A distributed key generation method based on blockchain and CP-ABE

By adopting a combination method of blockchain and CP-ABE in the distributed key generation protocol, the problems of high computational complexity and communication overhead of key generation protocols in the prior art are solved, and efficient and secure key generation and management are achieved.

CN118984222BActive Publication Date: 2025-05-13GUIZHOU UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411219914.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-02
Publication Date
2025-05-13
Estimated Expiration
2044-09-02

AI Technical Summary

Technical Problem

The existing distributed key generation protocol has problems with high computational complexity and communication overhead during the sharing and reconstruction stages, and CP-ABE is difficult to identify the original key owner when decrypting the privileged sharing, which affects data security.

Method used

The distributed key generation method based on blockchain and CP-ABE is adopted to encrypt and transmit key shares through the blockchain as a public channel, and the validity of key shares is verified by smart contracts, and the decryption key is collected by external users during the reconstruction stage to reconstruct the protocol master and private key.

Benefits of technology

It reduces the computational complexity and communication complexity in the sharing and reconstruction stages, reduces computational costs and communication overhead, improves data security, and realizes efficient key generation and management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118984222B_ABST
    Figure CN118984222B_ABST
Patent Text Reader

Abstract

The present invention provides a distributed key generation method based on blockchain and CP-ABE, including: step 1: in the sharing stage, n participating nodes independently select random values ​​as their key shares, encrypt the key shares using the CP-ABE algorithm, and generate corresponding CP-ABE ciphertexts; the protocol sub-public keys of the participating nodes and the corresponding CP-ABE ciphertexts are verified for validity through smart contracts on the blockchain, and the verification process includes verification of hash commitments; step 2: in the reconstruction stage, after an external user initiates a request to reconstruct the protocol master private key, the participating node provides its corresponding decryption key; the external user collects and uses at least t corresponding decryption keys and corresponding ciphertexts, and then reconstructs the master private key. The present invention reduces the computational complexity and communication complexity in the sharing stage and the reconstruction stage, reduces the computational cost and communication overhead, and improves security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain, and in particular to a distributed key generation method based on blockchain and CP-ABE. Background Art

[0002] Distributed key generation (DKG) protocol is a core component of many key management systems. It allows a group of participants to collaboratively generate a shared key in an environment without a trusted third-party intermediary. In the process of generating shared keys, since each participant independently generates their own key share, an attacker cannot derive the shared key without holding the key share of other participants. It can effectively avoid the trusted settings in various threshold cryptographic systems, such as threshold encryption, threshold signature, universal threshold coin and other technologies, which can be used as basic modules for building blockchain and consensus protocols. Considering the widespread use of distributed key generation protocols in practical applications, there is an urgent need to develop more efficient distributed key generation protocols.

[0003] The ideal DKG protocol includes two phases: sharing and reconstruction. The sharing phase generates the protocol master public key, and the reconstruction phase calculates the protocol master private key. In order to generate the protocol master public key in the sharing phase and achieve threshold recovery in the reconstruction phase, Verifiable Secret Sharing (VSS) and Public Verifiable Secret Sharing (PVSS) are widely used to implement the DKG protocol. Usually, VSS ensures that each participating node can verify the share it receives by attaching a non-interactive zero-knowledge proof to each share, such as the document Publicly verifiable homomorphic secret sharing for polynomial evaluation.

[0004] However, since the shares of participating nodes are transmitted through private channels, participating nodes may send incorrect shares in the sharing phase to initiate DoS attacks, and honest participating nodes need to handle disputes separately. PVSS integrates an additional public key encryption scheme for VSS, so that shares can be encrypted and publicly verified. After using PVSS instead of VSS, the DKG protocol can be built on the public channel. However, in the DKG protocol based on PVSS, the encrypted shares can only be decrypted by users holding the corresponding shares. Therefore, when external users start the reconstruction phase, it will inevitably bring serious computing costs and communication overheads.

[0005] Cipher-policy attribute-based encryption (CP-ABE) is an encryption technology that provides fine-grained access control. It allows users to encrypt data based on specific attributes or attribute combinations, and can achieve external decryption of ciphertext. It is widely used in environments that require fine-grained access control of data, such as cloud computing, healthcare, and financial services. Although both PVSS and CP-ABE allow each participating node to hide its secret share in the process of interacting with multiple participants, and perform public verification and threshold recovery. However, since CP-ABE has the feature of external decryption (i.e., external users can decrypt ciphertext), this provides an innovative solution strategy for designing a DKG protocol with an efficient reconstruction phase.

[0006] However, in traditional CP-ABE, since the decryption privilege is shared by multiple users with the same attributes, it is difficult to identify the original key owner given a public key. This gives malicious users the opportunity to leak their data for profit, seriously compromising data security. In addition, most existing CP-ABE access control schemes involve intermediary entities, which have problems such as high trust establishment cost and single point of failure. Therefore, how to design an efficient DKG protocol in combination with CP-ABE remains a challenge to be solved. Summary of the invention

[0007] The purpose of the present invention is to provide a distributed key generation method based on blockchain and CP-ABE, which reduces the computational complexity and communication complexity in the sharing stage and the reconstruction stage, reduces the computational cost, communication overhead and trust establishment cost, and improves security.

[0008] The present invention provides a distributed key generation method based on blockchain and CP-ABE, comprising:

[0009] Step 1: In the sharing phase, n participating nodes independently select random values ​​as their key shares, and use the CP-ABE algorithm to encrypt the key shares generated by each participating node to generate the corresponding CP-ABE ciphertext;

[0010] Use blockchain as a public channel to encrypt and transmit key shares;

[0011] The participating node calculates its protocol sub-public key and generates a hash commitment associated with the ciphertext and protocol sub-public key; and submits its ciphertext, protocol sub-public key and corresponding hash commitment through the smart contract;

[0012] The validity of the protocol sub-public key and the corresponding CP-ABE ciphertext of each participating node is verified through the smart contract on the blockchain, and the verification process includes the verification of the hash commitment;

[0013] Furthermore, the CP-ABE algorithm is used as a cryptographic primitive to construct a verifiable DKG protocol based on blockchain and CP-ABE. In this protocol, each participating node collaborates to generate a protocol public key in the sharing phase, and the verification complexity of the sharing phase is O(1).

[0014] Step 2: During the reconstruction phase, after an external user initiates a request to reconstruct the protocol master private key, the participating node responds to the request, generates and provides its corresponding decryption key;

[0015] The external user collects at least t corresponding decryption keys, uses the collected decryption keys to decrypt the corresponding ciphertext, and then reconstructs the master private key of the protocol.

[0016] Furthermore, honest participating nodes jointly recover the corresponding protocol private key during the reconstruction phase, and external users only need O(n) communication and computational complexity.

[0017] Furthermore, once an external user initiates a request to reconstruct the protocol master private key MSK, within the specified time, each participating node calls the AttrKeyGen algorithm to generate the decryption key K corresponding to its ciphertext component. θ , and send it offline to the external user. If the external user receives at least t decryption keys, he can decrypt the corresponding ciphertext and calculate the master private key of the DKG protocol.

[0018] The CP-ABE algorithm includes:

[0019] Security parameter input algorithm, used to generate global parameters and master keys;

[0020] Authorization setup algorithm, used to generate long-term secret keys and public key pairs;

[0021] Attribute key generation algorithm, generates attribute private key based on attribute set and master key;

[0022] Encryption algorithm, which generates ciphertext based on the access structure and the message and public parameters;

[0023] Decryption algorithm,decrypts the message based on the attribute private key and ciphertext.

[0024] Furthermore, the flexibility and fine-grained access control capabilities of CP-ABE enable the ciphertext in the DKG protocol to be decrypted externally, which makes key generation and key management in distributed systems more efficient.

[0025] Furthermore, hash commitment is introduced into the CP-ABE algorithm, and the external user can check the CP-ABE ciphertext to verify its validity.

[0026] Furthermore, the hash commitment algorithm is used to provide the verifiability properties of the CP-ABE ciphertext and the protocol sub-public key on the smart contract. The specific verification process is completed on the Ethereum platform to ensure the consistency and non-tamperability of the submitted content. A general hash-based commitment algorithm is introduced in the protocol. In the sharing phase, the smart contract verifies the CP-ABE ciphertext and the protocol sub-public key by checking the commitment.

[0027] Furthermore, the smart contract automatically performs the following operations:

[0028] Receive ciphertext components and commitments submitted by participating nodes;

[0029] Verify the ciphertext components and corresponding commitments submitted by participating nodes in the sharing phase;

[0030] Automatically executed after the validity period to calculate the protocol master public key;

[0031] During the reconstruction phase, the protocol master public key and other necessary credentials are provided to assist external users in calculating the protocol master private key.

[0032] Furthermore, blockchain platforms, such as Ethereum, integrate smart contract execution engines, allowing developers to write and deploy self-executing contracts that, once deployed, can be automatically executed when preset conditions are met. As a permissionless blockchain platform, Ethereum allows users to store authenticated data that, once on the chain, is tamper-proof, providing users with security for data storage. The Ethereum Virtual Machine (EVM) provides a Turing-complete execution environment to ensure the effective operation of smart contracts. Smart contracts are usually written in the Solidity programming language. Once deployed on the blockchain, these contracts can execute complex logic and operations, and all operations are publicly verifiable.

[0033] Furthermore, the t is a preset reconstruction threshold, and the threshold t is defined as a minimum integer greater than half of the total number of participating nodes.

[0034] Furthermore, the communication complexity and computational complexity of the sharing phase and the reconstruction phase are both O(n).

[0035] The present invention also provides a system for executing the distributed key generation method, characterized in that it includes:

[0036] Multiple participating nodes, each of which is able to generate a key share and encrypt using the CP-ABE algorithm;

[0037] A blockchain network for transferring encrypted key shares and protocol sub-public keys;

[0038] A smart contract, deployed on the blockchain, is used to verify the validity of key shares and protocol sub-public keys, obtain the protocol master public key and other necessary credentials to calculate the protocol master private key.

[0039] The present invention also provides a computer-readable storage medium on which a computer program is stored, characterized in that when the program is executed, the distributed key generation method based on blockchain and CP-ABE is implemented.

[0040] The present invention also provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the distributed key generation method based on blockchain and CP-ABE when executing the program.

[0041] Beneficial Effects of the Invention

[0042] 1) Using blockchain as a public channel and CP-ABE as a cryptographic primitive, a distributed key generation method based on blockchain and CP-ABE is proposed. It only takes one round to generate a distributed master public key, and the communication complexity and computational complexity of the protocol are both O(n).

[0043] 2) A general hash-based commitment is designed and integrated into the CP-ABE encryption algorithm, so that external participants can verify the validity of the CP-ABE ciphertext.

[0044] 3) The DKG protocol requires less verification overhead in the sharing phase and provides verifiable decryption capabilities in the master private key reconstruction phase of the protocol with little loss in efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 Schematic diagram of the distributed key generation method based on blockchain and CP-ABE provided by the present invention.

[0046] Figure 2 Schematic diagram of the smart contract algorithm provided by the present invention.

[0047] Figure 3 A schematic diagram of gas consumption of the smart contract provided by the present invention.

[0048] Figure 4 This is a schematic diagram of gas consumption when the participating nodes are increased in the present invention and other documents.

[0049] Figure 5 A schematic diagram of the decryption overhead of the present invention and different protocols in other documents. DETAILED DESCRIPTION

[0050] The preferred embodiments of the present invention will be described in detail below so that the purpose, features and advantages of the present invention can be more clearly understood. It should be understood that the following embodiments are not intended to limit the scope of the present invention, but are only intended to illustrate the essential spirit of the technical solution of the present invention.

[0051] In the following description, certain specific details are set forth for the purpose of illustrating the various disclosed embodiments to provide a thorough understanding of the various disclosed embodiments. However, those skilled in the relevant art will recognize that the embodiments may be practiced without one or more of these specific details. In other cases, well-known devices, structures, and techniques associated with the present application may not be shown or described in detail to avoid unnecessarily obscuring the description of the embodiments.

[0052] References throughout the specification to "one embodiment" or "an embodiment" indicate that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, the appearances of "in one embodiment" or "in an embodiment" in various places throughout the specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any manner in one or more embodiments.

[0053] The purpose of the present invention is to provide a distributed key generation method based on blockchain and CP-ABE. The present invention introduces a hash-based general commitment algorithm in the protocol. In the sharing phase, the smart contract verifies the CP-ABE ciphertext and the protocol sub-public key by checking the commitment. In the reconstruction phase, external users only need O(n) computational complexity and communication complexity to reconstruct the protocol private key. It has better security and performance, and is superior to the DKG protocol based on PVSS.

[0054] The following is a further detailed introduction to the distributed key generation method based on blockchain and CP-ABE described in the present invention in conjunction with specific embodiments. The technical solution of the present invention includes but is not limited to the following embodiments.

[0055] Table 1 is a partial description of symbols.

[0056] Table 1. Description of some symbols

[0057]

[0058] 1. As Figure 1 As shown in the figure, the proposed DKG protocol consists of a sharing phase and a reconstruction phase. Each participating node P θ Randomly select a secret M θ And encrypt it to get the ciphertext C θ The protocol sub-public key of the participating nodes is calculated as Among them, SK Γ,θ =γ(Mθ ) and γ is the function γ:G T →Z P Then, each participating node sends PK to the smart contract Γ,θ , C θ and the corresponding commitmentCom θ During the effective time, each participating node can submit multiple times, and the protocol only uses the last submission during the calculation process. The global time parameter Δ is set when the smart contract is initialized. T When the contract receives the tuple (PK Γ,θ ,C θ ,Com θ ), the contract automatically checks whether the tuple is valid. If it passes the validity check, the participating node is considered honest. Once the timeout event is triggered or the contract receives the tuples submitted by all participating nodes, the contract automatically calculates and outputs the protocol master public key. Where S r is a random value used to avoid malicious attacks, and Q is the set of participating nodes that honestly submit ciphertexts.

[0059] Once an external user initiates a request to reconstruct the protocol master private key MSK, within the specified time, each participating node calls the AttrKeyGen algorithm to generate the decryption key K corresponding to its ciphertext component θ , and send it offline to the external user. If the external user receives at least t decryption keys, he can decrypt the corresponding ciphertext and calculate the master private key of the DKG protocol.

[0060] 2. Smart contract design, such as Figure 2 As shown, in the proposed DKG protocol, the smart contract (SC) involves 5 algorithms, including the Initialization algorithm, the Join algorithm, the Check algorithm, the GenMPK algorithm, and the getCredentials algorithm. Among them, the Initialization algorithm is the constructor that is automatically executed when the smart contract is deployed, the Join algorithm is called by the participating nodes to submit the ciphertext components and commitments, the Check algorithm is automatically executed when the participating nodes join the sharing phase to verify the submitted ciphertext components and the corresponding commitments, and the GenMPK algorithm is automatically executed after the validity period to calculate the protocol master public key MPK. The getCredentials algorithm is called to obtain the MPK and other necessary credentials to calculate the protocol master private key MSK.

[0061] 3. Commitment Generation and Verification

[0062] 1) Commitment Generation Algorithm ComGen (CT fp ,pk θ ,ε θ ,M)→Comθ ·P θ Choose a random value Calculate and export Commitment θ as follows:

[0063]

[0064] 2)Verify(CT fp ,pk θ ,Com θ ,M)→True / False, the verifier verifies the correctness and validity of the commitment as follows:

[0065]

[0066] 4. Specific structure of DKG protocol

[0067] The proposed DKG protocol contains a set of n participating nodes, denoted as P = {P1,P2,...,P n}. Each participating node is considered to be an attribute authorizer and also an encryptor. The initialization algorithm Setup can be called by any participating node and outputs global parameters TK and mk. Each participating node P in the participating node set P θ Both can call the AuthSetup algorithm to obtain their long-term private key sk θ =d θ and the public key Among them, the public key {pk θ} θ∈P It is open to every participating node.

[0068] 4.1 In the sharing phase, participating nodes P θ First, a random value s←Z is chosen p , using its private key to calculate the auxiliary parameter ε θ =s+sk θθ and CT fp =h s Then, P θ The Encrypt algorithm is called to calculate the ciphertext component. Different from the encryption algorithm of the Waters protocol, the present invention introduces an encryption algorithm to ensure that external users can also check the validity of the CP-ABE ciphertext. The algorithm inputs the message M θ , access control policy A, public parameter TK, and output a ciphertext C θ , as follows:

[0069]

[0070] That is, P θ From G TRandomly select a value M from θ , transfer the threshold access tree (acp) to the LSSS matrix, and perform M θ Encrypt and generate ciphertext component C θ For any A=(A l×n ,ρ),A l×n Each row i in P corresponds to an attribute ρ(i), θ Random Selection And calculate the shared vector Among them A i is the i-th row of A. Then, P θ Randomly select {r1,r2,...,r l )∈Z p And calculate the ciphertext C θ :

[0071]

[0072] Then, P θ Calculate the DKG master public key PK Γ,θ :

[0073]

[0074] Here, h is a generator randomly selected from G1.

[0075] In addition, in order to commit to PK Γ,θ The effectiveness of the participating nodes P θ Choose a random value Extract and export Commitment Com θ , as shown below:

[0076]

[0077] Finally, P θ The tuple (C θ ,PK Γ,θ ,Com θ ) is sent to the contract SC, which indicates that P θ Commit PK to the contract Γ,θ efficient.

[0078] When the contract SC receives the tuple (C θ ,PK Γ,θ ,Com θ ) and automatically calls the Check algorithm to check Com θ The correctness and effectiveness are as follows:

[0079]

[0080] Nodes that pass the verification will be added to the set Q.

[0081] 4.2 Calculate the decryption key K corresponding to the ciphertext component θ

[0082] Participating Node P θ Call AttrKeyGen (computational complexity is O(1)) algorithm to generate K θ as follows:

[0083]

[0084] Where H is a publicly available function that maps attributes to a unique key using a hash function.

[0085] 4.3 Calculate the protocol master public key MPK:

[0086] Once all participating nodes are within the time limit Δ T Once each ciphertext and commitment is submitted or a timeout event occurs, external users can call the getCredentials algorithm in the contract SC to obtain the master public key MPK of the DKG protocol. The calculation formula is as follows:

[0087]

[0088] 4.4 Protocol Master Private Key MSK Reconstruction:

[0089] In the reconstruction phase, the protocol master private key MSK is defined as follows:

[0090]

[0091] Since every participating node in set Q is a legal node, if any user P in set Q u Want to recover P u First, send a reconstruction request to the contract SC to obtain the ciphertext and the corresponding decryption key set When the user receives at least t = [n / 2] + 1 valid decryption keys and ciphertexts, he can call the decryption algorithm M one by one. θ ←Decrypt(C θ ,K θ ) to get the secret value Specifically, for the secret value M θ , the algorithm first selects a set of constants w i ∈Z p , so that Among them A i Indicates A l×n The i-th row of P θ The attributes satisfy the LSSS strategy A=(Al×n ,ρ), and satisfy the following formula:

[0092]

[0093] Then, calculate F as:

[0094]

[0095] Finally, calculate M θ :

[0096]

[0097] When P u Receive at least t valid decryption keys The protocol master private key MSK can be reconstructed.

[0098]

[0099] 5. Correctness and security analysis

[0100] 5.1 Correctness Analysis

[0101] The correctness of CP-ABE ciphertext is mainly determined by formula (12), and its correctness is as follows:

[0102]

[0103] The contract verifies the protocol sub-public key mainly through formula (15), and its correctness is as follows:

[0104]

[0105] 5.2 Security Analysis

[0106] 5.2.1 Threat Model

[0107] In the sharing phase, the set of honest participating nodes is defined as Q. The attacker can calculate the MPK by submitting arbitrary messages to the public channel. He may also launch a DoS attack, deviate from or terminate the protocol. Assume that there are at most f malicious participating nodes in the protocol, that is, the worst case is that f malicious participating nodes collude with each other privately. In other words, if the attacker controls f participating nodes, the attacker can make adaptive behaviors based on honest behaviors, including launching fast attacks. In order to ensure vitality / availability, the number of honest participating nodes should be more than the corrupt party, that is, f<n / 2. In the reconstruction phase, the threshold is set to t<n / 2+1, that is, as long as there are t honest participating nodes, the private key of the DKG protocol can be reconstructed. The adversaries in the sharing phase and the reconstruction phase can be different sets, which means that the proposed DKG protocol can effectively resist adaptive attacks.

[0108] 5.2.2 Security Analysis

[0109] Given a smart contract SC, in a fast adaptive opponent There exists a secure DKG protocol that satisfies "effectiveness", "confidentiality" and "robustness".

[0110] Theorem 1 (Validity): The proposed DKG protocol is valid if the following conditions are met:

[0111] All honest participating nodes can calculate the unique protocol master key MSK;

[0112] For honest participating nodes, there is an efficient process to calculate the protocol master key MSK;

[0113] All honest participating nodes can calculate the public key MSK = h MSK .

[0114] Proof: In the sharing phase, You can submit an invalid protocol sub-public key to the contract SC by controlling f participating nodes To deviate from the protocol, but since the proposed DKG protocol uses hash commitment to check the tuples submitted by participating nodes (C θ ,PK Γ,θ ,Com θ ), through the verification formula (7), the dishonest participating nodes will be detected by the contract SC, and the tuple (C θ ,PK Γ,θ ,Com θ ) Once submitted to the contract, no attacker can tamper with its content. In addition, due to the discrete logarithm assumption, Unable to pass CP-ABE encryption θ and PK Γ,θ Get the secret value M θ Therefore, the protocol master key MSK is unique and is When a timeout event is triggered or n valid child public keys are collected When the contract SC can effectively calculate the protocol master public key in, and a random value h Sr is public. In the reconstruction phase, since all valid ciphertexts C θ In the encryption algorithm, the access tree has the same threshold. If t < n / 2 + 1 honest decryption keys K are collected θ , an external user can decrypt all ciphertexts C in Q θ , and then reconstruct the protocol master private key MSK. Even if one of the participating nodes in Q is dishonest during the reconstruction phase, {M θ}θ∈Q can be recovered by at least t honest participating nodes. Therefore, the proposed DKG protocol satisfies the “effectiveness”.

[0115] Theorem 2 (Confidentiality): The protocol master key MSK is kept secret from any participating node or any collusion member.

[0116] Proof: The protocol master key MSK is a random secret value M θ The sum. All secret values ​​{M θ} θ∈Q To achieve this goal, The discrete logarithm problem needs to be solved to obtain the secret value {M θ} θ∈Q Therefore, the protocol master key MSK is kept secret from any participating node or any collusion member f<(n / 2) before reconstruction. Therefore, the proposed DKG protocol satisfies the “confidentiality”.

[0117] Theorem 3 (Robustness): Even if there are f malicious participating nodes, any t<n / 2 honest participating nodes can effectively calculate the protocol master private key MSK.

[0118] Proof: Assume that there are f<n / 2 malicious participating nodes in the reconstruction phase, that is, the number of honest participating nodes is greater than the threshold t, that is, nf≥t. Set the threshold t to n / 2+1(>f). Each participating node can commit to the validity of its decryption key with the associated ciphertext. As long as t honest decryption keys are combined, the ciphertext of the honest party Q can be decrypted to ensure that the MSK is obtained. Each participating node calls the Encrypt algorithm as the encryptor when constructing the MPK, and calls the AttrKeyGen algorithm as the attribute authority when recovering the MSK. These two algorithms are called independently, and the honest party that guarantees availability may be different in each algorithm. Therefore, by calling the key generation and decryption algorithms, each participating node can effectively calculate the MSK, that is, the protocol remains "robust" against f(<n / 2) malicious participating nodes.

[0119] 6. Performance Evaluation

[0120] The proposed DKG protocol consists of offline and online parts. The experiment sets t=n / 2+1, and the performance evaluation is carried out on a computer equipped with an Intel Core 2.9GHz i7-7500U CPU and 8GB RAM, where t is the threshold used by CP-ABE. For offline overhead, the elliptic curve cryptography (ECC) curve "bn_128" is implemented based on the py_ecc library, and CP-ABE is implemented in the Python language. In addition, for the evaluation of online overhead, since in the sharing stage and the reconstruction stage, the participating nodes only need to interact with the smart contract and do not need to implement the P2P network, the present invention uses Solidityv0.5.17 to write the smart contract and deploy it to the Ethereum platform to evaluate the online overhead of the protocol.

[0121] The complexity of the proposed DKG protocol will be compared and analyzed below, and the efficiency of the proposed DKG protocol will be evaluated through simulation experiments.

[0122] 6.1 Complexity Analysis

[0123] Table 2 gives the number of operations for the Encrypt algorithm, AttrKeyGen algorithm, and Decrypt algorithm. i The addition and multiplication operations on G1×G2 are performed, ModPow represents the multiplication and division operations of large prime numbers, and Pairing represents the operation from G1×G2 to G T As shown in Table 2, for the Encrypt algorithm, in order to encrypt the secret value M θ , participating node P θ It is necessary to perform n+1 multiplication operations on group G1, n addition operations and 3n multiplication operations on group G2. T Perform n+1 addition operations and 3n multiplication operations on the AttrKeyGen algorithm to generate the decryption key K θ ,P θ It is necessary to perform 2 addition operations and 3 multiplication operations on group G1, and 1 multiplication operation on group G2; for the Decrypt algorithm, in order to decrypt the ciphertext C θ ,P θ Need to be in group G T 3n addition operations, 4n multiplication operations and 1 bilinear mapping operation are performed on it.

[0124] Table 2 Number of operations of each algorithm in CP-ABE

[0125]

[0126]

[0127] Table 3 gives the ciphertext C θ And the protocol sub-public key PK Γ,θ The creation cost of C. θ , P θ One Pairing operation and one MulG1 operation are required; in order to generate the ciphertext component C1, P θ It is necessary to perform n AddG1 operations, 2n MulG1 operations, and 3n ModPow operations; in order to generate the ciphertext component C2, P θ It is necessary to perform n AddG1 operations and 2n MulG1 operations; in order to generate PK Γ,θ One AddG1 operation and two MulG1 operations need to be performed.

[0128] Table 3 Creation cost of ciphertext and protocol sub-public key

[0129]

[0130] Table 4 gives the comparison results of the proposed DKG protocol with references A (Ciphertext-policy attribute-based encryption: an expressive, efficient, and provably secure realization) and B (Towards scalable threshold cryptosystems) in terms of cryptographic primitives, verification complexity, computational complexity, and communication complexity. As shown in Table 5, the complexity of the protocol in the sharing phase is consistent with references A and B, and the complexity of the protocol in the reconstruction phase is lower than that of reference A and consistent with reference B. However, in the verification phase, the complexity of the protocol depends on the number of participating nodes, and the verification complexity is O(n), which is lower than that of references A and B. This is because in the proposed DKG protocol, the smart contract only needs to verify the number of participating nodes P. θ Submitted PK Γ,θ During the sharing phase, the participating nodes run the Encrypt algorithm to generate encrypted shares C θ and PK Γ,θ , and upload it to the smart contract. Therefore, the communication complexity and computational complexity of the sharing phase are O(n). In the reconstruction phase, the external participating nodes need to call

[0131] Decrypt algorithm gets M θ , and the size of each decryption key is O(1), the computational complexity is O(n), and the communication complexity is O(n).

[0132] Table 4 Protocol complexity comparison

[0133]

[0134] 6.2 Experimental Results

[0135] 6.2.1 On-chain expenses

[0136] In the sharing phase, no matter how many malicious nodes are involved, the smart contract SC will Γ,θ The validity of the shared shares can be verified, and any external participating node can verify the correctness of the ciphertext. Therefore, smart contracts are used in Ethereum to estimate the cost of share verification to commit to the practicality of the proposed DKG protocol.

[0137] like Figure 3 As shown, the gas value consumed by deploying the contract SC is 909713Gas, and the check function is used to verify the DKG sub-public key PK Γ,θ The gas consumption of generating the DKG public key MPK using the genMPK function is small, and the gas consumption of participating nodes using the join function to submit commitments and using the getCredentials function to obtain credentials is also small. Figure 4 The total gas consumption of different DKG protocols when the number of participating nodes ranges from 20 to 1000 is given.

[0138] like Figure 4 As shown in the figure, the total gas cost increases linearly with the number of participating nodes. The total gas cost of the proposed DKG protocol is less than that of reference C (One round threshold discrete-log key generation without private channels) and reference D (1-round distributed key generation with efficient reconstruction using decentralized CP-ABE. IEEE Trans.). This is because reference C does not have one round in the sharing phase, and needs to send secret shares to each participating node, and its encrypted shares cannot be publicly verified. In addition, reference D needs to generate more encrypted shares in the sharing phase.

[0139] 6.2.2 Offline expenses

[0140] In the proposed DKG protocol, the ciphertext C θ And the protocol sub-public key PK Γ,θ The creation cost of C is independent of the number of participating nodes. The offline overhead is mainly determined by the decryption algorithm in the reconstruction phase. θ The decryption overhead is evaluated. Figure 5Given the number of participating nodes changes from 20 to 1000, the external user runs the decryption algorithm to decrypt the ciphertext C θ To get the secret value M θ expenses.

[0141] like Figure 5 As shown in the figure, as the number of participating nodes increases, the ciphertext decryption time of document C, document D and the proposed DKG protocol will increase. However, since the DKG protocol of document C is designed based on PVSS, its ciphertext decryption time is limited by the Lagrange interpolation method and is higher than that of document D and the proposed DKG protocol. The ciphertext decryption time required by document D is slightly lower than that of the proposed DKG protocol. This is because the proposed DKG protocol introduces a commitment seed in the process of ciphertext generation, which requires additional computational overhead. However, document D does not support external users to verify the validity of encrypted shares, so the overall performance of the proposed DKG protocol is better than that of document C and document D.

[0142] The matters not described in detail in the present invention are all known technologies to those skilled in the art.

[0143] The above shows and describes the basic principles and main features of the present invention and the advantages of the present invention. It should be understood by those skilled in the art that the present invention is not limited to the above embodiments. The above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention to be protected. The scope of protection of the present invention is defined by the attached claims and their equivalents.

Claims

1. A distributed key generation method based on blockchain and CP-ABE, characterized in that: include: Step 1: In the sharing phase, n participating nodes independently select random values ​​as their key shares, and use the CP-ABE algorithm to encrypt the key shares generated by each participating node to generate the corresponding CP-ABE ciphertext; Use blockchain as a public channel to encrypt and transmit key shares; The participating node calculates its protocol sub-public key and generates a hash commitment associated with the ciphertext and the protocol sub-public key; and submits its ciphertext, protocol sub-public key and corresponding hash commitment through a smart contract; The validity of the protocol sub-public key and the corresponding CP-ABE ciphertext of each participating node is verified through the smart contract on the blockchain, and the verification process includes the verification of the hash commitment; Step 2: During the reconstruction phase, after an external user initiates a request to reconstruct the protocol master private key, the participating node responds to the request, generates and provides its corresponding decryption key; The external user collects at least t corresponding decryption keys, uses the collected decryption keys to decrypt the corresponding ciphertext, and then reconstructs the master private key of the protocol; The t is a preset reconstruction threshold, and the threshold t is defined as the smallest integer greater than half of the total number of participating nodes.

2. The distributed key generation method based on blockchain and CP-ABE according to claim 1 is characterized in that: The CP-ABE algorithm includes: Security parameter input algorithm, used to generate global parameters and master keys; Authorization setup algorithm, used to generate long-term secret keys and public key pairs; Attribute key generation algorithm, generates attribute private key based on attribute set and master key; Encryption algorithm, which generates ciphertext based on the access structure and the message and public parameters; Decryption algorithm,decrypts the message based on the attribute private key and ciphertext.

3. The distributed key generation method based on blockchain and CP-ABE according to claim 2 is characterized in that: Hash commitment is introduced into the CP-ABE algorithm, and the external user checks the CP-ABE ciphertext to verify its validity.

4. The distributed key generation method based on blockchain and CP-ABE according to claim 1 is characterized in that: The hash commitment algorithm is used to provide the verifiability properties of the CP-ABE ciphertext and the protocol sub-public key on the smart contract, and the specific verification process is completed on the Ethereum platform.

5. The distributed key generation method based on blockchain and CP-ABE according to claim 4 is characterized in that: The smart contract automatically performs the following operations: Receiving the ciphertext and commitment submitted by the participating nodes; Verify the ciphertext and corresponding commitment submitted by the participating nodes in the sharing phase; Automatically executed after the validity period to calculate the protocol master public key; During the reconstruction phase, the protocol master public key and other necessary credentials are provided to assist external users in calculating the protocol master private key.

6. The distributed key generation method based on blockchain and CP-ABE according to claim 1 is characterized in that: The communication complexity and computational complexity of the sharing phase and the reconstruction phase are both O(n).

7. A system for executing the distributed key generation method based on blockchain and CP-ABE as claimed in any one of claims 1 to 6, characterized in that: include: Multiple participating nodes, each of which is able to generate a key share and encrypt using the CP-ABE algorithm; A blockchain network for transferring encrypted key shares and protocol sub-public keys; A smart contract, deployed on the blockchain, is used to verify the validity of key shares and protocol sub-public keys, obtain the protocol master public key and other necessary credentials to calculate the protocol master private key.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed, a distributed key generation method based on blockchain and CP-ABE as described in any one of claims 1 to 6 is implemented.

9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the distributed key generation method based on blockchain and CP-ABE as described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Improved attribute-based encryption scheme system and encryption algorithm thereof

    CN114117475A

  • Internet of Things ciphertext access control method based on block chain

    CN117081803A