A cross-domain key privacy dynamic adaptation method for threshold signature
Patent Information
- Application Number
- CN202611177197.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-05
- Publication Date
- 2026-09-08
AI Technical Summary
然而,在跨域复杂网络环境中,现有门限签名方案仍面临较多安全与管理问题
本发明通过构建跨域沙盒隔离环境,将密钥分片节点部署于不同安全域中,有效提升了门限签名过程中的隔离性与抗攻击能力,避免了传统集中式密钥管理带来的单点泄露风险。同时,通过引入密钥动态评估模型,对密钥使用行为、节点可信度及环境安全状态进行多维感知与实时评估,实现了对密钥分片调用路径的自适应重构,从而提高了跨域访问过程的安全性与灵活性。
Smart Images

Figure CN122717876A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of information security technology, specifically relating to a cross-domain key privacy dynamic adaptation method for threshold signatures. Background Technology
[0002] With the rapid development of distributed systems, cloud computing, and cross-domain collaborative applications, threshold signature-based distributed cryptography has been widely used in financial transactions, blockchain systems, and multi-party secure computation. Threshold signatures achieve a secure and reliable signature mechanism without centralized private key storage by dividing the private key into multiple key fragments and having multiple participating nodes collaboratively generate the signature, effectively reducing the risk of single-point leakage. However, in complex cross-domain network environments, existing threshold signature schemes still face many security and management challenges.
[0003] On the one hand, existing technologies typically lack effective security isolation mechanisms in cross-domain scenarios. Data interaction between different security domains relies on a unified trust model or simple encrypted channels, which is insufficient to address dynamic security risks in heterogeneous network environments and can easily lead to key fragmentation exposing potential attack surfaces during transmission or collaboration. On the other hand, traditional threshold signature schemes usually employ static key fragmentation and fixed participating node structures, lacking the ability to dynamically perceive changes in node behavior, environmental states, and risks, making key management strategies difficult to adapt to complex and ever-changing cross-domain environments.
[0004] Furthermore, existing technologies typically focus only on the correctness of the signature result during signature generation and verification, neglecting behavioral evolution information throughout the signature lifecycle. They fail to continuously monitor and analyze signature requests, node interaction paths, and abnormal behaviors, resulting in a lack of closed-loop optimization capabilities. Regarding key updates, most schemes rely on periodic or manual triggering mechanisms, employing a single update strategy that cannot adaptively adjust to changes in risk, thus reducing the overall system's security and robustness.
[0005] Meanwhile, in cross-domain collaborative signature processes, the lack of a dynamic evaluation mechanism for access paths and node behavior allows some malicious nodes to participate in the signature process under legitimate identities, thus threatening signature security. Therefore, how to construct a threshold signature and key management method that can adapt to complex cross-domain environments and support dynamic risk assessment and adaptive key adjustment has become a pressing technical problem to be solved. Summary of the Invention
[0006] To address the aforementioned problems in the existing technology, this invention provides a cross-domain key privacy dynamic adaptation method for threshold signatures. The objective of this invention can be achieved through the following technical solutions: S1: Obtain heterogeneous domain environment information data, encapsulate the threshold signature operation environment in a sandbox, build a cross-domain sandbox environment, allocate each key sharding node to an independent sandbox in a different security domain, define the isolation control boundary of each sandbox domain, and generate privacy isolation parameters. S2: Input the privacy isolation parameter into the threshold private key matching function, fragment the initial private key, encapsulate it into the participating nodes in the corresponding security domain, construct a key dynamic evaluation model, adaptively reconstruct the key cross-domain access path, and output a privacy access adaptation scheme. S3: Receive threshold signature requests from different sandbox domains, verify the identity of the initiator, and securely aggregate the partial signatures generated by each node according to the calling qualifications of the corresponding key fragments to generate a complete signature result. S4: After the complete signature result is sent to the verification node, multi-level signature verification is performed. When a policy change or potential risk event is detected, the signature lifecycle feedback mechanism is triggered to send the verification result and the running log back to the key dynamic evaluation model to update the initial private key.
[0007] Specifically, the process of sandboxing the threshold signature runtime environment includes the following steps: Introduce a security policy mapping function for threshold signature protocols; The security policy mapping function quantifies and evaluates the security capabilities of each domain based on heterogeneous domain environment information data and generates a domain security level vector. The heterogeneous domain environment information data includes: node attributes, network communication characteristics, and dynamic context information; Based on the domain security level vector, independent sandbox instances are set up in each security domain, and the topology of the sandbox instances is reconstructed by combining the differences in security levels between domains and communication trust relationships to build a cross-domain sandbox environment. The cross-domain sandbox environment is used to: perform multi-party interactions between different domains and to enable flexible scheduling and fault-tolerant migration of threshold signature tasks between different security domains.
[0008] Specifically, the process of deploying the key sharding nodes to independent sandboxes in different security domains includes the following steps: The threshold private key is split into multiple key sharding nodes in different domains and distributed according to the domain security level vector; The key sharding nodes include: a master key sharding node and redundant auxiliary sharding nodes; Deploy key fragments that meet the same threshold signature combination in different security domains, prioritize the deployment of high-sensitivity key fragments in high-security domains, and establish cross-domain deployment mapping relationships for key fragment nodes under the constraint that the communication path between nodes meets the principle of least trust transfer. Furthermore, based on the cross-domain deployment mapping relationship, the key shards are bound to the runtime environment, and the key shard nodes are loaded into the corresponding sandbox.
[0009] Specifically, the process of generating the privacy isolation parameters includes the following steps: Combining the privacy sensitivity weights of key sharding and the security requirements of threshold signature tasks, we perform constraint modeling on the data interaction relationships between different security domains and construct an access control matrix across sandbox domains. The cross-sandbox domain access control matrix is used to: set the isolation control boundary criteria for each sandbox domain, and perform critical penetration blocking on key access coverage to obtain privacy isolation parameters; The critical penetration blocking method converges or expands the isolation boundary of data between different sandbox domains based on real-time risk scores.
[0010] Specifically, the execution process of the threshold private key matching function includes the following steps: The initial private key is preprocessed in a structured manner and then mapped to the cross-domain sandbox scenario domain; The structured preprocessing process is as follows: introduce a key fragmentation adaptation factor, embed privacy isolation parameters into the threshold private key matching function, perturb the initial private key, and fragment the initial private key according to the threshold signature protocol parameters to obtain a key fragmentation set. The threshold signature protocol parameters include: key sharding node identifier set, finite field parameters, and cross-domain communication security parameters.
[0011] Specifically, the key dynamic evaluation model includes: a feature perception layer and a decision evaluation layer; The feature perception layer is used to extract multi-dimensional features from key usage behavior in a cross-domain sandbox environment and generate a key state representation vector. The key state representation vector includes, but is not limited to: access frequency, node identity trustworthiness, and historical signature behavior data. The decision evaluation layer: Based on the key state representation vector, it quantifies and evaluates the behavioral risks of key sharding during cross-domain calls and outputs a privacy access adaptation scheme.
[0012] Specifically, the process of adaptively reconstructing the cross-domain access path for the key includes the following steps: Based on the sandbox domain where the key fragment is located and the target call request, construct the initial cross-domain access path topology; Risk labeling is performed on each node and path edge in the initial cross-domain access path topology, and corresponding risk weight values are assigned to access control constraints. Based on the risk weight value, a path search is performed on the path topology to eliminate high-risk key distribution nodes or key distribution path edges and replace them with low-risk candidate key distribution nodes, thereby generating a reconstructed key cross-domain access path.
[0013] Specifically, the execution process of the privacy access adaptation scheme is as follows: Perform permission verification on each access node to verify whether the cross-domain access path meets the preset access control constraints and whether its operation does not exceed the predetermined permission range. The access control constraints include: node trustworthiness and path risk score; During execution, if the path risk score is detected to exceed the threshold or there is potential attack behavior, the cross-domain access path will be adjusted in real time, and an alternative low-risk path will be selected for access.
[0014] Specifically, the process of securely assembling the partial signatures includes the following steps: Encrypt and encapsulate the partial signature data generated by each participating node based on the cross-domain secure communication channel; The encryption and encapsulation process is as follows: the session key is bound to the public key of the target receiving node to form a key encapsulation body, and the authentication tag combination is sent to the target participating node by randomly rearranging the data blocks. After each participating node receives the encrypted partial signature data, it performs decryption, extracts the corresponding partial signature and its attached identity and timestamp information, and performs integrity verification on the partial signature data. After all participating nodes have completed the verification of partial signatures, the execution weights of the verified partial signatures are normalized through the threshold signature reconstruction function, and the valid partial signatures are combined and reconstructed according to the preset threshold parameters. The resulting partial signatures are then aggregated to generate a complete signature result.
[0015] Specifically, the multi-level signature verification process includes the following steps: Based on the identification information of the participating nodes and their corresponding public key certificates recorded during the signature generation process, the identity of the signing participants in the received complete signature result is verified. The identity trust authentication also includes behavior association layer verification and dynamic trust evaluation layer verification; The behavior association layer verification: Based on the signature request context and key state representation vector, the current signature behavior is analyzed for association, a signature behavior feature vector is constructed, abnormal call patterns are identified, and abnormal detection results are output. The abnormal call patterns include: frequent calls, path deviation, and abnormal node collaboration; The dynamic trust assessment layer verification: Based on the identity trust authentication result and historical verification records, the current signature result is dynamically trusted and scored, and the signature result is graded and judged according to the dynamic trust score, and a verification trust label is output.
[0016] Specifically, the execution of the signature lifecycle feedback mechanism includes the following steps: Throughout the entire process of signature generation, transmission, verification, and use, signature request information generated at each stage is collected to form a signature lifecycle data stream; Based on the signature lifecycle data stream, the node trustworthiness parameters and path constraint parameters in the key dynamic evaluation model are adaptively updated, and the model update parameters are written back to the cross-domain sandbox environment to generate a signature lifecycle evolution log, driving the execution of subsequent signature processes.
[0017] Specifically, updating the initial private key includes the following steps: Based on the verification credibility labels output during the multi-level signature verification process, the signature behavior is analyzed and processed to generate a key update evaluation dataset. The key update evaluation dataset includes: verification credibility data, behavioral risk data, node status data, and policy feedback data; Determine whether the initial private key needs to be updated. If it is determined that an update is needed, determine the key update based on the key state representation vector. The triggering conditions for the determination include, but are not limited to: risk score exceeding the threshold, abnormal behavior frequency exceeding the limit, or node credibility decreasing. The target private key is regenerated, the original private key is perturbed and updated, and the updated key fragments are securely distributed to the participating nodes in the corresponding security domains. The old key fragments are marked as invalid.
[0018] The beneficial effects of this invention are as follows: This invention constructs a cross-domain sandbox isolation environment, deploying key sharding nodes in different security domains. This effectively improves the isolation and attack resistance of the threshold signature process, avoiding the single point of leakage risk associated with traditional centralized key management. Simultaneously, by introducing a dynamic key evaluation model, it performs multi-dimensional perception and real-time evaluation of key usage behavior, node trustworthiness, and environmental security status, enabling adaptive reconstruction of the key sharding call path. This, in turn, enhances the security and flexibility of cross-domain access.
[0019] Furthermore, during the partial signature aggregation process, encrypted encapsulation and multi-verification mechanisms are employed, combined with a weighted reconstruction method based on node trustworthiness, effectively enhancing the anomaly resistance and robustness of signature generation. In the signature verification stage, a multi-layered verification mechanism not only verifies the correctness of the signature result but also performs correlation analysis and anomaly detection on the signature behavior, strengthening the system's ability to identify potential attack behaviors.
[0020] Furthermore, by introducing a signature lifecycle feedback mechanism, multi-source data from the signature generation, transmission, and verification processes are fused and analyzed to achieve adaptive updates of the key dynamic evaluation model parameters, forming a closed-loop optimization mechanism. Compared to existing technologies, this invention can dynamically adjust key policies and access control policies according to changes in risk, significantly improving the system's security, stability, and adaptability in complex cross-domain environments, and has promising application prospects. Attached Figure Description
[0021] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings.
[0022] Figure 1 This is a schematic diagram of the framework of a threshold signature-oriented cross-domain key privacy dynamic adaptation method according to the present invention.
[0023] Figure 2 This is a schematic diagram illustrating the principle of secure aggregation of partial signatures in a threshold signature-oriented cross-domain key privacy dynamic adaptation method of the present invention. Detailed Implementation
[0024] To further illustrate the technical means and effects of the present invention in achieving its intended purpose, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention, in conjunction with the accompanying drawings and preferred embodiments, is provided.
[0025] Please see Figure 1 A cross-domain key privacy dynamic adaptation method for threshold signatures: S1: Obtain heterogeneous domain environment information data, encapsulate the threshold signature operation environment in a sandbox, build a cross-domain sandbox environment, allocate each key sharding node to an independent sandbox in a different security domain, define the isolation control boundary of each sandbox domain, and generate privacy isolation parameters. S2: Input the privacy isolation parameter into the threshold private key matching function, fragment the initial private key, encapsulate it into the participating nodes in the corresponding security domain, construct a key dynamic evaluation model, adaptively reconstruct the key cross-domain access path, and output a privacy access adaptation scheme. S3: Receive threshold signature requests from different sandbox domains, verify the identity of the initiator, and securely aggregate the partial signatures generated by each node according to the calling qualifications of the corresponding key fragments to generate a complete signature result. S4: After the complete signature result is sent to the verification node, multi-level signature verification is performed. When a policy change or potential risk event is detected, the signature lifecycle feedback mechanism is triggered to send the verification result and the running log back to the key dynamic evaluation model to update the initial private key.
[0026] In this embodiment, a cross-domain threshold signature system containing multiple heterogeneous security domains (denoted as domains D_1, D_2, ..., D_m) is used as an example. Sandbox encapsulation technology is adopted to realize cross-domain privacy protection and dynamic adaptation of key fragmentation.
[0027] The specific technical solution is as follows: Heterogeneous domain environment information acquisition, sandboxing encapsulation, and privacy isolation parameter generation; Obtain heterogeneous domain environment information data, which includes: node attributes of each domain (denoted as node attribute set P), network communication characteristics (denoted as communication feature vector C), and dynamic context information (denoted as context vector X).
[0028] A security policy mapping function oriented towards threshold signature protocols is introduced to quantitatively evaluate the security capabilities of each domain and generate a domain security level vector. ,in, This is a domain security level vector, which characterizes the security status of each security domain in the current operating environment and serves as the basis for key sharding deployment, cross-domain access path selection, and access control policy adjustment. Specifically, the domain security level d... i The quantification formula is: , Among them, w k d is the preset weighting coefficient. i Let i be the domain security level score of the i-th evaluation object, where i is the index number of the evaluation object. To iterate over three preset feature dimensions, where k is the index of the feature dimension, norm(p k c k x k ) is the normalization function, p k c is the current observation value. k x is a constraint parameter. k This refers to the context state parameter corresponding to the k-th feature.
[0029] The normalization function dynamically adjusts the feature data by combining constraint parameters and context parameters, so that the processed feature data meets the input requirements of the cross-domain security assessment model.
[0030] The domain security level score is used to: characterize the overall security status of the corresponding security domain in the current operating environment, quantitatively reflect the risk level and trustworthiness of the security domain, and serve as an important basis for cross-domain security decisions; simultaneously, it is used for cross-domain access path selection and optimization control, filtering and sorting candidate access paths according to the domain security level score during key fragmentation transmission and threshold signature collaboration, prioritizing paths from high-security-level security domains; it is also used for adjusting key fragmentation allocation strategies, dynamically optimizing the deployment location and redundancy distribution of key fragments based on the score differences of different security domains to improve the overall anti-attack capability of the system; further, it is used for access control of threshold signature participating nodes, determining the eligibility of participating nodes through security level threshold constraints, reducing the risk of low-security-domain nodes accessing the system from the source; it also serves as one of the input parameters of the key dynamic evaluation model, used to adaptively update the risk evaluation weights and path constraint parameters, thereby achieving dynamic optimization of cross-domain security strategies; when a security domain score is detected to be lower than a preset threshold, a security alarm mechanism and key update or access path reconstruction operations can be triggered to ensure the continuous security and stability of the system in complex cross-domain environments.
[0031] based on Within each security domain, separate sandbox instances are set up (denoted as the sandbox instance set {SB}). i}), and combined with the differences in security levels between domains and the communication trust relationship (denoted as the trust relationship matrix T), the topology of the sandbox instance is reconstructed to build a cross-domain sandbox environment.
[0032] This environment supports multi-party interaction between different domains and elastic scheduling and fault-tolerant migration of threshold signature tasks.
[0033] Next, the initial threshold private key is split into multiple key sharding nodes (denoted as shard set {K) in different security domains. j This includes master key sharding nodes and redundant auxiliary sharding nodes.
[0034] according to Fragmentation and allocation: Key fragments satisfying the same threshold signature combination are deployed in different security domains, with high-sensitivity key fragments (denoted as sensitivity weight w) sen,j Prioritize deployment in high-security domains, and establish cross-domain deployment mapping relationships under the constraint that the communication path between nodes meets the minimum trust transfer principle (i.e., the path trust product is maximized), and finally load the key sharding nodes into the corresponding sandbox.
[0035] Privacy sensitivity weights w combined with key fragmentation sen,jTo meet the security requirements of threshold signature tasks, constraint modeling is performed on the data interaction relationships between different security domains, and an access control matrix (denoted as A) is constructed across sandbox domains. The specific access control matrix constraint modeling formula is as follows: , Among them, dist(D i D j ) is a metric function for the difference in security levels between domains. This metric function is used to constrain cross-domain data interaction relationships to achieve dynamic adjustment of key access control boundaries. Aij is the association strength between node i and node j, and w sen,i Let D be the security sensitivity weight at node i. i For the i-th security domain, D j Let i be the j-th security domain, and i and j be the security domain indices, where i ≠ j.
[0036] The privacy isolation parameters include: boundary encryption strength coefficient and cross-domain access blocking threshold.
[0037] The access control matrix is used to: set isolation control boundary criteria for each sandbox domain, and perform critical penetration blocking on key access coverage to obtain privacy isolation parameters (denoted as a: boundary encryption strength coefficient; b: cross-domain access blocking threshold). Critical penetration blocking is based on real-time risk scoring (denoted as r). real This allows for the convergence or expansion of the isolation boundary.
[0038] The critical penetration blocking is used to dynamically adjust access behavior based on the current risk status of the system during the cross-domain threshold signature and key sharding collaboration process.
[0039] When the real-time risk score r real When the threshold is exceeded, the system triggers a "convergence" strategy to shrink and constrain cross-domain access paths, the scope of participating nodes, and the key sharding call set, in order to reduce the system's exposure surface and suppress the spread of potential attacks; when r real When the threshold is less than or equal to, the system executes an "expansion" strategy to expand the access path candidate set, the scope of node participation, and the redundant signature capability, so as to improve the availability and fault tolerance of the system, thereby achieving a dynamic balance and adaptive adjustment between security and efficiency in a cross-domain security environment.
[0040] Construction of privacy isolation parameter input, key fragmentation, and dynamic key evaluation model; Input the privacy isolation parameters (a, b) into the threshold private key matching function.
[0041] First, the initial private key undergoes structured preprocessing. A key sharding adaptation factor λ is introduced, embedding privacy isolation parameters into the threshold private key matching function. The initial private key is then perturbed and encoded. Finally, key sharding is performed using the threshold signature protocol parameter set Param, which includes a key sharding node identifier set, finite field parameters, and cross-domain communication security parameters, resulting in the key sharding set {K}. j Specifically, the key fragmentation encoding process is as follows: , where K j Fragment the original key. For the perturbed key fragmentation, hash(Param) is the digest value obtained by hashing the protocol parameter set, and 'a' is the boundary reinforcement strength coefficient in the privacy isolation parameters. This is the key fragmentation adaptation factor.
[0042] A key dynamic evaluation model is constructed, which includes a feature perception layer and a decision evaluation layer; Feature-aware layer: Used to extract multi-dimensional features from key usage behavior in cross-domain sandbox environments and generate key state representation vectors. The key state representation vector includes at least access frequency features, node identity trustworthiness features, and historical signature behavior features.
[0043] Decision evaluation layer: based on the key state representation vector The system quantifies and assesses the behavioral risks of key sharding during cross-domain calls and outputs privacy access adaptation solutions.
[0044] Behavioral risk quantification assessment is expressed as follows: Where w is the risk weight vector, This is a bias term used to adjust the baseline value; risk is the behavioral risk value w. T This is the transpose of the risk weight vector w. This is the key state representation vector.
[0045] In this embodiment, the behavioral risk is used to: quantitatively assess the security status of key shards during cross-domain calls, and serve as the core input parameter of the key dynamic evaluation model to drive cross-domain access control and security policy adjustment; specifically, it is used to determine the risk of the access behavior, call path, and environment status of participating nodes, and dynamically optimize the call permissions of key shards, the selection of participating nodes, and the cross-domain access path based on the risk score results; it is also used to perform risk weighting on nodes and path edges during path reconstruction to filter low-risk access paths; and it triggers a security control mechanism when the risk score exceeds a preset threshold, including access restrictions, path convergence, key updates, or anomaly alarms, thereby achieving an adaptive balance between security and availability in the cross-domain threshold signature process.
[0046] In this embodiment, as Figure 2 As shown, the process of securely assembling the partial signatures includes the following steps: Encrypt and encapsulate the partial signature data generated by each participating node based on the cross-domain secure communication channel; After each participating node receives the encrypted partial signature data, it performs decryption, extracts the corresponding partial signature and its attached identity and timestamp information, and performs integrity verification on the partial signature data. After all participating nodes have completed the verification of partial signatures, the execution weights of the verified partial signatures are normalized through the threshold signature reconstruction function, and the valid partial signatures are combined and reconstructed according to the preset threshold parameters. The resulting partial signatures are then aggregated to generate a complete signature result.
[0047] The encryption and encapsulation process is as follows: the session key is bound to the public key of the target receiving node to form a key encapsulation body, and the authentication tag combination is sent to the target participating node by randomly rearranging the data blocks.
[0048] Adaptive reconstruction of cross-domain key access paths specifically includes: Based on the sandbox domain where the key fragment is located and the target call request, construct the cross-domain access path topology, denoted as: G=(V,E), where V is the set of nodes and E is the set of path edges; 2. Perform risk labeling on each node and path edge, and assign a risk weight r to each edge e∈E. e ; 3. Based on risk weights, perform path search and optimization calculations on the path topology, eliminate high-risk nodes or path edges, and replace them with low-risk candidate paths to generate reconstructed cross-domain access paths.
[0049] Path weight update is represented as: , where w e The original path weights, Here are the updated path weights, μ is the risk amplification factor, and r is the risk amplification factor. e Let e be the risk weight value of edge e in the path topology. Based on this weight, an improved shortest path search algorithm is executed to complete the path reconstruction.
[0050] In this embodiment, the path weight update is used to: introduce the behavioral risk information corresponding to each node and path edge in the path into the path evaluation process; by risk-weighted correction of the original path weight, the path weight can dynamically reflect the security status in the current cross-domain access process; and serve as an optimization basis in the path search and reconstruction process, penalizing high-risk paths with increased weight and relatively prioritizing low-risk paths, thereby guiding the shortest path or optimal path algorithm to prioritize access paths with higher security; at the same time, the path weight update is also used to realize the dynamic adjustment and adaptive optimization of cross-domain access paths, updating the path weight in real time when a risk change is detected, triggering the path reconstruction mechanism to reduce the probability of potential attack paths being selected, and improving the overall security and robustness of key fragmentation transmission and threshold signature processes.
[0051] The execution process of the privacy access adaptation scheme is as follows: perform permission verification on each access node, verify whether the cross-domain access path meets the preset access control constraints (including node trustworthiness and path risk score), and whether the operation does not exceed the predetermined permission range.
[0052] If a path risk score is detected to exceed a threshold or if potential attack behavior is detected, the path will be adjusted in real time, and a lower-risk alternative path will be selected.
[0053] Threshold signature request processing and secure convergence of partial signatures; After receiving threshold signature requests from different sandbox domains, the identity of the request initiator is first verified. This verification is based on a comprehensive assessment of the public key certificate and historical behavior records. After the verification is successful, the partial signatures generated by each participating node are securely aggregated according to the calling qualifications of the corresponding key shard (determined by the privacy access adaptation scheme).
[0054] The secure convergence process is as follows: 1. Encrypt and encapsulate the partial signature data generated by each participating node based on the cross-domain secure communication channel: bind the session key according to the public key of the target receiving node to form a key encapsulation body, and send the authentication tag combination to the target participating node by randomly rearranging the data blocks.
[0055] 2. After receiving the data, each participating node decrypts it, extracts a portion of the signature and its associated identity and timestamp information, and performs an integrity check.
[0056] 3. After all participating nodes have completed verification, the execution weights of the verified partial signatures are normalized through the threshold signature reconstruction function, and the valid partial signatures are combined and reconstructed according to the preset threshold parameter (denoted as t) to generate a complete signature result.
[0057] The process of partial signature reconstruction is as follows: , in, full For the final, complete threshold signature obtained from the reconstruction, j The partial signature generated for the j-th node, where j∈S is the j-th node currently participating in the computation, and S is the set of valid partial signatures, satisfying... w j Let be the dynamic weight coefficient of node j. All nodes except the current node j, x j x is the interpolation identifier corresponding to node j. m Let be the interpolation identifier (such as key fragmentation index or public identifier) corresponding to node m, m be the auxiliary node index for constructing interpolation coefficients, and j be the target node index for parameter calculation.
[0058] In this embodiment, the reconstructed complete threshold signature is used for: unified identity authentication and data integrity verification of cross-domain business requests to prove that the signature result is collaboratively generated by legitimate nodes that meet the threshold conditions, and to verify that the signature data has not been tampered with during generation and transmission; it is also used as a trusted credential for cross-domain access control, serving as a basis for security decisions in subsequent resource access, authorization, and business execution; further, it is used to submit the signature result to a verification node or blockchain network for consensus verification or record storage to achieve traceability and non-repudiation of the operation; and it is used to feed back the signature verification result and related operational information to the key dynamic evaluation model to support key lifecycle management and adaptive optimization of security policies, thereby improving the overall security and trustworthiness of the system.
[0059] Full signature verification, lifecycle feedback, and initial private key update; Complete signature result After the full signature is sent to the verification node, a multi-level signature verification process is performed, which includes the following steps: (1) Trusted identity authentication layer; Based on the identification information of participating nodes and their corresponding public key certificates recorded during the signature generation process, the identity of each participating node is authenticated, and its credibility is comprehensively judged in combination with the node's historical behavior records to confirm the legitimacy of the signature source.
[0060] (2) Behavior association verification layer; Based on signature request context information and key state representation vector A signature behavior feature vector is constructed to perform correlation analysis on signature behavior; by modeling features such as call frequency, access path deviation degree and node collaboration behavior, abnormal call patterns are identified and anomaly detection results are output.
[0061] (3) Dynamic credibility assessment layer; Based on the identity authentication results, anomaly detection results, and historical verification records, the current signature result is dynamically rated to obtain a credibility index. The signature result is then graded based on the rating, and a verification credibility label is generated. Based on the data stream, the node credibility parameters and path constraint parameters in the key dynamic evaluation model are adaptively updated, and the updated model parameters are written back to the cross-domain sandbox environment. At the same time, a signature lifecycle evolution log is generated to drive the adaptive execution of subsequent signature processes.
[0062] Based on the verification credibility label L output during the multi-level signature verification process cred The system generates a key update assessment dataset and determines whether the initial private key needs to be updated based on this dataset. Triggering conditions include risk scores exceeding preset thresholds, abnormal behavior frequency exceeding limits, or node trustworthiness decreasing.
[0063] When an update is determined, the key update method is determined based on the key state representation vector, including regenerating the target private key or performing a perturbation update on the original private key; and the updated key fragments are securely distributed to the participating nodes in the corresponding security domains, while the old key fragments are marked as invalid.
[0064] In this embodiment, the construction of the cross-domain sandbox environment includes: using virtualization or containerization technology to create an independent virtual sandbox or container sandbox for each domain, with domains interacting through encrypted communication channels; the communication protocol for the financial scenario adopts TLS + financial CA certificate + encrypted transaction flow identifier; the intranet for the government scenario adopts the national cryptographic SM2 / SM4 protocol + unified government identity authentication + electronic signature compliance module, desensitizes patient privacy information and adopts medical CA certificate + data access authorization record; the communication protocol for the energy scenario supports the encryption standard of industrial control network (IEC 62351); the communication protocol for the transportation scenario integrates ticket anti-counterfeiting verification fields (dynamic anti-counterfeiting code, device fingerprint binding information); and the communication protocol for the Internet scenario is compatible with the OAuth 2.0 / OpenID Connect identity authentication system + high-concurrency request queuing mechanism.
[0065] In this embodiment, the key dynamic evaluation model includes: a feature perception layer and a decision evaluation layer; The feature perception layer is used to extract multi-dimensional features from key usage behavior in a cross-domain sandbox environment and generate a key state representation vector. The key state representation vector includes, but is not limited to: access frequency, node identity trustworthiness, and historical signature behavior data. The decision evaluation layer: Based on the key state representation vector, it quantifies and evaluates the behavioral risks of key sharding during cross-domain calls and outputs a privacy access adaptation scheme.
[0066] In this embodiment, key fragment distribution also requires binding a four-dimensional access strategy of "scenario-industry-department-entity" to each fragment: 1. Scene dimension: In the financial scenario, "transactions ≥ RMB 1 million require secondary verification from two industry regulatory nodes" and "cross-border payments require additional anti-money laundering compliance verification (connected to the anti-money laundering system API)". In the government scenario, "only government approval process nodes can call corresponding file fragments" and "signatures of classified documents require offline verification (disconnected from the public network)". In the medical scenario, "fragment calls require patient authorization records within 24 hours (electronic signature authorization)" and "medical record data signatures require medical ethics review approval (review records on the blockchain)". In the energy scenario, "dispatch instruction signatures require normal grid load monitoring (real-time load data acquisition)" and "classified pipeline instructions require physical isolation environment calls (no network interface devices)". In the transportation scenario, "ticket signatures require real-time online verification of anti-counterfeiting codes (connected to the ticketing anti-counterfeiting system)". In the internet scenario, "user identity authentication signatures require cross-verification across multiple devices (mobile phone + computer + face)". 2. Industry Dimension: The financial industry requires that the encryption strength of the sharding comply with the "Guidelines for Information Technology Risk Management of Commercial Banks" (key length ≥ 256 bits); the government sector requires compliance with the "Administrative Measures for Electronic Government Electronic Authentication Services" (using national cryptographic algorithms); the healthcare industry requires compliance with the dual control requirements of data anonymization and access authorization; the energy industry requires compliance with the "Basic Requirements for Cybersecurity Level Protection in the Power Industry" (encryption adaptation of industrial control equipment); the transportation industry requires compliance with the "Administrative Measures for Cybersecurity of Transportation" (encrypted transmission of ticketing data); and the internet industry requires compliance with the "Cybersecurity Law" and the "Data Security Law" (user data access with minimum privileges). 3. Department / Organization Dimension: Core departments / institutions (bank headquarters, government affairs offices, core departments of hospitals, energy dispatch centers, transportation hub operators, and core computer rooms of internet platforms) have the authority to distribute / update data in segments; collaborating departments / institutions (bank branches, government service centers, outpatient departments of hospitals, energy substations, transportation stations, and internet platform partners) have partial signature generation authority; and auxiliary departments / institutions (third-party payment institutions, third-party government service companies, third-party testing institutions, energy equipment suppliers, transportation ticketing agents, and internet user terminals) only have signature verification or limited access authority. 4. Subject Dimension: Based on the health of the main device, the baseline of operational behavior, and the status of the root of trust, set flexible thresholds. When the device health score is less than 70 or the root of trust status is abnormal, trigger two-factor authentication (face recognition + U-shield + trusted platform module authentication). When the behavior deviates from the baseline (high-frequency access during non-working hours, multiple requests from different IP addresses in a short period of time, frequent changes in device fingerprints), increase the verification strength (add verification code + manual review). When the main device does not have industry compliance qualifications, refuse access (e.g., personnel without medical practice qualifications cannot access medical record signature fragments).
[0067] In this embodiment, the key sharding full lifecycle access policy is covered, and industry-customized extensions are supported: 1. Generation stage: Only core administrators of the cross-domain coordination center and industry regulatory nodes (who must pass multi-factor authentication: password + U-shield + face recognition + trusted platform module authentication) are allowed to initiate generation requests in an offline secure environment (physically isolated encrypted server, Trusted Execution Environment (TEE)). The generation process must meet industry compliance requirements (the financial industry is prohibited from outsourcing the core key generation process). The generation log is synchronized in real time to the cross-industry audit nodes and regulatory nodes (the log includes generation time, administrator ID, and environment information). 2. Backup phase: Supports key sharding and off-site backup (compliant with "three-site backup" requirements, such as the "two-site three-center" architecture in the financial industry). The backup shards use different encryption algorithms than the main shards (SM4 for the main shards, AES-256 for the backup shards) and are stored on secure nodes in different regions (backup to an off-site disaster recovery center in the financial industry, and backup to a regional medical data center in the medical industry). Backup calls require additional authorization verification through the industry regulatory node (the regulatory node sends a dynamic authorization code). 3. Invocation phase: A new "Call Purpose - Data - Compliance Qualification" binding rule has been added. When calling a shard, the hash value of the data to be signed, a description of the call purpose (structured text, such as "20250902 Enterprise Registration Document Signature"), and industry compliance certification documents (patient authorization letter in medical scenarios, anti-money laundering audit form in financial scenarios) must be submitted. The access control unit will connect to the industry compliance system (such as medical ethics review system, financial anti-money laundering system) through API to verify that the call purpose, data type, and compliance qualification are consistent before the call can be allowed. 4. Destruction Phase: In addition to safety wiping, a destruction report (including destruction time, participating nodes, destruction method, verification results, and residue detection report) must also be generated and reviewed by cross-industry audit and regulatory nodes.
[0068] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. A cross-domain key privacy dynamic adaptation method for threshold signatures, characterized in that, include: S1: Obtain heterogeneous domain environment information data, encapsulate the threshold signature operation environment in a sandbox, build a cross-domain sandbox environment, allocate each key sharding node to an independent sandbox in a different security domain, define the isolation control boundary of each sandbox domain, and generate privacy isolation parameters. S2: Input the privacy isolation parameter into the threshold private key matching function, fragment the initial private key, encapsulate it into the participating nodes in the corresponding security domain, construct a key dynamic evaluation model, adaptively reconstruct the key cross-domain access path, and output a privacy access adaptation scheme. S3: Receive threshold signature requests from different sandbox domains, verify the identity of the initiator, and securely aggregate the partial signatures generated by each node according to the calling qualifications of the corresponding key fragments to generate a complete signature result. S4: After the complete signature result is sent to the verification node, multi-level signature verification is performed. When a policy change or potential risk event is detected, the signature lifecycle feedback mechanism is triggered to send the verification result and the running log back to the key dynamic evaluation model to update the initial private key.
2. The method according to claim 1, characterized in that, The process of sandboxing the threshold signature runtime environment includes the following steps: Introduce a security policy mapping function for threshold signature protocols; The security policy mapping function quantifies and evaluates the security capabilities of each domain based on heterogeneous domain environment information data and generates a domain security level vector. Based on the domain security level vector, independent sandbox instances are set up in each security domain, and the topology of the sandbox instances is reconstructed by combining the differences in security levels between domains and communication trust relationships to build a cross-domain sandbox environment. The cross-domain sandbox environment is used to: perform multi-party interactions between different domains and to enable flexible scheduling and fault-tolerant migration of threshold signature tasks between different security domains.
3. The method according to claim 1, characterized in that, The process of deploying the key sharding nodes to independent sandboxes in different security domains includes the following steps: The threshold private key is split into multiple key sharding nodes in different domains and distributed according to the domain security level vector; Deploy key fragments that meet the same threshold signature combination in different security domains, prioritize the deployment of high-sensitivity key fragments in high-security domains, and establish cross-domain deployment mapping relationships for key fragment nodes under the constraint that the communication path between nodes meets the principle of least trust transfer. Furthermore, based on the cross-domain deployment mapping relationship, the key shards are bound to the runtime environment, and the key shard nodes are loaded into the corresponding sandbox.
4. The method according to claim 1, characterized in that, The process of generating the privacy isolation parameters includes the following steps: Combining the privacy sensitivity weights of key sharding and the security requirements of threshold signature tasks, we perform constraint modeling on the data interaction relationships between different security domains and construct an access control matrix across sandbox domains. The cross-sandbox domain access control matrix is used to: set the isolation control boundary criteria for each sandbox domain, and perform critical penetration blocking on key access coverage to obtain privacy isolation parameters; The critical penetration blocking method converges or expands the isolation boundary of data between different sandbox domains based on real-time risk scores.
5. The method according to claim 1, characterized in that, The execution process of the threshold private key matching function includes the following steps: The initial private key is preprocessed in a structured manner and then mapped to the cross-domain sandbox scenario domain; The structured preprocessing process is as follows: a key fragmentation adaptation factor is introduced, privacy isolation parameters are embedded into the threshold private key matching function, the initial private key is perturbated and encoded, and the initial private key is fragmented according to the threshold signature protocol parameters to obtain a key fragment set.
6. The method according to claim 1, characterized in that, The key dynamic evaluation model includes: a feature perception layer and a decision evaluation layer; The feature perception layer is used to extract multi-dimensional features from key usage behavior in a cross-domain sandbox environment and generate a key state representation vector. The key state representation vector includes, but is not limited to: access frequency, node identity trustworthiness, and historical signature behavior data. The decision evaluation layer: Based on the key state representation vector, it quantifies and evaluates the behavioral risks of key sharding during cross-domain calls and outputs a privacy access adaptation scheme.
7. The method according to claim 1, characterized in that, The process of adaptively reconstructing the cross-domain access path of the key includes the following steps: Based on the sandbox domain where the key fragment is located and the target call request, construct the initial cross-domain access path topology; Risk labeling is performed on each node and path edge in the initial cross-domain access path topology, and corresponding risk weight values are assigned to access control constraints. Based on the risk weight value, a path search is performed on the path topology to eliminate high-risk key distribution nodes or key distribution path edges and replace them with low-risk candidate key distribution nodes, thereby generating a reconstructed key cross-domain access path.
8. The method according to claim 6, characterized in that, The execution process of the privacy access adaptation scheme is as follows: Perform permission verification on each access node to verify whether the cross-domain access path meets the preset access control constraints and whether its operation does not exceed the predetermined permission range. During execution, if the path risk score is detected to exceed the threshold or there is potential attack behavior, the cross-domain access path will be adjusted in real time, and an alternative low-risk path will be selected for access.
9. The method according to claim 1, characterized in that, The process of securely merging the partial signatures includes the following steps: Encrypt and encapsulate the partial signature data generated by each participating node based on the cross-domain secure communication channel; The encryption and encapsulation process is as follows: the session key is bound to the public key of the target receiving node to form a key encapsulation body, and the authentication tag combination is sent to the target participating node by randomly rearranging the data blocks; After each participating node receives the encrypted partial signature data, it performs decryption, extracts the corresponding partial signature and its attached identity and timestamp information, and performs integrity verification on the partial signature data. After all participating nodes have completed the verification of partial signatures, the execution weights of the verified partial signatures are normalized through the threshold signature reconstruction function, and the valid partial signatures are combined and reconstructed according to the preset threshold parameters. The resulting partial signatures are then aggregated to generate a complete signature result.
10. The method according to claim 1, characterized in that, The multi-level signature verification process includes the following steps: Based on the identification information of the participating nodes and their corresponding public key certificates recorded during the signature generation process, the identity of the signing participants in the received complete signature result is verified. The identity trust authentication also includes behavior association layer verification and dynamic trust evaluation layer verification; The behavior association layer verification: Based on the signature request context and key state representation vector, the current signature behavior is analyzed for association, a signature behavior feature vector is constructed, abnormal call patterns are identified, and abnormal detection results are output. The dynamic trust assessment layer verification: Based on the identity trust authentication result and historical verification records, the current signature result is dynamically trusted and scored, and the signature result is graded and judged according to the dynamic trust score, and a verification trust label is output.
11. The method according to claim 1, characterized in that, The execution of the signature lifecycle feedback mechanism includes the following steps: Throughout the entire process of signature generation, transmission, verification, and use, signature request information generated at each stage is collected to form a signature lifecycle data stream; Based on the signature lifecycle data stream, the node trustworthiness parameters and path constraint parameters in the key dynamic evaluation model are adaptively updated, and the model update parameters are written back to the cross-domain sandbox environment to generate a signature lifecycle evolution log, driving the execution of subsequent signature processes.
12. The method according to claim 1, characterized in that, The update of the initial private key includes the following steps: Based on the verification credibility labels output during the multi-level signature verification process, the signature behavior is analyzed and processed to generate a key update evaluation dataset. Determine whether the initial private key needs to be updated. If it is determined that an update is needed, determine the key update based on the key state representation vector. The target private key is regenerated, the original private key is perturbed and updated, and the updated key fragments are securely distributed to the participating nodes in the corresponding security domains. The old key fragments are marked as invalid.