Key processing method and device, key reconstruction method and device, equipment and medium

By sharding the original key twice and processing it based on a secret sharing algorithm, the problem of key share being easily recovered in the existing key sharing technology is solved, and higher security and anti-eavesdropping capabilities are achieved.

CN120017257APending Publication Date: 2025-05-16CHINA TELECOM CORP LTD

Patent Information

Application Number
CN202510142539.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the existing key sharing technology, the key share division dimension is relatively single, and if at least t key shares are stolen at the same time, the stolen party is very likely to recover the original key, resulting in serious security risks for the enterprise's sensitive data.

Method used

By performing the first segmentation of the original key, a collection of key shard tuples is obtained, and based on the preset secret sharing algorithm, it is converted into a key matrix, and then the second segmentation is performed to obtain N key matrix shards. In response to the request of the key user, k shards of N key matrix shards are sent.

Benefits of technology

This method increases the entropy of the key threshold sharing technology by sharding the key twice, greatly improving the difficulty of the key being cracked and the overall security of the system, and improving the anti-leakage and anti-eavesdropping capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017257A_ABST
    Figure CN120017257A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a key processing method and device, a key reconstruction method and device, equipment and a medium, and relates to the field of network technologies and security. The method comprises the steps that an original key is segmented for the first time, a key fragment tuple set is obtained, and the key fragment tuple set comprises a plurality of key fragment tuples; based on a preset secret sharing algorithm, converting the key fragment tuple set into a key matrix, and performing second segmentation on the key matrix to obtain N key matrix fragments; in response to a received key acquisition request sent by a key user, k key matrix fragments in the N key matrix fragments are sent to the key user; n and k are positive integers greater than 1, and N is greater than k. According to the method, the original secret key is subjected to two-time different fragmentation, higher-dimension fragmentation of the secret key is achieved, the entropy of the secret key threshold sharing technology is greatly improved, and the anti-leakage and anti-eavesdropping capabilities of the secret key are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technology and security, and in particular to a key processing, key reconstruction method, device, equipment and medium. Background Art

[0002] The key is the core information used to control the encryption algorithm to complete the conversion between the original data (plain text) and the encrypted data (cipher text). Encryption algorithms can be divided into symmetric algorithms (such as AES (Advanced Encryption Standard), 3DES (Triple Data Encryption Standard), SM4 algorithm) and asymmetric encryption algorithms (such as RSA algorithm, ECC (Ellipse Curve Cryptography) algorithm). According to the encryption algorithm type, the key can be divided into symmetric key and asymmetric key, which are generally expressed in Base64, Hex, PEM and DER encoding formats.

[0003] Key sharing is a vital component of information security. Among the existing key sharing technologies, the most widely used is the threshold scheme, that is, the key is divided into n parts, but only t of them (t≤n) are needed to recover the key. Among them, Shamir's Secret Sharing technology based on polynomial interpolation theory is more typical.

[0004] Specifically, assuming that the key is an integer S, first select the sharing threshold t and the total share n (t≤n), and then select a polynomial f(x)=S+a1x+a2x 2 +……+a t-1 x t-1 and n different non-zero integers x1, x2, ..., x n , calculate y i =f(x i ), and (x i ,y i ) is distributed to the participants as the i-th share. When at least t participants’ shares are collected, the Lagrange interpolation method can be used to recover the polynomial f(x), calculate f(0) = S, and thus recover the key.

[0005] In the actual application of this threshold sharing technology, the key share division dimension is relatively simple, and if at least t key shares are stolen at the same time, the thief is very likely to recover the original key. If the key is leaked or obtained by unauthorized persons, the company's sensitive data may face serious security risks and cause huge economic and reputation losses. Summary of the invention

[0006] In order to solve the above technical problems or at least partially solve the above technical problems, an embodiment of the present invention provides a key processing, key reconstruction method, device, electronic device and medium.

[0007] In a first aspect, an embodiment of the present invention provides a key processing method, including:

[0008] Performing a first split on the original key to obtain a key shard tuple set, wherein the key shard tuple set includes a plurality of key shard tuples;

[0009] Based on a preset secret sharing algorithm, the key shard tuple set is converted into a key matrix, and the key matrix is ​​split for a second time to obtain N key matrix shards;

[0010] In response to receiving a key acquisition request sent by a key user, k key matrix slices out of the N key matrix slices are sent to the key user; wherein N and k are both positive integers greater than 1, and N>k, k represents the threshold value of the preset secret sharing algorithm.

[0011] Optionally, the splitting of the original key to obtain the key shard tuple set includes: dividing the original key into m sub-keys, converting each sub-key into an integer; using a predefined function cluster to reduce the integer corresponding to each sub-key to obtain the key shard tuple set.

[0012] Optionally, converting each subkey into an integer includes: performing binary conversion on each subkey to obtain a binary form corresponding to each subkey; and converting the binary form corresponding to each subkey into an integer according to a large number algorithm.

[0013] Optionally, based on a preset secret sharing algorithm, the key sharding tuple set is converted into a key matrix, and the key matrix is ​​split for a second time to obtain N key matrix shards, including: determining the secret sharing threshold of the preset secret sharing algorithm as k and the total share as N; constructing a polynomial function corresponding to each key sharding tuple to obtain a polynomial function set corresponding to the key sharding tuple set; constructing a random number matrix, and using the elements in the random number matrix as coefficients of corresponding elements in the polynomial function set; letting the independent variables of each polynomial function in the polynomial function set take integers between [1, N], and calculating the function value of each polynomial function; forming a key matrix with the function values ​​of each polynomial function; and splitting the key matrix for a second time to obtain N key matrix shards.

[0014] Optionally, determining the secret sharing threshold of the preset secret sharing algorithm to be k and the total share to be N includes: determining the secret sharing threshold of the preset secret sharing algorithm to be k, the number of spare key shards to be h, and the total share to be N, N=k+h, h is a positive integer greater than or equal to 1.

[0015] Optionally, in response to receiving a key acquisition request sent by a key user, sending k key matrix slices out of the N key matrix slices to the key user, comprises:

[0016] In response to receiving a key acquisition request sent by a key user, acquiring k key matrix slices from the N key matrix slices;

[0017] Using a random seed, randomizing the k key matrix slices to obtain k randomized key matrix slices;

[0018] The k randomized key matrix slices are sent to the key user.

[0019] Optionally, the using a random seed to perform random processing on the k key matrix slices to obtain k randomized key matrix slices includes:

[0020] Generate a random number matrix using a random number seed, wherein the random number matrix is ​​a non-singular matrix;

[0021] Slice the k key matrices into a first matrix, and calculate the product of the first matrix and the random number matrix to obtain a second matrix;

[0022] The second matrix is ​​divided into k matrix slices, where the k matrix slices are k randomized key matrix slices.

[0023] In a second aspect, an embodiment of the present invention provides a key reconstruction method, including:

[0024] Receiving k key matrix slices sent by a key sender, and combining the k key matrix slices into a key matrix;

[0025] Performing Lagrange interpolation on the key matrix to obtain a plurality of key shard tuples;

[0026] The multiple key shard tuples are reconstructed to obtain the original key.

[0027] Optionally, reconstructing the multiple key shard tuples to obtain the key includes: using a predefined function cluster to convert the multiple key shard tuples into multiple integers; and converting based on the multiple integers to obtain the original key.

[0028] Optionally, the method also includes: concatenating the original key with a timestamp from the key sender to obtain a first sequence; calculating a hash value of the first sequence; comparing the hash value of the first sequence with the hash value from the key sender; and when the hash value of the first sequence is the same as the hash value from the key sender, determining that the original key is the correct key.

[0029] In a third aspect, an embodiment of the present invention provides a key processing device, including:

[0030] A first sharding module, used for performing a first sharding on the original key to obtain a key sharding tuple set, wherein the key sharding tuple set includes a plurality of key sharding tuples;

[0031] A second sharding module is used to convert the key sharding tuple set into a key matrix based on a preset secret sharing algorithm, and perform a second sharding on the key matrix to obtain N key matrix shards;

[0032] A key transmission module is used to send k key matrix slices out of the N key matrix slices to the key user in response to receiving a key acquisition request sent by the key user; wherein N and k are both positive integers greater than 1, and N>k, k represents the threshold value of the preset secret sharing algorithm.

[0033] Optionally, the first sharding module is further used to: divide the original key into m sub-keys, convert each sub-key into an integer; use a predefined function cluster to reduce and decompose the integer corresponding to each sub-key to obtain a set of key sharding tuples.

[0034] Optionally, the first sharding module is further used to: perform binary conversion on each subkey to obtain a binary form corresponding to each subkey; and convert the binary form corresponding to each subkey into an integer according to a large number algorithm.

[0035] Optionally, the second sharding module is also used to: determine the secret sharing threshold of the preset secret sharing algorithm as k and the total share as N; construct a polynomial function corresponding to each key sharding tuple to obtain a polynomial function set corresponding to the key sharding tuple set; construct a random number matrix, and use the elements in the random number matrix as coefficients of corresponding elements in the polynomial function set; let the independent variables of each polynomial function in the polynomial function set take integers between [1, N] respectively, and calculate the function value of each polynomial function; form a key matrix with the function values ​​of each polynomial function; and divide the key matrix for a second time to obtain N key matrix shards.

[0036] Optionally, the second sharding module is also used to: determine the secret sharing threshold of the preset secret sharing algorithm as k, the number of spare key shards as h, and the total share as N, N=k+h, h is a positive integer greater than or equal to 1.

[0037] Optionally, the key transmission module is also used to: in response to receiving a key acquisition request sent by a key user, obtain k key matrix slices from the N key matrix slices; use a randomization seed to randomize the k key matrix slices to obtain k randomized key matrix slices; and send the k randomized key matrix slices to the key user.

[0038] Optionally, the key transmission module is also used to: generate a random number matrix using a random number seed, and the random number matrix is ​​a non-singular matrix; form a first matrix by the k key matrix slices, calculate the product of the first matrix and the random number matrix to obtain a second matrix; divide the second matrix to obtain k matrix slices, and the k matrix slices are k randomized key matrix slices.

[0039] In a fourth aspect, an embodiment of the present invention provides a key reconstruction device, including:

[0040] A matrix construction module, used for receiving k key matrix slices sent by a key sender, and forming a key matrix from the k key matrix slices;

[0041] An interpolation module, used for performing Lagrange interpolation on the key matrix to obtain a plurality of key shard tuples;

[0042] The reconstruction module is used to reconstruct the multiple key shard tuples to obtain the original key.

[0043] Optionally, the matrix construction module is further used to: convert the multiple key sharding tuples into multiple integers using a predefined function cluster; and perform conversion based on the multiple integers to obtain the original key.

[0044] Optionally, the key reconstruction device also includes a key verification module, which is used to: concatenate the original key with the timestamp from the key sender to obtain a first sequence; calculate the hash value of the first sequence; compare the hash value of the first sequence with the hash value from the key sender; and when the hash value of the first sequence is the same as the hash value from the key sender, determine that the original key is the correct key.

[0045] In a fifth aspect, an embodiment of the present invention provides an electronic device, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; the memory is used to store computer programs; and the processor is used to implement the key processing method or key reconstruction method provided by any embodiment of the present invention when executing the program stored in the memory.

[0046] In a sixth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a key processing method or a key reconstruction method provided by any embodiment of the present invention.

[0047] The technical solution provided by the embodiments of the present disclosure brings at least the following beneficial effects:

[0048] The key processing method provided by the embodiment of the present invention performs a first segmentation on the original key to obtain a key segmentation tuple set, converts the key segmentation tuple set into a key matrix based on a preset secret sharing algorithm, and performs a second segmentation on the key matrix to obtain N key matrix segments; in response to receiving a key acquisition request sent by a key user, k key matrix segments of the N key matrix segments are sent to the key user; wherein N and k are both positive integers greater than 1, and N>k, and k represents the threshold value of the preset secret sharing algorithm. The method realizes higher-dimensional segmentation of the key by performing two different segmentations on the original key, which can effectively increase the entropy of the key threshold sharing technology, greatly improve the difficulty of key cracking and the overall security of the system, and improve the system's anti-leakage and anti-eavesdropping capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art are briefly introduced below.

[0050] Figure 1 A schematic diagram showing a flow chart of a key processing method according to an embodiment of the present invention;

[0051] Figure 2 A schematic diagram showing a flow chart of a key processing method according to another embodiment of the present invention;

[0052] Figure 3 A schematic diagram showing a flow chart of a key processing method according to another embodiment of the present invention;

[0053] Figure 4 A schematic diagram showing a flow chart of a key reconstruction method according to an embodiment of the present invention is shown;

[0054] Figure 5 A schematic diagram showing the structure of a key processing device according to an embodiment of the present invention is shown;

[0055] Figure 6 A schematic diagram showing the structure of a key reconstruction device according to an embodiment of the present invention is shown;

[0056] Figure 7 A schematic structural diagram of an electronic device according to an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0057] The following is a description of exemplary embodiments of the present invention in conjunction with the accompanying drawings, including various details of the embodiments of the present invention to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those of ordinary skill in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for clarity and conciseness, the description of well-known functions and structures is omitted in the following description.

[0058] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of one type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.

[0059] Figure 1 FIG. 1 is a flow chart showing a key processing method according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0060] Step S101: performing a first split on the original key to obtain a key shard tuple set, wherein the key shard tuple set includes a plurality of key shard tuples.

[0061] The original key (denoted as K) can be the key of a symmetric encryption algorithm or the key of an asymmetric encryption algorithm, and the present invention does not limit this. The original key can be represented in Base64 (Base64 is a method of representing binary data based on 64 printable characters), Hex (Hexadecimal, representing hexadecimal), PEM (Privacy Enhancement Message, a coding format based on Base64) and DER (Distinguished Encoding Rules) encoding and other formats. When the original key is split for the first time, the original key K is divided into m sub-keys (m is a positive integer greater than or equal to 1). Convert each sub-key into an integer to obtain an integer set, denoted as S0={s i |1≤i≤m},s i Indicates the integer corresponding to the i-th subkey.

[0062] In order to reduce the computational complexity, this embodiment uses a predefined function cluster (a predefined function cluster refers to a set of predefined functions) to decompose the integer corresponding to each subkey to obtain a smaller value as possible. A key fragmentation tuple set is obtained. As an optional example, the predefined function cluster is T i (x), let x be the current timestamp T, calculate the value of the predefined function cluster when x = T, denoted as T i (x)| x=T , using this predefined function cluster to convert each integer s i Decompose it into small parts, that is, s i =f i ×T i (x)| x=T +g i , and obtain the key sharding tuple set, denoted as S = {k i =(f i ,g i )|1≤i≤m}. k i Represents the key shard tuple corresponding to the i-th (or i-th) subkey.

[0063] This step uses a predefined function cluster to decompose the original key into small pieces, so that the key shard tuple k i As small as possible to reduce computational complexity.

[0064] In an optional embodiment, the m subkeys may be converted to binary, and the binary forms corresponding to the m subkeys may be converted to integers based on a big number algorithm, and the integers corresponding to each subkey may be decomposed into smaller numbers. Among them, BNA (BigNumber Algorithms) is an algorithm used to process numerical values ​​that exceed the range that can be represented by conventional data types (such as integers int or long). This type of algorithm is mainly used to process very large integers or real numbers, which usually exceed the maximum value directly supported by computer hardware.

[0065] Step S102: Based on a preset secret sharing algorithm, the key shard tuple set is converted into a key matrix, and the key matrix is ​​split for a second time to obtain N key matrix shards.

[0066] The preset secret sharing algorithm may be based on the Shamir threshold key sharing algorithm. The process of converting the key sharding tuple of the first key sharding into N key matrix shards based on the Shamir threshold key sharing algorithm includes:

[0067] (1) Determine the secret sharing threshold of the preset secret sharing algorithm as k and the total share as N.

[0068] (2) Construct a polynomial function corresponding to each key shard tuple to obtain a set of polynomial functions corresponding to the key shard tuple set: For each key shard tuple k in the key shard tuple set S, i =(f i ,g i ) Construct the polynomial function f i (x) = f i +a i1 x+a i2 x 2 +……+a i(k-1) x k-1 and g i (x) = g i +a i1 x+a i2 x 2 +……+a i(k-1) x k-1 , we get the polynomial function set F of the key shard tuple = {f i (x)|1≤i≤m} and G={g i (x)|1≤i≤m}.

[0069] (3) Construct a random number matrix, and use the elements in the random number matrix as coefficients of corresponding elements in the polynomial function set: Generate an m×(k-1) random number matrix The coefficients of the set F and G as polynomial functions.

[0070] (4) Calculate f when x=1, x=2, …, x=N i (x), g i (x), and obtain the function values ​​of the m×N polynomial set F and G, thereby completing the conversion of the key shard tuple set into the key matrix, that is, and

[0071] Among them, any element in the key matrix F1 and G1 has no correlation with the original key K.

[0072] (5) Perform a second slicing of the key matrix to obtain N key matrix slices: Divide the key matrices F1 and G1 into key matrix slices. The slicing method is not unique, such as slicing by column. After the second slicing, any key matrix slice does not contain a complete key slice tuple element f i or i All information of the key matrix can be restored, and any combination of k key matrix slices can restore the original key K.

[0073] In an optional embodiment, the present invention also includes storing the shards of the key matrices F1 and G1 in N different, mutually isolated and sufficiently secure media, such as media that adopt authority control, vault mode, biometric identification, multi-factor authentication, etc.

[0074] Step S101 slices the original key to obtain a key slice tuple, and step S102 slices the key slice tuple, which is equivalent to a second slice of the original key. By slicing the original key twice, the obtained key matrix slices are no longer related to the original key, which greatly increases the difficulty of key cracking and the overall security of the system, and improves the system's anti-leakage and anti-eavesdropping capabilities.

[0075] Step S103: In response to receiving a key acquisition request sent by a key user, k key matrix slices among the N key matrix slices are sent to the key user; wherein N and k are both positive integers greater than 1, and N>k.

[0076] When a key acquisition request is received from a key user, k key matrix slices are randomly acquired from the N key matrix slices, and the k key matrix slices are sent to the key user.

[0077] The key processing method provided by the embodiment of the present invention performs a first segmentation on the original key to obtain a key shard tuple set, converts the key shard tuple set into a key matrix based on a preset secret sharing algorithm, and performs a second segmentation on the key matrix to obtain N key matrix shards; in response to receiving a key acquisition request sent by a key user, k key matrix shards among the N key matrix shards are sent to the key user; wherein N and k are both positive integers greater than 1, and N>k. The method achieves higher-dimensional sharding of the key by performing two different segmentations on the original key, reduces the correlation between the key shards, can effectively increase the entropy of the key threshold sharing technology, greatly improves the difficulty of key cracking and the overall security of the system, and improves the system's anti-leakage and anti-eavesdropping capabilities.

[0078] Figure 2 FIG. 2 is a flow chart showing a key processing method according to another embodiment of the present invention. Figure 2 As shown, the method includes:

[0079] Step S201: Divide the original key into m subkeys, perform binary conversion on each subkey, and obtain the binary form corresponding to each subkey.

[0080] Step S202: Convert the binary form corresponding to each subkey into an integer.

[0081] Step S203: using a predefined function cluster, the integer corresponding to each subkey is decomposed to obtain a key fragment tuple set.

[0082] Step S204: Determine that the secret sharing threshold of the preset secret sharing algorithm is k, the number of spare key fragments is h, and the total share is N, N=k+h, k and h are positive integers greater than or equal to 1.

[0083] Step S205: Construct a polynomial function corresponding to each key sharding tuple to obtain a set of polynomial functions corresponding to the key sharding tuple set: for each key sharding tuple k in the key sharding tuple set S, i =(f i ,g i ) Construct the polynomial function f i (x) = f i +a i1 x+a i2 x 2 +……+a i(k-1) x k-1 and g i (x) = g i +a i1 x+a i2 x 2 +……+a i(k-1)x k -1 , we get the polynomial function set F of the key shard tuple = {f i (x)|1≤i≤m} and G={g i (x)|1≤i≤m}.

[0084] Step S206: construct a random number matrix, and use the elements in the random number matrix as coefficients of corresponding elements in the polynomial function set: generate an m×(k-1) random number matrix The coefficients of the set F and G as polynomial functions.

[0085] Step S207: Calculate f when x=1, x=2, ..., x=N i (x), g i (x), and obtain the function values ​​of the m×N polynomial set F and G, thereby completing the conversion of the key shard tuple set into the key matrix, that is, and

[0086] Among them, any element in the key matrix F1 and G1 has no correlation with the original key K.

[0087] Step S208: Divide the key matrix for the second time to obtain N key matrix slices: Divide the key matrices F1 and G1 into key matrix slices. The slicing method is not unique, such as slicing by column. After the second slicing, any key matrix slice does not contain a complete key slice tuple element f i or i All information of the key matrix can be restored, and any combination of k key matrix slices can restore the original key K.

[0088] The key processing method provided by the embodiment of the present invention proposes, in the key sharding stage, a method of generating a two-dimensional key matrix after performing multiple rounds of transformations such as large number conversion, decomposition and polynomial construction on the original key, and performing secondary sharding on the key matrix to generate key matrix shards, thereby reducing the correlation between key shards and greatly improving the entropy and anti-leakage capabilities of the key threshold sharing technology. Compared with the prior art, the key can be operated on a higher dimension, thereby improving the flexibility and fault tolerance of the system.

[0089] Figure 3 FIG. 2 is a flow chart showing a key processing method according to another embodiment of the present invention. Figure 3 As shown, the method includes:

[0090] Step S301: split the original key for the first time to obtain a key shard tuple set, where the key shard tuple set includes multiple key shard tuples.

[0091] Step S302: Based on a preset secret sharing algorithm, the key shard tuple set is converted into a key matrix, and the key matrix is ​​split for the second time to obtain N key matrix shards.

[0092] Step S303: In response to receiving a key acquisition request sent by a key user, k key matrix slices are randomly acquired from the N key matrix slices.

[0093] Step S304: using the randomization seed, randomizing the k key matrix slices to obtain k randomized key matrix slices.

[0094] Step S305: Send the k randomized key matrix slices to the key user. Optionally, the key sender may send the k randomized key matrix slices to the key user via an encrypted transmission protocol.

[0095] Among them, steps S301-S302 can refer to Figure 1 or Figure 2 The illustrated embodiments are not described in detail here to avoid repetition.

[0096] For step S304, in an optional embodiment, the process of randomizing k key matrix slices using a random seed includes:

[0097] A random number matrix is ​​generated using a random number seed, and the random number matrix is ​​a non-singular matrix. Optionally, a k×k random number matrix B is generated according to a preset PRNG algorithm and a specified random number seed, and B is a non-singular matrix (reversible matrix). If B is not reversible, the random number seed is changed and regenerated until B is reversible. Among them, the PRNG (pseudo-random number generator) algorithm generates a series of seemingly random numbers through a specific algorithm, but in fact these numbers are certain.

[0098] The k key matrix slices are formed into the first matrix (denoted as F k and G k ), calculate the product of the first matrix and the random number matrix B, and get the second matrix, denoted as F′ k =F k ×B and G′ k =G k ×B.

[0099] The second matrix is ​​segmented (for example, segmented by columns) to obtain k matrix slices, where the k matrix slices are k randomized key matrix slices.

[0100] After the key matrix slices are reorganized in the key transmission stage, the embodiment of the present invention randomizes the matrix composed of the key matrix slices based on the randomization method specified by the key sender, thereby improving the anti-eavesdropping and anti-leakage protection capabilities of key transmission between systems.

[0101] The key processing method of the embodiment of the present invention splits the original key into multiple parts, converts each part into an integer in turn based on the large number algorithm, and then decomposes the integer into a key shard tuple. Then the key shard tuple is converted into a k-1 degree polynomial set F and G, thereby obtaining two key matrices, wherein any matrix element has no correlation with the original key. Finally, the key matrix is ​​divided into key matrix slices, and then stored in different, mutually isolated and sufficiently secure media (such as media using means such as authority control, vault mode, biometric identification, multi-factor authentication, etc.). When the key user needs to use the key, the key sender selects the PRNG algorithm and generates a random number matrix according to the specified random number seed, and the random number matrix is ​​a non-singular matrix, and the randomized matrix is ​​multiplied by the matrix composed of k key matrix slices to obtain a randomized key matrix slice, and then the randomized key matrix slice is encrypted and sent to the user using an encrypted transmission protocol. This method can effectively increase the entropy of the system through multiple protection mechanisms, and improve the system's anti-leakage and anti-eavesdropping capabilities.

[0102] Figure 4 FIG. 1 is a flow chart of a key reconstruction method provided by an embodiment of the present invention. Figure 4 As shown, the method includes:

[0103] Step S401: Receive k key matrix slices sent by the key sender, and combine the k key matrix slices into a key matrix to obtain F′ k and G′ k .

[0104] Step S402: Generate a k×k random number matrix B according to the agreed PRNG algorithm and random number seed, and use the random number matrix to encrypt the key matrix F′ k and G′ k De-randomize and restore F k and G k . That is, F k =F′ k ×B -1 =F k ×B×B -1 =F k ×E,G k =G′ k ×B -1 =G k ×B×B -1 =G k ×E, where E is the k×k identity matrix.

[0105] Step S402: Perform Lagrange interpolation on the key matrix to obtain multiple key fragment tuples.

[0106] F k and G k Perform Lagrange interpolation, we have and Where 1≤i≤m. According to the Lagrange interpolation formula, when x=0, and That is, S = {k i =(f i ,g i )|1≤i≤m}.

[0107] Step S402: Use the key fragment tuple (f i ,g i ) and predefined function clusters T i (x) Restore all integer slices f i ×T i (x)| x=T +g i , that is, {s i |1≤i≤m}, and finally convert the integer shard into the original m (m≥1) key shards (i.e., subkeys).

[0108] Step S402: reorganize the key fragments to obtain the original key K.

[0109] When reconstructing the key, the key user needs to know the key reconstruction elements such as randomization method, predefined function cluster and reconstruction rule (the inverse rule of the segmentation rule of the key sender for the second segmentation of the key matrix) to reconstruct the key. The key sender can choose different key reconstruction elements according to different key users, and these key reconstruction elements can be notified to the key users through different security hardware or other forms to ensure that the leakage of all key reconstruction elements will not temporarily affect the systems of other users, thereby minimizing the risk of data leakage.

[0110] In an optional embodiment, after reconstructing the original key, the key user also needs to verify the accuracy of the original key. For example, the key user concatenates the original key with the timestamp from the key sender to obtain a first sequence; calculates the hash value of the first sequence; compares the hash value of the first sequence with the hash value from the key sender; and determines that the original key is the correct key if the hash value of the first sequence is the same as the hash value sent by the key sender.

[0111] In this embodiment, by concatenating the reconstructed original key with the timestamp and then using a hash algorithm to calculate the hash value, the accuracy of the reconstructed key can be verified, and attacks similar to rainbow tables can be effectively prevented.

[0112] Figure 5 FIG. 2 shows a schematic diagram of the structure of a key processing device provided by an embodiment of the present invention. Figure 5 As shown, the key processing device 500 includes:

[0113] The first sharding module 501 is used to perform a first sharding on the original key to obtain a key sharding tuple set, wherein the key sharding tuple set includes a plurality of key sharding tuples;

[0114] A second sharding module 502 is used to convert the key sharding tuple set into a key matrix based on a preset secret sharing algorithm, and perform a second sharding on the key matrix to obtain N key matrix shards;

[0115] The key transmission module 503 is used to send k key matrix slices out of the N key matrix slices to the key user in response to receiving a key acquisition request sent by the key user; wherein N and k are both positive integers greater than 1, and N>k, k represents the threshold value of the preset secret sharing algorithm.

[0116] Optionally, the first sharding module is further used to: divide the original key into m sub-keys, convert each sub-key into an integer; use a predefined function cluster to reduce and decompose the integer corresponding to each sub-key to obtain a set of key sharding tuples.

[0117] Optionally, the first sharding module is further used to: perform binary conversion on each subkey to obtain a binary form corresponding to each subkey; and convert the binary form corresponding to each subkey into an integer according to a large number algorithm.

[0118] Optionally, the second sharding module is also used to: determine the secret sharing threshold of the preset secret sharing algorithm as k and the total share as N; construct a polynomial function corresponding to each key sharding tuple to obtain a polynomial function set corresponding to the key sharding tuple set; construct a random number matrix, and use the elements in the random number matrix as coefficients of corresponding elements in the polynomial function set; let the independent variables of each polynomial function in the polynomial function set take integers between [1, N] respectively, and calculate the function value of each polynomial function; form a key matrix with the function values ​​of each polynomial function; and divide the key matrix for a second time to obtain N key matrix shards.

[0119] Optionally, the second sharding module is also used to: determine the secret sharing threshold of the preset secret sharing algorithm as k, the number of spare key shards as h, and the total share as N, N=k+h, h is a positive integer greater than or equal to 1.

[0120] Optionally, the key transmission module is also used to: in response to receiving a key acquisition request sent by a key user, obtain k key matrix slices from the N key matrix slices; use a randomization seed to randomize the k key matrix slices to obtain k randomized key matrix slices; and send the k randomized key matrix slices to the key user.

[0121] Optionally, the key transmission module is also used to: generate a random number matrix using a random number seed, and the random number matrix is ​​a non-singular matrix; form a first matrix by the k key matrix slices, calculate the product of the first matrix and the random number matrix to obtain a second matrix; divide the second matrix to obtain k matrix slices, and the k matrix slices are k randomized key matrix slices.

[0122] The key processing device provided by the embodiment of the present invention performs a first segmentation on the original key to obtain a key segmentation tuple set, converts the key segmentation tuple set into a key matrix based on a preset secret sharing algorithm, and performs a second segmentation on the key matrix to obtain N key matrix segments; in response to receiving a key acquisition request sent by a key user, k key matrix segments of the N key matrix segments are sent to the key user; wherein N and k are both positive integers greater than 1, and N>k, and k represents the threshold value of the preset secret sharing algorithm. The method realizes higher-dimensional segmentation of the key by performing two different segmentations on the original key, which can effectively increase the entropy of the key threshold sharing technology, greatly improve the difficulty of key cracking and the overall security of the system, and improve the system's anti-leakage and anti-eavesdropping capabilities.

[0123] Figure 6 FIG. 1 is a schematic diagram showing the structure of a key reconstruction device provided by an embodiment of the present invention. Figure 6 As shown, the key reconstruction device 600 includes:

[0124] The matrix construction module 601 is used to receive k key matrix slices sent by the key sender, and form a key matrix with the k key matrix slices;

[0125] An interpolation module 602, configured to perform Lagrange interpolation on the key matrix to obtain a plurality of key shard tuples;

[0126] The reconstruction module 603 is used to reconstruct the multiple key shard tuples to obtain the original key.

[0127] Optionally, the matrix construction module is further used to: convert the multiple key sharding tuples into multiple integers using a predefined function cluster; and perform conversion based on the multiple integers to obtain the original key.

[0128] Optionally, the key reconstruction device also includes a key verification module, which is used to: concatenate the original key with the timestamp from the key sender to obtain a first sequence; calculate the hash value of the first sequence; compare the hash value of the first sequence with the hash value from the key sender; and when the hash value of the first sequence is the same as the hash value from the key sender, determine that the original key is the correct key.

[0129] The above device can execute the method provided by the embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method. For technical details not described in detail in this embodiment, please refer to the method for configuring mobile service resources provided by the embodiment of the present invention.

[0130] Figure 7 FIG. 1 is a schematic diagram showing the structure of an electronic device according to an embodiment of the present invention. Figure 7 As shown, the electronic device includes:

[0131] Processor 701, communication interface 702, memory 703 and communication bus 704, wherein processor 701, communication interface 702, memory 703 communicate with each other via communication bus 704.

[0132] Memory 703, used for storing computer programs;

[0133] The processor 701 is used to execute the program stored in the memory 703 to implement the following steps:

[0134] Performing a first split on the original key to obtain a key shard tuple set, wherein the key shard tuple set includes a plurality of key shard tuples;

[0135] Based on a preset secret sharing algorithm, the key shard tuple set is converted into a key matrix, and the key matrix is ​​split for a second time to obtain N key matrix shards;

[0136] In response to receiving a key acquisition request sent by a key user, k key matrix slices out of the N key matrix slices are sent to the key user; wherein N and k are both positive integers greater than 1, and N>k, k represents the threshold value of the preset secret sharing algorithm.

[0137] The communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus. The communication interface is used for communication between the above terminal and other devices.

[0138] The memory may include a random access memory (RAM) or a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.

[0139] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0140] In another embodiment of the present invention, a computer-readable storage medium is provided, in which instructions are stored. When the computer-readable storage medium is run on a computer, the computer executes the key processing method described in any one of the above embodiments.

[0141] In another embodiment of the present invention, a computer program product including instructions is provided, which, when executed on a computer, enables the computer to execute the key processing method described in any one of the above embodiments.

[0142] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk Solid State Disk (SSD)), etc.

[0143] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0144] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0145] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.

Claims

1. A key processing method, characterized in that: include: Performing a first split on the original key to obtain a key shard tuple set, wherein the key shard tuple set includes a plurality of key shard tuples; Based on a preset secret sharing algorithm, the key shard tuple set is converted into a key matrix, and the key matrix is ​​split for a second time to obtain N key matrix shards; In response to receiving a key acquisition request sent by a key user, k key matrix slices out of the N key matrix slices are sent to the key user; wherein N and k are both positive integers greater than 1, and N>k, k represents the threshold value of the preset secret sharing algorithm.

2. The method according to claim 1, characterized in that The original key is segmented to obtain a key segment tuple set, including: Divide the original key into m subkeys and convert each subkey into an integer; Using a predefined function cluster, the integer corresponding to each subkey is decomposed to obtain a set of key shard tuples.

3. The method according to claim 2, characterized in that The process of converting each subkey into an integer includes: Perform binary conversion on each subkey to obtain the binary form corresponding to each subkey; According to the large number algorithm, the binary form corresponding to each subkey is converted into an integer.

4. The method according to claim 1, characterized in that: The key sharding tuple set is converted into a key matrix based on a preset secret sharing algorithm, and the key matrix is ​​split for the second time to obtain N key matrix shards, including: Determine the secret sharing threshold of the preset secret sharing algorithm to be k and the total share to be N; Constructing a polynomial function corresponding to each key sharding tuple to obtain a set of polynomial functions corresponding to the set of key sharding tuples; Constructing a random number matrix, and using the elements in the random number matrix as coefficients of corresponding elements in the polynomial function set; The independent variables of each polynomial function in the polynomial function set are set to be integers between [1, N], and the function values ​​of each polynomial function are calculated; the function values ​​of each polynomial function are combined into a key matrix; The key matrix is ​​split for the second time to obtain N key matrix slices.

5. The method according to claim 4, characterized in that Determining the secret sharing threshold of the preset secret sharing algorithm as k and the total share as N includes: Determine that the secret sharing threshold of the preset secret sharing algorithm is k, the number of spare key fragments is h, and the total share is N, N=k+h, and h is a positive integer greater than or equal to 1.

6. The key processing method according to any one of claims 1 to 5, characterized in that: The step of sending k key matrix slices out of the N key matrix slices to the key user in response to receiving a key acquisition request sent by the key user comprises: In response to receiving a key acquisition request sent by a key user, acquiring k key matrix slices from the N key matrix slices; Using a random seed, randomizing the k key matrix slices to obtain k randomized key matrix slices; The k randomized key matrix slices are sent to the key user.

7. The method according to claim 2, characterized in that The method of using a random seed to perform random processing on the k key matrix slices to obtain k randomized key matrix slices includes: Generate a random number matrix using a random number seed, wherein the random number matrix is ​​a non-singular matrix; Slice the k key matrices into a first matrix, and calculate the product of the first matrix and the random number matrix to obtain a second matrix; The second matrix is ​​divided into k matrix slices, where the k matrix slices are k randomized key matrix slices.

8. A key reconstruction method, characterized in that: include: Receiving k key matrix slices sent by a key sender, and combining the k key matrix slices into a key matrix; Performing Lagrange interpolation on the key matrix to obtain a plurality of key shard tuples; The multiple key shard tuples are reconstructed to obtain the original key.

9. The method according to claim 8, characterized in that The reconstructing the multiple key shard tuples to obtain the key includes: Using a predefined function cluster, convert the plurality of key shard tuples into a plurality of integers; Convert the multiple integers to obtain an original key.

10. The method according to claim 8 or 9, characterized in that: The method further comprises: Concatenate the original key with a timestamp from the key sender to obtain a first sequence; Calculating a hash value of the first sequence; comparing the hash value of the first sequence with the hash value from the key sender; In the case where the hash value of the first sequence is the same as the hash value from the key sender, the original key is determined to be the correct key.

11. A key processing device, characterized in that: include: A first sharding module, used for performing a first sharding on the original key to obtain a key sharding tuple set, wherein the key sharding tuple set includes a plurality of key sharding tuples; A second sharding module is used to convert the key sharding tuple set into a key matrix based on a preset secret sharing algorithm, and perform a second sharding on the key matrix to obtain N key matrix shards; A key transmission module is used to send k key matrix slices out of the N key matrix slices to the key user in response to receiving a key acquisition request sent by the key user; wherein N and k are both positive integers greater than 1, and N>k, k represents the threshold value of the preset secret sharing algorithm.

12. A key reconstruction device, characterized in that: include: A matrix construction module, used for receiving k key matrix slices sent by a key sender, and forming a key matrix from the k key matrix slices; An interpolation module, used for performing Lagrange interpolation on the key matrix to obtain a plurality of key shard tuples; The reconstruction module is used to reconstruct the multiple key shard tuples to obtain the original key.

13. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, configured to implement the method according to any one of claims 1 to 10 when executing a program stored in a memory.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.

Citation Information

Patent Citations

  • Distributed key encryption method and device, electronic equipment and storage medium

    CN112084525A

  • Intel SGX trusted service clustering security deployment realization method and system

    CN114006741A

  • Data distributed storage method and system based on secret sharing technology

    CN119172077A

  • Safe and neutral digital currency intelligent contract implementation method

    CN119338462A

  • Haematococcus lacustris RLK with improved astaxanthin and unsaturated fatty acid production capacity due to drought stress and culture method thereof

    KR1020250139526A

Cited By

  • Large model security protection method and system based on double access matrixes and secret fragmentation

    CN121418089A