Private key secure storage method

The use of a random matrix for secure key storage addresses the limitations of existing methods by enhancing security and reducing the risk of key exposure through increased complexity and device-specific mapping.

CN120320941APending Publication Date: 2025-07-15BEIJING RENXINZHENG TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510557933.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

In the prior art, hardware security modules have high dependence and high cost, and key cloud storage depends on the network environment, resulting in insufficient security of key storage, making it difficult to perform secondary welding on factory circuit boards, and when the network environment is poor, it is easy to cause key download failure.

Method used

The random number matrix is used to map the hash value of the key and the device identification information into matrix points, generate a binary file for storage, and verify the legality of the key through the hash value to ensure the security and uniqueness of the key.

Benefits of technology

Improve the security of keys, reduce the risk of being cracked, prevent key copying, and reduce economic losses caused by key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120320941A_ABST
    Figure CN120320941A_ABST
Patent Text Reader

Abstract

The invention provides a private key secure storage method. The method comprises the following steps: inputting a legal key and equipment identification information; generating a matrix of which the row number and the column number are not less than the key length; calculating a hash value of equipment identification information, mapping the hash value into points of the matrix, and storing the points into a set; replacing each point in the matrix with a corresponding byte in the key according to the mapping information stored in the set; and converting the replaced matrix into a binary file. The method has the beneficial effects that the complexity of the secret key is increased through the matrix, the cracking risk is reduced, the secret key copying problem is prevented by introducing the equipment information, and the economic loss risk caused by secret key privacy leakage is further reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security, and particularly relates to a method for securely storing private keys. Background Art

[0002] With the development of software technology and digitization, the secure storage of keys has become particularly important. With the frequent occurrence of data leakage incidents, how to effectively protect the security of keys has become an important issue.

[0003] Currently, there are various methods for storing keys in the market, including solutions such as hardware security modules, secure chips, and key cloud storage. However, hardware security modules and secure chips have a high dependence on hardware and need to design the chips into the circuit board at the initial stage of PCB design. For the already manufactured circuit boards, secondary soldering cannot be effectively carried out. And introducing secure chips also increases the hardware cost. Key cloud storage depends on the network environment. When the network environment is poor, it is easy for the key to fail to be downloaded. Summary of the Invention

[0004] In view of this, the present invention aims to propose a method for securely storing private keys in order to solve at least one of the above-mentioned partial technical problems.

[0005] To achieve the above object, the technical solution of the present invention is realized as follows:

[0006] The first aspect of the present invention proposes a method for securely storing private keys, including:

[0007] Input a legal key and device identification information;

[0008] Generate a matrix with the number of rows and columns both not less than the length of the key;

[0009] Calculate the hash value of the device identification information, map the hash value to the points of the matrix, and store them in a set;

[0010] According to the mapping information stored in the set, replace each point in the matrix with the corresponding byte in the key;

[0011] Convert the replaced matrix into a binary file.

[0012] Furthermore, it also includes:

[0013] Read the binary file and map it to a new matrix, calculate the hash value of the device identification information, map the hash value to the points of the new matrix, and store them in a new set. Use the new set to obtain the data in the new matrix, and complete the verification of the key by comparing the data in the new matrix with the key value.

[0014] Further, the legal lengths of the secret key and the device identification information are both at least 16 bytes and are not all zero.

[0015] Further, the process of mapping the hash value to the points of the matrix includes:

[0016] Performing a modulo operation on each byte of the hash value with the number of rows of the matrix to obtain the coordinates of the points of the matrix corresponding to the current byte, and storing the coordinates of the points in a set.

[0017] Further, each byte of the hash value carries a subscript, the initial value of the subscript is 0, and the subscript increments with the coordinates of the points corresponding to the current byte until the value of the subscript is greater than the hash length, and then the subscript is reset to 0;

[0018] Repeat the increment and reset operations of the subscript until the number of points is the same as the secret key length.

[0019] Further, when inputting the secret key and the device identification information, perform a legality verification on the secret key and the device identification information;

[0020] When the input secret key and device identification information do not meet the legal length or are all zero, re-enter the secret key and device identification information and perform a legality verification.

[0021] Further, if the comparison result between the data in the new matrix and the secret key value is the same, the current secret key is successfully stored; otherwise, recalculate the hash value of the device identification information and map the hash value to the points of the matrix.

[0022] A second aspect of the present invention provides an electronic device, including a processor and a memory communicatively connected to the processor and used for storing executable instructions of the processor, and the processor is used to execute the method described in the first aspect above.

[0023] A third aspect of the present invention provides a server, including at least one processor and a memory communicatively connected to the processor, the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor to enable the at least one processor to execute the method described in the first aspect.

[0024] A fourth aspect of the present invention provides a computer-readable storage medium, storing a computer program, and when the computer program is executed by a processor, the method described in the first aspect is implemented.

[0025] Compared with the prior art, the privacy key security storage method described in the present invention has the following beneficial effects:

[0026] The present invention provides a method for secure key storage, aiming to solve the problem of insufficient key storage security in the prior art. The invention increases the complexity of the key through a random number matrix, reduces the risk of being cracked, and prevents the occurrence of key copying problems by introducing device information, thereby reducing the risk of economic losses caused by key privacy leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] The drawings constituting a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0028] Figure 1 It is a schematic flowchart of the execution process of a method for secure key storage according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.

[0030] In the description of the present invention, it should be understood that the terms "center", "longitudinal", "lateral", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. They are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the present invention. In addition, the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first", "second", etc. may explicitly or implicitly include one or more of such features. In the description of the present invention, unless otherwise specified, the meaning of "a plurality" is two or more.

[0031] In the description of the present invention, it should be noted that unless otherwise clearly defined and limited, the terms "installed", "connected", "connected" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood through specific situations.

[0032] The present invention will be described in detail below with reference to the drawings and in conjunction with the embodiments.

[0033] As Figure 1Example 1 shown, a method for secure storage of private keys, comprising:

[0034] Input a legal key and device identification information;

[0035] Generate a matrix whose number of rows and columns are both not less than the length of the key;

[0036] Calculate the hash value of the device identification information, map the hash value to points of the matrix, and store them in a set;

[0037] According to the mapping information stored in the set, replace each point in the matrix with the corresponding byte in the key;

[0038] Convert the replaced matrix into a binary file.

[0039] The matrix is a random matrix (M), the number of rows (R) of the random matrix (M) is greater than or equal to the key length, and the number of columns (C) is greater than or equal to the key length.

[0040] It further includes:

[0041] Read the binary file and map it to a new matrix, calculate the hash value of the device identification information, map the hash value to points of the new matrix, and store them in a new set, use the new set to obtain the data in the new matrix, and complete the verification of the key by comparing the data in the new matrix with the key value.

[0042] The legal lengths of the key and the device identification information are both at least 16 bytes and are not all zeros; that is, the key length N and the device identification information ID are both legal data (not all zeros), and to ensure the dispersion effect, both the key and the identification information need to be greater than or equal to 16 bytes.

[0043] The process of mapping the hash value to points of the matrix includes:

[0044] Perform a modulo operation on each byte of the hash value with the number of rows of the matrix to obtain the coordinates of the points of the matrix corresponding to the current byte, and store the coordinates of the points in the set.

[0045] Each byte of the hash value carries a subscript, the initial value of the subscript is 0, and the subscript increments with the coordinates of the points corresponding to the current byte until the value of the subscript is greater than the hash length, then the subscript is reset to 0;

[0046] Repeat the increment and reset operations of the subscript until the number of points is the same as the key length.

[0047] Specifically, the number of times of calculating the hash value (H) of the device identification is greater than or equal to 1 time, and the algorithm for mapping the hash value to points on the matrix is as follows:

[0048] Perform a modulo operation on each byte (Hi) of the calculated hash value with R to obtain the column number y of point Pi above row x in that line, and store point P(x, y) in set S. When the value of i is greater than the hash length, reset i to 0 and repeat the loop until the number of points is the same as the key length, at which point it ends.

[0049] When inputting the key and device identification information, perform a legality verification on the key and device identification information;

[0050] When the input key and device identification information do not meet the legal length or are all zero, re-enter the key and device identification information and perform a legality verification.

[0051] If the comparison result between the data in the new matrix and the key value is the same, the current key is successfully stored; otherwise, recalculate the hash value of the device identification information and map the hash value to the points of the matrix.

[0052] In some embodiments, a specific execution process of the method described in Embodiment 1 above is as follows:

[0053] Input information: Input the key (1122334455667788) and device identification information (1HGCM82633A123456). After verification, the key and device identification information are legal and both are greater than or equal to 16.

[0054] Generate a random matrix: Generate a random matrix (M), and take the number of rows of the random matrix (M) as R(16) and the number of columns as S(16).

[0055] Calculate the key storage points: Calculate the MD5 value of the device identification 3 times to obtain bbc3a74108d90e24ff798fd766889923, and map the hash value to the points on the matrix. The specific algorithm is as follows: Perform a modulo operation on each byte (Hi) of the calculated hash value with R(16) (bb(187) % 16 = 11) to obtain that point P1 is the column number 11 above row 1 in that line. Store point P(1, 11) in set S. Calculate the points corresponding to c3, a7, 41, 08, d9, 0e, 24, ff, 79, 8f, d7, 66, 88, 99, 23 as (2, 3), (3, 7), (4, 1), (5, 8), (6, 9), (7, 14), (8, 4), (9, 15), (10, 9), (11, 15), (12, 7), (13, 6), (14, 8), (15, 9), (16, 3) in sequence, and store them in set S.

[0056] Replacement matrix: Retrieve the position information stored in the set S where the key is stored, and replace the corresponding points in S with the ciphertext information values. To make the replacement observable, first convert the key value 112233445566778899 to hexadecimal representation as 31313232333334343535363637373838, and perform the replacement with the converted hexadecimal characters.

[0057] Store the key: Map the replaced matrix to binary data and store it as a file.

[0058] Verify the key: Read the file, map the file to a matrix, and repeat the operation in step 3. After calculating S, obtain the data in the matrix through S as 31313232333334343535363637373838. Comparing it with the hexadecimal representation of the original key value 1122334455667788 shows that they are consistent. Therefore, it is estimated that the key is successfully stored securely.

[0059] Embodiment 2: An electronic device includes a processor and a memory communicatively connected to the processor and used to store executable instructions of the processor. The processor is used to execute the method described in Embodiment 1 above.

[0060] Embodiment 3: A server includes at least one processor and a memory communicatively connected to the processor. The memory stores instructions executable by the at least one processor. When the instructions are executed by the processor, the at least one processor is caused to execute the method described in Embodiment 1.

[0061] Embodiment 4: A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the method described in Embodiment 1 is implemented.

[0062] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the present practical embodiments, and they should all be covered by the scope of the claims and the description of the present invention.

[0063] The above is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for securely storing a private key, characterized in that, Including: Inputting a legal key and device identification information; Generating a matrix where both the number of rows and columns are not less than the length of the key; Calculating the hash value of the device identification information, mapping the hash value to points of the matrix, and storing them in a set; According to the mapping information stored in the set, replacing each point in the matrix with the corresponding byte in the key; Converting the replaced matrix into a binary file.

2. The privacy key security storage method according to claim 1, wherein Also including: Reading the binary file and mapping it to a new matrix, calculating the hash value of the device identification information, mapping the hash value to points of the new matrix, and storing them in a new set, obtaining the data in the new matrix using the new set, and completing the verification of the key by comparing the data in the new matrix with the key value.

3. A privacy key secure storage method according to claim 1, characterized in that, The legal lengths of the key and the device identification information are both at least 16 bytes and are not all zero.

4. A privacy key secure storage method according to claim 1, characterized in that The process of mapping the hash value to points of the matrix includes: Performing a modulo operation on each byte of the hash value with the number of rows of the matrix to obtain the coordinates of the points in the matrix corresponding to the current byte, and storing the coordinates of the points in the set.

5. A method for securely storing a privacy key according to claim 4, characterized in that, Each byte of the hash value carries a subscript, the initial value of the subscript is 0, and the subscript increments with the coordinates of the points corresponding to the current byte until the value of the subscript is greater than the hash length, then the subscript is reset to 0; Repeating the increment and reset operations of the subscript until the number of points is the same as the length of the key.

6. The privacy key security storage method according to claim 1, wherein When inputting the key and the device identification information, performing a legality verification on the key and the device identification information; When the input key and device identification information do not meet the legal length or are all zero, re-inputting the key and the device identification information and performing a legality verification.

7. A method for securely storing a privacy key according to claim 2, characterized in that: If the comparison result between the data in the new matrix and the key value is the same, the current key is successfully stored; Otherwise, recalculating the hash value of the device identification information and mapping the hash value to points of the matrix.

8. An electronic device, comprising a processor and a memory communicatively connected to the processor and configured to store executable instructions of the processor, characterized in that: The processor is used to execute the method described in any one of claims 1 - 7 above.

9. A server, characterized in that: Including at least one processor and a memory communicatively connected to the processor, the memory storing instructions executable by the at least one processor, and when the instructions are executed by the processor, enabling the at least one processor to execute the method described in any one of claims 1 - 7.

10. A computer-readable storage medium stores a computer program, characterized in that: When the computer program is executed by the processor, it implements the method described in any one of claims 1 - 7.