Nova Patents
CN106027245A

Key sharing method and device

Abstract

The invention provides a key sharing method and device. The method comprises the steps of decomposing a key k into n mutually different sub-keys by employing a (t, n) threshold algorithm according to preset parameters of a system; adding time stamps and parity check bits to the sub-keys, thereby generating n sub-key interaction information packets; signing the sub-key interaction information packets by employing a second public key and a first private key, thereby generating n signed information packets, and distributing the signed information packets to corresponding sub-key clients; verifying the signed information packets by employing a second private key and a first public key and checking the signed information packets according to the time stamps and the parity check bits, thereby obtaining the sub-keys, and storing the sub-keys in the corresponding sub-key clients; and obtaining the sub-keys stored in at least t sub-key clients, restoring the at least t sub-keys to the key k by employing the (t, n) threshold algorithm, wherein the first private key and the first public key are a mutually matching key pair, and the second private key and the second public key are a mutually matching key pair.

CN106027245A, drawing sheet 1
Sheet 1 of 17

Term

9.8 yearsto projected expiry

Projected expiry 22 July 2036, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

10 claims: 2 independent, 8 dependent

  1. 1
    A key sharing method, characterized in that the key sharing method comprising:preset parameters according to the system, the use of (t, n) threshold algorithm key k η is decomposed into a mutually different sub-key ;for each of the sub-key add a timestamp and parity bits generated η subkey interactive information packet;using a second public key and private key pair for each of the first sub-key interactive information package signature, generate η packet signatures and the signature of each packet distributed to the respective sub key clients;using a second private key and the first public key to verify the signature packet, and according to the time stamp and parity check digit verify the signature packet for each of the sub-key and stored in the corresponding sub-key in the client;t get at least one of the sub-sub-key client stored key, use (t , n) threshold algorithm the least t subkey back into the key k;wherein the first and the first public private key pair to match each other, the second with the second private key public key match each key pair. 1. 一种密钥共享方法,其特征在于,所述密钥共享方法包括: 根据系统预设参数,利用(t,n)门限算法将密钥k分解成η个互不相同的子密钥; 对各个所述子密钥添加时间戳及奇偶校验位,生成η个子密钥交互信息包; 利用第二公钥及第一私钥对各个所述子密钥交互信息包进行签名,生成η个签名信息 包,并将各所述签名信息包分发给相应的子密钥客户端; 利用第二私钥及第一公钥对所述签名信息包进行验证,并根据时间戳及奇偶校验位校 验所述签名信息包,以获取各所述子密钥并存储在对应的子密钥客户端; 获取至少t个所述子密钥客户端中存储的子密钥,利用(t,n)门限算法将该至少t个子 密钥恢复成所述密钥k;其中,所述第一私钥与第一公钥为互相匹配的密钥对,所述第二私钥与第二公钥为互 相匹配的密钥对。
  2. 6
    - kind of key sharing apparatus, characterized in that said key sharing apparatus comprising:a subkey generation unit for generating system according to preset parameters, the use of (t, η) Threshold algorithm decomposed into key k [eta] a mutually different sub-key;interactive packet generating unit for each of the sub-key add a timestamp and parity bits generated η subkey interactive information package;signature packet distribution unit for using a second public key and private key pair for each of the first sub-key interactive information package is signed, signatures generated η packets, and the signature of each packet distributed to the respective sub key clients;check means for using the second private key and the first public key to verify the signature information packet, and the packet signature and time stamp based on the parity check bit, for each of the sub-key and stores in the corresponding sub-key in the client;key recovery unit for acquiring at least one of the t sub-keys stored in the client sub-key, use (t, n) threshold algorithm for the least t sub-key recovery as the key k;wherein the first and the first public private key pair to match each other, the second private key and the second public key match each key pair. 6. -种密钥共享装置,其特征在于,所述密钥共享装置包括: 子密钥生成单元,用于根据系统预设参数,利用(t,η)门限算法将密钥k分解成η个互不 相同的子密钥; 交互信息包生成单元,用于对各个所述子密钥添加时间戳及奇偶校验位,生成η个子密 钥交互信息包; 签名信息包分发单元,用于利用第二公钥及第一私钥对各个所述子密钥交互信息包进 行签名,生成η个签名信息包,并将各所述签名信息包分发给相应的子密钥客户端; 校验单元,用于利用第二私钥及第一公钥对所述签名信息包进行验证,并根据时间戳 及奇偶校验位校验所述签名信息包,以获取各所述子密钥并存储在对应的子密钥客户端; 密钥恢复单元,用于获取至少t个所述子密钥客户端中存储的子密钥,利用(t,n)门限 算法将该至少t个子密钥恢复成所述密钥k;其中,所述第一私钥与第一公钥为互相匹配的密钥对,所述第二私钥与第二公钥为互 相匹配的密钥对。