Threshold encryption and decryption method, device and computer equipment for group member data protection

Through the threshold encryption and decryption method of group member data protection, the symmetric key and decryption shards of group public key encryption are used for decryption operations, which solves the problem of key loss and backup key easy loss, and improves the security of data decryption.

CN115834122BActive Publication Date: 2025-05-13HANGZHOU DBAPPSECURITY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211278107.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-19
Publication Date
2025-05-13
Estimated Expiration
2042-10-19

AI Technical Summary

Technical Problem

In the prior art, there is a lack of effective solution to the problem of loss of keys that lead to inability to decrypt and easy loss of backup keys.

Method used

The threshold encryption and decryption method of group member data protection is adopted. By obtaining the symmetric key encrypted by the group public key, the encrypted shard is verified, and the decryption shard is obtained based on the private key of the threshold group members, and the decryption operation is performed to restore the symmetric key and original data.

Benefits of technology

It solves the problem that key loss causes undecryption and backup keys are easily lost, and prevents the loss of keys from being undecrypted, and improves the security of secrets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834122B_ABST
    Figure CN115834122B_ABST
Patent Text Reader

Abstract

The present application relates to a threshold encryption and decryption method, apparatus and computer equipment for group member data protection, wherein the threshold encryption and decryption method for group member data protection comprises: encrypting original data and a symmetric key to obtain encrypted data, and encrypting the symmetric key and the group public key to obtain a symmetric key encrypted by the group public key, wherein the symmetric key encrypted by the group public key comprises an encrypted segment; sending the encrypted segment to the group member, verifying the encrypted segment, and if the verification passes, obtaining the corresponding decrypted segment according to the private key of a threshold number of group members, decrypting the symmetric key and the decrypted segment encrypted by the group public key to obtain the symmetric key, and decrypting the encrypted data and the symmetric key to obtain the original data. Through the present application, the problem of being unable to decrypt due to key loss and the problem of easy loss of backup keys is solved, and the problem of being unable to decrypt due to key loss is prevented and the security of secrets is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security, and in particular to a threshold encryption and decryption method, apparatus, and computer equipment for protecting group member data. Background Art

[0002] With the development of computers and the widespread application of network communication technology, data storage methods have gradually changed from paper storage to electronic storage. However, storing large amounts of data in electronic storage presents problems with data classification management and storage security. Therefore, secret sharing mechanisms are usually used to solve the problem of securely managing data storage keys.

[0003] The current key management scheme saves important file data based on a primary key and other keys. However, if the primary key is lost, the file data encrypted by the primary key cannot be decrypted by other keys. Alternatively, the primary key is backed up in multiple copies, in multiple locations, and by multiple people to prevent the loss of the primary key. However, this makes it easy for the key to be stolen, resulting in the loss of important files, and the risk of leakage of encrypted important data.

[0004] With regard to the problems in the related art where key loss results in inability to decrypt and backup keys are easily lost, no effective solution has been proposed yet. Summary of the invention

[0005] In this embodiment, a threshold encryption and decryption method, apparatus, computer equipment and storage medium for protecting group member data are provided to solve the problems in the related art of being unable to decrypt due to key loss and easy loss of backup keys.

[0006] In a first aspect, a threshold decryption method for protecting group member data is provided in this embodiment, which is applied to a server side. The threshold decryption method includes:

[0007] Obtaining a symmetric key encrypted by a group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment;

[0008] Send the encrypted slice to the group members, verify the encrypted slice, and if the verification is successful, obtain the corresponding decrypted slice according to the private keys of the threshold group members;

[0009] The encrypted data is obtained, a decryption operation is performed on the symmetric key encrypted by the group public key and the decryption slice to obtain a symmetric key, and a decryption operation is performed on the encrypted data and the symmetric key to obtain original data.

[0010] In some embodiments, sending the encrypted slice to the group member and verifying the encrypted slice includes:

[0011] sending the encrypted fragments to the group members;

[0012] The encrypted shards are verified through non-interactive zero-knowledge proof.

[0013] In some embodiments, if the verification is successful, then obtaining corresponding decrypted fragments according to the private keys of at least two of the group members includes:

[0014] If the verification is successful, obtaining the private keys of a threshold number of the group members;

[0015] The private key and the encrypted fragment of each of the group members are calculated to obtain the decrypted fragment of each of the group members.

[0016] In some embodiments, performing a decryption operation on the symmetric key encrypted by the group public key and the decryption slice to obtain the symmetric key includes:

[0017] Based on the decryption process of the Elgamal encryption algorithm, a decryption operation is performed on the symmetric key encrypted by the group public key and the decryption fragment to obtain the symmetric key.

[0018] In a second aspect, an encryption method for protecting group member data is provided in this embodiment, which is applied to a client side. The encryption method includes:

[0019] Get the original data and symmetric key;

[0020] Performing encryption operation on the original data and the symmetric key to obtain encrypted data;

[0021] The group public key of the group member is obtained, and the symmetric key and the group public key are encrypted to obtain the symmetric key encrypted by the group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment.

[0022] In some embodiments, obtaining a group public key of a group member includes:

[0023] obtaining a private key of each member of the group;

[0024] Obtaining a public key of each of the group members according to the private key;

[0025] An aggregation operation is performed on the public keys to obtain the group public key.

[0026] In some embodiments, the symmetric key and the group public key are encrypted to obtain a symmetric key encrypted by the group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment, including:

[0027] Performing encryption operation on the symmetric key and the group public key by using the Elgamal encryption algorithm to obtain a symmetric key encrypted by the group public key;

[0028] During the encryption operation, a non-interactive zero-knowledge proof corresponding to the user is generated according to the user's private key to obtain the encrypted fragment.

[0029] In a third aspect, a threshold decryption device for group member data protection is provided in this embodiment, and the device includes:

[0030] A first acquisition module acquires a symmetric key encrypted by a group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment;

[0031] A first verification module sends the encrypted slice to the group members, verifies the encrypted slice, and if the verification is successful, obtains the corresponding decrypted slice according to the private keys of at least two of the group members;

[0032] The first decryption module obtains the encrypted data, performs a decryption operation on the symmetric key encrypted by the group public key and the decryption slice to obtain the symmetric key, and performs a decryption operation on the encrypted data and the symmetric key to obtain the original data.

[0033] In a fourth aspect, a computer device is provided in this embodiment, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the threshold decryption method for protecting group member data as described in the first aspect when executing the computer program.

[0034] In a fifth aspect, in this embodiment, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the threshold decryption method for protecting group member data described in the first aspect above is implemented.

[0035] Compared with the related art, the threshold encryption and decryption method, apparatus and computer equipment for group member data protection provided in this embodiment obtains the symmetric key encrypted by the group public key, the symmetric key encrypted by the group public key includes an encrypted segment, and sends the encrypted segment to the group member, verifies the encrypted segment, and if the verification passes, obtains the corresponding decrypted segment according to the private keys of at least two group members, further obtains the encrypted data, performs decryption operation on the symmetric key encrypted by the group public key and the decrypted segment to obtain the symmetric key, and performs decryption operation on the encrypted data and the symmetric key to obtain the original data, thereby solving the problem of being unable to decrypt due to key loss and the problem of easy loss of backup keys, and preventing being unable to decrypt due to key loss and effectively improving the security of secrets.

[0036] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0038] Figure 1 It is a hardware structure block diagram of a terminal device of a threshold decryption method for group member data protection provided by an embodiment of the present application;

[0039] Figure 2 It is a flow chart of a threshold decryption method for group member data protection provided by an embodiment of the present application;

[0040] Figure 3 It is a schematic diagram of the principle of a threshold decryption method for group member data protection provided by an embodiment of the present application;

[0041] Figure 4 is a flow chart of an encryption method for protecting group member data provided by an embodiment of the present application;

[0042] Figure 5 It is a schematic diagram of the principle of an encryption method for protecting group member data provided by an embodiment of the present application;

[0043] Figure 6 This is a preferred flow chart of a threshold encryption and decryption method for group member data protection provided by an embodiment of the present application;

[0044] Figure 7 It is a structural block diagram of a threshold decryption device for group member data protection provided by an embodiment of the present application;

[0045] Figure 8 It is a structural block diagram of an encryption device for protecting group member data provided by an embodiment of the present application.

[0046] In the figure: 10, first acquisition module; 20, first verification module; 30, first decryption module; 100, second acquisition module; 200, first encryption module; 300, second encryption module. DETAILED DESCRIPTION

[0047] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present application is described and illustrated below in conjunction with the accompanying drawings and embodiments.

[0048] Unless otherwise defined, the technical terms or scientific terms involved in this application shall have the general meaning understood by people with ordinary skills in the technical field to which this application belongs. The words "one", "a", "a", "the", "these" and the like in this application do not represent quantitative restrictions, and they can be singular or plural. The terms "include", "comprise", "have" and any variants thereof involved in this application are intended to cover non-exclusive inclusions; for example, a process, method and system, product or device comprising a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent to these processes, methods, products or devices. The words "connect", "connected", "coupled" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether directly or indirectly. The "multiple" involved in this application refers to two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, "A and / or B" can mean: A exists alone, A and B exist at the same time, and B exists alone. Usually, the character " / " indicates that the objects associated with each other are in an "or" relationship. The terms "first", "second", "third", etc. involved in this application are only used to distinguish similar objects and do not represent a specific ordering of the objects.

[0049] The method embodiment provided in this embodiment can be executed in a terminal, a computer or a similar computing device. For example, running on a terminal, Figure 1 1 is a hardware structure block diagram of a terminal of the threshold encryption and decryption method for group member data protection of this embodiment. Figure 1 As shown, the terminal may include one or more ( Figure 1 Only one is shown in the figure) processor 102 and memory 104 for storing data, wherein processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA. The above terminal may also include a transmission device 106 and an input and output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations shown.

[0050] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the threshold encryption and decryption method for group member data protection in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0051] The transmission device 106 is used to receive or send data via a network. The above network includes a wireless network provided by the communication provider of the terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, referred to as RF) module, which is used to communicate with the Internet wirelessly.

[0052] In this embodiment, a threshold decryption method for protecting group member data is provided. Figure 2 is a flow chart of the threshold decryption method for group member data protection of this embodiment. Figure 2 As shown, the process includes the following steps:

[0053] Step S210, obtaining a symmetric key encrypted by a group public key, where the symmetric key encrypted by the group public key includes an encryption fragment.

[0054] Specifically, obtain the symmetric key encrypted by the group public key, that is, Enc(Y, Key)= <g r ,Key Y r , z>, where the symmetric key encrypted by the group of public keys includes the encrypted fragment <g r , z>.

[0055] Step S220, the encrypted slice is sent to the group members, and the encrypted slice is verified. If the verification is successful, the corresponding decrypted slice is obtained according to the private keys of the threshold group members.

[0056] What you need to know is that each group member randomly generates a corresponding private key s i , each group member cannot obtain the private key shards of other group members, and at the same time, each group member cannot obtain the symmetric key encrypted by the group public key.

[0057] Step S230, obtaining encrypted data, performing a decryption operation on the symmetric key and the decryption slice encrypted by the group public key to obtain the symmetric key, and performing a decryption operation on the encrypted data and the symmetric key to obtain the original data.

[0058] What you need to know is that Figure 3 As shown, the encrypted data is obtained by encrypting the original data with a symmetric key. The secret holder needs to decrypt the symmetric key encrypted by the group public key through a threshold number of decryption fragments to obtain the symmetric key, and then further decrypt the encrypted data to obtain the original data.

[0059] The current key management scheme saves important file data based on a primary key and other keys. However, if the primary key is lost, the file data encrypted by the primary key cannot be decrypted by other keys, or the primary key is further backed up in multiple copies, multiple locations, and multiple people to prevent the loss of the primary key. However, this makes the key easy to be stolen, resulting in the loss of important files, and the encrypted important data is at risk of leakage. The present application optimizes the key preservation method in the prior art, firstly obtains the symmetric key encrypted by the group public key, wherein the symmetric key encrypted by the group public key includes an encrypted segment, and sends the encrypted segment to the group member, verifies the encrypted segment, and if the verification is passed, obtains the corresponding decrypted segment according to the private key of the threshold group member, further obtains the encrypted data, performs a decryption operation on the symmetric key encrypted by the group public key and the decryption segment, obtains the symmetric key, and performs a decryption operation on the encrypted data and the symmetric key to obtain the original data, thereby solving the problem of being unable to decrypt due to key loss, preventing the inability to decrypt due to key loss, and effectively improving the security of secrets.

[0060] In some embodiments, sending the encrypted slices to the group members and verifying the encrypted slices includes the following steps:

[0061] Step S221, sending the encrypted fragments to group members;

[0062] Step S222: verify the encrypted shards through non-interactive zero-knowledge proof.

[0063] Specifically, the encrypted shard of the secret holder <g r , z> is ​​sent to the group members according to the public key g of the secret holder in the encrypted shard r and non-interactive zero-knowledge proof z, verifying the equation g z =g r *X e Is it true, where g is the generator, r is the random factor, z = r + x * e, e = Hash (g r||Y||X), x is the identity private key of the secret holder, X=g x The public key of the secret holder.

[0064] It is important to know that in the process of verifying the encrypted shard, the random challenge number e is calculated by the hash function, where the hash function is a one-way hash function, and the secret holder cannot predict the output of the hash function, so group members can verify the encrypted shard through the public key of the secret holder without interaction.

[0065] Through this embodiment, the encrypted slice is sent to the group members, and the corresponding equation is verified based on the public key of the secret holder in the encrypted slice and the non-interactive zero-knowledge proof to determine whether g r Whether it is generated by the secret holder, so as to ensure that users other than the secret holder cannot obtain the decrypted fragment, thereby improving the security of the decryption process.

[0066] In some of the embodiments, if the verification is successful, the corresponding decrypted fragments are obtained according to the private keys of the threshold group members, including the following steps:

[0067] If the verification is successful, the private keys of the threshold group members are obtained;

[0068] The private key and encrypted slice of each group member are calculated to obtain the decrypted slice of each group member.

[0069] What you need to know is that if you verify the equation g z =g r *X e Established, indicating that g in the encrypted shard r is generated by the secret holder, then the private keys s of the threshold k group members are obtained i , where 2≤k≤n, n is the number of all group members, and each group member P i Generate a random k-1 degree polynomial f i (x), the polynomial f i (x) satisfies f i (0) = s i .

[0070] Specifically, assuming f(x) = ∑ i f i (x), then the group private key is f(0) = ∑ i s i =S, and each group member P i Has a unique identity information identifier, denoted by x i , and by calculating f i (x j ) is forwarded to group member P j , then group member Pi Summarize the other group members j (x i ) is calculated to obtain the threshold k group private key shards, that is, ∑ i f j (x i )=f(x i )=sk i .

[0071] Furthermore, among the threshold k group members, the group private key is fragmented into sk i and g in the encrypted shard r Calculate and get the threshold k decryption fragments And through a one-way encrypted channel, the threshold k decrypted fragments Sent to the secret holder whose secret has been verified by equation.

[0072] Through this embodiment, after the verification equation is established, the private keys of the threshold group members are obtained, and the private key and encrypted slice of each group member are calculated to obtain the decrypted slices of the threshold group members. Therefore, under the premise of determining the identity information of the secret holder, the decrypted slices of the threshold group members are securely obtained and securely transmitted.

[0073] In some embodiments, performing a decryption operation on the symmetric key encrypted by the group public key and the decryption slice to obtain the symmetric key includes the following steps:

[0074] Based on the decryption process of the Elgamal encryption algorithm, the symmetric key encrypted by the group public key and the decryption fragment are decrypted to obtain the symmetric key.

[0075] Specifically, the threshold decryption fragments are aggregated and calculated to obtain in Δ i (0) is the Lagrangian constant, and based on the decryption process of the Elgamal encryption algorithm (abbreviated as the Elgamal encryption algorithm), calculate That is, the symmetric key is obtained.

[0076] It should be noted that in the process of encrypting the symmetric key with the group public key, the symmetric key Key and the group public key Y are encrypted to obtain the symmetric key encrypted with the group public key, that is, Enc(Y, Key) = <g r ,Key Y r , z>, correspondingly, due to Y r =(g s ) r , then aggregate the threshold decrypted fragments to obtain (g r ) s , and further obtain the symmetric key Key.

[0077] Through this embodiment, based on the decryption process of the Elgamal encryption algorithm, a decryption operation is performed on the symmetric key and the decryption slice encrypted by the group public key to obtain the symmetric key, thereby realizing the recovery of the symmetric key through a threshold number of decryption slices.

[0078] In this embodiment, an encryption method for protecting group member data is also provided. Figure 4 is a flow chart of the encryption method for protecting group member data of this embodiment. Figure 4 As shown, the process includes the following steps:

[0079] Step S410, obtaining original data and a symmetric key.

[0080] Step S420, performing encryption operation on the original data and the symmetric key to obtain encrypted data.

[0081] Specifically, the encrypted data is obtained by encrypting the original data with a symmetric key, where symmetric key encryption means that the two parties sending and receiving the data must use the same key to encrypt and decrypt the plaintext, and the symmetric key encryption algorithms mainly include the standard encryption algorithm (Data Encryption Standard, abbreviated as DES), the triple standard encryption algorithm (Triple Data Encryption Standard, abbreviated as TDES) and the international data encryption algorithm (International Data Encryption Algorithm, abbreviated as IDEA), etc.

[0082] It is important to know that there are multiple modes for encrypting original data using symmetric keys, which are mainly divided into two categories: sequence encryption mode and block encryption mode. The sequence encryption mode includes self-synchronous sequence encryption mode and synchronous sequence encryption mode, while the block encryption mode includes electronic code book mode, encrypted block link mode, encrypted feedback mode and output feedback mode.

[0083] Step S430, obtaining the group public key of the group member, performing encryption operation on the symmetric key and the group public key, and obtaining the symmetric key encrypted by the group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment.

[0084] What you need to know is that Figure 5 As shown, the symmetric key Key and the group public key Y are encrypted to obtain the symmetric key encrypted by the group public key, and the original data M is encrypted by the symmetric key, so that in the decryption process, after the symmetric key is restored by a threshold number of group members, only the secret holder can further decrypt the encrypted data to obtain the original data.

[0085] The current key management scheme saves important file data based on a primary key and other keys. However, if the primary key is lost, the file data encrypted by the primary key cannot be decrypted by other keys, or the primary key is further backed up in multiple copies, multiple locations, and multiple people to prevent the loss of the primary key. However, this makes the key easy to be stolen, resulting in the loss of important files, and the encrypted important data is at risk of leakage. This embodiment optimizes the encryption method and key preservation method in the prior art, based on the Elgamal encryption algorithm, through a dual encryption method of encrypting the original data with a symmetric key and encrypting the symmetric key with a group public key, thereby improving the security of data encryption and solving the problem of easy loss of backup keys.

[0086] In some embodiments, obtaining a group public key of a group member includes the following steps:

[0087] Step S421, obtaining the private key of each group member;

[0088] Step S422, obtaining the public key of each group member according to the private key;

[0089] Step S423, performing aggregation operation on the public keys to obtain a group public key.

[0090] Specifically, according to the private key s of each group member i , calculate the public key corresponding to each group member And perform aggregation operation on the public key of each group member to obtain the group public key Where g is the generator.

[0091] What you need to know is that the private key s corresponding to each group member i is a randomly generated random integer.

[0092] Through this embodiment, the public key corresponding to each group member is obtained according to the private key of each group member, and further, the group public key is calculated, so that the symmetric key can be encrypted using the group public key.

[0093] In some embodiments, performing an encryption operation on a symmetric key and a group public key to obtain a symmetric key encrypted by the group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment, comprises the following steps:

[0094] Step S431, using the Elgamal encryption algorithm, encrypting the symmetric key and the group public key to obtain a symmetric key encrypted by the group public key;

[0095] Step S432, during the encryption operation, a non-interactive zero-knowledge proof corresponding to the user is generated according to the user's private key to obtain an encrypted fragment.

[0096] It should be noted that the Elgamal encryption algorithm is an asymmetric encryption algorithm based on the Diffie-Hellman key exchange, which specifically includes three processes: key generation, encryption, and decryption. Here, through the encryption process of the Elgamal encryption algorithm, the symmetric key Key and the group public key Y are encrypted to obtain the symmetric key encrypted by the group public key, that is, Enc(Y, Key) = <g r ,Key Y r , z>, where r is the random factor and z is the non-interactive zero-knowledge proof corresponding to the secret holder.

[0097] Specifically, in the process of encrypting the symmetric key, based on the secret holder generating g r , and it can be verified that g r Is consistent with the identity information of the secret holder, generating a non-interactive zero-knowledge proof z corresponding to the secret holder, where z = r + x * e, e = Hash (g r ||Y||X), x is the identity private key of the secret holder, X=g x The public key of the secret holder.

[0098] Furthermore, after obtaining the non-interactive zero-knowledge proof corresponding to the secret holder, the encrypted shard is generated <g r , z>, and in the process of encrypting the symmetric key with the group public key, the encrypted fragments are generated synchronously.

[0099] Through this embodiment, the symmetric key and the group public key are encrypted by the Elgamal encryption algorithm to obtain the symmetric key encrypted by the group public key, and in the process of encryption operation, a non-interactive zero-knowledge proof corresponding to the secret holder is generated according to the user's private key to obtain the encrypted fragment, so that the non-interactive zero-knowledge proof in the encrypted fragment can be verified to determine whether g r Whether it is consistent with the identity information of the secret holder.

[0100] The present embodiment is described and illustrated below through preferred embodiments.

[0101] Figure 6 is a preferred flow chart of the threshold encryption and decryption method for group member data protection in this embodiment, such as Figure 6 As shown, the threshold encryption and decryption method for protecting the group member data includes the following steps:

[0102] Step S610, obtaining original data and symmetric key;

[0103] Step S620, performing encryption operation on the original data and the symmetric key to obtain encrypted data;

[0104] Step S630, obtaining the group public key of the group member, performing encryption operation on the symmetric key and the group public key to obtain a symmetric key encrypted by the group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment;

[0105] Step S640, obtaining a symmetric key encrypted by a group public key, where the symmetric key encrypted by the group public key includes an encryption fragment;

[0106] Step S650, sending the encrypted slice to the group members, verifying the encrypted slice, and if the verification is successful, obtaining the corresponding decrypted slice according to the private keys of the threshold group members;

[0107] Step S660, obtaining the encrypted data, performing a decryption operation on the symmetric key and the decryption slice encrypted by the group public key to obtain the symmetric key, and performing a decryption operation on the encrypted data and the symmetric key to obtain the original data.

[0108] Through this embodiment, first, in the encryption process, the original data and the symmetric key are encrypted to obtain the encrypted data, and the symmetric key and the group public key are encrypted to obtain the symmetric key encrypted by the group public key, and the symmetric key encrypted by the group public key includes the encryption slice; correspondingly, in the decryption process, the encrypted slice is sent to the group member, and the encrypted slice is verified. If the verification is successful, the corresponding decryption slice is obtained according to the private key of the threshold group member. Further, the symmetric key encrypted by the group public key and the decryption slice are decrypted to obtain the symmetric key, and the encrypted data and the symmetric key are decrypted to obtain the original data. It can be seen that the symmetric key and the group public key double-encrypt the data. After successfully verifying the identity information of the secret holder, the symmetric key can be restored by the threshold group members, and only the secret holder can further decrypt the encrypted data, thereby improving the security of the data encryption and decryption process, and preventing the situation where the key is lost and the decryption cannot be caused.

[0109] It should be noted that the steps shown in the above process or the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0110] In this embodiment, a threshold decryption device for group member data protection is also provided, which is used to implement the above embodiments and preferred implementation modes, and will not be repeated hereafter. The terms "module", "unit", "subunit", etc. used below may be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and conceivable.

[0111] Figure 7 is a structural block diagram of the threshold decryption device for group member data protection of this embodiment, such as Figure 7 As shown, the device includes: a first acquisition module 10, a first verification module 20 and a first decryption module 30;

[0112] A first acquisition module 10 acquires a symmetric key encrypted by a group public key, where the symmetric key encrypted by the group public key includes an encryption fragment;

[0113] The first verification module 20 sends the encrypted slice to the group members and verifies the encrypted slice. If the verification is successful, the corresponding decrypted slice is obtained according to the private keys of the threshold group members;

[0114] The first decryption module 30 obtains the encrypted data, performs a decryption operation on the symmetric key encrypted by the group public key and the decryption slice to obtain the symmetric key, and performs a decryption operation on the encrypted data and the symmetric key to obtain the original data.

[0115] Through the device provided in this embodiment, the symmetric key encrypted by the group public key is obtained, and the symmetric key encrypted by the group public key includes an encrypted segment. The encrypted segment is sent to the group member, and the encrypted segment is verified. If the verification is successful, the corresponding decrypted segment is obtained according to the private keys of at least two group members. Further, the encrypted data is obtained, the symmetric key encrypted by the group public key and the decrypted segment are decrypted to obtain the symmetric key, and the encrypted data and the symmetric key are decrypted to obtain the original data, which solves the problem of being unable to decrypt due to key loss and the easy loss of backup keys, and achieves the prevention of being unable to decrypt due to key loss and effectively improves the security of secrets.

[0116] In some of these embodiments, Figure 7 On the basis of, the device also includes a second verification module, which is used to send the encrypted fragments to group members; and verify the encrypted fragments through non-interactive zero-knowledge proof.

[0117] In some of these embodiments, Figure 7 On the basis of, the device also includes a second decryption module, which is used to obtain the private keys of a threshold number of group members if the verification is successful; calculate the private key and the encrypted slice of each group member to obtain the decrypted slice of each group member.

[0118] In some of these embodiments, Figure 7 On the basis of, the device also includes a third decryption module, which is used to perform decryption operation on the symmetric key encrypted by the group public key and the decryption fragment based on the decryption process of the Elgamal encryption algorithm to obtain the symmetric key.

[0119] In this embodiment, an encryption device for protecting group member data is also provided. Figure 8is a structural block diagram of the encryption device for protecting group member data of this embodiment, such as Figure 8 As shown, the device includes: a second acquisition module 100, a first encryption module 200 and a second encryption module 300;

[0120] The second acquisition module 100 acquires original data and a symmetric key;

[0121] The first encryption module 200 performs encryption operation on the original data and the symmetric key to obtain encrypted data;

[0122] The second encryption module 300 obtains the group public key of the group member, performs encryption operation on the symmetric key and the group public key, and obtains the symmetric key encrypted by the group public key, where the symmetric key encrypted by the group public key includes encryption fragments.

[0123] Through the device provided in this embodiment, the symmetric key encrypted by the group public key is obtained, and the symmetric key encrypted by the group public key includes an encrypted segment. The encrypted segment is sent to the group member, and the encrypted segment is verified. If the verification is successful, the corresponding decrypted segment is obtained according to the private key of the threshold group member. Further, the encrypted data is obtained, the symmetric key encrypted by the group public key and the decrypted segment are decrypted to obtain the symmetric key, and the encrypted data and the symmetric key are decrypted to obtain the original data. It can be seen that the double encryption method of encrypting the original data with the symmetric key and encrypting the symmetric key with the group public key solves the problem of easy loss of the backup key and improves the security of data encryption.

[0124] In some of these embodiments, Figure 8 On the basis of, the device also includes a group public key module, which is used to obtain the private key of each group member; obtain the public key of each group member according to the private key; and perform aggregation operation on the public keys to obtain the group public key.

[0125] In some of these embodiments, Figure 8 On the basis of this, the device also includes a third encryption module, which is used to encrypt the symmetric key and the group public key through the Elgamal encryption algorithm to obtain the symmetric key encrypted by the group public key; during the encryption operation, a non-interactive zero-knowledge proof corresponding to the user is generated according to the user's private key to obtain an encrypted fragment.

[0126] In this embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0127] Optionally, the computer device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0128] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation modes, and will not be repeated in this embodiment.

[0129] In addition, in combination with the threshold encryption and decryption method for protecting group member data provided in the above embodiments, a storage medium can also be provided in this embodiment to implement the method. The storage medium stores a computer program; when the computer program is executed by a processor, any threshold encryption and decryption method for protecting group member data in the above embodiments is implemented.

[0130] It should be understood that the specific embodiments described herein are only used to explain the application, rather than to limit it. Based on the embodiments provided in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the protection scope of this application.

[0131] Obviously, the drawings are only some examples or embodiments of the present application. For ordinary technicians in the field, the present application can also be applied to other similar situations based on these drawings without creative work. In addition, it is understandable that although the work done in this development process may be complicated and lengthy, for ordinary technicians in the field, certain changes in design, manufacturing or production based on the technical content disclosed in this application are only conventional technical means and should not be regarded as insufficient content disclosed in this application.

[0132] The term "embodiment" in this application refers to a specific feature, structure or characteristic described in conjunction with the embodiment that can be included in at least one embodiment of the present application. The appearance of this phrase in various locations in the specification does not necessarily mean the same embodiment, nor does it mean that it is mutually exclusive with other embodiments and is independent or optional. It is clearly or implicitly understood by those of ordinary skill in the art that the embodiments described in this application can be combined with other embodiments without conflict.

[0133] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of patent protection. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the scope of protection of the present application. Therefore, the scope of protection of the present application shall be subject to the attached claims.

Claims

1. A threshold decryption method for group member data protection, characterized in that: Applied to the server side, the threshold decryption method includes: Obtaining a symmetric key encrypted by a group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment; Send the encrypted slice to the group members, verify the encrypted slice, and if the verification is successful, obtain the corresponding decrypted slice according to the private keys of the threshold group members; The encrypted data is obtained, a decryption operation is performed on the symmetric key encrypted by the group public key and the decryption slice to obtain a symmetric key, and a decryption operation is performed on the encrypted data and the symmetric key to obtain original data.

2. The threshold decryption method for group member data protection according to claim 1, characterized in that: The step of sending the encrypted fragment to the group member and verifying the encrypted fragment includes: sending the encrypted fragments to the group members; The encrypted shards are verified through non-interactive zero-knowledge proof.

3. The threshold decryption method for group member data protection according to claim 1, characterized in that: If the verification is successful, the corresponding decryption fragments are obtained according to the private keys of the threshold group members, including: If the verification is successful, obtaining the private keys of a threshold number of the group members; The private key and the encrypted fragment of each of the group members are calculated to obtain the decrypted fragment of each of the group members.

4. The threshold decryption method for group member data protection according to claim 1, characterized in that: The step of performing a decryption operation on the symmetric key encrypted by the group public key and the decryption fragment to obtain the symmetric key comprises: Based on the decryption process of the Elgamal encryption algorithm, a decryption operation is performed on the symmetric key encrypted by the group public key and the decryption fragment to obtain the symmetric key.

5. An encryption method for protecting group member data, characterized in that: Applied to the client side, the encryption method includes: Get the original data and symmetric key; Performing encryption operation on the original data and the symmetric key to obtain encrypted data; Obtaining a group public key of a group member, performing encryption operation on the symmetric key and the group public key to obtain a symmetric key encrypted by the group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment; The obtaining of the group public key of the group members includes: obtaining the private key of each of the group members; obtaining the public key of each of the group members according to the private key; and performing an aggregation operation on the public keys to obtain the group public key.

6. The encryption method for protecting group member data according to claim 5, characterized in that: The symmetric key and the group public key are encrypted to obtain a symmetric key encrypted by the group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment, including: Performing encryption operation on the symmetric key and the group public key by using the Elgamal encryption algorithm to obtain a symmetric key encrypted by the group public key; During the encryption operation, a non-interactive zero-knowledge proof corresponding to the user is generated according to the user's private key to obtain the encrypted fragment.

7. A threshold decryption device for group member data protection, characterized in that: The device comprises: A first acquisition module acquires a symmetric key encrypted by a group public key, wherein the symmetric key encrypted by the group public key includes an encryption fragment; A first verification module sends the encrypted slice to the group member, verifies the encrypted slice, and if the verification passes, obtains the corresponding decrypted slice according to the private key of the threshold group member; The first decryption module obtains the encrypted data, performs a decryption operation on the symmetric key encrypted by the group public key and the decryption slice to obtain the symmetric key, and performs a decryption operation on the encrypted data and the symmetric key to obtain the original data.

8. A computer device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps of the threshold decryption method for protecting group member data according to any one of claims 1 to 4.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the threshold decryption method for protecting group member data according to any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Privacy protection and data supervision control method based on shared account book

    CN111010386A