Computer-implemented systems and methods for transferring access to digital resources
By using the private key puzzle of elliptic curve cryptography on the blockchain, the problems of security and flexibility in cross-blockchain resource exchange are solved, and atomic exchange that does not rely on public hash functions is realized, improving security and efficiency.
Patent Information
- Application Number
- CN201980064210.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2018-09-28
- Filing Date
- 2019-09-19
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2039-09-19
AI Technical Summary
When the existing technology exchanges resources on the blockchain, it is necessary to share a common hash function, which poses security vulnerabilities and malicious intervention risks. Atomic exchanges across different blockchains need to share the same hash function, which limits the flexibility and security of the exchange.
By using private key puzzles of elliptic curve cryptography, resource access or control is performed across blockchain networks, and the signature information in blockchain transactions is used to calculate the private key without relying on public hash functions to realize atomic exchange.
Improves the security and efficiency of resource exchange, allows atomic exchange across incompatible blockchains, reduces storage requirements, and enhances control over resource access.
Smart Images

Figure CN112789825B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to securely transferring access to or control of resources, and more particularly to atomically transferring such access or control via cryptographic keys transmitted using one or more blockchain transactions. Background Art
[0002] In this document, we use the term "blockchain" to include all forms of electronic computer-based distributed ledgers. These include consensus-based blockchain and transaction chain technologies, permissioned and unpermissioned ledgers, shared ledgers, and their variants. The term "user" can refer to a human or a processor-based resource in this document.
[0003] A blockchain is a peer-to-peer electronic ledger implemented as a computer-based decentralized distributed system composed of blocks, which in turn are composed of transactions. Each transaction is a data structure that encodes the transfer of control of digital assets between participants in the blockchain system and includes at least one input and at least one output. Each block contains the hash value of the previous block, so the blocks are linked together to create a permanent, immutable record of all transactions that have been written to the blockchain since its inception. Transactions contain small programs called scripts embedded in their inputs and outputs that specify how and by whom the outputs of the transaction can be accessed.
[0004] In order to write a transaction to the blockchain, it must be "verified". Network nodes perform work to ensure that each transaction is valid, and invalid transactions are rejected by the network. The software client installed on the node performs this verification work on unspent transaction outputs (UTXOs) by executing their locking scripts and unlocking scripts. If the execution of the locking script and the unlocking script is evaluated as TRUE, the transaction is valid and the transaction is written to the blockchain. Therefore, in order to write a transaction to the blockchain, it must: i) be verified by the first node receiving the transaction - if the transaction is verified, the node relays it to other nodes in the network; ii) add the transaction to a new block; and iii) the transaction is added to the public ledger of past transactions.
[0005] One area of current research is the use of blockchains to implement "smart contracts". These are computer programs designed to automatically execute the terms of a machine-readable contract or agreement. Unlike conventional contracts written in natural language, smart contracts are machine-executable programs that include rules capable of processing inputs to produce results, which can then prompt actions to be taken based on those results.
[0006] Another area related to blockchain is the use of "tokens" to represent real - world entities and transfer real - world entities via the blockchain. Potentially sensitive or secret entries can be represented by tokens with no discernible meaning or value. Thus, the tokens serve as identifiers that allow referencing real - world entries from the blockchain.
[0007] The concept of atomic swaps has been discussed previously. The exchange between parties is "atomic" in the sense that all participants either receive the resources they expect or none of the participants receive the resources they expect. Atomic swap systems use hash time - locked smart contracts so that parties must deliver the currency to be exchanged within a specified time or the transaction will be cancelled. This maintains atomicity, where either the exchange takes place or no currency is exchanged - https: / / en.wikipedia.org / wiki / Atomic_swap.
[0008] Thus, atomic swaps provide enhanced security in transfers via the blockchain because removing the need for a trusted third - party eliminates the risk of exploitation and malicious interference, where many security breaches or "hacks" have occurred. Summary of the Invention
[0009] Accordingly, it is desirable to provide a cryptographically enhanced resource - exchange method that atomically exchanges resources with the distrust and immutability provided by blockchain technology and enhances the security of exchanges conducted on a network implemented by the blockchain.
[0010] Now such an improved solution has been devised.
[0011] According to the present disclosure, a computer - implemented method can be provided. It can be described as a method for transferring control of resources. It can control the transfer of resources across a blockchain network or via a blockchain network. Additionally or alternatively, it can be described as a secure transfer method. Additionally or alternatively, it can be described as a secure method for controlling when and / or by whom access to the controlled resources is granted. The resources can be resources stored on or referenced from the blockchain, such as part of a tokenized entry / asset / entity.
[0012] The method may include the following steps: providing a redeemable first blockchain transaction by providing at least one data item to a first blockchain transaction to enable access to a first resource, wherein the data item is determinable only by a controller of both a revealable value and a secret value; and providing the revealable value to the controller of the secret value to enable the controller to determine the data item. In the context of the present disclosure, "enabling access" includes, but is not limited to, transferring control of a resource, or enabling access to a document, an online resource, or a secure access code.
[0013] The method enables the use of one or more blockchains to access or control a resource to be securely transferred without the protocols of those blockchains sharing one or more common hash functions, thereby providing the advantage that an increase in the number of blockchains across which the transfer can be achieved. Thus, while increasing the versatility of the transfer, the security and efficiency of the transfer of such control or access are maintained. The method also allows transfers across other incompatible network / blockchain protocols.
[0014] The data item may include a first private key of a first cryptographic key pair.
[0015] The first blockchain transaction may also be required to provide a second private key of a second cryptographic key pair that can be redeemed, wherein the second cryptographic key pair is associated with an intended recipient of the first resource.
[0016] This provides the advantage of increasing the security of the method, which is achieved by preventing any actor who does not wish to know the first private key from redeeming the first transaction.
[0017] The first private key may be a deterministic private key of a deterministic cryptographic key pair, wherein the deterministic public key of the deterministic cryptographic key pair is derived using the first public key of the first cryptographic key pair and the second public key of the second cryptographic key pair.
[0018] By providing a degree of obfuscation, this further enhances the security of the method so that an undesired revelation of the first private key does not compromise the first transaction while still maintaining the ability of the intended recipient to redeem the first transaction.
[0019] The step of providing the revealable value to the controller may include: providing a redeemable second blockchain transaction by providing at least the data item to a second blockchain transaction to enable access to a second resource, wherein redemption of the second blockchain transaction causes the revealable value to be provided to the controller; and redeeming the second blockchain transaction.
[0020] This enables atomic swapping of resource access or control without the use of a hash function, thereby providing a mechanism for performing secure and simultaneous digital swaps without restricting those blockchain protocols that share a common hash function.
[0021] The redemption of any of the above blockchain transactions may include computing a cryptographic signature corresponding to the data item and comparing the value stored in the transaction with at least a portion of the computed signature.
[0022] This enables a large portion of the cryptographic algorithms to be performed off-block, thereby distributing the necessary tasks to maintain the cryptographic security level from the blockchain and providing the associated advantages of reducing the size of the first transaction (and thus storage requirements), and improving the efficiency of the method.
[0023] The secret value may be a temporary key used in the digital signature process.
[0024] The present disclosure also provides a system including: a processor; and a memory including executable instructions that, when executed by the processor, cause the system to perform any of the embodiments of the computer-implemented methods described herein.
[0025] The present disclosure also provides a non-transitory computer-readable storage medium having stored thereon executable instructions that, when executed by a processor of a computer system, cause the computer system to perform at least an embodiment of the computer-implemented methods described herein. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] These and other aspects of the present disclosure will become apparent from and be elucidated with reference to the embodiments described herein. Embodiments of the present disclosure will now be described, by way of example only, and with reference to the accompanying drawings, in which:
[0027] Figure 1 A distinguishable coding rule table of the prior art is shown;
[0028] Figure 2 A table including a script for extracting a portion of a signature is shown;
[0029] Figure 3 A flowchart including steps of an embodiment of the present disclosure is shown;
[0030] Figure 4 A flowchart including steps of an embodiment of the present disclosure is shown;
[0031] Figure 5 A flowchart including steps of an embodiment of the present disclosure is shown; and
[0032] Figure 6It is a schematic diagram showing a computing environment in which various embodiments can be implemented. Detailed implementation
[0033] A typical hash function (e.g., SHA-256) takes a data structure X and outputs a 256-bit number It is a one-way deterministic function
[0034]
[0035] A hash function can be used to create a hash puzzle. This is the function <SolveH(X)>, which evaluates to TRUE if and only if the pre-image X is provided in the input of the function. That is
[0036] <x><SolveH(X)> = TRUE.
[0037] For SHA-256, such a function is given in the script by the following formula:
[0038] <SolveH(X)> = OP_HASH256<H(X)>OP_EQUALVERIFY.
[0039] The hash puzzle can be used in the script of a blockchain transaction (e.g., the redemption script) to ensure that if the transaction is redeemed, the preimage x must be exposed in the input of the redemption script and thus the preimage X is visible on the blockchain.
[0040] Input Redemption script <x> < / x> <SolveH(X)>
[0041] Under the ECDSA protocol, the signature of the private key S1 and the message hash H(m) are created in the following way (note that everyone knows the message hash, but only the person who signs the message knows the private key):
[0042] The first step is to generate a random number called the ephemeral key From which the value r is derived, where r is the ephemeral key multiplied by the x coordinate of the generator point
[0043] r = R x ,(R x ,R y ) = k·G.
[0044] The value r forms half of the signature. The second half s is defined by the following equation:
[0045] s = k -1 (H(m) + S1*r) mod n.
[0046] The combination (r, s) = Sig P1 is the ECDSA signature.
[0047] An important feature of ECDSA is that if the ephemeral key k is known, the private key can be calculated as follows:
[0048] S1 = r -1 (s*k - H(m)) mod n.
[0049] The data structure of the signature (r, s) contains the integer values of r and s concatenated with some additional encoded data.
[0050] According to the Distinguished Encoding Rules (DER) [S. Blake-Wilson, D. Brown, P. Lambert, Use of Elliptic Curve Cryptography (ECC) Algorithms in Cryptographic Message Syntax (CMS), Network Working Group (2002); https: / / tools.ietf.org / html / rfc3278], the specific encoding of the data structure of an ECDSA signature (r, s) is given by Figure 1 the table shown in
[0051] (note that pseudo r and s data values are used). Figure 1 Refer to
[0052] and note that the last byte representing the sighash type is not in standard DER encoding but is used in the signature encoding. The 4th byte of the signature represents the length of r. If the leading bit in the binary representation of r is 0, the length of r is 32 bytes; if the leading bit is 1, the length of r is 33 bytes, in which case an additional zero-valued byte is added to the byte string. The 5th byte to the 36th or 37th byte of the signature represents the value or r itself.
[0052] A method for creating a private key puzzle will now be described.
[0053] A private key puzzle is a function in the redeem script that evaluates to true if an input is provided that enables the calculation of the private key S1 for a given public key P1.
[0054] This form of puzzle allows the exploitation of the algebraic properties of an Elliptic Curve Cryptography (ECC) public / private key pair in the implementation of resource access and control. If the sum of two public keys is calculated, the corresponding private key will be the sum of the individual private keys:
[0055] P1 + P2 = (S1 + S2)·G.
[0056] Compare this with a hash function: if the sum of the hashes of two values is calculated, the corresponding pre-images are generally not the sum of the individual pre-images:
[0057] H(X1 + X2) ≠ H(X1) + H(X2).
[0058] There are hash functions (known as homomorphic hash functions) for which the sum of the hash values of the individual pre-images is equal to the hash value of the sum of the pre-images, but these are generally not feasible to implement. Additionally, public / private key pairs allow for the encryption / decryption of data and the signing of messages using the Elliptic Curve Digital Signature Algorithm (ECDSA).
[0059] Examples of implementing private key puzzles in atomic swaps are disclosed below. These examples allow users of the methods disclosed herein to perform cross-chain exchanges on blockchains that do not share a common hash function. These examples include transferring control or access to resources controlled by a public / private key pair.
[0060] Throughout the application, the private key puzzles are formulated based on ECC key pairs and the ECDSA protocol. However, the present disclosure is not limited to these standards. For example, the method is also applicable to Schnorr signatures and RSA key pairs with the DSA protocol.
[0061] As described above, the private key puzzle is a function <solvep1>, if this function acts on the corresponding private key <s1>, the function will evaluate to true. That is:
[0062] <s1> <solvep1>= TRUE。
[0063] Such a function does not currently exist. Include in the trading redemption script <solvep1>It will be ensured that, for a redemption transaction, the input provided to the redemption script must include the corresponding private key S1, which means that S1 is exposed to the public on the blockchain. However, at least in the case where the redemption script is the redemption script of a blockchain transaction on the blockchain, such a function will require a particularly large number of operators that will prevent the transaction from being constructed and used. This issue will be described in more detail below.
[0064] Assume there is an operator OP_ECMULT that performs elliptic curve point multiplication. This means multiplying a point on the elliptic curve (e.g., the generator point G) by a positive integer (e.g., ). That is:
[0065] <s1> <g>OP_ECMULT = <p1>。
[0066] In this case, the private key puzzle will be given by:
[0067] <solvep1> = <s1> <g>OP_ECMULT <p1>OP_EQUALVERIFY。
[0068] However, currently, there is no such elliptic curve operator in the script.
[0069] After some previously retried opcodes (such as OP_MOD) were restored in the May 2018 fork, technically, all the operators required to perform elliptic curve multiplication in the script exist, that is, OP_ECMULT is constructed using other operators. However, for practical reasons, this is not possible.
[0070] Such a function would require at least 256 iterations, each iteration containing multiple lines of complex operations. Most notably, each iteration would require applying the extended Euclidean algorithm to find the modular inverse. Therefore, the size of the required script would far exceed the 201 opcode or 10KB limit.
[0071] In contrast, the method introduced below uses only a few lines of opcodes.
[0072] Embodiments of a method for creating and utilizing a private key puzzle are disclosed below, which includes calculating the private key outside the block. In an embodiment, the private key itself is not exposed in the input of the redeem script, but rather the components of the signature are exposed.
[0073] The key idea is to require the unlocking script to contain a signature related to a specific ephemeral key. Then, anyone who knows the ephemeral key can calculate the corresponding private key based on the signature.
[0074] The embodiments described with reference to the script do not use any non-standard script operations.
[0075] Construct the function <SolveP1,r0>, where P1 is the public key and r0 is derived from a specific ephemeral key k0. If and only if it is for the input <SigP1,r0> <p1>When operating, this function evaluates to true, where <SigP1,r0> represents the signature of P1 using a specific ephemeral key k0. Since a signature with a known ephemeral key exposes the corresponding private key, once <SigP1,r0> is made public, anyone who knows k0 can compute the private key.
[0076] Reference Figure 2 , a script for extracting the r part of the signature is disclosed. According to the DER encoding of the signature given above, to extract the r part, we need to split the signature from the 5th byte up to the 36th or 37th byte, depending on the value of the 4th byte. This is achieved by the script:
[0077] OP_3OP_SPLIT OP_NIP OP_1OP_SPLIT OP_SWAP OP_SPLIT OP_DROP.
[0078] Consider the public key P1. As mentioned above, a method for creating a locking script such that the corresponding unlocking script exposes sufficient information for the controller of the ephemeral key to determine the private key of P1 is disclosed.
[0079] The method includes forcing the unlocking script to contain the signature of P1 using a specific ephemeral key represented as k0. Anyone who knows the ephemeral key can compute the corresponding private key represented as S1 from the signature. The users of the method agree to use the value of k0. The users can communicate this value to each other using a known method with appropriate security.
[0080] As mentioned above, an ECDSA signature consists of two components, namely: SigP1 = (r, s), where r is directly related to the ephemeral key k0, and r can be computed from the ephemeral key k0.
[0081] The value of r corresponding to the ephemeral key k0 is r = R x is computed (out-of-block) by the following equation:
[0082] (R x , R y ) = k0 · G.
[0083] Then a redeem script is created that requires the signature of P1 using a specific ephemeral key k0 as input.
[0084]
[0085] An example of a redeem script compatible with the blockchain is given below:
[0086] Input Redemption script <![CDATA[<SigP1,r0> <p1> ]]> < / p1> <![CDATA[<SolveP1,r0>]]>
[0087] Among them, the script of the key puzzle <SolveP1, r0> =
[0088]
[0089] In the above table, the first row places the public key P1 on the alt-stack and copies the signature. The second row checks whether the correct ephemeral key is used. The third row retrieves the public key from the alt-stack and checks whether the signature is valid. The script operations used above (i.e., OP_DUP, OP_TOALTSTACK, and OP_FROMALTSTACK) are not strict requirements, and for example, if the input variables are copied and reordered, these script operations can be dropped.
[0090] Note that there are also alternative ways to formulate the private key puzzle in the script. In particular, the OP_CAT operation can be used instead of OP_SPLIT. In this case, the input of the redemption script will be the partial signature containing only the s component (which will be calculated using the predetermined ephemeral key k0 and the private key S1). Then, the redemption script concatenates the predetermined value of r with the partial signature to produce the complete signature (r, s). By construction, this signature will have the desired r. Then all that remains is to perform the standard check operations.
[0091] Atomic swap refers to two transactions, one from Alice to Bob and the other from Bob to Alice. Atomic swap ensures that either both transactions are redeemable or neither is. The mechanism that allows this to happen is the hash puzzle in the redemption script. The advantages of atomic swap include:
[0092] · Resources on different blockchains can be swapped.
[0093] · Tokens on the same blockchain can be swapped.
[0094] Note that currently, atomic swaps across different blockchains require the two blockchains to share a common hash function in their script languages. The advantage of the present disclosure is that blockchains no longer require a common hash function, thus enabling the transfer of control or access to resources across a greater variety of blockchains. Additionally, by making atomic swaps based on digital signatures, it is possible to verify the consistency of the digital signature with the corresponding public key, thereby enhancing the security of the swap.
[0095] A known method is described below to provide the background for the subsequent description of the embodiments of the present disclosure.
[0096] Let P A and P B represent the ECDSA public keys of Alice and Bob, respectively.
[0097] 1. Alice selects a secret known only to herself (where n is the order of the elliptic curve generator point G).
[0098] 2. Alice transfers the funds locked by the redemption script to Bob
[0099] <CheckSig P B ><Solve H(A0)>
[0100] At this stage, Bob cannot spend the funds because he does not know the preimage of H(A0).
[0101] 3. Bob transfers the funds locked by the redemption script to Alice
[0102] <CheckSig P A ><Solve H(A0)>
[0103] 4. Since Alice knows A0, she can spend her funds. This reveals A0 on the blockchain as the input to Alice's redemption script.
[0104] Bob now knows A0 and can spend his funds.
[0105] As previously mentioned, the private key puzzles of the present disclosure can be used to achieve atomic swaps between users of one or more blockchains without the need for a shared hash function. The method for achieving such an atomic swap is described below.
[0106] Instead of using hash puzzles in atomic swaps, the private key puzzles disclosed above are used. This preserves all the functionality of known atomic swaps while allowing for advantageous generalisations, which include:
[0107] ● Atomic swaps across blockchains that do not share a common hash function; and
[0108] ● Atomic swaps for control or access to resources controlled by a public key / private key pair.
[0109] As described above, when using private key puzzles instead of hash puzzles, when Alice redeems a transaction, she does not reveal the preimage of the hash, but rather enables the determination of the private key for a known public key. The following table shows this comparison:
[0110] Mechanism Standard atomic swap <![CDATA[Hash Puzzle <SolveH(A0)>]]> Generalized atomic swap <![CDATA[Private key puzzle <SolveP1,r0>]]>
[0111] Reference Figure 3 , the embodiments of the present disclosure are described according to the following method steps:
[0112] 1. (110) Alice selects a temporary key k0 and sends it to Bob via an appropriate secure channel. Alternatively, Alice and Bob can reach a consensus on k0.
[0113] 2. (120) Alice selects a private key that only she knows She calculates the corresponding public key P1 = S1·G.
[0114] 3. (130) Alice creates a transaction TxA with a redemption script
[0115] <CheckSig P B ><Solve P1,r0>
[0116] where P B is Bob's public key, and <Solve P1,r0> is the private key puzzle introduced above. At this stage, Bob cannot redeem the transaction because he does not know the private key corresponding to the public key P1, i.e., S1. Alice submits TxA to the blockchain.
[0117] 4. (140) Bob creates a transaction TxB with a redemption script
[0118] <CheckSig P A ><Solve P1,r0>
[0119] where P A is Alice's public key. Bob submits TxB to the blockchain.
[0120] 5. Since Alice knows S1, she can redeem TxB. As input to the redemption script of TxB, Alice must provide a signature for P1 using a specific temporary key k0. Redeeming TxB by submitting a redemption transaction presenting an unlocking script to the blockchain will necessarily expose the value of s. Given that Bob already knows the value of the temporary key k0, this disclosure of s allows Bob to calculate the private key S1. (160) There may or may not be time constraints imposed on the redemption of TxA and TxB using a time-locking function, and if the time expires, the time-locking function is configured to return control of TxA and TxB to Alice and Bob by means of Alice and Bob submitting appropriate refund transactions to the blockchain.
[0121] 6. (170) If Alice redeems TxB, then (180) Bob can calculate S1, and (190) Bob can redeem Tx1 by providing a signature corresponding to S1 to it via the unlocking script of the redemption transaction.
[0122] Since this method does not rely on hash puzzles, it can be used for atomic swaps across blockchains that do not share a common hash function in their scripting languages. All that is required is that the scripting language includes sufficient functionality to create private key puzzles. This is a less stringent set of requirements.
[0123] Reference Figure 4 , in another embodiment, Alice and Bob each choose their own ephemeral keys k A and k B as well as their own private keys X A and X B . They exchange their ephemeral keys in a manner similar to how they communicated the ephemeral key k0 of the asynchronous embodiment above. Then, Alice and Bob can compute the signature components r A and r B , where r A is the x - component of the point k A ·G, and r B is the x - component of the point k B ·G. The remaining signature components of the signature computed using X A and X B are denoted as s A and s B respectively, such that Sig X A =(r A ,s A ), and Sig k B =(r B ,s B ). Note that in this embodiment, k A and k B can be the same or can be different, i.e., a common k0 can alternatively be used.
[0124] This embodiment proceeds according to the following steps:
[0125] 1. (210A, 210B) Alice and Bob choose their own ephemeral keys k A and k B , and communicate them to each other.
[0126] 2. (220A) Alice chooses a private key known only to herself She computes the corresponding public key Y A =X A ·G.
[0127] 3. (230) Alice creates a transaction Tx1A with a redeem script
[0128] <CheckSig P B ><Solve Y A ,Y B , r A , r B >
[0129] Among them, P B is Bob's public key, and <Solve Y A , Y B , r A , r B > is a private key puzzle that requests a signature corresponding to the private keys X A and X B . At this stage, Bob cannot redeem the transaction because he does not know the private key corresponding to the public key Y A (i.e., X A ).
[0130] 4. (220B) Bob selects a private key known only to himself He calculates the corresponding public key Y B = X B ·G.
[0131] 5. (240) Bob creates a transaction Tx1B with a redemption script
[0132] <CheckSig P A ><Solve Y A , Y B , r A , r B >
[0133] Among them, P A is Alice's public key.
[0134] Note that the key puzzle parts of the scripts of Tx1A and Tx1B are the same. The key puzzle <Solve Y A , Y B , r A , r B > requests the presentation of signatures corresponding to the private keys X A and X B , that is, the signatures (r A , s A ) and (r B , s B ).
[0135] (250) At this time, Alice does not know X B , nor can she calculate X B , because she does not know s B . Similarly, Bob also does not know X A or s A 。Therefore, neither Alice nor Bob has enough information to redeem Tx1A or Tx1B. Both Alice and Bob can act honestly by communicating their respective signature components s A / s B or private key X A / X B to each other, or only one of them can act honestly, or neither of them can act honestly. Therefore, one of the following results may occur:
[0136] 6A.1) Suppose Alice sends s A or X A to Bob, and Bob sends s B or X A to Alice (i.e., both parties act honestly). (295) Then, both Alice and Bob have enough information to provide signatures to the redemption scripts of transactions Tx1A and Tx1B to solve the key puzzles in the redemption scripts. Therefore, Tx1A and Tx1B can be redeemed by Bob and Alice respectively by submitting spending transactions presenting the corresponding unlocking scripts to Tx1A and Tx1B.
[0137] 6B.2) Suppose only Alice acts honestly by sending s A or X A to Bob, while Bob acts dishonestly by not sending the correct s B or X B to Alice or not sending anything at all. (270) Then, Bob can redeem Tx1A by submitting a redemption transaction (providing a signature corresponding to X A ) in the unlocking script of the redemption transaction to solve the key puzzle contained in the redemption script of Tx1A. Once Bob submits a redemption transaction containing an unlocking script arranged to redeem Tx1A to the blockchain, the signature (r B , s B ) becomes publicly available. (280) This enables Alice to know the value of s B because she knows the ephemeral key k B , enabling her to calculate the key X B , and thus having enough information to redeem Tx1B. (290) Then, Alice submits a redemption transaction providing a signature corresponding to X B in its unlocking script to solve the key puzzle contained in the redemption script of Tx1B.
[0138] 6C.3) Suppose neither Alice nor Bob sends s A / s B or X A / X B (260). In this case, transactions Tx1A and Tx1B remain non - redeemable until the time lock (if active) expires at which time control of the transactions is returned to their respective owners by means of the respective owners submitting appropriate redemption transactions to the blockchain.
[0139] The symmetric configuration of the transactions as described in the above embodiments enables the use of transactions configured with key puzzles for synchronous atomic swaps. This enables both transactions Tx1A and Tx1B to transfer access or control of their respective resources to the other party simultaneously, rather than one party having to wait for a mined block to reveal the information required for the redemption transaction that depends on the said necessary information.
[0140] Now, reference will be made to Figure 5 describe embodiments of the present disclosure that enable the atomic swap of access or control of one or more resources.
[0141] In this embodiment, Alice controls access to a resource via an ECC public - key / secret - key pair. The resource can be access to a web application, a rental car, or an encrypted document, or control of an Internet of Things smart device (e.g., a webcam or a door lock). A method will be described below that enables Bob to obtain access to the resource from Alice using a blockchain protocol. This swap is atomic.
[0142] This method ensures that when the atomic swap is completed, the information required to compute the secret key that controls the resource is exposed by the controller of the ephemeral key. This eliminates the need to trust the party that grants access to the controlled resource.
[0143] The method includes the following steps:
[0144] 1. (310) Alice selects an ephemeral key k0 and communicates it to Bob.
[0145] 2. (320) Alice selects a secret key known only to herself She computes the corresponding public key P1 = S1·G. This public key controls access to the resource and is publicly broadcast.
[0146] 3. (325) Alice uses Bob's public key P B to compute the deterministic public key P′ = P1 + P B = P1 + S B ·G, and (330) enables the owner of the secret key S′ = S B + S1 to obtain access to the resource. For example, this can be achieved by creating a transaction Tx′ that sends a certain amount of the resource to the address P′ or by encrypting a document with the public key P′ and then broadcasting the document on an open forum.
[0147] 4. (340) Bob submits transaction TxB locked using a redemption script
[0148] <CheckSig P A ><Solve P1,r0>
[0149] 5. (370) Since Alice knows S1, she is able to redeem TxB. As described above, this allows Bob to calculate S1 from the information provided in the input of Alice's redemption script. (360) There may or may not be a time constraint imposed on the redemption of Tx' and TxB using a time-locking function, and if the time expires, the time-locking function is configured to return control of Tx' and TxB to Alice and Bob.
[0150] 6. (370) Alice redeems transaction TxB by submitting a redemption transaction that provides a signature corresponding to S1 in the unlocking script, thereby revealing the s part of the signature to Bob.
[0151] 7. (380) Bob now calculates S1 and is therefore able to (385) calculate the private key S' of P' = S B + S1. Thus, he gains access to the resources controlled by P'.
[0152] Note that even if the private key S1 is exposed to the public on the blockchain or elsewhere, only Bob can access or control the resources locked at P'. This is because the resources are locked by the combination of S1 and Bob's private key. In this sense, S1 acts as a deterministic key.
[0153] In this example, it can be seen that there is no longer a requirement that the resources purchased by Bob contain certain operations in its scripting language. It is only required that Bob pay a fee for the collection of resources and use ECDSA signatures to control the transaction.
[0154] To prevent Bob's resources from being locked by Alice forever, a time-locked return can be introduced into the method. This is a transaction from Alice to Bob that returns the resources to Bob after a certain relative time (e.g., 24 hours) has passed since his first transaction to Alice.
[0155] Similarly, after a certain amount of time has passed, Alice can return access to her controlled resources to herself.
[0156] If the exchange is not completed, after a certain amount of time, it may not be necessary or practical for Alice to return control of the resources to herself. For example, if the resources are an encrypted document to which Bob has been granted access, there is no disadvantage for Alice to leave the document encrypted with the key P' indefinitely.
[0157] Now turning to Figure 6 , an illustrative simplified block diagram of a computing device 2600 that can be used to practice at least one embodiment of the present disclosure is provided. In various embodiments, the computing device 2600 can be used to implement any of the systems shown and described above. For example, the computing device 2600 can be configured to function as a data server, a network server, a portable computing device, a personal computer, or any electronic computing device. As Figure 6 shown, the computing device 2600 can include one or more processors (collectively 2602) having one or more levels of cache memory and a memory controller, which can be configured to communicate with a storage subsystem 2606 including a main memory 2608 and a permanent storage device 2610. As shown, the main memory 2608 can include dynamic random access memory (DRAM) 2618 and read-only memory (ROM) 2620. The storage subsystem 2606 and the cache memory 2602 can be used to store information, such as details associated with transactions and blocks described in the present disclosure. The (one or more) processors 2602 can be used to provide the steps or functions of any embodiment described in the present disclosure.
[0158] The (one or more) processors 2602 can also communicate with one or more user interface input devices 2612, one or more user interface output devices 2614, and a network interface subsystem 2616.
[0159] The bus subsystem 2604 can provide a mechanism for enabling the various components and subsystems of the computing device 2600 to communicate with each other as expected. Although the bus subsystem 2604 is schematically shown as a single bus, alternative embodiments of the bus subsystem can utilize multiple buses.
[0160] The network interface subsystem 2616 can provide an interface to other computing devices and networks. The network interface subsystem 2616 can function as an interface for receiving data from other systems different from the computing device 2600 and transmitting data to other systems. For example, the network interface subsystem 2616 can enable a data technician to connect a device to a network so that the data technician can transmit data to and receive data from the device while being located at a remote location (e.g., a data center).
[0161] The user interface input device 2612 can include one or more user input devices, such as a keyboard; a pointing device such as an integrated mouse, trackball, touchpad, or graphics tablet; a scanner; a barcode scanner; a touch screen incorporated into a display; an audio input device such as a voice recognition system, a microphone; and other types of input devices. Generally, the use of the term "input device" is intended to include all possible types of devices and mechanisms for inputting information into the computing device 2600.
[0162] One or more user interface output devices 2614 may include a display subsystem, a printer, or a non-visual display such as an audio output device. The display subsystem may be a cathode ray tube (CRT), a flat panel device such as a liquid crystal display (LCD), a light emitting diode (LED) display, or a projector, or other display device. Generally, the use of the term "output device" is intended to include all possible types of devices and mechanisms for outputting information from the computing device 2600. One or more user interface output devices 2614 may be used, for example, to present a user interface to facilitate interaction of a user with an application that performs the described processes and variations thereof, when such interaction is appropriate.
[0163] The storage subsystem 2606 may provide a computer-readable storage medium for storing basic programming and data constructs that may provide the functionality of at least one embodiment of the present disclosure. When executed by one or more processors, application programs (programs, code modules, instructions) may provide the functionality of one or more embodiments of the present disclosure and may be stored in the storage subsystem 2606. These application program modules or instructions may be executed by one or more processors 2602. Additionally, the storage subsystem 2606 may provide a repository for storing data used in accordance with the present disclosure. For example, the main memory 2608 and the cache memory 2602 may provide volatile storage for programs and data. The permanent storage device 2610 may provide permanent (non-volatile) storage for programs and data and may include flash memory, one or more solid state drives, one or more magnetic hard disk drives, one or more floppy disk drives with associated removable media, one or more optical drives (e.g., CD-ROM or DVD or Blue-Ray) with associated removable media, and other similar storage media. Such programs and data may include programs for performing the steps of one or more embodiments as described in the present disclosure and data associated with the transactions and blocks described in the present disclosure.
[0164] The computing device 2600 may be of various types, including a portable computer device, a tablet computer, a workstation, or any other device described below. Additionally, the computing device 2600 may include another device that may be connected to the computing device 2600 through one or more ports (e.g., USB, headphone jack, Lightning connector, etc.). Devices that may be connected to the computing device 2600 may include a plurality of ports configured to accept fiber optic connectors. Thus, the device may be configured to convert an optical signal into an electrical signal that may be transmitted through a port connecting the device to the computing device 2600 for processing. Due to the ever-changing nature of computers and networks, Figure 6 The description of the computing device 2600 depicted is only intended as a specific example for the purpose of illustrating a preferred embodiment of the device. Many other configurations with more or fewer components than the Figure 6 system depicted are possible.
[0165] It should be noted that the above embodiments illustrate rather than limit the present disclosure, and those skilled in the art will be able to design many alternative embodiments. In the claims, any reference signs in parentheses shall not be construed as limiting the claims. The word "comprising" etc. does not exclude the presence of elements or steps other than those listed in any claim or the entire specification. In this specification, "comprise" means "include or consist of", and "comprising" means "including or consisting of". The singular form of an element does not exclude the plural form of such element, and vice versa. The present disclosure can be implemented by hardware including several different elements and by a suitably programmed computer. In a device claim enumerating several devices, several of these devices can be implemented by one and the same piece of hardware. The fact that certain means are recited in mutually different dependent claims does not indicate that a combination of these means cannot be used advantageously. < / g> < / s1> < / solvep1> < / g> < / s1> < / s1> < / x>
Claims
1. A computer-implemented method, the method comprising the steps of: generating a first signature from a data item and a first secret value, the first signature comprising a first component and a second component, wherein the data item is the first private key of a first cryptographic key pair and can only be determined by a controller of at least the second component and the first secret value, and the secret value is a temporary key for generating the signature; providing a first redeemable blockchain transaction by providing at least the second component of the first signature to a first blockchain transaction such that access to a first resource is enabled; and providing a second redeemable blockchain transaction by providing at least the second component of the first signature to a second blockchain transaction such that access to a second resource is enabled, wherein redemption of the second blockchain transaction causes the second component to be provided to the controller.
2. The method according to claim 1, wherein The method further comprises: generating a second signature from a second private key of a second cryptographic key pair and a second secret value, the second signature comprising a third component and a fourth component; and providing the second component to the controller, wherein the first blockchain transaction further requires the provision of the second signature to be redeemable, and wherein the second cryptographic key pair is associated with an intended recipient of the first resource.
3. The method according to claim 1, wherein, The data item comprises a deterministic private key of a deterministic cryptographic key pair, wherein the deterministic public key of the deterministic cryptographic key pair is derived using the first public key of the first cryptographic key pair and the second public key of the second cryptographic key pair.
4. The method according to any of the preceding claims, further comprising: redeeming the second blockchain transaction.
5. The method according to any one of the preceding claims, wherein, Redeeming the first blockchain transaction or the second blockchain transaction comprises: comparing a value stored in the transaction with at least a portion of the first signature.
6. A computer-implemented system, comprising: a processor; and a memory comprising executable instructions which, upon execution by the processor, cause the system to perform the method according to any of the preceding claims.
7. A non-transitory computer-readable storage medium having stored thereon executable instructions which, when executed by a processor of a computer system, cause the computer system to perform the method according to any of claims 1 to 5.
Citation Information
Patent Citations
Blockchain-implemented method and system
TW201810151A