High-Security Group Key Agreement Method with Equal Load
Through the construction of a negotiation interaction model and a design key aggregation and multi-signature collaborative aggregation mechanism, the existing group key negotiation protocol is solved, and the existing group key negotiation protocol is large-scale distributed environments is achieved, and efficient and secure group key negotiation is achieved.
Patent Information
- Application Number
- CN202510466638.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-04-15
AI Technical Summary
The existing group key negotiation protocols have problems such as high resource consumption, low efficiency, high computational complexity, and lack of effective resistance mechanisms for key control attacks in large-scale distributed environments.
Through the difference set, the negotiation interaction model is built, the number of decryption operations of each user is fixed, and the key aggregation and multi-signature collaborative aggregation mechanism is designed to achieve group key negotiation with high load and security.
It reduces computing overhead, improves execution efficiency, can operate efficiently in a large-scale distributed environment, provides strong security guarantees for dynamic membership and multi-party collaboration, and avoids excessive resource consumption and single point of failure risk.
Smart Images

Figure CN120017271B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security, and particularly to a method for evenly load - high - security group key negotiation. Background Art
[0002] With the wide application of distributed systems and multi - party collaboration, secure and efficient data sharing has become an urgent problem to be solved. However, most current secure data sharing schemes rely on the Key Encapsulation Mechanism (KEM). Specifically, the KEM mechanism requires the data owner to encrypt the data with a symmetric key, encrypt the symmetric key with a public key, and then broadcast the encrypted key and data to the receiver together. Although this mechanism can achieve one - to - many data sharing, it has problems of high resource consumption and low efficiency in group data sharing. Especially when the number of users is large, the communication and computing overhead will increase significantly. Therefore, although the KEM mechanism can operate efficiently in small - scale sharing, it obviously cannot meet the requirements of high efficiency and security in large - scale distributed environments.
[0003] To address this problem, researchers have proposed Group Key Agreement (GKA). The GKA protocol aims to generate a shared session key through multi - party negotiation and ensure secure communication among multiple parties through this key. However, most existing GKA protocols rely on the broadcast interaction model. In the broadcast model, each user needs to broadcast its key information to all other users in each round of the protocol. With the increase in the number of users, the resulting communication and computing overhead grow exponentially, severely restricting the scalability and execution efficiency of the protocol. Especially in distributed systems, the computing power and network bandwidth of users may be limited, and the high overhead of the broadcast interaction model will seriously affect the practicality of the protocol. In addition, most existing KGA protocols adopt an unbalanced interaction mode, that is, a completely trusted manager is responsible for generating the session key and distributing it to other users. In this mode, the initiator or leader of the protocol undertakes more computing and communication tasks. Especially in distributed systems, the uneven distribution of resources may cause some nodes to be overloaded, thereby affecting the security and reliability of the entire system. That is to say, in GKA, if the leader is attacked or fails, the security of the entire protocol will be threatened. More importantly, this unbalanced interaction mode makes the computing burden of some users too heavy, especially in resource - limited environments, which may lead to the failure of protocol execution.
[0004] Moreover, in the GKA protocol, it is usually assumed that all users are fully trusted, that is, they will not deliberately disclose the session key or tamper with the execution process of the protocol. However, in practical applications, users are often semi-trusted, and some users are not completely honest. They may even tamper with the key generation process through key control attacks, thereby obtaining illegal session keys. This type of attack makes the protocol lose its security, and existing protocols generally lack an effective resistance mechanism against such attacks. In addition, existing GKA protocols also have the problem of too high computational complexity. The design of many protocols relies on complex mathematical structures, and the construction and calculation processes of these structures are relatively complex and do not support parallel execution. Although these structures have certain advantages in theory, their construction and calculation processes are often very complex, requiring users to handle large matrices or high-degree equations in each round of interaction. As the number of users increases, the computational and storage overheads show a large increase, resulting in a significant decrease in the execution speed of the protocol and the response time of the system. Especially in resource-constrained environments, users can hardly bear such high computational and storage burdens. Therefore, these protocols usually cannot make full use of the parallelism of distributed computing resources, thus limiting their application in large-scale distributed systems. Summary of the Invention
[0005] The embodiments of the present application provide a method for evenly loaded and highly secure group key negotiation. By constructing a negotiation interaction model through difference sets, not only the number of decryption operations of each user is fixed to a constant to reduce the computational overhead and improve the execution efficiency, but also it can operate efficiently in a large-scale distributed environment, providing a strong security guarantee for dynamic member multi-party collaboration.
[0006] In a first aspect, the embodiments of the present application provide a method for difference set extended group key negotiation, the method comprising:
[0007] Generating a difference set, and calculating a negotiation interaction model for each user in the blockchain based on the difference set. The negotiation interaction model defines the interaction objects of the user, and the number of interaction objects of each user is the same. Each user and all corresponding interaction objects in the negotiation interaction model are taken as a group. Among all groups, the number of times any two users appear together in different groups is a preset constant, where the interaction objects are other users in the blockchain;
[0008] Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform a first interaction and a second interaction. In the first interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user, and the receiver user aggregates all the encrypted private keys received to obtain a first aggregation value; in the second interaction, each sender user encrypts its own first aggregation value and sends it to the corresponding receiver user, and the receiver user aggregates all the encrypted first aggregation values received to obtain a second aggregation value, where the interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user;
[0009] Each user uses its own private key and the second aggregation value to obtain a group session key through a hash operation.
[0010] In a second aspect, an embodiment of the present application provides a method for evenly load group key negotiation, including:
[0011] Use the same method as in the first aspect to calculate a negotiation interaction model for each user in the blockchain;
[0012] Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform a third interaction and a fourth interaction. In the third interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user, and the receiver user aggregates all the encrypted private keys received to obtain a third aggregation value, and attaches a BLS signature to the third aggregation value to obtain a first signature value; in the fourth interaction, each sender user encrypts its own third aggregation value and sends it jointly with the first signature value to the corresponding receiver user, and the receiver user aggregates all the encrypted third aggregation values received to obtain a fourth encrypted aggregation value, and at the same time aggregates all the first signature values received to obtain a second signature value, where the interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user;
[0013] Each user verifies the second signature value, and after the verification passes, uses its own private key and the fourth aggregation value to obtain a group session key through a hash operation.
[0014] In a third aspect, an embodiment of the present application provides an electronic device, including a memory and a processor, where a computer program is stored in the memory, and the processor is configured to run the computer program to execute a difference set expansion group key negotiation method or an evenly load group key negotiation method.
[0015] In a fourth aspect, an embodiment of the present application provides a readable storage medium, where a computer program is stored in the readable storage medium, and the computer program includes program codes for controlling a process to execute a process, and the process includes a difference set expansion group key negotiation method or an evenly load group key negotiation method.
[0016] The main contributions and innovations of the present invention are as follows:
[0017] The embodiments of the present application construct a difference-set parallel distributed cluster interaction model. By means of the difference-set combinatorial mathematical structure, the confidentiality and integrity of multi-party interaction data in a distributed environment are guaranteed. At the same time, the SDR evolution mechanism is revealed to facilitate the rapid achievement of group key negotiation. The developed group key negotiation algorithm that supports parallel interaction defines serial and parallel interaction modes, avoiding excessive resource consumption and the risk of single-point failure. The designed key aggregation and multi-signature collaborative aggregation mechanism effectively prevents key control attacks, ensures fair and secure negotiation. It not only fixes the decryption operation times of each user to a constant to reduce the computational overhead and improve the execution efficiency, but also can operate efficiently in a large-scale distributed environment, providing a strong security guarantee for dynamic member multi-party collaboration.
[0018] The details of one or more embodiments of the present application are set forth in the following drawings and description to make the other features, objects, and advantages of the present application more comprehensible. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments and descriptions thereof of the present application are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0020] Figure 1 is a flowchart of a difference-set extended group key negotiation method according to an embodiment of the present application;
[0021] Figure 2 is a schematic diagram of a packet mapping table according to an embodiment of the present application;
[0022] Figure 3 is a schematic hardware structure diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0023] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with one or more embodiments of this specification. On the contrary, they are merely examples of devices and methods consistent with some aspects of one or more embodiments of this specification as detailed in the appended claims.
[0024] It should be noted that: In other embodiments, the steps of the corresponding method are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.
[0025] Embodiment 1
[0026] An embodiment of the present application provides a method for negotiating a differential set extended interactive group key. By constructing a negotiation interaction model through a differential set, not only can the decryption operation times of each user be fixed to a constant to reduce the computational overhead and improve the execution efficiency, but also it can operate efficiently in a large-scale distributed environment, providing a strong security guarantee for dynamic member multi-party collaboration. Specifically, referring to Figure 1 , the method includes:
[0027] Generate a differential set, and calculate a negotiation interaction model for each user in the blockchain based on the differential set. In the negotiation interaction model, the interaction objects of the user are defined, and the number of interaction objects of each user is the same. Each user and all corresponding interaction objects in the negotiation interaction model are used as a group. In all groups, the number of times any two users appear together in different groups is a preset constant, where the interaction objects are other users in the blockchain;
[0028] Generate a public-private key pair for each user in the blockchain, and use each user as the sending user to perform the first interaction and the second interaction. In the first interaction, each sending user encrypts its own private key and sends it to the corresponding receiving user, and the receiving user aggregates all the encrypted private keys received to obtain a first aggregation value; in the second interaction, each sending user encrypts its own first aggregation value and sends it to the corresponding receiving user, and the receiving user aggregates all the encrypted first aggregation values received to obtain a second aggregation value, where the interaction objects in the negotiation interaction model corresponding to the sending user are the corresponding receiving users;
[0029] Each user uses its own private key and the second aggregation value to obtain a group session key through a hash operation.
[0030] In some specific embodiments, during the process of generating the differential set, let α be the generator of the multiplicative group , and the integer set constitutes a cyclic difference set with parameters [q, m], where the trace function is defined as , and based on this, a combinatorial design with parameters can be obtained, where is the order of the difference set, and the parameters [q, m] are classical parameters in the projective set. are parameters of the combinatorial design.
[0031] Exemplarily, starting from an arbitrary initial state using the parameters PG(4, 2), i.e., m = 4 and q = 2, the calculated difference set is , and then based on the difference set D, a combinatorial interval design with parameters (15, 7, 3) is extended as shown in Table 1. This combinatorial interval design represents a grouping situation that satisfies the parameters (15, 7, 3), where 15 corresponds to the number of users in the blockchain, 7 corresponds to the number of users in each group, and 3 corresponds to the number of times any two users appear together in different groups.
[0032] Table 1 Combinatorial Interval Design with Parameters (15, 7, 3)
[0033]
[0034] That is to say, in the step of "calculating the negotiation interaction model for each user in the blockchain based on the difference set", the difference set is normalized to obtain a normal difference set, and the normal difference set is cyclically added bit by bit modulo based on the preset expansion parameters to obtain a grouping mapping table. Based on the grouping mapping table, negotiation interaction models are assigned to the users in the blockchain, where the expansion parameters include the number of users in the blockchain, the number of users in each group, and the number of times any two users appear together in different groups.
[0035] Specifically, the normalization operation is to change the first element in the difference set to 0, and the remaining elements are successively subjected to modulo addition operations. For example, there is a difference set , first calculate the additive inverse of the first element 5 modulo 15 as 10. Based on this, calculate the values of each element after modulo addition with 10 modulo 15: 6 + 10 (mod 15) = 1; 7 + 10 (mod 15) = 2; 9 + 10 (mod 15) = 4; 10 + 10 (mod 15) = 5; 13 + 10 (mod 15) = 8; 0 + 10 (mod 15) = 10. Then change the first element 5 to 0 to obtain the normalized normal difference set {0, 1, 2, 4, 5, 8, 10}.
[0036] Then, based on the expansion parameters, cyclic modulo addition operations are performed on the normal difference set to generate a grouping mapping table. The grouping mapping table is as Figure 2 shown. From Figure 2 , it can be seen that the generated grouping mapping table meets the SDR requirements. In Figure 2 , 0 - 14 respectively represent the users in the blockchain, and each row represents a group. And from Figure 2 , it can be seen that the number of users in each group and the number of times any two users appear together in different groups are both 3.
[0037] Specifically, this solution explores the applicable application of difference sets in the construction of distributed multi-party interaction models, reveals the evolution mechanism of the System of Distinct Representatives (SDR) in the construction of distributed multi-party interaction models, defines a method for constructing a distributed interaction model based on the extension of SDR, and effectively supports the rapid achievement of group key negotiation.
[0038] In some specific embodiments, the first interaction and the second interaction are performed in a serial interaction manner, that is, an interaction order is assigned to each sender user. In the first interaction, each sender user encrypts its own private key according to the interaction order and sends it to the corresponding receiver user. In the second interaction, each sender user encrypts its own first aggregation value according to the interaction order and sends it to the corresponding receiver user.
[0039] Exemplarily, the first interaction and the second interaction are serially performed using a serial interaction algorithm. In the first interaction, the algorithm traverses each user in the blockchain , and within the grouping mapping table for each element of each group , the elements in are updated to , that is , where j is from 1 to k - 1. That is to say, in the first interaction, each sender user's own private key is sequentially encrypted and sent to the corresponding receiver in a traversal manner, and then the receiver aggregates all the received encrypted private keys to obtain the first aggregation value. It is worth mentioning that the number of encrypted private keys received by each receiver is the number of group members minus one. That is to say, only when the number of encrypted private keys received by the receiver is the number of group members minus one, all the encrypted private keys are aggregated to obtain the first aggregation value.
[0040] In the second interaction, the encrypted first aggregation value of each sender user is sequentially sent to the corresponding receiver user by continuing to traverse. In the serial second interaction, the algorithm traverses each element in the grouping mapping table , and searches for the smallest positive integer such that , and uses this smallest positive integer to update the interaction model of user to complete the sending, where N is the number of users in the blockchain.
[0041] Specifically, since the grouping mapping table is constructed using a normalized difference set, it can be passed through The data is transmitted in the following way, and the formula of the serial interaction algorithm is as follows:
[0042] First interaction:
[0043] For i = 0 to N - 1, execute:
[0044] For j = 1 to k - 1, execute:
[0045] 1. 。
[0046] Second interaction:
[0047] For i = 1 to N - 1, execute:
[0048] For j = 1 to k - 1, execute:
[0049] 1. Find the smallest positive element , such that:
[0050] 。
[0051] 2. 。
[0052] In some specific embodiments, the first interaction and the second interaction are performed in a parallel interaction manner. That is, in the first interaction, all sender users simultaneously encrypt their own private keys and send them to the corresponding receiver users. In the second interaction, each sender user simultaneously encrypts its own first aggregation value and sends it to the corresponding receiver user.
[0053] Exemplarily, taking the parallel interaction algorithm to serially execute the first interaction and the second interaction, initialize the variable dis, and the value of dis is the current user's number i. In the first interaction, the parallel interaction algorithm traverses each element in D , calculate , and use the user corresponding to this index as the interaction model of the current user, so as to parallelly encrypt the own private key of each sender user and send it to the corresponding receiver, where D is the difference set, j ranges from 1 to k - 1, and k is the number of users in the group.
[0054] In the second interaction, the parallel interaction algorithm traverses each element in the difference set , and finds the smallest positive integer , such that , and use this smallest positive integer to update the interaction model of user 。
[0055] The formula of the parallel interaction algorithm is as follows:
[0056] First interaction:
[0057] 1. Set dis = 1;
[0058] 2. For j = 1 to k - 1, execute:
[0059]
[0060] Second interaction:
[0061] 3. For j = 1 to k - 1, execute:
[0062] (1) Find the smallest positive integer , such that:
[0063]
[0064] (2)
[0065] In some embodiments, given a security parameter , based on the security parameter generate a public-private key pair for each user in the blockchain , where is randomly selected from , , and g is the generator of the cyclic group G.
[0066] In some embodiments, in the first interaction, each sender encrypts its own private key through ElGamal, and the receiving user numbered receives the encrypted private key from . The form of the encrypted private key is, where sen is the index of the sender user, rec is the index of the receiving user, represents the random value selected by the sender user for the receiving user, is the sub-key of the sender user, is the public key of the receiving user.
[0067] Specifically, in the first interaction, each user in each group will receive the encrypted private keys of k - 1 users, where k is the number of users in the group. The formula for the receiving user to aggregate all the received encrypted private keys to obtain the first aggregation value is as follows:
[0068]
[0069] where g is the generator of the cyclic group G, represents the random value selected by the sender user for the receiving user, is the sub-key of the sender user, is the public key of the receiving user, i is the current user, is the sub - key of the current user, is the first aggregation value, is the private key of the current user.
[0070] In some embodiments, in the second interaction, the first aggregation value of each user is encrypted and sent to the corresponding receiving user. The user numbered receives the encrypted first aggregation value from . The form of the encrypted first aggregation value is . Each user in the group will receive the encrypted first aggregation values of k - 1 users. k is the number of users in the group. The formula for the receiving user to aggregate all the received encrypted first aggregation values to obtain the second aggregation value is as follows:
[0071]
[0072] where g is the generator of the cyclic group G, represents the random value selected by the sending user for the receiving user, is the encrypted first aggregation value of the sending user, is the public key of the receiving user, i is the current user, is the smallest positive integer of the current user, is the second aggregation value.
[0073] In some specific embodiments, the formula for each user to obtain the group session key through hash operation using its own private key and the second aggregation value is as follows:
[0074]
[0075] where, is the group session key of user i, is the user sub - key, SID is the session identifier, H is the hash operation. The reason for calculating the k - 2 power of is that the parameter calculation can be offset.
[0076] Specifically, in the key negotiation method through difference set expansion in this solution, each user only needs to transfer keys within the group, greatly reducing the total required computational amount and effectively supporting the rapid achievement of group key negotiation.
[0077] Embodiment 2
[0078] This application also proposes a method for evenly - loaded group key negotiation, including:
[0079] Using the same method as in the embodiment to calculate the negotiation interaction model for each user in the blockchain;
[0080] Generate a public-private key pair for each user in the blockchain, and use each user as the sender user to perform the third interaction and the fourth interaction. In the third interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user. The receiver user aggregates all the encrypted private keys received to obtain a third aggregation value, and attaches a BLS signature to the third aggregation value to obtain a first signature value. In the fourth interaction, each sender user encrypts its own third aggregation value and sends it to the corresponding receiver user jointly with the first signature value. The receiver user aggregates all the encrypted third aggregation values received to obtain a fourth encrypted aggregation value, and at the same time aggregates all the first signature values received to obtain a second signature value. Among them, the interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user;
[0081] Each user verifies the second signature value. After the verification passes, use its own private key and the fourth aggregation value to obtain the group session key through a hash operation.
[0082] Specifically, in the first embodiment, when the user is completely trusted and the transmitted message is authenticated, it has AKE security. To improve the security performance of the protocol, semi-trusted users are further considered. They may jointly modify the received sub-keys, resulting in the protocol being vulnerable to key control attacks by internal attackers. Therefore, the method of adding BLS signatures is used to avoid malicious attacks.
[0083] Specifically, the specific method for the receiver user to aggregate all the encrypted private keys received to obtain a third aggregation value and the method for the receiver user to aggregate all the encrypted third aggregation values received to obtain a fourth encrypted aggregation value are the same as those in the first embodiment, and will not be elaborated here.
[0084] Specifically, use bilinear mapping and hash function to perform BLS signatures, so as to resist malicious public key attacks.
[0085] Specifically, the signature calculation when attaching the BLS signature is:
[0086]
[0087] Let the set T be , and each receiver user aggregates all the BLS signatures received through . Among them, represents the BLS signature of user , and the initial value of is .
[0088] Specifically, the formula for aggregating all received first signature values to obtain a second signature value is as follows:
[0089]
[0090] Specifically, the second signature value is verified through the following formula:
[0091]
[0092] Specifically, the generation of the group session key and the same parameters in the above formula are the same as those in Embodiment 1, and will not be elaborated here.
[0093] Embodiment 3
[0094] This embodiment also provides an electronic device. Referring to Figure 3 , it includes a memory 404 and a processor 402. A computer program is stored in the memory 404, and the processor 402 is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0095] Specifically, the above processor 402 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured as one or more integrated circuits implementing the embodiments of the present application.
[0096] Among them, the memory 404 may include a mass storage 404 for data or instructions. By way of example and not limitation, the memory 404 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disc, a magneto-optical disc, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 404 may include removable or non-removable (or fixed) media. Where appropriate, the memory 404 may be internal or external to the data processing device. In a particular embodiment, the memory 404 is non-volatile memory. In a particular embodiment, the memory 404 includes a read-only memory (ROM) and a random access memory (RAM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these. Where appropriate, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended date out dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0097] The memory 404 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 402.
[0098] By reading and executing the computer program instructions stored in the memory 404, the processor 402 implements any one of the differential set expansion group key negotiation method and the equal load group key negotiation method in the above embodiments.
[0099] Optionally, the above electronic device may further include a transmission device 406 and an input / output device 408. Among them, the transmission device 406 is connected to the above processor 402, and the input / output device 408 is connected to the above processor 402.
[0100] The transmission device 406 can be used to receive or send data via a network. Specific examples of the above network may include a wired or wireless network provided by a communication provider of the electronic device. In one example, the transmission device includes a network adapter (abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one example, the transmission device 406 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0101] The input / output device 408 is used to input or output information. In this embodiment, the input information can be differential set parameters, public and private key pairs of each user, etc., and the output information can be a group session key, etc.
[0102] Optionally, in this embodiment, the above processor 402 can be set to execute the following steps by a computer program:
[0103] Generate a differential set, and calculate a negotiation interaction model for each user in the blockchain based on the differential set. The negotiation interaction model defines the interaction objects of the user, and the number of interaction objects of each user is the same. Each user and all corresponding interaction objects in the negotiation interaction model are used as a group. Among all groups, the number of times any two users appear together in different groups is a preset constant, where the interaction objects are other users in the blockchain;
[0104] Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform a first interaction and a second interaction. In the first interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user, and the receiver user aggregates all the encrypted private keys received to obtain a first aggregation value; in the second interaction, each sender user encrypts its own first aggregation value and sends it to the corresponding receiver user, and the receiver user aggregates all the encrypted first aggregation values received to obtain a second aggregation value, where the interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user.
[0105] Each user uses its own private key and the second aggregation value to obtain a group session key through a hashing operation.
[0106] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, and will not be elaborated herein.
[0107] Generally, various embodiments can be implemented in hardware or a dedicated circuit, software, logic, or any combination thereof. Some aspects of the present invention can be implemented in hardware, while other aspects can be implemented in firmware or software that can be executed by a controller, a microprocessor, or other computing devices, but the present invention is not limited thereto. Although the various aspects of the present invention can be shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, by way of non-limiting example, the blocks, devices, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, a dedicated circuit or logic, general hardware or a controller, or other computing devices, or some combination thereof.
[0108] Embodiments of the present invention can be implemented by computer software, which can be executed by a data processor of a mobile device, such as in a processor entity, or can be implemented by hardware, or by a combination of software and hardware. A computer software or program (also referred to as a program product), including software routines, applets, and / or macros, can be stored in any device-readable data storage medium, and they include program instructions for performing specific tasks. The computer program product can include one or more computer-executable components configured to perform the embodiments when the program runs. One or more computer-executable components can be at least one software code or a part thereof. Additionally, in this regard, it should be noted that any block in the logical flow, as Figure 3 shown, can represent a program step, or an interconnected logical circuit, block, and function, or a combination of a program step and a logical circuit, block, and function. The software can be stored on physical media such as a memory chip or a storage block implemented within a processor, magnetic media such as a hard disk or a floppy disk, and optical media such as, for example, a DVD and its data variants, a CD. The physical media is a non-transitory medium.
[0109] Those skilled in the art should understand that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0110] The above embodiments only represent several implementation manners of the present application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A difference set extended group key negotiation method, characterized in that: The following steps are involved: Generate a difference set, and calculate a negotiation interaction model for each user in the blockchain based on the difference set, wherein the negotiation interaction model defines the interaction objects of the user, and each user has the same number of interaction objects, and each user and all corresponding interaction objects in the negotiation interaction model are grouped as a group. In all groups, the number of times any two users appear together in different groups is a preset constant, wherein the interaction objects are other users in the blockchain; Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform the first interaction and the second interaction. In the first interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user. The receiver user aggregates all the encrypted private keys received to obtain a first aggregate value. The formula for the receiver user to aggregate all the encrypted private keys received to obtain the first aggregate value is as follows: Among them, g is the generator of the cyclic group G, represents a random value chosen by the sender user for the receiver user, is the subkey of the sending user, is the public key of the recipient user, i is the current user, is the subkey of the current user, is the first aggregate value, is the private key of the current user; in the second interaction, each sending user encrypts its own first aggregate value and sends it to the corresponding receiving user, and the receiving user aggregates all the received encrypted first aggregate values to obtain the second aggregate value, wherein the interaction object in the negotiation interaction model corresponding to the sending user is the corresponding receiving user, and the formula for the receiving user to aggregate all the received encrypted first aggregate values to obtain the second aggregate value is as follows: Among them, g is the generator of the cyclic group G, represents a random value chosen by the sender user for the receiver user, is the encrypted first aggregate value of the sending user, is the public key of the recipient user, i is the current user, is the minimum positive integer of the current user. is the second aggregate value; Each user uses its own private key and the second aggregate value to obtain the group session key through a hash operation. The formula for each user to obtain the group session key through a hash operation using its own private key and the second aggregate value is as follows: in, is the group session key of user i, SID is the session identifier, H is the hash operation, is the second aggregate value.
2. A difference set extended group key negotiation method according to claim 1, characterized in that: In the step of "calculating a negotiation interaction model for each user in the blockchain based on a difference set", the difference set is normalized to obtain a normal difference set, and the normal difference set is cyclically bitwise modulo-added based on a preset extended parameter to obtain a group mapping table, and a negotiation interaction model is assigned to the users in the blockchain based on the group mapping table, wherein the extended parameter includes the number of users in the blockchain, the number of users in each group, and the number of times any two users appear together in different groups.
3. A difference set extended group key negotiation method according to claim 1, characterized in that: The first interaction and the second interaction are performed in a serial interaction manner, that is, an interaction order is assigned to each sending user. In the first interaction, each sending user encrypts its own private key according to the interaction order and sends it to the corresponding receiving user. In the second interaction, each sending user encrypts its own first aggregate value according to the interaction order and sends it to the corresponding receiving user.
4. A difference set extended group key negotiation method according to claim 1, characterized in that: The first interaction and the second interaction are performed in a parallel interaction manner, that is, in the first interaction, all sending users simultaneously encrypt their own private keys and send them to the corresponding receiving users, and in the second interaction, each sending user simultaneously encrypts its own first aggregate value and sends it to the corresponding receiving user.
5. A load-balanced high-security group key negotiation method, characterized in that: include: Using the same method as in claim 1 to calculate a negotiation interaction model for each user in the blockchain; Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform the third interaction and the fourth interaction. In the third interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user. The receiver user aggregates all the received encrypted private keys to obtain a third aggregate value, and adds a BLS signature to the third aggregate value to obtain a first signature value. In the fourth interaction, each sender user encrypts its own third aggregate value and sends it to the corresponding receiver user in conjunction with the first signature value. The receiver user aggregates all the received encrypted third aggregate values to obtain a fourth encrypted aggregate value, and aggregates all the received first signature values to obtain a second signature value. The interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user. Each user verifies the second signature value, and after passing the verification, uses its own private key and the fourth aggregate value to obtain the group session key through a hash operation.
6. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to execute a difference set extended group key negotiation method as described in any one of claims 1 to 4 or a load-balanced high-security group key negotiation method as described in claim 5.
7. A readable storage medium, characterized in that: The readable storage medium stores a computer program, which includes a program code for controlling a process to execute a process, wherein the process includes a differential set extended group key negotiation method according to any one of claims 1 to 4 or a load-balanced high-security group key negotiation method according to claim 5.
Citation Information
Patent Citations
Data privacy fusion method and device
CN113468601A
Hazardous waste block chain supervision system and method based on group key agreement
CN114338016A