A signature method and device of a hyperledger and a storage medium
By dividing Hyperledger user private keys into multiple copies and storing them on multiple devices, and combining distributed signature contracts and P2P networks to generate signatures, the problem of low transaction security caused by leakage of user private keys is solved, achieving higher transaction security and resource efficiency.
Patent Information
- Application Number
- CN202011606178.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-28
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2040-12-28
AI Technical Summary
User private keys in Hyperledger are easily leaked, resulting in low transaction security.
The user's private key in Hyperledger is divided into several different private key shares and stored on multiple devices. Signatures are generated through distributed signature contracts and P2P network collaboration to ensure the accuracy and security of the signatures.
It improves the security of user private key storage, avoids transaction forgery caused by the leakage of private keys from a single device, reduces Hyperledger resource consumption, and ensures the security and accuracy of transactions.
Smart Images

Figure CN112686669B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of blockchain, and particularly relates to a signature method and device of a super ledger and a storage medium. BACKGROUND
[0002] The blockchain technology is a kind of distributed shared ledger technology, and has the characteristics of decentralization and openness. At present, there are multiple blockchain technology platforms in the world for researching the blockchain technology and its application, and the super ledger is a representative platform.
[0003] The super ledger (Hyperledger) is an open source blockchain platform with smart contract function. When a user in the super ledger initiates a transaction, the user private key needs to be used to sign the transaction. Like the Bitcoin and Ethereum, the user private key in the super ledger is also stored in a single device only, and once the user private key in the storage device is leaked, it is easy to cause transaction forgery and other events. SUMMARY
[0004] The embodiments of the present application provide a signature method and device of a super ledger and a storage medium, to solve the technical problem that the user private key in the existing super ledger is easy to be leaked, resulting in low transaction security in the super ledger.
[0005] In one aspect, the embodiments of the present application provide a signature method of a super ledger. A first device divides a private key corresponding to the super ledger into a plurality of different private key shares; wherein the super ledger is a super ledger corresponding to an account to which the first device belongs; the first device is any one of a plurality of devices of the same account, and the private key share is any one of a plurality of different parts into which the private key is divided; the first device stores the plurality of different private key shares in a plurality of devices of the account respectively; the first device triggers a request for a distributed signature event based on a distributed signature contract of the super ledger; and each device in the account uploads a generated distributed signature to a blockchain after listening to the trigger request for the distributed signature event initiated by the first device.
[0006] The embodiments of the present application divide the user private key corresponding to the super ledger account into different private key shares and store them in a plurality of devices, thereby realizing the security of the user private key storage. The leakage of the private key share in one device will not cause a transaction forgery event, avoiding the situation that the user private key is stored in a single device, and once the private key is leaked, the transaction security will be threatened. At the same time, the devices belonging to the same account in the embodiments of the present application can all request to trigger the distributed signature event and listen to the distributed signature event. Moreover, each device can upload the distributed signature, and therefore, the accuracy of the signature can be verified by verifying whether the plurality of distributed signatures uploaded by the plurality of devices are the same, thereby providing security guarantee for the accuracy of the distributed signature.
[0007] In an implementation form of the method, the plurality of devices of the account respectively encrypt the private key share corresponding to the device to obtain an encrypted private key share; the plurality of devices of the account are connected through a P2P connection; the plurality of devices of the account are connected through a P2P network, and the generated encrypted private key share is broadcasted among the plurality of devices; and the encrypted private key share is the private key share encrypted by the plurality of devices respectively based on the stored private key share.
[0008] The embodiments of the application generate a distributed signature based on P2P network cooperation. The process of generating the distributed signature is performed off-chain, reducing the consumption of super account resources. Moreover, based on the P2P network connection, the encrypted private key shares among the devices can be shared. Through the cooperation among the plurality of devices, the distributed signature is generated together, making the private key and transaction more secure.
[0009] In an implementation form of the method, the plurality of devices of the account respectively encrypt the private key share corresponding to the device to obtain an encrypted private key share; the plurality of devices of the account are connected through a P2P connection; the plurality of devices of the account are connected through a P2P network, and the generated encrypted private key share is broadcasted among the plurality of devices; and the encrypted private key share is the private key share encrypted by the plurality of devices respectively based on the stored private key share.
[0010] The embodiments of the application perform homomorphic addition operation on the encrypted private key share by each device, and the private key share in any missing device cannot continue the process of generating the signature. The security of generating the distributed signature is increased, and the transaction forgery phenomenon caused by the leakage of the private key of a single device is avoided. Moreover, in the process of generating the distributed signature, the operations of consuming resources are performed in multiple devices, reducing the consumption of super account resources.
[0011] In an implementation form of the present application, before the first device divides the private key corresponding to the Hyperledger into a plurality of different private key shares, the method further comprises: the first device calling a register device address method in the distributed signature contract, adding address information of a plurality of other devices belonging to the same account as the first device to the device register address method, and registering the plurality of other devices; wherein the register device address method is a program for device registration pre-stored in the distributed signature contract; the first device deploying an off-chain distributed signature program for the plurality of other devices belonging to the same account; wherein the off-chain distributed signature program is used for listening to a request distributed signature event in the Hyperledger and for submitting the generated distributed signature.
[0012] In the present application, the first device calls the register device address method in the contract to register a plurality of other devices belonging to the same account. Thus, a plurality of devices correspond to one Hyperledger account, so that the Hyperledger can identify the devices belonging to the same account.
[0013] In an implementation form of the present application, before the devices in the account upload the generated distributed signature to the blockchain after listening to the trigger request distributed signature event initiated by the first device, the method further comprises: a plurality of devices of the account verifying the identity of the device triggering the request distributed signature event; and the plurality of devices generating the signature in the case that the device triggering the request distributed signature event and the plurality of devices belong to the same account.
[0014] In the present application, the identity of the device triggering the request distributed signature event is verified, so that the device listening to the event can filter the request distributed signature event initiated by the device not belonging to the same account as itself. Meanwhile, the device listening to the event generates the signature only for the distributed signature event initiated by the device belonging to the same account as itself, which can ensure the accuracy and security of the signature.
[0015] In an implementation form of the present application, after the generated distributed signature is uploaded to the blockchain, the method further comprises: a second device verifying a plurality of distributed signatures uploaded to the blockchain according to the distributed signature contract in the Hyperledger and according to the public key corresponding to the private key, the account corresponding to the second device being different from the account corresponding to the first device; and the first device needs to re-trigger the request distributed signature event in the case that the distributed signature is incorrect.
[0016] In the present application, the second device verifies the signature through the public key to ensure the accuracy of the signature. Moreover, the account corresponding to the second device is different from the account corresponding to the first device, and in the case that the two devices perform a transaction, verifying the accuracy of the signature can improve the security of the transaction and make the transaction run normally.
[0017] In an implementation form of the present application, the generated distributed signatures are respectively uploaded to the block chain, specifically including: a plurality of devices of an account respectively invoking a distributed signature submission method in a distributed signature contract; wherein the distributed signature submission method is a program for uploading the distributed signatures to the block chain; the distributed signatures are respectively added to the corresponding distributed signature submission methods, and the generated plurality of distributed signatures are uploaded to the block chain through the distributed signature submission methods.
[0018] In an implementation form of the present application, before the first device divides the private key corresponding to the hyperledger into a plurality of different private key shares, the method comprises: the first device obtains the private key by registering an account of the hyperledger.
[0019] On the other hand, the present application also provides a signature device of a hyperledger, comprising: at least one processor; and a memory in communication connection with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to: divide a private key corresponding to a hyperledger into a plurality of different private key shares by a first device; wherein the hyperledger is a hyperledger corresponding to an account to which the first device belongs; the first device is any one of a plurality of devices of the same account, and the private key share is any one of a plurality of different parts into which the private key is divided; the first device respectively stores the plurality of different private key shares in a plurality of devices of the account; the first device triggers a request for a distributed signature event based on a distributed signature contract of the hyperledger; and each device in the account uploads the generated distributed signature to the block chain after listening to the trigger request for the distributed signature event initiated by the first device.
[0020] On the other hand, the present application also provides a storage medium, which is a non-volatile computer readable storage medium, and the non-volatile computer readable storage medium stores at least one program, each of which includes instructions that, when executed by a terminal, cause the terminal to perform the above method. BRIEF DESCRIPTION OF DRAWINGS
[0021] The accompanying drawings, which are included to provide a further understanding of the present application, constitute a part of the present application, and the illustrative embodiments of the present application and their descriptions serve to explain the present application and do not constitute improper limitations on the present application. In the drawings:
[0022] Figure 1 A hyperledger signature method flow chart is provided for the embodiments of the present application;
[0023] Figure 2 An internal structure schematic diagram of a hyperledger signature device is provided for the embodiments of the present application. DETAILED DESCRIPTION
[0024] In order to make the purposes, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described clearly and completely below in combination with specific embodiments of the present application and corresponding drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.
[0025] Blockchain technology is a kind of distributed shared ledger technology, which has the characteristics of decentralization and openness. At present, there are many blockchain technology platforms in the world for researching blockchain technology and its application, and Hyperledger is a representative platform among them. Hyperledger is an open source blockchain platform with smart contract function. When a user in Hyperledger initiates a transaction, the user private key needs to be used to sign the transaction. Like Bitcoin and Ethereum, the user private key in Hyperledger is also stored in a single device only, and once the user private key in the storage device is leaked, it is easy to cause transaction forgery and other events.
[0026] The embodiments of the present application provide a Hyperledger signature method and device and storage medium, which divide the user private key of the Hyperledger into different private key shares and store them in multiple devices. And the distributed signature is generated by multiple devices, which solves the security problem that the user private key is stored in a single device and the private key is easily leaked to cause transaction forgery. And each device can generate a distributed signature, and the generated signature can be uploaded to the blockchain, so that the devices of different accounts can determine the accuracy of the signature according to whether each distributed signature is the same. At the same time, the operation process of generating the distributed signature is performed off-chain, so as to reduce the consumption of Hyperledger resources.
[0027] The technical solutions of the embodiments of the present application will be described in detail below with reference to the drawings.
[0028] Figure 1 A flowchart of a Hyperledger signature method provided by the embodiments of the present application is shown in FIG. 1. As shown in FIG. 1, the Hyperledger signature method includes the following steps: Figure 1
[0029] S101, the first device divides the obtained private key into several private key shares, and stores the several private key shares in multiple devices respectively. The first device is any one of the multiple devices of the same account.
[0030] In one embodiment of this application, the administrator deploys a distributed signature contract on Hyperledger, which includes methods for requesting distributed signatures, submitting distributed signatures, and registering device addresses. Simultaneously, the administrator publishes the download address of the off-chain distributed signature program on Hyperledger.
[0031] Specifically, Hyperledger is an open-source blockchain platform with smart contract functionality. The off-chain distributed signature program listens for distributed signature request events in Hyperledger and submits the generated distributed signatures. The request distributed signature method is a pre-defined program in the distributed signature contract used to trigger distributed signature request events. The submit distributed signature method is a program that uploads the distributed signature to the blockchain. The register device address method is a pre-defined program in the distributed signature contract used for device registration.
[0032] In one embodiment of this application, the first device obtains the private key and certificate corresponding to the Hyperledger account by registering an account with the Hyperledger. The first device divides the private key corresponding to the Hyperledger into several different private key shares. The Hyperledger is the Hyperledger corresponding to the account to which the first device belongs. Each private key share is any one of the several different parts into which the private key is divided.
[0033] It should be noted that multiple devices under the same account can be computers, mobile phones, or other devices or platforms with processing capabilities.
[0034] In one embodiment of this application, the first device stores several different private key shares in several devices of the account.
[0035] Specifically, in this embodiment, the user's private key p is divided into n private key shares, where n is a positive integer greater than 1. First, n-1 random numbers p1, p2, ..., p are randomly selected from the public parameter set. n-1 As the first n-1 shares of the private key. Secondly, according to the expression p n =p-p1-p2-...-p n-1 Calculate the share p of the nth private key. n The obtained n user private key shares p1, p2, p3...p n Stored on n devices under the same account.
[0036] It should be noted that the private key in this application embodiment is base64 encoded and has a corresponding PEM format. Therefore, there can be multiple arrangements of several private key shares.
[0037] For example, assuming the key is 123456, it is divided into 120000, 3400, and 56, and stored in three different devices A, B, and C. At this time, device A can store 120000, device B can store 56, and device C can store 3400. The password order may not be consistent with the storage order of the devices.
[0038] Embodiments of the present application divide the user private key corresponding to the Hyperledger account into different private key shares and store them in multiple devices. This avoids transaction forgery losses caused by loss of storage devices and private key leakage, and improves the security of signed transactions.
[0039] In an embodiment of the present application, the first device calls the register device address method in the distributed signature contract, adds the address information of the other several devices belonging to the same account as the first device to the device address registration method, and registers the other several devices.
[0040] Specifically, the embodiments of the present application can add the device identifiers of the other devices to the device address registration method to register the devices. The embodiments of the present application register the devices belonging to the same account, so that the Hyperledger identifies the devices belonging to the same account.
[0041] For example, assume that four different devices are mobile phone 1, mobile phone 2, computer 3, and tablet 4. First, the user registers a Hyperledger account, for example, account A, and obtains the user private key p corresponding to the account A. The user private key p is divided into p1, p2, p3, and p4, where p4 = p-p1-p2-p3, and stored in mobile phone 1, mobile phone 2, computer 3, and tablet 4, respectively. Any device, for example, mobile phone 1, calls the register device address method in the distributed signature contract to register mobile phone 2, computer 3, and tablet 4, so that mobile phone 2, computer 3, and tablet 4 also correspond to account A. At this point, the user private key corresponding to the Hyperledger account A is divided into p1, p2, p3, and p4 and stored in the four devices of mobile phone 1, mobile phone 2, computer 3, and tablet 4, respectively, and the four devices have been registered and belong to the same account.
[0042] In an embodiment of the present application, the first device deploys an off-chain distributed signature program for the other several devices belonging to the same account. This allows each of the other devices to listen to the request distributed signature event in the Hyperledger and submit the generated distributed signature.
[0043] S102, each device in the account listens to the trigger request distributed signature event initiated by the first device.
[0044] In an embodiment of the present application, when a transaction needs to be signed, the devices belonging to the same account start a distributed signing procedure. Each device reads the private key share stored in itself and listens to the request distributed signing event in the super ledger.
[0045] In an embodiment of the present application, when a transaction needs to be signed, the first device triggers a request distributed signing event based on the request distributed signing method in the distributed signing contract of the super ledger.
[0046] In an embodiment of the present application, the devices belonging to the same account authenticate the device triggering the request distributed signing event. In the case that the device triggering the request distributed signing event and the listening devices belong to the same account, the devices generate a signature.
[0047] Specifically, the devices need to authenticate the device triggering the request distributed signing event, which can be authenticated according to the device identifier. In the embodiment of the present application, the devices only generate a signature for the request distributed signing event triggered by the device belonging to the same account.
[0048] In an embodiment of the present application, the devices belonging to the same account as the first device generate a distributed signature and upload the distributed signature to the blockchain respectively after listening to the request distributed signing event triggered by the first device.
[0049] It should be noted that any device in the same account can trigger a request distributed signing event. Any device in the same account needs to listen to the request distributed signing event in the super ledger.
[0050] S103、The devices belonging to the same account generate a distributed signature through a P2P network connection.
[0051] In an embodiment of the present application, the devices belonging to the same account are connected through P2P. Through the P2P connection, the devices can transmit and receive information in the signature generation process, so as to ensure that the distributed signature can be accurately and effectively generated.
[0052] In an embodiment of the present application, the devices belonging to the same account encrypt the private key shares corresponding to themselves respectively to obtain encrypted private key shares. The devices belonging to the same account broadcast the generated encrypted private key shares among the devices through a P2P network connection. The encrypted private key share is the private key share encrypted by the devices respectively.
[0053] In an embodiment of the present application, the key algorithm used in the embodiment of the present application is the Elliptic Curve Digital Signature Algorithm (ECDSA), and the private key is a random number randomly selected from a set of public parameters.
[0054] In an embodiment of the present application, the several devices of the account perform a first encryption operation on the private key shares stored respectively by the devices to obtain first private key shares. The first private key shares are broadcast among the several devices of the account. The several devices of the account perform homomorphic addition encryption on the received several first private key shares to obtain second private key shares.
[0055] In an embodiment of the present application, the homomorphic addition encryption refers to re-encryption of plaintext by performing addition operation in a ring, and the result is equivalent to performing corresponding operation on ciphertext after encryption. The homomorphic multiplication encryption refers to re-encryption of plaintext by performing multiplication operation in a ring, and the result is equivalent to performing corresponding operation on ciphertext after encryption.
[0056] It should be noted that the embodiment of the present application supports a threshold homomorphic encryption protocol, such as a threshold Pailler homomorphic encryption protocol.
[0057] Specifically, let+E be a homomorphic addition operation, ×E be a homomorphic multiplication operation, E be an individual encryption operation that can be performed individually, D be a decryption operation that can be participated in only by all individuals in agreement, and m be a message digest to be signed. Then, c=E(m) and m=D(c) need to be met, m1+m2+...+mn=D(E(m1)+E(m2)+...+E(mn)), and m1×m2=D(m1×E(m2)). E E E E
[0058] Specifically, each device first performs a first encryption on the private key share stored by the device to obtain an encrypted first private key share E(pn). Then, each device broadcasts the obtained first private key share E(pn) among devices belonging to the same account. After each device obtains the first private key share of other devices, the device performs homomorphic addition encryption on the first private key share. E(p)=E(p1)+E(p2)+E...+E(pn) is obtained, that is, the second private key share. E E E
[0059] In one embodiment of the present application, the second private key share is broadcast among several devices of the account. The several devices of the account perform a second encryption operation on the received second private key share to generate a third private key share and a first signature. The several devices of the account perform a decryption operation on the third private key share to obtain a second signature. The first signature and the second signature together constitute a distributed signature, and the several distributed signatures generated by the several devices are consistent.
[0060] Specifically, each device generates a random number yn, calculates un=E(yn), vn=un× E E(p), and broadcasts the generated un, vn. After receiving the un, vn transmitted by other devices, each device calculates u=u1+ E u2+ E ... E un, v=v1+ E v2+ E ... E vn. Then, each device generates a random number kn, cn, calculates Rn=knG, wi=(kn*Eu)+ E E(cnq). and broadcasts the calculated Rn, wi. Wherein, G is a generator, q is an order of a group in which the generator is located, i is an encoding number, × E is a homomorphic multiplication operation. After receiving the Rn, wi transmitted by other devices, each device calculates w=w1+ E w2+ E ... E wn, R=R1+R2+...+Rn, r=R->x mod q. Wherein, R->x is an x coordinate of a point of R, and mod is a remainder function.
[0061] Specifically, all devices decrypt w, calculate a=D(w) mod q and z=a^(-1) mod q, and calculate b=z× E [(m×Eu)+ E (r×Ev)]. Wherein m is a message digest to be signed, and D is a decryption operation that all individuals agree to participate in. All devices decrypt b, calculate s=D(b) mod q. Finally, (r, s) is obtained, which is a signature of the message m.
[0062] The signature obtained in the embodiment of the present application must be calculated by all devices according to their respective private key shares. Any missing device cannot generate a signature. Therefore, the signature is distributedly generated by multiple devices, which improves the security of the transaction.
[0063] S104, the second device verifies the plurality of distributed signatures uploaded to the blockchain according to the distributed signature contract in the super ledger and the public key corresponding to the private key.
[0064] In an embodiment of the present application, the second device verifies the plurality of distributed signatures uploaded to the blockchain according to the distributed signature contract in the super ledger and the public key corresponding to the private key. The account corresponding to the second device is different from the account corresponding to the first device.
[0065] For example, the first device is a first transaction party, and the second device is a second transaction party. The accounts corresponding to the first device and the second device are different. The first device triggers a request for a distributed signature event. A plurality of devices under the account corresponding to the first device generate a plurality of distributed signatures according to a plurality of private key shares and upload the plurality of distributed signatures to the blockchain respectively. The second device first confirms whether the plurality of distributed signatures are the same through the distributed signature contract. In the case that the plurality of distributed signatures are the same, the second device verifies the plurality of distributed signatures according to the public key corresponding to the private key through the distributed signature contract.
[0066] In an embodiment of the present application, in the case that the distributed signature is incorrect, the first device needs to trigger the request for the distributed signature event again.
[0067] In an embodiment of the present application, a plurality of devices under an account call a submit distributed signature method in the distributed signature contract respectively. The plurality of distributed signatures are added to the corresponding submit distributed signature method respectively. The plurality of generated distributed signatures are uploaded to the blockchain through the submit distributed signature method.
[0068] Figure 2 An internal structure diagram of a super ledger signature device provided in an embodiment of the present application.
[0069] A super ledger signature device provided in an embodiment of the present application includes:
[0070] at least one processor; and
[0071] a memory in communication connection with the at least one processor; wherein
[0072] The memory stores instructions executable by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to:
[0073] The first device divides the private key corresponding to the super ledger into a plurality of different private key shares. The super ledger is a super ledger corresponding to the account to which the first device belongs. The first device is any one of a plurality of devices of the same account, and the private key share is any one of a plurality of different parts into which the private key is divided.
[0074] The first device stores the several different private key shares into several devices of the account respectively.
[0075] The first device triggers a request for a distributed signature event based on a distributed signature contract of Hyperledger.
[0076] After listening to the trigger for the request for the distributed signature event initiated by the first device, each device in the account uploads the generated distributed signature to the blockchain respectively.
[0077] The embodiments of the present application further provide a storage medium, which is a non-volatile computer readable storage medium, and stores at least one program. Each of the programs includes instructions, which, when executed by a terminal, cause the terminal to perform the method described above.
[0078] Each of the embodiments of the present application is described in a progressive manner, and the same or similar parts of each of the embodiments can be referred to each other. Each of the embodiments mainly describes the difference from other embodiments. In particular, the device embodiments are described simply because they are basically similar to the method embodiments, and the relevant parts can be referred to the part of the method embodiments.
[0079] It should be further understood that the terms "comprise", "contain" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, product or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, product or device. Without more limitation, the element defined by the statement "comprises a" does not exclude the presence of another identical element in the process, method, product or device including the element.
[0080] The above only describes the embodiments of the present application and is not intended to limit the present application. The present application can have various changes and modifications for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the scope of the claims of the present application.
Claims
1. A signature method of a hyperledger, characterized by, The method comprises: The first device divides the private key corresponding to the hyperledger into a plurality of different private key shares; wherein the hyperledger is a hyperledger corresponding to an account to which the first device belongs; the first device is any one of a plurality of devices of the same account, and the private key share is any one of a plurality of different parts into which the private key is divided; The first device stores the plurality of different private key shares in a plurality of devices of the account respectively; The first device triggers a request for a distributed signature event based on a distributed signature contract of the hyperledger; After listening to the trigger request for the distributed signature event initiated by the first device, each device in the account uploads the generated distributed signature to the blockchain respectively; The method further comprises: The plurality of devices of the account respectively encrypt their corresponding private key shares to obtain encrypted private key shares; The plurality of devices of the account are connected through a P2P network; The plurality of devices of the account broadcast the generated encrypted private key shares among the plurality of devices through the P2P network connection; wherein the encrypted private key share is a private key share obtained by encrypting the stored private key share by the plurality of devices; n-1 random numbers p1, p2,..., pn-1 are randomly selected from a set of public parameters as the first n-1 private key shares, and the nth private key share pn is calculated according to the expression pn=p-p1-p2-...-pn-1, and the n user private key shares p1, p2, p3…pn obtained are stored in the n devices of the same account; The plurality of devices of the account respectively encrypt their corresponding private key shares to obtain encrypted private key shares, which specifically comprises: The plurality of devices of the account perform a first encryption operation on the stored private key shares to obtain first private key shares; and the first private key shares are broadcast among the plurality of devices of the account; The plurality of devices of the account perform homomorphic addition encryption on the received first private key shares to obtain second private key shares; and the second private key shares are broadcast among the plurality of devices of the account; The plurality of devices of the account perform a second encryption operation on the received second private key shares to generate third private key shares and a first signature; The plurality of devices of the account perform a decryption operation on the third private key shares to obtain a second signature; Wherein the first signature and the second signature together constitute a distributed signature, and the plurality of devices generate a plurality of consistent distributed signatures respectively; Before the first device divides the private key corresponding to the hyperledger into a plurality of different private key shares, the method further comprises: The first device calls a register device address method in the distributed signature contract to add address information of a plurality of other devices belonging to the same account as the first device to the device register address method to register the plurality of other devices; wherein the register device address method is a program for device registration pre-stored in the distributed signature contract. The first device deploys an off-chain distributed signature program for other devices belonging to the same account; wherein the off-chain distributed signature program is used to listen to a request distributed signature event in the Hyperledger, and is used to submit the generated distributed signature; Before the devices in the account upload the generated distributed signature to the blockchain respectively after listening to the trigger request distributed signature event initiated by the first device, the method further comprises: The devices of the account perform identity verification on the device triggering the request distributed signature event; In the case that the device triggering the request distributed signature event and the devices belong to the same account, the devices generate a signature.
2. The method of claim 1, wherein, After uploading the generated distributed signature to the blockchain respectively, the method further comprises: A second device verifies a plurality of distributed signatures uploaded to the blockchain according to the distributed signature contract in the Hyperledger and according to the public key corresponding to the private key, wherein the account corresponding to the second device is different from the account corresponding to the first device; In the case that the distributed signature is incorrect, the first device needs to re-trigger the request distributed signature event. 3.The method of claim 1, wherein, Uploading the generated distributed signature to the blockchain respectively specifically comprises: The devices of the account respectively call a submit distributed signature method in the distributed signature contract; wherein the submit distributed signature method is a program for uploading the distributed signature to the blockchain; The distributed signature is added to the corresponding submit distributed signature method, and the generated plurality of distributed signatures are uploaded to the blockchain through the submit distributed signature method.
4. The method of claim 1, wherein, Before the first device divides the private key corresponding to the Hyperledger into a plurality of different private key shares, the method comprises: The first device obtains the private key by registering the account of the Hyperledger.
5. A signing apparatus of a hyperledger, characterized by, Comprise: At least one processor; And The memory is in communication connection with the at least one processor; wherein The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to: The first device divides the private key corresponding to the Hyperledger into a plurality of different private key shares; wherein the Hyperledger is a Hyperledger corresponding to the account to which the first device belongs; the first device is any one of a plurality of devices of the same account, and the private key share is any one of a plurality of different parts into which the private key is divided; The first device stores the plurality of different private key shares in the plurality of devices of the account respectively; The first device triggers a request distributed signature event based on the distributed signature contract of the Hyperledger; After the devices in the account listen to the trigger request distributed signature event initiated by the first device, the generated distributed signature is uploaded to the blockchain respectively; Further comprising: The plurality of devices of the account respectively encrypt their corresponding private key shares to obtain encrypted private key shares; The plurality of devices of the account are connected through P2P. The generated encrypted private key shares are broadcasted among the plurality of devices through a P2P network connection; wherein the encrypted private key shares are the private key shares encrypted by the plurality of devices respectively for the stored private key shares; The plurality of devices of the account encrypt the private key shares corresponding to the plurality of devices respectively to obtain the encrypted private key shares, and the method specifically comprises: The plurality of devices of the account perform a first encryption operation on the private key shares stored by the plurality of devices respectively to obtain first private key shares; and the first private key shares are broadcasted among the plurality of devices of the account; The plurality of devices of the account perform homomorphic addition encryption on the received first private key shares to obtain second private key shares; and the second private key shares are broadcasted among the plurality of devices of the account; The plurality of devices of the account perform a second encryption operation on the received second private key shares to generate third private key shares and a first signature; The plurality of devices of the account perform a decryption operation on the third private key shares to obtain a second signature; The first signature and the second signature jointly constitute a distributed signature, and the plurality of distributed signatures generated by the plurality of devices are consistent; Before the first device divides the private key corresponding to the hyperledger into a plurality of different private key shares, the method further comprises: The first device calls a registration device address method in the distributed signature contract to add address information of a plurality of other devices belonging to the same account as the first device to the device registration address method to register the plurality of other devices; wherein the registration device address method is a program for device registration pre-stored in the distributed signature contract; The first device deploys an off-chain distributed signature program for the plurality of other devices belonging to the same account; wherein the off-chain distributed signature program is used to listen to a request distributed signature event in the hyperledger and is used to submit the generated distributed signature; Before each device in the account uploads the generated distributed signature to the blockchain after listening to the trigger request distributed signature event initiated by the first device, the method further comprises: The plurality of devices of the account perform identity verification on the device triggering the request distributed signature event; In the case that the device triggering the request distributed signature event and the plurality of devices belong to the same account, the plurality of devices generate a signature.
6. A storage medium, characterized by The storage medium is a non-volatile computer readable storage medium, and the non-volatile computer readable storage medium stores at least one program, each of the programs includes instructions, and the instructions make the terminal execute the method according to any one of claims 1-4 when executed by the terminal.
Citation Information
Patent Citations
Collaborative generation method and system of digital signatures based on homomorphic encryption
CN107872322A
Blockchain encryption ledger based on secret sharing
CN108809652A
Efficient threshold distributed elliptic curve key generation and signature method and system
US10630477B1