A distributed privacy computing network node management method and system
Through the certificate-free public key cryptography system and star network architecture, the high operation and maintenance costs, insufficient security and cross-institutional trust in distributed privacy computing technology are solved, and efficient and secure end-to-end encrypted communication is achieved.
Patent Information
- Application Number
- CN202510272468.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-03-10
AI Technical Summary
The existing distributed privacy computing technology has high operation and maintenance costs, insufficient security, and the cross-institutional trust problem is difficult to solve.
The certificate-free public key cryptography system (CL-PKC) is used for computing node identity authentication, and end-to-end encrypted communication is realized through the star network architecture and the Diffie-Hellman key exchange algorithm to reduce dependence on the centralized trust root.
It improves the flexibility of cross-institutional cooperation, reduces operation and maintenance costs and security risks, and enhances its ability to resist man-in-the-middle attacks and traffic analysis attacks.
Smart Images

Figure CN119788426B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of privacy computing, and in particular relates to a distributed privacy computing networking node management method and system. Background Art
[0002] With the rapid development of technologies such as big data and artificial intelligence, the value of data has become increasingly prominent. However, data privacy protection issues have also arisen. In cross-institutional data cooperation scenarios, institutions need to conduct joint computing without sharing original data for data security and privacy protection considerations. Therefore, how to achieve data sharing and joint computing while ensuring data privacy has become an urgent problem to be solved.
[0003] At present, distributed privacy computing technology has received widespread attention as an effective solution. Privacy computing, as an important technical system in the field of data security and privacy protection, achieves the goal of "data available but invisible" by realizing data analysis and calculation under the premise of protecting the data itself from external leakage. Privacy computing has been widely used in many industries such as finance, telecommunications, medical care, and government affairs, especially in scenarios such as data sharing, joint modeling, and privacy protection. With the implementation of laws and regulations related to data privacy, the demand for privacy computing by enterprises and institutions continues to increase.
[0004] The Chinese invention patent application with publication number CN116015906A discloses a node authorization method, node communication method and device for privacy computing. In the node authorization method for privacy computing, node authentication is performed based on the first digital certificate and the second digital certificate issued to the authorization node and the node to be authorized respectively based on the common trust root of the authorization node and the node to be authorized; in response to the node authentication being passed, the following authorization credential negotiation steps are performed within the validity period of the node authentication being passed: generating a first key; receiving a second encryption key sent by the node to be authorized, wherein the second encryption key is obtained by encrypting the second key using the first public key obtained after processing the first digital certificate; using the negotiated key generation algorithm to generate a key as the authorization credential.
[0005] The above scheme relies on the first digital certificate and the second digital certificate preset by the root of trust (Root CA) for node authentication, requiring all computing participants to share the same root of trust, limiting interoperability across institutions. At the same time, the scheme also has certain shortcomings in terms of node authentication, key negotiation, and node management, such as cumbersome certificate management, complex key negotiation process, lack of effective end-to-end secure communication mechanism, etc. The exchange method of the first key and the second key may make the key negotiation process vulnerable to man-in-the-middle attacks. Summary of the invention
[0006] The present invention provides a distributed privacy computing networking node management method and system, aiming to solve the problems of high operation and maintenance costs, insufficient security, and cross-institutional trust in the prior art.
[0007] In order to solve the above technical problems, the present invention proposes a distributed privacy computing network node management method, which includes the following steps:
[0008] A computing node obtains the first private key fragment, generates a node temporary public key, and sends registration information to the central node, wherein the registration information includes the node temporary public key, the node identity, and the node system parameters;
[0009] The central node performs registration verification on the received registration information, and after the registration verification is passed, uses the same random number to calculate the authorization public key and the second private key fragment and returns them to the one computing node;
[0010] The computing node constructs a computing node private key according to the first private key fragment and the second private key fragment, generates a self-signature using the computing node private key, constructs an access authentication request and sends it to the central node;
[0011] The central node performs signature verification on the received access authentication request, allocates a virtual address to the computing node after the verification is passed, and synchronizes the node list containing all computing nodes;
[0012] The computing node configures a virtual network according to the allocated virtual address, and connects the central node and other computing nodes through the virtual network;
[0013] The computing node calculates shared keys with other computing nodes based on the node list, and uses the shared keys to encrypt data during the communication process.
[0014] Preferably, the calculation method of the node temporary public key is:
[0015]
[0016] In the formula, is the node's temporary public key, represents the elliptic curve base point, is the first private key fragment, randomly selected from the multiplication group of integers modulo n.
[0017] Preferably, the calculation method of the authorization public key is:
[0018]
[0019] In the formula, is the authorized public key for calculation, is a random number, randomly selected from the multiplication group of integers modulo n, represents the elliptic curve base point, The node temporary public key sent to the compute node.
[0020] Preferably, the second private key fragment is generated by:
[0021]
[0022] In the formula, is the second private key fragment, is a random number, randomly selected from the multiplication group of integers modulo n, The master public key of the central node The corresponding central node private key, is the identification factor, and its calculation method is:
[0023]
[0024] in, represents a hash function, is the node identity of the computing node, is the authorized public key of the computing node, is the system parameter of the computing node, Represents a string concatenation operation.
[0025] Preferably, the signature verification method is specifically as follows:
[0026] The central node calculates the verification public key based on the access authentication request data :
[0027]
[0028] in, It is the authorized public key calculated by the central node based on the registration information. It is an identification factor, which is obtained through hash operation based on registration information, node system parameters and authorized public key. The private key of the central node The corresponding central node master public key;
[0029] Use the verification public key to verify that the compute node is self-signed using the compute node's private key.
[0030] Preferably, the shared key is based on the Diffie-Hellman key exchange algorithm, and the generation method is:
[0031]
[0032]
[0033] In the formula, For computing nodes and compute nodes The shared key between represents a hash function, Indicates characterization operation, Represents a compute node and compute nodes Node identity and Perform an XOR operation, Indicates the splicing calculation node and compute nodes Authorized public key and Perform an XOR operation, For computing nodes The key generated in collaboration with the central node, For computing nodes The key generated in collaboration with the central node, For computing nodes The identification factor, For computing nodes The identification factor, The private key of the central node The corresponding central node master public key.
[0034] Preferably, the synchronization data of the node list includes the node identity of the computing node, the authorization public key, the node access timestamp, the node virtual address and the node self-signature.
[0035] Preferably, the self-signature is signed using an SM2 signature algorithm.
[0036] Preferably, the computing node establishes a secure communication channel based on a shared key and encrypts the data for transmission, wherein:
[0037] The computing nodes use a symmetric encryption algorithm to encrypt the communication data and use a shared key as the encryption key;
[0038] The computing node decrypts the received encrypted data using the shared key.
[0039] In another aspect of the present invention, a distributed privacy computing network node management system is also provided. The system is used to implement the above method, including:
[0040] The computing node is used to generate a first private key fragment and a node temporary public key, send registration information to the central node, and after receiving the authorization public key and the second private key fragment returned by the central node, calculate the computing node private key, and complete access authentication and end-to-end encrypted communication;
[0041] The central node is used to receive the registration information of the computing node, perform registration verification, calculate the authorization public key and the second private key fragment and return them to the computing node, perform access authentication, allocate virtual addresses, and synchronize node list information;
[0042] The node management module is deployed on the central node to maintain the node list of all computing nodes and synchronize it to each computing node regularly;
[0043] The key management module is used to manage the private key fragments, authorized public keys, and shared keys of each computing node, and to execute the Diffie-Hellman key exchange algorithm to generate end-to-end communication keys;
[0044] A communication encryption module, used to calculate a shared key, and encrypt and decrypt communication data between computing nodes based on the shared key to achieve end-to-end encrypted communication;
[0045] The authentication module is used to calculate and verify the public key and verify the self-signature of the computing node based on the SM2 signature algorithm to ensure the legitimacy of the computing node.
[0046] Compared with the prior art, the present invention has the following technical effects:
[0047] 1. The node management method proposed in this invention adopts certificate-less public key cryptography (CL-PKC) to authenticate computing nodes, avoiding the reliance of traditional public key infrastructure (PKI) on centralized trust roots. Computing nodes do not need to rely on a unified trust root, which improves the flexibility of cross-institutional cooperation and is suitable for decentralized computing scenarios such as federated learning and privacy computing.
[0048] 2. The node management method proposed in the present invention does not require certificate management, thus avoiding the security risks and high operation and maintenance costs in the process of certificate issuance, storage, and revocation, preventing security threats such as certificate forgery and trust chain attacks in traditional PKI schemes, and improving the security of computing node identity authentication.
[0049] 3. The node management method proposed in the present invention adopts non-interactive key negotiation. The computing nodes can establish a shared key without communication, and use the key for end-to-end encryption. This avoids the risk of traditional protocols requiring interactive transmission of public keys and effectively avoids man-in-the-middle attacks.
[0050] Since key negotiation between computing nodes does not require interaction, even if an attacker intercepts the communication data, it cannot be decrypted, thereby enhancing the ability to resist traffic analysis attacks.
[0051] 4. The node management method proposed in the present invention makes the key negotiation process more efficient due to its non-interaction-related characteristics, and is suitable for high-concurrency, low-latency privacy computing applications.
[0052] 5. The node management method proposed in the present invention adopts a star network architecture for cross-institutional networking, avoiding the need to establish direct connections between each computing node and reducing the reliance on dedicated network. The computing nodes are securely routed through the central node. Compared with the traditional fully connected P2P structure, the system is easier to expand and supports the dynamic joining and exit of large-scale computing nodes.
[0053] 6. The node management method proposed in the present invention introduces zero-trust single-packet authentication and performs access control at the port level of the central node. Only legitimate computing nodes can initiate connections. To prevent port scanning and brute force attacks, computing nodes cannot detect whether the target port is open before passing authentication, which fundamentally reduces the exposed attack surface and enhances the security of the privacy computing environment. Combined with non-interactive key negotiation, even if an attacker forges the identity of a computing node to perform a port scan, they cannot bypass security authentication, further improving security. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 It is a flowchart of the node management method of the present invention;
[0055] Figure 2 is a schematic diagram of the cross-institutional network structure according to an embodiment of the present invention;
[0056] Figure 3 is a schematic diagram of node registration according to an embodiment of the present invention;
[0057] Figure 4 is a schematic diagram of node access according to an embodiment of the present invention;
[0058] Figure 5 This is a schematic diagram of node communication according to an embodiment of the present invention. DETAILED DESCRIPTION
[0059] In order to make the objectives, technical solutions and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in combination with specific embodiments of the present application and with reference to the accompanying drawings.
[0060] Embodiment 1
[0061] This embodiment is a distributed privacy computing network node management method. Figure 1 As shown, the steps include steps one to six:
[0062] First, in this embodiment, Figure 2As shown in the figure, it is a schematic diagram of the cross-institutional network structure, which has a central node and several computing nodes, forming a star network structure, and the central node is connected to each computing node through a physical line. The physical line can be the public network line of the operator, or it can be a dedicated line connection, such as a power line, a public security line, or a financial line.
[0063] The node registration process is as follows: Figure 3 As shown, step one and step two are involved.
[0064] Step 1: A computing node obtains the first private key fragment and generates a node temporary public key , send registration information to the central node, the registration information includes the node temporary public key , Node identity and node system parameters .
[0065] The calculation method of the node temporary public key is:
[0066]
[0067] In the formula, is the node's temporary public key, represents the elliptic curve base point, is the first private key fragment, which is obtained by the computing node from the integer modulus Randomly select from the multiplication group, satisfying ,in is the order of the elliptic curve. After the calculation is completed, an integrity check is performed to ensure Comply with legal curve parameters to prevent small subgroup attacks.
[0068] In some other embodiments of the present invention, the registration information may also include the registration timestamp and entity information of the organization described in the computing node, such as the organization name, organization code, etc. The central node will compare the validity of the registration timestamp and the authenticity of the entity information one by one when performing registration verification. It may also include the computing node's unique device identifier Device_ID (such as the identity identifier provided by the trusted execution environment TEE), the computing node's computing power parameters (such as CPU, memory, bandwidth limit), the node's network information (such as IP address, NAT type), and the security modules supported by the computing node (such as SGX, TPM).
[0069] Step 2: The central node performs registration verification on the received registration information. After the registration verification is passed, the same random number is used to calculate the authorization public key and the second private key fragment and return them to the computing node. In this embodiment, the registration verification is that the central node compares the computing node registration application information according to preset data. If the comparison is passed, the registration verification is passed.
[0070] The central node's verification of the registration information also includes:
[0071] Check whether the timestamp is within the allowed range (such as valid within 5 minutes) to prevent replay attacks;
[0072] Verify the node identity and compare whether the ID matches the organization entity information;
[0073] Verify that the temporary public key is valid and ensure that it belongs to a legal elliptic curve point;
[0074] Query the list of registered nodes to prevent malicious nodes from impersonating legitimate nodes for repeated registration.
[0075] The calculation method of the authorization public key is:
[0076]
[0077] In the formula, is the authorized public key for calculation, is a random number, randomly selected from the multiplication group of integers modulo n, represents the elliptic curve base point, The node temporary public key sent to the compute node.
[0078] The method for generating the second private key fragment is:
[0079]
[0080] In the formula, is the second private key fragment, is a random number, randomly selected from the multiplication group of integers modulo n, The master public key of the central node The corresponding central node private key, is the identification factor, and its calculation method is:
[0081]
[0082] in, represents a hash function, is the node identity of the computing node, is the authorized public key of the computing node, is the system parameter of the computing node, Represents a string concatenation operation.
[0083] Among them, the random number used to calculate the authorized public key and the second private key fragment is the same random number.
[0084] See also Figure 4, is a schematic diagram of node access. The node access process involves steps three to five.
[0085] Step 3: The computing node constructs a computing node private key according to the first private key fragment and the second private key fragment, generates a self-signature using the computing node private key, constructs an access authentication request and sends it to the central node. In this step, the computing node has obtained the first private key fragment and the second private key fragment, wherein the first private key fragment is randomly selected locally in step 1, and the second private key fragment is generated and returned by the central node in step 2. The computing node uses these two private key fragments to construct a complete computing node private key.
[0086] Specifically, the calculation method of the computing node private key is as follows:
[0087]
[0088] in, is the computing node private key, The second private key fragment is generated by the central node based on the central node key, random number and identification factor. It is the first private key fragment, which is randomly selected by the computing node from the integer modulo n multiplication group. This ensures that the computing node private key is jointly generated by the computing node and the central node, and is only owned by the computing node and is invisible to the central node.
[0089] So far, for the computing nodes , which stores relevant information locally , corresponding to the central node public key and computing node The node identity of the central node to the computing node Returned authorization public key, computing node The computing node private key obtained by self-calculation.
[0090] The computing node uses its private key Generate a self-signed , used to initiate authentication requests to the central node later.
[0091] In one embodiment of the present invention, the signature generation method may be the ECDSA (Elliptic Curve Digital Signature Algorithm) algorithm:
[0092]
[0093] In the formula, For the generated self-signed Indicates the use of private key Compute elliptic curve digital signatures, represents a hash function, They represent the node identity, authorization public key and access timestamp of the computing node respectively. Represents a string concatenation operation.
[0094] The access authentication request format sent by the computing node to the central node is , respectively represent the node identity, authorized public key, access authentication timestamp, and generated self-signature of the computing node. Since the authentication request contains the timestamp and signature, the central node can verify the data integrity and prevent tampering. If an attacker attempts to replay an old authentication request, the central node can check whether the timestamp is within the valid time window and reject it if it exceeds the threshold. An attacker cannot forge the signature of a computing node. The private key of a computing node is only calculated by the computing node itself and cannot be obtained by the central node, ensuring privacy and security.
[0095] In step 4, the central node performs signature verification on the received access authentication request. After the verification is passed, a virtual address is assigned to the computing node, and a node list containing all computing nodes is synchronized; the synchronization data of the node list includes the node identity of the computing node, the authorization public key, the node access timestamp, the node virtual address and the node self-signature.
[0096] The goals of this step include: verifying the access authentication request signature of the computing node and confirming the legitimacy of the computing node's identity; assigning a virtual address to the computing node for subsequent networking communications; and synchronizing the node list to all computing nodes to ensure that the node information in the entire distributed privacy computing network is consistent. First, the central node parses the access authentication request, extracts the data, and prepares for signature verification.
[0097] The signature verification method is specifically as follows:
[0098] The central node calculates the verification public key based on the access authentication request data :
[0099]
[0100] in, The authorization public key is calculated by the central node based on the registration information. In step 2, it is calculated by the central node and returned to the computing node and saved locally in the central node. It is the identification factor, which is obtained by hashing the registration information, node system parameters and the authorized public key. The calculation method is the same as that in the second private key fragment. The calculation method of The private key of the central node The corresponding central node master public key;
[0101] Will Substitute verification public key The calculation formula is , and the central node public key Use private key Based on the elliptic curve algorithm, there are ,therefore , and since in step 2 there is , and finally transformed into , substitute ,get , and then substitute ,have According to the above derivation, there is a prerequisite for signature verification in this step: .
[0102] Based on the above premise, the central node in this step calculates and verifies the public key , which is consistent with the public key calculated by the computing node using the computing node private key based on the elliptic curve algorithm in step 3. Therefore, the verification public key is used to verify the self-signature of the computing node using the computing node private key.
[0103] Step 5: The computing node configures a virtual network according to the allocated virtual address, and connects the central node and other computing nodes through the virtual network.
[0104] After successfully verifying the signature of the computing node, the central node assigns a virtual address to the computing node. This embodiment adopts a distributed virtual network (Overlay Network) mechanism to provide an isolated environment. Specifically, the address allocation strategy can be one of static allocation, static allocation and distributed Hash. Among them, static allocation is maintained by the central node to allocate a fixed virtual IP to the computing node; dynamic allocation uses a DHCP-like mechanism to dynamically allocate a virtual IP when accessing; distributed Hash: DHT (Distributed Hash Table) is used to allocate virtual addresses.
[0105] The central node needs to synchronize the current node information to all computing nodes to ensure network availability. The central node constructs the latest computing node list to calculate the node For example, the fields , respectively represent the computing nodes Node identity, authorization public key, access timestamp, virtual address, and self-signature.
[0106] The node list synchronization mechanism of this embodiment includes:
[0107] Based on peer-to-peer (P2P) synchronization, the Gossip protocol is used for distributed synchronization to reduce network load; computing nodes regularly exchange incremental updates with neighboring nodes;
[0108] Based on broadcast (Multicast) synchronization, the central node periodically broadcasts to all computing nodes. After receiving the information, the computing nodes update the node information stored locally.
[0109] Based on query (On-demand) synchronization, computing nodes can actively request the latest node list from the central node, which is suitable for situations with low network bandwidth or low node joining rate.
[0110] Step 6: The computing node calculates the shared key with each other computing node based on the node list, and uses the shared key to encrypt the data in the communication process, such as Figure 5 As shown, it is a schematic diagram of node communication in this embodiment.
[0111] The shared key is based on the Diffie-Hellman key exchange algorithm and is generated as follows:
[0112]
[0113]
[0114] In the formula, For computing nodes and compute nodes The shared key between represents a hash function, Indicates characterization operation, Represents a compute node and compute nodes Node identity and Perform an XOR operation, Indicates the splicing calculation node and compute nodes Authorized public key and Perform an XOR operation, For computing nodes The key generated in collaboration with the central node, For computing nodes The key generated in collaboration with the central node, For computing nodes The identification factor, For computing nodes The identification factor, and The calculation method is the same as in the second private key fragment The calculation method of Central node and key The corresponding public key.
[0115] The premise for the above shared key generation equation is: , Therefore, the calculated key On the compute node and They are consistent and can be used for symmetric encryption.
[0116] Compute Node Compute nodes The communication process between them is as follows:
[0117] Encrypted data, computing nodes Send data to compute nodes When first finding and calculating the node Shared key Encrypt data using a symmetric encryption algorithm; send encrypted data along with a message authentication code to ensure integrity.
[0118] Decrypt data, compute nodes After receiving the encrypted data, find and calculate the node Shared key , decrypted using the same encryption algorithm, and verified data integrity through a message authentication code.
[0119] The above-mentioned symmetric encryption algorithms include AES-GCM, ChaCha20, etc.
[0120] The computing nodes establish a secure communication channel based on a shared key and encrypt and transmit data, wherein:
[0121] The computing nodes use a symmetric encryption algorithm to encrypt the communication data and use a shared key as the encryption key;
[0122] The computing node decrypts the received encrypted data using the shared key.
[0123] Embodiment 2
[0124] A distributed privacy computing network node management system, the system is used to implement the method as described in Example 1, including:
[0125] The computing node is used to generate a first private key fragment and a node temporary public key, send registration information to the central node, and after receiving the authorization public key and the second private key fragment returned by the central node, calculate the computing node private key, and complete access authentication and end-to-end encrypted communication;
[0126] The central node is used to receive the registration information of the computing node, perform registration verification, calculate the authorization public key and the second private key fragment and return them to the computing node, perform access authentication, allocate virtual addresses, and synchronize node list information;
[0127] The node management module is deployed on the central node to maintain the node list of all computing nodes and synchronize it to each computing node regularly;
[0128] The key management module is used to manage the private key fragments, authorized public keys, and shared keys of each computing node, and to execute the Diffie-Hellman key exchange algorithm to generate end-to-end communication keys;
[0129] A communication encryption module, used to calculate a shared key, and encrypt and decrypt communication data between computing nodes based on the shared key to achieve end-to-end encrypted communication;
[0130] The authentication module is used to calculate and verify the public key and verify the self-signature of the computing node based on the SM2 signature algorithm to ensure the legitimacy of the computing node.
[0131] The above is only a preferred embodiment of the present invention. It should be pointed out that a person skilled in the art can make several modifications and improvements without departing from the inventive concept of the present invention, which all belong to the protection scope of the present invention.
Claims
1. A distributed privacy computing network node management method, characterized in that: The following steps are involved: A computing node obtains the first private key fragment, generates a node temporary public key, and sends registration information to the central node, wherein the registration information includes the node temporary public key, the node identity, and the node system parameters; The central node performs registration verification on the received registration information, and after the registration verification is passed, uses the same random number to calculate the authorization public key and the second private key fragment and returns them to the one computing node; The computing node constructs a computing node private key according to the first private key fragment and the second private key fragment, generates a self-signature using the computing node private key, constructs an access authentication request and sends it to the central node; The central node performs signature verification on the received access authentication request, allocates a virtual address to the computing node after the verification is passed, and synchronizes the node list containing all computing nodes; The computing node configures a virtual network according to the allocated virtual address, and connects the central node and other computing nodes through the virtual network; The computing node calculates the shared keys with other computing nodes based on the node list, and uses the shared keys to encrypt data in the communication process; The calculation method of the node temporary public key is: In the formula, is the node's temporary public key, represents the elliptic curve base point, is the first private key fragment, randomly selected from the multiplication group of integers modulo n; The calculation method of the authorization public key is: In the formula, is the authorized public key for calculation, is a random number, randomly selected from the multiplication group of integers modulo n, represents the elliptic curve base point, The node temporary public key sent to the computing node; The method for generating the second private key fragment is: In the formula, is the second private key fragment, is a random number, randomly selected from the multiplication group of integers modulo n, The master public key of the central node The corresponding central node private key, is the identification factor, and its calculation method is: in, represents a hash function, is the node identity of the computing node, is the authorized public key of the computing node, is the system parameter of the computing node, Represents string concatenation operation; The signature verification method is specifically as follows: The central node calculates the verification public key based on the access authentication request data : in, It is the authorized public key calculated by the central node based on the registration information. It is an identification factor, which is obtained through hash operation based on registration information, node system parameters and authorized public key. The private key of the central node The corresponding central node master public key; Use the verification public key to verify the self-signature of the compute node using the compute node private key; The shared key is based on the Diffie-Hellman key exchange algorithm and is generated as follows: In the formula, For computing nodes and compute nodes The shared key between represents a hash function, Indicates characterization operation, Represents a compute node and compute nodes Node identity and Perform an XOR operation, Indicates the splicing calculation node and compute nodes Authorized public key and Perform an XOR operation, For computing nodes The key generated in collaboration with the central node, For computing nodes The key generated in collaboration with the central node, For computing nodes The identification factor, For computing nodes The identification factor, Central node and key The corresponding public key.
2. A distributed privacy computing network node management method according to claim 1, characterized in that: The synchronization data of the node list includes the node identity of the computing node, the authorization public key, the node access timestamp, the node virtual address and the node self-signature.
3. A distributed privacy computing network node management method according to claim 1, characterized in that: The self-signature is signed using the SM2 signature algorithm.
4. A distributed privacy computing network node management method according to claim 1, characterized in that: The computing nodes establish a secure communication channel based on a shared key and encrypt and transmit data, wherein: The computing nodes use a symmetric encryption algorithm to encrypt the communication data and use a shared key as the encryption key; The computing node decrypts the received encrypted data using the shared key.
5. A distributed privacy computing network node management system, characterized in that: The system is used to implement the method according to any one of claims 1 to 4, comprising: The computing node is used to generate a first private key fragment and a node temporary public key, send registration information to the central node, and after receiving the authorization public key and the second private key fragment returned by the central node, calculate the computing node private key, and complete access authentication and end-to-end encrypted communication; The central node is used to receive the registration information of the computing node, perform registration verification, calculate the authorization public key and the second private key fragment and return them to the computing node, perform access authentication, allocate virtual addresses, and synchronize node list information; The node management module is deployed on the central node to maintain the node list of all computing nodes and synchronize it to each computing node regularly; The key management module is used to manage the private key fragments, authorized public keys, and shared keys of each computing node, and to execute the Diffie-Hellman key exchange algorithm to generate end-to-end communication keys; A communication encryption module, used to calculate a shared key, and encrypt and decrypt communication data between computing nodes based on the shared key to achieve end-to-end encrypted communication; The authentication module is used to calculate and verify the public key and verify the self-signature of the computing node based on the SM2 signature algorithm to ensure the legitimacy of the computing node.
Citation Information
Patent Citations
Node authorization method, node communication method and device for privacy computing
CN116015906A
A system and method for designing secure client-server communication protocols based on certificateless public key infrastructure
CN102098157A
Alliance chain privacy protection method and system
CN117521158A
Cited By
Non-anonymized privacy preserving global and local anomaly detection in distributed systems
US12495055B2
Non-anonymized privacy preserving global and local anomaly detection in distributed systems
US20240291838A1