Key fragmentation storage system, method and device based on block chain and medium
By sharding and storing keys in different participating organizations of the blockchain network, and combining secret sharing with blockchain technology, the single point failure and low security problems of traditional key storage methods are solved, and secure sharded storage and enhanced reliability of keys are achieved.
Patent Information
- Application Number
- CN202510987237.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-17
- Publication Date
- 2025-09-05
AI Technical Summary
Traditional key storage methods have the risk of single point failure and low security, and blockchain technology makes it difficult to ensure the secure storage of keys on it.
A preset secret sharing algorithm is used to process key shards into multiple shards. Taking advantage of the decentralized and tamper-proof characteristics of blockchain, these shards are stored in the private data sets of different participating organizations. The required shards are obtained through the key reconstruction module to reconstruct the original key. The hybrid cloud operation mode of offline key services and public cloud is combined to ensure the security and reliability of the key.
It realizes the secure sharding storage of keys, avoids the risk of single point failure, reduces the risk of key loss caused by malicious attacks, improves the security and reliability of key storage, and adapts to diverse security needs.
Smart Images

Figure CN120602072A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of blockchain technology, and in particular to a blockchain-based key sharding storage system, method, device, and medium. Background Art
[0002] As a core element of security, the storage and management of keys present numerous challenges. Traditional centralized key storage methods present a single point of failure risk. If the storage medium is attacked or damaged, the entire key system will be invalidated, posing a serious data security risk. Some solutions use encrypted key storage, but this cannot guarantee the security of the encryption keys themselves.
[0003] With the development of blockchain technology, its decentralized and tamper-proof characteristics enable blockchain to be applied to data storage. However, it is difficult to ensure the secure storage of keys in the blockchain. Summary of the Invention
[0004] The embodiments of the present application provide a blockchain-based key sharding storage system, method, device, and medium, which can solve the problems and risks of single point failure, low security, and human factors in traditional key storage methods, and improve the security, reliability, and manageability of key storage.
[0005] In one aspect, an embodiment of the present application provides a blockchain-based key sharding storage system, the system comprising a key sharding generation module, a blockchain storage module, and a key reconstruction module; the key sharding generation module and the key reconstruction module run on an offline key service in an offline environment, and the blockchain storage module runs on a public cloud;
[0006] The key shard generation module is configured to employ a preset secret sharing algorithm to shard the original key according to a preset threshold strategy to generate a preset first number of key shards;
[0007] The blockchain storage module is configured to store the preset first number of key shards in the private data sets of different participating organization nodes of the blockchain network respectively;
[0008] The key reconstruction module is configured to initiate a blockchain key sharding request, obtain at least a preset second number of key shards from the blockchain network, and reconstruct the at least preset second number of key shards to obtain the original key; the preset second number is less than or equal to the preset first number;
[0009] Among them, the key sharding generation module performs sharding processing when the offline key service is run for the first time; the key reconstruction module automatically initiates the blockchain key sharding request for reconstruction when the offline key service is started.
[0010] On the other hand, an embodiment of the present application provides a blockchain-based key sharding storage method, which is applied to a key sharding storage system, and the method includes:
[0011] Using a preset secret sharing algorithm, the original key is sharded according to a preset threshold strategy to generate a preset first number of key shards;
[0012] Storing the preset first number of key shards in private data sets of different participating organizations of the blockchain network respectively;
[0013] When there is a need to reconstruct the original key, a blockchain key shard request is initiated, at least a preset second number of key shards are obtained from the blockchain network, and the at least preset second number of key shards are reconstructed to obtain the original key; the preset second number is less than or equal to the preset first number.
[0014] On the other hand, an embodiment of the present application further provides an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, any one of the blockchain-based key sharding storage methods is implemented.
[0015] On the other hand, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements any one of the blockchain-based key sharding storage methods.
[0016] On the other hand, an embodiment of the present application further provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the blockchain-based key sharding storage method described in the above aspects.
[0017] The blockchain-based key sharding storage system, method, device, and medium provided in the embodiments of the present application employ a preset secret sharing algorithm through a key sharding generation module to shard an original key according to a preset threshold policy to generate a preset first number of key shards. The block storage module then stores the preset first number of key shards in the private data sets of different participating organization nodes in the blockchain network. Furthermore, a key reconstruction module initiates a blockchain key sharding request to obtain at least a preset second number of key shards from the blockchain network, and reconstructs the at least preset second number of key shards to obtain the original key. By combining blockchain with secret sharing technology, utilizing the threshold characteristics of secret sharing to shard the original key and utilizing the characteristics of blockchain to store the shards, the system can avoid the risk of single point failures, and the immutable nature of blockchain ensures the integrity and authenticity of shard storage, thereby achieving secure sharded storage of keys. Furthermore, the decentralized and distributed storage of blockchain can disperse key shards across multiple participating organizations, reducing the risk of key loss due to various malicious attacks or system problems, and enhancing system reliability. Furthermore, the key sharding generation module and the key reconstruction module adopt a hybrid cloud operation mode with the blockchain storage module, which can prevent the private key from existing in an untrusted public cloud environment and further improve the security of key storage. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 This is a structural block diagram of a blockchain-based key sharding storage system provided in an embodiment of the present application;
[0019] Figure 2 Schematic diagram of the operation architecture of the key sharding generation module provided in an embodiment of the present application;
[0020] Figure 3 Schematic diagram of the operation architecture of the key reconstruction module provided in an embodiment of the present application;
[0021] Figure 4 This is a flowchart of a blockchain-based key sharding storage method provided in an embodiment of the present application;
[0022] Figure 5 This is a structural block diagram of an electronic device provided in an embodiment of the present application;
[0023] Figure 6 This is a structural block diagram of a computer-readable storage medium provided in an embodiment of the present application. DETAILED DESCRIPTION
[0024] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.
[0025] The embodiments of the present application combine blockchain with secret sharing technology, utilize the threshold characteristics of secret sharing to shard keys and utilize the characteristics of blockchain to store them. This can avoid the risk of single point failure, and the tamper-proof characteristics of blockchain ensure the integrity and authenticity of shard storage, thereby achieving secure shard storage of keys. Furthermore, the decentralized and distributed storage method of blockchain can disperse key shards across multiple participating organizations, reducing the risk of key loss due to various malicious attacks or system problems and enhancing system reliability. Furthermore, by setting different threshold policies, the number of shards and the number of shards required for reconstruction can be adjusted according to different security requirements to meet diverse application scenarios. Furthermore, the key shard generation module and the key reconstruction module adopt a hybrid cloud operation mode with the blockchain storage module, which can prevent private keys from existing in untrusted public cloud environments and further improve the security of key storage.
[0026] Reference Figure 1 , shows a structural block diagram of a blockchain-based key sharding storage system provided in an embodiment of the present application. The key sharding storage system 1 may include a key sharding generation module 11, a blockchain storage module 12 and a key reconstruction module 13.
[0027] The key shard generation module 11 and the key reconstruction module 13 can be deployed with the blockchain storage module 12 in a hybrid cloud operation mode. Optionally, the key shard generation module 11 and the key reconstruction module 13 can be run in an offline environment, specifically in the same offline key service, to ensure that the private key is kept in an offline private and trusted environment; the blockchain storage module 12 can be run in a public cloud to take advantage of the decentralized and distributed storage characteristics of the blockchain.
[0028] It should be noted that the key sharding generation module 11 and the key reconstruction module 13 running in the offline key service can also be deployed in a hybrid cloud operation mode with other modules. For other specific modules, the embodiments of this application do not limit them.
[0029] Specifically, the key shard generation module 11 may be configured to employ a preset secret sharing algorithm to perform sharding processing on the original key according to a preset threshold strategy, thereby generating a preset first number of key shards.
[0030] Exemplarily, the preset secret sharing algorithm adopted can be, for example, the Shamir secret sharing algorithm or the Blakley secret sharing algorithm; assuming that the preset threshold strategy is (n, k), it means that the original key is sharded to obtain n key shards, and at least k key shards are required to reconstruct the original key, where n is the total number of key shards generated, that is, the preset first number can be n.
[0031] The blockchain storage module 12 can be used to store a preset first number of key shards in the private data sets of different participating organization nodes of the blockchain network.
[0032] For example, a blockchain network can be a public chain, a private chain, or a consortium chain. A blockchain network can include multiple organizations or participants, each of which is complete and independently operated, physically isolated from each other, and located in different environments or geographical locations. Each blockchain participating organization node has a dedicated private data set for storing key shards. The private data set of each participating organization node stores at least 1 / n key shards. For example, assuming n=5, indicating that the original key is sharded to obtain 5 key shards, if there are 5 participating organizations in the blockchain network, the number of key shards stored in each organization's private data set can be 1; if there are 3 participating organizations in the blockchain network, the number of key shards stored in the private data set of a particular organization can be 2. In other words, a participating organization cannot know the key shards of other organizations, thus avoiding the risk of single point failure and achieving secure sharded storage of keys.
[0033] It should be noted that the private data set on the blockchain organization can be understood as a special data chain. In essence, when the key shards are stored through the private data set, they are still stored in the blockchain as blocks. That is, the private data set can have the characteristics of the blockchain to ensure that only authorized entities can access it, such as offline key services.
[0034] The key reconstruction module 13 can be used to initiate a blockchain key sharding request when there is a need to reconstruct the original key, obtain at least a preset second number of key shards from the blockchain network, and reconstruct at least the preset second number of key shards to obtain the original key.
[0035] The preset second number is usually less than or equal to the preset first number. For example, assuming the preset threshold policy is (n, k), it means that the original key is fragmented to obtain n key fragments, and at least k key fragments are required to reconstruct the original key. That is, the preset second number can be k, and k is used to indicate that the key reconstruction module requires at least k key fragments when reconstructing the original key. That is, k can specifically be the minimum number of key fragments to be obtained by the key reconstruction module during reconstruction.
[0036] It should be noted that k can be specified according to n. Generally, it has no fixed value, but usually k ≤ n. For example, assume that the system can tolerate at most m malicious nodes or lost shares. The value of k can satisfy: 2m + 1 < k < n or m < k < n. If m = 3 and n = 5, when m < k < n is satisfied, the value of k can be 3 to 5. The embodiments of the present application do not limit this.
[0037] In some embodiments of the present application, the key sharding generation module 11 can perform sharding processing when the offline key service runs for the first time.
[0038] Specifically, the offline key service refers to the offline deployment of the key service. The offline deployment of the key service can ensure the security of the key as much as possible. The offline key service has the operation permissions of each participating organization node in the blockchain network and usually has the CA (Certificate Authority, which refers to a trusted third-party institution responsible for issuing, managing, and verifying digital certificates) certificates and relevant connection information of each participating organization node to implement the connection and interaction between the offline key service and the blockchain storage module running in the public cloud based on the CA certificate. Among them, the interaction between the offline key service and the public cloud depends on the output ability of the offline key service. Its output ability is manifested as providing a decryption function using the private key stored in it, and it can mainly serve applications, services, programs, etc. running on the public cloud, such as the blockchain storage module running in the public cloud in the embodiments of the present application.
[0039] Optionally, when the offline key service is started for the first time, it can automatically perform key generation, key sharding, and on-chain operations.
[0040] Exemplarily, as Figure 2 shown, when the offline key service is started for the first time, the key sharding generation module 11 can perform sharding processing on the original key according to a preset secret sharing algorithm and a preset threshold policy, such as the (n,k) threshold policy. Among them, the key sharding generation module 11 can be composed of one or more servers, and it can install an implementation program of the secret sharing algorithm. The installed implementation program is used to receive the input of the original key and generate key shards according to the preset (n,k) threshold policy.
[0041] The blockchain storage module 12 can store the n key shards obtained by sharding processing. Exemplarily, assume n = 5. The n key shards can be respectively stored in the private data sets of different participating organization nodes in the blockchain network, such as the private data set 1 of the organization 1 node, the private data set 2 of the organization 2 node, the private data set 3 of the organization 3 node, the private data set 4 of the organization 4 node, and the private data set 5 of the organization 5 node.
[0042] It should be noted that after the key sharding process is performed, the number of key shards obtained is related to the preset threshold strategy. When allocating blockchain organizations, the allocation can be combined with the preset strategy threshold and the number of blockchain organizations. The specific allocation strategy is not limited in the embodiment of the present application.
[0043] In the embodiment of the present application, when the key security segmentation is achieved through the secret sharing algorithm, the decentralized and tamper-proof characteristics of the blockchain can be utilized to store the key shards, breaking the limitations of centralized storage and improving the security of key storage.
[0044] In some embodiments of the present application, the key reconstruction module 13 can automatically initiate a blockchain key sharding request for reconstruction when the offline key service is started.
[0045] Specifically, the offline key service can connect and interact with the blockchain storage module running on the public cloud based on the CA certificate, requesting the blockchain storage module to obtain at least a second predetermined number of key shards. This can be manifested as requesting the smart contract service in the blockchain network to obtain at least the second predetermined number of key shards. It should be noted that the core module and smart contract service in the blockchain network are both deployed in a cluster.
[0046] like Figure 3 As shown, when the offline key service is started, the key reconstruction module 13 can request to obtain at least a preset second number of key shards from the blockchain network. Assuming that the preset threshold policy is the (n, k) threshold policy, the preset second number can be k. At this time, the corresponding k key shards can be obtained from the corresponding data sets of any k organization nodes, such as the private data set 1 of the organization 1 node, the private data set 2 of the organization 2 node, the private data set 3 of the organization 3 node, the private data set 4 of the organization 4 node, and the private data set 5 of the organization 5 node, and then the k key shards are used for reconstruction to obtain the original key.
[0047] In an embodiment of the present application, the offline key service running offline is responsible for generating keys and shards, and recovering keys based on key shards. It can automatically obtain key shards and reconstruct keys without human intervention, which can reduce the risk of key leakage and improve the security of key storage and acquisition.
[0048] It should be noted that the key storage module in the embodiment of the present application takes blockchain as an example, but the actual application scenario may not be limited to blockchain, and may be any other form of storage medium with distributed storage and decentralization characteristics. The embodiment of the present application does not limit this.
[0049] Reference Figure 4, shows a flowchart of the steps of a blockchain-based key sharding storage method provided by an embodiment of the present application, which is applied to Figure 1 The key sharding storage system shown may specifically include the following steps:
[0050] Step S401: Using a preset secret sharing algorithm, the original key is fragmented according to a preset threshold strategy to generate a preset first number of key fragments.
[0051] In the embodiment of the present application, blockchain and secret sharing technology can be combined to apply the secret sharing algorithm to key sharding processing to achieve secure key segmentation.
[0052] Optionally, assuming that the preset threshold strategy is (n, k), it means that the original key is sharded to obtain n key shards, and at least k key shards are required to reconstruct the original key, where n is the total number of key shards generated, that is, the preset first number can be n.
[0053] Specifically, a preset secret sharing algorithm can be used, with the original key as a constant term, to construct a first polynomial with a polynomial degree of k-1, and then n values are selected from the finite field of the polynomial, and n key shards are calculated based on the n values.
[0054] It should be noted that the specific operating architecture for key sharding generation can be as follows: Figure 2 As shown, the key sharding processing process can refer to the implementation process of the key sharding generation module 11 mentioned above, and the embodiment of the present application will not be described here in detail.
[0055] Step S402: Store a preset first number of key shards in private data sets of different participating organizations of the blockchain network.
[0056] In an embodiment of the present application, when secure key segmentation is achieved through a secret sharing algorithm, the decentralized and tamper-proof characteristics of the blockchain can be used to store key shards, breaking the limitations of centralized storage and improving the security of key storage.
[0057] For example, a blockchain network can be a public chain, a private chain, or a consortium chain. A blockchain network can include multiple organizations or participants, each of which is complete and independently operated, physically isolated from each other, and located in different environments or geographical locations. Each blockchain participating organization node has a dedicated private data set for storing key shards. The private data set of each participating organization node stores at least 1 / n key shards. For example, assuming n=5, indicating that the original key is sharded to obtain 5 key shards, if there are 5 participating organizations in the blockchain network, the number of key shards stored in each organization's private data set can be 1; if there are 3 participating organizations in the blockchain network, the number of key shards stored in the private data set of a particular organization can be 2. In other words, a participating organization cannot know the key shards of other organizations, thus avoiding the risk of single point failure and achieving secure sharded storage of keys.
[0058] Step S403: When there is a need to reconstruct the original key, a blockchain key sharding request is initiated, at least a preset second number of key shards are obtained from the blockchain network, and at least the preset second number of key shards are reconstructed to obtain the original key.
[0059] In an embodiment of the present application, after the blockchain network normally stores key shards, the private data center of each participating organization node stores key shards that do not meet the number of key shards required to reconstruct the original key, and it is impossible to know and obtain other key shards for recovery. The reconstruction and recovery of the original key belong to the authority of the offline key service.
[0060] In some embodiments of the present application, when there is a need to reconstruct the original key, that is, when the original key needs to be reconstructed, a blockchain key sharding request can be initiated to reconstruct the original key. When the offline key service is first started, it can automatically perform key generation, key sharding, and chain operations. Scenarios where the original key needs to be reconstructed include scenarios such as when the offline key service is restarted for some reason or when a new cluster node joins. In these scenarios, the original key reconstruction operation can be performed to obtain the original key.
[0061] Optionally, for reconstruction of the original key, at least a preset second number of key shards may be obtained from the blockchain network, where the preset second number is typically less than or equal to the preset first number. For example, assuming the preset threshold policy is (n, k), it indicates that the original key is sharded to obtain n key shards, and at least k key shards are required to reconstruct the original key. That is, the preset second number may be k, and k is used to indicate that the key reconstruction module requires at least k key shards when reconstructing the original key. That is, k may specifically be the minimum number of key shards to be obtained by the key reconstruction module during reconstruction.
[0062] It should be noted that the specific operating architecture for key reconstruction generation can be as follows Figure 3 As shown, the key preparation process can refer to the implementation process of the key reconstruction module 12 mentioned above, and the embodiment of the present application will not be described in detail here.
[0063] Specifically, any at least k key shards can be obtained from the private data sets of n participating organization nodes in the blockchain network, and then at least k key shards can be used to reconstruct a second polynomial with a polynomial degree of k-1 through the Lagrange interpolation method to obtain the original key as a constant term in the second polynomial.
[0064] Exemplarily, the preset secret sharing algorithm used may be, for example, the Shamir secret sharing algorithm or the Blakley secret sharing algorithm.
[0065] Taking the Shamir secret sharing algorithm as an example, assuming that the preset threshold strategy (n, k) is (5, 3), it means that the original key is sharded to obtain 5 key shards, and at least 3 key shards are required to reconstruct the original key.
[0066] The key sharding process can be expressed as taking the original key as the constant term of the polynomial to construct a polynomial of degree k-1=2, that is, a quadratic polynomial. At this time, 5 different x values can be selected on the finite field, and then the corresponding y values can be calculated to obtain 5 key shards, which can be (x1, y1), (x2, y2), (x3, y3), (x4, y4), and (x5, y5).
[0067] After the five key shards are divided, the five key shards can be stored in the private data sets of the five different blockchain participating organization nodes of the blockchain, for example Figure 2 and Figure 3 Shown are private dataset 1 of organization 1 node, private dataset 2 of organization 2 node, private dataset 3 of organization 3 node, private dataset 4 of organization 4 node, and private dataset 5 of organization 5 node.
[0068] For the key reconstruction process, it can be expressed as follows: when the original key needs to be reconstructed, any three key shards can be obtained from the five blockchain participating organizations of the blockchain, and the aforementioned three points obtained are used to reconstruct a quadratic polynomial through the Lagrange interpolation method, so as to obtain the original key based on the constant term of the reconstructed quadratic polynomial.
[0069] It should be noted that by setting an (n,k) threshold policy, the original key can be reconstructed only when at least k key shards are obtained. Even if some key shards are leaked or lost, as long as the number of leaks or losses is less than k, the original key remains secure, further enhancing key security. In the above example, at least three key shards are required to recover the complete original key. Even if any two key shards are leaked, the key will not be stolen. Moreover, even if any two key shards are unavailable for any reason, it will not affect the offline key service's ability to recover the complete original key.
[0070] In some embodiments of the present application, different threshold policies can be set to adjust the number of shards and the number of shards required for reconstruction according to different security requirements to meet diverse application scenarios, which is not limited by the embodiments of the present application.
[0071] In the embodiment of the present application, by combining blockchain with secret sharing technology, utilizing the threshold characteristics of secret sharing to shard the key and utilizing the characteristics of blockchain to store it, the single point failure risk of centralized storage can be avoided, and the tamper-proof characteristics of blockchain ensure the integrity and authenticity of shard storage, thereby achieving secure shard storage of keys and solving the high risk of key leakage in centralized storage. Moreover, the decentralized and distributed storage method of blockchain can be used to disperse key shards across multiple participating organizations, so that partial leakage does not affect security, reducing the risk of key loss caused by various malicious attacks or system problems, and enhancing system reliability. Furthermore, by setting different threshold strategies, the number of shards and the number of shards required for reconstruction can be adjusted according to different security requirements to meet diverse application scenarios and enhance the flexibility of key management. Furthermore, the key shard generation module and the key reconstruction module adopt a hybrid cloud operation mode with the blockchain storage module, which can prevent private keys from existing in untrusted public cloud environments and further improve the security of key storage.
[0072] It should be noted that for the method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present application are not limited by the order of the actions described, because according to the embodiments of the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present application.
[0073] The present application also provides an electronic device, Figure 5The provided electronic device 500 includes a memory 510, a processor 520, and a computer program 511 stored in the memory 510 and capable of running on the processor 520. When the computer program 511 is executed by the processor, the various processes of the above-mentioned blockchain-based key sharding storage method embodiment are implemented and can achieve the same technical effects. To avoid repetition, they will not be described here.
[0074] The present application also provides a computer-readable storage medium. Figure 6 The computer-readable storage medium 600 provided stores a computer program 511. When the computer program 511 is executed by the processor, the various processes of the above-mentioned blockchain-based key sharding storage method embodiment are implemented, and the same technical effects can be achieved. To avoid repetition, they will not be described here.
[0075] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0076] It should be noted that the terms "first", "second", etc. in the description and claims of the embodiments of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate so that the embodiments described herein can be implemented in an order other than that shown or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or modules is not necessarily limited to the steps or modules clearly listed, but may include other steps or modules that are not clearly listed or inherent to these processes, methods, products or devices. The division of modules that appears in the embodiments of the present application is only a logical division. In actual applications, there may be other division methods. For example, multiple modules can be combined into or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, and the indirect coupling or communication connection between modules can be electrical or other similar forms, which are not limited in the embodiments of the present application. Moreover, the modules or sub-modules described as separate components may or may not be physically separated, may or may not be physical modules, or may be distributed into multiple circuit modules, and some or all of the modules may be selected according to actual needs to achieve the purpose of the embodiment of the present application.
[0077] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0078] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and modules described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0079] In the several embodiments provided in the embodiments of the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules, which can be electrical, mechanical or other forms.
[0080] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected to achieve the purpose of the present embodiment according to actual needs.
[0081] In addition, the functional modules in each embodiment of the present application can be integrated into a processing module, or each module can exist physically separately, or two or more modules can be integrated into a module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules. If the integrated modules are implemented in the form of software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium.
[0082] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the embodiments may be implemented in the form of a computer program product.
[0083] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in accordance with the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that can be stored on a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, hard disk, or magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).
[0084] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0085] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 These computer program instructions can also be loaded into a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for implementing the process in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0086] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0087] Finally, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0088] The above is a detailed introduction to the technical solutions provided in the embodiments of the present application. Specific examples are used in the embodiments of the present application to illustrate the principles and implementation methods of the embodiments of the present application. The description of the above embodiments is only used to help understand the methods and core ideas of the embodiments of the present application. At the same time, for those skilled in the art, according to the ideas of the embodiments of the present application, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as a limitation on the embodiments of the present application.
Claims
1. A blockchain-based key sharding storage system, characterized in that: The system includes a key shard generation module, a blockchain storage module, and a key reconstruction module; the key shard generation module and the key reconstruction module run on an offline key service in an offline environment, and the blockchain storage module runs on a public cloud; The key shard generation module is configured to employ a preset secret sharing algorithm to shard the original key according to a preset threshold strategy to generate a preset first number of key shards; The blockchain storage module is configured to store the preset first number of key shards in the private data sets of different participating organization nodes of the blockchain network respectively; The key reconstruction module is configured to initiate a blockchain key sharding request, obtain at least a preset second number of key shards from the blockchain network, and reconstruct the at least preset second number of key shards to obtain the original key; The preset second number is less than or equal to the preset first number; Wherein, the key fragmentation generation module performs fragmentation processing when the offline key service is first run; The key reconstruction module automatically initiates the blockchain key sharding request for reconstruction when the offline key service is started.
2. The system according to claim 1, wherein: The preset threshold strategy is (n, k), wherein the preset first number is n, which is used to indicate the total number of key shards generated by the key shard generation module; the preset second number is k, which is used to indicate that the key reconstruction module requires at least k key shards when reconstructing the original key.
3. The system according to claim 2, characterized in that The private data set of each participating organization node stores at least 1 / n key shards.
4. The system according to claim 1, wherein: The offline key service has operation authority of each participating organization node of the blockchain network to request the blockchain storage module to obtain at least a preset second number of key shards.
5. A key sharding storage method based on blockchain, characterized in that: Applied to the key sharding storage system according to any one of claims 1 to 4, the method comprises: Using a preset secret sharing algorithm, the original key is sharded according to a preset threshold strategy to generate a preset first number of key shards; Storing the preset first number of key shards in private data sets of different participating organizations of the blockchain network respectively; When there is a need to reconstruct the original key, a blockchain key shard request is initiated, at least a preset second number of key shards are obtained from the blockchain network, and the at least preset second number of key shards are reconstructed to obtain the original key; the preset second number is less than or equal to the preset first number.
6. The method according to claim 5, characterized in that The preset threshold strategy is (n, k), wherein the preset first number is n, which is used to indicate the total number of key shards generated; the preset second number is k, which is used to indicate that at least k key shards are required when reconstructing the original key.
7. The method according to claim 6, characterized in that The method of adopting a preset secret sharing algorithm to shard the original key according to a preset threshold strategy to obtain a preset first number of key shards includes: Using a preset secret sharing algorithm, the original key is used as a constant term to construct a first polynomial with a polynomial degree of k-1; N values are selected from a finite field of the polynomial, and n key shards are obtained by calculation based on the n values.
8. The method according to claim 6, characterized in that The obtaining at least a preset second number of key shards from the blockchain network and reconstructing the at least preset second number of key shards to obtain the original key includes: Obtain at least k key shards from the private datasets of n participating organization nodes of the blockchain network; The at least k key fragments are used to reconstruct a second polynomial with a polynomial degree of k-1 through a Lagrange interpolation method to obtain the original key as a constant term in the second polynomial.
9. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the blockchain-based key sharding storage method according to any one of claims 5 to 8 is implemented.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, it implements the blockchain-based key sharding storage method as described in any one of claims 5 to 8.
Citation Information
Patent Citations
Block chain data writing and accessing method and device
CN113259123A
Systems and methods for blockchain-enabled end-to-end encryption
US12341910B1
Consensus service for blockchain networks
US20220103532A1