An ECDH-based group encryption method
A shared public key tree is generated through the ECDH algorithm with a binary tree structure, which solves the problem of high key update complexity in ECDH group communication and realizes instant group communication with low cost and low network load.
Patent Information
- Application Number
- CN202511054174.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2045-07-30
AI Technical Summary
The existing ECDH group communication method has high key update complexity when the number of group members increases, resulting in excessive delays and bandwidth resource usage, and high-frequency member changes may cause communication congestion.
A shared public key tree is generated using the ECDH algorithm with a binary tree structure. The private key of the tree node is calculated using the temporary private key and the public key of the other communicating parties. The shared private key is then removed and only the shared public key tree is transmitted. The other communicating parties calculate the final shared key based on the public key tree for decryption.
It enables instant communication with low cost and low network load when group members increase or decrease. The encryption method is suitable for large-scale groups and reduces the complexity and delay of key updates.
Smart Images

Figure CN120582787B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to an ECDH-based group encryption method. Background Art
[0002] The Internet has been widely used in the new era of social development. It has brought convenience to people's lives and work, but its open nature also means that information exchange also faces the risk of information leakage.
[0003] There are two mainstream secure communication models: one is a secure communication model under end-to-server encryption mode, and the other is a secure communication model under end-to-end encryption mode.
[0004] For the secure communication model under the end-to-server encryption mode, all the user's messages will be known to the server. If the server is hacked or is malicious, the security of the user's messages cannot be guaranteed.
[0005] In a secure communication model using end-to-end encryption, the server cannot decrypt the plaintext message and, therefore, cannot re-encrypt and forward it, as is done with end-to-server encryption. Typically, each group member first generates a message encryption key Gk for their own outgoing messages and then shares this Gk with other group members. Each group member stores the message encryption keys sent by other members, forming a key library. When a member wants to send a message, they encrypt it using the previously generated message encryption key Gk and send it to the server, which forwards it to the other members. Upon receiving the message, the other members select the corresponding group member's key Gk from the key library to decrypt it. This allows the message sender to initiate a group chat by sending only one message, while the server forwards multiple messages. In this communication model, the operator only knows the communication relationship between users and cannot directly decrypt their messages, further enhancing the security of user messages. Therefore, the secure communication model using end-to-end encryption primarily addresses the threat of operator attacks.
[0006] ECDH (Elliptic Curve Diffie-Hellman) is a key exchange protocol based on elliptic curve cryptography. It combines the mathematical properties of Diffie-Hellman (DH) key exchange with the elliptic curve discrete logarithm problem (ECDLP). It aims to generate secure shared keys over insecure communication channels without pre-sharing any secret information. The basic key negotiation process is as follows:
[0007] 1. The communicating parties agree on the elliptic curve parameters, base point G, and prime numbers.
[0008] 2. Each of them generates a key pair. For example, if Alice’s private key is pA, then the public key HA = pA·G; if Bob’s private key is pB, then the public key HB = pB·G.
[0009] 3. Alice and Bob exchange their public keys HA and HB through the channel.
[0010] 4. Calculate the shared key: Alice calculates the shared key S = skA = pA·HB = pA·(pB·G), and Bob calculates the shared key S = skB = pB·(pA·G). The shared key S calculated by both parties is the same. This key S is then used as the encryption key shared by Alice and Bob for subsequent data encryption.
[0011] The ECDH protocol itself is a two-party key exchange protocol. For multi-party conversations, it can often be extended to support multi-party group communication through a chaining mechanism. For example, in a group communication involving five parties, the first pair (A, B) is established, followed by a third party (C), a fourth party (D), and finally a fifth party (E). At the beginning of the conversation, A and B negotiate a shared symmetric key using the standard ECDH protocol, denoted as key_ab. When the third party (C) joins, the host (usually the first member, A) performs a separate ECDH operation with C to generate a new shared key (key_abc). A encrypts AES_key_abc using the current group key (AES_key_ab) and sends it to B via a secure channel. After B decrypts it, all three parties possess AES_key_abc. This process repeats with subsequent members (e.g., D, E, etc.), with the host generating a new key (e.g., AES_key_abcd) each time, encrypting it with the previous round's key and distributing it to all existing members. However, with this method, the key update complexity increases linearly as the number of group communication members increases. Especially in large groups, distributing keys to each member will cause significant delays, and high-frequency member changes may cause communication congestion. Each update requires the transmission of n encrypted messages, which consumes a lot of bandwidth resources. The host needs to perform n encryption operations and members need to perform n decryption operations, which affects real-time performance. Summary of the Invention
[0012] In order to solve the above-mentioned problems in the prior art, the present invention provides a group encryption method based on ECDH.
[0013] A group encryption method based on ECDH, comprising the following steps:
[0014] Step 1: Each communicating party generates its own key pair based on the ECC algorithm and exchanges or publishes the generated public key through the channel;
[0015] Step 2: When sending a message, the message sender generates a temporary ECC key pair, combines the temporary private key with the public key of the other communicating party through the ECDH algorithm, and calculates the parent node from the bottom child node upwards according to the binary tree structure. The key calculated at the root node is used as the final shared key. All private keys and the root node in the tree node are removed to obtain the shared public key tree;
[0016] Step 3: The message sender encrypts the message using the final shared key and sends the encrypted message along with the shared public key tree to other communication parties through the channel;
[0017] Step 4: After the other communicating parties obtain the shared public key tree, they find the position of the communicating party in the shared public key tree, and perform ECDH calculations from child nodes to parent nodes according to the tree structure to obtain the final shared key, which is used as the message key for subsequent decryption of messages.
[0018] Furthermore, step 2 includes the following sub-steps:
[0019] Step 201: The message sender calculates the private key of the temporary key pair with all the public keys of other communicating parties using the ECDH algorithm to obtain the private keys of all first-level tree nodes;
[0020] Step 202: Generate the public keys corresponding to the private keys in all first-level tree nodes based on the ECC algorithm;
[0021] Step 203: Perform ECDH calculations on each first-level tree node in pairs to obtain the private key of the second-level tree node, and generate the corresponding public key through the ECC algorithm. For the isolated first-level tree node, it is directly transferred to the second-level tree node by leaving it blank; perform calculations on each second-level tree node in pairs to obtain the second-level tree node. For the isolated second-level child node, it is directly transferred to the second-level tree node by leaving it blank; and so on, until the private key of the root node is calculated and used as the final shared key;
[0022] Step 204: All shared private keys and root nodes in the tree nodes are removed, and the tree structure composed of all the remaining shared public keys is used as the shared public key tree.
[0023] Furthermore, before the shared public key tree is sent to other communication parties through a channel, the shared public key tree is encoded.
[0024] Furthermore, step 4 includes the following sub-steps:
[0025] Step 401: After obtaining the shared public key tree, the other communication parties search for the location of the communication party in the shared public key tree.
[0026] Step 402: Calculate the private keys in the tree nodes using the ECDH algorithm from the tree position upward according to the tree structure until the final shared key in the root node is obtained;
[0027] Step 403: A message key for decrypting the message is further generated using the final shared key.
[0028] Furthermore, step 3 further includes using the final shared key as a seed to further generate a message key, and using the generated message key to encrypt the message
[0029] Furthermore, step 3 also includes storing the shared public key tree separately on a server that can be obtained by group members, calculating the hash value of the shared public key tree, and sending the hash value of the shared public key tree together with the message. Other communication parties access the public area and obtain the shared public key tree through the hash value, then cache it locally and calculate the key to decrypt the message.
[0030] Furthermore, when a member of the communicating party changes, the server monitors the public keys of all members and sends each message with a hash value generated by sorting the public keys of all members. When the server detects a change in the hash value, it immediately initiates the process of recalculating the public key tree and updates the stored shared public key tree.
[0031] The beneficial effects of the present invention are as follows: the present invention implements a group encryption method that can be used for instant communication by using a shared tree, and extends the benefits of ECDH to group communication by calculating a shared public key tree, with extremely low recalculation and network costs as the number of group members increases or decreases. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 Flow chart of the method of the present invention.
[0033] Figure 2 This is a schematic diagram of a shared public key tree without removing the private key in Example 2 of the present invention.
[0034] Figure 3 Schematic diagram of a shared public key tree after removing the private key in an embodiment of the present invention. DETAILED DESCRIPTION
[0035] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0036] Example 1: Reference Figure 1As shown, an ECDH-based group encryption method according to an embodiment of the present invention includes:
[0037] Step 1: Each communicating party generates its own key pair based on the ECC algorithm and exchanges or publishes the generated public key through the channel;
[0038] Step 2: When sending a message, the message sender generates a temporary ECC key pair, combines the temporary private key with the public key of the other communicating party through the ECDH algorithm, and calculates the parent node from the bottom child node upwards according to the binary tree structure. The key calculated at the root node is used as the final shared key. All private keys and the root node in the tree node are removed to obtain the shared public key tree;
[0039] Step 3: The message sender encrypts the message using the final shared key and sends the encrypted message along with the shared public key tree to other communication parties through the channel;
[0040] Step 4: After the other communicating parties obtain the shared public key tree, they find the position of the communicating party in the shared public key tree, and perform ECDH calculations from child nodes to parent nodes according to the tree structure to obtain the final shared key, which is used as the message key for subsequent decryption of messages.
[0041] Before the shared public key tree is sent to other communication parties through a channel, the shared public key tree is also encoded.
[0042] It should be noted that in addition to the above-mentioned individual participants in the settlement of their respective nodes, the actual operation of the shared key tree is generally calculated by the person who sends the message.
[0043] Example 2: In actual encryption applications, for any number of communicating parties, the process of generating a shared public key tree is as follows:
[0044] 1. The message sender calculates the private key of the temporary key pair with all the public keys of other communicating parties through the ECDH algorithm to obtain the private keys of all first-level tree nodes;
[0045] 2. Generate the public key corresponding to the private key in all first-level tree nodes based on the ECC algorithm;
[0046] 3. Perform ECDH calculations on each first-level tree node in pairs to obtain the private key of the second-level tree node, and generate the corresponding public key through the ECC algorithm. For the isolated first-level tree node, it is directly transferred to the second-level tree node by leaving it blank; perform calculations on each second-level tree node in pairs to obtain the second-level tree node. For the isolated second-level child node, it is directly transferred to the second-level tree node by leaving it blank; and so on, until the private key of the root node is calculated and used as the final shared key;
[0047] 4. Remove all shared private keys and root nodes from the tree nodes, and use the tree structure composed of all the remaining shared public keys as the shared public key tree.
[0048] Except for the root node, other tree nodes include shared private keys and shared public keys.
[0049] The following example illustrates the generation of a shared public key tree. Assume a group of six individuals, ABCDEF, generate their own public-private key pairs: (pA0, HA0), (pB, HB), (pC, HC), (pD, HD), (pE, HE), and (pF, HF). (A's public-private key is appended with 0 to distinguish it from subsequent temporary public-private key pairs.)
[0050] Everyone in the group knows the public keys HA0, HB, HC, HD, HE, HF.
[0051] like Figure 2 As shown, when A sends a message, it generates a temporary public and private key (pA, HA) and combines it with the public keys of all other people to calculate the shared public key tree. First, the private key pA is calculated with the public keys of all other people through the ECDH algorithm to obtain the first level (skAB, HAB), (skAC, HAC), (skAD, HAD), (skAE, HAE), (skAF, HAF); further calculation is performed to obtain the second level public key tree node and the number of communication parties is not 2 by leaving it blank to the next level. n The problem is solved, and the second level (skABC, HABC), (skADE, HADE), (skAF, HAF) are obtained; similarly, the third level public key tree nodes (skABCDE, HABCDE), (skAF, HAF) are calculated, and finally the key (skABCDEF) shared by everyone is obtained.
[0052] A removes all shared keys, leaving all shared public keys to form a tree structure, such as Figure 3 As shown, and a certain encoding is performed, and the public key tree is sent out with the message. N The pairing method of the power is not limited to leaving the last HF blank all the time, and can be any other node.
[0053] In Example 3, the processing process of other group members after receiving the message and sharing the public key tree is as follows:
[0054] 1) After the other communicating parties obtain the shared public key tree, they search for the location of the communicating party in the shared public key tree;
[0055] 2) According to the tree structure, the shared private key in the tree node is calculated by the ECDH algorithm from the position in the tree upward until the final shared key in the root node is obtained;
[0056] 3) The message key for decrypting the message is further generated through the final shared key.
[0057] Example 4: For a group with a small number of members, the encrypted public key tree obtained in this way can be sent along with each message. To save communication resources, for a large group with a large number of members, the shared public key tree can be stored separately on a server that can be accessed by group members, and the hash value of the shared public key tree is calculated. The hash value of the shared public key tree is sent along with the message. Other communication parties access the public area and obtain the shared public key tree through the hash value, cache it locally, and calculate the key to decrypt the message. In addition, the server monitors the public keys of all members, and each message is sent with a hash value generated by sorting all member public keys. When the server detects a change in the hash value, the server immediately initiates a process to recalculate the public key tree and update the stored shared public key tree. The server recalculates the current hash value when a member modifies the public key or a member joins or leaves. When the hash value attached to the message sent by the client is different from that of the server, the server returns the latest member public key list. The client recalculates the public key tree and the corresponding required hash value, and needs to re-encrypt and send the current message.
[0058] In the description of the embodiments of the present invention, the terms "first," "second," "third," and "fourth" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly specifying the number of the technical features indicated. Therefore, a feature specified as "first," "second," "third," or "fourth" may explicitly or implicitly include one or more of the features. In the description of the present invention, unless otherwise specified, "plurality" means two or more.
[0059] In describing the embodiments of the present invention, the term "and / or" is used herein to describe the association relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Furthermore, the character " / " is generally used herein to indicate that the associated objects are in an "or" relationship.
[0060] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A group encryption method based on ECDH, characterized in that: The following steps are involved: Step 1: Each communicating party generates its own key pair based on the ECC algorithm and exchanges or publishes the generated public key through the channel; Step 2: When sending a message, the message sender generates a temporary ECC key pair, combines the temporary private key with the public key of the other communicating party through the ECDH algorithm, and calculates the parent node from the bottom child node upwards according to the binary tree structure. The key calculated at the root node is used as the final shared key. All private keys and the root node in the tree node are removed to obtain the shared public key tree; The step 2 includes the following sub-steps: Step 201: The message sender calculates the private key of the temporary key pair with all the public keys of other communicating parties using the ECDH algorithm to obtain the private keys of all first-level tree nodes; Step 202: Generate the public keys corresponding to the private keys in all first-level tree nodes based on the ECC algorithm; Step 203: Perform ECDH calculations on each first-level tree node pairwise to obtain the private key of the second-level tree node, and generate the corresponding public key through the ECC algorithm. For the single first-level tree node, it is directly transferred to the second-level tree node by leaving it blank. Calculate each secondary tree node in pairs to obtain the secondary tree node. For a single secondary child node, directly transfer it to the secondary tree node by leaving it blank. And so on, until the private key of the root node is calculated and used as the final shared key; Step 204: remove all shared private keys and the root node from the tree nodes, and use the tree structure composed of all the remaining shared public keys as the shared public key tree; Step 3: The message sender encrypts the message using the final shared key and sends the encrypted message along with the shared public key tree to other communication parties through the channel; Step 4: After the other communicating parties obtain the shared public key tree, they find the position of the communicating party in the shared public key tree, and perform ECDH calculations from child nodes to parent nodes according to the tree structure to obtain the final shared key, which is used as the message key for subsequent decryption of messages.
2. The ECDH-based group encryption method according to claim 1, wherein: Before the shared public key tree is sent to other communication parties through a channel, the shared public key tree is encoded.
3. The ECDH-based group encryption method according to claim 1, wherein: The step 4 includes the following sub-steps: Step 401: After obtaining the shared public key tree, the other communication parties search for the location of the communication party in the shared public key tree. Step 402: Calculate the private keys in the tree nodes using the ECDH algorithm from the tree position upward according to the tree structure until the final shared key in the root node is obtained; Step 403: A message key for decrypting the message is further generated using the final shared key.
4. The ECDH-based group encryption method according to claim 1, wherein: The step 3 further includes using the final shared key as a seed to further generate a message key, and encrypting the message with the generated message key.
5. The ECDH-based group encryption method according to claim 1, wherein: The step 3 also includes storing the shared public key tree separately on a server that can be obtained by group members, calculating the hash value of the shared public key tree, and sending the hash value of the shared public key tree together with the message. Other communication parties access the public area and obtain the shared public key tree through the hash value, then cache it locally and calculate the key to decrypt the message.
6. The ECDH-based group encryption method according to claim 5, characterized in that: When a member of the communication party changes, the server monitors the public keys of all members and sends a hash value generated by sorting the public keys of all members with each message. When the server detects a change in the hash value, it immediately initiates the process of recalculating the public key tree and updates the stored shared public key tree.