A consortium chain system based on identification cryptography

By adopting the technology based on the identification cryptographic system in the alliance chain system, the problem of excessive key management and storage burden in the existing technology is solved, and more efficient system operation and secure permission control are achieved.

CN113987546BActive Publication Date: 2025-05-23SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111304732.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-05
Publication Date
2025-05-23
Estimated Expiration
2041-11-05

AI Technical Summary

Technical Problem

The existing hyperledger system relies on a complex public key certificate cryptography system, which leads to excessive burden of key management and storage, affecting the operating efficiency of the system.

Method used

A consortium chain system based on the identification cryptography system is adopted to generate the master key and private key through KGC, and a signature verification algorithm for identification cryptography and encrypted communication of the negotiation key are used to reduce the storage and management requirements of the key.

Benefits of technology

It effectively reduces the system's key storage and management burden, improves the system's operating efficiency, and achieves secure permission control through lightweight main public keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113987546B_ABST
    Figure CN113987546B_ABST
Patent Text Reader

Abstract

The present invention discloses a consortium chain system based on an identification password system, and relates to the field of blockchain technology. The implementation content thereof includes: (1) key generation stage: running a master key generation algorithm and a private key extraction algorithm through KGC to generate a master private key, a master public key, and private keys of a server and a client; (2) signature verification stage: locally searching and inputting the corresponding master public key, the signer identifier, the message to be signed, and the signature, and verifying whether the output signature is valid; (3) secure communication stage: the communicating parties use the negotiated valid symmetric key to encrypt the sent and received messages; (4) transaction submission stage: using the method of step (2) to verify the signature, and using the method of step (3) to send and receive messages; (5) contract code calling stage: completing the environment construction and calling of the contract code through the client, and saving the block to complete the chain code calling. The present invention can effectively reduce the key storage and management burden of the system and improve the operation efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of blockchain technology, and in particular to an alliance chain system based on an identification cryptographic system. Background Art

[0002] Blockchain is an immutable distributed shared ledger. In blockchain, data is stored by multiple parties, and consensus algorithms are used to achieve consistency of multi-node data. In blockchain, data can only be appended and cannot be deleted or modified. The new blockchain is programmable, and business rules can be encoded into the blockchain using smart contracts. Rules (codes) cannot be deleted or modified like data. Codes are automatically executed when called and cannot be skipped. The results of execution are also written into the blockchain. Since data is stored by multiple parties and the data on the chain cannot be tampered with, blockchain can be used to achieve trusted data sharing among multiple parties.

[0003] Consortium chain is a type of blockchain. In a consortium chain, relevant nodes can join the blockchain network only after authorization and can participate in consensus and read and write block data according to the rules.

[0004] At present, the most common consortium chain system is IBM's open source Hyperledger system. The Hyperledger system is based on a mature public key certificate cryptography system to implement its system authorization and licensing functions. Although it can effectively control the permissions of system nodes and users, the complex certificates still bring a huge certificate management and storage burden to the Hyperledger system. Summary of the invention

[0005] In view of the needs and shortcomings of current technological development, the present invention provides a consortium chain system based on an identification cryptographic system, so as to reduce the burden of key management and storage and improve operational efficiency while ensuring the node security authentication and communication of the consortium chain system.

[0006] The alliance chain system based on the identification password system of the present invention adopts the following technical solutions to solve the above technical problems:

[0007] A consortium chain system based on an identification cryptographic system, the implementation of which includes:

[0008] (1) Key generation phase: The master key generation algorithm and private key extraction algorithm are run through KGC to generate the master private key, master public key, and the private keys of the server and client;

[0009] (2) Signature verification phase: The corresponding master public key is searched and input locally, followed by the signer ID, the message to be signed, and the signature, to verify whether the output signature is valid.

[0010] (3) Secure communication stage: The communicating parties use the method in step (2) to verify the signature in the negotiated key, and use the negotiated valid symmetric key to encrypt the messages sent and received before communicating;

[0011] (4) Transaction submission phase: Use the method in step (2) to verify the signature, and use the method in step (3) to send and receive messages;

[0012] (5) Contract code calling phase: The contract code environment is constructed and called through the Client, and the block is saved to complete the chain code call.

[0013] Specifically, the implementation of the alliance chain system involves multiple KGC nodes, multiple Client nodes and multiple Server nodes.

[0014] Optionally, execute step (1) to generate the key:

[0015] (1.1) All KGCs run the master key generation algorithm to generate their own master private key and master public key, and publish the master public key;

[0016] (1.2) The KGC responsible for server key generation runs the private key extraction algorithm, concatenates the KGC name and the server name into an identification name as the input of the private key extraction algorithm, and generates private keys for all servers;

[0017] (1.3) The KGC responsible for generating the client key runs the private key extraction algorithm, concatenates the KGC name and the client name into an identification name as the input of the private key extraction algorithm, and generates a private key for the required client.

[0018] Preferably, KGC securely distributes the private key generated in step (1.2) to the corresponding Server;

[0019] KGC securely distributes the private key generated in step (1.3) to the corresponding Client.

[0020] Optionally, step (2) is performed, and the specific process of verifying the signature is as follows:

[0021] (2.1) According to the signer ID, search for the corresponding master public key in the local trusted KGC master public key list. If not found, the verification fails. If found, continue;

[0022] (2.2) Input the signer ID, the message to be signed, the master public key and signature in (2.1), run the verification algorithm of the ID password, and output the verification result.

[0023] Further optionally, when executing step (3), it is assumed that the communicating parties are A and B, A is identified as IDA, the identifying private key is skA, and is issued by KGC1, B is identified as IDB, the identifying private key is skB, and is issued by KGC2, and KGC1 and KGC2 are both on the trusted KGC list of A and B. Then, the communicating parties use the negotiated valid symmetric key to encrypt the sent and received messages and then communicate. The specific process is as follows:

[0024] (3.1) A initiates a connection request to B. If the symmetric key negotiated by A and B last time has not expired, the symmetric key negotiated last time is used to encrypt the sent and received messages before communication. Otherwise, the following steps are executed;

[0025] (3.2) A calculates the temporary public and private keys tpkA and tskA for key negotiation, and uses skA to run the signature algorithm of the identification password on the message spliced ​​by tpkA and IDA to obtain sigA, and sends tpkA, IDA, and sigA to B;

[0026] (3.3) After receiving tpkA, IDA, and sigA, B verifies whether the signature sigA is correct according to the method in step (3.2). If it is wrong, it exits. If it is correct, B calculates the temporary public and private keys tpkB and tskB for key negotiation, uses skB to run the signature algorithm of the identification password on the message spliced ​​with tpkB and IDB to obtain sigB, and uses tskB and tpkA to calculate the symmetric key sk, and uses sk to splice tpkA and tpkB and encrypt them to obtain the ciphertext cB; tpkB, IDB, sigB, and cB are sent to A;

[0027] (3.4) After receiving tpkB, IDB, and sigB, A verifies whether the signature sigB is correct according to the method in step (3.2). If it is wrong, it exits. If it is correct, tskB and tpkA calculate the symmetric key sk, and use sk to verify whether the decrypted content of cB is the concatenation of tpkA and tpkB. If not, it exits. If so, it uses sk to encrypt the concatenation of tpkB and tpkA to obtain cA, and sends cA to B;

[0028] (3.5) After receiving cA, B verifies whether the content after decrypting cA with sk is the concatenation of tpkB and tpkA. If not, it exits the connection. If so, it executes step (3.6);

[0029] (3.6) A and B use sk to encrypt the message into ciphertext and send it to the recipient. The recipient decrypts the ciphertext with sk to obtain the specific message and process it.

[0030] Optionally, step (4) is performed, and the specific process of submitting the transaction is as follows:

[0031] (4.1) The client uses its own private key to run the identity cryptographic signature algorithm on the transaction information to obtain a signature, performs secure communication according to step (3), and sends its own identity, transaction information, and the signature of the transaction information to a server;

[0032] (4.2) After receiving the identifier, transaction information and signature, the Server verifies whether the signature is correct according to the method in step (2). If it is incorrect, the Client sends a transaction error message. If it is correct, it executes step (4.3);

[0033] (4.3) The servers communicate securely according to step (3) to send each other the transaction information they have received, sort the transaction information and reach a consensus;

[0034] (4.4) The server packages the sorted transactions and the hash value of the previous block into a block and stores it locally, and then performs secure communication according to step (3) to broadcast the block information to all clients;

[0035] (4.5) After receiving the broadcasts from all servers, the client compares the contents of the same block number to see if they are consistent. If they are consistent, the block content is saved locally. If they are inconsistent, the block is not saved.

[0036] Optionally, execute step (5), and the specific process of calling the contract code is as follows:

[0037] (5.1) The name, version, and content of the contract code are entered into the Client, and the Client builds a simulated operating environment for the contract code according to the established rules, and packages the features of the aforementioned contract code and the simulated operating environment into transaction information;

[0038] (5.2) The client submits the transaction according to the transaction process of step (4), and when it detects that the newly saved local block contains the transaction information in step (5.1), the simulation operation environment is actually effective;

[0039] (5.3) The Client calls the chain code, simulates and modifies the chain code running environment, and packages the simulated and modified chain code environment into new transaction information;

[0040] (5.4) The client submits the transaction according to the transaction process of step (4), and when it detects that the newly saved local block contains the transaction information in step (5.3), the simulated modification of the operating environment actually takes effect and the chain code call is completed.

[0041] Compared with the prior art, the alliance chain system based on the identification password system of the present invention has the following beneficial effects:

[0042] (1) The present invention uses an identification password system to ensure secure permission control, effectively reducing the key storage and management burden of the system, which is conducive to improving the system operation efficiency;

[0043] (2) Compared with the public key certificate management system, the identification cryptographic system of the present invention only needs to store the master public key of the trusted KGC and its own private key to complete the authentication, and the master public key has the advantages of being lightweight and taking up little storage space. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Attached Figure 1 It is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0045] In order to make the technical solution, the technical problem solved and the technical effect of the present invention more clearly understood, the technical solution of the present invention is clearly and completely described below in conjunction with specific embodiments.

[0046] Embodiment 1:

[0047] Combined with Figure 1 This embodiment proposes a consortium chain system based on an identification password system, based on multiple KGC nodes, multiple Client nodes and multiple Server nodes, and its implementation content includes:

[0048] (1) Key generation phase: KGC runs the master key generation algorithm and private key extraction algorithm to generate the master private key, master public key, and the private keys of the server and client. The specific process is as follows:

[0049] (1.1) All KGCs run the master key generation algorithm to generate their own master private key and master public key, and publish the master public key;

[0050] (1.2) The KGC responsible for server key generation runs the private key extraction algorithm, concatenates the KGC name and the server name into an identification name as the input of the private key extraction algorithm, generates private keys for all servers, and securely distributes the private keys to each server;

[0051] (1.3) The KGC responsible for generating the client key runs the private key extraction algorithm, concatenates the KGC name and the client name into an identification name as the input of the private key extraction algorithm, generates a private key for the required client, and securely distributes the private key to each client.

[0052] (2) Signature verification phase: The corresponding master public key is searched and entered locally, followed by the signer ID, the message to be signed, and the signature, to verify whether the output signature is valid. The specific process is as follows:

[0053] (2.1) According to the signer ID, search for the corresponding master public key in the local trusted KGC master public key list. If not found, the verification fails. If found, continue;

[0054] (2.2) Input the signer ID, the message to be signed, the master public key and signature in (2.1), run the verification algorithm of the ID password, and output the verification result.

[0055] (3) Secure communication phase: The communicating parties use the method in step (2) to verify the signature in the negotiated key, and use the negotiated valid symmetric key to encrypt the messages sent and received before communicating.

[0056] When executing step (3), it is assumed that the two communicating parties are A and B, A is identified as IDA, the identification private key is skA, and it is issued by KGC1, B is identified as IDB, the identification private key is skB, and it is issued by KGC2, and KGC1 and KGC2 are both on the trusted KGC list of A and B. Then, the two communicating parties use the negotiated valid symmetric key to encrypt the messages sent and received before communicating. The specific process is as follows:

[0057] (3.1) A initiates a connection request to B. If the symmetric key negotiated by A and B last time has not expired, the symmetric key negotiated last time is used to encrypt the sent and received messages before communication. Otherwise, the following steps are executed;

[0058] (3.2) A calculates the temporary public and private keys tpkA and tskA for key negotiation, and uses skA to run the signature algorithm of the identification password on the message spliced ​​by tpkA and IDA to obtain sigA, and sends tpkA, IDA, and sigA to B;

[0059] (3.3) After receiving tpkA, IDA, and sigA, B verifies whether the signature sigA is correct according to the method in step (3.2). If it is wrong, it exits. If it is correct, B calculates the temporary public and private keys tpkB and tskB for key negotiation, uses skB to run the signature algorithm of the identification password on the message spliced ​​with tpkB and IDB to obtain sigB, and uses tskB and tpkA to calculate the symmetric key sk, and uses sk to splice tpkA and tpkB and encrypt them to obtain the ciphertext cB; tpkB, IDB, sigB, and cB are sent to A;

[0060] (3.4) After receiving tpkB, IDB, and sigB, A verifies whether the signature sigB is correct according to the method in step (3.2). If it is wrong, it exits. If it is correct, tskB and tpkA calculate the symmetric key sk, and use sk to verify whether the decrypted content of cB is the concatenation of tpkA and tpkB. If not, it exits. If so, it uses sk to encrypt the concatenation of tpkB and tpkA to obtain cA, and sends cA to B;

[0061] (3.5) After receiving cA, B verifies whether the content after decrypting cA with sk is the concatenation of tpkB and tpkA. If not, it exits the connection. If so, it executes step (3.6);

[0062] (3.6) A and B use sk to encrypt the message into ciphertext and send it to the recipient. The recipient decrypts the ciphertext with sk to obtain the specific message and process it.

[0063] (4) Transaction submission phase: Use the method in step (2) to verify the signature, and use the method in step (3) to send and receive messages. The specific process is as follows:

[0064] (4.1) The client uses its own private key to run the identity cryptographic signature algorithm on the transaction information to obtain a signature, performs secure communication according to step (3), and sends its own identity, transaction information, and the signature of the transaction information to a server;

[0065] (4.2) After receiving the identifier, transaction information and signature, the Server verifies whether the signature is correct according to the method in step (2). If it is incorrect, the Client sends a transaction error message. If it is correct, it executes step (4.3);

[0066] (4.3) The servers communicate securely according to step (3) to send each other the transaction information they have received, sort the transaction information and reach a consensus;

[0067] (4.4) The server packages the sorted transactions and the hash value of the previous block into a block and stores it locally, and then performs secure communication according to step (3) to broadcast the block information to all clients;

[0068] (4.5) After receiving the broadcasts from all servers, the client compares the contents of the same block number to see if they are consistent. If they are consistent, the block content is saved locally. If they are inconsistent, the block is not saved.

[0069] (5) Contract code calling stage: The contract code environment is built and called through the Client, and the block is saved to complete the chain code call. The specific process is as follows:

[0070] (5.1) The name, version, and content of the contract code are entered into the Client, and the Client builds a simulated operating environment for the contract code according to the established rules, and packages the features of the aforementioned contract code and the simulated operating environment into transaction information;

[0071] (5.2) The client submits the transaction according to the transaction process of step (4), and when it detects that the newly saved local block contains the transaction information in step (5.1), the simulation operation environment is actually effective;

[0072] (5.3) The Client calls the chain code, simulates and modifies the chain code running environment, and packages the simulated and modified chain code environment into new transaction information;

[0073] (5.4) The client submits the transaction according to the transaction process of step (4), and when it detects that the newly saved local block contains the transaction information in step (5.3), the simulated modification of the operating environment actually takes effect and the chain code call is completed.

[0074] In summary, the alliance chain system based on the identification cryptographic system of the present invention can effectively reduce the key storage and management burden of the system and improve the system operation efficiency.

[0075] The above specific examples are used to explain the principles and implementation methods of the present invention in detail. These examples are only used to help understand the core technical content of the present invention. Based on the above specific embodiments of the present invention, any improvements and modifications made by technicians in this technical field without departing from the principles of the present invention should fall within the scope of patent protection of the present invention.

Claims

1. A consortium chain system based on an identification password system. Features , the implementation content includes: (1) Key generation phase: KGC runs the master key generation algorithm and private key extraction algorithm to generate the master private key, master public key, and the private keys of the server and client. The specific process of generating keys is as follows: (1.1) All KGCs run the master key generation algorithm to generate their own master private key and master public key, and publish the master public key; (1.2) The KGC responsible for server key generation runs the private key extraction algorithm, concatenates the KGC name and the server name into an identification name as the input of the private key extraction algorithm, and generates private keys for all servers; (1.3) The KGC responsible for generating the client key runs the private key extraction algorithm, concatenates the KGC name and the client name into an identification name as the input of the private key extraction algorithm, and generates a private key for the required client; (2) Signature verification phase: by searching and inputting the corresponding master public key locally, then inputting the signer ID, the message to be signed, and the signature, to verify whether the output signature is valid; the specific process of signature verification is as follows: (2.1) According to the signer ID, search for the corresponding master public key in the local trusted KGC master public key list. If not found, the verification fails. If found, continue; (2.2) Input the signer ID, the message to be signed, the master public key and signature in (2.1), run the verification algorithm of the ID password, and output the verification result; (3) Secure communication stage: The communicating parties use the method in step (2) to verify the signature when negotiating the key, and use the negotiated valid symmetric key to encrypt the messages sent and received before communicating. In this stage, it is assumed that the communicating parties are A and B, A is identified as IDA, the identification private key is skA, issued by KGC1, B is identified as IDB, the identification private key is skB, issued by KGC2, and KGC1 and KGC2 are both on the trusted KGC list of A and B. Then, the communicating parties use the negotiated valid symmetric key to encrypt the messages sent and received before communicating. The specific process is as follows: (3.1) A initiates a connection request to B. If the symmetric key negotiated by A and B last time has not expired, the symmetric key negotiated last time is used to encrypt the sent and received messages before communication. Otherwise, the following steps are executed; (3.2) A calculates the temporary public and private keys tpkA and tskA for key negotiation, and uses skA to run the signature algorithm of the identification password on the message spliced ​​by tpkA and IDA to obtain sigA, and sends tpkA, IDA, and sigA to B; (3.3) After receiving tpkA, IDA, and sigA, B verifies whether the signature sigA is correct according to the method in step (3.2). If it is wrong, it exits. If it is correct, B calculates the temporary public and private keys tpkB and tskB for key negotiation, uses skB to run the signature algorithm of the identification cipher on the message spliced ​​with tpkB and IDB to obtain sigB, and uses tskB and tpkA to calculate the symmetric key sk, and uses sk to splice tpkA and tpkB and encrypt them to obtain the ciphertext cB; tpkB, IDB, sigB, and cB are sent to A; (3.4) After receiving tpkB, IDB, and sigB, A verifies whether the signature sigB is correct according to the method in step (3.2). If it is wrong, it exits. If it is correct, tskB and tpkA calculate the symmetric key sk, and use sk to verify whether the decrypted content of cB is the concatenation of tpkA and tpkB. If not, it exits. If so, it uses sk to encrypt the concatenation of tpkB and tpkA to obtain cA, and sends cA to B. (3.5) After receiving cA, B verifies whether the content after decrypting cA with sk is the concatenation of tpkB and tpkA. If not, it exits the connection. If so, it executes step (3.6); (3.6) A and B use sk to encrypt the message into ciphertext and send it to the receiving party. The receiving party uses sk to decrypt the ciphertext to obtain the specific message and process it; (4) Transaction submission phase: Use the method in step (2) to verify the signature, and use the method in step (3) to send and receive messages; (5) Contract code calling phase: The contract code environment is constructed and called through the Client, and the block is saved to complete the chain code call.

2. According to claim 1, a consortium chain system based on an identification password system, It is characterized in that The implementation of the alliance chain system involves multiple KGC nodes, multiple Client nodes and multiple Server nodes.

3. According to claim 2, a consortium chain system based on an identification password system, It is characterized in that KGC securely distributes the private key generated in step (1.2) to the corresponding Server; KGC securely distributes the private key generated in step (1.3) to the corresponding Client.

4. According to claim 3, a consortium chain system based on an identification password system, It is characterized in that Execute step (4) and submit the transaction as follows: (4.1) The client uses its own private key to run the identity cryptographic signature algorithm on the transaction information to obtain a signature, performs secure communication according to step (3), and sends its own identity, transaction information, and the signature of the transaction information to a server; (4.2) After receiving the identifier, transaction information and signature, the Server verifies whether the signature is correct according to the method in step (2). If it is incorrect, the Client sends a transaction error message. If it is correct, it executes step (4.3). (4.3) The servers communicate securely according to step (3) to send each other the transaction information they have received, sort the transaction information and reach a consensus; (4.4) The server packages the sorted transactions and the hash value of the previous block into a block and stores it locally, and then performs secure communication according to step (3) to broadcast the block information to all clients; (4.5) After receiving the broadcasts from all servers, the client compares the contents of the same block number to see if they are consistent. If they are consistent, the block content is saved locally. If they are inconsistent, the block is not saved.

5. According to claim 4, a consortium chain system based on an identification password system, It is characterized in that Execute step (5) and the specific process of calling the contract code is as follows: (5.1) Enter the name, version, and content of the contract code into the Client, which builds a simulated operating environment for the contract code according to established rules and packages the features of the contract code and the simulated operating environment into transaction information; (5.2) The client submits the transaction according to the transaction process of step (4), and when it detects that the newly saved local block contains the transaction information in step (5.1), the simulation operation environment is actually effective; (5.3) The Client calls the chain code, simulates and modifies the chain code running environment, and packages the simulated and modified chain code environment into new transaction information; (5.4) The client submits the transaction according to the transaction process of step (4), and when it detects that the newly saved local block contains the transaction information in step (5.3), the simulated modification of the operating environment actually takes effect and completes the chain code call.

Citation Information

Patent Citations

  • Double-agent cross-domain authentication method based on identification password and alliance chain

    CN110138560A