Distributed anonymous transaction method for realizing joint supervision

By adopting a distributed anonymous transaction method with joint supervision in blockchain technology, using the two-layer certificate mechanism and Shamir threshold secret sharing algorithm, the problems of centralized power, single point of failure and the easy target of supervisors in the existing technology are solved, and a more efficient, secure and transparent regulatory system is achieved.

CN119941253AActive Publication Date: 2025-05-06NANJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202411963401.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-06
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

Existing blockchain technology has challenges in protecting user privacy and strengthening regulation, including excessive concentration of power, single point of failure and the issue of possible targets of regulators.

Method used

A distributed anonymous transaction method that realizes joint supervision is adopted. By generating signed public-private key pairs and supervised public-private key pairs, combining the two-layer certificate mechanism and Shamir threshold secret sharing algorithm, it decentralizes regulatory power and ensures that only the joint action of regulators who reach the threshold value can restore user identity.

Benefits of technology

Effectively prevent abuse of power, enhance the fairness and transparency of the system, reduce the risk of single point failure, improve regulatory efficiency, and reduce the risk of system attack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119941253A_ABST
    Figure CN119941253A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed anonymous transaction method for realizing joint supervision, and the method specifically comprises the steps: carrying out the initialization of a system: generating a signature and supervision public and private keys for a supervisor, enabling the signature public key and the supervision public key to be public, dividing the supervision private key into a plurality of shares, and transmitting the shares to the corresponding supervisor; the user performs identity authentication: the user generates a long-term public key, uses the real identity and the long-term public key to register to the supervisor to obtain a long-term certificate, uses the long-term public key to generate an anonymous public key, and uses the anonymous public key to apply for an anonymous certificate from the supervisor; transaction: the transaction sender generates a transaction by using the anonymous public keys of the two transaction parties, and sends the transaction to the verification node; and verification: verifying the validity of the transaction after the verification node receives the transaction, and packaging the transaction passing the verification out of a block for uplink. The method enhances the anonymity of the user in the transaction process, avoids the limitation that a supervisor must verify, effectively disperses the supervision authority, and prevents the centralization and abuse of the authority.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of blockchain, and in particular relates to a distributed anonymous transaction method for realizing joint supervision. Background Art

[0002] Since its conception, blockchain technology has attracted extensive attention and in-depth research from academia and industry due to its core characteristics of decentralization, immutability, and high transparency. As a prominent application of blockchain technology, cryptocurrency has spawned a large and continuously expanding market. However, it faces many challenges in protecting user privacy and strengthening supervision.

[0003] First, many current schemes implement supervision through a single trusted third party, which leads to excessive concentration of power. In the absence of effective constraints and supervision mechanisms, regulators may wantonly infringe on users' privacy rights and access users' private information without authorization, thereby causing the risk of data abuse and leakage. DAPCR has designed a mechanism for allocating regulatory authority, splitting the authority and granting it to two independent entities. This design effectively reduces the risk of abuse of power because no entity can decode the transaction content alone to access transaction privacy. However, this regulatory model still has the problem of single point failure. Once one of the entities fails, the entire regulatory function will not function properly.

[0004] Secondly, some anonymous schemes put forward additional requirements for regulators to perform regulatory duties at the same time. When verifying the validity of the user's identity, the verifier needs to recover the long-term public key from the user's anonymous public key and determine the validity of the user's identity through the validity of the long-term public key. Only the regulator has the right to recover the user's long-term public key, so the regulator needs to act as a verifier to complete the verification work. However, this setting may cause the regulator to ignore its regulatory responsibilities in order to quickly obtain block rewards, thereby reducing the efficiency of monitoring and verifying transactions. More seriously, the regulator as a regulator may become the focus of attackers because they control the verification of transactions and the generation of blocks. This will make the system more vulnerable to targeted attacks such as witch attacks and bribery attacks, thereby further exacerbating the security risks of the system. Therefore, how to design an efficient and secure regulated cryptocurrency system has become a technical problem that needs to be solved urgently. Summary of the invention

[0005] Purpose of the invention: In order to solve the problems existing in the above-mentioned prior art, the present invention provides a distributed anonymous transaction method for realizing joint supervision.

[0006] Technical solution: The present invention discloses a distributed anonymous transaction method for realizing joint supervision, specifically:

[0007] Initialization: Randomly select an elliptic curve, obtain the generator P of the elliptic curve and the order q of the elliptic curve;

[0008] Generate a signature public-private key pair (K s ,k s ) and supervise the public-private key pair (K R ,k R );K s is the signature public key, k s is the signature private key, K R To supervise the public key, k R To supervise the private key; the signature public key and the supervision public key are made public, and the signature private key k s Sent to each regulator through a secure channel; split the regulatory private key into n private key shares s i , and sent to the corresponding regulator, i = 1, 2, ..., n; n is the total number of regulators;

[0009] User identity registration: Before a user enters the system, a long-term public-private key pair (K, k) is generated for the user, where K is the long-term public key and k is the long-term private key. The supervisor applies for a long-term certificate for the user based on the user's ID and long-term public key, and puts it into the long-term certificate sequence.

[0010] Identity verification before transaction: Based on (K, k) and K R Generate an anonymous public key AK for the user. The user sends the anonymous public key AK to the regulator. The regulator authenticates the user's identity through the anonymous public key AK. If the authentication is successful, the regulator uses the signature private key to generate an anonymous certificate for the anonymous public key AK.

[0011] Transaction authentication: The initiator of the transaction uses his own anonymous public key and the anonymous public key of the recipient of the transaction to generate a transaction tx, puts the anonymous certificate of AK into the transaction tx, and sends the transaction tx to the verification node; after receiving the transaction, the verification node verifies the validity of the transaction, and if the verification passes, the transaction is packaged into a block and put on the chain.

[0012] Furthermore, the relationship between the supervisory public key and the supervisory private key is: K R =k R P, the relationship between the public key K and the private key k during the user registration phase is: K=kP.

[0013] Furthermore, in step 1, the Shamir threshold secret sharing algorithm is used to divide the supervisory private key into n private key shares s i Specifically: set the threshold value t, select t-1 random numbers in the finite field GF(q), a1, a2, a3, …, a t-1 ; Then generate the i-th private key share s according to the following formula i :

[0014] s i =(i,y i )

[0015] Among them, y i =k R +a1i+a2i 2 +…+a t-1 i t-1 (mod q).

[0016] Furthermore, the supervisor authenticates the user's identity through the anonymous public key AK as follows:

[0017] Step 1: Randomly select w supervisors, and randomly select a supervisor from the w supervisors, denoted as supervisor R main , regulator R main Determine whether the user's long-term certificate is in the long-term certificate sequence. If so, go to step 2 to continue authentication. Otherwise, terminate authentication.

[0018] Step 2: Each supervisor calculates the verification code u i’ :

[0019]

[0020] Where i' is the i'th regulator among w regulators, i'=1,2,…,w, j represents the jth regulator among w regulators, B1 is an element in AK, B1=bK, b is a random number selected in the finite field GF(q);

[0021] Step 3: w supervisors send their own verification code u i’ Send to the supervisor R main , regulator R main Calculate the user's long-term public key K': K'=B2-∑u i’ ; Determine whether K' is equal to K. If they are equal, the authentication is successful, otherwise the authentication is terminated. B2 is an element in AK, B2 = bkK R +K.

[0022] Furthermore, the method also includes tracking user identities. When regulator A discovers that a user has engaged in malicious trading behavior, the regulator broadcasts the behavior to other regulators. When t regulators all determine that the user has engaged in malicious behavior, the t regulators calculate the corresponding verification code according to step 2 and send the verification code to regulator A. Supervisor A calculates the user's long-term public key, then adds the user's long-term public key and ID to the blacklist, revokes the user's permissions, and sets the status of all certificates of the user to invalid.

[0023] Furthermore, in the identity authentication before the transaction, the anonymous public key AK is generated according to the following formula:

[0024] AK=(B1,B2)

[0025] Among them, B1=bK, B2=bkK R +K, b is a random number selected in the finite field GF(q).

[0026] Furthermore, when the supervisor generates a long-term certificate for the user during the user identity registration phase, it is necessary to determine whether the user is on the blacklist based on the user's public key and ID. If the user is on the blacklist, the user's registration is terminated.

[0027] Furthermore, transaction authentication is the verification of the validity of a transaction, including the verification of the initiator of the transaction and the verification of the transaction itself;

[0028] The verification of the initiator of the transaction is specifically as follows: the verification node obtains the anonymous certificate in the transaction, and uses the signature public key to verify the signature private key on the anonymous certificate.

[0029] Beneficial effects:

[0030] Efficient verification: The dual-layer certificate mechanism adopted by this invention greatly simplifies the verification process of the legitimacy of user identity. Compared with traditional solutions, it does not require the participation of regulators, thereby improving regulatory efficiency and reducing the risk of system attacks. It also avoids the problem of regulators neglecting their regulatory responsibilities in order to quickly obtain block rewards.

[0031] Joint supervision: This invention disperses supervision power through secret sharing algorithm, ensuring that only joint action by supervisors who reach the threshold value can restore the user's identity, effectively preventing abuse of power and enhancing the fairness and transparency of the system.

[0032] Prevent single point failure: By dividing the regulator's private key, even if some nodes fail, as long as the number of normal nodes exceeds the threshold, the system can still perform regulatory tasks normally, ensuring the stability and reliability of the system and ensuring that the real identity of malicious users can be restored and punished accordingly. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 is a flow chart of the present invention;

[0034] Figure 2 It is a schematic diagram of the double-layer certificate mechanism in the present invention;

[0035] Figure 3 It is a schematic diagram of the joint supervision mechanism in the present invention. DETAILED DESCRIPTION

[0036] The accompanying drawings, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0037] like Figure 1 As shown, the present invention is specifically:

[0038] The system is initialized:

[0039] A trusted third party randomly selects an elliptic curve for the regulator, P is the generator of the elliptic curve, and q is the order of the elliptic curve;

[0040] A trusted third party generates and distributes signature public-private key pairs and supervises public-private key pairs.

[0041] Generating and distributing signature public-private key pairs for regulators includes: Randomly generating signature public-private key pairs (K s ,k s ), the signature public key K s Make it public and make the signature private key k s Sent to each regulator via a trusted channel;

[0042] Generating and distributing regulatory public-private key pairs for regulators includes: Randomly generating regulatory public-private key pairs (K R ,k R ), where K R =k R P, will supervise the public key K R The Shamir threshold secret sharing algorithm is used to split the supervisory private key into n shares equal to the total number of supervisors, thereby dispersing the power of the supervisors. Specifically:

[0043] Set the threshold value to t, and select t-1 random numbers a1, a2, a3, …, a in the finite field GF(q). t-1 , construct the following inequality:

[0044] f(x)=k R +a1x+a2x 2 +…+a t-1 x t-1 (mod q)

[0045] The set of regulators is represented as {R1,R2,…,R n}, calculate y i =f(i),s i =(i,y i )(i∈n), the private key share s i Sent to the supervisor R i save.

[0046] Identity Authentication:

[0047] Before entering the system, users need to generate a long-term public-private key pair (K, k), where K represents the long-term public key and k represents the long-term private key; where K = kP; and send K and the real identity information ID to the regulator for registration.

[0048] After receiving the user's registration application, the supervisor checks whether the user's K and ID are in the blacklist. If not, the supervisor will approve the application, generate a long-term certificate for the user, and send the long-term certificate to the user, indicating that the user has obtained permission to enter the system. The supervisor will put the long-term certificate into the long-term certificate sequence.

[0049] like Figure 2 As shown, before a user wants to make a transaction, he needs to pass the registered long-term public key K and the regulator's public key K R Generate anonymous public key AK with random number. The same K can generate multiple AKs:

[0050] AK=(B1,B2)

[0051] Among them, B1=bK, B2=bkK R +K; b represents a random number selected in the finite field GF(q).

[0052] The user sends AK to the regulator to apply for an anonymous certificate, specifically:

[0053] like Figure 3 As shown, w supervisors are randomly selected, and one supervisor is randomly selected from the w supervisors, denoted as supervisor R main , regulator R main Determine whether the user's long-term certificate is in the long-term certificate sequence. If not, terminate the authentication. Otherwise, continue the authentication. w supervisors calculate their own verification codes respectively. Among them, i' is the i'th regulator among w regulators, i'=1,2,…,w, j represents the jth regulator among w regulators; w regulators will calculate u i’ Send to R main . R main Calculate B2-∑u i =B2-k R B1 = K', the regulators determine whether K' is equal to K. If they are equal, the anonymous public key is indeed generated by K, and the verification is successful. Then the regulator uses the signature private key to generate an anonymous certificate for the anonymous public key AK.

[0054] trade:

[0055] The user uses the anonymous public key generated during the identity authentication phase to conduct transactions. The initiator of the transaction asks the recipient of the transaction for his anonymous public key.

[0056] The transaction initiator uses the anonymous public keys of both parties to generate the transaction tx. The transaction initiator puts its own anonymous certificate into the transaction. Then the transaction is sent to the verification node.

[0057] Verifying transactions

[0058] After receiving a transaction from a user, the verification node needs to verify the validity of the transaction, which is specifically divided into verifying the legitimacy of the user's identity in the transaction and verifying the validity of the transaction itself.

[0059] First, the legitimacy of the user's identity needs to be verified. The verification node obtains the anonymous certificate in the transaction and uses the signature public key to verify the validity of the certificate (the signature private key in the anonymous certificate is verified by the signature public key). If the verification passes, the validity of the transaction itself is verified, otherwise the transaction is discarded.

[0060] Next, the validity of the transaction itself is verified to check whether the transaction is generated correctly. The validity verification includes verifying the format of the transaction and whether the account balance of the transaction initiator is sufficient.

[0061] Verified transactions will be packaged into blocks, and multiple regulators will conduct PBFT consensus before being uploaded to the chain.

[0062] Tracking user identity

[0063] When regulator A in the blockchain finds that a user (the initiator of the transaction) has malicious behavior (the malicious behavior is artificially preset, such as a large transaction within a specified time, or a large amount of money is divided into small amounts and sent to the transaction recipient in a short period of time), the regulator broadcasts the malicious behavior to other regulators; other regulators verify the illegal behavior of the malicious user; when more than the threshold value t regulators have verified that the user has indeed engaged in malicious behavior, these regulators will use their respective supervisory private key shares to jointly restore the user's true identity. Specifically: The regulators participating in the joint supervision calculate their own verification code u i’ , and sends the verification code to regulator A. Supervisor A recovers the user's long-term public key, adds the malicious user's long-term public key K and ID to the blacklist, revokes the user's permissions, and sets the status of all certificates of the user to invalid.

[0064] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, the present invention will not further describe various possible combinations.

Claims

1. A distributed anonymous transaction method for realizing joint supervision, characterized in that: Specifically: Initialization: Randomly select an elliptic curve, obtain the generator P of the elliptic curve and the order q of the elliptic curve; Generate a signature public-private key pair (K s , k s ) and supervise the public-private key pair (K R , k R );K s is the signature public key, k s is the signature private key, K R To supervise the public key, k R To supervise the private key; the signature public key and the supervision public key are made public, and the signature private key k s Sent to each regulator through a secure channel; split the regulatory private key into n private key shares s i , and sent to the corresponding regulator, i = 1, 2, ..., n; n is the total number of regulators; User identity registration: Before a user enters the system, a long-term public-private key pair (K, k) is generated for the user, where K is the long-term public key and k is the long-term private key. The supervisor applies for a long-term certificate for the user based on the user's ID and long-term public key, and puts it into the long-term certificate sequence. Identity verification before transaction: According to (K, k) and K R Generate an anonymous public key AK for the user. The user sends the anonymous public key AK to the regulator. The regulator authenticates the user's identity through the anonymous public key AK. If the authentication is successful, the regulator uses the signature private key to generate an anonymous certificate for the anonymous public key AK. Transaction authentication: The initiator of the transaction uses his own anonymous public key and the anonymous public key of the recipient of the transaction to generate a transaction tx, puts the anonymous certificate of AK into the transaction tx, and sends the transaction tx to the verification node; after receiving the transaction, the verification node verifies the validity of the transaction, and if the verification passes, the transaction is packaged into a block and put on the chain.

2. A distributed anonymous transaction method for realizing joint supervision according to claim 1, characterized in that: The relationship between the supervisory public key and the supervisory private key is: K R =k R P, the relationship between the public key K and the private key k during the user registration phase is: K=kP.

3. A distributed anonymous transaction method for realizing joint supervision according to claim 1, characterized in that: In step 1, the Shamir threshold secret sharing algorithm is used to divide the supervisory private key into n private key shares s i Specifically: set the threshold value t, select t-1 random numbers in the finite field GF(q), a1, a2, a3, ..., a t-1 ; Then generate the i-th private key share s according to the following formula i : s i =(i,y i ) Among them, y i =k R +a1i+a2i 2 +…+a t-1 i t-1 (mod q).

4. A distributed anonymous transaction method for realizing joint supervision according to claim 3, characterized in that: The regulator authenticates the user's identity through the anonymous public key AK as follows: Step 1: Randomly select w supervisors, and randomly select a supervisor from the w supervisors, denoted as supervisor R main , regulator R main Determine whether the user's long-term certificate is in the long-term certificate sequence. If so, go to step 2 to continue authentication. Otherwise, terminate authentication. Step 2: Each supervisor calculates the verification code u i’ : Where i' is the i'th regulator among w regulators, i'=1,2,...,w,j represents the jth regulator among w regulators, B1 is an element in AK, B1=bK, b is a random number selected in the finite field GF(q); Step 3: w supervisors send their own verification code u i’ Send to the supervisor R main , regulator R main Calculate the user's long-term public key K': K'=B2-∑u i’ ; Determine whether K is equal to K. If they are equal, the authentication is successful, otherwise the authentication is terminated. B2 is an element in AK, B2 = bkK R +K.

5. A distributed anonymous transaction method for realizing joint supervision according to claim 4, characterized in that: The method also includes tracking user identities. When regulator A discovers that a user has engaged in malicious trading behavior, the regulator broadcasts the behavior to other regulators. When t regulators all determine that the user has engaged in malicious behavior, the t regulators calculate the corresponding verification code according to step 2 and send the verification code to regulator A. Supervisor A calculates the user's long-term public key, then adds the user's long-term public key and ID to the blacklist, revokes the user's permissions, and sets the status of all certificates of the user to invalid.

6. A distributed anonymous transaction method for realizing joint supervision according to claim 1, characterized in that: In the identity authentication before the transaction, the anonymous public key AK is generated according to the following formula: AK=(B1,B2) Among them, B1=bK, B2=bkK R +K, b is a random number selected in the finite field GF(q).

7. A distributed anonymous transaction method for realizing joint supervision according to claim 1, characterized in that: During the user identity registration phase, when the regulator generates a long-term certificate for the user, it is necessary to determine whether the user is on the blacklist based on the user's public key and ID. If the user is on the blacklist, the user's registration will be terminated.

8. A distributed anonymous transaction method for realizing joint supervision according to claim 1, characterized in that ,Transaction authentication is ,the verification of the validity of a transaction, including the verification of the initiator of the transaction and the verification of the transaction itself; The verification of the initiator of the transaction is specifically as follows: the verification node obtains the anonymous certificate in the transaction, and uses the signature public key to verify the signature private key on the anonymous certificate.

Citation Information

Patent Citations

  • Distributed authoritative node block chain system with (n,t) threshold and authentication method thereof

    CN110851859A

  • Blockchain key management method, multi-person common signature method and electronic device

    CN111639361A

  • Supervisable member identity (validity period) anonymous authentication method

    CN116723031A

  • Block chain privacy protection method, electronic equipment and storage medium

    CN117040769A

  • Method for realizing distributed digital certificate, computer equipment and storage medium

    CN117118633A