此不做具体限定。
另外,本申请实施例中,某个用户的令牌列表包括该用户获得的各个数字资产的操作权限的令牌,每个令牌对应于一个数字资产的一种操作权限。所述操作权限具体包括操作类型和/或操作时间。
步骤22,所述第一功能模块向第二功能模块发送第二请求,用于查验所述第一用户是否具有所述第一数字资产的第一操作的权限。
步骤23,所述第一功能模块接收第二功能模块发送的第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限。
上述步骤22~23中,第一功能模块在接收到第一请求后,向第二功能模块发送第二请求,用于查验/确定/判断所述第一用户是否具有所述第一数字资产的第一操作的权限。第二功能模块收到第二请求后,查验/确定/判断所述第一用户是否具有所述第一数字资产的第一操作的权限,并根据查验/确定/判断的结果,向所述第一功能模块返回第二响应,用于表示所述第一用户是否具有所述第一数字资产的第一操作的权限。
步骤24,所述第一功能模块向第一平台发送第一响应,用于指示所述第一数字资产的第一操作的结果。
这里,所述第一功能模块在接收到第二响应后,可以根据所述第二响应允许执行或不允许所述第一用户对所述第一数字资产的所述第一操作。本申请实施例中,各个平台的数字资产可以预先注册并存储在所述第一功能模块中。这样,在所述第二响应表示所述第一用户具有所述第一数字资产的第一操作的权限的情况下,所述第一功能模块可以对所述第一数字资产执行所述第一操作;而在所述第二响应表示所述第一用户不具有所述第一数字资产的第一操作的权限的情况下,所述第一功能模块可以拒绝所述第一操作。然后,所述第一功能模块还可以向所述第一平台发送步骤24中的第一响应,第一平台收到后可以发送给所述第一终端(第一用户),以通知所述第一用户(第一终端)所述第一数字资产的第一操作的结果,具体可以包括所述第一操作是否允许执行以及在允许执行时所述第一操作是否成功执行等信息。
通过以上步骤,本申请实施例通过第二功能模块,实现了对第一用户针对第一数字资产的第一操作的权限管控,由于第一用户所属的第一平台和第一数字资产所属的第二平台可以是不同的平台,从而能够实现数字资产跨平台操作权限的管控。
需要说明的是,本申请实施例中,所述第二功能模块可以有多种方式,查验所述第一用户是否具有所述第一数字资产的第一操作的权限。例如,通过记录用户获得的数字资产的操作授权,从而可以利用记录数据来进行查验。一种具体的实现手段可以是权限令牌的形式。例如,第二功能模块存储/保存各个数字资产的令牌列表,其中,某个数字资产的令牌列表中的每个令牌,对应于该数字资产的一个操作授权,且与一个操作的信息相关联,所述操作的信息包括操作类型和/或操作时间。每个用户分别保存本用户的令牌列表,一个用户的令牌列表中的每个令牌,对应于一个数字资产的操作授权。以第一用户的令牌列表为例,在本实施例中,第一用户请求对第一数字资产的第一操作时,可以向第一平台发送请求,该请求携带的内容除了所述第一用户的第一用户信息、第一数字资产的信息、第一操作的信息之外,还可以携带所述第一用户的令牌列表。类似的,上述步骤21~22中的所述第一请求和所述第二请求还可以分别包括:所述第一用户的令牌列表,其中,所述第一用户的令牌列表中的每个令牌,对应于一个数字资产的操作授权,从而将所述第一用户的令牌列表发送给第二功能模块,以与第二功能模块保存的第一数字资产的令牌列表进行比对。这样,第二功能模块可以通过对第一用户的令牌列表与第一数字资产的令牌列表进行比对,判断两者之间是否存在相同的令牌,在存在相同令牌时,获取该相同令牌关联的关联操作的信息,并判断所述第一操作是否与所述关联操作相匹配,以获得查验结果。在所述第一操作属于所述关联操作的子集的情况下,确定所述第一操作与所述关联操作相匹配,否则,确定所述第一操作与所述关联操作不匹配。
例如,在所述第一操作的信息包括第一操作类型和第一操作时间的情况下,若所述关联操作也包括所述第一操作类型,且对应的第二操作时间覆盖了所述第一操作时间,此时,确定所述第一操作属于所述关联操作的子集,否则,确实所述第一操作不属于所述关联操作的子集。
又例如,在所述第一操作的信息仅包括第一操作类型的情况下,若所述关联操作也包括所述第一操作类型,且未限制所述第一操作类型对应的操作时间,此时,确定所述第一操作属于所述关联操作的子集,否则,确实所述第一操作不属于所述关联操作的子集。
再例如,在所述第一操作的信息仅包括第一操作时间的情况下,若所述关联操作也仅包括第二操作时间,且所述第一操作时间是所述第二操作时间的子集,此时,确定所述第一操作属于所述关联操作的子集,否则,确实所述第一操作不属于所述关联操作的子集。
在本申请的一些实施例中,第一用户可以在上述步骤21之前,向第二功能模块申请对所述第一数字资产的第一操作的权限。如果获得授权,此时,第二功能模块会为第一数字资产生成一个令牌(为便于描述,称之为第一令牌),并保存在所述第一数字资产的令牌列表中,并将第一令牌与所述第一操作相关联。所述第二功能模块还会通过第一平台向第一用户发送所述第一令牌,第一用户接收到第一令牌后,保存在第一用户的令牌列表中。这样,在上述步骤21和步骤22中,所述第一请求和第二请求中的第一用户的令牌列表中包含有所述第一令牌。在第二功能模块进行上述查验时,将查验出所述第一用户的令牌列表与第一数字资产的令牌列表中存在相同的第一令牌。
在本申请的另一些实施例中,第一用户可能在步骤21之前并未申请过对所述第一数字资产的第一操作的权限,或者,虽然申请过但未获得授权。这样,上述第二功能模块还可以在接收到上述步骤22中的第二请求后,在允许所述第一用户对所述第一数字资产的第一操作的情况下,生成第一数字资产的一个新令牌(为了便于描述,称之为第二令牌),保存在所述第一数字资产的令牌列表中,并与所述第一操作相关联。另外,第二功能模块还在第二响应中携带所述第二令牌。在所述第二响应包括第二令牌的情况下,第一功能模块在向第一平台发送的步骤24中所述的第一响应中包括所述第二令牌,以供所述第一用户对应的第一终端将所述第二令牌增加到所述第一用户的令牌列表中。
从以上描述可以看出,上文的第一令牌和第二令牌均是第一用户对第一数字资产的第一操作的授权,由此可见,第一令牌和第二令牌是相同的令牌。
如图3所示,上述流程1在应用于第二功能模块侧时,包括以下步骤:
步骤31,第二功能模块接收第一功能模块发送的第二请求,所述第二请求用于查验所述第一用户是否具有所述第一数字资产的第一操作的权限。
这里,所述第二请求可以包括:所述第一用户的第一用户信息和/或第一数字资产的信息和/或第一操作的信息。所述第一用户信息包括用户标识和/或第一用户的令牌列表;所述第一数字资产的信息包括:第一数字资产的数字资产标识;所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
步骤32,所述第二功能模块查验所述第一用户是否具有所述第一数字资产的第一操作的权限。
步骤33,所述第二功能模块向所述第一功能模块发送第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限。
通过以上步骤,本申请实施例由第二功能模式对第一用户对第一数字资产的第一操作的权限进行查验并反馈第二响应,从而实现了数字资产跨平台操作权限的管控。
本申请实施例中,数字资产的控制模式包括通用控制模式(也可以分别称为第一控制模式)、宽松控制模式(也可以分别称为第二控制模式)、严格控制模式(第三控制模式)。其中,所述通用控制模式是指对所述数字资产的任何操作都需要得到所有方的授权;宽松控制模式是指对所述数字资产的任何操作都不需要得到所有方的授权;严格控制模式是除所有方外,任何使用者对所述数字资产的任何操作都被拒绝。
在步骤32中,所述第二功能模块可以查验所述第一数字资产的控制模式:
(1)在所述第一数字资产是宽松控制模式的情况下,进入步骤33,此时所述第二响应具体用于指示所述第一用户具有所述第一数字资产的第一操作的权限。
(2)在所述第一数字资产是严格控制模式或通用控制模式的情况下,所述第二功能模块进一步验证所述第一用户对所述第一数字资产的第一操作的权限:
如果权限验证成功,则进入步骤33,此时所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限;
如果权限验证失败,所述第二功能模块还可以向第二平台和/或第二终端发送第三请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限;然后,所述第二功能模块接收所述第二平台和/或第二终端发送的第三响应,用于指示是否允许所述第一用户对所述第一数字资产的第一操作。这样,在所述第三响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,进入步骤33,此时所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限;而在所述第三响应指示不允许所述第一用户对所述第一数字资产的第一操作的情况下,进入步骤33,且所述第二响应用于指示所述第一用户不具有所述第一数字资产的第一操作的权限。
这里,所述第三请求可以包括以下至少一项:第一用户信息、第一数字资产的信息、第一操作的信息。所述第一用户信息包括用户标识;所述第一数字资产的信息包括:第一数字资产的数字资产标识;所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
具体的,所述第二功能模块验证所述第一用户对所述第一数字资产的第一操作的权限,具体可以包括:通过第二功能模块存储的授权记录,验证所述第一用户对所述第一数字资产的第一操作的权限。所述授权记录是各个数字资产对用户的操作授权的记录。
另外,在所述第三响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,所述第二功能模块还可以根据所述第三响应,存储新的授权记录,所述新的授权记录包括所述第一数字资产的信息和所述第一操作的信息。
如前文所述的,本申请实施例的授权记录可以为令牌。此时,所述第二请求包括所述第一用户的令牌列表,其中,所述第一用户的令牌列表中的每个令牌,对应于一个数字资产的操作授权。这样,上述步骤32中,在通过第二功能模块存储的授权记录,验证所述第一用户对所述第一数字资产的第一操作的权限时,可以将所述第一用户的令牌列表与所述第一数字资产的令牌列表进行匹配,其中,所述第一数字资产的令牌列表中的每个令牌,对应于所述第一数字资产的一个操作授权,且与一个操作的信息相关联。这样,在所述第一用户的令牌列表与所述第一数字资产的令牌列表之间存在相同的第一令牌的情况下,获取所述第一令牌所关联的第二操作的信息,并在所述第一操作的信息与第二操作的信息相匹配的情况下,确定权限验证成功,否则,确定权限验证失败。具体的,是否匹配的判断方式可以参考上文的描述,此处不再赘述。
在授权记录采用令牌形式时,上述流程中的存储新的授权记录,具体包括:所述第二功能模块生成第二令牌,存储在所述第一数字资产的令牌列表中,并将所述第二令牌与所述第一操作的信息相关联。在生成第二令牌后,所述第二功能模块可以在所述第二响应包括所述第二令牌,以供所述第一用户对应的第一终端将所述第二令牌增加到所述第一用户的令牌列表中。
如图4所示,以元宇宙业务平台为例,第一功能模块为数字资产存储管理平台/功能模块,第二功能模块为数字资产操作权限管理平台,上述流程1在各个设备/模块间的交互流程,包括:
步骤101.使用方通过元宇宙业务平台发起对特定数字资产进行某一种或多种操作的请求,携带数字资产信息(例如数字资产标识),用户信息(例如用户标识,权限令牌列表),特定操作(例如对数字资产的访问、修改/升级,下载等),请求发送给数字资产存储管理平台/功能模块。
步骤102.数字资产存储管理平台/功能模块向数字资产操作权限管理平台/功能模块发起查询申请,查询该用户是否对特定数字资产有所申请的操作权限。该申请携带数字资产标识和用户权限令牌列表。
步骤103.数字资产操作权限管理平台/功能模块判断该数字资产是否作了操作权限管控,如果被管控,判断此次操作申请是否已经授权。判断内容包括平台提取数字资产对应权限令牌列表并对用户所携带的权限令牌记性验证,验证通过的权限令牌对应的操作权限是否包含用户此次申请权限,该权限令牌是否在有效期内。判断此次操作是否可以执行,如果可以,则跳到步骤109,否则进行下一步。
步骤104.数字资产操作权限管理平台/功能模块基于数字资产标识寻找所有方。
步骤105.数字资产操作权限管理平台/功能模块发送询问所有方意向请求。请求信息包括数字资产信息,使用者信息,申请的操作和操作时间。
步骤106.业务平台向所有方获取用户意见,告知是否允许数字资产操作权限的申请。
步骤107.业务平台向数字资产操作权限管理平台/功能模块反馈用户意向。
步骤108.数字资产操作权限管理平台/功能模块验证所有方权限后,记录此次所有方的授权信息,信息包括数字资产标识、授权的操作、权限令牌等。此次生成的权限令牌存储于数字资产对应的权限令牌列表中并存储该权限令牌对应的权限信息和授权时限。
步骤109.数字资产操作权限管理平台/功能模块向数字资产存储管理平台/功能模块反馈该用户是否有操作权限,如若首次对该数字资产操作则返回权限令牌。
步骤110.数字资产存储管理平台/功能模块根据权限结果执行对数字资产的操作或拒绝本次操作,如若首次对该数字资产操作则返回权限令牌。
步骤111.数字资产存储管理平台/功能模块向使用方元宇宙业务管理平台反馈此次操作响应,如若首次对该数字资产操作则提供权限令牌,用户本地存储权限令牌。
流程2:第一用户在发起对第一数字资产的第一操作的请求前,申请对所述第一数字资产的第一操作的权限的流程
请参照图5~图6,本申请一些实施例提供的数字资产的操作权限的控制方法,在第一用户申请获得相关授权的请求流程中实现相关权限管控。其中,图5是上述流程2在第二功能模块侧的流程图,图6是以元宇宙业务平台为例,提供上述流程2在各个设备/模块间的交互流程的示例图。
如图5所示,上述流程2在应用于第二功能模块侧时,包括以下步骤:
步骤51,第二功能模块接收第一平台或第一终端发送的第四请求,用于申请第一用户对第一数字资产的第一操作的权限。
这里,第一用户在希望获得对第一数字资产的第一操作的权限时,可以直接向第二功能模块发送所述第四请求,例如,通过接口IF4发送;也可以向第一平台发送相关请求,进而由第一平台通过接口IF4发送所述第四请求。
具体的,所述第四请求可以包括第一用户的第一用户信息和/或第一数字资产的信息和/或第一操作的信息;所述第一用户信息包括用户标识;所述第一数字资产的信息包括:第一数字资产的数字资产标识;所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
步骤52,所述第二功能模块确定所述第四请求是否需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权。
步骤53,所述第二功能模块在所述第四请求需要获得同意和/或授权的情况下,向第二平台和/或第二终端发送第五请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限。
通过以上步骤,本申请实施例实现了使用方操作数字资产前申请相关授权的流程,从而实现了数字资产跨平台操作权限的管控。
在上述步骤53之后,所述第二功能模块还可以接收所述第二平台和/或第二终端发送的第五响应,用于指示是否允许所述第一用户对所述第一数字资产的第一操作。例如,在所述第五响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,记录和/或存储所有方和/或第二平台对第一数字资产的授权信息,授权信息包括第一数字资产的信息和/或用户信息和/或第一操作的信息。所述用户信息可以是用户身份信息,所述第一操作的信息包括操作类型和/或操作时间等。
在一些实施例中,所述第二功能模块,还可以向所述第一平台或第一终端发送第四响应,所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请结果,例如是否获得授权。
上述步骤52中,所述第二功能模块确定所述第四请求是否需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权的具体方式,可以包括:
查验所述第一数字资产的控制模式:
在所述第一数字资产是严格控制模式的情况下,进入向所述第一平台或第一终端发送第四响应的步骤,且所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请被拒绝;
在所述第一数字资产是通用控制模式的情况下,确定所述第四请求需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权;
在所述第一数字资产是宽松控制模式的情况下,确定所述第四请求不需要所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权,此时向所述第一平台或第一终端发送第四响应,且所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请获得同意和/或授权。
类似的,本申请实施例中,授权信息可以采用令牌形式。此时,记录和/或存储所有方和/或第二平台对第一数字资产的授权信息,具体包括:生成第三令牌,存储在所述第一数字资产的令牌列表中,并将所述第三令牌与所述第一操作的信息相关联。另外,所述第二功能模块在发送所述第四响应时,在所述第四响应中包括所述第三令牌,以供所述第一终端将所述第三令牌增加到所述第一用户的令牌列表中。
从以上描述可以看出,所述第三令牌与上文的第一令牌、第二令牌一样,均是第一用户对第一数字资产的第一操作的授权。
如图6所示,以元宇宙业务平台为例,第一功能模块为数字资产存储管理平台/功能模块,第二功能模块为数字资产操作权限管理平台,上述流程2在各个设备/模块间的交互流程,包括:
步骤201.使用方通过元宇宙业务平台/权限管理客户端发起对特定数字资产进行某一种或多种操作的权限请求,请求发送给数字资产操作权限管控平台/功能模块,请求携带数字资产标识、操作方式、权限时长。
步骤202.数字资产操作权限管控平台/功能模块判断特定资产的操作是否需要获取所有方授权。如果需要,则基于数字资产标识寻找所有方;如果不需要,跳到步骤206。
步骤203.数字资产操作权限管控平台/功能模块发送询问所有方意向请求。
步骤204.所有方通过业务平台对询问进行反馈,告知是否允许申请方对特定数字资产进行操作。
步骤205.数字资产操作权限管控平台/功能模块记录此次所有方的授权信息,信息包括数字资产标识、可操作的类型、操作时间等,生成针对使用方对数字资产操作的权限令牌,并将此权限令牌存储与该数字资产对应的权限令牌列表中。
步骤206.数字资产操作权限管控平台/功能模块向使用方元宇宙业务管理平台反馈此次操作权限申请响应,告知申请结果及发送权限令牌。使用方将收到的权限令牌存储本地。
流程3:数字资产的所有方设置或更新数字资产的控制模式的流程
如果用户未在数字资产上传时未对控制模式进行设置,或在进行初始设置后所有方主动发起对控制模式的修改,可进行流程3。
请参照图7~图10,本申请一些实施例提供的数字资产的操作权限的控制方法,实现了数字资产的所有方对数字资产的控制模式的设置或更新。其中,图7是上述流程3在第二功能模块侧的流程图,图8是上述流程3在第一功能模块侧的流程图。以元宇宙业务平台为例,图9和图10提供上述流程3设置或更新控制模式的流程在各个设备/模块间的两个交互示例。
如图7所示,上述流程3在应用于第二功能模块侧时,包括以下步骤:
步骤71,第二功能模块接收第三平台和/或第三终端和/或第一功能模块发送的第六请求,用于设置或更新所述第一数字资产的控制模式。
这里,所述第六请求包括第一数字资产的信息和/或控制模式。所述控制模式可以包括三种,具体可以参考前文,此处不再赘述。
步骤72,所述第二功能模块验证所述第六请求是否获得第一数字资产的所有方和/或第二平台和/或第二终端的授权,在验证成功的情况下,根据所述第六请求设置和/或更新和/或存储所述第一数字资产的控制模式,并向所述第三平台和/或第三终端发送第六响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
通过以上步骤,本申请实施例实现了对数字资产控制模式的设置或更新。
上述步骤72中,所述第二功能模块在验证失败的情况下,可以向所述第三平台和/或第三终端第一功能模块发送第六响应,且所述第六响应用于指示所述第一数字资产的控制模式设置或更新失败。
如图8所示,上述流程3在应用于第一功能模块侧时,包括以下步骤:
步骤81,第一功能模块接收第三平台和/或第三终端发送的第七请求,用于设置或更新所述第一数字资产的控制模式。
这里,所述第七请求包括第一数字资产的信息、控制模式。
步骤82,所述第一功能模块向第二功能模块发送第八请求,用于设置或更新所述第一数字资产的控制模式。
步骤83,所述第一功能模块接收所述第二功能模块发送的第八响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
步骤84,所述第一功能模块向第三平台和/或第三终端发送第七响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
如图9所示,以元宇宙业务平台为例,第二功能模块为数字资产操作权限管理平台,第三平台为所有方元宇宙业务平台,第三终端为所有方对应终端的权限管理客户端。上述流程3设置或更新数字资产的控制模式在各个设备/模块间的交互流程,包括:
步骤301.所有方通过元宇宙业务平台向数字资产操作权限管控平台/模块发起数字资产控制模式设置请求或更新请求,请求中数字资产标识、对数字资产操作的控制模式等。
步骤302.数字资产操作权限管控平台/模块验证所有方是否有设置或更新的权限。如果有,跳到步骤3,否则跳到步骤304。
步骤303.数字资产操作权限管控平台/模块存储所有方对数字资产控制模式的最新设置或最新更新。
步骤304.数字资产操作权限管控平台/模块向元宇宙业务平台返回控制模式设置或更新的结果。
图10所示的示例,包括步骤401~406,与图9不同的是,图10中的所有方的平台(元宇宙业务平台)或所有方对应的终端中的权限管理客户端,是经由第一功能模块(数字资产存储管理模块/功能模块)来转发控制模式的设置或更新请求。
流程4:数字资产注册过程中的控制模式设置的流程
各个平台的数字资产需要注册到第一功能模块,在注册过程中,第二功能模块可以设置数字资产的控制模式,并为数字资产的所有方生成相关授权记录(如权限令牌)。
请参照图11~图14,本申请一些实施例提供的数字资产的操作权限的控制方法,实现了在数字资产注册过程中的控制模式的设置。其中,图11是上述流程4在第二功能模块侧的流程图,图12是上述流程4在第一功能模块侧的流程图。以元宇宙业务平台为例,图13提供上述流程4在各个设备/模块间的两个交互示例。
如图11所示,上述流程4在应用于第二功能模块侧时,包括以下步骤:
步骤1101,第二功能模块接收第一功能模块发送的第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息。
这里,所述第一数字资产的信息包括第一数字资产的数字资产标识;所述第一数字资产的所有方信息包括所有方标识;所述第二平台的信息包括平台IP地址、平台标识、平台调用接口中的至少一种。
步骤1102,所述第二功能模块向所述第一功能模块发送第九请求,用于向所述第一数字资产的所有方和/或第二平台和/或第二终端请求设置所述第一数字资产的控制模式。
步骤1103,所述第二功能模块接收所述第一功能模块发送的第九响应,用于指示所述第一数字资产的控制模式。
这里,所述第九响应可以包括:第一数字资产的信息和/或控制模式。
步骤1104,所述第二功能模块根据所述第九响应,设置和/或存储所述第一数字资产控制模式。
通过以上步骤,本申请实施例在数字资产注册到第一功能模块的过程中,实现了第二功能模块侧对所述第一数字资产的控制模式的设置。
可选的,所述第二功能模块还可以向所述第一功能模块发送第四信息,用于指示所述第一数字资产的控制模式的设置结果。
另外,在采用令牌作为权限时,所述第二功能模块可以为所述第一数字资产创建令牌列表,生成所述第一数字资产的所有方的第四令牌,将所述第四令牌与第三操作信息相关联,并将所述第四令牌保存在所述第一数字资产的令牌列表。在一些实施例中,在发送所述第四信息时,还可以在所述第四信息中包括所述第四令牌。需要说明的是,前文的第一、第二、第三令牌是使用方令牌,本流程中的第四令牌是所有方令牌,但这些令牌从格式和功能上来看,可以是相同或相类似的。与前文的第一、第二、第三令牌相比,第四令牌的权限可能更宽。
如图12所示,上述流程4在应用于第一功能模块侧时,包括以下步骤:
步骤1201,第一功能模块向第二功能模块发送第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息。
这里,所述第一数字资产的信息包括第一数字资产的数字资产标识;所述第一数字资产的所有方信息包括所有方标识;所述第二平台的信息包括平台IP地址、平台标识、平台调用接口中的至少一种。
步骤1202,所述第一功能模块接收所述第二功能模块发送的第九请求,用于请求设置所述第一数字资产的控制模式。
步骤1203,所述第一功能模块向第二平台和/或第二终端发送第十请求,用于请求设置所述第一数字资产的控制模式。
步骤1204,所述第一功能模块接收所述第二平台和/或第二终端发送的第十响应,用于指示所述第一数字资产的控制模式。
这里,所述第十响应是针对第十请求的响应,具体的,所述第十响应可以包括:第一数字资产的信息和/或控制模式。
步骤1205,所述第一功能模块向所述第二功能模块发送第九响应,用于指示所述第一数字资产的控制模式。
通过以上步骤,第二功能模块在数字资产注册过程中能够设置数字资产的控制模式。
在一些实施例中,上述方法中,所述第一功能模块还可以接收所述第二功能模块发送的第四信息,用于指示所述第一数字资产的控制模式的设置结果。所述第一功能模块还可以向所述第二平台或第二终端发送第五信息,所述五信息包括所述第一数字资产的控制模式的设置结果。
具体的,所述第四信息还可以包括第四令牌,所述第一功能模块还在第五信息中包括所述第四令牌,以供所述第二终端将所述第四令牌保存在所述第一数字资产的所有方的令牌列表中。
如图13所示,以元宇宙业务平台为例,第二功能模块为数字资产操作权限管理平台,第一功能模块为数字资产存储管理平台/功能模块,上述流程4更新数字资产的控制模式在各个设备/模块间的交互流程,包括:
步骤501.所有方通过元宇宙业务平台发起数字资产信息的注册和数字资产文件上传的请求,请求中携带数字资产相关信息(例如数字资产标识、数字资产属性、数字资产使用条款等)、所有者相关信息(例如所有者标识)和数字资产文件。
步骤502.数字资产存储管控平台/模块存储数字资产文件及数字资产信息、所有者信息。
步骤503.数字资产存储管理平台/功能模块转发数字资产注册信息给数字资产操作管控平台/功能模块,包括数字资产信息、所有方信息。
步骤504.数字资产操作管控平台/功能模块存储数字资产基本信息,发起数字资产操作的控制模式设置请求给数字资产存储管理平台/模块。
步骤505.数字资产存储管理平台/模块转发设置数字资产操作的控制模式请求。
步骤506.元宇宙业务平台发送所有者设置的数字资产操作的控制模式,包含数字资产标识、控制模式信息(严格控制,通用控制,宽松控制。严格控制用于私人使用情况,其他人不允许对数字资产进行操作;一般控制是允许部分人使用的情况,他人操作前是否需要征求所有者授权意向;宽松控制是公共使用的情况,开放给所有人对数字资产操作等)。
步骤507.数字资产存储管理平台/模块转发数字资产操作的控制模式设定信息给数字资产操作权限管控平台/模块。
步骤508.操作权限管控平台/模块存储所有方对该数字资产操作权限的设定。针对新注册数字资产生成权限令牌列表,为所有方对此数字资产的操作权限生成权限令牌,将此权限令牌存储于数字资产对应的权限令牌列表中。
步骤509.操作权限管控平台/模块向数字资产存储管理平台/模块返回数字资产操作的控制模式设定的响应,携带设定成功失败结果及设置成功后的权限令牌。
步骤510.数字资产存储管理平台/模块向元宇宙业务平台返回数字资产注册响应,携带资产注册结果,设置成功后的权限令牌。
从以上各个实施例可以看出,本申请实施例提供了一种跨平台数字资产协作共享的系统和方法,实现了跨平台的数字资产的操作权限的管控。本申请实施例在应用于元宇宙场景下时,能够为各元宇宙用户提供了一个跨平台数字资产协作共享的方案,满足了元宇宙世界中人们匿名畅游各个元宇宙业务平台且能实现对同一个数字资产共享和协同操作的需求。
以上介绍了本申请实施例的各种方法。下面将进一步提供实施上述方法的装置。
请参考图14,本申请实施例还提供一种第一功能模块,包括:
第一接收模块141,用于接收第一平台发送的第一请求,用于请求第一用户对第一数字资产的第一操作;
第一发送模块142,用于向第二功能模块发送第二请求,用于查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
第二接收模块143,用于接收第二功能模块发送的第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限;
第二发送模块144,用于向第一平台发送第一响应,用于指示所述第一数字资产的第一操作的结果。
可选的,所述第一请求包括:所述第一用户的第一用户信息、第一数字资产的信息、第一操作的信息。
可选的,所述第一用户信息包括用户标识和/或第一用户的令牌列表;
所述第一数字资产的信息包括:第一数字资产的数字资产标识;
所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
可选的,所述第一请求和所述第二请求还分别包括:所述第一用户的令牌列表,其中,所述第一用户的令牌列表中的每个令牌,对应于一个数字资产的操作授权。
可选的,所述第二发送模块,还配置为在所述第二响应包括第二令牌的情况下,在向第一平台发送的所述第一响应中包括所述第二令牌,以供所述第一用户对应的第一终端将所述第二令牌增加到所述第一用户的令牌列表中。
请参考图15,本申请实施例还提供一种第二功能模块,包括:
第一接收模块151,配置为接收第一功能模块发送的第二请求,所述第二请求用于查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
查验模块152,用于查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
第一发送模块153,用于向所述第一功能模块发送第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限。
可选的,所述第二请求包括:所述第一用户的第一用户信息和/或第一数字资产的信息和/或第一操作的信息。
可选的,所述第一用户信息包括用户标识和/或第一用户的令牌列表;
所述第一数字资产的信息包括:第一数字资产的数字资产标识;
所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
可选的,所述查验模块,还配置为:
查验所述第一数字资产的控制模式;
在所述第一数字资产是宽松控制模式的情况下,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限。
可选的,所述查验模块,还配置为:
在所述第一数字资产是严格控制模式或通用控制模式的情况下,验证所述第一用户对所述第一数字资产的第一操作的权限,并在权限验证成功时,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限。
可选的,所述查验模块,还配置为:
通过第二功能模块存储的授权记录,验证所述第一用户对所述第一数字资产的第一操作的权限。
可选的,所述查验模块,还配置为:
在权限验证失败时,所述第二功能模块向第二平台和/或第二终端发送第三请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限;
所述第二功能模块接收所述第二平台和/或第二终端发送的第三响应,用于指示是否允许所述第一用户对所述第一数字资产的第一操作。
可选的,还包括:
第一处理模块,配置为在所述第三响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限;
第二处理模块,配置为在所述第三响应指示不允许所述第一用户对所述第一数字资产的第一操作的情况下,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户不具有所述第一数字资产的第一操作的权限。
可选的,所述第三请求包括:第一用户信息和/或第一数字资产的信息和/或第一操作的信息;
所述第一用户信息包括用户标识;
所述第一数字资产的信息包括:第一数字资产的数字资产标识;
所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
可选的,所述第一处理模块,还配置为在所述第三响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,根据所述第三响应,存储新的授权记录,所述新的授权记录包括所述第一数字资产的信息和所述第一操作的信息。
可选的,所述第二请求包括所述第一用户的令牌列表,其中,所述第一用户的令牌列表中的每个令牌,对应于一个数字资产的操作授权;
所述查验模块,还配置为:将所述第一用户的令牌列表与所述第一数字资产的令牌列表进行匹配,其中,所述第一数字资产的令牌列表中的每个令牌,对应于所述第一数字资产的一个操作授权,且与一个操作的信息相关联;
在所述第一用户的令牌列表与所述第一数字资产的令牌列表之间存在相同的第一令牌的情况下,获取所述第一令牌所关联的第二操作的信息,并在所述第一操作的信息与第二操作的信息相匹配的情况下,确定权限验证成功,否则,确定权限验证失败。
可选的,所述第一处理模块,还配置为:生成第二令牌,存储在所述第一数字资产的令牌列表中,并将所述第二令牌与所述第一操作的信息相关联。
可选的,所述第二响应包括所述第二令牌,以供所述第一用户对应的第一终端将所述第二令牌增加到所述第一用户的令牌列表中。
请参考图16,本申请实施例还提供一种第二功能模块,包括:
第一接收模块161,用于接收第一平台或第一终端发送的第四请求,用于申请第一用户对第一数字资产的第一操作的权限;
确定模块162,用于确定所述第四请求是否需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权;
第一发送模块163,用于在所述第四请求需要获得同意和/或授权的情况下,向第二平台和/或第二终端发送第五请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限。
可选的,所述第四请求包括第一用户信息和/或第一数字资产的信息和/或第一操作的信息;
所述第一用户信息包括用户标识;所述第一数字资产的信息包括:第一数字资产的数字资产标识;所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
可选的,还包括:
第二接收模块,配置为接收所述第二平台和/或第二终端发送的第五响应,用于指示是否允许所述第一用户对所述第一数字资产的第一操作。
可选的,还包括:
第一处理模块,配置为在所述第五响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,记录和/或存储所有方和/或第二平台对第一数字资产的授权信息,授权信息包括第一数字资产的信息和/或用户信息和/或第一操作的信息。
可选的,还包括:
第二发送模块,配置为向所述第一平台或第一终端发送第四响应,所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请结果。
可选的,所述确定模块,还配置为:
查验所述第一数字资产的控制模式;
在所述第一数字资产是严格控制模式的情况下,进入向所述第一平台或第一终端发送第四响应的步骤,且所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请被拒绝;
在所述第一数字资产是通用控制模式的情况下,确定所述第四请求需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权;
在所述第一数字资产是宽松控制模式的情况下,确定所述第四请求不需要所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权,进入向所述第一平台或第一终端发送第四响应的步骤,且所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请获得同意和/或授权。
可选的,所述第一处理模块,还配置为:生成第三令牌,存储在所述第一数字资产的令牌列表中,并将所述第三令牌与所述第一操作的信息相关联;
所述第四响应包括所述第三令牌,以供所述第一终端将所述第三令牌增加到所述第一用户的令牌列表中。
请参考图17,本申请实施例还提供一种第二功能模块,包括:
第一接收模块171,用于接收第三平台和/或第三终端和/或第一功能模块发送的第六请求,用于设置或更新所述第一数字资产的控制模式;
第一处理模块172,用于验证所述第六请求是否获得第一数字资产的所有方和/或第二平台和/或第二终端的授权,在验证成功的情况下,根据所述第六请求设置和/或更新和/或存储所述第一数字资产的控制模式,并向所述第三平台和/或第三终端发送第六响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
可选的,所述第六请求包括第一数字资产的信息和/或控制模式。
可选的,还包括:
第一发送模块,配置为在验证失败的情况下,向所述第三平台和/或第三终端第一功能模块发送第六响应,且所述第六响应用于指示所述第一数字资产的控制模式设置或更新失败。
请参考图18,本申请实施例还提供一种第一功能模块,包括:
第一接收模块181,用于接收第三平台和/或第三终端发送的第七请求,用于设置或更新所述第一数字资产的控制模式;
第一发送模块182,用于向第二功能模块发送第八请求,用于设置或更新所述第一数字资产的控制模式;
第二接收模块183,用于接收所述第二功能模块发送的第八响应,用于指示所述第一数字资产的控制模式是否设置或更新成功;
第二发送模块184,用于向第三平台和/或第三终端发送第七响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
可选的,所述第七请求包括第一数字资产的信息、控制模式。
请参考图19,本申请实施例还提供一种第二功能模块,包括:
第一接收模块191,用于接收第一功能模块发送的第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
第一发送模块192,用于向所述第一功能模块发送第九请求,用于向所述第一数字资产的所有方和/或第二平台和/或第二终端请求设置所述第一数字资产的控制模式;
第二接收模块193,用于接收所述第一功能模块发送的第九响应,用于指示所述第一数字资产的控制模式;
第一处理模块194,用于根据所述第九响应,设置和/或存储所述第一数字资产控制模式。
可选的,所述第一数字资产的信息包括第一数字资产的数字资产标识;所述第一数字资产的所有方信息包括所有方标识;所述第二平台的信息包括平台IP地址、平台标识、平台调用接口中的至少一种。
可选的,所述第九响应包括:第一数字资产的信息和/或控制模式。
可选的,还包括:
第二发送模块,配置为向所述第一功能模块发送第四信息,用于指示所述第一数字资产的控制模式的设置结果。
可选的,还包括:
第一处理模块,配置为为所述第一数字资产创建令牌列表,生成所述第一数字资产的所有方的第四令牌,将所述第四令牌与第三操作信息相关联,并将所述第四令牌保存在所述第一数字资产的令牌列表;
其中,所述第四信息还包括所述第四令牌。
请参考图20,本申请实施例还提供一种第一功能模块,包括:
第一发送模块2001,配置为向第二功能模块发送第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
第一接收模块2002,配置为接收所述第二功能模块发送的第九请求,用于请求设置所述第一数字资产的控制模式;
第二发送模块2003,配置为向第二平台和/或第二终端发送第十请求,用于请求设置所述第一数字资产的控制模式;
第二接收模块2004,配置为接收所述第二平台和/或第二终端发送的第十响应,用于指示所述第一数字资产的控制模式;
第三发送模块2005,配置为向所述第二功能模块发送第九响应,用于指示所述第一数字资产的控制模式。
可选的,所述第一数字资产的信息包括第一数字资产的数字资产标识;所述第一数字资产的所有方信息包括所有方标识;所述第二平台的信息包括平台IP地址、平台标识、平台调用接口中的至少一种。
可选的,第十响应包括:第一数字资产的信息和/或控制模式。
可选的,还包括:
第三接收模块,配置为接收所述第二功能模块发送的第四信息,用于指示所述第一数字资产的控制模式的设置结果;
第四发送模块,配置为向所述第二平台或第二终端发送第五信息,所述五信息包括所述第一数字资产的控制模式的设置结果。
可选的,所述第四信息还包括第四令牌,所述第五信息还包括所述第四令牌,以供所述第二终端将所述第四令牌保存在所述第一数字资产的所有方的令牌列表中。
需要说明的是,以上实施例中的设备是与上述应用于第一功能模块或第二功能模块的方法对应的设备,上述各实施例中的实现方式均适用于该设备的实施例中,也能达到相同的技术效果。本申请实施例提供的上述设备,能够实现上述方法实施例所实现的所有方法步骤,且能够达到相同的技术效果,在此不再对本实施例中与方法实施例相同的部分及有益效果进行具体赘述。
本申请另一实施例的第一功能模块或第二功能模块,如图21所示,包括收发器2110、处理器2100、存储器2120及存储在所述存储器2120上并可在所述处理器2100上运行的程序或指令;所述处理器2100执行所述程序或指令时实现上述第一功能模块或第二功能模块的数字资产的操作权限的控制方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
所述收发器2110,用于在处理器2100的控制下接收和发送数据。
其中,在图21中,总线架构可以包括任意数量的互联的总线和桥,具体由处理器2100代表的一个或多个处理器和存储器2120代表的存储器的各种电路链接在一起。总线架构还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口提供接口。收发器2110可以是多个元件,即包括发送机和接收机,提供用于在传输介质上与各种其他装置通信的单元。处理器2100负责管理总线架构和通常的处理,存储器2120可以存储处理器2100在执行操作时所使用的数据。
本申请实施例还提供一种计算机可读存储介质,所述计算机可读存储介质上存储计算机程序,所述计算机程序被处理器执行时实现上述数字资产的操作权限的控制方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。其中,所述的计算机可读存储介质,如只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等。
本申请实施例还提供一种计算机程序产品,包括计算机指令,所述计算机指令被处理器执行时实现上述数字资产的操作权限的控制方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
需要说明的是,在本文中,术语“包括”、“中包含”或者其任何其他变体意在涵盖非排他性的中包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,所述计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。

Claims (51)

  1. 一种数字资产的操作权限的控制方法,包括:
    第一功能模块接收第一平台发送的第一请求,用于请求第一用户对第一数字资产的第一操作;
    所述第一功能模块向第二功能模块发送第二请求,用于查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
    所述第一功能模块接收第二功能模块发送的第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限;
    所述第一功能模块向第一平台发送第一响应,用于指示所述第一数字资产的第一操作的结果。
  2. 根据权利要求1所述的方法,其中,
    所述第一请求包括:所述第一用户的第一用户信息、第一数字资产的信息、第一操作的信息。
  3. 根据权利要求2所述的方法,其中,
    所述第一用户信息包括用户标识和/或第一用户的令牌列表;
    所述第一数字资产的信息包括:第一数字资产的数字资产标识;
    所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
  4. 根据权利要求2所述的方法,其中,所述第一请求和所述第二请求还分别包括:所述第一用户的令牌列表,其中,所述第一用户的令牌列表中的每个令牌,对应于一个数字资产的操作授权。
  5. 根据权利要求4所述的方法,其中,在所述第二响应包括第二令牌的情况下,在向第一平台发送的所述第一响应中包括所述第二令牌,以供所述第一用户对应的第一终端将所述第二令牌增加到所述第一用户的令牌列表中。
  6. 一种数字资产的操作权限的控制方法,包括:
    第二功能模块接收第一功能模块发送的第二请求,所述第二请求用于查验第一用户是否具有第一数字资产的第一操作的权限;
    所述第二功能模块查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
    所述第二功能模块向所述第一功能模块发送第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限。
  7. 根据权利要求6所述的方法,其中,
    所述第二请求包括:所述第一用户的第一用户信息和/或第一数字资产的信息和/或第一操作的信息。
  8. 根据权利要求7所述的方法,其中,
    所述第一用户信息包括用户标识和/或第一用户的令牌列表;
    所述第一数字资产的信息包括:第一数字资产的数字资产标识;
    所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
  9. 根据权利要求6所述的方法,其中,所述第二功能模块查验所述第一用户是否具有所述第一数字资产的第一操作的权限,包括:
    所述第二功能模块查验所述第一数字资产的控制模式;
    在所述第一数字资产是宽松控制模式的情况下,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限。
  10. 根据权利要求6所述的方法,其中,所述第二功能模块查验所述第一用户是否具有所述第一数字资产的第一操作的权限,还包括:
    在所述第一数字资产是严格控制模式或通用控制模式的情况下,验证所述第一用户对所述第一数字资产的第一操作的权限,并在权限验证成功时,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限。
  11. 根据权利要求10所述的方法,其中,验证所述第一用户对所述第一数字资产的第一操作的权限,包括:通过第二功能模块存储的授权记录,验证所述第一用户对所述第一数字资产的第一操作的权限。
  12. 根据权利要求10所述的方法,其中,所述第二功能模块查验所述第一用户是否具有所述第一数字资产的第一操作的权限,还包括:
    在权限验证失败时,所述第二功能模块向第二平台和/或第二终端发送第三请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限;
    所述第二功能模块接收所述第二平台和/或第二终端发送的第三响应,用于指示是否允许所述第一用户对所述第一数字资产的第一操作。
  13. 根据权利要求12所述的方法,其中,还包括:
    在所述第三响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户具有所述第一数字资产的第一操作的权限;
    在所述第三响应指示不允许所述第一用户对所述第一数字资产的第一操作的情况下,进入所述第二功能模块向所述第一功能模块发送第二响应的步骤,且所述第二响应用于指示所述第一用户不具有所述第一数字资产的第一操作的权限。
  14. 根据权利要求12所述的方法,其中,
    所述第三请求包括:第一用户信息和/或第一数字资产的信息和/或第一操作的信息;
    所述第一用户信息包括用户标识;
    所述第一数字资产的信息包括:第一数字资产的数字资产标识;
    所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
  15. 根据权利要求13所述的方法,其中,还包括:
    在所述第三响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,根据所述第三响应,存储新的授权记录,所述新的授权记录包括所述第一数字资产的信息和所述第一操作的信息。
  16. 根据权利要求15所述的方法,其中,
    所述第二请求包括所述第一用户的令牌列表,其中,所述第一用户的令牌列表中的每个令牌,对应于一个数字资产的操作授权;
    通过第二功能模块存储的授权记录,验证所述第一用户对所述第一数字资产的第一操作的权限,包括:将所述第一用户的令牌列表与所述第一数字资产的令牌列表进行匹配,其中,所述第一数字资产的令牌列表中的每个令牌,对应于所述第一数字资产的一个操作授权,且与一个操作的信息相关联;
    在所述第一用户的令牌列表与所述第一数字资产的令牌列表之间存在相同的第一令牌的情况下,获取所述第一令牌所关联的第二操作的信息,并在所述第一操作的信息与第二操作的信息相匹配的情况下,确定权限验证成功,否则,确定权限验证失败。
  17. 根据权利要求16所述的方法,其中,
    所述存储新的授权记录,具体包括:生成第二令牌,存储在所述第一数字资产的令牌列表中,并将所述第二令牌与所述第一操作的信息相关联。
  18. 根据权利要求17所述的方法,其中,还包括:
    所述第二响应包括所述第二令牌,以供所述第一用户对应的第一终端将所述第二令牌增加到所述第一用户的令牌列表中。
  19. 一种数字资产的操作权限的控制方法,包括:
    第二功能模块接收第一平台或第一终端发送的第四请求,用于申请第一用户对第一数字资产的第一操作的权限;
    所述第二功能模块确定所述第四请求是否需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权;
    所述第二功能模块在所述第四请求需要获得同意和/或授权的情况下,向第二平台和/或第二终端发送第五请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限。
  20. 根据权利要求19所述的方法,其中,
    所述第四请求包括第一用户信息和/或第一数字资产的信息和/或第一操作的信息;
    所述第一用户信息包括用户标识;所述第一数字资产的信息包括:第一数字资产的数字资产标识;所述第一操作的信息包括操作类型和/或操作时间,所述操作类型包括访问、更新、更改、下载中的一种或多种。
  21. 根据权利要求19所述的方法,其中,还包括:
    所述第二功能模块接收所述第二平台和/或第二终端发送的第五响应,用于指示是否允许所述第一用户对所述第一数字资产的第一操作。
  22. 根据权利要求21所述的方法,其中,还包括:
    在所述第五响应指示允许所述第一用户对所述第一数字资产的第一操作的情况下,记录和/或存储所有方和/或第二平台对第一数字资产的授权信息,授权信息包括第一数字资产的信息和/或用户信息和/或第一操作的信息。
  23. 根据权利要求22所述的方法,其中,还包括:
    向所述第一平台或第一终端发送第四响应,所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请结果。
  24. 根据权利要求23所述的方法,其中,所述第二功能模块确定所述第四请求是否需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权,包括:
    所述第二功能模块查验所述第一数字资产的控制模式;
    在所述第一数字资产是严格控制模式的情况下,进入向所述第一平台或第一终端发送第四响应的步骤,且所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请被拒绝;
    在所述第一数字资产是通用控制模式的情况下,确定所述第四请求需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权;
    在所述第一数字资产是宽松控制模式的情况下,确定所述第四请求不需要所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权,进入向所述第一平台或第一终端发送第四响应的步骤,且所述第四响应用于指示所述第一用户对第一数字资产的第一操作的权限的申请获得同意和/或授权。
  25. 根据权利要求23所述的方法,其中,
    所述记录和/或存储所有方和/或第二平台对第一数字资产的授权信息,具体包括:生成第三令牌,存储在所述第一数字资产的令牌列表中,并将所述第三令牌与所述第一操作的信息相关联;
    所述第四响应包括所述第三令牌,以供所述第一终端将所述第三令牌增加到所述第一用户的令牌列表中。
  26. 一种数字资产的操作权限的控制方法,包括:
    第二功能模块接收第三平台和/或第三终端和/或第一功能模块发送的第六请求,用于设置或更新第一数字资产的控制模式;
    所述第二功能模块验证所述第六请求是否获得第一数字资产的所有方和/或第二平台和/或第二终端的授权,在验证成功的情况下,根据所述第六请求设置和/或更新和/或存储所述第一数字资产的控制模式,并向所述第三平台和/或第三终端发送第六响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
  27. 根据权利要求26所述的方法,其中,还包括:
    所述第六请求包括第一数字资产的信息和/或控制模式。
  28. 根据权利要求26所述的方法,其中,还包括:
    在验证失败的情况下,向所述第三平台和/或第三终端第一功能模块发送第六响应,且所述第六响应用于指示所述第一数字资产的控制模式设置或更新失败。
  29. 一种数字资产的操作权限的控制方法,包括:
    第一功能模块接收第三平台和/或第三终端发送的第七请求,用于设置或更新第一数字资产的控制模式;
    所述第一功能模块向第二功能模块发送第八请求,用于设置或更新所述第一数字资产的控制模式;
    所述第一功能模块接收所述第二功能模块发送的第八响应,用于指示所述第一数字资产的控制模式是否设置或更新成功;
    所述第一功能模块向第三平台和/或第三终端发送第七响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
  30. 根据权利要求29所述的方法,其中,还包括:
    所述第七请求包括第一数字资产的信息、控制模式。
  31. 一种数字资产的操作权限的控制方法,包括:
    第二功能模块接收第一功能模块发送的第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
    所述第二功能模块向所述第一功能模块发送第九请求,用于向所述第一数字资产的所有方和/或第二平台和/或第二终端请求设置所述第一数字资产的控制模式;
    所述第二功能模块接收所述第一功能模块发送的第九响应,用于指示所述第一数字资产的控制模式;
    所述第二功能模块根据所述第九响应,设置和/或存储所述第一数字资产控制模式。
  32. 根据权利要求31所述的方法,其中,所述第一数字资产的信息包括第一数字资产的数字资产标识;所述第一数字资产的所有方信息包括所有方标识;所述第二平台的信息包括平台IP地址、平台标识、平台调用接口中的至少一种。
  33. 根据权利要求31所述的方法,其中,所述第九响应包括:第一数字资产的信息和/或控制模式。
  34. 根据权利要求31所述的方法,其中,还包括:
    所述第二功能模块向所述第一功能模块发送第四信息,用于指示所述第一数字资产的控制模式的设置结果。
  35. 根据权利要求34所述的方法,其中,还包括:
    所述第二功能模块为所述第一数字资产创建令牌列表,生成所述第一数字资产的所有方的第四令牌,将所述第四令牌与第三操作信息相关联,并将所述第四令牌保存在所述第一数字资产的令牌列表;
    其中,所述第四信息还包括所述第四令牌。
  36. 一种数字资产的操作权限的控制方法,包括:
    第一功能模块向第二功能模块发送第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
    所述第一功能模块接收所述第二功能模块发送的第九请求,用于请求设置所述第一数字资产的控制模式;
    所述第一功能模块向第二平台和/或第二终端发送第十请求,用于请求设置所述第一数字资产的控制模式;
    所述第一功能模块接收所述第二平台和/或第二终端发送的第十响应,用于指示所述第一数字资产的控制模式;
    所述第一功能模块向所述第二功能模块发送第九响应,用于指示所述第一数字资产的控制模式。
  37. 根据权利要求36所述的方法,其中,所述第一数字资产的信息包括第一数字资产的数字资产标识;所述第一数字资产的所有方信息包括所有方标识;所述第二平台的信息包括平台IP地址、平台标识、平台调用接口中的至少一种。
  38. 根据权利要求36所述的方法,其中,第十响应包括:第一数字资产的信息和/或控制模式。
  39. 根据权利要求38所述的方法,其中,还包括:
    所述第一功能模块接收所述第二功能模块发送的第四信息,用于指示所述第一数字资产的控制模式的设置结果;
    所述第一功能模块向所述第二平台或第二终端发送第五信息,所述五信息包括所述第一数字资产的控制模式的设置结果。
  40. 根据权利要求39所述的方法,其中,所述第四信息还包括第四令牌,所述第一功能模块还在第五信息中包括所述第四令牌,以供所述第二终端将所述第四令牌保存在所述第一数字资产的所有方的令牌列表中。
  41. 一种第一功能模块,包括:
    第一接收模块,配置为接收第一平台发送的第一请求,用于请求第一用户对第一数字资产的第一操作;
    第一发送模块,配置为向第二功能模块发送第二请求,用于查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
    第二接收模块,配置为接收第二功能模块发送的第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限;
    第二发送模块,配置为向第一平台发送第一响应,用于指示所述第一数字资产的第一操作的结果。
  42. 一种第二功能模块,包括:
    第一接收模块,配置为接收第一功能模块发送的第二请求,所述第二请求用于查验第一用户是否具有第一数字资产的第一操作的权限;
    查验模块,配置为查验所述第一用户是否具有所述第一数字资产的第一操作的权限;
    第一发送模块,配置为向所述第一功能模块发送第二响应,用于指示所述第一用户是否具有所述第一数字资产的第一操作的权限。
  43. 一种第二功能模块,包括:
    第一接收模块,配置为接收第一平台或第一终端发送的第四请求,用于申请第一用户对第一数字资产的第一操作的权限;
    确定模块,配置为确定所述第四请求是否需要获得所述第一数字资产的所有方和/或第二平台和/或第二终端的同意和/或授权;
    第一发送模块,配置为在所述第四请求需要获得同意和/或授权的情况下,向第二平台和/或第二终端发送第五请求,用于请求所述第一用户对所述第一数字资产的第一操作的权限。
  44. 一种第二功能模块,包括:
    第一接收模块,配置为接收第三平台和/或第三终端和/或第一功能模块发送的第六请求,配置为设置或更新第一数字资产的控制模式;
    第一处理模块,配置为验证所述第六请求是否获得第一数字资产的所有方和/或第二平台和/或第二终端的授权,在验证成功的情况下,根据所述第六请求设置和/或更新和/或存储所述第一数字资产的控制模式,并向所述第三平台和/或第三终端发送第六响应,配置为指示所述第一数字资产的控制模式是否设置或更新成功。
  45. 一种第一功能模块,包括:
    第一接收模块,配置为接收第三平台和/或第三终端发送的第七请求,用于设置或更新第一数字资产的控制模式;
    第一发送模块,配置为向第二功能模块发送第八请求,用于设置或更新所述第一数字资产的控制模式;
    第二接收模块,配置为接收所述第二功能模块发送的第八响应,用于指示所述第一数字资产的控制模式是否设置或更新成功;
    第二发送模块,配置为向第三平台和/或第三终端发送第七响应,用于指示所述第一数字资产的控制模式是否设置或更新成功。
  46. 一种第二功能模块,包括:
    第一接收模块,配置为接收第一功能模块发送的第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
    第一发送模块,配置为向所述第一功能模块发送第九请求,用于向所述第一数字资产的所有方和/或第二平台和/或第二终端请求设置所述第一数字资产的控制模式;
    第二接收模块,配置为接收所述第一功能模块发送的第九响应,用于指示所述第一数字资产的控制模式;
    第一处理模块,配置为根据所述第九响应,设置和/或存储所述第一数字资产控制模式。
  47. 一种第一功能模块,包括:
    第一发送模块,配置为向第二功能模块发送第一信息,所述第一信息包括第一数字资产的信息和/或第一数字资产的所有方信息和/或第二平台信息;
    第一接收模块,配置为接收所述第二功能模块发送的第九请求,用于请求设置所述第一数字资产的控制模式;
    第二发送模块,配置为向第二平台和/或第二终端发送第十请求,用于请求设置所述第一数字资产的控制模式;
    第二接收模块,配置为接收所述第二平台和/或第二终端发送的第十响应,用于指示所述第一数字资产的控制模式;
    第三发送模块,配置为向所述第二功能模块发送第九响应,用于指示所述第一数字资产的控制模式。
  48. 一种第一功能模块,包括:收发器、处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序或指令;其中,所述处理器执行所述程序或指令时实现如权利要求1至5、权利要求29至30、权利要求36至40中任一项所述的方法的步骤。
  49. 一种第二功能模块,包括:收发器、处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序或指令;其中,所述处理器执行所述程序或指令时实现如权利要求6至18、权利要求19至25、权利要求26至28、权利要求31至35中任一项所述的方法的步骤。
  50. 一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器执行时实现如权利要求1至40任一项所述的方法的步骤。
  51. 一种计算机程序产品,包括计算机指令,所述计算机指令被处理器执行时实现如权利要求1至40任一项所述的方法的步骤。
PCT/CN2025/106662 2024-07-02 2025-07-02 数字资产的操作权限的控制方法、模块及存储介质 Pending WO2026007993A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202410880745.5 2024-07-02
CN202410880745.5A CN121283655A (zh) 2024-07-02 2024-07-02 数字资产的操作权限的控制方法、模块及存储介质

Publications (1)

Publication Number Publication Date
WO2026007993A1 true WO2026007993A1 (zh) 2026-01-08

Family

ID=98237413

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2025/106662 Pending WO2026007993A1 (zh) 2024-07-02 2025-07-02 数字资产的操作权限的控制方法、模块及存储介质

Country Status (2)

Country Link
CN (1) CN121283655A (zh)
WO (1) WO2026007993A1 (zh)

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110929231A (zh) * 2019-12-06 2020-03-27 北京阿尔山区块链联盟科技有限公司 数字资产的授权方法、装置和服务器
US11138580B1 (en) * 2021-01-05 2021-10-05 Mythical, Inc. Systems and methods for peer-to-peer exchanges of non-fungible digital assets
CN113743921A (zh) * 2021-09-09 2021-12-03 网易(杭州)网络有限公司 数字资产的处理方法、装置、设备及存储介质
CN114266576A (zh) * 2022-02-28 2022-04-01 环球数科集团有限公司 一种元宇宙数字资产的交易系统
CN114707973A (zh) * 2022-03-08 2022-07-05 中科计算技术创新研究院 面向元宇宙应用的链上链下协同数字资产管理方法、协议
CN116108414A (zh) * 2023-02-16 2023-05-12 山大地纬软件股份有限公司 一种基于授权码和授权树的数字资产权限控制方法及系统

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110929231A (zh) * 2019-12-06 2020-03-27 北京阿尔山区块链联盟科技有限公司 数字资产的授权方法、装置和服务器
US11138580B1 (en) * 2021-01-05 2021-10-05 Mythical, Inc. Systems and methods for peer-to-peer exchanges of non-fungible digital assets
CN113743921A (zh) * 2021-09-09 2021-12-03 网易(杭州)网络有限公司 数字资产的处理方法、装置、设备及存储介质
CN114266576A (zh) * 2022-02-28 2022-04-01 环球数科集团有限公司 一种元宇宙数字资产的交易系统
CN114707973A (zh) * 2022-03-08 2022-07-05 中科计算技术创新研究院 面向元宇宙应用的链上链下协同数字资产管理方法、协议
CN116108414A (zh) * 2023-02-16 2023-05-12 山大地纬软件股份有限公司 一种基于授权码和授权树的数字资产权限控制方法及系统

Also Published As

Publication number Publication date
CN121283655A (zh) 2026-01-06

Similar Documents

Publication Publication Date Title
US11736292B2 (en) Access token management method, terminal, and server
US9178915B1 (en) Cookie preservation when switching devices
CN105024975B (zh) 账号登录的方法、装置及系统
US20180077091A1 (en) Presence-based systems and methods using electronic messaging activity data
US9871778B1 (en) Secure authentication to provide mobile access to shared network resources
JP2004512594A (ja) インターネットサイトに対するアクセス制御方法
CN102498701A (zh) 用于身份认证的方法和设备
CN101282330A (zh) 网络存储访问权限管理方法及装置、网络存储访问控制方法
WO2008034366A1 (en) Method and system of service subscription and device therefof
CN110636057B (zh) 一种应用访问方法、装置和计算机可读存储介质
US9275204B1 (en) Enhanced network access-control credentials
WO2007090332A1 (fr) Procédé et système de gestion de document xml
CN109788005A (zh) 设备控制权限共享方法、装置、系统及计算机存储介质
CN107438054B (zh) 基于公众平台实现菜单信息控制的方法及系统
WO2023280009A1 (zh) 访问控制方法及装置、设备、存储介质
US20240211554A1 (en) User-centric data management system
CN111985000A (zh) 模型服务输出方法、装置、设备及存储介质
CN103188244A (zh) 基于开放授权协议实现授权管理的系统及方法
US20140040376A1 (en) Method and apparatus for updating personal information in communication system
CN114584967B (zh) 数据管理方法、装置、系统及计算机可读存储介质
CN114202840B (zh) 身份验证控制方法、装置及介质
WO2026007993A1 (zh) 数字资产的操作权限的控制方法、模块及存储介质
KR102303754B1 (ko) 사용자 인증을 지원하는 방법, 시스템 및 비일시성의 컴퓨터 판독 가능 기록 매체
WO2015021842A1 (zh) 访问ott应用、服务器推送消息的方法及装置
CN116743472A (zh) 一种资源访问方法、装置、设备及介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25832318

Country of ref document: EP

Kind code of ref document: A1