Distributed key management method suitable for government affair block chain network and application
By deploying smart contracts in the government blockchain network, using key polynomial encoding and data fragment storage, the security risks and complexity of traditional key management in the government blockchain network are solved, and secure, reliable and flexible key management is achieved.
Patent Information
- Application Number
- CN202510122802.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-01-26
AI Technical Summary
Traditional key distribution centers are difficult to adapt to the characteristics of government blockchain networks. Government blockchain network nodes have serious security risks for key management, and user characteristics and cross-chain scenarios increase the complexity of key management.
By deploying smart contracts in the government blockchain network, key polynomial encoding and data fragment storage, security management and access control of keys are achieved. The method includes key generation, encoding, storage and reconstruction, supporting fault tolerance and accuracy repair.
It realizes the secure, reliable and flexible management of keys in the government blockchain network, reduces the risk of key leakage, adapts to the permission requirements of users at different levels, and supports cross-chain application scenarios.
Smart Images

Figure CN119966619A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of distributed key management technology, and in particular to a distributed key management method applicable to a government blockchain network. Background Art
[0002] With the continuous development of government blockchain networks, traditional key security management methods can no longer meet the needs of government blockchain networks. Specifically, the following situations exist:
[0003] One of the situations is that the traditional Key Distribution Center (KDC) is difficult to adapt to the characteristics of the government blockchain network. This is because the traditional KDC needs to establish an authoritative key distribution agency that all parties trust. When the parties need to communicate securely, the KDC distributes keys to the parties through a "secure channel" so that the parties can communicate securely and encrypted.
[0004] However, the government blockchain network has the characteristics of decentralization, distributed storage, no central hardware and authority, equal rights and responsibilities of all nodes, and data in the government blockchain network is maintained by all nodes. In the government blockchain network environment, it is impossible to establish an authoritative KDC agency node, and there is no so-called "secure channel". Therefore, the traditional key distribution center's key management method can no longer meet the actual needs of the government blockchain, and it is necessary to study the key management method that meets the government blockchain network point.
[0005] The second situation is that most government blockchain network nodes currently have serious security risks in the management of keys. For example, most government blockchain nodes use private keys for digital signatures or keys for encrypted transmission, which are stored in plain text in configuration files. In the event of system errors, human operation errors, hacker attacks, etc., these private keys and keys are likely to be leaked, thus affecting the security of the entire government blockchain network. Although some network nodes use encryption to encrypt the keys used before storing them, how to manage the keys used for encryption is still a difficult problem to solve.
[0006] The third situation is that the user characteristics of the government blockchain network have brought new challenges to key management. The users in the government blockchain network are often government departments rather than individuals, and there is often a hierarchical relationship between superiors and subordinates within the organization formed by government departments. The importance of the organizational hierarchy is different, and users at different levels in the organization have different permissions to use the keys owned by the organization. For example, some keys can be used by one user alone, while some keys require two users to use them together, and so on. In addition, organizations often need to manage and use multiple keys at the same time instead of just one key, and each key has its own usage permissions and requirements. These new requirements have brought unprecedented challenges to the key management of the government blockchain network.
[0007] The fourth situation is that the cross-chain scenario in the government blockchain network makes key management very important. There are often homogeneous and heterogeneous architecture designs in the government blockchain network. Different government blockchain networks need to be connected and communicated with each other, and it is even more necessary to solve the differences in consensus mechanisms between different government blockchain networks to ensure data consistency and reliability.
[0008] In order to realize the communication and interaction of different heterogeneous government blockchains, it is very important to establish a verifiable distributed key management mechanism that can adapt to different heterogeneous chains to enable secure and reliable communication and interaction.
[0009] Based on this, the present invention provides a distributed key management method and application suitable for government blockchain networks to solve the problem of how to securely manage keys in government blockchain network scenarios, which is a technical problem that needs to be solved urgently. Summary of the invention
[0010] The purpose of the present invention is to overcome the shortcomings of the prior art and provide a distributed key management method and application suitable for a government blockchain network. The present invention can deploy smart contracts in a government blockchain network and securely manage the distributed keys in the government blockchain network through smart contracts.
[0011] In order to solve the existing technical problems, the present invention provides the following technical solutions:
[0012] A distributed key management method applicable to a government blockchain network, deploying at least one smart contract into the government blockchain network, and managing the distributed keys in the government blockchain network through the smart contract, wherein the management performs access control management and digital identity management on the data fragments obtained after key encoding according to preset key usage permissions.
[0013] Further, the method comprises the steps of:
[0014] Obtain at least one key and process it; the processing includes constructing at least one key polynomial P(X) for at least one key, and storing at least one data fragment obtained by the aforementioned key polynomial P(X) in a node of the government blockchain network; wherein, before obtaining the key, it also includes a key generation step S110, as follows: S111, using a random number generator or a pseudo-random number generator to generate k keys key0,...,key k-1 , where k is an integer greater than 1; S112, when the k keys have different lengths, select an integer h = max(log2(key0), ..., log2(key k-1 )) is the bit length of the longest key among the k keys; S113, select a secure prime number p whose bit length is greater than or equal to h to construct a finite field So that the finite field There are p different elements in total And the length of each element is bits; S114, mapping k keys key0, ..., key k-1 For a finite field The last k distinct elements
[0015] Obtain data fragments from the government blockchain network based on preset key usage permissions;
[0016] When the number of obtained data fragments is greater than or equal to the minimum threshold value allowing reconstruction of the key, determining whether the key needs to be reconstructed; wherein, determining whether the aforementioned collected data fragments may have errors based on whether the source of the collected data fragments is credible;
[0017] When there are no errors in the collected data segments, an error-free reconstruction step is performed to obtain a correct key; when at least one of the collected data segments may have errors, a fault-tolerant reconstruction step is performed; wherein, when the number of erroneous data segments is less than or equal to a preset number, the fault-tolerant reconstruction step can locate the erroneous data segments while reconstructing the correct key;
[0018] For the data segment in which an error occurs, an error handling step is performed according to the preset key repair requirements; when executing the error handling step, choose to execute the accuracy repair step or the functional repair step to complete the key reconstruction; wherein, the data segment repaired by the aforementioned accuracy repair step is exactly the same as the original data segment, and the corresponding function and data segment value are the same; the data segment value repaired by the said functional repair step is different from the original data segment value, but the implemented function is the same.
[0019] Furthermore, the parameters configured in the method include:
[0020] The number of data fragments n, the minimum number of reconstructed fragments k and the secure strong prime number p, the maximum number of erroneous data fragments allowed in n data fragments is e;
[0021] The above parameters are all positive integers and satisfy 1≤k≤n≤p-1 and Alternatively, 1≤k≤n≤p-1 and n=k+2e are satisfied at the same time; wherein the strong prime number p can select a safe prime number whose bit length is greater than or equal to h.
[0022] Furthermore, after step S110 and before obtaining the key, a key encoding step S120 is also included, as follows:
[0023] S121, construct at least one k-1 order key polynomial according to the number of keys k to be managed The coefficients of the key polynomial P(X) are the aforementioned finite field elements Right now Among them, the Representing a finite field The set of all key polynomials P(X) on ;
[0024] S122, Select finite field The last n distinct non-zero elements As an independent variable, and calculate P(a i ), i∈[n], and get n key-value pairs As the encoded n data fragments.
[0025] Further, determining whether the key needs to be reconstructed includes executing a reconstruction condition determination step S130 as follows:
[0026] S131, counting the number of data segments obtained;
[0027] S132, when the number of acquired data segments is greater than or equal to the minimum number of reconstructed segments k, determining whether the aforementioned collected data segments may have errors;
[0028] S133, when the judgment is no, execute the error-free reconstruction step; otherwise, execute the fault-tolerant reconstruction step.
[0029] Further, the error-free reconstruction step S140 includes:
[0030] S141, for the obtained n error-free data segments In the definition of y i =P(α i ), i∈[n] represents all the acquired data segments, and k data segments are randomly selected as input to the error-free reconstruction step;
[0031] S142, construct k k-1 order polynomials The reconstructed key polynomial is expressed as Among them, the coefficients of the key polynomial P(X) are the reconstructed keys.
[0032] Further, the fault-tolerant reconstruction step S150 includes:
[0033] S151, for all i∈[n] let P(α i )=y i , y=(y1,...,y n ), get n data fragments
[0034] S152, construct an e-order non-zero polynomial L(X) and obtain the error location polynomial When the error location polynomial L(X) satisfies L(α i )=0 if and only if y i ≠P(α i ), among the n data segments collected, the α of all the data segments with errors i ∈{y i ≠P(α i )} are all roots of the error location polynomial L(X);
[0035] S153, assuming that the expansion of the error locator polynomial L(X) is L(X)=b0+b1X 1 +…+b e-1 X e-1 +b e X e , combined with Determine the highest order term X of the above L(X) e The coefficient is b e =1, then determine the remaining e unknown coefficients b0, b1, ..., b in L(X). e-1 , and then determine L(X);
[0036] S154, construct a k+e-1 order non-zero polynomial N(X) that satisfies y i L(α i )=N(α i ), i∈[n], let the coefficients of N(X) be a0, a1, ..., a k+e-1 , then the expanded form of N(X) is expressed as N(X)=a0+a1X 1 +…+a k+e-1 X k+e-1 , by determining the k+e unknown coefficients a0, a1, ..., a of N(X) k+e-1 , and then determine the expansion of N(X);
[0037] S155, due to the equation P(α i )=y i holds for all i∈[n], and when y i ≠P(α i ), i∈[n] when L(α i )=0, so y i L(α i )=L(α i )P(α i ) holds for all i∈[n], that is, N(α i )=L(α i )P(α i ) holds for all i∈[n];
[0038] S156, due to N(α i )=L(α i )P(α i ) holds for all i∈[n], so we establish a system of equations with k+2e equations and k+2e unknowns, and obtain:
[0039]
[0040] Solve the above system of equations to obtain a0, a1, ..., a k+e-1 and b0, b1, ..., b e-1 The value of , thereby determining the non-zero polynomial N(X) and the error location polynomial L(X);
[0041] S157, after determining the aforementioned N(X) and L(X), when Δ(y, (P(α i )) i )≤e, the number of erroneous data fragments is less than or equal to the value e, which can be calculated by Reconstruct the key polynomial P(X) to obtain the key; conversely, Δ(y, (P(α i )) i )>e, the number of erroneous data fragments is greater than the aforementioned value of e, and since P(X) cannot be reconstructed, the key cannot be obtained.
[0042] Further, when executing the aforementioned step S157, an error handling step S160 can also be executed simultaneously; the error handling step S160 includes an error locating step S161 and an error repairing step S162; after executing the error locating step S161 and locating the erroneous data segment, the error repairing step S162 is executed to obtain the correct data segment; wherein, the error repairing step S162 selects to execute the accuracy repairing step S1621 or the functional repairing step S1622 according to the repairing requirements of the aforementioned erroneous data segment; wherein,
[0043] The error location step S161 is configured to: locate the data segment where the error occurs by using the aforementioned error location polynomial L(X), detect the n data segments collected Among them, all α i ∈{L(α i )=0, i∈[n]} are all data fragments with errors;
[0044] The error repair step S162 is configured as follows: the key polynomial reconstructed by the fault-tolerant reconstruction step Calculate the correct value of the data segment; according to the repair requirements of the data segment, perform the accuracy repair step S1621 or the functional repair step S1622 in the above error repair step; wherein,
[0045] The accuracy repair step S1621 refers to the position of the data segment corresponding to the error, that is, α i ∈{L(α i )=0,i∈[n]} restore the original data segment; the functional repair step S1622 refers to selecting an unused data segment position Calculate a new And use the new data segment (α j , P(α j )) replaces the erroneous data fragment; wherein, the data fragment that has undergone the functional repair step is a legitimate data fragment that can be used to reconstruct the key, and the data fragment that has undergone the functional repair step is stored in the node of the government blockchain network.
[0046] A distributed key management system suitable for a government blockchain network, comprising:
[0047] Nodes of the government blockchain network are used to store data fragments obtained after key encoding;
[0048] Smart contracts are used for access control management of key-encoded data fragments and user digital identity management;
[0049] A system server, wherein the system server is connected to a node of the government blockchain network;
[0050] The system server is configured to: deploy at least one smart contract into the government blockchain network, and manage the distributed keys in the government blockchain network through the smart contract, wherein the management performs access control management and digital identity management on the data fragments obtained after the key encoding according to the preset key usage permissions.
[0051] A computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the implementation steps of any of the above methods.
[0052] Based on the above advantages and positive effects, the advantage of the present invention is that it is suitable for the management of keys by hierarchical government departments in the government blockchain network, wherein the keys are encoded and stored in the government blockchain network in the form of data fragments.
[0053] Furthermore, a smart contract is designed and deployed to the aforementioned government blockchain network, and the smart contract code is set corresponding to the steps in the method; and then through the smart contract, access control management and digital identity management are performed on the data fragments obtained after key encoding according to the preset key usage permissions.
[0054] Furthermore, when the total number of legal data fragments obtained is greater than or equal to the minimum number of data fragments k required to reconstruct the key, the key can be reconstructed. And because the key is stored in the blockchain network as data fragments rather than plain text throughout its life cycle, it is possible to achieve "available but invisible" management of multiple keys.
[0055] Furthermore, since the preset key fault-tolerant reconstruction step of the present invention can also locate erroneous data fragments and, according to the preset key repair requirements, perform accurate or functional repair on the erroneous data fragments when executing the key repair step, it has extremely high practicality and robustness in engineering.
[0056] Furthermore, it is implemented by smart contracts across government blockchains, thereby solving the key management and application problems in cross-chain application scenarios in government blockchains. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 A method flow chart provided for an embodiment of the present invention.
[0058] Figure 2 Another method schematic diagram provided for an embodiment of the present invention.
[0059] Figure 3 A schematic diagram of the structure of a system provided in an embodiment of the present invention.
[0060] Description of reference numerals:
[0061] System 200, node 201, smart contract 202, system server 203. DETAILED DESCRIPTION
[0062] The following is a further detailed description of a distributed key management method and application applicable to a government blockchain network disclosed in the present invention in combination with the accompanying drawings and specific embodiments. It should be noted that the technical features or combinations of technical features described in the following embodiments should not be considered isolated, and they can be combined with each other to achieve better technical effects. In the drawings of the following embodiments, the same reference numerals appearing in each drawing represent the same features or components, which can be applied to different embodiments. Therefore, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.
[0063] It should be noted that the structures, proportions, sizes, etc. illustrated in the drawings of this specification are only used to match the contents disclosed in the specification for people familiar with this technology to understand and read, and are not used to limit the limiting conditions for the implementation of the invention. Any modification of the structure, change of the proportion relationship or adjustment of the size should fall within the scope of the technical content disclosed by the invention without affecting the effects and purposes that can be achieved by the invention. The scope of the preferred embodiments of the present invention includes other implementations, in which the functions can be performed in a substantially simultaneous manner or in a reverse order according to the functions involved, which should be understood by those skilled in the art of the technical field to which the embodiments of the present invention belong.
[0064] Techniques, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the techniques, methods, and devices should be considered part of the authorization specification. In all examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not as limiting. Therefore, other examples of the exemplary embodiments may have different values.
[0065] Example
[0066] This embodiment preferably constructs at least one government blockchain network. Specifically, at least one smart contract is deployed in the government blockchain network, and the distributed keys in the government blockchain network are managed by the smart contract, wherein the management performs access control management and digital identity management on the data fragments obtained after the key encoding according to the preset key usage permissions.
[0067] The deployment operation preferably writes smart contract code, so as to deploy at least one smart contract to the aforementioned government blockchain network. In this embodiment, the smart contract code is set corresponding to the steps in the method, that is, all the steps in this embodiment can be implemented by writing smart contract code.
[0068] The government blockchain network refers to the alliance chain formed by government departments through blockchain. Among them, government departments use the government blockchain network to achieve real-time synchronization of business data, digital identity, access control and operation records, ensuring that all node data are consistent and reach consensus.
[0069] At the same time, various government departments convert relevant business agreements into executable smart contract codes and deploy them on the government blockchain network. This enables various government departments to intelligently and automatically perform relevant smart contracts in accordance with pre-set business rules and operating logic, and achieve efficient cross-departmental business collaboration through the government blockchain network.
[0070] In this embodiment, the smart contract deployed in the aforementioned government blockchain network is mainly used to implement identity authentication and access control. Specifically, the identity information of each user in the government blockchain network is stored and verified through smart contracts. Each user in the government blockchain network can set operation permissions to limit the access rights of the access object to access, obtain and use the data held by the access object; and each user in the government blockchain network can manage and control the access rights of the access object to specific resources through smart contracts, such as file storage, digital content, data fragments, etc.
[0071] The users include but are not limited to various government departments, their cooperating departments, and their collaborative departments.
[0072] It is worth noting that in terms of network security and data security, the permission control logic of smart contracts in the government blockchain network should be combined with the data security management of government departments outside the chain. This is because smart contracts stipulate the business logic of permission control and data leakage prevention, so unauthorized access can be strictly rejected.
[0073] As an example, not a limitation, for example: directly opening a local database to browse government blockchain data is strictly prohibited. Government departments should design and implement permissions at the smart contract and interface levels to ensure that data is not leaked in the system corresponding to the aforementioned government blockchain network. The aforementioned government blockchain will not be accessed without authorization at the application layer, display interface, report, log, database and other links, thereby eliminating possible internal operation risks.
[0074] In addition, the operating logic of the smart contract on each node is consistent, so no matter which node the request is sent to, the result obtained is the same.
[0075] See Figure 1 FIG. 1 is a flow chart of a method provided in this embodiment. The implementation step S100 of the method is as follows:
[0076] S101, obtaining at least one key and processing it.
[0077] The processing includes constructing at least one key polynomial P(X) for at least one key, and storing at least one data fragment obtained by the aforementioned key polynomial P(X) in a node of the government blockchain network.
[0078] Among them, because the keys are stored in the government blockchain network in the form of data fragments rather than plain text, it is possible to achieve "available but invisible" for multiple keys, which has excellent practicality and robustness in engineering practice.
[0079] S102, obtaining data fragments from the government blockchain network according to preset key usage permissions.
[0080] S103, when the number of obtained data fragments is greater than or equal to the minimum threshold value allowing reconstruction of the key, determine whether the key needs to be reconstructed; wherein, based on whether the source of the collected data fragments is credible, determine whether the aforementioned collected data fragments may have errors.
[0081] S104, when there are no errors in the collected data segments, an error-free reconstruction step S140 is performed to obtain the correct key; when at least one of the collected data segments may have errors, a fault-tolerant reconstruction step S150 is performed. When the number of erroneous data segments is less than or equal to a preset number, the fault-tolerant reconstruction step S150 can locate the erroneous data segments while reconstructing the correct key.
[0082] S105, for the data segment with errors, according to the preset key repair requirements, execute the error handling step S160; when executing the error handling step S160, choose to execute the accuracy repair step S1621 or the functional repair step S1622 to complete the key reconstruction. Among them, the data segment repaired by the aforementioned accuracy repair step S1621 is completely the same as the original data segment, and the corresponding function and data segment value are the same; the data segment value repaired by the said functional repair step S1622 is different from the original data segment value, but the function achieved is the same.
[0083] By way of example and not limitation, see Figure 2As shown in FIG. 1 , a schematic diagram of a method provided by this embodiment is provided. Assume that there are s keys to be managed in an organization formed by various government departments. The organization groups the s keys according to the government departments' rights to use the keys, and establishes a key polynomial for each group for management. Therefore, it is divided into t key polynomials P i (X), i∈{1, 2,...,t}.
[0084] Taking one of the key polynomials P1(X) as an example, the key polynomial P1(X) can be used to manage three keys, which means that the organization's management requirements for the three keys are the same, and also means that the minimum number of data fragments required to reconstruct the key polynomial P1(X) is at least three.
[0085] This embodiment preferably uses Figure 2 For example, the key polynomial P1(X) in the example is used to show the whole process of key management. In order to show the generality, the key polynomial P1(X) is represented by P(X), and the minimum number of reconstruction fragments k i Indicated by k.
[0086] Since each key polynomial P(X) of degree k-1 can manage at least k keys, taking any key polynomial P(X) as an example, before obtaining the key, a key generation step S110 is also included.
[0087] The key generation step S110 includes:
[0088] S111, use a random number generator or a pseudo-random number generator to generate k keys kty0, ..., key k-1 , where k is an integer greater than 1.
[0089] The key is preferably displayed in PKCS#1 format or PKCS#8 format. The key generation step supports the use of mainstream public key encryption algorithms and symmetric encryption algorithms in the prior art, including but not limited to national secret algorithms, elliptic curve encryption algorithms, RSA algorithms, etc.
[0090] In this embodiment, it is assumed that the organization generates three random keys in the key generation step, whose binary representations are "1111011", "11101010" and "101011001", and the three keys need to be managed.
[0091] S112, when the k keys have different lengths, select an integer h = max(log2(key0), ..., log2(key k-1 )) is the bit length of the longest key among the k keys.
[0092] In this embodiment, among the three randomly generated keys, the bit length of the longest key is 9 bits, that is, h = 9. In practical applications, ensure that h is an integer multiple of 8, and if it is less than 8, add 0 to fill the position.
[0093] S113, select a secure prime number p with a bit length greater than or equal to h to construct a finite field So that the finite field There are p different elements in total And the length of each element is Bit.
[0094] For the convenience of explanation, in this embodiment, a prime number p=997 with a length of 10 bits is selected to construct a finite field Then the finite field There are 997 unique elements on Then the length of each element is 10 bits; in practical applications, strong prime numbers are often used to enhance the security of the system, such as p = 2 128 +12451.
[0095] S114, mapping k keys key0, ..., key k-1 For a finite field The last k distinct elements
[0096] Using finite field elements m0, ..., m k-1 As polynomial coefficients, construct a finite field The k-1 order key polynomial P(X) on is called the key polynomial or coding polynomial.
[0097] In this embodiment, the original keys "1111011", "11101010" and "101011001" are mapped to the finite field The elements on are m0=123, m1=234 and m2=345 respectively.
[0098] Preferably, the parameters configured by the method described in this embodiment include: the number of encoded data segments n, the minimum number of reconstructed segments k and a secure strong prime number p, and the maximum number of erroneous data segments e allowed in the n data segments.
[0099] The above parameters are all positive integers and satisfy 1≤k≤n≤p-1 and Alternatively, 1≤k≤n≤p-1 and n=k+2e are satisfied at the same time; wherein the strong prime number p can select a safe prime number whose bit length is greater than or equal to h.
[0100] In this embodiment, integers k=3, n=5, and e=1 are selected to satisfy 5=3+2*1, which means that 3 original keys are encoded into 5 data fragments, of which at most 1 data fragment is allowed to have an error. That is to say, when 1 of the 5 data fragments has an error, the fault-tolerant reconstruction step can still reconstruct the correct key and locate the data fragment with the error.
[0101] Preferably, after step S110 and before obtaining the key, a key encoding step S120 is further included. The key encoding step S120 includes:
[0102] S121, construct at least one k-1 order key polynomial according to the number of keys k to be managed The coefficients of the key polynomial P(X) are the aforementioned finite field elements Right now Among them, the Representing a finite field The set of all key polynomials P(X) on .
[0103] It is worth emphasizing that in this embodiment, the number k of keys managed by the organization as needed is the minimum number k of reconstruction fragments configured in the corresponding method of this embodiment, so as to ensure that k keys can be managed.
[0104] In this embodiment, the aforementioned organization can construct one or more key polynomials according to the number of keys to be managed. As an example, since three keys need to be managed, a second-order coding polynomial is constructed, that is, At the same time, taking m0=123, m1=234 and m2=345 as the coefficients of the polynomial P(X), we get P(X)=123+234X+345X 2 (mod997).
[0105] S122, Select finite field The last n distinct non-zero elements As an independent variable, and calculate P(α i ), i∈[n], and get n key-value pairs As the encoded n data fragments.
[0106] In this embodiment, a finite field is selected The five different non-zero elements above are selected because we want to locate the data segment where the error occurs. This is to facilitate the location of the data segment where the error occurs, and there is no mandatory requirement for the selection of non-zero elements.
[0107] As an example and not a limitation, for example, the calculation process of the key encoding is as follows:
[0108]
[0109] Correspondingly, five data fragments are obtained: [1,702], [2,974], [3,939], [4,597], and [5,945]. These data fragments are stored in the nodes of the government blockchain network, and permission groups are established through smart contracts to manage and control the access rights of the data fragments. Figure 2 As shown, see Figure 2 The arrows of the data segments in the figure point to the access rights of the data segments to which the access rights are assigned via the permission groups.
[0110] As one of the preferred implementations of this embodiment, dynamic authorization of plug-ins is implemented through smart contracts to meet the need to manage and control access rights to data fragments by establishing permission groups. Dynamic authorization of plug-ins can improve the flexibility and security of the system while reducing maintenance costs. The specific implementation method is to implement plug-in authorization through predefined permission rules and conditions. When a user calls a plug-in, the smart contract will determine whether to allow the execution of the plug-in based on the current user's permission status and the authorization rules of the plug-in.
[0111] Compared with the traditional static authorization method, this authorization method has higher flexibility and can be adjusted dynamically according to actual needs. The flexibility of this authorization method is very important for the government blockchain network. This is because the users in the government blockchain network are often government departments rather than individuals, and the organizations formed by government departments often have hierarchical relationships between superiors and subordinates. The importance of organizational levels is different, and users at different levels in the organization have different permissions to use the keys owned by the organization. For example, some keys can be used by one user alone, while some keys require two users to use them together, etc. In addition, organizations often need to manage and use multiple keys at the same time instead of just one key, and each key has its own usage permissions and requirements, etc.
[0112] Establishing a permission group is one of the predefined permission rules and conditions for plug-in authorization, which has extremely high flexibility. By establishing a permission group, you can decide which government departments in the organization can obtain how many data fragments, and then realize the management of different keys of the organization. For example: a certain key is encoded into 3 data fragments, and two permission groups can be established. Users who join one of the permission groups can obtain 3 data fragments. For example, the administrator of the organization can obtain 3 data fragments by joining the permission group, so the administrator can reconstruct and use the key alone; at the same time, establish another permission group, and users in the group can only obtain 2 data fragments at most. For example, ordinary users in the organization except administrators can join the permission group, because the number of data fragments obtained by every 2 ordinary users exceeds 3, so the management requirement that only two users can use the key together can be realized.
[0113] In addition, the immutability of smart contracts ensures the security of authorization information. With the continuous development of government blockchain technology, the smart contract plug-in authorization mechanism can also be applied to scenarios such as digital identity authentication and data sharing. The existing technology applies artificial intelligence and machine learning technology to smart contract plug-in authorization to achieve more intelligent and automated authorization management, which helps to improve system performance and user experience. Among them, the application of artificial intelligence and machine learning technology to smart contract plug-in authorization is an existing technology, so I will not go into details here.
[0114] It is also worth noting that the data fragments can also be selected to be stored in the government blockchain network according to the organization's key management requirements, and some data fragments are stored off-chain and managed by a dedicated person. Among them, the relevant information of the data fragments stored in the government blockchain (such as creation time, validity period, usage status, etc.) is automatically managed by the aforementioned smart contract.
[0115] Preferably, determining whether the key needs to be reconstructed includes executing a reconstruction condition determination step S130. The reconstruction condition determination step S130 includes:
[0116] S131, counting the number of obtained data segments.
[0117] Since users within the aforementioned organization (i.e., various government departments) can obtain a corresponding number of data fragments by joining different permission groups in the government blockchain network, the way to collect data fragments can come from the blockchain network or from local storage under the chain.
[0118] S132: When the number of acquired data segments is greater than or equal to the minimum number of reconstructed segments k, determine whether the aforementioned collected data segments may have errors.
[0119] Considering that the total number of data fragments obtained by users in the aforementioned organization is greater than or equal to the minimum number of reconstruction fragments k required to reconstruct the key, the condition of the number of data fragments for reconstructing the key is met at this time, but it is still not considered whether the data fragments may have errors or whether they are complete and have an impact on reconstructing the correct key. Therefore, it is necessary to determine whether the aforementioned collected data fragments may have errors or data integrity issues.
[0120] S133, when the determination is no, execute the error-free reconstruction step S140; otherwise, execute the fault-tolerant reconstruction step S150.
[0121] It is worth noting that when the aforementioned collected data fragments all originate from the aforementioned government blockchain network, because the data integrity of the government blockchain network can be guaranteed by the tamper-proof nature of the data, the aforementioned error-free reconstruction step S140 can be executed to obtain the correct key; on the contrary, when the aforementioned collected data fragments have off-chain sources, it is necessary to determine whether the aforementioned collected data fragments may contain errors or data integrity issues, and therefore it is preferred to execute the fault-tolerant reconstruction step S150.
[0122] As one of the preferred implementations of this embodiment, the error-free reconstruction step S140 includes:
[0123] S141, for the obtained n error-free data segments In the definition of y i =P(α i ), i∈[n] represents all the acquired data segments, and k data segments are randomly selected As input to the error-free reconstruction step.
[0124] The error-free reconstruction step does not require obtaining all n error-free data fragments. The correct key can be reconstructed only when the minimum number of reconstruction fragments k≤n required to reconstruct the key is obtained.
[0125] In this embodiment, the user obtains 5 data fragments for reconstructing the key. After determining that the sources of the 5 data fragments are all credible, it is preferred to perform the aforementioned error-free reconstruction steps to obtain the correct key, and arbitrarily select 3 data fragments from the 5 data fragments, for example, select data fragments [1, 702], [2, 974], [3, 939] for reconstructing the key.
[0126] S142, construct k k-1 order polynomials The reconstructed key polynomial is expressed as Among them, the coefficients of the key polynomial P(X) are the reconstructed keys.
[0127] In this embodiment, three 2nd order polynomials are preferably constructed:
[0128] and
[0129] At this point, the reconstructed key polynomial is as follows:
[0130]
[0131] The polynomial coefficients are the keys. In this embodiment, the process of reconstructing the keys without errors can also be obtained by matrix calculation. After the reconstructed keys are expressed as column vectors, they are multiplied by a unit diagonal matrix to obtain a specific key. Since the matrix calculation method is a prior art, it will not be described in detail here.
[0132] As another preferred implementation of this embodiment, when there may be errors in the n collected data fragments, for example, when the integrity and legality of the data fragments cannot be determined, it is preferred to perform the fault-tolerant reconstruction step S150. The fault-tolerant reconstruction step S150 includes:
[0133] S151, for all i∈[n] let P(α i )=y i , y=(y1,...,y n ), get n data fragments
[0134] Assume that users in the aforementioned organization obtain n data fragments. If for all i∈[n], assume that P(α i )=y i That is, y=(y1,...,y n ), then the n data fragments can be expressed as
[0135] At this point, there may be an erroneous data fragment among the n data fragments obtained, but it is not clear which data fragment has the error; assuming that among the n data fragments, at most e data fragments have errors, satisfying In order to reconstruct the correct key, the fault-tolerant reconstruction step needs to locate e erroneous data fragments at the same time.
[0136] In this embodiment, the user obtains 5 data segments for reconstructing the key. Assume that one of the data segments has an error, for example, the data segment [5, 945] becomes [5, 0]. That is to say, the data segments used to reconstruct the key are [1, 702], [2, 974], [3, 939], [4, 597], and [5, 0]. At this time, assume that y represents all the data segments used to reconstruct the key, that is, y = (702, 974, 939, 597, 0). Correspondingly, in order to reconstruct the correct key from y, the fault-tolerant reconstruction step needs to detect that the erroneous data segment is [5, 0].
[0137] S152, construct an e-order non-zero polynomial L(X) and obtain the error location polynomial When the error location polynomial L(X) satisfies L(α i )=0 if and only if y i ≠P(α i ), among the n data segments collected, the α of all the data segments with errors i ∈{y i ≠P(α i )} all incorrectly locate the roots of the polynomial L(X), that is, the polynomial L(X) has at most e roots.
[0138] In this embodiment, the parameters satisfy 1≤k≤n≤p-1 and Therefore, when constructing the error location polynomial L(X), the specific location of the data segment where the error occurs is not known, but if the error location polynomial L(X) can be determined, the error that occurred can be located. This is because the preset parameter e=1 is preferably used in this embodiment, so the fault-tolerant reconstruction step needs to construct a 1st-order non-zero polynomial L(X).
[0139] S153, assuming that the expansion of the error location polynomial L(X) is L(X)=b0+b1X 1 +…+b e-1 X e-1 +b e X e , combined with the error location polynomial L(X), it can be expressed as Determine the highest order term X of the above L(X) e The coefficient is b e =1, then determine the remaining e unknown coefficients b0, b1, ..., b in L(X). e-1 , and then determine L(X).
[0140] Among them, due to the error location polynomial It is the first polynomial, so the highest order term X of the error location polynomial L(X) can be determined eThe coefficient of must be b e =1, therefore, L(X) can be expressed as L(X)=b0+b1X 1 +…+b e-1 X e-1 +X e .
[0141] Based on this, if we can determine the other e unknown coefficients b0, b1, ..., b e-1 , then the error location polynomial L(X) can be determined, and all roots α of L(X) i ∈{y i ≠P(α i )} is the location of the data segment where the error occurred.
[0142] Therefore, in this embodiment, since e=1, the coefficient of L(X) is assumed to be b0, then L(X)=X-b0. That is to say, by determining the value of b0, L(X) can be determined, thereby determining the location where the error occurred and correcting the data segment where the error occurred.
[0143] S154, construct a k+e-1 order non-zero polynomial N(X) that satisfies y i L(α i )=N(α i ), i∈[n], let the coefficients of N(X) be a0, a1, ..., a k+e-1 , then the expanded form of N(X) is expressed as N(X)=a0+a1X 1 +…+a k+e-1 X k+e-1 , by determining the k+e unknown coefficients a0, a1, ..., a of N(X) k+e-1 , and then determine the expansion of N(X).
[0144] In N(X)=a0+a1X 1 +…+a k+e-1 X k+e-1 When we know that the polynomial N(X) has k+e unknown coefficients a0, a1, ..., a k+e-1 If we can determine a0, a1, ..., a k+e-1 , then the polynomial N(X) can be determined.
[0145] In this embodiment, a third-order polynomial N(X) is constructed to satisfy y i L(α i )=N(α i ), i∈[5]. Assuming the coefficients of the polynomial N(X) are a0, a1, a2, a3, then the polynomial N(X)=a0+a1X 1 +a2X 2+a3X 3 There are 4 unknowns in total. If we can determine the values of a0, a1, a2, and a3, we can determine the polynomial N(X).
[0146] S155, due to the equation P(α i )=y i holds for all i∈[n], and when y i ≠P(α i ), i∈[n] when L(α i )=0, so y i L(α i )=L(α i )P(α i ) holds for all i∈[n], that is, N(α i )=L(α i )P(α i ) holds for all i∈[n].
[0147] That is to say, among the n data fragments collected, when a certain data fragment is error-free, the equation P(α i )=y i Established; when a data segment has an error, the error location polynomial L(α i )=0, then equation y i L(α i )=L(α i )P(α i ) Both sides are equal to 0, the equation y i L(α i )=L(α i )P(α i ) also holds true, and because we define y i L(α i )=N(α i ), i∈[n], so N(α i )=L(α i )P(α i ) holds for all i∈[n].
[0148] S156, due to N(α i )=L(α i )P(α i ) holds for all i∈[n], so we establish a system of equations with k+2e equations and k+2e unknowns, and obtain:
[0149]
[0150] Solve the above system of equations to obtain a0, a1, ..., a k+e-1 and b0, b1, ..., be-1 The value of , thereby determining the non-zero polynomial N(X) and the error locator polynomial L(X).
[0151] Since the above system of equations has k+2e equations and a total of k+2e unknowns, solving this system of equations can simultaneously obtain the coefficients a0, a1, ..., a of the polynomials N(X) and L(X). k+e-1 and b0, b1, ..., b e-1 , thereby determining the non-zero polynomial N(X) and the error location polynomial L(X).
[0152] If this set of equations has no solution, it means that the number of erroneous data fragments exceeds e. At this time, it is impossible to reconstruct the key and locate the erroneous data fragments.
[0153] In this embodiment, because y i L(α i )=L(α i )P(α i ), i∈[5] holds, that is, N(α i )=L(α i )P(α i ), i∈[5] holds, therefore, it is preferred to establish a system of five equations to solve the five unknowns a0, a1, a2, a3 and b0:
[0154] a0+a1+a2+a3≡702(1-b0)(mod997)
[0155] a0+2a1+4a2+8a3≡974(2-b0)(mod997)
[0156] a0+3a1+9a2+27a3≡939(3-b0)(mod997)
[0157] a0+4a1+14a2+64a3≡597(4-b0)(mod997)
[0158] a0+5a1+25a2+125a3≡0(5-b0)(mod997)
[0159] The above equations are calculated in matrix form to solve the five unknowns a0, a1, a2, a3 and b0 as follows:
[0160]
[0161] Thus, we obtain a0=382, a1=947, a2=503, a3=345, and b0=5.
[0162] S157, after determining the aforementioned N(X) and L(X), when Δ(y, (P(α i )) i )≤e, the number of erroneous data fragments is less than or equal to the value e, which can be calculated by Reconstruct the key polynomial P(X) to obtain the key; conversely, Δ(y, P(α i )) i )>e, the number of erroneous data fragments is greater than the aforementioned value of e, and since P(X) cannot be reconstructed, the key cannot be obtained.
[0163] In this embodiment, solving the above equations can obtain the polynomial N(X)=382+947X 1 +503X 2 +345X 3 ,L(X)=X-5=992+X(mod997).
[0164] Since the number of erroneous data fragments is less than or equal to the aforementioned e=1, the key polynomial P(X) can be reconstructed, namely:
[0165]
[0166] It is also worth noting here that when executing the aforementioned step S157, the error handling step S160 can also be executed simultaneously; the error handling step S160 includes an error location step S161 and an error repair step S162; after executing the error location step S161 and locating the erroneous data segment, the error repair step S162 is executed to obtain the correct data segment; wherein, the error repair step S162 chooses to execute the accuracy repair step S1621 or the functional repair step S1622 according to the repair requirements of the aforementioned erroneous data segment.
[0167] Among them, as one of the preferred implementations of this embodiment, the error handling step S160 includes:
[0168] Error location step S161, locate the data segment where the error occurs by using the aforementioned error location polynomial L(X), and detect the collected n data segments Among them, all α i ∈{L(α i )=0, i∈[n]} are all erroneous data segments, that is, the roots of all the aforementioned error location polynomials L(X) are the erroneous data segments.
[0169] In this embodiment, the erroneous data segment [5, 0], according to the error locating polynomial L(5)=5-5=992+5=0(mod997), it can be known that the position of the erroneous data segment is the root of the error locating polynomial L(X).
[0170] Error repair step S162, the key polynomial reconstructed by the fault-tolerant reconstruction step The correct value of the data segment is calculated; according to the repair requirements of the data segment, the accuracy repair step S1621 or the functional repair step S1622 in the aforementioned error repair step is executed.
[0171] The accuracy repair step S1621 refers to the position of the data segment corresponding to the error, that is, α i ∈{L(α i )=0, i∈[n]} restore the original data fragment. That is, recalculate α i ∈{L(α i )=0,i∈[n]};then the original value of the erroneous data fragment can be accurately repaired (α i , P(α i )), α i ∈{L(α i )=0,i∈[n]}.
[0172] The functional repair step S1622 is to select an unused data segment location Calculate a new And use the new data segment (α j , P(α j )) replaces the erroneous data fragment; wherein, the data fragment that has undergone the functional repair step is a legitimate data fragment that can be used to reconstruct the key, and the data fragment that has undergone the functional repair step is stored in the node of the government blockchain network.
[0173] In this embodiment, the accuracy repair step can be performed by calculating (5, P(5)) to obtain the original value [5, 945] of the erroneous data segment; the functional repair step can be performed by selecting an unused data segment position, such as selecting an unused new data segment position 6, and calculating (6, P(6)), thereby obtaining a new data segment [6, 986] to replace the original value [5, 0] of the erroneous data segment; the new data segment [6, 986] is functionally exactly the same as the original data segment, can be used to reconstruct the legitimate data segment of the key, and is stored in the government blockchain network.
[0174] For other technical features, please refer to the previous embodiments and will not be described in detail here.
[0175] In addition, see Figure 3 As shown, the present invention also provides an embodiment, providing a distributed key management system 200 applicable to a government blockchain network, including:
[0176] Node 201 of the government blockchain network is used to store data fragments obtained after key encoding.
[0177] Smart contract 202 is used for access control management of key-encoded data fragments and user digital identity management.
[0178] The system server 203 is connected to the node 201 of the government blockchain network.
[0179] The system server 203 is configured to: deploy at least one smart contract into the government blockchain network, and manage the distributed keys in the government blockchain network through the smart contract, wherein the management performs access control management and digital identity management on the data fragments obtained after the key encoding according to the preset key usage permissions.
[0180] For other technical features, please refer to the previous embodiments and will not be repeated here.
[0181] In addition, an embodiment of the present invention also provides a computer-readable storage medium on which a program is stored for use in the aforementioned distributed key management system applicable to a government blockchain network. When the program is executed by a processor, it can implement any of the steps of the above-mentioned distributed key management method applicable to a government blockchain network.
[0182] For other technical features, please refer to the previous embodiments and will not be repeated here.
[0183] In the above description, within the scope of the target protection of the present disclosure, the components can be selectively and operatively combined in any number. In addition, terms such as "including", "comprising" and "having" should be interpreted as inclusive or open by default, rather than exclusive or closed, unless they are explicitly defined to the contrary. All technical, scientific or other terms have the meaning understood by those skilled in the art unless they are defined to the contrary. Common terms found in dictionaries should not be interpreted too idealistically or too impractically in the context of relevant technical documents, unless the present disclosure explicitly defines them as such.
[0184] Although the exemplary aspects of the present disclosure have been described for illustrative purposes, those skilled in the art should appreciate that the above description is only a description of the preferred embodiments of the present invention and is not intended to limit the scope of the present invention. The scope of the preferred embodiments of the present invention includes other implementations in which functions may not be performed in the order in which they appear or are discussed. Any changes or modifications made by those skilled in the art based on the above disclosure are within the scope of the claims.
Claims
1. A distributed key management method applicable to a government blockchain network, characterized in that: Deploy at least one smart contract into the government blockchain network, and manage the distributed keys in the government blockchain network through the smart contract, wherein the management performs access control management and digital identity management on the data fragments obtained after the key encoding according to the preset key usage permissions.
2. The method according to claim 1, characterized in that The method comprises the steps of: obtaining at least one key and processing; the processing comprises constructing at least one key polynomial P(X) for at least one key, and storing at least one data fragment obtained by the aforementioned key polynomial P(X) in a node of the government blockchain network; wherein, before obtaining the key, it also comprises a key generation step S110, as follows: S111, using a random number generator or a pseudo-random number generator to generate k keys key0, ..., key k-1 , where k is an integer greater than 1; S112, when the k keys have different lengths, select an integer h = max(log2(key0), ..., log2(key k-1 )) is the bit length of the longest key among the k keys; S113, select a secure prime number p whose bit length is greater than or equal to h to construct a finite field So that the finite field There are 3 different elements in total And the length of each element is bits; S114, mapping k keys key0, ..., key k-1 For a finite field The last k distinct elements Obtain data fragments from the government blockchain network based on preset key usage permissions; When the number of obtained data fragments is greater than or equal to the minimum threshold value allowing reconstruction of the key, determining whether the key needs to be reconstructed; wherein, determining whether the aforementioned collected data fragments may have errors based on whether the source of the collected data fragments is credible; When there are no errors in the collected data segments, an error-free reconstruction step is performed to obtain a correct key; when at least one of the collected data segments may have errors, a fault-tolerant reconstruction step is performed; wherein, when the number of erroneous data segments is less than or equal to a preset number, the fault-tolerant reconstruction step can locate the erroneous data segments while reconstructing the correct key; For the data segment in which an error occurs, an error handling step is performed according to the preset key repair requirements; when executing the error handling step, choose to execute the accuracy repair step or the functional repair step to complete the key reconstruction; wherein, the data segment repaired by the aforementioned accuracy repair step is exactly the same as the original data segment, and the corresponding function and data segment value are the same; the data segment value repaired by the said functional repair step is different from the original data segment value, but the implemented function is the same.
3. The method according to claim 2, characterized in that The parameters configured in the method include: The number of data fragments n, the minimum number of reconstructed fragments k and the secure strong prime number p, the maximum number of erroneous data fragments allowed in n data fragments is e; The above parameters are all positive integers and satisfy 1≤k≤n≤p-1 and Alternatively, 1≤k≤n≤p-1 and n=k+2e are satisfied at the same time; among which, the strong prime number can select a safe prime number whose bit length is greater than or equal to h.
4. The method according to claim 2, characterized in that After step S110 and before obtaining the key, a key encoding step S120 is also included, as follows: S121: Construct at least one k-1 order key polynomial according to the number of keys to be managed. The coefficients of the key polynomial P(X) are the aforementioned finite field elements Right now Among them, the Representing a finite field The set of all key polynomials P(X) on ; S122, Select finite field The last n distinct non-zero elements As an independent variable, and calculate P(α i ), i∈[n], and get n key-value pairs As the encoded n data fragments.
5. The method according to claim 2, characterized in that: Determining whether the key needs to be reconstructed includes executing the reconstruction condition determination step S130 as follows: S131, counting the number of data segments obtained; S132, when the number of acquired data segments is greater than or equal to the minimum number of reconstructed segments k, determining whether the aforementioned collected data segments may have errors; S133, when the determination is no, executing the error-free reconstruction step; Otherwise, perform the fault-tolerant reconstruction step.
6. The method according to claim 5, characterized in that The error-free reconstruction step S140 includes: S141, for the obtained n error-free data segments In the definition of y i =P(α i ), i∈[n] represents all the acquired data segments, and k data segments are randomly selected as input to the error-free reconstruction step; S142, construct k k-1 order polynomials The reconstructed key polynomial is expressed as Among them, the coefficients of the key polynomial P(X) are the reconstructed keys.
7. The method according to claim 5, characterized in that The fault-tolerant reconstruction step S150 includes: S151, for all i∈[n] let P(α i )=y i , y=(y1,...,y n ), get n data fragments S152, construct an e-order non-zero polynomial L(X) and obtain the error location polynomial When the error location polynomial L(X) satisfies L(α i )=0 if and only if y i ≠P(α i ), among the n data segments collected, the α of all the data segments with errors i ∈{y i ≠P(α i )} are all roots of the error location polynomial L(X); S153, assuming that the expansion of the error locator polynomial L(X) is L(X)=b0+b1X 1 +…+b e-1 X e-1 +b e X e , combined with Determine the highest order term X of the above L(X) e The coefficient is b e =1, then determine the remaining e unknown coefficients b0, b1, ..., b in L(X). e-1 , and then determine L(X); S154, construct a k+e-1 order non-zero polynomial N(X) that satisfies y i L(α i )=N(α i ), i∈[n], let the coefficients of N(X) be a0, a1, …, a k+e-1 , then the expanded form of N(X) is expressed as N(X)=a0+a1X 1 +…+a k+e-1 X k+e-1 , by determining the k+e unknown coefficients a0, a1, ..., a of N(X) k+e-1 , and then determine the expansion of N(X); S155, due to the equation P(α i )=y i holds for all i∈[n], and when y i ≠P(α i ), i∈[n] when L(α i )=0, therefore, yxL(α i )=L(α i )P(α i ) holds for all i∈[n], that is, N(α i )=L(α i )P(α i ) holds for all i∈[n]; S156, due to N(α i )=L(α i )P(α i ) holds for all i∈[n], so we establish a system of equations with k+2e equations and k+2e unknowns, and obtain: Solve the above system of equations to obtain a0, a1, ..., a k+e-1 and b0, b1, ..., b e-1 The value of , thereby determining the non-zero polynomial N(X) and the error location polynomial L(X); S157, after determining the aforementioned N(X) and L(X), when Δ(y, (P(α i )) i )≤e, the number of erroneous data fragments is less than or equal to the value e, which can be calculated by Reconstruct the key polynomial P(X) to obtain the key; conversely, Δ(y, (P(α i )) i )>e, the number of erroneous data fragments is greater than the aforementioned value of e, and since P(X) cannot be reconstructed, the key cannot be obtained.
8. The method according to claim 7, characterized in that When executing the aforementioned step S157, an error handling step S160 can also be executed simultaneously; the error handling step S160 includes an error locating step S161 and an error repairing step S162; After executing the error location step S161 to locate the erroneous data segment, the error repair step S162 is executed to obtain the correct data segment; wherein the error repair step S162 selects to execute the accuracy repair step S1621 or the functional repair step S1622 according to the repair requirements of the aforementioned erroneous data segment; wherein, The error location step S161 is configured to: locate the data segment where the error occurs by using the aforementioned error location polynomial L(X), detect the n data segments collected Among them, all α i ∈{L(α i )=0, i∈[n]} are all data fragments with errors; The error repair step S162 is configured as follows: the key polynomial reconstructed by the fault-tolerant reconstruction step Calculate the correct value of the data segment; according to the repair requirements of the data segment, perform the accuracy repair step S1621 or the functional repair step S1622 in the above error repair step; wherein, The accuracy repair step S1621 refers to the position of the data segment corresponding to the error, that is, α i ∈{L(α i )=0,i∈[n]} restore the original data segment; the functional repair step S1622 refers to selecting an unused data segment position Calculate a new And use the new data segment (α j , P(α j )) replaces the erroneous data fragment; wherein, the data fragment that has undergone the functional repair step is a legitimate data fragment that can be used to reconstruct the key, and the data fragment that has undergone the functional repair step is stored in the node of the government blockchain network.
9. A distributed key management system applicable to a government blockchain network according to the method described in any one of claims 1 to 8, characterized in that: include: Nodes of the government blockchain network are used to store data fragments obtained after key encoding; Smart contracts are used for access control management of key-encoded data fragments and user digital identity management; A system server, wherein the system server is connected to a node of the government blockchain network; The system server is configured to: deploy at least one smart contract into the government blockchain network, and manage the distributed keys in the government blockchain network through the smart contract, wherein the management performs access control management and digital identity management on the data fragments obtained after the key encoding according to the preset key usage permissions.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Efficient access method and system for multi-level block chain government affair data
CN113434880A
Industrial Internet of Things security data sharing method based on block chain
CN116015828A
Key escrow method and system and electronic equipment
CN118199869A
Computer-implemented method of generating a threshold vault
US20200213099A1
Staging of non-fungible tokens before deployment
US20240412185A1