A method, device, equipment and storage medium for secret information recovery

By utilizing smart contracts and multi-party secure computation in a trusted execution environment, the separation of the protector and the computer of secret information fragmentation is achieved, solving the problem that the trustworthiness of the administrator affects the security of secret information in existing technologies, and improving the security of secret information and its protection during transmission.

CN115766003BActive Publication Date: 2025-11-07太保科技有限公司
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211427185.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-15
Publication Date
2025-11-07
Estimated Expiration
2042-11-15

AI Technical Summary

Technical Problem

In existing technologies, because the administrator simultaneously possesses the ability to protect secret information fragments and perform multi-party secure computation, the security of secret information depends on the user's trust in the administrator, which leads to a decrease in the security of secret information.

Method used

By invoking a smart contract, the encrypted secret information fragments stored by the secret information fragment protector are sent to the corresponding computer. In a trusted execution environment, multi-party secure computation is performed to recover the secret information. The computer's public key is used for encryption and decryption, thus achieving the separation of the secret information fragment protector and the computer.

Benefits of technology

It improves the security of secret information, reduces the requirements for those who protect secret information fragments, and ensures the security of secret information fragments during transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766003B_ABST
    Figure CN115766003B_ABST
Patent Text Reader

Abstract

The application discloses a secret information recovery method, device, equipment and storage medium. The method comprises the following steps: calling a smart contract according to a secret information recovery request, sending encrypted secret information fragments saved by n secret information fragment protectors to corresponding calculators of the n secret information fragment protectors respectively; uploading the n encrypted secret information fragments received by the corresponding calculators of the n secret information fragment protectors to a trusted execution environment; and recovering secret information by multi-party secure calculation in the trusted execution environment according to the n encrypted secret information fragments. Since the secret information fragment protectors do not have multi-party secure calculation capability, the calculators with multi-party secure calculation capability can only receive the encrypted secret information fragments, so that the secret information fragments can be effectively protected, and the security of the secret information is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of multi-party secure computation, and in particular to a secret information recovery method, device, equipment and storage medium. BACKGROUND

[0002] With the popularization of Internet technology and the development of digitization, more and more secret information is saved in electronic form, and the security of secret information faces new challenges.

[0003] In the prior art, secret information is divided into multiple secret information fragments, encrypted secret information fragments are stored by multiple secret information fragment protectors, one of the multiple secret information fragment protectors is selected as a manager, when secret information needs to be recovered, the encrypted secret information fragments are decrypted into plaintext by the private key of the manager, and then the manager performs multi-party secure computation to recover the secret information.

[0004] However, since the manager is not only a secret information fragment protector but also has multi-party secure computation capability, the security of the secret information depends on the credibility of the user to the manager, which reduces the security of the secret information. SUMMARY

[0005] Based on the above problems, the present application provides a secret information recovery method, device, equipment and storage medium.

[0006] The embodiments of the present application disclose the following technical solutions:

[0007] In a first aspect, the embodiments of the present application provide a secret information recovery method, comprising:

[0008] According to the secret information recovery request, an intelligent contract is called, and the encrypted secret information fragments stored by the n secret information fragment protectors are sent to the corresponding calculators of the n secret information fragment protectors, wherein the encrypted secret information fragments are obtained by encrypting the secret information fragments by the public keys of the corresponding calculators of the secret information fragment protectors, and n is a positive integer;

[0009] The n encrypted secret information fragments received by the corresponding calculators of the n secret information fragment protectors are uploaded to a trusted execution environment;

[0010] In the trusted execution environment, the secret information is recovered by multi-party secure computation according to the n encrypted secret information fragments.

[0011] Further, the secret information is recovered by multi-party secure computation according to the n encrypted secret information fragments in the trusted execution environment, comprising:

[0012] In the trusted execution environment, the n encrypted secret information fragments are decrypted by using private keys corresponding to public keys of the n secret information fragment protectors respectively to obtain n secret information fragments;

[0013] According to the n secret information fragments, the secret information is recovered through multi-party secure computation.

[0014] Further, after the step of recovering the secret information through multi-party secure computation in the trusted execution environment according to the n encrypted secret information fragments, the method further comprises:

[0015] The smart contract is invoked to encrypt the secret information by using a public key corresponding to a private key of the user to obtain encrypted secret information.

[0016] The encrypted secret information is sent to the user.

[0017] Further, the steps of determining the secret information fragment protectors and the calculators comprise:

[0018] According to distributed digital identity information created by a plurality of secret information management participants in a blockchain, the secret information fragment protectors and the calculators are determined from the plurality of secret information management participants.

[0019] Further, the distributed digital identity information comprises a distributed digital identity identifier and an identity identification description document, and the identity identification description document comprises a public key corresponding to the distributed digital identity identifier, an identity authentication protocol and an identity authentication service endpoint.

[0020] Further, the step of invoking the smart contract according to the secret information recovery request and sending the encrypted secret information fragments saved by the n secret information fragment protectors respectively to the calculators corresponding to the n secret information fragment protectors comprises:

[0021] The smart contract is invoked according to the secret information recovery request, and a distributed digital identity identifier of a user in the secret information recovery request is verified with a distributed digital identity identifier of the user saved in the blockchain.

[0022] If the verification is passed, the encrypted secret information fragments saved by the n secret information fragment protectors respectively are sent to the calculators corresponding to the n secret information fragment protectors.

[0023] In a second aspect, an embodiment of the present application provides a secret information recovery device, comprising:

[0024] The device comprises a sending module, an uploading module and a recovery module.

[0025] The sending module is configured to call the smart contract according to a secret information recovery request, and send encrypted secret information fragments saved by the n secret information fragment protectors to the corresponding calculators of the n secret information fragment protectors respectively, wherein the encrypted secret information fragments are obtained by encrypting secret information fragments by the secret information fragment protectors using the public keys of the corresponding calculators, and n is a positive integer.

[0026] The uploading module is configured to upload the n encrypted secret information fragments received by the corresponding calculators of the n secret information fragment protectors to the trusted execution environment.

[0027] The recovery module is configured to recover secret information according to the n encrypted secret information fragments in the trusted execution environment.

[0028] Further, the recovery module comprises:

[0029] a decryption unit and a recovery unit.

[0030] The decryption unit is configured to decrypt the n encrypted secret information fragments using private keys corresponding to the public keys of the corresponding calculators of the n secret information fragment protectors in the trusted execution environment, to obtain n secret information fragments.

[0031] The recovery unit is configured to recover secret information by multi-party secure computation according to the n secret information fragments.

[0032] Further, the method further comprises an encryption module and a secret information sending module.

[0033] The encryption module is configured to call the smart contract, and encrypt the secret information using the public key corresponding to the private key of the user, to obtain encrypted secret information.

[0034] The secret information sending module is configured to send the encrypted secret information to the user.

[0035] Further, the determination of the secret information fragment protectors and the calculators comprises:

[0036] determining the secret information fragment protectors and the calculators from a plurality of secret information management participants according to distributed digital identity information created by the plurality of secret information management participants in a blockchain.

[0037] Further, the distributed digital identity information comprises a distributed digital identity identifier and an identity identification description document, and the identity identification description document comprises a public key corresponding to the distributed digital identity identifier, an identity authentication protocol, and an identity authentication service endpoint.

[0038] Further, the sending module comprises:

[0039] a checking unit and a sending unit;

[0040] The checking unit is configured to invoke the smart contract according to the secret information recovery request, and check the distributed digital identity identifier of the user in the secret information recovery request against the distributed digital identity identifier of the user saved in the blockchain.

[0041] The sending unit is configured to send the encrypted secret information fragments saved by the n secret information fragment protectors respectively to the corresponding calculators of the n secret information fragment protectors, if the checking passes.

[0042] In a third aspect, an embodiment of the present application provides a computer device, which comprises a processor and a memory:

[0043] The memory is configured to store program code and transmit the program code to the processor.

[0044] The processor is configured to execute the steps of the secret information recovery method according to the instructions in the program code.

[0045] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the secret information recovery method are implemented.

[0046] Compared with the prior art, the present application has the following beneficial effects:

[0047] According to the present application, the smart contract is invoked according to the secret information recovery request, the encrypted secret information fragments saved by the n secret information fragment protectors are sent to the corresponding calculators of the n secret information fragment protectors, and the secret information is recovered through multi-party secure calculation in the trusted execution environment according to the n encrypted secret information fragments received by the n calculators. Since the secret information fragment protectors do not have multi-party secure calculation capability, the calculators with multi-party secure calculation capability can only receive the encrypted secret information fragments, which can effectively protect the secret information fragments and improve the security of the secret information. BRIEF DESCRIPTION OF DRAWINGS

[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the description of the embodiments or the prior art will be briefly introduced. Obviously, the accompanying drawings in the following description only constitute some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.

[0049] Figure 1 A flowchart of a secret information recovery method provided by an embodiment of the present application;

[0050] Figure 2 A flowchart of a secret information fragment sending method provided by an embodiment of the present application;

[0051] Figure 3 A structural schematic diagram of a secret information recovery device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0052] As described above, how to improve the security of secret information has become a technical problem to be solved by those skilled in the art.

[0053] Through research, it is found that in the prior art, secret information is divided into multiple secret information fragments, the secret information fragments are stored by multiple secret information fragment protectors, one of the multiple secret information fragment protectors is selected as a manager, when it is necessary to recover the secret information, the encrypted secret information fragments are decrypted into plaintext by the private key of the manager, and then the manager performs multi-party secure computation to recover the secret information. Since the manager is not only a secret information fragment protector, but also has multi-party secure computation capability, the security of the secret information depends on the trustworthiness of the user to the manager. If the manager is not honest or the private key of the manager is leaked, the plaintext of the secret information fragments may be leaked, thereby existing a security risk, and the security of the secret information cannot be guaranteed.

[0054] Based on this, the present application calls a smart contract according to a secret information recovery request, sends the encrypted secret information fragments stored by the n secret information fragment protectors to the corresponding calculators of the n secret information fragment protectors, and recovers the secret information through multi-party secure computation in the trusted execution environment according to the n encrypted secret information fragments received by the n calculators. Since the secret information fragment protectors do not have multi-party secure computation capability, the calculators with multi-party secure computation capability can only receive the encrypted secret information fragments, which can effectively protect the secret information fragments and improve the security of the secret information.

[0055] In the following well-known description of the embodiments of the present application with reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be described clearly and completely, obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0056] Referring to Figure 1 The figure is a flow chart of a secret information recovery method provided by the embodiments of the present application. The secret information recovery method can be realized by S101-S103.

[0057] S101: calling a smart contract according to a secret information recovery request, sending encrypted secret information fragments saved by n secret information fragment protectors to the corresponding calculators of the n secret information fragment protectors, the encrypted secret information fragments being obtained by the secret information fragment protectors by encrypting secret information fragments with the public keys of the corresponding calculators, and n being a positive integer.

[0058] Specifically, the smart contract technology of the block chain can be used to complete the protection or recovery of the secret information in a decentralized manner. Only the user, that is, the owner of the secret information, can use the private key of the user to call the smart contract to protect the secret information, or initiate the process of secret information recovery.

[0059] According to the secret information recovery request, the smart contract is called, and the encrypted secret information fragments saved by the n secret information fragment protectors are sent to the corresponding calculators of the n secret information fragment protectors. Specifically, the secret information is divided into several parts, each part is a secret information fragment, and the encrypted secret information fragment is protected by the secret information fragment protector. When the secret information needs to be recovered, a certain number of secret information fragment protectors need to provide encrypted secret information fragments to recover the secret information. Wherein n is a positive integer, which is the number of secret information fragments required to recover the secret information.

[0060] The secret information fragment protectors and the calculators can be in a many-to-one relationship, that is, the secret information fragment protectors of different secret information can select the same calculator for multi-party secure calculation of secret information recovery. For example, secret information A corresponds to secret information fragment protectors S1, S2, and S3, secret information B corresponds to secret information fragment protectors S4, S5, and S6, and there are three calculators C1, C2, and C3. When performing secret information recovery, secret information fragment protector S1 of secret information A and secret information fragment protector S4 of secret information B can select the same calculator C1, secret information fragment protector S2 of secret information A and secret information fragment protector S5 of secret information B can select calculator C2, and secret information fragment protector S3 of secret information A and secret information fragment protector S6 of secret information B can select calculator C3.

[0061] The secret information fragment protectors have secret information fragments and do not have calculation capabilities. The secret information fragment protectors encrypt the secret information fragments using the public keys of the corresponding calculators, and send the encrypted secret information fragments to the calculators. The calculators have multi-party secure calculation capabilities to recover the secret information, but cannot obtain the plaintext of the secret information fragments, that is, the calculators can only receive the encrypted secret information fragments, thereby ensuring the security of the secret information fragments.

[0062] S102: Upload the n encrypted secret information fragments received by the n secret information fragment protectors and the corresponding calculators to a trusted execution environment.

[0063] The trusted execution environment (Trusted Execution Environment, TEE) refers to a trusted, isolated, and independent execution environment on a device that is independent of an untrusted operating system, and provides a secure and confidential space for private data and sensitive calculations in an untrusted environment. The security thereof is usually guaranteed by hardware-related mechanisms. Specifically, the hardware and software resources of a system are divided into two execution environments, namely, a trusted execution environment and a normal execution environment. The two environments are securely isolated and have independent internal data paths and computing storage spaces. Application programs in the normal execution environment cannot access the TEE. Even inside the TEE, the running of multiple applications is independent of each other and cannot access each other without authorization. The encrypted secret information fragments received by the n secret information fragment protectors and the corresponding calculators are uploaded to the trusted execution environment, so as to recover the secret information in the trusted execution environment.

[0064] S103: In the trusted execution environment, the secret information is recovered by multi-party secure calculation according to the n encrypted secret information fragments.

[0065] Specifically, the computer provides multi-party secure computing capability through the trusted execution environment, and the secret information fragments are used in the trusted execution environment, that is, the plaintext of the secret information fragments is invisible to the computer, so that the separation of the secret information fragment protector and the computer is realized, and the security of the secret information is improved.

[0066] To sum up, in the embodiment of the application, the encrypted secret information fragments obtained by the computer are uploaded to the trusted execution environment, and the secret information is recovered through multi-party secure computing in the trusted execution environment. Based on the trusted execution environment, the secret information fragment protector that provides the encrypted secret information fragments does not have multi-party secure computing capability, and the computer that has multi-party secure computing capability cannot obtain the secret information fragments, so that the separation of the secret information fragment protector and the computer is realized, and the security of the secret information fragments is improved.

[0067] Further, the above S103 can be implemented through S201-S202.

[0068] S201: In the trusted execution environment, the n encrypted secret information fragments are decrypted by using the private key corresponding to the public key of the computer corresponding to each of the n secret information fragment protectors, to obtain n secret information fragments.

[0069] Specifically, the private key corresponding to the public key of the computer corresponding to each of the n secret information fragment protectors is embedded in the trusted execution environment, so that the private key is invisible to the computer. The n encrypted secret information fragments are decrypted in the trusted execution environment by using the n private keys corresponding to the public keys of the n computers, to obtain n secret information fragments. Since the data in the trusted environment are invisible to the computer, the n secret information fragments are also invisible to the computer.

[0070] S202: The secret information is recovered through multi-party secure computing according to the n secret information fragments.

[0071] Specifically, based on the trusted execution environment, the secret information can be recovered without the computer obtaining the secret information fragments, so that the security of the secret information fragments is guaranteed.

[0072] Further, after the above S103, S301-S302 are further included.

[0073] S301: The smart contract is called, and the secret information is encrypted by using the public key corresponding to the private key of the user, to obtain encrypted secret information.

[0074] Specifically, after the secret information is recovered, the secret information is encrypted in the trusted execution environment by using the public key corresponding to the private key of the user, to guarantee the security of the recovered secret information in the transmission process.

[0075] S302: sending the encrypted secret information to the user.

[0076] Specifically, the encrypted secret information is sent to the user, ensuring the security of the recovered secret information during transmission. After receiving the encrypted secret information, the user can decrypt it using the private key stored by the user, and then obtain the secret information.

[0077] Further, the determining step of the secret information fragment protector and the calculator includes:

[0078] According to the distributed digital identity information created by the plurality of secret information management participants in the blockchain, the secret information fragment protector and the calculator are determined from the plurality of secret information management participants.

[0079] The distributed digital identity information is created on the blockchain for the secret information management participants using the distributed digital identity technology (DID). The secret information management participants include users, secret information fragment protectors, and calculators. Each identity corresponding to the distributed digital identity information needs to be created on the blockchain, such as the distributed digital identity information of the user, the distributed digital identity information of the secret information fragment protector, and the distributed digital identity information of the calculator. According to the distributed digital identity information, the secret information fragment protector and the calculator can be determined from the plurality of secret information management participants.

[0080] Specifically, the distributed digital identity information includes a distributed digital identity identifier and an identity description document.

[0081] The distributed digital identity identifier corresponds to the identity of the secret information management participant and is used to represent the unique identity of a secret information management participant in the secret information management system. The corresponding secret information management participant can be specified as a secret information fragment protector according to the distributed digital identity identifier. Thus, the identities of the n secret information fragment protectors can be determined according to the distributed digital identity identifiers of the n secret information fragment protectors, and the n secret information fragments stored in the blockchain can be allocated to the corresponding n secret information fragment protectors. Each secret information fragment corresponds to a unique distributed digital identity identifier of a secret information fragment protector. Through the smart contract, it can be verified whether each distributed digital identity identifier is a valid distributed identifier registered on the blockchain, thereby ensuring that the secret information fragments are allocated to the correct secret information fragment protectors. Similarly, the calculator can be determined according to the distributed digital identity identifier. The identity description document includes the public key corresponding to the distributed digital identity identifier, the identity authentication protocol, and the identity authentication service endpoint. The public key can be used to encrypt the secret information fragment.

[0082] The secret information management participant only needs to provide its own identity information to register its distributed digital identity information on the blockchain. When the user needs to select a secret information shard protector, the user only needs to select a unique distributed digital identity identifier corresponding to the identity. The selected secret information shard protector can be a person trusted by the user or a familiar person around the user, which can be freely selected by the user. Meanwhile, compared with the prior art, the secret information shard protector needs to have multi-party secure computing capability, which requires high cost and limits the selection of the secret information shard protector by the user. The method provided in the embodiments of the present application reduces the requirement for the secret information shard protector, because the secret information protector does not need to have multi-party secure computing capability and is only responsible for protecting the secret information shard.

[0083] Further, S101 can be implemented through S401-S402, as shown in the figure, which is a flowchart of a secret information shard sending method provided in the embodiments of the present application. Figure 2

[0084] S401: According to the secret information recovery request, the smart contract is called, and the distributed digital identity identifier of the user in the secret information recovery request is checked with the distributed digital identity identifier of the user saved in the blockchain.

[0085] Specifically, the user can sign the secret information shard using a private key, and send the distributed digital identity identifier of the user and the signature to the smart contract. When the secret information needs to be recovered, the smart contract is called according to the secret information recovery request, and the distributed digital identity identifier of the user in the secret information recovery request is checked with the distributed digital identity identifier of the user saved in the blockchain, to ensure that the secret information recovery request is initiated by the user.

[0086] S402: If the check passes, the encrypted secret information shards saved by the n secret information shard protectors are sent to the corresponding calculators of the n secret information shard protectors.

[0087] Specifically, if the check passes, it means that the secret information recovery request is initiated by the user, and the encrypted secret information shards saved by the n secret information shard protectors can be sent to the corresponding calculators of the n secret information shard protectors to recover the secret information.

[0088] ​To sum up, in the embodiment of the application, the secret information fragment protector is responsible for protecting the secret information fragments, and does not have the multi-party secure computing capability, thereby reducing the requirement for the secret information fragment protector. The computer provides the multi-party secure computing capability in the trusted execution environment, and can perform computation on the encrypted secret information fragments provided by the secret information fragment protector to recover the secret information. Through the distributed digital identity technology and the trusted execution environment technology, the separation between the secret information fragment protector and the computer is realized, and the security of the secret information is improved.

[0089] The embodiment of the application provides a secret information recovery device. Figure 3 As shown in the figure, it is a structure schematic diagram of a secret information recovery device provided by the embodiment of the application. The specific implementation manner is consistent with the implementation manner recorded in the above-mentioned method embodiment, and the technical effects achieved are consistent. Part of the content will not be repeated.

[0090] A secret information recovery device comprises:

[0091] The sending module 1101, the uploading module 1102 and the recovery module 1103.

[0092] The sending module 1101 is configured to call an intelligent contract according to a secret information recovery request, and send the encrypted secret information fragments saved by the n secret information fragment protectors respectively to the computers corresponding to the n secret information fragment protectors respectively, wherein the encrypted secret information fragments are obtained by encrypting the secret information fragments by the secret information fragment protectors using the public keys of the computers corresponding to the secret information fragment protectors, and n is a positive integer.

[0093] The uploading module 1102 is configured to upload the n encrypted secret information fragments received by the computers corresponding to the n secret information fragment protectors respectively to a trusted execution environment.

[0094] The recovery module 1103 is configured to recover the secret information according to the n encrypted secret information fragments in the trusted execution environment.

[0095] Further, the recovery module 1103 comprises:

[0096] A decryption unit and a recovery unit.

[0097] The decryption unit is configured to decrypt the n encrypted secret information fragments using the private keys corresponding to the public keys of the computers corresponding to the n secret information fragment protectors respectively in the trusted execution environment, and obtain n secret information fragments.

[0098] The recovery unit is configured to recover the secret information through multi-party secure computation according to the n secret information fragments.

[0099] Further, the method further comprises: an encryption module and a secret information sending module;

[0100] The encryption module is configured to call the smart contract, encrypt the secret information by using a public key corresponding to a private key of the user, and obtain encrypted secret information.

[0101] The secret information sending module is configured to send the encrypted secret information to the user.

[0102] Further, the determining of the secret information shard protector and the computer comprises:

[0103] The secret information shard protector and the computer are determined from a plurality of secret information management participants according to distributed digital identity information created by the plurality of secret information management participants in a blockchain.

[0104] Further, the distributed digital identity information comprises a distributed digital identity identifier and an identity identification description document, and the identity identification description document comprises a public key corresponding to the distributed digital identity identifier, an identity authentication protocol and an identity authentication service endpoint.

[0105] Further, the sending module comprises:

[0106] a verification unit and a sending unit;

[0107] The verification unit is configured to call the smart contract according to a secret information recovery request, and verify a distributed digital identity identifier of the user in the secret information recovery request with a distributed digital identity identifier of the user saved in the blockchain.

[0108] The sending unit is configured to send encrypted secret information shards saved by the n secret information shard protectors to the computers corresponding to the n secret information shard protectors, respectively, if the verification is passed.

[0109] In summary, in the embodiments of the present application, the encrypted secret information shards obtained by the computers are uploaded to the trusted execution environment, and the secret information is recovered through multi-party secure computation in the trusted execution environment. Based on the trusted execution environment, the secret information shard protectors that provide the encrypted secret information shards do not have multi-party secure computation capability, and the computers that have multi-party secure computation capability cannot obtain the secret information shards, so that the separation of the secret information shard protectors and the computers is realized, and the security of the secret information shards is improved.

[0110] The embodiments of the present application also provide a computer device, which comprises a processor and a memory:

[0111] The memory is configured to store program code and transmit the program code to the processor.

[0112] The processor is configured to execute steps of the method for recovering secret information according to instructions in the program code.

[0113] The application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement steps of the method for recovering secret information.

[0114] It should be noted that each of the embodiments in the specification adopts a progressive manner for description, and the same parts between each of the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments. Especially, the device, equipment and storage medium embodiments are described simply because they are basically similar to the method embodiments. The relevant parts can be referred to the part of the method embodiments. The device, equipment and storage medium embodiments described above are only illustrative, and the units described as separate components can be or can not be physically separated, and the components indicated as units can be or can not be physical units, that is, they can be located in one place or distributed on multiple network units. According to the actual needs, part or all of the modules can be selected to achieve the purpose of the embodiments. Those skilled in the art can understand and implement it without creative labor.

[0115] The above description is only one specific embodiment of the application, but the protection scope of the application is not limited to this. Any skilled person in the art can easily think of changes or replacements within the technical range disclosed in the application, which should be covered in the protection scope of the application. Therefore, the protection scope of the application should be subject to the protection scope of the claims.

Claims

1. A method of secret information recovery, characterized by, The method comprises the following steps: According to the secret information recovery request, the smart contract is called, and the encrypted secret information fragments saved by the n secret information fragment protectors are sent to the corresponding calculators of the n secret information fragment protectors, wherein the encrypted secret information fragments are obtained by encrypting the secret information fragments by the secret information fragment protectors using the public keys of the corresponding calculators, and n is a positive integer; the secret information fragment protectors have the secret information fragments and do not have the multi-party secure computing capability of recovering the secret information; the calculators have the multi-party secure computing capability of recovering the secret information; The n encrypted secret information fragments received by the corresponding calculators of the n secret information fragment protectors are uploaded to a trusted execution environment; In the trusted execution environment, the secret information is recovered by multi-party secure computing according to the n encrypted secret information fragments.

2. The method of claim 1, wherein, The step of recovering the secret information by multi-party secure computing according to the n encrypted secret information fragments in the trusted execution environment comprises the following steps: In the trusted execution environment, the n encrypted secret information fragments are decrypted by using the private keys corresponding to the public keys of the corresponding calculators of the n secret information fragment protectors, and n secret information fragments are obtained; The secret information is recovered by multi-party secure computing according to the n secret information fragments.

3. The method of claim 1, wherein, After the step of recovering the secret information by multi-party secure computing according to the n encrypted secret information fragments in the trusted execution environment, the following steps are further included: The smart contract is called, the secret information is encrypted by using the public key corresponding to the private key of the user, and the encrypted secret information is obtained; The encrypted secret information is sent to the user.

4. The method of claim 1, wherein, The determination of the secret information fragment protectors and the calculators comprises the following steps: According to the distributed digital identity information created by a plurality of secret information management participants in a blockchain, the secret information fragment protectors and the calculators are determined from the plurality of secret information management participants.

5. The method of claim 4, wherein, The distributed digital identity information comprises a distributed digital identity identifier and an identity identification description document, and the identity identification description document comprises a public key corresponding to the distributed digital identity identifier, an identity authentication protocol and an identity authentication service endpoint.

6. The method of claim 1, wherein, The step of calling the smart contract according to the secret information recovery request and sending the encrypted secret information fragments saved by the n secret information fragment protectors to the corresponding calculators of the n secret information fragment protectors comprises the following steps: According to the secret information recovery request, the smart contract is called, and the distributed digital identity identifier of the user in the secret information recovery request is verified with the distributed digital identity identifier of the user saved in the blockchain; If the verification is passed, the encrypted secret information fragments saved by the n secret information fragment protectors are sent to the corresponding calculators of the n secret information fragment protectors.

7. An apparatus for secret information recovery, characterized by comprising: The method comprises the following steps: The sending module, the uploading module and the recovering module are included. The sending module is configured to call a smart contract according to a secret information recovery request, and send encrypted secret information fragments saved by n secret information fragment protectors to corresponding calculators of the n secret information fragment protectors respectively, the encrypted secret information fragments being obtained by encrypting secret information fragments by the secret information fragment protectors using public keys of the corresponding calculators, n being a positive integer; the secret information fragment protectors have the secret information fragments and do not have multi-party secure computing capability for recovering the secret information; and the calculators have the multi-party secure computing capability for recovering the secret information. The uploading module is configured to upload the n encrypted secret information fragments received by the corresponding calculators of the n secret information fragment protectors to a trusted execution environment. The recovery module is configured to recover the secret information according to the n encrypted secret information fragments in the trusted execution environment.

8. The apparatus of claim 7, wherein, The recovery module includes: a decryption unit and a recovery unit. The decryption unit is configured to decrypt the n encrypted secret information fragments using private keys corresponding to the public keys of the corresponding calculators of the n secret information fragment protectors in the trusted execution environment, to obtain n secret information fragments. The recovery unit is configured to recover the secret information by multi-party secure computing according to the n secret information fragments.

9. A computer device, comprising: The computer device includes a processor and a memory: The memory is configured to store program code and transmit the program code to the processor. The processor is configured to execute the steps of the secret information recovery method according to instructions in the program code.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the steps of the secret information recovery method. The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the steps of the secret information recovery method.

Citation Information

Patent Citations

  • Secure multi-party computing method, device and system and storage medium

    CN112751665A

  • Method, device and system for acquiring data authorization

    CN113987554A

  • Secret image sharing and recovering method based on block chain

    CN114826564A

  • Distributed anonymized compliant encryption management system

    TW202213147A