Key recovery method and device, computer equipment and storage medium
By dividing the master key into multiple key shares and obfuscating it, the security risks of traditional key management methods are solved, and higher information encryption security and legality of key use are achieved.
Patent Information
- Application Number
- CN202311762623.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-19
- Publication Date
- 2025-06-20
AI Technical Summary
Traditional key management methods have security risks and are easily stolen by attackers, resulting in insufficient security of information encryption.
By splitting the master key into multiple key shares and obfuscating each key share, storing and distributing it. After receiving the key recovery request, perform authentication, decrypt the key share, and restore the master key.
It increases the difficulty of attackers stealing full keys, provides an additional layer of protection, improves the security of information encryption, and prevents the illegal use of keys through authentication.
Smart Images

Figure CN120185801A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technologies, and particularly to a key recovery method, apparatus, computer device, storage medium, and computer program product. Background Art
[0002] With the development of computer technologies, cryptography technologies have emerged. Cryptography is a technical science that studies the compilation and deciphering of codes. The emergence of cryptography enables important information in electronic form to be encrypted and decrypted through keys, thereby realizing the encrypted storage and transmission of information and ensuring the security of information. However, in the traditional way of encrypting information, the information owner usually encrypts it with the key held by himself. Once the key is stolen, it is easy for the attacker to steal the information, so there are certain security risks. Summary of the Invention
[0003] Based on this, it is necessary to provide a key recovery method, apparatus, computer device, computer-readable storage medium, and computer program product that can improve information security for the above technical problems.
[0004] In a first aspect, the present application provides a key recovery method, including:
[0005] Authenticating the source of the key recovery request when receiving the key recovery request;
[0006] Extracting and storing the obfuscated key shares in the key recovery request when the authentication is passed;
[0007] Determining a preset decryption method corresponding to the obfuscated key shares when the number of stored obfuscated key shares reaches a first number;
[0008] Decrypting each obfuscated key share according to the preset decryption method to obtain key shares;
[0009] Recovering a master key based on the first number of key shares.
[0010] In a second aspect, the present application further provides a key recovery apparatus, including:
[0011] An authentication module, configured to authenticate the source of the key recovery request when receiving the key recovery request;
[0012] An extraction module, configured to extract and store the obfuscated key shares in the key recovery request when the authentication is passed;
[0013] A determination module, configured to determine a preset decryption method corresponding to the obfuscated key shares when the number of stored obfuscated key shares reaches a first number;
[0014] A decryption module, configured to decrypt each obfuscated key share according to the preset decryption method to obtain key shares;
[0015] A recovery module, configured to perform key recovery based on the first number of key shares to obtain a master key.
[0016] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the key recovery method are implemented.
[0017] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the key recovery method are implemented.
[0018] In a fifth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the key recovery method are implemented.
[0019] For the above key recovery method, device, computer device, storage medium, and computer program product, when a key recovery request is received, the source party of the key recovery request is authenticated. If the authentication is passed, the obfuscated key shares in the key recovery request are extracted and stored. When the number of stored obfuscated key shares reaches a first number, a preset decryption method corresponding to the obfuscated key shares is determined, and then each obfuscated key share is decrypted according to the preset decryption method to obtain key shares, so that key recovery can be performed based on the first number of key shares to obtain a master key. That is to say, in the present application, the master key is split into multiple key shares. In this way, even if a part of the key shares are stolen, the attacker cannot obtain the complete key, which increases the difficulty for malicious attackers to steal the complete key. At the same time, by obfuscating each key share, an additional protection layer is further provided for the master key. Even if the key shares are exposed, it is very difficult to restore the original master key, which can greatly improve the security of information encryption. Moreover, when the present application receives a key recovery request, by verifying the legality of the identity, the illegal use of the key can be prevented, further ensuring information security. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] To more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or related technologies. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0021] Figure 1 It is an application environment diagram of the key recovery method in an embodiment;
[0022] Figure 2 It is a schematic flowchart of the key recovery method in an embodiment;
[0023] Figure 3 It is a schematic flowchart of the steps of confusing key share distribution in an embodiment;
[0024] Figure 4 It is a schematic diagram of the principle of key share confusion in an embodiment;
[0025] Figure 5 It is a schematic diagram of the principle of key share confusion in another embodiment;
[0026] Figure 6 It is a schematic diagram of confusing key share distribution in an embodiment;
[0027] Figure 7 It is a schematic flowchart of the steps of extracting and storing the confusing key share in the key recovery request when the authentication is passed in an embodiment;
[0028] Figure 8 It is a schematic flowchart of the key recovery method in another embodiment;
[0029] Figure 9 It is a structural block diagram of the key recovery device in an embodiment;
[0030] Figure 10 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0031] In order to make the objectives, technical solutions and advantages of the present application clearer, the following further details the present application in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0032] The key recovery method provided by the embodiments of the present application can be applied to, for example Figure 1In the application environment shown. Among them, the terminal 102 communicates with the computer device 104 through the network. The data storage system can store the data that the computer device 104 needs to process. The data storage system can be integrated on the computer device 104, or can be placed in the cloud or other network servers. The terminal 102 sends a key recovery request to the computer device 104. When the computer device 104 receives the key recovery request, it authenticates the source of the key recovery request; when the authentication is passed, it extracts and stores the obfuscated key share in the key recovery request; when the number of stored obfuscated key shares reaches the first number, it determines the preset decryption method corresponding to the obfuscated key share; decrypts each obfuscated key share according to the preset decryption method to obtain the key share; performs key recovery based on the first number of key shares to obtain the master key.
[0033] Among them, the terminal 102 can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices (such as vehicle terminals), etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The computer device 104 can be a terminal or a server. Among them, the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, and this application does not make any restrictions here.
[0034] The key recovery method in this application can be executed through a smart contract, and the smart contract can be a smart contract deployed on a blockchain. Among them, the blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. Blockchain, essentially a decentralized database, is a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity (anti-counterfeiting) of the information and generate the next block. The blockchain can include the blockchain underlying platform, the platform product service layer, and the application service layer.
[0035] The underlying blockchain platform may include processing modules such as user management, basic services, smart contracts, and operation monitoring. Among them, the user management module is responsible for the identity information management of all blockchain participants, including maintaining the generation of public and private keys (account management), key management, and the maintenance of the correspondence between the real identity of the user and the blockchain address (permission management). And under authorization, it supervises and audits the transaction situations of certain real identities, and provides the rule configuration for risk control (risk control audit); the basic service module is deployed on all blockchain node devices to verify the validity of business requests, and after reaching a consensus on valid requests, records them on the storage. For a new business request, the basic service first performs interface adaptation parsing and authentication processing (interface adaptation), then encrypts the business information through a consensus algorithm (consensus management), transmits it intact and consistently to the shared ledger after encryption (network communication), and performs record storage; the smart contract module is responsible for the registration and issuance of contracts, as well as contract triggering and contract execution. Developers can define contract logic through a certain programming language, publish it to the blockchain (contract registration), and trigger the execution by calling keys or other events according to the logic of the contract terms to complete the contract logic. At the same time, it also provides functions for contract upgrade and cancellation; the operation monitoring module is mainly responsible for the deployment, configuration modification, contract setting, cloud adaptation during the product release process, and the visual output of the real-time status during product operation, such as: alarming, monitoring the network situation, monitoring the health status of node devices, etc.
[0036] The platform product service layer provides the basic capabilities and implementation frameworks of typical applications. Developers can build on these basic capabilities and overlay the characteristics of the business to complete the blockchain implementation of the business logic. The application service layer provides application services based on the blockchain solution for business participants to use.
[0037] In an exemplary embodiment, as Figure 2 shown, a key recovery method is provided. Taking the computer device in Figure 1 as an example for illustration, it includes the following steps 202 to 210. Among them:
[0038] Step 202, when receiving a key recovery request, authenticate the source party of the key recovery request.
[0039] Among them, the key recovery request is a request for recovering the master key. Specifically, when the computer device receives a key recovery sent by the terminal, it can authenticate the source party of the key recovery request to confirm whether the source party of the key recovery request is a party participating in saving the obfuscated key share. If so, it means that the current key recovery request is legal. Otherwise, the computer device can not respond to the key recovery request to prevent the illegal use of the master key and ensure information security.
[0040] In some embodiments, the computer device may receive one key recovery request at a time, or may receive multiple key recovery requests at a time. Different key recovery requests may come from the same source party or from different source parties. The embodiments of the present application do not limit this.
[0041] In some embodiments, when any participating party determines that the condition is met, it may initiate a key recovery request based on the obfuscated key share it stores itself. In some embodiments, the participating party may encrypt the obfuscated key share it stores itself with its own participating party public key and send the encrypted result to the computer device to request the recovery of the master key.
[0042] In some embodiments, the computer device may authenticate the source party of the key recovery request in the following manner: The computer device extracts the data carried in the key recovery request, and this data includes encrypted data and a source party identifier. Search for the source party identifier in the participating party identifier list. If a participating party identifier that matches the source party identifier is found, obtain the participating party public key based on the found participating party identifier; decrypt the encrypted data with the participating party public key. If the decryption is successful, it is determined that the authentication is passed.
[0043] Among them, the source party identifier is used to uniquely identify the initiator of the key recovery request. Specifically, it may be the terminal identifier or account identifier of the initiator of the key recovery request, etc., and can usually be represented by letters, words, numbers, or strings, etc. A participating party refers to the object that receives the obfuscated key share during the previous distribution of the obfuscated key share. The participating party identifier list is a list composed of the participating party identifiers of all participating parties. The participating party identifier is used to uniquely identify the participating party, and can specifically be letters, words, numbers, or strings, etc.
[0044] Specifically, the computer device can extract the source party identifier from the key recovery request, and then, by looking up the table, determine whether this source party identifier exists in the participating party identifier list. If it exists, it is determined that there is a match, and then the participating party public key can be obtained based on the successfully matched participating party identifier.
[0045] In some embodiments, the computer device may pre-store the participating party public keys corresponding to each participating party respectively. These participating party public keys may be the keys publicly disclosed by the participating parties or the keys transmitted by the participating parties to the computer device through a trusted communication environment.
[0046] In some embodiments, the computer device may associate and store the participating party identifier and the participating party public key of each participating party in the form of a table or a database, and then, in a scenario where legal verification is required, obtain the participating party public key according to the participating party identifier.
[0047] Further, the computer device can decrypt the encrypted data with the participant public key. If the decryption is successful, it indicates that the encrypted data is encrypted based on the participant private key of the participant, that is, it is sent by a legitimate participant. Therefore, the source party can be considered to have passed the authentication.
[0048] In the above embodiment, authenticating the source party of the key recovery request with the participant public key can ensure the authenticity and reliability of the source of the master key to be recovered, avoid malicious behavior, and further enhance the security of the master key usage.
[0049] In some embodiments, the computer device can also use other methods to authenticate the source party, as long as it can prove the legitimacy of the source party's identity. The embodiments of the present application do not limit this. For example: The computer device can detect whether there is a preset credential in the key recovery request. If it exists, it indicates that the source party has passed the verification. If it does not exist, it indicates that the source party has not passed the verification. The preset credential is a credential pre-agreed between the participant and the computer device to prove the identity of the participant. Also for example: The computer device can extract the source party identifier from the key recovery request. If the source party identifier exists in the participant identifier list, it indicates that the source party has passed the verification. If it does not exist, it indicates that the source party has not passed the verification.
[0050] In some embodiments, the key recovery method of the present application can be executed by a smart contract deployed on a computer device. A smart contract is a computer protocol designed to spread, verify, or execute a contract in an information-based manner. Smart contracts allow for trusted transactions without a third party, and these transactions are traceable and irreversible. Generally speaking, a smart contract is a set computer program that can automatically execute the content of a trusted contract without the participation of a third-party intermediary institution, and all operations are publicly available and irreversible.
[0051] The conclusion process of the smart contract includes: After the participants participating in the conclusion agree, they jointly formulate a smart contract; the smart contract is broadcast and stored to the fulcrums of each blockchain globally through the blockchain network; the successfully constructed smart contract waits for the conditions to be met and then automatically executes the contract content.
[0052] In some embodiments, a smart contract can be pre-deployed in a computer device (such as a smart contract platform). The smart contract has the ability to authenticate the source party and decrypt the obfuscated key share, and will automatically execute the contract content after the master key is reconstructed. When the smart contract is a contract for resource transfer, the corresponding contract content is to automatically transfer resources.
[0053] Step 204, when the authentication is passed, extract the obfuscated key share in the key recovery request and store it.
[0054] Specifically, when the authentication is passed, the computer device can directly extract the obfuscated key share carried in the key recovery request and store it in a preset storage space. The preset storage space can be a space dedicated to storing obfuscated key shares, which can specifically be a cache queue, a table, a database, or other forms of storage spaces, etc. The embodiments of the present application do not limit this.
[0055] Step 206: When the number of stored obfuscated key shares reaches a first number, determine a preset decryption method corresponding to the obfuscated key shares.
[0056] It can be understood that whenever the computer device receives a key recovery request, it will authenticate the source of the key recovery request. When the authentication is passed, it will extract the obfuscated key share in the key recovery request for storage. In this way, as the number of received key recovery requests that pass the authentication continuously increases, correspondingly, the number of obfuscated key shares stored in the preset storage space also continuously increases.
[0057] When the computer device determines that the number of obfuscated key shares stored in the preset storage space reaches the first number, it can determine the preset decryption method corresponding to the obfuscated key shares. The first number is the minimum number required to reconstruct the master key.
[0058] In some embodiments, after splitting a master key into multiple key shares in advance, different encryption methods are used to process different key shares to obtain obfuscated key shares. Therefore, for each different obfuscated key share, there is a corresponding preset decryption method, and they are all different from each other.
[0059] In some embodiments, after splitting a master key into multiple key shares in advance, the same encryption method is used to process different key shares to obtain obfuscated key shares. Therefore, for each different obfuscated key share, the same preset decryption method is corresponding.
[0060] In some embodiments, when the computer device encrypts the key shares, a preset obfuscation function is used for encryption. Therefore, in the decryption process, an inverse obfuscation function opposite to the preset obfuscation function can be used for decryption.
[0061] Step 208: Decrypt each obfuscated key share according to the preset decryption method to obtain key shares.
[0062] In some embodiments, after splitting a master key into multiple key shares in advance, different encryption methods are used to process different key shares to obtain obfuscated key shares. Therefore, for each different obfuscated key share, there is a corresponding preset decryption method, and they are all different from each other.
[0063] Furthermore, for any obfuscated key share, the computer device can use the preset decryption method that matches the obfuscated key share to decrypt the obfuscated key share to obtain the key share. In this way, after all the first number of obfuscated key shares are decrypted, the first number of key shares will be obtained.
[0064] In some embodiments, after splitting a master key into multiple key shares in advance, the same encryption method is used to process different key shares to obtain obfuscated key shares. Therefore, for each different obfuscated key share, there is the same preset decryption method.
[0065] Furthermore, for all the obfuscated key shares, the computer device can use the same preset decryption method to decrypt the obfuscated key shares to obtain the key shares. In this way, after all the first number of obfuscated key shares are decrypted, the first number of key shares will be obtained.
[0066] In some embodiments, when the computer device encrypts the key share, a preset obfuscation function is used for encryption. Therefore, in the decryption process, the inverse obfuscation function opposite to the preset obfuscation function can be used for decryption. The preset obfuscation function is, for example, the exclusive OR function, and the inverse obfuscation function is, for example, the reverse exclusive OR function.
[0067] In some embodiments, when the computer device encrypts the key share, shifting or transposition operations can be used for encryption. Therefore, in the decryption process, the obfuscated key share can be decrypted by performing reverse shifting or reverse transposition on it.
[0068] Step 210, perform key recovery based on the first number of key shares to obtain the master key.
[0069] Specifically, when the number of stored key shares reaches the first number, the computer device can perform key reconstruction based on the first number of key shares through interpolation to obtain the master key. In some embodiments, the computer device can calculate based on k key shares through the Lagrange interpolation formula to obtain the master key. In other embodiments, the computer device can use the difference interpolation method and calculate based on k key shares to obtain the master key.
[0070] It should be noted that the multiple key shares can be obtained by processing the master key in the following way in advance:
[0071] A computer device or a smart contract deployer can construct a polynomial of degree k-1, with the master key as the constant term. The polynomial of degree k-1 is as follows: ; where s is the master key, a 1、 a2……a k-1 are the coefficients of the polynomial, P is a prime number, and mod(P) is the modulo operation with respect to P. The computer device can substitute N different x values into F(x) to obtain N sets of key shares [x1, F(x1)], [x2, F(x2)]... [x N , F(x N )], and distribute these N sets of key shares to N participants for their respective custody.
[0072] After the computer device obtains k key shares, it can construct the following polynomial: , which is a transformation of the above polynomial. Here, x i is the x value in the i-th set of key shares, y i is the value of F(x i ) in the i-th set of key shares, and x j is the x value in the j-th set of key shares.
[0073] Furthermore, the computer device can take x = 0 and substitute the k key shares into this polynomial respectively to solve for F(0), which is the value of the master key.
[0074] In some embodiments, the computer device can also generate a second number of key shares through other means based on the master key, and then reconstruct the first number of key shares to obtain the master key through a reconstruction method matching the key share generation method. For example, the computer device can generate a second number of key shares based on the master key through Shamir secret sharing (a threshold secret sharing technique), Blakley secret sharing (a threshold secret sharing technique), or CRT (Chinese Remainder Theorem) secret sharing, etc., and then reconstruct the master key based on k key shares through a reconstruction method matching the key share generation method.
[0075] The above key recovery method authenticates the source of the key recovery request when receiving the key recovery request. If the authentication is passed, the obfuscated key shares in the key recovery request are extracted and stored. When the number of stored obfuscated key shares reaches the first number, the preset decryption method corresponding to the obfuscated key shares is determined, and then each obfuscated key share is decrypted according to the preset decryption method to obtain the key shares. Thus, the master key can be recovered based on the first number of key shares. That is to say, in this application, the master key is split into multiple key shares. In this way, even if some key shares are stolen, the attacker cannot obtain the complete key, which increases the difficulty for malicious attackers to steal the complete key. At the same time, by obfuscating each key share, an additional protection layer is further provided for the master key. Even if the key share is exposed, it is very difficult to restore the original master key, which can greatly improve the security of information encryption. Moreover, when receiving the key recovery request, this application can prevent the illegal use of the key by verifying the legitimacy of the identity, further ensuring information security.
[0076] Continuing from the above, before receiving the key recovery request, the master key needs to be split into multiple key shares in advance, and the key shares are obfuscated to obtain obfuscated key shares. The obfuscated key shares are distributed to multiple participating parties for custody. When the master key needs to be reconstructed, the terminal can initiate a key recovery request to the computer device. It should be noted that the steps of key splitting, obfuscation, and distribution can specifically be executed by the computer device in this application, or can also be executed by other computer devices. The embodiments of this application do not limit this. Taking the computer device in this application as an example to execute the steps of key splitting, obfuscation, and distribution, the following is a detailed description:
[0077] In some embodiments, the method further includes the step of distributing obfuscated key shares, and this step specifically includes:
[0078] Step 302, obtain the master key and generate the second number of key shares based on the master key.
[0079] Among them, the master key is the key used to encrypt the data that needs to be protected to prevent the data that needs to be protected from being leaked or stolen. Among them, the data that needs to be protected can specifically be media data, session messages, voice data, or digital assets, etc.
[0080] In some embodiments, the master key can specifically be the wallet key of an electronic wallet. The electronic wallet can specifically be a digital wallet or a software wallet, which is used to store resources in electronic form. In other embodiments, the master key can specifically be a key related to the actual business, such as a user private key, or a symmetric key used for data storage and transmission, etc. The embodiments of this application do not limit this.
[0081] Specifically, the computer device can generate the master key by itself or receive the master key transmitted by other computer devices. Furthermore, the computer device can generate a second number of distinct key shares based on the master key, where at least k key shares can be used to recover the master key.
[0082] In some embodiments, the wallet creator can generate a digital wallet, set a wallet key, and transmit the wallet key to the computer device today. The computer device can use the received wallet key as the master key.
[0083] Furthermore, the computer device can construct a polynomial of degree k - 1, with the master key as the constant term, as shown in the following formula: ; where s is the master key, a 1、 a2……a k-1 are the coefficients of the polynomial, and P is a prime number. The computer device can substitute N different x values into F(x) to obtain N groups of key shares, and distribute these N groups of key shares to N participants for their respective custody.
[0084] Of course, the computer device can also generate multiple key shares based on the master key through other methods, such as through Blakley (a threshold secret sharing technique) secret sharing or CRT (Chinese Remainder Theorem) secret sharing, etc. The embodiments of the present application do not limit this.
[0085] Step 304: Determine the noise data, and encrypt each key share with the noise data to obtain a second number of obfuscated key shares.
[0086] Among them, the noise data can specifically be preset fixed noise or random noise, such as preset values, preset symbols, random values, random symbols, etc.
[0087] In the process of encrypting the key shares with the noise data, the computer device can determine the noise data respectively matching each key share. Specifically, the computer device can use different noise data for different key shares for obfuscation to obtain obfuscated key shares. Or, the same noise data is used for different key shares for obfuscation to obtain obfuscated key shares. Or, some key shares are obfuscated with the same noise data, and some key shares are obfuscated with different noise data. The embodiments of the present application do not limit this.
[0088] In some embodiments, after the computer device determines the noise data that matches each key share, it can determine the confusion method corresponding to each key share, and encrypt the key share and the noise data through the corresponding confusion method to obtain the confused key share. Specifically, the computer device can use different confusion methods for different key shares to perform confusion and obtain the confused key share. Or, the same confusion method is used for different key shares to perform confusion and obtain the confused key share. Or, some key shares are confused with the same confusion method, and some key shares are confused with different confusion methods. In this regard, the embodiments of the present application do not make any limitations.
[0089] Exemplarily, for N key shares, the computer device can use the same noise data and the same confusion method to encrypt the N key shares to obtain N confused key shares.
[0090] Exemplarily, for N key shares, the computer device can use the same noise data and different confusion methods to encrypt the N key shares to obtain N confused key shares.
[0091] For example, for key share 1, the computer device can use noise data Z and confusion method 1 to encrypt the key share to obtain confused key share 1; for key share 2, the computer device can use noise data Z and confusion method 2 to encrypt the key share to obtain confused key share 2,..., for key share n, the computer device can use noise data Z and confusion method n to encrypt the key share to obtain confused key share n (n is a natural number less than or equal to N).
[0092] Exemplarily, for N key shares, the computer device can use different noise data and the same confusion method to encrypt the N key shares to obtain N confused key shares.
[0093] For example, for key share 1, the computer device can use noise data 1 and confusion method H to encrypt the key share to obtain confused key share 1; for key share 2, the computer device can use noise data 2 and confusion method H to encrypt the key share to obtain confused key share 2,..., for key share n, the computer device can use noise data n and confusion method H to encrypt the key share to obtain confused key share n (n is a natural number less than or equal to N).
[0094] Exemplarily, for N key shares, the computer device can use different noise data and different confusion methods to encrypt the N key shares to obtain N confused key shares.
[0095] For example, for key share 1, the computer device may use noise data 1 and scrambling method 1 to encrypt the key share, obtaining scrambled key share 1; for key share 2, the computer device may use noise data 2 and scrambling method 2 to encrypt the key share, obtaining scrambled key share 2, ……, for key share n, the computer device may use noise data n and scrambling method n to encrypt the key share, obtaining scrambled key share n (n is a natural number less than or equal to N).
[0096] In some embodiments, the way the computer device encrypts the key share may specifically be by inserting the noise data into the key share. For example, for key share n, the computer device may add the noise data matching it to a preset position of key share n to obtain the scrambled key share. Among them, the preset position may be a fixed position or a position satisfying a preset rule.
[0097] Exemplarily, for any key share, the computer device may scramble the key share with the noise data matching the key share to obtain the scrambled key data. Among them, the scrambling methods corresponding to different key shares may be the same or different.
[0098] For example, the computer device may perform the following processing on all key shares:
[0099] In some embodiments, referring to Figure 4 , the computer device inserts the noise data matching the key share into a fixed position of the key share to obtain the scrambled key share. As in Figure 4 , the noise data matching the key share is inserted between the second data block and the third data span of the key share.
[0100] In some embodiments, referring to Figure 5 , the computer device may sort the key shares, determine the insertion positions corresponding to different key shares according to the sorting order, and then insert the noise data matching each key share into the corresponding insertion position. Among them, the insertion positions determined according to the sorting order may be distributed in an arithmetic queue, or distributed according to other mathematical rules, or not distributed regularly, etc., and the embodiments of the present application do not limit this. For example Figure 5 the insertion position in
[0101] Step 306, transfer the second quantity of scrambled key shares to the second quantity of participants; wherein, each participant stores one of the scrambled key shares.
[0102] Please refer to Figure 6, the computer device can transfer the second quantity of obfuscated key shares to the second quantity of participants, and each participant stores one of the obfuscated key shares.
[0103] In some embodiments, the computer device can distribute the obfuscated key shares through a network security channel or a preset security protocol. Alternatively, a hardware device can also be used to distribute the obfuscated key shares. Each obfuscated key share is stored in a different hardware device, such as a USB token, and then the hardware devices are distributed to different participants.
[0104] In some embodiments, the computer device can transfer the obfuscated key shares in the following manner, that is, any obfuscated key share can be transferred in the following manner: receiving the key-encrypted data sent by the participant; the key-encrypted data is obtained by encrypting the first shared key with the participant's private key; decrypting the key-encrypted data with the participant's public key to obtain the first shared key; encrypting the obfuscated key share with the first shared key and transferring the encrypted obfuscated key share to the participant.
[0105] Specifically, before transferring the obfuscated key shares, the participant and the computer device can agree on a shared key for encrypting the obfuscated key shares, that is, the first shared key, to ensure the security of the transmission of the obfuscated key shares. The participant can generate a symmetric key, use the symmetric key as the first shared key, and then transmit the symmetric key to the computer device through a secure transmission method.
[0106] In some embodiments, the participant can generate a symmetric key through an encryption algorithm and encrypt the symmetric key with its own participant private key to obtain key-encrypted data. Then, the key-encrypted data is sent to the computer device. The computer device decrypts the key-encrypted data with the participant's public key to obtain the symmetric key, and uses the symmetric key as the first shared key. Then, the computer device can use the first shared key to encrypt the obfuscated key share and send the encrypted obfuscated key share to the participant.
[0107] It should be noted that each participant can negotiate a shared key with the computer device. When the computer device distributes the obfuscated key shares, it can encrypt the obfuscated key shares with the corresponding shared key and then distribute them, which can ensure the security of the distribution of the obfuscated key shares. Of course, it is also possible for multiple participants to share a single shared key. When the computer device distributes the obfuscated key shares, it encrypts them with the same shared key and then distributes them, avoiding the non-participants from obtaining the obfuscated key shares and also ensuring the security of the transmission process of the obfuscated key shares.
[0108] In the above embodiments, the first shared key can be transmitted through the private key of the participant, and then the obfuscation key share can be securely transmitted through the first shared key, which can ensure the security of the obfuscation key share transmission process and avoid potential security risks such as leakage or theft of the obfuscation key share.
[0109] In some embodiments, the computer device can also distribute the obfuscation key share through quantum key distribution. The specific steps are as follows: obtain a random bit string, for any bit value in the random bit string, randomly select a polarization basis, and encode the targeted bit value according to the selected polarization basis to obtain quantum bits; send each quantum bit to the participant to instruct the participant to measure each quantum bit based on the randomly selected polarization basis to obtain the measurement results of each quantum bit; obtain the polarization bases selected by the participant, and match the locally selected polarization bases with the polarization bases selected by the participant to determine the successfully matched polarization bases; determine the second shared key based on the bit values corresponding to the successfully matched polarization bases; encrypt the obfuscation key share with the second shared key and transmit the encrypted obfuscation key share to the participant.
[0110] Specifically, the computer device can utilize the properties of quantum mechanics to achieve secure distribution of the obfuscation key share. The core idea is that certain properties of the quantum system are disturbed when measured, so any third party attempting to intercept or measure will inevitably disrupt the state of the quantum bits in transmission, and this interference can be detected by the sender and receiver of the key.
[0111] The computer device can select a random bit string as the original information, randomly select a polarization basis (e.g., rectangular basis or diagonal basis) within a preset range for each bit value in the random bit string, and encode the bit value with the selected polarization basis.
[0112] For example, if the random bit string has m bit values, such as A1A2A3A4…A m , then for each bit value, a polarization basis will be randomly selected to encode the bit value to obtain a quantum bit. These m polarization bases can be represented as: sequence L1L2L3L4……L m ; the m quantum bits can be represented as: B1B2B3B4…B m .
[0113] Furthermore, the computer device can send each quantum bit (i.e., the encoded bit data, whose manifestation form can be a photon in a polarization state) to the participant.
[0114] After receiving each quantum bit, the participant randomly selects a polarization basis to measure it. The participant records the measurement results and the polarization bases used for each quantum bit, which can be denoted as sequence l1l2l3l4……lm 。
[0115] The computer device and the participating party disclose the polarization bases they use, but do not disclose the actual bit values. In this way, the computer device can, according to the polarization base sequence l1l2l3l4... l m disclosed by the participating party, compare it with the polarization base sequence L1L2L3L4... L m selected locally by itself. If the polarization bases at the same serial number are the same, it is considered that the polarization bases corresponding to this serial number are successfully matched. Furthermore, the computer device can filter out the bit values corresponding to the serial numbers of the successfully matched polarization bases, discard the bit values with unmatched polarization bases, and then construct a second shared key based on the filtered bit values. Specifically, the filtered bit values can be combined to form a shared key. Then, the key share is encrypted and obfuscated through this shared key to achieve the secure transmission of the key share.
[0116] In the above embodiment, a shared key is agreed with the participating party through the quantum key distribution method, and then the key share is encrypted based on the shared key for the encrypted transmission of the key share, which can ensure the security of the key share transmission process and avoid potential security risks such as the leakage or theft of the key share.
[0117] Furthermore, determining the second shared key based on the bit values corresponding to the successfully matched polarization bases includes: taking the bit values corresponding to the successfully matched polarization bases as target bit values; disclosing some of the target bit values and obtaining some data disclosed by the participating party; if the some bit values disclosed locally are consistent with the some data disclosed by the participating party, determining the shared key based on the target bit values, otherwise discarding the target bit values and returning to the step of obtaining a random bit string to continue execution until the second shared key is obtained and then stopping.
[0118] In some embodiments, to detect the risk of information leakage, the computer device and the participating party can disclose some of the target bit values and compare them. If the disclosed bit values match successfully, it is very likely that there is no risk of information leakage; if there are unmatched bit values, it indicates that there may be information leakage. If there is information leakage, the step of obtaining a random bit string can be returned to continue execution to obtain a secure shared key again. In this way, by disclosing some bit values to determine whether there is a risk of information leakage and retaining the shared key for subsequent encryption of the key share in the absence of information leakage, the security of the key share encryption transmission process can be further ensured.
[0119] It can be understood that in the above embodiments, the computer device is used as the sender and the participating party is used as the receiver to negotiate the shared key. In actual applications, the computer device can be used as the receiver and the participating party can be used as the sender to negotiate the shared key. The embodiments of the present application do not limit this.
[0120] It can be understood that the terms "first", "second", etc. used in the present application can be used in this document to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from another element. For example, without departing from the scope of the present application, the first shared key can be referred to as the second shared key.
[0121] In the above embodiments, the master key is pre-divided into a second number of key shares, and then each key share is encrypted with noise data to obtain a second number of confused key shares. Furthermore, the second number of confused key shares are distributed to the second number of participating parties, so that each participating party stores its own confused key share. When the master key needs to be restored, at least k confused key shares can be provided to restore the master key. Even if some participating parties lose their confused key shares, the master key can still be restored, which is more flexible.
[0122] In some embodiments, the method further includes the step of storing configuration data, specifically including recording the correspondence between the confused key shares and the noise data, and the correspondence between the confused key shares and the participating parties to obtain configuration data; and saving the configuration data.
[0123] Specifically, after the computer device obtains the second number of confused key shares, it can establish the correspondence between the confused key shares and the noise data, and establish the correspondence between the confused key shares and the participating parties. Furthermore, based on the correspondence between the confused key shares and the noise data, and the correspondence between the confused key shares and the participating parties, configuration data is obtained and the configuration data is saved to a non-volatile storage medium.
[0124] In some embodiments, the computer device can also establish the correspondence between the confused key shares and the confusion method. Furthermore, based on the correspondence between the confused key shares and the noise data, the correspondence between the confused key shares and the participating parties, and the correspondence between the confused key shares and the confusion method, configuration data is obtained.
[0125] Schematically, the format of the configuration data is shown in Table 1:
[0126]
[0127] Table 1 Configuration Data
[0128] In some embodiments, at least one type of data such as a master key, a second quantity of key shares, a time for distributing the obfuscated key shares, a method for distributing the obfuscated key shares, etc. may also be stored in the configuration data.
[0129] In the above embodiments, the correspondence between the obfuscated key shares and the noise data, and the correspondence between the obfuscated key shares and the participating parties are stored, which facilitates decrypting the obfuscated key shares to obtain the key shares when a key recovery request sent by a participating party is received subsequently.
[0130] In some embodiments, authenticating the source party of the key recovery request includes: detecting whether a dynamic token is carried in the key recovery request; if carried, verifying the validity of the dynamic token, and determining that the source party passes the authentication when the validity verification passes.
[0131] It should be noted that the computer device can pre-divide the master key into N key shares (N is a natural number greater than 1 and N is greater than the second quantity k), and encrypt each key share to obtain N obfuscated key shares. These N obfuscated key shares are distributed to N participating parties, and each participating party stores one of the obfuscated key shares. At the same time, each participating party will set up a dynamic Token generator. This dynamic Token generator will generate a new and random token, that is, a dynamic token, at a specified time interval. Among them, the dynamic Token generator can specifically be a hardware device or a software application (such as Google Authenticator).
[0132] When a participating party wants to recover the master key, it first needs to provide the current dynamic token. The computer device detects whether a dynamic token is carried in the key recovery request. If carried, it continues to verify whether this dynamic token is correct and currently valid, so as to verify the legitimate identity of the participating party through this dynamic token. If the key recovery request does not carry a dynamic token, the computer device can directly discard the key recovery request without response.
[0133] In some embodiments, the computer device can detect whether the dynamic token is a duplicate dynamic token. If not, it determines that the dynamic token passes the validity verification and records the dynamic token. If it is a duplicate token, it determines that the dynamic token fails the validity verification. The recorded dynamic token is used to determine the repeatability of the dynamic tokens in subsequent key recovery requests.
[0134] In some embodiments, the computer device can detect whether the dynamic token is within the validity period. If it is, it determines that the dynamic token passes the validity verification. If not, it determines that the dynamic token fails the validity verification.
[0135] In some embodiments, the computer device may detect whether the dynamic token is a duplicate dynamic token and whether the dynamic token is within the valid period. If the dynamic token is not a duplicate dynamic token and is within the valid period, the computer device determines that the dynamic token is valid and records the dynamic token. Otherwise, the computer device determines that the dynamic token fails the validity check.
[0136] In the above embodiments, the verification of the source party's identity is implemented through the dynamic token, which can verify the legal identity of the source party, identify illegal attackers, and ensure the security of key recovery.
[0137] In some embodiments, referring to Figure 7 , in the case where the identity authentication is passed, extracting and storing the obfuscated key share in the key recovery request includes:
[0138] Step 702, in the case where the identity authentication is passed, determining the set condition corresponding to the source party.
[0139] The set condition is the condition for the participating party to be responsible for confirming whether the master key recovery can be performed, and it can be pre-submitted to the computer device. The set conditions responsible for different participating parties can be the same or different.
[0140] For example, it is reaching the preset number of years or a specific event occurs. In the field of resource inheritance, the condition can specifically be obtaining the permission of the digital wallet owner, or the natural death of the digital wallet owner, or the initiator of the resource transfer presenting a specific object, or triggering a preset event, etc., without limitation.
[0141] Step 704, extracting the data to be verified carried in the key recovery request.
[0142] The data to be verified is the data submitted by the participating party to prove that the set condition is met. In some embodiments, the computer device can directly extract the data to be verified from the data carried in the key recovery request. In other embodiments, the computer device can decrypt the data in the key recovery request through the public key of the participating party corresponding to the participating party that initiates the key recovery request to extract the data to be verified. It should be noted that in addition to the data to be verified, the decrypted data also includes the obfuscated key share.
[0143] Step 706, verifying the data to be verified based on the set condition, and extracting and storing the obfuscated key share in the key recovery request in the case where the verification is passed.
[0144] Specifically, the computer device can extract the set conditions related to the participant from the pre-stored data. Then, based on the data to be verified, it determines whether the set conditions can be met. If so, it indicates that the timing of initiating the key recovery request is appropriate, so it determines that the verification passes. Then, the computer device can extract the obfuscated key share in the key recovery request and store it.
[0145] In some embodiments, when the computer device determines whether the set conditions can be met based on the data to be verified, it can also obtain established knowledge for auxiliary judgment. For example, when the set conditions involve time, the computer device can obtain the current system time. When the judgment conditions involve established facts, the computer device can obtain the established facts from the network or the knowledge base, etc. In this way, accurate judgment of the data to be verified can be achieved through the established knowledge and the set conditions together.
[0146] In the above embodiments, by verifying the data to be verified and extracting the obfuscated key share for storage only after the verification passes, key recovery requests that do not meet the submission requirements can be screened out.
[0147] In some embodiments, determining the preset decryption method corresponding to the obfuscated key share includes: reading configuration data, which records the obfuscation methods corresponding to each participant respectively. According to the configuration data, determine the obfuscation methods corresponding to the participants from which the stored obfuscated key shares are derived respectively. Based on the determined obfuscation methods, determine the preset decryption methods corresponding to the stored obfuscated key shares respectively.
[0148] Specifically, the computer device can read the configuration data stored locally. The configuration data records the obfuscation methods corresponding to each participant respectively, that is, the corresponding relationship between the participant and the obfuscation method. In some embodiments, the configuration data also records the corresponding relationship between the obfuscated key share and the noise data, the corresponding relationship between the obfuscated key share and the participant, and the corresponding relationship between the obfuscated key share and the obfuscation method. For specific content, please refer to Table 1 in the foregoing embodiments.
[0149] Furthermore, the computer device can determine the participant identifier of the participant from which each obfuscated key share stored in the preset storage space is derived respectively. Then, according to the participant identifier, it searches in the configuration data to determine the obfuscation methods corresponding to each participant identifier respectively, that is, determines the obfuscation methods corresponding to each obfuscated key share.
[0150] Exemplarily, the obfuscation method can be a shift operation, a splicing operation, or dividing the key share into blocks and scrambling the order of different data blocks, etc. The embodiments of the present application do not limit this.
[0151] For any obfuscated key share, the computer device can determine a matching preset decryption method according to the obfuscation method corresponding to the obfuscated key share. For example, the preset decryption method is obtained by performing the reverse operation on the obfuscation method. For example, reverse shifting, reverse splicing, or restoring the order of data blocks to the original order, etc.
[0152] It should be noted that for different key shares, the computer device can encrypt them using the same obfuscation method or different obfuscation methods. The embodiments of the present application do not limit this. Therefore, when determining the preset decryption method, the preset decryption methods corresponding to different obfuscated key shares can be the same decryption method or different decryption methods.
[0153] In the above embodiments, through the configuration data, the obfuscation method corresponding to each obfuscated key share can be accurately obtained, so that the preset decryption method corresponding to each obfuscated key share can be determined according to the obfuscation method.
[0154] In some embodiments, decrypting each obfuscated key share according to the preset decryption method to obtain the corresponding key share includes: determining the noise data used during key obfuscation; decrypting each obfuscated key share according to the preset decryption method and based on the noise data to obtain the corresponding key share.
[0155] In some embodiments, the computer device can determine the noise data from the data stored locally. Furthermore, for each obfuscated key share, according to the preset decryption method corresponding to the obfuscated key share, and decrypting the obfuscated key share through the noise data to obtain the key share.
[0156] In some embodiments, when encrypting N key shares, the same noise data can be used for encryption, or different noise data can be used for encryption. The embodiments of the present application do not limit this.
[0157] In the above embodiments, the noise data used during key obfuscation is utilized to assist in decrypting the obfuscated key share to obtain the accurate key share.
[0158] In some embodiments, determining the noise data used during key obfuscation includes: determining the noise data used for each key share respectively during key obfuscation; determining the noise data corresponding to the stored obfuscated key shares respectively from the noise data used for each key share respectively. Decrypting each obfuscated key share according to the preset decryption method and based on the noise data to obtain the corresponding key share includes: decrypting each obfuscated key share according to the preset decryption method and based on the noise data corresponding to the stored obfuscated key shares respectively to obtain the corresponding key share.
[0159] In some embodiments, when encrypting N key shares, different noise data is used for encryption. Therefore, when decrypting, it is necessary to confirm the noise data corresponding to each obfuscated key share. Furthermore, according to the preset decryption method, each obfuscated key share is decrypted based on the noise data respectively corresponding to the stored obfuscated key shares to obtain the corresponding key shares.
[0160] In the above embodiments, by decrypting according to the noise data corresponding to each obfuscated key share, the key share can be accurately obtained.
[0161] In some embodiments, the method further includes a resource transfer step, which specifically includes: determining a first wallet address associated with the master key; obtaining a preset second wallet address; accessing the first wallet address according to the recovered master key, and performing resource transfer according to the second wallet address.
[0162] In some embodiments, the computer device can determine a first wallet address associated with the master key, obtain the second wallet address carried in the key recovery request, or obtain a preset second wallet address in advance. Then, according to the recovered master key, the first wallet address is accessed, and resource transfer is performed according to the second wallet address. That is, the resources in the first wallet pointed to by the first wallet address are transferred to the second wallet pointed to by the second wallet address.
[0163] In some embodiments, the amount of resource transfer can be a preset amount, the amount carried in the key recovery request, or the total amount of all resources in the first wallet.
[0164] In some embodiments, the computer device can generate a resource transfer request based on the first wallet address, the second wallet address, and the amount of resource transfer, and send the resource transfer request to the relevant institution to implement the resource transfer operation through the relevant structure.
[0165] In some embodiments, after the resource transfer is completed, the master key, all key shares, and obfuscated key shares are cleared. That is, after the resource transfer is completed, the computer device can clear the master key, all key shares, and obfuscated key shares. Even clean the storage space of the computer device to improve the performance of the computer device.
[0166] In some embodiments, the above key recovery method is executed by a smart contract to obtain the master key. Therefore, after the master key is recovered by the smart contract, resource transfer can be directly performed based on the first wallet address and the second wallet address pre-stored in the smart contract.
[0167] In the above embodiments, after the master key is restored, resource transfer can be automatically performed, ensuring the transparency of processing resource transfer after all conditions are met and eliminating the possibility of human intervention.
[0168] In some embodiments, referring to Figure 8 , the key recovery method includes the following steps:
[0169] The first stage, the key generation stage (including steps 802 - 804):
[0170] Step 802, construct the original N key shares.
[0171] The computer device receives the master key S of the digital wallet automatically generated based on the key algorithm, selects a polynomial of degree k - 1, sets the constant term as the master key S, and randomly selects other terms (selected in the finite field F) to obtain a target polynomial, and decomposes the master key S into N key shares. Wherein, k can be a custom value and needs to be less than N.
[0172] Step 804, noise injection.
[0173] Introduce random noise and mix it with each key share (such as complex shift or XOR operations) to create obfuscated key shares. This random noise can be a random number, random string, or other random data. Save this noise data in a secure place because the recovery process requires them.
[0174] Alternatively, multiple random noises can be introduced, and a random noise is assigned to each key share and associated with it.
[0175] The second stage, the key distribution stage (including step 806):
[0176] Step 806, distribute the N obfuscated key shares to N parties.
[0177] Distribute the N obfuscated key shares to N holders or custodian institutions, and at the same time require each holder or custodian institution to set a dynamic Token generator, which will generate a new and random token at regular time intervals. When a holder or custodian institution wants to restore the master key, they first need to provide the current dynamic token. The smart contract deployed in the computer device verifies whether this token is correct and currently valid to verify the legal identity of the holder or custodian institution through this token.
[0178] Set a condition for each holder or custodian institution to submit the obfuscated key share respectively. For example, it is to reach a preset number of years or a certain specific event occurs.
[0179] The third stage, smart contract deployment (including step 808):
[0180] Step 808, deploy a smart contract for digital resource transfer on the smart contract platform.
[0181] This smart contract can handle dynamic token verification and the de - obfuscation process of obfuscated key shares.
[0182] The fourth stage, submission of obfuscated key shares (including step 810):
[0183] Step 810, the participating party submits a key recovery request.
[0184] When the conditions set for a certain participating party are met, the obfuscated key shares and dynamic tokens held by that participating party are submitted to the smart contract platform. The smart contract verifies whether the dynamic tokens are legal. If legal, the obfuscated key shares are stored first.
[0185] The fifth stage, key recovery (including step 812):
[0186] Step 812, decrypt based on k obfuscated key shares to obtain k key shares, and reconstruct the master key based on the k key shares.
[0187] When the smart contract platform receives k obfuscated key shares, it can execute the de - obfuscation function to obtain the original key shares, and then use these original key shares to combine and recover the master key.
[0188] The sixth stage, asset transfer (including step 814):
[0189] Step 814, the smart contract automatically uses the recovered master key to access the digital wallet and transfers the resources to the recipient according to the contract provisions.
[0190] The recipient creates a new digital wallet or provides a wallet address. After the smart contract verifies that the wallet address is passed, it transfers the resources from the original wallet to the new wallet. After the resource transfer is completed, all the original key share data is destroyed.
[0191] The above key recovery method divides the master key into multiple key shares, ensuring that even if some key shares are stolen, the attacker cannot obtain the complete key, increasing the difficulty for malicious attackers to steal the complete key. By introducing random noise to obfuscate each key share, an additional protection layer is further provided for the key. Even if the obfuscated key share is exposed, it is difficult to restore the master key. The dynamic Token generator ensures the legitimacy of the identity of the holder or institution submitting the obfuscated key share, thus preventing illegal distribution and use. Setting conditions for submission for each key share holder or institution allows different N values and conditions to be set according to different application scenarios and requirements, taking into account both customization and flexibility. The automatic execution of the smart contract ensures the transparency of asset transfer after all conditions are met, eliminating the possibility of human intervention.
[0192] The key recovery method provided in this application can specifically be applied to the resource transfer scenario. The recovered master key is the wallet key, and automatic resource transfer can be achieved after the master key is recovered. Of course, the key recovery method provided in this application can also be applied to other scenarios, such as the data transmission scenario, where the recovered master key is the transmission key for encrypting and transmitting important data, and also the permission control scenario, where the recovered master key is the operation credential for performing operations within the appropriate permission scope through this permission credential, etc. The embodiments of this application do not make any limitations in this regard.
[0193] It should be understood that although the steps in the flowcharts involved in the above embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limitation, and these steps can be executed in other orders. Moreover, at least some of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0194] Based on the same inventive concept, the embodiments of this application also provide a key recovery device for implementing the above-mentioned key recovery method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more of the following key recovery device embodiments can refer to the limitations on the key recovery method in the above text and will not be elaborated here.
[0195] In an exemplary embodiment, as Figure 9As shown, a key recovery device 900 is provided, including: an authentication module 901, an extraction module 902, a determination module 903, a decryption module 904, and a recovery module 905, where:
[0196] The authentication module 901 is configured to authenticate the source party of the key recovery request when receiving the key recovery request.
[0197] The extraction module 902 is configured to extract and store the obfuscated key shares in the key recovery request when the authentication is passed.
[0198] The determination module 903 is configured to determine the preset decryption method corresponding to the obfuscated key shares when the number of stored obfuscated key shares reaches the first number.
[0199] The decryption module 904 is configured to decrypt each obfuscated key share according to the preset decryption method to obtain the key shares.
[0200] The recovery module 905 is configured to perform key recovery based on the first number of key shares to obtain the master key.
[0201] In some embodiments, the authentication module is specifically configured to: detect whether a dynamic token is carried in the key recovery request; if so, verify the validity of the dynamic token, and determine that the source party passes the authentication when the validity verification passes.
[0202] In some embodiments, the extraction module is specifically configured to, when the authentication is passed, determine the set conditions corresponding to the source party; extract the data to be verified carried in the key recovery request; verify the data to be verified based on the set conditions, and extract and store the obfuscated key shares in the key recovery request when the verification passes.
[0203] In some embodiments, the determination module is specifically configured to read the configuration data, where the configuration data records the obfuscation methods corresponding to each participating party respectively; according to the configuration data, determine the obfuscation methods corresponding to the participating parties from which the stored obfuscated key shares are derived respectively; based on the determined obfuscation methods, determine the preset decryption methods corresponding to the stored obfuscated key shares respectively.
[0204] In some embodiments, the decryption module is specifically configured to determine the noise data used during key obfuscation; decrypt each obfuscated key share according to the preset decryption method and based on the noise data to obtain the corresponding key shares.
[0205] In some embodiments, the decryption module is specifically configured to determine the noise data respectively used for each key share during key obfuscation; determine, from the noise data respectively used for each key share, the noise data corresponding to the stored obfuscated key shares respectively; decrypt each obfuscated key share according to a preset decryption method and based on the noise data corresponding to the stored obfuscated key shares respectively, to obtain the corresponding key shares.
[0206] In some embodiments, the apparatus further includes a resource transfer module, configured to determine a first wallet address associated with the master key; obtain a preset second wallet address; access the first wallet address according to the recovered master key, and perform resource transfer according to the second wallet address.
[0207] In some embodiments, the apparatus further includes a clearing module, configured to clear the master key, all key shares, and obfuscated key shares after the resource transfer is completed.
[0208] In some embodiments, the apparatus further includes a key distribution module, configured to obtain the master key, and generate a second number of key shares according to the master key; determine noise data, and encrypt each key share respectively through the noise data to obtain a second number of obfuscated key shares; transfer the second number of obfuscated key shares to a second number of participants; wherein, each participant stores one of the obfuscated key shares.
[0209] In some embodiments, the apparatus further includes a saving module, configured to record the corresponding relationship between the obfuscated key shares and the noise data, and the corresponding relationship between the obfuscated key shares and the participants, to obtain configuration data; save the configuration data.
[0210] Each module in the above key recovery apparatus can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in the form of hardware or be independent of the processor, or be stored in the memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0211] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 10As shown in the figure. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store key data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a key recovery method.
[0212] Those skilled in the art can understand that Figure 10 the structure shown in the figure is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0213] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the steps in the above method embodiments are implemented.
[0214] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0215] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0216] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0217] Those of ordinary skill in the art can understand that all or part of the processes in the above-described embodiment methods can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-described method embodiments. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0218] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.
[0219] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A key recovery method, characterized in that, The method includes: When a key recovery request is received, authenticate the source party of the key recovery request; When the authentication is passed, extract and store the obfuscated key shares in the key recovery request; When the number of stored obfuscated key shares reaches a first number, determine the preset decryption method corresponding to the obfuscated key shares; Decrypt each obfuscated key share according to the preset decryption method to obtain key shares; Perform key recovery based on the first number of key shares to obtain the master key.
2. The method according to claim 1, characterized in that, The authenticating the source party of the key recovery request includes: Detect whether a dynamic token is carried in the key recovery request; If carried, verify the validity of the dynamic token, and when the validity verification passes, determine that the source party passes the authentication.
3. The method according to claim 1, characterized in that, The extracting and storing the obfuscated key shares in the key recovery request when the authentication is passed includes: When the authentication is passed, determine the set conditions corresponding to the source party; Extract the data to be verified carried in the key recovery request; Verify the data to be verified based on the set conditions, and when the verification passes, extract and store the obfuscated key shares in the key recovery request.
4. The method according to claim 1, characterized in that, The determining the preset decryption method corresponding to the obfuscated key shares includes: Read the configuration data, which records the obfuscation methods respectively corresponding to each participant; According to the configuration data, determine the obfuscation methods respectively corresponding to the participants from which the stored obfuscated key shares are sourced; Based on the determined obfuscation methods, determine the preset decryption methods respectively corresponding to the stored obfuscated key shares.
5. The method according to claim 1, characterized in that, The decrypting each obfuscated key share according to the preset decryption method to obtain the corresponding key share includes: Determine the noise data used during key obfuscation; Decrypt each obfuscated key share according to the preset decryption method and based on the noise data to obtain the corresponding key share.
6. The method according to claim 5, characterized in that, The determining the noise data used during key obfuscation includes: Determine the noise data respectively used for each key share during key obfuscation; From the noise data respectively used for each key share, determine the noise data respectively corresponding to the stored obfuscated key shares; The decrypting each obfuscated key share according to the preset decryption method and based on the noise data to obtain the corresponding key share includes: Decrypt each obfuscated key share according to the preset decryption method and based on the noise data respectively corresponding to the stored obfuscated key shares to obtain the corresponding key share.
7. The method according to claim 1, characterized in that, The method further includes: Determine the first wallet address associated with the master key; Obtain the preset second wallet address; Access the first wallet address according to the recovered master key, and perform resource transfer according to the second wallet address.
8. The method according to claim 7, characterized in that, The method further includes: After the resource transfer is completed, clear the master key, all key shares, and obfuscated key shares.
9. The method according to any one of claims 1 to 8, characterized in that,The method further includes: Obtain the master key, and generate a second number of key shares according to the master key; Determine the noise data, and encrypt each key share with the noise data to obtain a second number of obfuscated key shares; Transmit the second number of obfuscated key shares to the second number of participants; wherein, each participant stores one of the obfuscated key shares.
10. The method according to claim 9, wherein The method further includes: Record the correspondence between the obfuscated key shares and the noise data, and the correspondence between the obfuscated key shares and the participants, to obtain configuration data; Save the configuration data.
11. A key recovery device, characterized in that The apparatus includes: A verification module, configured to authenticate the source party of the key recovery request when receiving the key recovery request; An extraction module, configured to extract and store the obfuscated key share in the key recovery request when the authentication is passed; A determination module, configured to determine a preset decryption method corresponding to the obfuscated key share when the number of stored obfuscated key shares reaches a first number; A decryption module, configured to decrypt each obfuscated key share according to the preset decryption method to obtain key shares; A recovery module, configured to perform key recovery based on the first number of key shares to obtain a master key.
12. The device according to claim 11, wherein The verification module is specifically configured to: Detect whether a dynamic token is carried in the key recovery request; If carried, verify the validity of the dynamic token, and determine that the source party passes the authentication when the validity verification passes.
13. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that When the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.
14. A computer-readable storage medium, having a computer program stored thereon, characterized in that When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 10 are implemented.
15. A computer program product, comprising a computer program, characterized in that When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 10 are implemented.
Citation Information
Cited By
System and method for secure decryption using multi-party computation
US12744658B2
System and method for secure decryption using multi-party computation
US20260163716A1