Asynchronous distributed key generation method and device

By using an asynchronous fully secret sharing protocol and a multi-valued verification Byzantine negotiation protocol, a four-stage key generation method is designed. This method resolves the ADKG protocol's dependence on PKI and the trade-off between throughput and latency, achieving efficient key generation and security without the need for PKI. It is suitable for large-scale distributed systems.

CN120956410APending Publication Date: 2025-11-14BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511099032.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

The existing ADKG protocol relies on Public Key Infrastructure (PKI) to ensure the authenticity of public keys, which cannot be directly adapted to existing threshold encryption systems. Furthermore, there is a contradiction between throughput and latency, leading to increased latency at high throughput.

Method used

An asynchronous fully secret sharing protocol is adopted, combined with a multi-valued verification Byzantine negotiation protocol and a super-invertible matrix. A four-stage mechanism of sharing, negotiation, random extraction and key derivation is designed to achieve key generation without PKI, parallel execution of bandwidth-intensive transaction distribution, and online error correction algorithm to ensure the efficiency and security of key generation.

Benefits of technology

It achieves key generation without PKI, eliminates scalability challenges, balances throughput and latency, ensures that each honest node receives a consistent and complete share of secrets at the end of the sharing phase, and improves the system's resistance to censorship and the efficiency of key generation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956410A_ABST
    Figure CN120956410A_ABST
Patent Text Reader

Abstract

The invention discloses an asynchronous distributed key generation method and device. The method comprises a sharing stage, a negotiation stage, a random extraction stage and a key derivation stage which are executed in sequence. In the sharing stage, an asynchronous complete secret sharing protocol is adopted, and secret share distribution is achieved through the steps of sending, confirmation, preparation and amplification; in the negotiation stage, consensus screening is carried out on terminated secret sharing instances based on a multi-valued verification Byzantine negotiation protocol; in the random extraction stage, a negotiation result is operated by using an ultra-reversible matrix to generate an intermediate parameter; and in the key derivation stage, a key related result is finally output through an online error correction algorithm and Lagrange interpolation calculation. The method gets rid of dependence on public key infrastructure and credible setting, relieves the contradiction between throughput and delay, improves the security, reliability and anti-review performance of the system, and is suitable for a large-scale distributed system or a resource limited environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of key generation technology, specifically relating to an asynchronous distributed key generation method and apparatus. Background Technology

[0002] Key generation is the foundation of key management. Certificate-free key generation methods do not require certificate verification of public key legitimacy, which simplifies the process, reduces costs, and reduces the risk of single points of failure because they do not rely on centralized institutions. They are suitable for large-scale distributed systems or resource-constrained environments.

[0003] Distributed key generation protocols (DKGs) support the joint generation of public-private key pairs by mutually untrusted nodes. The private key is distributed among nodes through threshold secret sharing, and can be used in threshold cryptography systems. With the increasing demand for decentralized Byzantine Fault Tolerance (BFT) applications, DKGs have become a research hotspot. Many BFT protocols rely on threshold cryptography primitives and need to avoid dependence on trusted distributors, thus requiring DKG protocols. While there are many DKG protocols for synchronous networks, they differ significantly from real-world environments; therefore, asynchronous DKGs (ADKGs) have gained attention in recent years. AVSS and ACSS technologies are commonly used in asynchronous networks. AVSS suffers from the problem that honest nodes may enter the reconstruction phase without receiving a valid share. ACSS, as an improved version, addresses this issue through integrity properties, ensuring that honest nodes receive a complete and consistent secret share.

[0004] However, the existing ADKG protocol has two main bottlenecks: First, it relies on Public Key Infrastructure (PKI) and trusted settings to ensure the authenticity of public keys, but existing threshold encryption systems do not support PKI, making it impossible for the ADKG protocol to be directly adapted and also posing scalability challenges; Second, there is a contradiction between throughput and latency. Like the existing BFT protocol, the ADKG protocol has a conflict between the protocol phase and the broadcast phase. The protocol phase wastes bandwidth and increases latency, affecting subsequent broadcast rounds, so pursuing high throughput often comes at the cost of increased latency. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide an asynchronous distributed key generation method and apparatus to solve or partially solve the problems mentioned in the background art.

[0006] In view of the above objectives, in a first aspect, the present invention provides an asynchronous distributed key generation method, comprising:

[0007] Sharing phase: An asynchronous fully secret sharing protocol is adopted. Through the steps of sending, confirming, preparing and amplifying, the distributor generates and distributes secret shares and preset commitments to designated nodes. After verification, the designated nodes obtain valid secret shares as the basis for secret information.

[0008] Negotiation Phase: Building on the sharing phase, designated nodes run a multi-valued verification Byzantine negotiation protocol to perform consensus filtering on terminated asynchronous fully secret shared instances, forming a vector of instance sets that meet the conditions, and determining the effective computation range for the random extraction phase.

[0009] Random extraction phase: Based on the set definition vector obtained in the negotiation phase, the set definition vector is operated on using a super invertible matrix to generate the secret share of the set definition vector and define a polynomial to realize the transformation from consensus result to the intermediate parameters required for key generation;

[0010] Key derivation phase: Participants receive the calculation results from the random extraction phase, process them through an online error correction algorithm to obtain the key value, and perform Lagrange interpolation calculations upon receiving a valid key message, finally outputting the key result and completing the generation from intermediate parameters to the final key.

[0011] As a preferred scheme for asynchronous distributed key generation, the sending step in the sharing phase includes:

[0012] The distributor randomly samples a recovery polynomial R of degree t such that R(0) = s, calculates the Feldman polynomial commitment of the recovery polynomial R, and samples n shared polynomials S1, ..., S of degree t. n And satisfy S i (i) = R(i), calculate all shared polynomials S i The polynomial commitment constructs a vector containing the evaluation value. Form a root commitment C, and send the root commitment, the polynomial commitment, and an evaluation value for each share polynomial to the designated server.

[0013] As a preferred scheme for asynchronous distributed key generation, the confirmation steps during the sharing phase include:

[0014] Participant P i Verify the multinomial commitment after the distributor receives the first broadcast message. and the vector of evaluation values Check if it is in the expected position in root commitment C. If the check passes, send an acknowledgment message containing root commitment C and shared polynomial information.

[0015] As a preferred scheme for asynchronous distributed key generation, the preparation steps during the sharing phase include:

[0016] When the server receives 2t+1 valid acknowledgment messages with the same root commitment C, it broadcasts a ready message.

[0017] If the server receives a ready message t+1 with the same root commitment C and has not broadcast a ready message, then broadcast the ready message.

[0018] As a preferred scheme for asynchronous distributed key generation methods, the amplification step in the sharing phase includes:

[0019] When participant P i If 2t+1 acknowledgment messages with the same vector commitment C are received, and if no preparation message is sent but t+1 valid preparation messages with root commitment C and root commitment G are received, then a preparation message is sent.

[0020] If 2t+1 valid prepare messages with root commitments C and G are received, wait for t+1 valid acknowledgment messages with root commitments C and G to be received, and then process the polynomial S. i Perform interpolation.

[0021] As a preferred scheme for asynchronous distributed key generation, during the negotiation phase, a designated node maintains a set S to store instances that have completed sharing. The propagated instances in set S are input into a multi-valued verification Byzantine negotiation protocol, utilizing the predicate P(S) j ,S) Verification |S j |≥2t+1 and Select instances that meet the criteria and add them to set T. When |T|≥nt, delete the extra participants.

[0022] As a preferred scheme for asynchronous distributed key generation, in the random extraction stage, the formula for generating the secret share of the set-defined vector by performing operations on the set-defined vector using a super-invertible matrix is ​​as follows:

[0023]

[0024] In the formula, the left side is the vector [z0, z1, ..., z t The middle part is a superinvertible matrix, and the right side is a vector a = [a1, a2, ..., a2]. n ], and a j =0, T is the set of outputs from the negotiation phase, n is the total number of nodes, t is the upper limit of the number of malicious nodes, and w1, w2, ..., w t+1 are elements of a superinvertible matrix.

[0025] As a preferred scheme for asynchronous distributed key generation, the online error correction algorithm running during the key derivation stage includes the following steps:

[0026] For the loop variable r from 0 to t, first wait until the size of the input fragment set T is not less than 2t+r+1, then use the decoding function RSDec to decode t+r and set T to obtain message M, and then use the encoding function RSEnc to encode message M, parameter m and t+1 to obtain fragment set T'. If there are 2t+1 fragments in set T' that match set T, then return message M.

[0027] In a second aspect, the present invention provides an asynchronous distributed key generation device, comprising:

[0028] The sharing module is used to generate and distribute secret shares and preset commitments to designated nodes through the steps of sending, confirming, preparing and amplifying using an asynchronous fully secret sharing protocol. After verification, the designated nodes obtain the valid secret shares as the basic secret information.

[0029] The negotiation module, based on the sharing module, specifies the node to run the multi-valued verification Byzantine negotiation protocol, performs consensus filtering on terminated asynchronous fully secret shared instances, forms a vector of instance sets that meet the conditions, and determines the effective computation range for the random extraction phase.

[0030] The random extraction module is used to perform operations on the set definition vector obtained by the negotiation module using a super invertible matrix to generate the secret share of the set definition vector and define a polynomial, thereby realizing the transformation from consensus result to the intermediate parameters required for key generation.

[0031] The key derivation module is used by the participants to receive the calculation results from the random extraction module, process them through an online error correction algorithm to obtain the key value, perform Lagrange interpolation calculations upon receiving a valid key message, and finally output the key result, thus completing the generation from intermediate parameters to the final key.

[0032] As a preferred embodiment of the asynchronous distributed key generation device, the sharing module includes:

[0033] The sending submodule is used to randomly sample a recovery polynomial R of degree t, such that R(0) = s, calculate the Feldman polynomial commitment of the recovery polynomial R, and sample n shared polynomials S1, ..., S of degree t. n And satisfy S i (i) = R(i), calculate all shared polynomials S i The polynomial commitment constructs a vector containing the evaluation value. Form a root commitment C, and send the root commitment, the polynomial commitment, and an evaluation value for each share polynomial to the designated server;

[0034] The confirmation submodule is used by participant P. iVerify the multinomial commitment after the distributor receives the first broadcast message. and the vector of evaluation values Check if it is in the expected position in root commitment C. If the check passes, send an acknowledgment message containing root commitment C and shared polynomial information.

[0035] As a preferred embodiment of the asynchronous distributed key generation device, the sharing module includes:

[0036] The preparation submodule is used to broadcast a ready message when the server receives 2t+1 valid acknowledgment messages with the same root commitment C; if the server receives t+1 ready messages with the same root commitment C and has not broadcast a ready message, then it broadcasts a ready message.

[0037] The amplification submodule is used when participant P i Upon receiving 2t+1 acknowledgment messages with the same vector commitment C, if no preparation message has been sent and t+1 valid preparation messages with root commitment C and root commitment G have been received, then a preparation message is sent; if 2t+1 valid preparation messages with root commitment C and root commitment G have been received, wait until t+1 valid acknowledgment messages with root commitment C and root commitment G have been received, and then proceed with the polynomial S. i Perform interpolation.

[0038] As a preferred embodiment of the asynchronous distributed key generation device, in the negotiation module, a designated node maintains a set S to store instances that have completed sharing. The propagation instances in set S are input into a multi-valued verification Byzantine negotiation protocol, utilizing the predicate P(S) j ,S) Verification |S j |≥2t+1 and Select instances that meet the criteria and add them to set T. When |T|≥nt, delete the extra participants.

[0039] As a preferred embodiment of the asynchronous distributed key generation device, the random extraction module uses a super-invertible matrix to perform operations on the set-defined vector to generate the secret share of the set-defined vector, as follows:

[0040]

[0041] In the formula, the left side is the vector [z0, z1, ..., z t The middle part is a superinvertible matrix, and the right side is a vector a = [a1, a2, ..., a2]. n ], and a j =0, T is the set of outputs from the negotiation phase, n is the total number of nodes, t is the upper limit of the number of malicious nodes, and w1, w2, ..., w t+1 are elements of a superinvertible matrix.

[0042] As a preferred embodiment of the asynchronous distributed key generation device, in the key derivation module, for the loop variable r from 0 to t, it first waits until the size of the input fragment set T is not less than 2t+r+1, then uses the decoding function RSDec to decode t+r and set T to obtain message M, and then uses the encoding function RSEnc to encode message M, parameter m and t+1 to obtain fragment set T'. If there are 2t+1 fragments in set T' that match set T, then message M is returned.

[0043] Thirdly, the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the asynchronous distributed key generation method of the first aspect or any possible implementation thereof.

[0044] Fourthly, the present invention provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to perform steps in the asynchronous distributed key generation method of the first aspect or any possible implementation thereof.

[0045] The beneficial effects of the technical solution provided by this invention are as follows:

[0046] First, this invention implements an asynchronous distributed key generation scheme that does not require PKI by employing an improved Asynchronous Complete Secret Sharing Protocol (ACSS) and drawing on settings from Haven, thus eliminating the dependency on PKI and other trusted settings. This makes the scheme directly applicable to existing threshold encryption systems while avoiding the scalability challenges caused by PKI dependence, thereby broadening its application scope.

[0047] Secondly, the Par-ADKG protocol proposed in this invention, through its mechanism of parallel execution of the sharing and negotiation phases, allows bandwidth-intensive transaction distribution to run continuously, closely tracking network capacity and eliminating the need for batch processing to compete for network resources with bandwidth-intensive protocol modules throughout all operation periods. This enables the protocol to achieve peak throughput without affecting latency, solving the problem in existing ADKG protocols where pursuing maximum throughput often comes at the cost of increased latency.

[0048] Third, relying on the integrity property of the Asynchronous Complete Secret Sharing Protocol (ACSS), regardless of whether the distributor is a malicious node, each honest node can receive a consistent and complete secret share at the end of the sharing phase, which ensures the security and reliability of secret sharing and avoids the problem in Asynchronous Verifiable Secret Sharing (AVSS) where honest nodes may enter the reconstruction phase without receiving a valid share.

[0049] Fourth, the quality properties of the Multivalued Verification Byzantine Agreement (MVBA) protocol are utilized to ensure that there is at least a 1 / 2 probability that its output will come from an honest node. As the protocol runs, the probability of censorship decreases exponentially, thus ensuring that all broadcast transactions will eventually be output, effectively improving the system's resistance to censorship.

[0050] Fifth, through the clear division and collaborative work of four stages (sharing stage, negotiation stage, random extraction stage, and key derivation stage), combined with technologies such as super invertible matrices, Lagrange interpolation, and online error correction (OEC) algorithms, the key generation process becomes more efficient and accurate, enabling the rapid and reliable generation of key pairs in a distributed environment.

[0051] Sixth, since this invention does not rely on a centralized institution, it reduces the risk of single point of failure and achieves a balance between throughput and latency in terms of performance. Therefore, it is very suitable for large-scale distributed systems or resource-constrained environments, meeting the security and efficiency requirements for key generation in such scenarios. Attached Figure Description

[0052] To more clearly illustrate the technical solutions in this invention or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0053] Figure 1 This is a schematic diagram of the AVSS algorithm execution process provided in an embodiment of the present invention;

[0054] Figure 2 This is a schematic diagram of the ACSS algorithm execution process provided in an embodiment of the present invention;

[0055] Figure 3 This is a schematic diagram of the asynchronous distributed key generation method provided in an embodiment of the present invention;

[0056] Figure 4 This is a schematic diagram of the Par-ADKG protocol process provided in an embodiment of the present invention;

[0057] Figure 5 This is a schematic diagram illustrating the parallel sharing and negotiation phases provided in an embodiment of the present invention.

[0058] Figure 6 These are experimental results of the average runtime of the Par-ADKG protocol provided in this embodiment of the invention.

[0059] Figure 7 Experimental results of Par-ADKG protocol bandwidth usage provided in embodiments of the present invention;

[0060] Figure 8 The throughput experimental results of the Par-ADKG protocol provided in the embodiments of the present invention;

[0061] Figure 9 This invention provides a balance between throughput and latency when the number of nodes in the Par-ADKG protocol is 16.

[0062] Figure 10 This invention provides a balance between throughput and latency when the number of nodes in the Par-ADKG protocol is 32.

[0063] Figure 11 This invention provides a balance between throughput and latency when the number of nodes in the Par-ADKG protocol is 64.

[0064] Figure 12 This is a schematic diagram of the asynchronous distributed key generation device architecture provided in an embodiment of the present invention;

[0065] Figure 13 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0066] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to specific embodiments and accompanying drawings.

[0067] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this invention should have the ordinary meaning understood by those skilled in the art to which this invention pertains. The terms "comprising" or "including," or similar words used in the embodiments of this invention, mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects.

[0068] Key generation is fundamental to the key management process and plays a crucial role in the entire key management system. Certificate-free key generation methods differ from traditional certificate-based methods (such as public key infrastructure) in that they do not require certificates to verify the legitimacy of public keys. This significantly simplifies the entire key management process and effectively reduces costs. Furthermore, certificate-free key generation does not rely on a centralized certificate authority, thus reducing the risk of a single source of trust, effectively mitigating single points of failure, and making it suitable for large-scale distributed systems or resource-constrained environments.

[0069] Distributed Key Generation (DKG) protocols enable a group of untrusted nodes to collaboratively generate a public / private key pair. The private key is shared among the nodes using a threshold secret-sharing scheme and is never reconstructed or stored on a single node. These secretly shared private keys are used in threshold cryptography systems, for example, to generate threshold signatures, decrypt threshold-encrypted ciphertext, or generate common random numbers needed for consensus. With the increasing demand for decentralized Byzantine fault-tolerant applications on the internet, DKG protocols have become a popular research area.

[0070] Many Byzantine Fault Tolerance (BFT) protocols use threshold signatures to improve communication efficiency and threshold encryption to prevent censorship. The classic FLP impossibility theorem states that deterministic Byzantine Fault Tolerance protocols do not exist in asynchronous networks. For asynchronous BFT protocols that assume no bounded message delays, shared randomness is needed to circumvent FLP impossibility. All these threshold cryptographic primitives require nodes to possess a secret share of their private keys. A simple way to initiate them is to rely on a trusted distributor, but if this distributor is controlled by a malicious node, it will compromise the entire system. Therefore, a DKG protocol is needed to initiate these threshold cryptographic primitives while avoiding any centralized trust or single point of failure. Many DKG protocols are known when the underlying network is synchronous. Due to the significant difference between synchronous networks and real-world network environments, DKG protocols for asynchronous networks have gained considerable attention in recent years, known as Asynchronous Distributed Key Generation (ADKG).

[0071] Many existing ADKG protocols face two main bottlenecks: 1) They rely on public key infrastructure (PKI) and trusted settings to ensure the authenticity of public keys. ADKG protocols are the foundation of threshold encryption systems, but existing threshold encryption systems do not support PKI. If ADKG protocols rely on PKI, they cannot be directly used in existing threshold encryption systems and will also present scalability challenges. 2) Existing BFT protocols often encounter significant latency issues when achieving high throughput. These BFT protocols consist of two phases: a bandwidth-intensive broadcast phase and a bandwidth-independent protocol phase. Unlike the broadcast phase, which helps increase throughput, the protocol phase wastes available bandwidth, leading to significant latency and hindering subsequent broadcast rounds. In the context of ADKG protocols, there is also a certain conflict between the protocol and broadcast phases.

[0072] In related technologies, the secret sharing techniques frequently used in asynchronous network environments are Asynchronous Verifiable Secret Sharing (AVSS) and Asynchronous Complete Secret Sharing (ACSS).

[0073] The asynchronous verifiable secret sharing protocol consists of two sub-protocols: Share and Reconstruct. Let (Sh, Rec) be a pair of protocols, where the distributor L uses the Sh protocol to share a secret s, and other nodes use the Rec protocol to recover the shared secret. Assume a finite field F of order q, and let λ denote the security parameter, where negl(λ) is a negligible function in λ. If (Sh, Rec) is an AVSS scheme, the following properties must hold with probability 1-negl(λ), even with at most t malicious nodes controlling the system. These properties are described below:

[0074] (1) Termination:

[0075] 1) If the distributor L is honest, then each honest node will eventually terminate the Sh protocol.

[0076] 2) If an honest node terminates the Sh protocol, then every honest node will eventually terminate Sh.

[0077] 3) If all honest nodes start executing Rec, then each honest node will eventually terminate Rec.

[0078] (2) Correctness:

[0079] 1) If L is honest, then each honest node outputs the shared secret s when Rec is terminated.

[0080] 2) If an honest node terminates Sh, then there exists a fixed secret s'∈F such that every honest node will output s' when terminating Rec.

[0081] (3) Secrecy:

[0082] If L is honest and no honest node starts executing Rec, then an attacker who controls up to t nodes has no information about s.

[0083] See Figure 1This illustrates the execution process of the AVSS algorithm. The termination property defined in AVSS allows honest nodes to enter the reconstruction phase even if they haven't received a valid share from the distributor. This situation typically occurs when the distributor is a malicious node. In this case, the distributor might only send valid shares to some honest nodes, while maliciously controlled nodes falsely claim to have received their shares. Due to the presence of the malicious node, all honest nodes will terminate the sharing phase without receiving a valid share, thus entering the reconstruction phase.

[0084] To address this issue, a more robust primitive called Asynchronous Complete Secret Sharing (ACSS) was proposed. ACSS is an improved version of AVSS, providing an additional property: at the end of the sharing phase, regardless of whether the distributor is a malicious node, each honest node receives a consistent and complete share of the secret, ensuring their smooth entry into the reconstruction phase. This additional property is called completeness, previously referred to as ultimate secret sharing. By introducing the completeness property, ACSS solves the potential problems of AVSS when facing malicious distributors, thus providing stronger security guarantees. The execution process of the ACSS algorithm is as follows: Figure 2 As shown.

[0085] The definition of ACSS is as follows: The Asynchronous Fully Secret Sharing Protocol is an AVSS protocol that additionally satisfies the following integrity property: If an honest node terminates Sh, then there exists a polynomial p(·) of degree t in... F Above, such that p(0) = s', and each honest node i will eventually hold a share s. i =p(i). Furthermore, when L is honest, s' = s.

[0086] In related technologies, the Multi-Valued Validation Byzantine Agreement (MVBA) protocol was initially proposed by Cachin et al. As the name suggests, this protocol is a generalization of the Byzantine consensus protocol, allowing message lengths greater than one bit. Furthermore, Abraham et al. introduced a feature that allows participating parties to check whether the agreed-upon message satisfies certain predicates Q, typically checked during the protocol process when matching against some additional information W. This protocol requires several properties to be satisfied, described in detail below.

[0087] (1) Termination

[0088] If all messages have been delivered between the honest parties, then all honest parties will terminate and output v.

[0089] (2) Agreement

[0090] If an honest party outputs v, then all honest parties will also terminate and output v.

[0091] (3) External Validity

[0092] Each terminating honest party must determine that v is verified by w and satisfies the predicate Q(v,w).

[0093] (4) Integrity

[0094] If all parties comply with the agreement, and an honest party decides that v is verified by w, then any other party that proposes v must also verify v with w.

[0095] (5) Quality Attribute

[0096] The probability that the value v proposed by the correct participant is ultimately determined is at least 1 / 2, ensuring resistance to censorship.

[0097] Many existing ADKG protocols face two main bottlenecks: 1) They rely on public key infrastructure (PKI) and trusted settings to ensure the authenticity of public keys. ADKG protocols are the foundation of threshold encryption systems, but existing threshold encryption systems do not support PKI. If ADKG protocols rely on PKI, they cannot be directly used in existing threshold encryption systems and will also present scalability challenges. 2) The pursuit of maximum throughput often comes at the cost of increased latency. Existing BFT protocols often encounter significant latency issues when achieving high throughput. These BFT protocols consist of two phases: a bandwidth-intensive broadcast phase and a bandwidth-independent protocol phase. Unlike the broadcast phase, which helps increase throughput, the protocol phase wastes available bandwidth, leading to significant latency and hindering subsequent broadcast rounds. In the context of ADKG protocols, there is also a certain conflict between the protocol and broadcast phases.

[0098] In view of this, the present invention proposes an asynchronous distributed key generation method and apparatus, which can effectively alleviate the tension between throughput and latency, allowing each node to act as a sender in continuous multi-round broadcasts while simultaneously running a negotiation phase, packaging the broadcast transactions into the final consensus output. In this scenario, bandwidth-intensive transaction distribution continues to run, closely tracking network capacity and eliminating the need for batch processing to compete for network resources with bandwidth-intensive protocol modules throughout all operating periods. Therefore, peak throughput can be achieved without affecting latency. The following are the specific details of the embodiments of the invention.

[0099] See Figure 3This invention provides an asynchronous distributed key generation method, comprising:

[0100] S1. Sharing Phase: An asynchronous fully secret sharing protocol is adopted. Through the steps of sending, confirming, preparing, and amplifying, the distributor generates and distributes secret shares and preset commitments to designated nodes. After verification, the designated nodes obtain valid secret shares as the basis for secret information.

[0101] S2, Negotiation Phase: Building on the sharing phase, designated nodes run a multi-valued verification Byzantine negotiation protocol to perform consensus filtering on terminated asynchronous fully secret shared instances, forming a vector of instance sets that meet the conditions, and determining the effective computation range for the random extraction phase.

[0102] S3, Random Extraction Phase: Based on the set definition vector obtained in the negotiation phase, the set definition vector is operated on using a super invertible matrix to generate the secret share of the set definition vector and define a polynomial to realize the transformation from consensus result to the intermediate parameters required for key generation;

[0103] S4. Key Derivation Stage: Participants receive the calculation results from the random extraction stage, process them using an online error correction algorithm to obtain the key value, and upon receiving a valid key message, perform Lagrange interpolation calculations to finally output the key result, thus completing the generation from intermediate parameters to the final key.

[0104] The asynchronous distributed key generation method of this invention is defined as the Par-ADKG protocol. The Par-ADKG protocol includes four phases: sharing phase, negotiation phase, randomness extraction phase, and key derivation phase. Figure 4 The entire Par-ADKG protocol process is demonstrated. The sharing phase primarily utilizes an asynchronous fully secret sharing protocol, distributing secret shares mainly through reliable broadcasting. The negotiation phase employs multi-valued verification Byzantine negotiation. The random extraction phase leverages the properties of super-invertible matrices. Finally, Lagrange interpolation is used in the key derivation phase.

[0105] The Par-ADKG protocol in this embodiment differs from other ADKG protocols in that each node simultaneously runs a sharing phase and a negotiation phase. The sharing phase is based on an asynchronous fully secret sharing protocol and employs a continuously running broadcast mechanism, while the consensus protocol in the negotiation phase uses a series of operational mechanisms. Each node uses a multi-round continuous broadcast mechanism to continuously propagate its message set throughout the network, such as... Figure 5As shown. This broadcast is not blocked by waiting for broadcasts from any consensus module or other nodes; instead, it proceeds sequentially at its own pace. In each message set, the broadcast transmits the secret share and its associated vector commitment. The vector commitment transmitted in a certain message set proves that at least t+1 honest nodes received the same transaction in all previous broadcast batches.

[0106] This multi-round broadcasting is feasible because each node only needs to maintain a few local variables related to the current time slot and the immediately preceding time slot. All previously transmitted transactions can be persistently stored, awaiting the final consensus output. Because this embodiment adds vector commitments to the continuous broadcasting, it enables the parallel execution of an optimized multi-valued validation Byzantine negotiation protocol with external validity conditions to fully order the broadcast transactions. Specifically, when a node receives a new transaction from nt different broadcasts (along with nt new commitments), it triggers the multi-valued validation Byzantine negotiation protocol, using these nt vector commitments as input. The external validity condition of the multi-valued validation Byzantine negotiation protocol is set to first verify the validity of all vector commitments, and then confirm that these nt vector commitments correspond to newly delivered transactions for which a consensus output has not yet been reached.

[0107] Once the Multivalued Validation Byzantine Agreement (MVA) returns its results, all honest nodes receive a list of nt valid vector commitments and package the transactions certified by these vector commitments into a block as the consensus output. Relying solely on the external validity of the MVA does not necessarily guarantee that all broadcast transactions will eventually be output, as adversaries could make the MVA always return inputs of nt vector commitments under their control, effectively excluding vector commitments broadcast by t honest nodes and censoring those honest nodes. However, some recent quality properties of the MVA address this issue without incurring additional costs. As mentioned earlier, the quality property guarantees at least a 1 / 2 probability that the output of the MVA will come from an honest node. Therefore, as the protocol runs, the probability of censorship decreases exponentially, thus ensuring that all broadcast transactions will eventually be output.

[0108] In one possible embodiment, during the sharing phase, the sending step includes:

[0109] The distributor randomly samples a recovery polynomial R of degree t such that R(0) = s, calculates the Feldman polynomial commitment of the recovery polynomial R, and samples n shared polynomials S1, ..., S of degree t. n And satisfy S i (i) = R(i), calculate all shared polynomials S iThe polynomial commitment constructs a vector containing the evaluation value. Form a root commitment C, and send the root commitment, the polynomial commitment, and an evaluation value for each share polynomial to the designated server.

[0110] The sharing phase employs an asynchronous fully secret sharing protocol, utilizing a three-stage broadcast format similar to reliable broadcasting—Bracha broadcast. The execution process of this phase is summarized in Algorithm 1. Conceptually, the asynchronous fully secret sharing protocol in the sharing phase includes four distinct steps: the sending step, the acknowledgment step, the preparation step, and the amplification step. The acknowledgment step ensures the consistency of the protocol, while the preparation step ensures its integrity.

[0111] Specifically, in the sending step, the distributor first randomly samples a recovery polynomial R of degree t such that R(0) = s. Then the distributor calculates the Feldman polynomial commitment of R. In line 3, let G represent g. s In lines 4-7, the distributor first samples n shared polynomials S1,...,S with degree t. n It satisfies S. i (i) = R(i), but the remaining shared polynomials are uniformly randomly sampled. The distributor then calculates all S... i The multinomial commitment. In lines 9-10, the distributor forms a vector. It contains n evaluation values ​​(in transpose order). This vector contains each shared polynomial S1,...,S n The evaluation of a point on the vector. In total, the vector contains n. 2 In line 12, the distributor forms a root commitment C, which is a vector commitment over all polynomial commitments. This embodiment assumes that each polynomial commitment contains a proof of itself in C. For simplicity, these proofs are ignored when running PVerify. In lines 13-14, the distributor sends a message to the server p. i Send the root commitment, the secret commitment, all n+1 polynomial commitments, and an evaluation value for each share polynomial. Once server p... i Upon receiving the sent message from the distributor, it will verify whether the message is "consistent". All polynomial commitments are linked back to the root commitment. All received polynomial evaluation values ​​are S. j The verifiable part.

[0112]

[0113]

[0114] The confirmation steps during the sharing phase include:

[0115] Participant Pi Verify the multinomial commitment after the distributor receives the first broadcast message. and the vector of evaluation values Check if it is in the expected position in root commitment C. If the check passes, send an acknowledgment message containing root commitment C and shared polynomial information.

[0116] Specifically, from the moment the distributor receives the first broadcast message, participant P... i verify and all Is it in the expected position in C? If all checks pass, participant P... i Send an acknowledgment message containing the root commitment C and two pieces of shared polynomial information about the distributor: its commitment and at a certain point S m (i) evaluation, to help p m Interpolation polynomial. This step is crucial for implementing the "integrity" property of the ACSS protocol. The remaining protocol steps are the same as Bracha's broadcast.

[0117] Next, in the sharing phase, the preparation steps include:

[0118] When the server receives 2t+1 valid acknowledgment messages with the same root commitment C, it broadcasts a ready message.

[0119] If the server receives a ready message t+1 with the same root commitment C and has not broadcast a ready message, then broadcast the ready message.

[0120] Specifically, once 2t+1 valid acknowledgment messages with the same C are received, a server will broadcast a ready message. If a server has received t+1 ready messages with the same C, and if any server has not yet broadcast a ready message, then it will broadcast a ready message. When a participant sends an acknowledgment message, it does not know whether its multinomial commitment will become part of the consensus, because the three-stage broadcast protocol has not yet fully ended. In the construction of this embodiment, a Merkle tree is used as the underlying vector commitment. The root element of a Merkle tree is a vector with O(n) elements, and the communication cost of Merkle tree proof is O(λn log n). The total communication cost caused by the Merkle tree in transmission is limited to O(λn log n). 2 In the receiving process, it is O(log n), while in the receiving process it is O(λn). 3 ).

[0121] In the sharing phase, the amplification steps include:

[0122] When participant P iIf 2t+1 acknowledgment messages with the same vector commitment C are received, and if no preparation message is sent but t+1 valid preparation messages with root commitment C and root commitment G are received, then a preparation message is sent.

[0123] If 2t+1 valid prepare messages with root commitments C and G are received, wait for t+1 valid acknowledgment messages with root commitments C and G to be received, and then process the polynomial S. i Perform interpolation.

[0124] Specifically, when a participant P i Receive 2t+1 acknowledgment messages from different participants with the same vector commitment C. To ensure that each honest participant sends a preparation message, an amplification step is used, similar to the Bracha broadcast protocol. If participant P... i If no prepare message has been sent and t+1 valid prepare messages with C and G have been received, then a prepare message is sent. If participant P... i Received 2t+1 valid prepare messages with C and G, participant P i Wait until t+1 valid acknowledgments with C and G are received, instead of 2t+1. This condition must eventually be met because at least one honest party has received 2t+1 acknowledgments, where t+1 must come from an honest party. Once t+1 valid acknowledgments are heard, the protocol continues as before, i.e., participant P... i For polynomial S i Perform interpolation.

[0125] In one possible implementation, during the negotiation phase, a designated node maintains a set S to store instances that have completed sharing. The propagated instances in set S are input into a multi-valued valid Byzantine negotiation protocol, utilizing the predicate P(S). j ,S) Verification |S j |≥2t+1 and Select instances that meet the criteria and add them to set T. When |T|≥nt, delete the extra participants.

[0126] Specifically, this protocol effectively alleviates the tension between the sharing phase described above and the negotiation phase described in this section by executing them in parallel, thereby improving the protocol's throughput. In the negotiation phase, each node runs a multi-valued validator Byzantine negotiation protocol to reach consensus on a subset of the terminated asynchronous fully secret sharing scheme. Specifically, each participant waits for a set S containing 2t+1 instances. Node p iThe distributor of S is then input into the multi-valued validating Byzantine negotiation protocol. Furthermore, each node needs to locally maintain a set S representing all instances that have terminated at that node up to that point, and incrementally update it. Given a value S... j The propagation instance in the protocol provides a multi-valued verification Byzantine negotiation protocol, node p i Using predicate P(S) j To verify |S) j |≥2t+1 and Confirm all S j The propagation instance does indeed terminate at node p. i After completion, the multi-valued verified Byzantine negotiation protocol outputs a set T, where |T| ≥ 2t+1. After the multi-valued verified Byzantine negotiation protocol determines set T, each participant selects the first t+1 participants from set T and removes the remaining participants. The algorithm for the negotiation phase is summarized in Algorithm 2.

[0127]

[0128] In one possible embodiment, during the random extraction phase, the formula for generating the secret share of the set-defined vector by performing operations on the set-defined vector using a super-invertible matrix is ​​as follows:

[0129]

[0130] In the formula, the left side is the vector [z0, z1, ..., z t The middle part is a superinvertible matrix, and the right side is a vector a = [a1, a2, ..., a2]. n ], and a j =0, T is the set of outputs from the negotiation phase, n is the total number of nodes, t is the upper limit of the number of malicious nodes, and w1, w2, ..., w t+1 are elements of a superinvertible matrix.

[0131] Specifically, the random extraction phase requires the preceding negotiation phase to terminate. Let 'a' be defined as the following vector:

[0132] a = [a1, a2, ..., a n ], where a j =0,

[0133] Let a i It is the secret share of vector a owned by node i. Each node i can compute the vector [z0, z1, ..., z] locally. l The secret share of ], where the elements are represented as in Formula 3-1, and the matrix in the formula is a super-invertible matrix.

[0134]

[0135] Using the secretly shared vector a (n, t+1), each node i locally computes the secretly shared vector [z0, z1, ..., z...]. l The share of vector a is operated on by applying formula 3-1. Assume... It can be defined as a polynomial of degree l as follows:

[0136] Z(x) = z0 + z1x + ... + z l x l

[0137] Each node i has an (n, t+1) share of each coefficient of the polynomial Z(x). Each node i locally computes [z(j)] for each node j. i Let the vector Z be defined as [z(1), z(2), ..., z(n)]. Besides calculating [z]... i The node also needs to be utilized in the same way. To calculate Node i then sends to node j The algorithm for the random extraction phase is summarized in Algorithm 3.

[0138]

[0139]

[0140] In one possible embodiment, during the key derivation phase, the running online error correction algorithm includes the following steps:

[0141] For the loop variable r from 0 to t, first wait until the size of the input fragment set T is not less than 2t+r+1, then use the decoding function RSDec to decode t+r and set T to obtain message M, and then use the encoding function RSEnc to encode message M, parameter m and t+1 to obtain fragment set T'. If there are 2t+1 fragments in set T' that match set T, then return message M.

[0142] Specifically, during the key derivation phase, participant P i Received from node j Set (j,[z(i)]) j Add to set K and Join set Q. Participant P i Running the OEC algorithm from Algorithm 4 on sets K and Q yields z(i) = OEC(K). Send after information.

[0143]

[0144] Once received from node i Let i,g z(i) Add the set H. When |H|≥l+1, perform Lagrange interpolation to obtain g. z(0) ,g z(j) The final output is z(i),g z(0) ,g z(j) After receiving l+1 valid key messages, the node can compute the Lagrange interpolation threshold public key g in the exponent. z(0) And the missing threshold public key g for each j∈[n] z(j) The algorithm for the key derivation stage is summarized in Algorithm 5.

[0145]

[0146] To compare the Par-ADKG protocol with other ADKG protocols, this embodiment selects the best-performing open-source ADKG protocol currently available. For convenience, "2023USENIX" will be used to refer to existing ADKG protocol one, and "2022SP" will be used to refer to existing ADKG protocol two. Only "2023USENIX" and "2022SP" will be used in the following text and figures. To facilitate comparison with baseline experiments, this experiment uses different numbers of nodes to evaluate the Par-ADKG protocol, selecting 16, 32, 64, and 128 nodes. For a given n ≥ 3t + 1, a reconstruction threshold of l = 2t was tested. The algorithm bandwidth usage in this experiment remains consistent for any l ∈ [t, nt - 1], and the impact of l on computational performance is negligible. Therefore, the results of this experiment represent the case for any reconstruction threshold.

[0147] All nodes are deployed on Amazon Web Services (AWS) t3a.medium virtual machines (VMs), with each VM running a separate node. Each VM is equipped with 2 vCPUs and 4GB of RAM, running Ubuntu 20.04. This experiment establishes an overlay network where all nodes are fully connected, forming a complete graph. The following experimental evaluation demonstrates that the Par-ADKG protocol significantly outperforms previous state-of-the-art ADKG protocols in terms of scalability.

[0148] This experiment focuses on four aspects: runtime, bandwidth usage, throughput, and the balance between latency and throughput. The first set of experiments tests runtime, measuring the runtime of the Par-ADKG protocol as the time difference required from the start of the protocol to the node outputting its shared public key and its secret share. The runtime is the average across all nodes to calculate the overall runtime of the protocol. Figure 6As shown, the Par-ADKG protocol consistently achieves lower runtime compared to the other two protocols. Compared to 2022SP, the protocol in this experiment significantly reduces the average runtime, and as the number of nodes n increases, the average runtime is almost only one-quarter of that protocol when the number of nodes reaches 128. Compared to 2023USENIX, the Par-ADKG protocol generally shows a slightly lower average runtime. When the number of nodes is 16 or 32, the average runtime of the two protocols is similar. However, starting from 32 nodes, as the number of nodes n increases, the runtime of Par-ADKG is slightly lower than that of 2023USENIX.

[0149] The second set of experiments tested bandwidth usage, which was measured as the total number of bytes sent by each node throughout the entire Par-ADKG protocol process. Figure 7 The results show that the Par-ADKG protocol consumes less bandwidth than the other two protocols. When the number of nodes is 16, the bandwidth usage of the three protocols is roughly the same. As the number of nodes increases, the bandwidth usage of the Par-ADKG protocol decreases significantly compared to 2022SP. When the number of nodes is less than 64, the bandwidth usage of the Par-ADKG protocol is not significantly different from 2023USENIX. However, when the number of nodes reaches 64 or higher, the bandwidth usage of the Par-ADKG protocol begins to be slightly lower than that of 2023USENIX.

[0150] The third set of experiments focuses on throughput, defined as the number of keys generated per second. This metric is calculated based on bandwidth and the size of each key, clearly demonstrating the system's efficiency in generating encryption keys over time. Figure 8 The experimental results presented show that, with the same number of nodes, the Par-ADKG protocol demonstrates a significant advantage, achieving significantly higher throughput than other protocols. This superior performance is evident from the outset, as Par-ADKG's throughput is noticeably higher. Furthermore, this advantage becomes even more pronounced as the number of nodes increases. Unlike other protocols, Par-ADKG maintains high throughput while exhibiting a relatively rapid growth rate. This trend underscores Par-ADKG's scalability and efficiency, making it well-suited for scenarios involving a large number of nodes while maintaining excellent performance. Par-ADKG's throughput is more than 14% higher overall than the previous state-of-the-art ADKG protocol, 2023Usenix.

[0151] The main purpose of the fourth set of experiments was to explore the trade-off between throughput and latency. This set of experiments included three sub-experiments that compared the throughput and latency trade-offs between the Par-ADKG protocol and 2022SP and 2023USENIX under different numbers of nodes (n = 16, 32, 64). Latency was defined as the time required to execute each stage of the protocol, and throughput was defined as described above. The first set of experiments analyzed the trade-off between throughput and latency for the three ADKG protocols when the number of nodes was 16. The experimental results are as follows: Figure 9 As shown. From Figure 9 As can be seen, the Par-ADKG protocol exhibits the best balance between throughput and latency. As the protocol continues to run, its throughput remains consistently the highest. Compared to the other two protocols, Par-ADKG has the shortest latency for the same throughput. The second and third groups conducted experiments with the same setup, selecting 32 and 64 nodes respectively, to investigate the balance between throughput and latency for the three protocols. The experimental results are shown below. Figure 10 , Figure 11 As shown in the two graphs, regardless of whether the number of nodes is 32 or 64, the Par-ADKG protocol consistently maintains the best balance between throughput and latency during operation. With the same throughput, the Par-ADKG protocol consistently has the lowest latency, and with the same latency, the Par-ADKG protocol's throughput is significantly higher than the other two protocols, demonstrating a clear advantage.

[0152] The combined results of these three sub-experiments show that, as the number of nodes increases, the Par-ADKG protocol maintains low and relatively stable latency while achieving high throughput. In contrast, other protocols experience a significant increase in latency as they approach peak throughput. This indicates that the Par-ADKG protocol is more suitable for a wide range of applications, whether prioritizing throughput or low latency. Figures 9 to 11 As shown, in all three cases, the Par-ADKG protocol offers the optimal balance between throughput and latency. Furthermore, the advantages of the Par-ADKG protocol are maintained even as the number of nodes increases.

[0153] In summary, this invention, by employing an improved Asynchronous Complete Secret Sharing Protocol (ACSS) and drawing on the settings in Haven, implements an asynchronous distributed key generation scheme that does not require PKI, eliminating the dependency on PKI and other trusted settings. This allows the scheme to be directly applied to existing threshold encryption systems while avoiding the scalability challenges caused by PKI dependence, thus broadening its application scope. The Par-ADKG protocol proposed in this invention, through its mechanism of parallel execution of the sharing and negotiation phases, allows bandwidth-intensive transaction distribution to run continuously, closely tracking network capacity and eliminating the need to use batch processing to compete for network resources with bandwidth-intensive protocol modules during all operation periods. This enables the protocol to achieve peak throughput without affecting latency, solving the problem in existing ADKG protocols where pursuing maximum throughput often comes at the cost of increased latency. Relying on the integrity properties of the Asynchronous Complete Secret Sharing Protocol (ACSS), regardless of whether the distributor is a malicious node, each honest node receives a consistent and complete secret share at the end of the sharing phase, ensuring the security and reliability of secret sharing and avoiding the problem in Asynchronous Verifiable Secret Sharing (AVSS) where honest nodes may enter the reconstruction phase without receiving a valid share. By utilizing the quality properties of the Multivalued Verification Byzantine Negotiation (MVBA) protocol, it is guaranteed that there is at least a 1 / 2 probability that the output will come from an honest node. As the protocol runs, the probability of censorship decreases exponentially, ensuring that all broadcast transactions will eventually be output, effectively improving the system's censorship resistance. Through the explicit division and coordinated operation of four phases (sharing phase, negotiation phase, random extraction phase, and key derivation phase), combined with technologies such as superinvertible matrices, Lagrange interpolation, and online error correction (OEC) algorithms, the key generation process becomes more efficient and accurate, enabling the rapid and reliable generation of key pairs in a distributed environment. Since this invention does not rely on a centralized institution, it reduces the risk of single points of failure and achieves a balance between throughput and latency in performance. Therefore, it is highly suitable for large-scale distributed systems or resource-constrained environments, meeting the security and efficiency requirements for key generation in such scenarios.

[0154] It should be noted that the method of this embodiment can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of this embodiment, and these multiple devices will interact with each other to complete the data cross-border risk monitoring method based on rich information about data flow paths.

[0155] It should be noted that the above description describes some embodiments of the present invention. In some cases, the described actions or steps can be performed in a different order than that shown in the above embodiments and the desired result can still be achieved. Furthermore, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0156] See Figure 12 Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this embodiment of the invention also provides an asynchronous distributed key generation device, comprising:

[0157] The sharing module 100 is used to generate and distribute secret shares and preset commitments to designated nodes through the steps of sending, confirming, preparing and amplifying an asynchronous fully secret sharing protocol. After verification, the designated nodes obtain valid secret shares as the basis for secret information.

[0158] The negotiation module 200 is used, based on the sharing module, to specify nodes to run the multi-value verification Byzantine negotiation protocol, to perform consensus screening on terminated asynchronous fully secret shared instances, to form a vector of instance set that meets the conditions, and to determine the effective computation range for the random extraction phase.

[0159] The random extraction module 300 is used to perform operations on the set definition vector obtained by the negotiation module using a super invertible matrix to generate the secret share of the set definition vector and define a polynomial, thereby realizing the transformation from consensus result to the intermediate parameters required for key generation.

[0160] The key derivation module 400 is used by the participants to receive the calculation results of the random extraction module, process them through an online error correction algorithm to obtain the key value, perform Lagrange interpolation calculations upon receiving a valid key message, and finally output the key result, thus completing the generation from intermediate parameters to the final key.

[0161] In this embodiment, the sharing module 100 includes:

[0162] The sending submodule 101 is used to randomly sample a recovery polynomial R of degree t, such that R(0) = s, calculate the Feldman polynomial commitment of the recovery polynomial R, and sample n shared polynomials S1, ..., S of degree t. n And satisfy S i (i) = R(i), calculate all shared polynomials S i The polynomial commitment constructs a vector containing the evaluation value. Form a root commitment C, and send the root commitment, the polynomial commitment, and an evaluation value for each share polynomial to the designated server;

[0163] Confirmation submodule 102, used by participant P i Verify the multinomial commitment after the distributor receives the first broadcast message. and the vector of evaluation values Check if it is in the expected position in root commitment C. If the check passes, send an acknowledgment message containing root commitment C and shared polynomial information.

[0164] In this embodiment, the sharing module 100 includes:

[0165] The preparation submodule 103 is used to broadcast a ready message when the server receives 2t+1 valid acknowledgment messages with the same root commitment C; if the server receives t+1 ready messages with the same root commitment C but has not broadcast a ready message, then it broadcasts a ready message.

[0166] Amplification submodule 104 is used when participant P i Upon receiving 2t+1 acknowledgment messages with the same vector commitment C, if no preparation message has been sent and t+1 valid preparation messages with root commitment C and root commitment G have been received, then a preparation message is sent; if 2t+1 valid preparation messages with root commitment C and root commitment G have been received, wait until t+1 valid acknowledgment messages with root commitment C and root commitment G have been received, and then proceed with the polynomial S. i Perform interpolation.

[0167] In this embodiment, in the negotiation module 200, a designated node maintains a set S to store instances that have completed sharing. The propagation instances in set S are input into a multi-valued valid Byzantine negotiation protocol, utilizing the predicate P(S) j ,S) Verification |S j |≥2t+1 and Select instances that meet the criteria and add them to set T. When |T|≥nt, delete the extra participants.

[0168] In this embodiment, the random extraction module 300 uses a super-invertible matrix to perform operations on the set definition vector to generate the secret share of the set definition vector. The formula is as follows:

[0169]

[0170] In the formula, the left side is the vector [z0, z1, ..., z t The middle part is a superinvertible matrix, and the right side is a vector a = [a1, a2, ..., a2]. n ], and a j =0, T is the set of outputs from the negotiation phase, n is the total number of nodes, t is the upper limit of the number of malicious nodes, and w1, w2, ..., wt+1 are elements of a superinvertible matrix.

[0171] In this embodiment, in the key derivation module 400, for the loop variable r from 0 to t, it first waits until the size of the input fragment set T is not less than 2t+r+1, then uses the decoding function RSDec to decode t+r and set T to obtain message M, and then uses the encoding function RSEnc to encode message M, parameter m and t+1 to obtain fragment set T'. If there are 2t+1 fragments in set T' that match set T, then message M is returned.

[0172] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement an asynchronous distributed key generation method as described in any of the above embodiments.

[0173] Figure 13 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 510, a memory 520, an input / output interface 530, a communication interface 540, and a bus 550. The processor 510, memory 520, input / output interface 530, and communication interface 540 are interconnected internally via the bus 550.

[0174] The processor 510 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0175] The memory 520 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 520 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 520 and is called and executed by the processor 510.

[0176] Input / output interface 530 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touch screens, microphones, various sensors, etc., and output devices may include displays, speakers, vibrators, indicator lights, etc.

[0177] The communication interface 540 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (e.g., USB, Ethernet cable) or wireless means (e.g., mobile network, Wi-Fi, Bluetooth).

[0178] Bus 550 includes a pathway for transmitting information between various components of the device, such as processor 510, memory 520, input / output interface 530, and communication interface 540.

[0179] It should be noted that although the above-described device only shows the processor 510, memory 520, input / output interface 530, communication interface 540, and bus 550, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.

[0180] The electronic devices described above are used to implement an asynchronous distributed key generation method corresponding to any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0181] Based on the same inventive concept, corresponding to any of the above embodiments, the present invention also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute an asynchronous distributed key generation method as described in any of the above embodiments.

[0182] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.

[0183] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute an asynchronous distributed key generation method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0184] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the invention is limited to these examples; within the framework of the invention, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of the different aspects of the embodiments of the invention as described above, which are not provided in detail for the sake of brevity.

[0185] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of the invention, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of the invention, and this also takes into account the fact that the details of implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of the invention will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of the invention, it will be apparent to those skilled in the art that the embodiments of the invention may be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0186] Although the invention has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAMDRAM) may be used with the embodiments discussed.

[0187] The embodiments of this invention are intended to cover all such substitutions, modifications, and variations falling within the scope of the claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this invention should be included within the scope of protection of this invention.

Claims

1. An asynchronous distributed key generation method, comprising: Sharing phase: An asynchronous fully secret sharing protocol is adopted. Through the steps of sending, confirming, preparing and amplifying, the distributor generates and distributes secret shares and preset commitments to designated nodes. After verification, the designated nodes obtain valid secret shares as the basis for secret information. Negotiation Phase: Building on the sharing phase, designated nodes run a multi-valued verification Byzantine negotiation protocol to perform consensus filtering on terminated asynchronous fully secret shared instances, forming a vector of instance sets that meet the conditions, and determining the effective computation range for the random extraction phase. Random extraction phase: Based on the set definition vector obtained in the negotiation phase, the set definition vector is operated on using a super invertible matrix to generate the secret share of the set definition vector and define a polynomial to realize the transformation from consensus result to the intermediate parameters required for key generation; Key derivation phase: Participants receive the calculation results from the random extraction phase, process them through an online error correction algorithm to obtain the key value, and perform Lagrange interpolation calculations upon receiving a valid key message, finally outputting the key result and completing the generation from intermediate parameters to the final key.

2. The asynchronous distributed key generation method according to claim 1, wherein, During the sharing phase, the sending steps include: The distributor randomly samples a recovery polynomial R of degree t such that R(0) = s, calculates the Feldman polynomial commitment of the recovery polynomial R, and samples n shared polynomials S1, ..., S of degree t. n And satisfy S i (i) = R(i), calculate all shared polynomials S i The polynomial commitment constructs a vector containing the evaluation value. Form a root commitment C, and send the root commitment, the polynomial commitment, and an evaluation value of each share polynomial to the designated server; During the sharing phase, the confirmation steps include: Participant P i Verify the multinomial commitment after the distributor receives the first broadcast message. and the vector of evaluation values Check if it is in the expected position in root commitment C. If the check passes, send an acknowledgment message containing root commitment C and shared polynomial information.

3. The asynchronous distributed key generation method according to claim 1, wherein, The preparation steps during the sharing phase include: When the server receives 2t+1 valid acknowledgment messages with the same root commitment C, it broadcasts a ready message. If the server receives t+1 ready messages with the same root commitment C and has not broadcast any ready messages, then it will broadcast the ready message. During the sharing phase, the amplification steps include: When participant P i If 2t+1 acknowledgment messages with the same vector commitment C are received, and if no preparation message is sent but t+1 valid preparation messages with root commitment C and root commitment G are received, then a preparation message is sent. If 2t+1 valid prepare messages with root commitments C and G are received, wait for t+1 valid acknowledgment messages with root commitments C and G to be received, and then process the polynomial S. i Perform interpolation.

4. The asynchronous distributed key generation method according to claim 1, wherein, During the negotiation phase, a designated node maintains a set S to store instances that have completed sharing. The propagated instances in set S are input into a multi-valued valid Byzantine negotiation protocol, utilizing the predicate P(S). j ,S) Verification |S j |≥2t+1 and Select instances that meet the criteria and add them to set T. When |T|≥nt, delete the extra participants.

5. The asynchronous distributed key generation method according to claim 1, wherein, In the random extraction phase, the formula for generating the secret share of the set definition vector by performing operations on the set definition vector using a super-invertible matrix is ​​as follows: In the formula, the left side is the vector [z0, z1, ..., z t The middle part is a superinvertible matrix, and the right side is a vector a = [a1, a2, ..., a2]. n ], and a j =0, T is the set of outputs from the negotiation phase, n is the total number of nodes, t is the upper limit of the number of malicious nodes, and w1, w2, ..., w t+1 are elements of a superinvertible matrix.

6. The asynchronous distributed key generation method according to claim 1, wherein, During the key derivation phase, the online error correction algorithm includes the following steps: For the loop variable r from 0 to t, first wait until the size of the input fragment set T is not less than 2t+r+1, then use the decoding function RSDec to decode t+r and set T to obtain message M, and then use the encoding function RSEnc to encode message M, parameter m and t+1 to obtain fragment set T'. If there are 2t+1 fragments in set T' that match set T, then return message M.

7. An asynchronous distributed key generation device, comprising: The sharing module is used to generate and distribute secret shares and preset commitments to designated nodes through the steps of sending, confirming, preparing and amplifying using an asynchronous fully secret sharing protocol. After verification, the designated nodes obtain the valid secret shares as the basic secret information. The negotiation module, based on the sharing module, specifies the node to run the multi-valued verification Byzantine negotiation protocol, performs consensus filtering on terminated asynchronous fully secret shared instances, forms a vector of instance sets that meet the conditions, and determines the effective computation range for the random extraction phase. The random extraction module is used to perform operations on the set definition vector obtained by the negotiation module using a super invertible matrix to generate the secret share of the set definition vector and define a polynomial, thereby realizing the transformation from consensus result to the intermediate parameters required for key generation. The key derivation module is used by the participants to receive the calculation results from the random extraction module, process them through an online error correction algorithm to obtain the key value, perform Lagrange interpolation calculations upon receiving a valid key message, and finally output the key result, thus completing the generation from intermediate parameters to the final key.

8. The asynchronous distributed key generation device according to claim 7, wherein, The sharing module includes: The sending submodule is used to randomly sample a recovery polynomial R of degree t, such that R(0) = s, calculate the Feldman polynomial commitment of the recovery polynomial R, and sample n shared polynomials S1, ..., S of degree t. n And satisfy S i (i) = R(i), calculate all shared polynomials S i The polynomial commitment constructs a vector containing the evaluation value. Form a root commitment C, and send the root commitment, the polynomial commitment, and an evaluation value of each share polynomial to the designated server; The confirmation submodule is used by participant P. i Verify the multinomial commitment after the distributor receives the first broadcast message. and the vector of evaluation values Check if it is in the expected position in root commitment C. If the check passes, send an acknowledgment message containing root commitment C and shared polynomial information.

9. An asynchronous distributed key generation device according to claim 7, wherein, The sharing module includes: The preparation submodule is used to broadcast a ready message when the server receives 2t+1 valid acknowledgment messages with the same root commitment C; if the server receives t+1 ready messages with the same root commitment C and has not broadcast a ready message, then it broadcasts a ready message. The amplification submodule is used when participant P i Upon receiving 2t+1 acknowledgment messages with the same vector commitment C, if no preparation message has been sent and t+1 valid preparation messages with root commitment C and root commitment G have been received, then a preparation message is sent; if 2t+1 valid preparation messages with root commitment C and root commitment G have been received, wait until t+1 valid acknowledgment messages with root commitment C and root commitment G have been received, and then proceed with the polynomial S. i Perform interpolation.

10. An asynchronous distributed key generation device according to claim 7, wherein, In the negotiation module, a designated node maintains a set S to store instances that have completed sharing. The propagation instances in set S are input into a multi-valued valid Byzantine negotiation protocol, utilizing the predicate P(S) j ,S) Verification |S j |≥2t+1 and Select instances that meet the criteria and add them to set T. When |T|≥nt, delete any extra participants. In the random extraction module, the formula for generating the secret share of the set definition vector by performing operations on the set definition vector using a super-invertible matrix is ​​as follows: In the formula, the left side is the vector [z0, z1, ..., z t The middle part is a superinvertible matrix, and the right side is a vector a = [a1, a2, ..., a2]. n ], and a j =0, T is the set of outputs from the negotiation phase, n is the total number of nodes, t is the upper limit of the number of malicious nodes, and w1, w2, ..., w t+1 are elements of a superinvertible matrix; In the key derivation module, for the loop variable r from 0 to t, it first waits until the size of the input fragment set T is not less than 2t+r+1. Then, the decoding function RSDec is used to decode t+r and set T to obtain message M. Then, the encoding function RSEnc is used to encode message M, parameter m and t+1 to obtain fragment set T'. If there are 2t+1 fragments in set T' that match set T, then message M is returned.