Secret sharing method and system based on block chain
By recording secret shares and identity verification on the blockchain, the problem of high cost and low efficiency in the secret sharing method is solved, and an efficient and secure secret sharing and decryption process is achieved.
Patent Information
- Application Number
- CN202311655209.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-10-19
- Filing Date
- 2023-12-05
- Publication Date
- 2025-07-11
AI Technical Summary
There are problems in the existing secret sharing methods that are high in the cost of secret reconstruction and low efficiency, and the threshold is not considered, so it is necessary to agree to all participants before decryption, resulting in inefficiency.
The secret sharing method based on blockchain is adopted, and the original data is encrypted into points on the elliptic curve through the agreed key in the group, the hyperplane of the t-dimensional space is used as the secret share, and the blockchain is uploaded through hash operation, combining identity authentication and access control, allowing some participants to decrypt.
Improve data integrity and security, reduce secret reconstitution costs, improve the efficiency of secret sharing, and achieve secure decryption in restricted networks, reducing the risk of adversary attacks.
Smart Images

Figure CN120301581A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of blockchain, and particularly relates to a secret sharing method and system based on blockchain. Background Art
[0002] With the development of Internet of Things technology, large-scale Internet of Things devices have promoted the innovation of various emerging technologies, such as smart cities, smart life, etc. However, this also means generating a large-scale data system. And these large-scale data are usually handed over to a third-party cloud service provider to help with storage and calculation, which has caused various problems, such as adversary network intrusion attacks on the server, thereby modifying and deleting privacy data. More seriously, it has caused the leakage and sale of privacy data. Therefore, big data security has become a key technical problem.
[0003] With the rise and development of blockchain technology, currently, big data and blockchain have been gradually combined for secret sharing. The required sensitive information is processed in two places. First, the sensitive information is subjected to hash operation, then the sensitive information is stored in the local database, and the desensitized information and the storage address of the local database are uploaded to the blockchain together. Macroscopically, the remarkable feature of blockchain is that it can ensure the integrity of data transmission; microscopically, blockchain is essentially a distributed database system, and sensitive data can be hidden through some encryption algorithms. Therefore, combining blockchain with privacy data plays an important role in data protection. However, currently, the method of using blockchain for secret sharing is prone to data leakage problems before sharing the shares, and is prone to problems such as data tampering and impersonation after sharing the shares. Therefore, in the current secret sharing method, the problem of incomplete shares is likely to occur, resulting in a high cost of secret reconstruction. In addition, in the current secret sharing method, the general secret sharing method does not consider the threshold, so the secret must be decrypted with the consent of all participants, resulting in low secret sharing efficiency. Summary of the Invention
[0004] The purpose of the present invention is to solve the problems of high secret reconstruction cost and low secret sharing efficiency in the existing secret sharing method, and to propose a secret sharing method and system based on blockchain.
[0005] The specific process of a secret sharing method based on blockchain is as follows:
[0006] Step 1: Encrypt the original data with the group-agreed key X l to obtain the secret information, and map each group-agreed key X l to a point (X l , Y l ) on the elliptic curve;
[0007] Step 2: The (X obtained in Step 1l ,Y l ), as a point in the t-dimensional space, uses the hyperplanes intersecting at a point as a secret share based on the t-dimensional space, enabling the newly added sharer to decrypt the secret information;
[0008] Step Three: Perform a hash operation on each secret share, obtain the address for storing the secret share, and upload the hashed secret share and the corresponding address for storing the secret share to the blockchain;
[0009] Step Four: Obtain the identity of the user operating on the secret share, access the transaction process in the blockchain based on the user's identity, return the access result to the client, and update the blockchain.
[0010] Furthermore, enabling the newly added sharer to obtain the key to decrypt the secret information in Step Two includes the following steps:
[0011] Step Two One: The original sharer obtains the linear coefficients a i , b i , c i , and sends a i , b i , c i to the newly added sharer:
[0012] First, the original sharer selects a prime number p and takes random values in Z of mod p to obtain the homogeneous coordinates Q(X l , Y l , Y l , Z l );
[0013] Then, use Q(X l , Y l , Z l ) to obtain the linear coefficient c i ;
[0014] Finally, the original sharer sends a i , b i , c i to the newly added sharer;
[0015] Step Two Two: The newly added sharer uses the linear coefficients a i , b i , c i to obtain the key X l .
[0016] Furthermore, obtaining the linear coefficient c l , Y l , Z l ) using Q(X i , is as follows:
[0017] c i ≡Z l -a i X l -b i Y l (mod p)
[0018] where a i and b i are known linear coefficients.
[0019] Furthermore, the newly added sharer in Step 2 uses the linear coefficients a i , b i , c i to obtain the key X l , using the following formula:
[0020]
[0021] where n - v is the total number of equations, and the value of n - v is determined according to the share size and the threshold value, and n is the total number of sharers.
[0022] Furthermore, the identity of the user who obtains the operation secret share in Step 4 accesses the transaction process in the blockchain based on the user's identity, returns the access result to the client, and updates the blockchain, including the following steps:
[0023] Step 4.1: Obtain the identity of the user who calls the smart contract operation secret share and verify the user's identity. If the identity verification is passed, execute Step 4.2; otherwise, end the access:
[0024] Step 4.2: The user submits a transaction plan tx = [User ID , chaincode ID , User PK , type], and sends the transaction plan tx submitted by the user to the endorsing node, and then executes Step 4.3;
[0025] where User ID is the user's ID, chaincode ID is the chain code number, User PK is the user's public key, and type is the type of the transaction;
[0026] Step 4.3: After receiving tx, the endorsing node evaluates whether the current user has the right to participate in the current transaction. If the user has the right to participate in the current transaction, execute Step 4.4; if the user has no right to participate in the current transaction, return to Step 4.2:
[0027] Step 44: The endorsement node simulates the execution of tx, sends the result of the simulated execution of tx generated by each endorsement node and the signature of the endorsement node to the client, and then executes step 45;
[0028] The results of the simulated execution of tx include: 1, 0, -1; 1 means that the account is queried and the relevant instruction operation is completed; 0 means that the account exists; -1 means that the account does not exist;
[0029] Step 45: The client determines whether to conduct a transaction based on the result of the simulated tx execution obtained in step 44 and the signature of the endorsement node. If a transaction is conducted, the plan submitted by the user is actually executed and the blockchain is updated; if no transaction is conducted, the transaction ends directly.
[0030] Furthermore, the step 41 of obtaining the identity of the user who calls the smart contract to operate the secret share and verifying the identity of the user includes the following steps:
[0031] User identities include user and admin;
[0032] Among them, user has only read permission, and admin has write and do permissions;
[0033] If the user is user, determine the public key PK and User provided by the user ID Is it legal? If the public key PK and User ID If both are valid, it means that the identity authentication is successful, and the current valid PK is used as the User PK ; If any of the conditions are not met, it means that the identity verification has not passed;
[0034] If the user identity is admin, determine the public key PK and User ID and whether the certificate CA is legal, if the public key PK, User ID If the certificate CA is valid, the identity authentication is successful, and the current valid PK is used as the User PK ; If any of the conditions are not met, it means that the identity verification has not passed;
[0035] in, User sig is the user signature, Time Stamp is the timestamp, Period of validity is the validity period, User ID is the user ID.
[0036] Furthermore, after receiving tx, the endorsement node in step 43 evaluates whether the current user has the right to participate in the current transaction, specifically:
[0037] First, according to the User ID find the corresponding User PK , and determine whether the User ID corresponds to the bound public key User PK . If the User ID , User PK is legal and the User ID corresponds to the User PK , it means that the current user has the right to participate in the current transaction. If any condition is not met, it means that the current user has no right to participate in the current transaction.
[0038] Furthermore, in steps four and five, the client determines whether to conduct a transaction based on the result of the simulated execution of tx obtained in step four and four and the signatures of the endorsing nodes. Specifically:
[0039] When the result after the simulated execution of tx is 0 or 1, the results generated by different endorsing nodes for the user-submitted plan are the same, and the signatures of each endorsing node are legal, it means that the transaction can be conducted; if any condition is not met, it means that the transaction cannot be conducted.
[0040] A blockchain-based secret sharing system for implementing a blockchain-based secret sharing method according to any one of claims 1 to 9.
[0041] The beneficial effects of the present invention are:
[0042] The present invention proposes a blockchain-based secret sharing method and system. The present invention introduces blockchain technology on the basis of secret sharing technology, and uses the characteristics of blockchain such as immutability, decentralization, and information traceability to verify the shares in the local database and record the verification results on the blockchain, effectively ensuring the integrity of the data and the credibility of the calculation process. At the same time, the present invention uploads the storage address to the blockchain, making it more convenient to search and trace data. The present invention has strong anti-attack and fault-tolerant capabilities. Even if a small amount of shares in the database are leaked and tampered with, the original data cannot be reconstructed, reducing the cost of secret reconstruction. At the same time, after uploading to the blockchain, the operations and IDs of users are transparent, improving the tracing effect and enhancing the data protection performance. The present invention combines identity authentication and access control to achieve the privacy protection of sensitive data, and all operations after uploading to the blockchain are transparent, greatly reducing the security risk, increasing the cost of adversary attacks, and enhancing the security of the secret. In addition, the present invention divides confidential data into multiple parts in a restricted network (a network with limited resources such as power, memory, and processing power), distributes them to different participants, and allows secure decryption without the consent of all participants, improving the efficiency of secret sharing. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 is a flowchart of the present invention;
[0044] Figure 2 is the schematic diagram of secret sharing;
[0045] Figure 3 is the workflow diagram of hierarchical access control in the blockchain;
[0046] Figure 4 is the system timing diagram of the present invention. Specific implementation manners
[0047] Specific implementation manner one: As shown in Figure 1 and Figure 4 , a secret sharing method based on the blockchain in this implementation manner includes the following steps:
[0048] Step 1, encrypt the original data with the key X agreed within the group l to obtain the secret information, and map each key X agreed within the group l to a point (X l , Y l ) on the elliptic curve, which is implemented by the following formula:
[0049] y 2 = x 3 + 324x + 1287
[0050] wherein, X l is the key, Y l is the ordinate corresponding to the key, x and y are parameter variables, (x, y) are the coordinates of the point on the ellipse, and l is the label of the key;
[0051] The key is a binary value or a byte sequence;
[0052] In the present invention, the original data is encrypted with the key X agreed within the group l by using the symmetric encryption method.
[0053] Step 2, take the point (X l , Y l ) on the ellipse obtained in Step 1 as a point in the t-dimensional space, and take the hyperplane intersecting at one point as a secret share based on the t-dimensional space, so that the newly added sharer can obtain the key to decrypt the secret information;
[0054] This scheme is a linear threshold scheme similar to the Shamir scheme. A hyperplane refers to a key sharer, Figure 2 defining that each plane represents a key sharer;
[0055] In this scheme, the key and the share can be summarized into a linear system CX = Y. Among them, the linear word matrix The sum vector Y corresponds to the hyperplane equation. The secret key is a point in the t-dimensional space, which is the intersection of all hyperplanes. The affine hyperplanes in this space represent n shares. Therefore, the linear system can be represented as CX mod p = Y.
[0056] X is the vector composed of the secret key X l , and Y is the vector composed of Y l ;
[0057] Therefore, to reconstruct the secret key and enable the newly added sharer to decrypt the secret information, it can be obtained in the following way:
[0058] Step 2-1. The original sharer obtains the linear coefficients a i , b i , c i , and transfers a i , b i , c i to the newly added sharer. Specifically:
[0059] First, the original sharer selects a prime number p and takes random values in Z of mod p, and determines the source domain size by using X l , Y l , Z l to obtain the homogeneous coordinates Q(X l , Y l , Z l ) l ;
[0060] Then, use Q(X l , Y l , Z l ) to obtain the linear coefficient c i , as shown in the following formula:
[0061] c i ≡ Z l - a i X l - b i Y l (mod p)
[0062] Where a i and b i are known linear coefficients, and a i and b i are the values selected by the system in mod p;
[0063] Finally, the original sharer transfers a i , b i , c i to the newly added sharer;
[0064] Step 2-2. The newly added sharer uses the linear coefficient ai , b i , c i Obtain the secret key X l , as shown in the following formula:
[0065]
[0066] where, n - v is the total number of equations, v is the number of redundant equations, and the value of n - v is determined according to the share size and the threshold value;
[0067] In this step, using the values of a, b, and c, define the hyperplane as follows:
[0068] z ≡ ax + by + c (mod p)
[0069] Assume that each person has a specific hyperplane. For example, if there are 5 sharers, that is, 5 hyperplane formulas are as follows:
[0070] a1x + b1y - z ≡ -c1 (mod p)
[0071] a2x + b2y - z ≡ -c2 (mod p)
[0072] a3x + b3y - z ≡ -c3 (mod p)
[0073] a4x + b4y - z ≡ -c4 (mod p)
[0074] a5x + b5y - z ≡ -c5 (mod p)
[0075] It can be generalized as:
[0076] a i x + b i y - z ≡ -c i (mod p) 1 ≤ i ≤ 5 (2)
[0077] where, i ∈ [1, n], i is the label of the sharer, and n is the total number of sharers;
[0078] Therefore, in the above example, we only need to select 3 people from 5 people, that is, find three equations to solve the secret key X1. The secret key value can be solved inversely from Equation (2). To sum up, as long as there is an inverse matrix modulo p, the secret key can be found through the inverse operation.
[0079] Therefore, the 5 sharers reconstruct the secret key X1 using the following formula:
[0080]
[0081] The present invention designs a program for users to allocate initial prime numbers, the number of users, the number of selected users, and key values. Users can define corresponding parameters at the corresponding positions in the code. As shown in Table 1, based on the algorithm in Table 1, the program calculates the coefficient matrix and constant vector. For the solution of linear equations, we use the gflin eq toolkit for calculation.
[0082] Table 1 Pseudo-code for Secret Sharing
[0083]
[0084] After the program runs, each output shows a solution of a point, which also contains the key.
[0085] Step 3: Perform a hash operation on each secret share, obtain the address for storing the secret share using the local database interface, and upload the hashed secret share and the corresponding address for storing the secret share to the blockchain by invoking a smart contract through a blockchain transaction;
[0086] Step 4: As Figure 3 shown, obtain the identity of the user who invokes the smart contract to operate on the secret share, access the transaction process in the blockchain based on the user's identity, return the obtained result to the client, and update the ledger. Specifically:
[0087] Step 4-1: Obtain the identity of the user who invokes the smart contract to operate on the secret share, and verify the user's identity. If the identity verification passes, execute Step 4-2; otherwise, end the access:
[0088] The smart contract permissions correspond to two identities {user, admin}. The user has only read permission and can view the request types initiated by other users to the smart contract and the identities of the users through the smart contract. The admin has write and execution powers. When a member with this permission needs data, a request is sent through the blockchain to invoke the contract, and the required share is obtained from the local database as Figure 2 ;
[0089] There are many types of transactions. In this solution, three types are set, namely read, write, and execution pre-plans, that is Set different ACLs according to different transaction types. In the query pre-plan, judge whether the public key PK provided by the user and User ID are legal. If both the public key PK and User ID are legal, it means that the identity verification passes, and at the same time, the current legal PK is used as User PK , if any condition is not met, it means that the identity verification fails; but in the write and execution pre-plans, both the public key PK and User ID are legal and a legal certificate CA is required to invoke this contract.
[0090]
[0091] Among them, User sig is the user signature, Time Stamp is the timestamp, Period of validity is the validity period, User ID is the user ID;
[0092] Step Four Two: The user submits a transaction plan and sends the submitted transaction plan to the endorsing node, and then execute Step Four Three:
[0093] The user on the client initiates a transaction tx = [User ID , chaincode ID , User PK , type];
[0094] Among them, User ID is the user ID, chaincode ID is the chaincode number, used to distinguish the types of contracts; User PK is the public key of the user, type is the type of the transaction, which facilitates the system to quickly locate the smart contract.
[0095] Step Four Three: After receiving tx, the endorsing node evaluates whether the current user has the right to participate in this transaction. If the user has the right to participate in this transaction, execute Step Four Four; if the user has no right to participate in this transaction, return to Step Four Two:
[0096] First, verify the legitimacy of User ID , and then find the corresponding User ID according to User PK , and judge whether User ID corresponds to the bound public key User PK . If User ID , User PK are legal and User ID corresponds to User PK , it means that the current user has the right to participate in this transaction. If any item does not meet the requirements, it means that the current user has no right to participate in this transaction;
[0097] Step Four Four: The endorsing node simulates the execution of tx, sends the result after the simulated execution of tx and the signature Endorsig of its own node to the client, and then execute Step Four Five;
[0098] The result after the simulated execution of tx includes: 1, 0, -1; 1 means that the account is queried and the relevant instruction operations are completed; 0 means that the account exists; -1 means that the account does not exist;
[0099] Step 45: The client determines whether to conduct a transaction based on the result of the simulated execution of tx obtained in step 44 and the signature Endorsig of the current node. If a transaction is conducted, the plan submitted by the user is actually executed and the account book is updated; if no transaction is conducted, the transaction ends directly:
[0100] When the result of the simulated execution of tx is 0 or 1 and the results generated by different endorsement nodes for the user's submitted plan are the same and the signatures of each endorsement node are Endorsig 1,...,n If it is legal, it means that the transaction can be carried out, and the client performs different operations according to the requirements of the plan; if any of the above conditions is not met, it means that the transaction cannot be carried out;
[0101] In order to simplify blockchain operations, the type will be checked after the above operations are judged. If it is read, the block will not be updated after the transaction is completed.
[0102] Specific implementation method 2: A secret sharing system based on blockchain, used to implement a secret sharing method based on blockchain.
Claims
1. A secret sharing method based on blockchain, characterized in that The specific process of the method is as follows: Step 1: Use the pre-agreed key X within the group l to encrypt the original data to obtain the secret information, and map the key X l to a point (X l , Y l ) on the elliptic curve; Step 2: Take the (X l , Y l ) obtained in Step 1 as a point in the t-dimensional space. Based on the t-dimensional space, take the hyperplanes intersecting at a point as a secret share, and enable the newly added sharer to obtain the key to decrypt the secret information; Step 3: Perform a hash operation on each secret share, obtain the address for storing the secret share, and upload the hashed secret share and the corresponding address for storing the secret share to the blockchain. Step 4: Obtain the identity of the user operating on the secret share, access the transaction process in the blockchain based on the user's identity, return the access result to the client, and update the blockchain.
2. The method for secret sharing based on blockchain according to claim 1, characterized in that: The step of enabling the newly added sharer to obtain the key in Step 2 includes the following steps: Step 2-1. The original sharer obtains the linear coefficients a i , b i , c i , and sends a i , b i , c i to the newly joined sharer: First, the original sharer selects a prime number p and takes a random value in Z modulo p, so as to obtain the homogeneous coordinates Q(X l , Y l , Z l ) l ; Then, use Q(X l , Y l , Z l ) to obtain the linear coefficient c i ; Finally, the original sharer sends a i , b i , c i to the newly joined sharers; Step Two: The newly added sharer uses the linear coefficients a i , b i , c i to obtain the key X l .
3. The method for secret sharing based on blockchain according to claim 2, wherein: The use of Q(X l , Y l , Z l ) to obtain the linear coefficient c i is as follows: c i ≡Z l -a i X l -b i Y l (mod p) where a i and b i are known linear coefficients.
4. A secret sharing method based on blockchain according to claim 3, characterized in that: The newly added sharer in Step 22 uses the linear coefficients a i , b i , c i to obtain the key X l , using the following formula: n - v ≥ 1 Among them, n - v is the total number of equations, and the value of n - v is determined according to the share size and the threshold value. n is the total number of sharers.
5. A secret sharing method based on blockchain according to claim 4, characterized in that: The step of obtaining the identity of the user operating on the secret share in Step 4, accessing the transaction process in the blockchain based on the user's identity, returning the access result to the client, and updating the blockchain includes the following steps: Step 4.1: Obtain the identity of the user who calls the smart contract to operate on the secret share, and verify the user's identity. If the identity verification is passed, execute Step 4.2; otherwise, end the access. Step Four Two: The user submits a transaction plan tx = [User ID , chaincode ID , User PK , type], and sends the transaction plan tx submitted by the user to the endorsing node, and then executes Step Four Three; Among them, User ID is the ID of the user, and chaincode ID is the number of the chaincode. User PK is the public key of the user, and type is the type of the transaction; Step 4.3: After the endorsing node receives the tx, evaluate whether the current user has the right to participate in the current transaction. If the user has the right to participate in the current transaction, execute Step 4.4; if the user has no right to participate in the current transaction, return to Step 4.
2. Step 4.4: The endorsing node simulates the execution of the tx, sends the results after the simulation execution of the tx generated by each endorsing node and the signature of the endorsing node to the client, and then executes Step 4.
5. The results after the simulation execution of the tx include: 1, 0, -1; 1 indicates that the account is queried and the relevant instruction operations are completed; 0 indicates that the account exists; -1 indicates that the account does not exist. Step 4.5: The client determines whether to conduct the transaction based on the results after the simulation execution of the tx obtained in Step 4.4 and the signature of the endorsing node. If the transaction is to be conducted, actually execute the plan submitted by the user and update the blockchain; if the transaction is not to be conducted, directly end.
6. The method for secret sharing based on blockchain according to claim 5, characterized in that: The step of obtaining the identity of the user who calls the smart contract to operate on the secret share in Step 4.1 and verifying the user's identity includes the following steps: The identity of the user includes user and admin. Among them, user only has the read permission, and admin has the write and do permissions. If the user is of the user identity, then determine whether the public key PK provided by the user and User ID are legal. If both the public key PK and User ID are legal, it means that the identity verification is passed, and at the same time, the current legal PK is used as User PK . If any condition is not satisfied, it means that the identity verification fails; If the user identity is the admin identity, then it is determined whether the public key PK, User ID and the certificate CA provided by the user are legal. If the public key PK, User ID and the certificate CA are both legal, it means that the identity verification is passed, and at the same time, the current legal PK is used as User PK ; if any condition is not met, it means that the identity verification has not passed; Among them, User sig is the user signature, TimeStamp is the timestamp, Period of validity is the validity period, and User ID is the user ID.
7. A secret sharing method based on blockchain according to claim 6, characterized in that: After the endorsing node in Step 4.3 receives the tx, evaluate whether the current user has the right to participate in the current transaction. Specifically: First, according to User ID find the corresponding User PK , and determine whether User ID corresponds to the bound public key User PK . If User ID , User PK is legal and User ID corresponds to User PK , it means that the current user has the right to participate in the current transaction. If any condition is not met, it means that the current user has no right to participate in the current transaction.
8. A secret sharing method based on blockchain according to claim 7, characterized in that: The client in Step 4.5 determines whether to conduct the transaction based on the results after the simulation execution of the tx obtained in Step 4.4 and the signature of the endorsing node. Specifically: When the result after the simulation execution of the tx is 0 or 1, and the results generated by different endorsing nodes for the plan submitted by the user are the same and the signatures of each endorsing node are legal, it indicates that the transaction can be conducted. If any one of the conditions is not met, it indicates that the transaction cannot be conducted.
9. A blockchain-based secret sharing system, characterized in that: The system is used to execute a blockchain-based secret sharing method as claimed in any one of claims 1 to 8.