Key recovery method, device, system, storage medium and electronic device
By encrypting key fragments and recovering the key using the target private key, the problem of low key security is solved, and the security of the key is improved.
Patent Information
- Application Number
- CN202210753849.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-29
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2042-06-29
AI Technical Summary
In existing technologies, distributed key storage schemes cannot prevent collusion among participants, resulting in low key security. Furthermore, key recovery can only be achieved by the participant who owns the key fragments, posing a risk of leakage.
The key fragments are encrypted using the target public key and decrypted using the target private key to recover the key. The security of the key fragments is protected by fragment encryption. Only the first object can use the target private key to recover the target key, thus avoiding collusion attacks.
It improves key security, prevents key leakage due to collusion attacks, and achieves secure protection of the target key.
Smart Images

Figure CN115001681B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the field of key management, and in particular, to a key recovery method, device, system, storage medium and electronic device. BACKGROUND
[0002] In the era of network interconnection, data security problems gradually become the focus of attention, and for the secure storage or sharing of data, the data is usually encrypted using a key to ensure the security of the data, and the key is securely stored. There is a risk of single point failure in the above process. In other words, if the device storing the key fails or is attacked by the outside world, the key becomes unavailable or lost. Therefore, the distributed key storage idea is more practical.
[0003] At present, in the existing scheme, most of them use the threshold idea to realize the distributed storage of the key, each participant has a key fragment, and the key can be recovered when the number of key fragments reaches the threshold. However, the scheme in the related art cannot prevent collusion between participants; in addition, the recovery of the key can only be realized by the participants who have the key fragments, and if the key fragments are sent to other participants, it may lead to the leakage of the key. Therefore, there is a problem of low security of the key in the related art.
[0004] In view of the problem of low security of the key in the related art, no effective solution has been proposed so far. SUMMARY
[0005] Embodiments of the present application provide a key recovery method, device, system, storage medium and electronic device to at least solve the problem of low security of the key in the related art.
[0006] According to one embodiment of the present application, a key recovery method is provided, applied to a first object, comprising: obtaining N sub-ciphertexts, wherein the N sub-ciphertexts are ciphertexts obtained by a second object encrypting N sub-keys using a target public key and respectively sending to N third objects, the N sub-keys are keys obtained by the second object fragmenting a target key, the N sub-ciphertexts are respectively sent to the first object by the N third objects notified by the second object after the first object sends a first target request to the second object, the first target request is used to request to recover the target key, and N is a positive integer greater than or equal to 2; decrypting the N sub-ciphertexts using a target private key to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm.
[0007] In an example embodiment, decrypting the N sub-ciphertexts with the target private key to recover the target key comprises: decrypting the N sub-ciphertexts respectively with the target private key to obtain N sub-keys; and recovering the target key based on the N sub-keys.
[0008] In an example embodiment, recovering the target key based on the N sub-keys comprises: performing an addition operation on the N sub-keys to obtain the target key.
[0009] In an example embodiment, before obtaining the N sub-ciphertexts, the method further comprises: receiving a second target request sent by the second object, wherein the second target request is used to request to obtain the target public key; and sending the target public key to the second object to instruct the second object to encrypt the N sub-keys with the target public key to obtain the N sub-ciphertexts after authenticating the identity of the second object and passing the authentication.
[0010] In an example embodiment, sending the target public key to the second object comprises: sending the target public key to the second object to instruct the second object to destroy the target key and the N sub-keys.
[0011] In an example embodiment, sending the target public key to the second object comprises: sending the target public key to the second object to instruct the second object to send the N sub-ciphertexts respectively to the N third objects after authenticating the identities of the N third objects and passing the authentication.
[0012] In an example embodiment, the method further comprises: receiving a third target request, wherein the third target request is sent by a first target sub-object after performing a predetermined operation and obtaining target ciphertext, the third target request is used to request decryption of the target ciphertext to recover the target key, the first target sub-object is any object included in the N third objects, and the predetermined operation comprises: the first target sub-object sending a fourth target request to a second target sub-object to request obtaining second sub-ciphertext, wherein the second target sub-object is all objects included in the N third objects except the first target sub-object, and the second sub-ciphertext comprises the sub-ciphertext stored by each of the second target sub-objects; obtaining the second sub-ciphertext, wherein the second sub-ciphertext is composed of the sub-ciphertext sent by each of the second target sub-objects after identity authentication of the first target sub-object and authentication passing; performing an additive operation on the first sub-ciphertext and the second sub-ciphertext to obtain the target ciphertext; and decrypting the target ciphertext based on the third target request using the target private key to recover the target key.
[0013] According to another embodiment of the present application, a key recovery method applied to a second object is also provided, comprising: receiving a first target request sent by a first object, wherein the first target request is used to request recovery of a target key; notifying N third objects to send N sub-ciphertexts to the first object respectively, and instructing the first object to decrypt N sub-ciphertexts using a target private key to recover the target key, wherein N sub-ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using a target public key and sent to N third objects respectively, N sub-keys are keys obtained by the second object fragmenting the target key, the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, and N is a positive integer greater than or equal to 2.
[0014] According to a further embodiment of the present application, a key recovery method applied in a third object is also provided, comprising: receiving a target notification, wherein the target notification is used to instruct each of the N third objects to send N ciphertexts to a first object respectively, the N ciphertexts are ciphertexts obtained by a second object encrypting N sub-keys using a target public key and sending to the N third objects respectively, the N sub-keys are keys obtained by the second object fragmenting a target key, the target notification is sent by the second object after receiving a first target request sent by the first object, and the first target request is used to request to recover the target key; and sending the ciphertexts to the first object and instructing the first object to decrypt the N ciphertexts using a target private key after receiving the N ciphertexts to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, and N is a positive integer greater than or equal to 2.
[0015] In one exemplary embodiment, the method further comprises: sending a fourth target request to a second target sub-object to request to obtain second ciphertexts, wherein the second target sub-object is all objects included in the N third objects except the first target sub-object, and the second ciphertexts comprise the ciphertexts stored in each of the second target sub-objects; obtaining the second ciphertexts, wherein the second ciphertexts are composed of the ciphertexts sent by each of the second target sub-objects after identity authentication of the first target sub-object and passing the authentication; performing an addition operation on the second ciphertexts and a first ciphertext to obtain target ciphertexts, wherein the first ciphertext is the ciphertext stored in the first target sub-object; and sending a third target request to the first object to request the first object to decrypt the target ciphertexts to recover the target key.
[0016] According to still another embodiment of the present application, a key recovery apparatus is also provided, located in a first object, comprising: a first obtaining module, configured to obtain N ciphertexts, wherein the N ciphertexts are ciphertexts obtained by a second object encrypting N sub-keys using a target public key and sending to N third objects respectively, the N sub-keys are keys obtained by the second object fragmenting a target key, the N ciphertexts are notified by the second object to the N third objects to send to the first object respectively after the first object sends a first target request to the second object, the first target request is used to request to recover the target key, and N is a positive integer greater than or equal to 2; and a first recovering module, configured to decrypt the N ciphertexts using a target private key to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm.
[0017] According to still another embodiment of the present application, a key recovery apparatus is also provided, located in a second object, comprising: a first receiving module, configured to receive a first target request sent by a first object, wherein the first target request is used to request to recover a target key; and a first processing module, configured to notify N third objects to send N ciphertexts to the first object respectively, and instruct the first object to decrypt the N ciphertexts using a target private key to recover the target key, wherein the N ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using a target public key and sending to the N third objects respectively, the N sub-keys are keys obtained by the second object fragmenting the target key, the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, and N is a positive integer greater than or equal to 2.
[0018] According to a further embodiment of the present application, there is also provided a key recovery device located in a third object, comprising: a second receiving module configured to receive a target notification, wherein the target notification is configured to instruct each of the N third objects to send N ciphertexts to a first object respectively, the N ciphertexts being ciphertexts obtained by a second object encrypting N sub-keys using a target public key and sending to the N third objects respectively, the N sub-keys being keys obtained by the second object fragmenting a target key, the target notification being sent by the second object after receiving a first target request sent by the first object, the first target request being configured to request to recover the target key; and a second processing module configured to send the ciphertexts to the first object and instruct the first object to decrypt the N ciphertexts using a target private key to recover the target key after receiving the N ciphertexts, the target public key and the target private key being a key pair generated by the first object using a predetermined algorithm, N being a positive integer greater than or equal to 2.
[0019] According to a further embodiment of the present application, there is also provided a key recovery system, comprising: a first object, a second object and N third objects, wherein the first object comprises the key recovery device located in the first object, the second object comprises the key recovery device located in the second object, and the third object comprises the key recovery device located in the third object.
[0020] According to a further embodiment of the present application, there is also provided a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is configured to perform the steps of any one of the method embodiments when executed.
[0021] According to a further embodiment of the present application, there is also provided an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the computer program to perform the steps of any one of the method embodiments.
[0022] By the present application, after the first object sends a first target request to the second object, the second object informs N third objects to send N sub-ciphertexts to the first object respectively, the first object acquires the N sub-ciphertexts, and then decrypts the N sub-ciphertexts by using a target private key to recover a target key, wherein the target public key and the target private key are a key pair generated by the first object by using a predetermined algorithm, the N sub-ciphertexts are obtained by encrypting N sub-keys by using the target public key after the second object divides the target key into the N sub-keys, and the second object sends the N sub-ciphertexts to the N third objects respectively, and the N third objects store the N sub-ciphertexts respectively. By dividing and encrypting the target key, the security of each key fragment is protected, and the security of the target key is protected. In addition, since the N sub-ciphertexts can be decrypted and the target key can be recovered by using the target private key by the first object, the problem that the security of the key is difficult to guarantee due to collusion attack of each participant who has a key fragment in the related art is avoided, and thus the problem of low security of the key in the related art is solved, and the effect of improving the security of the key is achieved. BRIEF DESCRIPTION OF DRAWINGS
[0023] Figure 1 is a mobile terminal hardware structure block diagram of a key recovery method of an embodiment of the present application;
[0024] Figure 2 is a flow of a key recovery method according to an embodiment of the present application Figure 1 ;
[0025] Figure 3 is a flow of another key recovery method according to an embodiment of the present application Figure 2 ;
[0026] Figure 4 is a flow of still another key recovery method according to an embodiment of the present application Figure 3 ;
[0027] Figure 5 is a key recovery system architecture diagram according to an embodiment of the present application;
[0028] Figure 6 is an initialization module example diagram according to a specific embodiment of the present application;
[0029] Figure 7 is a master key fragment encryption module example diagram according to a specific embodiment of the present application;
[0030] Figure 8 is a master key recovery module example diagram according to a specific embodiment of the present application;
[0031] Figure 9is a structural block of a key recovery device according to an embodiment of the present application Figure 1 ;
[0032] Figure 10 is a structural block of another key recovery device according to an embodiment of the present application Figure 2 ;
[0033] Figure 11 is a structural block of still another key recovery device according to an embodiment of the present application Figure 3 . DETAILED DESCRIPTION
[0034] Hereinafter, embodiments of the present application will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.
[0035] It should be noted that the terms "first", "second", and the like in the description and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence.
[0036] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking the case of running on a mobile terminal, Figure 1 is a hardware structural block diagram of a mobile terminal of a key recovery method according to an embodiment of the present application. As shown in Figure 1 , the mobile terminal can include one or more (only one is shown in Figure 1 ) processors 102 (the processor 102 can include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the above-mentioned mobile terminal can also include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that Figure 1 the structure shown is only schematic, which does not limit the structure of the above-mentioned mobile terminal. For example, the mobile terminal can also include more or less components than those shown in Figure 1 , or have a different configuration from that shown in Figure 2 .
[0037] The memory 104 can be used to store computer programs, such as software programs of application software and modules, such as a computer program corresponding to the key recovery method in the embodiments of the present application. The processor 102 can execute various functional applications and data processing, i.e., implement the above method, by running the computer programs stored in the memory 104. The memory 104 can include a high-speed random access memory, and can further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include memories remotely arranged with respect to the processor 102, which can be connected to the mobile terminal through a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0038] The transmission device 106 is configured to receive or send data via a network. Specific examples of the network can include a wireless network provided by a communication provider of the mobile terminal. In one example, the transmission device 106 includes a network adapter (NIC), which can be connected to other network devices through a base station so as to be able to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is configured to communicate with the Internet in a wireless manner.
[0039] In the embodiments, a key recovery method is provided, Figure 1 is a flow of a key recovery method according to the embodiments of the present application Figure 2 As shown in Figure 3 applied to a first object, the flow includes the following steps:
[0040] In step S202, N ciphertexts are obtained, wherein the N ciphertexts are ciphertexts obtained by a second object encrypting N sub-keys using a target public key and respectively sending to N third objects, the N sub-keys are keys obtained by the second object fragmenting a target key, the N ciphertexts are respectively sent to the first object by the N third objects notified by the second object after the first object sends a first target request to the second object, the first target request is used to request to recover the target key, and N is a positive integer greater than or equal to 2.
[0041] In step S204, the N ciphertexts are decrypted using a target private key to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm.
[0042] By the above steps, after the first object sends the first target request to the second object, the second object informs N third objects to send N ciphertexts to the first object respectively, the first object obtains the N ciphertexts, and then decrypts the N ciphertexts by using the target private key to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object by using a predetermined algorithm, the N ciphertexts are obtained by encrypting N sub-keys by using the target public key after the second object divides the target key into the N sub-keys, and the second object sends the N ciphertexts to N third objects respectively, and the N third objects store the N ciphertexts respectively. By dividing and encrypting the target key, the security of each key fragment is protected, and the security of the target key is protected. In addition, since the first object needs to use the target private key to decrypt the N ciphertexts and recover the target key, the problem that the security of the key is difficult to guarantee due to collusion attack of each participant who has a key fragment in the related art is avoided, thereby solving the problem of low security of the key in the related art, and achieving the effect of improving the security of the key.
[0043] The execution subject of the above steps can be a device, such as a key management device, or the first object, or a terminal, or a key recovery device in an actual application, but is not limited thereto. The following describes the first object performing the above operations as an example (only an exemplary description, and other devices or modules can also perform the above operations in actual operation).
[0044] In the above embodiment, the first object obtains N ciphertexts, wherein the N ciphertexts are ciphertexts obtained by encrypting N sub-keys by using the target public key and sent to N third objects respectively by the second object, the N sub-keys are keys obtained by dividing the target key by the second object, the N ciphertexts are sent to the first object by the N third objects respectively after the first object sends the first target request to the second object, the first target request is used to request to recover the target key, N is a positive integer greater than or equal to 2; for example, the first object can be a master key restorer in a key management system, the second object can be a master key publisher in the key management system, and the third object can be a master key fragment storage in the key management system, for example, the second object divides a master key (or called plaintext master key, equivalent to the target key) S into n (equivalent to the N) master key fragments, such as s1, s2, …, sn, and satisfies S = s1 + s2 + … + sn, then the second object encrypts each plaintext master key fragment s n by using the target public key to obtain the corresponding ciphertext fragment C n , and then the second object encrypts each plaintext master key fragment s i by using the target public key to obtain the corresponding ciphertext fragment C i, wherein, 1≤i≤n, the second object sends the n key fragments to n third objects respectively, that is, each third object stores one ciphertext fragment; by fragmenting and encrypting the target key, the security of each key fragment is protected, and the security of the target key is achieved; then, the first object decrypts the N ciphertexts using the target private key to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, for example, the first object selects a homomorphic encryption algorithm with additive homomorphism to generate a pair of public and private keys (i.e., a target public key and a target private key pair), that is, only the first object can decrypt the N ciphertexts using the target private key and recover the target key, avoiding the problem that in related technologies, the security of the key is difficult to guarantee due to collusion attacks by each participant who has a key fragment. Therefore, the problem of low security of the key in related technologies is solved, and the effect of improving the security of the key is achieved.
[0045] In an optional embodiment, decrypting the N ciphertexts using the target private key to recover the target key comprises: decrypting the N ciphertexts using the target private key to obtain N sub-keys; and recovering the target key based on the N sub-keys. In this embodiment, the first object decrypts the N ciphertexts (corresponding to the aforementioned ciphertext fragments C i , wherein 1≤i≤N) using the target private key to obtain N sub-keys, for example, the first object decrypts the aforementioned N ciphertexts (such as C i ) using the target private key to obtain s1, s2, …, s n , and then recovers the target key based on the N sub-keys. Through this embodiment, the first object uses the target private key to achieve the purpose of decrypting the N ciphertexts and recovering the target key.
[0046] In an optional embodiment, recovering the target key based on the N sub-keys comprises: performing an addition operation on the N sub-keys to obtain the target key. In this embodiment, the first object performs an addition operation on the N sub-keys to obtain the target key, for example, by performing an addition operation S=s1+s2+…+s n , the target key S is obtained. Through this embodiment, the purpose of performing an addition operation on the N sub-keys to recover the target key is achieved.
[0047] In an optional embodiment, before the N sub-ciphertexts are acquired, the method further comprises: receiving a second target request sent by the second object, wherein the second target request is used to request to acquire the target public key; and after the identity of the second object is authenticated and the authentication is passed, sending the target public key to the second object to instruct the second object to encrypt the N sub-keys by using the target public key to obtain the N sub-ciphertexts. In this embodiment, the first object receives the second target request sent by the second object to request the target public key before the N sub-ciphertexts are acquired, and after the identity of the second object is authenticated and the authentication is passed, the target public key is sent to the second object. In actual application, the public key and the private key pair (i.e., the target public key and the target private key pair) is generated by the first object, and after the identity of the second object is authenticated, the target public key is sent to the second object. The first object can authenticate the identity of the second object by using dynamic password or authentication based on the public key cryptography. After the second object acquires the target public key, the second object can encrypt the N sub-keys by using the target public key to obtain the N sub-ciphertexts. Through this embodiment, the target public key is sent to the second object after the second target request is received, and the second object is instructed to encrypt the N sub-keys by using the target public key, so that the security of each master key fragment is protected, and the security of the master key is further protected.
[0048] In an optional embodiment, the target public key is sent to the second object, comprising: sending the target public key to the second object to instruct the second object to destroy the target key and the N sub-keys. In this embodiment, the first object sends the target public key to the second object, and instructs the second object to destroy the target key (corresponding to the master key) and the N sub-keys (such as s1, s2, …, sN in the foregoing embodiment) after the target key is fragmented and encrypted by the second object. In actual application, the original master key (such as the master key S in the foregoing embodiment) and the master key fragments (such as s1, s2, …, sN in the foregoing embodiment) are destroyed to avoid the master key or the master key fragments from being leaked, so that the security of the key management is further improved. n
[0049] In an optional embodiment, the target public key is sent to the second object, comprising: sending the target public key to the second object to instruct the second object to send the N sub-ciphertexts to the N third objects respectively after the identities of the N third objects are authenticated and the authentication is passed. In this embodiment, the first object sends the target public key to the second object, and instructs the second object to send the N sub-ciphertexts (such as the ciphertext fragments in the foregoing embodiment) to the N third objects respectively after the identities of the N third objects are authenticated and the authentication is passed, that is, the sub-ciphertexts are sent to the third objects after the identities of the third objects are determined, so that the security of the key is improved.
[0050] In an optional embodiment, the method further includes: receiving a third target request, wherein the third target request is sent by a first target sub-object after performing a predetermined operation and obtaining target ciphertext, the third target request being used to request decryption of the target ciphertext to recover the target key, the first target sub-object being any one of the N third objects, the predetermined operation including: the first target sub-object sending a fourth target request to a second target sub-object to request obtaining second sub-ciphertext, wherein the second target sub-object is all objects other than the first target sub-object included in the N third objects, the second sub-ciphertext including the sub-ciphertext stored by each object in the second target sub-object; obtaining the second sub-ciphertext, wherein the second sub-ciphertext is composed of the sub-ciphertext sent by each object in the second target sub-object after authenticating the first target sub-object and the authentication is successful; performing an addition operation on the first sub-ciphertext and the second sub-ciphertext to obtain the target ciphertext; and decrypting the target ciphertext using the target private key based on the third target request to recover the target key. In this embodiment, a first target sub-object can send a fourth target request to a second target sub-object to request the acquisition of a second sub-ciphertext. The first target sub-object is any one of N third objects, and the second target sub-object is any one of the N third objects excluding the first target sub-object. That is, the second target sub-object includes N-1 third objects. The second sub-ciphertext corresponds to a combination of the sub-ciphertexts stored by each of these N-1 third objects. After acquiring the second sub-ciphertext, the first target sub-object adds the first sub-ciphertext to the second sub-ciphertext to obtain the target ciphertext. The first sub-ciphertext is the sub-ciphertext stored in the first target sub-object. Through this operation, any one of the N third objects initiates a request to the other N-1 third objects to acquire the second sub-ciphertext, and then adds its own stored first sub-ciphertext (e.g., C1) and second sub-ciphertext (e.g., C2+C3+…+C…). n Adding , ) will yield the target ciphertext, such as C = C1 + C2 + C3 + ... + C n After obtaining the target ciphertext, the first sub-target object can send a third target request to the first object. Upon receiving the third target request, the first object uses the target private key to decrypt the target ciphertext and recover the target key. This embodiment achieves the goal of having a third object initiate a key recovery request to request the first object to recover the master key, thus improving the flexibility of key recovery requests. Simultaneously, it avoids the problem in related technologies where collusion attacks by parties possessing key fragments can compromise key security.
[0051] In the embodiment, another key recovery method is also provided, Figure 2 is a flow of another key recovery method according to an embodiment of the application Figure 3 As shown in the figure, applied to the second object, the flow includes the following steps: Figure 4
[0052] In step S302, a first target request sent by a first object is received, wherein the first target request is used to request to recover a target key;
[0053] In step S304, N third objects are notified to send N ciphertexts to the first object respectively, and the first object is instructed to decrypt the N ciphertexts by using a target private key to recover the target key, wherein the N ciphertexts are ciphertexts obtained by encrypting N sub-keys by using a target public key and sent to the N third objects respectively, the N sub-keys are keys obtained by fragmenting the target key, the target public key and the target private key are a key pair generated by the first object by using a predetermined algorithm, and N is a positive integer greater than or equal to 2.
[0054] Through the above steps, the second object receives the first target request sent by the first object to request to recover the target key, and then notifies the N third objects to send the N ciphertexts to the first object respectively, and instructs the first object to decrypt the N ciphertexts by using the target private key to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object by using a predetermined algorithm, and the N ciphertexts are obtained by encrypting the N sub-keys by using the target public key after the target key is fragmented into the N sub-keys, and the second object sends the N ciphertexts to the N third objects respectively, and the N third objects store the N ciphertexts respectively. By fragmenting and encrypting the target key, the security of each key fragment is protected, and the security of the target key is protected. In addition, by instructing the first object to decrypt the N ciphertexts by using the target private key and recover the target key, the problem that the security of the key is difficult to guarantee due to collusion attack of each participant who has a key fragment in the related art is avoided, thus solving the problem of low security of the key in the related art, and achieving the effect of improving the security of the key.
[0055] The execution subject of the above steps can be a device, such as a key management device, or the second object, or a terminal, or a key issuing device in actual application, but is not limited thereto. The second object is taken as an example to perform the above operations (only an exemplary description, and other devices or modules can also perform the above operations in actual operation).
[0056] In the above embodiment, the second object receives a first target request sent by the first object, wherein the first target request is used to request the recovery of the target key; the second object then notifies N third objects to send N sub-ciphertexts to the first object respectively, and instructs the first object to decrypt the N sub-ciphertexts using the target private key to recover the target key, wherein the N sub-ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using the target public key and then sending them to the N third objects respectively, and the N sub-keys are keys obtained by the second object after fragmenting the target key, where N is a positive integer greater than or equal to 2. For example, the first object can be the master key recoverer in the key management system, the second object can be the master key publisher in the key management system, and the third object can be the master key fragment storer in the key management system. For example, the second object divides the master key (or plaintext master key, equivalent to the aforementioned target key) S into n (equivalent to the aforementioned N) master key fragments, such as s1, s2, ..., s n The condition S = s1 + s2 + ... + s n Then, the second object uses the target public key to encrypt each plaintext master key fragment s. i The corresponding ciphertext fragment C is obtained. i There are n ciphertext fragments, where 1 ≤ i ≤ n. The second object then sends each of the n master key fragments to n third objects, meaning each third object stores one ciphertext fragment. By encrypting the target key in fragments, the security of each key fragment is protected, thereby protecting the security of the target key. The second object instructs the N third objects to send N sub-ciphertexts to the first object and instructs the first object to decrypt the N sub-ciphertexts using the target private key to recover the target key. The target public key and target private key are a key pair generated by the first object using a predetermined algorithm. For example, the first object selects a homomorphic encryption algorithm with additive homomorphism to generate a public-private key pair (i.e., the target public key and target private key pair). This instructs the first object to use the target private key to decrypt the N sub-ciphertexts and recover the target key, avoiding the problem in related technologies where the security of the key is difficult to guarantee due to collusion attacks among the parties possessing the key fragments. Therefore, this solves the problem of low key security in related technologies and achieves the effect of improving key security.
[0057] This embodiment also provides another key recovery method. Figure 3 This is a flowchart of another key recovery method according to an embodiment of the present invention. Figure 4 ,like Figure 5 As shown, when applied to a third object, the process includes the following steps:
[0058] Step S402, receiving a target notification, wherein the target notification is used to instruct each of the N third objects to send N ciphertexts to the first object respectively, the N ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using a target public key and sending to the N third objects respectively, the N sub-keys are keys obtained by the second object fragmenting a target key, the target notification is sent by the second object after receiving a first target request sent by the first object, and the first target request is used to request to recover the target key;
[0059] Step S404, sending the ciphertexts to the first object and instructing the first object to decrypt the N ciphertexts using a target private key after receiving the N ciphertexts to recover the target key, the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, and N is a positive integer greater than or equal to 2.
[0060] Through the above steps, the third object receives the target notification sent by the second object to instruct each of the N third objects to send N ciphertexts to the first object respectively, wherein the target notification is sent by the second object after receiving the first target request sent by the first object, and each of the N third objects sends the ciphertexts to the first object respectively after receiving the target notification, and instructs the first object to decrypt the N ciphertexts using the target private key to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, and the N ciphertexts are obtained by the second object encrypting the N sub-keys using the target public key after fragmenting the target key into the N sub-keys, and the second object sends the N ciphertexts to the N third objects respectively, and the N third objects store the N ciphertexts respectively. By fragmenting and encrypting the target key, the security of each key fragment is protected, and the security of the target key is protected. In addition, by instructing the first object to decrypt the N ciphertexts using the target private key and recovering the target key, the problem that the security of the key is difficult to guarantee due to collusion attack of each participant who has a key fragment in the related art is avoided, thus solving the problem of low security of the key in the related art, and achieving the effect of improving the security of the key.
[0061] The execution subject of the above steps can be a device, such as a ciphertext storage device, or the third object, or a terminal, or a key fragment storage device in actual application, but is not limited thereto. The third object performs the above operations is taken as an example (only an exemplary description, and other devices or modules can also perform the above operations in actual operation).
[0062] In the above embodiment, the third object receives a target notification, wherein the target notification is used to instruct each third object included in the N third objects to respectively send N ciphertexts to the first object, the N ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using a target public key and respectively sending to the N third objects, the N sub-keys are keys obtained by the second object fragmenting a target key, the target notification is sent by the second object after receiving a first target request sent by the first object, and the first target request is used to request to recover the target key; each third object included in the N third objects sends the ciphertexts to the first object, that is, sends the N ciphertexts to the first object, and instructs the first object to decrypt the N ciphertexts using a target private key after receiving the N ciphertexts, so as to recover the target key, for example, the first object can be a master key restorer in a key management system, the second object can be a master key publisher in the key management system, and the third object can be a master key fragment storage in the key management system, for example, the second object divides a master key (or called plaintext master key, equivalent to the foregoing target key) S into n (equivalent to the foregoing N) master key fragments, such as s1, s2, …, sn, and satisfies S = s1 + s2 + … + sn. n , satisfies S = s1 + s2 + … + sn. n Then, the second object encrypts each plaintext master key fragment s i to obtain a corresponding ciphertext fragment C i , that is, n ciphertext fragments, wherein 1≤i≤n, and the second object further sends the n master key fragments to the n third objects respectively, that is, each third object respectively stores one ciphertext fragment; by fragmenting and encrypting the target key, the security of each key fragment is realized, and the security of the target key is achieved; the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, for example, the first object selects a homomorphic encryption algorithm with additive homomorphism to generate a pair of public and private keys (that is, a target public key and a target private key pair), that is, instructing the first object to decrypt the N ciphertexts using the target private key and recover the target key, avoiding the problem that in the related art, the security of the key is difficult to guarantee because the parties having the key fragments may collude. Therefore, the problem of low security of the key in the related art is solved, and the effect of improving the security of the key is achieved.
[0063] In an optional embodiment, the method further includes: sending a fourth target request to a second target sub-object to request the acquisition of a second sub-ciphertext, wherein the second target sub-object is all objects included in the N third objects except for the first target sub-object, and the second sub-ciphertext includes the sub-ciphertext stored by each object in the second target sub-object; acquiring the second sub-ciphertext, wherein the second sub-ciphertext is composed of the sub-ciphertext sent by each object in the second target sub-object after authenticating the first target sub-object and the authentication is successful; performing an addition operation between the second sub-ciphertext and the first sub-ciphertext to obtain a target ciphertext, wherein the first sub-ciphertext is the ciphertext stored in the first target sub-object; and sending a third target request to the first object to request the first object to decrypt the target ciphertext to recover the target key. In this embodiment, the first target sub-object sends a fourth target request to the second target sub-object to request the acquisition of the second sub-ciphertext. The first sub-target object is any one of N third objects, and the second sub-target object is any one of the N third objects excluding the first sub-target object. That is, the second sub-target object includes N-1 third objects. The second sub-ciphertext corresponds to a combination of the sub-ciphertexts stored by each of these N-1 third objects. The first sub-target object acquires the second sub-ciphertext and then adds the first sub-ciphertext to the second sub-ciphertext to obtain the target ciphertext. The first sub-ciphertext is the sub-ciphertext stored in the first sub-target object. Through this operation, any one of the N third objects initiates a request to the other N-1 third objects to acquire the second sub-ciphertext, and then adds its own stored first sub-ciphertext (e.g., C1) and second sub-ciphertext (e.g., C2+C3+…+C…). n Adding , ) will yield the target ciphertext, such as C = C1 + C2 + C3 + ... + C n The first sub-target object then sends a third target request to the first object, requesting the first object to decrypt the target ciphertext C using the target private key to recover the target key (as described in S above). This embodiment achieves the goal of having a third object initiate a key recovery request to request the first object to recover the master key, thus improving the flexibility of the key recovery request. Simultaneously, it avoids the problem in related technologies where the security of the key may be compromised due to collusion attacks by various parties possessing key fragments.
[0064] Obviously, the embodiments described above are only some embodiments of the present invention, and not all embodiments. The present invention will be specifically described below with reference to the embodiments.
[0065] This embodiment also provides a key recovery system. Figure 6is a key recovery system architecture diagram according to an embodiment of the application, the system comprises: a master key publisher SD 504 (corresponding to the aforementioned second object), a master key restorer SR 502 (corresponding to the aforementioned first object), n (n≥2) master key shard storers P i (i=1, 2, …, n) 506 (corresponding to the aforementioned third object), wherein the master key corresponds to the aforementioned target key.
[0066] Wherein, the master key publisher SD is used for sharding the master key, and encrypting the master key shards; the master key restorer SR is used for generating a key pair and decrypting the master key ciphertext to restore the master key; and the master key shard storer P i (i=1, 2, …, n) is used for saving the master key shards.
[0067] The application embodiment provides a master key recovery method, and the scheme mainly includes three roles: a master key publisher SD (corresponding to the aforementioned second object), a master key restorer SR (corresponding to the aforementioned first object), and n (n≥2) master key shard storers P i (i=1, 2, …, n) (corresponding to the aforementioned third object).
[0068] The application embodiment is based on a master key (corresponding to the aforementioned target key) sharing scheme of an additive homomorphism algorithm, and includes three modules: an initialization module, a master key shard encryption module, and a master key recovery module. The functions of the three modules and their working processes are described below.
[0069] (1) Initialization module
[0070] Figure 7 is an initialization module example diagram according to a specific embodiment of the application, and the module involves an initialization process between the master key restorer and the master key publisher, and the specific process is as follows:
[0071] 1.1, the master key restorer SR selects a homomorphic encryption algorithm with additive homomorphism (for example, a paillier homomorphic encryption algorithm, corresponding to the aforementioned predetermined algorithm), generates a pair of public and private keys, denoted as <pub, pri>.
[0072] 1.2, the master key publisher SD requests the public key pub from the master key restorer SR.
[0073] 1.3, the key restorer SR performs identity authentication (for example, dynamic password, authentication based on a public key cryptography system, etc.) on the master key publisher SD, and after the authentication is passed, the public key pub is sent to the master key publisher SD.
[0074] (2) Master key shard encryption module
[0075] Figure 8 is a main key fragmentation encryption module example diagram according to the embodiment of the present application, the module involves the main key publisher to fragment the main key and encrypt the main key fragment, specifically as follows:
[0076] 2.1, the main key publisher SD owns the main key S, divides the main key S into n main key fragments s1, s2, …, sn. n (n≥2) (corresponding to the foregoing sub-key), S=s1+s2+…+sn. n .
[0077] 2.2, the main key publisher SD encrypts each plaintext main key fragment s i using the public key pub, obtains the corresponding ciphertext fragment (corresponding to the foregoing ciphertext), denoted as C i =E pub (s i )(i=1, 2, …, n), and destroys the original main key S and plaintext main key fragments s1, s2, …, sn. n .
[0078] 2.3, the main key publisher SD authenticates the n main key fragment storage identities, and after the authentication is passed, sends the n ciphertext fragments (or called main key fragments) to each main key fragment storage respectively.
[0079] 2.4, each main key fragment storage stores the ciphertext fragment.
[0080] (3) main key recovery module
[0081] Figure 8 is a main key recovery module example diagram according to the embodiment of the present application, the module involves the process that the main key restorer requests to recover the main key, specifically as follows:
[0082] If the main key restorer SR wants to recover the main key, the main key restorer SR sends a main key recovery request to the main key publisher SD, and the main key publisher SD notifies each main key fragment storage Pi (i=1, 2, …, n).
[0083] The main key recovery has two modes, Figure 8 the first mode of recovery is shown.
[0084] Mode one: the main key restorer SR collects the ciphertext fragments of each main key fragment storage, and recovers the main key, specifically including:
[0085] 3.1, the main key fragment storage P i (i=1, 2, …, n) sends the ciphertext fragment C i to the main key restorer SR.
[0086] 3.2 The master key recoverer SR decrypts each ciphertext fragment, obtaining s1, s2, ..., s1 in sequence. n That is, to obtain the master key S = s1 + s2 + ... + s n .
[0087] Method 2: The master key is fragmented and stored by P. i (i∈n) Perform the ciphertext reporting and master key recovery operation, specifically including:
[0088] 4.1. Master Key Fragmented Storer P i (i∈n) Request ciphertext master key fragments from other master key fragment stores, P. j (j≠i) For master key fragment storer P i After successful authentication, the encrypted master key fragments are sent to the master key fragment storer P. i .
[0089] 4.2. Master Key Fragmented Storer P i For master key fragments C1, C2, ..., C n Performing addition, we get C = C1 + C2 + ... + C n E pub (s i (i = 1, 2, ..., n).
[0090] According to the homomorphic property of addition, C1 + C2 + ... + C n =E pub (s1+s2+…+s n ) is established, that is
[0091] C = E pub (s1+s2+…+s n ) = E p u b (S).
[0092] 4.3 Master Key Fragmented Storer P i Send the encrypted master key C to the master key recoverer SR.
[0093] 4.4 The master key restorer SR uses the private key pri to decrypt the ciphertext C and obtain the master key S.
[0094] In Method 2 of the master key recovery module, the master key recoverer can act solely as a private key decryptor; homomorphic operations on ciphertext fragments can be performed by other master key fragment storers or other hosts. Method 2 does not include... Figure 9 As shown in the image.
[0095] In the above embodiment, the security of each master key fragment is protected by encrypting the master key fragments, thereby protecting the security of the master key; collusion attacks by each participant who has a key fragment are resisted, and the participants can only jointly restore the ciphertext of the key, but cannot obtain the plaintext key information; the plaintext of the key is restored using a cryptographic algorithm that satisfies the homomorphic addition property, so that the roles of the key storage and the key restoration are separated, and the key storage role is decentralized, thereby improving the security of key storage and restoration.
[0096] According to the embodiments of the present application, the master key is split by using the splitting mode of additive secret sharing, and is stored in a distributed manner, which improves the security of master key storage compared with single-point key storage, and also achieves the effect that the key fragment storage process has no redundancy, and the storage is indispensable; the restorer who holds the homomorphic private key is a key point, the secret fragment storage only has the ciphertext of the secret fragment, even if all the secret fragment storages collude, only the ciphertext of the master key can be obtained, and therefore, the purpose of resisting collusion among the secret fragment storages can be achieved; at the same time, the flexibility in the master key restoration process is also improved. Any host (including the secret fragment storage) can calculate the ciphertext of the master key through the additive homomorphism of the encryption algorithm, without revealing the plaintext of the master key, and only the restorer can restore the master key.
[0097] From the above description of the embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and a general hardware platform as required, and of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as a ROM / RAM, a magnetic disk, or an optical disk), and includes a plurality of instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device) to execute the method described in each embodiment of the present application.
[0098] In the present embodiment, a key restoration device is also provided in the first object, Figure 1 The structure of a key restoration device according to an embodiment of the present application is shown in Figure 9 As shown in Figure 10 The device includes:
[0099] The first obtaining module 902 is configured to obtain N sub-ciphertexts, wherein the N sub-ciphertexts are ciphertexts obtained by a second object encrypting N sub-secret keys by using a target public key and respectively sending to N third objects, the N sub-secret keys are keys obtained by the second object fragmenting a target secret key, the N sub-ciphertexts are respectively sent to the first object by the N third objects notified by the second object after the first object sends a first target request to the second object, the first target request is used to request to recover the target secret key, and N is a positive integer greater than or equal to 2.
[0100] The first recovering module 904 is configured to decrypt the N sub-ciphertexts by using a target private key to recover the target secret key, wherein the target public key and the target private key are a key pair generated by the first object by using a predetermined algorithm.
[0101] In an optional embodiment, the first recovering module 904 includes a first decryption unit configured to respectively decrypt the N sub-ciphertexts by using the target private key to obtain the N sub-secret keys, and a first recovering unit configured to recover the target secret key based on the N sub-secret keys.
[0102] In an optional embodiment, the first recovering unit includes an obtaining sub-unit configured to add the N sub-secret keys to obtain the target secret key.
[0103] In an optional embodiment, the apparatus further includes a third receiving module configured to receive a second target request sent by the second object before obtaining the N sub-ciphertexts, wherein the second target request is used to request to obtain the target public key, and a third processing module configured to send the target public key to the second object to instruct the second object to encrypt the N sub-secret keys by using the target public key to obtain the N sub-ciphertexts after authenticating an identity of the second object and passing the authentication.
[0104] In an optional embodiment, the third processing module includes a first processing unit configured to send the target public key to the second object to instruct the second object to destroy the target secret key and the N sub-secret keys.
[0105] In an optional embodiment, the third processing module includes a second processing unit configured to send the target public key to the second object to instruct the second object to respectively send the N sub-ciphertexts to the N third objects after authenticating identities of the N third objects and passing the authentication.
[0106] In an optional embodiment, the apparatus further comprises a fourth receiving module configured to receive a third target request, wherein the third target request is sent by a first target sub-object after performing a predetermined operation and obtaining a target ciphertext, the third target request is used to request decryption of the target ciphertext to recover the target key, the first target sub-object is any one of the N third objects, and the predetermined operation comprises that the first target sub-object sends a fourth target request to a second target sub-object to request acquisition of a second sub-ciphertext, wherein the second target sub-object is all objects except the first target sub-object in the N third objects, and the second sub-ciphertext comprises the sub-ciphertext stored by each object in the second target sub-object; the second sub-ciphertext is composed of the sub-ciphertext sent by each object in the second target sub-object after identity authentication of the first target sub-object and authentication passing; and the first sub-ciphertext is subjected to an addition operation with the second sub-ciphertext to obtain the target ciphertext; and a second recovering module configured to decrypt the target ciphertext based on the third target request and using the target private key to recover the target key.
[0107] In the embodiment, another key recovering apparatus is also provided, which is located in the second object, Figure 2 is a structural block of another key recovering apparatus according to an embodiment of the present application Figure 10 As shown in Figure 11 The apparatus comprises:
[0108] A first receiving module 1002 configured to receive a first target request sent by a first object, wherein the first target request is used to request recovery of a target key.
[0109] A first processing module 1004 configured to notify N third objects to send N sub-ciphertexts to the first object respectively, and instruct the first object to decrypt N sub-ciphertexts using a target private key to recover the target key, wherein the N sub-ciphertexts are ciphertexts obtained by the second object after encrypting N sub-keys using a target public key and sent to the N third objects respectively, the N sub-keys are keys obtained by the second object after fragmenting the target key, the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, and N is a positive integer greater than or equal to 2.
[0110] In the embodiment, still another key recovering apparatus is also provided, which is located in the third object, Figure 3 is a structural block of still another key recovering apparatus according to an embodiment of the present application Figure 11 As shown in The apparatus comprises:
[0111] The second receiving module 1102 is configured to receive a target notification, wherein the target notification is used to instruct each of the third objects included in the N third objects to send N sub-ciphertexts to the first object respectively, the N sub-ciphertexts are ciphertexts obtained by encrypting N sub-secret keys by the second object using a target public key and sent to the N third objects respectively, the N sub-secret keys are keys obtained by the second object by fragmenting a target secret key, the target notification is sent by the second object after receiving a first target request sent by the first object, and the first target request is used to request to recover the target secret key.
[0112] The second processing module 1104 is configured to send the sub-ciphertexts to the first object and instruct the first object to decrypt the N sub-ciphertexts using a target private key after receiving the N sub-ciphertexts to recover the target secret key, the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, and N is a positive integer greater than or equal to 2.
[0113] In an optional embodiment, the apparatus further includes a first sending module configured to send a fourth target request to a second target sub-object to request to obtain a second sub-ciphertext, wherein the second target sub-object is all objects included in the N third objects except the first target sub-object, and the second sub-ciphertext includes the sub-ciphertext stored in each of the second target sub-objects; a second obtaining module configured to obtain the second sub-ciphertext, wherein the second sub-ciphertext is composed of the sub-ciphertext sent by each of the second target sub-objects after identity authentication of the first target sub-object and passing the authentication; a first obtaining module configured to perform an addition operation on the second sub-ciphertext and a first sub-ciphertext to obtain a target ciphertext, wherein the first sub-ciphertext is the ciphertext stored in the first target sub-object; and a second sending module configured to send a third target request to the first object to request the first object to decrypt the target ciphertext to recover the target secret key.
[0114] It should be noted that each of the above modules can be implemented by software or hardware, and for the latter, the following implementation manners can be used, but are not limited thereto: all the above modules are located in the same processor; or the above modules are located in different processors in any combination.
[0115] The embodiment also provides a key recovery system, comprising a first object, a second object and N third objects, wherein the first object comprises the key recovery device in the first object, the second object comprises the key recovery device in the second object, and the third object comprises the key recovery device in the third object.
[0116] The embodiment of the present application also provides a computer readable storage medium, which stores a computer program, wherein the computer program is configured to execute the steps in any of the method embodiments when running.
[0117] In an example embodiment, the computer readable storage medium can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media capable of storing computer programs.
[0118] The embodiment of the present application also provides an electronic device, comprising a memory storing a computer program and a processor configured to execute the computer program to perform the steps in any of the method embodiments.
[0119] In an example embodiment, the electronic device can further comprise a transmission device connected to the processor and an input / output device connected to the processor.
[0120] The specific examples in the embodiment can refer to the examples described in the above embodiments and example embodiments, and will not be described here again.
[0121] Obviously, those skilled in the art should understand that the modules or steps of the present application described above can be realized by general computing devices, which can be concentrated on a single computing device or distributed on a network composed of multiple computing devices, and can be realized by program codes executable by the computing devices, so that they can be stored in storage devices and executed by the computing devices, and in some cases, the steps shown or described can be executed in different orders, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps can be manufactured into a single integrated circuit module. Therefore, the present application is not limited to any specific combination of hardware and software.
[0122] The above merely provides the preferred embodiments of the present application, and is not used to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present application shall fall into the protective scope of the present application.
Claims
1. A key recovery method, characterized in that, Applied to the first object, including: Obtain N sub-ciphertexts, wherein the N sub-ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using the target public key and then sending them to N third objects respectively; the N sub-keys are keys obtained by the second object after fragmenting the target key; the N sub-ciphertexts are sent to the first object by the second object after the first object sends a first target request to the second object; the first target request is used to request the recovery of the target key; and N is a positive integer greater than or equal to 2. The target key is recovered by decrypting N sub-ciphertexts using the target private key, wherein the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm; Before obtaining the N sub-ciphertexts, the method further includes: receiving a second target request sent by the second object, wherein the second target request is used to request the acquisition of the target public key; after authenticating the identity of the second object and the authentication is successful, sending the target public key to the second object to instruct the second object to use the target public key to encrypt the N sub-keys to obtain the N sub-ciphertexts; Sending the target public key to the second object includes: sending the target public key to the second object to instruct the second object to send the N sub-ciphertexts to the N third objects respectively after authenticating the N third objects; The method of decrypting N sub-ciphertexts using the target private key to recover the target key includes: decrypting each of the N sub-ciphertexts using the target private key to obtain N sub-keys; and recovering the target key based on the N sub-keys.
2. The method according to claim 1, characterized in that, Recovering the target key based on N sub-keys includes: The target key is obtained by performing an addition operation on the N subkeys.
3. The method according to claim 1, characterized in that, Sending the target public key to the second object includes: The target public key is sent to the second object to instruct the second object to destroy the target key and N subkeys.
4. The method according to claim 1, characterized in that, The method further includes: Receive a third target request, wherein the third target request is sent by a first target sub-object after performing a predetermined operation and obtaining target ciphertext, the third target request is used to request decryption of the target ciphertext to recover the target key, the first target sub-object is any one of the N third objects, and the predetermined operation includes: The first target sub-object sends a fourth target request to the second target sub-object to request the acquisition of the second sub-ciphertext, wherein the second target sub-object is all objects except the first target sub-object included in the N third objects, and the second sub-ciphertext includes the sub-ciphertext stored by each object in the second target sub-object; Obtain the second sub-ciphertext, wherein the second sub-ciphertext is composed of the sub-ciphertext sent by each object in the second target sub-object after authenticating the first target sub-object and the authentication is successful; Add the first sub-ciphertext to the second sub-ciphertext to obtain the target ciphertext; Based on the third target request, the target private key is used to decrypt the target ciphertext in order to recover the target key.
5. A key recovery method, characterized in that, Applied to the second object, including: Receive a first target request sent by a first object, wherein the first target request is for requesting the recovery of a target key; The system notifies N third objects to send N sub-ciphertexts to the first object, and instructs the first object to decrypt the N sub-ciphertexts using the target private key to recover the target key. The N sub-ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using the target public key and then sending them to the N third objects. The N sub-keys are keys obtained by the second object after fragmenting the target key. The target public key and the target private key are key pairs generated by the first object using a predetermined algorithm. N is a positive integer greater than or equal to 2. Before notifying N third objects to send N sub-ciphertexts to the first object respectively, and instructing the first object to decrypt the N sub-ciphertexts using the target private key to recover the target key, the method further includes: sending a second target request, wherein the second target request is used to request the first object to obtain the target public key; after the first object authenticates the identity of the second object and the authentication is successful, receiving the target public key sent by the first object; and encrypting the N sub-keys using the target public key to obtain the N sub-ciphertexts. After the first object authenticates the identity of the second object and the authentication is successful, the target public key sent by the first object is received, including: after authenticating the identities of N third objects and the authentication is successful, the N sub-ciphertexts are sent to the N third objects respectively; The first object decrypts the N sub-ciphertexts using the target private key to recover the target key, including: the first object decrypts the N sub-ciphertexts respectively using the target private key to obtain N sub-keys; and the first object recovers the target key based on the N sub-keys.
6. A key recovery method, characterized in that, When applied to a third object, including: The target notification is received, wherein the target notification is used to instruct each of the N third objects to send N sub-ciphertexts to the first object respectively, wherein the N sub-ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using the target public key and then sending them to the N third objects respectively, wherein the N sub-keys are keys obtained by the second object after fragmenting the target key, and the target notification is issued by the second object after receiving the first target request sent by the first object, wherein the first target request is used to request the recovery of the target key; The sub-ciphertext is sent to the first object, and the first object is instructed to decrypt the N sub-ciphertexts using the target private key after receiving N sub-ciphertexts in order to recover the target key. The target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, and N is a positive integer greater than or equal to 2. Before obtaining the N sub-ciphertexts, the first object is also used to receive a second target request sent by the second object, wherein the second target request is used to request to obtain the target public key; after authenticating the identity of the second object and the authentication is successful, the first object sends the target public key to the second object to instruct the second object to use the target public key to encrypt the N sub-keys to obtain the N sub-ciphertexts; Before receiving the target notification, the method further includes: authenticating the N third objects through the second object; and after the N third objects are successfully authenticated through the second object, receiving the N sub-ciphertexts sent by the second object. After receiving N sub-ciphertexts, the first object decrypts the N sub-ciphertexts using the target private key to recover the target key, including: the first object decrypts each of the N sub-ciphertexts using the target private key to obtain N sub-keys; and the first object recovers the target key based on the N sub-keys.
7. The method according to claim 6, characterized in that, The method further includes: Send a fourth target request to the second target sub-object to request the acquisition of the second sub-ciphertext, wherein the second target sub-object is all objects included in the N third objects except the first target sub-object, and the second sub-ciphertext includes the sub-ciphertext stored by each object in the second target sub-object; Obtain the second sub-ciphertext, wherein the second sub-ciphertext is composed of the sub-ciphertext sent by each object in the second target sub-object after authenticating the first target sub-object and the authentication is successful; The second sub-ciphertext is added to the first sub-ciphertext to obtain the target ciphertext, wherein the first sub-ciphertext is the ciphertext stored in the first target sub-object; A third target request is sent to the first object to request the first object to decrypt the target ciphertext in order to recover the target key.
8. A key recovery device, characterized in that, Located in the first object, including: The first acquisition module is used to acquire N sub-ciphertexts, wherein the N sub-ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using the target public key and then sending them to the N third objects respectively; the N sub-keys are keys obtained by the second object after fragmenting the target key; the N sub-ciphertexts are sent to the first object by the second object after the first object sends a first target request to the second object, and the first target request is used to request the recovery of the target key, where N is a positive integer greater than or equal to 2; The first recovery module is used to decrypt N sub-ciphertexts using the target private key to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm; The first recovery module is further configured to receive a second target request sent by the second object before obtaining the N sub-ciphertexts, wherein the second target request is used to request the acquisition of the target public key; after authenticating the identity of the second object and the authentication is successful, the target public key is sent to the second object to instruct the second object to use the target public key to encrypt the N sub-keys to obtain the N sub-ciphertexts; The device is further configured to send the target public key to the second object, so as to instruct the second object to send the N sub-ciphertexts to the N third objects respectively after authenticating the N third objects and the authentication is successful; The first recovery module includes: a first decryption unit, used to decrypt the N sub-ciphertexts using the target private key to obtain the N sub-keys; and a first recovery unit, used to recover the target key based on the N sub-keys.
9. A key recovery device, characterized in that, Located in the second object, including: A first receiving module is configured to receive a first target request sent by a first object, wherein the first target request is used to request the recovery of a target key; A first processing module is configured to notify N third objects to send N sub-ciphertexts to the first object respectively, and instruct the first object to decrypt the N sub-ciphertexts using a target private key to recover the target key. The N sub-ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using a target public key and then sending them to the N third objects respectively. The N sub-keys are keys obtained by the second object fragmenting the target key. The target public key and the target private key are key pairs generated by the first object using a predetermined algorithm. N is a positive integer greater than or equal to 2. The first object decrypting the N sub-ciphertexts using the target private key to recover the target key includes: the first object decrypting each of the N sub-ciphertexts using the target private key to obtain N sub-keys; and the first object recovering the target key based on the N sub-keys. The device is further configured to, before notifying N third objects to send N sub-ciphertexts to the first object respectively, and instructing the first object to decrypt the N sub-ciphertexts using a target private key to recover the target key, send a second target request, wherein the second target request is used to request the first object to obtain a target public key; after the first object authenticates the identity of the second object and the authentication is successful, receive the target public key sent by the first object; and encrypt the N sub-keys using the target public key to obtain the N sub-ciphertexts; The device is further configured to authenticate the identities of the N third objects, and after successful authentication, send the N sub-ciphertexts to the N third objects respectively.
10. A key recovery device, characterized in that, Located in the third object, including: The second receiving module is used to receive a target notification, wherein the target notification is used to instruct each of the N third objects to send N sub-ciphertexts to the first object respectively. The N sub-ciphertexts are ciphertexts obtained by the second object encrypting N sub-keys using the target public key and then sending them to the N third objects respectively. The N sub-keys are keys obtained by the second object after fragmenting the target key. The target notification is sent by the second object after receiving a first target request sent by the first object. The first target request is used to request the recovery of the target key. The second processing module is used to send the sub-ciphertexts to the first object and instruct the first object to decrypt the N sub-ciphertexts using the target private key after receiving N sub-ciphertexts to recover the target key. The target public key and the target private key are a key pair generated by the first object using a predetermined algorithm, where N is a positive integer greater than or equal to 2. The process of the first object decrypting the N sub-ciphertexts using the target private key to recover the target key includes: the first object decrypting each of the N sub-ciphertexts using the target private key to obtain N sub-keys; and the first object recovering the target key based on the N sub-keys. Before obtaining the N sub-ciphertexts, the first object is also used to receive a second target request sent by the second object, wherein the second target request is used to request to obtain the target public key; after authenticating the identity of the second object and the authentication is successful, the first object sends the target public key to the second object to instruct the second object to use the target public key to encrypt the N sub-keys to obtain the N sub-ciphertexts; The device is further configured to, before receiving a target notification, authenticate N of the third objects through the second object, and after authenticating N of the third objects through the second object, receive N of the sub-ciphertexts sent by the second object.
11. A key recovery system, characterized in that, include: The first object, the second object, and N third objects, among which... The first object includes the apparatus of claim 8, the second object includes the apparatus of claim 9, and the third object includes the apparatus of claim 10.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the method described in any one of claims 1-4, 5, or 6-7.
13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1-4, 5, or 6-7.
Citation Information
Patent Citations
Key management method, system and device
CN111245597A
Data uplink storage method, data uplink tracing method, device and equipment based on block chain
CN112182609A