Threshold key escrow and member update method and device based on a blockchain system
By employing a threshold key escrow and member update method based on the Paillier cryptographic algorithm in a blockchain system, the difficulties of key protection and escrow are solved, achieving secure and efficient key escrow and member update, and providing key escrow services suitable for distributed environments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIHANG UNIV
- Filing Date
- 2023-04-13
- Publication Date
- 2026-05-01
AI Technical Summary
In blockchain systems, the protection and custody of keys present challenges, and existing technologies struggle to achieve secure and efficient key custody and member updates.
By employing the Paillier encryption algorithm and utilizing threshold key escrow and member update methods, the blockchain system is used to allocate, decrypt, and reconstruct key shares, ensuring that new members can securely acquire and escrow key shares.
It enables secure and efficient key escrow and member updates in blockchain systems, improving the security and ease of use of key escrow solutions, and providing key escrow services adapted to distributed environments.
Smart Images

Figure CN116527247B_ABST
Abstract
Description
A method and apparatus for threshold key custody and member update based on a blockchain system. Technical Field
[0001] This invention relates to the field of blockchain and cryptography, and in particular to a threshold key custody and member update method and apparatus based on a blockchain system. Background Technology
[0002] The Paillier encryption algorithm, based on the difficult problem of compound residue classes, provides a homomorphic encryption algorithm that satisfies addition and has been widely used in encrypted signal processing and third-party data processing. Leveraging a blockchain system, a Paillier key escrow model can be constructed. This model distributes Paillier private keys through secret sharing, with each node holding its corresponding share of the private key and managing it in a distributed manner. Simultaneously, a secret sharing committee is used to establish a membership group, providing double encryption protection that greatly enhances the security of the key escrow scheme.
[0003] In the distributed environment of blockchain, the protection and attack of private keys have been persistent hot topics since the inception of blockchain systems, leading to a surge in research on key custody and protection. Currently, key storage remains a challenge in blockchain systems. Summary of the Invention
[0004] Therefore, the purpose of this invention is to provide a threshold key custody and member update method and apparatus based on a blockchain system.
[0005] To achieve the above objectives, the present invention provides the following solution:
[0006] A threshold key escrow and member update method based on a blockchain system includes:
[0007] The group public and private keys of the Paillier encryption scheme are determined, and the threshold share of the Paillier encryption scheme private key is allocated according to the number of members in the committee, so that the escrow share of each member's threshold Paillier private key after encryption can be placed on the blockchain system.
[0008] When a member leaves the committee, the remaining members use the results of the initial decryption of the escrow share to determine the new member's Lagrange factor and send the new member's Lagrange factor to the new member.
[0009] The new member performs a combination operation on the obtained Lagrange factors to obtain an encrypted message containing the new member's threshold Paillier private key share;
[0010] After receiving the encrypted message containing the new member's share of private key, the remaining members of the committee use their own threshold Paillier private key shares to determine each remaining member's decryption share.
[0011] After receiving a valid decryption share that meets the threshold value, the new member decrypts the encrypted message containing the new member's threshold Paillier private key share to obtain the new member's threshold Paillier private key share and determines the escrow share of the new member's threshold Paillier private key share so that the new member's escrow share can be placed on the blockchain system.
[0012] Optionally, the group public and private keys of the Paillier encryption scheme are determined, and a threshold share of the Paillier encryption scheme private keys is allocated according to the number of members in the committee, so that the escrow share of each member's threshold Paillier private key, after encryption, can be placed on the blockchain system. Specifically, this includes:
[0013] The system initialization phase specifically involves: initializing the overall system parameters of the Paillier encryption scheme to obtain the group public key and private key of the Paillier encryption scheme;
[0014] The threshold Paillier initialization phase specifically involves: allocating threshold shares of the Paillier encryption scheme's private keys according to the number of members in the committee, determining the threshold Paillier private key share for each member, and determining the public-private key pair for each member;
[0015] In the share custody phase, specifically: for any member, the threshold Paillier private key share is encrypted using the public key of the Paillier encryption scheme and the member's corresponding public key to obtain the custody share corresponding to each member, and a proof document proving the correctness of the custody share is generated. Then, the custody share and proof document corresponding to each member are put into the blockchain system for custody operation.
[0016] Optionally, when a member leaves the committee, the remaining members use the initial decryption of the escrow share to determine the Lagrange factor of the new member, and send the new member's Lagrange factor to the new member, specifically including:
[0017] The initial declassification phase of the share allocation is as follows:
[0018] The correctness of the custodial share of each node in the blockchain system is verified, and the set of members that pass the verification is recorded as follows. ;
[0019] New members To set Members initiate applications, gathering Members to new members Qualification and identity are verified, and once verified, the group is assembled. Each member within Using your own independent private key, you can initially decrypt the escrow share and obtain the initial decryption result;
[0020] Calculate new members using preliminary decryption results Corresponding Lagrange factor and supporting documents, and new members Corresponding Lagrange factor and supporting documents sent to new members .
[0021] Optionally, the new member performs combination operations on the obtained Lagrange factors to obtain an encrypted message containing the new member's threshold Paillier private key share, specifically including:
[0022] The share restructuring phase specifically includes:
[0023] The new member verifies the obtained Lagrange factor and performs combination operations based on the successfully verified Lagrange factor to obtain an encrypted message containing the new member's threshold Paillier private key share.
[0024] Optionally, after receiving the encrypted message containing the new member's private key share, the remaining members of the committee determine their decryption share using their own threshold Paillier private key share, specifically including:
[0025] The threshold Paillier decryption phase is as follows:
[0026] After receiving the encrypted message containing the new member's private key share, the remaining members of the committee use their own threshold Paillier private key share to generate their own decryption share, thereby determining the decryption share of each remaining member and generating a proof document proving the correctness of the decryption process.
[0027] Send the decryption share and proof document corresponding to each remaining member to the new member.
[0028] Optionally, after receiving a valid decryption share that meets the threshold value, the new member decrypts the encrypted message containing the new member's threshold Paillier private key share to obtain the new member's threshold Paillier private key share, specifically including:
[0029] The new share withdrawal phase is as follows:
[0030] New members verify the decryption shares based on the proof documents proving the correctness of the decryption process, and add the successfully verified decryption shares to the collection set;
[0031] When the collection receives a number of decryption shares that meet the threshold value, the encrypted message containing the new member's threshold Paillier private key share is decrypted using the threshold Paillier decryption operation and the Lagrange reconstruction method to obtain the new member's threshold Paillier private key share.
[0032] Optionally, a threshold Paillier private key share for new members is determined for escrow, so that the escrow share of new members can be placed on the blockchain system, specifically including:
[0033] Determine the public / private key pair for the new member;
[0034] The threshold Paillier private key share of the new member is encrypted using the public key of the Paillier encryption scheme and the public key corresponding to the new member, to obtain the escrow share of the threshold Paillier private key share of the new member, and a proof document proving the correctness of the escrow share is generated. Then, the escrow share corresponding to the new member and the proof document are put into the blockchain system for escrow operation.
[0035] Secondly, the present invention also provides a threshold key custody and member update device based on a blockchain system, comprising:
[0036] The group public and private key determination module is used to determine the group public and private keys of the Paillier encryption scheme, and to allocate a threshold share of the Paillier encryption scheme private key according to the number of members in the committee, so that the escrow share of each member's threshold Paillier private key after encryption can be placed on the blockchain system.
[0037] The remaining members are used for:
[0038] When a member leaves the committee, the Lagrange factor of the new member is determined using the result of the initial decryption of the escrow share, and the Lagrange factor of the new member is sent to the new member; the remaining member is any member of the committee excluding the member who left.
[0039] Upon receiving an encrypted message containing the new member's private key share, it uses its own threshold Paillier private key share to determine the decryption share;
[0040] The new member is used to: perform combination operations on the obtained Lagrange factors to obtain an encrypted message containing the Paillier private key share of the new member threshold;
[0041] After receiving the number of valid and correct decryption shares that meet the threshold value, the encrypted message containing the new member's threshold Paillier private key share is decrypted to obtain the new member's threshold Paillier private key share. The escrow share of the new member's threshold Paillier private key share is then determined so that the new member's escrow share can be placed on the blockchain system.
[0042] According to specific embodiments provided by the present invention, the present invention discloses the following technical effects:
[0043] This invention implements threshold share custody of Paillier private keys. During initialization, the Paillier private key is linked with the blockchain private key or other key information. This is equivalent to implementing a threshold key custody and update method in a distributed environment based on the existing solution, building a complete and secure key custody service in a distributed scenario. Relying on the distributed environment verified by the blockchain system open course, it improves the security and ease of operation of the entire key custody solution. Attached Figure Description
[0044] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0045] Figure 1 is a flowchart illustrating the threshold key custody and member update method based on a blockchain system provided in an embodiment of the present invention.
[0046] Figure 2 is a schematic diagram of the specific process of the threshold key custody and member update method based on the blockchain system provided in the embodiment of the present invention;
[0047] Figure 3 is a schematic diagram of multi-party interaction in the threshold key custody and member update method based on the blockchain system provided in the embodiment of the present invention. Detailed Implementation
[0048] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0049] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0050] Based on a thorough study of threshold secret sharing, Paillier encryption, and blockchain technology, this invention designs a threshold key escrow and member update method and apparatus based on a blockchain system. This invention implements a Paillier key escrow scheme within the blockchain system, ensuring the security of escrow shares through member encryption. Building upon this, the Paillier key escrow model constructed by this invention can form a key escrow service, linking with the private keys or other key information of the blockchain system to achieve a distributed, multi-party, secure key escrow service, and supporting the updating and replacement of escrow members. In summary, this invention provides a secure and efficient distributed key escrow service model.
[0051] Building upon this, the present invention links the Paillier key with the private key of the blockchain system, thus enabling the escrow of the blockchain system's keys. Based on Paillier key distributed escrow, a multi-party distributed key escrow service model can be constructed. In practical provision of escrow services, changes in committee members regarding escrow shares need to be considered. The present invention can provide new key escrow shares to new members even when personnel are replaced, without disclosing the shares of other members.
[0052] Example 1
[0053] The threshold key custody and member update core of the blockchain system described in this embodiment consists of a committee and a blockchain system. The committee is a secret sharing committee that controls the threshold Paillier private key share, and also an encrypted oversight committee with independent public and private keys. When new members are added to the committee and are replaced, the key share of the new members needs to be updated.
[0054] As shown in Figures 1, 2, and 3, the threshold key escrow and member update method based on a blockchain system provided in this embodiment includes:
[0055] Step 100: Determine the group public and private keys of the Paillier encryption scheme, and allocate threshold shares of the Paillier encryption scheme private keys according to the number of members in the committee, so that the escrow share of each member's threshold Paillier private key after encryption can be placed on the blockchain system.
[0056] Step 200: When a member leaves the committee, the remaining members of the committee use the results of the initial decryption of the escrow share to determine the Lagrange factor of the new member and send the Lagrange factor of the new member to the new member.
[0057] Step 300: The new member performs a combination operation on the obtained Lagrange factor to obtain an encrypted message containing the new member's threshold Paillier private key share.
[0058] Step 400: After receiving the encrypted message containing the new member's private key share, the remaining members of the committee use their own threshold Paillier private key share to determine the decryption share of each remaining member.
[0059] Step 500: After receiving the number of valid decryption shares that meet the threshold value, the new member decrypts the encrypted message containing the new member's threshold Paillier private key share to obtain the new member's threshold Paillier private key share, and determines the escrow share of the new member's threshold Paillier private key share so that the new member's escrow share can be placed on the blockchain system.
[0060] In a preferred embodiment, step 100 specifically includes:
[0061] (1) System initialization phase, specifically: allocating threshold shares of the Paillier encryption scheme private keys according to the number of members in the committee, determining the threshold Paillier private key share for each member, and determining the public-private key pair for each member; the detailed process is as follows:
[0062] Initialize system parameters and select security parameters. Randomly select two prime numbers and , and Both are prime numbers; choose RSA integers. Random selection ( (where the order of the computational group is given) and the leader (hereinafter referred to as dealer) is randomly selected. ,calculate , , , The number of members in the committee, rank Lcm() generates the least common multiple of the two numbers within the parentheses, which is one way of representing it; let The group public key is The private key is .
[0063] Purpose: This stage is used to determine the parameters used in the initialization system scheme. This initialization is mainly the initialization process of the overall system parameters of the Paillier encryption scheme. The parameter initialization settings of the system are completed by a dealer, forming the overall group public key and private key.
[0064] (2) Threshold Paillier initialization phase, specifically: allocating threshold shares of the Paillier encryption scheme private keys according to the number of members in the committee, determining the threshold Paillier private key share for each member, and determining the public-private key pair for each member. The detailed process is as follows:
[0065] The committee assumes a total of There are 1 member, denoted as 1. Members, guided by a dealer, perform initialization procedures. The dealer starts from... Random selection Construct a polynomial, ,Will The threshold quota is distributed to the corresponding members through a secure channel, thus completing the allocation of quotas.
[0066] Each member from Random selection Build your own independent public-private key pair .
[0067] Purpose: For each member, this stage generates their own independent public-private key pair, facilitating secondary encryption as a member. More importantly, this process requires the private key to be shared under the dealer's guidance. The system performs shard share custody, with each member keeping a portion of their share. Members who reach the threshold can recover the corresponding private key together. In this embodiment, each member custodys their key share on the blockchain and distributes the corresponding key share to newly replaced members, thus completing the custody and update operation of the threshold Paillier private key share.
[0068] (3) Share custody stage, specifically: For any member, the threshold Paillier private key share is encrypted using the public key of the Paillier encryption scheme and the member's corresponding public key to obtain the custody share corresponding to each member, and a proof document proving the correctness of the custody share is generated. Then, the custody share and proof document corresponding to each member are put into the blockchain system for custody operation. The detailed process is as follows:
[0069] Committee members must encrypt their threshold Paillier private key share twice as a message. from Random selection and The public key used in the Paillier encryption scheme and its own independent public key. Threshold share Encryption is performed to calculate one's own system hosting share. And generate the corresponding proof and put it on the blockchain for safekeeping.
[0070] .
[0071] Function: For each user, their threshold private key share needs to be encrypted twice to generate their own escrow share, which is then placed on the blockchain for escrow. During the calculation process, a discrete logarithm equality proof corresponding to the threshold Paillier scheme needs to be generated to prove the correctness of their escrow share, so that other users can verify it.
[0072] As a preferred embodiment, step 200 specifically includes:
[0073] The initial declassification phase of the share allocation is as follows:
[0074] When a member leaves, a new member must be added to replace them. This is recorded as a new member who wishes to join the committee and be allocated a threshold Paillier private key share. Before joining, the correctness of the custodial share of each node on the blockchain system must first be verified, and the set of members that have passed the verification is recorded as follows: Secondly, new members To set Members initiate applications, gathering The members verify their qualifications and identities, and once verified, the group... Each member within Using your own independent private key, perform a preliminary decryption of the escrow share to obtain a preliminary decryption result. The preliminary decryption process is as follows:
[0075] .
[0076] Based on the preliminary decryption results, calculate the new members. Lagrange factor Among them, members are utilized. For new members Lagrange parameters After the calculation is completed, a corresponding proof is generated using an operation similar to the previous step of hosting. Lagrange factor Send to new members together Its Lagrange factor The process of determining is as follows:
[0077] .
[0078] Purpose: To ensure the timely replacement and addition of new members upon member departure, the committee must function properly. Ideally, departing members should no longer possess a threshold Paillier private key share, and newly joined members should acquire their own threshold Paillier private key share without affecting or acquiring information about other members' threshold Paillier private key shares or the system private key. First, the newly joined member verifies the correctness of the escrow share on the system. Upon successful verification, a request is sent. Receiving the request, committee members verify the new member in various aspects. Upon successful verification, the member is approved for joining and performs partial decryption using their independent private key. Finally, the threshold Paillier private key share for the newly joined member is calculated using Lagrange interpolation. The new member represents a new point on the curve. Through Lagrange control of the member's reconstruction, a corresponding discrete logarithmic equality proof is generated and sent to the corresponding member for calculation and verification.
[0079] As a preferred embodiment, step 300 specifically includes:
[0080] The share reconstruction phase specifically involves: the new member verifying the acquired Lagrange factor and performing combination operations based on the successfully verified Lagrange factors to obtain an encrypted message containing the new member's private key share. The detailed process is as follows:
[0081] New members After receiving the Lagrange factor and its proof, verify it. Add successfully verified elements to the set. In the middle, for sets Combining the Lagrange factors in the formula yields an encrypted message containing the new member threshold Paillier private key share. .
[0082] .
[0083] Function: After receiving the Lagrange factors and corresponding proofs from committee members, new members first perform a verification operation, adding the verified Lagrange factors to the corresponding sets. Then, they combine the Lagrange factors in the sets to obtain their own share of the private key. (i.e., the corresponding encrypted content containing the new member threshold Paillier private key share); where, the random values of each member in the corresponding formula can be... Combinations are viewed as random selections .
[0084] In a preferred embodiment, step 400 specifically includes:
[0085] The threshold Paillier decryption phase is as follows:
[0086] Send encrypted messages to committee members containing their share of the Paillier private key, which represents the new member threshold. , This can be seen as a random selection. Regarding private key shares The Paillier form. Request the committee's assistance in calculating the encrypted share of the private key share, and then perform threshold decryption.
[0087] Committee members regarding the received Calculate your own decryption share Simultaneously, a proof of the equality of discrete logarithms during the decryption process was calculated and sent to [the relevant authority]. .
[0088] Function: The new member node reconstructs its own share of private key using the Lagrange operation in the previous step. The total ciphertext in threshold Paillier form is sent to each committee member node, requesting them to decrypt the ciphertext. Upon receiving it, each committee member generates their own decryption share using their threshold Paillier private key share, and simultaneously generates a proof document demonstrating the correctness of the decryption process. The decryption shares and proof documents of each remaining member are then sent to the new members for reconstruction.
[0089] In a preferred implementation, after a new member receives a valid decryption share that meets the threshold value, the new member decrypts the encrypted message containing the new member's threshold Paillier private key share to obtain the new member's threshold Paillier private key share, specifically including:
[0090] The new share withdrawal phase is as follows:
[0091] New members Verification is performed based on the supporting documents proving the correctness of the decryption process, and the decrypted shares that pass verification are... Add to collection In the middle, if the number of messages that meet the threshold value is received... Then, threshold reconstruction using Lagrange interpolation is performed, followed by threshold Paillier decryption. for right The Lagrange parameters, .
[0092] .
[0093] Function: After receiving the decryption share and proof from each member, a new member verifies it. If the verification is successful, the correct decryption share is added to the collection set. Once the threshold number of valid decryption shares is received, the reconstruction operation of the encrypted message can begin. Using the threshold Paillier decryption operation and the Lagrange reconstruction method, the private key share can be reconstructed and recovered. .
[0094] As a preferred implementation, the escrow share of the new member's threshold Paillier private key is determined so that the escrow share of the new member can be placed on the blockchain system. Specifically, this includes: determining the new member's public-private key pair, then encrypting the new member's threshold Paillier private key share using the public key of the Paillier encryption scheme and the new member's corresponding public key to obtain the escrow share of the new member's threshold Paillier private key share, generating a proof document proving the correctness of the escrow share, and then placing the new member's corresponding escrow share and proof document on the blockchain system for escrow operation.
[0095] This embodiment constructs a key encryption escrow scheme based on threshold Paillier keys, which can be associated with blockchain and other systems to realize distributed escrow of blockchain keys, and build a distributed key escrow service. This key escrow is distributed and multi-party participated in, and security is improved through members. It also supports the updating and replacement of committee members, and is constructed based on Paillier and ElGamal encryption and threshold cryptography.
[0096] Compared with existing technologies, this embodiment designs a threshold key custody and member update method based on a blockchain system, which realizes the secure distribution and custody of threshold Paillier public and private keys, forming a key share custody committee in a distributed scenario to provide key share custody services.
[0097] Meanwhile, the method provided in this embodiment can largely solve the problem of difficult key storage in traditional blockchain system environments. It constructs a Paillier key encryption escrow model, where each member of the secret sharing committee holds a corresponding key share. This share is then encrypted again using a dual public key system, and the inclusion of a group of members significantly enhances the security of the key escrow process. The system employs threshold secret sharing as the escrow method for supervising the escrow group. Threshold cryptography has a more complex security model and richer application characteristics than traditional public key cryptography, making it more suitable for distributed environments. Multiple parties hold different shares of a public secret through threshold technology, and the secret is reconstructed only when the threshold value is met. The distributed storage protection model further enhances the security of the escrow keys.
[0098] In addition to security, this embodiment also provides a secure key share allocation scheme to adapt to actual use scenarios when members are replaced. The new member is assigned a new point on the secret sharing curve. Without knowing the shares held by other members, a series of processes such as verification, application, joining, and extraction are completed, realizing convenient member replacement.
[0099] Example 2
[0100] In order to implement the method corresponding to Embodiment 1 above and achieve the corresponding functions and technical effects, a threshold key custody and member update device based on a blockchain system is provided below.
[0101] The threshold key escrow and member update device based on a blockchain system provided in this embodiment includes:
[0102] The group public and private key determination module is used to determine the group public and private keys of the Paillier encryption scheme, and to allocate a threshold share of the Paillier encryption scheme private key according to the number of members in the committee, so that the escrow share of each member's threshold Paillier private key after encryption can be placed on the blockchain system.
[0103] The remaining members are used for:
[0104] When a member leaves the committee, the Lagrange factor of the new member is determined using the result of the initial decryption of the escrow share, and the Lagrange factor of the new member is sent to the new member; the remaining member is any member of the committee excluding the member who left.
[0105] Upon receiving an encrypted message containing the new member's private key share, it uses its own threshold Paillier private key share to determine the decryption share.
[0106] The new member is used to: perform combination operations on the obtained Lagrange factors to obtain an encrypted message containing the Paillier private key share of the new member threshold;
[0107] After receiving the number of valid and correct decryption shares that meet the threshold value, the encrypted message containing the new member's threshold Paillier private key share is decrypted to obtain the new member's threshold Paillier private key share. The escrow share of the new member's threshold Paillier private key share is then determined so that the new member's escrow share can be placed on the blockchain system.
[0108] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple; relevant parts can be referred to the method section.
[0109] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. Furthermore, those skilled in the art will recognize that, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A threshold key escrow and member update method based on a blockchain system, characterized in that, include: The process involves determining the group public and private keys for the Paillier encryption scheme, and allocating threshold shares of the Paillier private keys according to the number of committee members. This ensures that each member's threshold Paillier private key share, after encryption, can be placed on the blockchain system. When a member leaves the committee, the remaining members use the initial decryption of the escrow shares to determine the new member's Lagrange factor and send it to the new member. The new member then performs a combination operation on the obtained Lagrange factor to obtain the Paillier key containing the new member's threshold. The committee receives an encrypted message containing the new member's private key share. The remaining committee members then use their own threshold Paillier private key shares to determine their decryption share. The new member, upon receiving a valid decryption share that meets the threshold value, decrypts the encrypted message containing the new member's threshold Paillier private key share to obtain the new member's threshold Paillier private key share and determines the escrow share of the new member's threshold Paillier private key share, enabling the new member's escrow share to be placed on the blockchain system.
2. The threshold key custody and member update method based on a blockchain system according to claim 1, characterized in that, The process involves determining the group public and private keys for the Paillier encryption scheme and allocating threshold shares of the Paillier private keys according to the number of committee members. This ensures that each member's threshold Paillier private key share, after encryption, can be placed on the blockchain system. Specifically, this includes: a system initialization phase, which initializes the overall system parameters of the Paillier encryption scheme to obtain the group public and private keys; a threshold Paillier initialization phase, which allocates threshold shares of the Paillier private keys according to the number of committee members, determining each member's threshold Paillier private key share and their public-private key pair; and a share custody phase, which encrypts each member's threshold Paillier private key share using the Paillier encryption scheme's public key and the member's corresponding public key to obtain their corresponding custodial share. A proof document demonstrating the correctness of the custodial share is generated, and then each member's custodial share and proof document are placed on the blockchain system for custody.
3. The threshold key custody and member update method based on a blockchain system according to claim 2, characterized in that, When a member leaves the committee, the remaining members use the initial decryption of the escrow shares to determine the Lagrange factor of the new member and send the new member's Lagrange factor to the new member. This process includes: an initial share decryption phase, specifically: verifying the correctness of the escrow shares of each node on the blockchain system, and denoting the set of members that have passed verification as U. e New member P e To set U e Members initiate applications, gathering U e Members to new member P e Qualification and identity are verified, and once verified, the set U is... e Each member P within i Using their own independent private key, the escrow share is initially decrypted to obtain a preliminary decryption result; the new member P is then calculated using the preliminary decryption result. e The corresponding Lagrange factor L ie and supporting documents, and will add new member P e The corresponding Lagrange factor L ie And supporting documents sent to new member P e .
4. The threshold key custody and member update method based on a blockchain system according to claim 1, characterized in that, The new member performs combination operations on the acquired Lagrange factors to obtain an encrypted message containing the new member's threshold Paillier private key share. Specifically, this includes the share reconstruction stage, in which the new member verifies the acquired Lagrange factors and performs combination operations on the successfully verified Lagrange factors to obtain an encrypted message containing the new member's threshold Paillier private key share.
5. The threshold key custody and member update method based on a blockchain system according to claim 1, characterized in that, After receiving the encrypted message containing the new member's private key share, the remaining members of the committee use their own threshold Paillier private key shares to determine their own decryption share. This process includes the threshold Paillier decryption stage, where each remaining member uses their own threshold Paillier private key share to generate their own decryption share, thereby determining the decryption share for each remaining member. Simultaneously, a proof document demonstrating the correctness of the decryption process is generated. The decryption share and proof document corresponding to each remaining member are then sent to the new member.
6. The threshold key custody and member update method based on a blockchain system according to claim 5, characterized in that, After a new member receives a valid decryption share that meets the threshold value, it decrypts the encrypted message containing the new member's threshold Paillier private key share to obtain the new member's threshold Paillier private key share. This process includes: a new share extraction phase, where the new member verifies the decryption share based on the proof document demonstrating the correctness of the decryption process and adds the successfully verified decryption share to the collection set; when the collection set receives a decryption share that meets the threshold value, the new member uses the threshold Paillier decryption operation and the Lagrange reconstruction method to decrypt the encrypted message containing the new member's threshold Paillier private key share to obtain the new member's threshold Paillier private key share.
7. A threshold key custody and member update method based on a blockchain system according to claim 5, characterized in that, The process of determining the escrow share of a new member's threshold Paillier private key, so that the escrow share of the new member can be placed on the blockchain system, specifically includes: determining the new member's public-private key pair; encrypting the new member's threshold Paillier private key share using the public key of the Paillier encryption scheme and the new member's corresponding public key to obtain the escrow share of the new member's threshold Paillier private key, generating a proof document proving the correctness of the escrow share, and then placing the new member's corresponding escrow share and proof document on the blockchain system for escrow operation.
8. A threshold key escrow and member update device based on a blockchain system, characterized in that, include: The group public and private key determination module is used to determine the group public and private keys of the Paillier encryption scheme, and to allocate threshold shares of the Paillier encryption scheme private keys according to the number of committee members, so that each member's threshold Paillier private key share, after encryption, can be placed on the blockchain system. The remaining members are used to: when a member leaves the committee, determine the Lagrange factor of the new member using the result of the initial decryption of the escrow shares, and send the new member's Lagrange factor to the new member; the remaining members are any member of the committee excluding the departing member; upon receiving... After receiving an encrypted message containing the new member's private key share, the decryption share is determined using the new member's own threshold Paillier private key share. The new member is used to: perform combination operations on the obtained Lagrange factors to obtain an encrypted message containing the new member's threshold Paillier private key share; after receiving a valid decryption share that meets the threshold value, the new member decrypts the encrypted message containing the new member's threshold Paillier private key share to obtain the new member's threshold Paillier private key share, and determines the escrow share of the new member's threshold Paillier private key share so that the new member's escrow share can be placed on the blockchain system.