Private key storage method and device and related product

By splitting the private key into multiple shares and storing them in batches to different private key storage parties, the problem of high private key storage overhead is solved, and the efficiency and security of private key storage are achieved, which is suitable for the field of blockchain technology.

CN120671155APending Publication Date: 2025-09-19TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410317548.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-19
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

In the existing technology, there is a problem of high storage overhead when storing private keys. In particular, when a new private key storage party joins the blockchain, all private key shares need to be retrieved and redistributed, resulting in a continuous increase in storage overhead.

Method used

The private key to be stored is split into M private key share groups and stored in batches to two different private key storage parties until the Mth private key share group is stored to the Nth private key storage party and the conflicting party. A 2-out-of-n additive secret sharing mechanism is used to ensure that only the corresponding private key shares are distributed each time a new private key storage party joins.

Benefits of technology

By distributing private key shares in batches, frequent retrieval and redistribution are avoided, the storage overhead of private keys is reduced, the security and efficiency of private key storage are improved, and the optimal number of private key shares held by each storage party is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671155A_ABST
    Figure CN120671155A_ABST
Patent Text Reader

Abstract

The invention discloses a private key storage method and device and a related product. And ending the storage operation of the to-be-stored private key until the private key share in the Mth private key share group in the M private key share groups is stored in the Nth private key storage party and the conflict party corresponding to the Nth private key storage party in the N private key storage parties. According to the method, the private key shares in each private key share group are stored in two different private key storage parties in batches until the private key shares in the Mth private key share group are stored in the Nth private key storage party and the conflict party corresponding to the Nth private key storage party, so that the private key shares are distributed and stored in batches, and the private key shares in the Mth private key share group are stored in the Nth private key storage party and the conflict party corresponding to the Nth private key storage party. The problem that when a new private key storage party joins the block chain, the private key share needs to be withdrawn and re-distributed, so that the overhead is increased is solved, and the storage overhead of the private key is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of blockchain technology, and in particular to a private key storage method, device, and related products. Background Art

[0002] With the continuous development of information technology, data encryption has become a crucial part of protecting data privacy. Data is typically encrypted using a public key, and then decrypted using a private key when needed to ensure data security. However, the storage of private keys is typically entrusted to a single private key storage entity, which may lose or leak the private key due to errors, resulting in low security.

[0003] Related technologies propose splitting a private key into multiple private key shares and distributing them to multiple private key storage entities to improve the security of private key storage. However, since related technical solutions distribute multiple private key shares to multiple private key storage entities at once, when a new private key storage entity joins the blockchain, all distributed private key shares must be retrieved from the multiple private key storage entities and redistributed to all private key storage entities, increasing the storage overhead of private keys.

[0004] Therefore, how to reduce the storage overhead of private keys has become a technical problem that needs to be solved urgently in the current field. Summary of the Invention

[0005] The embodiments of the present application provide a private key storage method, device and related products, aiming to reduce the storage overhead of private keys.

[0006] The first aspect of the present application provides a private key storage method, comprising:

[0007] Obtaining a private key to be stored, and determining N private key storage parties, where the private key storage parties are used to store private key shares corresponding to the private key to be stored;

[0008] Splitting the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties to obtain M private key share groups corresponding to the private key to be stored, where the sum of the private key shares in each private key share group is equal to the private key to be stored, and N is greater than M;

[0009] If N is greater than or equal to 3, and M is greater than or equal to 2, then the private key shares in the first private key share group in the M private key share groups are stored in the first private key storage party and the second private key storage party in the N private key storage parties;

[0010] storing the private key shares in the kth private key share group among the M private key share groups to the first private key storage party among the N private key storage parties that does not store the private key shares and the corresponding conflicting party, where k is greater than 1 and k is less than or equal to M;

[0011] Until the private key share in the Mth private key share group in the M private key share groups is stored in the Nth private key storage party among the N private key storage parties and the conflicting party corresponding to the Nth private key storage party, the storage operation for the private key to be stored is terminated, wherein the conflicting party includes the private key storage party that holds the least number of private key shares among the private key storage parties that have stored private key shares.

[0012] A second aspect of the present application provides a private key storage device, comprising:

[0013] A storage party private key acquisition unit, configured to acquire a private key to be stored and determine N private key storage parties, wherein the private key storage parties are configured to store private key shares corresponding to the private key to be stored;

[0014] a to-be-stored private key splitting unit, configured to split the to-be-stored private key according to the number N of private key storage parties corresponding to the N private key storage parties, to obtain M private key share groups corresponding to the to-be-stored private key, wherein the sum of the private key shares in each private key share group is equal to the to-be-stored private key, and N is greater than M;

[0015] a first private key share storage unit, configured to store the private key shares in a first private key share group among the M private key share groups to a first private key storage and a second private key storage among the N private key storages if N is greater than or equal to 3 and M is greater than or equal to 2;

[0016] a second private key share storage unit, configured to store the private key share in the kth private key share group among the M private key share groups to a first private key storage party among the N private key storage parties that does not store a private key share and a corresponding conflicting party, wherein k is greater than 1 and is less than or equal to M;

[0017] The third private key share storage unit is used to store the private key shares in the Mth private key share group among the M private key share groups until the private key shares in the Nth private key storage party among the N private key storage parties and the conflicting party corresponding to the Nth private key storage party are stored, thereby ending the storage operation for the private key to be stored, wherein the conflicting party includes the private key storage party that holds the least number of private key shares among the private key storage parties that have stored private key shares.

[0018] A third aspect of the present application provides a computer device, the device comprising a processor and a memory:

[0019] The memory is used to store a computer program and transmit the computer program to the processor;

[0020] The processor is configured to execute the steps of the private key storage method provided in the first aspect according to the instructions in the computer program.

[0021] In a fourth aspect, the present application provides a computer-readable storage medium, which is used to store a computer program. When the computer program is executed by a computer device, the steps of the private key storage method provided in the first aspect are implemented.

[0022] The fifth aspect of the present application provides a computer program product, including a computer program, which, when executed by a computer device, implements the steps of the private key storage method provided in the first aspect.

[0023] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:

[0024] In the technical solution of the present application, the private key to be stored is first obtained, and N private key storage parties are determined. After that, the private key to be stored is split according to the number N of private key storage parties corresponding to the N private key storage parties, and M private key share groups corresponding to the private key to be stored are obtained; finally, if N is greater than or equal to 3, and M is greater than or equal to 2, the private key shares in the first private key share group in the M private key share groups are stored in the first private key storage party and the second private key storage party in the N private key storage parties, and the private key shares in the kth private key share group in the M private key share groups are stored in the first private key storage party that does not store private key shares among the N private key storage parties and the corresponding conflicting party, until the private key shares in the Mth private key share group in the M private key share groups are stored in the Nth private key storage party among the N private key storage parties and the conflicting party corresponding to the Nth private key storage party.

[0025] It can be seen that in this application, it is proposed to store the private key shares in each private key share group in batches to two different private key storage parties, until the private key shares in the Mth private key share group are stored in the Nth private key storage party and the conflicting party corresponding to the Nth private key storage party, so as to distribute the private key shares in batches, and even when a new private key storage party joins, the private key shares will be distributed to the newly joined private key storage party, thereby avoiding the problem of increased overhead caused by the need to recover and redistribute private key shares when a new private key storage party joins the blockchain, and reducing the storage overhead of the private key. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 A private key share distribution flow chart provided for related technologies;

[0027] Figure 2Another private key share distribution flow chart provided for related technologies;

[0028] Figure 3 A scenario architecture diagram of a private key storage method provided in an embodiment of the present application;

[0029] Figure 4 A flowchart of a private key storage method provided in an embodiment of the present application;

[0030] Figure 5 A schematic diagram of private key share distribution in a private key storage method provided in an embodiment of the present application;

[0031] Figure 6 A schematic diagram of private key share distribution in another private key storage method provided in an embodiment of the present application;

[0032] Figure 7 A schematic diagram of distributing private key shares in another private key storage method provided in an embodiment of the present application;

[0033] Figure 8 A flowchart of another private key storage method provided in an embodiment of the present application;

[0034] Figure 9 A flowchart of private key distribution and restoration in a private key storage method provided in an embodiment of the present application;

[0035] Figure 10 A schematic diagram of the structure of a private key storage device provided in an embodiment of the present application;

[0036] Figure 11 A schematic diagram of the structure of the server in the embodiment of the present application;

[0037] Figure 12 This is a structural diagram of a terminal device in an embodiment of the present application. DETAILED DESCRIPTION

[0038] The embodiments of the present application are described below with reference to the accompanying drawings.

[0039] With the continuous development of information technology, data encryption has become a crucial part of protecting data privacy. Data is typically encrypted using a public key, and then decrypted using a private key when needed to ensure data security. However, the storage of private keys is typically entrusted to a single private key storage entity, which may lose or leak the private key due to errors, resulting in low security.

[0040] Related technologies propose splitting a private key into multiple private key shares and distributing them to multiple private key storage entities within a blockchain. This allows multiple private key storage entities to store the private key shares, thereby improving the security of private key storage. It should be noted that in related technologies, the number of private key shares to be generated is determined based on the number of storage entities within the multiple private key storage entities to facilitate subsequent distribution. Furthermore, during the distribution process, it must be ensured that the private key shares held by any two private key storage entities are sufficient for subsequent private key recovery.

[0041] like Figure 1 As shown, Figure 1 A private key share distribution flow chart provided for related technologies, Figure 1 In the proposed scheme, multiple private key storage parties are three private key storage parties, and the private key S is split into three private key shares {S1, S2, S3}, where S = S1 + S2 + S3. When distributing private key shares, it is necessary to ensure that the private key shares held by any two private key storage parties are sufficient for subsequent private key recovery. That is, the private key shares S1 and S2 can be distributed to the first of the three private key storage parties, the private key shares S1 and S3 can be distributed to the second of the three private key storage parties, and the private key shares S2 and S3 can be distributed to the third of the three private key storage parties.

[0042] like Figure 2 As shown, Figure 2 Another private key share distribution flow chart provided for related technologies, in Figure 2 It is proposed that the multiple private key storage parties are four private key storage parties, that is, on the basis of the three private key storage parties, a new private key storage party is added to determine four private key storage parties, and the private key S is split into 4 private key shares {S1, S2, S3, S4}, where S = S1+S2+S3+S4. At this time, when distributing private key shares, it is necessary to ensure that the private key shares held by any two private key storage parties can meet the subsequent recovery of the private key, that is, it is necessary to redistribute private key shares to each private key storage party.

[0043] At this time, the S2, S3 and S4 private key shares can be distributed to the first private key storage party among the four private key storage parties, the S1, S3 and S4 private key shares can be distributed to the second private key storage party among the four private key storage parties, the S1, S2 and S4 private key shares can be distributed to the third private key storage party among the four private key storage parties, and the S1, S2 and S3 private key shares can be distributed to the fourth private key storage party among the four private key storage parties.

[0044] Combine Figure 1 and Figure 2As can be seen, the relevant technical solution is to distribute multiple private key shares to multiple private key storage parties at one time. When a new private key storage party joins the blockchain, all previously distributed private key shares need to be reclaimed from the multiple private key storage parties. In combination with the new private key storage party, private key shares must be redistributed to other historical private key storage parties in the blockchain to ensure that the private key shares held by any two private key storage parties are sufficient for subsequent private key recovery. In addition, with each additional private key storage party in the relevant technical solution, the number of private key shares distributed to each private key storage party also increases, which will lead to a continuous increase in private key storage overhead. Therefore, how to reduce private key storage overhead has become a technical problem that needs to be solved urgently in the current field.

[0045] In view of the above problems, a private key storage method, device and related products are provided in the present application, the purpose of which is to reduce the storage overhead of the private key. In the technical solution provided in the present application, first, the private key to be stored is obtained, and N private key storage parties are determined; then, the private key to be stored is split according to the number N of private key storage parties corresponding to the N private key storage parties, and M private key share groups corresponding to the private key to be stored are obtained; finally, if N is greater than or equal to 3, and M is greater than or equal to 2, the private key shares in the first private key share group in the M private key share groups are stored in the first private key storage party and the second private key storage party in the N private key storage parties, and the private key shares in the kth private key share group in the M private key share groups are stored in the first private key storage party that does not store private key shares in the N private key storage parties and the corresponding conflicting party, until the private key shares in the Mth private key share group in the M private key share groups are stored in the Nth private key storage party and the conflicting party corresponding to the Nth private key storage party in the N private key storage parties.

[0046] It can be seen that the present application proposes to divide the private keys to be stored into M private key share groups according to N private key storage parties, and then store the private key shares in each private key share group in two different private key storage parties respectively, so as to improve the storage efficiency of the private key by distributing the private key shares in pairs. In addition, the present application also proposes to distribute the private key shares in each private key share group to the two private key storage parties in batches, so that the two private key storage parties respectively store the private key shares until the private key shares in the Mth private key share group are stored in the conflicting parties corresponding to the Nth private key storage party and the Nth private key storage party.

[0047] In this way, a scenario in which a new private key storage party joins the blockchain every time is simulated, and private key shares are stored in batches. Even when a new private key storage party joins, the private key shares of the newly joined private key storage party are stored in batches, thereby avoiding the problem of increased overhead caused by the need to retrieve, redistribute and store private key shares when a new private key storage party joins the blockchain, reducing the storage overhead of private keys, and thus realizing distributed storage of private keys, and improving the security of private key storage. Compared with related technologies, it ensures that the number of private key shares held by each private key storage party is optimal and less than the number of private key shares held by the private key storage party in the related technical solutions.

[0048] The execution subject of the private key storage method provided in the embodiment of the present application may be a terminal device. For example, the private key to be stored is obtained on the terminal device, and N private key storage parties are determined. As an example, the terminal device may specifically include but is not limited to a mobile phone, a desktop computer, a tablet computer, a laptop computer, a PDA, an intelligent voice interaction device, a smart home appliance, a vehicle-mounted terminal, an aircraft, etc. The execution subject of the private key storage method provided in the embodiment of the present application may also be a server, that is, the private key to be stored may be obtained on the server, and N private key storage parties may be determined. In addition, the private key storage method provided in the embodiment of the present application may also be executed collaboratively by the terminal device and the server. Among them, the terminal and the server may be directly or indirectly connected via wired or wireless communication, and this application does not limit this. Therefore, the embodiment of the present application does not limit the implementation subject of the technical solution of the present application.

[0049] Figure 3 This diagram illustrates an example scenario architecture of a private key storage method, including a server and various terminal devices. Figure 3 The server shown can be a standalone physical server, a server cluster composed of multiple physical servers, or a distributed system. Furthermore, the server can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.

[0050] Cloud technology refers to a hosting technology that unifies hardware, software, and network resources within a wide or local area network (WAN) to enable data computing, storage, processing, and sharing. Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model. It can form a resource pool that can be used on demand with flexibility and convenience. Cloud computing technology will become a crucial support. Backend services for technical network systems, such as video websites, image websites, and more portals, require extensive computing and storage resources. With the rapid development and application of the internet industry, every item will likely have its own unique identification mark and will need to be transmitted to backend systems for logical processing. Data of varying levels will be processed separately, and data from all industries will require a strong system backend, which can only be achieved through cloud computing.

[0051] The private key storage method provided in this application mainly relates to big data. Big data refers to a collection of data that cannot be captured, managed and processed by conventional software tools within a certain time frame. It is a massive, high-growth and diversified information asset that requires new processing modes to have stronger decision-making power, insight discovery power and process optimization capabilities. With the advent of the cloud era, big data has also attracted more and more attention. Big data requires special technologies to effectively process large amounts of data within a tolerable time. Technologies suitable for big data include large-scale parallel processing databases, data mining, distributed file systems, distributed databases, cloud computing platforms, the Internet and scalable storage systems. In the embodiments of the present application, big data is mainly used to realize the distribution of private key shares corresponding to the private key to be stored, thereby realizing distributed storage of private keys, thereby improving the security of private key storage and reducing the storage overhead of private keys.

[0052] See also Figure 4 , which is a flow chart of a private key storage method provided by an embodiment of the present application. Figure 4 The private key storage method shown includes the following steps:

[0053] S401: Acquire the private key to be stored and determine N private key storage parties.

[0054] In this step, the private key storage party includes the client in the blockchain, wherein the private key to be stored and the public key corresponding to the private key to be stored form a key pair, the public key corresponding to the private key to be stored is used to encrypt data, and the private key to be stored is used to decrypt data, and the private key storage party is used to store the private key share corresponding to the private key to be stored in the blockchain, thereby realizing distributed storage of the private key to be stored, so that the private key to be stored can be restored through the cooperation of some private key storage parties in the subsequent process, thereby improving the security and availability of the blockchain private key.

[0055] It should be noted that before determining the N private key storage parties, it is necessary to obtain N private key storage parties to be sorted. The N private key storage parties to be sorted include the private key storage parties that will participate in the storage of private key shares in the blockchain, and each private key storage party to be sorted has a blockchain joining time. At this time, the N private key storage parties to be sorted can be parsed to obtain the joining time corresponding to each of the N private key storage parties to be sorted. The joining time can be understood as the time when each private key storage party to be sorted joined the blockchain.

[0056] Finally, the N private key storage parties to be sorted can be sorted according to their joining time to obtain N private key storage parties. For example, the N private key storage parties to be sorted are 3 private key storage parties to be sorted (U1, U2, and U3), where U1's joining time is 2024.1.1, 00:00:03; U2's joining time is 2024.1.1, 00:00:01; and U3's joining time is 2024.1.1, 00:00:07. At this time, U1, U2, and U3 can be sorted according to the joining time of each private key storage party to be sorted to obtain the 3 sorted private key storage parties (U2, U1, and U3).

[0057] In the present application, each of the N private key storage parties can be numbered, that is, the ranking value of the private key storage party among the N private key storage parties is the number of the private key storage party, for example: U2 is numbered 1, U1 is numbered 2, and U3 is numbered 3. In this way, when a new private key storage party joins, it can be numbered immediately after the N private key storage parties, so that in the subsequent process, the conflicting party corresponding to the first private key storage party among the N private key storage parties that does not store the private key share can be quickly determined according to the number.

[0058] S402: Split the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties to obtain M private key share groups corresponding to the private key to be stored.

[0059] In this step, the sum of the private key shares in each private key share group is equal to the private key to be stored, where N is greater than M. It should be noted that before the application splits the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties and obtains the M private key share groups corresponding to the private key to be stored, the logarithmic function formula and the finite ring Z can also be obtained. 2l , where the logarithmic function formula is used to determine the number of private key share groups, the finite ring Z 2l Used to generate random numbers to obtain private key shares.

[0060] In one feasible implementation, the logarithmic function formula can be expressed as formula (1), which is specifically embodied as follows:

[0061]

[0062] in, is a rounding function, where M is the number of private key share groups, and N is the number of storage parties corresponding to N private key storage parties. For example, if the number of storage parties N is 2, then the number of private key share groups M is 1; if the number of storage parties N is 3 or 4, then the number of private key share groups M is 2.

[0063] Specifically, in the present application, the N private key storage parties can be counted first to obtain the number N of storage parties corresponding to the N private key storage parties. After that, the number N of storage parties can be substituted into the logarithmic function formula for calculation to obtain the number M of private key share groups corresponding to the private key to be stored, that is, the private key to be stored is processed to generate M number of private key share groups. Finally, when it is known that M number of private key share groups will be generated, a random number is selected from the finite ring in combination with the private key to be stored to obtain M private key share groups corresponding to the private key to be stored.

[0064] Next, the process of obtaining M private key share groups is further described. After determining the number of private key shares M, this application needs to select M random number pairs on a finite ring based on the private key to be stored, and each random number pair includes two different random numbers. After this, the M random number pairs can be used as the M private key share groups corresponding to the private key to be stored. It can be understood that the sum of the random numbers in each random number pair is equal to the private key to be stored, thereby ensuring that the generated random number is the correct value, which can achieve the subsequent recovery of the private key to be stored.

[0065] It can be further understood that, since each random number pair includes two different random numbers, each private key share group includes two different private key shares. It should also be noted that, before obtaining the M private key share groups corresponding to the private key to be stored, the present application can sort and number each private key share group according to the generation time of each random number pair, wherein the numerical order of sorting and numbering is 1-M, thereby obtaining M private key share groups, so that the private key share groups can be quickly extracted later, and the tedious problems caused by repeated extraction of private key share groups can be avoided, thereby improving the distribution efficiency of private key shares.

[0066] In another possible implementation, the private key share group can be represented as S z , two different private key shares in the private key share group can be expressed as and in and The superscript z indicates the share group number to which the private key share group belongs (i.e., the ranking value / number value of the private key share group in the M private key share groups). and The subscripts b and c indicate the order of the private key shares in the z private key share group, that is, the order of the private key shares can be determined according to and Different numbers to determine and Two different private key shares belong to the same private key share group. For example: private key share group S1 includes and That is to say

[0067] S403: If N is greater than or equal to 3, and M is greater than or equal to 2, the private key shares in the first private key share group in the M private key share groups are stored in the first private key storage party and the second private key storage party in the N private key storage parties.

[0068] It should be noted that before executing step S403, it is necessary to determine whether N is greater than or equal to 3, and whether M is greater than or equal to 2. It is understandable that when M is greater than or equal to 2, it means that two or more private key share groups have been generated. At this time, these two or more private key share groups can be stored in batches to the private key storage party to simulate the situation where a new private key storage party joins the blockchain each time, thereby realizing the batch distribution of private key shares.

[0069] Furthermore, before executing step S403, multiple private key share groups have been sorted to obtain M private key share groups, and multiple private key storage parties have been sorted to obtain N private key storage parties. At this time, when N is greater than or equal to 3, and M is greater than or equal to 2, it is necessary to distribute the private key shares in the first private key share group in the M private key share groups to the first private key storage party and the second private key storage party in the N private key storage parties, so that the first private key storage party and the second private key storage party can respectively store the private key shares in the first private key share group, so as to ensure that two private key storage parties can realize private key storage in the initial stage of private key share storage, thereby ensuring the success of subsequent private key restoration.

[0070] It should also be noted that the private key storage process in this application is mainly implemented using 2-out-of-n additive secret sharing, where the 2 in 2-out-of-n additive secret sharing means that private key shares need to be distributed to two private key storage parties each time, so that the two private key storage parties to which the private key shares are distributed can store the private key shares, and the n in 2-out-of-n additive secret sharing means that private key shares can be distributed to n private key storage parties, so that the n private key storage parties to which the private key shares are distributed can store the private key shares.

[0071] Next, we will use 2-out-of-2 as an example to introduce the distribution and storage process of private key shares:

[0072] When N is greater than or equal to 3, and M is greater than or equal to 2, it can be determined based on 2-out-of-2 that two private key storage parties are allowed to be distributed and store private key shares this time, and private key shares need to be distributed to two private key storage parties each time, that is, the N private key storage parties can be determined as two private key storage parties, and the Mth private key share group can be determined as the first private key share group.

[0073] After that, the first private key storage party and the second private key storage party among the N private key storage parties can be directly extracted, where the first private key storage party can be understood as the private key storage party ranked first among the N private key storage parties, and the second private key storage party can be understood as the private key storage party ranked second among the N private key storage parties.

[0074] It is also possible to directly extract the M private key share groups to obtain the first private key share group among the M private key share groups, where the first private key share group can be understood as the private key share group that is ranked first among the M private key share groups, and the first private key share group includes the first private key share and the second private key share, so that the first private key share is stored in the first private key storage party, and the second private key share is stored in the second private key storage party.

[0075] like Figure 5 As shown, Figure 5 A schematic diagram of private key share distribution in a private key storage method provided in an embodiment of the present application, Figure 5 In this article, we take two private key storage parties as an example to introduce the process of distributing private key shares to the two private key storage parties. Figure 5 The two private key storage parties are U1 and U2, and the private key shares in the private key share group are and At this time, the private key share S1 1 Distribute to the private key storage party U1, so that the private key storage party U1 stores the private key share And the private key share Distribute to the private key storage party U2, so that the private key storage party U2 stores the private key share

[0076] S404: The private key shares in the kth private key share group among the M private key share groups are stored in the first private key storage party among the N private key storage parties that does not store the private key shares and the corresponding conflicting party.

[0077] In this step, the conflicting party includes the private key storage party with the least number of private key shares among the private key storage parties that have stored private key shares, k is greater than 1, and k is less than or equal to M. It can be understood that in step S404, the first private key storage party and the second private key storage party among the N private key storage parties, and the first private key share group among the M private key share groups have been extracted. At this time, there are still private key storage parties among the N private key storage parties that do not hold private key shares, and there are still private key share groups among the M private key share groups that have not distributed private key shares.

[0078] At this time, the first private key storage party among the N private key storage parties that has not stored the private key share, and the conflicting party corresponding to the first private key storage party among the N private key storage parties that has not stored the private key share can be determined, so as to facilitate storing the private key share in the kth private key share group among the M private key share groups, thereby simulating the situation where new storage parties join each time, and gradually and incrementally realizing the storage of private key shares.

[0079] Next, we will use 2-out-of-3 as an example to introduce the distribution and storage process of private key shares:

[0080] At this point, based on the 2-out-of-3 rule, it can be determined that three private key storage parties are allowed to be distributed and store private key shares. Private key shares are distributed to two private key storage parties at a time. This means that N private key storage parties are determined to be 3 private key storage parties, and the k-th private key share group is equal to the M-th private key share group as the second private key share group. Next, the conflicting party corresponding to the third private key storage party can be determined, and the private key shares of the second private key share group can be distributed to the conflicting party corresponding to the third private key storage party and the third private key storage party, thus achieving the distribution of private key shares in batches.

[0081] like Figure 6 As shown, Figure 6 A schematic diagram of private key share distribution in another private key storage method provided in an embodiment of the present application, Figure 6 In this article, we take three private key storage parties as an example to introduce the process of distributing private key shares to these three private key storage parties. Figure 6 The three private key storage parties are U1, U2 and U3. U1 can be identified as the conflicting party of U3. The first group of private key shares in the private key share group is and ( and is a private key share group), the second group of private key shares in the private key share group is and ( and is a private key share group), the private key share held by the private key storage party U1 is The private key share held by the private key storage party U2 is At this time, the private key share Distribute to the private key storage party U1 so that the private key storage party U1 can store the private key share and share the private key Distribute to the private key storage party U3 so that the private key storage party U3 can store the private key share

[0082] It should be noted that before storing the private key shares in the kth private key share group in the M private key share groups to the first private key storage party that has not stored the private key shares among the N private key storage parties and the corresponding conflicting party, the present application can also obtain the private key storage party that has stored the private key shares among the N private key storage parties.

[0083] After this, since the N private key storage parties are sorted, the first private key storage party among the N private key storage parties that does not store a private key share can be determined based on the sorting of each private key storage party among the N private key storage parties and the private key storage parties among the N private key storage parties that have stored a private key share. In other words, the first private key storage party among the N private key storage parties that does not store a private key share can be determined based on the sorting of the private key storage parties among the N private key storage parties that have stored a private key share. In this way, determining the private key storage parties based on the sorting can better manage the private key storage parties that do not hold a private key share and facilitate the subsequent distribution of private key shares.

[0084] In an embodiment of the present application, after determining the first private key storage party among N private key storage parties that does not store a private key share, it is also necessary to determine the conflicting party corresponding to the first private key storage party among the N private key storage parties that does not store a private key share. Specifically, the number of private key shares held by the private key storage parties that have stored a private key share among the N private key storage parties can be calculated to obtain the number of private key shares held by each private key storage party that has stored a private key share among the N private key storage parties.

[0085] After this, the number of private key shares held by each of the N private key storage parties that has stored private key shares can be compared to obtain a comparison result. The comparison result is divided into two cases, which are described below. The conflicting party corresponding to the first private key storage party that does not store private key shares among the N private key storage parties can be determined based on these two cases.

[0086] The first case is: if the comparison result shows that among the N private key storage parties that have stored private key shares, there is a private key storage party that holds the least number of private key shares, then the private key storage party that holds the least number of private key shares among the N private key storage parties that have stored private key shares will be used as the conflicting party corresponding to the first private key storage party that has not stored private key shares among the N private key storage parties. In other words, if there is only one private key storage party that holds the least number of private key shares among multiple private key storage parties that have stored private key shares, then this private key storage party will be used as the conflicting party corresponding to the first private key storage party that has not stored private key shares among the N private key storage parties.

[0087] The second scenario is: if the comparison result shows that among the N private key storage parties that have stored private key shares, there are multiple private key storage parties that hold the least number of private key shares, then the private key storage party with the smallest ranking value among the multiple private key storage parties will be used as the conflicting party corresponding to the first private key storage party that has not stored a private key share among the N private key storage parties. In other words, if among the multiple private key storage parties that have stored private key shares, there are only multiple private key storage parties that hold the least number of private key shares, then the private key storage party with the smallest ranking value among the multiple private key storage parties will be used as the conflicting party corresponding to the first private key storage party that has not stored a private key share among the N private key storage parties.

[0088] As can be understood, when there are multiple private key storage parties each holding the smallest number of private key shares, the ranking values ​​of these multiple private key storage parties can be determined, and the private key storage party with the smallest ranking value can be designated as the conflicting party, thereby ensuring that the private key can be successfully recovered during subsequent private key recovery. In this way, since private key shares will subsequently need to be distributed to the conflicting parties, the private key storage party holding the smallest number of private key shares can be designated as the conflicting party. This ensures that each private key storage party receives the optimal number of private key shares, thereby optimizing storage overhead.

[0089] In another achievable implementation, after determining the first private key storage party among N private key storage parties that does not store a private key share, the present application also has another method for determining the conflicting party corresponding to the first private key storage party among N private key storage parties that does not store a private key share. Specifically, first obtain a conflicting party calculation formula, wherein the conflicting party calculation formula is used to determine the conflicting party corresponding to the first private key storage party among N private key storage parties that does not store a private key share, wherein the conflicting party calculation formula can be expressed as formula (2), and formula (2) is specifically embodied as follows:

[0090]

[0091] Wherein, i represents the ranking value of the i-th private key storage party (i.e., the first private key storage party among the N private key storage parties that does not store the private key share) among the N private key storage parties, conflict represents the ranking value of the conflicting party corresponding to the i-th private key storage party among the N private key storage parties, i is greater than or equal to 3, conflict is less than i, and i is less than or equal to N.

[0092] After that, the present application can determine the ranking value of the first private key storage party among the N private key storage parties that does not store the private key share based on the first private key storage party among the N private key storage parties that does not store the private key share, and bring the ranking value into the conflicting party calculation formula for calculation to obtain the conflicting party value, and finally determine the conflicting party corresponding to the first private key storage party among the N private key storage parties that does not store the private key share based on the conflicting party value, wherein the conflicting party value includes the ranking value of the conflicting party corresponding to the first private key storage party among the N private key storage parties that does not store the private key share.

[0093] It should also be noted that in this application, the conflicting party calculation formula can be directly used to determine the conflicting party corresponding to the i-th private key storage party. When there are multiple private key storage parties with the least number of private key shares, the conflicting party calculation formula can also be used to determine the conflicting party corresponding to the i-th private key storage party.

[0094] As can be seen in the embodiments of this application, there are two implementation methods for determining conflicting parties. The first optional implementation method for determining conflicting parties is: among all private key storage parties holding private key shares, determine the private key storage party holding the fewest private key shares, and determine the conflicting party from the private key storage party holding the fewest private key shares; the second optional implementation method for determining conflicting parties is: determine the conflicting party according to the conflicting party calculation formula. It should be noted that for the above two optional implementation methods, the terminal device can select one or a combination of multiple implementation methods, and this application does not impose any restrictions on this.

[0095] It should further be explained that, before storing the private key shares in the kth private key share group among the M private key share groups to the first private key storage party among the N private key storage parties that has not stored the private key shares and the corresponding conflicting party, the present application can also distribute the private key shares of the conflicting party corresponding to the first private key storage party among the N private key storage parties that has not stored the private key shares to the first private key storage party among the N private key storage parties that has not stored the private key shares, so as to ensure that there is a pair of private key shares that can recover the private key among any two private key storage parties among the N private key storage parties, so as to improve the efficiency of subsequent private key recovery, and when there is a newly joined private key storage party, it is also necessary to distribute the original private key shares to the newly joined private key storage party, so as to avoid the high overhead problem caused by recovering the private key shares held by the private key storage party.

[0096] It can be understood that since the private key share of the conflicting party corresponding to the first private key storage party that does not store the private key share among the N private key storage parties is the same as the private key share of the first private key storage party that does not store the private key share among the N private key storage parties, they are in a conflicting party relationship and cannot be combined to recover the private key. At this time, it is necessary to distribute the private key share in the kth private key share group in the M private key share groups to the first private key storage party that does not store the private key share among the N private key storage parties and the corresponding conflicting party. In this way, in the embodiment of the present application, in addition to the first private key storage party and the second private key storage party, the private key storage party that needs to distribute the private key share later not only needs to store the private key share in the new private key share group, but also needs to store the private key share of the corresponding conflicting party (that is, the private key share that has been distributed before), so as to ensure that there is at least one group of private key shares in any two private key storage parties to realize subsequent private key recovery.

[0097] S405: Until the private key share in the Mth private key share group in the M private key share groups is stored in the Nth private key storage party among the N private key storage parties and the conflicting party corresponding to the Nth private key storage party, the storage operation for the private key to be stored is terminated.

[0098] It can be understood that in the 2-out-of-2 and 2-out-of-3 examples mentioned in step S403 and step S404, the first private key storage, the second private key storage and the third private key storage among the N private key storages, as well as the first private key share group and the second private key share group among the M private key share groups have been extracted. At this time, it is possible to determine, based on the private key storages that have stored private key shares, whether there are still private key storages among the N private key storages that do not hold private key shares, and it is possible to determine, based on the N private key storages, whether there are still private key share groups among the M private key share groups that have not distributed private key shares. If there is no private key share group with stored private key shares among the M private key share groups, the private key shares of the last private key share group among the M private key share groups will be distributed to the private key storages that do not hold private key shares.

[0099] Next, we will use 2-out-of-4 as an example to introduce the distribution and storage process of private key shares:

[0100] At this point, based on 2-out-of-4, it can be determined that four private key storage parties are allowed to be distributed and store private key shares. Private key shares are distributed to two private key storage parties each time. This means that N private key storage parties can be determined to be 4 private key storage parties, the kth private key share group is equal to the Mth private key share group, and the Mth private key share group can be determined to be the second private key share group. Next, the conflicting party corresponding to the fourth private key storage party can be determined, and the private key shares of the second private key share group can be distributed to the conflicting party corresponding to the fourth private key storage party and the fourth private key storage party, thus achieving the distribution of private key shares in batches.

[0101] like Figure 7 As shown, Figure 7 A schematic diagram of private key share distribution in another private key storage method provided in an embodiment of the present application, Figure 7 In this article, we take four private key storage parties as an example to introduce the process of distributing private key shares to these four private key storage parties. Figure 7 The four private key storage parties are U1, U2, U3 and U4. U2 can be identified as the conflicting party of U4. The first group of private key shares in the private key share group is and ( and is a private key share group), the second group of private key shares in the private key share group is and ( and is a private key share group), the private key share held by the private key storage party U1 is The private key share held by the private key storage party U2 is The private key share held by the private key storage party U3 is At this time, the private key share Distribute to the private key storage party U2, so that the private key storage party U2 stores the private key share and share the private key Distribute to the private key storage party U4, so that the private key storage party U4 stores the private key share

[0102] It is further understood that in this application, the number N of storage parties of N private key storage parties can be determined first, so that the blockchain is generated according to the number N of storage parties. private key share groups (i.e., M private key share groups), A private key share group can be specifically expressed as That is, the specific form of the private key share in each private key share group.

[0103] After this, you can The private key share groups are divided into two share vector groups, namely and Where share1 can be understood as the first private key share in multiple groups of private key shares, and share2 can be understood as the second private key share in multiple groups of private key shares. And the initialization vector Vshare is generated according to the number of storage parties N, where the initialization vector Vshare includes N empty sub-vectors (i.e., N private key storage parties that have not yet stored private key shares). It can be understood that each sub-vector corresponds to a private key storage party U i , which facilitates the subsequent use of empty vectors to store private key shares, where i∈[1,N].

[0104] Finally, if the i-th private key storage party exists among the N private key storage parties, determine whether i is greater than or equal to 3, and whether i is less than or equal to N. If i is greater than or equal to 3, and i is less than or equal to N, determine the conflicting party corresponding to the i-th private key storage party, and copy Vshare[conflict] to Vshare[i], that is, distribute the private key share of the conflicting party corresponding to the i-th private key storage party to the i-th private key storage party.

[0105] and will The first of the private key share groups The private key shares in the private key share group are distributed to the conflicting party corresponding to the i-th private key storage party and the i-th private key storage party. It should be noted that each private key storage party in this application holds In this way, by implementing 2-out-of-n additive secret sharing to distribute and store private keys, each private key share storage can be targeted at a new private key storage party, and the number of private key shares held by each private key storage party is optimal, thus avoiding the problem of increased storage overhead caused by the need to retrieve and redistribute private key shares in related technologies.

[0106] It should also be noted that when a new private key storage party joins the blockchain, it is necessary to determine P private key storage parties based on the new private key storage party and the original private key storage parties (i.e., N private key storage parties), and then determine Q private key share groups based on the P private key storage parties, where P is greater than N, Q is less than P, and Q is greater than or equal to M. Since the technical solution of the present application is to distribute private key shares one by one according to the ranking of each private key storage party and the ranking of each private key share group, when a new private key storage party joins the blockchain, the ranking of the new private key storage party is after the N private key storage parties, that is, each private key storage party that joins is immediately sorted after the N private key storage parties, so as to determine the conflicting party of the newly added private key storage party according to the ranking value, and determine the private key share group that needs to be distributed to the newly added private key storage party. In this way, the present application avoids the problem of increased storage overhead caused by the need to reclaim private key shares from private key storage parties that have distributed private key shares when a new private key storage party joins, and reduces the storage overhead of private keys compared to related technologies.

[0107] like Figure 8 As shown, Figure 8 A flowchart of another private key storage method provided in an embodiment of the present application. The flowchart includes the following steps:

[0108] S801: Obtain the private key to be stored and determine N private key storage parties.

[0109] It should be noted that the implementation process of step S801 is the same as that of step S401 and will not be repeated here.

[0110] S802: Split the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties to obtain M private key share groups corresponding to the private key to be stored.

[0111] It should be noted that the implementation process of step S802 is the same as that of step S402 and will not be repeated here.

[0112] S803: If N is not greater than or equal to 3, and M is not greater than or equal to 2, the private key share in the Mth private key share group among the M private key share groups is stored in the N-1th private key storage party and the Nth private key storage party among the N private key storage parties.

[0113] It should be noted that before executing step S803, it is necessary to determine whether N is greater than or equal to 3 and whether M is greater than or equal to 2. If N is greater than or equal to 3 and M is greater than or equal to 2, then steps S403-S405 are executed. The implementation process of steps S403-S405 has been described in the previous process and will not be repeated here.

[0114] If N is not greater than or equal to 3, and M is not greater than or equal to 2, then execute step S803. It can be understood that when N is not greater than or equal to 3, and M is not greater than or equal to 2, that is, when N is equal to or less than 2, and M is equal to 1, then the N-1th private key storage party and the Nth private key storage party among the N private key storage parties can be directly extracted, and the private key shares in the Mth private key share group among the M private key share groups can be stored in the N-1th private key storage party and the Nth private key storage party, respectively. That is, the private key shares in a group of private key share groups are stored in two different private key storage parties, respectively, so as to ensure that private key shares are distributed to two private key storage parties each time, and when the private key is recovered later, the private key can also be recovered by the private key shares stored by the two private key storage parties.

[0115] Furthermore, after all M private key share groups are stored in N private key storages, a private key recovery request may be received, where the private key recovery request requires restoring the private key shares to obtain a restored private key for decrypting the ciphertext using the restored private key, where the restored private key is the same as the private key to be stored. Because this application uses 2-out-of-n additive secret sharing when distributing private key shares, the 2 in 2-out-of-n additive secret sharing also indicates that restoring the private key requires extracting any two private key storages from the N private key storages.

[0116] Therefore, an extraction operation can be performed on N private key storages according to the private key recovery request, that is, any two private key storages among the N private key storages can be extracted, and the two private key storages are the first private key storage and the second private key storage. After this, it is determined whether there is a conflicting party relationship between the first private key storage and the second private key storage, where the conflicting party relationship includes the first private key storage being a conflicting party of the second private key storage, or the second private key storage being a conflicting party of the first private key storage.

[0117] If there is a conflicting party relationship between the first private key storage party and the second private key storage party, then the private key shares in the first private key storage party and the second private key storage party, except for the same private key shares, that are in the same private key share group are extracted. It can be understood that if there is a conflicting party relationship between the first private key storage party and the second private key storage party, it means that the first private key storage party and the second private key storage party have the same private key shares, and the same private key shares cannot support the restoration of the private key. At this time, it is necessary to select the private key shares in the first private key storage party and the second private key storage party that belong to the same private key share group, and the private key shares of the same private key share group are not the same in the first private key storage party and the second private key storage party.

[0118] Alternatively, if there is no conflicting party relationship between the first private key storage party and the second private key storage party, the private key shares of the first private key storage party and the second private key storage party that are in the same private key share group are directly extracted, and finally the private key shares of the same private key share group are added together to obtain a restored private key, where the restored private key is used to decrypt the ciphertext encrypted using the public key corresponding to the private key to be stored. It can be seen that this application can realize the restoration of private keys based on any two private key storage parties, improving the user experience and the usability of private keys.

[0119] It can be further understood that in this application, the vector recon = [id1, id2] can be used to first record the IDs of the first private key storage party and the second private key storage party, that is, the ranking value of the private key storage party among the N private key storage parties (such as id1 can represent the first private key storage party, id2 can represent the second private key storage party), and then id1 and id2 are judged, that is, it can be determined whether the larger ID number of id1 and id2 is 2. If the larger ID number of id1 and id2 is 2, the private key share in the first private key share group received by id1 and id2 is output.

[0120] If the larger ID number between id1 and id2 is not 2, the larger ID number between id1 and id2 is determined, which is id2. The conflicting party for id2 can then be determined. If the conflicting party for id2 is id1, the private key shares received in id1 and id2 that are in the same share group but different from each other are output.

[0121] Furthermore, if the conflicting party of id2 is not id1, the first two steps are repeated until the two private key storage parties conflict with each other or the larger ID number is 2. i (i∈{id1,id2}) is executed.

[0122] like Figure 9 As shown, Figure 9 This is a flowchart of private key distribution and restoration in a private key storage method provided in an embodiment of the present application. Figure 9 The process of distributing the private key shares in the private key share group and extracting any two private key storage parties to obtain the restored private key is shown. Figure 9 First, M private key share groups are obtained based on N private key storage parties, and then the private key shares in the M private key share groups are distributed in batches to N private key storage parties (U1, U2, U3, ..., UN), so that the N private key storage parties can store the private key shares in the M private key share groups, thereby realizing the distribution of private key shares and the distributed storage of private keys. After that, two private key share parties (Uid1 and Uid2) can be arbitrarily selected from the N private key share parties to restore the private key based on the private key shares in Uid1 and Uid2 that are in the same share group and different from each other, to obtain the restored private key. In this way, the distributed storage of private keys is realized, the security of private key protection is improved, and faster and more efficient recovery of private keys is supported.

[0123] In summary, this application simulates the scenario in which a new private key storage party joins the blockchain every time, and distributes private key shares in batches, that is, private key shares are distributed to newly joined private key storage parties without changing the existing shares of the private key storage party, thereby avoiding the need to recover and redistribute private key shares when a new private key storage party joins the blockchain, and compared with related technologies, reducing the storage overhead of private keys, realizing distributed storage of private keys, and thereby improving the security of private key storage.

[0124] In addition, the technical solution of the present application has strong scalability, allowing private key shares to be distributed to N private key storage parties. The technical solution of the present application has strong performance, which can optimize the number of private key shares held by each private key storage party, and has strong private key recovery capabilities. The private key can be restored based on any two private key storage parties, avoiding the risk of key leakage in the client and server memory. It should also be noted that the 2-out-of-n additive secret sharing proposed in the technical solution of the present application has strong anti-attack performance, which can tolerate a maximum of t-1 detection event participants and a maximum of nt stop-response participants.

[0125] It should be further explained that, compared with the related art, the number of private key shares held by each private key storage party in the related art is n-1, while the number of private key shares held by each private key storage party in the technical solution of this application is Where n is the number of private key storage parties. Obviously, the technical solution of this application is better than the relevant technical solutions and has lower storage overhead.

[0126] Based on the private key storage method provided in the above embodiment, this application also provides a corresponding private key storage device. The private key storage device provided in the embodiment of this application is described in detail below.

[0127] See also Figure 10 , which is a structural diagram of a private key storage device provided by an embodiment of the present application. Figure 10 As shown, the private key storage device specifically includes:

[0128] The storage party private key acquisition unit 1001 is used to obtain the private key to be stored and determine N private key storage parties, where the private key storage parties are used to store the private key shares corresponding to the private key to be stored;

[0129] a to-be-stored private key splitting unit 1002, configured to split the to-be-stored private key according to the number N of private key storage parties corresponding to the N private key storage parties, to obtain M private key share groups corresponding to the to-be-stored private key, wherein the sum of the private key shares in each private key share group is equal to the to-be-stored private key, and N is greater than M;

[0130] a first private key share storage unit 1003 configured to store the private key shares in a first private key share group among the M private key share groups to a first private key storage and a second private key storage among the N private key storages if N is greater than or equal to 3 and M is greater than or equal to 2;

[0131] a second private key share storage unit 1004, configured to store the private key share in the kth private key share group among the M private key share groups to a first private key storage party among the N private key storage parties that does not store a private key share and a corresponding conflicting party, where k is greater than 1 and is less than or equal to M;

[0132] The third private key share storage unit 1005 is used to store the private key shares in the Mth private key share group among the M private key share groups until the private key shares in the Nth private key storage party among the N private key storage parties and the conflicting party corresponding to the Nth private key storage party are stored, and the storage operation for the private key to be stored is terminated, wherein the conflicting party includes the private key storage party that holds the least number of private key shares among the private key storage parties that have stored private key shares.

[0133] Optionally, the device further includes:

[0134] a function finite ring acquisition unit, configured to acquire a logarithmic function formula and a finite ring, wherein the logarithmic function formula is used to determine the number of private key share groups, and the finite ring is used to obtain the private key shares;

[0135] The private key splitting unit 1002 to be stored includes:

[0136] a share group quantity obtaining unit, configured to obtain the number M of private key share groups corresponding to the private key to be stored according to the number N of storage parties corresponding to the N private key storage parties and the logarithmic function formula;

[0137] A private key share group obtaining unit is used to select random numbers from the finite ring based on the number M of private key share groups and the private key to be stored, generate M random number pairs corresponding to the private key to be stored, and use the M random number pairs as M private key share groups, where each random number pair includes two different random numbers.

[0138] Optionally, the storage party private key acquisition unit 1001 includes:

[0139] A private key storage acquiring unit, configured to acquire N private key storages to be sorted;

[0140] a private key storage parsing unit, configured to parse the N private key storages to be sorted, and obtain joining times corresponding to the N private key storages to be sorted, wherein the joining times include the times when the private key storages to be sorted joined the blockchain;

[0141] The private key storage party sorting unit is used to sort the N private key storage parties to be sorted according to the joining time, obtain N sorted private key storage parties, and determine the N sorted private key storage parties as N private key storage parties.

[0142] Optionally, the device further includes:

[0143] A private key storage unit is used to obtain a private key storage unit that has stored a private key share among the N private key storage units;

[0144] The first storage party determination unit is used to determine the first private key storage party among the N private key storage parties that does not store a private key share based on the order of each private key storage party among the N private key storage parties and the private key storage parties among the N private key storage parties that have stored private key shares.

[0145] Optionally, the device further includes:

[0146] a comparison result obtaining unit, configured to compare the number of private key shares held by the private key storage parties that have stored private key shares among the N private key storage parties, and obtain a comparison result;

[0147] a first conflicting party determining unit configured to, if the comparison result shows that one of the N private key storage parties that have stored private key shares holds the least number of private key shares, determine the private key storage party that holds the least number of private key shares among the N private key storage parties that have stored private key shares as the conflicting party corresponding to the first private key storage party among the N private key storage parties that has not stored any private key shares;

[0148] The second conflicting party determination unit is used for, alternatively, if the comparison result is that among the N private key storage parties that have stored private key shares, there are multiple private key storage parties that hold the least number of private key shares, taking the private key storage party with the smallest ranking value among the multiple private key storage parties as the conflicting party corresponding to the first private key storage party among the N private key storage parties that has not stored private key shares.

[0149] Optionally, the device further includes:

[0150] a calculation formula obtaining unit, configured to obtain a conflicting party calculation formula, wherein the conflicting party calculation formula is used to determine the conflicting party corresponding to the first private key storage party that does not store a private key share among the N private key storage parties;

[0151] a ranking value determining unit, configured to determine, based on the first private key storage party among the N private key storage parties that does not store a private key share, a ranking value of the first private key storage party among the N private key storage parties that does not store a private key share among the N private key storage parties;

[0152] a conflicting party value obtaining unit, configured to calculate the ranking value according to the conflicting party calculation formula to obtain a conflicting party value, wherein the conflicting party value includes a ranking value among the N private key storage parties of the conflicting party corresponding to the first private key storage party that does not store a private key share among the N private key storage parties;

[0153] The third conflicting party determining unit is configured to determine, according to the conflicting party value, a conflicting party corresponding to a first private key storage party among the N private key storage parties that does not store a private key share.

[0154] Optionally, the device further includes:

[0155] The conflicting party storage unit is used to store the private key share of the conflicting party corresponding to the first private key storage party among the N private key storage parties that does not store the private key share to the first private key storage party among the N private key storage parties that does not store the private key share.

[0156] Optionally, the device further includes:

[0157] a storage party extraction unit, configured to extract a first private key storage party and a second private key storage party from the N private key storage parties, wherein the first private key storage party and the second private key storage party are any two private key storage parties from the N private key storage parties;

[0158] a first private key share extraction unit configured to extract, if a conflicting party relationship exists between the first private key storage and the second private key storage, private key shares of the first private key storage and the second private key storage that are in the same private key share group except for the same private key shares;

[0159] a second private key share extraction unit configured to, alternatively, if no conflicting party relationship exists between the first private key storage and the second private key storage, extract private key shares in the same private key share group from the first private key storage and the second private key storage;

[0160] The restored private key obtaining unit is used to restore the private key shares of the same private key share group to obtain a restored private key, wherein the restored private key is used to decrypt the ciphertext obtained by encrypting with the public key corresponding to the private key to be stored.

[0161] Optionally, the device further includes:

[0162] A fourth private key share storage unit is used to store the private key share in the Mth private key share group among the M private key share groups to the N-1th private key storage party and the Nth private key storage party among the N private key storage parties if N is not greater than or equal to 3 and M is not greater than or equal to 2.

[0163] An embodiment of the present application provides a computer device, which may be a server. Figure 11 This is a schematic diagram of a server structure provided in an embodiment of the present application. The server 900 may have relatively large differences due to different configurations or performances, and may include one or more central processing units (CPU) 922 (for example, one or more processors) and memory 932, and one or more storage media 930 (for example, one or more mass storage devices) for storing application programs 942 or data 944. Among them, the memory 932 and the storage medium 930 can be short-term storage or persistent storage. The program stored in the storage medium 930 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the server. Furthermore, the central processing unit 922 can be configured to communicate with the storage medium 930 to execute a series of instruction operations in the storage medium 930 on the server 900.

[0164] The server 900 may also include one or more power supplies 926, one or more wired or wireless network interfaces 950, one or more input and output interfaces 958, and / or one or more operating systems 941, such as Windows Server 2003 or Windows Server 2003R. TM , Mac OS X TM , Unix TM ,Linux TM , FreeBSD TM etc.

[0165] The CPU 922 is configured to execute the following steps:

[0166] Obtaining a private key to be stored, and determining N private key storage parties, where the private key storage parties are used to store private key shares corresponding to the private key to be stored;

[0167] Splitting the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties to obtain M private key share groups corresponding to the private key to be stored, where the sum of the private key shares in each private key share group is equal to the private key to be stored, and N is greater than M;

[0168] If N is greater than or equal to 3, and M is greater than or equal to 2, then the private key shares in the first private key share group in the M private key share groups are stored in the first private key storage party and the second private key storage party in the N private key storage parties;

[0169] storing the private key shares in the kth private key share group among the M private key share groups to the first private key storage party that does not store any private key shares among the N private key storage parties and the corresponding conflicting party, wherein the conflicting party includes the private key storage party that holds the least number of private key shares among the private key storage parties that have stored private key shares, and k is greater than 1 and less than or equal to M;

[0170] Until the private key share in the Mth private key share group in the M private key share groups is stored to the Nth private key storage party among the N private key storage parties and the conflicting party corresponding to the Nth private key storage party, the storage operation for the private key to be stored is terminated.

[0171] The present application embodiment also provides another computer device, which may be a terminal device. Figure 12 For the sake of convenience, only the parts related to the embodiment of the present application are shown. For specific technical details not disclosed, please refer to the method part of the embodiment of the present application. Take the terminal device as a mobile phone as an example:

[0172] Figure 12 The block diagram shows a partial structure of the mobile phone provided by the embodiment of the present application. Figure 12 The mobile phone includes components such as a radio frequency (RF) circuit 1010, a memory 1020, an input unit 1030, a display unit 1040, a sensor 1050, an audio circuit 1060, a wireless fidelity (WiFi) module 1070, a processor 1080, and a power supply 1090. Those skilled in the art will appreciate that Figure 2 The mobile phone structure shown in the figure does not constitute a limitation to the mobile phone, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0173] The following combination Figure 12 A detailed introduction to the various components of a mobile phone:

[0174] RF circuitry 1010 can be used to receive and transmit signals during information transmission or calls. Specifically, it receives downlink information from the base station and transmits it to processor 1080 for processing. It also transmits uplink data to the base station. Typically, RF circuitry 1010 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier (LNA), a duplexer, and more. RF circuitry 1010 can also communicate with the network and other devices via wireless communications. The above-mentioned wireless communications may use any communication standard or protocol, including but not limited to Global System of Mobile Communications (Global System of Mobile communication, English abbreviation: GSM), General Packet Radio Service (English full name: General Packet Radio Service, GPRS), Code Division Multiple Access (English full name: Code Division Multiple Access, English abbreviation: CDMA), Wideband Code Division Multiple Access (English full name: Wideband Code Division Multiple Access, English abbreviation: WCDMA), Long Term Evolution (English full name: Long Term Evolution, English abbreviation: LTE), email, Short Messaging Service (English full name: Short Messaging Service, SMS), etc.

[0175] The memory 1020 can be used to store software programs and modules. The processor 1080 executes the various functional applications and data processing of the mobile phone by running the software programs and modules stored in the memory 1020. The memory 1020 may mainly include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function, an image playback function, etc.); the data storage area may store data created based on the use of the mobile phone (such as audio data, a phone book, etc.). In addition, the memory 1020 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state memory device.

[0176] The input unit 1030 can be used to receive input digital or character information, and to generate key signal input related to the user settings and function control of the mobile phone. Specifically, the input unit 1030 may include a touch panel 1031 and other input devices 1032. The touch panel 1031, also known as a touch screen, can collect user touch operations on or near it (such as operations performed by the user using any suitable object or accessory such as a finger, stylus, etc. on or near the touch panel 1031) and drive the corresponding connection device according to a pre-set program. Optionally, the touch panel 1031 may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch direction and detects the signal caused by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device and converts it into touch point coordinates, which are then sent to the processor 1080. It can also receive commands sent by the processor 1080 and execute them. In addition, the touch panel 1031 can be implemented using various types such as resistive, capacitive, infrared and surface acoustic wave. In addition to the touch panel 1031, the input unit 1030 may further include other input devices 1032. Specifically, the other input devices 1032 may include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick.

[0177] The display unit 1040 can be used to display information input by the user or information provided to the user and various menus of the mobile phone. The display unit 1040 may include a display panel 1041. Optionally, the display panel 1041 may be configured in the form of a liquid crystal display (English full name: Liquid Crystal Display, English abbreviation: LCD), an organic light-emitting diode (English full name: Organic Light-Emitting Diode, English abbreviation: OLED), etc. Further, the touch panel 1031 may cover the display panel 1041. When the touch panel 1031 detects a touch operation on or near it, it is transmitted to the processor 1080 to determine the type of touch event. Subsequently, the processor 1080 provides corresponding visual output on the display panel 1041 according to the type of touch event. Although in Figure 12 In the embodiment, the touch panel 1031 and the display panel 1041 are used as two independent components to realize the input and output functions of the mobile phone, but in some embodiments, the touch panel 1031 and the display panel 1041 can be integrated to realize the input and output functions of the mobile phone.

[0178] The mobile phone may also include at least one sensor 1050, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor may adjust the brightness of the display panel 1041 according to the brightness of the ambient light, and the proximity sensor may turn off the display panel 1041 and / or the backlight when the mobile phone is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that identify the posture of the mobile phone (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that the mobile phone can also be configured with, such as gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., they will not be described here.

[0179] Audio circuit 1060, speaker 1061, and microphone 1062 provide an audio interface between the user and the phone. Audio circuit 1060 converts received audio data into electrical signals and transmits them to speaker 1061, which then converts them into sound signals for output. Microphone 1062, on the other hand, converts collected sound signals into electrical signals, which are then received by audio circuit 1060 and converted into audio data. The audio data is then processed by processor 1080 and transmitted to, for example, another phone via RF circuit 1010, or stored in memory 1020 for further processing.

[0180] WiFi is a short-range wireless transmission technology. The mobile phone can help users send and receive emails, browse the web and access streaming media through the WiFi module 1070. It provides users with wireless broadband Internet access. Figure 12 A WiFi module 1070 is shown, but it is understandable that it is not an essential component of the mobile phone and can be omitted as needed without changing the essence of the invention.

[0181] Processor 1080 is the control center of the phone, connecting all parts of the phone using various interfaces and circuits. By running or executing software programs and / or modules stored in memory 1020 and accessing data stored in memory 1020, it executes various phone functions and processes data, thereby collecting data and information about the phone as a whole. Optionally, processor 1080 may include one or more processing units; preferably, processor 1080 may integrate an application processor and a modem processor, where the application processor primarily handles the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into processor 1080.

[0182] The mobile phone also includes a power supply 1090 (such as a battery) for supplying power to various components. Preferably, the power supply can be logically connected to the processor 1080 through a power management system, thereby managing charging, discharging, and power consumption through the power management system.

[0183] Although not shown, the mobile phone may also include a camera, a Bluetooth module, etc., which will not be described in detail here.

[0184] In the embodiment of the present application, the processor 1080 included in the mobile phone also has the following functions:

[0185] Obtaining a private key to be stored, and determining N private key storage parties, where the private key storage parties are used to store private key shares corresponding to the private key to be stored;

[0186] Splitting the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties to obtain M private key share groups corresponding to the private key to be stored, where the sum of the private key shares in each private key share group is equal to the private key to be stored, and N is greater than M;

[0187] If N is greater than or equal to 3, and M is greater than or equal to 2, then the private key shares in the first private key share group in the M private key share groups are stored in the first private key storage party and the second private key storage party in the N private key storage parties;

[0188] storing the private key shares in the kth private key share group among the M private key share groups to the first private key storage party that does not store any private key shares among the N private key storage parties and the corresponding conflicting party, wherein the conflicting party includes the private key storage party that holds the least number of private key shares among the private key storage parties that have stored private key shares, and k is greater than 1 and less than or equal to M;

[0189] Until the private key share in the Mth private key share group in the M private key share groups is stored to the Nth private key storage party among the N private key storage parties and the conflicting party corresponding to the Nth private key storage party, the storage operation for the private key to be stored is terminated.

[0190] An embodiment of the present application further provides a computer-readable storage medium for storing a computer program. When the computer program is run on a computer device, the computer device executes any one of the implementation methods of a private key storage method described in the aforementioned embodiments.

[0191] An embodiment of the present application also provides a computer program product including a computer program, which, when executed on a computer device, enables the computer device to execute any one of the implementations of the private key storage method described in the aforementioned embodiments.

[0192] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems and devices can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0193] In the several embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the system is merely a logical function division. In actual implementation, there may be other division methods, such as multiple systems can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0194] The systems described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the objectives of this embodiment as needed.

[0195] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0196] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (English full name: Read-Only Memory, English abbreviation: ROM), random access memory (English full name: Random Access Memory, English abbreviation: RAM), disk or optical disk and other media that can store computer programs.

[0197] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program that has a predetermined function and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.

[0198] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A private key storage method, characterized in that: include: Obtaining a private key to be stored, and determining N private key storage parties, where the private key storage parties are used to store private key shares corresponding to the private key to be stored; Splitting the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties to obtain M private key share groups corresponding to the private key to be stored, where the sum of the private key shares in each private key share group is equal to the private key to be stored, and N is greater than M; If N is greater than or equal to 3, and M is greater than or equal to 2, then the private key shares in the first private key share group in the M private key share groups are stored in the first private key storage party and the second private key storage party in the N private key storage parties; storing the private key shares in the kth private key share group among the M private key share groups to the first private key storage party that does not store any private key shares among the N private key storage parties and the corresponding conflicting party, wherein the conflicting party includes the private key storage party that holds the least number of private key shares among the private key storage parties that have stored private key shares, and k is greater than 1 and less than or equal to M; Until the private key share in the Mth private key share group in the M private key share groups is stored to the Nth private key storage party among the N private key storage parties and the conflicting party corresponding to the Nth private key storage party, the storage operation for the private key to be stored is terminated.

2. The method according to claim 1, characterized in that Before splitting the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties to obtain M private key share groups corresponding to the private key to be stored, the method further includes: Obtaining a logarithmic function formula and a finite ring, wherein the logarithmic function formula is used to determine the number of private key share groups, and the finite ring is used to obtain the private key shares; The step of splitting the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties to obtain M private key share groups corresponding to the private key to be stored includes: Obtaining, according to the number N of storage parties corresponding to the N private key storage parties and the logarithmic function formula, the number M of private key share groups corresponding to the private key to be stored; Random numbers are selected from the finite ring according to the number M of private key share groups and the private key to be stored, M random number pairs corresponding to the private key to be stored are generated, and the M random number pairs are used as M private key share groups, where each random number pair includes two different random numbers.

3. The method according to claim 1, characterized in that Determining N private key storage parties includes: Get N private key storage parties to be sorted; Parsing the N private key storage parties to be sorted to obtain the joining time corresponding to each of the N private key storage parties to be sorted, wherein the joining time includes the time when the private key storage party to be sorted joined the blockchain; The N private key storage parties to be sorted are sorted according to the joining time to obtain N sorted private key storage parties, and the N sorted private key storage parties are determined as N private key storage parties.

4. The method according to claim 3, characterized in that Before storing the private key shares in the kth private key share group among the M private key share groups to the first private key storage party among the N private key storage parties that does not store the private key shares and the corresponding conflicting party, the method further includes: Obtaining a private key storage party that has stored a private key share among the N private key storage parties; According to the order of each private key storage party among the N private key storage parties and the private key storage parties among the N private key storage parties that have stored private key shares, determine the first private key storage party among the N private key storage parties that has not stored private key shares.

5. The method according to claim 4, characterized in that After determining the first private key storage party among the N private key storage parties that does not store a private key share, the method further includes: Comparing the numbers of private key shares held by the private key storage parties that have stored private key shares among the N private key storage parties to obtain a comparison result; If the comparison result shows that there is a private key storage party among the N private key storage parties that have stored private key shares and that holds the least number of private key shares, the private key storage party among the N private key storage parties that have stored private key shares and that holds the least number of private key shares is used as the conflicting party corresponding to the first private key storage party among the N private key storage parties that has not stored any private key shares; Alternatively, if the comparison result is that among the N private key storage parties that have stored private key shares, there are multiple private key storage parties that hold the least number of private key shares, the private key storage party with the smallest ranking value among the multiple private key storage parties shall be used as the conflicting party corresponding to the first private key storage party among the N private key storage parties that has not stored private key shares.

6. The method according to claim 4, characterized in that After determining the first private key storage party among the N private key storage parties that does not store a private key share, the method further includes: Obtaining a conflicting party calculation formula, wherein the conflicting party calculation formula is used to determine the conflicting party corresponding to the first private key storage party that does not store a private key share among the N private key storage parties; Determining, according to the first private key storage party among the N private key storage parties that does not store a private key share, a ranking value of the first private key storage party among the N private key storage parties that does not store a private key share among the N private key storage parties; Calculating the ranking value according to the conflicting party calculation formula to obtain a conflicting party value, wherein the conflicting party value includes the ranking value of the conflicting party corresponding to the first private key storage that does not store a private key share among the N private key storages; According to the conflicting party value, the conflicting party corresponding to the first private key storage party that does not store the private key share among the N private key storage parties is determined.

7. The method according to claim 5 or claim 6, characterized in that Before storing the private key shares in the kth private key share group among the M private key share groups to the first private key storage party among the N private key storage parties that does not store the private key shares and the corresponding conflicting party, the method further includes: The private key share of the conflicting party corresponding to the first private key storage party among the N private key storage parties that does not store the private key share is stored in the first private key storage party among the N private key storage parties that does not store the private key share.

8. The method according to claim 7, characterized in that After storing the private key shares in the M-th private key share group among the M private key share groups to the N-th private key storage among the N private key storages and the conflicting party corresponding to the N-th private key storage, the method further includes: Extracting a first private key storage party and a second private key storage party from the N private key storage parties, wherein the first private key storage party and the second private key storage party are any two private key storage parties from the N private key storage parties; If there is a conflicting party relationship between the first private key storage party and the second private key storage party, extract the private key shares in the same private key share group from the first private key storage party and the second private key storage party except for the same private key shares; Alternatively, if there is no conflicting party relationship between the first private key storage and the second private key storage, extracting the private key shares in the same private key share group from the first private key storage and the second private key storage; The private key shares of the same private key share group are restored to obtain a restored private key, wherein the restored private key is used to decrypt ciphertext obtained by encrypting with the public key corresponding to the private key to be stored.

9. The method according to claim 1, characterized in that After splitting the private key to be stored according to the number N of private key storage parties corresponding to the N private key storage parties to obtain M private key share groups corresponding to the private key to be stored, the method further includes: If N is not greater than or equal to 3, and M is not greater than or equal to 2, the private key share in the Mth private key share group among the M private key share groups is stored in the N-1th private key storage and the Nth private key storage among the N private key storages.

10. A private key storage device, characterized in that: include: A storage party private key acquisition unit, configured to acquire a private key to be stored and determine N private key storage parties, wherein the private key storage parties are configured to store private key shares corresponding to the private key to be stored; a to-be-stored private key splitting unit, configured to split the to-be-stored private key according to the number N of private key storage parties corresponding to the N private key storage parties, to obtain M private key share groups corresponding to the to-be-stored private key, wherein the sum of the private key shares in each private key share group is equal to the to-be-stored private key, and N is greater than M; a first private key share storage unit, configured to store the private key shares in a first private key share group among the M private key share groups to a first private key storage and a second private key storage among the N private key storages if N is greater than or equal to 3 and M is greater than or equal to 2; a second private key share storage unit, configured to store the private key share in the kth private key share group among the M private key share groups to a first private key storage party among the N private key storage parties that does not store a private key share and a corresponding conflicting party, wherein k is greater than 1 and is less than or equal to M; The third private key share storage unit is used to store the private key shares in the Mth private key share group among the M private key share groups until the private key shares in the Nth private key storage party among the N private key storage parties and the conflicting party corresponding to the Nth private key storage party are stored, thereby ending the storage operation for the private key to be stored, wherein the conflicting party includes the private key storage party that holds the least number of private key shares among the private key storage parties that have stored private key shares.

11. A computer device, characterized in that: The device includes a processor and a memory: The memory is used to store a computer program and transmit the computer program to the processor; The processor is configured to execute the steps of the private key storage method according to any one of claims 1 to 9 according to the instructions in the computer program.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium is used to store a computer program, and when the computer program is executed by a computer device, the steps of the private key storage method according to any one of claims 1 to 9 are implemented.

13. A computer program product, characterized in that The invention comprises a computer program, which implements the steps of the private key storage method according to any one of claims 1 to 9 when executed by a computer device.